Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Invisible Startup Items


  • Please log in to reply
11 replies to this topic

#1 ndzied1

ndzied1

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 25 July 2007 - 03:23 PM

When I run msconfig, in the Startup Tab there are two items that have no name under the Startup Item or Command Columns.

One shows the location HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The other shows HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

I'm running XP Pro SP2.

Is this normal or should I be worried?

Thank You
ndzied1

BC AdBot (Login to Remove)

 


#2 oldf@rt

oldf@rt

  • Members
  • 2,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Avondale, Arizona USA
  • Local time:10:31 PM

Posted 25 July 2007 - 03:36 PM

Normally things like that are viruses or spyware/malware. I would recommend starting with an online virus scanning program such as TrendMicro™ HouseCall Java Scan
  • Please go HERE to run the Trend Micro™ HouseCall Scan.
  • Click Scan now. It's free!
  • Read and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • If confirmed that HouseCall can run on your system, under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
  • You may receive a Security Warning about the TrendMicro Java applet, click YES.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.
this scanner will run in internet explorer or firefox. Just make sure that you have the latest version of java, from Sun Microsystems. this is the offline installer, which is about 13.9 meg in size.
The name says it all -- 59 and holding permanently

**WARNING** Links I provide might cause brain damage

#3 Starbuck

Starbuck

    'r Brudiwr


  • Malware Response Team
  • 4,149 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Midlands, UK
  • Local time:06:31 AM

Posted 25 July 2007 - 04:13 PM

Do you have Spybot Search & Destroy installed on your pc?
I prefer to use the start up manager on spybot rather than use 'msconfig' to stop or delete start up programs.
If you use 'msconfig' to alter the start up programs.... the start up is no longer 'normal'
Msconfig should really only be used as a temporary measure.

To access the start up manager in Spybot...
Open Spybot Search & Destroy
Then click on the Mode... then on the Advanced tab ( at the warning screen, click YES)
Now click on the Tools button
Then System Startup

Now just untick anything you don't want to start..... and reboot your pc.

If you ever change your mind..... go back and retick it.
It's so simple...... and safe.

Edited by Starbuck, 25 July 2007 - 04:17 PM.

BBPP6nz.png


#4 ndzied1

ndzied1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 26 July 2007 - 08:59 AM

Starbuck:

Thanks for the tip. I will use the Spybot advanced feature.

oldf@rt:

Ran the Housecall and it said I had 1 possible virus and 1 possible vulnerability but it doesn't say what the virus is. When I clicked Clean All it seemed like it was doing something but never popped up a finished screen...

Ran it again with the same results. The screen says idle and the hard disk light is not flashing... Here's what the screen looks like:

Posted Image

Any other suggestions are greatly appreciated.

Thanks,

<Edit: fixed picture link>

Edited by ndzied1, 26 July 2007 - 09:02 AM.


#5 oldf@rt

oldf@rt

  • Members
  • 2,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Avondale, Arizona USA
  • Local time:10:31 PM

Posted 26 July 2007 - 12:04 PM

On the asp.net issue, just click on the link underneath, this will take you to Microsoft's page, which will have the download link for the patch, just download and install it.

On the possible virus, Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

The name says it all -- 59 and holding permanently

**WARNING** Links I provide might cause brain damage

#6 ndzied1

ndzied1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 26 July 2007 - 10:07 PM

I ran the Kaspersky and it came up with 3 viruses and 12 infected objects.

Here is the log file:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, July 26, 2007 10:02:51 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 27/07/2007
Kaspersky Anti-Virus database records: 368283
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 178197
Number of viruses found: 3
Number of infected objects: 12
Number of suspicious objects: 0
Duration of the scan process: 02:43:51

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12082006-091726.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NormD\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\cert8.db Object is locked skipped
C:\Documents and Settings\NormD\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\NormD\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\history.dat Object is locked skipped
C:\Documents and Settings\NormD\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\key3.db Object is locked skipped
C:\Documents and Settings\NormD\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\parent.lock Object is locked skipped
C:\Documents and Settings\NormD\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\search.sqlite Object is locked skipped
C:\Documents and Settings\NormD\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\NormD\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{BE07268C-E41C-43FB-A795-B2371A47E552} Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Application Data\Mozilla\Firefox\Profiles\ydvmmmcr.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\History\History.IE5\MSHist012007072620070727\index.dat Object is locked skipped
C:\Documents and Settings\NormD\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NormD\My Documents\Download Files\VNC\vnc-4_1_2-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\NormD\My Documents\Download Files\VNC\vnc-4_1_2-x86_win32.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\NormD\My Documents\Download Files\VNC\vnc-4_1_2-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\NormD\My Documents\Download Files\VNC\vnc-4_1_2-x86_win32.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\NormD\My Documents\Download Files\VNC\vnc-4_1_2-x86_win32.exe Inno: infected - 4 skipped
C:\Documents and Settings\NormD\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NormD\ntuser.dat.LOG Object is locked skipped
C:\Program Files\CA\eTrust Antivirus\DB\rtmaster.dbf Object is locked skipped
C:\Program Files\CA\eTrust Antivirus\DB\rtmaster.ntx Object is locked skipped
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\SaveNow\Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.au skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EFE771F3-3075-496A-AA0E-AA2FA6FB817D}\RP567\A0055493.exe Infected: not-a-virus:AdWare.Win32.SaveNow.w skipped
C:\System Volume Information\_restore{EFE771F3-3075-496A-AA0E-AA2FA6FB817D}\RP575\A0058296.exe/data0007/SaveNow.exe Infected: not-a-virus:AdWare.Win32.SaveNow.w skipped
C:\System Volume Information\_restore{EFE771F3-3075-496A-AA0E-AA2FA6FB817D}\RP575\A0058296.exe/data0007/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.au skipped
C:\System Volume Information\_restore{EFE771F3-3075-496A-AA0E-AA2FA6FB817D}\RP575\A0058296.exe/data0007 Infected: not-a-virus:AdWare.Win32.SaveNow.au skipped
C:\System Volume Information\_restore{EFE771F3-3075-496A-AA0E-AA2FA6FB817D}\RP575\A0058296.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{EFE771F3-3075-496A-AA0E-AA2FA6FB817D}\RP615\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngenrootstorelock.dat Object is locked skipped
C:\WINDOWS\Microsoft.NET\ngenservice_pri3_lock.dat Object is locked skipped
C:\WINDOWS\pfirewall.log Object is locked skipped
C:\WINDOWS\Prefetch\Layout.ini Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\gnserv.dat Object is locked skipped
C:\WINDOWS\temp\spnserv.dat Object is locked skipped
C:\WINDOWS\temp\spserv.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

#7 oldf@rt

oldf@rt

  • Members
  • 2,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Avondale, Arizona USA
  • Local time:10:31 PM

Posted 26 July 2007 - 10:19 PM

On those viruses that you have, i would recommend running a complete scan with superantispyware in safe mode. It normally kills these.

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
After this you need to clean the system restore:

Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

The name says it all -- 59 and holding permanently

**WARNING** Links I provide might cause brain damage

#8 ndzied1

ndzied1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 26 July 2007 - 10:25 PM

Thanks for the quick response. I'll download and run overnight.

#9 ndzied1

ndzied1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 27 July 2007 - 06:01 AM

Ran the SuperAntiSpyware in Safe Mode. Here is the log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/27/2007 at 01:43 AM

Application Version : 3.9.1008

Core Rules Database Version : 3259
Trace Rules Database Version: 1270

Scan type : Complete Scan
Total Scan Time : 03:03:16

Memory items scanned : 181
Memory threats detected : 0
Registry items scanned : 11346
Registry threats detected : 6
File items scanned : 164622
File threats detected : 42

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt
C:\Documents and Settings\NormD\Cookies\normd@ad.contentmedianetwork[1].txt
C:\Documents and Settings\NormD\Cookies\normd@ad.thewheelof[2].txt
C:\Documents and Settings\NormD\Cookies\normd@ads.addesktop[1].txt
C:\Documents and Settings\NormD\Cookies\normd@ads.allaboutvision[1].txt
C:\Documents and Settings\NormD\Cookies\normd@ads.as4x.tmcs.ticketmaster[1].txt
C:\Documents and Settings\NormD\Cookies\normd@ads.as4x.tmcs[1].txt
C:\Documents and Settings\NormD\Cookies\normd@ads.cnn[2].txt
C:\Documents and Settings\NormD\Cookies\normd@ads.iambic[1].txt
C:\Documents and Settings\NormD\Cookies\normd@adv.medscape[1].txt
C:\Documents and Settings\NormD\Cookies\normd@adv.webmd[1].txt
C:\Documents and Settings\NormD\Cookies\normd@anad.tacoda[1].txt
C:\Documents and Settings\NormD\Cookies\normd@anat.tacoda[1].txt
C:\Documents and Settings\NormD\Cookies\normd@clicktracks.newcitymedia[1].txt
C:\Documents and Settings\NormD\Cookies\normd@click_track[2].txt
C:\Documents and Settings\NormD\Cookies\normd@data3.perf.overture[1].txt
C:\Documents and Settings\NormD\Cookies\normd@dynamicsitestats[2].txt
C:\Documents and Settings\NormD\Cookies\normd@ecnext.advertserve[1].txt
C:\Documents and Settings\NormD\Cookies\normd@ehg-kasperskylab.hitbox[1].txt
C:\Documents and Settings\NormD\Cookies\normd@hitbox[1].txt
C:\Documents and Settings\NormD\Cookies\normd@icc.intellisrv[2].txt
C:\Documents and Settings\NormD\Cookies\normd@itxt.vibrantmedia[2].txt
C:\Documents and Settings\NormD\Cookies\normd@lw.cdmediaworld[2].txt
C:\Documents and Settings\NormD\Cookies\normd@m1.webstats4u[1].txt
C:\Documents and Settings\NormD\Cookies\normd@nextag[2].txt
C:\Documents and Settings\NormD\Cookies\normd@nitrousexpress[1].txt
C:\Documents and Settings\NormD\Cookies\normd@partner2profit[2].txt
C:\Documents and Settings\NormD\Cookies\normd@redorbit.us.intellitxt[1].txt
C:\Documents and Settings\NormD\Cookies\normd@redorbit[2].txt
C:\Documents and Settings\NormD\Cookies\normd@sales.liveperson[2].txt
C:\Documents and Settings\NormD\Cookies\normd@sec1.liveperson[2].txt
C:\Documents and Settings\NormD\Cookies\normd@sitestats.tiscali.co[1].txt
C:\Documents and Settings\NormD\Cookies\normd@stats2.clicktracks[1].txt
C:\Documents and Settings\NormD\Cookies\normd@stats[1].txt
C:\Documents and Settings\NormD\Cookies\normd@track.bestbuy[1].txt
C:\Documents and Settings\NormD\Cookies\normd@track.searchignite[2].txt
C:\Documents and Settings\NormD\Cookies\normd@tracking.foxnews[2].txt
C:\Documents and Settings\NormD\Cookies\normd@tracking.webdiversity.co[1].txt
C:\Documents and Settings\NormD\Cookies\normd@visicommedia[1].txt
C:\Documents and Settings\NormD\Cookies\normd@www.crackpassword[1].txt
C:\Documents and Settings\NormD\Cookies\normd@www.doctorsforadults[1].txt
C:\Documents and Settings\NormD\Cookies\normd@xiti[1].txt

Malware.VirusBurst
HKCR\TypeLib\{A569F6C9-29F0-43BC-80CF-6BA138C66108}
HKCR\TypeLib\{A569F6C9-29F0-43BC-80CF-6BA138C66108}\1.0
HKCR\TypeLib\{A569F6C9-29F0-43BC-80CF-6BA138C66108}\1.0\0
HKCR\TypeLib\{A569F6C9-29F0-43BC-80CF-6BA138C66108}\1.0\0\win32
HKCR\TypeLib\{A569F6C9-29F0-43BC-80CF-6BA138C66108}\1.0\FLAGS
HKCR\TypeLib\{A569F6C9-29F0-43BC-80CF-6BA138C66108}\1.0\HELPDIR

#10 oldf@rt

oldf@rt

  • Members
  • 2,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Avondale, Arizona USA
  • Local time:10:31 PM

Posted 27 July 2007 - 11:51 AM

Did you set an new restore point, also, I would like for you to post a hijack this log, Hijack this forum

there are some things that need to be looked at, I am still worried about your VNC program, here C:\Documents and Settings\NormD\My Documents\Download Files\VNC\vnc-4_1_2-x86_win32.exe
The name says it all -- 59 and holding permanently

**WARNING** Links I provide might cause brain damage

#11 ndzied1

ndzied1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 27 July 2007 - 03:37 PM

I did set the restore point as described.

Here is the thread with the hijack log:

Hijack Log Thread

Thank You very much

#12 oldf@rt

oldf@rt

  • Members
  • 2,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Avondale, Arizona USA
  • Local time:10:31 PM

Posted 27 July 2007 - 03:53 PM

Bleeping Computer welcomes you, IMHPO, your machine looks to be in pretty good shape, but I want one of the experts to give you the all clear.
The name says it all -- 59 and holding permanently

**WARNING** Links I provide might cause brain damage




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users