Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

What is External Dependencies


  • Please log in to reply

#1
reilapi

reilapi

    New Member

  • Member
  • Pip
  • 5 posts
Windows ME, Internet Explorer

An email supposedly from my ISP gave me a virus/spyware/i donno. HiJackThis cannot remove it. My Ad-Aware SE , Spybot S&D, Symantec & Enigma Firewall/Pop-up Blocker can NOT do anything. Seems like it will re-attach itself even HiJackThis removes it.

The registry name is: [External Dependencies]external.exe

Please someone advice me what to do? PLEASE HELP. Thanks in advance!

Logfile of HijackThis v1.99.1
Scan saved at 2:31:04 PM, on 6/26/2005
Platform: Windows ME (Win9x 4.90.3000A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMA POPUP STOP\ENIGMAPOPUPSTOP.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\ENIGMAFIREWALL.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PLUS\AD-WATCH.EXE
C:\PROGRAM FILES\CHIKKA\CHIKKA.EXE
C:\PROGRAM FILES\CHIKKA\BNRREPO2.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aroundhawaii.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQInet] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\Enigma Software Group\Enigma Popup Stop\EnigmaPopupStop.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Enigma Firewall] C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\EnigmaFirewall.exe
O4 - HKLM\..\Run: [Digital Dashboard] C:Program Files\Compaq\Digital Dashboard\DevGulp.exe
O4 - HKLM\..\Run: [XFILTER] C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\ESPFSDK.DLL
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [External Dependencies] External.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PLUS\AD-WATCH.EXE"
O4 - Startup: Compaq Knowledge Center.lnk = C:\Program Files\Compaq Knowledge Center\bin\silent.exe
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O12 - Plugin for .asx: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .avi: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npavi32.dll
O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npswf32.dll
  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Hi reilapi and Welcome!

First Disable Ad Watch,it can prevent some of the Fixes!
http://www.lavasofth...watchauto.shtml

Please Download this Removal Tool From Symantec
http://securityrespo...er/FixMytob.exe

Close all the running programs and Double-click the FixMytob.exe file to start the removal tool.

Click Start to begin the process, and then allow the tool to run.

Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.syma...src=sec_doc_nam


Run the removal tool again!

Restart Normal and Use this Scanner

Please Download the MWAV Scanner from Here

Unzip it to its predetermined Directory (C:\Kaspersky)

Locate "kavupd.exe" in the New Folder and Double Click to Update!

If you it says the signatures are more than 30 days old, keep trying!
Keep trying until you get the actual signatures!

When you see "Updates downloaded Successfully"

Please Press Enter to Continue!

It should open automatically>Leave the "Default Settings ticked" and add a "tick" "Drives">this will light up "All Drives">Click "Scan Clean" to begin!

This Scan can take Several Hours or more to Complete,Depending on the Hard Drive Size!

Please be sure it is Completed before proceeding!

Once the Scan has finished,All entries Identified as Infected will displayed in the lower pane!

Highlight everything that is inside the lower pane and press Ctrl+C at the same time to Copy!

Open a Blank Notepad Page and Paste the results (Ctrl+V) to it!

Post those results back here along with a fresh HijackThis log!
  • 0

#3
reilapi

reilapi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
I GOT LUCKY! I ALSO ASKED HELP FROM OTHER FORUM LIKE YOURS.
EACH OF YOUR ADVICES DID NOT REMOVE MY PROBLEM. THEN, I TRIED TO
COMBINE BOTH OF YOUR ADVICES AND PRESTO! MY LAST HIJACKTHIS FILE
NO LONGER SHOW "[EXTERNAL DEPENDENCIES] EXTERNAL.EXE" I divided
my donation to you guys also. Thank you for starting this type
of help, I am learning too.

HERE IS WHAT I DID, HOPEFULLY TO HELP OTHERS WITH THE SAME PROBLEM.
SITUATION: After doing all the advices on both sides, I was able to
remove the file. But after running the HiJackThis, the same problem
appears again and again even I cannot find the files "external.exe"
anymore in the original locations.

I disabled my pop-up and firewall (not to be loaded on start-up).
Here are the advices:

First Disable Ad Watch,it can prevent some of the Fixes!
http://www.lavasofth...watchauto.shtml

Please Download this Removal Tool From Symantec
http://securityrespo...er/FixMytob.exe

Close all the running programs and Double-click the FixMytob.exe
file to start the removal tool.

Click Start to begin the process, and then allow the tool to run.

Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.syma...src=sec_doc_nam

Run the removal tool again!

I ALSO RUN THE HIJACKTHIS TOOL AND CHECK/FIXED THE PROBLEM.

Also in safe mode navigate to the C:\Windows\Temp folder.
Open the Temp folder and go to Edit > Select All then Edit > Delete
to delete the entire contents of the Temp folder.

Go to Start > Run and type %temp% in the Run box.
The Temp folder will open. Click Edit > Select All then Edit >
Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options.
On the General tab under "Temporary Internet Files" Click "Delete Files".
Put a check by "Delete Offline Content" and click OK.
Click on the Programs tab then click the "Reset Web Settings" button.
Click Apply then OK.

Empty the Recycle Bin.
  • 0

#4
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Excellent Job!!!! :tazz: ;)

Now get these 2 installed to assist Internet Explorer or Forefox

SpywareBlaster:
http://www.javacools...areblaster.html
Update Immediatly!

IE Spyad:
http://www.bleepingc...showtutorial=53
There is a direct download inside and great tutorial also!

Disable System Restore
http://service1.syma...src=sec_doc_nam

Restart the PC

Go back and Renable System Restore by Unchecking the Box and Moving the Slider to the Half Way Position!

The 3 little black links in my signature have a wealth of information to look at!

I do appreciate you posting back and letting me know what happened!

Thanks

MJ ;)
  • 0

#5
reilapi

reilapi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
I SPOKE TOO SOON! SORRY. Noticed that it is attached to the Ad-Watch at start-up. I disabled the Ad-Watch at start-up and the HiJackThis did not find the problem. Now that I know where is at, what shall I do? Sorry again for the bother.
  • 0

#6
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
I guess I am not following what you said,can you explain further?
  • 0

#7
reilapi

reilapi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
I thought I was able to remove the WORM, the log shows it's still here. If I load my Ad-Watch at start-up & run my HiJackThis, I still see the EXTERNAL DEPENDENCIES in the log. BUT if I disable my Ad-Watch at start-up and run the HiJackThis, the EXTERNAL DEPENDENCIES is not in the log. Also, noticed that my email wont receive/send if Ad-Watch is disabled. Below are 2 example log I mentioned:

Logfile of HijackThis v1.99.1
Scan saved at 7:38:59 PM, on 6/28/2005
Platform: Windows ME (Win9x 4.90.3000A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMA POPUP STOP\ENIGMAPOPUPSTOP.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\ENIGMAFIREWALL.EXE
C:\PROGRAM FILES\CHIKKA\CHIKKA.EXE
C:\PROGRAM FILES\CHIKKA\BNRREPO2.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aroundhawaii.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQInet] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Digital Dashboard] C:Program Files\Compaq\Digital Dashboard\DevGulp.exe
O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\Enigma Software Group\Enigma Popup Stop\EnigmaPopupStop.exe
O4 - HKLM\..\Run: [Enigma Firewall] C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\EnigmaFirewall.exe
O4 - HKLM\..\Run: [XFILTER] C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\ESPFSDK.DLL
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - Startup: Compaq Knowledge Center.lnk = C:\Program Files\Compaq Knowledge Center\bin\silent.exe
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O12 - Plugin for .asx: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .avi: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npavi32.dll
O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npswf32.dll

Logfile of HijackThis v1.99.1
Scan saved at 7:44:42 PM, on 6/28/2005
Platform: Windows ME (Win9x 4.90.3000A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMA POPUP STOP\ENIGMAPOPUPSTOP.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\ENIGMAFIREWALL.EXE
C:\PROGRAM FILES\CHIKKA\CHIKKA.EXE
C:\PROGRAM FILES\CHIKKA\BNRREPO2.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PLUS\AD-WATCH.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aroundhawaii.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQInet] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Digital Dashboard] C:Program Files\Compaq\Digital Dashboard\DevGulp.exe
O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\Enigma Software Group\Enigma Popup Stop\EnigmaPopupStop.exe
O4 - HKLM\..\Run: [Enigma Firewall] C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\EnigmaFirewall.exe
O4 - HKLM\..\Run: [XFILTER] C:\PROGRAM FILES\ENIGMA SOFTWARE GROUP\ENIGMAFIREWALL\ESPFSDK.DLL
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [External Dependencies] External.exe
O4 - Startup: Compaq Knowledge Center.lnk = C:\Program Files\Compaq Knowledge Center\bin\silent.exe
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\espfspi.dll
O12 - Plugin for .asx: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .avi: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npavi32.dll
O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npswf32.dll
  • 0

#8
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
This is different,I need you to run an Online Scan and lets see whats hanging around!

First lets do this

Copy everything in the code box below and paste it into notepad. Go up to "File > Save As..." and click the drop-down box to change the "Save As Type" to "All Files". Save it as locate.bat on your desktop.

dir %Systemdrive%\External.exe /a h /s > files.txt
start notepad files.txt


Double click locate.bat and when it is ready it will open files.txt
Copy the content of files.txt and paste it here.

Online Scan
http://www.kaspersky...oduct=161744315

If you can Save or Make a Report of what happened during the Online Scan,please do so!
  • 0

#9
reilapi

reilapi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
dir %Systemdrive%\External.exe /a h /s > files.txt
BELOW THE: C:\WINDOWS\Desktop>dir \External.exe /a h /s > files.txt
SHOWED THE: Too many parameters - h

C:\WINDOWS\Desktop>start notepad files.txt
A BLANK NOTE PAD POPPED-UP.
  • 0

#10
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Thats what I thought!!

Its locked up in Ad Watch Some how!

Uninstall Ad Aware Completely and ReInstall!

Thats the only way I know to clear out Ad Watch

There is a Ad Aware forum here somewhere,I have never been to it though!
http://www.geekstogo..._aware-f62.html

See if they have any ideas other than Uninstall!

Let me know if Kaspersky found anything!

Remember,once all is well and fine,Disable System Restore and then Restart>> Go back and Renable and the next time you reboot it shuold automatically set you afresh clean Restore Point!

http://www.aroundhaw...dhawaii.com/<<< Wish I was there!!! :tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP