Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HijackThis Log: Please help Diagnose


  • Please log in to reply
11 replies to this topic

#1 Izasworld

Izasworld

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 13 May 2010 - 12:04 PM

Hello,

Please help!
XP is frozen after normal start up.
Works on save mode.

I hoop this is not a problem but I have a frensh notebook!


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:30:56, on 13/05/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\Documents and Settings\Ten\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.therasmus.com/start.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Fichiers communs\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1257960844490
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Fichiers communs\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe

--
End of file - 6884 bytes

EDIT: Moved from XP to more appropriate Malware Removal Logs forum ~ Hamluis.

Edited by hamluis, 13 May 2010 - 12:12 PM.


BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:29 PM

Posted 13 May 2010 - 01:53 PM

Hello Izasworld,

Welcome to Bleeping Computer. smile.gif

As long as we can communicate, then I can read the logs, so no problem. thumbup2.gif Can you tell me anything more about what is happening? Is that the only problem?

See if you can download this scanner and post a log from it. It's like HijackThis, but will provide me with more details.

http://download.bleepingcomputer.com/sUBs/dds.scr

Thanks,
tea


Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 Izasworld

Izasworld
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 13 May 2010 - 05:36 PM

Hello Tea,

Thanks for the welcome and thank you so much for trying to help me!
I think my english will be okey enough to communicate as long as it is not going to become too technical... Then I'll probably need my dictionnary wink.gif

You asked me more details:
We are talking about a notebook IBM ThinkPad T41

The problems started with a strange noise in the hard disk, after that the hard disk did not work at all:
black page with hard disk error massage.

I don't know exactly how it worked, but I managed to recover the hard disk with SeaTool DO32.
After that it worked perfectly again.

After a few weeks the hard disk failed again, so I used SeaTool DO32 once more.
It seemed to have worked again but after a while Windows started to freez (no strange noise in HD anymore)

Okey, when I say freez... this is what happens:

Windows starts up.
Files and programs are visible on the desktop.
I can move the mouse.
But I can't do anything else.
I can't go in "start".
I can't open any files.
It is like the "click" funtion of the mouse is not working anymore.
If I try too much the mouse freezes too.

When I start up in safe mode the mouse workes properly and everything seems normal.

I hope I have given you the information you need.
And I hope my english was not too bad!

If I did it right, the files you asked for are attached to this message.

If you post today again please note that I will not respond right away because
here it is 0.45 AM so goodnight or actually for you (I think) good afternoon smile.gif

Iza

Attached Files


Edited by Izasworld, 13 May 2010 - 05:44 PM.


#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:29 PM

Posted 13 May 2010 - 06:31 PM

Hello smile.gif

I think we'll be all right then. smile.gif If there are any problems I do have a few colleagues that are French as well and can help out.

Okay, so your only option is Safe Mode for right now. Normally this tool should be run in normal mode, but go ahead and run it in safe mode :

Please visit this webpage for download links, and instructions for running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review. If the web page confuses you, the ComboFix prompts should be in French for you, so just follow them. If you have any questions first, please ask. thumbup2.gif

If you have trouble running it the first time, then rename ComboFix.exe to Izasworld.exe and try again.

I believe you are 6 or 7 hours ahead of me, so it's early evening here. smile.gif Sleep well.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 Izasworld

Izasworld
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 14 May 2010 - 05:03 AM

Good morning Tea,

This is the log from Combofix
I had disabled the virus scanner but Combofix was warning me that it was still running so I had to delete it completely.
I didn't restart and now I see on the log that it states "avast : enabled" ! Do you want me to scan again or is this ok?


ComboFix 10-05-13.03 - Ten 14/05/2010 10:47:21.1.1 - x86 NETWORK
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1023.824 [GMT 2:00]
Lancé depuis: c:\documents and settings\Ten\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100509-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((( Fichiers créés du 2010-04-14 au 2010-05-14 ))))))))))))))))))))))))))))))))))))
.

2010-05-13 15:35 . 2010-05-13 15:35 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
2010-05-05 07:09 . 2010-05-05 07:09 -------- d-----w- c:\program files\Fichiers communs\AmbraSoft
2010-05-05 07:09 . 2010-05-05 07:09 -------- d-----w- c:\program files\AmbraSoft

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-13 15:51 . 2009-11-11 17:16 31592 ----a-w- c:\documents and settings\Ten\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-12 14:33 . 2009-12-26 18:35 -------- d-----w- c:\program files\Google
2010-05-12 12:14 . 2010-04-12 20:10 -------- d-----w- c:\program files\CCleaner
2010-03-31 19:28 . 2004-08-05 12:00 72912 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-31 19:28 . 2004-08-05 12:00 461974 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-31 18:08 . 2010-03-31 16:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Pure Networks
2010-03-31 18:05 . 2010-03-31 18:05 -------- d-----w- c:\program files\Linksys
2010-03-31 16:59 . 2010-03-31 16:59 -------- d-----w- c:\program files\Pure Networks
2010-03-31 16:58 . 2010-03-31 16:58 -------- d-----w- c:\program files\WebEx
2010-03-31 16:58 . 2010-03-31 16:58 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2010-03-31 16:57 . 2010-03-31 16:57 -------- d-----w- c:\program files\Fichiers communs\Pure Networks Shared
2010-03-30 18:11 . 2009-11-11 17:27 -------- d--h--w- c:\program files\InstallShield Installation Information
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 88363]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"nmctxth"="c:\program files\Fichiers communs\Pure Networks Shared\Platform\nmctxth.exe" [2009-04-07 642856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-04-07 467240]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\program files\Fichiers communs\Pure Networks Shared\Platform\nmsrvc.exe"= c:\program files\Fichiers communs\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service

R3 PCX504;Cisco Systems Wireless LAN Adapter Driver;c:\windows\system32\drivers\PCX504.sys [04/05/2004 13:35 119296]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [26/12/2009 20:35 135664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenu du dossier 'Tâches planifiées'

2010-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-26 18:35]

2010-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-26 18:35]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.therasmus.com/start.php
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-14 10:52
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(416)
c:\docume~1\Ten\LOCALS~1\Temp\catchme.dll
.
Heure de fin: 2010-05-14 10:53:32
ComboFix-quarantined-files.txt 2010-05-14 08:53

Avant-CF: 19 537 309 696 octets libres
Après-CF: 19 610 296 320 octets libres

WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect

- - End Of File - - 4820D7E099A9AB4E26F3AD3A99FEBB48

Thanks
Iza

#6 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:29 PM

Posted 14 May 2010 - 01:07 PM

Not much showing there, so don't worry about another run. A test, please.....in safe mode click start>run> type in msconfig>OK. Click on the services tab. Check the "Hide Microsoft Services" box and turn off the other services. Now try to boot into normal mode and see what happens. Let me know what happens. smile.gif

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#7 Izasworld

Izasworld
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 14 May 2010 - 04:29 PM

Hello Tea,

After following your instructions,

1 - Windows restart and I get a message telling me that Windows has started in Diagnostic or Selection mode.
I manage to close the message.
Then the system config box stands open on the desktop with "hide Windows services" uncheked and other services checked again.
When I close that dialoge box I am asked to restart.
So I did.
Then you can start reading from 1 again whistling.gif

Well the second time I did not restart and now it looks like everything is working properly.

What's do you think ?

Best wishes
Iza

#8 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:29 PM

Posted 14 May 2010 - 05:14 PM

So now you can work in normal mode? Then one by one turn the services back on. It is time consuming, but in this way you will know which one is causing your problem. smile.gif
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#9 Izasworld

Izasworld
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 15 May 2010 - 08:03 AM

Hi smile.gif
Yes I can work on normal mode now.
Ok, I did what you asked.
Checking the services one by one!
No change untill the last one I checked!!! (Network sharing service for Windows Media from unknown manufacturer)
Then my hard disk did that strange noise again and Windows froz again, so I thought "yes got it"
I stopped my notebook wanting to restart on safe mode to uncheck that service but then I thought to try again on normal mode.
And now I don't know what to make of it because I didn't change anything but the noise is gone and Windows is working again!!!
huh.gif Any idea?
Thanks
Iza

Edited by Izasworld, 15 May 2010 - 08:04 AM.


#10 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:29 PM

Posted 15 May 2010 - 12:54 PM

blink.gif Well that's good news anyway. I honestly don't know what to make of it. Viruses and bugs are my forte, not troubleshooting beyond the basics. laugh.gif

Please delete ComboFix and its accompanying folder C:\Qoobox. Empty your Recycle bin and reboot your computer.

If it happens again I will send you to the hardware forum. They would have a better idea of what it might be. thumbup2.gif I will leave this thread open for a few days until we know for sure the problem is gone. smile.gif

Regards,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#11 Izasworld

Izasworld
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:29 PM

Posted 15 May 2010 - 03:59 PM

Hi Tea,

Thank you so much for your help, your time and your patience!
I know where to come to if I am in trouble again thumbup.gif

Thank you so much again!
Best wishes
Iza

#12 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:29 PM

Posted 15 May 2010 - 04:30 PM

You're most welcome. Any time! thumbup2.gif
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users