Computer Support Forum

Serious help needed!! (log file inside-very long)

Question: Serious help needed!! (log file inside-very long)

Logfile of HijackThis v1.98.2
Scan saved at 6:29:52 AM, on 9/6/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0EIC1.EXE
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\nacqzagb.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.phantasytour.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {54A45EF9-287B-69B9-1EAD-B92AAFBB91BA} - C:\WINDOWS\system32\vnqraogv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo 820 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0EIC1.EXE /P29 "EPSON Stylus Photo 820 Series" /O6 "USB001" /M "Stylus Photo 820"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\av.exe
O4 - HKLM\..\Run: [akrnpbmf] C:\WINDOWS\nacqzagb.exe
O4 - HKLM\..\Run: [iehelper] C:\Program Files\syslaunch.exe
O4 - HKLM\..\Run: [b] C:\WINDOWS\System32\ppwqcl.exe
O4 - HKLM\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
O4 - HKLM\..\Run: [npxruxhcj] C:\WINDOWS\System32\gvkjjq.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [timestamp=servername&Year(now())&Month(now())&Day(now())&Hour(Now())&minute(Now())&second(no] c:\WINDOWS\System32\timestamp=servername&Year(now())&Month(now())&Day(now())&Hour(Now())&minute(Now())&second(now())
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [// Browser Detec] c:\WINDOWS\System32\// Browser Detection
O4 - HKLM\..\Run: [NS4 = (document.layers) ? true : fa] c:\WINDOWS\System32\NS4 = (document.layers) ? true : false;
O4 - HKLM\..\Run: [IEmac = ((document.all)&&(isMac)) ? true : fa] c:\WINDOWS\System32\IEmac = ((document.all)&&(isMac)) ? true : false;
O4 - HKLM\..\Run: [IE4plus = (document.all) ? true : fa] c:\WINDOWS\System32\IE4plus = (document.all) ? true : false;
O4 - HKLM\..\Run: [ver4 = (NS4 || IE4plus) ? true : fa] c:\WINDOWS\System32\ver4 = (NS4 || IE4plus) ? true : false;
O4 - HKLM\..\Run: [NS6 = (!document.layers) && (navigator.userAgent.indexOf('Netscape')!=-1)?true:fa] c:\WINDOWS\System32\NS6 = (!document.layers) && (navigator.userAgent.indexOf('Netscape')!=-1)?true:false;
O4 - HKLM\..\Run: [IE5plus = IE5 || ] c:\WINDOWS\System32\IE5plus = IE5 || IE6;
O4 - HKLM\..\Run: [IEMajor ] c:\WINDOWS\System32\IEMajor = 0;
O4 - HKLM\..\Run: [if (IE4p] c:\WINDOWS\System32\if (IE4plus)
O4 - HKLM\..\Run: [ IEMajor = p****Int(navigator.appVersion.substring(start+5,en] c:\WINDOWS\System32\ IEMajor = p****Int(navigator.appVersion.substring(start+5,end));
O4 - HKLM\..\Run: [// Body onload utility (supports multiple onload functi] c:\WINDOWS\System32\// Body onload utility (supports multiple onload functions)
O4 - HKLM\..\Run: [var gSafeOnload = new Arra] c:\WINDOWS\System32\var gSafeOnload = new Array();
O4 - HKLM\..\Run: [function SafeAddOnloa] c:\WINDOWS\System32\function SafeAddOnload(f)
O4 - HKLM\..\Run: [ if (IEmac && IE4) // IE 4.5 blows out on testing window.on] c:\WINDOWS\System32\ if (IEmac && IE4) // IE 4.5 blows out on testing window.onload
O4 - HKLM\..\Run: [ window.onload = SafeOnl] c:\WINDOWS\System32\ window.onload = SafeOnload;
O4 - HKLM\..\Run: [ gSafeOnload[gSafeOnload.length] ] c:\WINDOWS\System32\ gSafeOnload[gSafeOnload.length] = f;
O4 - HKLM\..\Run: [ else if (window.onl] c:\WINDOWS\System32\ else if (window.onload)
O4 - HKLM\..\Run: [ if (window.onload != SafeOnl] c:\WINDOWS\System32\ if (window.onload != SafeOnload)
O4 - HKLM\..\Run: [ gSafeOnload[0] = window.onl] c:\WINDOWS\System32\ gSafeOnload[0] = window.onload;
O4 - HKLM\..\Run: [ window.onload = SafeOnl] c:\WINDOWS\System32\ window.onload = SafeOnload;
O4 - HKLM\..\Run: [ ] c:\WINDOWS\System32\ else
O4 - HKLM\..\Run: [ window.onload ] c:\WINDOWS\System32\ window.onload = f;
O4 - HKLM\..\Run: [function SafeOnlo] c:\WINDOWS\System32\function SafeOnload()
O4 - HKLM\..\Run: [ gSafeOnload[i] c:\WINDOWS\System32\ gSafeOnload[i]();
O4 - HKLM\..\Run: [function isInt(nu] c:\WINDOWS\System32\function isInt(numIn)
O4 - HKLM\..\Run: [ var checknum = p****Int(num] c:\WINDOWS\System32\ var checknum = p****Int(numIn);
O4 - HKLM\..\Run: [ return !isNaN(checkn] c:\WINDOWS\System32\ return !isNaN(checknum);
O4 - HKLM\..\Run: [function PUW_In] c:\WINDOWS\System32\function PUW_Init()
O4 - HKLM\..\Run: [ if (gPopupWindow.CheckFrequenc] c:\WINDOWS\System32\ if (gPopupWindow.CheckFrequency())
O4 - HKLM\..\Run: [function PUW_Sh] c:\WINDOWS\System32\function PUW_Show()
O4 - HKLM\..\Run: [ var newWin = window.open(this.url,this.name,settin] c:\WINDOWS\System32\ var newWin = window.open(this.url,this.name,settings);
O4 - HKLM\..\Run: [ if (! this.on] c:\WINDOWS\System32\ if (! this.ontop)
O4 - HKLM\..\Run: [ window.focu] c:\WINDOWS\System32\ window.focus();
O4 - HKLM\..\Run: [function PUW_CheckFrequen] c:\WINDOWS\System32\function PUW_CheckFrequency()
O4 - HKLM\..\Run: [ var shouldShow = this.frequency !] c:\WINDOWS\System32\ var shouldShow = this.frequency != 0;
O4 - HKLM\..\Run: [ var allCookies = document.coo] c:\WINDOWS\System32\ var allCookies = document.cookie;
O4 - HKLM\..\Run: [ end = allCookies.len] c:\WINDOWS\System32\ end = allCookies.length;
O4 - HKLM\..\Run: [ var freqStr = allCookies.substring(start+9,e] c:\WINDOWS\System32\ var freqStr = allCookies.substring(start+9,end);
O4 - HKLM\..\Run: [ if (isInt(freqS] c:\WINDOWS\System32\ if (isInt(freqStr))
O4 - HKLM\..\Run: [ this.frequency = p****Int(freqS] c:\WINDOWS\System32\ this.frequency = p****Int(freqStr);
O4 - HKLM\..\Run: [ this.frequenc] c:\WINDOWS\System32\ this.frequency--;
O4 - HKLM\..\Run: [ ] c:\WINDOWS\System32\ else
O4 - HKLM\..\Run: [ shouldShow = fa] c:\WINDOWS\System32\ shouldShow = false;
O4 - HKLM\..\Run: [ var exp = new Dat] c:\WINDOWS\System32\ var exp = new Date();
O4 - HKLM\..\Run: [ exp.setTime(exp.getTime()+this.renew*60*60] c:\WINDOWS\System32\ exp.setTime(exp.getTime()+this.renew*60*6000);
O4 - HKLM\..\Run: [ return shouldS] c:\WINDOWS\System32\ return shouldShow;
O4 - HKLM\..\Run: [function PopupWindow(url,width,hei] c:\WINDOWS\System32\function PopupWindow(url,width,height)
O4 - HKLM\..\Run: [ this.width = wi] c:\WINDOWS\System32\ this.width = width;
O4 - HKLM\..\Run: [ this.height = hei] c:\WINDOWS\System32\ this.height = height;
O4 - HKLM\..\Run: [ this.top = screen.availHeight/2 - height/2; // ce] c:\WINDOWS\System32\ this.top = screen.availHeight/2 - height/2; // center
O4 - HKLM\..\Run: [ this.left = screen.availWidth/2 - width/2; // ce] c:\WINDOWS\System32\ this.left = screen.availWidth/2 - width/2; // center
O4 - HKLM\..\Run: [ this.url = ] c:\WINDOWS\System32\ this.url = url;
O4 - HKLM\..\Run: [ this.showDelay = 2] c:\WINDOWS\System32\ this.showDelay = 2000;
O4 - HKLM\..\Run: [ this.frequency = 1; // how many times show per renewal time pe] c:\WINDOWS\System32\ this.frequency = 1; // how many times show per renewal time period
O4 - HKLM\..\Run: [ this.renew = 1; // renew showing every x h] c:\WINDOWS\System32\ this.renew = 1; // renew showing every x hours
O4 - HKLM\..\Run: [ this.scrollbars= fa] c:\WINDOWS\System32\ this.scrollbars= false;
O4 - HKLM\..\Run: [ this.toolbar= fa] c:\WINDOWS\System32\ this.toolbar= false;
O4 - HKLM\..\Run: [ this.statusbar= fa] c:\WINDOWS\System32\ this.statusbar= false;
O4 - HKLM\..\Run: [ this.resizable = fa] c:\WINDOWS\System32\ this.resizable = false;
O4 - HKLM\..\Run: [ this.locationbar = fa] c:\WINDOWS\System32\ this.locationbar = false;
O4 - HKLM\..\Run: [ this.menubar = fa] c:\WINDOWS\System32\ this.menubar = false;
O4 - HKLM\..\Run: [ this.ontop = fa] c:\WINDOWS\System32\ this.ontop = false;
O4 - HKLM\..\Run: [ this.Init = PUW_I] c:\WINDOWS\System32\ this.Init = PUW_Init;
O4 - HKLM\..\Run: [ this.Show = PUW_S] c:\WINDOWS\System32\ this.Show = PUW_Show;
O4 - HKLM\..\Run: [ this.CheckFrequency = PUW_CheckFreque] c:\WINDOWS\System32\ this.CheckFrequency = PUW_CheckFrequency;
O4 - HKLM\..\Run: [function PUWSta] c:\WINDOWS\System32\function PUWStart()
O4 - HKLM\..\Run: [ gPopupWindow.Ini] c:\WINDOWS\System32\ gPopupWindow.Init();
O4 - HKLM\..\Run: [SafeAddOnload(PUWSta] c:\WINDOWS\System32\SafeAddOnload(PUWStart);
O4 - HKLM\..\Run: [gPopupWindow.toolbar = fa] c:\WINDOWS\System32\gPopupWindow.toolbar = false;
O4 - HKLM\..\Run: [gPopupWindow.statusbar = fa] c:\WINDOWS\System32\gPopupWindow.statusbar = false;
O4 - HKLM\..\Run: [gPopupWindow.resizable = fa] c:\WINDOWS\System32\gPopupWindow.resizable = false;
O4 - HKLM\..\Run: [gPopupWindow.ontop = fa] c:\WINDOWS\System32\gPopupWindow.ontop = false;
O4 - HKLM\..\Run: [A:hover {background: #FFCC00; color: bla] c:\WINDOWS\System32\A:hover {background: #FFCC00; color: black;}
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\RunOnce: [cetec] regedit.exe /s C:\DOCUME~1\ELIZAB~1\LOCALS~1\Temp\cetec.reg
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [timestamp=servername&Year(now())&Month(now())&Day(now())&Hour(Now())&minute(Now())&second(no] c:\WINDOWS\System32\timestamp=servername&Year(now())&Month(now())&Day(now())&Hour(Now())&minute(Now())&second(now())
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O4 - HKCU\..\Run: [// Browser Detec] c:\WINDOWS\System32\// Browser Detection
O4 - HKCU\..\Run: [NS4 = (document.layers) ? true : fa] c:\WINDOWS\System32\NS4 = (document.layers) ? true : false;
O4 - HKCU\..\Run: [IEmac = ((document.all)&&(isMac)) ? true : fa] c:\WINDOWS\System32\IEmac = ((document.all)&&(isMac)) ? true : false;
O4 - HKCU\..\Run: [IE4plus = (document.all) ? true : fa] c:\WINDOWS\System32\IE4plus = (document.all) ? true : false;
O4 - HKCU\..\Run: [ver4 = (NS4 || IE4plus) ? true : fa] c:\WINDOWS\System32\ver4 = (NS4 || IE4plus) ? true : false;
O4 - HKCU\..\Run: [NS6 = (!document.layers) && (navigator.userAgent.indexOf('Netscape')!=-1)?true:fa] c:\WINDOWS\System32\NS6 = (!document.layers) && (navigator.userAgent.indexOf('Netscape')!=-1)?true:false;
O4 - HKCU\..\Run: [IE5plus = IE5 || ] c:\WINDOWS\System32\IE5plus = IE5 || IE6;
O4 - HKCU\..\Run: [IEMajor ] c:\WINDOWS\System32\IEMajor = 0;
O4 - HKCU\..\Run: [if (IE4p] c:\WINDOWS\System32\if (IE4plus)
O4 - HKCU\..\Run: [ IEMajor = p****Int(navigator.appVersion.substring(start+5,en] c:\WINDOWS\System32\ IEMajor = p****Int(navigator.appVersion.substring(start+5,end));
O4 - HKCU\..\Run: [// Body onload utility (supports multiple onload functi] c:\WINDOWS\System32\// Body onload utility (supports multiple onload functions)
O4 - HKCU\..\Run: [var gSafeOnload = new Arra] c:\WINDOWS\System32\var gSafeOnload = new Array();
O4 - HKCU\..\Run: [function SafeAddOnloa] c:\WINDOWS\System32\function SafeAddOnload(f)
O4 - HKCU\..\Run: [ if (IEmac && IE4) // IE 4.5 blows out on testing window.on] c:\WINDOWS\System32\ if (IEmac && IE4) // IE 4.5 blows out on testing window.onload
O4 - HKCU\..\Run: [ window.onload = SafeOnl] c:\WINDOWS\System32\ window.onload = SafeOnload;
O4 - HKCU\..\Run: [ gSafeOnload[gSafeOnload.length] ] c:\WINDOWS\System32\ gSafeOnload[gSafeOnload.length] = f;
O4 - HKCU\..\Run: [ else if (window.onl] c:\WINDOWS\System32\ else if (window.onload)
O4 - HKCU\..\Run: [ if (window.onload != SafeOnl] c:\WINDOWS\System32\ if (window.onload != SafeOnload)
O4 - HKCU\..\Run: [ gSafeOnload[0] = window.onl] c:\WINDOWS\System32\ gSafeOnload[0] = window.onload;
O4 - HKCU\..\Run: [ window.onload = SafeOnl] c:\WINDOWS\System32\ window.onload = SafeOnload;
O4 - HKCU\..\Run: [ ] c:\WINDOWS\System32\ else
O4 - HKCU\..\Run: [ window.onload ] c:\WINDOWS\System32\ window.onload = f;
O4 - HKCU\..\Run: [function SafeOnlo] c:\WINDOWS\System32\function SafeOnload()
O4 - HKCU\..\Run: [ gSafeOnload[i] c:\WINDOWS\System32\ gSafeOnload[i]();
O4 - HKCU\..\Run: [function isInt(nu] c:\WINDOWS\System32\function isInt(numIn)
O4 - HKCU\..\Run: [ var checknum = p****Int(num] c:\WINDOWS\System32\ var checknum = p****Int(numIn);
O4 - HKCU\..\Run: [ return !isNaN(checkn] c:\WINDOWS\System32\ return !isNaN(checknum);
O4 - HKCU\..\Run: [function PUW_In] c:\WINDOWS\System32\function PUW_Init()
O4 - HKCU\..\Run: [ if (gPopupWindow.CheckFrequenc] c:\WINDOWS\System32\ if (gPopupWindow.CheckFrequency())
O4 - HKCU\..\Run: [function PUW_Sh] c:\WINDOWS\System32\function PUW_Show()
O4 - HKCU\..\Run: [ var newWin = window.open(this.url,this.name,settin] c:\WINDOWS\System32\ var newWin = window.open(this.url,this.name,settings);
O4 - HKCU\..\Run: [ if (! this.on] c:\WINDOWS\System32\ if (! this.ontop)
O4 - HKCU\..\Run: [ window.focu] c:\WINDOWS\System32\ window.focus();
O4 - HKCU\..\Run: [function PUW_CheckFrequen] c:\WINDOWS\System32\function PUW_CheckFrequency()
O4 - HKCU\..\Run: [ var shouldShow = this.frequency !] c:\WINDOWS\System32\ var shouldShow = this.frequency != 0;
O4 - HKCU\..\Run: [ var allCookies = document.coo] c:\WINDOWS\System32\ var allCookies = document.cookie;
O4 - HKCU\..\Run: [ end = allCookies.len] c:\WINDOWS\System32\ end = allCookies.length;
O4 - HKCU\..\Run: [ var freqStr = allCookies.substring(start+9,e] c:\WINDOWS\System32\ var freqStr = allCookies.substring(start+9,end);
O4 - HKCU\..\Run: [ if (isInt(freqS] c:\WINDOWS\System32\ if (isInt(freqStr))
O4 - HKCU\..\Run: [ this.frequency = p****Int(freqS] c:\WINDOWS\System32\ this.frequency = p****Int(freqStr);
O4 - HKCU\..\Run: [ this.frequenc] c:\WINDOWS\System32\ this.frequency--;
O4 - HKCU\..\Run: [ ] c:\WINDOWS\System32\ else
O4 - HKCU\..\Run: [ shouldShow = fa] c:\WINDOWS\System32\ shouldShow = false;
O4 - HKCU\..\Run: [ var exp = new Dat] c:\WINDOWS\System32\ var exp = new Date();
O4 - HKCU\..\Run: [ exp.setTime(exp.getTime()+this.renew*60*60] c:\WINDOWS\System32\ exp.setTime(exp.getTime()+this.renew*60*6000);
O4 - HKCU\..\Run: [ return shouldS] c:\WINDOWS\System32\ return shouldShow;
O4 - HKCU\..\Run: [function PopupWindow(url,width,hei] c:\WINDOWS\System32\function PopupWindow(url,width,height)
O4 - HKCU\..\Run: [ this.width = wi] c:\WINDOWS\System32\ this.width = width;
O4 - HKCU\..\Run: [ this.height = hei] c:\WINDOWS\System32\ this.height = height;
O4 - HKCU\..\Run: [ this.top = screen.availHeight/2 - height/2; // ce] c:\WINDOWS\System32\ this.top = screen.availHeight/2 - height/2; // center
O4 - HKCU\..\Run: [ this.left = screen.availWidth/2 - width/2; // ce] c:\WINDOWS\System32\ this.left = screen.availWidth/2 - width/2; // center
O4 - HKCU\..\Run: [ this.url = ] c:\WINDOWS\System32\ this.url = url;
O4 - HKCU\..\Run: [ this.showDelay = 2] c:\WINDOWS\System32\ this.showDelay = 2000;
O4 - HKCU\..\Run: [ this.frequency = 1; // how many times show per renewal time pe] c:\WINDOWS\System32\ this.frequency = 1; // how many times show per renewal time period
O4 - HKCU\..\Run: [ this.renew = 1; // renew showing every x h] c:\WINDOWS\System32\ this.renew = 1; // renew showing every x hours
O4 - HKCU\..\Run: [ this.scrollbars= fa] c:\WINDOWS\System32\ this.scrollbars= false;
O4 - HKCU\..\Run: [ this.toolbar= fa] c:\WINDOWS\System32\ this.toolbar= false;
O4 - HKCU\..\Run: [ this.statusbar= fa] c:\WINDOWS\System32\ this.statusbar= false;
O4 - HKCU\..\Run: [ this.resizable = fa] c:\WINDOWS\System32\ this.resizable = false;
O4 - HKCU\..\Run: [ this.locationbar = fa] c:\WINDOWS\System32\ this.locationbar = false;
O4 - HKCU\..\Run: [ this.menubar = fa] c:\WINDOWS\System32\ this.menubar = false;
O4 - HKCU\..\Run: [ this.ontop = fa] c:\WINDOWS\System32\ this.ontop = false;
O4 - HKCU\..\Run: [ this.Init = PUW_I] c:\WINDOWS\System32\ this.Init = PUW_Init;
O4 - HKCU\..\Run: [ this.Show = PUW_S] c:\WINDOWS\System32\ this.Show = PUW_Show;
O4 - HKCU\..\Run: [ this.CheckFrequency = PUW_CheckFreque] c:\WINDOWS\System32\ this.CheckFrequency = PUW_CheckFrequency;
O4 - HKCU\..\Run: [function PUWSta] c:\WINDOWS\System32\function PUWStart()
O4 - HKCU\..\Run: [ gPopupWindow.Ini] c:\WINDOWS\System32\ gPopupWindow.Init();
O4 - HKCU\..\Run: [SafeAddOnload(PUWSta] c:\WINDOWS\System32\SafeAddOnload(PUWStart);
O4 - HKCU\..\Run: [gPopupWindow.toolbar = fa] c:\WINDOWS\System32\gPopupWindow.toolbar = false;
O4 - HKCU\..\Run: [gPopupWindow.statusbar = fa] c:\WINDOWS\System32\gPopupWindow.statusbar = false;
O4 - HKCU\..\Run: [gPopupWindow.resizable = fa] c:\WINDOWS\System32\gPopupWindow.resizable = false;
O4 - HKCU\..\Run: [gPopupWindow.ontop = fa] c:\WINDOWS\System32\gPopupWindow.ontop = false;
O4 - HKCU\..\Run: [A:hover {background: #FFCC00; color: bla] c:\WINDOWS\System32\A:hover {background: #FFCC00; color: black;}
O4 - Startup: DLHelperEXE.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file) (HKCU)
O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - (no file) (HKCU)
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://205.159.125.199/central/02030...verContent.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - http://portal.uga.edu/nps/portal/gad.../LocalExec.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minib...ansporter.cab?
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhel...7/dlhelper.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {CE74A05D-ED12-473A-97F8-85FB0E2F479F} (dlControl.UserControl1) - http://www.nugs.net/dev/dlControl.CAB
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mp...CX/FlashAX.cab

the system32 file opens at startup and randomly loops while using IE.

also ran microtrends online scanner and it reported 13 trojans and 1 backdoor.

Trojans: HOOKER.B, ADCLICKER.G, WINFAVS.A, IMISERV.C, SMALL.EU, PMS.3, GOLID.A, BROK.A, BENUTI.A, MLFREE.A, MSCACHE.A, PYFUCA.CN

Backdoor: Jeemp.c

please help me sort out this mess

Relevance 100%
Preferred Solution: Serious help needed!! (log file inside-very long)

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

Answer: Serious help needed!! (log file inside-very long)

bump

thanks

2 more replies
Relevance 56.99%

Hello, We have gone to the website
http://www.salonrenovationmaisonneuve.com/en/exposants
and download the file to open Inside of IE. Once the file is open, none of the links either e-mail or web site works. However, if we open the same file Inside of Google Chrome, the links work. So, we want to know if we are missing something in IE or a plugin.
The PDF file opens with no problem but the links are not enabled. The file works in an Apple Machine and Google Chrome. However, if we download the file physically inside of the computer and then open the file with Adobe Reader, the links all work! Any ideas
how to solve this issue? Thanks Miguel Moreno

Miguel A. Moreno Alfa Logos inc. Tel. 514-253-2548

Answer:UNABLE TO OPEN AN HYPERLINK INSIDE OF A WEB PDF FILE OPENED INSIDE OF IE 11

Internet Options>Security tab, click "Reset all zones to default" (there's a setting for scripting of ActiveX controls)
Start>Adobe Reader>Edit Preferences>there are setting for how embedded links are handled.
Chromium uses its own pdf reader plugin.Rob^_^

3 more replies
Relevance 54.94%

Hello, I was just browsing the internet and then I started getting popups all of a sudden, and I noticed that they all had a common trait.... "Advertisement by Outerinfo." Curse them!! So I did a little digging and I decided to download the Hijack this thingie and here is the log.....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:07:44 PM, on 7/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAFA.EXE
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\System32\CTXFIHLP.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.... Read more

Answer:Pop-UP help by Outerinfo!! HJT long inside!

6 more replies
Relevance 53.3%

Here's how it started.

Let me start off with I have Windows XP Pro and Vista 64 installed as a dual boot on the same drive. So I tried to install Windows 7 RTM on the same drive.
Ran into a problem. Could not install on same drive. So I installed on different drive, look good until I rebooted. It seems there's no way to boot to Windows 7. I see XP and Vista in boot up. But no 7.. It's on that drive but don't know how boot from it. Except it will boot if I have the install disc in the dvd drive. Does anybody know how what why?Click to expand...


So I am assuming that if I use WD Data Lifeguard Tools to format the drive Windows 7 is on and use the option to make the drive so I can boot from it. Then reinstall Windows 7. This will solve the problem?Click to expand...


Messed up won't boot into XP and no option to boot into Vista now. Help
Edit/Delete MessageClick to expand...


I am having a bad problem now. I cannot boot XP. How do I fix it? I tried to use repair with the disc and used the fixboot option that didn't fix it.
Edit/Delete MessageClick to expand...


Let's see. I need to get Windows XP Pro to boot up, I'll worry about Vista and as for Windows 7 it's gone for now. I tried the repair option and used Fixboot. That is why Vista won't boot. I tried and use Bootcfg, it won't let me Add or Rebuild. It's say use CHKDSK I did but I get this message - The volume appear to contain one or more unrecover... Read more

Answer:Help Vista won't boot without disc, long story inside.

This seems to come up every so often. If you repair the current install using the Vista disc, it should boot by itself.
 

10 more replies
Relevance 52.48%

In Windows 7, it will go into this state where it won't update folders automatically, and I have to hit F5, as well, if I go for example, New->Text Document - it will hang the desktop and take like 3-4 minutes before coming back and showing the file.It is like something is preventing or slowing down the refresh of windows explorer.It happens about once a day, sometimes I reboot to see if I can get it to go away.

Answer:Windows Explorer Does Not Refresh Automatically (Needs F5) AND Takes A Long Long Time To Make New File

I've narrowed down more the possible causes of the issue: If You disable the Client for Microsoft Networks in properties of Local Area Connection - the issue disappear (maybe only in my case).

57 more replies
Relevance 52.07%

Hello,

I have recently changed my laptop OS from Linux RHEL 6.4 to Windows 7. Before changing the OS, I have copied all my data (abt 40+ GB) into an external USB drive. When I tried to restore the backup files into the Win7 laptop, it gives an error viz : Filename
too long,  file path too long, exceeded 256 characters, etc.   I have many folders and files to move and will not be able to manually shorten every file name.  


Is there any way/tool from Microsoft, thru which I can seamlessly transfer from my USB HDD to Local drive  ????
~I am the administrator user on the laptop.

==============

Note: After going thru a couple of blogs, I have used the Robocopy which is inbuilt in Win7 and was able to succeed to a greater extent...but not 100%.  There are few files which has been skipped by the command ( as per the copy summary, see attached)
and I am unable identify those exact files which are missed, so that I can manually located them on my USB HDD and copy to the local system.   Is there an way to locate those missing files ???


------------------------------------------------------------------------------

               Total          Copied       Skipped  Mismatch    FAILED    Extras
    Dirs :  &nbs... Read more

Answer:Error: Filename too long, file path too long, exceeded 256 characters, etc: when renaming or copying to/from local HDD to External USB HDD

If you capture the detailed robocopy log then you can see which files were skipped.

3 more replies
Relevance 51.25%

I've got a http://www.windowws.cc/hp.htm?id=9 jack. Can't get rid of it.

Logfile of HijackThis v1.97.7
Scan saved at 12:46:51 AM, on 9/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Raveen\Local Settings\Temp\Temporary Directory 15 for hjt.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com... Read more

Answer:Help needed...log inside

8 more replies
Relevance 50.43%

First of all I would like to thank all members of TSF team for being very informative and helping a lot of people on these forums, the fact that this is my first post only confirms the fact that a lot of information is available already and after reading carefully 99% of problems can get solved without bothering team once more.Thanks for your help an efforts!
Now I'd like to tell about my problem, it may look like one that Bubbawut had.
Some time ago I started to have blue screens of death, I'm no afraid of such things but, it started to be very frequent. Reasons were various. IRQL NOT LESS OR EQUAL, BAD POOL CALLER, unexpected termination of various SYS files, PAGING ERROR in NON PAGED AREA and others. The times and events were different, blue screen could occur while Xp was booting up, or while closing an application, but rather during Processor and RAM straining operations. Also a lot of corrupted data was being written to HDD sometimes corrupting system files so Windows Reinstall was and is very frequent.
my system specs are:

PSU - PSU is 250 watt. sticker was half covered with a supporting metal but I think it's 17 amps on my +12 rail, although power is something I would not suspect at the moment.

Operating System: Microsoft Windows XP Professional
OS Service Pack Service Pack 2
DirectX 4.09.00.0904 (DirectX 9.0c)
CPU Type Intel Pentium 4, 2400 MHz (12 x 200)
Motherboard Chipset VIA Apollo P4X533/PT880
System Memory 512 MB (PC3200 DDR SDRAM)
BIOS Type... Read more

Answer:Help Needed, All info Inside

Sorry for bumping the thread, still no answers.. no ideas? :)

4 more replies
Relevance 50.43%

I am on my friends laptop the now with him as he wanted me to help him wth several problems which i could not deal with, these problems are virus's slow computer, CPU 100% PLEASE HELP Thanks

Logfile of HijackThis v1.99.1
Scan saved at 22:29:00, on 08/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\ATI Technologies\ATI.A... Read more

Answer:Solved: Immediate Help Needed!!! Hjt Inside----->>

16 more replies
Relevance 50.43%

Logfile of HijackThis v1.96.0
Scan saved at 9:18:29 AM, on 8/10/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\Program Files\DownloadWare\dw.exe
C:\WINDOWS\System32\msbb.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\PROGRA~1\COMMON~2\Toolbar\winnet.exe
C:\Program Files\NoAds\NoAds.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\ClientMan\mscman.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\ebkrdr\mediaman.exe
C:\Program Files\ClientMan\msckin.exe
c:\program files\clientman\run\ause3.exe
C:\WINDOWS\System32\SahDownloader.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\mdm.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Inte... Read more

Answer:Help Needed HijackThis log inside

16 more replies
Relevance 50.02%

This keeps flashing up now and then:



This is my HJT log:


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\**********\Start Menu\Programs\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - Global Startup: Slim Multimedia Keyboard.lnk = C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe



I can't see anything there that relates to this problem, can anyone help?

Thanks

Answer:winantivirus pro 2007 pop-up, help needed, HJT Log inside.

Hello Lostnumber,

Please post the log once more, being sure to include the header information.

5 more replies
Relevance 50.02%

I have a Dell D620 running windows 7. In the past couple months I have had a handful of BSOD's at start up. The sign in page comes up and boom Blue Screen. Attached are the dump files.

32 bit OS
Core2 Duo
4GB ram

Answer:BSOD- Help needed Dumps inside

  
Quote: Originally Posted by cerveza1980


I have a Dell D620 running windows 7. In the past couple months I have had a handful of BSOD's at start up. The sign in page comes up and boom Blue Screen. Attached are the dump files.

32 bit OS
Core2 Duo
4GB ram


The Windows Debugging Tools aren't able to access symbols for your operating system files (in particular NTOSKRNL.EXE / NTKRNLMP.EXE / NTKRNLPA.EXE / NTKRPAMP.EXE) from the Microsoft Symbol Server - so that makes debugging them difficult if not impossible.

Please do the following:
- activate/validate the Windows installation at Genuine Microsoft Software
- run sfc.exe /scannow to replace any problem files
- open a support incident with Microsoft to see if they can fix the missing symbols issue ( Windows 7 Solution Center )
- If that doesn't fix it, then wipe the hard drive and reinstall Windows
- don't use "leaked"/torrent builds


Code:

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\032710-18330-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*F:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Unable to load image \SystemRoot\system32\ntkrnlpa.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntkrnlpa.exe
*** ERROR: Module load completed but symbols could not b... Read more

2 more replies
Relevance 50.02%

Hello,

I know for sure that I have ad 234 adware, and I'm sure I have more. This is really killing my internet speed, someone help please. Here is my HJT analysis:

================================================== ================================================== =======================
Log was analyzed using KRC HijackThis Analyzer - Updated on 1/12/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiViru... Read more

Answer:HJT Posted inside, help badly needed

DO NOT! post more then one message on the same subject . I answered your other thread. MOD's please delete/close this thread!

1 more replies
Relevance 49.61%

Hello, new to the forum, think this is great learning for a novice like me and appreciate the help if I could get it here.

I have the AWOLA virus/scarewware on my system. My virus scan picks it up as Generic FakeAlert.b

A warning is posted on my right hand lower toolbar that says "Windows has detected syware infection. It is recommended to use a special antispyware to prevent data loss etc.."

I went through the 5 steps posted here and created this log, I hope I didn't screw this up.

Deckard's System Scanner v20071014.68
Run by Jeff on 2008-01-12 22:18:17
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
70: 2008-01-13 05:18:26 UTC - RP1052 - Deckard's System Scanner Restore Point
69: 2008-01-12 03:19:33 UTC - RP1051 - Removed QuickTime
68: 2008-01-12 03:08:02 UTC - RP1050 - Software Distribution Service 3.0
67: 2008-01-12 02:51:28 UTC - RP1049 - Spybot-S&D Spyware removal
66: 2008-01-11 03:57:49 UTC - RP1048 - Spybot-S&D Spyware removal


-- First Restore Point --
1: 2007-10-16 05:41:31 UTC - RP983 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Mic... Read more

Answer:AWOLA scareware help needed, Log posted inside.

Bump, any help would be appreciated. thx

- Installed Java 6.4

19 more replies
Relevance 49.61%

Please help. I recently removed a virus/malware problem, but I think there is still a problem. My pc will send and recieve lots of data by itself.
I did a ewido scan, Ad-Aware scan and a SPYBOT Search & Destroy scan in xp safe mode.
Back in Windows I did a HighJackThis scan.
Here are my Ewido scan and HighJackThis reports below.

Thanks for all the help.
CactusJack
=========================================================

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 09:00:25 AM, 2006/12/17
+ Report-Checksum: E99D388A

+ Scan result:

C:\!KillBox\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup
C:\avenger\backup.zip/avenger/sysfind.exe -> Trojan.Dialer.hz : Cleaned with backup
C:\avenger\backup.zip/avenger/sysmon.exe -> Downloader.Small.crc : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][2].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\user\Desktop\3file.tmp -> Downloader.Small.buy : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\apef.exe -> Downloader.Small.crc : Cleaned with backup
C:\Documents and Set... Read more

Answer:Solved: Help needed with possible malware (reports inside)

12 more replies
Relevance 49.61%

User name: chipbutty
email address: [email protected]
Web browser: Internet explorer.
I think I accindently downloaded an msn virus or something when I accepted a picture over msn. I have tried to delete the file but I'm still having problems with msn, when I sign in it opens chat windows with all of my online contacts and tires to send them the same file and does let me talk to my contacts.
Here's my Hijak log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:28:16, on 18/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files... Read more

Answer:Solved: msn virus, help needed please! hijack log inside

10 more replies
Relevance 49.61%

Hello again. Another big thanks for helping clear out my computer. I've got another one that may need cleansing as well. Any help would be appreciated. Many thanks in advance.

Logfile of HijackThis v1.98.0
Scan saved at 3:11:48 PM, on 7/2/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINNT\system32\devldr32.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Navnt\POPROXY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Navnt\navapw32.exe
C:\PROGRA~1\MICROS~3\Office\OUTLOOK.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\taskmgn.exe
C:\Documents and Settings\Dan\My Documents\Personal\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microso... Read more

Answer:[Solved] Assitance needed - Hijackthis log inside

12 more replies
Relevance 48.79%

Hi everyone, I am having a great time exploring Ubuntu, having installed it as a download to Windows7 with Wubi. The concern I am having now is, is it ok to run the 'gufw' firewall for Ubuntu because I still have Kaspersky Internet Security 2012 in Windows. And I would also feel safer with an antivirus for Ubuntu too for online banking etc. Apparently, I have read that Windows recognises Ubuntu as a different OS whereas in fact it is only a download and that is what I can't relate to this issue.
Read more: http://www.pcadvisor.co.uk/forums/28/windows-7-help/4169329/windows-7-os-with-ubuntu-virtual-drive-installed/#ixzz25LTFPauV

Answer:Ubuntu installed inside Windows 7 ... antivirus needed or not?

wubi is simply an installer for Windows. Once the installation has completed and you select Ubuntu, you are actually using Ubuntu (as opposed to Windows). Therefore, I see no reason why you should not use the gufw firewall. However, if you're using a router for your Internet connection, it should have a built in firewall, so a further firewall shouldn't be necessary.
As regards anti-virus software, it's not necessary at this present time. Whether that will alter in the future, who knows, but Linux is simply not at risk in the same way and you don't have to nursemaid it like Windows.
If you're really unhappy about that, then clamav is a powerful Linux anti-virus application, but be aware, you won't have fancy a GUI, as it's written primarily for Linux email servers.
I've been using Linux for about 5 years now (for all intents and purposes as an exclusive system) and have never needed to use anti-virus software on my desktop production machine. But I do have it on my email servers, as Windows infested emails are still very much the norm. This is purely to protect my Windows users connecting to the servers.
Use Ubuntu, relax and enjoy :-)

5 more replies
Relevance 48.79%

Hello againI am really desperate for help the list below is what I have got to build a pc following the 3 part series that was pc advisor magazine. Asus P4T533-RAID Motherboard Intel Pentium 4 2.66 GHz Boxed PC533 Enermax PSU ATX 431W (P-4) Microsoft OS Windows ME Cordless Desktop DeluxeSanyo-Denki 80mm Fan - 3 Pin (FG-001-SY) Alpha PAL8942 T Heatsink LiteON LTR-52246S 52x/24x/52x CD-RW Freecom Classic 4x DVD+R/RW - Internal Coolermaster ATC-201 Case Hercules 3D Prophet All-In-Wonder 9000 Pro 64MB 256Mb Rambus PC1066 32-bit RDRAM (RIMM4200) Barracuda ATA V 120GB UDMA100 HarddriveEthernet cardFloppy Drivepci card for dailup telephone service ( sorry forgot what it's called) This is what I have installed I connected all cables to the motherboard. The last one I installed was the floppy drive did all the cables when I tested the pc to see if it was OK It wasn't there was smoke coming from inside the case.Asus P4T533-RAID Motherboard Intel Pentium 4 2.66 GHz Boxed PC533 Enermax PSU ATX 431W (P-4) Cordless Desktop DeluxeSanyo-Denki 80mm Fan - 3 Pin (FG-001-SY) Alpha PAL8942 T HeatsinkHercules 3D Prophet All-In-Wonder 9000 Pro 64MB 2 X 256Mb Rambus PC1066 32-bit RDRAM (RIMM4200) Ethernet cardpci card for dailup telephone serviceFloppy DriveCan anyone help me please a dare not touch incase it goes up in flames!!The PSU Unit that I order from komplett came with a two pin socket for the mains like the one you see on some shavers I purchased a mains computer cable from staples they tol... Read more

Answer:help needed fast smoke coming from inside pc case

Oh dear..... This sounds like you could have your hands tied for a couple of hour's, make yourself a cup of tea then we'll go through it step by step

10 more replies
Relevance 48.79%

Hello. I've tried everything I could but there is no way I can open any ports. They don't even open with DMZ enabled... Either I'm doing something wrong or my router is malfunctioning.
I'm under Windows XP. My Windows Firewall is DISABLED (Firewall). I've set up a static IP address (Static IP). My antivirus is NOD32 2.5.

My router is a Linksys Wireless WRT54G v2. I'm using Firmware: DD-WRT v23 SP2 (09/15/06) mini. I am connected through a Cat5 cable (not using wireless). I've configured the port opening (Port Range Forward).

My cable modem is a Motorola SURFboard® Cable Modem SB5120 (Modem). My internet provider is Suddenlink (Speed Test Results).

Port Scans:
(Using www.whatsmyip.org/ports/)
(Using www.amule.org/testport.php)
(Using www.canyouseeme.org/)

I've even tried restoring the router to Factory Default but with no luck. I've scanned my computer for viruses/spyware/ect already. If you need any other information, don't hesitate to ask. Any help is appreciated here. I've lived with it for almost 2 years now, all my friends have tried to solve this problem with no success. I figured it was time I asked the crowd here. Thanks in advance.
 

Answer:[Help Needed] WRT54G - Cannot Open Ports (Details inside)

8 more replies
Relevance 47.97%

i recently got a new computer with WIN7 Home , 32 bits .

These vid formats dont work:

mkv

(one of the mkv files had the phrase "h.264-ac3" in its name, if its important for u)


ogm

rm files

flv

one vid file played with video but didn't play with sound - it was .mpg

one file didnt play well - was .mpeg , had slow downs


AND the following photos didnt open -

GIF images, and by that i mean, those gif image who "move", which are like vids but without sound and the Windows image opener thingy used to open these normally on my other computer (who had Windows XP)
Gif images open usually with the internet explorer (even though its not my default browser) and there they are "played" ok (meaning they are displayed flawlessly)

One image is catagolized by my pc as "File". meaning the part that supposed to say GIF or JPEG says "file". it is a moving image which always asks me how to be opened, NEVER allowing me to tick the "always use this software to open this type of files". it is displayed well on the Internet explorer.

Just in case i will mention that i have IE9.

so my questions are what should i download as codecs, formats, whateverr? sound codecs, and vids, how about the k-lite ? i just dont want to clug my pc with codecs. so if u know what i need to DL to make the pics work on the windowd image displayer tool thingy and make all the vids play well, i will appreciate it.

... Read more

Answer:GIF imgs dont open, vid formats needed (full list inside)

VLC media player.will play just about anything

2 more replies
Relevance 47.97%

As of a few days ago when I was searching for HTML codes for my website and opened a google search result, my computer has been running MUCH slower, crashing all the time, opening Internet Explorer ad windows on its own even when I don't have IE open to sites like bigdiscountbuy.com, blow-outsales.com, buyer-shabit.com, partypoker.com, realcoupon-s.com, etc.Also, when I do control alt delete, I see all sort of new programs that haven't been there before. Every time I see them I search them and delete them, but they're just replaced by new programs I've never heard of. I ran Adware, deleted everything it found, ran a full system scan with Norton Anti-Virus, deleted everything it found, and ran Spybot, but it froze as I was deleting the files. It's impossible to keep my computer running for more than 20 minutes, then it crashes. Sometimes it even comes up with a black screen and automatically restarts somehow without me doing anything. It's making it pretty much impossible to use my computer, and if anyone could help, it would be greatly appreciated. Thanks in advance,-AlecHere's my HijackThis log:Logfile of HijackThis v1.99.1Scan saved at 5:57:17 PM, on 2/28/06Platform: Windows 98 SE (Win9x 4.10.2222A)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\MST... Read more

Answer:Ahhhh, Huge Problems, Help Needed Asap. Hijackthis Log Inside. Urgent!

Hi Alex, and welcome to the forum. This looks like the bad one: O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\SYSTEM\wintask.exe read about it here: http://www.sophos.com/virusinfo/analyses/trojdloaderna.html Not one of the worse, it is still bad enough, review the information under all tabs to see how it may have compromised you system and perhaps how you got it. Let's check you out since this is a downloader, like this:1) This one: O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe If it is still in Add Remove programs, look at these links:http://www.clickz.com/news/article.php/3561546http://www.greatis.com/appdata/u/v/viewmgr.exe.htmhttp://www.spywareinfo.com/newsletter/arch...4.php#viewpoint2) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\SYSTEM\wintask.exeClose all programs but HJT and all browser windows, then click on "Fix Checked"Enable hidden files&folders..reverse the process when finished.http://www.xtra.co.nz/help/0,,4155-1916458,00.htmlRIGHT Click on Start then click on Explore. Locate and delete these items:C:\WINDOWS\SYSTEM\wintask.exe >>> fileIf you don't have a good cleaner, use this one with these instuctions:Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions htt... Read more

5 more replies
Relevance 47.15%

I need a A to B usb cable but its needs to be about 20 metres in length is this possible?

Answer:VERY long usb cable needed

Only using 5m "Reapter" cables. click here You can chain upto 5 of them.click here USB 1.1 Line Extender (up to 150 feet) Uses an Ethernet cable to achieve the distance.

3 more replies
Relevance 46.74%

Right, have a long running problem

upon start up i get an error message.

the error message is for 11228.ex (but that increases on every start) and that it cant run cause i don't have xpat.dll on my system. I know for a fact that i have xpat.dll cause i found it. I have a feeling this is a Virus or something but it is doing nothing bad to my comp (no pop ups ar probs)

here is my HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 20:14:18, on 17/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\WINDOWS\system32\sol.exe
C:\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{CFBF... Read more

Answer:Long running problem, help needed!!!

9 more replies
Relevance 46.74%

I have a external my book fat32 formated and a new mybook ntfs formated external as well.  Now when I copy my files from the fat32 to the ntfs external all files copy fine but some give that destination location file characters are too long, meaning that the file names are too long.  Now I could change the file names but that would conflict with programs that need that file name.  I am using vista ultimate and would like to copy all the files over from the fat32 to ntfs so I can reformat the fat32 to ntfs.  The files got on the ntfs from a simple drag and drop from my IDE NTFS internal hard drive. I hope you guys to tell me what to do. Thank you :)

More replies
Relevance 46.74%

well i unlocked a system locked (pad lock symbol) folder by accident looking for something else and since than the following issues are observed. and i don't remember the folder =(

when the system boots it will boot very slowly. the screen will turn black with the mouse pointer visible for
maybe 30 seconds? than the desktop will appear as normal. all systems once booted appear to be normal.
i already did these steps attempting:
system restore....no points past date of issue.

Defragged both disks just in case.

Ran CC cleaner on the registry and the standard caches.

ran scan now tool and found one issue listed below:

C:\Windows\system32>sfc/scannow

Beginning system scan. This process will take some time.

Beginning verification phase of system scan.
Verification 100% complete.
Windows Resource Protection found corrupt files but was unable to fix some of th
em.
Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
C:\Windows\Logs\CBS\CBS.log

cannot view log even when i give admin full access under property's.

Answer:long boot....unlocked system file by accident cant remember what file

How about doing a System Restore to before you made the change?

2 more replies
Relevance 46.33%

A month or two ago I started noticing that when I try to save files to HDD from Opera it takes about 4 seconds for the (explorer) file menu to appear and let me save it.

Now I noticed the same in Subtitle Workshop and Irfanview, only that in these it takes even longer, like 7 seconds, for the load file menu to appear after I click on the "open file" icon.

Some other programs, like VLC and Winamp, don't have this problem.


Any clues?

Using Win 7 64bit, BTW. Everything updated.

Answer:File load and file save menus take a long time to appear

  
Quote: Originally Posted by eyo


A month or two ago I started noticing that when I try to save files to HDD from Opera it takes about 4 seconds for the (explorer) file menu to appear and let me save it.

Now I noticed the same in Subtitle Workshop and Irfanview, only that in these it takes even longer, like 7 seconds, for the load file menu to appear after I click on the "open file" icon.

Some other programs, like VLC and Winamp, don't have this problem.


Any clues?

Using Win 7 64bit, BTW. Everything updated.


Are you seeing a thin green bar at the top of your screen in Windows Explorerer?

2 more replies
Relevance 46.33%

Hi All,

I've got a problem creating long named folders or files on a Linux network share.

I can see and log in to the share without any problems, but if I try to create a folder that is longer than 8 characters, I get the following error message:
The drive that this file or folder is stored on does not allow long file names, or names containing blanks or any of the following characters: \ / : , ; * ? < > |

Also, I can not see files on the share that have long names...

I only have this problem when I use my Windows 7 machine. XP and Ubuntu work just fine.

I am using Windows 7 Professional.

Help?

Answer:The drive that this file or folder is stored on does not allow long file names...

Anybody???

1 more replies
Relevance 46.33%

someone deleted a file that is buried in a bunch of folders with a long name. we need to restore it. i went into previous versions and found the file but i cannot do ANYTHING with it because the file name is too long. all the tools out there to fix this are for files that actually exist (this one technically doesn't because it shows up in previous versions).

how do i restore this?!
 

Answer:the file name is too long. deleted file, trying to restore previous version.

have you tried copying/restoring to a different location first?
another thing to try would be to map a network drive to 1 folder before the folder where the file exists then try the restore previous version
 

2 more replies
Relevance 46.33%

My server is a Frankenstine computer. MOST parts have been swapped out at one time or another.

The last upgrade to the machine was a good old fashioned cleaning, and case swap from a mini tower to a full tower.

ALL the drive bays that are within reach of the cables are used, but I have a few available spaces that are out of reach, and the system has open connectors for more drives.

Where can I get SATA cables [data is most important, I think I also need power extenders] that are long enough for full towers on the cheap? The SATAs on the board are 1s, but it's a home server, so they are fast enough, if it makes a difference.

Answer:LONG SATA cables needed [ok, wanted]

You can probably get them from Newegg, but I really like Performance PC's. Wide selection, good prices on some things and they do full custom work if you want. Performance PC's

7 more replies
Relevance 46.33%

Since this is my first gaming PC, I know basically nothing about how long a graphics card will last before needing an upgrade to keep playing newer games. I'm getting a bit worried with the 6000 series already out, and I'm still using a 4000 series. I have the money, I just do not want to buy a new card until it will actually do me some good.

Answer:ATi Radeon HD 4890 - How long until an upgrade is needed?

Hello there, mate

Well, the HD 4890 is similar in performance to a GTX 280, it's better than a HD 4870 of course but is less powerful than a HD 5830, GTX 285 and GTX 460.

You'd need it if you run games at extremely high resolutions with extremely high details on graphics, or if you're an enthusiast

The HD 6900 Series are actually top on the line, HD 6970 is between the GTX 480 and the GTX 570.

But again, if your games are perfect now, you don't need to upgrade

Also, HD 4000 Series supports Dx10.1, HD 5000/6000 series have full Dx11 support, that's another thing to have in mind.

9 more replies
Relevance 46.33%

Can someone check my HijackThis log, and let me know if anything can be removed! Anything that can help make my computer go a bit faster can only be a good thing!!

Logfile of HijackThis v1.97.7
Scan saved at 20:08:33, on 04/06/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\IMSECURE\IMSECURE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\DESKTOP\DOWNLOADS\HIJACK THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\PROGRAM FILES\SYSSHIELD TOOLS\INTERNET ERASER\PKEXT.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 -... Read more

Answer:Only a Quick check needed, shouldn't take long!

Looks ok, keep your temp folder empty, scandisk and defrag.
 

1 more replies
Relevance 46.33%

My question is a security question.
If someone has a file on his/her computer that contains personal/secure information, for example a text file that contains passwords and account numbers, or an audio recording of a conversation where account numbers and passwords were spoken out loud...  Is it possible for fragments of the secure file to end up getting stuck inside of another file or group of files on the same pc...making it possible for someone to reconstruct the secure file from the fragmented pieces and/or view its original contents?  Or could it be possible even for the entire secure file to somehow end up inside of another larger file on the same computer...making it easy for someone to view the secure information....(by the way I only used a text file or an audio file as an example...it could be any file containing secure data)...My simplified concern is this...If you have a file that contains information that you want to keep secure...is there anyway that pieces of this file, if not the whole file it self, could end up inside of another file or a group of files on the same computer that the file containing the secure information was created on?...thus making it a security risk to even share mp3s on a computer that ever had any secure information on it...since maybe there'd be a change ur credit card numbers and passwords might somehow end up in one of those mp3s that ur sharing in a peer to peer file sharing program online.....or do things not work like tha... Read more

Answer:Can a File somehow end up inside of another file/files

It all depends on the program you are using to access the files. For example, Windows (starting from XP) creates a hidden file thumbs.db that contains thumbnails of all the images inside a folder. If you delete the original pictures through some other program or command line, and do not open the folder in Windows Explorer, this file still stays there. If you share the folder, this file gets shared too. Your information gets leaked.
 
If you use a computer for banking online or shopping online (any kind of financial transaction), then do not ever use that computer for P2P file sharing.

1 more replies
Relevance 46.33%

I have a jar file that contains a Java class and a txt file. My program can read from the txt file (using URL) but does anyone know how I can write to the txt file? I need it to overwrite what is already in there each time. Thanks
 

More replies
Relevance 45.92%

Hello,   I am trying to purge a cookie from my windows system and it has a very long file name. When trying to rename or delete it, I get an error message of File Name Too Long. It seems as though the creator of this cookie intentively created it to be able to be saved to a system, but a pain to remove.   Anyone know of any way to destroy this long file name pest without reformatting the hard drive?  Cookie washers etc also cant get it to budge!!!  If I can get this file name smaller, i am thinking that I can delete it, and I am an admin of this system, so its not a permissions issue causing this.Thanks,Dave

Answer:Trying to delete a temporary internet file with long file name

Try Unlocker: http://ccollomb.free.fr/unlocker/

4 more replies
Relevance 45.92%

I am running windows XP with my desktop and have recently added an external hard drive via usb (MD ELEMENTS 1 Terrabyte).

I copied over the avi files etc that I wanted to put across, but now, when I try and copy a folder to a folder on this external drive, I get the error:

The Destination does not support long file names. Please enter a filename for this file.

Anyone have any ideas pls????? There are already files on there with longer names.....?
 

More replies
Relevance 45.92%

i dont know if anything is wrong with my PC but some weird stuff is happening like cable modem starting to run very slow when watching video. also, could someone tell me if i have 2 antivirus programs running at the same time. thanks all

Logfile of HijackThis v1.99.1
Scan saved at 5:35:16 PM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\AMERIC~1.0A\waol.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\AMERIC~1.0A\shellmon.exe
C:\Program Files\Viewpoi... Read more

More replies
Relevance 45.92%

I have received an mail that has a RAR attachment. The contents of the email are such that it can only have been written by someone who knows me, i.e. its not been generated automatically and the suggested contents could be useful to me. Unfortunately my reply to him bounced as his email company saw me as spam. Is there any way I can view the contents of a RAR file without actually opening it and possibly exposing my PC to some sort of nasty surprise?

Answer:Looking inside a RAR file

I wouldn't risk it.
"Unfortunately my reply to him bounced as his email company saw me as spam"
So is this someone you normally have no problem emailing? Seems funny if suddenly your emails are seen as spam. Have you tried sending a plain text email with no attachements to him?
This info might be help you decide about opening it click here

6 more replies
Relevance 45.92%

Just a quick question, is there an application to sort through the contents of an .exe file? And will it just display coded gibberish? What sort of language are .exe files written in? Is is possible to edit .exe files? Sorry, questions, questions....Thanks ;)

Answer:How can I look 'inside' an .exe file??

I would think open with notepad or editor.

5 more replies
Relevance 45.92%

alrighty am going to get a new graphics card after my old one conked out. please could you tell me which would be better, a radeon x850 or a x1300? i read the x1300 was a mobile series (like for laptops?) so would an x850 outperform it?

My systems bout 3-4 years old so im limited by what i think is a 250-305watt ps

also i dont know how to find out if my comp has a pci-e port (my last gfx card was an agp 9800xt till the fan bust, but at the mo its got an ancient rage 128 pro in there) makes counter strike source look like quake at about 4fps!

Any help very much appreciated guys
 

Answer:Solved: okay shouldnt take long to answer (opinion needed)

8 more replies
Relevance 45.92%

Just reformatting a friends pc, then realised no mobo disc, & she doesnt have it either.
Abit website is no more, and cant find these drivers anywhere, as its an old one.
ABIT VA-20

Does anyone have the drivers for this? Inc VGA & Sound?
I know its a long shot, but thought I would ask you never know,
Chrz
 

Answer:Motherboard Drivers needed - This is a long shot - ABIT VA-20

7 more replies
Relevance 45.92%

Hello folks:I am trying to copy a folder to another disk -- on Windows 7.The folder has subfolders and files, and this way there are many hierarchical subfolders. So the files down at the bottommost subfolders have really long path-names from the root folder. That is: the path-name, e.g., folder\sub-folder\sub-sub-folder\.....\file is quite long.Now, the standard drag and drop (or copy and paste) does not work satisfactorily. It complains that the path-names are too long. I would rather not move the affected folders and files higher up in the hierarchy to shorten the path-names because logically they belong to where they are now.So, the question is if someone really knows how to copy such hierarchically deep folders. I am not sure but someone told me that the *Copy/Paste* cannot handle path-names longer than 164 characters. My file path-names are much longer than 164 characters.Also, I tried *Robocopy* (available from Microsoft tech. site) which supposedly copies files with long path-names. The problem I ran into here was that the *number* of folders and files in the destination drive is *not* the same (after copying) as that at source. So, I really have no faith that *every* folder and file has been copied by *Robocopy*.If someone has some tips for me I would greatly appreciate that.Thanks very much.nhmxxx

Answer:Help needed with copying files with very long *pathnames* -- plz & thnx!

In Windows 7 and Vista one can synchronize two folders. Have you looked in this as a possible solution?This may provide some helpful information.http://windows.microsoft.com/en-US/windows-vista/Sync-Center-frequently-asked-questions

5 more replies
Relevance 45.92%

I was told to move my thread over here and post a hijack this log as well as the avast log, they are at the bottom of this thread:

A few days ago I was watching TV on my computer (Media Center) when everything went black and froze up for 5+ minutes. I had to do a Ctrl-Alt-Del to get it unfrozen. When I re-started it I got a message saying "The system has recovered from a serious error" or something like that. I immediately ran Spybot and Avast anti-virus. Spybot came back clean and Avast came back with a worm/virus and one adware which I moved to the chest. The same day the latest Windows Update downloaded and installed.

Ever since all that happened my internet is either veryyyy slow or comes back that it can't load the webpage I requested. When I get the can't load I click on refresh and bang the page usually comes up instantly. Just to give you an example when I tried to register on your website the first 2 times I clicked on submit registration I got the page cannot display after waiting like 5 minutes each time then finally the 3rd time it went thru. This is just so frustrating and I'm not sure where to look or what to do to troubleshoot the problem . I did run CCleaner and deleted temp files and cookies from my IE. We have a second computer in our house hooked up to the same cable via router and there are no problems with that computer at all. I also tried to do a system restore and it won't do it...... it goes thru all the steps then when... Read more

Answer:Solved: HELP NEEDED Web pages take super long or won't load at all

8 more replies
Relevance 45.51%

Major things happening the last few days. 1) insufferable amount of pop-ups (IE powered by Comcast) 2)over 100 shortcut messages (EXAMPLE: MORZE5.lnk refers to a location that is unavailable) at boot-up that have to be clicked through. I do see these on the HJT log and know you will know how to help. 3) Computer crashes, blue screen, white screen, you name it, several times a day.
What I did BEFORE I ran this log. I updated Adavare 6 and ran then deleted all it said, then ran spybot and that was all clear.
Here is the HJT log:Logfile of HijackThis v1.97.7
Scan saved at 10:49:36 AM, on 4/1/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\TREND PC-CILLIN 2000\PCCIOMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\TREND PC-CILLIN 2000\POP3TRAP.EXE
C:\WINDOWS\SYSTEM\HPZTSB01.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\TYPE32.EXE
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOTASKBARICON.EXE
C:\WINDOWS\WBLCG0L5.EXE
C:\PROGRAM FILES\KODAK\KODAK EASYSHARE SOFTWARE\BIN\EASYSHARE.EXE
C:\... Read more

Answer:PROBLEMS HJT log file inside

16 more replies
Relevance 45.51%

Hi i am using windows vista ultimate 32 bit and yesterday my computer went incredibly slow for seemingly no reason so i opened task manager and saw that my CPU usage was at 100%,after looking through the list of processes to see what was being such a resource wh0re, i couldn't see any processes that were using alot of cpu power so i downloaded "Process Explorer" and found that my problem was something called "Hardware Interrupts" which was (and still is) using 88-100% of my cpu how can i fix this problem? PLEASE help as i am completely stumped by this one.oh,and by the way,the 100% cpu usage is constant from the minute my PC is turned on,even with no apps running it stays at a constant 100%.

Thanks,
Tom

Here is my log file:
Deckard's System Scanner v20070328.36
Run by Tom on 2007-04-07 at 21:57:40
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
12: 2007-04-06 20:49:00 UTC - RP59 - Installed DriverMagic
11: 2007-04-06 14:00:46 UTC - RP58 - Installed Driver Detective
10: 2007-04-06 10:00:24 UTC - RP56 - Restore Operation
9: 2007-04-06 08:51:57 UTC - RP55 - Windows Update
8: 2007-04-05 23:19:12 UTC - RP54 - Restore Operation


-- First Restore Point --
1: 2007-04-04 09:51:03 UTC - RP47 - Removed Autodesk DWF Viewer 7


Backed up registry hives.

Performed disk cleanup.


-- HijackThis (run as Tom.exe) ------------------------------------... Read more

More replies
Relevance 45.51%

Logfile of HijackThis v1.99.1
Scan saved at 12:01:59 PM, on 5/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\ItBill\itbill.exe
F:\New Programs\ITunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
F:\New Programs\iPod\bin\iPodService.exe
F:\New Programs\ITunes\iTunes.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\owner\Desktop\Misc\Hi Jack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://awesomestart.com/killola/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r4.attbi.com:8000
R1 - HKCU\Softwa... Read more

Answer:MOVIELAND!!! Please help... log file inside

8 more replies
Relevance 45.51%

Hi,

I am setting up a backup system for my pc, backsup to a remote machine via ftp. The files to backup will be compressed into a zip file and then backed up to the remote machine. My question is, if my pc gets infected with a virus and those files backed up to the remote machine, will the virus infect the remote machine as well ? (if the files are not unzipped on the remote machine & both machines running on windows Xp pro). Appreciate any help or suggestions in this.

Regards
Sudhi

Answer:Virus inside a rar or zip file

No, malware inside a ZIP or RAR file can't infect a machine, unless you extract the malware (and execute it).

So in your case, the simple fact of storing a ZIP backup on a remote machine will not infect that remote machine.

That's why malware researchers share malware samples in password-protected ZIP files.

2 more replies
Relevance 45.51%

We are supporting business offices systems running Windows 7 SP1 in 64 bit. System RAM is 16GB and HD is 200GB.
In one of the partition (Drive F), a folder appeared (Aug 19, 2015), the folder name is 973d3e99d0b18144c2ffb4c55570d78a (we can change it to junk or some such). Inside it has a cabinet file called SFX.CAB created same date and file size is 0.
Can you please tell me what this is? and should we remove it?
Thank you

More replies
Relevance 45.51%

I was referred to start posting on this forum with my logs. I'm not quite sure what's wrong, but I'll assume one of you wonderful people will.if you need any background information it's all included here: http://www.bleepingcomputer.com/forums/t/263302/not-able-to-run-hjt-or-any-anti-virus/and I'm not able to get DDS or HiJackThis to run at the moment, I can't download from this computer (it disappears.) and my fiance' isn't here to download from his.here are the logs from the other forum.From a comand prompt:Volume in drive C is COMPAQVolume Serial Number is 70BB-FF3BDirectory of C:\Windows\ERDNT\cache04/11/2009 02:28 AM 177,152 scecli.dllDirectory of C:\Windows\ERDNT\cache04/11/2009 02:28 AM 592,896 netlogon.dll2 File(s) 770,048 bytesDirectory of C:\Windows\System3204/11/2009 02:28 AM 177,152 scecli.dllDirectory of C:\Windows\System3204/11/2009 02:28 AM 592,896 netlogon.dll2 File(s) 770,048 bytesDirectory of C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e11/02/2006 05:46 AM 176,640 scecli.dll1 File(s) 176,640 bytesDirectory of C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f1201/19/2008 03:36 AM 177,152 scecli.dll1 File(s) 177,152 bytesDirectory of C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e04/11/2009 02:28 AM 177,152 scecli.dll1 File(s) 177,152 bytesDirectory of C:\Win... Read more

Answer:Peek.bat file inside

Hi My name is Extremeboy (or EB for short), and I will be helping you with your log.We apologize for the delay of response. If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems just let me know in your next reply or simply post a Hijackthis log.For your next reply I would like to see:-The DDS logs---DDS.txt and Attach logs-RootRepeal logs-Description of any remaining problems you may still have.Thanks again and we apologize for the delay.With Regards,Extremeboy

3 more replies
Relevance 45.1%

I'm getting swamped with business and need a good business partner. I've tried a few guys and so far I can't find anyone reliable enough to trust my customer base to. So if anyone wants to help out with some small business/ home computer work just let me know.

Few key points
* What skills can you bring to the table
* Roughly, what is your availability (full time student, part time student, full time worker, etc)

The pay is pretty good and my clients are all great people.

To the ops...I'm just throwing this out. So if you need to move this thread just let me know.
 

More replies
Relevance 45.1%

are keyloggers part of a program or can they be tiny like viruses. also can i keylogger or a threat be in a .dll file

Answer:Can a keylogger be inside of a file smaller then 3mb?

Well - designed keylogger can fit in few hundreds of bytes. And of course dll can host it.

2 more replies
Relevance 45.1%

I have a fairly large Fortran 77/90 & C program, compiled using Compaq Visual Fortran 6 & Microsoft Visual C++ 6 under Win XP.  On a particular test case it generally executes ok when invoked outside a batch file, but always fails when invoked from a particular batch file.  It stops on a Fortran 90 Allocate statement, but does not return the STAT result coded into that statement.  Seems to relate more to how much storage has been allocated rather than to the particular array being allocated, because I can reorder the allocation of different arrays and the stop does not occur on the same array.Although this is a large body of code, the test case is small and should not be requiring a large amount of allocated storage.I have tryed cutting the batch file down to just the statements that occur before invoking the EXE file (which are SET /P, ECHO, COPY, DEL, IF EXIST), then running the truncated batch file, then executing the EXE outside the batch file.  The EXE also fails in that usage.Any ideas on what I should be looking for to fix this?

More replies
Relevance 45.1%

Without using any Nero or file burning software, can Windows XP itself supports simple file copying to disc. Not that I know of, but i have a user who can do these.

1. select a file, right click and press SEND TO the burner
2. simply copy and paste the file to the burner
3. reopen a file on a disc, edit it, and then can save it back onto the disc.

Strange, anyone welcome to comment. Thanks.
 

Answer:File burning inside Windows XP only

10 more replies
Relevance 45.1%

Hi. I'm posting this in regards to a friend who has a trojan on his computer. He ran Webroot system analyzer and it detected a trojan, but no other software is picking it up. Here is his log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:45 PM, on 7/13/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Digsby\Digsby.exe
C:\Users\Pete\Desktop\SystemAnalyzer\SystemAnalyzer.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com... Read more

More replies
Relevance 45.1%

I got caught this morning. Hungover, tired, and just plain dumb.

"A friend" sent me a file. Supposedly some great an amazing pics of her new baby. On offer was a .zip file which I downloaded. Within there was a "picture" only it was xxx.jpg.xxx.com, so in fact it was really a .com file.

I ran this file (yes, I am dumb), and now my MSN sends out endless requests to other people to download these files from me which will infect them.

Perhaps my saving grace is that I use WinPatrol. When I ran this it detected changes to my registry startup areas which I told it to remove. Once I had rebooted I am no longer sending out nasty messages (so far, its hard to say exactly how often the messages are sent). However, the virus files are still on my machine in an unknown location.

I do still have the original infected file that I was sent which can be made available for analysis.

I am running XP Pro SP2, and use Eset NOD32 V3 with most recent updates. The bug went straight through this like a knife through butter. I have updated and recanned my machine both locally, and with Eset's online scanner. Nothing found. Eset misses the install files for the virus, and also the running virus (my friend's machine is still actively spamming the virus files out).

Hijack log as follows:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:02:39, on 08/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode:... Read more

Answer:MSN Hijacked by .com file wrapped up inside .zip

8 more replies
Relevance 45.1%

hello everyone im having numerous pop ups and its slowing down my machine big time for virus scanners and random pop ads. Here is the Hijackthis log file. What do you think?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:21 PM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\... Read more

More replies
Relevance 45.1%

i dont know y but from last few days i m getting this thing whenever i open my MY COMPUTER icon ..........even on some other folders i do get the same thing but after custominzing the folder it works fine below is the screen capture



can any one tell me how to remove this thing

Answer:How do i remove this (Hijack This Log file inside)

We'll require a HijackThis log from you.

But before you post your log at the HijackThis Log Help forum, please read through the sticky first.

16 more replies
Relevance 45.1%

Large downloaded file often come in parts I understand the method ..extracting these parts are where I get confused I often see many parts or one zip file..or so..its the different ways of extraction where I get confused..when I select say a large compressed one it extracts to show a rar or series of rar file which then have to be extracted to show the compressed data..it seems a simple task and hard to explain. I am sure I am not re-inventing the wheel here..but I need help..anyone..

Answer:How to extract rar file that have zip files inside

You will see the files named R00, R02, R03 etc.. all you need to do is start the extraction of R00 and the rest should be extracted automatically...

4 more replies
Relevance 45.1%

Guys im in serious need of help no idea whats wrong with my computer any help would be helpful can anyone check my htj file? tell me what they think i got a 3meg connection and it takes me 10 minutes to open up a site i used showtraffic program and its sending loads of spam mail out i cant stop it.

Logfile of HijackThis v1.99.1
Scan saved at 10:39:00 PM, on 7/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\home\LOCALS~1\Temp\Rar$EX00.360\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&... Read more

Answer:computer using all my bandwidth htj file inside

will someone please help?
 

1 more replies
Relevance 45.1%

ok i have windows vista home premium. i am having link redirect problems. not just from google. basically any link i click redirects me. i ran gooredfix.exe deleted what came up still have problems. ran malwarebytes and still having trouble. so i am posting a log file from hijackthis. i would love it for someone to please check it out and give me some advice thanks.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:18:28 PM, on 7/15/2009Platform: Windows Vista SP2 (WinNT 6.00.1906)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:Windowssystem32sdra64.exeC:Windowssystem32Dwm.exeC:WindowsExplorer.EXEC:Windowssystem32taskeng.exeC:Windowstemp1154251.tmpC:Windowssystem32taskeng.exeC:WindowsSystem32igfxtray.exeC:WindowsSystem32hkcmd.exeC:WindowsSystem32igfxpers.exeC:WindowsRtHDVCpl.exeC:Program FilesSynapticsSynTPSynTPEnh.exeC:WindowsSystem32rundll32.exeC:Program FilesDropboxDropbox.exeC:Windowssystem32igfxsrvc.exeC:Program FilesSynapticsSynTPSynTPHelper.exeC:Program FilesMozilla Firefoxfirefox.exeC:Program FilesTrend MicroHijackThisHijackThis.exeR1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.comcast.net/R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.toshibadirect.com/dpdstartR1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=5... Read more

Answer:HiJackThis Log file please help info inside

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Relevance 45.1%

So I downloaded some program off of Limewire and now everything is messed up. When you try to open internet explorer its very slow. It goes to the homepage and then a bunch of pop ups come. I also get error messages such as microsoft C++ buffer underrun error. The popups are like this...http://www.interracialsingles.net/in...D1909&opt=6943 or CID Popups and others. also my desktop background is just the white error that says restore to active desktop I click it and get another error message. How do i fix all this. Am i gonna use Hijackthis and Combofix?Logfile of Trend Micro HijackThis v2.0.2Scan saved at 08:52, on 2008-02-04Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16574)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exeC:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService... Read more

Answer:Bunch Of Different Virus's Hjt File Inside

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. Please download ComboFix and save it to your desktop.Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.Double click combofix.exe and follow the prompts.When it's done running it will produce a log for you. Please post that log in your next reply.Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

19 more replies
Relevance 45.1%

Hello .
I cant access my system volume information file on my hard drive. Spyware doctor has located a trojan there and blocked it on several occasions but I cant access the file to delete it. It says that access is denied. What do I do.
thanks

Answer:Help, cant access file with trojan inside

If you can boot into Safe Mode try deleting the file there. Safe Mode has a limited amount of applications running which makes it ideal for purposes like this.

I've asked that a Moderator move this topic to the Am I Infected forum where there are those that are more knowledgeable about these problems.

5 more replies
Relevance 45.1%

Everytime I start my computer my background is changed and it says I have spayware and that I need to remove it. Also my screen saver is roaches eating the screen and I can never change it. Please help
 

Answer:Idk what the virus is but my hijack file is inside.

Hi tony82x,
Welcome to Major Geeks!

I'm making a bug collection, so if you'd like to contribute, please attach a screen shot of the bugs with your next post. Then please continue as follows:

Go to the READ & RUN ME FIRST and work through all the instructions. If there is something you can't do, just make a note of what happens to tell us later and then continue on. When you're finished, use the Manage Attachments button down below the reply window to attach your logs. If you get all four logs, you'll need to post twice, because you can only attach three logs with each post.

Thanks.
abri
 

26 more replies
Relevance 45.1%

I picked up some spyware. The communicator toolbar and also I have a lot of text double underlined and hyperlinked while browsing the internet.

Thanks,
TimS

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symante... Read more

Answer:Communicator Toolbar and More - hjt log file inside

Hi TimS -

If you had followed through on your last thread here we may have avoided another round of cleaning. Please see this through to the end, where you will be given valuable protection information once your system is clean.

I'm going to have you run some scanning tools first, then we'll go after whatever is left.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Go to My Computer->Tools->Folder Options->View tab:
* Under the Hidden files and folders heading, select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm and then click OK.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Before attacking an adware/spyware problem with hijackthis make sure you have already run the following tools. Download and update the databases on each program before running. Ad-Aware? SE Personal Edition
*Note* For Ad-AwareSE also install the VX2 Addon Cleaner To run this tool ... Read more

1 more replies
Relevance 45.1%

https://drive.google.com/open?id=1BJhjrNSaa6rIpQW1d4R_7aFvTuC0Czqx

google file of the .dmp, just started happening 2 days ago after an update so i'm assuming it's software related, doesn't happen constantly, sometimes i can go hours without blue screening, get a DPC watchdog violation when i let it error report

The bugcheck was: 0x00000133 (0x0000000000000001, 0x0000000000001e00, 0x0000000000000000, 0x0000000000000000). 

More replies
Relevance 44.28%

For those of you who have been complaining about the perceived slowness of Vista file copy operations (And <insert deity name here> knows ther have been many), I now present to you a copy of Mark Russinovich's blog dated 4 February 2008.

In his blog, he provides in-depth details of how the copy engine works, and what improvments have been made to this engine in Vista SP1.

Happy reading!

----------------------
The original text for this post can be read in Mark Russinovich's blog at http://blogs.technet.com/markrussinovich/
----------------------

Windows Vista SP1 includes a number of enhancements over the original Vista release in the areas of application compatibility, device support, power management, security and reliability. You can see a detailed list of the changes in the Notable Changes in Windows Vista Service Pack 1 whitepaper that you can download here. One of the improvements highlighted in the document is the increased performance of file copying for multiple scenarios, including local copies on the same disk, copying files from remote non-Windows Vista systems, and copying files between SP1 systems. How were these gains achieved? The answer is a complex one and lies in the changes to the file copy engine between Windows XP and Vista and further changes in SP1. Everyone copies files, so I thought it would be worth taking a break from the ?Case of?? posts and dive deep into the evolution of the copy engine to show how SP1 improves its performance.

... Read more

Answer:Inside Vista SP1 File Copy Improvements

I downloaded the article by microsoft about all the inprovements. Too many Kxxx articles to go into. Needless to say there is alot. Waiting for the final release before upgrading.

2 more replies
Relevance 44.28%

Recently got the poka poka virus...i ran several scans, and bleieve i got it and several other spyware thingys out of my registry...i still see some possible files that arent good, plz lend me some ideas since my PC seems to run a bit glitchy espeically with games/programs that prior ran better. I'm not sure if it matters but this file was not taken while in safe mode...rather in normal windows mode....

Logfile of HijackThis v1.99.1
Scan saved at 9:50:00 PM, on 10/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dual-Band Wireless A+G PCI Adapter\WLService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Dual-Band Wireless A+G PCI Adapter\WMP55AGV2.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\XoftSpy\XoftSpy.exe
C:\DOCUME~1\RAPHAE~1\LOCALS~1\Temp\Rar$EX00.906\HijackThis.exe
C:\Documents and Settings\Raphael Kosmicki\Desktop\HijackThis.exe
C:\Documents and Settings\Raphael Kosmicki\Desktop\h\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = ... Read more

Answer:Computer Possibly Infected (Log File inside)

Welcome to TSG

Please download LQfix.exe and save it to your desktop.

Double-Click LQfix.exe and click Next > Next > Install.
Leave the default settings, if you change them, the fix will Fail!
Now make sure the "Launch LQfix" box is checked.
Click the Finish button, after clicking the Finish button the fix will start.
Follow the on-screen prompts.
Your system will now reboot afterwards.
Please be patient after the reboot, there is a script running in the background that needs to complete.

Post a new Hijack This log.
 

1 more replies
Relevance 44.28%

I'm recently noticed that some zip files that I store images on contain some empty image files "0 KB".
I'm just wondering if anybody knows of a quick way to scan a bunch of folders each with several zip each and then show which zip files contain empty files.

Thank you.

Answer:Check inside zip files for empty file

Use wither 7-zip or Winzip. Basic computing 101.

6 more replies
Relevance 44.28%

I'm having problems with my iframe when viewing in IE (version 6)

The problem has to do with the URL/src of the iframe:
http://www.resonline.com.au/affredir/v2/affredir.asp?CommodityTypeID=1&StateID=401&DestinationID=454&AffiliateTheme ID=203&r=5&view=3&AffiliateID=203&refcode=OZACCOMM
(the page contains jscript)

I can view this URL in IE with no probs but when I try to view it within an iframe it won't stop reloading.. about every 2 seconds. It works fine in Firefox.

To see the problem in action you can check this link:
http://members.optusnet.com.au/~reen...comm/test.html

------------
Is there some jscript or something that I can use to force it to stop reloading.

Please HELP!
 

More replies
Relevance 44.28%

Hello,
I have a couple of computers set up in the network. They're all inside the same workgroup.
Every folder I share is visible by everyone.
Now I want to define permissions on only one folder which containes files only to be editable (modified) by, let say, one computer.
So I need to define special peermissions for this particular folder.
However I came accros to a problem. In network neighbourhood I can see all computers and their share folder and they see my shared files. But when I want to define special permissions on only one folder (one user can write and read, the rest is read only access), I cannot see other computers in the "Select user or groups" window just as shown in the attached picture.

One friend of mine told me that this is only possible when computers are on domain. It is really hard for me to understand that permissions cannot be defined for each folder and for each network user separately.

Can you give me any advice?

Thanks
 

Answer:File and folder permissions inside workgroup

Permissions are configured for local users on the machine, not network users or machines.
 

1 more replies
Relevance 44.28%

I am getting into batch file programming and wanted to know if I can get help with with extracting files with command prompt.
I can mostly navigate and manage my pc through cmd with out the gui so this would be awesome if I could extract files as well. I wanted to know this just so I can incorporate extracting files into a batch file if needed. I'm on xp. I have winrar, universal extractor, and extract now. I'm unsure if they have a command line feature or not or how to use it. maybe some basic examples would help if no one minds.
 

Answer:Solved: extraction inside batch file help

Maybe this will help you.

[WINRAR] First link
https://www.google.com/search?q=winrar+commandline

[UNI. EXTRACTOR] Didn't find a cmdline
https://www.google.com/search?q=universal+extractor+commandline

[EXTRACT NOW] First link > Documentation
https://www.google.com/search?q=EXTRACT+NOW+commandline

[7ZIP] This is my fav cmdline extractor; First link
https://www.google.com/search?q=7zip+commandline
 

1 more replies
Relevance 44.28%

Hi I am trying to remove MWMBs and even after using the MWMBs Removal Tool and rebooting twice" its still in "Program Files" It keeps saying: "Error Deleting File or Folder: Cannot Delete the Directory is Not Empty" When I open the MWMBs folder it has one little file with no description in it if I try and drag it to the Recycle Bin it says: "cannot read from the source file or disk" anyone have any ideas please Dazza

Answer:Cannot uninstall MWMByts Folder and 1 File inside

Hello Dazza -2 ideas. First, run chkdsk /r as the problem may be your system -Next, If the problem persists, please contact Malwarebytes Support desk << with this form for personal help -They have just told me that they will look after you as soon as a helper is available -Thank You -

4 more replies
Relevance 44.28%

How do I encrypt a .txt file inside an Image so that when I change the extension of the Image into .rar and I open the rar file, there's a .txt file in it? This does work, you can try it yourself.
http://www.icon-hack.cc.cc/img/product/2009/200905/20090502/188360_1_Fsdfdf.jpg
Change the file extension to .rar and open it.
 

Answer:Solved: Encrypting a .txt file inside an Image

6 more replies
Relevance 44.28%

hey guys, i got attacked by some virus or trojan or whatever it was, got some services removed and i need some reg keys to restore them....

If you are on Windows 7 x64 sp1, just go here in regedit;

HKEY_LOCAL_MACHINE\SYSTEM\CurrenControlSet\

and export the services subfolder and paste it up in a reply!

All the headache from trying to fix this with solutions now, i think im missing some vital part and only the right registry files can fix.

make sure you are on 7 x64 sp1...

thanks.

Answer:Got a virus, need a reg file, Windows 7 x64 sp1, directions inside.

Hello dek

Here you go hope it helps
Services.zip

Danny

3 more replies
Relevance 44.28%

the folders when you right click and click properties it is 0 size, or the folder is empty but the file is inside. but i can not open the files, when i right click it just has open with, folder synchronization, send to no other features as usual.And it spread to other files and folders. and when i burn it with Nero, it failed it said the file is too

PLEASE HELP, HOW TO REMOVE THE VIRUS!

Thx.

Answer:New Virus: The Folder is Empty but the file is inside

Hello and Welcome.

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

---------------------------------------------------------------------------------------------

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.

1 more replies
Relevance 44.28%

Hello folks. I'm trying to fix my mother's computer and needless to say it's in bad shape. The memory is being hogged like crazy and the only form of virus scanner i have at my disposal atm is housecall. What's weird is the terms don't load for me to continue, but hijack this works. Here's the log from safe mode. I'm going to restart and run it normally and see if there are differences. ty in advance.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:01:23 PM, on 8/2/2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Users\Mahnaz\Downloads\HijackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,... Read more

Answer:Mess of a system (Hijackthis file inside)

not on safe mode:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:33:28 PM, on 8/2/2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Mahnaz\Downloads\HijackThis(2).exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http:... Read more

2 more replies
Relevance 44.28%

I recently downloaded starry night which is a program that you can use to look at space features and stuff, but I had to uninstall it becuase it was taking up to much space on my computer, well now I can't delete the sucker and I'm constantly barraged by "this program is being used by another person or program", so I unistalled those programs and yet it still wants to stay, what do I do?
 

Answer:Certain file inside a program can't be deleted.. no matter what I do..

Before you delete anything else that you might actually want, try a system restore to before you had starry night installed.

If this does not help then post details of your system, the files you want to eliminate and the exact error messages.
 

4 more replies
Relevance 44.28%

PING 192.168.0.3 (192.168.0.3): 56 data bytes
64 bytes from 192.168.0.3: icmp_seq=1 ttl=128 time=0.5 ms
64 bytes from 192.168.0.3: icmp_seq=3 ttl=128 time=0.2 ms
64 bytes from 192.168.0.3: icmp_seq=4 ttl=128 time=0.3 ms
64 bytes from 192.168.0.3: icmp_seq=7 ttl=128 time=0.3 ms
64 bytes from 192.168.0.3: icmp_seq=13 ttl=128 time=0.5 ms
64 bytes from 192.168.0.3: icmp_seq=14 ttl=128 time=0.5 ms
64 bytes from 192.168.0.3: icmp_seq=15 ttl=128 time=0.2 ms
64 bytes from 192.168.0.3: icmp_seq=17 ttl=128 time=0.4 ms
64 bytes from 192.168.0.3: icmp_seq=18 ttl=128 time=0.5 ms
64 bytes from 192.168.0.3: icmp_seq=19 ttl=128 time=0.2 ms
64 bytes from 192.168.0.3: icmp_seq=20 ttl=128 time=0.2 ms
64 bytes from 192.168.0.3: icmp_seq=25 ttl=128 time=0.5 ms
64 bytes from 192.168.0.3: icmp_seq=27 ttl=128 time=0.2 ms
64 bytes from 192.168.0.3: icmp_seq=28 ttl=128 time=0.3 ms
64 bytes from 192.168.0.3: icmp_seq=29 ttl=128 time=0.4 ms
64 bytes from 192.168.0.3: icmp_seq=30 ttl=128 time=0.1 ms
64 bytes from 192.168.0.3: icmp_seq=46 ttl=128 time=0.4 ms
64 bytes from 192.168.0.3: icmp_seq=49 ttl=128 time=0.5 ms

--- 192.168.0.3 ping statistics ---
50 packets transmitted, 18 packets received, 64% packet loss
round-trip min/avg/max = 0.1/0.3/0.5 ms

I am getting this after doing a fresh install of Debian 3.0r2 on a computer with the following hardware:

Pentium 3 500MHz
2x 256MB PC133 RAM
Asus P2B
ATI RADEON 6500 VIVO
Creative SoundBlaster Live!
3Com 3C905-TX

I've never had problems like this bef... Read more

Answer:Getting 64% Packet Loss - What's causing this? (log file inside)

Seems reltek more reliable in this case, but I bet this is some driver problem...
 

8 more replies
Relevance 44.28%

Hi guys,

i come to you after formating my computer and without success to solve my blue screens problem.

when i watch a movie and specially while playing i get a blue screen
i attached the dump file.

thanks a lot!

Answer:Windows crashed + dump file inside

  
Quote: Originally Posted by shiker


Hi guys,

i come to you after formating my computer and without success to solve my blue screens problem.

when i watch a movie and specially while playing i get a blue screen
i attached the dump file.

thanks a lot!


SPDT.SYS used by daemon tools/alcohol and KeyMagic. Both.

Your computer was up for 2 plus days so it isnt happening frequently, and removing those two items may fix it.
Ken J

Please remove any CD virtualization programs such as Daemon Tools and Alcohol 120%. They use a driver, found in your dmp, sptd.sys, that is notorious for causing BSODs. Use this SPTD uninstaller when you're done: DuplexSecure - Downloads
[/quote]
You can use MagicDisc as an alternative.

Freeware MagicISO Virtual CD/DVD-ROM(MagicDisc) Overview


Code:

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\dump_110310-26083-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols;srv*e:\symbols
*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82a19000 PsLoadedModuleList = 0x82b61810
De... Read more

3 more replies
Relevance 44.28%

currently, I'm using CA Security suite, I'm wondering if I can use the anti-virus to scan the inside of a RAR file, which composed of dozens of files, and confirm if there is a virus inside the packed rar file or not
 

Answer:Can anti-virus scan the inside of a RAR or zip file?

NOD32 does... perhaps the CA cra--- uhmmm... product has an option to scan inside archives that needs to be enabled (seems like it should be on by default; it is with NOD32).
 

6 more replies
Relevance 44.28%

Is it possible to request elevation inside a CMD/batch file? I have a Command Script( .cmd) and one of the command require admin right to run. I am NOT looking for right-click "Run as administrator", I would like the script itself to call the UAC prompt.Thank you,

Ray

Answer:Request Elevation inside CMD/batch file

Hi,To elevate the permission, please refer to the following article:Windows7 elevated command prompt priviledges throug a scriptThanks,Novak

11 more replies
Relevance 44.28%

Hi there,

So in April I decided to go all in on an Alienware 18 which I use for business and pleasure. After a couple weeks I started noticing the computer would not wake from sleep during extended times such as over night. I would simply close the lid at night and open it in the morning where the HDD light would come on and then the computer would be frozen in a state with a black screen before bootup where I am forced to hold the power button down to reset. It would then tell me that the computer was shut down incorrectly etc.

I finally had Dell tech support work on it who were absolutely fantastic at the time. They went through all kinds of system setting changes including how the computer sleeps, updated video and MANY other drivers including a reinstall of windows. Problem persisted.

Next they sent a tech out to replace the Video cards... problem persisted.

Next they replaced the HDD's, motherboard, and video cards again... problem persisted.

They were completely stumped so they sent me a brand new system which is even better than the last one I had!

After a few days I noticed this system is doing the exact same thing. I called tech support and the original guy is now in another department so I'm dealing with a new guy now who is starting from scratch again with this system. I spoke with their manager as this guy wanted to reset the computer to factory again and he also suggested that they are 99% sure that a reinstall of windows (or an alien res... Read more

Answer:Invisible BSOD on computer wake after long periods - Hard reset needed

Welcome to 7F.

Your dumps ared indicating a device driver as being the problem but none are showing.

Driver Verifier will stress your drivers and cause BSODs if any fail and will flag them up in the dump files. Follow this tutorial to enable/disable it. Driver Verifier - Enable and Disable



   Information
Enable Driver Verifier but only enable these options:
Standard settings and IRP logging step 3.
Don't enable Force Pending I/O Requests



   Warning
Make a System Restore point before enabling Driver Verifier.



   Note
Your system will act very sluggishly while DV is enabled, this is normal as your drivers will be being subjected to heavy testing in order to make them crash.

9 more replies
Relevance 43.87%

Hi everyone,Here's something I was wondering. I have a VB application how's calling another application. This second application is a commandline software that use a password as parameter.my code looks like that:Public const MYPASSWORD ="ThisIsMyPassword12345"

dim result as integer

result =  Shell("C:\Application2.exe " & MYPASSWORD , vbHide)I was asking myself if it was secure to store a password as a constant inside an application.Once the code is compile and transform to binary format, is it possible that a hacker retreive this password with some kind of password recovery tool.Thanks. Fred

Answer:Is it safe to store passwords inside binary file?

Yes if you have the password stored in a file, then it would be possible to reverse engineer that file and gain the password.

6 more replies
Relevance 43.87%

I have try all the ideas everyone has had about drivers, deleting the file that causes the problem and nothing is working.. not sure if one of the video cards is going bad, but here is the dump file if anyone can help greatly appreciated.. win 7 ultimate 64
I7 2600

Answer:BSOD Bccode 116 atikmpag.sys dump file inside

STOP 0x116: VIDEO_TDR_ERROR troubleshooting

Either your RAM or one of the video is defective, try using one card at a time.
RAM - Test with Memtest86+

2 more replies
Relevance 43.87%

How do I make Windows 7 search inside of file contents on a removable device?

I have a flash drive with a few hundred spreadsheets on it, in .xls format. I need to search for words that are located inside of the spreadsheets. How do I do that?

Note: I have set my indexing options to search the contents of .xls files - this flash drive is probably not indexed, as it is only occasionally plugged into this machine. I am looking for a way to make Win7 search inside of files without having to index the thing.

Answer:How to search inside file contents on removable device?

Hello Dizzious, and welcome to Seven Forums.

Sorry, but you will not be able to add removable locations to be included in the index anyway.

An alternative, is to select the flash drive in Computer or Windows Explorer, and search it from there instead.

Hope this helps,
Shawn

3 more replies
Relevance 43.87%

I got a powerpoint in an email attachment, virustotal reports a zip file inside...
 
1.) Is there always a .zip file inside powerpoints?
2.) What malicious benefit could a zip file provide?
3.) How can I alalize the ZIP compressed archive (2.5%)
 
ssdeep
1536:d98NvL6Ra3cQewv87TClJ2HsrwRKbbEBbfnCY9Gbt09bfmh4jVuJTVxZbbFH5T14:dfJR4EBfnCK+JTVxZbb59q5/nfcQtb
 
TrID
PowerPoint Microsoft Office Open XML Format document (97.4%)ZIP compressed archive (2.5%)
 
F-Prot packer identifier
appended
 
ExifTool
SharedDoc................: No
Title....................: MEMORY
HyperlinksChanged........: No
TitlesOfParts............: Office Theme, MEMORY, What is Memory, Memory involved three fundamental processes, The stage model of Memory, Sensory Memory, Sensory Memory, Sensory Memory, Short-Term Memory, Short-Term Memory, Short-Term Memory, Short-Term Memory Working Memory, Long-term Memory, Long-Term Memory, Long-Term Memory Transforming or encoding memory, Long-Term Memory Types of Information, Long-Term Memory Subsystems, Maintenance Rehearsal , Elaborate Rehearsal , Retrieval , PowerPoint Presentation, PowerPoint Presentation, Encoding Specificity Principle , Forgetting , Forgetting
LinksUpToDate............: No
LastModifiedBy...........: RLLocal
Application..............: Microsoft Office PowerPointZipFileName..............: [Content_Types].xml
CreateDate...............: 2013:03:19 17:24:18ZZipRequiredVersion.......: 20
PresentationFormat.......: On-screen Show ... Read more

More replies
Relevance 43.87%

Here is the dumpfiles

http://sdrv.ms/17NJyVN

Basically ive been having the problem for a few months now, it wasnt as frequent BSOD to start but now the last 2 weeks its been every 2-3 hours, ive tried removing programs from the last few months and downloading driver after driver but i cant seem to find the source of the problem, if you need anymore info feel free to ask.

Answer:BSOD from Ndis.sys,ntoskrnl.exe & ataport.sys. DMP FILE INSIDE!

Are you using a USB PC Port adapter from 2Wire?

The driver, 2WirePCP.sys seems to have caused the Blue screen that generated the dump file.

I would get an updated driver.

5 more replies
Relevance 43.87%

Just upgraded to Windows 8 and I'm having an issue I never had in Windows 7. Whenever somebody sends me an archive (.zip, .rar, etc.) that contains file names that are in Japanese, they always appear garbled (文字化け).

1. I am using Outlook 2010
2. This happens through both WinRAR and Windows' native unarchiving program.
3. The file name of the archive itself (also in Japanese) is not garbled, just the file names inside.
4. I have the Japanese language pack (Windows IME) installed on top of this U.S. version of Windows 8, but setting Japanese language priority higher than English (through Control Panel/language) does not fix the problem.

Does anyone have any ideas how I might fix this issue, as right now I have to boot back into Windows 7 to unzip any Japanese archive.

Answer:Japanese file names inside archives getting garbled

Anyone have any ideas?

1 more replies
Relevance 43.46%

Alright, here's my Hijack This log...

Logfile of HijackThis v1.99.1
Scan saved at 11:14:43 PM, on 10/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\... Read more

Answer:Solved: Trojan.Vundo Virus, File: geedc.dll, log inside.

9 more replies
Relevance 43.46%

If I encrypt the folder of a software accounting program on my hard drive using windows 7 pro 64 bit, can I backup only my data file to an external flash drive? If so, what steps would be necessary to restore that file in the accounting program?

Answer:can I backup a single data file inside an encrypted folder

http://support.microsoft.com/kb/309340A flash drive is a pretty poor choice. I'd be more inclined to have a usb hard drive and store the file without encryption but store the usb drive in a secure location. Google is evil

5 more replies
Relevance 43.46%

Can someone please look through this log to see what files I should check? Thanks guys.Logfile of Trend Micro HijackThis v2.0.3 (BETA)Scan saved at 15:05:54, on 18/03/2010Platform: Windows Vista SP2 (WinNT 6.00.1906)MSIE: Internet Explorer v8.00 (8.00.6001.18882)Boot mode: NormalRunning processes:C:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\System32\igfxtray.exeC:\Windows\System32\hkcmd.exeC:\Windows\System32\igfxpers.exeC:\Program Files\Apoint2K\Apoint.exeC:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exeC:\Program Files\Hp\QuickPlay\QPService.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exeC:\Program Files\Windows Defender\MSASCui.exeC:\Program Files\Hp\HP Software Update\hpwuSchd2.exeC:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exeC:\Program Files\AVG\AVG8\avgtray.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Epson Software\Event Manager\EEventManager.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Windows\System32\spool\drivers\w32x86\3\E_FATICKE.EXEC:\Windows\System32\spool\drivers\w32x86\3\E_F... Read more

Answer:Google redirecting and email not recieving - Hijack file inside

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Follow the instructions... Read more

3 more replies