Computer Support Forum

*not urgent* can someone check my HJT to make sure everything is in check?

Question: *not urgent* can someone check my HJT to make sure everything is in check?

just wanted to see if anyone noticed anything out of the ordinary.

Logfile of HijackThis v1.99.1
Scan saved at 8:57:04 PM, on 10/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Windows folder: C:\WINDOWS
System folder: C:\WINDOWS\SYSTEM32
Hosts file: C:\WINDOWS\System32\drivers\etc\hosts

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunes.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\AJ\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank" class="invilink">http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20060511/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.42/WinSSWebAgent.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144375235872
O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) - https://oca.microsoft.com/en/secure/ocarpt.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSMPSVC - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe" -n 4 (file missing)

Relevance 100%
Preferred Solution: *not urgent* can someone check my HJT to make sure everything is in check?

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

Answer: *not urgent* can someone check my HJT to make sure everything is in check?

Looks fine

1 more replies
Relevance 72.16%

hello,

I had installed some program few days ago from the net. I noticed that the tool was safe to be installed but then later the software acted strange and suddenly strange things like closing of internet explorers for no reason and sometimes firefox also closes.

thanks


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:39:09 PM, on 1/3/2014
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre7\bin\jqs... Read more

Answer:urgent:please check

16 more replies
Relevance 72.16%

Hi can someone check this log please?
Logfile of HijackThis v1.99.1
Scan saved at 14:17:23, on 29/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Windows Defender\MsMpEng.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Ahead\InCD\InCDsrv.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\WINDOWS\system32\mgabg.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Canon\Memory Card Utility\iP6220D\PDUiP6220DMon.exe
F:\Program Files\BroadJump\Client Foundation\CFD.exe
F:\WINDOWS\system32\ctfmon.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Documents and Settings\Moozer\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - F:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avg... Read more

Answer:Urgent help pls! HJT log check

Are you experiencing problems
 

1 more replies
Relevance 72.16%

Computer is slow as hell and sometimes wont connect anymore and it has nothing to do with my connection!
Save me now before I lose everything!

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:13:59, on 2007-05-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program ... Read more

Answer:Someone please check my HJT Log! URGENT!

11 more replies
Relevance 71.34%

Hey, Just like to say hi first.

I've had a few nasties on my PC and I think I've cleared most everything up now. I just wanted to get some people a little more techy than me to check things up, because it's been such a long time since I've had a HJT log checked that things must be out of shape by now.

It seems awful long, but then there's an awful lot of junk on my PC. I've run pretty much every spyware, adware and virus remover (apart from ones I've never heard of) so I guess it comes down to this. No rush to reply, as everything is fairly alright (Except for ZoneAlarm causing PC hangs, which a reinstall seems to have pretty much sorted).

Cheers!

Edit by bjgarrick: Inline HJT log removed. READ & RUN ME sticky not followed.
Thanks again!
 

Answer:Non Urgent HiJack this log check please?

Welcome to MajorGeeks.com, please follow our standard cleaning procedures:

Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support


Make sure you check version numbers and get all updates.
Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

After doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

Downloading, Installing, and Running HijackThis

Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around..
When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
CounterSpy Log - only for Windows XP, 2K, & NT users
AVG Antispyware Log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
Bitdefender Log - from step 6
Panda Scan Log - from step 6
runkeys.txt - the log from GetRunKey.bat
newfiles.txt - the log from ShowNew.bat
HijackThis Log
NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
 

11 more replies
Relevance 71.34%

Dear guys as per ur solution regarding my computers slow perfomance and constant hangups.And applications not opening.
I did a check using, SPYBOT then with hijack list. But still there was not much difference i .still cant connect to net

I ran CWShredder fixed it, Did LSPFIX and then finally got removed YAHA worm using Symantec removal tool. Then i ran spybot again it said no threats found.Now am sending my new HJT list pls check and advise accordingly. Coz still am unable to connect to the net. thanks for replying!!

Logfile of HijackThis v1.97.7
Scan saved at 22:06:02, on 23/02/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\P331ZI98.EXE
C:\ARCHIVOS DE PROGRAMA\CREATIVE\SHAREDLL\CTNOTIFY.EXE
C:\ARCHIVOS DE PROGRAMA\USB FLASHDISK\UFD UTILITY 2003\UFDTOOL.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\STARTER.EXE
C:\ARCHIVOS DE PROGRAMA\USB FLASHDISK\UFD UTILITY 2003\UFDLMON.EXE
C:\ARCHIVOS DE PROGRAMA\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\ARCHIVOS DE PROGRAMA\CREATIVE\SHAREDLL\MEDIADET.EXE
C:\ARCHIVOS DE PROGRAMA\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\ARCHIVOS DE PROGRAMA\ESCRITORIO INALáMBRICO LABTEC\MULMOUSE.EXE
C:\WIND... Read more

Answer:Hjt List Check(urgent)

Duplicate post, see here:

http://forums.techguy.org/t206087/s1e9fd2eba6477ada667d488eca8058d9.html
 

1 more replies
Relevance 71.34%

Logfile of HijackThis v1.99.1
Scan saved at 12:14:02 AM, on 6/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\HEDY\KBS01\hotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.e... Read more

Answer:HiJackThis Log...Please Check...URGENT!!!!

Please do not start a new thread for the same problem.

You are being helped here:

http://forums.techguy.org/security/475638-hijackthis-log-please-check-urgent.html
Closing duplicate.
 

1 more replies
Relevance 71.34%

Hi all guys,

Maybe I got problem with my computer. Pls help me to repair my computer from any threat, thanks. Here is my hijack this:
Logfile of HijackThis v1.99.1
Scan saved at 10:15:08 AM, on 4/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
C:\WINDOWS\system32\LckFldService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\urtclsvc.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\ISS... Read more

Answer:Pls help me to check my computer - urgent pls

What problems do you have
 

1 more replies
Relevance 70.52%

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:22:51, on 27/07/2008Platform: Windows Vista (WinNT 6.00.1904)MSIE: Internet Explorer v7.00 (7.00.6000.16681)Boot mode: NormalRunning processes:C:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\System32\rundll32.exeC:\Program Files\Synaptics\SynTP\SynTPStart.exeC:\Windows\System32\rundll32.exeC:\Program Files\Hp\QuickPlay\QPService.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exeC:\Program Files\Windows Defender\MSASCui.exeC:\Program Files\Hp\HP Software Update\hpwuSchd2.exeC:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exeC:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exeC:\Program Files\Java\jre1.6.0_07\bin\jusched.exeC:\Program Files\Windows Live\Family Safety\fssui.exeC:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exeC:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exeC:\Program Files\Alwil Software\Avast4\ashDisp.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\... Read more

Answer:Hijackthis Log Urgent Please Check Asap Thanks -pf

Welcome to the BleepingComputer Forums. Since it has been a few days, please post a new Deckard's System Scanner which includes the HijackThis log. Please see Preparation Guide for use before posting about your potential Malware problem. Thank you for your patience.If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped. Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I don't think that you are attaching anything scary but others may do so. Thanks.

2 more replies
Relevance 69.7%

Hello guys i need help regarding this error i just ordered my laptop and turned it on it say PXE-E61 Media test failure check cable i dont understand what is wrong with the system as its new i haven't turned it on yet it says this what should i do?should i send it back to lenovo?

More replies
Relevance 69.7%

#include<conio.h>
#include<stdio.h>
void main(void)
{
clrscr();
int arr[50],j,hold,len;
printf("enter length:");
scanf("%d",&len);
printf("\nenter array:\n");
for(int i=0;i<len;i++)
{
scanf("%d",&arr[i]);
}
for(i=1;i<len;i++);
{
hold=arr[i];
while((j-1>=0)&&hold<arr[j-1])
{
arr[j]=arr[j-1];
j--;
}
arr[j]=hold;
}
printf("\nsorted array is:\n");
for(i=0;i<len;i++)
{
printf("\t%d",arr[i]);
}
getch();
}

Answer:Please Check My Prcogram Urgent,i m having logical error

Moving to the Programing Forum for better results.

2 more replies
Relevance 69.29%

Logfile of HijackThis v1.99.1Scan saved at 17:16:35, on 20/04/2007Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\CTHELPER.EXEC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exeC:\WINDOWS\System32\LVCOMSX.EXEC:\Program Files\Logitech\Video\LogiTray.exeC:\Program Files\Java\jre1.5.0_09\bin\jusched.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\Program Files\iTunes\iTunesHelper.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\MSN Messenger\MsnMsgr.ExeC:\Program Files\PeerGuardian2\pg2.exeC:\Program Files\Microsoft ActiveSync\wcescomm.exeC:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exeC:\PROGRA~1\MICROS~3\rapimgr.exeC:\Program Files\Logitech\Video\FxSvr2.exeC:\PROGRA~1\Grisoft ... Read more

Answer:Could Somebody Just Check To Make Sure This Is Ok.

Hello there and welcome to BleepingComputer. My name is Charles and I will be dealing with your log today. Please print off a copy of these instructions, and also save them to a Notepad file on your desktop, so they are easily accessible. We are going to boot into Safe Mode later in the fix, and there is no internet access. You're using an outdated version of Java (latest one is Java Runtime Environment (JRE) 6). Please update and remove the older versions. Do the following:Go to Start | Control Panel | Add/Remove ProgramsSearch in the list for all previous installed versions of Java. (J2SE Runtime Environment.... )Select it and click Remove.Then download and install the newest version from here:Java Runtime Environment (JRE) 6Scan again with HijackThis and put a checkmark next to each of the following entries (if present): O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\System32\regscan.exeThen close all other windows--you should only see HijackThis on your Desktop--and click the Fix checked button.Please reboot your computer into Safe Mode. This is done by rebooting Windows and pressing F8 at boot/Windows startup, usually right after the beep. Then select Safe Mode from the list. Make sure you choose the option without Networking Support.Set your system to show all files. Navigate to Start | My Computer | Tools | Folder Options.Select the View tab. Under the "Hidden Files and... Read more

6 more replies
Relevance 68.47%

i ran a scan with farbar before right after fresh install now that my system has had time to run for a bit i wanted to do another one to make sure im not infected im still getting used to windows 10 and not familiar with certain services and processes  

More replies
Relevance 68.47%

I want to check my network for spyware and chat programs. Please help me add to this list. Basically I'm going to search my network periodically for any of these. If they come up positive then i'll go to that machine and investigate further. I realize that just having one of these exe's is not full proof, but it is a good indication.

Thanks.

Chat:
C:\Program Files\AIM6\aim6.exe

Spyware:
C:\Program Files\MyWebSearch\bar\1.bin\mwsoemon.exe
 

Answer:Help me make a list of exe's to check

You're looking at this kind of backwards. Why not perform a full audit of the machine and put in place proper protections to keep them from getting any malicious? First off, don't let your users run as administrators. Second, get a good corporate anti virus. That right there will drastically cut the number of malware infections you receive.
 

16 more replies
Relevance 68.47%

I was having a minor issue with some malware (things like unable to download, unable to start .exe files, unable to open documents in Word, and the Internet Explorer icon in the start menu didn't work), but after running everything in the READ ME FIRST thread, things seem to be running smoothly.

The only issue I had was with RootRepeal. It crashed twice in one run.

Here are the good logs:
 

Answer:Please check logs to make sure all is well

And here is one of the logs from the RootRepeal crash. Apparently it wont let me upload the other because it says I already did in a previous thread:
 

2 more replies
Relevance 68.47%

Hi all.I am currently working on a document (Word, in Office XP)and I am wanting to include some check boxes. I have created the form and added the said insertions but I am wanting to make them bigger. Is this possible? I have used the 'control' options but all this does is increase the size of the 'frame' not the actual box.Any ideas?Thanks in anticipation.Mike

Answer:How do I make a 'check box' bigger??!

If I am not mistaken, the 'check box' is a VBScript component, in which case would have to be altered within VisualBasic??

5 more replies
Relevance 67.65%

hey guys me again

I discovered after i had that virus a lot of my system registry stuff was missing and i could not use windows firewall, nor could i use windows updates, after a bit of messing about i managed to re-install both to the registry.

I would now just like to double check with someone to make sure all parts of the virus have been removed, and not come back somehow.

could someone please help me double check to make sure im not still infected?

you can view the problem i had with the virus in this post

http://forums.majorgeeks.com/showthread.php?t=267647

thanks
 

Answer:would like to double check to make sure im not still infected

TimW gave you final steps, no? If you suspect you are infected again, then you need to run the READ & RUN ME FIRST. Malware Removal Guide again and attach requested logs. Thanks.
 

12 more replies
Relevance 67.65%

I need to make a list of stuff and next to it an empty box. For example, if an item is present, then there should be a box right next to the item so that the person can check it off for inventory purposes. Any idea on how to make those check boxes? Thanks.
 

Answer:How do I make check boxes in MS Word?

Turn on your forms toolbar
 

1 more replies
Relevance 67.65%

I think my system is clean; can someone take a quick look to make sure?
Here is my hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 2:59:36 PM, on 4/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Microsoft Anti... Read more

Answer:Solved: Now have clean PC, Can someone check to make sure?

clean log apart from this minor entry.

have hijack this fix this one.

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/25e863ba9bcc54...ip/RdxIE601.cab

here's some free tools to protect you even moew.

to stop reinfection get these two tools, spywareguard and spywareblaster
from

www.javacoolsoftware.com
get the hosts file from here.

put it into C:\windows\system32\drivers\etc, for xp and w2k or

C:\windows\ for 95,98 and ME

http://www.mvps.org/winhelp2002/hosts.htm
ie-spyad.Puts over 5000 sites in your restricted zone so you'll be protected

when you visit innocent-looking sites that aren't actually innocent at all.

https://netfiles.uiuc.edu/ehowes/www/resource.htm
winpatrol

http://www.winpatrol.com/winpatrol.html
prevX a new tool, looks like a good one

http://www.prevx.com/prevxhome.asp
Use spybot's immunize button and use spywareblaster' enable
protection once you update it. you can put spybot's hosts file into
your own and lock it. Plus you can also turn on spybot's tea timer
for added protection against pests.

I would also suggest switching to Mozilla's firefox browser, it's safer, has a built in pop up blocker, blocks cookies and adds.

http://www.mozilla.org/
 

2 more replies
Relevance 67.65%

A couple of days ago I started having pop ups asking me to install antivirus 2009 (while loading yahoo home page), I didn't install it, but the pop upts kept coming back. I ran my McAfee antivirus scan but nothing was found, then I ran malwarebytes found a bunch of malware, it deleted most of it but couldn't erase some. My computer is working much better now and I haven't had any pop ups for some time, but I would still like to make sure nothing is left in the system. Could you please check my hijackthis log? Thanks you so much!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:59:34 PM, on 1/2/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16762)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\hkcmd.exeC:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\Java\jre1.6.0_05\bin\jusched.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\HP\KBD\KBD.EXEC:\WIN... Read more

Answer:please, check up my log to make sure my system is clean!

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results, click no to the Optional_ScanFollow the ... Read more

3 more replies
Relevance 67.65%

Thanks so much! I have updated and ran both spybot and Ad-aware, [latest versions] prior to posting this log, and eliminated everything that was 'wrong', but I would like some expert in-put on whether everything checks out as 'o.k.' or not. Thanks so much! :)

Logfile of HijackThis v1.98.2
Scan saved at 10:10:47 PM, on 11/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\ctfmon.exe ... Read more

Answer:Can someone please check my HJT logfile? I want to make sure all is clear now...

Hi
Just a bit of a cleanup...
Run hjt and fix these items and then post a fresh log please...

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab

3 more replies
Relevance 67.24%

Hello,

There may be other infections, (virtumonde, or is that part of Vundo??) but Vundo was there when the scans I ran found issues.

Long story short... I messed up and had to re-install XP on my PC.

Up until that point I have not had any problems on this PC with Viruses or Mal ware.

When I re-installed XP the only security software I installed was Avast! anti virus. It was late and I went to bed. Problem being that the PC was then used all day the next day while I was at work by my wife and kids.

They started having problems with pop ups, most of them Mal ware for Anti Virus 2009 "has detected blah blah blah" click here to scan and remove these threats from your computer"

Now I know that clicking on that button is a bad thing but my kids did not...the only alarms they see are from Avast! and they know that if it comes up they are to let it run.

Thats apparently when all hell broke loose...my wife called me at work about Icons for websites appearing randomly on the desktop and IE not working right (some very non family friendly pop ups) so she shut the PC down.

When I got home I re installed and ran the other security software that I normally use and has kept my PC virus / malware free for years.

Zone Alarm
Ad-Aware
Spyware Blaster
SpyBot Search and Destroy
Windows Defender

I did a boot time scan with Avast and it found multiple files infected and removed them.
The same with SpyBot, Spyware Blaster and Ad-Aware. Scanned Found and Removed infected fi... Read more

Answer:Recent Vundo infection - How do I check to make sure its gone

16 more replies
Relevance 67.24%

For my German class I have to write papers etc.

Well I use microsoft but its useless to me since well it doesn't do german grammar. Is there like a way I can make microsoft switch from doing spell check, grammar check from english to german?

Answer:How to make Microsoft spell check in German

Hello Nik

Wie Geht es dir? Is that right, can't remember, my German girlfriend would be very annoyed.

There are several software solutions for typing German on a US, British or other English-language computer. Programs such as SwapKeys? offer one way to switch between English and German on a PC using the Windows OS. (See our software links below.) But Win XP and Mac OS X both allow you to easily change your keyboard setup in the Control Panel or Preferences (see Optimize Your PC for German).

The Windows XP and Mac OS X operating systems are much more multilanguage-friendly than previous versions. The latest English versions of MS Word (both Mac and Windows) now include tools for German-language spell-checking, grammar checking, and a German thesaurus as an option. All you have to do is install it. But there are a few tricks you should know.

Multilingual Support in Windows XP
There are several levels of multilingual support in Windows XP. Some are for the typical user, while others are aimed more at network administrators. You also have a choice of using a localized version (e.g., German in Germany) or an English version with foreign-language options.

To change the default language:
1. Click Start and then Control Panel.
2. Double-click Regional and Language Options.
3. Click the Languages tab.
4. Click Details, then Add.
5. Under Input Language, add the language you want.
6. Under Keyboard Layout/IME, click the keyboard layout you want to use.
7. Click... Read more

5 more replies
Relevance 67.24%

Hello everyone. How can I check to make sure that Adobe Flash Player is up to date on my computer? Here are my system specifications:

Tech Support Guy System Info Utility version 1.0.0.4
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: AMD Athlon(tm) II X2 215 Processor, AMD64 Family 16 Model 6 Stepping 2
Processor Count: 2
RAM: 4863 Mb
Graphics Card: NVIDIA GeForce 9100, 256 Mb
Hard Drives: C: 584 GB (528 GB Free); D: 10 GB (1 GB Free);
Motherboard: PEGATRON CORPORATION, VIOLET6
Antivirus: Malwarebytes, Enabled and Updated
 

Answer:How do I check to make sure Flash Player is up to date?

For some reason, it's listing Malwarebytes as my antivirus and while I do have it installed, I am actually using BitDefender Free for my antivirus and Zone Alarm Free for my firewall.
 

1 more replies
Relevance 66.42%

The problem start with my wife's PC. It started a few weeks ago she told me. She can't open Outlook Express (doesn't start), access My Space or get updates at Windows Update. Also some images on sites do not load.

I then checked my PC and found, I couldn't access Windows Update, My Space, Thunderbird fails to retrieve emails. I have not noticed any issues with images.

Given this sounded like some of the behaviors I have heard of trojans doing I thought I would post my logs here and see if anyone sees anything out of place. Normally I wouldn't consider a cross contamination but about two weeks I temporarily set up a home network between our PCs to share a few files. The next day I disabled NetBIOS on my PC but as we are both behind a hardware firewall, I guessing if it happened it must have happened then.

Nothing jumps out at me but I wanted to get a second opinion.

Any help would be appreciated.

Wife's PC
Logfile of HijackThis v1.99.1
Scan saved at 5:12:51 PM, on 4/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\sys... Read more

Answer:Hijack This Check (Can't Update Windows, Check Email or access My Space)

I ran SuperAntiSpyware and found nothing but 10 tracker cookies. Running Panda Virus Scanner online. I couldn't run F-Secure because IE7 Active X controls prevent it from running.

Zero clue as to what is going on so far.
 

3 more replies
Relevance 66.42%

Hi all, Around a year ago I bought a Z500. To put a long story relatively short, I handed it in for repair after the battery broke, and then recieved somebody else's Z500 with a huge list of issues- it was barely usable. Nobody seemed to be able to help replace it, so we handed it in to be inspected and to persue the Sales of Goods Act. They must have changed something, because now it is slightly more functional. However, running from essentially a blank install of Windows 8.1, the machine seems extremely slow. For instance, the BIOS seems to take a little longer to boot, and it takes more than 5 seconds to load Firefox. Additionally, a simple Unity game (Rust) is barely able to run, with a huge lag. I have tried a few things- cleaning up startup applications, defragging and trying to isolate the problem with task manager etc, but to no avail. All I have noticed is that the applcation CCleaner tells me that I'm running on Intel HD graphics 4000, when I have a NVIDIA GT 635M graphics card. Device Manager lists both the Intel graphics and the NVIDIA graphics card. It's probably worth noting that I installed (or essentially downgraded) the drivers for the intel graphics because the brightness wouldn't work. I wonder if this is the possible cause, and if so, how should I go about making sure that my laptop (whose OS has most likely been reinstalled around 5 times now) uses my NVIDIA graphics card? Many thanks in advance.

More replies
Relevance 66.42%

I was very disappointing with the spell checking in windows xp and thought they'd defiantly fix it in Win 7 but it's still complete and utter crap.
99% of the time when I misspell a word longer than 6 letters long when right click even when it gives me 4 words for suggestions it's never the correct word and I've actually lost marks in English class before from reading the suggested word too fast as it looked similar.....YET when I type any word into Google by completely butchering the word, sometimes not even getting half the right letters correct it somehow always gives me the correct spelling of the word with 1 freaking correction "NOT 4".
Overall I've very disappointed with windows 7 compared to XP as there are so many pointless useless features that just get in the way at times.
And windows 8 is just a complete joke. I could understand if windows 8 was strictly for tablets/phones but come on, it's like windows is taking steps backwards.

tbh once "Steam" is released on Linux I'm switching and never looking back.
Free upgrades ftw.
You know what they say, the best things in life are free.

GF windows

Answer:How do I make Windows spell check as good as Google

I use speckie spell checker...it works very well.

Speckie - Spell Check Internet Explorer

2 more replies
Relevance 66.42%

i think i finally got my server to work! i've spent the last three or four weeks planning this and building a sweet little computer to put it on, so can you all check to see if you can reach the site so i can start working on it some more?

the address is

http://192.168.0.102/

hopefully i'll set it up with a domain name within the next day or two. also, what did you all think about it? i did it with photoshop, golive, dreamweaver, and Abyss Web Server. thanks!
 

Answer:Hey, can you all check out this site real quick to make sure it's working?

16 more replies
Relevance 66.42%

How can I check what make/model is a certain drive under Windows 7?

I already tried under Device Manager > Disk Drives but it only indicated the make/model but not the drive letter assignment.

I also tried Computer Management > Disk Management > Right Click Disk > Properties > Hardware but when it shows all the drives' make/model but not the drive letter assignment?

Is Windows 7 capable of showing the drive letter as well as the make/model of the aforementioned drive letter? If Windows 7 is incapable of doing this, is there a software that you can recommend that can do this?

Answer:Drive Letter's Make/Model? How to check it under Windows 7

This might be of help.
Speccy - System Information - Free Download

3 more replies
Relevance 66.42%

Logfile of HijackThis v1.99.1
Scan saved at 8:31:36 AM, on 9/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SealedMedia\sealmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Mes... Read more

Answer:Solved: please check my wife's Hjack log....make me look good

10 more replies
Relevance 66.42%

How can you run a check to see if your quad core is running how it should ?

How can you see if one core is running while another is running something else? Is there a way you can check ?
 

Answer:How can you check to make sure quad core is working properly?

Not specifically, but if you open task manager and go to the performance tab, it will track cpu usage in real time for each core and logical processor.

.
 

2 more replies
Relevance 66.42%

Is verifying files by check sum / content after transferring (copying, moving) indeed unreliable?

Since "ever" I - if I checked files at all - checked files by content or check sum after transferring them, so this information sounds very astonishing to me now, I hadn't had any clue about what I read here: http://blogs.msdn.com/b/oldnewthing/archive/2012/09/19/10350645.aspx

Obviously meaning in many cases checking files by content / check sum checks the data in the buffer, if I see it right.

So, is it like that? Does it refer to all of the synchronizing / backup / copying, check sum, etc. programs?

And what is the best / easiest way to (automatically) check files after transferring. E.g. when copying all of the files of a 4TB drive to another one.
 

Answer:Verifying files by check sum / content after transferring unreliable - how to check?

Re: Verifying files by check sum / content after transferring unreliable - how to che

Kletus...

I'm not in my league with this, but could this make sense?

I think the article is referring to times when you are seeking to verify data across a network span between two systems (operating systems), where system b (copy destination) requests a checksum from system a (file original location). I believe the author is saying that in that particular situation checksums would be created from the cache/buffer on both computers. In the case of you copying to a secondary disk connected to a single computer I think the checksum should work fine. Sounds like one of those programmer's dilemmas to me.

Sorry if I am off on this. I know you are looking for some programming expertise. I'll just say that reading this, it made sense to me about the author's comments:



This really sounds like you're overthinking it.

First, what possible reason would there be for giving someone write access but not read access to a certain location? That's screwed up on so many different levels...

Second, you're right that having the sender compute a checksum of the destination file is a bad idea for all the reasons mentioned. But why did you even think of doing that in the first place?!? If I was implementing a system like that, I'd have the *destination* system compute the checksum on the file it received and send it back to the sender for verificati... Read more

5 more replies
Relevance 66.42%

Hi, i have hp pavilion g6 laptop and its upgraded from windows 8 to 8.1 then windows 10.  From last few days i was getting "Memory_Management", "Kernel_Data_Inpage_Error" and so many other errors with blue screen. Due to this i have to power off the system from main power button by holding for few seconds. Now i was getting hang problem. I saw in task manager that DISK UTILIZATION was 100%. I did a hardware test where i got below results : HARD DRIVE SHORT DST Check : WARNING HARD DRIVE Optimized DST Check  : FAILEDFAILURE ID: 9U3UWX-6KT85B-MFPWWJ-61Q003 Can anybody tell me how to resolve this or i need to replace the hard drive. -ThanksPankaj 

Answer:Hard Drive Short DST Check : WARNING and Optimized DST Check...

Yes you need to replace the hard drive. Since you have upgraded to Windows 10 it is very easy to get recovery media directly from the Microsoft Media Creation Tool. For most people, the problem is not physically swapping out the hard drive, but restoring the operating system since they do not have recovery disks. Post back if you want a service manual and/or video showing the replacement, purchase options for a new hard drive and step-by-step for restoring Windows 10. We would need the full model...g6-???? 

2 more replies
Relevance 66.42%

Hello, My PC is disk usgae is at 100%  and somtimes the CPU usage jumps up to. I tested my system and recived- Hard Drive Short DST Check and Long DST Check: Warning  How do I determine what the warning is? Do this mean my hard drive is on the verge of failing? 

More replies
Relevance 66.42%
Answer:how do i change ms word's spell check to check for british spelling?

is there a british version of office xp? i dont know if you can do that


 

6 more replies
Relevance 65.6%

Ok guys, trying to build a somewhat decent gaming computer here, and stay around 700 bucks or so. Heres what I've got so far - Let me know if something is not compatible etc, and I'll figure out something else.

Case - http://www.newegg.com/product/product.asp?item=N82E16811119068
Motherboard - http://www.newegg.com/product/product.asp?item=N82E16813131030
Video Card - http://www.newegg.com/product/product.asp?item=N82E16814141041
PSU- http://www.newegg.com/product/product.asp?item=N82E16817153028
Processor- http://www.newegg.com/product/product.asp?item=N82E16819115004
Memory - http://www.newegg.com/product/product.asp?item=N82E16820145588
DVD- http://www.newegg.com/product/product.asp?item=N82E16827152058
Cooling- http://www.newegg.com/product/product.asp?item=N82E16835106061

Plans are to overclock it, and probably toss on a Zalman video card cooler.

Running it to a Dell 19" flat screen monitor.


Look good so far, any compatability issues or anything of that nature?
 

More replies
Relevance 65.6%

Hi all

I have been trying to create an Excel macro that deletes only the check mark inside the check box albeit with no success. Is there a way to do this?? I have plenty of check boxes and it is taking me a lot of time to go into each one and delete only the check marks. It would be would be pretty neat to create a macro to delete the check marks in every single check box. If someone out there has figured out how to do it, it would be a great help.

Thanks

Mario
 

Answer:Deleting the Check mark only inside the check box using VBA in Excel

6 more replies
Relevance 65.6%

i have a panasonic toughbook cf 53 running windows 7 pro.my computer works fine. when i turn the computer on it states that there is a media test failure check cables. the only thing that is not working on my computer is the sound. i have checked the control panel and the settings, nothing is muted. im confused why the sound will not turn on. i pressed fn f4 to mute the volume and now it seems to be stuck on mute? any help would be greatly appreciated.thanks, jason

Answer:media test failure check check cables.

Check in Device Manager. Are there any yellow exclamation points?You've been helped by a 14 year old.

6 more replies
Relevance 65.6%

My daughter called me and asked what was wrong with her monitor. She said that when she starts her computer she gets this message "Self check, check your PC and signal cable, monitor is working" and no other display...

kds x-flat monitor, onboard video, XP, AMD

She has unplugged and replugged the video cable several times... any ideas why this is?
 

Answer:Self check, check your PC and signal cable, monitor is working

That suggests that the computer is not booting, or if it is, there is no video output.

The monitor is simply saying "I am OK, but the computer isn't sending me anything"

A simple check to see if the computer is booting is to try the CAPS Lock key. Pressing it will toggle the CAP light on and off each press, if the PC is running.
 

2 more replies
Relevance 65.6%

I have what I believe is a probably Hard Disk failiure; however, the Windows utility provides different output than the error codes provided by the System level check. The below is from my OS check:Microsoft Windows [Version 6.1.7601]Copyright (c) 2009 Microsoft Corporation. All rights reserved.C:\Users\user>wmicwmic:root\cli>diskdrive get statusStatusOKwmic:root\cli> It seems to indicate status as OK. However, the system level Hardware Test before booting shows the following:Failiure ID is: 9PMPKK-5B284T-XD002K-60QS03Product ID is XG809UA#ABA  I assume the OS level SMART Test is less reliable, then?Thanks!

More replies
Relevance 64.37%

Sup ppl?

I've been trying to get chech disk to run on startup for about a month now with now succes. I've searched the net constantly and tried tons of different approaches, but they all failed for me.

Anyway, I keep getting a baloon popup saying I should run chech disk because I have errors. I was hoping there's any type of software I can buy/download that will do the same thing as Check Disk, as in fix errors and bad sectors on disk.

Thanks in advance ppl.


-Des
 

Answer:Check Disk \ Auto Check Alternatives

Well...? I'm sure there must be some available.

-Des
 

7 more replies
Relevance 64.37%

So I have this problem, I have a user that have to check that box every time he open outlook for always check spelling before sending, it won't save the setting when I close it, my last resort would be a new profile but I want to try get help here first since google wasn't very helpful

We use outlook 2010 and the PC is part of a domain, I also tried checking the web outlook but the option is not there.

He is the only user having this problem and to be honest I have never seen this problem before.

More replies
Relevance 64.37%

Hello.

I have a SuperMicro server with windows 7 32bit. I am using a specialized hardware that can understandably may cause machine check errors because I have a pcie device that can stop responding to cpu non posted transactions for long pepriod of time. I have disabled the pcie timeouts in the hardware, but some other cpu exception occurs due to this long waiting time for the pcie transaction to complete. I get the BSOD with WHEA exception 124.
Bug Check 0x124: WHEA_UNCORRECTABLE_ERROR

Reported by compenent: Processor Core
Error source : 3
Error type: 9
Processor ID: 36

Event ID 18

How do I disable this machine check in windows 7 ?

Thanks

Rayyan

Answer:how to DISABLE Machine Check, WHEA bug check

Hello and welcome to the sevens forum. You said you are getting BSOD"s can you do the following because the BSOD team will need it to help you.

Blue Screen of Death (BSOD) Posting Instructions

1 more replies
Relevance 64.37%

I have listbox with check box as listbox items, i need to select to checkox dynamically. help me to do this.

Answer:Unable to check the check box dynamically in listbox in wp7

sorry but I clearly didn't get your question here. Could please give me some more details ? :)

2 more replies
Relevance 64.37%

Sup ppl?

I've been trying to get chech disk to run on startup for about a month now with now succes. I've searched the net constantly and tried tons of different approaches, but they all failed for me.

Anyway, I keep getting a baloon popup saying I should run chech disk because I have errors. I was hoping there's any type of software I can buy/download that will do the same thing as Check Disk, as in fix errors and bad sectors on disk.

Thanks in advance ppl.


-Des

Answer:Check Disk \ Auto Check Alternatives

There isn't any such software??

-Des

3 more replies
Relevance 64.37%

Hey guys,

The company I'm working for has grown a lot and now I'm no longer the only programmer. We're looking for an app that lets us do code check-in/check-out that'll also store all the changes.

All the files we need monitored are plaintext, and we do most of our development in Notepad or Notepad++. The app must work in Server 2003.

Any suggestions?

Thanks!
 

Answer:Code Repository/Check-in/Check-out system

I think subversion should handle your needs...
 

13 more replies
Relevance 64.37%

If it ain't one thing, it is another with this computer.
My spell check is having a nervous breakdown. It checks and offers alternatives for almost every word. This check can include words such as A or An, It, etc. At times I get spellings for words nowhere similar
In a paragraph similar in length to the preceding one, I might have suggetions for practically every word.
Plus, the auto check feature is not working
Anyone help? Appreciate any

Sarge
 

Answer:Spell check doesn't check correctly

You need to tell us what OS you are using and where this is happening - in a browser, in a word processor etc.
 

4 more replies
Relevance 64.37%

What is the best check -in check-out asset management software? A list of what's out there would be appreciated because I cant seem to find an authoritative one of what's best for asset management (game development). I hear Alien brain is good and there's one that starts with a 'p' that I can't remember the name of it to save my life... Alien brain is too expensive and hard to find. It's an open source project so I know the 'p' one would work because they offer open source licenses so if anyone knows what Im talking about feel free to enlighten me.

Something similar to Project but with asset management and check in/check out functionality would be great if anyone could suggest something. A step beyond that would be real time preview of maya scenes, psds, and xsi files. But maybe I want too much with the latter...

edit: Oh and it doesn't have to be free, Im just curious as to what's out there...
 

More replies
Relevance 61.91%

So, a couple of weeks ago someone sent me a strange email.  I wouldn't have opened it, but I was expecting a response from this person, along with an attachment re: a group email I had sent to them.  I couldn't open the stinking thing, and I knew I was going to see them this holiday weekend, and I was going to ask them about it then.  Anyhow, just a few hours ago my gmail inbox starts exploding with people from my Contact list asking if I sent them this e-mail.  Here is what the e-mail read:"Kindly view the document I uploaded for you using Google Apps . VIEW DOC HERE  with your personal email to view the document it's good and very important.Thanks,George" Does anyone here have a remedy?GPL

Answer:URGENT: REMEDY NEEDED FOR GOOGLE APPS "CHECK DOC" VIRUS

Change your gmail password.

2 more replies
Relevance 61.91%

greetings,
when I try to enter checks in the check register, I cannot set the check date to anything other than today's date (ie, the day I am trying to enter the check).

I have googled, etc, but cannot find the cause of this problem.

Anybody have an idea ?

thanks in advance.
 

Answer:Check dates in check register

What program
 

2 more replies
Relevance 61.91%

So, a couple of weeks ago someone sent me a strange email. I wouldn't have opened it, but I was expecting a response from this person, along with an attachment re: a group email I had sent to them. I couldn't open the stinking thing, and I knew I was going to see them this holiday weekend, and I was going to ask them about it then. Anyhow, just a few hours ago my gmail inbox starts exploding with people from my Contact list asking if I sent them this e-mail.

Here is what the e-mail read:

"Kindly view the document I uploaded for you using Google Apps . VIEW DOC HERE with your personal email to view the document it's good and very important.

Thanks,
George"

Does anyone here have a remedy?

GPL

Answer:Urgent: Remedy needed for google app "check doc" virus

What symptoms are you experiencing?

7 more replies
Relevance 58.63%

I get this blue screen error "Auto Check Program not found - Skipping auto check" each time that I boot up. What's the cause and how can a fix it?

More replies
Relevance 58.63%

Hi -Have you changed or added anything recently, or had any type of infection on the computer ? ?Go > Start Accessories > Command Prompt and Right click on it > Select Run as Administrator > Then type scf /scannow and press Enter -This "should" only take about 20 to 30 mins and will check your System Files -Next do the same, but type chkdsk /r and follow any prompts and reboot your computer - The 5 stage check may take from 1 to 2 hours depending on your system, but please let it finish -Thank You -

Answer:auto check program not found-skipping auto check

If sfc /scannow doesnt help then try thisDownloadAutorunsExtract and launch autoruns.exeAllow the scan to run,click on FILE-SAVE Filename:Autoruns.txtsave as type:textUpload the file to wwww.filedropper.com and post the link here

3 more replies
Relevance 55.76%

       

We are migrating from XP to Windows 7 and using USMT offline to migrate user settings etc.
Network printers are migrated but on the users first login if the user tries to set their default printer they receive the following error message:-

"Operation could not be completed (error 0x00000709) Double check the printer name and make sure that the printer is connected to the network."  

The printer is in fact installed and it is possible to print a test print, just not set the default printer.

The issue is resolved by restarting the print spooler (or logging out and back in or rebooting or re-installing the printer) so is only
an issue during the users first login.                                                                                                                             ... Read more

Answer:Printers "Operation could not be completed (error 0x00000709) Double check the printer name and make sure that the printer is connected to the network."

Hi,
According to the error message, I assume that the spooler service cannot find out the printer on the network.

You may set the startup type of Printer Spooler service to Manual or Delayed Start for a test.Juke Chou
TechNet Community Support

34 more replies
Relevance 52.07%

Today, I was online, reading the news and noticed that the pages were loading slower and slower. Using IE 8. Anyways, I got the Blue Screen of Death with (this is the first time I've seen this message):

Hardware Malfunction
Call hardware vendor for support
NMI: Parity Check/Memory Parity Error
The system has halted

I have a Dell Inspiron E1705 laptop
Win XP, Svc Pack 3
RAM: 1GB
BIOS version: Dell Inc. A03 (2006)
Recent changes to computer: Upgraded from IE 7 to IE 8 12 Apr 09, Windows Auto Update 15 Apr 09, Reg Fix Pro Update 16 Apr 09

After rebooting, I came to your site and checked out some similar posts, I've blown away the dust and went to the link for memtest86, downloaded, installed and updated drivers.

So, far have not received this msg again, but there were some other suggestions I'd like to try. How do I clear CMOS & set BIOS? (And years ago I heard the term - flash the BIOS is this the same thing? Or something else & do I need to do it?) Can you give me guidance on opening up a laptop to reseat & switch memory (I've only opened a desktop)? I did try to go into Setup (F2), but most fields were unchangeable. The battery is 100% charged and performing normally.

Any other things I should do?

Thanks so much!
 

Answer:parity check/memory parity check

There should be a slot on the bottom to get to the memory. Laptop memory sits flat, you will press 2 clips on the RAM holder and the memory will come up about 45 degrees. You can then lift it out of the slot. To install new memory, you slide it into the holder then press it down so it lies flat and you will hear it click in place.

As far as BIOS, avoid flashing it. If this is the first problem you've had and the error seems to point to memory, you do not need to do anything with your BIOS.
 

8 more replies
Relevance 52.07%

Running the Computer Check Disk Function
Step 1
Determine whether you are using Windows XP or Windows Vista. XP users can simply click on the "Windows Start Button" and then go to the "Run" link. Once run pops up type in "CMD" and hit enter which will cause the MS DOS prompt to appear. Type in "CHKDSK /r" which will check for hard disk errors. Vista users need to click on "Start" then go to "Accessories" followed by "System Tools" and then run the MSDOS program followed by "CHKDSK /r"
Step 2
Insert your restore CD if errors are found and not fixed by the check disk function listed above.
Step 3
Turn your computer off and then back on. You'll be asked to hit any button to boot from your CD; press any key. You will then be asked if you want to install a fresh version of your OS or "Repair" a current copy. Choose the "Repair" option and allow the computer to go through the necessary steps.
Step 4
After the repair function has run, turn your computer off and then back on. Wait and see if the computer shuts down again. If it does not shut down, your computer's restore function has fixed the file, which was probably caused by a bad system file.
Fixing Computer Shut Downs Via The Power source
Step 1
Check if your power source is properly connected inside your computer. Your power source is the large box that your computer's power cable plugs into. If this connection becomes loo... Read more

Answer:How to check for disk errors using Check Disk

Very useful share angelcotty

2 more replies
Relevance 50.02%

click herebut especially this:click hereI have rushed and changed my IE settings to block Javascript, but some sites need it but what if it is malicious.Try the links above, am I safe if I enable Javascript again?Thanks.

Answer:URGENT: What do you make of this?

Ok so the first link is a bit worring but as to the second didnt your antivirus pick up and stop the downloads?Remember this site is trying to sell you something.

10 more replies
Relevance 49.61%

**Already tried the search function

Alright, I now have 2.4 GB of files which includes my antivirus program, all my important drivers for my VGA card, sound card, web browser.

My C drive has a capacity of something around 74 GB. However, I want my C Drive to have 4.5 GB of capacity with my copy of XP in it, and make a new partition with all my files, games, and music so it won't disrupt the system.

How do I make this new partition?

If you are going to recommend me to use a partition program like Partition Magic, please tell me a version that works. Unlike Partition Manager which says demo version, and doesn't actually let you make a partition.

Thank you very much. This is URGENT!! I have to do my homework ^_^

Answer:How to make a partition. URGENT!

You have to buy partition magic. You can create partitions when you load your o/s, so if you want to do it that way you have to reformat your drive but make a 4.5g partition and load it on there with fdisk. OR use partition Magic, it does work, i use it all the time.


This link may be helpful

http://support.microsoft.com/default...67&product=w98

9 more replies
Relevance 49.2%

I have to computers one is XP and other is Vista , both are online 24hours , I leave the vista at work and my home laptop is XP , I control the vista one by any of the popluar RAT programs (Remote Administrative Tools) , but as you know the server file of the RATs always infected , so I want to know how to make the exe trusted by firewall and antivirus and windows defender and all security that might affect that server file not to work , and its URGENT

Answer:URGENT: I need to make an infected *.exe for my work

Duke,
Go into your AV program on your home computer. Look into the program, and look for a section for trusted files. You gave us almost no information. What av are you using? What is your firewall situation, windows or 3rd party?

Let us know,
Ben

1 more replies
Relevance 49.2%
Answer:Urgent help needed to make a calender

hi...myself and my grandaughter want to make a calender, there is not one in MS works,only a business type. So can someone guide us to a site where we can download all the pictures and the months, bearing in mind she is 9.thanks allanything for a bit of peace......

8 more replies
Relevance 49.2%

I exactly don't know what I am facing
but I need help
Disk Management

Spoiler
my computer

Spoiler
when I restarted my PC I received an error on booting screen named "B8"
and then I got to know that my earlier version of windows corrupted due to some reasons and now when I install new windows I was unable to chose any of the other partition as it showed that every partition was full but last time when I used my PC there was 102 gb free in 1tb HDD and 309 gb free in 500gb HDD so there was no other choice so I installed windows on 10gb partition
as you can see above those small partition (3.58gb, 10gb and 3.92gb) are not created by me
and while installing the windows I got alert of all "0 mb free" but disk management shows 100% free
please help se so those hidden partition can be visible on "my computer"
and is my data safe ? is there any way by which I can get my data back ??
 

Answer:[Urgent] how could i make all my partition visible

delete and format to NTFS and create as primary, the partition you want to install your system (i guess Disk0, the one with 461gb) , when you launch your installation of Windows, choose advanced setup , and install manually Windows there;
 

9 more replies
Relevance 47.97%

Hi, Dear all, I really hope I can get help here, this is the problem, At first my X201 cannot connect to my university's wireless network even it works well at my home.I found methods to resolve this problem online while failed though I tried so many......So I installed another version windows 7 since I thought it may be caused by the system installed,While it turned out to be not and my x201 still can not connect to my campus' wireless.Finally I decided to make a factory recovery while unfortunately I can not.Both thinkvantage and F11 did not give me a factory recovery option. So that 's the story, can anyone here give me a hand? Many many tks !













Solved!

Go to Solution.

Answer:Urgent Help Needed: how to make a factory recovery to my x201

is your recovery partition still intact? How many drives do you see under my computer?
 
 

4 more replies
Relevance 46.33%
Question: HJT log check

Hello there,
Just a little curious here and there after finding 2 trojans from a virus scan and wondering if they did anything =P. One was lurking around windows/temp and another at applicationdata/symantec/subeng/temp, and so it lead me to running a check.
I'd be greatful if someone can check my HJT log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 04:51:34, on 04/09/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\CPUCooL\CooLSrv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Progr... Read more

Answer:HJT log check

16 more replies
Relevance 46.33%

hi, i think we were hacked into last week (everything on our computer was lime green and purple)- also pup keeps on showing up as does system when i control-alt-delete

i ran hijack this and here is what it says

Logfile of HijackThis v1.97.2
Scan saved at 3:04:02 PM, on 9/12/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\ptsnoop.exe
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\PROGRAM FILES\BELLSOUTH\CONNECTION MANAGER\CMANAGER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\BROADJUMP\CORRECTCONNECT ENGINE\CCD.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.eases.net/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bellsouth.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.white-pages.ws/results.php?show=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:... Read more

Answer:need help! check this please! thanks!

9 more replies
Relevance 46.33%

HJT log posted below. Computer has started to run slow at times. Would appreciate any suggestions.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:38 PM, on 11/1/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\wanmpsvc.exe
... Read more

More replies
Relevance 46.33%

I really appreciate this.. I got a weird pop up the other day that told me I had to click one of two sites and that I was a VIP member. I couldn't close it.. Just making sure everything is cool so if someone can check it out and see if you see anything weird.. THANKS IN ADVANCE. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 6:04:52 PM, on 8/4/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16876)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\System32\snmp.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\WINDOWS\wanmpsvc.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\carpserv.exeC:\WINDOWS\System32\sistray.EXEC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeC:\Program Files\Security Task Manager.11\SpyProtector.exeC:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Java&... Read more

Answer:Please check and see if my log is ok..

Welcome to the BleepingComputer Forums. Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again. Double click on RSIT.exe to run RSIT. Click Continue at the disclaimer screen. Please post the contents of log.txt. Thank you for your patience.Please see Preparation Guide for use before posting about your potential Malware problem. If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped. Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so. While we are working on your HijackThis log, please: Reply to this thread; do not start another! Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so. Do not run any other tool until ... Read more

2 more replies
Relevance 46.33%
Question: Check Please

Please let me know if ive been hijacked

 hijackthis.log   12.12KB
  5 downloads

Answer:Check Please

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Relevance 46.33%
Question: check up

Logfile of HijackThis v1.98.2
Scan saved at 2:33:59 PM, on 10/3/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Norton AntiVirus\navapsvc.exe
C:\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WinAmp_5.03\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\CursorXP\CursorXP.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE
C:\Documents and Settings\Owner\Application Data\eber.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Norton AntiVirus\SAVScan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\?hkntfs.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\HJT\HJT.exe

R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {6BAD6874-C061-5893-D457-61557EF1701F} - C:\... Read more

Answer:check up

Please print out or copy this page to Notepad. You should not have any open browsers when you are following the procedures
below.

Make sure to update Windows and Internet Explorer at http://windowsupdate.microsoft.com.

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you may turn it back on and create a new restore point.

Go to My Computer->Tools->Folder Options->View tab and make sure that Show hidden files and folders is enabled. Also make sure
that the System Files and Folders are showing/visible also.

Please download Ad-aware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it. Go to this site to get the plug-in for fixing VX2 variants. Also make sure to customize the settings in Adaware for better scan results. Run the scan and fix everything that it finds.

Reboot into Safe Mode (hit F8 key until menu shows up).

Hopefully Adaware has removed some entries for you already. So if you see that something doesn't exist anymore, Adaware probably
fixed/deleted it already. Just continue on with the other fixes/deletions.

Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following a... Read more

1 more replies
Relevance 46.33%

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 20:10:55, on 22/02/2010
Platform: Windows 7 (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\soundman.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Users\2die4\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\2die4\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\2die4\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\2die4\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1... Read more

More replies
Relevance 46.33%

Here is my log... Could some one please give a look and let me know if I have anything unwanted running in my pc. Thank you in advance.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:37:10 PM, on 7/8/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16850)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\DRoster\Firebird\bin\fbguard.exeC:\WINDOWS\system32\LxrJD31s.exeC:\Program Files\PC Tools AntiVirus\PCTAVSvc.exeC:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYSC:\WINDOWS\system32\wdfmgr.exeC:\Program Files\DRoster\Firebird\bin\fbserver.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\RTHDCPL.EXEC:\Program Files\QuickTime\qttask.exeC:\... Read more

Answer:Please check my log.

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Relevance 46.33%

Hi, I just started using HJT and just want to know if a few members here could give it a look over and see if anything is amiss. Thanks alot! Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:38:01 PM, on 8/12/2009Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v8.00 (8.00.6001.18813)Boot mode: NormalRunning processes:C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exeC:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explo... Read more

Answer:HJT Log- Just want a check over

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to create an OTL ReportPlease download OTL from one of the following mirrors:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the button.Two reports will open, copy and paste them in a reply here:OTListIt.txt Will be openedExtra.txt Will be minimizedInformation on A/V control HEREEDIT: Just not... Read more

2 more replies
Relevance 46.33%

Hi - Ive run AVG, spybot and adaware and hopefully got rid af a trojan and a worm and some other stuff. Please could you check my HJT log as I dont know what im looking at.
Thanks
Sue

Logfile of HijackThis v1.98.2
Scan saved at 18:08:18, on 30/09/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
C:\PROGRAM FILES\LEXMARKX83\ACBTNMGR_X83.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\FREESERVE\FREESERVECONNECTIONKIT\ATDIALLER1.EXE
C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.02.3000.1001\EN-GB\MSNAPPAU.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\COREL\OFFICE7\SHARED\PFIT7\PFPPOP70.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanado... Read more

Answer:Please check my HJT log

Hi Sooetie,

You have just to 2 following entries to fix with HijackThis :

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-GB\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1001\EN-XU\STMAIN.DLL

I don't see anything else.
 

1 more replies
Relevance 46.33%

My PC is running fine overall, but I suspect something is lurking about. I recently tried to run RegCleaner, but ran into some issues. The process started (as verified by task manager), but RegCleaner never came up on screen. I tried an updated version but the results were the same.

Can someone take a look at my logs and see if anything looks suspicious?

Thanks!
 

Answer:Just want a check-up

MGLogs
 

4 more replies
Relevance 46.33%

hi there,..
couple of days ago my comp got infected with trojan (win32/adaware.virtumonde ).have already tried to run vundofix,virtumundobegone in normal and safe mode, nothing really helped,so trying the way with hjlog now, but need sb`s help to check the files for me.my comp is getting slow and confused, and nod32 detected about another 8 trojans. would be grateful for any help.
THANX A LOT
 

Answer:anybody to check my log?

Hi diver23,
Welcome to Major Geeks!

Your computer is still infected. Please go through the instructions in the READ & RUN ME FIRST and attach the requested logs when you get done. This will allow us to see which files need to be removed. Please be sure that you put your computer into normal startup mode as per the instructions regarding msconfig.

Thanks.
abri
 

1 more replies
Relevance 46.33%

it would be soo much appreciated if someone could take a look at this, my computers running super slow and i ant seem to find the Problem.. decided to try this out.. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:54:46 PM, on 6/20/2009Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v7.00 (7.00.6001.18248)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\system32\taskeng.exeC:\Windows\Explorer.EXEC:\Program Files\Windows Defender\MSASCui.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\WINDOWS\RtHDVCpl.exeC:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exeC:\Program Files\HP\QuickPlay\QPService.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exeC:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exeC:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\WINDOWS\System32\rundll32.exeC:\Program Files\HP\HP Software Update\hpwuSchd2.exeC:\WINDOWS\ehome\ehtray.exeC:\Program Files\Windows Media Player\wmpnscfg.exeC:\Windows\ehome\ehmsas.exeC:\Program Files\Synaptics\SynTP\SynTPHelper.exeC:\Program Files\Hewlett-Pac... Read more

Answer:Hey can someone check out my log? Thanks! :)

Hi ThomasBrennan,Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.Please subscribe to this topic, if you haven't already.
Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
Please reply to this post so I know you are there.The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day then I will close the topic.------------------------------------------------------------------------------------------------------------Please do the following:We need to scan for Rootkits with GMERPlease download GMER from one of the following locations, and save it to your desktop, please rename it as gamer.exe.Main Mirror
This version will download a randomly named file (Recommended)Zip Mirror
This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.Close any and all open programs, as this process may crash your computer.Double click or on your desktop.Allow the gmer.sys driver to load if asked.You may see this window. If you do, click No.
Click on and wait for the scan to finish.If you see a rootkit warning window, click OK.Push and save the logfile to your desktop.Copy and Paste the contents of that file in your next post.ThenPlease download Malwarebytes ... Read more

8 more replies
Relevance 46.33%

My brother's old Compaq has XP pro and he wants SP1 to be "up to date"...How can I check to see what he has?
 

Answer:How to check XP if it has SP1?

just do a windows update.
 

3 more replies
Relevance 46.33%

Hi, before I post my HJT log I would like to mention that I've ran McAfee, Ad-Aware and Spybot and also the online Trend Micro and Panda anti-virus. I thought I was finally virus and worm free but this morning I got a message saying that the following virus could not be cleaned and had to be deleted:

c:\windows\system32\drivers\etc\hosts
Qhosts.apd

I am constantly fighting worms and viruses and running the above programs but I believe the problem lies in my registry. Here's my HJT log:

Logfile of HijackThis v1.98.2
Scan saved at 9:52:59 AM, on 2004-09-30
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Vir... Read more

Answer:Please check my HJT log

16 more replies
Relevance 46.33%
Question: HJT log check

I'm on a friend's computer, trying to clean it up for him. I've gone as far as I can with spybot, etc, but don't have much experience with HJT, never having needed it on my comp. I think I see several problems, but thought to be sure, I'd let some more knowledgeable folk take a look.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:38:46 PM, on 6/13/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0013)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\LEXPPS.EXEC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\ctfmon.exeC:\WINDOWS\system32\cisvc.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Canon\IJPLM\IJPLMSVC.EXEC:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exeC:\WINDOWS\system32\HPZipm12.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Novatel Wireless&#... Read more

Answer:HJT log check

Hello and to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.-----------------------------------------------------------We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, ... Read more

2 more replies
Relevance 46.33%

Hello,

I'm rather certain that I'm, save still once in a while it's useful to check the computer for malware.

Here is the log, thank you.

Tolomir
DDS (Ver_09-05-14.01) - NTFSx86
Run by root at 15:20:07,87 on 11.06.2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2047.1258 [GMT 2:00]

AV: ZoneAlarm Extreme Security Antivirus *On-access scanning enabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
AV: Prevx Edge *On-access scanning enabled* (Updated) {D486329C-1488-4CEB-9CC8-D662B732D901}
FW: ZoneAlarm Extreme Security Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\Programme\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programme\PrevxCSI\pre... Read more

Answer:Need a check please

Hi My name is Extremeboy (or EB for short), and I will be helping you with your log.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.If you do not make a reply in 5 days, we will need to close your topic.You may want to keep the link to this topic in your favourites. Alternatively, you can click the button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.Please take note of some guidelines for this fix:Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.Even if things appear to be better, it might not mean we... Read more

3 more replies
Relevance 46.33%

It's been a while since I did an HJT scan and the computer seems to be running slow again. I've run CWS, Adaware, and Spybot, and usually have Zone Aleam firewall running (except when my wife turns it off to download something and forgets to turn it back on ). Anyway, here is the log and please tell me what does not need to be there.

Logfile of HijackThis v1.99.1
Scan saved at 12:01:13 PM, on 1/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software U... Read more

Answer:Please check this HJT log

6 more replies
Relevance 46.33%

Logfile of HijackThis v1.97.2
Scan saved at 10:45:42 AM, on 9/13/2003
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\HPOOPM07.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZAPRO.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\PROGRAM FILES\ADSGONE\ADSGONE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\AIM.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cox.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
O4 - HKLM\..\Run: [Sy... Read more

Answer:HJT check for me please

13 more replies
Relevance 46.33%

Hi!!!

I've got some applications that wouldn't launch directly...i've a "anti win" stuff that shouldn't be there, so if you could check my ht log or tell me about "anti win" if you've heard about it!

Thanks in advance!

Logfile of HijackThis v1.98.2
Scan saved at 19:57:58, on 04/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\... Read more

Answer:Please check my HT log!

Hi. You have a Lop infection that came in from Messenger Plus 3...it is bundled with Lop...
You should definitely uninstall Messenger Plus 3....I have read that during setup to install, there is an option for a custom install or something that does not put Lop on the system but I cannot confirm that....

To get rid of Lop, please use this Lop uninstaller:

Download it, close all browser windows, and run the uninstaller. There is a number code to type in the box...

After the uninstaller is finished, Restart the computer.

http://lop.com/new_uninstall.exe

Yes, it runs from the Lop website- it does work, though; there will usually be some manual removals also after you post the new log from HJT, so post it after you do the above.

The weird folder/filename is part of the LOP infection and should be removed by the uninstaller or manual deletion...after you try the uninstaller.
 

3 more replies
Relevance 46.33%
Question: PLD check?

When I start my computer, I get an error that says "Unable to open database in PLD check".

I have been getting "virtual memory low" messages alot lately. What does that mean?

Also my printer no longer works.

I am running Windows XP on a H/P computer that is about 6 months old.

Any ideas what might be the problem?
 

Answer:PLD check?

Check out this link:
http://www.ups.com/using/custserv/techfaq/ermes.html
 

1 more replies
Relevance 46.33%

Hello, this is the HJT log from my husband's office computer which has been playing up lately. Seems the longer the comp is used, whether on or offline it gets slower and slower. If anyone can tell us what should/can be removed to speed it up again it would be much appreciated.

Kate

Logfile of HijackThis v1.98.2
Scan saved at 8:05:35 PM, on 10/4/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SPYWARE DOCTOR\SPYDOCTOR.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\ONLINE SERVICES\MSN50\MSNDC.EXE
C:\PROGRA~1\NETROPA\ONSCRE~1\OSD.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\MY DOCUMENTS\HIJACKTHIS[1].EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local P... Read more

Answer:Please can someone check this out

7 more replies
Relevance 46.33%

Hi, someone hacked into my computer around 2 days ago, and i have everything back under control. But my internet seems to be going a little slow for some reason every since he got in. Also some websites just say no such domain when i clearly used it on my brothers computer a couple of hours ago.Anyway here is my log please check it for me:)Logfile of Trend Micro HijackThis v2.0.2Scan saved at 7:47:59 PM, on 6/8/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\RTHDCPL.EXEC:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exeC:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exeC:\Program Files\CyberLink\PowerDVD\PDVDServ.exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor.exeC:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exeC:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\... Read more

Answer:Someone Check this log for me please

My computer got hacked a couple of days ago, and i want to make sure the hacker didnt put anything on my pc.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:35:27 AM, on 6/13/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\COMODO\COMODO Internet Security\cmdagent.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\CTsvcCDA.exeC:\Program Files\ESET\ESET Smart Security\ekrn.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\IoctlSvc.exeC:\WINDOWS\system32\HPZipm12.exeC:\WINDOWS\system32\PnkBstrA.exeC:\Program Files\CyberLink\Shared Files\RichVideo.exeC:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exeC:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\RTHDCPL... Read more

7 more replies
Relevance 46.33%

Not sure if JS/Wonka has infected machine I run Firefox with no script enabled also run Norton 2010

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:53:55, on 01/04/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Freecorder\FLVSrvc.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Link... Read more

Answer:Can you check this log please - thanks

10 more replies
Relevance 46.33%
Question: please check log..

please help me coz im having the svchost.exe error everytime i use the internet. it prevents me from copying and pasting stuff and from running some applications. i have to restart in order for my computer to function normally. pasted below is my hijackthis log file. thanks!

Logfile of HijackThis v1.97.2
Scan saved at 1:52:37 PM, on 09/15/2003
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Winamp\Winampa.exe
C:\WINNT\System32\spool\dr... Read more

Answer:please check log..

run hijackthis, tick all below, doublecheck to make sure you haven't missed any, close all browser windows & press fix checked

O2 - BHO: (no name) - {000004CC-E4FF-4F2C-BC30-DBEF0B983BC9} - C:\WINNT\ipinsigt.dll
O2 - BHO: (no name) - {392BE62B-E7DE-430A-8859-0AFE677DE6E1} - C:\WINNT\bs2.dll
O4 - HKLM\..\Run: [BookedSpace] RunDLL32.EXE C:\WINNT\bs2.dll,DllRun
O4 - HKLM\..\Run: [WinStart001.EXE] C:\WINNT\System\WinStart001.EXE -b

reboot & delete the following files
C:\WINNT\ipinsigt.dll
C:\WINNT\bs2.dll
C:\WINNT\System\WinStart001.EXE
 

1 more replies
Relevance 46.33%
Question: can u check my log

Unable to run DDS. ~ OBi just want to know if i have any viruses. just checking. thank you!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:23:55 PM, on 8/17/2009Platform: Windows Vista SP2 (WinNT 6.00.1906)MSIE: Internet Explorer v8.00 (8.00.6001.18813)Boot mode: NormalRunning processes:C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exeC:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exeC:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exeC:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exeC:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exeC:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exeC:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exeC:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXEC:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exeC:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exeC:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exeC:\Program Files (x86)\iTunes\iTunesHelper.exeC:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media&#... Read more

Answer:can u check my log

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.We need to create an OTL ReportPlease download OTL from one of the following mirrors:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the button.Two reports will open, copy and paste them in a reply here:OTListIt.txt Will be openedExtra.txt Will be minimizedThanks and again sorry for the delay.Information on A/V control HEREEDIT: typo

8 more replies
Relevance 46.33%

I rely on this click here forum for help etc using my Tom Tom Go navigator and for about 30 hours I have been unable to get onto the forum. Can someone please check the link for me and let me know if it is their website or my computer.Thanks for any help.

Answer:Can someone please check this.

phpBB : Critical ErrorError creating new sessionDEBUG MODESQL Error : 1016 Can't open file: 'phpbb_sessions.MYD'. (errno: 145)INSERT INTO phpbb_sessions (session_id, session_user_id, session_start, session_time, session_ip, session_page, session_logged_in, session_admin) VALUES ('e32de69779188c6f4456e5bbc7b37413', -1, 1122836480, 1122836480, '522cb0e5', 0, 0, 0)Line : 172File : sessions.php

5 more replies
Relevance 46.33%

I see alot of gambling popups and other annoying things thanks for your help

Logfile of HijackThis v1.98.2
Scan saved at 6:47:30 PM, on 10/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Documents and Settings\Leet\Application Data\aasi.exe
C:\WINDOWS\System32\r?ndll32.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Hijack this\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acro... Read more

Answer:Will someone check my log please

Please download and run the following program(s):

AD-AWARE

Go here: http://www.lavasoftusa.com/support/download/
and download Ad-Aware SE Personal

Install the program and launch it.

First, in the bottom right-hand corner of the main window click on Check for updates now then click Connect and download the latest reference files.

Then, in the main window: Click Start and under Select a scan Mode tick Perform full system scan.

Then, deselect Search for negligible risk entries.

To start the scan, click the Next button.

When the scan is finished mark everything for removal and get rid of it. (Right-click the window and choose select all from the drop down menu and then click Next)

Restart your computer.

SPYBOT SEARCH & DESTROY

http://majorgeeks.com/download2471.html

Open Spybot Search & Destroy (Click Start, Programs, Spybot S&D (Advanced Mode). Click online, Search for updates, Download all available updates. Close all Browser windows, Click ''Check for Problems''. Anything that needs to be fixed it will show in red and have a green check in the box to the left. Click ''Fix Selected Problems'', Then restart your computer.

Then, after rebooting, please post another log and we’ll see what’s left to get rid of.
 

1 more replies
Relevance 46.33%
Question: log check

i am clean?i dont know also whats UniFSService.exethanks Logfile of Trend Micro HijackThis v2.0.2Scan saved at 08:39:32, on 02/12/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\ESET\ESET Smart Security\ekrn.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exeC:\Program Files\Acer\Acer VCM\RS_Service.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\UnisonPlay\UniFSService.exeC:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exeC:\PROGRA~1\LAUNCH~1\LManager.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\WINDOWS\system32\igfxsrvc.exeC:\Program Files\ESET\ESET Smart Security\egui.exeC:\WINDOWS\WebCam\M3000\M3000Mnt.exeC:\WINDOWS\sys... Read more

Answer:log check

Hello , And to the Bleeping Computer Malware Removal Forum. My name is Elise and I'll be glad to help you with your computer problems.I will be working on your malware issues, this may or may not solve other issues you may have with your machine.Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.-----------------------------------------------------------If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explanation about the tool. No inp... Read more

2 more replies