Computer Support Forum

HJT log for "Ultimate Cleaner 2007" browser hijacking and "Worm.Win32.NetSky" warning

Question: HJT log for "Ultimate Cleaner 2007" browser hijacking and "Worm.Win32.NetSky" warning

hello,

This site helped me cure my Laptop in the past and now I am in the process of aiding a friend whose IE is being hijacked to a suspected Anti-malware site for a product known as "Ultimate Cleaner 2007". He also keeps getting repetative pop-ups for an alleged virus known as "Worm.Win32.NetSky" which redirects you again to an unknown site.

here is his HJT log:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:27:09 PM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Chris\Desktop\Hijacked\HiJackThis_v2\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank" class="invilink">http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank" class="invilink">http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop" target="_blank" class="invilink">http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: The sdrmod - {30DACEEB-1BAE-4D12-966B-D4C35359B9A8} - C:\WINDOWS\sdrmod.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153498802531
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/heavyweapon/popcaploader_v10.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/controls/DigWebX2.cab?10,0,910,0
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: hupsrv - {54328C41-8B94-4714-B1B6-26D692883B81} - C:\WINDOWS\hupsrv.dll
O21 - SSODL: bindmod - {C84E4154-214D-4593-BA7E-E5387E878154} - C:\WINDOWS\bindmod.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 7368 bytes

I have also included a Superantispyware log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/11/2007 at 08:17 PM

Application Version : 3.9.1008

Core Rules Database Version : 3342
Trace Rules Database Version: 1343

Scan type : Complete Scan
Total Scan Time : 00:54:52

Memory items scanned : 334
Memory threats detected : 0
Registry items scanned : 4620
Registry threats detected : 17
File items scanned : 24942
File threats detected : 9

Trojan.Net-MSV/VPS
HKLM\Software\Classes\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}\InprocServer32
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}\InprocServer32#ThreadingModel
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}\ProgID
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}\Programmable
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}\TypeLib
HKCR\CLSID\{6BE306E6-555D-41B1-98FF-6453622F4F4B}\VersionIndependentProgID
C:\WINDOWS\ADVREPKON.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6BE306E6-555D-41B1-98FF-6453622F4F4B}
HKCR\MSVPS.MSVPSApp
HKCR\MSVPS.MSVPSApp\CLSID
HKCR\MSVPS.MSVPSApp\CurVer

Browser Hijacker.Internet Explorer Settings Hijack
HKU\S-1-5-21-854245398-776561741-725345543-1004\Software\Microsoft\Internet Explorer\Main#Start Page [ http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2 ]

Trojan.DNSChanger-Codec
C:\Program Files\VideoAccessCodec\install.ico
C:\Program Files\VideoAccessCodec

Desktop Hijacker.AboutYourPrivacy
C:\Documents and Settings\Chris\Desktop\Error Cleaner.url
C:\Documents and Settings\Chris\Desktop\Privacy Protector.url
C:\Documents and Settings\Chris\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Chris\Favorites\Error Cleaner.url
C:\Documents and Settings\Chris\Favorites\Privacy Protector.url
C:\Documents and Settings\Chris\Favorites\Spyware&Malware Protection.url

Trojan.Net-MU/Gen
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#uninstallString
Would anyone be interested in attempting to sort this out?

Thank you all for your time and support.

Relevance 100%
Preferred Solution: HJT log for "Ultimate Cleaner 2007" browser hijacking and "Worm.Win32.NetSky" warning

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

Answer: HJT log for "Ultimate Cleaner 2007" browser hijacking and "Worm.Win32.NetSky" warning

Welcome to TSG

Please download SmitfraudFix

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

3 more replies
Relevance 157.47%

I am infected with this crap and have used the following tools to try to get rid of it:
Windows Defender, Unible PowerSuite (SpeedUpMyPC, Registry Booster & Spyware Protector) and Norton's One Button Checkup and WinDoctor.

Not sure if it's related, but my DISPLAY is locked at 640 X 480.

Atempted the 5 Step Process before posting and Panda ActiveScan froze and crashed after scanning 59253 files, but not before identifying 28 spyware files.

Here's my extra.txt log from Deckard's:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel(R) Pentium(R) 4 CPU 2.80GHz
Percentage of Memory in Use: 36%
Physical Memory (total/avail): 1277.95 MiB / 810.39 MiB
Pagefile Memory (total/avail): 1516.89 MiB / 1165.44 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1930.88 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 37.21 GiB total, 18.7 GiB free.
D: is CDROM (CDFS)

\\.\PHYSICALDRIVE0 - ST340014A - 37.25 GiB - 1 partition
\PARTITION0 - Unknown - 39.19 MiB
\PARTITION1 (bootable) - Installable File System - 37.21 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled... Read more

Answer:Netsky Worm-Popups-The Three Icons - "Error Cleaner" "Privacy Protector" "Spyware..."

Bump.

14 more replies
Relevance 119.48%

Is this spywear? because when i open IE i get that popup saying i should download it

Answer:"Internet Explorer Pre-Cleaner: Ultimate Cleaner 2007"

Where did you get it from?

11 more replies
Relevance 115.42%

hi,

was in the middle of browsing last night and got hit with this virus. a screen popped up and said my computer was infected and to scan my drives. at the same time, it shut down chrome and my ad-aware watch popped up and said started a live scan. I let ad-aware finish, restarted my computer, and I got the same fake antivirus pop ups as before. ad-aware started again in the background. I let it finish again and restarted again, and the same process happened. this is the popup I get after I restart:


it also turns my desktop white after I click OK.

I stopped the scan and tried to open chrome, firefox, IE, nothing works. sometimes they won't even open (and a popup will say that the file is infected) and sometimes it will open but will not display any websites; the browser just remains white or gives me a "this webpage cannot be displayed" general error.

I tried to open add/remove programs and nothing shows up (the window opens but I do not get a list of programs, the area is just white).

I was able to save GMER and DDS to a flash drive and ran them from the desktop.

during my GMER scan I had periodic popups saying my files were infected and that a scan would begin (which of course it didn't). eventually the pop ups stopped but all 3 browsers still don't work.

also, regarding the GMER scan, I have two hard drives, C: and F: (not partitioned, 2 actual drives). I unchecked F and left C checked. while the main drive is C, most of my actual file... Read more

Answer:virus prompting me to install fake anti-virus software.. "Worm.Win32.Netsky"

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

------------------------------------------------------

Please visit this webpage for download links, and instructions for running ComboFix:

http://www.bleepingcomputer.com/comb...o-use-combofix

* Ensure you have disabled all antivirus and antimalware programs so they do not interfere with the running of ComboFix.

Please see this >> http://img.photobucket.com/albums/v6...ee_disable.gif

Please post the C:\ComboFix.txt in your next reply for further review.

Please re-enable your antivirus before posting the ComboFix.txt log.

------------------------------------------------------

15 more replies
Relevance 114.84%

In Windows XP, fully updated, I have several folders full of mp3's and want to see the bit rate and duration. I right click on a column heading and select "Bit rate". I then click on "More..." so I can get to "Duration", and I select that one too.

But all the figures in the "Duration" column appear to be in "hours" and "minutes", so I see "00:04" or "00:03", but what I want is "minutes" and "seconds".

Any thoughts as to how to change this?
 

Answer:Solved: Windows Explorer "Duration" Column - no "Seconds", just "Hours" and "Minutes"

16 more replies
Relevance 113.39%

I am running Windows XP SP3, fully updated, on an Acer lap top PC.

I have several folders full of .mp3's and want to see the bit rate and duration. To do this I right click on a column heading and select "Bit rate". I then click on "More..." so I can get to "Duration", and I select that one too.

The two new columns appear, but the format of the "Duration" column appears to be "hours:minutes", so I see "00:04" or "00:03" for most .mp3's, when what I want to see is 'hours:minutes:seconds", e.g. "00:03:45".

This also happens for video files (.avi files), e.g. all my episodes of "Heroes" (sad, I know) have a duration of "00:42" instead of "00:42:xx".


Here are two pictures showing the problem with the .mp3's. The first is of Explorer showing the Duration as "Hours:Minutes":




The second picture is of the properties window of the first .mp3 in the list above:




I copied some .mp3 files to another (old) PC on my home network, and it displayed the duration field correctly:




Also, the properties window correctly shows the duration also:





I'm not the only person to have this problem. I received a private message from a member of another forum where I posted about this problem several weeks ago. That person also has the same problem with the duration field.

The tech guys on that forum were unable to find the source... Read more

Answer:Windows Explorer "Duration" Column - no "Seconds", just "Hours" and "Minutes"

* bump *

Tricky, this one!

8 more replies
Relevance 109.04%

I am running Windows XP Professional version 2002, service pack2. Dell Dimension 2350 Pentium 4 CPU 2.00Ghz 1.99 Ghz 512RAMwith 7.31GB free of 27.9GB.
Using "Internet Explorer 8 and/or "Mozilla 3.0.12".
95% of the time i use Firefox.
I have Glary Utlities and PC-Tools Spyware Doctor. Just REcently added UniBlue Registry Booster2009. I do not want to pay for removal and it reports over 400 registry problems(will only remove 15)
?? What to Do? please help.
Originally i recieved this error/alert:

~Aug 1 09:
re: VIrus : "W32/Gaobot.worm.gen.u"
______________________________
Today: Aug 22 09:
Spyware Dr. scan reports:
19 threats and 3455 infections in my computer. :

[ high-Trojan.CWS(3 infection). 422(low)application.tracking cookies. high-Trojan.FakeAlert(100 infec.) Elavated-Adware.Component.Claria (2479 infec.)
Adware.BHO.GEN(19) Adware.eBates ~ Trojan.WinShow ~ Adware.IE_Driver,.. etc. etc.]


AVG never downloaded properly to get req'd updates needed to even start it. (i have downloaded & removed it several times.) Same problem with Avira. (connection to server failed/access denied )

Another Quirk i'm having is:
Other than being slow(at times) and Browser hanging/or crashing,...
Upon Reboot a black screen appears with only this text: E.S.C.D. updating ,, (Extended System Configuration Data) in which it started to hang. i reboot F2 or F10, exit the diagnostic test, hit F2 again and Widows started.

When u... Read more

Answer:Malware-Virus re:"W32/Gaobot.worm.gen.u"/re:"feriopsedi.com" alert-...Protocol

Welcome to Major Geeks!

Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.

TDSSserv Non-Plug & Play Driver Disable

READ & RUN ME FIRST. Malware Removal Guide
If something does not run, write down the info to explain to us later but keep on going.
Do not assume that because one step does not work that they all will not.

After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
Helpful Notes:
If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
Starting your computer in Safe mode

If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to s... Read more

1 more replies
Relevance 108.46%

I am hoping that someone can help me with what may be a complex question.

I have a spreadsheet, similar to the demonstration file I have attached. In it, there are a range of columns. One set of columns (A - D), shows a list of numbers that are references to items in a store, and it also shows their location in the store, so it acts as a floor-plan. The next column (E) lists those items again to show the dollar amount that those items have produced in total sales (F).

So, what I'd like to do is to add a conditional formatting to show me the "cold" and "hot" spots on the floor-plan so I can see where sales are most concentrated. I would assume that this would be done with a colour scale (using the range of values in column F to work itself out)?

Either way, the figures in column F would change weekly, so the relevant cells in columns A - D would need to automatically change when they're matching cells in column E - F change.

I hope this makes sense, as it's difficult to explain, but any help that someone could provide would be greatly appreciated.
 

Answer:Solved: Creating Cell "Cold" And "Hot" Spots Based On Values In Microsoft Excel 2007

16 more replies
Relevance 108.17%

My office just upgraded, and I can no longer use Windows XP. On this system, I was able to add a separate taskbar to facilitate quick access to commonly-browsed folder locations on our vast network, and another one expedited the launching of useful programs and lists. Each task on each taskbar was represented with a big custom icon to save eye strain. I had them installed in opposite vertical margins, and they were set on auto-hide to keep them out of the way when not being used. Just move your mouse pointer to the left or right margin, and BAM! Sorry for the cliche, but I really got used to the convenience of what I had set up, and I just don't think I can be as efficient without anything comparable.

Now there appears to be nothing comparable in the Windows 7 GUI, and it's making me sick with rage! I see only the option to put a "toolbar" on an existing "taskbar", and no option to create any additional taskbars! This cramps up your one-and-only taskbar, plus the tiny toolbar access buttons require way too much precision for anything that's supposed to be quick. When you've figured out how to bring up that ridiculous button, the list that it yields is small enough to cause painful eyestrain - nothing efficient, much less cool about this at all! I have seen customization options in other OS GUIs that may have resolved some of these issues, but I see none such in W7.

I have tried every google search string that I can think of, and found... Read more

Answer:Need to add "TASKBARS" (MSese for "Launchpads", "Docks" NOT "Toolbars"

Several possibilities here: Second taskbar in windows7? [Solved] - Windows 7 - Windows 7

1 more replies
Relevance 108.17%

I recently built a call log database in Access 2007 for my team to use when calling agents on our top errors we see from a vendor's error report. My boss is requesting a report to see how many items have been resolved

I have a query started and I am trying to complete this task in a single query (if possible) instead of several queries (as I've done for a couple other things).

I have 3 tables I'm using: Assignment, AgtInfo and CallLog
Joins as follows: Assignment.st=AgtInfo.agcy_st
AgtInfo.agt_id=CallLog.agt_id

Fields in the results: Assignment.assigned_analyst, CallLog.rpt_mnth, CallLog.resolved

Resolved is a yes/no field. I've done a query that converts the -1 to a 1, so that the sum is a positive number for the "Yes" values. I'm not sure how to enter the expression to subract the "Yes" values from the total number of values (yes/no) to get to my "No" count.

Essentially, I'd like the results to display as:

assigned_analyst, rpt_mnth, CountYes_resolved, CountNo_resolved

Somehow the connection is just not clicking in my brain with everything I've read though searches. Any help is appreciated! Thanks!
 

Answer:Solved: Access 2007 Query: Return count of "Yes" and "No" values for Analyst/Report M

It is easier to add another column to counf the Nos, use
0 or is null
as the IIf statement and use a 1 to count them
 

3 more replies
Relevance 108.17%

Microsoft Security Essentials (MSE) keeps identifying the following malware. Every time I try to delete it, MSE says the deletion is successful, but the problem returns in a few minutes.TrojanDownloader:Win32/Karagany.I
Rogue:Win32/Winwebsec
Looking at the detailed information from MSE, I discovered that there's an undeletable executable that's causing the problems.C:\Users\Default.Default-PC\AppData\Local\gfrzerf.exe
I have the following programs on my computer:ClamWin Antivirus
Comodo Firewall
Microsoft Security Essentials (MSE)
Spybot Search & Destroy
I'v tried to delete the file with Unlocker, which says it requires a reboot first, but the file markedion is still there after the reboot.

I've tried to delete the file with FileAssassin, but it says I don't have the necessary permissions to open the file, even though I'm running FileAssassin as an Administrator.

I've tried to use the following command line functions to delete the file, but it says access denied.CD C:\Users\Default.Default-PC\AppData\Local
DEL gfrzerf.exe

RMDIR DEL /F /Q /A C:\Users\Default.Default-PC\AppData\Local\gfrzerf.exe

DEL C:\Users\Default.Default-PC\AppData\Local\gfrzerf.exe

DEL /F /Q /A C:\Users\Default.Default-PC\AppData\Local\gfrzerf.exe
As per the instructions stickied for posting requests for help, the appropriate DDS logs are attached to this message and presented below.

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion... Read more

Answer:Unremovable Viruses "Win32/Karagany.I" and "Win32/Winwebsec" from Undeletable File

Just a quick update. An old related problem re-occured. An infected file I removed before has returned.
TrojanDownloader:Win32/Karagany.I C:\Users\Default.Default-PC\AppData\Local\Temp\oleda0.14743533410625287.exe
This means that now I have two infected files...
C:\Users\Default.Default-PC\AppData\Local\gfrzerf.exe
C:\Users\Default.Default-PC\AppData\Local\Temp\oleda0.14743533410625287.exe
... causing two problems:
TrojanDownloader:Win32/Karagany.I
Rogue:Win32/Winwebsec
I've continued my own Google research and have tried to delete the file using the following command prompt lines, with CMD running in Administrator mode:takeown /f C:\Users\Default.Default-PC\AppData\Local\Temp\oleda0.14743533410625287.exe

icacls C:\Users\Default.Default-PC\AppData\Local\Temp\oleda0.14743533410625287.exe /GRANT ADMINISTRATORS:F

attrib -r -a -s -h del C:\Users\Default.Default-PC\AppData\Local\Temp\oleda0.14743533410625287.exe

DEL /F /Q /A C:\Users\Default.Default-PC\AppData\Local\Temp\oleda0.14743533410625287.exe
Each time returns "acess is denied". I cannot seem to get rid of the infected files.

2 more replies
Relevance 108.17%

I have followed pre-steps. My computer is running Win 98 (don't ask why), and when I went to Windows update page I got a message saying that the updates page was for Windows not Mac users? Many pop-ups are saying that they are from Drive Cleaner, but Drive Cleaner search programs haven't helped. Many thanks for any who can provide help cause I'm gettin' lotsa lotsa pop ups. Phil

Panda Soft and Hijack This logs attached.

Logfile of HijackThis v1.99.1
Scan saved at 7:17:19 PM, on 3/20/07
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\PROGRAM FILES\COMMON FILES\ADAPTEC SHARED\CREATECD\CREATECD50.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\SCANSOFT\OMNIPAGESE\OPWARE32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\PROGRAM FILES\LOGITECH\SETPOINT\KEM.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\MEMOREX\TRAVELDRIVE003C\UFDSE98.EXE
C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGR... Read more

Answer:"Drive Cleaner" "Oinadserver" and Misc popups

Quote:





Originally Posted by Iguana07


I have followed pre-steps. My computer is running Win 98 (don't ask why), and when I went to Windows update page I got a message saying that the updates page was for Windows not Mac users? Many pop-ups are saying that they are from Drive Cleaner, but Drive Cleaner search programs haven't helped. Many thanks for any who can provide help cause I'm gettin' lotsa lotsa pop ups. Phil

Panda Soft and Hijack This logs attached.

Logfile of HijackThis v1.99.1
Scan saved at 7:17:19 PM, on 3/20/07
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\PROGRAM FILES\COMMON FILES\ADAPTEC SHARED\CREATECD\CREATECD50.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\SCANSOFT\OMNIPAGESE\OPWARE32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\PROGRAM FILES\LOGITECH\SETPOINT\KEM.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\MEMOREX\TRAV... Read more

5 more replies
Relevance 107.88%

Hi,

When our website users click on an html attachment embedded on a web-page in IE9, the download manager will not display the "Open" option. It will only display "Save" and "Cancel" which our users don't like, having to save the
html document in a folder to open it. Whereas, when downloading attachments like pdf, word etc. all three options are displayed. 

Is there any setting to tweak , which will display all the 3 options for HTML attachments as well?

Answer:IE9 download manager will not display "Open" option (only "Save" and "Cancel" is displayed) for downloading HTML documents.

Hi,
As you know, the Open-Save-Cancel dialog box helps you prevent your computer from affecting by virus while downloading. 
So I suggest you test to reset all zones to a lower level temporarily and then please attempt to download this html attachment again.

However, since you can normally download the other documents, I suspect there is some restriction in the website which you are trying to view. I recommend you to contact the administrator of that website if possible.
could you please send me the link of the website from where you are trying to download the html attachment?
Thanks!


We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place.

6 more replies
Relevance 107.88%

I have run webroot antivirus with antispyware, several times. Every time I do, it finds the same virus (sometimes others with similar names). This is from the latest scan:

Mal/EncPk-CZ
Troj/FakeAle-FK

and some cookies. However often I quarantine them, they reappear on the next scan and I also can't get the desktop to go back to its normal appearance, it's gone white with a big warning (as above) and refers to:

win32/adware.virtumonde
win32/privacyremover.M64

having been detected on my computer.

I have gone through the 5 steps.

This is the active scan log:

;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-08-21 18:37:14
PROTECTIONS: 1
MALWARE: 13
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Webroot AntiVirus with AntiSpyware 5.8.1.55 Yes Yes
;==============================================================================================... Read more

Answer:Can't get rid of "Troj/FakeAle-FK" and "Warning! Spyware detected on your Computer!"

Hi Henry


Disable SpySweeper's realtime protection. Open Spysweeper and click on Options
Choose Program Options and uncheck
load at windows
startup
.
On the left click
shields
and then uncheck everything.
Uncheck
home page shield
.
Uncheck
automatically restore default without notification
.
Exit the program.


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/comb...o-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
Remember to re-enable them afterwards.

Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log.

A word of warning: Neither I nor sUBs are responsible for any... Read more

19 more replies
Relevance 107.88%

I've run SuperAntiSpyware, Ad-Aware, SpyBot and Norton which removed some trojan files and registry items but I'm still getting pop-ups ("Security System Warning" and "System Integrity Scan Wizard"). Below is my HiJackThis log. Thanks in advance!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:00:21 PM, on 4/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\cryptainersrv.exe
C:\WIND... Read more

Answer:"Sys Integrity Scan Wizard" & "Security System Warning" Pop-ups

Hi Welcome to TSG!!
Please visit this webpage for instructions for downloading and running ComboFix.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
 

1 more replies
Relevance 107.88%

I got my dell few days ago. Installed it with Samsung EVO 850 SSD 500 Gb and Kingston 8GB PC3L - 12800 SODIMM.The Windows 10 Home OEM home is installed on HDD 1TB so I decided to use Samsung Data Migration software to clone the data to SSD. However, the OS crashed and decided to install a fresh Windows 10 Enterprise to SSD and deleted the previous OS on HDD using diskpart.Now after Installing Windows 10 Ent OS files. Every after BIOS run, I got BSOD errors "MEMORY MANAGEMENT" + "Page Fault it non paged area" + "IRQL NOT LESS OR EQUAL" 

More replies
Relevance 107.3%

When I am building a query in Access 2007, the "Sort:" and "Criteria:" selctions don't work when I switch from 'Design View' to 'Datasheet View'.
If I change the query type from 'Select' to 'Make Table' and run the query, the data in the new table mathces the "Sort:" and "Criteria:" selctions correctly.
What is wrong with my Select Query - Datasheet View? This is very annoying.
 

Answer:Access 2007 "Sort:" and "Criteria:" not working in Datasheet View

10 more replies
Relevance 106.72%

Ok, so im new here so hey everybody..

to the point: my laptop is "stuttering"/lagging/skipping.
whatever you wanna call it its doing it.
my video/music/and cursor skip every second for a splt second it starts on start-up and dont stop til i turn my laptop off. it happens in a pattern its not random, ive done checked my drivers, spyware, and m RAM is good.. so can someone please help me? ***could it be because my battery wont hold a charger? so it has to be hooked up to the charger at ALL times or it dies Example: is the charger not got the "juice" to run the laptop by itself so it studders/skips..*** i dont know if this has anything to do with my problem but i ran "event viewer" and found this : The following boot-start or system-start driver(s) failed to load:
Cdrom
Imapi
redbook

PLEASE HELP




OS Version: Microsoft Windows XP Home Edition, Service Pack 3, 32 bit
Processor: Genuine Intel(R) CPU T2250 @ 1.73GHz, x86 Family 6 Model 14 Stepping 8
Processor Count: 2
RAM: 502 Mb
Graphics Card: Mobile Intel(R) 945GM Express Chipset Family, 224 Mb
Hard Drives: C: Total - 39723 MB, Free - 23484 MB; D: Total - 12684 MB, Free - 3633 MB;
Motherboard: Dell Inc., 0FF049, , .HWPLLB1.CN1296167S5169.
Antivirus: McAfee VirusScan, Updated: Yes, On-Demand Scanner: Disable
 

Answer:Solved: Whole computer "studders"/"skips"/"lags" .. have event viewer report (PLEASE

6 more replies
Relevance 106.72%

I double-click and get "search" instead of "open"--only when I click a disk, like Hard Drive C: or Floppy A: or CD F: and so on.

It didn't used to do this, so I must've inadvertently changed some setting somewhere, but darned if I can find it now.

Any ideas?
 

Answer:Solved: On the "my computer" list, I double-click on disks and get "search" instead of "open"

12 more replies
Relevance 106.72%

It seems that no matter how I set this, after the next start-up it reverts to "15 minutes".  What registry key controls this?

More replies
Relevance 106.14%

I have a nested "IF" statement that inlcudes the "OR" function because I have more than 7 logical tests. One of the logical tests looks for two fields to be true in order to return the "value if true". If either or both fields are false, then the "value if false" is returned, in this case zero. When the value of the first field is correct, but the value of the second field is not correct, zero is returned, which is the "value if false" and a correct return.

However, when both fields are false, the formula is returning the word "FALSE" instead of zero.

The attached file shows these returns and the formulas. Cells F2-7 are corrrect returns (highlighted in green), while cells F8-11 are not correct returns (highlighted in red).

Any ideas on how to return the "value if false" (zero) in cells F8-11 would be appreciated.
 

Answer:Solved: Excel 2007 - Nested "IF" formula using "OR" Function

8 more replies
Relevance 106.14%

Hiya

This is doing the rounds a lot. Seems to be causing no end of trouble for people with IIS.

http://www.kav.ch/avpve/worms/iis/bady.stm

Regards

eddie
 

Answer:I--Worm.Bady (aka "Code Red","CodeRed") Update

Found this also:

http://www.cert.org/advisories/CA-2001-19.html

Unix or NT:

http://www.cert.org/tech_tips/win-UNIX-system_compromise.html

Regards

eddie
 

1 more replies
Relevance 105.85%
Answer:will vista ultimate "upgrade version" have the "extras?"

Upgrade versions always have the same features and extras as the full version of the same type. The only difference is the pre-installation requirements.
 

4 more replies
Relevance 105.85%

I'm at the end of the line here. My friend downloaded a suspicious program from Sourceforge and I can't get rid of the malware that came along with it. I consider myself a tech-savy person but I just can't find the source of this evil thing that's infected my computer. I've uploaded an MBR check and the FRST logs including shortcuts.

The main reason I know the malware still exists is that it keeps writing in redirects to sweetpageurl on chrome. I can remove them manually or through anti-malware but they keep reappearing. I am in serious need of help or I might have to reformat and lose about 500 pdfs worth of medical study notes.

Please help me!
 

More replies
Relevance 105.56%

Found this on the Chrome Web Store, which I suspect to be a scam.

Code:
https://chrome.google.com/webstore/detail/avira-browser-safety-pro/glgamdmhnnkacilfgbcbdippgnpfjahg
"Avira Browser Safety PRO" by "from Google Quantum Developers" which when clicked redirects to Avira's legit SafeSearch site, https://safesearch.avira.com - Priced at £0.59

They have other extensions that requires a single payment to use.

"Hangouts" by "from Google Quantum Developers" - £0.59

"Google Voice Pro (by Google)" by "from Google Quantum Developers" - £0.59

Even a monthly subscription based scam.

"Hide My Ass! VPN Proxy Client" by "from Google Quantum Developers" - £31.99 per month!

------


Please stay aware when deciding on which Extensions you use, always read reviews or find extensions through the developers site.
 

Answer:"Avira Browser Safety PRO" by "from Google Quantum Developers" is a scam!

Thanks @Huracan ,the scam extension submitted to Extension Defender
 

1 more replies
Relevance 105.56%

ie9 new browser opens "blank" windows 7. Changing it to "home" doesn't last if you shut down. Next session, it still opens "blank"

Answer:ie9 new browser opens "blank" windows 7. Changing it to "home" doesn't

Welcome to Seven Forums bobbot11. Help us understand. When you 1st open IE, it opens to a blank page instead of your home page? Or is opening new tabs that open a blank tab? Or is opening a new window that opens a blank window?

If IE is opening to a blank page instead of a home page you have set, try re-registering IE.

Download the IE Restorator, and choose Re-register 32 bit IE in (whichever version your OS is) W7

SF IE Restorator - Troubleshooting General Issues with IE

See if that helps. A Guy

1 more replies
Relevance 105.56%

Ok, so im new here so hey everybody..

to the point: my laptop is "stuttering"/lagging/skipping.
whatever you wanna call it its doing it.
my video/music/and cursor skip every second for a splt second it starts on start-up and dont stop til i turn my laptop off. it happens in a pattern its not random, ive done checked my drivers, spyware, and m RAM is good.. so can someone please help me? ***could it be because my battery wont hold a charger? so it has to be hooked up to the charger at ALL times or it dies Example: is the charger not got the "juice" to run the laptop by itself so it studders/skips..*** i dont know if this has anything to do with my problem but i ran "event viewer" and found this : The following boot-start or system-start driver(s) failed to load:
Cdrom
Imapi
redbook

PLEASE HELP
 

Answer:Whole computer "studders"/"skips"/"lags" .. have event viewer report (PLEASE HELP)

**(DONT KNOW IF THIS WILL HELP..)***

Tech Support Guy System Info Utility version 1.0.0.1
OS Version: Microsoft Windows XP Home Edition, Service Pack 3, 32 bit
Processor: Genuine Intel(R) CPU T2250 @ 1.73GHz, x86 Family 6 Model 14 Stepping 8
Processor Count: 2
RAM: 502 Mb
Graphics Card: Mobile Intel(R) 945GM Express Chipset Family, 224 Mb
Hard Drives: C: Total - 39723 MB, Free - 23484 MB; D: Total - 12684 MB, Free - 3633 MB;
 

2 more replies
Relevance 105.56%

MODS MOVE THIS TO THE RIGHT SECTION IF ITS IN THE WRONG?..thanks!

help me please! about "POP""IMAP""SMTP" incoming/outgoing mail server for Tbird....

i have no clue on what to do.. im stuck at a screen that says this





?..? said:



"Server Infomation"
"Select the type of incoming server you are using"
"[_??_] POP [_??_] IMAP"

"Enter the name of your incoming server (for example, "mail.example.net")."

"Incoming Server: [___????????????????___]"
______________________________________________________________________

"Uncheck this checkbox to store mail for this account in its own directory. that will make this account appear as a top-level acount."

"[_??_] Use Global Inbox (Store mail in Local Folders}"

"Enter the name of your outgoing server (SMTP)(for example, "smtp.example.net")."

"outgoing Server: [___????????????????___]"Click to expand...


 

Answer:help me please! about "POP""IMAP""SMTP" incoming/outgoing mail server for Tbird...

afaik hotmail does not provide pop\imap or smtp for free you may get it if you pay for the hotmail service but i would not recommend you do that just so you can get pop\imap or smtp

hrrm tbird and hotmail from the thunderbird faq
Can I access my Netscape WebMail or Hotmail accounts through Thunderbird?

No. Netscape WebMail and Hotmail use proprietary protocols. To access WebMail directly through an e-mail client requires you to use Netscape 6+ with AIM; to do so with Hotmail requires either Microsoft Outlook or Outlook Express. Of course, you can access your WebMail account on the Web at http://webmail.netscape.com/, or Hotmail at http://www.hotmail.com/.
 

8 more replies
Relevance 105.27%

ok!!!!!!!!!! what is it and how do i fix it,,,, eyes crossed knees woobly help?????????????????????
 

Answer:[Solved] mplay32.exe,1"/play/close"%L"." and sndrec32.exe"%L"."

9 more replies
Relevance 104.69%

I keep getting strange warnings on some forum sites and stuff like craigslist and ebay at times. You know when you go to a sire that is "untrusted" and there is a "get me out of here" button in grey and under that there is the "Technical details" text (clickable" and the "I understand the Risks" text (also clickable). I get thee when I install a new server on my LAN and I go to an admin port on that server and it says it is an unknown connection.

But what I am getting, while browsing stuff on Craigslist, like in the forsale, I click on an ad (the ad hasn't even opened yet) and it takes me to this "Untrusted connection) screen. I also get this for a number of forums from time to time. I use the same URL on one computer and it doesn't show up, but on another computer it will, both loading at the same time. Also it seems that it can vary based upon which ISP I'm connected with at the time - sometimes one will have the warning while the other doesn't, sometimes both have it.

I've suspected MITM attacks on my machine and don't know what to do about figuring that out and how to stop it.

Can anyone shed any light on this issue or point me in the correct direction?
 

Answer:"This connection is Untrusted" - pops up in browser on "safe sites" - why?

What are you using for an antivirus program?
 

4 more replies
Relevance 104.69%

This week I'm at my in-laws -- and doing routing maintenance on their computers and wireless network -- which includes thorough bumper to bumper scanning of their computers for a variety of things. While doing so with their relatively new Dell laptop I encountered the infamous and incredibly annoying Browser Helper [??] that Dell, in a deal with Google, is installing on new computers.

This "feature" is incredibly annoying when ultimately encountered during the loading of a legit web page. It takes what is presumed to be a mis-typed URL or one that doesn't resolve in the DNS (domain name server) -- including from embedded ad banners -- and instead of returning a standard DNS error, it redirects the browser to a Dell web page with Google search box and a host of click-through adverts. My ISP's home page (which I was using to get to my web mail) was triggering this before the web page could completely load -- as were some web pages on Newegg before that.

Took me a while to sort out what it was as Spybot S&D, Adaware and Hijack This didn't find it (at the least I didn't recognize it in the Hijack This log). Turns out it's not that difficult to get rid of -- but Dell/Google don't make it plainly obvious.

Here's the fix:

Close Internet Explorer (important!)
Fire up the Control Panel
Go to "Add or Remove Programs"
Look for one of these programs (they've used several different program names):
"Browser Addre... Read more

More replies
Relevance 104.69%

Browser (IE7) will frequently redirect to a page with a message "Sorry we couldn't find "http://www.atdmt.com..." or "http://ad.doubleclick.com" or other various tags (though these are most common).

Web pages will often not load at all or will redirect while reading a webpage without any user action.

Occasionally it will simply say unable to load "actual web page trying to visit". Also oddly - problem seems to occur much more frequently in the morning than evening. This makes me wonder if it is a internet provider issue.

Problem has been occuring over the last 2-3 weeks.

I have followed the 5 Step process to the letter and run DSS after the first four steps. The contents of file main.txt are listed below and extra.txt is attached as a separate file.

Very much appreciated in advance for your help when you get a chance to review this.

Main.txt
---
Deckard's System Scanner v20071014.68
Run by SJL on 2008-01-30 17:09:02
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------



-- Last 5 Restore Point(s) --
83: 2008-01-30 22:03:16 UTC - RP661 - Deckard's System Scanner Restore Point
82: 2008-01-30 20:21:50 UTC - RP660 - System Checkpoint
81: 2008-01-29 18:59:32 UTC - RP659 - System Checkpoint
80: 2008-01-28 18:34:48 UTC - RP658 - Installed Microsoft Office Live Meeting 2007
79... Read more

More replies
Relevance 104.4%

Hi.. My scanner showed that my system was infected with these 2 virus' and I need help removing them as I have read that they are very bad. Any help is greatly appreciated. I have attached and pasted what I believe is required. Thank you in advance!

Hijackthis.log
------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:18:35, on 6/23/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Luth Research\SavvyConnectFramework\bin\dtservice\JavaInvoke.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Common Files\Hewlett-Packard\WJA Update Service\HPWJAUpdateService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\1.3.21.57\GoogleCrashHandler.exe
C:\Program Files\Common F... Read more

Answer:"Win32:Alureon-er" and "badcab-k" removal help needed!

3 more replies
Relevance 104.4%

Hi there,

I'm using Windows XP SP3. I'm having a good deal of trouble with both "Win32/Cryptor", "Packed.Monder" amongst others. AVG is also reporting "Trojan Horse Backdoor.Genericll.AJFO" and "Trojan Horse Rootkit-Pakes.M".

The main problem I am having is that when running in normal mode, my computer is suddenly restarting without warning!

Before this happens, typically AVG will become aware of about 3 - 6 sudden instances of infection - C:\Windows\System32\drivers\braviax.exe (cryptor) or C:\Windows\system32\drivers\ntfs.sys (rootkit-pakes) among others. And then the computer will surely restart.

Here is what I did before running DDS and GMER.

Firstly I ran a full scan in AVG (while in safe mode). I have the log of this if you need it.

After this, I ran AVG again, it removed 10 infections - I rebooted my computer and then installed the Malwarebites Anti-Malware scanner, updated it, renamed the .exe file and ran a quick scan which removed
a host of other infections.

After this, my computer wasn't restarting anymore, but I'm nearly certain the viruses are still around. In fact, I think it might have something to do with the fact that I'm disconnected from the internet now.

Here is what DDS gives me now:


DDS (Ver_09-07-30.01) - NTFSx86
Run by Owner at 20:26:17.59 on 16/08/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2553 [GMT 1:00]

AV: AVG... Read more

Answer:"Win32/Cryptor", "Packed.Monder" Issues

BUMP please! Sorry guys. My computer has been out action for days!

1 more replies
Relevance 104.4%

I noticed my computer is not starting up the same as it use to. I used Ad-Aware SE and it found "Win32.Mydoom.A". When i clicked to delete the file a popup screen said "Some objects could not be removed, Try closing browser windows prior to the removal. If this does not help, reboot and run Ad-Aware again."
The files were "c:\windows\system32\wmimgr32.dll". This file address was listed 13 times.
After I rebooted the system I got the same message.
I also tried and used xoftspy and superantispyware with no luck, then I tried to delete "wmimgr32.dll" manually but wasn't allowed to.
Logfile of HijackThis v1.99.1
Scan saved at 10:17:07 PM, on 6/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGR... Read more

Answer:Solved: "Win32.Mydoom.A" and "wmimgr32.dll" problem

16 more replies
Relevance 104.11%

Windows 7 Home Premium

I would provide a screenshot (or three) however that is at the crux of my problem - I should perhaps say my current problem...now, with "7" (I am beginning to tire RAPIDLY of 7, much more quickly than I did with either XP, or Vista).

PROBLEM: When I attempt to "Save As" a document (Notepad, for instance), or even a Paint image, I get a window/page/screen/whatever, that has no "Buttons" ... no button to "Save", no button to "Cancel". Simply NO BUTTONS???

I had this problem the other night, and we "faked" or cheated our way through it, by using the Enter (Return?) Key to advance the cursor (cursor??) to where we wanted to be (well, we "hoped" we were "there", anyway, since we could not "see" what button or drop-down dialog box was selected or highlighted).

It's almost as if I had a "Resolution" problem, whereby the resolution is set too low (say, 800 x 600), things are too big to be seen/won't FIT on the page. However, my resolution is set to the "Recommended" 1366 x 768.

Please help...this Netbook would be a WHOLE LOT easier to throw against a wall than my desktops ever were . . .

Thanks in advance,
glenn . . .
PS, Hoping I was/am clear here...under the drop-down boxes of "File Name" and "Save as Type", there is nothing to select - not "Save" or "OK" or "Cancel" ... NOTHING????... Read more

Answer:No "Buttons" to "Save" or "Cancel" in Dialog Boxes WIN7

Hi,

Type dpi into the Search box and choose "Make text smaller or larger" at the top of the search result list. In the window that opens see what it is set to. You want it at 100% rather than 125% or 150%. So if higher than 100% change it back to 100%. Hit Apply. You will need to reboot. See if that helps.
 

5 more replies
Relevance 104.11%

I am using Windows 7 on my laptop and I have question about when to use "Home", "Work" and "Public" profile.

If I am logging in without setting password, and I am logging in network with "Public" profile, then will any other user, who can see my computer, be able to enter my computer and check the contents on my computer ?

I am connecting to a network and there are 6 other users connected to this network. In the set network location window, if I select the netwoek as "Home", does it mean that other 6 users will not be able to see my computer on network and if I use "Public", then all other six users will be able to see my computer on network ?

Thanks

More replies
Relevance 104.11%

Hey there...I found a folder that I've never seen in my D partition before...I partition my hdd into 3 parts...C=OS installation...D=Programs and Games...E=Misc downloads and music and pr0n ...

Well I've never had a virus or anything in my D partition before...I just found this folder named "winnt" and it had some bat files and some kind of Airline JScript and something that looks like an airplane tracker...

Then in a folder named sdata (still in the winnt folder) there's files like 911, police, air, fire, etc...OMFG!!! This is like some terrorist thing or something...FBI is gonna find me and I'll never see the light of day again!!! I'll miss the [H] and I haven't even watched LOTR Extended Platinum Collectors DVD thing (the big ass package with those book holder things)...I haven't even completed Doom 3 or started playing HL2 or even had a chance to buy an X-Box and play Halo 2!!!

AHHHHHH!!!!!! WTF is this crap on my computer??? I'm gonna delete this...I should delete it right??? Scans say it isn't a virus but what do they know...I'm screwed...

THANX
C'YA
 

Answer:OMG!!! Found some folder with files like "911" "police" "air" and a airplane tracker!

if youre os is on C: there shouldn't be a winnt dir on d:, should be safe to delete it.
 

7 more replies
Relevance 104.11%

Please help review my HijackThis File. My computer has problems with "Redirected Searches", "Advertising Pop-Ups", "Fake Anti-Virus Pop-Ups".

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:46:28 PM, on 10/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.
 

Answer:"Redirected Searches", "Advertising Pop-Ups", "Fake Anti-Virus Pop-Ups"

Welcome to Major Geeks!

Please read ALL of this message including the notes before doing anything.

Please follow the instructions in the below link:

READ & RUN ME FIRST. Malware Removal Guide
and attach the requested logs when you finish these instructions.

**** If something does not run, write down the info to explain to us later but keep on going. ****
Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
Helpful Notes:

If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

Starting your computer in Safe mode

If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
If you cannot seem to login to an infected user account, try using a different user... Read more

5 more replies
Relevance 104.11%

Hi all,

So I'm kind of stuck.. I currently have the problem where I am in an endless cycle of "loading files" -> "Windows Boot Manager" (see: How To Boot Into Safe Mode On Windows 8 (The Easy Way)).
I have tried to load all of the options -- and none successfully load.
I also end up at a OneKey Recovery as well.. unfortunately, the laptop does not have initial backup or user backup images.
I have a Windows 8 CD for repairing purposes.. however, I cannot load the BIOS/UEFI to change the boot order to load the optical drives first. I have also tried to remove the CMOS battery to fix it.. did not work. .
Also - Windows Boot Manager:
Windows Setup [EMS Enabled] -- does not load properly (leads to OneKey Recovery) Safe Mode (does not load properly) Safe Mode with Networking (does not load properly) Safe Mode with Command Prompt (doesn't load - tries to boot and load all files onto partition that is too small.. can't change partition?)
Enable Boot Logging Enable Low-Resolution Video Debugging MOde Disable automatic restart on system failure Disable Driver Signature Enforcement Display Early Launch Anti-Malware Driver
Start Windows Normally
Any ideas would be greatly appreciated! Thanks!

More replies
Relevance 104.11%

Hello guys, the last week I've been strugling with these nasty BSODs. At first I thought it was my HDDs as ntoskrn.exe somewhat hinted towards that from googling it. My HDDs have been causing a lot of trouble earlier as well due to their somewhat long years of service. However, I've recently reformated my computer and installed W7 on a brand new Corsair Force GT 120GB SSD hoping the BSODs would go away, they didn't.

I googled BSOD and I stumbled upon this forum and I thought I'd give it a try. I'm somewhat desperate, as I need my computer working for both work, school and amusement.

I've been trying to run Memtest in order to test my memory but without any results. I'm also currently running on only on 4GB chip instead of two, to see if the problem still exists. Also, without any results.

This is the second time I'm writing this thread btw, I was just about to post it and my PC crashed.

Here is my two logs + dxdiag (last crash didn't generate a log oddly enough).

Here is additional hardware/gear that I use:

Razer Megalodon 7.1 Headset
Razer Naga
Logitech G19
Logitech C920 (Webcam)
Corsair 750W PSU

My temperatures are also good. Both CPU and MB idles at around ~25. GPU's all good too. I'm also using a Corsair 650D chassi with dustfilters at both air-income so dust is minimal. On top off this, I use airpressure to clean away dust somewhat regularly and I also did exactly this 2 days ago when I reinstalled the pc.
... Read more

Answer:BSOD - "Memory management", "Bad pool header", "ntoskrnl.exe"

Are you over-clocking? Is the bios set to its defaults? Is the SSD set on a SATA 3 port in AHCI mode?
 

5 more replies
Relevance 104.11%

Hi everyone!

Yesterday my HP laptop (Windows 7) started getting BSOD with various types of errors (mostly "STOP: 0x00000F4", "STOP: 0x0000007A", "c00021a" and one "missing %hs, c0000135"). Most of the time it restarts without any issues and works fine right after the BSOD and then an hour or two later I get a BSOD again.

I have tried restoring to Last Known Good Configuration, startup repair, hard disk check, virus scans and I also uninstalled any recently added programs I could think of and cleared up more than 50% of my hard disk space. None of these seem to have helped and I still get BSOD regularly.

I have attached the folder from the SF Diagnostic Tool and would appreciate any advice!
Thank you!

Answer:BSOD every few hours: mostly "STOP: 0x00000F4", "c00021a" & "c0000135"

Welcome to the forum.

MSINFO32:
Please go to Start and type in "msinfo32.exe" (without the quotes) and press Enter
Save the report as an .nfo file, then zip up the .nfo file and upload/attach the .zip file with your next post.
Also, save a copy as a .txt file and include it also (it's much more difficult to read, but we have greater success in getting the info from it).
------------------------
Upload a screenshot using: CrystalDiskInfo For how to upload a screenshot or file, read here
Test your Hard Drive(s) by running: Hard Drive Diagnostic Procedure
------------------------
Test and Diagnose RAM Issues with Memtest86+: RAM - Test with Memtest86+


   Tip
Pay close attention to Part 3 of the tutorial "If you have errors"
Test the RAM with Memtest86+ for at least 7-10 passes. It may take up to 22 passes to find problems. Make sure to run it once after the system has been on for a few hours and is warm, and then also run it again when the system has been off for a few hours and is cold.


------------------------
Monitor hardware temperature with system monitoring software like Speccy or HWMonitor. Upload a screen shot of the Summary tab as well:Piriform - Speccy
CPUID - HWMonitor
For how to upload a screenshot or file, read here

Code:
*******************************************************************************
* *
* Bugche... Read more

5 more replies
Relevance 104.11%

Ok so I'm using a custom visual style made by another user however I don't really like the buttons used that I mentioned above. The creator states it is acceptable to change the theme to however you like as long as you don't redistribute it anywhere.

Ok so I opened up the .msstyles file (using Restorator) located in the theme folder of this VS. I went into the images directory and located what seems to be the images used for the buttons. Intuitively, it seems like it would make sense to replace those images with different ones (perhaps from another visual style) and it should change them. However, would this actually work? Could the theme get messed up in some other way (like proportions or something if the new button images are smaller)? I don't know of any other way to change them that would be easy.

But I did run into another problem. For some visual styles I can't even locate those buttons in the images directory. Where else would they be?

Answer:Changing the "minimize" "maximize" and "close" buttons of a theme

Use Windows Style Builder to do that...

9 more replies
Relevance 104.11%

Posting hi-jack this log - I was having some problems with browser hi-jacking - are these things legitimate: about:blank, iesu.exe, begin2search(a command with google in it). I also finally downloaded XP2 service pack and now I can't get access anything by the Start button. I can't get to my Control Panel - well, I click it and the hourglass comes up but nothing happens...here's my log - thanks in advance...OH! I keep deleting those "dll.000" thingies and they keep coming back - THAT is what is trying to change my browser because the GiantBeta thing says it's blocked at first but then they get through and it says it's blocking one of those from being changed to another! Help! Thanks again.

Logfile of HijackThis v1.99.1
Scan saved at 5:36:52 PM, on 2/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\apivw.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\tbctray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C... Read more

More replies
Relevance 104.11%

Example sentence: vrytim I prss ths kys, nothing happns. Now I'm writing with my on-sreen keyboard. I'm clueless when it comes to computer stuff. How do I fix this? Is this a software problem, or a hardware problem?Help is much appreciated!

Answer:Kyboard deos not respond to the keys: "e", "d", "c" and "3"

My keyboard hath the thame problem with the thupid eth key. The blathted thing ith driving me nutth.

All theriousneth...er...seriousness aside, usually, that is a hardware problem. Can you find or borrow another keyboard and see if it will work correctly on your machine?

6 more replies
Relevance 104.11%

Hi, my sister dropped off a gateway MT3432 laptop and when i turned it on, nothing works, It starts up but nothing shows on the screen. I hear the system booting up and spinning off the hard drive but cant get to the BIOS screen or nothing. I tried plugging in an external monitor and still nothing. I don't know what the deal is. Plz Help. I replaced the ram and the harddrive and still doing the same thing.

Answer:GATEWAY LAPTOP WONT BOOT """"HELP""""

Did your sister say she had did anything to the machine?  Played with registry? dropped it?

3 more replies
Relevance 103.82%

I downloaded what I thought was a new online chat-based game today, "iP (imaginary palaces) castles of the mind". When I realised it wasnt what I thought I tried to uninstall it. My security told me the program was trying to copy itself numerous times on my system so I looked up ""iP (imaginary palaces) castles of the mind" copied itself.""

I found a report from a Professor about an Internet Worm which I didnt understand much of except that I really need to see if it is still in my system, and if necessary remove it completely. I have contacted the Professor by e-mail, but may not receive any help as he is obviously a very busy man.

So this is a warning to all those who are thinking of downloading iP. If ANYONE can tell me anything about how to resolve this please reply to this.
 

Answer:WARNING - Worm attached to game - "iP (imaginary palaces) castles of the mind"

The program is on "a million" different download sites and on the major reputable ones, so I would tend to believe it is not (normally) infected.

What site did you download it from?

"My security told me "
What security??

Did you uninstall it?
Are you having any issues with the PC?

You can always completely back out of it using System Restore.
 

1 more replies
Relevance 103.53%

First time here..I'm a noob!!!! Any how...wow!!!! what a sight of information..sure glad I found this place.Heres my problem.I am running WinXP SP1..with all the latest updates (fresh udate last night)I have a problem with this "coolwebsearch" crap..it has hijacked my browser.i am running ad-aware..and spysweeper(seperate times of course) both these programs find coolweb search and 9 entries of it...they remove it..but when I reboot.."coolwebsearch" comes back.

I also see a "futuremark measurement client" in my "add/remove" programs list..."IT WON'T UNINSTALL" I hit the remove button..the screen twitches a litlle..but it seems the program remains....these two problems of mine connected??? i have saved my Hijack.log file..how do I post it here???

sorry..noob here on removeing spyware..hope you all can help.

thanks for your time

Brent
 

Answer:Can''t remove "coolwebsearch"..hijacking browser every reboot

15 more replies
Relevance 103.53%

Popup toolbar "Internet Speed Monitor" on the left side of my browser anytime I do a search.
Have run avg virus scanner and webroot spysweeper in safe mode and with system restore off and still can't get rid of it. tia for any help.

XP Pro
Code:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:30:16 PM, on 11/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\P... Read more

Answer:"Internet speed monitor" hijacking my browser

I also have run trend micros online scanner and pandas online scanners, I have the log saved of the pandas active scan.
 

1 more replies
Relevance 103.53%

Boy, I was really hoping to never have to post in this part of the forums, but I've been struck!!

Last night upon performing a scan with AVG it came up with a virus warning: "I-Worm/Opas.K" Originally located in WINDOWS folder (init.bat or something like that?). Upon completion of the scan it said it was cleaned by AVG. HA! Guess again! I restarted and ran another scan to be sure.....then it came up with "I-Worm/Opaserv.K", now located in the file C:\WINDOWS\_RESTORE\TEMP\A0001444.CPY. Upon completion of second scan it said it couldn't be cleaned and AVG recommended moving to virus vault, but when I clicked on move, it said it couldn't do that either!

So, I thought I'd run another scan at Housecall. It couldn't clean it either, so I followed their instructions, and downloaded the Trend Micro System Cleaner. No joy there either, after running it and running another AVG scan, it's still there!

So, now I'm really stuck! Does anyone know how to get rid of this thing?? This is the first virus I've had, and I've done everything I know to do...

Thanks in advance to anyone that can help! Sorry to be so long winded too, but I figured it would help to know exactly what I have (or have NOT!) done so far!
 

Answer:[Resolved] Worm - "Opas.K" and/or "Opaserv.K" - Won't Go Away!

15 more replies
Relevance 103.53%

My work laptop has picked up this virus/malware. What it does is blocks your desktop and all programs with a white screen, and if you are connected to the internet it brings up a bogus FBI warning that says you have to pay a fine. Task Manager is unavailable. I cannot remove it because I cannot get to the BIOS without an admin password, nor can I boot in safe mode w/o this. I do not want to give it to the I.T. of my work place because they will probably just wipe the drive and re-install the programs of my work place. I hate to have that happen because I have installed on this computer several programs I need for my work, and if the drive gets wiped I'll have to spend hours hunting down these programs again and re-installing them. Is there some way around the "admin rights" stuff so that I can run Kaspersky's WindowsUnlocker and be done with it?

Answer:"White Screen", "FBI Warning" Malware!

Really, you should just take it to your IT department to let them deal with it so you don't make it worse.

I work in a corporate IT environment right now, and much prefer a user come to us before they tried to fix it on their own..

Yes, you'll most likely get the drive wiped, however you can tell them to back up your data for you, and possibly even reinstall those programs that you need; especially if its for work, they should have the licenses and/or installers for the software.

3 more replies
Relevance 103.24%

Laptop ASUS with Windows 7 Ultimate - 32bits.
I manually did a windows update search and found 4 new updates available.
Downloaded and installed the 4 new windows update. After completion, only 3 installed correctly.
Only 1 new update failed to install and I got a message error: "WindowsUpdate_800F020B" "WindowsUpdate_dt000".
Tried searching for it's meaning through Microsoft, Windows Help and other Forums to no avail.
Does anyone know what it's meaning?

Answer:"WindowsUpdate_800F020B" "WindowsUpdate_dt000" - Windows 7 Ultimate 32 bit

Hi,
I would like to confirm which update you are trying to install? To see which device is causing the problem, you can review available updates before trying to install them. The device name or manufacturer will be displayed in the list of available updates.
The error code 800F020B can occur if an update that you're trying to install applies to a device that is not connected to the computer. Make sure that all of your devices are connected and turned on, and then try installing updates again.
Best regards,
Della Li

3 more replies
Relevance 102.95%

Seriously?
Really?
There is only one log on for this comptuer...mine.
Logic would dictate that I am the administrator...

Is there a way to run some sort of script at log on or is there some way to assign a log on so that I AM ALWAYS the administrator?
No one else uses this machine so, having to right click and "Run as administrator" seems just silly.

It's windows 7. The 64 bit instal.

Answer:"run as administrator" "browser not running with Administrative Privileges"

hi grumpops,

goto control panel-user accounts and then change user account control settings, move slider down to disable it.

4 more replies
Relevance 102.95%

Ok...here's an interesting problem:
1) Used to have problems with 680180.net popups; however, surprisingly enough, they just stopped popping up.
2) Every time I tried to enter a website more than about one or two links in, IE would just shut down on me. I suspect that this had something to do with cookies, because it happened whenever i tried to access any webpage that needed a password or username (it even happened when i tried to view any techguy.org discussion). However, this has also suddenly gone away, enabling me to post here.

That was a mini-history of recent problems...but here's the problem at hand:
1) The "Back" and "Forward" buttons are permanently shaded grey, as if the current page was the first page in the history. However, when I put my mouse over the "back" button, the little yellow tag still comes up with information about the last page visited.
2) This might be related or not, but everytime i open IE, i get redirected to a searchpage: http://ssearch.biz/?wmid=3309 This is obviously a browser hijack, but I ran Adaware and Spyboy S&D and niether helped. Also, the browser still returns to the correct homepage when i press the "home" button.

Comp. info: Running windows XP professional version 2002 service pack 1. I dont have HT, but i will get it if you guys think that it would help. Feel free to email, but i would prefer any replies be posted here so that others can benifit. Hope you guys can help.
 

Answer:Browser "back" and "forward" buttons not working

7 more replies
Relevance 102.66%

I am about ready to throw my computer out the window. "Search for..." is making itself my homepage, and taking over my about:blank screen, making me think I have the same problem that stiffy272 had a few posts ago. For this reason, I have downloaded FINDnFIX, run it, and attached the log.

»»»»»»»»»»»»»»»»»»*** freeatlast100.100free.com ***»»»»»»»»»»»»»»»»

Microsoft Windows XP [Version 5.1.2600]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q818529-Q330994-Q828750-Q824145-Q832894-Q837009-Q831167
The type of the file system is NTFS.
C: is not dirty.

Mon 07/05/2004
2:42am up 1 day, 8:38

»»»»»»»»»»»»»»»»»»***LOG!***»»»»»»»»»»»»»»»»

Scanning for file(s)...
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»» (*1*) »»»»» .........
»»Locked or 'Suspect' file(s) found...

C:\WINDOWS\System32\EVENTLOG.DLL +++ File read error
\\?\C:\WINDOWS\System32\EVENTLOG.DLL +++ File read error

»»»»» (*2*) »»»»»........
**File C:\FINDnFIX\LIST.TXT
EVENTLOG.DLL Can't Open!
LOG.DLL Can't Open!
MSDTCLOG.DLL Can't Open!
TXFLOG.DLL Can't Open!
WMDMLOG.DLL Can't Open!

»»»»» (*3*) »»»»»........

C:\WINDOWS\SYSTEM32\
log.dll Sun Jun 27 2004 1:14:10a A...R 57,344 56.00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57,344 bytes 56.00 K

unknown/hidden files...

C:\WINDOWS\SYSTEM32\
ncmyb.dll Mon May 17 2004 6... Read more

Answer:[solved]"Search for..." is hijacking my web browser

16 more replies
Relevance 102.08%

PROBLEM:
I am having several issues? It started by giving me a Generic Host Process error that reads, ?Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry for the inconvenience.? This is followed by the ?NT Shutdown error? which reads:

?System Shutdown This system is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY\SYSTEM?

This also displays a 60 second countdown before it shuts down. I was able to stop the shutdown by entering the command prompt and typing ?shutdown ?a? but that is only a temporary solution. The virus has now turned my desktop background black with a grey box in the center with flashing ?Warning? text and a message that reads:

?Warning Dangerous Spyware Many viruses were found on your computer such as : Trojan horse, PassCapture, etc. Your personal information can fall into in the ?third hands?. Please check up the computer with a special software. Thank? (It wouldn?t let me change my desktop background in the Display Properties)

This is partnered with a pop-up balloon stemming from a red circle with an X in the center; the balloon reads: ?Warning! Security report Your computer is infected! It is recommended to start Spyware cleaner tool.? After which it tries to connect to the Internet to download more spyware.

Also, when I try to run SpyBot or any other Spyware removal programs I get an error message that... Read more

Answer:Win32 Shutdown Virus; Black background, flashing "Warning"

Hello and welcome to TSF.

We want all our members to perform the steps outlined in the link given below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

1 more replies
Relevance 101.79%

Ok, so basically, whenever I turn the computer on, 3 error messages appear:

- A virtual driver failed to inicialize DLL. Chose close to end the program. H:/Windows/system32/code/pRee.exe

- A virtual driver failed to inicialize DLL. Chose close to end the program. H:/Windows/system32/code/pRee1.exe

- Error loading H:/Archiv~/GBPLUG~/gbiehcef.dll. Couldn't find specific module.

(sorry if some terms are incorrect, my computer is in Spanish, to I tried to translate as best as possible)

Please help me solve this terrible problem, it is really getting me on my nerves! (oh, and if this helps, I've recently donwloaded this so called "Limewire acceleration", and whenever I ran the setup, it didn't work. I don't really remember the name of the website I downloaded it from, sorry...)

Answer:Can't Open "My Documents", "Trash" or other files in "My Computer"!?

Hi and Welcome to the forum

I am almost certain that you have malware problems. Most like caused by you doing file sharing/ P2P - Limewire.

Suggest that you go here and follow the directions:

http://www.techsupportforum.com/secu...oval-help.html

Please be advised that the malware people are very busy and it could take a couple days to assist you.

BG

1 more replies
Relevance 101.79%

Guys,

I am a little confused with regard to some of the mail options in Outlook Express. (I have version 6) What is the difference between the "Drafts" and "Outbox" folders?

Further how does the "Send Later" option work from the file menu? I always thought that "Send Later" was the same as using "Drafts" but what happend was that I was doing an e-mail, went to Drafts, or clicked on "Send Later" or Outbox and then after I clicked on "Send" doing a regular send, I checked my Sent folder and about 3 copies of the same message were delivered to the same person! (I only sent one message-not 3!)

What is the deal with the "Outbox" folder? Apparently that is not like the Drafts folder....correct?

What's the difference between doing a Save, Save As, and Send Later with regard to OE functions? If I want to save a message that isn't done yet, which of these 3 options should I use? (I.e, I want the message to go to the Drafts folder for example and stay there until I TELL OE to send it.) I think whatever I did above was that I modified my message and then click on where it just automatically sent next time I opened the message. A review of these features would be helpful!

Just for the record, I also use Yahoo Mail and find that so much easier!

Jack
 

Answer:Please Review OE "Send", "Drafts", and "Outbox" Options

Jack
To save an E-Mail to your Drafts folder for work on later then you use the File\Save option.
If you wish to save the E-Mail in another format such as .EML or .TXT or .HTM then you use the Save as function. You will also be required to specify a folder to save in or use its "My Documents" default.
Send later function if only one e-mail account exists will place the e-mail in the outbox and send it the next time you click on the send receive button. If you have multiple accounts then you can specify which account to send it from.

Dave
 

2 more replies
Relevance 101.79%

Hi
I have recently updated to the creator version
My files end up in unintended destinations. When I click in the documents tab in the sidebar of the documents screen, it takes me to a ?Documents? folder that appears in ?One Drive? group. Any files that I send from my desktop end up there
Those files are also shown when I open the first ?Documents? folder that appears in the ?Quick Access? group. I have similar problems with ?Pictures? folders
I have attached screen shots that I hope will explain. I want all my files of any description to end up in the ?Documents? folder contained in the ?This PC? group. Can anyone help please?
Incidentally, I don?t understand the purpose of ?One Drive?, and don?t believe that I will have a use for it. Can I remove/disable it?

More replies
Relevance 101.79%

I thought I was computer savvy until this problem came up. When I double click my computer, recycle bin, control panel, etc, the hourglass comes up for a few seconds, goes off, and nothing else. No error messages or anything, just nothing. I have viewed a few of the threads covering this and a common link was the hijack this result. I have posted that here, and really hope that someone can help me with this. I have run SpyBotSD and adaware, I have run mutiple virus scans, I did an SFC, and the final thing was to repair windows using the original disk, none of which has help. I am running Window XP w/SP2. Any other suggestions would be certainly appreciated. Hope to here from someone soon. MTCS, out.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TDSTEL~1\ENTERN~1\app\pppoeservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusCl... Read more

Answer:I cannot open "my computer" "control panel" "recycle bin", etc...

You may want to reinstall the operating system.

Backupthe files that are importantto you before you reinstall.

The "New" installation will overwrite the current one

If you do not format your hard drive before the reinstall the installation should not harm your files (That's why I suggest backingup your files) and will speed up the installation process.
 

1 more replies
Relevance 101.79%

Hi:

Looking for insight/advice re: KB3054476.

According to Infoworld, it was "Optional" in May, but I was not offered it then.
This week, it was offered as "Important" and "Recommended" (!), but only for one of my 2 Win7/64 boxes.

I have read the MS KB article, as well as THIS FORUM THREAD, the latter of which includes a report of a BSOD due to this particular update.

However, there isn't much out on the web about it.
And most of the discussion about it is overly technical for me.
And I am confused as to why it was previously offered as "Optional", but now is "Important" or "Recommended".

I don't *think* I "need" it (as I have no webcam on this box). And I don't like to tempt fate by fixing things that are not broken.

So, 3 questions:
Is it safe to install?
Is it really necessary/important?
Or would I be OK to hide it?
Thanks very much in advance!

Answer:KB3054476 offered as "Important"/"Recommended"/"Optional"

The status of updates changes with circumstances.
If an update isn't relevant, it won't be offered at all.
If however it's relevant but the related software is not apparently in use, it may be 'optional' - and gravitate to 'Recommended' or 'Important' if the related software is in use.
It can also be promoted through the hierarchy by MS depending on feedback through WU and error-trapped feedback.


If you have (and use) a webcam, then it's probably best to install the update.

4 more replies
Relevance 101.79%

hi,

OK, this is a weird one.

I wanted to move the "My Music", "My Pictures", "My Videos" folders to another HDD. I moved the "My Documents" Folder to this HDD without a problem but the others I accidentally set the whole HDD as the folder (if that makes sense). So now the music, videos and pictures folders are set to this HDD and dont have an actual folder to change the properties of. Therein lies my dilema.

If anyone can offer any advice on this curly issue it would be greatly appreciated.

Shane

Answer:Remaking "My Music", "My Pictures", "My Videos" folders

  
Quote: Originally Posted by Legume


hi,

OK, this is a weird one.

I wanted to move the "My Music", "My Pictures", "My Videos" folders to another HDD. I moved the "My Documents" Folder to this HDD without a problem but the others I accidentally set the whole HDD as the folder (if that makes sense). So now the music, videos and pictures folders are set to this HDD and dont have an actual folder to change the properties of. Therein lies my dilema.

If anyone can offer any advice on this curly issue it would be greatly appreciated.

Shane


You have a backup from before the problem started? a win 7 dvd to do a repair install?
ken

4 more replies
Relevance 101.79%

I tried to associate the file extension .txt to a new editor program
with the well known cmdline programs ASSOC and FTYPE.

No, assigning them through WinExplorer menu does not work.
But this is another problem which should not discussed here.

When I type now one of the following alternative commands at the CommandPrompt then Win7 returns me something like:

assoc .txt=txtfile

"Access denied"
The following error occurs: .txt"

or

ftype txtfile=D:\notepad++\notepad++.exe "%%1"

"Access denied"
The following error occurs: txtfile"

Why?

The command above work fine under WinXP

Peter

Answer:"access denied" when using "assoc" and "ftype" from cmdline?

Question:

Did you run cmd.exe with administrative previlliges?
Elevated Command Prompt

3 more replies
Relevance 101.79%

OK.....
As I said I am new.....
Hope this info is the way you need it.
MANY MANY THANKS IN ADVANCE FOR THE TIME & HELP !!!
Check out the following .....HHEELLLPPP


Logfile of HijackThis v1.98.2
Scan saved at 12:38:36 PM, on 11/12/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\System32\Promon.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\interMute\AdSubtract\AdSub.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\McAfee.com\VSO\mcshield.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Frank M. Gazzo\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Micro... Read more

Answer:NEW THREAD / "xads", "xlime", "Context3.kanoodle"

hi

how to create a folder ?

right click anywhere in your desktop
click new,a tab opens ,click folder ,name it hjtantivirus .

download again hijackthis and install it in the new created folder .

your hjt is here now
C:\Documents and Settings\Frank M. Gazzo\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

it will not work properly if it stays there .

and don t create a new thread ,keep only one thread .this one ,now .

1 more replies
Relevance 101.79%

Hello, It is my first time posting but long time reader.
This is my wife's computer so I am not sure when all the problems got started I first noticed a problem with Internet Explorer when links would not work. I then got a message W32/Gaobot.worm.gen.u Win32/RBot.3eu!Worm detected just before the PC shut down. I re-booted and attempted to remove and reinstall IE. I ran Trend house call and McAfee prior. I can not install any version of IE or turn on McAfee I get permission errors such as " Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item." It happens with other files and apps as well. I am able to use Mozilla and I was able to update it making it possible to make this post. It took all of the tricks listed to get the 4 log files but I got em!
 

Answer:Please help "Win32/RBot.3eu!Worm" Got my attention I think its worse

Combofix log

Thanks in advance!
 

5 more replies
Relevance 101.5%

Hi

Is it possible to start the app without "Security Worning" window ("Cancel. Open, More Info" buttons)? If yes, how you can make changes then?

Is it possible to start the app without "Microsoft Access" window on the background?

Thanks,
Barbos
 

Answer:Solved: Access 2003 - To start the app w/o "Security Warning" and "Microsoft Access"

6 more replies
Relevance 101.5%

"";"C:\Windows\System32\services.exe";"Trojan horse Dropper.Generic_c.MMI";"Object is white-listed (critical/system file that should not be removed)"

There are a lot of other trojan horse walkthroughs, if someone can point in the right direction more specific to my horse droppings... :cry

Brand new computer... and AV wasnt the first thing to get downloaded... doh!
 

Answer:C:\Windows\System32\services.exe";"Trojan horse Dropper.Generic_c.MMI"";"Object is

Re: C:\Windows\System32\services.exe";"Trojan horse Dropper.Generic_c.MMI"";"Object i

Welcome to MajorGeeks, thernbear

Delete items using RogueKiller.

Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
When it opens, press the Scan button
Now press the Delete button.
When it is finished, there will be a log on your desktop called: RKreport[3].txt
Attach RKreport[3].txt to your next message. (How to attach)

__

- Rescan with HitmanPro, when it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
If Desktop.ini - Trojan if detected again, you can allow HitmanPro to Delete this but Ignore any other detections from the time being.
Afterwards, click the Next button.
HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

__

Once you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log. (How to attach)

__

Completely delete these two folders manually using Windows Explorer:
c:\windows\installer\{0f7e99ff-f00f-32b4-d531-ecd74ed08177}
c:\users\#2\appdata\local\{0f7e99ff-f00f-32b4-d531-ecd74ed08177}

Let me know if you were successful or not.
 

3 more replies
Relevance 101.5%

First things first, thanks to all who can help.....





I need to programmatically make some adjustments to the Internet Explorer security settings. Most of these settings I have found but there are a few I have not been able to get a clear exact location for in the registry. I will be using a .BAT file to make
the adjustments on 100+ PCs.





Here is what I am looking for.....





Under the "Internet  Properties" found in control panel, under the "Privacy" tab there is an "Advanced" option button. When I click on it I get an "Advance Privacy Settings" options box. On it are several settings.
The first setting, "Override automatic cookie handling" needs to be checked in order to access the other options. I can do that by adjusting the DWord value of "PrivacyAdvanced" under the "Internet Settings" key in the registry,
"HKCU\Software\Microsoft\Windows\CurrentVersion\Internet settings", to be specific.





What I have not been able to find are the registry entries for the "First-party Cookies" "Accept, Block, or Prompt" options, the "Third-party Cookies" "Accept, Block, or Prompt" options, and the "Always allow
session cookies" check box. Please see picture below....















I have seen references to the following settings as being where those options exist, but nothing that explains ... Read more

More replies
Relevance 101.21%

Hi,

I have at least three things going on on my computer, "!protect your browser" has taken over my desktop. and this pop up "please select your country" keeps coming up and my home page keeps going to "about: blank". I followed your instructions for posting and have run adaware and spybot and I have run the Hijack this and made a log. Can you assist me? Thanks.

kim

Answer:hijacked browser: "!protect your browser" & "please select a country"

Welcome to TSF.

Please post the HijackThis log here.

14 more replies
Relevance 100.63%

My browser has been hijacked on my computer. When I click on Google Chrome or Firefox, I am taken to this page: http://start.sweetpacks.com/?barid={20CE9071-E45F-11E2-B64A-001DBAEDB043}&src=10&crg=3.5000006.10045&st=23 Going into my programs and deleting Sweetpacks makes no difference. It keeps coming back.

I'm attaching the logs that I received from following the steps in the Malware Removal Guide. How do I get rid of this nasty bug?
 

Answer:"Sweetpacks" hijacking browser

Rescan with Hitman and have it delete Potential Unwanted Programs.

Now rescan again and attach fresh log from doing so.

Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
 

14 more replies
Relevance 100.63%

my pc get tis virus "Worm.Win32.AutoIt.c"...pls help me to remove it

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:43:15 PM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Documents and Settings\User\Desktop\Internet Download Manager\IDMan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PPStream\ppsap.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\PPStream\PPStream.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\StormII\stormliv.exe
C:\P... Read more

More replies
Relevance 100.63%

Dear Community,

first i have to say, that the PC I'm talking about is not my own one. So i lack some information you might want to have.

What I know:

Few days ago, Windows brought up a warning (propably from Windows-Defender) about an infection with "PWS:Win32/Daurso.A". (I do not know the users reaction. She "clicked OK" ...) There had been a warning of the installed AV (Sophos Anti Virus) some days before, but that warning had been ignored. I do not know what kind of warning it has been, but the user thinks that there was no similarity to the one of Windows Defender.

Since that warning of Windows Defender we experience from time to time a cpu running for minutes on 100%. There has been no further warning.

System is Win XP Pro 32 Bit SP 3. It contains standard office software. all sowftware is licensed and the user does not use illegal software or visit suspicious websites. Since the PC is used for massive Email correspondence, the virus - if there is one - might have come by mail.

We do have acces to a windows install disc.

Here is the DDS-Log:
--------------------------------

DDS (Ver_09-12-01.01) - NTFSx86
Run by Schlatter at 16:31:22,82 on 17.03.2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.478.102 [GMT 1:00]

AV: Sophos Anti-Virus *On-access scanning enabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}

============== Running P... Read more

Answer:"PWS:Win32/Daurso.A" Windows-Warning and 100% CPU

Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

---------------------------------------------------------------------------------------------

PWS:Win32/Daurso.A is not what I see in the logs, but here's some information about it.

https://www.microsoft.com/security/p...n32%2fDaurso.A


Quote:




PWS:Win32/Daurso.A is a detection for a trojan that steals FTP credentials, which it then sends to a remote server. When run, PWS:Win32/Daurso.A queries the registry and traverses folders and files found in the system to look for FTP-related information such as user names, passwords, host names, and ports that it later sends to a remote server




What I do see is trojan Bredolab, which is a trojan downloader.



Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Stay with me until given the 'all clear' ev... Read more

12 more replies
Relevance 100.34%

Hey all,

I have some malware infecting my system that is doing the following:

- at random times (as I attempt to move on to a different webpage from the one I am currently viewing) my browser will move either to "fubar.com" or "fling.com". Online dating type of websites
- My screen saver has been hijacked by something that shows bugs (supposedly a "virus" that slowly eats the screensaver wallpaper into a blue background).
- I had been getting pop up windows trying to sell me some type of spyware removers which I assumed was related to the "virus" eating my wallpaper but adaware seems to have elminated those pop ups.

That is about all that is happening. Seems the long I surf the web the more often these things re-direct my browser and it begins to slow up as well.

I am running windows XP home (Version 2002). Service pack 2

I have updated and run ad-aware and spy-bot and removed everything it has shown.

I then did the hijackthis deal and have the following log. Not sure what do to from here.

I am using firefox browser. Not sure if that is critical or not:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:18:55 PM, on 5/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\syst... Read more

More replies
Relevance 100.34%

Hi There!               My browser which is "IE" sometimes stops working,and says "Not Responding" Whats wrong and what do I do?

Answer: Browser which is "IE" stops working and says "Not Responding"

    You could try different browser (for example, Mozilla Firefox: http://www.mozilla.com/en-US/)

6 more replies
Relevance 100.05%

HI there,
please help restore browsing ability. I'm not tech-literate but I'll adapt. Something called ChangeIcon seems unremovable. But I'm sure that's the least of my pc's problems. Essentially, I can't browse without being hijacked by pop-up ads rendering the search engine immobile. Thanks in advance.
 

Answer:Browser Hijacked by "Infected Computer Warning" Pop-up Ads

Hello,

They call me TwinHeadedEagle around here, and I'll be working with you.

Before we start please read and note the following:

At the top of your post, please click on the "Watch thread" button and make sure to check Watch this thread...and receive email notifications. This will send an email to you as soon as I reply to your topic, allowing me to solve your problem faster.
Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process. Please do not perform System Restore or any other restore.
Instructions I give to you are very simple and made for complete beginner to follow. That's why you need to read through my instructions carefully and completely before executing them.
Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.

All tools we use here are completely clean and do not contain any malware. If your antivirus detects them as malicious, please disable your antivirus and then continue.
If during the process you run across anything that is not in my instructions, please stop and ask. If any tool is running too much time (few hours), please stop and inform me.
I visit forum several times at day, making sure to respond to everyon... Read more

7 more replies
Relevance 99.47%

Hello everyone
I have this problem for more than 3 months for now...

The INSTRUCTION AT "0x00a96ce0"referenced memory at "000000000" couldn't be written".

That's always what i get when i restart my computer,just before screen goes dark.
I believe that it has to do something with Microsoft updates.The reason i believe this, is that i once reinstalled my PC and didn't have any problem until i didn't update my PC.
And i posted here that thinking my problem was solved but unfortunately i was wrong.

Please if you have any tips on this one let me know it would be greatly appreciated.

Thank you!
 

More replies
Relevance 99.47%

Hi Guys, any ideas how to access my external hard drive [TOSHIBA MK3029GACE] device manager can see it but it does not appear in disc management.

I use this HDD perfectly in my car HDD player. But when I try to connect it to my Laptop, it does not show up in disk management.

Please check the attached screen shot..

Thanks for the help....

Answer:HDD shows in "Device Manager" but not in "DiskPart"or" Disk Management

Specs show that drive has a ATA-6 interface (P-ATA, or IDE). How are you connecting this drive to your laptop? Does the laptop have a PATA or SATA connection? Does it use an adapter?

1 more replies
Relevance 98.89%

helof friends,

i have couple of viruses in my laptop which disturb me badly, I really appreiciate if anyone can help me in this,when i connect my phone to my laptop ,a message appear from AVG saying ''threat /virus/Worm/VB.6.BA'' after that i could not open my phone folder drive 'E' ,,,i have copy & past the full detail from virus vault,

1= "Infection";"Virus identified Worm/VB.6.BA";"E:\EXPLORER.EXE";"";"10/05/2009, 23:53:07"

2= "Infection";"Trojan horse Generic13.ACMS";"C:\Program Files\NokiaFREE Unlock Codes Calculator\dctx.dll";"";"09/05/2009, 10:33:59"

these are the two virus in my computer which really disturb me,

any hell will highly appriciated

thanks

azhar
 

More replies
Relevance 98.89%

I've done everything I was supposed to do except I can't make hijack this it's own folder in C :P I don't know why. Anyway, here is my log. I appreciate your time and look forward to your advice!
Thanks in advance!

Logfile of HijackThis v1.97.7
Scan saved at 9:46:45 PM, on 9/8/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Roxio\GoBack\GBPoll.exe
C:\PROGRA~1\NORTON~2\NORTON~2\GHOSTS~2.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Motherboard Monitor 5\MBM5.EXE
C:\Program ... Read more

Answer:Multiple pop-ups and virus eTriust calls "!update.exe" or win32/clspring.FH"

You are using an outdated version of HiJackThis. Please click on the link below to download the latest version:
http://www.bleepingcomputer.com/file...ckthis_sfx.exe

1. Delete your current HiJackThis.exe file
2. Double-click on the file you just downloaded.
3. Click on the "Unzip" button to install the newer version.
4. It will by default install to the directory - C:\PROGRAM FILES\HIJACKTHIS\

I require your next HJT log to be from this newer version

10 more replies
Relevance 98.89%

I keep getting "Ultimate Cleaner" and "Ultimate Defender" pop ups. I ran Adaware, Spybot Search n Destroy, and Norton Antivirus and still can't get rid of them. Spybot keeps finding "DoubleClick.com" and "Advertising.com" cookies, I eliminate them but they keep coming back. I have a feeling that I am getting these pop ups because of these cookies.
Any help to get rid of these pests is greatly appreciated.
 

Answer:"Ultimate Cleaner" pop up

13 more replies
Relevance 98.6%

I have been playing the game for a few weeks now in my spare time on my Windows 10 desktop and have acquired some bonus packs, a dozen vehicles, upgrades, unlocked 5 seasons, and moved my user rank up to 4824 in the multiplayer ranks amongst various other things. I do not want to lose my progress but for the first time i wanted to upload a ghost the other day and seen that (it seems) I will lose all progress if I log into Facebook now. Also, I noticed that my "local account" doesn't transfer my save data when I log into the game on my Windows 10 laptop (which is super inconvenient because I am rarely home). I seen topics posted that a Facebook sync fixes this but I am afraid I will lose all my progress.
Anyone have any experience with this?

Answer:On Windows 10: "Asphalt 8 Airborne" can I sync my "local account" with my "Facebook Account?"

I am with you on this. I'm having the same problem, and the Customer Care form at Gameloft is not set-up yet for inquiries on desktop platforms. Also, search engines are hard to trigger relative informaiton on the subject. I have no intention of changing over to my Facebook "version" if the progress isn't going to be transferred.
It's just a new problem brought around to headline the Windows 10 updates. I'm sure there will be a wait time, but there has got to be a flood of new Win10 users that are firing up their CC services for a fix.
If I find out that it fixable, I'll get back to this thread.
Jerry

2 more replies
Relevance 98.6%

Hi all
Previously the  "Save Picture"  box would put a web generated title in the box and automatically selected JPEG.  Now the title box reads "untitled" and the only file options offered are "png" & "bmp" 

Please note that a similar post has appeared, but the solution did not match the fault.  I'm seeking to restore the automatic response to save picture, that might have been upset by antivirus clean-up programme.

Thank youin advance for considering my problem

More replies
Relevance 98.6%

I often receive emails from my Pet Lover community that have images embedded in the body. I have a special email folder on my desktop into which I used to be able to download the pictures by selecting "view in browser" from my Outlook 2007 menu bar. Google Chrome would display all the images and I would download from there.

All of a sudden, when I select that command, all I get is text. It's almost as if I am looking at the source. I've uploaded a .doc file with the screen shot of what I get from that command.

Any help would be greatly appreciated. I know I could copy each and paste into Paint, then crop, save, etc., etc.. I simply don't have the time for all the extra steps.

Thanks.

More replies
Relevance 98.31%

Hardware: Toshiba Satellite P105-S6177 System: Vista Home PremiumMemory: 2GB RAM, 120GB DriveProcessor: Centrino Duo 1.73GHzChip Set: Intel 945GM ExpressFurther Explanation:User Choice:      System ActionShut Down      RebootHibernate         RebootSleep         Sleeps... but won't come out of SleepFurther Explanation and Attempts:Using the Toshiba Power Management feature does change choices of action but the outcome is the same as choices from Vista menu. For instance, if I choose to have the system Hibernate when the lid is closed, the system goes into hibernation momentarily then restarts, or if I press the power button, the system shuts down then immediately restarts.I can use the command line: ?rundll32.exe powrprof.dll,SetSuspendState? and the system will go into hibernation but then immediately restarts.The only way to turn-off this computer is to hold the power button for 5 seconds or more and then when powering-up again, I get the nasty Microsoft warning that the system didn't shut down properly last time and do I want to start in safe mode or normal, etc, etc with all it's slow checks with this type of startup.The Sordid Story:I just purchased this Toshiba Satellite P105-S6177 from RefurbDepot. I know, that's my first problem. Secondly, they did not include a manual or recovery disks. When calling ... Read more

More replies
Relevance 98.31%

Windows XP SP3
WMP 11

When I open a media folder & select Play All on the Explorer left pane I get the "Copy to" selection window and then the "Move to" window. When I cancel these the files load into WMP 11.

Anyway to get rid of the "Copy to" & "Move to" commands, so that it just loads the media files in WMP 11?
 

More replies
Relevance 98.31%

Hi - I have a thinkpad x61t. When it's in the docking station, whenever I press "shift" "alt" or "ctrl" a little pop up window tells me that key is being pressed. The laptop does not do this when it's out of the docking station. I've looked all over the control panel in vista and can't find any setting.

Any ideas how to switch it off? Driving me nuts! Thanks.
 

Answer:"shift", "alt", "ctrl" appear onscreen when pressed (see pic)

You mentioned that you have looked in the Control Panel so this may be something you tried already:

Control Panel - Ease of Access Center - Make the keyboard eaiser use - uncheck 'Turn on sticky keys'.
 

2 more replies
Relevance 98.31%

Hey guys. This morning I got a really strange error code. When I tryed to update Steam on my PC, this error message popped up;

"The instruction at "0x00172058" referenced memory at "0x00d1004". The memory could not be "read".

Click OK to terminate the program.

Lately, I have'nt been able to install WoW either, I install it all the way to 100% and then when I try to launch it, I obviously have to re-download all the patches but it prompts me that I have to install it again, even though it is all there.

Tryed downloading the full game digitally off of wow-europe.com too, I click run to get it started, nothing happens and then this message pops up.

"The instruction at "0x00182058" referenced memory at "0x0f070014". The memory could not be "read".

Click OK to terminate the program.

I don't know what's up with it. My freind told me to run a CHKDSK /R to see if there was anything wrong with my drive and it ran smoothly, although I must say it took about an hour or so.

So, that was complete, tryed to do it again and I still kept getting these error messages. But I saw something on my desktop that wasn't there previously. It is an error log. Here is the error log;
#
# An unexpected error has been detected by Java Runtime Environment:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x6d5ecb6d, pid=1584, tid=1248
#
# Java VM: Java HotSpot(TM) Client VM (11.0-b16 mixed mode, sharing wi... Read more

More replies
Relevance 98.31%

Recently after updating Windows 10 to Fall Creators Update (1709) (I think this started to happen after clicking the "forgot password" button on the sign in screen, just a theory), all messages on the shutdown/boot screen in Windows (for example "Shutting down", "Restarting", "Welcome", ...) became replaced with "Just a moment". It isn't a huge inconvenience, but "Working with updates" also got replaced by it, so I don't know if the computer is installing updates or is stuck at shutting down for example if it takes a long time.
I don't expect anyone to have a solution, I'm just wondering if someone else has this problem. SFC and DISM didn't help me, changing the system language did not help.
 

More replies
Relevance 98.31%

How do I change the font of "Welcome", "Logging Off" and "Shutting down"? Is it hard coded in a uifile? Which file are the words in? Is the file written in XML?? John

Answer:Change font of "Welcome", "Logging Off" and "Shutting down"?

  
Quote: Originally Posted by RBCC


How do I change the font of "Welcome", "Logging Off" and "Shutting down"? Is it hard coded in a uifile? Which file are the words in? Is the file written in XML?? John


I am not sure you can change the fonts though if you wish you can change the text from "Shutting Down" to "Bye Bye" or so, by editing, winlogon.exe.mui.

3 more replies
Relevance 98.31%

One feature I really liked in XP was the ability to look in a folder through My Computer and sort the files by extension. For example if I wanted to get all .jpg files to one side of the folder as I looked for a file, I could click View, Arrange Icons By, Type and make that happen. I don't see that feature in Windows 7. I'm using W7Pro and can't find that or a similar feature anywhere. Is it here and I just haven't found it? TIA

Answer:Where is "VIEW", "ARRANGE ICONS BY", "TYPE"

open a window ,click organise/layout /menubar.
then when you click view in the menu bar group by is in the list

3 more replies
Relevance 98.31%

Hey everyone,

Unfortunately, my computer has been infected with a particularly virulent, or relatively new, virus (for which I am currently awaiting help on the Malware removal sub-forum). I wanted to ask, though, if anyone else has had to deal with this particular Trojan before because, from what I have been able to find out, it (i.e. Trojan_Win32.Generic, or "TidyNetwork.com") doesn't seem to have a remedy as of yet. I've checked just about every virus database I could and have come up empty handed every time. What's more, I've downloaded and ran half a dozen different top-shelf Anti-virus' scans and removal programs, only to end up disappointed.

Does anyone know what the deal with this thing is?

Best,

John
 

Answer:"Trojan_Win32.Generic" a.k.a. "TidyNetwork.com" & "Strongvault"

Please do not start another thread for the same issue.

I'm sure someone will be along to help you in your other thread soon.

Closing duplicate.
 

1 more replies