Computer Hope
Software => Computer viruses and spyware => Topic started by: terk13 on August 15, 2008, 02:02:04 PM
-
I know this is an older topic but... I get IEXPLORER.exe has generated errors and will be closed by windows you will need to restart the program. An error has been created. This all started when I put CA SUIT istallation into my PC for free from The cable co. Is CA nny good. I have Hijackthislog as well. Is their another I should use "that's free" I had stinger but could not get it to update. It happens mostly on ebay and sending some yahoo emails. It is also running slower. What is the best way to free up space. I have windows IE 2000 5. Can I upgrade to 6? Is their a program that can help me fix problems and not lose any of my documents since I am in rural america and 1 1/2 hours to the nearest store and with the leaf's changing the snow will be here soon. ANY help would be great. Should I put CA back in for now as I have nothing for firewall protection? Thank You everybody for your time and patiance. I am new to the site and the next time I ask ?'s it will be short and simple. Sorry for the novel.
-
Only use one antivirus at a time. Running two is never advised. CA is good but in my opinion there are better ones out there.
Post a HijackThis log so we can have a look.
-
I do have HIJACKTHISLOG how would I post it? Thank you for your help. SERIOUSLY. Terk
-
Click on the Do a system scan and save a log file button
* HijackThis will scan and then a log will open in notepad.
* Copy and Paste the entire contents of the log in your post.
-
But would'nt that give everyone my info and hackers could get intp my PC or no. Thanks Terk13
-
But would'nt that give everyone my info and hackers could get intp my PC or no. Thanks Terk13
Nope. Pretty much all the HijackThis Log will tell us is what your computer is running at startup. You have nothing to worry about. ;)
(Even I have done this)
-
Might show your name, but nobody knows what state or even country you might be in so it's not much of a worry. Lots of people know your name.
-
Logfile of HijackThis v1.99.1
Scan saved at 11:39:56 PM, on 8/19/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lori\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O20 - Winlogon Notify: PFW - C:\WINNT\SYSTEM32\UmxWnp.Dll
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\KODAK\Kodak EasyShare software\bin\ptssvc.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Here you go. I am only running CA Firewall and Virus protection not spy-ware or spam. Thought it might help but...I was wrong Thank you so much. You do not know how much this means to me and my wife. It starts up slow now and the IEXPLORER is killing me and now we can't send mail out of yahoo unless we copy and paste. This means allot to me and my wife thank you.
-
Don't thank me yet ;)
I don't see anything too bad but we can do some cleanup to see if it improves anything.
You have Viewpoint installed.
Viewpoint Media Player/Manager/Toolbar is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".
More information: - ViewMgr.exe - Useless (http://www.greatis.com/appdata/u/v/viewmgr.exe.htm)
- Viewpoint To Track Browsing, Serve Ads (http://www.spywareinfo.com/newsletter/archives/2005/nov4.php#viewpoint)
- Viewpoint to Plunge Into Adware (http://www.clickz.com/news/article.php/3561546/)
It is suggested to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.- Viewpoint
- Viewpoint Manager
- Viewpoint Media Player
- Viewpoint Toolbar
- Viewpoint Experience Technology
.
----------
Download Malwarebytes' Anti-Malware (MBAM) (http://www.besttechie.net/tools/mbam-setup.exe)
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to the following:
- Update Malwarebytes' Anti-Malware
- Launch Malwarebytes' Anti-Malware
- Then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy and Paste the entire report in your next reply.
.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
----------
Old version of HJT
You are running an older version of HijackThis.
It is important that you uninstall any previous versions by using Add or Remove programs in your control panel before installing a newer version.
Download and rename the new version of TrendMicro HijackThis.exe (http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe) (HJT)
Post the new HijackThis log in the next reply along with the MBAM log.
-
Just before I begin, what is MBAM file? where do I find it? Then I will begin.
-
Download Malwarebytes' Anti-Malware (MBAM) (http://www.besttechie.net/tools/mbam-setup.exe)
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to the following:
- Update Malwarebytes' Anti-Malware
- Launch Malwarebytes' Anti-Malware
- Then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy and Paste the entire report in your next reply.
.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
-
I cannot get viewpoint off folder in control panal. Will malware.exe interfear with CA firewall and anti virus. They say to get rid of all that stuff before installing CA. Should I remove CA before installing Maleware? Sorry for being confused. Will it hurt any folders I have saved. Or just go for it and no looking back. :-\ And I will have to find notepad. Thank you soo much for your patiance. I am disabled so I get confused. Nothing better then heavy metal and chemical poisening fron the job.
-
Malwarebytes' Anti-Malware 1.25
Database version: 1062
Windows 5.0.2195 Service Pack 4
2:42:04 PM 8/20/2008
mbam-log-08-20-2008 (14-42-04).txt
Scan type: Quick Scan
Objects scanned: 1176
Time elapsed: 46 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Do you need both items pasted here or just the one. I have 2 of them Tnak you again.
Malwarebytes' Anti-Malware 1.25
Database version: 1072
Windows 5.0.2195 Service Pack 4
2:56:06 PM 8/20/2008
mbam-log-08-20-2008 (14-56-06).txt
Scan type: Quick Scan
Objects scanned: 32107
Time elapsed: 12 minute(s), 11 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 46
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.shellviewcontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.shellviewcontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2763e333-b168-41a0-a112-d35f96f410c0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{621feacd-8857-43a6-ae26-451d670d5370} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\MyWay (Adware.MyWay) -> Quarantined and deleted successfully.
Files Infected:
C:\WINNT\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
I gave you both..Terk13
-
Your doing fine. Don't worry, we'll get things taken care of. (hopefully) After we get all of the malware cleaned up you can install whatever you need to. Having CA installed now is a good thing. You have to have an antivirus running.
Download ViewpointKiller.zip (http://bellsouthpwp.net/p/r/prprogramsstudios/viewpointkiller.zip)
- Unzip the program and all of the contents of ViewpointKiller.zip to a location such as your desktop.
- Double click the ViewpointKiller icon to run ViewpointKiller.exe.
- Select the File menu, and select Check to see if you have Viewpoint installed.
- If ViewpointKiller indicates that any of the Viewpoint variants are installed, select the proper Kill option in the File menu.
- Follow the prompts and instructions very carefully, answering Yes or No depending on which option you are most comfortable with.
- The MsConfig instructions are very important, so be sure to read them carefully.
- Note: When done with ViewpointKiller right click and delete all files that were unzipped.
.
----------
Now run a new hijackThis scan and post that log.
Also how is the computer running now?
-
Now it did not ask me to shut down and restart but I will do so and then redo HIJACK to the new version. Seem's like we are making headway.
-
With the old HIJACK in my folder it will not put the new one their (scan) I will put it in another folder and try again. :'( And I did not restart the PC yet since I have not been asked to.
-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:46:26 PM, on 8/20/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKLM\..\Policies\Explorer\Run: [notepad.exe] msmsgs.exe
O4 - HKCU\..\Policies\Explorer\Run: [kbdswc] C:\WINNT\System32\kbdswc.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\KODAK\Kodak EasyShare software\bin\ptssvc.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O24 - Desktop Component 0: Security - C:\WINNT\desktop.html
--
End of file - 6217 bytes
The new HJTL...
-
What do I do with Malwarebytes anti malware? Remove or use it once in a while? Should I uninstall CA virus and firewall and repalce it with CA firewall, antivirus,spyware and anti-spam? Terk13 I had spybot once but that was a night mare. Will this also help with IEXPLORER.exe error that shuts down the program and should I get if I can Internet explorer 6 since my PC will not allow 7 or stick with 5? Is their anything else I can remove to increase diskspace? BUT let's get the problems fixed first and you all have been so helpfull THANK YOU SO MUCH. Terk13
And when I double click Viewpointkiller.zip winzip pops up asking for $29 this is not a free software. Do I just type in Viewpointkiller.exe and not .zip to get to where I need to go. This part has me a bit confused but I have been doing ok to this point. Also let me know about the CA programs like I had said I only used the firewall and anti virus I would have to remove them and reinstall with anti spam and spyware along with th other 2 but when the box pops up asking to allow or ok I am never sure which one to hit. Should I hit ok and check never show me this again otherwise it takes forever to do anything. Thank you Terk. I am going to owe you a dinner.
-
Keep Malwarebytes anti malware? and use it once in a while.
Use 7-zip to unzip files. It's free. http://downloads.sourceforge.net/sevenzip/7z457.exe
CA is good yo use, it's up to you which one to use.
Run the F-Secure Online Scanner (http://support.f-secure.com/enu/home/ols.shtml) for Viruses, Spyware and RootKits.
Note: This Scanner is for Internet Explorer Only!- Click on Online Services and then Online Scanner
- Accept the License Agreement.
- Once the ActiveX installs,Click Full System Scan
- Once the download completes,the scan will begin automatically.
- The scan will take some time to finish,so please be patient.
- When the scan completes, click the Automatic cleaning (recommended) button.
- Click the Show Report button and Copy&Paste the entire report in your next reply.
-
Now the PC runs slower then anything I have ever seen. My printer does not work anymore there was somthing in the lefthand lower corner next to yahoo about printing like a red roll. This thing is about forever to start up and to click onto yahoo about 5-7 minutes to pop up and I cannot do 2 things at once. Please help we are going backwords...I wish I had the money for a new one disability stinks and your hand are tied and I need to print documents I have in folders and it's not happening. My wife is literly crying n I feel bad. she has been the runner for my legal case and this PC is her life line right now. Please help Terk13
-
Can you boot to safe mode? In Safe mode, you run only the bare minimum windows needs in order to load. Be sure you boot into safe mode with networking, otherwise your internet connection is disabled until you reboot and load normally.
Maybe that will be able to allow you to cure your pc faster. ;)
-
Please do not give up on me yet, My PC will not shut down when told to do so. It says "The application failes to initialize because windows is shutting down" from yupsater or yudater and a big X in a red circle. The CA said their are errors istalling I uninstalled ad reinstalled several times and the error is their and I cannot open the fire wall protection to bring down the security setting. What is the best free software that will not damage the PC. WIth Malwarebytes it messed up my printer. I use yahoo mail and now cannot open attached files either. Things are slipping away on me. I live almost 2 hours from the nearest "city" big town for shopping and do not have access to peopl;e that can look or buy a new PC for that matter and the snow will fly soon and we get around 300 inches of lake effect every year and that will be on it's way soon. That is why I am hopeing you all can help. What do I do next and what do you want to see. I NEVER give credit card info or bank info over the net so I have nothing to hide. Please help if you can. Windows wants to update but takes forever then the end this program pops up or I can hit cancel. IEXPLORER is messed up and yahoo mail will not send unless I copy the original script and copy then past redo the address then it sends. It will not just send. Viewpoint is having trouble leaving even though I did what you all have told me. Please help again. Terk13
-
The tools we have used so far have just removed bad files. If any of your legitimate files related to your printer or OS were infected then some may have been removed. Sometimes a re-install is the only answer to solving a damaged OS due to a malware problem.
Can you do a System Restore to before this started happening to see if that helps?
-
I removed the malware program and got it back. With that program out it went back to normal it was weird. I plan on putting it back in as CA as become complete junk. TY for the quick response I did not expect that. TERK13
-
Honestly I would uninstall CA and use Avast instead. http://www.avast.com/eng/avast_4_home.html
-
I use yahoo for mail will that be effected?
-
No. Avast will work with any web mail.
-
does it have all firewall and virus protection spyware and stuff? Next we have to remove junk from the pc. I have had 166 hits and only a few replies. I would like to give you a donation for the help :)
-
It has virus protection and spyware protection.
For a good free firewall I suggest PC Tools Firewall Plus http://www.pctools.com/firewall/
-
Well thank's for your help. Now I still have to figure out the IEXPLORER.exe. problem because it is comming up more and more. I cannot access eBay at all or an only news channel as well. It shuts down the program(s) that are being used and it's killing me. Microsoft is lost and does not know why. If I can get rid of that I will deal with the speed. If I were to buy a new PC should I go with an APPLE MAC (this is what I was told to do) or just get a normal unit and set it up right. The IEXPLORER is finishing me off I am ready to snap. Thanks Evilfantasy you have been most helpfull..
-
There is likely no need to buy a new computer.
I would suggest looking for a new XP install disk and use it to install XP. That will give you a fresh start and you will also have the disk in case something like this happens again, then you can just do a repair.
-
Will do. I will install XP next week. So I guess I am down and out for now. Is their a way to check things on start up and shut down will not hallpw because yudater or yupdater forget which one pops up and does not allow for a proper shutdown. When I hit the X to rid of it I get a blue screen and wait a while then shut ut down with the button. I will try it at say 11pm then get up areund 4 and the machine is still on. Should I load up the "Microsoft Updates" the machine keeps talking about. I also clean c files and defrag every 3 days they say once a month but i guess it never hurts. Just so you know I am a whistle blowe at my former employment and do not know if this has anything to do with whats going on. And the Co. is one of the largest in the nation. I can't even remove CA anymore. Gives me errors. I was going to try one at a time from the 4 what do you think and what about downloading updates from microsoft? Thanks again evil you have been very helpfull. Terk13
-
Uninstall Yahoo messenger and see if it clears up.
Get the updates.
-
And If I uninstall this I can go to Yahoo main page to check mail correct then one day I can reinstall messanger or would I leave well enough alone? I just have to be able to get my mail from yahoo.
-
You will still be able to get mail at the homepage.
-
Ok my wife thinking she was helping just downloaded for a free scan but just downloaded it did not run the scan from "Uniblue Registry Booster Version 2" I cannot find it in my remove this program. Since she did not do the scan will it remove itself when the PC is shut down. I cannot find it anywhere in the control panal. Have you heard of them, what would they be under and how do I remove it before she tries to scan the PC. I explained we had done that already and I was going to remove yahoo messenger. When I remove it what should I make the main page still yahoo but in it's normal form? Thanks again I could kill her but she is trying to help and sees me at this thing to fix it for her and feels bad.
-
I wouldn't use Uniblue Registry Booster. It could cause more problems then what you have now. The tools in the malware removal guide are plenty and safe.
If you can't find it maybe it never actually got installed?
-
It would be under uniblue correct. Its not in my add /rmove programs. She did not do the scan just hit the download button then I shut the computer down after the folder showed up and looked like it downloaded but maybe I got rid of it on time. She said a folder open then the bars filled up then I shut her down and am back with you.
-
Create An Uninstall List
- Start HijackThis
- Click on the Open the Misc Tools section
- Click on the Open Uninstall Manager button.
- Click on the Save list button and specify where you would like to save this file and click Save.
- When you press Save button a notepad will open with the contents of that file.
- Copy and paste that list in your reply.
-
I wouldn't use Uniblue Registry Booster. It could cause more problems then what you have now. The tools in the malware removal guide are plenty and safe.
If you can't find it maybe it never actually got installed?
Once or twice a week registry scan should help keep your computer in good shape. That's what I was told by a microsoft certified tech support.
RegistryFix is a nice paid program, it sped up my computer after some cleans.
But as of now, terk, finish all the things that evilfantasy is helping you with before getting into other stuff.
-
This PC has enough problems that I'm afraid a registry cleaner might just do it the rest of the way in...
-
This PC has enough problems that I'm afraid a registry cleaner might just do it the rest of the way in...
Of course, fix the problems first. Registry cleaner should just be used for maintenance once computer is in good shape, in my opinion.
-
here ya go
Abacast Client
Adobe Acrobat 5.0
Adobe Flash Player ActiveX
Arts & Letters Clip Art Viewer
aspi
CA Internet Security Suite
CCHelp
CCScore
Efficient Networks SpeedStream DSL
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSstore
ESSvpaht
ESSvpot
Google Toolbar for Internet Explorer
HijackThis 2.0.2
HP Image Zone 4.7
HP PSC & OfficeJet 4.7
HP Software Update
Intel(R) 810/810E/815/815E/815EM Chipset Graphics Driver Software
Kazaa Media Desktop 2.1.1
Kodak EasyShare software
KSU
LiveUpdate 1.80 (Symantec Corporation)
MDP3880-W(U) PCI Modem
Microsoft .NET Framework 1.1
Microsoft Data Access Components KB870669
Microsoft Internet Explorer 6 SP1
Microsoft Office 2000 SR-1 Professional
MSXML 4.0 SP2 (KB936181)
Notifier
OTtBP
Outlook Express Update Q330994
Quicken 2003 Deluxe
QuickTime
Security Update for Windows Media Player (KB911564)
SFR
SFR2
Sony USB Driver
Sound Blaster PCI128 Drivers
Windows 2000 Hotfix - KB329115
Windows 2000 Hotfix - KB842773
Windows 2000 Hotfix - KB896422
Windows 2000 Hotfix - KB896423
Windows 2000 Hotfix - KB899587
Windows 2000 Hotfix - KB899589
Windows 2000 Hotfix - KB900725
Windows 2000 Hotfix - KB901017
Windows 2000 Hotfix - KB905495
Windows 2000 Hotfix - KB908519
Windows 2000 Hotfix - KB908531
Windows 2000 Hotfix - KB911280
Windows 2000 Hotfix - KB913580
Windows 2000 Hotfix - KB914388
Windows 2000 Hotfix - KB914389
Windows 2000 Hotfix - KB918118
Windows 2000 Hotfix - KB920213
Windows 2000 Hotfix - KB920670
Windows 2000 Hotfix - KB920683
Windows 2000 Hotfix - KB920685
Windows 2000 Hotfix - KB921398
Windows 2000 Hotfix - KB923810
Windows 2000 Hotfix - KB923980
Windows 2000 Hotfix - KB924270
Windows 2000 Hotfix - KB924667
Windows 2000 Hotfix - KB925902
Windows 2000 Hotfix - KB926436
Windows 2000 Hotfix - KB927891
Windows 2000 Hotfix - KB928843
Windows 2000 Hotfix - KB930178
Windows 2000 Hotfix - KB931784
Windows 2000 Hotfix - KB933729
Windows 2000 Hotfix - KB935839
Windows 2000 Hotfix - KB935840
Windows 2000 Hotfix - KB936021
Windows 2000 Hotfix - KB937894
Windows 2000 Hotfix - KB938827
Windows 2000 Hotfix - KB941693
Windows 2000 Hotfix - KB943055
Windows 2000 Hotfix - KB943484
Windows 2000 Hotfix - KB943485
Windows 2000 Hotfix - KB945553
Windows 2000 Hotfix - KB948590
Windows 2000 Hotfix - KB950749
Windows 2000 Hotfix - KB950974
Windows 2000 Hotfix - KB951698
Windows 2000 Hotfix - KB951748
Windows 2000 Hotfix - KB952954
Windows 2000 Hotfix (Pre-SP4) [See Q321856 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q322842 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q322913 for more information]
Windows 2000 Hotfix (Pre-SP4) [See q323172 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q324096 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q324380 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q326830 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q326886 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q329115 for more information]
Windows 2000 Hotfix (Pre-SP4) [See Q329834 for more information]
Windows 2000 Hotfix (Pre-SP4) Q328310
Windows 2000 Hotfix (Pre-SP4) Q329170
Windows 2000 Hotfix (Pre-SP4) Q331953
Windows 2000 Hotfix (Pre-SP4) Q810833
Windows 2000 Hotfix (SP4) Q329553
Windows 2000 Hotfix (SP4) Q811493
Windows 2000 Hotfix (SP4) Q814033
Windows 2000 Hotfix (SP4) Q815021
Windows Installer 3.1 (KB893803)
Windows Media Player Hotfix [See Q828026 for more information]
Windows Media Player system update (9 Series)
WinZip
Yahoo! Install Manager
Yahoo! Messenger
I will uninstall yahoo messenger in the morning when wife is not around. Let me know what I can get rid og ty evil and mcxeb52
-
I don't see anything out of place in the list.
-
Then what should we try next? And what would we do about the IEXPLORER.exe Problem. Thanks. Their has to be somthing hideing in their. then maybe try registry scan. Yhat might help if everything looks good. Should I put in malware again and do another scan. I would be happy to get rid of the IEXPLORER the slowness I can deal with. I cannot open my setings for CA either the PC won't allow it. Also under firewall sould safe and restricted both be checked or should restricted have a ? mark under access and mail etc. and YPager.exe, wmplayer and setup-wmexe show up as well should they? Thanks E
-
Preparing to remove Viewpoint Media Player...
Warning accepted, beginning removal process....
ViewpointKiller determined that "aim.exe" was not running.
ViewpointKiller determined that "aim6.exe" was not running.
ViewpointKiller determined that "aolsoftware.exe" was not running.
ViewpointKiller determined that "aol.exe" was not running.
ViewpointKiller determined that "MtsAxInstaller.exe" was not running.
Preparing to close the Viewpoint Manager Service if it is running...
Closing "Viewpoint Manager Service" failed, or the service is not running.
Searching for all known Viewpoint Media Player registry values and keys...
Found and removed: SOFTWARE\Viewpoint
Found and removed: SOFTWARE\Viewpoint
Found and removed: interface\{9dbb28cd-1925-11d3-a498-00104b6eb52e}
Finished searching for and removing all known Viewpoint Media Player registry values and keys.
Searching for all known Viewpoint Media Player files and folders...
Finished searching for and removing all known Viewpoint Media Player files and folders.
Finished reporting.
----------------------------------
Viewpointkiller now HJTL
-
I can't say it any other way. You need to get an operating system disk and repair or re-install the OS. It's damaged and needs the files replaced.
-
ok then how do I get rid of viewpointkiller.exe since I do not need it anymore? It shows up under Winzip
-
Just delete it. It doesn't install it runs from the exe.
-
So I take it we have gone as far as we can. Thank you 4 your help. Next time I will go with a MAC since they seem to be problem free. Thnak you for trying.
-
Sorry we couldn't get it fixed. Sometimes the damage is too great and a reinstall is the only option.
-
If anyone else has an idea let me know. With in 2-3 days the hard drive is comming out n this is going to the curb after my wife's files have been saved. Can you get a good PC for just under 2 grand? I think people who like to send out a virus should be taken out to the paster and.......or is it the company's doin this to sell like they do everywhere else..Would registryfix help somewhat or do more damage at this point? evil has been great and patiant with me I would like to thank evil and anyone else who had input. Keep up the good work and get those PC's you can fix back on track. I am a whistle blower for a MAJOR corp. and I think they had somthing to do with this plus in my position I had less rights then a normal citizan so I think the problems were intentional and started when I got back on line as with the phone clicking. I will continue the fight as it is a moral issue. You cannot sue your employer in NY so no money will come from this I just want to save my life that's slipping and the PC was a way for my wife to investigate that is why it was so important. Good luck to the rest of you. Peace out Terk13
-
well, windows is a usable operating system, and no doubt the most popular.
In my opinion .... one should just get a fresh installation of windows, put a antivirus program on ---> avast, avg or avira and also have firewall like either comodo or pctools or at worst, keep windows firewall on and you should be ok in terms of protection.
then, get ccleaner and run it (I have setup my pc to automatically run ccleaner's clean function at a specific time I wanted) and also run it's registry cleaner now and then.
also defrag your computer using windows defrag tool or get a defrag tool that you can set up to do the defragmenting on a scheduled basis.
----
I have tuneup utilities and it runs fine so far and I have registryfix 7. Both you have to pay for to get program licenses.
----
Then it comes down to being careful when reading email or surfing the web :)
-
I was also wondring about unzipping files. When I downloaded the site winzip came up and I was unable to unzip files. How would I do this and what NEW PC is worth the money nowadays? I do not need anything crazy, Thanks again.
-
Install IZArc, it's free. http://filehippo.com/download_izarc/
-
Thanks Evil I will down load it. Question I know it sounds silly but how do I get rid of YAHOO messenger with voice and reinstall just yahoo messenger? From what I have been seeing the messenger w/voice is the culpret like you mentioned a while back. I need to get rid of it and just put in yahoo messenger w/o voice. Thanks. I think you were right from the get go but all the other programs also helped thank you. If it people like you did not exists we would be spending a fortune. Now that program you just gave me will unzip files and is there anything special I should be looking for anything specieal and can it be removed? Thanks This site is great and VERY helpfull. :)>-
-
Now that program you just gave me will unzip files and is there anything special I should be looking for?
Not that I know of.
Yahoo Messenger. http://filehippo.com/download_yahoo_messenger/download/d60db2f4b0849d4e378ae1f9fe6ffa45/
-
Then just go through the motions and reinstall without voice yahoo? Is that possible? Also in my Task Manager I found 4 IEXPLORER.exe. Do I delete any of them or leave well enough alone. And with yahoo What is the best bet and then I think The problems will be gone then it will be time to figure how to clean this thing out other then defraf and c file sweep. I think we are making progress. Bless you my child lol.. :o 8)
-
You found 4 IEXPLORER.exe in the task manager. Look at them again and what does it say next to each one under "User Name"?
-
Shows them in folders HTML Document One in file folder One in shortcut Then the Internet icon says multible IEXPLORER's I open this folder and it is a mess Shall I post? It's in back up folders man it's all over the place.