COmputer won't allow me to follow your instructions [RESOLVED, Trying to clean out daughter's laptop |
![]() ![]() |
COmputer won't allow me to follow your instructions [RESOLVED, Trying to clean out daughter's laptop |
Jun 1 2006, 02:11 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
My daughter is home from college and her laptop has major problems. It shuts down for no reason, runs very slow, etc. I have been trying to follow diff instructions that I see on this board, to no avail. Have tried to run the suggested ad-aware and spybot search and destroy programs, but after partial scans and listings of infected items start showing up, the computer shuts down on it's own. I have tried running both scans in safe mode, with the same results. Originally, I was trying to get rid of her pop-ups on startup (winantivirus and sysprotect), which are not popping up at start up any longer, yet it seems as if something is intentionally shutting me down when I detect problems via scans so obviously I have done something wrong. Any advice for a 45 year old puter dummy that can't afford another laptop for my daughter? |
|
|
Jun 1 2006, 02:26 PM
Post
#2
|
|
![]() Malware Expert Posts: 8,272 From: Omaha, Nebraska U.S.A OS: Windows XP Professional/Windows Vista Ultimate x64/x86 |
Hello, Feisty.
You haven't done anything wrong as far as I can tell. I'd like you to download HijackThis, a utility that let's us see if/what kind of malware is present. * Click here to download HJTsetup.exe
|
|
|
Jun 1 2006, 02:43 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
Hi Rip! Thank you so much for your time.
Assuming I did as you stated correctly, here is what it says. Logfile of HijackThis v1.99.1 Scan saved at 3:37:43 PM, on 6/1/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\system32\LxrJD31s.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\ProSiteFinder\prositefinder.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe C:\WINDOWS\system32\igps.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Microsoft Money\System\mnyexpr.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\ProSiteFinder\prositefinderh.exe C:\Program Files\ProSiteFinder\prositefinder.exe C:\Program Files\Hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie...ton/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe O2 - BHO: (no name) - {00000000-0000-456A-9115-04F5A4B81E4D} - C:\Program Files\ProSiteFinder\ProSiteFinder.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\windows\msbbhook.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: LinkTracker Class - {8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} - C:\Program Files\QL\qlink32.dll O2 - BHO: AIMSite Class - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - C:\Program Files\AIM Toolbar\aimhelper.dll (file missing) O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [webscan] C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe -k O4 - HKLM\..\Run: [StopSignStatus] Rundll32.exe "C:\Program Files\Common Files\eAcceleration\Installer\stopsinfo.dll",VerifyStatus O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [ProSiteFinder] C:\Program Files\ProSiteFinder\prositefinder.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\system32\igps.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot O4 - Global Startup: hp psc 1000 series.lnk = ? O4 - Global Startup: hpoddt01.exe.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU) O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support2.charter.com/sdccommon/download/tgctlcm.cab O16 - DPF: {0878B424-1F95-4E26-B5AB-F0D349D89650} - http://download.bullseye-network.com/downl...MARKETING32.cab O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} (CInstall Class) - http://adserver.sharewareonline.com/adserver/Install.cab O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://www.mathxl.com/wizmodules/testgen/i...GenXInstall.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {59D04288-805E-4D43-BE09-83B1083E9E1E} (IUpdateAutoLaunch Control) - http://idenphones.motorola.com/iden/client...eAutoLaunch.ocx O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab30149.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - C:\Program Files\QL\qlink32.dll O20 - Winlogon Notify: tuvwt - C:\WINDOWS\system32\tuvwt.dll (file missing) O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: Service 8 (Service Filter) - Unknown owner - C:\WINDOWS\smncs.exe (file missing) O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE |
|
|
Jun 1 2006, 06:55 PM
Post
#4
|
|
![]() Malware Expert Posts: 8,272 From: Omaha, Nebraska U.S.A OS: Windows XP Professional/Windows Vista Ultimate x64/x86 |
Hello, Feisty.
You did everything correctly as instructed, we'll have that computer cleaned up in no time Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later. Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only Please download the Killbox by Option^Explicit. ( Save it to your desktop. ) Note: In the event you already have Killbox, this is a new version that I need you to download. Using Add Or Remove Programs remove the following entries (if present): (To get into add Or Remove Programs press the START button > Control Panel > Add Or Remove Programs.) Ebates_MoeMoneyMaker QL ProSiteFinder Please copy (Ctrl C) and paste (Ctrl V) the following text in the quote to Notepad. Save it as "All Files" and name it FixServices.bat. Please save it on your desktop. QUOTE sc stop Service Filter sc delete Service Filter exit Double click FixServices.bat. A window will open and close. This is normal. Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) O2 - BHO: (no name) - {00000000-0000-456A-9115-04F5A4B81E4D} - C:\Program Files\ProSiteFinder\ProSiteFinder.dll O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\windows\msbbhook.dll O2 - BHO: LinkTracker Class - {8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} - C:\Program Files\QL\qlink32.dll O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [ProSiteFinder] C:\Program Files\ProSiteFinder\prositefinder.exe O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\system32\igps.exe" O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU) O16 - DPF: {0878B424-1F95-4E26-B5AB-F0D349D89650} - http://download.bullseye-network.com/downl...MARKETING32.cab O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} (CInstall Class) - http://adserver.sharewareonline.com/adserver/Install.cab O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - C:\Program Files\QL\qlink32.dll O20 - Winlogon Notify: tuvwt - C:\WINDOWS\system32\tuvwt.dll (file missing) Now close all windows other than HiJackThis, then click Fix Checked. Close HijackThis. Boot into Safe Mode: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Select the first option, to run Windows in Safe Mode. Run ATF Cleaner:
Under Main choose: Select All Click the Empty Selected button.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. For Technical Support, double-click the e-mail address located at the bottom of each menu. Using Windows Explorer delete the following folders (if present): (To get into Windows Explorer, right click the START button and select "explore.") C:\Program Files\QL C:\Program Files\ProSiteFinder C:\Program Files\Ebates_MoeMoneyMaker Run Killbox:
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again. Reboot into Normal Mode. Open HijackThis, click Config, click Misc Tools Click "Open Uninstall Manager" Click "Save List" (generates uninstall_list.txt) Click Save, copy and paste the results in your next post. Please do an online scan with Kaspersky WebScanner Please note: You MUST use Internet Explorer for this scan to work. ) Click on Kaspersky Online Scanner You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
In your next reply please include the following:
|
|
|
Jun 1 2006, 08:12 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
Do you really think we can get this thing cleaned up? That is great news hon. My kid has been in tears over it. Broke my toes the other night so decided that while I'm out of work for a few days that I would try to surprise her.
You said to copy or post your text to a new document? Please pardon my ignorance, but I don't know how to do that. I did manage to figure out how to copy this to a sep thing on the desktop I think. Not sure if that is the same thing. OK. I already obviously messed up even the first thing you said to do. Clicked on atfcleaner to d/l and then on run [should I have selected save instead of run?], and I got a little window saying "select files to delete" when I never saw anything happen to begin with. Which of those things do I click on? Is a list of things uncheckd and then options of delete selected, donate, and something else. Thank you for your patience. |
|
|
Jun 1 2006, 09:12 PM
Post
#6
|
|
![]() Malware Expert Posts: 8,272 From: Omaha, Nebraska U.S.A OS: Windows XP Professional/Windows Vista Ultimate x64/x86 |
Hello, Feisty.
QUOTE Do you really think we can get this thing cleaned up? I don't think, I KNOW we can get this computer cleaned up, believe me this is but a scratch compared to some of the computers I've seen. QUOTE My kid has been in tears over it. Broke my toes the other night so decided that while I'm out of work for a few days that I would try to surprise her. I'm sorry to hear of your injury, never very fun to be out of work for a few days. I assure you we will have this computer fixed up in a few more posts, we're getting close now. QUOTE You said to copy or post your text to a new document? Please pardon my ignorance, but I don't know how to do that. I did manage to figure out how to copy this to a sep thing on the desktop I think. Not sure if that is the same thing. All that means is copy the instructions to a .txt file or something like Notepad. Just so you have the instructions available to you when you're in safe mode is all that counts, it doesn't matter how you do it. QUOTE OK. I already obviously messed up even the first thing you said to do. Clicked on atfcleaner to d/l and then on run [should I have selected save instead of run?], and I got a little window saying "select files to delete" when I never saw anything happen to begin with. Which of those things do I click on? Is a list of things uncheckd and then options of delete selected, donate, and something else. You got it there, download and save ATF-Cleaner for use later in safe mode. I posted instructions later on in my last post on how to further run the program. If you have any more questions, feel free to ask now. |
|
|
Jun 1 2006, 11:02 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
Hi. Hope yall don't throw me out for my puter ignorance.
What I have now is atf and Killbox as icons on my desktop. I moved on to your step saying to delete the 3 programs if I had them on the pc. I did have the ProSiteFinder and deleted. You mentioned QL. Is that the same as the program called Quicklinks (size=.92MB)? I didn't delete it yet. Wasn't sure if it was the same. You then say to copy something to notepad. I must admit to not even knowing where notepad is, but I'm looking. I found it! Will try to continue along. Please don't give up on me yet. I think I will be able to do some of the other things you posted without bothering you every few minutes. |
|
|
Jun 2 2006, 07:19 AM
Post
#8
|
|
![]() Malware Expert Posts: 8,272 From: Omaha, Nebraska U.S.A OS: Windows XP Professional/Windows Vista Ultimate x64/x86 |
Hello, Feisty.
Yes, QL is short for QuickLinks. QUOTE Please don't give up on me yet. I think I will be able to do some of the other things you posted without bothering you every few minutes. I haven't given up on anyone yet and I don't plan on starting now. I await your next reply. |
|
|
Jun 2 2006, 10:01 AM
Post
#9
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
Good Morning.
I have managed to move along a little bit, and am now to the part where I am supposed to be still in safe mode and running Killbox. I had selected 'delete on reboot' and 'click on all files' as you stated, but didn't understand what you meant by copying the files to the clipboard. What is the clipboard? Another thing I can't figure out is why I can't open the desktop saved copy of your instructions while in safe mode to copy it to begin with. I am now back on normal mode in order to get your instructions. Thank you and hope you are having a great day. Edited to add..... Is the reason I can't copy from you instructions in safe mode because I had a link on desktop to this thread instead of having the instructions on the notepad saved on desktop? Just in case, I have now copied them to notepad and put that on desktop as well. This post has been edited by Feisty: Jun 2 2006, 11:05 AM |
|
|
Jun 2 2006, 01:45 PM
Post
#10
|
|
![]() Malware Expert Posts: 8,272 From: Omaha, Nebraska U.S.A OS: Windows XP Professional/Windows Vista Ultimate x64/x86 |
Hello, Feisty.
The clipboard is what resides in the computer's memory. So all you need to do is select all of the files you need to delete, then select copy. Then open Killbox and paste the files there by right clicking at the correct spot and selecting "paste." QUOTE Is the reason I can't copy from you instructions in safe mode because I had a link on desktop to this thread instead of having the instructions on the notepad saved on desktop? Yes. The instructions need to be saved permamently on the computer, such as how you have it saved now, in notepad. |
|
|
Jun 2 2006, 03:56 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
Hi.
I am afraid that I may hove done something terribly wrong. Have tried 3 times to run the Kaspersky Scanner. THe first time it got to about 48% and then the pc shut down. Tried again twice more and it shut down at 0%. Edited to add.......... just tried it a fourth time and shut down at 24% Another problem..... (may be a sep issue), my task bar from the bottom has jumprd over to the right side going up and down. My friend told me how to make it go back down to the bottom, but on restart after shutdown of last Kasp Scan it went back to the right side. This post has been edited by Feisty: Jun 2 2006, 04:40 PM |
|
|
Jun 2 2006, 05:30 PM
Post
#12
|
|
![]() Malware Expert Posts: 8,272 From: Omaha, Nebraska U.S.A OS: Windows XP Professional/Windows Vista Ultimate x64/x86 |
Hello, Feisty.
It's ok, sometimes Kaspersky won't run for some people. We'll try something else. Go ahead and just drag it back down again, to do that if you don't remember, just hold the taskbar with your mouse and drag it to the bottom and release it. Please run the F-Secure Online Scanner Note: This Scanner is for Internet Explorer Only!
|
|
|
Jun 2 2006, 06:17 PM
Post
#13
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
Hello.....
I simply don't know what to do now. I hope this thread will not become the longest ever on this board. Again, I thank you for your patience and time. Tried to run F-Secure twice. Again, the pc shuts down after partial scan and I have to restart. I know this is prob not possible, but as I said in my initial post it nearly seems the puter somehow knows/sees when I am doing something to get rid of the bad stuff, and shuts me down when I do. Please tell me what to do next |
|
|
Jun 2 2006, 07:05 PM
Post
#14
|
|
![]() Malware Expert Posts: 8,272 From: Omaha, Nebraska U.S.A OS: Windows XP Professional/Windows Vista Ultimate x64/x86 |
Hello, Feisty.
Please post a new HijackThis log for review. |
|
|
Jun 2 2006, 07:54 PM
Post
#15
|
|
|
Member ![]() ![]() Posts: 58 OS: XP Pro |
Logfile of HijackThis v1.99.1 Scan saved at 8:52:03 PM, on 6/2/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Microsoft Money\System\mnyexpr.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\system32\LxrJD31s.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\Internet Explorer\iexplore.exe |