It means that you have a registry entry pointing at startup to that file which may no longer exist. Time to clean it out, and check on the job u did... :).
Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 -click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next, if you run Firefox click that button at the top, Select All again, and Empty Selected again.
Close ATF.
Go here and dl hijackthis: http://216.180.233.162/~merijn/files/HijackThis.exe
-install it to a new folder alongside your program files.
-in that folder start HijackThis by dclicking the .exe; now close ALL open windows including the explorer window containing HijackThis.
-Click the Scan and Save a Logfile button. Post the log here.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Hi munecka, you didn't get it all.. :)
Download killbox from here:- http://www.downloads.subratam.org/KillBox.zip unzip it onto your desktop.
Dclick killbox to start it. First off, make a quick check on your hosts file : go Tools, click Hosts File - in the notepad that opens the default is a hashed example followed by a valid hosts redirection line, 127.0.0.1 localhost
If there are no other lines in the file then skip the Hoster instruction block below.
In Killbox select "Delete on reboot", click the "single file" button.
Copy the pathname in the following line into the textbox:-
C:\WINDOWS\system32\xuabhqgp.dll
Click the red and white X button, click Yes on the reboot prompt, click OK if a pendingfilerenameoperation box opens. [do not be concerned if it says it cannot find a file...]
On restart:-
==Please download Hoster: http://www.funkytoad.com/download/hoster.zip and Extract it to your Desktop.
==Click the Restore MS Hosts Button and then click OK and exit Hoster.
Now open an explorer window and rename hijackthis.exe to Simplesimon.exe. Start hijackthis [Simplesimon], close all other applications and windows and press Do a Scan Only. Place checks against all the following if they exist:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\xuabhqgp.dll",setvm
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imagesrvr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://195.95.*.*
O15 - Trusted IP range: http://195.225.*.*
O15 - Trusted IP range: http://205.177.*.*
O15 - Trusted IP range: http://205.188.*.*
O15 - Trusted IP range: http://216.239.*.*
O15 - Trusted IP range: http://66.230.*.*
O15 - Trusted IP range: http://66.235.*.*
Press Fix Checkedand close hijackthis.
===Get CCleaner from http://www.ccleaner.com/ - and put it in a new folder. You should aim to keep this one for general use. I set it from the install checkboxes to only open from the recycle bin. It's neater that way.
===GET AVG antispyware 7.5 here.. http://free.grisoft.com/doc/5390/lng/us/tpl/v5 -the link is almost at the bottom of the page , avgas 7.5.0.50. Install it and update it.
Now run Ccleaner from the recycle bin rclick menu using its default settings [if you set up CCleaner as i suggested, rclicking the bin icon should give you the Open CCleaner option...]. Select the Cleaner icon and the Windows tab; press Run Cleaner. Next select the Applications tab and Run Cleaner again.
Start AVG a-s 7.5; under Scanner/ Settings set Recommended actions to Quarantine, and run the scan. Save the log file and only then click Apply all actions. Post the log file.
Do another Hijackthis scan and post the new logfile.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
harding, could you please repost that log and request into a new thread? And define your problem for us also... symptoms are important.
In a new thread it will get individual attention.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300