bunny 0 Light Poster

bunny, here i can give u only one suggestion

U create another User Account by clicking Start-Control Panel-User Accounts, and compare both the user accounts settings

The settings of both accounts are exact the same but the second account which i created are what i want on screen :the rectangle disappears under those icon on desktop.

bunny 0 Light Poster

This is my Desktop settings screen shot check whether ur is exactly set like this

yah look:
[IMG]http://img302.imageshack.us/img302/9400/desktop2vv.th.jpg[/IMG]

bunny 0 Light Poster

Merry Christmas
Go to My Computer-Properties-Advanced under Performace click on settings and on visual Effects tab see whether Let Windows choose what's best for my computer is selected and check whether all the options are Check marked

i did tried to uncheck the "Use drop shadows for icon labels on the desktop - option" but it doesn't help anything. :(

bunny 0 Light Poster

Why under the name of the icon on desktop there is always a white rectangle? i mean this [IMG]http://img489.imageshack.us/img489/3138/untitled5pv.jpg[/IMG] not like this [img]http://img489.imageshack.us/img489/6950/desktop4ry.jpg[/img]
ANd how can i get out of it?i know it doesn't matter but it makes the wallpaper and the desktop looks so ugly.
thanks and Merry Xmas

bunny 0 Light Poster

I'm not actually sure what's going on with the desktop settings. Can you effect any changes by right-clicking on the desktop, choosing "Properties" from the resulting drop-down menu, and "twiddling" with any of settings under the tabs there (Themes, Desktop, etc.)?

even when i change the theme it's still being in the same problem

bunny 0 Light Poster

All looks good!

Your HijackThis log is clean now, and the report from ewido shows that ewido found and deleted a handful of other "nasties" that were lurking in your system. :)


Does everything seem to be functioning normally now?

Yahhhh everything is working so fine now Thank you every much.but one more thing is anoying me is this:Why under the name of the icon on desktop there is always a white rectangle? i mean this [IMG]http://img489.imageshack.us/img489/3138/untitled5pv.jpg[/IMG] not like this [img]http://img489.imageshack.us/img489/6950/desktop4ry.jpg[/img]
ANd how can i get out of it?i know it doesn't matter but it makes the wallpaper and the desktop looks so ugly :mrgreen:

bunny 0 Light Poster
Logfile of HijackThis v1.99.1
Scan saved at 4:21:35 PM, on 12/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\INTERN~2\IDMan.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.yahoo.com/[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com[/url]
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKCU\..\Run: [IDMan] C:\PROGRA~1\INTERN~2\IDMan.exe /onboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: …
bunny 0 Light Poster

i think i'm gonna do it 2morrow cuz it's too late now and i have to go sleep for school 2morrow.i tell u this cuz i don't want u to keep waiting and checking if i have reply :cheesy:

bunny 0 Light Poster

Logfile of HijackThis v1.99.1
Scan saved at 12:14:43 AM, on 12/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\INTERN~2\IDMan.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: …

bunny 0 Light Poster

I'm asking for a new log from the HijackThis program, not the L2Mfix program.
Run HijackThis again and post the log it generates in the same way you did in your first post.

k sorry i misunderstood.Sorry :cheesy:i'll do it rite now

bunny 0 Light Poster

There's an L2M log in that post, but no log from HijackThis.

i have no idea what i did wrong.I did exact what u said i picked option #2 to run fix then the computer asked me to reboot then i reboot then it appeared the notepad with those words in it and i just copy and paste everything i got from there.so i should i do now?

bunny 0 Light Poster

There's an L2M log in that post, but no log from HijackThis.

i have no idea what i did wrong.I did exact what u said i picked option #2 to run fix then the computer asked me to reboot then i reboot then it appeared the notepad with those words in it and i just copy and paste everything i got from there.

bunny 0 Light Poster

I had asked for another HijackThis log in addition to the L2M log; can you post one please?

i did right after u asked me.Post #5

bunny 0 Light Poster

I just wanna ask if i'm done with this?Is so i have one more thing to ask:
Why under the name of the icon on desktop there is always a white rectangle? i mean this [IMG]http://img489.imageshack.us/img489/3138/untitled5pv.jpg[/IMG] not like this [img]http://img489.imageshack.us/img489/6950/desktop4ry.jpg[/img]
ANd how can i get out of it?i know it doesn't matter but it makes the wallpaper and the desktop looks so ugly :mrgreen:

bunny 0 Light Poster
L2mfix Beta 121205
Creating Account.
The command completed successfully.

Adding Administrative privleges. 
The command completed successfully.

Checking for L2MFix account(0=no 1=yes): 
1
 Granting SeDebugPrivilege to L2MFIX   ... successful

Running From:
C:\WINDOWS\system32

Killing Processes! 

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 [email]Craig.Peacock@beyondlogic.org[/email]
Killing PID 844 'smss.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 [email]Craig.Peacock@beyondlogic.org[/email]
Killing PID 960 'winlogon.exe'
Killing PID 960 'winlogon.exe'
Killing PID 960 'winlogon.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 [email]Craig.Peacock@beyondlogic.org[/email]
Killing PID 256 'explorer.exe'
Killing PID 256 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 [email]Craig.Peacock@beyondlogic.org[/email]
Error, Cannot find a process with an image name of rundll32.exe
Restoring Sedebugprivilege:
 Granting SeDebugPrivilege to Administrators   ... successful
 Granting SeDebugPrivilege to Administrateurs   ... failed (GetAccountSid(Administrateurs)=1332 
 Granting SeDebugPrivilege to Administrat÷rer   ... failed (GetAccountSid(Administrat÷rer)=1332 
 Granting SeDebugPrivilege to Administradores   ... failed (GetAccountSid(Administradores)=1332 
 Granting SeDebugPrivilege to Amministratore   ... failed (GetAccountSid(Amministratore)=1332 
 Granting SeDebugPrivilege to Administratoren   ... failed (GetAccountSid(Administratoren)=1332 

Scanning First Pass. Please Wait!

First Pass Completed 

Second Pass Scanning 

Second pass Completed!
Backing Up: C:\WINDOWS\system32\guard.tmp
        1 file(s) copied.
deleting: C:\WINDOWS\system32\guard.tmp  
Successfully Deleted: C:\WINDOWS\system32\guard.tmp


Zipping up files for submission:
  adding: Documents and Settings/Rick Dang/Desktop/l2mfix/backregs/notibac.reg (164 bytes security) (deflated 87%)
  adding: Documents and Settings/Rick Dang/Desktop/l2mfix/backregs/shell.reg (164 bytes security) (deflated 73%)


Restoring Windows Update Certificates.:

deleting local copy: guard.tmp   

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows …
bunny 0 Light Poster
L2MFIX find log 121205
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
  6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000
"Dllname"="C:\\Program Files\\Intel\\Wireless\\Bin\\LgNotify.dll"
"Logon"="IntelUserLogon"
"Logoff"="IntelUserLogoff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Syncmgr]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\l62slgf7162.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{1B5B3EB8-57D0-AE38-F549-A422C00FFDDC}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions …
bunny 0 Light Poster

But how did u do it

i just got some dangerous spyware and windows tell me to remove them so after i remove them my desktop get back to normal

bunny 0 Light Poster

such as Ctrl+Shift+E or Ctrl+Shift+I or even delete but i can type.What the heck is wrong with this?i use win XP btw.
Pls help me thanks :mrgreen:

bunny 0 Light Poster

Logfile of HijackThis v1.99.1
Scan saved at 3:42:47 PM, on 12/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\PROGRA~1\INTERN~2\IDMan.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun

bunny 0 Light Poster

I'm using Photoshop CS2 with Windows XP but i can't use any shortcut like : Ctrl + Shift + E ,or even Delete.
Can anyone show me how to enable this ?
Thanks :mrgreen:

bunny 0 Light Poster

Somtimes if you used any windows customization software (and it looks like you did) this happens . Check to see that they are unistalled. If you dont have software like that you may have a virus. But dont panic just post a HJT log in the spyware section. And one of the Spyware pro's will help you out.

-T

Thanks it works fine now ;)

bunny 0 Light Poster
bunny 0 Light Poster

Hi Guys
Now every problem above is over bcause i reformated the whole computer.
But the new problem begin is i don't have any driver for sound card,audio video.....For EVERYTHING.So now i have to go to library to type these thing.How can i install all the drivers i need to now?


bunny 0 Light Poster

After you follow those instructions, go to post #14 of this thread --
http://www.daniweb.com/techtalkforums/thread28196.html
to remove yupsearch (pokapoka); then post your HijackThis log. Make sure you post the HijackThis log in the Virus forum (not in this thread).

the pokapoka doesn't appear these day so i thihnk i don't have to worry about those heh?

bunny 0 Light Poster

Hi Bunny,

You have quite a few problems with your computer, but you should be able to get it cleaned up without reinstalling your Operating System.

Follow the suggestions and instructions in the links below to begin the process, and then post a HijackThis log in the Virus forum.

That said, you should still have backups of all the important things you wish to keep -- sooner or later your hard drive will fail or something else will happen that will cause you to lose some or all of what you have.

You can burn the data onto CD's which has alreday been advised, or you can get a USB flash drive (or several if necessary); they aren't too expensive, but I guess it depends on how important the stuff is to you.

I'm sure that i will do all of those thing u said.But i think it take at least one day to finish and i don't have time today.I will do it like next week then cuz my comp is kinda working fine now.And i'll tell you the result after do all those thing.
Thanks a lot man :cheesy:

bunny 0 Light Poster

Boot the computer using the XP CD. You may need to change the boot order in the system BIOS so the CD boots before the hard drive. Check your system documentation for steps to access the BIOS and change the boot order.

I don't get his part :cheesy:


Oh, and you can try another antivirus. avast! antivirus. I gave up Norton recently as it slowed my system to a crawl. I find avast! pretty effective. Besides, it's free for home use. Head here: http://www.avast.com/eng/download-avast-home.html

I'll try it Thanks dude

bunny 0 Light Poster

I'm so tired and sick of keep trying and trying and trying but nothing goes better.If this laptop wasn't from my uncle i'll sell it this and buy just a normal computer.instead of keep trying hopelessly like

bunny 0 Light Poster

Heres what i would try ,just did it with a laptop that had much the same problem as you are having
.reboot ,hitting the f8 key to go to safe mode ,choose safe mode with networking ,and you should be able to connect to the net .and run the online virus scans ,not just one of them 2 or 3 .
you should also get hijackthis and go to the security section of this fourm ,
as for moving files from you laptop to another hard drive you could try a usb dada transfer cable they sell here[Canada ] for about 30 dollars or less

i'm using the safe mode rite now and try to go to any online virus scan site but no site let me in. :mad:

bunny 0 Light Poster

k i'll try it rite now.Thanks alot man

I did download that the Ewido and scan clen remove everything it said should be removed but when i try to install Norton it still say the same thing "setup was unable to update the ....."like before.
About the 20-40 gs harddrive my dad has one but i don't know how to transfer files to that harddrive and i don't even know how to remove everything on mine and reinstall windows :cheesy: Sirry i'm a donkey

bunny 0 Light Poster

You could try burning those files to a CD. Small size (20-40 gig) hard drives are pretty cheap, maybe you could buy one, and install your windows on there, then slave your old hard drive to it, copy your data to the new drive, and wipe the old hard drive, to use as storage and backup. I guess it depends on how much those files mean to you.

What if some files that i want to put in another hard drive contains virus and errors ? :rolleyes:

bunny 0 Light Poster

If you are using XP, try and download Ewido and scan your computer with it.

You can download a trial version of Ewido here: http://www.ewido.net/en/

Be sure you update it before using it, and when it finds a problem, be sure to select the check box to do the same action (clean) when it finds a problem, otherwise, you will have to click continue, to keep scanning with every problem it finds.

k i'll try it rite now.Thanks alot man

bunny 0 Light Poster

So Bunny, I take it you're still having problems?

Yah i think i should remove everything in hard drive and reinstall windows.
But what is the best way to do this? :cheesy:
But i'm kinda hesitating cuz i have so many media files that i love and i won't able to downlaod them again.What can i do now or that's the only way?

bunny 0 Light Poster

So you could first scan with the online virus scanner (panda preferably) and then install nav 2006 afterwards.

i couldn't go to any site that u recommended. :sad:
They sad the connection was refused something.....

bunny 0 Light Poster

I told you not to get Norton...lol. You may have a virus that won't allow it to install.

i bought it b4 i read this :cry:

bunny 0 Light Poster

I've just bought the Norton Antivirus 2006 but when i try too install.Ther's a message appears say:
"The setup was unable to update the MSI system component. if this problem continues please contact Microsoft at www.micorsoft.com."
What can i do now?

bunny 0 Light Poster

I would also recommend you first clean your hard drive from viruses and then reinstall windows... if you dont want to take headache to scan your hard drive for viruses and malware ... just backup your data to another source other than the hard drive and repartition.

bunny,

If you have many errors, it is best to save the data you need on a CD, Floppy, or another computer then format (erase) your hard drive. Then you can re-install windows and all of your hardware, and the data you saved from your old computer. Does this sound like something you would like to do?

J_

I can't all my media files is about 50 Gs i can't put it anywhere to clean the hard drive.
and just_a_nobody i'll check those program.Thanks for those.

bunny 0 Light Poster

I think it's time to do something with my laptop so many problem happen with it.I think i will have to buy Norton AntiVirus 2006 tomorrow.And can anyone show me how to clean up my laptop but i still can choose which file to keep.Clean up like a very deep wash remove every error and everything worng that make my laptop become kinda brand new one :mrgreen: .I's kinda impossible but i don't have enough money to bring this crap to the store.So please help me with this.
Ohh and 3 anoying errors i talked about are:

[IMG]http://img109.imageshack.us/img109/2055/error27hx.jpg[/IMG]
[IMG]http://img109.imageshack.us/img109/9649/error30cz.jpg[/IMG]
And for this one i tried to search the pokapoka79 to remove it but i couldn't find it.
[IMG]http://img109.imageshack.us/img109/6050/error12ac.jpg[/IMG]
So i think there is the only way for me to get out of all this carps is clean every up like vacuum lol.
Anyone pls help me.
Thanks a lot more than a lot.So 2 lot lol.

bunny 0 Light Poster

I download a movie ripped from DVD .I extracted the videos completed but there are nothing in the audio folder so i have no idea if that is the cause of no sounds when i play video.So what can i do to get the sound?

bunny 0 Light Poster

give us a bit more to go on..
What type of service do you use? Cable? DSL? This sounds like you could have intermittant service from your ISP and its hanging your modem. They may even be dropping you when inactive to free up bandwidth.

Who makes your USB device? have you rebooted in recent history?
Sorry for all of the questions but my ESP is weak.

i used DSL.so if the problem i had is what u said so what can i do for it.
what do u mean by who make my USB device ? i used this one [IMG]http://img485.imageshack.us/img485/9867/100497196tm.gif[/IMG]
when it doesn't work it said like something can't recognized or something.No i habven't rebooted my comp in recent history.and what is it btw :cheesy: sorry i'm kinda dump
but that's ok when i unplug and plug it in again it works.

bunny 0 Light Poster

I hope i used to right to tell you guys what my problem is.I know know why my internet cann't go smooth it always drop after 2-3 hours using and then i have to turn off the modem and turn on again and it works.
It happen everyday everytime.Can i do anything to it.
And one more thing it is not network problem but i hope u guys can answer me here:My laptop just have 2 USB port so i had to buy a "USB 2.0 7 port hub" but when i connet it to my laptop by the USB port and it seems doesn't works.actually it worked 2 times and then gone like forever.
i hope u guys understand my problem and help me to fix it.The first problem is the most important thing so that's ok if u guys just skip the second problem.
Thank you very much :mrgreen:

bunny 0 Light Poster

Are there anyone here know how to downlaod trailers on Apple website?
I want to download them for my video ipod so pls help me.Thanks :cheesy:

bunny 0 Light Poster

Click "Start", click "Run...", type "sndvol32.exe", and press "OK". This will load up the volume control program. Click "Options", click "Properties", select "Recording" from the "Adjust volume for" options, make sure that "Microphone" has a check mark next to it under "Show the following volume controls", and press "OK". Click the checkbox beneath the "Microphone" heading and raise the volume slider about midway. If there is a button labeled "Advanced" underneath the "Microphone" heading, click it, put a check next to "Mic Boost" (if present), and press "Close".

Try the mic out. See if you are able to get any sounds through it. If you aren't able to, adjust the volume slider up until you get sounds out of it. A good way to test if you get any sounds through the mic is to load up Sound Recorder (sndrec32.exe), press the record button, speed directly into the microphone, press stop, and press play.

Thank you very much dude.It's working now but when i record i heard this:http://bunny.yeuamnhac.com/others/test.mp3
can u listen to it and see is that problem?
Thank you

bunny 0 Light Poster

i wanted to record a karaoke song with my voice.I have the software called Cool Edit Pro to record.But my microphone did work, and i tried to buy to new one but the neew one doesn't work either.
Even chat voice my friend couldn't hear what i said.
So what can i do now,if i have to operate the PC or something like that so don't tell me because it's impossible i use laptop. :cheesy:
Pls help me

bunny 0 Light Poster

Have you checked your fragmentation levels lately? Maybe running a defrag would speed up the startup.

can you show me how?

bunny 0 Light Poster

What have you installed or changed on the laptop since the last time it was quick to start. Obviously something is being loaded at startup which is slowing the process down.

nothing changed

bunny 0 Light Poster

Before speed of my laptop was great it was fast when i turn on laptop and go to windows right away but now it's so slow it take like 3-4 minutes.
i hope someone can explain and tell me what to do now