caperjack 875 I hate 20 Questions Team Colleague

cd clint.dll was/is a file installed with kazaa and is spyware releated and kazaa won't work if you remove the dll .have a look here ,for the dummy dll and download it to you system32 folder and then try uninstalling the program .http://www.dll-files.com/dllindex/dll-files.shtml?cd_clint

caperjack 875 I hate 20 Questions Team Colleague

before you format ,try this .
,,,,,,,,,
This problem could occur because of Spyware , go on over to the Security section of this fourm and post you problem along with a hijackthis log .
Spyware & Trojans and Other Nasties
,,,,,,,,,,,,,,,,,,,,,,,,
Please Don't post the hijackthis log in this section Thanks .
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,

Please do this.
Download 'Hijack This!'. HijackThis
Save it in a convenient permanent folder such as C:\HJT\, double click HijackThis.exe, and hit "Scan".

Or HERE if that link fails to work or you don't have a zip program installed .

Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. Since Temporary folders are emptied now and then (the files are DELETED), it would not be a good idea to have your backups there. Those backups would be VITAL to restoring your system if something went wrong in the FIX process!


1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.

2. Copy and paste HijackThis.exe to the new folder.

3. Close ALL windows except HJT

4. SCAN with HJT

5. POST the new log in this thread using 'Add Reply'

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE …

caperjack 875 I hate 20 Questions Team Colleague

You might get quicker help over in the networking section.
Networking

caperjack 875 I hate 20 Questions Team Colleague

This problem could occur because of Spyware , go on over to the Security section of this fourm and post you problem along with a hijackthis log .
Spyware & Trojans and Other Nasties
,,,,,,,,,,,,,,,,,,,,,,,,
Please Don't post the hijackthis log in this section Thanks .
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,

Please do this.
Download 'Hijack This!'. HijackThis
Save it in a convenient permanent folder such as C:\HJT\, double click HijackThis.exe, and hit "Scan".
Or HERE if that link fails to work or you don't have a zip program installed .

Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. Since Temporary folders are emptied now and then (the files are DELETED), it would not be a good idea to have your backups there. Those backups would be VITAL to restoring your system if something went wrong in the FIX process!


1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.

2. Copy and paste HijackThis.exe to the new folder.

3. Close ALL windows except HJT

4. SCAN with HJT

5. POST the new log in this thread using 'Add Reply'

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS SOME OF THE FILES ARE …

caperjack 875 I hate 20 Questions Team Colleague

Hi, whenever I open up a video file in WMP 10 it is zoomed in and crops part of the video off. Any suggestions?

Try this ,right click on the video when its open and go to video size and check off the fit to video and fit to player and make sure it set to 100%

caperjack 875 I hate 20 Questions Team Colleague

im getting an error message when i boot up that windows is missing load dll's. when i try to start up in safe mode, it says that the missing files are ntoskrnl.exe hal.dll and dkcom.dll i have another computer that is exactly the same hardware, and has windows set up nearly identical, and i tried replacing the files with copies of the files from that second computer but still no luck. i can't run a repair because for some reason when i try, the windows repair only shows an unformatted partition, but when i plug the harddrive into my other computer as a slave, i can access the files just fine. is there any way to fix this without reformatting?

Check this site .scroll dow a bit to see missing hal.dll and couple more down for the ntoskrnl one ,
http://www.freewebs.com/mobosnetxp/

caperjack 875 I hate 20 Questions Team Colleague

wow! one from the lost and found

caperjack 875 I hate 20 Questions Team Colleague

Follow the same directions to fix this one .
O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe

Then go to safe mode and delete this folder C:\Program Files\Windows ServeAd

caperjack 875 I hate 20 Questions Team Colleague

your welcome .

caperjack 875 I hate 20 Questions Team Colleague

Go Here and Get Trojan-Hunter Fully working trial! and run a full scan
,,,,,,,,,,,,,,,,,,,,,

Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings[b]username[/b]\Local Settings\Temp\
Also delete your Temporary Internet Files be sure to also select delete all offline content.

,,,,,,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.

CWShredder available from these places :-

http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
http://www.spywareinfo.com/downloads/tools/CWShredder.exe

We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from :-here
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT

First use Spybot S&D. (Version 1.3)
Spybot
Unzip, and update. Install the updates and run. Delete all that it marks in red.
Reboot

Then it’s time for Ad-Aware
Ad-Aware
Install and update by using the globe icon. Restart your computer and run Ad-Aware.
Press scan now and select drives and/or partitions …

caperjack 875 I hate 20 Questions Team Colleague

If you haven't restared you computer since you created this log do so to get spyBot to finish its scan .
also go to control panel add and remove programs and uninstall P2P networking ,its not needed


Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
You might want to print out or copy & paste to notePad , these instructions as you will need to close this browser window to fix with hijackthis !

O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start

O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
-Web P2P Installer
Fix all the 016s' just ot be safe as the good ones will download again when you revisit that site .


Now reboot into safe mode and delete the following files and folders if found .

C:\Program Files\Windows ServeAd,,,,,,,,,delete folder


to delete the above files and folder you will need to do the following
go to
Show hidden files & folders

"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer in safe mode

reboot computer and post a new log

caperjack 875 I hate 20 Questions Team Colleague

hace you tried to get it to display in another user account ,if you don' have another go to users in control panrl and create one and try it !you may have a corrupt acct.
also spyware/trojan could cause this ,check out the spyware abd other nasties section of this fourm

caperjack 875 I hate 20 Questions Team Colleague

Your welcome .good to hear ,wasn't sure if it would ,but a reinstall is always worth a try .

caperjack 875 I hate 20 Questions Team Colleague

check the software tools link in my signature it leats to a very good site/fourm also .

caperjack 875 I hate 20 Questions Team Colleague

Help, I am getting booted off the internet when I try and visit some web sites (example-eBay). I am getting an error signature that reads, "App Name: iexplore.exe, ModVer: 1.4.2.0, ModName: jpiexp32.dll, AppVer:6.0.2900.2180". Will PC Doctor or another software help me fix this problem? Otherwise my pc is working fine. Please any help will be appreciated.

jpiexp32.dll is for the java ie plugin ,try reloading java ,get the download
here download and install

caperjack 875 I hate 20 Questions Team Colleague

Check here !
http://support.microsoft.com/kb/q192315/


If that doesn't help try the ,reg file here in the last post ,its a zip file that needs ts to be renamed to .reg ,also please read all post in that link to make sure its for you .watch for the reference to you IE version .

http://forums.techguy.org/showthread.php?p=1768819#post1768819

caperjack 875 I hate 20 Questions Team Colleague

Tip: to find any other post you made just click on you name in your post and click view more post by Morgan25

caperjack 875 I hate 20 Questions Team Colleague

looked at the error messages on you site ,you should be able to delete those files in safe mode and maybe run spybot there as well .
hit f8 on bootup to get to safe mode .

caperjack 875 I hate 20 Questions Team Colleague
Fix this !
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares...ysb_regular.cab

The ip address inthe 017 ,is it yours ,a search says it this.reconise it .

Search results for: 209.12.79.2,63.84 

e.spire Communications, Inc. ESPIRE-3BL (NET-209-12-0-0-1) 
                                  209.12.0.0 - 209.12.255.255
Inflexion Communications Corporation INFLEX-200403040825347 (NET-209-12-79-0-1) 
                                  209.12.79.0 - 209.12.79.255
caperjack 875 I hate 20 Questions Team Colleague

Have you tried this .
Be sure to Check off Auto Fix on this site

http://housecall.trendmicro.com/housecall/start_corp.asp
please run this one also to be sure .

http://www.pandasoftware.com/activescan/com/activescan_principal.htm
Also do the following .

Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your Temporary Internet Files, be sure to also select delete all offline content.

caperjack 875 I hate 20 Questions Team Colleague

Super Power 2

www.superpower2game.com

i made sure my computer made the requirements so i cna play it.

TIP: this is a help forum not a chat forum for better help you should speak clearly .
I don't use chat language so i don't know what CNA means .If its just a typo .please except my apologies .
also do you mean your computer made the requirement or meets the requirements !Thanks .")

caperjack 875 I hate 20 Questions Team Colleague

I bought a new system and it has no OS on it. So I put in my CD and all it gives is Disk Boot Failure, Insert System Disk and press Enter and it doesnt work I've also set CD ROM Boot as first priority. What am I doing wrong?

does new mean NEW or just new to you !
have you removed the case cover to make sure that the cdrom/hard drive is all wired up right .

caperjack 875 I hate 20 Questions Team Colleague

Not sure this site might help .lot of similaritys.to what you are doing ,in on loading NT on drive bigger than 7.8gig and such .
http://www.computerhope.com/issues/ch000646.htm

caperjack 875 I hate 20 Questions Team Colleague

Tip:.make sure you go to file and export ,making a backup of your registry to you hard drive first ,then make the changes ,!

caperjack 875 I hate 20 Questions Team Colleague

what if win 2000

Hacer u tried ,check IE is the default web browser button,find this in IE/tools/internet options /programs .down the bottom!
I don't use 2000 and have only used it on a few occasions ,not sure if it has another way like XP

caperjack 875 I hate 20 Questions Team Colleague

are your double mms' in programs intentional!1
update and run a full scan with your antivirus program

caperjack 875 I hate 20 Questions Team Colleague

Computer A
These are "Nasty":


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R3 - Default URLSearchHook is missing
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINNT\EliteSideBar\EliteSideBar 08.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/D...e/bridge-c7.cab

Do you know the IP or Domain '209.12.79.2,63.84.206.2,67.103.22.222'?


Caperjack didnt mention this I don't think. But for the O4 files you have to delete those files by going to that file.

Also CaperJack Microsoft AntiSpyware works just as well as Ad-Aware.

A lot more in baddies computer A than that ,thats why i got them to run the programs in my post, first and then post a new log !:)
I agree about microsofts program but its Beta and i don't recomend Beta program ,but if anyone wants to use please do ,I do !!
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
anyway this is what i find bad in computer A ,if any of this remains after running recomended program fix it .
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Have Hijack This fix the following by placing …

caperjack 875 I hate 20 Questions Team Colleague

You post the log here and we can tell you what to delete but I'll look into this site.

Edit: I found the site http://hijackthis.de/index.php?langselect=english

This site is a starting point, but does give false info on bad stuff,nothing works better than hijack knowledge and Google.com ,as far as what to remove from hijackthis

caperjack 875 I hate 20 Questions Team Colleague

Does anybody have any other suggestions as to why my computer is running so slow (513 mhz instead of 1.6 ghz), other than hijackers, adware, or spyware. Everything seems to come up clean on scans with every program I have. My computer is still running VERY slow in comparison to when I first got it.

post a new hijackthis log ,just for the Halibut

caperjack 875 I hate 20 Questions Team Colleague

I tried what you suggested, but I was not ever able to find an option to set BIOS to defaults. Can anyone think of anything non spyware or adware that might be cutting my processor speed in half (1.6 Ghz to 513 Mhz)? Are there ANY other options or suggestions? My computer is ridiculously slow compared to when I first got it! HELP!!

Hi,I have been into all the different BIOS's screens I think, and they all had the option to set Set to default!What bios do you have ,AWARD,Phoenix the two popular ones

caperjack 875 I hate 20 Questions Team Colleague

run these free online Virus scan

Be sure to Check off Auto Fix on this site

http://housecall.trendmicro.com/housecall/start_corp.asp
please run this one also to be sure .

http://www.pandasoftware.com/activescan/com/activescan_principal.htm

caperjack 875 I hate 20 Questions Team Colleague

I syggest This to start with for computer A !
,,,,,,,,,,,,,,,,,,,,,


Go
Here
and Get Trojan-Hunter Fully working trial! and run a full scan
,,,,,,,,,,,,,,,,,,,,,

Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your Temporary Internet Files, be sure to also select delete all offline content.

Do a virus scan here.
If you get report of files that can’t be cleaned / deleted please write down the filenames and locations and post that in your reply.
,,,,,,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.

CWShredder available from these places :-


http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
http://www.spywareinfo.com/downloads/tools/CWShredder.exe

We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from :-
HERE
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT

First use Spybot …

caperjack 875 I hate 20 Questions Team Colleague

Computer B
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
You might want to print out or copy & paste to notePad , these instructions as you will need to close this browser window to fix with hijackthis !

R3 - URLSearchHook: (no name) - {18058D25-81D6-607F-E823-C2D73BC536CB} - (no file)

O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINNT\BTGrab.dll (file missing)

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

This one is optional ,not need in startup ,rescource hog.

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

These 2 016s' for sure ,but i recommend you fix all 016s'just to be sure as the good ones will download again when you revisit the site .
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/C.../bridge-c11.cab
-Blazefind Windupdates Adware

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2190602...ip/RdxIE601.cab
-Netster

O16 - DPF: {58F0B492-A42E-435A-BCBF-C6B2608077BA} - http://ak.imgfarm.com/images/nocach...etup1.0.0.7.cab


reboot computer and post a new log

EDIT:
Computer A ,has alot more ,and will need quite a bit more work than computer B

caperjack 875 I hate 20 Questions Team Colleague

check in my signature ,spyware tool ,for blockers and removal tool most free ,all free ,check out spwareblaster and spwareguard ,and iespyad for sure ,
Get AD-Aware,and Spy-Bot search and destroy for removal of spyware .

caperjack 875 I hate 20 Questions Team Colleague

Agree, options to block more !and settings to protect/scan deeper into the OS!
Just my opinion !:)

caperjack 875 I hate 20 Questions Team Colleague

i have been using norton anti virus for a while now however i have noticed that it doesnt find and remove all viruses on my computer. could anyone direct me in the way of the best freeware virus removal tools?

THANX

Make sure you are updating Nortons ,it should find ALL.mine does ,i got more trojans/viruses on this machine using Free one than i did with Nortons.
Have you noticed that all free virus removal tool have a version one up in version # that you pay for .makes me wonder whats missing in the free version!

caperjack 875 I hate 20 Questions Team Colleague

on boot up try going onto BIOS/SETUP and do a auto detect hard drive ,exit and save changes ,see what happens

caperjack 875 I hate 20 Questions Team Colleague

when booting you computer repietly hit the f8 key as soon as windows starts booting and go into safe mode and run it there ,also you should run scandisk first then defrag ,and not it ahouldn't take days ,a few hrs maybe,dependig on how bad it is fragmented

caperjack 875 I hate 20 Questions Team Colleague
caperjack 875 I hate 20 Questions Team Colleague

OK,a few more links and tips to get you hooked!
search startups like this one ,O4 - HKLM\..\Run: [SystemTray] SysTray.Exe, you can search either ,this from inside the brackets,"SystemTray" or the EXE listed .
Startup link !=
http://castlecops.com/StartupList.html

Search BHOs' and CLSID ,like this ,O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL, by searching the large number ! with out the brackets,{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} search here = http://castlecops.com/CLSID.html

Then i can use Spywareblaster to search this one ,using the large number as above .
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/...all/xscan53.cab

I use CSWShredder in Debug mode to search this line for CSW vairents
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kon4ay.biz/k/
taking the ,kon4ay.biz and paste it in shredder debug mode and search and its a needles search site but not a cws variant .
but others aren't !!
I use this site to search the 020,021,022,023
http://www.fbeej.dk/NewHJTEntries.htm

this site for the 010s'
http://castlecops.com/LSPs.html

Another Hijackthis tutorial.
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42

caperjack 875 I hate 20 Questions Team Colleague

What is the manual winsock fix? I think you need the Windows ME disks and such.

check the microsoft link in post #7
as for the me disk ,you should have it i think

caperjack 875 I hate 20 Questions Team Colleague

Hi, ignore the last log, I reran hijack this and think I got rid of everything you wanted deleted. However, IE is still not working. Also, I can't get online to run the winsock fix you mentioned. I tried to save it to disk using another computer, but when I try to open the exe program on the problem computer, it says that the program is corrupted.

Thx,
Kristin

Logfile of HijackThis v1.99.0
Scan saved at 6:14:57 PM, on 2/21/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETGEAR\MA521 CONFIGURATION UTILITY\WLANCFG5.EXE
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [rtvscn95] C:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\Program Files\Norton AntiVirus\defwatch.exe
O4 - Startup: MA521 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA521 Configuration Utility\wlancfg5.exe
O4 - Startup: PowerPanel.lnk = …

caperjack 875 I hate 20 Questions Team Colleague

check this site if you want to learn about hijackthis and how it works ,
http://www.spywareinfo.com/~merijn/htlogtutorial.html
Nothing replaces caution and Google.com

caperjack 875 I hate 20 Questions Team Colleague

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
You might want to print out or copy & paste to notePad , these instructions as you will need to close this browser window to fix with hijackthis !


R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)

O4 - HKLM\..\Run: [Windows AdStatus] C:\PROGRAM FILES\WINDOWS ADSTATUS\WINSTAT.EXE

O4 - HKLM\..\Run: [on4T36R] LFISSHRN.EXE

O4 - HKCU\..\Run: [ZCv3RWdpe] LFCPTDLG.EXE


Now reboot into safe mode and delete the following files and folders if found .

C:\PROGRAM FILES\WINDOWS ADSTATUS\,,,,delete folder

Search for and delete if found

LFISSHRN.EXE,,,,,,delete file


LFCPTDLG.EXE,,delete file


to delete the above files and folder you will need to do the following
go to
Show hidden files & folders

"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer in safe mode

reboot computer and post a new log


Try this winsocfix for win98 -me if you still need it after hijack fix
http://digital-solutions.co.uk/lavasoft/whndnfix.zip

caperjack 875 I hate 20 Questions Team Colleague

Well, It had preformed much better when compared to Spybot and Adaware (we stoped using adaware because of the need to pay for the imuunize function).

Wow ,just check SE pro ,I didn't reliase ad-aware se pro had those functions till now .

caperjack 875 I hate 20 Questions Team Colleague

Microsoft has come out with a AntiSpyware Beta! To download the beta go to the Microsoft home page scroll down untill you see popular downloads and click Microsoft AntiSpyware (Beta). NOTE: If you are using a Firefox browser to dowload it it has a little problem with Firefox but you can still download it, it just a couple of test type things. Once it is download you may choose some prefrences then run your first scan. On my first scan the results were amazing more than Ad-aware could ever do.

I use it now for about 2 mnts i guess ,its ok.i like the real time watching it does the best .
As for comparing it to AD-Aware ,i don't think thats fair as ad- aware is not a spyware prevention tool! just removal tool

caperjack 875 I hate 20 Questions Team Colleague

log looks ok .a lot of asus monitoring programs running !:)
let try this ,do you still have your XP installation disc?

If so, place it in the ROM drive and click start->run->type in SFC /SCANNOW

caperjack 875 I hate 20 Questions Team Colleague

OK I've had this problem for quite a while. I frequent several websites in which I have to log into them again every time I re-visit, and every time I put in my username and password, it asks me if I want to save it. Whether I push yes or no, it will always ask again the next time. I've went into internet options and fooled around with the privacy and security settings but no luck. :idea:

Hi ,I have the same problem ,must have been a Windows update that is causing it ,i dont have a fix ,as it is annoing I just live with it .

caperjack 875 I hate 20 Questions Team Colleague

Found a couple of cool sites that read hijack this logs automatically. Copy the log and paste in the box hit analize. http://www.hijackthis.de/, Oops only one thought I had 2. I have used it a few times. Handy little item.

A good site yes but you do need to be careful as its not 100% accurate.as for my log if told me to delete my home page ,nothing wrong with my homepage it my ISPs' site.also told me IESpell checker was bad ,Its not ,I use a program called hijackthis helper [not 100% either ],given to me when i joined a hijackthis learning class at Tom Coyotes last year,it actually reads the log the same way ,i think someone must have set this site up to used the hijackthis helper program .

caperjack 875 I hate 20 Questions Team Colleague

Have you done this !!
,,,,,,,,,,
to delete files and folder you will need to do the following
go to
Show hidden files & folders