Page 1 of 1

Sonic activation module

Posted: 27 Nov 2006, 22:46
by Brideoffrankenstein
Right this is really driving me bananas and has been for a while......

I bought a shiny new Dell about a year ago and it had a copy of Mcafee anti-virus on. I removed this after a while as it was a bit irritating and added another program for my anti-virus type things.

Since I uninstalled Mcafee I get a thing called "Sonic Activation Module" come up every time I boot up my PC. It asks me where I want to install it from but whatever you choose it won't do anything or go away. To get rid of it I have to keep pressing "cancel" while it is trying to install itself otherwise I can't shut my PC down as it says there are still active programs running.

This is getting really annoying now, can any of you peeps help me?

Posted: 27 Nov 2006, 22:53
by Izzy HaveMercy
HiJackThis to the rescue again! ;D

Run this proggie, don't let it delete ANYTHING (yet), but it will produce a logfile. Post that logfile here or PM it to me.

When all else fails, ask Scotty :twisted:

IZ.

Posted: 27 Nov 2006, 23:09
by Brideoffrankenstein
Thanks to the mighty IZ :notworthy:

:eek:
Logfile of HijackThis v1.99.1
Scan saved at 22:08:44, on 27/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\CG CoreEl\SyncQuick\SyncQuick.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\DOCUME~1\ELIZAB~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DK
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\WINDOWS\system32\WSBar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SyncQuick] C:\Program Files\CG CoreEl\SyncQuick\SyncQuick.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Search with Wanadoo - res://C:\WINDOWS\system32\WSBar.dll/VSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9256118578
O17 - HKLM\System\CCS\Services\Tcpip\..\{56D7B49C-53DB-43E0-9E89-CF649B156CED}: NameServer = 195.92.195.95 195.92.195.94
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

Posted: 27 Nov 2006, 23:20
by EvilBastard
In case of Sonic Attack on your district, follow these rules.....
If you are making love, it is imperative to bring all bodies to orgasm simultaneously
Do not waste time blocking your ears
Do not waste time seeking a soundproof shelter
Try to get as far away from the sonic source as possible, but do not panic.....
Use your wheels, it is what they are for

Posted: 27 Nov 2006, 23:57
by mh
EvilBastard wrote:In case of Sonic Attack on your district, follow these rules.....
If you are making love, it is imperative to bring all bodies to orgasm simultaneously
Do not waste time blocking your ears
Do not waste time seeking a soundproof shelter
Try to get as far away from the sonic source as possible, but do not panic.....
Use your wheels, it is what they are for
THINK ONLY OF YOURSELF
:lol: :notworthy: :lol: :notworthy: :lol: :notworthy:

Zero help to BoF, of course, but perfect all the same.

Her machine looks pretty healthy to me, actually... and this one seems from my research to come from a Creative webcam: http://forums.creative.com/creativelabs ... ge.id=3414

Posted: 28 Nov 2006, 00:21
by EvilBastard
mh wrote:Zero help to BoF, of course
No help now, certainly, but words to live by 8)

Posted: 28 Nov 2006, 00:43
by CellThree
The Sonic thing is something to do with the CD Burning software that Dell installs.

There's a few things about it if you Google it

Posted: 28 Nov 2006, 00:57
by weebleswobble
I thought this thread was going to be about a death metal mutant quite peeved off band :innocent:

Posted: 28 Nov 2006, 10:27
by limur
CellThree wrote:The Sonic thing is something to do with the CD Burning software that Dell installs.
Yes, it's part of Sonic MyDVD, the CD/DVD burning software that Dell installs. It's quite a good piece of software, at least it does what it says on the box.

I think it's part of Roxio now, or the other way round...

http://www.sonic.com/

Posted: 28 Nov 2006, 18:50
by Izzy HaveMercy
Sonic is indeed the firm that supports you with rather good software for burning CDs/DVDs, were it not that they ALWAYS provide you with the free crap that only functions when you update it and PAY for it.

Now, if you are going to use the Sonic software, go to the site LIMUR pointed out, http://www.sonic.com and search for an update. Be ready to pay for it tho.

If you are not going to use Sonic software, and opt for a more stable solution like, for example, NERO 6, you can delete these two lines:

O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

These are the two Sonic files that check your computer at startup and give these annoying messages.

IZ.

Posted: 28 Nov 2006, 20:29
by Brideoffrankenstein
Aha, right thanks IZ :notworthy:

I have deleted the two lines you said, and shall do a reboot in a bit and see if it works!

:notworthy: :notworthy: :notworthy: :notworthy:

Posted: 28 Nov 2006, 20:37
by Izzy HaveMercy
Prepare to buy a new PC ;)

IZ.

Posted: 28 Nov 2006, 20:54
by Brideoffrankenstein
Oh IZ you are an absolute star :notworthy: :notworthy: :kiss:

It booted up perfectly!!!!!!! :D :D :D :D :D

Posted: 28 Nov 2006, 21:13
by Izzy HaveMercy
Brideoffrankenstein wrote:Oh IZ you are an absolute star :notworthy: :notworthy: :kiss:

It booted up perfectly!!!!!!! :D :D :D :D :D
Yay for me! ;D (oh, AND for HiJackThis AND some helpful tips on this and that there geek forum ;) )

IZ.

Posted: 28 Nov 2006, 21:13
by Izzy HaveMercy
Scotty is SO out of business, BTW... :twisted:

IZ.

Posted: 28 Nov 2006, 21:14
by Brideoffrankenstein
:lol: A great help he was, he never even replied to the thread!

Posted: 28 Nov 2006, 21:16
by Izzy HaveMercy
Brideoffrankenstein wrote::lol: A great help he was, he never even replied to the thread!
He only turns his head for really BIG problems, not these trifles of mere mortals ;)

IZ.

Posted: 29 Nov 2006, 23:46
by Arch Deviant
Izzy HaveMercy wrote:Scotty is SO out of business, BTW... :twisted:

IZ.
:evil: :evil:

The man's a star :notworthy: :notworthy:

Posted: 29 Nov 2006, 23:51
by weebleswobble
Arch Deviant wrote:
Izzy HaveMercy wrote:Scotty is SO out of business, BTW... :twisted:

IZ.
:evil: :evil:

The man's a star :notworthy: :notworthy:
Games up, you really are Keith aren't you :lol: