Doctor Inferno 27 Posting Whiz in Training

Post a HijackThis log here.

Doctor Inferno 27 Posting Whiz in Training

You do not require another firewall, it may cause conflict. And yes, Kaspersky has a reliable firewall.

McAfee site advisor is free and you can use it, it's quite good.

And... You are already using the best antivirus... Kaspersky!

Kaspersky has a very strong engine that can disinfect, neutralise or delete almost any virus.

Doctor Inferno 27 Posting Whiz in Training

Is there a way to use javascript to reverse the effect?

Doctor Inferno 27 Posting Whiz in Training

‡‡Please print out or copy this page to Notepad since you will can not have any of browsers open while you

are fixing this and follow it.


‡‡Please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (Repeatedly).

3) Instead of Windows loading as normal, a menu should appear

4) Use the up arrow key to highlight Safe Mode and press Enter.


‡‡Please run HijackThis and click "Scan". Place checks next to the following entries if still present in the

code and

close all browser and other windows except for HijackThis, and click "Fix Checked".

O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O20 - Winlogon Notify: __c0042D22 - C:\WINDOWS\system32\__c0042D22.dat (file missing)
O20 - Winlogon Notify: __c00C3FCC - C:\WINDOWS\system32\__c00C3FCC.dat (file missing)

‡‡Run your Antivirus and do a full scan remember this is all in safe mode.


‡‡Reboot into Normal Mode.


‡‡Please take the following steps with the Internet Explorer:

Internet Explorer -> Tools -> Internet Options -> Advanced -> Click - Restore advanced Settings -> Click - Reset... -> Click

- OK


‡‡Do another scan with HiJackThis in normal windows mode and post your new log file here for final verification. Make sure it

is a new log file.


Also let me know how the systems …

Doctor Inferno 27 Posting Whiz in Training

‡‡Please print out or copy this page to Notepad since you will can not have any of browsers open while you

are fixing this and follow it.


‡‡Please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (Repeatedly).

3) Instead of Windows loading as normal, a menu should appear

4) Use the up arrow key to highlight Safe Mode and press Enter.


‡‡Please run HijackThis and click "Scan". Place checks next to the following entries if still present in the

code and

close all browser and other windows except for HijackThis, and click "Fix Checked".

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = [url]http://windiwsfsearch.com[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = [url]http://windiwsfsearch.com[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://safesearch.cyberdefender.com/smallsearch.html[/url]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://www.dufpy.com[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://windiwsfsearch.com[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://windiwsfsearch.com/ie6.html[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://windiwsfsearch.com[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://windiwsfsearch.com[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://windiwsfsearch.com[/url]
O2 - BHO: VRLWarningBHO Class - {0DCD4F35-9FD5-420b-A9AA-FED0E2AECEE0} - C:\Program Files\VirusRL2009\AVLWarning.dll (file missing)
O2 - BHO: 590075 helper - {AFC8A14F-B50A-4F0F-8FB7-77982092D81D} - C:\WINDOWS\system32\590075\590075.dll (file missing)
O2 - BHO: (no name) - {CFEE97A3-4911-444D-8BE8-E243A23D3DE2} - C:\Program Files\Applications\iebt.dll (file missing)
O3 - Toolbar: Internet Service - {144A6B24-0EBC-4D89-BF09-A06A718E57B5} - C:\Program Files\Applications\iebr.dll (file missing)

‡‡Run your Antivirus and do a …

Doctor Inferno 27 Posting Whiz in Training

If I have helped you, please mark the thread as solved.

Thank you.

Doctor Inferno 27 Posting Whiz in Training

So everything is running great for you? If so, I'm glad that I am able to help. Also, please mark the thread as solved.

Doctor Inferno 27 Posting Whiz in Training

And why?...

Doctor Inferno 27 Posting Whiz in Training

Which is better? Which should I choose?

Doctor Inferno 27 Posting Whiz in Training

It is best to install it in the C drive. Also note that no 2 antiviruses should be installed at the same time, it might cause your computer to crash.

Choosing between Internet Security and the antivirus is really up to you. Internet Security products provide an extra; firewall and antispyware which you need if you don't already have them.

Doctor Inferno 27 Posting Whiz in Training

Download SmitFraudFix from here and follow the instructions:

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

and tell me how your system is running now.

Doctor Inferno 27 Posting Whiz in Training

Kaspersky won't slow down your PC. the ram usage of kaspersky shown in my task manager is barely 1MB.

Doctor Inferno 27 Posting Whiz in Training

I recommend Kaspersky if you can buy. It's by far the best I've tested.

Doctor Inferno 27 Posting Whiz in Training

‡‡Please print out or copy this page to Notepad since you cannot have any browsers open while you are fixing this and try to follow it as closely as possible taking it step by step.

‡‡Update your Antivirus program.

‡‡Please download Spybot Search and Destroy install it and update the program.

http://www.safer-networking.org/en/mirrors/index.html


‡‡Please download VundoFix.exe to your desktop. Ignore the AntiVirus warnings and download it anyway because you need to run it. Wait on installation and running.

http://www.atribune.org/ccount/click.php?id=4


‡‡Download CleanUp! and install it. Wait on installation and running.

http://www.stevengould.org/downloads/cleanup/CleanUp452.exe


‡‡Please download following program CWSHREDDER. Wait on installation and running.

http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe


‡‡Download about:Buster and save it to your desktop. When it has finished downloading, unzip the folder to your desktop as well. You should now be left with an aboutbuster folder on your desktop.Wait on installation and running.

http://www.malwarebytes.org/AboutBuster.zip


‡‡I would suggest though that you download CCleaner. It is a great little program that I use every time I close my browser to get rid of temporary files. I usually just run the cleaner part every time I'm done with the browser.During the install there will be check marks for checking for updates that part I do not use and also to install a tool bar for yahoo or something. Make sure those are unchecked unless you want another …

Doctor Inferno 27 Posting Whiz in Training

Post a HijackThis log here.

Doctor Inferno 27 Posting Whiz in Training

Close all browser windows, open HijackThis, do a scan and remove this entry:

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

Here are some entries that are optional to remove so that your computer starts up faster:

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: VersionTrackerPro.lnk = ?

Now, rename HijackThis to Inferno and post back a new log, also tell me how your system is running.

Doctor Inferno 27 Posting Whiz in Training

You are probably infected with antivirus 2009.

Follow this removal guide on GeekPolice:

http://geekpolice.net/malware-removal-guides-f12/how-to-remove-antivirus-2009-removal-guide-t3138.htm

Doctor Inferno 27 Posting Whiz in Training

I recommend SuperAntispyware

Doctor Inferno 27 Posting Whiz in Training
<?php
/*************************************************
 * Max's File Uploader
 *
 * Version: 1.0
 * Date: 2007-11-26
 *
 ****************************************************/
class maxUpload{
    var $uploadLocation;
   
    /**
    * Constructor to initialize class varaibles
    * The uploadLocation will be set to the actual
    * working directory
    *
    * @return maxUpload
    */
    function maxUpload(){
        $this->uploadLocation = getcwd().DIRECTORY_SEPARATOR;
    }

    /**
    * This function sets the directory where to upload the file
    * In case of Windows server use the form: c:\\temp\\
    * In case of Unix server use the form: /tmp/
    *
    * @param String Directory where to store the files
    */
    function setUploadLocation($dir){
        $this->uploadLocation = $dir;
    }
   
    function showUploadForm($msg='',$error=''){
?>
      <div id="container">
            <div id="header"><div id="header_left"></div>
            <div id="header_main">Max's File Uploader</div><div id="header_right"></div></div>
            <div id="content">
<?php
if ($msg != ''){
    echo '<p class="msg">'.$msg.'</p>';
} else if ($error != ''){
    echo '<p class="emsg">'.$error.'</p>';

}
?>
                <form action="" method="post" enctype="multipart/form-data" >
                    <center>
                        <label>File:
                            <input name="myfile" type="file" size="30" />
                        </label>
                        <label>
                            <input type="submit" name="submitBtn" class="sbtn" value="Upload" />
                        </label>
                    </center>
                </form>
            </div>
            <div id="footer"><a href="http://www.phpf1.com" target="_blank">Powered by PHP F1</a></div>
        </div>
<?php
    }

    function uploadFile(){
        if (!isset($_POST['submitBtn'])){
            $this->showUploadForm();
        } else {
            $msg = '';
            $error = '';
           
            //Check destination directory
            if (!file_exists($this->uploadLocation)){
                $error = "The target directory doesn't exists!";
            } else if (!is_writeable($this->uploadLocation)) {
                $error = "The target directory is not writeable!";
            } else {
                $target_path = $this->uploadLocation . basename( $_FILES['myfile']['name']);

                if(@move_uploaded_file($_FILES['myfile']['tmp_name'], $target_path)) {
                    $msg = basename( $_FILES['myfile']['name']).
                    " was uploaded successfully!";
                } else{
                    $error = "The upload process failed!";
                }
            }

            $this->showUploadForm($msg,$error);
        }

    }

}
?>

Where can i set the file upload directory?

Doctor Inferno 27 Posting Whiz in Training

Post your HijackThis log here.

Doctor Inferno 27 Posting Whiz in Training

please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (Repeatedly).

3) Instead of Windows loading as normal, a menu should appear

4) Use the up arrow key to highlight Safe Mode and press Enter.


Please run HijackThis and click "Scan". Place checks next to the following entries if still present in the code and close all browser and other windows except for HijackThis, and click "Fix Checked".

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: (no name) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - (no file)

O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)

O2 - BHO: (no name) - {96372AB6-15EB-4316-B497-71C741BC548C} - (no file)

O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)

O3 - Toolbar: (no name) - {35065594-9169-4A34-B167-FC4865038E53} - (no file)

O3 - Toolbar: (no name) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - (no file)

O23 - Service: perfmons - Unknown owner - C:\WINDOWS\system32\perfs.exe

O23 - Service: Routing Service (Routing) - Unknown owner - C:\WINDOWS\system32\routing.exe

O23 - Service: roxtctm pass-through (roxtctm) - Unknown owner - C:\WINDOWS\system32\roxtctm.exe (file missing)

O23 - Service: roytctm Service (roytctm) - Unknown owner - C:\WINDOWS\system32\roytctm.exe (file missing)

O23 - Service: sobicyt Service (sobicyt) - Unknown owner - C:\WINDOWS\system32\sobicyt.exe (file missing)

O23 - Service: sotpeca Event propagation service (sotpeca) - Unknown owner - C:\WINDOWS\system32\sotpeca.exe (file missing)

O23 - Service: soxpeca Service (soxpeca) - Unknown owner …
Doctor Inferno 27 Posting Whiz in Training

My website has this kind of 'laggy' scrolling when i enable smooth scrolling in firefox.

Doctor Inferno 27 Posting Whiz in Training

Is there a way to slow down the scrolling or something like that?

Doctor Inferno 27 Posting Whiz in Training

Your log file is dirty.

‡‡Please print out or copy this page to Notepad since you will can not have any of browsers open while you are fixing this and follow it.


‡‡Next, please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (Repeatedly).

3) Instead of Windows loading as normal, a menu should appear

4) Use the up arrow key to highlight Safe Mode and press Enter.


‡‡Please run HijackThis and click "Scan". Place checks next to the following entries if still present in the code and

close all browser and other windows except for HijackThis, and click "Fix Checked".

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZCxdm238YYIE

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...tup1.0.1.0.cab

O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwssvc.exe

‡‡Run your Antivirus and do a full scan remember this is all in safe mode.


‡‡Reboot into Normal Mode.


‡‡Please take the following steps with the Internet Explorer:

Doctor Inferno 27 Posting Whiz in Training

Glad that I am able to help.

You can read this article on How To Avoid An Infection here:

http://geekpolice.net/malware-removal-guides-f12/-t2710.htm

Please also mark the thread as sloved.

Regards.

Doctor Inferno 27 Posting Whiz in Training

Open hikacthis, place a check beside this and fix it:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://server.toolbar.rediff.com/too...l?mode=toolbar

R3 - URLSearchHook: Rediff Toolbar - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\Rediff Toolbar\3.0\redifftoolbar.dll

O3 - Toolbar: Rediff Toolbar - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\Rediff Toolbar\3.0\redifftoolbar.dll

Then post back with a hiackthis log from version 2.0.2

Doctor Inferno 27 Posting Whiz in Training

Download the latest version of HijackThis. ( version 2.0.2)

Doctor Inferno 27 Posting Whiz in Training

‡‡Please print out or copy this page to Notepad since you cannot have any browsers open while you are fixing this and try to follow it as closely as possible taking it step by step.

‡‡Update your Antivirus program.

‡‡Please download Spybot Search and Destroy install it and update the program.

http://www.safer-networking.org/en/mirrors/index.html


‡‡Please download VundoFix.exe to your desktop. Ignore the AntiVirus warnings and download it anyway because you need to run it. Wait on installation and running.

http://www.atribune.org/ccount/click.php?id=4


‡‡Download CleanUp! and install it. Wait on installation and running.

http://www.stevengould.org/downloads/cleanup/CleanUp452.exe


‡‡Please download following program CWSHREDDER. Wait on installation and running.

http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe


‡‡Download about:Buster and save it to your desktop. When it has finished downloading, unzip the folder to your desktop as well. You should now be left with an aboutbuster folder on your desktop.Wait on installation and running.

http://www.malwarebytes.org/AboutBuster.zip


‡‡I would suggest though that you download CCleaner. It is a great little program that I use every time I close my browser to get rid of temporary files. I usually just run the cleaner part every time I'm done with the browser.During the install there will be check marks for checking for updates that part I do not use and also to install a tool bar for yahoo or something. Make sure those are unchecked unless you want another …

Doctor Inferno 27 Posting Whiz in Training

Post a HijackThis log in the virus & nasties forum

Doctor Inferno 27 Posting Whiz in Training

Is there a way to enable or disable smooth scrolling in CSS?

My site has this very slow smooth scrolling when I enable smooth scrolling in firefox.

Doctor Inferno 27 Posting Whiz in Training

Post a hijackthis log

Doctor Inferno 27 Posting Whiz in Training

Please post a HijackThis log file so we can help you from there.

Doctor Inferno 27 Posting Whiz in Training

Open HijackThis and do a scan, place a check beside these entries:

O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)

O3 - Toolbar: gksraemq - {3CC64413-8D34-4336-A176-4DA5F7C147F1} - C:\WINDOWS\gksraemq.dll (file missing)

O4 - HKLM\..\Run: [lphcvnkj0e79g] C:\WINDOWS\system32\lphcvnkj0e79g.exe
O4 - HKLM\..\Run: [inrhcrnkj0e79g] C:\Documents and Settings\Administrator\Local Settings\Temp\.tt15A.tmp.exe
O4 - HKLM\..\Run: [\VIE89C2.exe] C:\Windows\System32\VIE89C2.exe
O4 - HKLM\..\Run: [\VIE89C6.exe] C:\Windows\System32\VIE89C6.exe
O4 - HKLM\..\Run: [\VIE89D0.exe] C:\Windows\System32\VIE89D0.exe
O4 - HKLM\..\Run: [\VIE89DB.exe] C:\Windows\System32\VIE89DB.exe
O4 - HKLM\..\Run: [\VIE8A8E.exe] C:\Windows\System32\VIE8A8E.exe
O4 - HKLM\..\Run: [\VIE10.exe] C:\Windows\System32\VIE10.exe
O4 - HKLM\..\Run: [\VIE14.exe] C:\Windows\System32\VIE14.exe
O4 - HKLM\..\Run: [\VIE15C.exe] C:\Windows\System32\VIE15C.exe
O4 - HKCU\..\Run: [\VIE89C2.exe] C:\Windows\System32\VIE89C2.exe
O4 - HKCU\..\Run: [\VIE89C6.exe] C:\Windows\System32\VIE89C6.exe
O4 - HKCU\..\Run: [\VIE89D0.exe] C:\Windows\System32\VIE89D0.exe
O4 - HKCU\..\Run: [\VIE89DB.exe] C:\Windows\System32\VIE89DB.exe
O4 - HKCU\..\Run: [\VIE8A8E.exe] C:\Windows\System32\VIE8A8E.exe
O4 - HKCU\..\Run: [\VIE10.exe] C:\Windows\System32\VIE10.exe
O4 - HKCU\..\Run: [\VIE11.exe] C:\Windows\System32\VIE11.exe
O4 - HKCU\..\Run: [\VIE12.exe] C:\Windows\System32\VIE12.exe
O4 - HKCU\..\Run: [\VIE13.exe] C:\Windows\System32\VIE13.exe
O4 - HKCU\..\Run: [\VIE1236.exe] C:\Windows\System32\VIE1236.exe
O4 - HKCU\..\Run: [\VIE14.exe] C:\Windows\System32\VIE14.exe
O4 - HKCU\..\Run: [\VIE15C.exe] C:\Windows\System32\VIE15C.exe

O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html

O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)

O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanage...ex-2.2.1.6.cab

O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

O24 - Desktop Component …

Doctor Inferno 27 Posting Whiz in Training

Anybody knows how to transfer files to vmware?

Doctor Inferno 27 Posting Whiz in Training

A easy way to find keywords in firefox is to press Ctrl + F

A bar will pop in at the bottom of the screen you can easily find keywords.

sittas87 commented: nice tip ;) +3
Doctor Inferno 27 Posting Whiz in Training

I recommend getting either a .com, .net or .org

Doctor Inferno 27 Posting Whiz in Training

You have to have a specific targeted audience for your site, I don't think a forum which does everything will be successful, or maybe it will be difficult.

Doctor Inferno 27 Posting Whiz in Training

Firstly, you can get some money and you can make new friends.

Doctor Inferno 27 Posting Whiz in Training

If you are just a basic user getting Home premium is enough.

Doctor Inferno 27 Posting Whiz in Training

Try to submit interesting articles to digg.com

it has significantly improved my site's traffic.

It is now in the 500k range since it started on 1st July 2008

Doctor Inferno 27 Posting Whiz in Training

Hi all,

I have just submitted my site to the link directory.

I was just wondering, is there a way to edit the description?

Doctor Inferno 27 Posting Whiz in Training

Is it possible to convert a punBB CSS script to phpbb3 CSS?

Doctor Inferno 27 Posting Whiz in Training

So... Vista is good after all.

You'll know why after seeing this:

http://www.mojaveexperiment.com/

Doctor Inferno 27 Posting Whiz in Training

Please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (Repeatedly).

3) Instead of Windows loading as normal, a menu should appear

4) Use the up arrow key to highlight Safe Mode and press Enter.


Please run HijackThis and click "Scan". Place checks next to the following entries if still present in the code and close all browser and other windows except for HijackThis, and click "Fix Checked".


C:\DOCUME~1\Shalva\LOCALS~1\Temp\wintuihh.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


Rename hijackthis.exe to inferno.exe and post a new log, also tell me the condition of your PC.

Doctor Inferno 27 Posting Whiz in Training

Sorry for the late reply i haven't been checking back.

Please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (Repeatedly).

3) Instead of Windows loading as normal, a menu should appear

4) Use the up arrow key to highlight Safe Mode and press Enter.

Please run HijackThis and click "Scan". Place checks next to the following entries if still present in the code and close all browser and other windows except for HijackThis, and click "Fix Checked".

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.rd.yahoo.com/customize/yco.../info/ie6.html


O2 - BHO: (no name) - {01A33D85-4706-452A-B71A-99510ADA8C0C} - C:\WINDOWS\system32\hgGaayAP.dll (file missing)


O2 - BHO: (no name) - {DEB4C77B-189C-4011-A46C-C46EA56EDDD7} - C:\WINDOWS\system32\ljJAQJCr.dll (file missing)


O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll (file missing)


O4 - HKLM\..\Policies\Explorer\Run: [5h5qxgibA3] C:\Documents and Settings\All Users\Application Data\wtwjilgr\sjszedyz.exe


O17 - HKLM\System\CCS\Services\Tcpip\..\{2D8F349F-3BCF-4027-8B1A-6CB1E9AB97FF}: NameServer = 85.255.116.133,85.255.112.128



O17 - HKLM\System\CCS\Services\Tcpip\..\{A5757C1C-284B-45B8-BE97-C5D9D177C50F}: NameServer = 85.255.116.133,85.255.112.128


O17 - HKLM\System\CCS\Services\Tcpip\..\{B36B073F-A25F-4AFE-8DFF-2E21B276EBAB}: NameServer = 85.255.116.133,85.255.112.128


O17 - HKLM\System\CCS\Services\Tcpip\..\{E4F22FAC-9098-4ECA-A4E2-EC83D271936F}: NameServer = 85.255.116.133,85.255.112.128



O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.133 85.255.112.128


O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.133 85.255.112.128


O20 - Winlogon Notify: hgGaayAP - hgGaayAP.dll (file missing)

Rename hijackthis.exe to inferno.exe

Do another scan post a new log, also tell me the condition of your PC.

Doctor Inferno 27 Posting Whiz in Training

Boot into BIOS, gol to Peripherals > SATA Devices Configuration > SATA Mode [RAID] and change to [IDE]

Doctor Inferno 27 Posting Whiz in Training

There is no way actually...

And please do not attempt to download a block checker, they usually contain malicious files.

Doctor Inferno 27 Posting Whiz in Training

You can post a hijackthis log and i can take a look at it for you. Malware might be the cause.

Doctor Inferno 27 Posting Whiz in Training

Go to the BIOS configuration,

Usually by pressing the "Delete" button.

Look for the "HALT ON" Option.

Select it and choose the "No Errors" Options.

Save your changes and reboot.


It may also be caused by the CMOS abttery failing, which is very unlikely because your computer is onlt 3 days old...

Doctor Inferno 27 Posting Whiz in Training

You can try the software "mp3 my mp3" It records all audio the computer makes. you can also choose to record audio from a microphone.