InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3701. |
Solve : 3 logs for inspection? |
|
Answer» Hi, RECENTLY my computer has been popping up these KIND of notifications each time Windows STARTS and each time I open any kind of program: |
|
| 3702. |
Solve : 3 scan logs for inspection? |
|
Answer» faryl classical 2009 (RARE track).snd;C:\Documents and Settings\harold mullan\My Documents\FrostWire\Saved;Trojan.WMALoader;Cured.;
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.restore point done all programs were up to date windows up to date and always on i did have wot installed firewall safe my security is : sas , mbma , avast , CCLEANER , advanced system care , i think i have plenty do i take out dr web now or keep it what do you think , harryYes oyu can just delete it and it will be gone. |
|
| 3703. |
Solve : Computer wont boot up!? |
|
Answer» I need help, my computer won't boot up. I can get into the BIOS screen but i don't KNOW what to change from there. I don't have the boot disk ether. Its a toshiba satellite.Any error message Mauro? Can you create a boot CD from another PC you MAY have?No MESSAGES... just stays on the loading windows screen... no other how do i create a boot disk from another computer? |
|
| 3704. |
Solve : Reader_s / virut removal (formatting)? |
|
Answer» Hi If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers. Jesus... didn't realise it was that serious! cheers, will look into those programsYep. Virut was created to steal. wow, reader_s is virut. Wish I knew THAT a MONTH ago... don't worry liamb123, your not the only one affected by this bugger. Anyway, changed the pw on all the sites I frequent. Oh yeah, btw, I had it too. discovered through it's little HTML modifying habit. then I noticed, that when I expanded explorer.ex_ from my windows CD, it grew 18KB- but only with the "right" extension. that was when I knew something was seriously wrong. it's a nasty, so I'm in the process of reinstalling windows on my system partition as well. I already tried the AVG removal tool, which was fairly useless. After install I'm going to recursively delete all EXE,DLL, OCX, and SCR files. from my D: drive. I haven't used my external in ages; so if the MP3 files on there are smaller then those on my data drive, a replacement will be in order unfortunately since I cannot know which of my compilations of programs are infected I have removed ALL the known locations where I have them up for download. This explains the mysterious errors I would get right after compiling that I was attributing to my manual replacement of Visual Basic 6's C2.exe compiler with my own so I can add extra options. the idea is to conserve the data from the installed programs- then I can likely reinstall them, and they will place fresh executables in the respective folders and use the old data files (such as savegames). what about RAR and so forth? will it infect files if I haven't opened the zip/rar what have you? I'm probably going to keep any ZIPS- a lot of them don't contain any executables.adobe\reader_s is not Virut. Quote %System%\reader_s.exe Those are Virut. http://www.threatexpert.com/files/reader_s.exe.html Quote what about RAR and so forth? will it infect files if I haven't opened the zip/rar what have you? It can penetrate compressed files as well as find it's way into and back out of quarantined files. Nasty bugger!!Also how the heck does it infect a mp3? isn't that a data file format?Remember the article titled "Virut is a weird freak amongst malware"... http://www.teamfurry.com/wordpress/2007/02/15/under-the-hood-virut/ I'm not "authorized" or allowed to help you remove spyware/trojans ect as im not a malware removal specialist on the forums, but ive had my own problems with reader_s.exe, And i RECENTLY defeated it.. i could never remove the infection but I found the infection was caused by an mp3 file, Napalm-cruel tranquility-mind melt.mp3 .. I Reformatted my pc and the virus was gone, but i feel i should let you know, that reader_s.exe isnt it, thats just one of many the things it installs, in addition to reader_s.exe there was a large number of .dll files in the system32 folder , as well as a large number of .TMP files.. i found it was necessary to use the windows intallation cd and system repair in the install during boot-up to remove the files and not even safemode/administrator would remove them, the only thing i could recommend is deleting your %tmp% folder, not just the files but the folder itself, that seemed to slow it down alot.. but i think you should reformat it, I tryed AVG/nod 32/bitdefender 8/ and a number of malware removal tools that had no effect.Without a reformat the problem is impossible to fix. You have to remove all system files and start fresh. |
|
| 3705. |
Solve : Need Help, not sure what the problem is.? |
|
Answer» Hmm, well she was having problems with McAfee for a while before the other stuff started happening. However, she completely LOST use of McAfee around the same time that she lost internet connection. (Which is why I immediately suspected that something was messing with her comp.) But more or less, I suppose it was around the same time that McAfee died. Then I uninstalled it. Or at least attempted to. |
|
| 3706. |
Solve : What Do I Really Need?? |
|
Answer» As a computer 'newbie', I'm now totally confused as to what security measures I actually need. |
|
| 3707. |
Solve : Very bad virus or worm - can't use my computer anymore? |
|
Answer» I have a weird behavior on my computer, I can't run anything for more than a few SECONDS before the computer start hanging. I used Norton and i saw something weird: "*censored*.exe". I did a search and I tried a fix for this worm but it was not FOUND. I don't know where to start and I can't run anything without the computer hanging. Please help. Instead...if this is XP Professional, go to Start > Run and type in gpedit.msc and click OK. Go to Local Computer Policy > Computer Configuration > Windows Components > Windows Installer. On the list to the right, double-click Disable Windows Installer, click on Enable and click OK.Did you try these steps? And what about a new HijackThis log? IF if you have to reformat, do you have a way of backing up your important files?Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3708. |
Solve : How do I change my default homepage?? |
|
Answer» As this issue APPEARS to be resolved, I am closing this topic. If you are the original poster and you WOULD like this topic to be re-opened for any reason, PM me or ANOTHER moderator and it can be arranged. |
|
| 3709. |
Solve : Start up error? |
|
Answer» acording to me this is due to SOFTWARE not properly installed....Quote from: sukhija on July 13, 2007, 12:33:18 PM acording to me this is due to software not properly installed.... If you had been reading, you WOULD see that we already determined what the problem was and fixed it.As this issue APPEARS to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any REASON, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please START a New Topic with information about your computer and your problem. |
|
| 3710. |
Solve : Computer is very slow what's wrong??? |
|
Answer» My internet connects but my internet explorer won't open. I can't open my musicmatch jukebox or my control panel. Everything is very sluggish. My computer won't even shut itself down properly. I RAN AVG, Ad Aware and Spybot, I also defragmented that all seems to have helped it alot but I wanted to see if there may be something else I'm missing. |
|
| 3711. |
Solve : Firefox and IE together brew up security trouble? |
|
Answer» Users could face a "highly critical" risk if they have both IE and Firefox version 2.0, or later, loaded on their computer. The trouble begins when browsing a malicious site while using IE and it registers a "firefoxurl://" URI (uniform resource identifier) handler, which allows the browser to interact with specific resources on the Web. As a result, users may find their systems remotely compromised. Thanks for the info, Scott. I'm definitely going to have to look into this more. I'd hate to have to get rid of my Firefox, but if this is true, it may come down to that. Getting rid of Firefox would be the wrong move. Just do what Calum said and use IE for windows updates only.Yeah getting rid of FF is a pretty drastic measure to take, you can just remove the "firefoxurl://" URI and you're safe. Also from what I've read, people with NoScript installed (should be a default install IMO) is protected from the exploit.Quote from: 2k_dummy on July 13, 2007, 11:53:46 AM Quote from: CBMatt on July 13, 2007, 11:48:32 AMThanks for the info, Scott. I'm definitely going to have to look into this more. I'd hate to have to get rid of my Firefox, but if this is true, it may come down to that. Actually, I rarely use Firefox. It's mainly just for web design. If not for that, I wouldn't use it at all. But I'm not doing anything until I read into this a bit more...which won't be until after I get some sleep.today, I decided to do a "BIOS update" live -flash on my older emachine... it has an older msi board on it (which I still love!) and saw that a safe flash was only supported using IE . I hated to do it but, did the file hippo update thingy and installed new IE -7 . I received this virus update checking out cnet after that..... f..y..i.. I love the msi boards because of the GREAT live update utility they have including flashing the bios ........... but, you always need to be real careful doing a bios flash ..... everything needs to be turned off before attempting* |
|
| 3712. |
Solve : HELP my computer running windows is running really slow...? |
|
Answer» HI... HI... Guitar pro nice choice Quote from: Annon on July 06, 2008, 02:55:28 PM Quote from: Sean0514 on July 06, 2008, 01:57:14 PM?ok i ran ccleaner and i did nothing...i ran disk cleanup...i cant run defrag because lasttime i tried to it took so long i will defrag tonite but i analysed it and this is what i got \/HI... i dont think this is causeing the slowness tho because my com has never been this slow before. oh and the 5% free space shouldent mean anything because back when my computer was fast i had even less space than that.I would try defragmenting but you should keep at least 10% free. If this is a recent problem, I would try using System Restore and restoring to a date before the problem occurred. Any recent downloads/installs lately?yea this all started after i installed my CA internet security from TIme WarnerCan you uninstall it and see what happens?Quote from: drmsucks on July 06, 2008, 02:15:15 PM Difficult to tell but it looks like you have Windows Defender running. Perhaps it is conflicting with the program that you received from your ISP. Try disabling Windows Defender and post back. Did you do this?yes i did do that it did nothing. i believe the problem is that my something in my prosesses is making my cpu slow down. my cpu useage is 100%Quote from: Carbon Dudeoxide on July 06, 2008, 04:17:35 PM Can you uninstall it and see what happens?It wouldn't hurt to post a HijackThis log as well.a what http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis Scan the computer and post the log here. Don't fix anything yet.Here you go Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:33:50 PM, on 7/6/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe C:\WINDOWS\system32\LxrSII1s.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\tcpsvcs.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe C:\windows\system\hpsysdrv.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\LTMSG.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe C:\Documents and Settings\Owner\Local Settings\Application Data\Lexar Media\LxrAutorun.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http= R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - (no file) O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7 O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [LxrAutorun] C:\Documents and Settings\Owner\Local Settings\Application Data\Lexar Media\LxrAutorun.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation TOOL) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1214675863734 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214675775171 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing) O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: CA PEST Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 9892 bytes |
|
| 3713. |
Solve : Laptop freezes on "Setup is starting Windows". BSOD? |
|
Answer» i have some problem with my old laptop and hope that someone can help me. the problem is my laptop infected by virus and malware. after clean it with Avira antivir personal and Malwarebytes' Anti-Malware. reboot and it freeze on WINDOW start up. ( wellcome screen ). after a few days i become fed up and i tried to install a fresh copy of Windows XP. the problems begin.After insert the window xp cd, 1)copy FILES, 2) Welcome to Setup, 3)f8 agree and format, 4) Setup COPIES various files and reboot. after reboot it freeze on the screen(setup will complete in 39 minutes).i tried to install again now it freezes on "Setup is starting Windows"and won't go any further.and have no error message( BSOD ) i already tried the (Memtest+86.170 , change ram to 512mb,reformat my harddisk , used the F5 trick) I am so frustrated. this problem has been the last two MONTH. please help. note that now my hard disk already format ( no system )and my laptop freeze on setup is starting windows. how can i scan for virus or Malware. |
|
| 3714. |
Solve : Not sure if this is a virus issue or not? |
|
Answer» Dell Inspiron 1501 running XP |
|
| 3715. |
Solve : Nod32 or Kaspersky.Which is better? |
|
Answer» I want to buy anti virus,But I don't know between NOD32 or kaspersky.Which one should i buy?Quote from: kukkaikawaii on January 22, 2010, 01:57:50 AM I want to buy anti virus,But I don't know between Nod32 or kaspersky.Which one should i buy? I'd go with Kaspersky, better DETECTIONS and over all best out there I'm a Kaspersky fan, but you'll be FINE with either.Go with nod32. It never SLOW down your systemQuote from: Subhankar on January 25, 2010, 11:23:02 PM Go with nod32. It never slow down your SYSTEM |
|
| 3716. |
Solve : parent's computer? |
|
Answer» I just reinstalled windows xp on my parent's computer and it still looks like there is a virus on it. My guess is it's a rootkit, which I have no idea how to GET rid of (besides installing LINUX and just having them use that.) I've seen the virus before from my work development computer. Luckily Symantec has been doing a good job of cleaning up my FLASH drive before the virus can do anything there. I figured out the problem. It's not a rootkit. I was using a flash drive to copy drivers from my parent's computer to my laptop, which was also infected and am restoring. Silly me, I should have known better. Hi, could you tell me how exactly you fixed it ? I have this sywyrl0q.exe too on my drive and my anti virus software doesn't seem to detect it.. Thank you! Tomtmoe30 and sos2516 please do not give advice you are not malware expertsQuote from: WildIce on January 21, 2010, 01:20:12 PM Hi, could you tell me how exactly you fixed it ? I have this sywyrl0q.exe too on my drive and my anti virus software doesn't seem to detect it.. For people having the same problem (sywyrl0q.exe and his autorun.inf keep coming back on hard drives and usb sticks): I deleted that herss.exe file in my Temp folder and both the sywyrl0q.exe and autorun.inf on all drives (with command prompt: del /a:h /f ) and it solved it for me I think..Quote from: WildIce on January 21, 2010, 01:20:12 PM Hi, could you tell me how exactly you fixed it ? I have this sywyrl0q.exe too on my drive and my anti virus software doesn't seem to detect it.. http://www.symantec.com/security_response/writeup.jsp?docid=2009-081106-1401-99&tabid=3 |
|
| 3717. |
Solve : Weird websites in my history? |
|
Answer» Hi |
|
| 3718. |
Solve : IMPORTANT - Do not run ComboFix!? |
|
Answer» If you have recently ran ComboFix and it deleted everything from your desktop post a link here to your topic so I can help you GET your computer back to normal. Or start a new topic and post the contents of the C:\QooBox\ComboFix-quarantined-files.txt file. Please attach it as it will be huge. |
|
| 3719. |
Solve : is2010virus? |
|
Answer» From the Desktop go to -> My Computer -> Local Disk (C:) -> Documents and Settings -> All Users -> Start Menu -> Programs -> and find a folder called Startup. Inside this folder is a 1 KB icon called desktop with a Note pad and a gear next to it. Right clicked it, to go to its properties and choose "Hidden."Are ththose the only programs I need? I currently have: AVG 9.0,SUPERAntispyware, MalwareBytes, Advanced Systen Care, CCleaner, Startup Optimizer and Smart Defrag. Also, Should I, and how do I, delete ComboFix, HijackThis and all the crap left behind like the dequarantine log and such that saved themselves in more than ONE place?Delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt |
|
| 3720. |
Solve : Malware or system corruption? Windows XP? |
|
Answer» Fresh HJT log attached.
---------- Create An Uninstall List * Start HijackThis * Click on the Open the Misc Tools section * Click on the Open Uninstall Manager button. * Click on the Save list button and specify where you would like to save this file and click Save. * When you press Save button a notepad will open with the contents of that file. * Copy and paste that list in your reply. . ---------- Also let us know how things are now.Hi EF, Thanks for stopping by my thread. I appreciate all you and SD you for me. After running SFC, I've spent the last 48 hours verifying the operability of my installed applications so I can give a better quality report. It's good you asked about the uninstall report. I was going in that direction anyway because I needed to check for additional program corruption. At the beginning of the thread I reported problems with Google Chrome being corrupted, as well as frequent dirty disk Chkdsk generations. I don't know if this was a consequence of my infection or doing a repair install with an old XP disk (I forgot I had upgraded to a larger SATA drive). I actually verified every program on the Start Menu. You don't really appreciate how much MS has bundled in until you start going through all of them. Most of the programs all ran. Four programs had errors, but reinstalling got them running again. Three more had errors, but I didn't care about them anymore and just uninstalled them. Two or three more programs showed up in the wrong folder in the Start Menu. These entries were just deleted. I've had some uninstallable situations in Add/Remove programs in the past, but with the issue of drive corruption, I decided to TACKLE this issue with Revo. By the WAY, Revo and Winamp both gave this error on installation, but both programs seem to run okay anyway: "The procedure entry point IsThreadDesktopComposited could not be located in the dynamic link library USER32.dll" I'm surprised the HJT scan does not show an entry for JAVA(TM) 6 Update 7 that shows up in my Add/Remove Programs. It won't delete in there, and Revo can't get it either. I wondered if there was some cross-corruption between the two JAVA's, and since we had the Kaspersky issue in Reply # 14, I decided to run Kaspersky again. I guess that scanner is just problematic anyway from what I hear. It halted and fussed, but eventually I got a good scan out of it again. Didn't repeat the freeze and HDD flurry like before. So I wanted to track the issue of SAS halting on the "Unexpected error". It did halt once or twice on my, but I haven't been able to get it to duplicate that behavior anymore. Maybe it's because I uninstalled WMP. But I also uninstalled before the new halts. The reason I uninstalled WMP is that it wouldn't run because of an error message that the version number encountered was different from the version number expected. So, I'm thinking I'm getting out of the woods here, but one of the programs that was corrupted along with Chrome back in the beginning was Download Accelerator Plus, and it is one that had to be reinstalled to get it running again - and so I was alarmed at my SAS test scan to find Trojan.Agent /Gen pop up. I'm thinking, "Oh no, don't tell me it's that Karaplayer.exe. Or maybe on of the OEM programs I never run because I tested everything today." When finished, it turned out to be SBSEARCH.DLL - from Download Accelerator Plus. Looking at the keys, it's the browser hijack changing the home page and default search to SpeedBit Search. Well, I've noticed that before, and it really annoyed me, but I don't consider it real malware. It's been on CNET for 10 weeks, in the top 20 for a while, and now at # 36. CNET certifies everything as "Safe, Tested and Spyware Free". So I guess it just depends on where you draw the line at Malware. Sure, done without my permission for the purpose of commercial gain, but I don't think it is in the same league as the things that were done to harm my computer in this thread. So I removed DAP and reinstalled to see if I had just missed unchecking a box to decline the hijack, but there was nothing, and on rescanning it reappeared. So I let SAS remove it again, but haven't removed DAP again. So I hope I am safe now. So, additional duplications in my Add/Remove list are 2 copies of Google Earth and 3 copies of C++ Redistributable. I also see that Neroxml is on the HJT list, but not in my Add/Remove list. I just removed Nero as one of the programs that needed to be reinstalled. That's all I can think of for now. Logs posted below. Any thoughts on the possible false positives in Reply # 14? Thanks again. ------------------------- HJT Uninstall Log Sansa Media Converter 7-Zip 4.57 ACDSee 9 Photo Manager Adobe Acrobat 4.0 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3 Apple Application Support Apple Mobile Device Support Apple Software Update Atheros Communications Inc.(R) L2 Fast Ethernet Driver Avira AntiVir Personal - Free Antivirus Bentley Publishers - eBahn® Bonjour Canon MP Navigator EX 1.0 Canon MX310 series Canon My Printer Canon Utilities Easy-PhotoPrint EX Canon Utilities Solution Menu DivX Codec DivX Web Player ESET Online Scanner v3 FLAC 1.2.1b (remove only) Free Video Converter V 2.5 FurthurNET 1.7.5 Google Earth Google Earth Google Update Helper HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB961118) Intel(R) Graphics Media Accelerator Driver iTunes Java(TM) 6 Update 18 Malwarebytes' Anti-Malware MemTurbo Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Mozilla Firefox (3.0.16) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) neoDVDstandard4 neroxml Nokia Connectivity Cable Driver OpenOffice.org 3.1 Opera 10.10 PeaZip 2.3a Personal Ancestral File 5 Picasa 3 PIXMA Extended Survey Program Presto! PageManager 7.15.16 QuickTime RealPlayer Realtek High Definition Audio Driver Revo Uninstaller Pro 2.0.5 Roland Virtual Sound Canvas 3.2 Samsung ML-4500 Series Driver ScanSoft OmniPage SE 4 Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB975467) Serif 3DPlus 2.0 Serif DrawPlus 4.0 Serif PagePlus SE 1.0 Serif PhotoPlus 6.0 SiSoftware Sandra Lite 2009 SpeedBit Video Accelerator Spybot - Search & Destroy Stella 2.6.1 SUPERAntiSpyware Free Edition Switch Sound File Converter ThaiSoftware Dictionary V3.0 The KMPlayer (remove only) Ulead VideoStudio 10 Update for Windows XP (KB968389) Update for Windows XP (KB971737) VC80CRTRedist - 8.0.50727.762 VCRedistSetup Winamp Windows Essentials Media Codec Pack 1.0 Windows Live OneCare safety scanner Windows Live Sign-in Assistant Windows Media Format 11 runtime Windows Media Format Runtime WinRAR archiver WOT for Internet Explorer XP_Key_Changer 2.0.0 Xvid 1.2.1 final uninstall XviD MPEG-4 Codec --------------------------------- SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/24/2010 at 02:08 AM Application Version : 4.33.1000 Core Rules Database Version : 4510 Trace Rules Database Version: 2322 Scan type : Complete Scan Total Scan Time : 00:05:04 Memory items scanned : 506 Memory threats detected : 0 Registry items scanned : 5420 Registry threats detected : 22 File items scanned : 0 File threats detected : 1 Trojan.Agent/Gen HKLM\Software\Classes\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000} HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000} HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000} HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\InprocServer32 HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\InprocServer32#ThreadingModel HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\ProgID HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\Programmable HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\TypeLib HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\VersionIndependentProgID HKCR\SearchHook.SrchHook.1 HKCR\SearchHook.SrchHook.1\CLSID HKCR\SearchHook.SrchHook HKCR\SearchHook.SrchHook\CLSID HKCR\SearchHook.SrchHook\CurVer HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6} HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0 HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\0 HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\0\win32 HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\FLAGS HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\HELPDIR C:\PROGRA~1\DAP\SBSEARCH.DLL HKU\S-1-5-21-682003330-492894223-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4F10C1D-87C7-404A-B4B3-000000000000} HKU\S-1-5-21-682003330-492894223-1957994488-1003\Software\Microsoft\Internet Explorer\URLSearchHooks#{F4F10C1D-87C7-404A-B4B3-000000000000} Remove the old version(s) Download JavaRa * Unzip the file and open the JavaRa.exe * Click Remove Older Versions * JavaRa will search for and remove any outdated version of Java and remove any that are found. * Click Additional Tasks * Place a check next to Remove Useless JRE Files and click Go * Exit JavaRa * Delete the JavaRa files from the desktop ---------- Open Malwarebytes' Anti-Malware. * Click the Update tab. * Click Check for Updates * If an update is found, it will download and install. * Click the Scanner tab. * Select Perform Quick Scan, then click Scan. * The scan may take some time to finish,so please be patient. * When the scan is complete, click OK, then Show Results to view the results. * Make sure that everything is checked, and click Remove Selected. * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note) * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. * Copy & Paste the entire report in your next reply. Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. ---------- Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.
How is the computer running now?JavaRa removed more registry keys, but JAVA(TM) 6 Update 7 (133MB) persists in the Add/Remove programs list. I can't find it anywhere. Lots of Java folders around the system, but none this size, or that look like they don't belong where they are, so I have attached this log below as well. There's a dozen blank logs at the end because it took me a while to figure out that it was appending to the log rather than creating a new one each run. MBAM gave a clean scan, but it couldn't connect to update, asking me to report to them an Error Code 732 (0,0). I had this happen last month, and they sent me a list of possible causes, one of which was server congestion due to their upgrade release. The problem went away, so I figured that was it. I was thinking along the same lines tonight, but this also harks back to the original issues I had while still infected, i.e., erratic connectivity. In fact, just yesterday I was thinking how much smoother the internet was working when it started acting up again. The reason I mention this is that MBAM was able to update after running Dial-a-Fix. So I wonder if some of the malware damage was still waiting to be repaired. It is interesting to go through this process and learn that while Windows has some self-repair capabilities, some of these things require special tools. MS might be well to follow forums like this and upgrade their self-repair capabilities, or hire developers of these special tools. Clean MBAM log attached below. Dial-a-Fix ran as expected. I have attached the list of error messages below. Since this post, and this thread, deal with corruption issues, I should address the three error possibilities reported: 1 - Corruption, 2 - Not DLL Install-able, 3 - Not registerable. Since some of these errors may pertain to Windows Update, before assuming corruption, I should address the possibility that "Not registerable" could be happening because Windows has locked files because I have not dealt with the WGA issue. Product key registration failed because of the mismatch between the product key type and the Windows CD type (Retail - Full - No SP versus MSDN - Upgrade - SP3). I thought it best not to address this until we are finished because last time I had an issue like this, I had to call MS on the 800 number. I did not want to commit to this until we were sure this repair is finished and successful. If you would like me to take care of this at this time, I will. My next step in this regard was to try to use a Key Changer in order to see if it would accept my product key now that the installation is finished and stable. Otherwise, networking on the LAN seems improved over yesterday. Yesterday the other XP computer (Athlon) on the LAN could not even see this computer, and from the beginning of this thread I have had difficulty opening SharedDocs on the other computer to transfer back and forth all the tools and logs used in this thread. Today I checked all the computers and can summarize them as follows. The computer being treated in this thread is the Celeron: From Celeron to Athlon XP - Smooth Celeron to Q6600 Vista - Slower, but works. Celeron to P4 Vista - Blank password issue. Q6600 Vista to Celeron - Password mismatch issue - won't tell me how to resolve it. P4 Vista and Athlon XP to Celeron - both have the same error message as follows: "SharedDocs is not accessable. You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions. Access is denied." In the Properties tab, both of the following boxes are checked: - Share this folder on the network and - Allow network users to change my files In other issues, Revo and Winamp both continue to give the same error when run, but both programs still seem to run okay anyway: "The procedure entry point IsThreadDesktopComposited could not be located in the dynamic link library USER32.dll" Also, running my program checks yesterday, I noticed in System Information -> Hardware Resources -> Conflicts/Sharing that there are 6 listings, 2 Memory and 4 IRQ. 5 are double shares, IRQ 10 has 6 shares, but in Device Manger, all report no conflicts. So I suppose BIOS or Windows is managing sharing. It seems a bit much. Should I do something about it? Reset ESCD Config in BIOS? Should duplicate Google Earth and C++ entries be removed? My overall subjective feeling about how the computer is doing is that it has come a long way since where it was, even running better than before the infection, now that it is cleaner and healed. It has reminded of how I felt when I first got it - about how much faster it felt than the Athlon 2500 I used before - which surprised me, because when I first got the Athlon with XP way back when, it was not far from being state of the art at the time, and I was really proud of how fast it performed. So with this Celeron running at the same MHz, I was surprised how much faster it felt, and then I started to learn about increases in FSB speeds over the years, and etc. So I really feel good now about the system. It has that "smooth as butter" feeling when clicking on things and interacting with the internet that it hasn't had for a long time. That's all I can think of for now. Thanks. Logs follow: JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Tue Dec 08 14:19:45 2009 Found and removed: C:\Program Files\Java\jre1.6.0_04 Found and removed: C:\Program Files\Java\jre1.6.0_05 Found and removed: C:\Program Files\Java\jre1.6.0_07 Found and removed: C:\Program Files\Java\jre1.6.0_13 Found and removed: C:\Documents and Settings\COMPUTER\Application Data\Sun\Java\jre1.6.0_04 Found and removed: C:\Documents and Settings\COMPUTER\Application Data\Sun\Java\jre1.6.0_11 Found and removed: C:\Documents and Settings\COMPUTER\Application Data\Sun\Java\jre1.6.0_12 Found and removed: C:\Documents and Settings\COMPUTER\Application Data\Sun\Java\jre1.6.0_13 Found and removed: C:\Documents and Settings\COMPUTER\Application Data\Sun\Java\jre1.6.0_14 Found and removed: C:\Documents and Settings\COMPUTER\Application Data\Sun\Java\jre1.6.0_15 Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\JavaPlugin.160_04 Found and removed: SOFTWARE\Classes\JavaPlugin.160_05 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160040} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050} Found and removed: Software\Classes\JavaPlugin.160_04 Found and removed: Software\Classes\JavaPlugin.160_05 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05 Found and removed: Software\JavaSoft\Java2D\1.6.0_04 Found and removed: Software\JavaSoft\Java2D\1.6.0_05 Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07 Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\bin\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_04.b12\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_05.b13\ JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Tue Dec 08 14:20:20 2009 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Tue Dec 08 14:20:40 2009 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Fri Jan 22 03:15:23 2010 Found and removed: C:\Documents and Settings\COMPUTER\Application Data\Sun\Java\jre1.6.0_17 Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\JavaPlugin.160_04 Found and removed: SOFTWARE\Classes\JavaPlugin.160_05 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160040} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050} Found and removed: Software\Classes\JavaPlugin.160_04 Found and removed: Software\Classes\JavaPlugin.160_05 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07 Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_04.b12\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_05.b13\ ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:19:04 2010 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:21:04 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:28:22 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:29:04 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:34:17 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:47:23 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:48:17 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:49:55 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:50:18 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:54:13 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:54:35 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:57:20 2010 ------------------------------------ Finished reporting. JavaRa 1.15 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sun Jan 24 20:57:55 2010 ------------------------------------ Finished reporting. Malwarebytes' Anti-Malware 1.44 Database version: 3626 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 1/24/2010 10:59:34 PM mbam-log-2010-01-24 (22-59-34).txt Scan type: Quick Scan Objects scanned: 141336 Time elapsed: 5 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Dial-a-fix Error -2147467259 was encountered while trying to unregister C:\WINDOWS\system32\msxml3.dll. The error text is: Unspecified Error. Dial-a-fix currently has no suggestions for this error code. Please email [emailprotected] with a copy of the lop pane and any details you can provide about this error. Error 127: C:\WINDOWS\system32\iesetup.dll is not registerable or the file is corrupted. Your version of iesetup.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\iesetup.dll is not DLLInstall-able or the file is corrupted. Your version of iesetup.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\imgutil.dll is not registerable or the file is corrupted. Your version of imgutil.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\inseng.dll is not registerable or the file is corrupted. Your version of inseng.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\inseng.dll is not DLLInstall-able or the file is corrupted. Your version of inseng.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\mshtml.dll is not registerable or the file is corrupted. Your version of mshtml.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\mshtml.dll is not DLLInstall-able or the file is corrupted. Your version of mshtml.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\msrating.dll is not registerable or the file is corrupted. Your version of msrating.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\occache.dll is not registerable or the file is corrupted. Your version of occache.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\occache.dll is not DLLInstall-able or the file is corrupted. Your version of occache.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\pngfilt.dll is not registerable or the file is corrupted. Your version of pngfilt.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\webcheck.dll is not registerable or the file is corrupted. Your version of webcheck.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file. Error 127: C:\WINDOWS\system32\webcheck.dll is not DLLInstall-able or the file is corrupted. Your version of webcheck.dll is: 8.00.6001.18702. Please contact [emailprotected] so that an exception can be made for your version of this file.Delete An Uninstall Entry
---------- You may need to check with Mozilla on the other errors. https://support.mozilla.com/en-US/forum/1/478629 For the remaining Windows issues, slow transfers and passwords start a new topic in the Windows forum. I'm pretty sure the malware is gone. We can run another scan for a double check if you like. Download, update and run a-squared Free edition At the main menu, click Scan Now, there will be 4 options, choose Deep Scan and then click Scan * If malware is found, click the button Remove Selected Malware * If malware is found, select all found and click Quarantine selected objects * Click Save Report. Save the report to somewhere convenient, such as your desktop * Add the report as an attachment in your next post.JAVA(TM) 6 Update 7 does not appear in the HJT Uninstall Manager. Since JavaRa removed so much on the 2nd and 3rd runs, this issue is no longer a concern to me. I was afraid that a Java exploit was preventing its removal, but it appears JavaRa reports that there is no longer anything left on the HDD of this version of Java. So I see the Revo/Winamp error message is a system-wide thing, not application specific. I should have known since it occurs on two unrelated applications. The Mozilla thread was inadvertently closed by someone, but was reopened here: https://support.mozilla.com/en-US/forum/1/401389 Since the Mozilla thread is speculative, you might prefer to refer people to the Microsoft solution instead: http://support.microsoft.com/kb/969155 It concerns a Vista file ACCIDENTALLY installed in XP by some MS applications. The solution is just to delete it. So it's not a malware issue, so it is no longer of concern. The solution fixed both Winamp and Revo on my computer. As for the a-squared scan, the scan results really have me thinking about what this experience is teaching me about false positives. As I mentioned in Reply # 14, Quote I didn't pay much attention to the issue of false positives in the past. I just assumed AV publishers had their signature lists and that they just worked. A random match of data bits that match seemed too small a chance to worry about. But I've been following the CNET reviews of security software recently, and I noticed for the first time that the percentage of false positives is a rating factor. Also, upon installing Avira last month, I was surprised at their candor concerning the chances of false positives with respect to the sensitivity settings chosen. In fact, it is the first program I have ever seen with sensitivity settings. That together with what I learned from my Jotti's scans, also in Reply #14, and reviews of AV products at the Virus Bulletin web site, has me realizing that every anti-malware product has a small percentages of false positives, and therefore, mathematically, or statistically speaking, the more different brands of scanners you expose your system to, the more you are exposing yourself to the chance of a false positive. The reason I bring up this issue here is because of the items found by a-squared. The tracking cookies - that's fine. I delete them every chance I get. The inprocserver32 tracing detection - there is a big discussion of this on the Kaspersky forum: http://forum.kaspersky.com/lofiversion/index.php/t48032.html to the point of one post even accusing Emsisoft of false positives in the free edition to drive sales of the the paid edition. Whether or not that's an overreaction, the entire thread discussion shows there is not a consensus as to whether or not these keys should be deleted. Next there is Presto Pagemanager. This is off my Installation Disk that came with my Canon printer/scanner. Next is the Setup.exe for one of the Serif applications downloaded from the Serif webite. And then comes All in One Karaoke again (from Reply # 14 again). But this time it's not Karaplayer, it's NickWin.exe. When I installed Avira, it offered me 3 levels of scanning sensitivity and advised that the chance of false positives increased with the higher settings. Because this infection had me so worried, I chose the highest sensitivity anyway. Yet Avira did not pick of any of these files. Maybe it's because it is only an anti-virus and a-squared is a specialized tool. But the overall feeling I get is that a-squared is the most sensitive with a higher chance of reporting false positives. So my problem is that I do not have enough experience and judgement to evaluate this log to feel qualified to decide for myself whether to allow a-squared to remove these findings. The more you learn, the more you realize how much you don't know, so I can appreciate someone with your level of knowledge marking your profile experience level as "Beginner". So I have not allowed a-squared to remove these results so I can get your input first. I know one behavior of malware is to insert itself into other executable files on the system, so I don't know for sure what I should do. All for now. Thanks [Saving space, attachment deleted by admin]You can safely let a2 remove those. I believe that the malware is gone. Any further issues will need to be addressed in the proper forum.That's really good to hear. It has been so stressful going through this malware experience. I am so grateful you and SD have been able to help me return my computer to good health. Thanks so much. |
|
| 3721. |
Solve : Can someone please help me, I've asked a bunch of times, and get nothing? |
|
Answer» Quote from: mcummings36 on January 24, 2010, 10:12:46 AM Look, I'm not trying to make anyone MAD or sound like an ungrateful [emailprotected]!s. But I think anyone in my position would be a little frustrated and irritated. I realize that my computer is infected, but I also didn't have all the other problems, other than the Facebook and google issues, until I did what that first POST said. Now I keep losing my printer driver along with a whole NEW set of issues. If you don't want to help me, fine, but don't post a snide remark either, it just MAKES the whole thing worse. the additional stuff is probably just the infections trying to reassert CONTROL; or possibly a side effect from them being removed. For example, some infections also lodge themselves as Optical drive "filter" drivers; when a tool detects and cleans these, sometimes the CD-ROM drives can become inaccessible. |
|
| 3722. |
Solve : Windows failed to load because a required file is missing, or corrupt.? |
|
Answer» Hay my computer froze last night while I was doing the disk cleaning, cause my computer was being really slow, and I turned my computer off cause it wouldn't let me do anything. well now when I start up my computer it goes into the windows BOOT manager. this is exactly what it says... from top to bottom. |
|
| 3723. |
Solve : Google links redirect me, AND "google installer has stopped working"? |
|
Answer» I have two problems, both potentially from the same virus. First of all, every time I try to click on a google link, I get redirected to a RANDOM site. I have to click the link several times before it goes to the correct site WITHOUT redirecting. |
|
| 3724. |
Solve : My computer fan runs loud all the time? |
|
Answer» Quote Where do I go to find the Trend Micro folder? If I search, I get over 500 results with C:\Program Files, Trend Micro...Do it in Windows Explorer. Start, My Computer, click on the C: drive. Look for Program Files, Trend Micro and delete the folder. Quote The error is 0x80240030 error. And it gives you 2 solutions to TRY, which I didn't have luck on EITHER of them. Is this a PROBLEM with my computer or microsoft and can I fix it? Any SUGGESTIONS would be great!!!Check this link for that error. Quote Adobe Reader 8.x update gets an error about half way through the install (Error 1402,Here's a link to help with the above error. |
|
| 3725. |
Solve : UACD.sys and possibly more Removal Help Request? |
|
Answer» Hey Guys, I need help cleaning out my gf's infected system. I believe I have another case of uacd.sys, but possibly more now. I had the traditional music playing in the background, but couldn't find the source, as no windows were open. As well as the "google installer failed to start" and "windows defender is not working properly" Vista errors. They were popping up on the dot twice an hour on the 12 minute mark as well as the 58 minute mark. |
|
| 3726. |
Solve : .exe Bad Image issue? |
|
Answer» Before you go we need to do some clean-up. You can uninstall HJT and keep SAS and MBAM. Update them and run them about once a week. |
|
| 3727. |
Solve : Free, good antivirus program? |
|
Answer» Hello, I would suggest AVG 9.0 free.Ditto. Quote Unexpected renewal costsThere a re a number of free AV programs out there. Just hard to find.http://www.avast.com/en-gb/index#tab2 free , free , freeThank you for your help. My other machine is currently running BitDefender, but I am less than impressed with their support. The icon goes dark during the day at odd times and doesn't recover. They seem to be at a loss. If avast or AVG provide the same security, why pay for BitDefender?Remember to only install one antivirus! 1) Avast! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal 4) Microsoft Security Essentials for WINDOWS Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time. |
|
| 3728. |
Solve : Error on boot? |
|
Answer» My friend obtained a powerful gaming desktop a few months ago, but just recently upon start-up it WOULD go to a black screen with text on it. The screen said that one of the drives is missing and to insert the WINDOWS installation disk. Sadly, he does not KNOW the location of this disk. Is there any way to reinstall the DRIVER without that disk? Below is the file it says is missing: |
|
| 3729. |
Solve : help please... malware or spyware infects my desktop...? |
|
Answer» i desperately need help in solving this issue. it appears my desktop PC has been infected by malware or spyware. I am getting a message that says 'application cannot be executed. The file csc.exe is infected. do you want to activate your antivirus software now?' |
|
| 3730. |
Solve : how to remove recyler virus/trojan? |
|
Answer» Hi everyone, |
|
| 3731. |
Solve : My laptop is infected with Malware.trace... pls help! Windows Vista SP1? |
|
Answer» Hi SD, |
|
| 3732. |
Solve : Supposedly removed malware and now Internet will not work in Windows 7 !!!? |
|
Answer» if anything its very little , i cannot SAY yes , WAIT for a malware EXPERT to CLEAR you , HARRY |
|
| 3733. |
Solve : This started as Internet Security 2010? |
|
Answer» Yes evilfantasy it looks like you are right. After running the Dr Web rescue cd, the machine will no longer boot, I get a blue SCREEN of death telling me windows is shutting down to keep from damaging the computer. I do have all of my pictures an other personal files on the second drive. I tunes is backed up right after my last purchase to a dvd. So I'm hoping it is all ok. |
|
| 3734. |
Solve : Request for malware removal assistance? |
|
Answer» OK, |
|
| 3735. |
Solve : Is malware bytes telling lies.? |
|
Answer» Hi |
|
| 3736. |
Solve : Computer infected with 'Netsky' worm. Logs out as soon as I log in? |
|
Answer» Operating System: Windows XP Professional (5.1, Build 2600) Service Pack 2 (2600.xpsp_sp2_qfe.070227-2300) Language: English (Regional Setting: English) System Manufacturer: powerspec System Model: E361 BIOS: Default System BIOS Processor: Intel(R) Core(TM)2 QUAD CPU Q6700 @ 2.66GHz (4 CPUs) Memory: 3322MB RAM Page File: 203MB used, 5002MB available Windows Dir: C:\WINDOWS DirectX Version: DirectX 9.0c (4.09.0000.0904) DX Setup Parameters: Not found DxDiag Version: 5.03.2600.2180 32bit Unicode This warning came up saying some type of worm netsky has infected my computer. I ran a deep SCAN with SAS and it showed mutiple infections. I re-booted it and now my computer won't let me log in. Not in safe mode, safe with networking, NOTHING. It just logs me right back out to the log in screen. Is this something that can be fixed? . Go to this link to CREATE a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose. |
|
| 3737. |
Solve : getting redirected, virus warnings, pop-ups, right click menu stopped working? |
|
Answer» I am having the following problems: |
|
| 3738. |
Solve : Kav Rescue 2008 Help? |
|
Answer» I am USING Windows Xp, and downloaded. kav_rescue_2008 What are you trying to do? Trying to detect any Virus/Malware if found, with a Rescue Disk.. OS: Windows XP Home. I've tried using Avira Disk, scaned only for 5MINS and finished. Then used F-secure Disk, ran for 30mins or so, and found 0 Malware.Then it looks like you're fine. If not, download an antivirus (such as AVG Free).Quote from: Carbon Dudeoxide on January 22, 2010, 01:43:59 AM Then it looks like you're fine. I believe AVG rescue disk is not free, unless you have a link I can download from or recommend any other program to use. AVG Antivirus. Not a rescue disc. The Antivirus runs from within Windows and SCANS your computer for malware. http://free.avg.com/ |
|
| 3739. |
Solve : May be a Computer Virus? |
|
Answer» I have about 23 folders in my USB flash drive. When I double click to one of these folders it disapears. And I did the same THING to another FOLDER. The same thing HAPPENED. So I enabled the system files to be appeared in the folder OPTIONS. But that folder cannot be found. Please help me with this issue. |
|
| 3740. |
Solve : Ripper Virus!!!!? |
|
Answer» A RIPPER virus has taken over my computer. I am told by my pc that it doesn't detect my modem, CD-ROM Drive, CD-RW Drive, and until I did a quickrestore it changed my display settings to the lowest settings possible, then it changed it back when I tried to correct it. Now the only Disk Drive my pc detects is the Floppy Drive. I can't reboot it because it freezes my pc when I try to create a BOOT up diskette. Can someone please help. If so I would Really appreciate it. I am going to check for replies everyday until one works. THANK You for your time!!! http://vil.nai.com/vil/content/v_1037.htmRlCowboy02.....How did you determine that is a the "Ripper " virus....? If thats what it is you willl probably have to D/L the tool that merlin has pointed you at and put it on a cd as opposed to a floppy ........boot your P/C up in Safe Mode ......and the cd drives should be seen .......run the removal tool and you should be RID of it . The odd thing is if its ripper , thats a old virus, it funny your anti virus didnt catch it.....is it current ? |
|
| 3741. |
Solve : computer reformat? |
|
Answer» Guys', My computer is very new I just wanted to know if it's still as good as new after being reformatted because of a virus?? Does it perform 100% well after being reformatted??If you are asking if formatting the drive will completely rid the system of a virus, the ANSWER is yes (unless it is the VERY RARE BOOT sector virus, but I really wouldn't even worry about that). How can I know or check if my computer HARDWARE is in very good condition???You can DOWNLOAD UTILITIES that will test your various components. Just search on Google. For example, do a Google search for "memory testing software" or "video card testing software", etc. K' I'll try to search for it.... tanxxxxxx!!!!you're welcome. |
|
| 3742. |
Solve : Laptop is infected and is now useless, everything is blocked? |
|
Answer» Just ran into a problem today. didnt DOWNLOAD ANYTHING or go on any wrong sites. it happened while i was on youtube. I got this program that showed up in my icons at the bottom right called "INTERNET Security 2010". Im like oh great not this again. \so my background gets changed to keep my attention. Every like minute some pop up comes up from it " please update your anitvirus software" "your computer is infected". Ran a virus scan with avast and nothing came up. I had this happen to me before and i cant remember what i had to do but i remember is had to do with hijack this and regestry junk. Ill post what I got from Hijack this. BTW It wont let me open notepad or task manager. Code: [Select]Logfile of Trend Micro HijackThis v2.0.3 (BETA) Internet Security 2010 is a rogue antivirus program. Over the past year, there have been many variants of these fake antivirus programs. I haven't been able to determine what the software is attempting to do but the best thing to do is format your computer and reload your O/S. You can attempt to remove the trojan but this is very advanced malware and there will probably still be remnants of the trojan hiding in the registry. ignore this.Please go to this link and follow the directions and post the required logs. We will need the SAS and MBAM programs to be run and the logs posted. |
|
| 3743. |
Solve : AV Boot CD? |
|
Answer» Can you refer me to a good freeware av BOOT cd DOWNLOAD?HTTP://www.google.com/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-GB%3Aofficial&hs=QWv&q=dowlnoad+boot+time+av&aq=f&aql=&aqi=&oq=Boot Time, ok THANKS. |
|
| 3744. |
Solve : unhandled win32 exception occurred in svchost.exe? |
|
Answer» Getting this all the time, unhandled win32 exception occurred in svchost.exe, comes up in Visual Studio JIT Debugger. |
|
| 3745. |
Solve : Infection: Cannot download ComboFix? |
|
Answer» It appears that my machine has caught an infection, and I am having difficulty cleaning it. This bug appears to be blocking my attempts to download ComboFix from the three known mirrors for the download. On the first attempt, my anti-virus pops up and DELETES the ComboFix download, calling it "WIN32/SillyDl.PRR". On subsequent attempts, Firefox says that it cannot make the connection to the website. |
|
| 3746. |
Solve : Can anyone tell me what this was??? |
|
Answer» SD, just wanted you to know I haven't forgotten what you've asked me to do, downloading Security Check. We've had a serious illness in the FAMILY and I will do it as soon as I have time. I was on computer checking email and thought I'd let you know that I know I still need to do this. I'll get back with you. Thanks! |
|
| 3747. |
Solve : Application Cannot be executed...file is infected..HELP!? |
|
Answer» I can't run anything on my computer it is infected with something. I can't even access any of these programs to begin to try and remove this infection. I click on each one and I get the same thing everytime! help? |
|
| 3748. |
Solve : anti-spyware programs.....how many do I need?? |
|
Answer» Hello all, |
|
| 3749. |
Solve : Virus/Trojan Help Needed....? |
|
Answer» Hello SD, |
|
| 3750. |
Solve : how to use HiJackThis? |
|
Answer» Evilfantasy, |
|