Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Windows installer error...  (Read 27882 times)

0 Members and 1 Guest are viewing this topic.

Carbon Dudeoxide

  • Global Moderator

  • Mastermind
  • Thanked: 169
    • Yes
    • Yes
    • Yes
  • Certifications: List
  • Experience: Guru
  • OS: Mac OS
Re: Windows installer error...
« Reply #45 on: August 20, 2008, 08:29:38 AM »
If you have some free time, you may want to consider going through the full deal.
http://www.computerhope.com/forum/index.php/topic,46313.0.html

CBMatt

  • Mod & Malware Specialist


  • Prodigy

  • Sad and lonely...and loving every minute of it.
  • Thanked: 167
    • Yes
  • Experience: Experienced
  • OS: Windows 7
Re: Windows installer error...
« Reply #46 on: August 20, 2008, 05:13:14 PM »
Sorry for not responding sooner, as I wasn't aware of this thread.

Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file.  Open HijackThis and scan again.  Check the following entries, but don't do anything to them yet...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O4 - HKLM\..\Run: [ErrorFixer] C:\Program Files\Error Fixer\ErrorFixer.exe -AutoStart
O4 - HKCU\..\Run: [DietPower 4.4 Update Setup] C:\Documents and Settings\LG\Local Settings\Application Data\{792BCB21-C38B-40B3-96E1-4DFA8C61ED58}\DietPowerSetup.exe /updatesetup

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/SmileyCentralFWBIni tialSetup1.0.1.0.cab


Now, close all windows (including this one) besides HijackThis, then click Fix Checked.  Close HijackThis and reboot into Safe Mode and enable hidden files and folders.

Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...

Error Fixer or System Error Fixer

Please note any other programs that you dont recognize in that list in your next response.

Navigate to and delete the following folder(s) if present...

C:\Program Files\Error Fixer

Once you've done all of this, reboot into Normal Mode.  I would strongly suggest following the link above posted by Carbon Dudeoxide.  Follow the steps and post the SUPERAntiSpyware and MBAM logs along with a new HijackThis log.  In the meantime, I will read through the rest of this thread so I can get a better idea of what your situation is.
Quote
An undefined problem has an infinite number of solutions.
由obert A. Humphrey

Nuriko

    Topic Starter


    Beginner

    Re: Windows installer error...
    « Reply #47 on: August 21, 2008, 08:39:11 AM »
    Thank you for your reply  :)
    I did what you told me, I deleted the 5 logs you told me to delete...

    Quote
    Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...

    Error Fixer or System Error Fixer
    I didn't find this one   :-\

    Quote
    Navigate to and delete the following folder(s) if present...

    C:\Program Files\Error Fixer
    even this one, I didn't find it  :-\ hope it's a good thing!

    This is the new HijackThis Log...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:37:20 AM, on 8/22/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS.0\System32\smss.exe
    C:\WINDOWS.0\system32\winlogon.exe
    C:\WINDOWS.0\system32\services.exe
    C:\WINDOWS.0\system32\lsass.exe
    C:\WINDOWS.0\system32\Ati2evxx.exe
    C:\WINDOWS.0\system32\svchost.exe
    C:\WINDOWS.0\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS.0\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS.0\system32\svchost.exe
    C:\WINDOWS.0\system32\svchost.exe
    C:\WINDOWS.0\system32\Ati2evxx.exe
    C:\WINDOWS.0\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Battery miser\batterymiser.exe
    C:\Program Files\On Screen Display\Hotkey.exe
    C:\Program Files\IP Operator 2005\IP Operator 2005.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\WINDOWS.0\system32\RunDll32.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS.0\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS.0\System32\svchost.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\lg_swupdate\Gilautouc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\Symantec Shared\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\autoupdate.exe" Gilautouc
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS.0\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS.0\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS.0\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS.0\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [batterymiser] C:\Program Files\Battery miser\batterymiser.exe
    O4 - HKLM\..\Run: [KeybdUtility] "C:\Program Files\On Screen Display\Hotkey.exe"
    O4 - HKLM\..\Run: [IPO3] "C:\Program Files\IP Operator 2005\IP Operator 2005.exe" -aUtOsTaRtFrOmReG
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS.0\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 7802 bytes


    Nuriko

      Topic Starter


      Beginner

      Re: Windows installer error...
      « Reply #48 on: August 21, 2008, 11:41:21 AM »
      here's the MBAM log..it detected 17 errors but I didn't delete any of them incase  :-\

      Malwarebytes' Anti-Malware 1.25
      Database version: 1076
      Windows 5.1.2600 Service Pack 2

      8:27:14 AM 8/22/2008
      mbam-log-08-22-2008 (08-27-06).txt

      Scan type: Full Scan (C:\|D:\|)
      Objects scanned: 92202
      Time elapsed: 1 hour(s), 4 minute(s), 57 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 15
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 2

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> No action taken.
      C:\WINDOWS.0\system32\drivers\etc\services (Heuristics.Reserved.Word.Exploit) -> No action taken.

      Nuriko

        Topic Starter


        Beginner

        Re: Windows installer error...
        « Reply #49 on: August 21, 2008, 01:48:08 PM »
        This is the SUPERAntiSpyware scan log...

        SUPERAntiSpyware Scan Log
        http://www.superantispyware.com

        Generated 08/22/2008 at 09:23 AM

        Application Version : 4.15.1000

        Core Rules Database Version : 3542
        Trace Rules Database Version: 1531

        Scan type       : Complete Scan
        Total Scan Time : 00:40:10

        Memory items scanned      : 551
        Memory threats detected   : 0
        Registry items scanned    : 5544
        Registry threats detected : 0
        File items scanned        : 15725
        File threats detected     : 96

        Adware.Tracking Cookie
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@insightexpressai[2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@tacoda[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@tradedoubler[1].txt
           C:\Documents and Settings\LG\Cookies\lg@adlegend[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@americandadx[2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@mediafire[2].txt
           C:\Documents and Settings\LG\Cookies\lg@adecn[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@doubleclick[2].txt
           C:\Documents and Settings\LG\Cookies\lg@overture[2].txt
           C:\Documents and Settings\LG\Cookies\lg@socialmedia[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@2o7[1].txt
           C:\Documents and Settings\LG\Cookies\lg@tdstats[1].txt
           C:\Documents and Settings\LG\Cookies\lg@teenink[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@media6degrees[2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@kontera[1].txt
           C:\Documents and Settings\LG\Cookies\lg@revsci[1].txt
           C:\Documents and Settings\LG\Cookies\lg@mywebsearch[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@mediaonenetwork[1].txt
           C:\Documents and Settings\LG\Cookies\lg@adinterax[1].txt
           C:\Documents and Settings\LG\Cookies\lg@dmtracker[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][3].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@azjmp[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@burstnet[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@smileycentral[2].txt
           C:\Documents and Settings\LG\Cookies\lg@atwola[1].txt
           C:\Documents and Settings\LG\Cookies\lg@nextag[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@xiti[1].txt
           C:\Documents and Settings\LG\Cookies\lg@clicktorrent[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@dollarwarez[2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@adrenaline[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\lg@toplist[2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@calorie-count[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt
           C:\Documents and Settings\LG\Cookies\lg@discountanimedvd[1].txt
           C:\Documents and Settings\LG\Cookies\lg@chitika[1].txt
           C:\Documents and Settings\LG\Cookies\[email protected][2].txt

        Trojan.Unclassified-Packed/Suspicious
           C:\WINDOWS.0\SYSTEM32\B4FM.DLL

        CBMatt

        • Mod & Malware Specialist


        • Prodigy

        • Sad and lonely...and loving every minute of it.
        • Thanked: 167
          • Yes
        • Experience: Experienced
        • OS: Windows 7
        Re: Windows installer error...
        « Reply #50 on: August 21, 2008, 07:34:46 PM »
        It's okay that you couldn't find ErrorFixer.  As long as the files are gone, then you should be okay.

        Go to Add/Remove Programs and uninstall MyWebSearch.  Then run the MBAM scan again and let it remove all of those files.  When this program finds anything, it's safe to delete them 99% of the time.  If it ever detects an incorrect file (or false positive), then the process can be undone if necessary.

        Anyway, go ahead and follow these instructions and post a new MBAM log along with one more HijackThis log.

        And while you're at it...  You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo.  They're all good free firewalls.  Just be sure you only have one installed at a time!  Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.




        Are you still having trouble with the diet program?
        Quote
        An undefined problem has an infinite number of solutions.
        由obert A. Humphrey

        Nuriko

          Topic Starter


          Beginner

          Re: Windows installer error...
          « Reply #51 on: August 22, 2008, 07:04:30 AM »
          ok I could download one of these Firewalls but from a previous experience I downloaded Comodo but when I installed it suddenly I can't enter my router page!!
          (I have Linksys ...the page is 192.168.1.1), was the Firewall the actual cause of this situation or it was just a quencedence??

          Quote
          When this program finds anything, it's safe to delete them 99% of the time.  If it ever detects an incorrect file (or false positive), then the process can be undone if necessary.

          how can it be undone??? is it simple?

          no I still can't uninstall the software  :-[ but I think the start up error is gone  :)

          p.s: sorry for the stupid questions  :-[

          CBMatt

          • Mod & Malware Specialist


          • Prodigy

          • Sad and lonely...and loving every minute of it.
          • Thanked: 167
            • Yes
          • Experience: Experienced
          • OS: Windows 7
          Re: Windows installer error...
          « Reply #52 on: August 22, 2008, 07:13:12 AM »
          ok I could download one of these Firewalls but from a previous experience I downloaded Comodo but when I installed it suddenly I can't enter my router page!!
          (I have Linksys ...the page is 192.168.1.1), was the Firewall the actual cause of this situation or it was just a quencedence??
          It could have been the firewall; you have to make sure you ALLOW your internet connection so Comodo won't block it.  You have to play around with it a bit to get used to how the program works.

          how can it be undone??? is it simple?
          It's fairly simple, but I wouldn't worry about it right now.  You most likely won't ever have to do this.

          no I still can't uninstall the software  :-[ but I think the start up error is gone  :)
          I'm glad to hear that the error is gone.  I'm not sure what to do about uninstalling the program, though.  Perhaps you would have more luck at the DietPower forums...
          http://forums.dietpower.com/forum.asp?FORUM_ID=1
          Quote
          An undefined problem has an infinite number of solutions.
          由obert A. Humphrey

          Nuriko

            Topic Starter


            Beginner

            Re: Windows installer error...
            « Reply #53 on: August 22, 2008, 04:42:24 PM »
            ok now the file is removed from my program files but it's still not removed from my Add/Remove programs...can I uninstall it manually?? like from the register or somthing?? I would like simple instructions for that  :)

            CBMatt

            • Mod & Malware Specialist


            • Prodigy

            • Sad and lonely...and loving every minute of it.
            • Thanked: 167
              • Yes
            • Experience: Experienced
            • OS: Windows 7
            Re: Windows installer error...
            « Reply #54 on: August 22, 2008, 05:13:33 PM »
            One thing you can do is download CCleaner and install it.  Once this has been done, run CCleaner and click on Tools.  Find the DietPower in your list of programs and click on Delete entry.  Note: this step can't be undone.  Once you've done that, click on Cleaner and then click on Run Cleaner.  This will get rid of junk files that you don't need (it doesn't delete anything important).  When that finishes, click on Registry and then click on Scan for issues.  This will scan your registry for entries that are no longer being used.  When the scan has completed, click on Fix selected issues.  It will ask if you want to create a backup.  You don't have to, but I would suggest doing it, so click on Yes and then Save the file somewhere.  Another window will come up.  Click on Fix All Selected Issues and then OK and then Close.  You may now close CCleaner.


            It sounds like a lot, but it is actually quite simple.  Just download the program and you should have no problem following my instructions.
            Quote
            An undefined problem has an infinite number of solutions.
            由obert A. Humphrey

            Nuriko

              Topic Starter


              Beginner

              Re: Windows installer error...
              « Reply #55 on: August 22, 2008, 05:21:54 PM »
              will it remove it from Add/Remove program list?????

              CBMatt

              • Mod & Malware Specialist


              • Prodigy

              • Sad and lonely...and loving every minute of it.
              • Thanked: 167
                • Yes
              • Experience: Experienced
              • OS: Windows 7
              Re: Windows installer error...
              « Reply #56 on: August 22, 2008, 05:35:34 PM »
              Yes, once you click on Delete entry, it will be removed from Add/Remove Programs.  The other steps are simply to clear up extra files and registry entries that the program may have left behind on your computer.
              Quote
              An undefined problem has an infinite number of solutions.
              由obert A. Humphrey

              Nuriko

                Topic Starter


                Beginner

                Re: Windows installer error...
                « Reply #57 on: August 22, 2008, 05:58:21 PM »
                Thaaaaaank youuuuu verrry much CBMatt  :D
                you were verry helpfull  ;) (you too Carbon Dudeoxide were very helpful :))
                one last question though  ;D
                the program DietPower is now deleted from my Program Files and Add/Remove program list! is it considered removed from my computer???

                CBMatt

                • Mod & Malware Specialist


                • Prodigy

                • Sad and lonely...and loving every minute of it.
                • Thanked: 167
                  • Yes
                • Experience: Experienced
                • OS: Windows 7
                Re: Windows installer error...
                « Reply #58 on: August 22, 2008, 06:52:35 PM »
                You are very welcome, Nuriko!

                The majority of DietPower should be gone, but it can very difficult to remove every single little trace of a program for your computer.  Even when you are able to uninstall a program the proper way, many of them still leave certain files behind.  Because I'm not familiar with DietPower, I don't really know what other files it may have installed.  You shouldn't have to worry about it, though.  You most likely won't come across anything, and it shouldn't be taking up space on your computer.

                You could search your computer for anything related to DietPower, but in my opinion, it's probably not worth the effort.
                Quote
                An undefined problem has an infinite number of solutions.
                由obert A. Humphrey