InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1501. |
Solve : STOP:C000021a - 0xc0000005 - Can't boot up? |
|
Answer» Was recently hit with some BAD malware/viruses. Took it upon myself to do some "diagnosing" and found one of the culprits to be masked as CSRSS.EXE. Well,...long story short; I deleted the "GOOD" CSRSS.EXE from the Windows/System32 directory, and now I'm SCREWED. |
|
| 1502. |
Solve : how important are windows updates?? |
|
Answer» Hi all, |
|
| 1503. |
Solve : I got the Your computer is infected popup? |
|
Answer» Hello, OK, I reinstalled mbam still the same runtime error. As for the logging into safe mode I can't seem to get F8 to work at the win banner. your supposed to press f8, before the windows banner even appears; personally I just hit f8 repeatedly when I start my PC if I need safe mode.I can finally get to safe mode but I am not able to use SUPERSPYWARE or mbam to do anything. I click on them and they do nothing. superantispyware does then show up in the sys tray but I can't start a scan. I am about to reformat and start over. Is there anything else to do?Try renaming the programs and then try run in safe mode.I renamed the programs still not running in safe mode. Is there anything else I can do?Only thing I can think of- is combofix... May as well give a few more things a try. Make sure to BACKUP all the stuff you want to keep in case you end up needing to reinstall, which hopefully won't be the case, but you can never be too prepared. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a LIST of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will PRODUCE a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFix ---------- attach the combofix log to your next reply. |
|
| 1504. |
Solve : followed the instructions on malware thread. have logs. waiting for help? |
|
Answer» p.s. there were no errors in dial-a-fix. also, when i tried to reset internet explorer settings, it said that it had failed, and there was a big red 'X' NEXT to "resetting user CUSTOMIZATIONS". don't know if i should worry, since i don't really use internet explorer anyway Quote don't know if i should worry, since i don't really use internet explorer anyway You still use IE even though you don't open it. It's PART of the Windows shell so has to work properly in order for everything else to fall in place That's why it's still important to keep Windows Updates current. I'm not sure why the CPU is running so high. You might start a topic in the Windows forum on that. Final steps. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your COMPUTER. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.i'll definitely check out the windows section for my computer speed. thanks so much for all of your help! really appreciate it!Your welcome. Safe surfing...thank you!!! |
|
| 1505. |
Solve : How to: XP repair installation on partioned HD?? |
|
Answer» I've searched on "How To's" to do this. However, all of them (example) are like this: |
|
| 1506. |
Solve : Essential Security? |
|
Answer» Hi |
|
| 1507. |
Solve : Something new and nasty? |
|
Answer» I dont think something left from the last time.
|
|
| 1508. |
Solve : evil fantasy: need some help? |
|
Answer» Running out of options here...how about the keyboard ...... is it PS/2 or usb?..... came across some posts on another forum stating the USB keyboard can be at fault....and to make sure USB is enabled in Bios....can you try another keyboard and see if it makes a difference. (tapping F8 key, computer does not go into safe mode) Where is the USB plugged in? The tower or somewhere else?evilfantasy, by USB do you mean my keyboard? This is a Logitech PS/2 keyboard and it is plugged into the back of the tower. Quote from: beachguy on August 14, 2009, 04:12:07 PM This is a Logitech PS/2 keyboard and it is plugged into the back of the tower. Yea that's what I meant. Sometimes people plug in the keyboard to a monitor that has USB plugs. Since the monitor LOADS after the tower you can't use keyboard commands soon enough to get into the the boot options. Note: NEVER force Safe Mode if your computer is infected with malware. You may end up in a boot loop and have to reformat/reinstall. See here for details. Alternate method of entering Safe Mode. Force Windows to Boot Into Safe Mode Without Using the F8 Key There is also a tool in the SUPERAntiSpyware folder called BootSafe that you can use but again don't use it if your infected. http://www.superantispyware.com/WebHelp/How_do_I_boot_to_Safe_Mode_.htm XP - C:\Program Files\SUPERAntiSpyware > Double click Bootsafe Or Vista 64BIT - C:\Program Files (x86)\SUPERAntiSpyware > Double click Bootsafeevilfantasy, Thanks for the links. Now that everything is working again, I will just keep them for future reference. beachguy |
|
| 1509. |
Solve : Trojan-GameThief removal help? |
|
Answer» Several months ago I had gotten a similar infection on my computer and the guys at Bleepingcomputer.com helped, but they don't seem to be around anymore. They had recommended SuperAntispyware and Malware Bytes. I ran the Super Antispyware in Safe Mode and the logs are attached. the guys at Bleepingcomputer.com helped, but they don't seem to be around anymore.Huh? http://www.bleepingcomputer.com Quote C:\System Volume Information\_restore{63EFC063-C398-4284-88BB-D9A39A12ED8}\RP723\A0085341.exeThe REASON you are getting this is because the System Volume Information FOLDER is what the computer uses if you perform a System Restore. To get rid of it, - reset and re-enable your System Restore to remove infected files that have been BACKED up by Windows. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check "Turn off System Restore". Click Apply, and then click OK. 2. Restart your computer. 3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Uncheck "Turn off System Restore". Click Apply, and then click OK. |
|
| 1510. |
Solve : VIRSUES AND SPYWARE PLEASE HELP!!!!!!!!!!? |
|
Answer» How is the computer running now?it is better so far! thank you so much! Now is there anything else I need to do? Is there a way I can fix this problem with GETTING sp2? And do i need to keep all of these programs that this SITE has had me download?
. .
---------- You may need your product key for this. Go to How to Tell (Microsoft website) using Internet Explorer (not Firefox or any other browser as they won't work)
I did what you said and this is what i got This copy of Windows did not pass genuine validation. The product key found on this computer is a Volume License Key (VLK) that has been blocked.Call 1-866-PCSAFETY (1-866-727-2338). This phone number is for security-related support and you can explain to them what happened. They should be able to get you a new working key. It is available 24 HOURS a day for the U.S. and Canada.Unfortunatly that didnt work, because they said in order for them to generate a new product key, i have to have the cd, and it has to be one bought in the store.There isn't anything we can do here.well ty for all of your help! what do i do with all of these programs on my computer? which should i keep? Keep Malwarebytes and SUPERAntiSpyware. Update and run them now and then. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being ADDED to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.ok what about avira antivirus, ccleaner, hijackthis, securitycheck, sniper, and all of the log files?Obviously you want to keep Avira. You can delete or uninstall the others.just do it through add or remove pregrams?Now it is happening again, the ie windows are popping up all over the placeYou need to get a windows key and reinstall the right way. Until you get all of the Windows Updates this will likely keep happening no matter how much we try to clean it. |
|
| 1511. |
Solve : spamer has got my friends pc address? |
|
Answer» i got an e-mail from a friend and i new it was spam right away and she said she did not send it , so they have all kinds of electronical products I loves electonical products! Quote motorcycles Especially motorcycles! i had wot on my pc and took it out and now use below http://www.trendsecure.com/portal/en-US/tools/security_tools/trendprotect/overviewI ALWAYS wondered how people got a hold of my email address when it weren't given away or I had no given it away knowingly or something. If it's a yahoo address, you can get a new email address to same inbox.kpac , is there any why of stopping mail using her address or is it a lost cause , i know she can get a new addressWhy doesn't she use Mailwasher. I've been using it for years and it works great. Just PREVIEW the mail and bounce it before it reaches the computer. http://www.mailwasher.net/ Quote from: harry 48 on June 11, 2009, 04:07:34 PM kpac , is there any why of stopping mail using her address or is it a lost cause , i know she can get a new Nope, UNFORTUNATELY, there is no way to stop it without changing her email address. |
|
| 1512. |
Solve : 3 to 5 viruses and or spyware that wont go away? |
|
Answer» Ok, so my computer have these annoying files that don't get deleted when told to. One is called cool OOZE, another called amok eggs four web, and a delself.exe that keeps disappearing when I delete it and coming back somewhere else. There are a few other FILE that I don't remember, but they don't seam to show up in the logfile. There is also a Program that's called holetr~1.exe that comes up in my task manager when I try to delete anyone of the two iexplorer.exe that are that making them come back up. After starting iexplorer.exe it disappears. While using mozilla firefox the iexplorer.exe opens pop ups no matter what site I am on in firefox. I also want to delete anything related to hxxp://googlesearch.uuuq.com/ which got installed in my computer by itself, it seams. I haven't installed any new software from the point before and after I got hxxp://googlesearch.uuuq.com/ on my computer.
Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, EXIT HijackThis. ---------- Download OTM by OldTimer to your desktop. Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator. * Save it to your Desktop. * Double-click OTM.exe to run it. * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy) Code: [Select]:Processes explorer.exe :files C:\Documents and Settings\All Users\Application Data\part dead amok eggs C:\DOCUME~1\Yay!!!\APPLIC~1\STUPID~1 :Commands [purity] [emptytemp] [start explorer] * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste. * Click the red Moveit! button. * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply. Close OTM Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. ---------- If you already have Malwarebytes be sure to update it before running the scan! Download Malwarebytes' Anti-Malware (MBAM) Alternate MBAM download link
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. ---------- Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. 1) DDS.txt 2) Attach.txt * Save both logs to your desktop. * Please copy and paste the entire contents of both logs in your next reply. Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copy and pasting it into the reply. ---------- Next post please add:
|
|
| 1513. |
Solve : quariintined files? |
|
Answer» Hello |
|
| 1514. |
Solve : Does my computer still seem to be 'hacked'?? |
|
Answer» Recently I had to create a new FACEBOOK account due to someone HACKING in to it and also they changed my hotmail account password etc and now recently on my old facebook account there is a picture of myself EXACTLY the same as on my new account and they are also friend requests being sent out from my old facebook account to my friends on my new one. |
|
| 1515. |
Solve : Another IX-Find victim? |
|
Answer» Hello, and thanks in advance for the help.
. The above procedure will:
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 1516. |
Solve : unable to open internet explorer or internet options? |
|
Answer» IE7 wanted to update to IE8 and when it did am unable to open internet explorer from any of the links. When ever I tried the window would pop up like it normally should but then after about 2-5 seconds it would close again. When i tried to open internet options nothing would happen. I'm currently unable to surf the web though internet explorer. I talked to JustJoe on the live chat and he had me try several different things but to no avail, come to find out i couldn't even download anything. i was able to search the web by using either bitlord's web search or by using the windows help and support center. |
|
| 1517. |
Solve : Additional IE window opens when launching IE? |
|
Answer» This problem started a few days ago. When I open an IE BROWSER another one will pop up a few seconds later. The second one will be an ad but it won't always be the same one. It could be for VBS.TV, NEXPLORE.COM, PREMIERECARDOFFERS.COM, HOWIMADECASH.COM, etc. |
|
| 1518. |
Solve : Possibly Infected? |
|
Answer» Download ComboFix© by SUBS from one of the below links. Be sure top save it to the Desktop. |
|
| 1519. |
Solve : Infected Computer -- help!? |
|
Answer» I'll try to be brief but thorough. I am an intermediate computer user and know my way around Windows. My machine is a Pentium 4 with 512MB ram running Windows XP Pro SP3. This is a work computer connected to a small office network. |
|
| 1520. |
Solve : strang eMails? |
|
Answer» anyone ever heard of Noelia Trossero? attachment: "sexy picture of me, Neolia Trossero.exe" lol the name does have somewhat of an attractive ring to it.......gosh I want to look at it!! GO to the library and use their computer. yeah get them infected. I get alot of that stuff not this one I recall but its mainly spam.attachment 2: Melissa.jpg.vbs attachment 3: ILoveyou.txt.vbs You could always set the filter on your email to block it.you could just mark it as spam, not sure if it will then see others like it like that after WARDS or not.If you think it is spam, but you still want to open it, use someone elses computer. Do you have someone you dont like at all that would let you use their computer? Personally I open them to get their address. Hotmail only opens the main part, not any links within the email. Then set the filter to disallow from that web address, and delete them. Mystery cured. Hey, I have some mystery files I want to open, so, all you folks who are advocating using someone's else's computer, I'm sure you'll step up and help me out. If it's good enough for someone else, ought to be good enough for you. Find the sandboxie SOFTWARE which was recommended a while back, open it on your computer, or DECIDE whether you can live without knowing. |
|
| 1521. |
Solve : I'm having a really bad day!? |
|
Answer» Since installing a new printer, I've had no end of problems (got a post ongoing in another forum). Maybe coincidence, but since then my system has been acting really weird and slowing down but it's not a virus (?) as SAS and MBAM run clear. |
|
| 1522. |
Solve : ME anti-virus/malware?? |
|
Answer» I know very little about computer software. I have a anti-virus/malware PACKAGE through AVG 7.5. AVG quit giving me updates on the 7.5 version on 4/30/09. They do not support ME in their version 8. Does anyone know of a company that has and is still supporting anti-virus/malware for a ME? I am not "obsolete" and can not afford to upgrade my computer. Thanks in advance, Jayhttp://www.avast.com/eng/avast_4_home.html |
|
| 1523. |
Solve : how dangerous is this?? |
|
Answer» I'd been having a bit of time lately with malware on some of my websites. I've scanned my computer with three programmes and it seems clear for the moment. HOWEVER, I noticed something on a website yesterday. It is a script TAGGED onto the END of the some of the PAGES. Could someone tell me how DANGEROUS this script is please? I've only put a portion of it here, it is actually very very long |
|
| 1524. |
Solve : Do I have a problem?? |
|
Answer» I had a power interuption (lights blinked) while online & my computer restarted. When it finished loading & before I touched it, Zone Alarm had popped up with this MESSAGE. |
|
| 1525. |
Solve : Worst virus in the world? |
|
Answer» What has happened: Do you know anyone with a router? If so you need to set up a network, with another computer with a strong anti virus, use the boot sequence order to boot from networking, use this network to control your computer, and run the anti virus. Sometimes this works, and others not so much. that won't work. At all.I hear about a program called DBAN. I'm having trouble putting DBAN-2 on my flash drive because it does not come with a .exe like DBAN-1. Can anyone help me use an .iso file when I boot from a usb flash drive?I think Step 5 is what you want. http://www.ucd.ie/itservices/itsupport/itsecurity/securitytools/howtocreateadbandisktoerasecontentsofaharddisk/ Quote from: ireland-1 on June 23, 2009, 03:42:28 AM Do you know anyone with a router? If so you need to set up a network, with another computer with a strong anti virus, use the boot sequence order to boot from networking, use this network to control your computer, and run the anti virus. Sometimes this works, and others not so much.Why would you not just use an anti-virus program on a bootable cd?because she said she can't boot from one, that is what I had in mind when I came to this post, but as I read on I found out that she can't use it. |
|
| 1526. |
Solve : Getting rid of norton Antivirus? |
|
Answer» I am having trouble removing Norton 2006. The add/remove will not let me. It keeps telling me that live update is on {whether it is or not} and then stops. Is there SOMETHING I have missed, because I was UNABLE to find a UNINSTALL.... please help. |
|
| 1527. |
Solve : Bob-PC (D:)? |
|
Answer» If ComboFix alerts you that an antivirus is running just ignore it and keep on with the instructions. |
|
| 1528. |
Solve : I.explore x 2 in task manager & Scan logs? |
|
Answer» Hi Thanks strange now I have the yellow shield in the TASK BAR again & cant install the attached same problem which we managed to cure before! Im wondering if its definately needed? |
|
| 1529. |
Solve : Where to start !? |
|
Answer» My gf puter is very very sick. I plan on using all the info and available tools from here to cure the ills. |
|
| 1530. |
Solve : Best adware/malware tool? |
|
Answer» What about spyware blaster by javacool? Quote from: Bgs on June 15, 2009, 12:08:02 AM yeah except that one but I have a question in some Malware Removal sites in their removal guide i saw that Hijack this was replaced by OTListIt but still it is used even in that site it is some kinda confusing because we must learn how to read logs in HJT but in their malware removal guide they tell us that it has been replaced by OTL .sounds like geeks2go... Very good trustful site so it might want to be changed here too.DDS is another one which could replace HJT.I know I'll take some flack on this one, but I've been using Stopzilla for the past six months and it's one of the best programs I've used.....Nothing seems to get by it.....customer support is the best I've ever used, within minutes of an email there's a response......I downloaded the latest version and I think it performed well against the Spycar Suite, but I don't know whether I used the suite correctly... Kpac , PERHAPS you can RUN Spycar on Stopzilla and share your findings.....I found it worked well, but I'm not sure I did things right.autoruns is my FAVOURITE Hijackthis-equivalent. It has some stuff HJT doesn't have. Quote from: Karnac on June 15, 2009, 02:25:46 PM Kpac , perhaps you can run Spycar on Stopzilla and share your findings.....I found it worked well, but I'm not sure I did things right. What am I, the forum's virtual malware TESTER? Quote from: kpac on June 16, 2009, 04:23:57 AM What am I, the forum's virtual malware tester? Yes, and evilfantasy and broni are the designated malware fixer.I'll be NEEDED a custom title so.... |
|
| 1531. |
Solve : OnLine Banking Security? |
|
Answer» I use Win 2000 and IE 6.0 fully updated and I am considering banking online. also if your bank's website offers secure login vs standard login, then always use the secure login method. Right! Always look for https://www.example.com rather than just http. The "s" means it's a secure connection. https = hyper text transfer protocol secure |
|
| 1532. |
Solve : Laptop Buggy, Followed instructions, logs attatched.? |
|
Answer» Hi there,
- Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check "Turn off System Restore". Click Apply, and then click OK. 2. Restart your computer. 3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Uncheck "Turn off System Restore". Click Apply, and then click OK. - Keep your operating system up to date by visiting Microsoft Windows UPDATE frequently. - Be aware of what emails you open and what websites you visit. MyWOT (for Firefox) or McAfee Site Advisor (for Firefox and Internet Explorer) warns you when you visit bad or unwanted sites.Thanks, going to download comodo, I'm guessing Windows Firewall isn't secure enough. Seems fine now, I knew isn't wasn't too bad, you know what teens are like adding webfetti and the like. Quote Thanks, going to download comodo, I'm guessing Windows Firewall isn't secure enough.Yes, I would recommend Comodo over Windows - far better. Quote you know what teens are like adding webfetti and the like.Yes I do, being one myself. Fortunately, I am one of the sensible ones. Quote from: kpac on June 16, 2009, 12:56:07 PM Yes, I would recommend Comodo over Windows - far better. Glad to see you are mis-spending your formative years wisely, not downloading webfetti =) Many thanks for you're help. Quote from: evanesco on June 16, 2009, 12:59:56 PM Many thanks for you're help. No problem at all. Safe computing. |
|
| 1533. |
Solve : My Logs are Enclosed....? |
|
Answer» After trying to watch a video on a website about donating plasma, all my PROBLEMS started. It sounded like commercials were playing although I couldn't SEE anything running. I would also try to go to websites and be taken to something other than what I clicked on. After finding your website, I followed the instructions and I've attached all 3 logs. It seems as if something I did may have worked because I haven't had any of the problems for a little while but I wanted to follow through with the directions given. Thank you so much for your help!!! |
|
| 1534. |
Solve : Enourmous Fonts & Devise Manager missing? |
|
Answer» I am working on Windows XP. I was on my laptop and laid SOMETHING on the keyboard..I Think it was a FILED folder that I wrote on. When I picked it up everything on my COMP was larger. |
|
| 1535. |
Solve : Device manager is gone? |
|
Answer» I DONT' know where it WENT? Can I downlone it?it cannot be gone. Go to START - RUN and type devmgmt.msc and press ENTER. What happens? by the way, my computer can pick up other devices when they are connected with the usb, like my ipod, etc....That's nice.I just banned you on another forum for this spam/signature. Stop or you will be banned here as well. Quote from: mekarls on October 23, 2010, 01:10:36 PM by the way, my computer can pick up other devices when they are connected with the usb, like my ipod, etc.... |
|
| 1536. |
Solve : Need help with this error. c:\windows\soct32gi.dll? |
|
Answer» OS = Win XP When the computer boots and get to the desktop I get a pop-up box with the following: c:\windows\soct32gi.dll I think the entire message is: system error c:\windows\soct32gi.dllI'd like to know for sure. Meanwhile, open msconfig and choose "selective startup" (disable all startup items) and REBOOT. Does the message appear?Ok, Allan. Can't go MUCH further. I have no access to the computer. I can call and have them do the 'selective startup'. What should we look for? If the error appears after doing it...then what. If it does not appear.....what next? 99% sure that was the entire error message. c:\windows\soct32gi.dll is correct. Sorry, I have not given you much to go on. I know it's difficult and I appreciate your trying to help.Let's not do this third party. Have your friend do as I suggested and he can post here. I agree. The only reason I got involved is because he doesn't know 'crap' about how a computer works. Thanks for your help. |
|
| 1537. |
Solve : Help with a virus.? |
|
Answer» Which files should i remove with hijack this? ( have tried the previous steps in Read this before REQUESTING malware removal help thread) |
|
| 1538. |
Solve : connection to security sites is interrupted? |
|
Answer» That's likely a temporary file e can clean with CleanUp!
the C:\boot.txt was not deleted what do i do KNOW? thanks again for all the helpC:\boot.txt is a Text file so it can't do anything malicious. You can open C: and delete it yourself.yeah, i have deleted it. thanks for all the HELP. SOUNDS good. Any lingering problems?nope. connection is not interrupted anymore. and a huge boooooost of COMPUTER speed and internet browsing.. |
|
| 1539. |
Solve : W32\Conficker.worm? |
|
Answer» I have an infected PC again! |
|
| 1540. |
Solve : Maybe virus, maybe not.? |
|
Answer» Woah, no need to thank me. Quote from: evilfantasy on January 13, 2009, 07:07:06 PM You can delete them if you don't want them for your tests.Did the system restore, but not the Sun thing, i dont feel a need to do that. Thanks for all your help. Quote i dont feel a need to do that. You "feel" that outdated software is OK?software isn't like swiss cheese. it's better with fewer holes Good luck on getting help with the next infection. Although we do this free it is work reading the logs and coming up with fixes. You'll take our advice to remove the bad guys but not the advice in KEEPING secure. That's very insulting.... |
|
| 1541. |
Solve : bleeping computer malware removal? |
|
Answer» i want to sight up for malware REMOVAL but i get a error that says Quote No available slots. Please check back at a later time what does that mean Quote from: tylerisdabest on January 14, 2009, 09:02:29 PM i want to sight up for malware removal but i get a error that says QuoteNo available slots. Please check back at a later time It's actually quite difficult to ascertain exactly what that MESSAGE means. One possibility- and I'm just throwing out there- but it could mean that there are no available slots, and you should check back at a later time. Just a completely random guess at what it could possibly mean.It might also mean if you check back there may or may not be available slots... Quote from: PATIO on January 15, 2009, 07:10:45 AM It might also mean if you check back there may or may not be available slots... another possibility. It's HARD to tell THOUGH, it's only 99.99999% clear on what is says. |
|
| 1542. |
Solve : Automatic Updates Turned Off? |
|
Answer» I was hoping that would work. Glad it did!
. The above procedure will:
---------- DOWNLOAD OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed) 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive PROGRAMS alerts you, allow it access. 4. Click YES at the NEXT prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.OK, a few more things to ask: When I was doing the SDFix, I think, I got an Error that said: "Cannot find /// FAST Hardlock Driver!" then another message saying: "HLVDD.DLL. An intallable Virtual Device Driver failed Dll initialization. Choose 'Close' to terminate the application." A few times I just hit cancel but after like three times I had to choose close, that's when SDFix went all the WAY through. I was wondering, is this a problem? Also, when I did the Secunia Software Inspector, it said I had to update 13 types of Java and 9 types of Flash. What am I supposed to do? Update every one of them? And, is it worth getting SpywareBlaster if I have SAS? Quote from: ShadeLurker on January 15, 2009, 02:10:40 PM And, is it worth getting SpywareBlaster if I have SAS? Yes it's worth it. First install the new Sun Java Runtime Environment Be sure to close all browser windows before beginning the install. Remove the old version(s) Download JavaRa
Do this to remove all unstable older versions of Flash. Download the Flash Player Uninstaller and save it to your desktop. Run the uninstaller program and then reboot your computer to complete the uninstall. Download and install the latest version of Flash PlayerOk, this time the test came out much more credible. Now I still have 2 Java's of the same type that are outdated though. Is there anything I can do? A picture of what's showing up for me: http://i205.photobucket.com/albums/bb27/Shadow-Village-Ninja/Created%20by%20me/javainsecure.jpg Sorry for being a bother.No picture... Go to Add/Remove Programs and uninstall all but Java 6 update 11.Ok these are just frustrating little problems I guess I will deal with later. Anyways, thank you for your help in getting my computer back to it's normal state. |
|
| 1543. |
Solve : Suspected Malware problem. Need help!? |
|
Answer» I am having a problem with my Dell Inspiron 6000 laptop (Win XP SP2 running AVG 8.0, ADAWARE, and Zone Alarm) and hope you can offer some suggestions. I have been through the process outlined here and similar forums to erraticate viruses/malware before, but this time I'm stuck. |
|
| 1544. |
Solve : Really dumb question, what's a log?? |
|
Answer» Hi, |
|
| 1545. |
Solve : dumprep 0 -k? |
|
Answer» Perusing under misconfig - startup, I have noticed a new item, or at least I think it is a new item; dumprep 0 -k. What is this? I can find a little info on dumprep 0 -u but not the k. Is it safe to disable this from the startup? Is it a virus?
I have attached the HijackThis log and await further instructions. Again, thank you! [attachment deleted by admin]Oh yeah, I forgot to add to my earlier post - yes indeed, the computer recently crashed.There are a few Install Shield Update Services that are completely useless we can fix also. Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) - O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup - O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start - O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler - O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they COULD damage the workings of your system Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "ISUSPM Startup"=- "ISUSScheduler"=- "ISUSPM"=- "KernelFaultCheck"=- Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. Run CCleaner and restart the computer. Is everything else running OK?Okay, mission accomplished and I did receive a success message. On a side note: I only copied and pasted the information that was posted in the grey box from REGEDIT4 to "KernelFaultCheck - I did not include the word "Code:" that was outside the box. So if this omission was a mistake...oops. I noticed quite a few curious items in HijackThis, like most of the 08 entries and a couple of 09 and 016. What's the Easy Webprint stuff? Do I need it? I have a Canon camera but I never upload or download anything from my camera to the web. Ditto with Kodak gallery (016). Plus, I have about a dozen items that I had previously disabled in my startup. I am embarrassed to confess that I was using MSCONFIG as a startup manager. Should I list those for you to see if I should take care of them another way? As of late my computer has slowed somewhat and I have noticed a few quirky things - like my icons occasionally disappear for a few seconds, my wallpaper vanished suddenly today, never to return, and my computer crashed a few days ago when I was photo editing in Adobe Elements. Nothing terribly IMPOSSIBLE, just perplexing. Nothing shows up with my anti-virus or spyware. I had work done to rid myself of a trojan (see Help Removing RedGirl Trojan thread) and after that it looked like I was all clear. Thank you for your time and help! Quote Okay, mission accomplished and I did receive a success message. On a side note: I only copied and pasted the information that was posted in the grey box from REGEDIT4 to "KernelFaultCheck - I did not include the word "Code:" that was outside the box. So if this omission was a mistake...oops. That was right Quote I noticed quite a few curious items in HijackThis, like most of the 08 entries and a couple of 09 and 016. What's the Easy Webprint stuff? Do I need it? I have a Canon camera but I never upload or download anything from my camera to the web. Ditto with Kodak gallery (016). Yes that is likely printer and extra context menu items. I usually don't pay much mind to those entries. I do look at them but it is very rare that anything malicious will get in there. See this guide to better understand HJT entries. http://www.bleepingcomputer.com/tutorials/tutorial42.html Quote Plus, I have about a dozen items that I had previously disabled in my startup. I am embarrassed to confess that I was using MSCONFIG as a startup manager. Should I list those for you to see if I should take care of them another way? Enable Normal stsrtup in MSCONFIG, restart the computer and post a new HJT log. We'll get everything that you don't WANT running at startup taken care of that way. If you list them that will help so I don't have to decide for you Quote As of late my computer has slowed somewhat and I have noticed a few quirky things - like my icons occasionally disappear for a few seconds, my wallpaper vanished suddenly today, never to return, and my computer crashed a few days ago when I was photo editing in Adobe Elements. Nothing terribly impossible, just perplexing. After we get the startups under control we will have a look at another scan to see if anything is found.Happy Holidays! Hope the last week has been a good one for you. So, I have enabled normal start-up in msconfig and have run a hijack-this scan - the log is attached. Previously I had unchecked from start-up the following: BJMyPart Communications_H Quickcam10 LVCOMSX Opware SE4 SSBKgupdate StxMenuMgr GoogletoolbarNotifier WMPNSCFG Adobe Reader Bluetooth Manager Cisco Systems VPN I don't even know what some of these do, but a friend had advised me they were unnecessary at start-up. I'm not getting rid of any vital part of a program, correct? I can still access these programs when I need them through the shortcuts, yes? I only use the QuickCam sometimes, ditto the Cisco Systems (which I use RARELY). Bluetooth Manager would be great since I received a bluetooth mouse for Christmas, but I can't get the device and the program to successfully communicate with each other even after intervention with Microsoft Support help. Arggghh. So, I don't think I need it at start-up. Any thoughts? Thank you for all your patience and help!Umm, Ooops. This time the log is REALLY attached! [attachment deleted by admin]Yes you will still be able to use them. Just start them from the Start menu. --- Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there)
Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "SunJavaUpdateSched"=- "Alcmtr"=- "StxTrayMenu"=- "SSBkgdUpdate"=- "OpwareSE4"=- "LVCOMSX"=- "LogitechQuickCamRibbon"=- "LogitechCommunicationsManager"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"=- Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. ---------- Download CCleaner Slim and save it to your Desktop. When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe Follow the prompts to install the program. Complete the installation then:
---------- How is everything now?Done! Everything seems to be running smoothly except for the occasional disppearing icon, but since they only blink-out for a few seconds at a time this isn't too distracting. Haven't had a system crash in a while! What is the best way for a novice to manage the start-up services? Should I just come to this forum occasionally and have someone look at it - or is there a program that would help me do this? Thanks for all the work. I really, really, appreciate it!I prefer using StartUp 1.3. http://majorgeeks.com/StartUp_d4436.html Just run it and right click on anything you don't want running at startup and choose Remove. ---------- Try Dial-a-fix. Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.
Is the icon problem fixed?Okay, so under services I see that several items are running even though we removed them from start-up and even though I have not opened the corresponding programs - including: Cisco Systems VPN, Windows Media Player & Seagate Syn Service. It also seems that my computer is often running overtime - sort of in overdrive even when I do not have anything open. Figured this might need addressing before we tackle the icon situation which incidently has improved even though I haven't done anything yet. Now they just take awhile to load or blink out for a few seconds only when I open a new window. What first Maestro? Please accept my heartfelt thanks...For services you want to only run when needed. Only do this with the ones you are sure of. Disabling a critical service can have bad results. Go to Start > Run and type in Services.msc then click OK Scroll down until you find the service. Click once on the service to highlight it. Click Stop Right-Click on the service. Click on 'Properties' Select the 'General' tab Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box From the drop-down menu, click on 'Manual' Click the 'Apply' tab, then click 'OK' The service is now stopped and will only run when needed. ---------- Your going to have to refresh my memory on exactly what we are wanting to do next please |
|
| 1546. |
Solve : Can't install AVG? |
|
Answer» Hello,I am trying to install AVG antivirus,but it says another antivirus /security product is installed on this computer. |
|
| 1547. |
Solve : Windows XP Home Edition - Running really slow! 3 logs provided? |
|
Answer» You know what, I'm just going to say it's all good with the temp because I looked at the site, i looked at the program and was like... So yeah, anything else you can think of that would help computer run SMOOTHER or check for any other THINGS that you can think of?I think we have done all we can. I'm out of NEW ideas...OKAY, well thank you until next time! |
|
| 1548. |
Solve : Got Rid of win32.zafi.b but...? |
|
Answer» This is in reference to my daughter's Dell Inspiron E1705 laptop. It became infected with win32.zafi.b. The virus software on the laptop, Trend Micro PC-cillian could not detect it. Internet Explorer and Mozilla Firefox would start then indicate a virus threat was present. Browsing became impossible. I followed the malware removal guide I found in this forum. Everything seemed to go well. I saved the requested log files to the desktop but when I ran CCleaner the second time, it deleted the MALWAREBYTES log. For the moment, win32.zafi.b seems to be gone and the two browsers are working again. The last issue I guess is what to do with the the findings MADE by Highjack This. It's log is pasted below as instructed. Thanks. |
|
| 1549. |
Solve : Trojan horse virus help.? |
|
Answer» My DAUGHTER was sent a message on AIM and when she clicked on it I assume she installed the virus... Help is greatly appreciated. I could not find the HijackThis.exe in my TrendMircro folder to rename it Explain this please?How is the PC after the scans?Seems better, the thing is I still cant log into Windows Security Center or it wont start up. I get the message "The Security center service cannot be started."Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) - R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = - O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
Should I think I am ok or did I do something wrong? NOTE: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc] "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00 "DisplayName"="Security Center" "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,77,00,69,00,6e,00,\ 6d,00,67,00,6d,00,74,00,00,00,00,00 "ObjectName"="LocalSystem" "DESCRIPTION"="Monitors system security settings and configurations." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,59,00,53,00,54,00,45,00,4d,00,52,00,4f,00,4f,\ 00,54,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,73,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Security] "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\ 00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\ 00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Enum] "0"="Root\\LEGACY_WSCSVC\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs] "Description"="Provides the endpoint mapper and other miscellaneous RPC services." "DisplayName"="Remote Procedure Call (RPC)" "ErrorControl"=dword:00000001 "Group"="COM Infrastructure" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,72,00,70,00,\ 63,00,73,00,73,00,00,00 "ObjectName"="NT Authority\\NetworkService" "Start"=dword:00000002 "Type"=dword:00000020 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,02,00,00,00,60,ea,00,00 "DependOnService"=hex(7):44,00,63,00,6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,\ 68,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,70,00,63,00,73,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Enum] "0"="Root\\LEGACY_RPCSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs] "Description"="Provides the endpoint mapper and other miscellaneous RPC services." "DisplayName"="Remote Procedure Call (RPC)" "ErrorControl"=dword:00000001 "Group"="COM Infrastructure" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,72,00,70,00,\ 63,00,73,00,73,00,00,00 "ObjectName"="NT Authority\\NetworkService" "Start"=dword:00000002 "Type"=dword:00000020 "FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,02,00,00,00,60,ea,00,00 "DependOnService"=hex(7):44,00,63,00,6f,00,6d,00,4c,00,61,00,75,00,6e,00,63,00,\ 68,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 72,00,70,00,63,00,73,00,73,00,2e,00,64,00,6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security] "Security"=hex:01,00,14,80,a8,00,00,00,b4,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,78,00,05,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\ 02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 18,00,9d,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,01,01,00,\ 00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Enum] "0"="Root\\LEGACY_RPCSS\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001 Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. Restart the computer ans see if the Security Center is working.It didnt work, but the security center is working. Quote from: RustyRayR on January 15, 2009, 03:51:27 PM It didnt work, but the security center is working. You do realize that's a contradiction don't you. How is the computer running now? Sure I do, you asked me to tell you if the notepad note was accepted into the registry. It wasnt. But then I checked the security center and it worked. The cpu seems great. Thanks for your help. Anything else I should do? Quote from: RustyRayR on January 15, 2009, 05:32:02 PM Sure I do, you asked me to tell you if the notepad note was accepted into the registry. It wasnt. error messages? Quote from: BC_Programmer on January 15, 2009, 05:36:39 PM error messages? Might help, but since it did reactivate it then that's what matters. Since Dr. Web found nothing I'm thinking the malware is gone. Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed) 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. Security center stopped working again. I am getting ready to do these last steps you just posted. |
|
| 1550. |
Solve : Internet troubles.? |
|
Answer» Hey. |
|