Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Files blocking defragmenter and virus scan


  • Please log in to reply

#1
susan10179

susan10179

    Member

  • Member
  • PipPip
  • 95 posts
I hope you can help. I have been in a Malware forum and I have been checked for malware and all is ok.

My problems started when downloaded free game from a web site. My defragmenter cannot fragment all my files and when I do a Mcafee virus scan it stops at $hf_mig$\KB896428\update\updspapi . I have followed all the instructions given me before posting this.

Trojan Hunt found nothing. Ad aware stopped at C:\WINDOWS\$NtUninstallKB867282$. AVG also froze at C:\WINDOWS\$NtServicePackUninstall$\syimchnn.zip:\com\m...\column.class.

When I reboot, the screen sometimes is over one side so there is no start button on view .

Mc Afee detected a virus WdHxB.exe and o9e4.exe but could not delete this.

This is my Ewido file




---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 20:01:00, 13/12/2005
+ Report-Checksum: A5B539C2

+ Scan result:

HKU\S-1-5-21-3363089783-2645368650-3616532942-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04079851-5845-4DEA-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
HKU\S-1-5-21-3363089783-2645368650-3616532942-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -> Spyware.PopularScreensavers : Cleaned with backup


::Report End

+
This is my Hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 19:04:22, on 13/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Freeserve\freeserveconnectionkit\atdialler1.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\INCRED~1\bin\ImNotfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\DOCUME~1\SUSANH~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis_199.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\SUSANH~1\MYDOCU~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\RunOnce: [CleanUp!] C:\Program Files\CleanUp!\Cleanup.exe /WindowsRestart
O4 - Global Startup: Freeserve Connection Kit.lnk = C:\Freeserve\freeserveconnectionkit\atdialler1.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Ulead Photo Express 3.0 SE Calendar Checker.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Search with Freeserve - res://C:\PROGRA~1\FREESE~1\FSBar\FSBar.dll/VSearch.htm
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-24.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.co...84/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.shockwave...bugs/axhost.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.co...,21/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ol_v1-0-3-0.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.c...ebio5_1_5_0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/p...t/msnchat45.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

Hope you can help, Thanks alot, Susan
  • 0

Advertisements


#2
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Click start then run, type prefetch then press enter, click edit, select all, right click any file, click delete, confirm

Click start then all programmes, accessories, system tools to run disc clean up, click more options, click clean up restore points, confirm

Click start then run, type %TEMP% then press enter, click edit then select all, right click any file, click delete and when it shows access denied, delete as many as possible manually

Reboot the PC

If you can access online scans, try here

http://us.trendmicro...call/v6.5/?us=2

Tick to accept the agreement then launch housecall

If you are unable to run an online scan

Get the trial of Tune Up 2006 here

Tune Up 2006 Trial

Run disc clean up then registry clean up then click optimize to run reg defrag, which needs a reboot

Those will help the defragmenting

The others are suggestions for maiking the most of the free trial

After the reboot, click optimize then system optimizer to optimize the computer, select computer with an internet connection from the drop down menu, this also requires a reboot

After the reboot, click optimize then system optimizer to accelerate downloads, select the speed just above your actual connection speed, this requires a reboot

After the reboot, click optimize then system optimizer to run system advisor

  • 0

#3
susan10179

susan10179

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
Hi Keith

I have followed all your instructions . There were 4 files I couldnt delete. After doing this I did a defrag and there were two files left. It appears to be in my documents and settings. 2 files...size 638KB.

I also tried the virus scan and set it to scan sub folders only and it stopped again at the same point.

I made a note of the 4 files in case that was useful.

Thanks, Susan
  • 0

#4
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
If you are absolutely sure the files are not needed

Try with either of these

This is for the original Move On Boot

http://www.snapfiles...moveonboot.html

This is for a new version by a different author, it has a higher rating but I have not used it

http://www.snapfiles...et/emcomob.html

Whichever one you use, they will delete the files so it is important you check they are not required

You could try renaming them or moving them to a folder you create in my documents then reboot and they should delete from the new folder

Also, if you run defragmenter straight after booting the PC, or perhaps run it in safe mode it will run properly
  • 0

#5
susan10179

susan10179

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
Hi Keith

Am not sure if I need these files or not. I did %temp% again and all the names were totally different from the ones I noted the day before. I downloaded the second snapfiles but was totally lost . I am thinking of downloading the first one but wanted to check about these files first. They are a mixture of numbers and letters at random so I dont think they are needed. Thanks , Susan
  • 0

#6
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Click start then run, type %TEMP% then press enter, right click any file then look for a blue cross with delete file(s) on next boot, click that and the file will be removed. If you right click a file then press and hold down the ctrl key, it should highlight all the files you left click, if so, click as many as you want, release the ctrl key, right click while the mouse is still over a highlighted file then click delete files on next boot
  • 0

#7
susan10179

susan10179

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
hi Keith

I have just done as instructed. I have tried it three times but without success. I clicked on blue cross and then it came up as delete succeeded on next reboot. But they are not going. I tried a defrag and the virus scan and it still froze. These files seem to be in hidden files . The other files which are not hidden I can delete. I remember looking for hidden files before with no success .

Thanks, Susan
  • 0

#8
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Can you install SpeeDefrag from my signature, click yes for desktop icon then tick launch SpeeDefrag when it finishes installing, click OK on the box, this will restart the PC, it will load most of the way to the desktop but stop at the defragmenter, you will get a box with scan analysis report with two figures, the red light on the tower should be active, so leave that run, when it finishes it will show a second line, then it will shut down the PC

Hopefully that will be part of it out of the way

Click start then search, click advanced options to include hidden and system files
  • 0

#9
susan10179

susan10179

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
I have had real problems as after a reboot I lose the start icon and I have to keep rebooting till eventually it comes back. In the search what am I to look for as I can find the files but cant delete them. I did a search yesterday as I was determined to delte them but got the same result as when I tried the other way with %temp%. I will give it another go with speedefrag but it is hard when the screen goes to the left or right or I get left with no start icon. Thanks, Susan
  • 0

#10
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
If you press ctrl + alt + delete keys together you should get task manager, click file, new task, type explorer.exe then press enter and you should get the start button
  • 0

Advertisements


#11
susan10179

susan10179

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
Thanks for that as at least should now get the start button. If I do search and then advanced search .. I brought up some of the files in hidden folders that I found when doing %temp%. But I could still not delete. It says these are being used by another person or programme.
  • 0

#12
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
If you right click the file, you should see a blue X with delete file(s) on next boot, go for the big ones, making sure you do not need them because these will not go to the recycle bin this way.

If you press and hold down the ctrl key, you should be able to click a number of files, they should highlight blue, then still holding down ctrl, right click then click delete file(s) on next boot and they will be deleted, reboot, check for the files, run tune up reg clean up
  • 0

#13
susan10179

susan10179

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
Yes I have just done that and the files seem to have gone. Or at least I can see them but it is saying file size 0KB. I have done a tune up and clean up. I then did a defrag but there are still some files not defragmenting. One says My documents and the other system volume information. In the past I tried perfectdisk etc but it did not help. Is there anything else I can do please ? susan
  • 0

#14
Retired Tech

Retired Tech

    Retired Staff

  • Retired Staff
  • 20,563 posts
Try with SpeeDefrag again, or boot the PC and keep tapping F8 until you get options, choose safe mode then run disc clean up then disc defragmenter in safe mode
  • 0

#15
susan10179

susan10179

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
Ok Keith. Will give it a go. Thanks
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP