Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need Help


  • Please log in to reply
4 replies to this topic

#1 surpriseme

surpriseme

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:47 PM

Posted 24 January 2006 - 09:30 PM

I used smitrem.exe file to remove spywarestryker from computer. It worked great but now I can't log into secure websites. Any ideas to fix this. I did everything it said from the page cannot be displayed message.
Thanks

Logfile of HijackThis v1.99.1
Scan saved at 9:04:32 PM, on 1/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpBF96.tmp (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1138153256640
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://clubgames.pogo.com/online2/pogop/in...aploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Edited by surpriseme, 24 January 2006 - 09:48 PM.


BC AdBot (Login to Remove)

 


#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:03:47 PM

Posted 28 January 2006 - 04:25 PM

Fix this with HiJack

O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpBF96.tmp (file missing)

Go to the link below and download the trial version of SpySweeper:

SpySweeper http://www.webroot.com/consumer/products/s...&rc=4129&ac=tsg

* Click the Free Trial link under "SpySweeper" to download the program.
* Install it. Once the program is installed, it will open.
* It will prompt you to update to the latest definitions, click Yes.
* Once the definitions are installed, click Options on the left side.
* Click the Sweep Options tab.
* Under What to Sweep please put a check next to the following:
o Sweep Memory
o Sweep Registry
o Sweep Cookies
o Sweep All User Accounts
o Enable Direct Disk Sweeping
o Sweep Contents of Compressed Files
o Sweep for Rootkits

o Please UNCHECK Do not Sweep System Restore Folder.

* Click Sweep Now on the left side.
* Click the Start button.
* When it's done scanning, click the Next button.
* Make sure everything has a check next to it, then click the Next button.
* It will remove all of the items found.
* Click Session Log in the upper right corner, copy everything in that window.
* Click the Summary tab and click Finish.
* Paste the contents of the session log you copied into your next reply.
Also post a new Hijack This log.
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#3 surpriseme

surpriseme
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:47 PM

Posted 28 January 2006 - 11:54 PM

********
9:50 PM: | Start of Session, Saturday, January 28, 2006 |
9:50 PM: Spy Sweeper started
9:50 PM: Sweep initiated using definitions version 556
9:50 PM: Starting Memory Sweep
9:51 PM: Memory Sweep Complete, Elapsed Time: 00:01:38
9:51 PM: Starting Registry Sweep
9:51 PM: Registry Sweep Complete, Elapsed Time:00:00:08
9:51 PM: Starting Cookie Sweep
9:51 PM: Found Spy Cookie: 2o7.net cookie
9:51 PM: hp_owner@2o7[2].txt (ID = 1957)
9:51 PM: Found Spy Cookie: yieldmanager cookie
9:51 PM: hp_owner@ad.yieldmanager[2].txt (ID = 3751)
9:51 PM: Found Spy Cookie: adlegend cookie
9:51 PM: hp_owner@adlegend[1].txt (ID = 2074)
9:51 PM: Found Spy Cookie: adrevolver cookie
9:51 PM: hp_owner@adrevolver[2].txt (ID = 2088)
9:51 PM: Found Spy Cookie: addynamix cookie
9:51 PM: hp_owner@ads.addynamix[2].txt (ID = 2062)
9:51 PM: Found Spy Cookie: advertising cookie
9:51 PM: hp_owner@advertising[2].txt (ID = 2175)
9:51 PM: Found Spy Cookie: ask cookie
9:51 PM: hp_owner@ask[1].txt (ID = 2245)
9:51 PM: Found Spy Cookie: atlas dmt cookie
9:51 PM: hp_owner@atdmt[2].txt (ID = 2253)
9:51 PM: Found Spy Cookie: atwola cookie
9:51 PM: hp_owner@atwola[1].txt (ID = 2255)
9:51 PM: Found Spy Cookie: a cookie
9:51 PM: hp_owner@a[1].txt (ID = 2027)
9:51 PM: Found Spy Cookie: casalemedia cookie
9:51 PM: hp_owner@casalemedia[1].txt (ID = 2354)
9:51 PM: Found Spy Cookie: sextracker cookie
9:51 PM: hp_owner@counter2.sextracker[1].txt (ID = 3362)
9:51 PM: hp_owner@counter7.sextracker[1].txt (ID = 3362)
9:51 PM: Found Spy Cookie: fastclick cookie
9:51 PM: hp_owner@fastclick[1].txt (ID = 2651)
9:51 PM: Found Spy Cookie: go.com cookie
9:51 PM: hp_owner@go[1].txt (ID = 2728)
9:51 PM: Found Spy Cookie: military cookie
9:51 PM: hp_owner@military[1].txt (ID = 2996)
9:51 PM: hp_owner@psc.disney.go[1].txt (ID = 2729)
9:51 PM: Found Spy Cookie: questionmarket cookie
9:51 PM: hp_owner@questionmarket[1].txt (ID = 3217)
9:51 PM: Found Spy Cookie: serving-sys cookie
9:51 PM: hp_owner@serving-sys[1].txt (ID = 3343)
9:51 PM: hp_owner@sextracker[1].txt (ID = 3361)
9:51 PM: Found Spy Cookie: webtrendslive cookie
9:51 PM: hp_owner@statse.webtrendslive[2].txt (ID = 3667)
9:51 PM: Found Spy Cookie: trafficmp cookie
9:51 PM: hp_owner@trafficmp[2].txt (ID = 3581)
9:51 PM: Found Spy Cookie: tribalfusion cookie
9:51 PM: hp_owner@tribalfusion[1].txt (ID = 3589)
9:51 PM: Found Spy Cookie: adserver cookie
9:51 PM: hp_owner@z1.adserver[1].txt (ID = 2142)
9:51 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
9:51 PM: Starting File Sweep
9:52 PM: Found Adware: coolwebsearch (cws)
9:52 PM: a0002370.exe (ID = 54080)
9:52 PM: a0002382.exe (ID = 54080)
9:58 PM: Found Trojan Horse: trojan-downloader-ruin
9:58 PM: a0002418.exe (ID = 125496)
9:59 PM: Found Trojan Horse: trojan-downloader-perlink.biz
9:59 PM: a0002399.exe (ID = 137946)
9:59 PM: a0002397.exe (ID = 137946)
10:01 PM: msblank.html (ID = 135703)
10:03 PM: Warning: Unhandled Archive Type
10:04 PM: File Sweep Complete, Elapsed Time: 00:12:09
10:04 PM: Full Sweep has completed. Elapsed time 00:13:58
10:04 PM: Traces Found: 30
10:51 PM: Removal process initiated
10:51 PM: Quarantining All Traces: trojan-downloader-ruin
10:51 PM: Quarantining All Traces: coolwebsearch (cws)
10:51 PM: Quarantining All Traces: trojan-downloader-perlink.biz
10:51 PM: Quarantining All Traces: 2o7.net cookie
10:51 PM: Quarantining All Traces: a cookie
10:51 PM: Quarantining All Traces: addynamix cookie
10:51 PM: Quarantining All Traces: adlegend cookie
10:51 PM: Quarantining All Traces: adrevolver cookie
10:51 PM: Quarantining All Traces: adserver cookie
10:51 PM: Quarantining All Traces: advertising cookie
10:51 PM: Quarantining All Traces: ask cookie
10:51 PM: Quarantining All Traces: atlas dmt cookie
10:51 PM: Quarantining All Traces: atwola cookie
10:51 PM: Quarantining All Traces: casalemedia cookie
10:51 PM: Quarantining All Traces: fastclick cookie
10:51 PM: Quarantining All Traces: go.com cookie
10:51 PM: Quarantining All Traces: military cookie
10:51 PM: Quarantining All Traces: questionmarket cookie
10:51 PM: Quarantining All Traces: serving-sys cookie
10:51 PM: Quarantining All Traces: sextracker cookie
10:51 PM: Quarantining All Traces: trafficmp cookie
10:51 PM: Quarantining All Traces: tribalfusion cookie
10:51 PM: Quarantining All Traces: webtrendslive cookie
10:51 PM: Quarantining All Traces: yieldmanager cookie
10:51 PM: Removal process completed. Elapsed time 00:00:29
********
9:46 PM: | Start of Session, Saturday, January 28, 2006 |
9:46 PM: Spy Sweeper started
9:46 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
9:49 PM: Updating spyware definitions
9:49 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
9:49 PM: Updating spyware definitions
9:49 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
9:50 PM: | End of Session, Saturday, January 28, 2006

#4 surpriseme

surpriseme
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:47 PM

Posted 29 January 2006 - 12:37 AM

Logfile of HijackThis v1.99.1
Scan saved at 11:36:07 PM, on 1/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktop
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpBF96.tmp (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1138153256640
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138159733796
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://clubgames.pogo.com/online2/pogop/in...aploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#5 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:03:47 PM

Posted 29 January 2006 - 10:51 AM

Fix these with HJT – mark them, close IE, click fix checked

O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpBF96.tmp (file missing)

START – RUN – type in %temp% OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Not all temp files will delete and that is normal
Empty the recycle bin
Boot and post a new log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system
"Nothing could be finer than to be in South Carolina ............"

Member ASAP




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users