Question: It's Getting Worse & Worse. PLEASE. I cannot afford to bring it anywhere:( LOG INSIDE

My icons are disappearing
The computer is running slow
Viruses have completely taken over my computer
I am going through financial difficulties right now and would REALLY appreciate help.
I understand computers therefore I can take direction fairly well..
Just please tell me what I need to do.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:19:43 AM, on 5/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Documents and Settings\All Users\Application Data\nmtmzypk\nkrsjiri.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\PAULINA\cftmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\antiviirus.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =" target="_blank" class="invilink">
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =" target="_blank" class="invilink">
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avmhofon] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\avmhofon.dll"
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\PAULINA\cftmon.exe
O4 - HKLM\..\Run: [jdgf894jrghoiiskd] C:\DOCUME~1\MARKPE~1\LOCALS~1\Temp\winlogan.exe
O4 - HKLM\..\Run: [advap32] c:\d.exe/r
O4 - HKLM\..\Run: [405afe82] rundll32.exe "C:\WINDOWS\system32\gkcnyrti.dll",b
O4 - HKLM\..\Run: [antiviirus] C:\Program Files\antiviirus.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [BM4369cd1e] Rundll32.exe "C:\WINDOWS\system32\nqvndcud.dll",s
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [vvumyvbu] C:\WINDOWS\system32\vwjononu.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\PAULINA\cftmon.exe
O4 - HKCU\..\Run: [jdgf894jrghoiiskd] C:\DOCUME~1\MARKPE~1\LOCALS~1\Temp\winlogan.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\PAULINA\LOCALS~1\Temp\csrssc.exe
O4 - HKLM\..\Policies\Explorer\Run: [avg4J915IJ] C:\Documents and Settings\All Users\Application Data\nmtmzypk\nkrsjiri.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Jnskdfmf9eldfd] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone:
O15 - Trusted Zone:
O15 - Trusted Zone:
O15 - Trusted Zone:
O15 - Trusted Zone: http://*
O15 - Trusted Zone:
O15 - Trusted Zone:
O15 - Trusted Zone:
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) -
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) -
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) -
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) -
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{5E1E938D-16E2-4A37-9411-FDE68EFF3099}: NameServer =,
O17 - HKLM\System\CCS\Services\Tcpip\..\{820C749A-CBF0-4465-A221-A7BC5802F7ED}: NameServer =,
O17 - HKLM\System\CCS\Services\Tcpip\..\{9E8A814B-6996-4336-9096-A51FC25DDFFD}: NameServer =,
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer =
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O21 - SSODL: RamBoot - {787ce346-cedd-421a-91bb-4dd31133ceb1} - C:\WINDOWS\Resources\RamBoot.dll
O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\system32\jfiehayd.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Security Service (WDXC) - Unknown owner - C:\WINDOWS\system32\svcd\svchost.exe

End of file - 15439 bytes

Once again, I would really appreciate the help.

Answer: It's Getting Worse & Worse. PLEASE. I cannot afford to bring it anywhere:( LOG INSIDE

Hi all,

I started the day on a high note, before turning on the computer that is, thinking I was going to get some things done. This was not to be: So we start at:

After XP loaded it said that it had recovered from a serious error Product ID _251... so I did some digging around and got some info from microsoft's web pages complete with registry fixes (deleting bad entries, etc.)

I did a quick scan with malwarebytes and it found some stuff that I deleted and when I did a restart it didn't come up correctly.

Went into safe mode and it came up.
(made a HUGE mistake here. Did not copy files I wanted to save when I had the opportunity)
Closed out of safe mode and let it start normally.
Would not boot normally.
Tried to boot in to safe mode and now its recycling back to POST, we have gone to...
Hmmm. So I thought how about putting the XP disk in and then do an install leaving file system intact.
When I got to the point of doing the install I chickened out because it said that it might delete the My Documents folder (had some things in there I didn't want to lose) I've done this procedure before and perhaps I should have taken the second opportunity to recover gracefully but I did not.

I hit F3 to cancel out of the install to try and boot from my other HD that has XP (but with some driver issues that I had yet fixed.)

I went into the CMOS to change boot order and notice that the hard drive (the one that I was trying to boot into is not showing ... Read more

Answer:HD/Filesystem prob:Went from fair to bad; then to worse, much worse

Test the HDD with the drive manufacturers disk tools (preferably using a different PC). Run the short and long tests. If either test fails or has errors, the drive is faulty.

4 more replies
Relevance 94.3%

System Information
Time of this report: 7/28/2006, 17:12:38
Machine name: HOME-4E3Y5TSC3N
Operating System: Windows XP Home Edition (5.1, Build 2600) Service Pack 2 (2600.xpsp_sp2_gdr.050301-1519)
Language: English (Regional Setting: English)
System Manufacturer: MSI
System Model: MS-7032
BIOS: Version 07.00T
Processor: AMD Athlon(tm) 64 Processor 2800+, MMX, 3DNow, ~1.8GHz
Memory: 1024MB RAM
Page File: 291MB used, 2167MB available
Windows Dir: C:\WINDOWS
DirectX Version: DirectX 9.0c (4.09.0000.0904)
DX Setup Parameters: Not found
DxDiag Version: 5.03.2600.2180 32bit Unicode
DxDiag Notes
DirectX Files Tab: No problems found
Display Tab 1: No problems found.
Sound Tab 1: No problems found.
Music Tab: No problems found.
Input Tab: No problems found
Network Tab: No problems found.

DirectX Debug Levels
Direct3D: 0/4 (n/a)
DirectDraw: 0/4 (retail)
DirectInput: 0/5 (n/a)
DirectMusic: 0/5 (n/a)
DirectPlay: 0/9 (retail)
DirectSound: 0/5 (retail)
DirectShow: 0/6 (retail)

Display Devices
Card name: RADEON 9800 SERIES
Manufacturer: ATI Technologies Inc.
Chip type: RADEON 9800 PRO AGP (0x4E48)
DAC type: Internal DAC(400MHz)
Device Key: Enum\PCI\VEN_1002&DEV_4E48&SUBSYS_2097148C&REV_00
Display Memory: 256.0 MB
Current Mode: 1024 x 768 (32 bit) (75Hz)
Monitor: Plug and Play Monitor
Monitor Max Res: 1600,1200
Driver Name: ati2dvag.... Read more

Answer:Bad Performance - Seems gradually worse (DXDiag/HJT inside)

DXDiag Con't:
Name: VIA Rev 5 or later USB Universal Host Controller
Device ID: PCI\VEN_1106&DEV_3038&SUBSYS_03201462&REV_81\3&61AAA01&0&82
Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:38, 20480 bytes
Driver: C:\WINDOWS\system32\drivers\usbport.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:44, 142976 bytes
Driver: C:\WINDOWS\system32\usbui.dll, 5.01.2600.2180 (English), 8/4/2004 00:56:48, 74240 bytes
Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:44, 57600 bytes

Name: VIA Rev 5 or later USB Universal Host Controller
Device ID: PCI\VEN_1106&DEV_3038&SUBSYS_03201462&REV_81\3&61AAA01&0&81
Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:38, 20480 bytes
Driver: C:\WINDOWS\system32\drivers\usbport.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:44, 142976 bytes
Driver: C:\WINDOWS\system32\usbui.dll, 5.01.2600.2180 (English), 8/4/2004 00:56:48, 74240 bytes
Driver: C:\WINDOWS\system32\drivers\usbhub.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:44, 57600 bytes

Name: VIA Rev 5 or later USB Universal Host Controller
Device ID: PCI\VEN_1106&DEV_3038&SUBSYS_03201462&REV_81\3&61AAA01&0&80
Driver: C:\WINDOWS\system32\drivers\usbuhci.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:38, 20480 bytes
Driver: C:\WINDOWS\system32\drivers\usbport.sys, 5.01.2600.2180 (English), 8/3/2004 23:08:44, 1... Read more

3 more replies
Relevance 93.07%

So the virus seems to have gotten worse. Now all my desktop icons dont work and task manager doesnt work either it simply says i twas disabled by the administrator. I cant even get to the desktop properties it sayd runddl32.exe not found.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 4:04:26 PM, on 5/11/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exeC:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.e... Read more

Answer:Virus Got Worse! Desktop Doesnt Work. Hjt Inside


Please let me know in your next reply if your Norton is still up to date - because I can't believe it's up to date with this HUGE malware amount you are dealing with.
If your Norton was up to date, it would have blocked most of it.

2 more replies
Relevance 92.66%

I bought a Think Pad in April last year which does not start anymore, no lights,nothing.I wanted to send it back to Lenovo for guarantee.Ther ist only ONE problem, there is no sticker on the laptop which shows me the serial numer. Obviously there supposed to be on, but it is missing!!!I do have the invoice which shows the purchase date, but no serial either.I already quit wasted some time to with this bull**bleep**, I hopefully do not need a layer for that.Here you see the last response of the "support" manager -Dear Michael Mueller,Unfortunately I have to inform you that you have no guarantee for this machine.Repair of machines that do not have a sticker can only be carried out by a Lenovo service partner.Lenovo Service Partner: you have any further questions about this service case, please send us an e-mail to [email protected] or call us on the free phone number DE 0800 - 500 4618 / AT 0810-100-654 / CH 0800-55-54-54. Lenovo regularly conducts customer surveys on service quality.If you are selected, please take a few minutes to answer the questions.We thank you in advance.  Yours sincerely, Davor KrpanLenovo Technical Support IBM Hrvatska d.o.o. za proizvodnju i trgovinuMiramarska 23, 10 000 Zagreb, HrvatskaUpisan kod Trgova?kog suda u Zagrebu pod br. 080011422Temeljni kapital: 788,000.00 kuna - upla?en u cijelostiDirektor: ?eljka Ti?i??iro ra?un kod: RAIFFEISENBANK AUSTRIA d.d. Zagreb,... Read more

Answer:guarantee handling - bad worse than worse

I just forgot to mentioned, that the purchase was done through the Leonovo online shop itself -  VERSANDBESTÄTIGUNG Ihre Bestellung wurde versendetSehr geehrte(r) Michael Müller,vielen Dank für Ihre Bestellung im Lenovo Online-Shop, der von Digital River unterstützt wird.Die folgenden Produkte wurden versendet.Bestelldatum14. April 2017Bestellnummer23856585462Tracking-nummer1ZAF68846704024055Folgende Artikel wurden versendet: BestellmengeProdukt-SKUProduktnameVersandmengeVersandmenge gesamtBetrag120J1CTO1WWThinkPad 13 2G11800,52EURWenn Sie per Kreditkarte bezahlt haben, wurde Ihre Karte nun belastet.

1 more replies
Relevance 92.66%

i've had verizondsl for about half a year or so now, and from last month to present, the connection has been horrible.. sometimes it would just hang for up to a minute at a time, with the modem activity light blinking slowly (loss of connectivity).. before it started, speeds were decent, and although slow compared to the optimum cable i was used to, it was sufficient. now it's just pure garbage. if it weren't for the fact that we're getting free cable, i would immediately switch to roadrunner

i figure asking you guys is probly much more helpful than those scripted outsourced fools at tech support. i tried all that "reset your modem" "unplug the ethernet cord" "make sure you're computer is on" crap already and would like some REAL answers..

PS- at my old house, we used to have verizon as well, and after a while it just stopped all of a sudden and when we called to see what happened, they said since there was construction in the area, they must have switched our phone line over to one with a further CO, and we were now too far to service. verizon is teh gay.

Answer:verizondsl getting worse and worse speeds

Well try plugging the modem into the demark jack if you have one (by where the phone line comes into your house). See if this still happensl. If it doesn't maybe something happened to your internal phone lines. (this probalby won't be the issue I'm betting).

Beyond doing that phone your ISP and get them to file a support ticket or whatever they call it there. When I was having trouble with my DSL connection a couple years ago I phoned up, they sent a guy from the telephone company to test the line and they replaced a device at the CO and the connection has been perfect ever since.

The [H]orde needs You!

15 more replies
Relevance 92.66%

I was curious if anyone out there knows anything about this...

I have a self-built computer, three years old now...and day by day it's getting worse and worse!

AMD Athalon XP @ 1.1 GHz
Windows XP Pro.
Radeon 9500 Pro. 128MB DDR

The problems started about six months ago--every time I'd turn on the computer, it'd scan the hard drive for errors, claiming an improper shutdown. Then, two months ago, it started going to a black screen saying a windows file is corrupt, use the XP CD to restore the file--but simply restarting the computer at that point would get it going (only came up on a fresh start).

Then in the recent times, the screen is completely black. I turn on the computer, and no signal is sent (I'm guessing) to the monitor, so it's just flashing the power light...but after waiting approximently 10seconds, and restarting ('reset button'), it would go to the other problems--file corrupt screen, then the error scan...and this latest time, it took 4 resets for the screen to catch a signal...

All wires are plugged in good, and everything seems to be functioning properly, except for, of course, this problem I have...and I really have no idea where to start on fixing this. I planned on keeping this computer for another year or so--and hope this can be fixed! Anyways, any ideas/suggestions, please let me know!


Answer:My Computer - Getting Worse & Worse! Is there hope?

take the graphics card out and insert it back in firmly making sure it is sat properly in its slot. check the manufacturers websites for your motherboard and graphics card and see what the bios updates do, and see if they have any FAQ's to check if anyone else has been having similiar problems to you in terms of people who have the same motherboard or graphics card??

Email the manufacturer(s) for your motherboard company and graphics company.

2 more replies
Relevance 92.66%

Initially it was Edge not working properly, now it mostly crashes. Even the new "amazing" feature of tab previews doesn't work properly. Imagine, I moved back to Chrome after so many years of being a happy IE user. Cortana was a bit iffy with "Hey Cortana". Now she doesn't listen to what I say at all, even when I press the button. The notification center has its own mood. Often decides to hide until I restart for absolutely no reason at all. Same goes for the sound volume and other flyouts on the desktop.
In short, there is massive degradation of various major features with every new build. And since I post all the issues I find using the feedback app, I know it is not just me experiencing these things. This is disastrous.
So, is it just me or you experience similar issues yourself?

Answer:Is it just me or does Windows 10 get worse and worse with every new build?

It's just you.

10 more replies
Relevance 92.66%

Hi everyone,
My bottom fan on my PC was being very loud, so I opened up my case and unplugged the power supply, and flicked off the power switch on the back. I unscrewed the bottom fan and dusted it a little bit, and then I put it back together how it was before.

The part that I unscrewed also contained my hard drive, and now that it is reseated I cannot boot.

At first I got an error when booting:
Loading operating system . . .
disk boot failure, insert system disk and press enter.

THEN, I tried making sure everything was connected well and tight, and now I am not getting anything displayed on my screen.

Apologies for the lack of knowledge and thanks for the help.


Answer:Boot problem, getting worse and worse

It is possible that when you removed the fan and hard drive, you plugged the hard drives SATA cable into a different SATA port on the motherboard. Get into the bios, and make sure that the hard drive is being detected properly

1 more replies
Relevance 85.69%

Hello my new bestest friends. I need help ! (as does everyone who comes here) My computer has been running like a bag of you know what for about 3 weeks. IE became corrupt and will not start even after uninstalling and re installing Versions 6 & 7. However this is not the problem as I am currently using safari and finding it great. The problem lies with my computer and it's sluggishness, ever since IE became corrupt my computer seems to have slowed. I am getting occasional Internal memory (blue dos screen) errors and several other little glitches like windows XP's search program will not close after I perform a file search. I have performed several Virus & spyware checks such as AVG and Spyware Doctor also several registry progs like registry Booster.AVG comes up clean, however Spyware Doctor and Registry Booster both show a lot of Registry errors inluding heaps of lnk file and url files. I removed most of these the first time around but discovered it to have deleted all my shortcuts and bookmarks that I much needed (well not so much the shortcuts) It did not remove the actual .exe files but was a major hassle as my dektop shortcuts where wiped. So I performed a system restore and now have everything back.I am wondering are/have these files become corrupt or is this just overkill on the software (spyware Doc & reg booster) behalf?? I have also noticed in my Hijack this log that there are several (missing files).I am so in need of help as i use my computer to p... Read more

Answer:Need Help Computer Getting Worse And Worse!

Hello Krisso,

Welcome to Bleeping Computer

Sorry about the delay. If you still need help, please post a new HijackThis log to make sure nothing has changed, and I'll be happy to look at it for you.


2 more replies
Relevance 68.88%

Hey all.
I am loaded with popups. I went through all my prelim scans, booted safe mode, all that jazz. I didn't notice anything for about three minutes, then it all came back. If anything, they just seem to be getting worse. Anyway, here's my log, thank you much for your time.

Logfile of HijackThis v1.97.7
Scan saved at 11:43:05 PM, on 11/27/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C... Read more

Answer:Keeps getting worse.

You will need to get rid of the Peper Trojan first so run the PeperFix from my list..

After that
Make sure you have already run Adaware, Spybot S & D(check for updates) as these will do a preliminary clean first.Some files below may not be present after running the above programs.

Turn off your System Restore SEE HERE Reinstate it when your log is cleaned and then create a new restore point.Close your browser window and run hjt in safe mode... HOW TO RUN SAFE MODE and have "Hijack This" fix all the following items by placing a check in the appropriate boxes and selecting "fix checked".
Folders that have been highlighted RED in the log will need to be uninstalled.Check first as some folders maybe uninstalled via the Add/Remove program. Files highlighted in BLACK in the log will need to be removed from your hard drive. Make sure to have your system set to show hidden files and folders.. HOW TO SHOW FILES ..Please post a new log when finished...

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O4 - HKLM\..\Run: [W7ABA] c:\documents and settings\... Read more

5 more replies
Relevance 68.88%

I just finished a download that had some pretty nasty side effects. I am getting a pop up saying "It is recommended to update you antispyware protection to prevent data loss. Please install the most up-to-date antispyware for you" then an ok button. This isn't the only one, there are about 2 or 3 that seem random, none of which seem encouraging at all. Please help.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:48:46 PM, on 1/26/2009Platform: Windows XP SP3, v.5657 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.20935)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\Program Files\LSI SoftModem\agrsmsvc.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\TVersity\Media Server\MediaServer.exeC:\WINDOWS\explorer.exeC:\Program Files\Unlocker\Un... Read more

Answer:pop ups and probably worse

Hi,Your system is severly infected. Problem with these infections nowadays is, it causes a lot of damage. Even if we clean the malware off your system, I can't guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognise and logs won't show.Also, I can't promise you we can repair all the damage it caused... Even after cleaning the malware, you can still get errors afterwards because of the damage. Solving these is not always possible since it will be searching for a needle in a haystack to find the right cause and solution.So, we can try to clean this up and do what we can, but keep in mind that we can't solve ALL problems this malware already caused.In light of this it would be wise for you to back up any files and folders that you don't want to lose before we start. Reason I am telling this is because when a system is so terribly infected and we try to clean this up manually, the damage that is already present may interfere with our removal attempts. Actually, this doesn't suprise me at all.I notice that you never scanned with an Antivirus previously before starting this thread - because you don't even have an Antivirus installed!This is somewhat suicidal in today's digital world.That's why I want you to install one first!!* Please install Avira Antivirus: is a free Antivirus.Perform a full scan with Avira and let it delete everything it i... Read more

18 more replies
Relevance 68.88%
Question: Bad to Worse.

Hi all,  So not only does the Control Panel on my T520's nVidia card fail to work, but safe mode doesn't either. It gets stuck in a reboot loop for memory reasons. Using last known boot configuration I can get it to boot normally but the networking cards/drivers don't work. They are detected in Windows 7 but ipconfig only gives the Tunneling adapters.  Any ideas? Or should I just send it in for servicing?


Go to Solution.

Answer:Bad to Worse.

Hi kingofthering
If you need to use the machine temporary or to ensure your Nvidia GPU is defect, you could change the graphics settings in the BIOS to Integrated Graphics.
If you are not technical savvy or / and wish to save the hassle, it's probably good to send it in for servicing.
Have a nice day!
W520 (4284-A99)
Does someone?s post help you? Give them kudos as a reward, as they will do better to improve | Mark it as solved if the solution works for you, so it could be reference for others in the future
Sound Enthusiast and Enhancement (Post comments, share mixes, etc.)

9 more replies
Relevance 68.88%
Question: It could be worse

I come to this forum and read all the time in search of knowledge . With the reading and help of the fine people here I have fixed many problems . Some posts I have read complain about a program taking a minute to start up . Some complain about a slow boot up . Well when I said it could be worse I found one that couldn't be . Uncle brought his PC out to me to see iffin I could make it work for him . HP Pailion with 128 ram and XP Home . Hooked it up to my monitor and turned it on . One hour and 15 minutes later I could finally do something . First thing I attempted to do was run defrag . It took 15 minutes for the menue to work enough to let me click on defrag and another 29 minutes to open defrag . Now I have it open and click on derag to run , 7 hours later it finished . Pc Was still slow . A bit better but not much . Started to empty temp folders . One temp folder took 15 minutes to empty . Emptied all the temp folders and the history then deleated some programs . Only deleted 3 small programs but with them and the temp folders I regained 17 gigs of hard drive . Did another defrag and this time it went much faster . Then I started on malware and viruses . Did the ususal scans I learned from here and took a bunch of them out . Got to the point that the PC was healthy again . Took out the 128 megs of ram and replaced it with 512 which is the max for this HP . Now it is running very smooth and probably as fast as it ever will . So when you think you are running slow do t... Read more

More replies
Relevance 68.88%
Question: Bad to Worse


It appears my browser (IE/XPpro non-sp2) has been hijacked - at boot time I get an IE page that advertises WinAnti-Virus and demands I purchase. I can close the window and continue, but there are 37 processes running and the drive is constantly active, where an identical box has 28 processes running. I have downloaded (but not run) all the software you recommend, but apparently nudged the wrong bad actor and now the system won't boot at all. I have backed up some data, but don't want to loose everything if I can help it. I don't know how to use command line recovery and I can't remember the Admin password to use it anyway.

This happened once before and I let the system just run and reboot itself and after about 4 hours it was successful. I have about 4 hours on it now and no luck. I will let it run all night to be sure it doesn't heal itself.

If I reload XP, will all my data still be there?

Things started to go south about 2months ago when McAfee found Vundo and couldn't seem to kill it off.....

thanks, GearHead.

Answer:Bad to Worse

Hi GearHead,

Check out this link and try the removal tool from Symantec.

READ ME: Virtumundo Problems/Resolution Threads

Should that fail, I would suggest following the steps here:

READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

Best luck

2 more replies
Relevance 68.88%
Question: It's worse

my computer has been acting up for awhile running really slow, but now it's started this trick of adjusting the screen every little bit. It either moves up or down. It changes the sizes of the window as well. Then i noticed down at the bottom in the task bar, a button appears for just a second with a little icon in it. Then it disappears before i can do anything. Now, my email has started bouncing and i can't get outlook express to connect. Also, i was kicked off yahoo messenger and then all i could get was page cannot be displayed on even my home page. Here is my HJT log. I would appreciate your help.


Logfile of HijackThis v1.99.1
Scan saved at 1:01:23 AM, on 3/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\Dig... Read more

Answer:It's worse

6 more replies
Relevance 68.88%

new note pad mesgwhen I boot up.
[email protected]%SystemRoot%\system32\shell32.dll,-21787

I get this on start up and firefox is giving me an error

Well, this is embarrassing.

Firefox is having trouble recovering your windows and tabs. This is usually caused by a recently opened web page
Can any one help me out?

Thank you so much

More replies
Relevance 68.88%

my topic is here and it has been a couple days since a reply, and i was told not to reply again until i get a reply from someone to help me. but my computer is now losing the whole task bar whenever i close anything...i can bring up the task manager and see everything there, and i can ALT+TAB between programs and they will come up, but when i press the windows button will not bring up the start menu. the HJT log is in that other topic. thank you for looking

Answer:I Think My Pc Is Getting Worse

Hi dizz15,I know it's frustrating, but please be patient. It may take a while to get a response, because the HJT Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible.If after 5 days you still have received no response, then post a link to your HJT log in the thread titled "Haven't Had A Reply In Five Days?".To avoid confusion, I am closing this topic.

1 more replies
Relevance 68.88%

I've had 10 for a few months now. During that time I've had several automatic updates. Most have been unnoticeable, a few others were anti productive. The first and the last (two days ago) have been horrible. When I first downloaded 10 I immediately lost my CD/DVD drive. No matter where I look my computer can't find the old one. It also disabled sound from anything I recorded. The latest update is making me log in if I leave the computer for more than a couple of minutes. It also makes me wait before the log in window pops up. I'm beginning to think that switching from 8 to 10 was not a good decision.

Answer:Just when you think it can't be worse!

Would you consider doing an in-place upgrade install, also known as Repair install ?
Repair Install Windows 10 with an In-place Upgrade

0 more replies
Relevance 68.88%

 Can anyone help??? It all started when I installed a new game (well new for my old PC) the other day, when ever I tried to load it, once it got past the intro video it just returned to the desktop, most of the time, it did occasionally work. So I went to look on the web for advice and was told to update my sound and video drivers. My PC is an old PII 350 with windows 98. I went to ATI and downloaded what it said was the latest driver for my card, now when the game does play the colours are all wrong and blocky (I have also updated direct X above the one the game needs). So I tried a sligthly older driver, which was even worse, so I put the newer one back on. To add to this the company who made my sound card (Aureal) have gone out of business, so don't give drivers now. I have found on another page what was supposed to the the latest driver they did release, but when I load the diagnostic tool on my computer (some sort of direct X thing) when I test the sound, it says there is a fault there too. It seems that what ever I try to do, the thing just gets worse, I am starting to think about getting another PC, but when it works, it does everything I need. Does anyone have and advice how I should try and fix all this? Thanks James

Answer:It just keeps getting worse

Did you simply overwrite the videocard drivers? If yes, you may wish to thoroughly clean your computer by uninstalling them and running a program such Advanced System Optimizer V2 or Advanced Uninstaller Pro 2004 There is also a useful tool that removes drivers for you.. I'll get back to you on that once I recall the name. Even though your soundcard manufacturer has gone out of business, use Google to search for drivers. There is quite a high chance of still finding them.As for DirectX, see to it that you have the latest version from Mirosoft.Buying a new PC will not solve your problems. It is not the PC's fault, it is the users fault. Your problems will just start anew if you donot know what you're doing.

1 more replies
Relevance 68.88%

I have a virus on my computer in which my Windows Defender warning pops up every few minutes I remove it and it keeps coming back. I am also getting lots of internet pop-up ads. Please help before I throw my lap top out of my window. I ran hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:44:47 PM, on 12/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HP\HP Softw... Read more

Answer:Please help! It's getting worse

it is:
browser modifier: win32/fotomoto

2 more replies
Relevance 68.88%

Is a 635 slower than a 640? Is the camera worse? Is there less internal memory? What are the differences?

Answer:How much worse is a 635 than a 640?

Here's the differences compared to the 640...
The 635...
...has half the RAM, which meant Facebook and Messenger refused to run in my case on W10M, multitasking is less smooth and whatnot. But it works for the basics.
HOWEVER, there are some 635's that have 1 GB of RAM, matching the 640. not supported currently so you won't be getting Windows 10 Mobile easily, although some 635's have indeed been getting it with little effort oddly enough.
...has an inferior, lower-resolution 5 MP camera with no LED flash. (the 640 has a flash and an 8 MP shooter) smaller than the 640.
...does not have a proximity sensor.
...does not have double-tap to wake or Glance.
...has a smaller and lower-resolution display.
...has a smaller battery.
Although the 635 and 640 share the same Snapdragon 400 processor and 8 GB of storage + microSD.
The 640 is the better all-around phone but I your needs are very basic and the 635 is significantly cheaper then the 635 may make sense.

2 more replies
Relevance 68.88%
Question: Gotten Worse...

I know i posted about it a couple days ago with my computer going down the pooper. Well it was running real smooth untill recently. i had lots of disk drive space open now today it says i have 55.6GB of free space now i have a total of 74.5. I have been running virus protectors and spyware programs but its not working and there are icons showing up on my desktop that i cannot get rid of.... Do i have to re install windows or something? Sorry to ask again but i need help. Also i forgot to mention in my add remove programs there is a new program called search plug in and also micromedia flash player which im unfimiliar with and they are the biggest files in there.

Answer:Gotten Worse...

Please don't start a new thread for the same issue

If you are not getting any responses bump the original back to the top by simply posting to it...

here's the oiriginal...

closing this one


1 more replies
Relevance 68.88%

Like all AOL software, I'm wondering if the new AIM version is worse than the previous. Has anyone tried it yet?

It seems to have a lot of the features that AIM mods have introduced. I use DeadAIM myself, and have loved it for years. I tend to like things minimal. I've tried GAIM and Trillian, but I only use AIM, and GAIM messes up direct connections and profiles. I've tried AIMutation (sp?) and didn't like it much either.

What do you guys think?

Answer:AIM 6: worse because it's new?

i like it, but alot of people don't.
you just have to tweak it to the way you want it.

3 more replies
Relevance 68.88%

I have been workin on this for several days now and I am at my wits end. I am attaching my Bitdefender log and an HJT log. I have followed all of the instructions in the "Before Posting" page. And should tell you the following. My Add/Remove programs hasn't worked in years so when necessary I use the free trials downloadable from various places.
When I try and run Microsoft Windows Defender it says I need to perform an upgrade, and will not open.
I tried running Pandascan this morning and waited for over two hours and it never did complete downloading.
As I mentioned, I am at my wits end and believe it's time for some help.

Answer:The more I try the worse it gets! I need Help!

Welcome to Majorgeeks!

You did not attach your HJT log. Make sure you follow all instructions in step 7 properly and then attach your HJT log.

You should look at your Bitdefender log (change the .txt to .html and then double click on it and you can see it in your browser) You need to delete those items it is pointing out in your email.

Is your copy of Windows licensed to you and has it been activated with Microsoft?

What happens when you try to use Add/Remove programs? Be specific.

9 more replies
Relevance 68.88%


I just wanted to start by saying a very big thankyou to all of you that help people on this forum. It is very generous of you and it is appreciated.

I have been infected by this fake security application that says "Windows Security has found critical process activity on your system". It keeps redirecting our web searches. In safe mode I have ran malware bytes, super anti spyware and created a hijack this log all before finding this forum. Both these scans found problems initially however upon following the instructions of this forum no more were found. I tightened up my zonealarm resetting it to default and searching programs that try to run as they popped up, mshta.exe was one of the programs.

I have followed the instruction on this web site to the best of my knowledge and i will attach the logs of the various scans. All scans went well except for the combo fix scan that ran through to stage 50, flashed a page suggesting it was deleting files and then restarted my computer. I repeated it with the same result.

I now have a message that says "SQL Server could not find the default instance (MSSQLSERVER) - please specify the name of an existing instance on the invocation of sqlservr.exe." whenever i start my computer and it takes a long time before all the applications are loaded and ready to be accessed. It seems to run faster if the internet is turned off?

I am posting this from another computer.

Here are the logs - Thankyou for yo... Read more

Answer:Please Help, its getting worse

I am not seeing much in the way of malware on your system. Let's do this and see where you are after:

Download The Avenger by Swandog469, and save it to your Desktop.

* Extract+ avenger.exe from the Zip file and save it to your desktop

Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present --Unless you set this.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present --Unless you set this.Click to expand...

After clicking Fix, exit HJT.

* Run avenger.exe by double-clicking on it.
* -Do not change any check box options!!
* Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

Files to delete:
C:\WINDOWS\Ta... Read more

5 more replies
Relevance 68.88%
Question: From Bad to Worse

Hello to all the experts here at Bleeping Computers.

I was in the process of following your steps from the "Preparation Guide" when my computer decided to crash big time.
Initially I had my homepage hijacked by something called That by itself didn't seem to be a big deal. I was proceeding through the steps and made it to step 8 (Create a GMER Log). Approximately 5 minutes into the scan my entire screen went all screwy. It looked like the GMER scan program filled the screen and scrambled itself.

Now my computer won't work at all. After a restart, the computer locks up on the black screen with the green progress bar (Microsoft Corp underneath). I tried a safe mode reboot but it stops loading at the following line of text, "Windows\System32\Drivers\avgidshx.sys" This was the same line of text that was being scanned during the GMER scan.

After another restart (so many I lost count) my computer reads the following, "Windows failed to start. A recent hardware or software change might be the cause. To fix the problem:...." Several options are listed but even after inserting the original operating disc to repair, I can't get past the green progress bar thing.

Help!!! I'm moments away from turning this laptop into a very unaerodynamic flying brick.

(I'm typing this on my wife's Macbook, in case anyone was wondering how I could post)

More replies
Relevance 68.88%

dear all, any softwares that can fix this...

3 men go into a hotel for the night. The clerk informs them that it's $30 for the room, so they each take out a $10 bill to pay for the room. So far they paid $30, correct? You with me so far? Good.

A few moment after the men went up to the room, the manager reminds the clerk that there was a special promotion that night, and that the room was only $25. So the clerk gives the bell boy five dollars to bring back to the men. On his way up to the room, the bell boy says. "Hey, I'm not stupid, I'll give each of the man a dollar back and keep two for myself, $5 right, 30-5=25.

Well, since the bell boy gave each man a dollar back, that means each man only paid $9, correct?

Well, the last time I checked, 9x3=27, plus the 2 that the bell boy took makes 29, what happened to the other dollar??????

[This message has been edited by kokaik (edited 07-03-2000).]

Answer:the more you think, the worse it gets

7 more replies
Relevance 68.88%
Question: Getting worse

I followed your advise to rid my computer of a BHO and virus (red circle w/white X in system tray). Now my computer takes 20 minutes to boot, asks what mode to load in, (safe, normal, MS-DOS, etc), and only loads in 640 x 480 video. I've also lost the printer driver.

Logfile of HijackThis v1.99.1
Scan saved at 12:49:56 PM, on 12/12/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant ... Read more

Answer:Getting worse

hi, welcome to TSG.
you don't appear to have a firewall, even if you have a router you still need
a software frewall, downlaod the one from the link below!
Filseclab Personal Firewall Professional Edition
Download the pocket killbox
Download A2

update A2 and run a full scan.
*Download Cleanup from Here

* A window will open and choose SAVE, then DESKTOP as the destination.
* On your Desktop, click on Cleanup40.exe icon.
* Then, click RUN and place a checkmark beside "I Agree"
* Then click NEXT followed by START and OK.
* A window will appear with many choices, keep all the defaults as set when the Slide Bar to the left is set to Standard Quality.
* Click OK
* run cleanup

have hijack this fix these entries. close all browsers and programmes before
clicking FIX.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Ex... Read more

1 more replies
Relevance 68.88%
Question: Bad to worse

I posted a previous problem in regards to my computer shutting down at random and suspect virus. It seems things have gone from bad to worse in rapid time. I have lost internet connection, I open a program "regedit" and it closes, same with "msconfig" I cannot boot in safe mode. Suddenly all that was in my "connections" are completely gone, that folder is now blank. I know in the past I have tested your patience here but am throwing myself at your mercy once more. Sorry if this should have been posted with my previous question but I am unsure as to how protocol is.

btw forgot to give the basics.
Medion computer.
should be current on updates.
again tia.

More replies
Relevance 68.88%

i now cannot access my e-mail since doing an update every time i click on the e-mail icon nothing happens its just blank, nutty norm again

Answer:its seems to get worse

What email icon?????????????

3 more replies
Relevance 68.88%

I've had 10 for a few months now. During that time I've had several automatic updates. Most have been unnoticeable, a few others were anti productive. The first and the last (two days ago) have been horrible. When I first downloaded 10 I immediately lost my CD/DVD drive. No matter where I look my computer can't find the old one. It also disabled sound from anything I recorded. The latest update is making me log in if I leave the computer for more than a couple of minutes. It also makes me wait before the log in window pops up. I'm beginning to think that switching from 8 to 10 was not a good decision.

Answer:Just when you think it can't be worse!

Would you consider doing an in-place upgrade install, also known as Repair install ?
Repair Install Windows 10 with an In-place Upgrade

9 more replies
Relevance 68.88%
Question: bad to worse

Now I'm getting a little spooked.First it was just some irritating re-directs from Google searchers.Then multiple windows began propagating, sometimes blaring music, voices, phone sounds.Then, trying to work my way through the instructions in the preparation guide, I discovered that attempting to run the gmer.exe crashed me, locked up the processor, prevented me to restarting, the whole thing.Now, my touchpad has stopped responding. I uninstalled and restarted to replace the driver, but no effect. I am having to use a USB mouse, which works OK, but has not improved the touchpad.What's next?!Just curious. A question, for those of you who have experience with this forum--how long does it usually take to get help? Should I assume that all topics are addressed eventually, as folks find time? If I have failed to supply some bit of information, or violated some etiquette, I'd rather know, make my amends and start over that wait on the sidelines longer than necessary.Or should I just throw this piece-of-crap netbook out the window and get a real machine?

Answer:bad to worse

Hello pfosinger,It's hard to say how long it will take for a topic to get picked up. I know how frustrating it is when your computer isn't working properly. Let me assure you that your topic isn't lost, forgotten, or ignored. We work with hundreds of logs every day, so we have devised a means of seeing only those topics that don't have responses yet. At the moment, we have nearly 300 unanswered topics, the oldest dated Aug. 26, 2010 at 5:14 pm Eastern Daylight Savings time in the U.S.A. Your log topic is dated Aug. 30 2010 at 10:00 pm using the same time zone.Our volunteer MRT team members have various levels of expertise and training, so while we try to take the oldest DDS/HJT logs, it is often the skill level of the particular helper and sometimes the operating system that dictates which logs get selected first. Some infections are more complicated than others and require a higher skill level to remove. Without that skill level attempted removal could result in disastrous results. In other instances, the helper may not be familiar with the operating system that you are using, since they use another. In either case, neither of us would want someone to assist you who is not familiar with your issue and attempt to fix it.Please be patient. It may take a few more days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.Orange ... Read more

2 more replies
Relevance 68.88%

Hi, I have been using PC tools for the last couple of years with no bother. However, when I wanted to put it on my laptop I lost the ability to access the internet. They told me (eventuallY) to reboot using my windows XP home edition disc. having done that I was initially able to access the internet, but I could not open links or download any thing, and now explorer won't open at all, I just get error reporting. Things have gone from bad to worse and I need some help.Thanks

Answer:going from bad to worse

sorry - spyware doctor

2 more replies
Relevance 68.88%

Sorry to be such a bother but this problem is driving me bonkers!
Every turn develops into a new drama-here's the situation so far-

(1.) When I go to click on a program (any program) my computer either immediately or soon afterwards pops up a window that says "program error-process has already been exited-has generated errors and will be closed by windows. You will need to restart the program. An error log is being created." Of course restarting the process only sends me in circles-the same thing continues to happen-sometimes, obviously, I'm able to start the program but usually during the course of operation the "program error" window pops up and it's back to musical chairs again!
My system is, O/S Windows 2000 Pro, P4-1.6GHz 400MHz/P4FAN (P4-1600AR), Motherboard-D850MVL -MB Intel D850MV w/LAN, Rambus 256MB (2).

(2.) Now if I didn't already have enough problems I've apparently been infected with the Fortnight.E virus-it gets worse, in turn, I infected my ex-wife with the virus via an email (well, I'm sure you can imagine my situation-it would be better to have my nipples dipped in honey and dangled over a pool of hungry piranhas-she's pissed! Of course, the fact that the virus installed porno weblinks into her favorite file made matters even more unbearable-you'd think she was a nun or something! At any rate,
I have run a Panda On-Line AV-Scan-several Norton AV scans-SpyBot, Ad-Aware and SpySweeper-nothing works!
... Read more

Answer:Sos....from Bad 2 Worse!

6 more replies
Relevance 68.88%

Ok my computer has been progressivly getting worse becuase before i wasnt able to enter my control panel becuase explorer would just crash. And now i started up my computer and restarted a couple of times and i cannot see my tool bar(the one with the start button) and my cousin is bringing my xp disk christmas.. what can i do in the meantime? oh and when i click my windows key it doesnt do anything.

Answer:it just got worse...

looks like a virus to me
what antivirus program are you using? and is it up to date?

9 more replies
Relevance 68.88%

Just a curiosity question. I found an old AMD K6 chip in a scrap computer.
I would like to know if it is better/faster than my "Cyrix Instead" with MMX?
Both I think are 266's and socket 7.......

It's for my first PC that is now used for solitaire and surfing the net...

And what steps, if any, should I do to swap them, if the K-6 turns out better?

Answer:Better/Worse? Two old CPU's for old PC..

10 more replies
Relevance 68.88%

I tried to run a payment on a website and the submit button did nothing but make the cursor blink which it still is.  I looked under inspect Element and there was a JS file that downloaded.  I looked at it and it looked fishy.  I tried to run the normal cleaning techniques (ADW Cleaner, JRT, RKiill etc) and they all returned a messagge. "the service cannot accept control messages at this time "
It is slowly getting worse by the minute so I am not sure that this will even get to someone in tim,e cause I know u guys are backed up but if possible I dont know what to do I tried to use msconfig.exe , and the search functions to get safe mode to work but I just get either nothing happening or the same message.  I am afraid that if I turn off the computer to shift into safe mode that it will loack up..  Any helop would be appreciated.

Answer:I have something bad going on and ts getting worse byt the second

Sorry, but it seems that your pc is infected with a virus or malware which is going to take some more work and a deeper look. No sense running a bunch of tools here.Please follow this Preparation Guide, post in a new topic and include a link to this thread.Let me know if all went well.

3 more replies
Relevance 68.88%

Hello, I never write posts to ask questions when it comes computers, but this time I saw myself having to do so.
I have had many problems recently, and it just got to the point where stuff just doesnt work anymore.
I upgraded to Win 10 about 10 days after its launch. I loved it. I had that often problem everyone had but I could solve it.
About 20 days ago, everything worked greatly. Then, I don't remember what exactly happened, but all of a sudden I couldn't access the Groove Music App. Then I realized I couldnt open any other Windows built in apps, not even store worked. However, Edge and apps like calendar for some reason do work. So in an attempt to repair this, I messed up the Appdata folders's permissions. I had recently installed this context menu button when I right clicked, that let me take ownership of a folder, so I took the ownership "administrators."
Then, the hidden items check box in the View Tab on Explorer suddenly unchecked itself when I checked it. I looked up online and there it said it had to do with the Administrator account, but hell, I am the admin account on my PC, so this just didnt make sense. Then I read a simple reboot would help, so I rebooted and it was fixed.
This is where I mention my recent installs. Around the time, I installed this now piece of software on my pc, and this software was Bit defender Total Security. I had replaced my previous antivirus, Avast Internet Security, with this. Now, I highly doubt this program contributed to this in ... Read more

Answer:Help! My pc is getting worse

That last part went wrong somehow, here are the links:
click here

7 more replies
Relevance 68.88%

I've been trying to fix this computer for several days now, and it keeps getting worse instead of better

I know from my Ad-Aware scans that it has coolwebsearch on it, but CWShredder doesnt find anything wrong when I run it. ad-Aware does and keeps fixing it, but it's back within seconds. I've also run spybot search, about buster, and pest patrol. My HJT logs are getting worse, not better.

I would be much obliged if someone could help me; I can't figure out what else to do.

Here is my HJT log, let me know what if anything else will help.

Logfile of HijackThis v1.97.7
Scan saved at 11:41:07 PM, on 2/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program... Read more

Answer:It's Getting Worse....

I downloaded the newer version of log file is:

Logfile of HijackThis v1.99.0
Scan saved at 12:13:41 AM, on 2/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\DOCUME~1\ness\LOCALS~1\Temp\Temporary Directory 9 for\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system... Read more

3 more replies
Relevance 68.88%
Question: from bad to worse

please help-got a new laptop trying to use the wi fi.there is no wireless connection icon any where.maybe there no driver,im guessing. do i need to use the disc that came with my other laptop works fine.maybe i need to use another keycode,i dont know please help.thanks

Answer:from bad to worse

I think you're already running a thread on this: click herePlease don't double-post.

1 more replies
Relevance 68.88%

I made a post about my windows 7 explorer crashing, it seem to only happen when I move files from my internal to my external hard drive. it was still happening, nothing i tried fixed it.but NOW its gotten worse. Its crashing on a loop...every single second.this happens as SOON as I SIGN seconds it crashing and looping
and I cannot do a thing but use my internet...I get a message that tells me my program
fences (stardock program) has detected that there is problem with 7, and it disables itself, Then windows7 explorer crashes. sends info. then restarts...If I start a video or a program before it closes (which is seconds) then it will run. I have been up for HOURS trying to get this solved. I have NO clue what is going on. I ran Anti-Spyware free edition, found 8 harmful things, had them deleted. I also ran my microsoft essentials...BEFORE that..and it Finds NEVER does. but anti does...that confuses me.

SO what is going on? what do I do? PLEASE anyone, I am computer illiterate...
I have windows 7 (genuine)
32bit home premium.
I was tryng to get the rest of the info. but I can't as the explorer is completely locked up as I type this...please help I am so frustrated, I want to make Bill Gates come fix my computer lol...who has his number!?
ASLO! After it crashes and re-opens it keeps bringing up the c drive file location library? every single time, so now i have a list of these file locations open...also I JUST get a message saying that my firewall is... Read more

Answer:Oh no its worse! Help!

Can you get into Safe mode instead? If so, does it happen in safe mode?
Safe Mode

Do you have a system restore point you can revert to?

Oops sorry just read last line of your post.

9 more replies
Relevance 68.88%

Hi. I hate to be a nooge, but I posted a problem I had a week ago with a single search term being redirected in Google -- only that one search term was redirected. That much has stayed constant -- I've been using Google all week and only that one search term is redirected. My post has dropped down to page 12 and I think it's pretty much off the grid by now.Tonight I tried to run Hostsman to update my Hosts file and Avast! immediately put up the Warning notice that:12/2/2009 11:40:42 PM SYSTEM 2016 Sign of "Win32:Delf-MZG [Trj]" has been found in "C:\Program Files\HostsMan\hm.exe" file.I quarantined the file, but now I'm very concerned. When it was just the one redirect it was interesting, but this has me a bit panicked.I've copied last week's post here.Can anyone help?EDIT: Okay, it looks like Avast! may be reporting false positives right now with virus database 091203-0, the one I'm using right now, according to what I read in the various forums. I'll keep a good thought, anyway.But my redirect problem IS still there, and I'd like to get to the bottom of it, if anyone can help. Thanks!Hello again -- I was here with a severe problem about a year ago. It took several weeks, and a lot of help, but I got cleaned.I also learned a few things. I have since installed the NoScript and Cookie Whitelist addons to Firefox, I installed the free version of ZoneAlarm, and I installed a Hosts file manage... Read more

More replies
Relevance 68.06%

Thank you in advance for taking the time to review this and offer any help ....

a few of the problems windows has been having includestart menu stalling out
computer running really slow with every program
rtclick-->send to freezing up the system
cannot "save as" when downloading a file with mozilla
along with svchost.exe pop ups from McAfee

DDS (Ver_09-10-26.01) - NTFSx86
Run by cbellson at 12:05:45.25 on Mon 11/09/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.838 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\McAfee\... Read more

Answer:Windows is getting worse


Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Click on Yes, to continue scanning for malware.
When finished, it sh... Read more

2 more replies
Relevance 68.06%

Hi there! While I've been lurking here in the shadows learning from all of you, a nasty virus has decended upon my computer. It's the dreaded FBI virus, even though the pictures do not look exactly like the ones posted on this site, it's a moneygram, pay up or this will stay on your computer forever virus.

So I did some research here on what to do, but it's getting worse. Here are the steps I've taken:

Using Windows 7, Premium Home edition
Boot in safe mode with networking.
Downloaded Rkill and ran it.
Downloaded emsisoft antimal and ran it.
It quarantined 7 threats - 6 high risk, 1 medium risk.
I selected for it to quarantine, but it gave me a message that there was an error and it could not quarantine 3 of the files.
I tried to delete the items out of the recycle bin and it gave me the message that my recycle bin was corrupt.
I was trying to figure out what to do next when the white FBI screen took over in safe mode.
I rebooted in safe mode again, and every time, the FBI screen appears.
I'm also getting the message that emsisoft has encountered an error and it cannot load.

Please help. I'm at my wits end.

Answer:FBI Virus - getting worse!

Can you boot into safemode with networking?

Do not run any other tools when you are being assisted.

11 more replies
Relevance 68.06%

Hi Folks,

I somehow got nailed with Virtumonde two weeks ago and have been fighting with it ever since. Having tried everything I've been able to find on the web (short of attacking things in HJT), I've finally admitted defeat. I noticed some great postings here, so thought I'd ask for some help from the experts at Geeks. I've followed all of the steps in the READ & RUN ME FIRST sticky already, but have managed to end up worse off somehow. That's not a shot at the process, but typical of my last two weeks fighting this thing.

After finishing step 7 last night, I shut down. When I tried to boot into normal mode today, I am now getting a popup window with a title bar of RUNDLL and the message "Error loading C:\WINDOWS\system32\yekrmujm.dll. The specified file could not be found." When I click the OK button on that box, it pretty much causes the system to either grind to a halt or hang (can't tell which- the mouse moves, but nothing came back after an hour, and I can't get task manager to come up).

I can still get into safe mode OK, so I'm trying step 5 again in desperate hope it will at least let me boot into normal mode (it's my work laptop, so I'm a little unproductive right now...).

I've attached all the logs from yesterday's efforts and would greatly appreciate any help with getting back into normal mode, and even better, getting rid of Virtumonde. I was unable to get a log from Co... Read more

Answer:Virtumonde- From bad to worse

And the rest of the logs...

And I forgot to mention that I followed the additional step for Virtumonde and ran Vundofix, so that log is attached as well.

9 more replies
Relevance 68.06%

Hello, thank you for taking the time to view this. For some reason some links don't work on my home computer but do at my school. I tried them in both FireFox and IE, and nothing worked.

Links like:

Grinler's HiJackThis Tutorial

Said: "Not Found

The requested URL /forums/HijackThis_Tutorial_How_to_use_HijackThis_to_remov e_Browser_Hijackers_and_Spyware-tut42.html was not found on this server."

But they work perfectly at my school, or at my friends house. I'm starting to think its Mal-Ware vs. a problem with my browsers.

But I have the best of the best (pretty much every program Geek to Go admin's and staff has recommended) Anti Mal-Ware applications, and have been scanning non stop all day, and yesterday. Some have detected 1 or 2 problems, others have not, but nothing is better. I think things are getting worse, because now things are slowing down a lot, and programs are taking longer to open up.....and such.

So here is a HiJackThis Log:

Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

Help me please this is pissing me off

Answer:Serious Problems getting worse

Welcome to Majorgeeks!

Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
Make sure you check version numbers and get all updates.
Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
Downloading, Installing, and Running HijackThis​Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.​
When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
CounterSpy - only for Windows XP, 2K, & NT users
AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
Bitdefender - from step 6
Panda Scan - from step 6
runkeys.txt - the log from GetRunKey.bat
newfiles.txt - the log from ShowNew.bat

NOTE: You can o... Read more

49 more replies
Relevance 68.06%

           I just installed 10 is not much of a OS however that is not the problem. The agreements you have to sign  i know ther is two of them might be more i did not sign.Like most people usely i scan thru it and sign.
 This time it caught my eye I backed and read these things I was shocked. I am not a lawer but mabey there is one on the site could tell us what.they think. I will try to be short  as i can this is not all but what I thought was the worse     1you surrender your computer
      n                                2 you give permisson to use mic camera and who knows else this is 24-7 in your house
                                       3  they can use your cell phone to track you
                                       4  can use public careras to track you
           ... Read more

Answer:Windows 10 is worse than i have seen here

@lewis12398 ~ you might enjoy this BC thread:

1 more replies
Relevance 68.06%

I think I overheated the CPU in my laptop. I'm not entirely sure it's the CPU, though. Everything points to it according to my knowledge but I found this interesting...

Maybe it's worse...

Possibly the CPU is fine and just being used heavily because a different part is shot? Look at the virtual and hardware memory.

Need pro help. Thanks guys =)

Answer:CPU ruined or worse?

What is the problem that you are having?

3 more replies
Relevance 68.06%

ok....i give up LOL

Answer:Problems are getting worse = new log

oh and also, the nortons "clean sweep/smart sweep log" picked up this
File 'C:\HP\KBD\PS2.DLL' added.
and a lot more things, but the log is way to long to add here. Is the PS2 ok?

3 more replies
Relevance 68.06%

not sure where to begin. my problems started installing something i thought was activeX to my fujitsu xp sp2 2002 laptop(not able to upgrade to sp3). i know the date and time as well. half of my desktop disappeared along with half of the start/programs. loads of popups and a mighty sirupy internet connection. instantly scanned with malwarefighter/superantispyware/spybot/symantec antirus/ccleaner.. and later anything i could think of. think it was the malwarefighter which found rootkit infection.(rootkit0access c:system volume info/restore..... exe). things seemed back to normal for half a day, only to come back worse than before. my missing desktop icons/programs, start/programs came back as i learned they only were made hidden. though most systemtools etc were gone..(later installed back)

now my problems/symptoms are as follows :
at (every!!) startup im told there is hardware found, other pci device.
my wave sound (in advanced mode is muted)
internet slow with constant avast popups
control has no parent windo.
tidserve activity 5
generic host process for win32 services problem.
my avast pops up messages constantly when connected to the internet.most mention explorer.exe.
the fan usually runs wild when browsing

combofix says rootkit activity
mbrcheck says c: error, physical drive0 mbr code faked, found non standard or infected mbr.
rkill says xSystemrootx\system32svchost.exe -k rpcss incorrect imagepath
gmer wont run(most of these programs wont run at all) ... Read more

Answer:rootkit or/and worse

Please follow these instructions: READ & RUN ME FIRST. Malware Removal Guide

16 more replies
Relevance 68.06%

Please help!!!! My computer has been encountering various issues, the most severe has been the uninstalling of all installed printers. The issue first occured when we were not able to print using our photo printer, shortly after the photo editor application would be force closed everytime the "Print" button was clicked. Now all printers have been uninstalled without our doing. McAfee occassionally finds PrcViewer but cannot fully delete it.

Last scan came up with three detections (the two cookies were automatically deleted):
HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:20:42 PM, on 3/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
c:\PROGR... Read more

More replies
Relevance 68.06%

Hello... my sisters computer is totally messed up..

everytime I scan with adaware my sisters computer crashes once it finds something in the system32 folder, I managed to cancel the scan before it crashes and saw the name winfixer pop up in files found right b4 it crashed....

I also keep getting popups on her comp saying "your computer may be infected with blackworm virus!" and then it takes me to a antivirus site that wants me to buy thier stuff....

here is her HJT log...

Logfile of HijackThis v1.99.1
Scan saved at 10:05:08 PM, on 2/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\1139284886\ee\AOLSoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
c:\program files\common files\aol\1139284886\ee\aim6.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe... Read more

Answer:Winfixer? or something worse?

Hi and welcome to TSF

I'm Jet Ian, and I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem as soon as possible. Please be patient with me during this time.

We also recommend that you Subscribe to this thread so that when I or the other experts replied, you will get an email notification. To do this: Click on then and make sure you set it to Instant notification by email.

7 more replies
Relevance 68.06%

anything? anyone?


gonna be a long day for some of us i think

EDIT: this may help

Answer:what could be worse than heartbleed?

CentOS appears to have a new patch out. Get it via YUM.

New file is bash-4.1.2-15.el6_5.1.x86_64.rpm

29 more replies
Relevance 68.06%

I have several issues and am completely perplexed and need direction and your expertise badly.
Vista Home premium, 64 bit....SP 2.
AVG ...detected nothing
SuperAntiSpyware took an hour to removing 256 threats...usually takes 1-2 minutes.
Issues I am having.......
  * connecting to some/not all websites in IE.  Can connect to them in Google Chrome which I used out of desperation as I have it downloaded but never use it.
  *occasional 502 errors when clicking on a topic
  *back button is blocked by constant facebook/twitter plugin.
  *Windows Mail was wiped clean, and can no longer connect to server.  Yet it left my contacts in Mail intact.
  * slow and at times nonresponsive to some websites, especially Yahoo.
I do have a clean laptop (which does receive my Windows Mail) for backup use and research.
My computer knowledge, well I can follow directions pretty well.
My Windows Mail I am not worried about at this point, am trying to work with Verizon to restore it, but wanted to list everything I could remember.
Any help will be greatly appreciated.

Answer:Various symptoms and keeps getting worse

Download Security Check from here or here and save it to your Desktop. Double-click SecurityCheck.exe Follow the onscreen instructions inside of the black box. A Notepad document should open automatically called checkup.txt; please post the contents of that document.NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.Make sure the following options are checked:
Internet ServicesWindows FirewallSystem RestoreSecurity Center/Action CenterWindows UpdateWindows DefenderOther ServicesPress "Scan".It will create a log (FSS.txt) in the same directory the tool is run.Please copy and paste the log to your reply. Please download MiniToolBox and run it.Checkmark following boxes:Report IE Proxy SettingsReport FF Proxy SettingsList content of HostsList IP configurationList Winsock EntriesList last 10 Event Viewer logList Installed ProgramsList Devices (do NOT change any settings here)List Users, Partitions and Memory sizeList Restore PointsClick Go and post the result. Please download Malwarebytes Anti-Malware to your desktop.NOTE. If you already have MBAM 2.0 installed scroll down.Double-click mbam-se... Read more

19 more replies
Relevance 68.06%

Ok so anyone who uses GMX knows that it's often down or bugged in some way or another, but this one just ices the cake:
And since GMX has zero tech support,

Tried saving it, logging out and back in and re-sending.

Recomposed it also to no avail.

What can I do?

Didn't want to change mail provider but I've had so many incidents with them now I'm really considering it. Anybody know any good ones (dont say gmail, my name has already been taken)

Answer:GMX mail is getting worse.


Clearing my cookies and restarting my browser resloved this.

1 more replies
Relevance 68.06%

Hi, I was wrestling with an infection of W32.trats!inf on a laptop - Windows XP home.

Norton Antivirus keeps finding it and has been unable to get rid of it, so I was attempting to remove it manually.

vtstr.dll is in the Windows/system32 folder along with various registry entries related to it

I just tried to boot into safe mode, and it now will not log in and says "Unable to log you on because of an account restriction" in both safe and normal boot modes

Any suggestions?


Answer:W32/Trats!inf gone from bad to worse

16 more replies
Relevance 68.06%

You may remember my post not that long ago about my having a trojan horse, well after getting help to clean it up everything was running prefect for about 3 days and now it has come back and it is now worse than what it was before I hope I can stay connected longer than 2 mins

Answer:Its back & worse than ever

9 more replies
Relevance 68.06%

Very recently removed "Security Tool" virus but now have contracted sdra64.exe, know how to delete it, but the problem has got mysteriously worse.
When logging in on Admin(or any) account, it logs me straight back out, how can I get my windows XP to stay logged on, long enough to solve the problem? (It logs me out a second after I log in, even in safemode)
I can't run it with the command prompt because I can't GET to the command prompt otherwise I'd use it to get to the system restore screen, help?

Answer:Sdra64.exe gotten worse


Please do the following:

I hope you have acces to a PC that can burn CD's

We will need to make a BOOT CD

Print these instruction out so that you know what you are doing.

Two programs to download


Please download ISOBurner and save it to your desktop. This program will allow you to burn OTLPE.ISO to make a bootable CDDouble click the ISOBurner set up icon to install the program, from there on in it is fairly automatic.
There are Instructions for the iso burner here if you need them.

Download OTLPE.iso save it to your desktop. Now burn OTLPE.iso to a CD using ISO Burner. {NOTE: This file is 292Mb in size so it may take some time to download.)
When downloaded double click OTLPE.iso > this will then open ISOBurner to burn the file to CD

Reboot the infected system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
Your system should now display a REATOGO-X-PE desktop.
you will find an icon on the desktop called OTLPE > Double-click on the OTLPE icon.
When asked "Do you wish to load the remote registry", select Yes
When asked "Do you wish to load remote user profile(s) for scanning", select Yes
Ensure the box "Automatically Load All Remaining Users" is checked and press OK
OTL should now start. Change the following settingsChange Drivers to SafeList

Press Run... Read more

4 more replies
Relevance 68.06%

hey all, I believe my house could qualify to be in the most stone-age technology section in the world. I'm suprised I can get electricity for christ sake. The BEST I have ever seen out of 4 modems out of this house ever was a v.34 28.8 connection that is highly unreliable and can cripple anything but Lucent chipsets to be unusable. I go down the road (buddy's house) dial up into MY ISP just to be sure, and I get a 43+k connection out from there, which I'd say is about 1/4 mile away if that. I don't understand why my phone lines are so god awful that I cannot get even better then a 28.8kbps connection from this shithole. Is there ANYTHING I can do (like yelling at the phone company for something) to improve my phone lines... I know its not internal to my house either because I have taken a box outside and plugged it directly into the phone line and still only get 28.8k.

DSL - NONE (live too far from CO)
Cable - NONE (my street doesn't get even cable TV!)
satellite is absolutely not an option, ping times of 1900+ are unacceptable obviously.

okay, I think I'm done ranting. So, any advise?

Answer:I don't think anyone has a worse connection then me!

Pray for cable?

22 more replies
Relevance 68.06%

I have Windows XP.
Something has been eroding the quality of my PC.
I lost the ability to access programs through the START menu (I have to seek them out via Win Explorer).
Now when I am on-line (Internet Explorer) and I click on a link, it usually (not always) freezes and I have to shut it down via Taskmanager.

Could it be an infection?

I cannot run a full virus scan because I have a damaged Intel file that causes the PC to freeze whenever the scan touches it. But I do run Ewido and Spybot (fast scans). I used to have McAfee via AOL, but it was KILLING the speed of my PC (start-ups were painful).

Here is my HiJack log;

Logfile of HijackThis v1.99.1
Scan saved at 6:52:51 PM, on 3/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\PCCare\Client\srvc.exe
C:\Program Files\PCCare\Client\cust.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

Answer:XP - slowing getting worse

renz124ny said:

I lost the ability to access programs through the START menu (I have to seek them out via Win Explorer).Click to expand...

What exactly do you mean by this?

In any case, though, although I can't assist in HJT logs or malware removal, I must recommend that you have it moved to the Security forum.

In the top-right corner of your message is a red triangle with an exclamation mark: Report Post to Moderators. Ask them politely if they can move your post to the Security forum. You'll more likely (and more quickly) get a response.

2 more replies
Relevance 68.06%

When I ask for Dos Prompt, the machine shuts down. A friend was given a Dell "Dimension E520" running XP Pro, desktop computer by his boss. Their business was replacing some older machines and giving the old machines to some of the employees. My friend has a very old CAD program called Anvil. It is a Dos program. It fits on a floppy disc. He has been using Anvil for many years an would be lost without it. He asked me to look at the machine to see if I could figure out why his Anvil program will not work. When he tries to run the executable, the machine shuts down. I thought perhaps the executable was corrupt. After a few hours of trying to make it work, I thought maybe if I started with a Dos prompt, I could get the executable to run properly. That's when I discovered that the machine will not provide a Dos prompt. The request causes the machine to shut down. I am at a loss. Can someone offer some help with this? In the "safe mode" the dos program works fine.

Thanks for looking,


More replies
Relevance 68.06%

My PC is having multiple issues, even after trying the R&R scans. Only SAS and Malwarebytes completed without any issues. The last scan, MGTools, ended with a blue screen. Combofix never started the scan portion, even after waiting 3 hours. Root Repeal seemed to finish, but came up with a message about an inaccessable memory block and then the computer shut down.

The current problems I'm having: Google redirect (IE); Hard drive errors (last one was right after power on); programs not opening over time; almost all files on computer are hidden; message about corrupt files in recycle bin (even though it's empty); volume doesn't work; some file on my desktop called "settings.dat" that was created today and, according to it's properties, opens with daemon tools pro.

These are the only logs I have. I'm not sure what the MGTools log will show after the blue screen incident. If there is any step that may seem like I missed it, trust me, I did everything I my PC would allow me to do in its current condition.

Answer:Need help! Computer going from bad to worse.

Also, Combofix started off by telling me that ESET antivirus was running. That can't be possible since I uninstalled it right before I started the R&R cleaning.

11 more replies
Relevance 68.06%

My wife was on pintrest this morning and an alarm went off and a pop up came up saying our IP server was hacked and something about drivers, to call a phone # for Microsoft support. she called gave over control to the computer to the women on the phone. My wife was informed we had 2000 threats that we should take it to a Microsoft store where they will send it out for 400 $ or she can fix it on line for 2oo$. How bad of trouble am I in ? Thanks John

Answer:Help I maybe hacked or worse

16 more replies
Relevance 68.06%

I pretty much summed it up in the questionnaire. I'm trying to save my dad's notebook from layers and layers of browse hijackers, adwares and maybe something even worse, I don't know.

Hopefully you guys can show me the right tools and instructions for the job.
Thank you in advance!

More replies
Relevance 68.06%
Question: I made it worse...

This isn't a computer problem *exactly* but the screen is basically a computer screen so I'm assuming the rest is similar? I really have no idea what I'm doing or why I thought I could do it myself but -

The screen on my PGE (Gaems G115) was totally obliterated by a well-meaning toddler.

I decided to google remedies and found a tutorial with links to everything I needed. Everything was going great until I had to remove the connector thing from the old screen and I broke it worse than the toddler busted the screen.

Is there any hope for my PGE? Can I get this part somewhere as well or is there somewhere I could get it fixed? Or is it a lost cause and do I need to sell it for parts and move on?

Answer:I made it worse...

Is this what you are talking about?

If you are in the US, there is a toll free number to call the company.
They might be able to give info on the old G115 parts or where you can go for service; everything on the site in the M155 model.

1 more replies
Relevance 68.06%

Good Evening everyone,

I was asked to look at a Toshiba Satellite yesterday that was said it would not boot. I received said machine earlier today and started troubleshooting it. If I try to boot into regular Windows it comes to the starting Windows screen and just sits there hitting the hard drive, tried to boot into safe mode, but it starts loading the files and then just sits there again hitting the hard drive. At start-up it gives an option for a start-up repair if I click that it will load then just sit at a black screen with my mouse showing.
I was researching this and came across a post on the Toshiba boards with the same type of problem and it was said it could either be that the hard drive could be failing or it could be a deeper problem possibly the motherboard.
I had assumed from the beginning that it could very well be the hard drive, but I don't know how to make that a certainty so I can inform them of what their next step should be since I can not access the machine at all.
Any and all reply's greatly welcomed.

Thank you have a great evening.

Answer:Possible HDD issue, or worse.

The easiest route is to boot from a Live Linux DVD. That still requires the computer to function but not the hard drive.

4 more replies
Relevance 68.06%

I am runing Windows ME operating system.Ever since a friend messed about with my computor (took files out moved some around) to try to help it run smoother, it has never run right..PROBS>>>When I switch the computor on I get an unusual start up sequence..Black screen, white words, headed Micresoft Windows Millenium Startup Menu.I an given 1-6 options and a timer is running 30seconds. If I let the time run out, it carries on as normal. The desktop opens as if all is well BUT ... I have Norton Systems Doctor that is very ill as it does very little. It just says things like Norton Intergrator could not initialize the currant class ect other things ...The screen freezes for 25 -30 seconds every few minutes sometimes but it can be ok for 30 mins...When I click on Launch Outlook Express, a dialog box tells me it cannot be started because MSOE.DLL could not be loaded...I have no sound what so ever from anything....The internet runs fine BUT ..I have no MSN Messenger or Hotmail...I have tried to run msnconfig from the run commandbut a dialog box pops up stating ...msnconfig cannot be found ... an I writing this in correctlyAlso System Restore will not restore anything, I have tried a number of dates...Should I put in the Recovery Disk or is this a last resort or am I there already ....I will check back every 20 mins or so...ThanksDerek

Answer:Problems now worse ..please help.

Well, for one thing, the command you are looking for isMSCONFIG

10 more replies
Relevance 68.06%

first off, im not the most computer illeterate but i know some stuff so plz bare with me.

i keep getting the blue screen of death probably about an hour into my computer startup. doesnt matter what im doing wether a game, net, chat, etc. i wish i could tell you what it says on the blue screen but it only flashes for about a second or two.

what i can remember are a bunch of zeros or numbers and the 'fatal error' at the bottom of the paragraph. then my computer restarts.

when my computer boots up, a voice comes on saying "System completed power-on self test, computer now booting from operating system". but now every once in a while it says "System failed memory test, computer now booting from operating system".

i know i had to delete a bunch of stuff off my C drive because i kept getting alerts that i had no space but even when i did delete programs, it didnt seem like it was making any room on the C drive.
I have Adware 6.0 and almost everytime i do a scan, the same files come up as infected and they're always .DLL files too. then i quarantine but when i scan the next day the same files come up as infected again.

thats all the info i can think of. somebody plz help because this started out with the blue screen about once a week and now its once every hour. HELP ME

Answer:Problem getting worse! PLZ HELP!

6 more replies
Relevance 68.06%

I attempted to flash my mainboard, used the wrong model. (I have a pcchip m935, it was either the G series or the DLU, found out the hard way that its the DLU) It was a 50/50 chance, I picked the wrong 50! Now I have to send my board in to the manufacturer to fix (only $25). But in the mean time I went ahead and upgraded myself to a faster better board that should be here by Friday! Plus more memory. But, I was also told that my p4 may have problems too! One good thing about that, it is still under warrenty. New machine should be done in 1 month.

More replies
Relevance 68.06%

Trying to help someone who needed to get on the net in a pinch, I put Zone Alarm on his laptop. It immediately caused slow downs, and wouldn't let me remove it with it's own uninstall because it was a demo. So, I used add/remove programs. Then I went to the ZA site and found out what might remain in the registry, searched for it, it wasn't there.
The whole system was paralysed. I used Advanced System Optimizer to clean the registry, and then the programs would work, but both startup and shutdown took about 8 minutes. I tried reinstalling ZA with my own reg code, just so I could do another uninstall, using the right tool. I did that, but there was no improvement. When I tried starting in Safe Mode, I got a screen saying something was "stuck" and was directed to a bios page. Here was my biggest stupidest mistake: I said restore default bios. Dumb, dumb dumb!!!
After that, it would boot (still 8 minutes), but do nothing. I mean, I couldn't click on a thing that would work. I have no start menu...wait, it just came up, it took about 10 minutes!
What can I do? He has important data on here. I can't just wipe the disk! Is there a way to put the bios back to where they were when I clicked "restore default bios"????? Does that even matter? If I can get the programs to work again with ASO, is there another way to get startup and shutdown to work? Have I ruined everything?
Seriously, I'm shaking...please help if you can!!!

Answer:Worse and scared after ZA!!!

6 more replies
Relevance 68.06%

Ok bear with me as I try to explain this.

-There was a power outage in my area and my computer restarted. After restarting it would hang at the Windows loading screen with the blue bar, and it would stay like that forever.

-I went into safe mode which works fine and tried a system restore to an earlier date, and still wouldn't load.

-Went back into safe mode and it said Restoration Complete. Ran msconfig to do a diagnostic boot...still no luck.

-Ran chkdsk /r using Recovery Console, said it fixed the errors but still hangs at the same screen. Ran Samsung HD utility and detected ECC errors.

-Tried to do a Repair Windows installation using an original Windows cd, so it was SP1 when I had SP2. I tried a Windows XP Pro SP2 cd but there was no repair option so I went to my original, which was Home.

-Through the install there was a few errors such as COM+, directdb.dll, inetcomm.dll,msoe.dll and wab32.dll. I clicked okay with all of them and installation completed fine.

-After restarting, loading would be REALLY slow, and actually wouldn't go past the wallpaper. I checked task manager and explorer.exe isn't even there.

-Went into safe mode, which was super slow as well, and same thing with the no icons. Ran safe mode with Command prompt and opened system restore, only to find no restore points.

I am now at a loss as to what I should do.
Any help guys?


Answer:problem that keeps getting worse

Got my hands on a Sp3 Windows Home cd, and got it to the Installing files screen where it shows a Do you wish to install this non verified SoundMAX HD audio driver, and it freezes.


4 more replies
Relevance 68.06%

DDS (Ver_09-12-01.01)Microsoft Windows XP ProfessionalBoot Device: DeviceHarddiskVolume1Install Date: 18/06/2009 4:43:21 AMSystem Uptime: 12/02/2009 10:09:40 PM (7034 hours ago)Motherboard: MSI | | MS-7374Processor: AMD Athlon™ 64 X2 Dual Core Processor 5200+ | CPU 1 | 2700/200mhz==== Disk Partitions =========================A: is RemovableC: is FIXED (NTFS) - 466 GiB total, 375.161 GiB free.==== Disabled Device Manager Items ================= System Restore Points ===================RP100: 04/09/2009 3:12:42 AM - System CheckpointROOTREPEAL ? AD, 2007-2009==================================================Scan Start Time: 2009/12/03 00:04Program Version: Version Version: Windows XP SP3==================================================Drivers-------------------Name: 1394BUS.SYSImage Path: C:WINDOWSsystem32DRIVERS1394BUS.SYSAddress: 0xB80C8000 Size: 57344 File Visible: - Signed: -Status: -Name: Aavmker4.SYSImage Path: C:WINDOWSSystem32DriversAavmker4.SYSAddress: 0xB8340000 Size: 19072 File Visible: - Signed: -Status: -Name: ACPI.sysImage Path: ACPI.sysAddress: 0xB7F79000 Size: 187776 File Visible: - Signed: -Status: -Name: ACPI_HALImage Path: DriverACPI_HALAddress: 0x804D7000 Size: 2150400 File Visible: - Signed: -Status: -Name: afd.sysImage Path: C:WINDOWSSystem32driversafd.sysAddress: 0xB43BE000 Size: 138496 File Visible: - Signed: -Status: -Name: AmdK8.sysImage Path: C:WINDOWSsystem32DRIVERSAmdK8.sysAddress: 0xB7745000 Size: 57344 File Visible: - Sign... Read more

Answer:help ive tried everything and i think im making it worse!!!!!

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Relevance 68.06%

Hi To All!
I'm having some difficulties trying to reformat my friend's computer...she is currently running Windows NT which hasnt run properly from it was installed, we are now trying to install Windows 98.
I managed to run FDisk and deleted her non- dos partitions and NTFS but it will not allow me to format C: it keeps telling me bad command or file name at A> prompt
Can anyone help!

Answer:clueless and getting worse!

10 more replies
Relevance 68.06%

Doesn't do anything when I press some links unless I reload a page and try again, when scrolling on image heavy sites, the screen blanks out and then a portion of the page (website title or corner of an image) multiply across the screen before edge closes or reloads the page, also in general just closes itself whenever, and the keyboard is slow to open or do anything. I Haven't downloaded anything and always clearing cache and data, it still seems to happen more over time.
Running build .164 on mobile if that's any help.

Answer:Edge is worse than IE

Im on same Build as you do. And Lumia 640 LTE, i had no issues with the Edge browser, and Edge is my Favourite tho. What is your Lumia Model?

8 more replies
Relevance 68.06%

is there an easy way to stop these pop ups invading my computer every time i go on to amazon to look for something, windows 7

Answer:pop ups getting worse from amazon

Have you enabled the inbuilt PopUP blocker in your Browser? and do you have an additional AdBlocker for your browser?

3 more replies
Relevance 68.06%

I am having a problem with the Laptop An hp g7-2269. it does not boot up with the battery in and it will not charge the battery. It will however boot up and be fully functional if i remove the battery and plug in ac adapter. i can however replace the battery when it is running and it runs fine but still doesnt charge. uefi diagnostics battery test freezes when i try to run it so i get no information there. and the hp software battery tells me nothing either it just says that the battery or the charging adapter could be bad or to take in to see a hp specialist. my question then is can it be possible that its just a bad battery?

More replies
Relevance 68.06%

I have a series of problems. When booting up, a bright green light rises from bottom of the normally black Windows boot-up screen. Also, I am no longer able to prompt Safe Mode when I hit F8 during the start up. My screen is blurry (to the point that I can barely read text) and flickers. CPU is VERY slow (typing seems to make it slower). I have Symantec Antivirus and Spyware Doctor, but I don't believe either is working properly. Please help.
DDS (Ver_09-02-01.01) - NTFSx86
Run by Tom H at 8:09:49.23 on Wed 03/11/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.298 [GMT -5:00]

AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\ccSetMg... Read more

Answer:Possible virtumonde or worse

Hello.Install Recovery Console and Run ComboFixDownload Combofix from any of the links below, and save it to your desktop. Link 1Link 2 Link 3Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.Close any open windows, including this one.Double click on ComboFix.exe & follow the prompts.As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. If you did not have it installed, you will see the prompt below. Choose YES.Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help youshould your computer have a problem after an attempted removal of malware. It is a simple procedure that w... Read more

3 more replies
Relevance 68.06%


I need your help guys. I have some kind of virus on my computer and i cant delete it. I cant run any program and a cant run " RUN m first pograms all i do virus desabeles the program. Right now i am running my computer in safe mode, and trying to turn on the Search and Destroy program but once i do it it tell me "Error Invalid floating point operation". Whats seems now i can only run SUPERAnitSpyware... Milware bites is messed up too. Whan i press scan it scans my computer and once scan is finnished i pre3ss delete all selected and it sends my computer to lala land. ( different colors start to pop out and then blue screen of death ). Whan i start my pc windows is not starting explorer.exe. Just to let u know this happend in 2 days. Things like "AntiVirus 2009, and all the things from that category showed up before this happend, tried to delete them, but nothing was a succes.

Please help me and sorry for my english.

Answer:!Please HELP... fast before something worse happens

This might help.... Malwarebytes worked.... here is the log from that

13 more replies
Relevance 68.06%

Hello and thank you in advance.

My mother-in-law's lap top has a sudden problem.

Window's XP

Computer boots up, and log in screen appears. There are two account login options: Nana & Nicole (granddaughter). Click on either one, it say loading personal preferences, then logs off, back to log in screen.

Please help!



Answer:Mother-In-Law's lap top (what could be worse)

Hi .

Laptop manufacturer and model?

Do you have a Microsoft XP CD?


3 more replies
Relevance 68.06%

Sorry if this is too long...Starting Problem:
xp Home has been slowing down for about 6 months. IE pages would close line by line, and there was always a slight sound delay. Thought I could help myself - Here's what Ive done and the results ( all suggested by forums):
1. Downloaded Drivermax to update drivers. Before I could finish updating I lost my Wintv2000. Had to start undoing to get it back. I know this screwed up other stuff too.
2. Did all windows updates. This gave me the res:\\ieframe.dll error. Could not access my connected internet. After so much fiddling and changing settings, I decided to do a system restore.
3. Did a system restore ( after learning thru all this that it wasnt even turned on!?!) On reboot it said it "could not load personal profile" , so I lost all saved data. Undid the restore back to where I was.
4. Now the error changed to res:\\ieframe.dll\dnserrordiagoff. Started undoing the windows updates til I found it - for me it was KB960714. Now I dont know which updates to do.
5. Lost Google toolbar during this. Twice it asked to repair, but it still does not work.
6. Ran CCleaner ( ok - shoot me now). Did do a backup. Cleaned everyting except tv entries. Im sure this has mucked this further, yes?

monitor goes black after random periods of time. On reboot it does chkdsk. Computer still slow. Systray icons load in different order every day.

7. Started at your READ ME OR YOU DIE page. Yes, I have ... Read more

Answer:Everything I do makes it worse!

Welcome to Major Geeks!

Actually none of this really sounds like malware problems. Yes you could have malware, but the problems you are mentioned do not sound like malware. Sounds like you problems within your Windows OS.

Attach the logs requested in the READ & RUN ME. Yes ComboFix too. Check to see if MBAM made a log. If not, just skip it for now.

11 more replies
Relevance 68.06%

I tried everything in my power to get rid of this virus. This the third time I've been infected with this virus. Any help will be appreciated.Logfile of HijackThis v1.99.1Scan saved at 3:55:09 PM, on 5/21/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16441)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\brsvc01a.exeC:\WINNT\System32\brss01a.exeC:\WINNT\system32\LEXBCES.EXEC:\WINNT\system32\spoolsv.exeC:\WINNT\system32\LEXPPS.EXEC:\WINNT\Explorer.EXEC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINNT\system32\CTsvcCDA.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeC:\WINNT\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.... Read more

Answer:Vundo Getting Worse

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Download KillBox,unzip/extract it to your desktop. up Killbox and place a check in 'Delete on Reboot'.In the 'Full path of file to delete' box,copy and paste:C:\WINNT\svhost.exeThen press the red button with the white cross.It will then provide a window for you to confirm the delete.Next it will ask if you now wish to reboot,select YES.Allow it to reboot.If it does'nt reboot automatically,reboot manually.****************************Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: are well advised to remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:ViewpointViewpoint ManagerViewpoint Media PlayerThen restart your pc.****************************Please download VundoFix.exe to your desktop.Double-click VundoFix.exe to run it.When VundoFix re-opens,click the "Scan for Vundo" button.Once it's done scanning,click the "Remove Vundo" button.You will receive a prompt asking if you want to remove the files, click "YES".Once you click yes, your desktop will go blank as it starts removing Vundo.When completed,it will... Read more

9 more replies
Relevance 68.06%

Thanks in advance for your help and your valuable service to the community.

I picked up a nasty virus / malware recently and have tried to use McAfee and several Malware removers over the past 3 days to no avail. Everytime I seem to make progress something new emerges.

This started with the Antivirus 2009 Pro Malware taking over. It changed my file associations so I couldn't run any .exe's. It even removed the View Folder Options menu so that I couldn't re-associate the file extensions. Fortunately I was able to logon to the adminstrator logon and fix that issue.

I tried to do an XP repair but was unable to when the application couldn't recognize my administrator password even though I can log into the admin logon with that same password. I then ran Macfee, Spybot and Malwarebytes Anti-Malware. This seemed to clear up most of my problems although I noticed a prior issue of still having one or more iexplore.exe processes running even though I didn't have an IE browser open.

Sure enough the next day I suddenly was unable to connect to the internet.
I finally found your forum and started to follow your proceedures for cleaning.

I was unsuccessful in running several of the procedures. I have found that my DHCP Service will not start and gets the error "Error 1075: The dependency service does not exist or has been marked for deletion". When I try to look at dependencies I get the error "Win32: Access id denied".

He... Read more

Answer:Problem Getting Worse

What OS are you running?
Did you try getting into safe mode and doing a system restore to before this started?
Did you try renaming the programs, running them in safe mode, or changing the .exe extension to .com?
Did you disable your AV and AS programs before running any of the scans?

3 more replies
Relevance 68.06%

A few weeks ago I let a random person from this video game I play (Diablo 2) into my computer using team viewer 9. He said he was going to help me set up a bot to run the game..well he installed something alright.. I had no idea what it was that he put into my computer and I can't find it now but he was able to take my password that day after he told me to relog into Diablo 2 but at that point he was still in my computer so I figure once he was out i might be safe.
I ran malware bytes, avg antivirus and spybot search and destroy, I thought I got rid of any key logger that he might have installed and began using my computer regularly again. Nothing happened over a period of two weeks however just last night I saw him in the game(Diablo 2) and he was laughing about private conversations I was having with my girlfriend... So he is obviously still in my computer and has seen soo much information such as all my passwords for every website I use, where I live, my debit card number and etc.
I would just reinstall windows 7 altogether but I had a friend "build" my computer and this dude didn't even install a CDROM!! And I guess he used a bootleg version of windows even though I had the windows 7 cd?!?
Any ideas what I can do... Should I just throw away my computer??

Answer:I've been key logged or worse!!

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of t... Read more

2 more replies
Relevance 68.06%

A very interesting article on whether anti-virus software is getting worse in detection of both new and known threats.
What do you think?

Is anti-virus software getting worse at detecting both known and new threats?

Earlier this week, Stu Sjouwerman, CEO of security awareness training company KnowBe4, looked at the data published by the Virus Bulletin, a site that tracks anti-virus detection rates. And the numbers didn't look good.

Average detection rates for known malware went down a couple of percentage points slightly from 2015 to 2016, he said, while detection rates for zero-days dropped in a big way - from an average of 80 percent down to 70 percent or lower.

"If the industry as a whole is dropping 10 to 15 points in proactive protection, that's really bad," he said. "Anti-virus isn't exactly deal, but it sure smells funny."

According to Sjouwerman, the Virus Bulletin is the industry's premier testing site. The tests are comprehensive, and consistent from year to year, so that a historical comparison is valid.

? RELATED: 14 tips to secure cloud applications
Several major vendors aren't included in these statistics, he said, because they declined to participate -- and implied that there might be a reason for that.

What's happening is that current anti-virus vendors aren't able to keep up with the attackers, he said, who can generate new malware on the fly.

"The bad guys have completely automated this... Read more

More replies
Relevance 68.06%

while surfing, with no real site preference I started getting this and it is getting worse.. now there are some sites that only open to this even after multiple tries..
any ideas.

I think I attached a file

More replies
Relevance 68.06%

3 days ago when i visited a questionable streaming site my pc got infected with malware. After the infection i could not open any programs. In safe mode i scanned with my AV Kaspersky and malwarebytes: noumerous infections found and deleted.

But now still when my pc is idle, the cpu runs at +- 23% (4 gb processor ). I read in the log the it may be a possible MBR rootkit infection, tried to fix this with windows boot disk: recovery console: fixmbr, fixboot. But no succes. (i have this proces on and off running 2% of cpu: Isass.exe)

the logs of the cleaning procedure are attached.

any help would be greatly appriciated,

BTW let me know if you need that last log.

Answer:Which one is it??? MBR, sasser, worse?

We still need the C:\ --> from running the C:\MGTools.exe.

Also, download TDSSKiller from Kaspersky to your directly onto your Desktop
Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
Allow the application to run if prompted by Windows or any security programs you have installed
It will start the scan and run rather quickly and will notify you of whether anything is found or not.
Follow the instructions to delete/quarantine if asks you what to do when if finds something.
Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


9 more replies
Relevance 68.06%

Hi everyone. Let me say in advance, thank you for your time and consideration.

This afternoon I started the Malware Removal Guide (MRG) . Just finished. <sigh>

Anyway, I now have more processes running than ever before; my computer is even slower (didn't think that was possible, lol). It all started because yesterday anytime I tried to print a file it froze my computer. And in general it was running super slow. I restarted the computer several times to no avail.

Today I noticed that a program called wuauclt.exe was sucking up memory. I ended the process (if I hadn't I wouldn't have been able to follow the MRG).

I'm nearly at the end of my rope. I can't do my work without my computer. I could just :cry I backed up my entire C drive on an external hard disk last night. If I have to wipe it all clean and start over, I can, but I'd really rather not.

I have no ComboFix log because it never finished. I let it try to start up for over an hour and final had to kill the process; I never got to anything but a little box in the center of my computer saying it was starting ComboFix and I'm pretty sure that just starting the application should not take that long. <sigh>

Anyway, here are the rest of my logs.

Again, thank you for your time.

Answer:Things just seem to be getting worse :(

Today I noticed that a program called wuauclt.exe was sucking up memory. I ended the processClick to expand...

That's windows updates.

Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = to expand...

After clicking Fix exit HJT.

Now download The Avenger by Swandog469, and save it to your Desktop.

Extract avenger.exe from the Zip file and save it to your desktop
Run avenger.exe by double-clicking on it.
Do not change any check box options!!
Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

Files to delete:
C:\Documents and Settings\Faculty\Local Settings\Temp\42.tmp
C:\Documents and Settings\Faculty\Local Settings\Temp\43.tmp
C:\Documents and Settings\Faculty\Local Settings\Temp\EAD1.exe
C:\Documents and Settings\Faculty\Local Settings\Temp\EAD1.tmp
C:\Documents and Settings\Faculty\Local Settings\Temp\EAD6.exe
C:\Documents and Settings\Faculty\Loca... Read more

3 more replies
Relevance 68.06%

Hi,Somehow I am being blocked from creating any log files and from running the suggested program "DSS.exe". My browser has been hyjacked. Things are progressivly getting worse. I ran the scan with Hyjackthis and I was able to save a copy that I sent to Trend for a comparasion to other users but I was not able to save it to a log file and I was not able to fix the log file because I could not see the text to erase it plus I could not save the file with another name. Here it is === I sure hope you can help. VictoriaIndex % of PCs with item Code Data1 0.2% O1 ::1 localhost2 0.2% O13 java script:void(0)3 0.0% O16 {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - 0.0% O17 NameServer = 0.8% O2 Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll6 0.5% O2 Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll7 0.2% O2 SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll8 0.1% O2 (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll9 0.0% O2 Spybot-S&D IE Protection - {... Read more

Answer:Please Help-it's Getting Worse By The Minute

HelloApologize for the delay in response we get overwhelmed at times but we are trying our best to keep up.If you have since resolved the original problem you were having would appreciate you letting us know If not please perform the following below so I can have a look at the current condition of your machine.Thanks and again sorry for the delay.Please download Deckard's System Scanner (DSS) and save to your Desktop.alternate download siteDSS will do the following:Create a new System Restore point in Windows XP and Vista.Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.Check some important areas of your system and produce a report for an analyst to review.Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.You must be logged onto an account with administrator privileges when using.Close all applications and windows.Double-click on dss.exe to run it and follow the prompts.If your anti-virus or firewall complains, please allow this script to run as it is not
malicious.When the scan is complete, two text files will open in Notepad:main.txt <- this one will be maximizedextra.txt <- this one will be minimizedIf not, they both can be found in the C:\Deckard\System Scanner folder.Please copy (Ctrl+C) and paste (Ctrl+V) the c... Read more

4 more replies
Relevance 68.06%

Please can someone give me EASY CLEAR instructions how to get rid of this data miner..i am running windows xp and bullseye used to just open a web page..numerous times...however now opens a small window on every page I open as a layer over the web page i am trying to view..please adivse thank you,,,,

Answer:Bullseye..getting worse

click here

2 more replies
Relevance 68.06%

First phishing and now something called pharming which apparently clones the url frpm dns servers and when you type in the url of the site you want to get to, it redirects your private info to these buggers/criminals etc. can't find a suitable description that is sufficient to demean them. Any way, just read this this in Cnet. What do we have to do to protect ourselves? I guess its up to the ISPs and site Hosts now.

Answer:Warning worse to come!

I wonder whether Microsoft's new version of Internet Explorer 7 will offer some protection against this, when it's finally released?

4 more replies