Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

trojanhorse startpage 19.an and j [RESOLVED]


  • This topic is locked This topic is locked

#76
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
I still think se.dll is there, it will not be located directly on the C: drive, but in the TEMP directory inside the WINDOWS directory. We need to make sure it's gone...

Go to Start > Run - type:

command

Click OK.

Copy the following and paste it into the black window:

del C:\WINDOWS\TEMP\se.dll

hit enter.

Type exit hit enter.

autoexec.txt.bat - It may have something to do with the autoexec file we had you rename to autoexec.txt

We'll take a closer look at it shortly.

Please do this:

Copy everything in the code box below (starting with REGEDIT4) and paste it into notepad. Go up to "File > Save As", then click the drop-down box to change the "Save As Type" to "All Files". Save it as fixse.reg on your desktop:

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\New Windows]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
Double-click fixse.reg on your desktop and when asked if you want to merge with the registry click YES.

Reboot your computer, then post a new startdreck log and a new HiJackThis log.
  • 0

Advertisements


#77
shell38

shell38

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
i did the first bit and it said file could not be found

here are the 2 logs u asked for first startdreck
(take it u still wanted me to follow only ticking the ones i did before on configure

tartDreck (build 2.1.7 public stable) - 2005-07-29 @ 23:41:08 (GMT +01:00)
Platform: Windows 98 SE (Win 4.10.2222 A)
Internet Explorer: 6.0.2600.0000
Logged in as Sharon at HOME1

舞egistry
舞un Keys
翟urrent User
舞un
*msnmsgr="C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
舞unOnce
聞efault User
舞un
*msnmsgr="C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
舞unOnce
腿ocal Machine
舞un
*EnsoniqMixer=starter.exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*Adaptec DirectCD=C:\PROGRA~1\CD-WRI~1\DIRECTCD\DIRECTCD.EXE
*AVG7_CC=C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
*AVG7_AMSVR=C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
*LoadQM=loadqm.exe
*Motive SmartBridge=C:\PROGRA~1\NTL\BROADB~1\SMARTB~1\MotiveSB.exe
*AVG7_EMC=C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
*SetIcon=C:\Program Files\Icons\Seticon.exe
*ScanRegistry=C:\WINDOWS\scanregw.exe /autorun
*TaskMonitor=C:\WINDOWS\taskmon.exe
*SystemTray=SysTray.Exe
*internat.exe=internat.exe
*Welcome=C:\WINDOWS\Welcome.exe /R
*bcmwltry=bcmwltry.exe
*removecpl=RemoveCpl.exe
+OptionalComponents
+IMAIL
*Installed=1
+MAPI
*NoChange=1
*Installed=1
+MAPI
*NoChange=1
*Installed=1
舞unOnce
舞unServices
*SchedulingAgent=mstask.exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*Machine Debug Manager=C:\WINDOWS\SYSTEM\MDM.EXE
舞unServicesOnce
舞unOnceEx
舞unServicesOnceEx
翡rowser Helper Objects (LM)
肇iles
艋ystem/Drivers
舞unning Processes
+FFEF985D=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFFEFF5=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFFD885=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFFC23D=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFE2FA1=C:\WINDOWS\SYSTEM\MSTASK.EXE
+FFFE5CE1=C:\WINDOWS\SYSTEM\MDM.EXE
+FFFE5F55=C:\WINDOWS\EXPLORER.EXE
+FFFED8E9=C:\WINDOWS\STARTER.EXE
+FFFDA245=C:\PROGRAM FILES\CD-WRITER PLUS\DIRECTCD\DIRECTCD.EXE
+FFFDE53D=C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
+FFFC1205=C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
+FFFD973D=C:\WINDOWS\LOADQM.EXE
+FFFD98E9=C:\PROGRAM FILES\NTL\BROADBAND MEDIC\SMARTBRIDGE\MOTIVESB.EXE
+FFFC62B1=C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
+FFFC4C3D=C:\PROGRAM FILES\ICONS\SETICON.EXE
+FFFCFFA9=C:\WINDOWS\TASKMON.EXE
+FFFCEE41=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFFCCEC5=C:\WINDOWS\SYSTEM\INTERNAT.EXE
+FFF31345=C:\WINDOWS\SYSTEM\BCMWLTRY.EXE
+FFF37691=C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
+FFFD5AE9=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFF065D1=C:\PROGRAM FILES\NTL\BROADBAND MEDIC\BIN\MPBTN.EXE
+FFF715E9=C:\WINDOWS\SYSTEM\PSTORES.EXE
+FFF6762D=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFF33059=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
+FFF272F9=C:\MY DOCUMENTS\STARTDRECK\STARTDRECK.EXE
翠pplication specific


Logfile of HijackThis v1.99.1
Scan saved at 23:43:24, on 29/07/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\CD-WRITER PLUS\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\NTL\BROADBAND MEDIC\SMARTBRIDGE\MOTIVESB.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\ICONS\SETICON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\BCMWLTRY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NTL\BROADBAND MEDIC\BIN\MPBTN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\CD-WRI~1\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NTL\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [SetIcon] C:\Program Files\Icons\Seticon.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [Welcome] C:\WINDOWS\Welcome.exe /R
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: EPSON Background Monitor.lnk = C:\ESM2\Stms.exe
O4 - Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab

does that look better or not? :tazz:
  • 0

#78
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
Perfect :tazz:

First, download and install CleanUp! but do not run it yet.
*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
  • Empty Recycle Bins
  • Delete Cookies
  • Scan Local Drives for Temporary Files
  • Cleanup! All Users
  • Make sure NOTHING else is checked!
Click OK
Press the CleanUp! button to start the program.

It may ask you to reboot at the end, if it does go ahead and reboot.

Then, please run this online virus scan:
ActiveScan

Copy the results of the ActiveScan and paste them here along with a new HiJackThis log.
  • 0

#79
shell38

shell38

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Hi

Well panda scan did not show any virus detected so there is no scan log to show u. which is a good thing :tazz:

Also while that was running i did abit of detective work and sorted my pc out and you will be pleased to no (even though abit late) i have not got my computer settings back to how they were with th fonts right size colour right and also i can now see the whole of that page that i could not before..... So im learning alittle..... and while im bragging alittle here (i no its not hard to do them things but for me it is laffs) i feel quite proud of myself, as i installed my network cards in the pc and my router and got 3 computers now connected to the internet. so u must be doing your job very very well as im starting to learn alittle ;)

Right here for the latest hijack log

Logfile of HijackThis v1.99.1
Scan saved at 02:43:15, on 30/07/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\CD-WRITER PLUS\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\NTL\BROADBAND MEDIC\SMARTBRIDGE\MOTIVESB.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\ICONS\SETICON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\BCMWLTRY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NTL\BROADBAND MEDIC\BIN\MPBTN.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\CD-WRI~1\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NTL\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [SetIcon] C:\Program Files\Icons\Seticon.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [Welcome] C:\WINDOWS\Welcome.exe /R
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: EPSON Background Monitor.lnk = C:\ESM2\Stms.exe
O4 - Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab

Also once this is all finished i no u said that u would also run through everything i need to install on this pc like virus adware popups to keep it running. But as i said this is now my sons computer and i have downloaded lots of programs on here to try to get rid of this trojan, can u also tell me what i can delete and what is worth keeping. I will def keep the hijack this because i think it is a good prog to have.

Well its really late and this is my last post tonight (erm morning) once again thanks for everything u r a star...... goodnight
Shell
  • 0

#80
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
We can certainly remove unecessary programs from startup to speed it up!

You should be proud of yourself, you're doing a great job :tazz:

What kind of problems are you having with the system still? So I can see where we should go next as your log is clean and it is great that ActiveScan came back clean also!
  • 0

#81
shell38

shell38

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Hi

Well i dont think i am having much problems though the computer is quite slow, this might be due to the ram etc anyway. think its only bout 80.

the only thing that does come up on start up that im not sure about is machli i think that is it. if im quick and click on it, its like a dos window. Im not sure about the illegal error i am on the new pc and i have not booted up the old one since last night.

The only other thing i wanted to ask but this is coming away really from all of this. You might be able to point me in the right direction.
now that i have all 3 computers wireless. on the old computer that i was havig the probems i was using outlook express 6 which i am using on the new one. on the old one it has all my folders and email, address book. i have tried to save to disk and then import it all on to my new one but it keeps coming up with errors.
The other thing about outlook is that all 3 r recieving my mails obvious they would cos they r sharing my connection, can i stop this.
Also i have alot of pictures, doc, and lots of other diff bits and pieces that i would like to transfer to my new computer. Question is can i do this direct from pc to pc or do it like save to disk then install them on my new computer. of course some things might not work on here. What i dont want to do is let them gain access to any of my files from upstairs as i dont want them acciedently deleting them.
As i said this is not important at the moment and i no u have given me more than enough help but if u do have any ideas or could point me in the right direction maybe another forum i would be most grateful.

One thing i did notice though is a friend of mine gets that machli thing come up on start up now he is connected to ntl maybe this is something that happens with that. it does not seem to do anything to computer but thought i had better mention it.

The only other thing that i can think of is that agv warning but again from my end i can see it doing anything to the computer(it might be doing things i do not no about or understand)

Hope fully we are almost there ready to clear the mess up and get the computer back to a normal healthy state. Im sure we will both be pleased with all this.

Once again thanks does not seem enough but a very big thanks
Shell

Edited by shell38, 30 July 2005 - 04:52 AM.

  • 0

#82
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts

Well i dont think i am having much problems though the computer is quite slow, this might be due to the ram etc anyway.

It is definitely a RAM problem. It's an old computer with a lot of stuff loading on startup. As I said previously, we can remove optional items from startup to speed it up a little ;)

the only thing that does come up on start up that im not sure about is machli i think that is it. if im quick and click on it, its like a dos window. Im not sure about the illegal error i am on the new pc and i have not booted up the old one since last night.

matcli is absolutely nothing to worry about. It does belong to ntl. I have the exact same thing come up on my ME system from SBC. :tazz:

As far as any questions regarding the network, those I will not be able to answer. If they are on a network it would seem you could access files from another system, but I really have no idea.

The only other thing that i can think of is that agv warning but again from my end i can see it doing anything to the computer(it might be doing things i do not no about or understand)


Do me a quick favor. Right-click start go to "explore", then look on your C drive to see if the autoexec file you renamd to "autoexec.txt" is still named that or if it has been renamed "autoexec.txt.bat"

bdlt would like to take a look at your autoexec files and he will post the instructions when he gets a chance! Once that is done we will remove the optional items from startup to speed up the system, then we will be done!
  • 0

#83
bdlt

bdlt

    Member

  • Member
  • PipPipPip
  • 875 posts
shell38 & bananafanafo - congrats on the final cleanup yesterday. amazing job.

shell38,

I believe it would be worth our time to look at your autoexec files. it's possible that no changes are required.

let's see how many autoexec files are present. please post the names and dates of each file listed when you do the following:


Start>Run>command
cd \
dir auto*

  • 0

#84
shell38

shell38

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Hi

Well had a bit of a break yesterday from this computer. Right checked first to see if autoexec.txt had changed to autoexec.txt.bat. Could not find any of them all the auto i could see was

Autoexec.001 Autoexec Autoexec.pss. By putting that in the vault in agv did not actually remove the program so that it wont show. I moved it to the vault just to be on the safe side. should i put it back or leave it there. Or is the above correct.

Thanx bananafanafo

Hi bdlt

Thank u for the praise but this does not go to me its all u lot that deserve the praise and congratulations.

Right here is what u asked for

AUTOEXEC PSS 40 17.07.05 9.07p AUTOEXEC.PSS
AUTOEXEC BAT 81 28.07.05 10.13p autoexec.bat
AUTOEXEC 001 41 13.06.05 5.10P AUTOEXEC.001

3 files 162 bytes
o dir(s) 21,242.22mb free

Hope this is what u asked for.....

Once again so much thanks for everything
Shell
  • 0

#85
bdlt

bdlt

    Member

  • Member
  • PipPipPip
  • 875 posts
yes - that is exactly what we want.
please post the contents of the 3 autoexec files and identify the contents by filename.

Edited by bdlt, 31 July 2005 - 08:45 AM.

  • 0

Advertisements


#86
shell38

shell38

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
thanks wat program do i open them up in
  • 0

#87
bdlt

bdlt

    Member

  • Member
  • PipPipPip
  • 875 posts
the files are text files - you can use notepad.
  • 0

#88
shell38

shell38

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Hi

Here are the following


Autoexec.001 is as follows

C:\PROGRA~1\GRISOFT\AVGFRE~1\BOOTUP.EXE

Autoexec.pss

SET PATH=C:\WINDOWS\SYSTEM\WBEM;%PATH%

and can not find the one for Autoexec.bat

could this be because i moved the warning into the agv virus vault. i dont think so but do not know why there is not this file.

thanks
shell :tazz:
  • 0

#89
bdlt

bdlt

    Member

  • Member
  • PipPipPip
  • 875 posts
ok - that's 2 of 3.

let's try this for autoexec.bat:

Start>Run>command
cd \
type autoexec.bat


note - you actually enter "type autoexec.bat", without the quotes. 'type' is a dos command used to display the contents of a text file. please post the lines displayed after entering "type autoexec.bat".
  • 0

#90
shell38

shell38

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Hi

Well hope this is what u wanted;


C:\PROGRA~1\GRISOFT\AGVFRE~1\BOOTUP.EXE
set path +C:\WINDOWS\SYSTEM\WBEM;%PATH%

i made a silly mistake i clicked on make the screen full size button and now i cant get it back to how it was as there are no boxes to click just black screen. so i gather u have to use a command or something. I prefer it smaller so that i can read it type it on here at the same time.

Many thanks
Shell
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP