wagpofafi Topic Starter
Posts: 95
|
 |
« on: September 05, 2008, 07:30:40 PM » |
|
my yahoo messenger wont start anymore, at my first install of it it was running completely ic ould log in and log out without any problem,but after i turn off my pc.and tried to open it, it wont open up anymore,the yahoo messenger version i first installed was V.8,i tried to uninstall at and reinstall it,it still wont open up any more,also tried V. 8.1 it also wont start or open.i also tried reformat my pc an tried reinstalling it,but still wont open up.what should i do know please help me..
previously posted on the software section.but after doing all the advices they gave me.it still does not start up or open.so we think that the software might not be the problem it might be my unit for having viruses?hope you could help me.
im using:
win XP professional version 2002 Service pack 3
Amd Sempron(tm)Processor 3000+ 1.81Ghz, 1g ram
[recovering disk space -- attachment deleted by admin]
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #2 on: September 05, 2008, 09:44:39 PM » |
|
i had installed avg 8.0. please help me.after the installation of avg. the resident shield detected a threat.and i moved it to the volt.when i have done this.avg was telling me force removal of the said threat could cause system to crash.with this warning i still selected to force remove the object and know i cant access all my drives when i double click it or explore.is this what was avg telling me when i tried to remove it?i have tried system restore hoping that it would come back to normal but it was always restore incomplete.help me please.i dont want to format all my drives.i have files that are needed.help please.i saw the said threat.on the hijackthis log. O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe this was the file that i forced remove
[recovering disk space -- attachment deleted by admin]
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #3 on: September 05, 2008, 10:04:40 PM » |
|
Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) - O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exeImportant: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your systemGo to Start > Run and type notepad.exe then click OKCopy the text in the Code box below and paste it into Notepad. REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "kamsoft"=-
In Notepad go to File > Save as...Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the Desktop. There should now be a file on the Desktop that looks like this  Double-click fixme.reg it and allow it to merge with the Registry. You may not see anything happen but give it a few seconds or so to finish. Now delete the fixme.reg file from the Desktop. ---------- Download SDFix by AndyManchesta and save it to your desktop. When using this tool, you must use the Administrator's account or an account with Administrative rights- Double click SDFix.exe and it will extract the files to %systemdrive%
- (this is the drive that contains the Windows Directory, typically C:\SDFix).
- DO NOT use it just yet.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Open the SDFix folder and double click RunThis.bat to start the script. - Type Y to begin the cleanup process.
- It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
- Copy and paste the contents of the results file Report.txt in your next reply.
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #4 on: September 06, 2008, 05:43:27 AM » |
|
does this process,makes me access again my drives when i double click my drives?because i still cant open my drives when i double click it,it still asking me other programs to open my drives.and i also read the log from the last procedure that you tell me to do.and it says no trojan files found?  help me please.i want my pc to turn back to normal.and i want to use yahoo messenger  [recovering disk space -- attachment deleted by admin]
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #5 on: September 06, 2008, 10:36:18 AM » |
|
Run this Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the Desktop. ---------- Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1Link #2**Note: It is important that it is saved directly to your DesktopClose any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #6 on: September 06, 2008, 11:54:08 AM » |
|
here are the new logs
[recovering disk space -- attachment deleted by admin]
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #7 on: September 06, 2008, 12:09:07 PM » |
|
Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your systemDelete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+CKillAll::
Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]3. Go to the Notepad window and click Edit > Paste4. Then click File > Save5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!  ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply.Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
|
|
|
|
inDio™
Posts: 1
|
 |
« Reply #8 on: September 07, 2008, 03:30:51 AM » |
|
hi there.. i experienced the same problem for almost 3 weeks, but now my YM is working fine.. What i did? i downloaded AVG FREE 8.0 and installed it. When i restart my PC there's a threat found and moved it to vault.. after that YM appeared and seems working just fine.. I tried to close it and hoping that it will open again and it did, with a new threat found and i also moved it to vault. Just try to do the same.. i hope it will fix your YM.. GudLuck.. 
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #10 on: September 07, 2008, 07:33:37 AM » |
|
I've got errors during the process.when i dragged the .txt to the icon it runs the my avg detected some kind of a threat.but i just ignored it.then an error message or warning that im not allowed to do the process.but the program still runs.will it effect my log??  [recovering disk space -- attachment deleted by admin]
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #11 on: September 07, 2008, 06:53:59 PM » |
|
WOW!  i've tried installing yahoo messenger and it's working fine now.the tray icon does not disappear any more when i try to open it.i also tried rebooting my pc and it still runs! i'll just monitor it,if the problem appears again back again.many thanks to evilfantasy and Carbon Dudeoxide. thanks a lot!!what should i do now to prevent my previous problem from happening again??  .and can i use this procedures to other pc units with the same problem??
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #12 on: September 08, 2008, 01:49:11 AM » |
|
what should i do now to prevent my previous problem from happening again Wait until you are given the all clear first and I will then give final instructions. - Click START then RUN
- Now type Combofix /u in the runbox
- Make sure there's a space between Combofix and /u
- Then hit Enter.
. . - The above procedure will:
- Delete the following:
- ComboFix and its associated files and folders.
- Reset the clock settings.
- Hide file extensions, if required.
- Hide System/Hidden files, if required.
- Set a new, clean Restore Point.
. ---------- Download ATF Cleaner by Atribune to your Desktop. Alternate download linkNote: Vista users must use Run As Administrator- Under Main: Select Files to Delete choose: Select All.
- Click the Empty Selected button.
- If you use Firefox browser click Firefox at the top and choose: Select All
- Click the Empty Selected button.
If you would like to keep your saved passwords click No at the prompt.
- If you use Opera browser click Opera at the top and choose: Select All
- Click the Empty Selected button.
If you would like to keep your saved passwords click No at the prompt.
- Click Exit on the Main menu to close the program.
Note that your system will run slower for a reboot or two after having used this tool so don't panic.Important: Restart the computer before continuing. ---------- Download OTCleanIt.exe and save it to your Desktop. - Double-click OTCleanIt.exe.
- Click the CleanUp! button.
- Select Yes when the "Begin cleanup Process?" prompt appears.
- If you are prompted to Reboot during the cleanup, select Yes.
- The tool will delete itself once it finishes, if not delete it yourself.
. ---------- Run the Kaspersky Online ScannerIn Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator. - Click on SCAN NOW
- Click Accept.
- The program will then begin downloading the latest definition files.
- Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
- The scan will take a while, so be patient and let it finish.
. When the scan is done, in the Scan is complete window, any infection is displayed. There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As- Next, in the Save as prompt, Save in area, select: Desktop.
- In the File name area use KScan, or something similar.
- In Save as type: click the drop arrow and select: Text file [*.txt]
- Then, click: Save
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #13 on: September 08, 2008, 06:39:17 PM » |
|
sorry i thought it all alright when i have run my yahoo messenger.and access my drives.when i tried visisting the kaspersky lin with firefox.my firefox explorer has error message that tells me that my firefox needs to close.and on my internet explorer but it only happens when i close my internet explorer the same message comes out.
[recovering disk space -- attachment deleted by admin]
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #15 on: September 08, 2008, 09:07:31 PM » |
|
nope.only the files in akin are the one's that i know.but on the files detected in C: and D: . i don't know what they are. 
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #16 on: September 08, 2008, 09:11:23 PM » |
|
OTMoveIt2 by OldTimerNote: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator. - Double-click OTMoveIt2.exe to run it.
- Copy the lines in the codebox below.
[/list] [kill explorer] C:\WINDOWS\system32\Tools\Restart.exe D:\akin\installer\Photoshop\Goodies\PROGRAMS & EXTRA STUFF\WinZip 9.0.6224-SR1.zip D:\6qaiu.com F:\akin\installer\dream\keygen.exe F:\akin\installer\keygen.exe F:\akin\installer\Photoshop\Goodies\PROGRAMS & EXTRA STUFF\WinZip 9.0.6224-SR1.zip EmptyTemp [start explorer]- Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) and paste it in your next reply.
- Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #17 on: September 09, 2008, 09:43:57 AM » |
|
here is the log,i still have the debug message when i close may internet explorer,just a question.the avg always detects a tracking cookie when i open my yahoo messenger  [recovering disk space -- attachment deleted by admin]
|
|
|
|
« Last Edit: September 09, 2008, 11:03:06 AM by wagpofafi »
|
IP logged
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #18 on: September 09, 2008, 12:11:11 PM » |
|
avg always detects a tracking cookie when i open my yahoo messenger Do you mean you open messenger and AVG pops up? Do this and then see if you still get the debug message. To reconfigure script debugging options and - Click on Start > Run and type: iexplore.exe.
- On the Tools menu, click Internet Options > Advanced tab.
- Click the "Advanced tab" and scroll down to "Browsing".
- Put a check mark next to "Disable Script Debugging (IE)".
- Put a check mark next to "Disable Script Debugging (Other)".
- Uncheck "Display a notification about every script error".
- Click "OK" and close Internet Explorer.
. To disable the service: - Click on Start > Run and type: services.msc
- Press OK.
- Click the "Extended tab" at the bottom to view all the info on your services.
- Scroll down the list and find the service called Machine Debug Manager.
- When you find the service, double-click on it or right-click and choose "Properties".
- In the Properties Window > General Tab that opens, click the "Stop" button.
- From the drop-down menu next to "Startup Type", click on "Disabled".
- Click Apply, then OK and close any open windows.
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #19 on: September 09, 2008, 06:18:58 PM » |
|
my avg detects tracking cookies when i open my i explorer to yahoo index page.and when i log in my yahoo messenger.i tried to configure the internet options, it was al ready on that configuration the check box that you told me to check was already checked.and on the services.msc i can't find the machine debugger its not on the list. 
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #20 on: September 09, 2008, 07:07:26 PM » |
|
Tracking cookies are not dangerous. 1. Double click OTMoveIt2.exe to launch it. If using Vista Right-Click OTMoveIt and choose Run As Administrator2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) - When finished exit out of OTMoveIt2
. ---------- Run CCleaner. ---------- Run this online scan. Requires Internet ExplorerUse the ESET Nod32 Online Scanner1. Check the box next to YES, I accept the Terms of Use. 2. Click Start3. When asked, allow the activex control to install 4. Click Start5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #21 on: September 10, 2008, 06:13:23 PM » |
|
here are the log
[recovering disk space -- attachment deleted by admin]
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #23 on: September 11, 2008, 03:23:00 PM » |
|
the problem that im still having is the debug message when i close the internet explorer. is there any trouble with my pc if that happens?
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #25 on: September 11, 2008, 03:38:47 PM » |
|
nope still having the debug message when i close the internet explorer
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #27 on: September 11, 2008, 03:55:43 PM » |
|
avg toolbar.and does mozilla really debugs on some sites?because i can't visit some sites with mozilla.
|
|
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #30 on: September 11, 2008, 04:26:24 PM » |
|
it say it cannot find minidump???
|
|
|
|
|
|
|
wagpofafi Topic Starter
Posts: 95
|
 |
« Reply #32 on: September 12, 2008, 01:18:29 PM » |
|
 my internet explorer problem is ok now.i've just installed internet explorer 7.any suggestions.on how can i prevent my resent problem from coming back?
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #33 on: September 12, 2008, 02:02:51 PM » |
|
Set a New Restore Point to prevent possible reinfection from an old oneSetting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed. - Go to Start > Programs > Accessories > System Tools and click System Restore
- Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
- The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
- Next go to Start > Run and type Cleanmgr
- Click OK
- Click the More Options Tab.
- Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here: Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software. - Click Start Now
- Check the box next to Enable thorough system inspection.
- Click Start
- Allow the scan to finish and scroll down to see if any updates are needed.
- Update anything listed.
. ---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScriptTo prevent unknown applications from being installed on your computer install WinPatrol 2008* Using Winpatrol to protect your computer from malicious softwareI suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware* If you don't know what ActiveX controls are, see hereCheck out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
|
|
|
|
theRapist
Posts: 1
|
 |
« Reply #34 on: October 05, 2008, 03:39:54 AM » |
|
i have the same problem ... my ym doesnt start,, literally.... nothing happens when you doubleclick on it... pls help
|
|
|
|
|
|
|