2,042 Posted Topics
Re: And if you rclick your cd drive and select properties, do you have an Autoplay tab? No? Then click Start, Run and enter SERVICES.MSC Scroll down to Shell Hardware Detection and make sure this service is Started and set to Automatic. | |
Re: You don't have a microsoft installation cd? Google UBCD, or get this one which gives you a recovery console on a bootable cd, or ... Because you may not be in possession of an Xp install CD, here's a boot disc with a recovery console on it; the console runs … | |
Re: Step 1: Remove either Symantec or AVG AV - very important. Step 2: Get HostsXpert from [url]www.funkytoad.com[/url], start it, press Restore MS hosts file button. Do your scans and post another HT log. | |
Re: Hi, Angel, clean log, but either AVG AV or Trend must go - you definitely should only run one resident AV service, and because you have the Trend suite, to get rid of AVG is my advice... | |
Re: Your log is clean, but if you don't have at least a half-Gig of RAm I can see that all those autostart entries [the O4's..] would bog your sys. Let's look at a couple.... igfxtray.exe - this puts an icon in your sys tray and monitors it by hanging about … | |
Re: We are different people... so it is hard to comment. Certainly you have an adware entry: O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" -you could fix that one with HT, and then delete the file and folder. Fix this one also: O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - [url]http://ak.exe.imgfarm.com/images/noc...1.0.0.15-3.cab[/url] And you have what … | |
Re: Please post a copy of your boot.ini file : go cp, system, advanced tab, startup n recovery settings, press edit -okay, post that notepad that opens. | |
Re: If you have FAT32 and do an improper shutdown windows will want to do a disc check.. there is no need to do it - windows is just programmed to assume that in the case of FAT32 it was a HD error that caused the failure. Skip it. But anyway, … | |
Re: Normally, I'd help. But I see no resident AV, no evidence of an AV online scanner having been run, no firewall [perhaps u use Windows firewall?], no evidence of an AS scanner, or even an online scanning service... what I do see is a load of adware and trojan traces. … | |
Re: You didn't get rid of mcaffee completely.... Use hijackthis to fix these service entries [which will stop them running] and then paste this into the Run text window: sc delete McDetect.exe McTskshd.exe mcupdmgr.exe -press OK at each prompt. It is a friendly thing to do to run ATF cleaner before … | |
Re: I may be barking up the wrong tree, but perhaps if you navigate to this key in your registry [go Start, run, type regedit and press OK]: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall -then rclick on uninstall in left pane, choose permissions and ensure that the administrator [you, perhaps] at least has Full Control. That … | |
Re: No, it cannot be used by a virus to attack your computer, unless the virus wrote a file in there [NOT a .pf file] and then called it from some other location. If a virus process or a trojan once ran then xp would create a prefetch file for it … | |
Re: SP1, eh? No wonder she got whacked.... well, it makes it much more likely, much more. Oh boy... where to start? Download these pgms onto a CDRW for her machine: ==Download this temp file cleaner from [url]http://www.atribune.org/ccount/click.php?id=1[/url] ==Download Avenger from [url]http://swandog46.geekstogo.com/avenger.zip[/url] ==Download this file to your desktop: [url]http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe[/url] ...or from … | |
Re: Try googling "jquery.corner" - you will find that it is legitimate. It is used to shape window/object corners! The [1] would possibly indicate a duplicate.. the .js is just javascript. | |
Re: They are service handlers, they group services, and so depending upon what you have running you will see several svchosts running. | |
Re: Hi lethal, I see that you got rid of a few problem files already, such as C:\temp\svchost.exe etc. A few more things to tidy up... First, you need to make a choice about your resident AV: you cannot keep both AVG and Norton on the machine cos they will conflict … | |
Re: You may check this for yourself, but I think the maximum size that windows setup will allow for a FAT32 partition is 32GB. Either use the NTFS system, or make a sensible size for the windows partition of about 8 -10GB, and a second, third partition for data. OR you … | |
Re: What is this to you? O16 - DPF: {037B3D58-D14A-4C41-BDFD-BD779B0B97BA} - [url]http://www.thepaymentcentre.com/build/vxiewer.cab[/url] Actually, why bother answering?, just remove it: start hijackthis, select Scan Only, place a checkmark against the entry, and then press Fix Checked. Tell us what happens next... | |
Re: Turf out ALL the yahoo gear - toolbars, buttons, search, desktop - uninstall it all. junk. more than that, it's slowing junk. Google too. They have a great search engine website - what else does she need from them? My opinion, only. And follow up on that resident AV issue. … | |
Re: Azriel, just add to your posts, pls don't start a new thread on the same topic.... it makes us chase the thread over several windows.... A big, important point to make: you must run ONLY ONE resident AV - you have both AVG and Mcafee, so one of them must … | |
Re: You have MyWebSearch Search Assistant - Go to Add/Remove programs and remove MyWebSearch Bar, MyWeb Search and Search Assistant. You also have SpywareBot - it has a less than good reputation. Remove it, I think. Remove also any pgm that looks like SpywareQuake. Start hijackthis, select Scan Only, place checkmarks … | |
Re: Sigh.... To start off, move hijackthis to a new folder in C:\. Only then, start hijackthis, select Scan Only, place checkmarks against all the entries listed below that still exist, and then press Fix Checked. O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto O4 - HKLM\..\Run: [winlog] winlog.exe O4 - HKLM\..\RunServices: … | |
Re: guessing.. could be a hidden partition... in which case search won't find it. Try diskmanagement.. go run, diskmgmt.msc, and see if it shows up. If it does rclick it, explore, and you will then see it in folder view in explorer and you can then play inside it. | |
Re: Heya, CC... did you mean to mark the thread solved already? Start hijackthis, select Scan Only, place checkmarks against all the entries listed below that still exist, and then press Fix Checked. O4 - HKLM\..\Run: [startkey] C:\WINDOWS\system32\winsystem.exe O4 - HKCU\..\Run: [startkey] C:\WINDOWS\system32\winsystem.exe Good. Now browse to this file and delete … | |
Re: ...so clean it squeaks, jb. You could fix that O2 entry with no file, but it was never a problem BHO -it's a common enough CLSID. Were/are there any symptoms bothering you? | |
Re: I see that you have MyWay Search Assistant [there, courtesy DELL]. We can get rid of it first off.. First see if it is listed in Add/remove pgms list - remove it if able, then.. Go start > run, paste: MsiExec.exe /X {78d944d7-a97b-4004-ab0a-b5ad06839940} -and Enter. If it is found click … | |
Re: A few things there; let's work through them. Does this work for you? No adware at all? R3 - URLSearchHook: Share Accelerator Toolbar - {f5c93451-2609-4723-a053-5c19516be1a8} - C:\Program Files\Share_Accelerator\tbShar.dll O3 - Toolbar: Share Accelerator Toolbar - {f5c93451-2609-4723-a053-5c19516be1a8} - C:\Program Files\Share_Accelerator\tbShar.dll if you do not want it remove it via add/remove pgms. … | |
Re: You may laugh at this, but I could not see the issues with your first log; the last shows clean also. It can be like that sometimes. I do see that you are still running Nod32 as well as Symantec AV - now that is trouble; two resident AV services … | |
Re: Memory violations usually result when a process you have running tries to dive into protected memory where the kernel is working. Instant BSOD because the OS is programmed that way to protect its operations. You either have a poorly scripted pgm or a virus. Or something else. A driver not … | |
Re: Get ATF Cleaner: ===Download this temp file cleaner from [url]http://www.atribune.org/ccount/click.php?id=1[/url] --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected. Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that … | |
Re: i would be very suspicous of your power supply. It issues a PS Good signal to BIOS which triggers bios execution and so on. If it then cannnot handle the load of assorted operations it will cut the signal. Everything just stops. No warning. | |
Re: Snatch, she has two resident AV services running. That is not at all for the good, cos they interfere terribly - you must remove one of them AVG7 or Avast.. you choose. I certainly would not load up another one.... Apart from that she is clean. I would hope that … | |
Re: Hello, equate, you've got a vundo infestation, but we can deal with that.... For a start would you please delete your copy of HJT and put this one into its place... ==download hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files and then rename the Hijackthis.exe to … | |
Re: You have an annoying little trojan, a worm... please delete hijackthis from the folder where it is and follow this: ==download a fresh copy of hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files. -in that folder start HijackThis by dclicking the .exe; -select Scan Only, place … | |
Re: For a start you have a vundo infection... Please download VundoFix.exe to your desktop from [url]http://www.atribune.org/ccount/click.php?id=4[/url] Double-click VundoFix.exe to start it, click the Scan for Vundo button. *****When the scan completes rclick inside the white text box, lclick the Addmore files? line, paste into the new window these two pathnames … | |
Re: Is it not inbuilt? I just go start > log off > switch user panel > select user n that's it. Can it be faster than that? Why? No files, applications from the old user are closed.... it is available if you have this value in registry: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] DWORD … | |
Re: ==Download Lspfix.exe from [url]http://cexx.org/lspfix.htm[/url] -start it by dclicking the .exe, and press Finish. Start hijackthis, do a Scan Only and place a checkmark beside this entry below, and press Fix Checked. O20 - Winlogon Notify: winfda32 - winfda32.dll (file missing) Post another hjt log. | |
Re: Good lord! You've got every mcafee process and service known to science running there. I think if you examine the fine print you will find that it all protects your sys by bogging it down so slowww that any virus will die of old age before it can replicate. | |
Re: ==Download Lspfix.exe from [url]http://cexx.org/lspfix.htm[/url] -start it by dclicking the .exe, and press Finish. Post another hjt log. | |
Now it is my turn to beg, plead ignorance..:) this one has me beaten, and i am tired of googling for a solution. I recently added a second SATA hd [my boot disk is also SATA, there are no IDE drives on my sys apart from my DVD combo on … | |
Re: run HiJackThis ===download hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files and then rename the Hijackthis.exe to imabunny.exe. -in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis. -click the Scan and … | |
Re: HAL would be umm... bemused if dropped onto another mobo... | |
Re: Looks clean now!! Hey, would you do something for me please? Run regedit and navigate to this key and select it [lclick on Windows in left pane], then rclick AppInit_DLLs in right pane, select Modify binary data, and then type into a notepad what is shown in the window? .Press … | |
I'm on a posting roll.... :) Why does Firefox [the clean mozilla versio] make my pc emit a highpitched buzz when it is loading? The noise is from the mobo, not the sys speaker [I think- anyway it does not emit from my soundsys... could it be the sys speaker?]... … | |
Re: Yep. This is where you get to do a windows Repair..... grab your installation cd, change your one-time boot to cdrom [F11 at boot?] and go past Recovery Console to Repair section in Setup. You won't lose your data, but your apps will possibly need reinstallation. | |
Re: or download a copy of DOS, load it onto a bootable floppy and then use copy, xcopy... | |
Re: For a start you definitely don't want WinAntispyware 2007 - it IS actually spyware, a fake, and gives fake detections to lead you to purchase.! Video activeX is another baddie. Any pgm you do not use every time you turn on is not needed to start... Google toolbar - dyu … | |
Re: Interesting. Although you do not have all the usual signs of it, you do have what appears to be a vundo infection... so just in case something else is hidden would you rename hijackthis.exe to.. umm... imabunny.exe for the next scan, please? Please download VundoFix.exe to your desktop from [url]http://www.atribune.org/ccount/click.php?id=4[/url] … |
The End.