Over 1 million tech questions and answers.

Keyboard Issues/Repeat Issues on Virus Scan

Q: Keyboard Issues/Repeat Issues on Virus Scan

Hello

I am running xp

Original problem involved internet being redirected when clicking on links but after reinstalling AVG and running Malwarebytes along with deleting a number of suspicious files that has now discontinued to happen

AVG is still showing multiple issues on daily scans as to is Malwarebytes

Keyboard is now not working correctly and sometimes certain keys will work then later they will

I have run both tests as requested as well as Hijack This

I really appreciate your help

Thank you

DDS text


DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 18:28:42.09 on Wed 22/09/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.3549.2358 [GMT 10:00]

AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Ahead\InCD\InCDsrv.exe
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Software Informer\softinfo.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
c:\program files\logitech\quickcam\lu\lulnchr.exe
c:\program files\logitech\quickcam\lu\LogitechUpdate.exe
C:\Program Files\Microsoft Office\OFFICE11\FRONTPG.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Software Informer] "c:\program files\software informer\softinfo.exe" -autorun
uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [IBP]
uRun: [fsm]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1274420661109
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 74.125.45.100 getantivirusplusnow.com
Hosts: 74.125.45.100 www.getantivirusplusnow.com
Hosts: 74.125.45.100 www.secure-plus-payments.com
Hosts: 74.125.45.100 www.getavplusnow.com
Hosts: 74.125.45.100 safebrowsing-cache.google.com

Note: multiple HOSTS entries found. Please refer to Attach.txt

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\vkb7kqu5.default\
FF - prefs.js: browser.search.selectedEngine - search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_HBLiteSA.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-9-19 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-9-19 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-9-19 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-9-19 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-9-19 243024]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-9-19 921952]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-9-19 308136]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-9-21 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-9-19 5897808]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-9-19 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-9-19 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-9-19 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-9-19 26192]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-31 136176]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2010-5-31 547744]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-5-21 1684736]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-9-19 30104]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2010-5-23 112640]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [2010-5-23 102656]

=============== Created Last 30 ================

2010-09-22 08:28:40 0 d-----w- c:\temp\305.tmp
2010-09-22 08:19:02 0 d-----w- c:\program files\Trend Micro
2010-09-22 08:14:03 0 d-----w- c:\temp\plugtmp
2010-09-21 23:49:51 0 d-----w- c:\temp\msohtmlclip1
2010-09-21 23:49:51 0 d-----w- c:\temp\msohtmlclip
2010-09-21 04:02:06 0 d-----w- c:\temp\WPDNSE
2010-09-20 23:17:00 0 d-----w- c:\temp\Icons
2010-09-19 23:35:58 0 d-----w- c:\temp\DefaultEmoticons
2010-09-19 08:11:22 0 d-----w- c:\temp\MessengerCache
2010-09-19 07:36:03 0 d--h--w- C:\$AVG
2010-09-19 07:22:25 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-09-19 07:22:15 0 d-----w- c:\windows\system32\drivers\Avg
2010-09-19 07:22:03 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-09-19 07:22:03 25168 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-09-19 07:22:02 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-09-19 07:22:00 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-09-19 07:18:41 0 d-----w- c:\temp\7zS3.tmp
2010-09-19 07:13:38 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-09-19 07:13:38 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-09-19 07:13:37 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-09-19 07:11:07 0 d-----w- c:\temp\7zS32.tmp
2010-09-19 06:21:47 27968 ----a-w- c:\temp\Spanish.bin
2010-09-19 06:21:47 27665 ----a-w- c:\temp\Italian.bin
2010-09-19 06:21:47 27417 ----a-w- c:\temp\French.bin
2010-09-19 06:21:47 26464 ----a-w- c:\temp\Portuguese.bin
2010-09-19 06:21:47 26314 ----a-w- c:\temp\Russian.bin
2010-09-19 06:21:47 26282 ----a-w- c:\temp\Hungarian.bin
2010-09-19 06:21:47 25944 ----a-w- c:\temp\Dutch.bin
2010-09-19 06:21:47 25927 ----a-w- c:\temp\German.bin
2010-09-19 06:21:47 25776 ----a-w- c:\temp\Slovak.bin
2010-09-19 06:21:47 25712 ----a-w- c:\temp\Lithuanian.bin
2010-09-19 06:21:47 25357 ----a-w- c:\temp\Greek.bin
2010-09-19 06:21:47 25276 ----a-w- c:\temp\Portuguese(Brazil).bin
2010-09-19 06:21:47 24523 ----a-w- c:\temp\Japanese.bin
2010-09-19 06:21:47 24504 ----a-w- c:\temp\Czech.bin
2010-09-19 06:21:47 24502 ----a-w- c:\temp\Polish.bin
2010-09-19 06:21:47 24271 ----a-w- c:\temp\SWEDISH.bin
2010-09-19 06:21:47 24100 ----a-w- c:\temp\Slovenian.bin
2010-09-19 06:21:47 23040 ----a-w- c:\temp\Finnish.bin
2010-09-19 06:21:47 22970 ----a-w- c:\temp\Danish.bin
2010-09-19 06:21:47 22436 ----a-w- c:\temp\Turkish.bin
2010-09-19 06:21:47 22149 ----a-w- c:\temp\Thai.bin
2010-09-19 06:21:47 22142 ----a-w- c:\temp\Norwegian.bin
2010-09-19 06:21:47 22118 ----a-w- c:\temp\English.bin
2010-09-19 06:21:47 21150 ----a-w- c:\temp\Arabic.bin
2010-09-19 06:21:47 20307 ----a-w- c:\temp\Korean.bin
2010-09-19 06:21:47 19700 ----a-w- c:\temp\Hebrew.bin
2010-09-19 06:21:47 17090 ----a-w- c:\temp\TradChin.bin
2010-09-19 06:21:47 16540 ----a-w- c:\temp\SimChin.bin
2010-09-19 05:12:22 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-09-19 05:05:34 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-19 05:05:33 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-19 02:18:48 0 d-----w- c:\windows\pss
2010-09-18 06:29:33 116 ----a-w- c:\windows\system32\BestSpywareScanner.lie
2010-09-18 03:17:17 42 ----a-w- c:\windows\system32\scud.udf
2010-09-18 02:32:56 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-09-18 02:32:56 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-09-16 08:40:39 0 d-----w- c:\program files\Software Informer
2010-09-16 08:40:39 0 d-----w- c:\docume~1\owner\applic~1\Software Informer
2010-09-12 23:51:19 0 d-----w- c:\windows\system32\wbem\Repository
2010-09-12 23:50:38 0 d-----w- c:\program files\AUSIFD
2010-09-12 00:03:30 0 d-----w- c:\docume~1\owner\applic~1\Gygan
2010-09-11 22:15:55 0 d-----w- c:\docume~1\alluse~1\applic~1\ReviverSoft
2010-09-11 22:13:39 1554944 ----a-w- c:\windows\system32\vorbis.acm
2010-09-11 22:13:18 0 d-----w- c:\program files\Outsim
2010-09-11 22:13:18 0 d-----w- c:\program files\Image-Line
2010-09-11 20:46:03 0 d-----w- C:\My Videos
2010-09-11 20:45:58 0 d-----w- c:\docume~1\owner\applic~1\aHisoft
2010-09-11 17:04:33 0 ---ha-w- c:\windows\SwSys2.bmp
2010-09-11 17:04:33 0 ---ha-w- c:\windows\SwSys1.bmp
2010-09-11 11:58:02 0 d-----w- c:\docume~1\alluse~1\applic~1\8752149
2010-09-11 10:25:00 0 d-----w- c:\program files\eMule

==================== Find3M ====================

2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-07-27 07:53:38 262144 ----a-w- c:\windows\system32\default_user_class.dat
2010-07-22 15:49:15 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57:20 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-03 06:52:12 47052 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
2006-06-25 06:48:54 32768 ----a-r- c:\windows\inf\UpdateUSB.exe

============= FINISH: 18:28:50.57 ===============


Hijack This

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:21:50 PM, on 22/09/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Software Informer\softinfo.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
c:\program files\logitech\quickcam\lu\lulnchr.exe
c:\program files\logitech\quickcam\lu\LogitechUpdate.exe
C:\Program Files\Microsoft Office\OFFICE11\FRONTPG.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank" class="wLink">http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1274420661109
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 9854 bytes

RELEVANCY SCORE 200
Preferred Solution: Keyboard Issues/Repeat Issues on Virus Scan

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: Keyboard Issues/Repeat Issues on Virus Scan

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

I need to see a gmer log in order to help you.

http://www.techsupportforum.com/f50/...lp-305963.html

Please attach the log to your next reply.

------------------------------------------------------

Read other 2 answers
RELEVANCY SCORE 80.4

Okay, About three months ago, I got hacked HARD...permissions were changed, administrator rights were removed from my administrator accounts, etc. i was flabbergasted. THe iactually didn't bother me though until I ran a MBAM scan and found 133 viruses and spyware instances on my drive (NOT including tracking cookies!). I cleaned and recleaned, using MBAM, SuperantiSpyware, Avira, running each one in safe mode first, then loading into my normal account and running them, and finally erasing my user account and creating a new one. But even after the new user account was created with Administrator privileges, I still routinely received virus and Malware threat warnign flags from MBAM and Avira. Eventually, Avira and MBAM were disabled and Avira was "deleted" (Windows will not uninstall because the setup.exe file has been 'Changed" and won't reinstall it because I don't have "Administrator privileges" on my Administrator accounts!) even though at startup I receive an error message saying that Avira has been corrupted. The most telling issue is that antivirus and spyware/Malware scans come up clean on Safe mode scans, but using my normal account, the machine reboots. Using Superantispyware I notice that it's always during the memory test that this occurs (and in Safe Mode, it passes through this section with no issue). None of my antivirus programs will download updates, even ones I start manually, and although I have no problem acc... Read more

A:Machine reboots during Spyware scan...won't load updates. Issues issues issues!

bump
 

Read other 3 answers
RELEVANCY SCORE 71.6

I've done as much I know how to do so far but need some help with my HJT log. Any help appreciated thanks.

Logfile of HijackThis v1.97.7
Scan saved at 1:13:14 AM, on 10/24/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\GUARDIAN\CMGRDIAN.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\MCAFEE\QUICKCLEAN\PLGUNI.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\DCFSSVC.EXE
C:\WINDOWS\APPLICATION DATA\BTMW.EXE
C:\WINDOWS\SYSTEM\HVEB.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT UPDATER\RULAUNCH.EXE
C:\PROGRAM FILES\NETGEAR\MA101 USB ADAPTER CONFIGURATION UTILITY\WLANMONITOR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uvic.ca/
R... Read more

A:Ran adaware and virus scan but still having some issues. HJT log

Hi RAUSCH,

1 Log in safe mode;

2 With your Add/Remove Programs utility, uninstall (if they exist) My Web Search and Net2Phone;

3 Close all open applications : it is very important;

4 Run HijackThis and fix the following entries :
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
O2 - BHO: (no name) - {3A883C2D-E732-1FC8-8753-60550DF12A1C} - C:\WINDOWS\SYSTEM\HZWQ.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\2.BIN\MWSBAR.DLL (file missing)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\2.BIN\MWSSRCAS.DLL (file missing)
O3 - Toolbar: (no name) - {498AE3C0-2993-11D8-8867-00E029834F05} - (no file)
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\2.BIN\MWSBAR.DLL (file missing)
O4 - HKLM\..\Run: [BFILP] C:\WINDOWS\BFILP.exe
O4 - HKLM\..\Run: [dlrydiiiwddiy] C:\WINDOWS\SYSTEM\pnperxa.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\2.BIN\MWSOEMON.EXE
O4 - HKCU\..\Run: [Occa] C:\WINDOWS\Application Data\btmw.exe
O4 - HKCU\..\Run: [Rrvhp] C:\WINDOWS\SYSTEM\hveb.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\2.BIN\MWSOEMON.EXE
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\Net2Phone... Read more

Read other 2 answers
RELEVANCY SCORE 70.8

While visiting a site that had recently been hacked, I noticed a command-prompt style pop-up appear. It was too quick for me to see what it said. I quit the browser, disconnected from the internet and ran Malwarebytes, which found two potentially unwanted programs (PUP.Optional.ConduitTB.GEN and Pup.Optional.Conduit) and quarantined them. I also ran AVG, which quit without notification in the middle of the scan. At the same time a system tray notification popped up informing me that AVG and Windows Firewall had both been switched off. When I restarted AVG, the interface looked completely different from how it had moments ago.

I'm somewhat wary of using this computer now, as I worry it might have been infected with something. It's possible the change of interface was just a poorly-timed update, as I know one was released for AVG about a week ago. Any help or advice about whether my computer is harbouring something would be greatly appreciated.
 

A:Suspicious Popup Followed By Issues With AVG Virus Scan

Hello,

Your computer isn't infected. There is a change AVG isn't operating properly, so I would uninstall it and then install again.

Make sure to use AVG Remove tool to clean up all remnants.

How to uninstall AVG software | AVG Support
 

Read other 0 answers
RELEVANCY SCORE 70

I have a HP 4200 with 42megs memory. Every once in a while when printing for example a 36 page document. Once it nears the end let say page 35 it starts printing from page one again and then it prints complete. It is intermitten and not document specific.

I have tried printing at a lower resolution, printing in raw format.

Any ideas?
 

Read other answers
RELEVANCY SCORE 69.6

I run avira personal free and i recently ran a full system scan my computer. I computer runs really slow and completely freezes during the scan. During one scan i got an error screen saying windows was forced to shut down to prevent further damage.

I have been using avira for a few days becuase i switched from AVG 8.5, i had to switch because i kept on getting a notification from windows security centre saying avg was turned off.

I have posted my hijackthis log and wonder if there is anything suspicious that could be causing these problems ... thanks in advance for your time.

( i have windows vista home prem (32 bit) windows defender and avira personal, i also have spybot and malware bytes but do not use in real time )
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:32:14, on 15/06/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\ehome\ehtray.exe
C:\... Read more

Read other answers
RELEVANCY SCORE 69.6

Hi Techguy(s),

I am having some major virus issues.

I have eliminated (I think) all I could find yet my poor computer still runs like a tandy 386. Could you guys please take a scan through my latest hijackthis log and tell me what else needs to be removed?

Thanks so much,
Jimmy

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:54:12 PM, on 4/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AutoMate 6\AMTS.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Installer\MSI521.tmp
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\... Read more

A:Major Virus Issues... BHO, Trojans and others... Hijack scan enclosed

Jimmy:

I'm not a qualified malware expert, but I don't see any obvious infection in your log.

---------------------------------------------------------------

There's over-kill with toolbars and a lot of programs running in the background, which is going to contribute to the slowness of your computer.

You should consider getting rid of some of those toolbars and reducing the startup load.

These 2 sites will assist you in trimming down the startup load:

Start - Run - MSCONFIG - OK - "Startup" tab
http://www.sysinfo.org/startuplist.php?type=&filter=&count=100&offset=0

Start - Run - SERVICES.MSC - OK
http://www.blackviper.com/WinXP/Archive/service411.htm
(The "safe" column is a good starting point.)

---------------------------------------------------------------
 

Read other 2 answers
RELEVANCY SCORE 68.8

I have an intermittent issue where my keyboard does not display the correct character when I type it. For example, if I enter Q I get A or if I type @ I get a " instead.

This seems to only happen typing in Explorer and Office Communicator 2005. It NEVER happens in notepad. Very seldom does it happen in Outlook.

To remedy this I type my info in a notepad first. As I am typing this message (in HTML) now I do NOT experience the issue. Again it is intermittent. I believe it is a virus or some tracking thing.

IF I allow a netmeeting from someone else to my PC while the issue is occuring , they can type in my browser and the correct characters display. This problemoccurs with an external or the build in keyboard

At one point I thought some anti-virus software fixed it, In fact it did not. Perhaps it did briefly, then it re-loaded itself.

I have re-imaged my hard-drive and have 'not' put any files back on my PC except Outlook PST files. I did this to eliminate if any files on my PC may be corrupt. Maybe one of the pst files has a bug.

Paul
IBM Thinkpad T-60 XP Professinal 2002 SP3
Parker, CO
 

Read other answers
RELEVANCY SCORE 68.8

Hi!

Yesterday I began experience some issues with my computer. The "next track"-button stopped working as intended, and acts like a right-click now. Thinking my keyboard was broke (dropped it a week ago) I ignored it and played a couple of games. This is where the oddity starts to annoy me; commands which I had not given, such as going left, jumping, opening bags, chats, you name it, occurred every now and then. Believing that it had been one serious hit to the floor some weeks ago I was mostly annoyed with it. This morning, though, it started to type by itself every now and then (about as often as it ruined my game the previous night) making me increasingly frustrated. I tested my keyboard on the family laptop and it worked just fine then (next-track-button works).

PS. I'm not a native English speaker, so I apologize for any grammatical errors.
Also, here is the hijackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:10:26, on 2013-05-02
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\Robin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Robin\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\App... Read more

Read other answers
RELEVANCY SCORE 68.8

I just recently picked up a trojan that keeps my keyboard from working. AVG antivirus (free version) picked it up, I chose to delete the file and was told that the process would be completed on the next reboot. I restarted the system right there and discovered that I could not type in my password in order to get back into windows.

I gave up on getting rid of the problem and attempted to reformat only until realizing that I could not access the boot menu due to the fact that it involves the F12 key command! I cant imagine there is a way to boot from disk without using the keyboard but you never know. Is this common? Is there anyway to sort it out?

The machine in question is a Dell Vostro 1500 running Windows XP. Ive had a couple viruses before but nothing this immobilizing. Any hope?

Preston

Read other answers
RELEVANCY SCORE 68.8

I adjust the sliders for delay and rate but they are inefective

Read other answers
RELEVANCY SCORE 68.8

Winbook with Windows XP Pro, 3 partition HD: "restore" / "user" partition/ 8GB "partition info"; got some horrible virus- couldn't detect with multiple anti-virus prgrms, online scanners. Killed Windows Restore, then internet, then Winbook System Restore, coping files from one folder to another, writing to rewriteable CD; and program after program, when double-clicked to run, instead did not load and show splash screens, but Comodo began popping up error messages that some (not always same one) process or .exe wanted increased rights, control over other prgrms/ processes running in Task Manager, etc.

Finally tried to get as much datafiles off to USB flashdrives and CD, then reinstalled xp pro with options of wiping the two partitions: user and system restore; DID NOT WIPE 'PARTION INFO' partition.

Now funny stuff is happening: 1st: Add Remove Programs would not run until I put an icon on the desktop, selected and right clicked 'Run As', and unchecked the box for protection from rogue program activity. 2nd: Although it worked at first, now AVG will not run scans on individual folders or files when they are right-clicked and "Scan with AVG Freej" (8.0) is chosen from the pop-up list. Looking at processes in Task Manager, alphabatized, shows NO activity in any AVG process when the right-click individual file/folder scan is chosen.

Is this a lost association problem with the OS's right-click option and AVG&... Read more

A:Virus??: AVG won't scan single files with right click. Add/Remove Programs issues

Post a HijackThis log and I'll tell you whether you're infected or not. This topic should be in the Malware Removal & HijackThis Logs forum just to let you know.
 

Read other 2 answers
RELEVANCY SCORE 68.8

Hi;
I inherited a new PC and am debating whether or not to do a reinstall of Windows XP due to all the garbage files and wasted storage I am running into, some of which may be infected by security/virus/trojan issues. Thought the best way to start was to run a HJT scan to see what I am dealing with. Scan is attached if someone would be good enough to take a look, I would appreciate it-
Thanks
Webz

_______________________________HJT SCAN___________________________

Logfile of HijackThis v1.99.1
Scan saved at 7:16:43 AM, on 1/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\ehome\ehtray.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINNT\system32\hphmon03.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINNT\system32\ctfmon.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\CA\CA Interne... Read more

A:Solved: Sorting-out possible virus/trojan security issues...HJT Scan included...

Read other 16 answers
RELEVANCY SCORE 67.2

Friday April 27 I kept on hearing the Windows XP opening fanfare interwoven with my nightmares. At 9 AM I discovered that Windows had been stopping and restarting since 4 AM. The blue stop screen said:
Technical information:
***STOP: 0x0000008e (0xC0000005, 0xFAF3339E, 0xF9B2BAB4, 0x00000000)
I was only able to break the cycle by starting in safe mode, unistalling McAfee, restarting in normal mode with no protection, and downloading McAfee again from the web site. After that I thought I had the problem whipped, until next Friday morning when it started again at 4 AM.

Now I know that it starts when McAfee scans my computer for viruses, whether automatically or because I manually called for a scan.

I got help from McAfee's online chat technical support people. First they sent me MCPR.exe to do a better removal job than the Windows removal service. I ran this iteratively until after the run it had found nothing to remove. Also I removed all TEMP files, .TMP files, and Temporary Internet Files. I ran the McAfee Free Scan and it found nothing.

Usually after an error stop and restart Windows scans the directory structure of the disk. Almost always it names a McAfee file, says that the first allocation unit is not valid, and truncates the entry. Then there are lost chains that it converts into a file with a name Windows invents, FILE0000.CHK. One such file in \Windows\Prefetch was MCVSSHLD.EVE-1E6C14B0.pf and another was MCUIMGR.EXE-0E667E1B.pf. I saved the first f... Read more

A:Virus scan makes Windows stop, blaming mferkdk.sys, restart and repeat endlessly

BUMP bump

Read other 1 answers
RELEVANCY SCORE 66.8

Anyone know how to change the keyboard repeat delay, repeat rate in RC build?

Annoying as hell, as its so slow, and I cant find it anywhere lol!

Many thx

A:Keyboard repeat delay, repeat rate??

Hello Rik,

You can find it in the Control Panel (large or small icon view) under the Keyboard icon. Yours may look a little different since this is driver specific, but it should be similar.



Hope this helps,
Shawn

Read other 6 answers
RELEVANCY SCORE 64.4

I have been trying to post for several days but unable to. The issues i have been having includes: my driver for my NVIDIA GeForce 7400 is preventing standby, google is directing me to junk sites, and i am having issues with restarting with either it taking forever to shut down, or when it restarts, all i get is a background and pointer, but that's it.

whenever i try to copy and paste, i think that is what is preventing me from being able to post. so my dds log is attached but that's all i can do for now...

A:several issues... virus? junk sites, device driver, logging on issues

Hello Leah,

I appreciate your efforts, but I really need to see the dds.txt. That's the one with all the 'meat'

Can you please run dds.scr again and attach the dds.txt?

What about gmer? Were you able to run that?

Read other 13 answers
RELEVANCY SCORE 64

Everytime I do a search, I click on the links and am redirected to different nonsense websites. Most of these websites are about making money from home, entering a contest or telling me I am a winner of something. I also cannot download any new games from a gaming website. My computer is running very slow and it seems to be getting worse by the day. I have ran several programs to fix this and nothing is found. Can these logs tell anyone anything? Everytime I run the GMER program I get the blue screen so I do not have those logs, sorry.DDS (Ver_10-03-17.01) - NTFSx86 Run by Owner at 17:54:49.51 on Sun 07/11/2010Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.307 [GMT -4:00]AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}============== Running Processes ===============C:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\wltrysvc.exeC:\WINDOWS\System32\bcmwltry.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Sys... Read more

A:Search Engine redirect issues issues! Virus? Malware?

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.Double click DeFogger to run the tool. The ap... Read more

Read other 3 answers
RELEVANCY SCORE 64

Upon restart the blue screen says wsock32 deleted or changed (can't remember which) and after login to windows IE asks if i want to restore previous session and if yes is clicked it opens some 24-28 windows. I've also got 8 different svchost.exe processes running in task manager which is a new thing. Avast has found and isolated (but not deleted) wsock32.sys & xwr15685.dll in its virus chest.EDIT... Unsure if it helps at all but i also have unsecapp.exe running in the task manager processes which is similar to processes run by 2 known viruses. I'm also unable to start the windows firewallDDS (Ver_10-03-17.01) - NTFSx86 Run by gregeahh at 23:31:31.29 on Wed 08/18/2010Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.83 [GMT -6:00]AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}AV: Norton 360 *On-access scanning disabled* (Outdated) {A5F1BC7C-EA33-4247-961C-0217208396C4}FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcsC:\WINDOWS\system32\svchost.exe -k WudfServiceGroupsvchost.exesvchost.exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exeC:\Program Files\Lavasoft\Ad-Aware\AAWSe... Read more

A:Possible multiple virus/malware issues (wsock32.sys & xwr15685.dll known issues)

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the ... Read more

Read other 10 answers
RELEVANCY SCORE 63.2

I am going insane with the issues on my computer right now. If I use a search engine, any links I click on redirect me to random virus scans and other pages that have nothing to do with the original link. Whatever has taken hold of my computer also makes my Norton 360 freeze, shutdown, and not work correctly. Scanning with anti-malware is nearly impossible. I've changed the file name to get them to run, and then only in safe mode will they somewhat work. Whenever I try to download new programs to help, it leads me to a blank page. I can't even get to windows update because it is blocked and just leads me to a search engine. I would appreciate any help that you can give me. Attached is the logs requested in the before you post message and the hijackthis log.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:32:52 PM, on 5/31/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16827)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\TGTSoft\StyleXP\StyleXPService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\bgsvcgen.exeC:\Program Files\Bonjour\mDNSResponder.exeC:&... Read more

A:Redirect issues, Shuts down Virus Protection, other issues.

Hi spagtscully,Welcome to BC HijackThis forum. I am farbar. I am going to assist you with your problem.Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.Your log(s) show that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world the cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."Removal InstructionsYou computer is infected with at least a trojan DNS-Changer.Empty all p2p download folders. They might contain infected files. Please avoid using these p2p applications until the system is clean. Using these applications at this stage might lead to reinfection or infecting other users.
Download ComboFix from one of these locations:Link 1
Link 2
Link... Read more

Read other 12 answers
RELEVANCY SCORE 62

Hello everyone.
I've done this before once last year and you guys saved my computer.. thanks for that.
I'm here once again with a different dilemma.

I've noticed today that I got a warning from my windows telling me I did not have my firewall "on". I don't know what happened as I never touch those settings.. but I went to turn it back on and it won't let me.. all I get is an error msg saying something like.." Windows cannot start the windows firewall/internet connection sharing service.. ERROR 2 ".

I've also noticed (today) that when I click on a Google result link, it does not take me to the link address.. instead, in redirects me to another place (directory?).... also, when I have my browser open while reading something, it automatically opens a new tab on my browser transferring me to who knows where out of the blue I use FireFox.

Another problem is that I almost always do a scan with Spybot (S&D) and it always finds the SAME problems and destroys them, but the problems keeps coming back over and over again
something called "Gamevance.Playsushi".. I have killed that thing like 100 times per day with spy bot and it still keeps coming back... I have tried to uninstall these gamevance but they are no where to be found in my system... I also downloaded today something called "housecall" to do a scan and found NOTHING... I've also scanned it with AVAST home edition and found NOTHING.

Only Spybo... Read more

Read other answers
RELEVANCY SCORE 58.8

Please help, my cat sat on my keyboard this morning and turned something on - it was a Flash keys option I think (or Filter Keys?) - couldn't really see around her. I now have noises each time I press a key and am not able to repeat keys easily - only one stroke per key is allowed at a time

I have no idea what keys she hit, but she was near the bottom left side of my keyboard. Can anybody help PLEASE?
Thanks in advance.
DiverJen

A:Keyboard making sounds, won't repeat keystrokes - cat sat on keyboard!

  
Quote: Originally Posted by Diverjenno


Please help, my cat sat on my keyboard this morning and turned something on - it was a Flash keys option I think (or Filter Keys?) - couldn't really see around her. I now have noises each time I press a key and am not able to repeat keys easily - only one stroke per key is allowed at a time

I have no idea what keys she hit, but she was near the bottom left side of my keyboard. Can anybody help PLEASE?
Thanks in advance.
DiverJen


Are the sounds like a hissing or scratching or more like a purrring........Sorry, I couldn't resist. -- Have you tried connecting a different keyboard? This way you would know if the keyboard is broken or if the cat set off a combination of keys that codes something into the PC.

Read other 9 answers
RELEVANCY SCORE 58.4

Hello ppl
Problem::
Ok i did a full scan last night with MBAM, got couple of file which i quarantined, regardless of noticing ther might be false+, i belive i have deletetd some windows file

Symptom::
I cant open up the services console from the start menu , whenever i try, it gives me an error saying ''windows cannot open the file'' and gives me an option to choose a program to open it or search for it on the web,

Solution i have tried::
Well i can go to services only through MMC (adding snapins )
Anyone please advise, is there a folder where therz a backup of all the quarantined files?
Also

m getting a regular msg of ''interactive services dialogue detection'', like every 5mins, and if select to view the message, all i get is a plane desktop with a rogue/fake AV scanning and shows fake reults, probably its one of those fake vista guardian anti virus,

also if i right click my computer, windows explorer restarts.....some random bollux in my pc

i have the logs for DDS and Gmer and obv the MBAM log as well.

shall i post all of them here Or zipping it is must?

please advise

thanks

A:Scan, Quarantined and issues!

??

Read other 1 answers
RELEVANCY SCORE 58.4

Hello, I'm having problems scanning with microsoft security essentials, and have some other issues as well. I didn't think I was infected at first but now there are just a few too many issues occurring so I'd like to make sure. I'm running 64-bit Windows 7. I have MSE set up to scan every week but I've noticed lately that the scan never completes. I can see the icon spinning in the taskbar, but if I try to maximize the MSE window, the window opens but doesn't respond. I'm unable to see if there's a specific file it's stuck on. It's ok when doing quick scan, but not a full scan. I've also had some weird explorer dialogue box popping up a few times, but I can't remember what it said other than something about a .dll file. I haven't been able to replicate the popup, it seemed to happen when first logging into the computer but didn't most recently. What can I do to fix MSE and make sure that this isn't being caused by any adware? Thanks for the help.

A:MSE scan won't complete; other issues

cjshoop9:
to the Bleeping Computer Am I Infected Forum. My name is Phil. I would like to call you by your first name as well, if that is alright with you.
It could possibly be adware that is interfering with your MSE, but I think we should first just have a look and see if the problem is caused by something more nefarious. Let's run a couple of scans.
ESET Online Scanner using Internet Explorer:Note 1: These instructions are for Internet Explorer only! If you're using Chrome or Firefox, you will need to download and install the ESET Smart Installer tool before it can scan. See instructions here.Note 2: You will need to disable your currently installed Anti-Virus, how to do so can be found here.
*Click this link to open ESET OnlineScan.
* Place a checkmark next to "Yes, I accept the Terms of Use", then click the button.
* When prompted allow the Add-On/Active X to install.
* In the new window that opens, tic the radio button next to Enable detection of potentially unwanted applications.
* Then click "Advanced settings", and make sure there is a checkmark next to only the following items (uncheck everything else):
Remove found threats
Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology
*Then click the button and ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
*When the scan completes, click List Found Threats (only if anything is found).
*Then clic... Read more

Read other 8 answers
RELEVANCY SCORE 58.4

Upon doing my typical AVG virus scan I saw many warnings for varioius things including but not limited to yieldmanager and other nasties. I am currently also having issues where every so often my internet connection seems to just shut down for a few seconds and it is enough to knock me off of all programs before it restores itself. I am not sure if it could be spyware sending info in or out but thought I would mention it as well. Following is my hijack log,

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:27:31 PM, on 10/4/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSUI.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSMonitor.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink... Read more

Read other answers
RELEVANCY SCORE 58.4

why is avast unable to read so many files[so scan report says] when AVG and A-Squared
say no such thing? I'm talking about a huge number of files where possibly viruses
could be hiding.
fortunately AVG and A-Squared scans always come up clean.

thanks
 

A:avast scan issues

Hi what sort of files is it unable to read?
Do you disable Avg before running a scan with Avast?
 

Read other 3 answers
RELEVANCY SCORE 58.4

Someone please help! Ad-Ware found these issues on my computer. I'm not sure what they are, what they mean or what I should do about them. All help and advice are welcome. Thanks!

A:Ad-Aware scan issues

Those are known nasties, I would suggest you quarantine them.

Read other 2 answers
RELEVANCY SCORE 58.4

I have a HP 6110xi all in one printer that works OK for SCAN when I do it from the HP Director software. I want to be able to scan by just loading documents on the 6110 and pressing Scan. When I do that I get the "No Scan Option" and it says I need to run HP software. I can find no documentation on web to correct this or add options or determine what softare I need to load. Can you give me step by step directions on what is wrong?
Thank you very much!
 

Read other answers
RELEVANCY SCORE 58.4

I recently downloaded the free trial for ESET Smart Security 4 to try it out, and for some reason, scans dont seem to be working properly. First off, they take forever. I let one run for 6 hours and it was at about 43%. Also, when I read the log, it lists failed attempts to open files or to extract. I was hoping someone knows what might be causing this problem and could help me out. I'm going to include a part of one of the scan logs as well for reference.

Thank you,

Zach
Scan Log
Version of virus signature database: 6227 (20110621)
Date: 6/21/2011 Time: 6:39:13 PM
Scanned disks, folders and files: Operating memory;C:\Boot sector;C:\;D:\Boot sector;D:\;E:\Boot sector;E:\
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\12116c1e6a6500d4c400f4\$shtdwn$.req - error opening [4]
C:\12116c1e6a6500d4c400f4\mrt.exe._p - error opening [4]
C:\12116c1e6a6500d4c400f4\mrtstub.exe - error opening [4]
C:\cb1adca8e19af86b6c862927\netfx_Core.mzz ? CAB ? _001_dfshim_dll_x86 - decompression could not complete (possible reasons: insufficient free memory or disk space, or a problem with temp folders)
C:\cb1adca8e19af86b6c862927\netfx_Core.mzz ? CAB ? _003_mscoree_dll_x86 - decompression could not complete (possible reasons: insufficient free memory or disk space, or a problem with temp folders)
C:\cb1adca8e19af86b6c862927\netfx_Core.mzz ? CAB ? _007... Read more

A:ESET Scan Issues

Does your system meet all of the requirements? Particularly the Memory commit charge: 80 MB

Read other 11 answers
RELEVANCY SCORE 58.4

Hello,Reading around web and many sites recommended downloading/running HijackThis. Did so 2 days ago. Scan showed 48 entries though all greek to me, lol. This site also came recommended for such. Decipering them that is.Followed post "Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help". Was hoping the logs done could be looked at to see if all is ok. Computer runs fine, scans with Norton NIS 2011, Malwarebytes, SuperAntispyware and Ad-Aware always come up clean, but being a novice I figured maybe something sneaked in.The only part I guess I didn't need to do was the GMER scan. Didn't realize I had 64-bit. Because Internet Explorer has the 32-bit browser I thought I needed it (GMER).ThanksFred

A:Problem issues with HJT log scan?

If your computer is running fine, leave it alone.

Read other 3 answers
RELEVANCY SCORE 58

Hello!I noticed problems with my pc. redirecting, pc freezing up, funny things with email.I did I hijack log below. I did a malware scan and I had tons of malware in my registry keys..one being "backdoor.exe" HELP please. I would like to know how to delete these without me screwing something up.Thanks,Cyberabyss.Logfile of HijackThis v1.99.1Scan saved at 11:22:09 AM, on 9/2/2005Platform: Windows ME (Win9x 4.90.3000)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\SPOOL32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\SYSTEM\SSDPSRV.EXEC:\PROGRAM FILES\COMMON FILES\AOL\TOPSPEED\2.0\AOLTSMON.EXEC:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXEC:\PROGRAM FILES\COMMON FILES\AOL\TOPSPEED\2.0\AOLTPSPD.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\RESTORE\STMGR.EXEC:\WINDOWS\SYSTEM\DDHELP.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXEC:\WINDOWS\SYSTEM\HPSYSDRV.EXEC:\PROGRAM FILES\MOTIVE\MOTMON.EXEC:\PROGRAM FILES\THE CLEANER\TCA.EXEC:... Read more

A:I did a scan because of all kinds of pc issues YIKES

Welcome to the BleepingComputer forum. We are currently studying your log and will have instructions for you shortly. Thank you for your patience.

Read other 7 answers
RELEVANCY SCORE 58

I am having issues with Symantec saying it is scanning several emails when I don't even have outlook set up or any other programs running. Here is the HijackThis Log. Can someone please guide me as to which items I should fix and remove? Thank you.Marc ALogfile of Trend Micro HijackThis v2.0.4Scan saved at 9:04:27 PM, on 8/7/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEc:\Program Files\Common Files\Symantec Shared\ccProxy.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Norton Internet Security\ISSVC.exec:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exec:\Program Files\Common Files\Symantec Shared\SNDSrvc.exec:\Program Files\Common Files\Symantec Shared\SPBBC\... Read more

A:Symantec email scan issues

Hello Marc Anthony and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Follow the... Read more

Read other 5 answers
RELEVANCY SCORE 58

I ran Malwarebytes and Dr. Webb scans earlier today just to see if I had any infections and according to the scan results I do have some problems. I posted the logs to each of these scans today, but I think I failed to follow BC forum rules. Sorry!! How should I proceed?

rlight

A:Malware Scan Results I've got issues.

Hello,

I would add a post to the other topic explaining your computer symptoms and what led you to run those scans.

To avoid confusion, I shall close this topic.

Orange Blossom

Read other 1 answers
RELEVANCY SCORE 57.2

Hello,

Slow...my pc should by movin faster than I can think and it's not. Also I get many "port scan attack is logged" and "traffic from ip...is blocked" from sygate ALL the time. (and if I check the "do not show this again" box, it keeps on popping up??)
I know I've got some junk in here just not sure where or what. BTW I just switched over to firefox to surf.

I've followed all the reccomended steps before posting. The internet scans found 16 infections but only could get rid of one. I have the results saved if that would help. Well here is my hijackthis log. Hope you can help, thanks!



Logfile of HijackThis v1.99.1
Scan saved at 10:02:28 PM, on 9/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ESRI\License\arcgis9x\ARCGIS.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WI... Read more

A:slow pc, repeat port scan attacks

bump.

Read other 10 answers
RELEVANCY SCORE 57.2

Hi,
 
I did a scan with EEK today and for the 1st time it alerted me to some problems.  I did a search online to try to get information on the items it listed but didn't really find anything helpful.  Can someone take a look at my log and tell me what these things are?  Occasional scans with Malwarebytes never picked up a thing.  Thanks in advance.
 
Emsisoft Emergency Kit - Version 4.0
Last update: 2/27/2014 3:54:35 PM
User account: ****-PC\****
 
Scan settings:
Scan type: Smart Scan
Objects: Rootkits, Memory, Traces, C:\Windows\, C:\Program Files\, C:\Program Files (x86)\
Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off
Scan start:    2/27/2014 3:56:23 PM
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR     detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-3151099521-301102294-2406360421-1001\SO... Read more

A:Did a scan with Emsisoft Emergency Kit, found Issues

The command prompt and Task manager have been disabled by whom I don`t know.Do you use optimization software like Advance system care or similar? I am guessing at the moment.

Read other 11 answers
RELEVANCY SCORE 57.2

I have Windows ME, and I am unable to defrag or run scan disk. I have had this problem for sometime now, and cannot figure out how to fix it. Any ideas?
 

A:Solved: Having issues with defrag and scan disk

Read other 16 answers
RELEVANCY SCORE 57.2

Adivce and assistance will be welcome, please?

My symptoms
---------------------
Slow program initial-loads; slow internet browse. Today, Spybot-SD (free version) scan revealed about 58 issues of which 55 fixed but 3 issues that resist Spybot-SD fixing. I also use Avast! Antivirus (free version).

To assist I include below, the final SpybotS-D scan.

I include below the suggested TSG SysInfo; and, I followed Tech Support Guys guidance http://forums.techguy.org/virus-other-malware-removal/943214-

everyone-must-read-before-posting.html and also include below, scans-reports - per HijackThis, dds.scr, and per GMER download. Each report separated by batch of pluses (++++++++).

+++ start of TSG SysInfo +++++++
TSG SysInfo
---------------------------------------------------
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows XP Professional, Service Pack 3, 32 bit
Processor: Genuine Intel(R) CPU T2130 @ 1.86GHz, x86 Family 6 Model 14 Stepping 12
Processor Count: 2
RAM: 1919 Mb
Graphics Card: ATI RADEON XPRESS 200M Series, 256 Mb
Hard Drives: C: Total - 46865 MB, Free - 14252 MB; D: Total - 65687 MB, Free - 44738 MB;
Motherboard: ASUSTeK Computer Inc., F5R
Antivirus: avast! Antivirus, Updated: Yes, On-Demand Scanner: Enabled

+++ end of Sysinfo ++++
+++++++++++++++++++++++

+++ start of hijack thus ++++++
hijackthis.log
----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:52:48, on 22/11/2013
Pla... Read more

Read other answers
RELEVANCY SCORE 57.2

Hi all,

Desperate for help and cannot imagine I am the only one who has had this!

During an AVG scan (possibly by coincidence) I got a second fake anti virus program, including resident shield, program appear. I had delat wiht one a couple of weeks ago using Malwarebytes and Windows defender but this one refused to shift. After running Malware bytes in normal mode, I then then ran super anti spyware in safe mode. It removed about 300 threats (!!!) to my machine, but then hung on the welcome screen to windows (running XP pro).

Reading up on various forums I followed advice and ran AVG in safe mode, in the command line version. I looked over and saw that it had detected a problem with WINLOGON.EXE and EXPLORER.EXE and had deleted both. Warning signs, as you can imagine went off. I let the PC finish the scan overnight and sure enough, in the morning I tried to boot the machine and only got the initial Windows start up screen before it restarted on its own accord.

Got a copy of XP (not original) and tried to gain access to recovery mode but to no avail. Don't want to re format machine (believe I have product key on sticker on machine) as all my music etc is there .

Any ideas on how to bring my machine back to life would be much appreciated as GF is about to start uni again and I dont have the money for a new machine yet!!

Thanks all, apologies if this has been posted before just having a nightmare and don't know what to do next.

Thanks

Towe... Read more

A:Major Boot up issues follwing AVG Scan

Hi Towelie, can you please try to create and boot from the CD?Please download ARCDC from Artellos.com.Double click ARCDC.exeFollow the dialog until you see 6 options. Please pick: Windows Professional SP2 & SP3You will be prompted with a Terms of Use by Microsoft, please accept.You will see a few dos screens flash by, this is normal.Next you will be able to choose to add extra files. Select the Default Files.The last window will allow you to burn the disk using BurnCDCCYour ISO is located on your desktop. Insert the CD-ROM into the CD-ROM drive, and then restart the computer.

If your PC is not booting from the CD, you need to change the boot order:Restart your PC As soon as you get an image, press the Setup key. This is usually F2, or Del. On some machines the key can also be a different one. It should, however, be stated on the screen which key is the setup key. Once you enter the computer's BIOS, use the arrow keys and tab key to move between elements. Press enter to select an item to change. Navigate to the tab, where you can set the boot order. It should be called Boot or Boot order The tab should now show your current boot order.
If the CD-drive is not at the top, please navigate to the CD-Rom drive with the keys arrows. Then move it to the top of the list. The keys for switching boot position are usually + to move up and - to move down. However they can be different, but they should be stated in the help, so that you can find them easily. Once the CD-driv... Read more

Read other 1 answers
RELEVANCY SCORE 57.2

Hello
I'm having several issues: Initially my system kept freezing after 2 or so minutes after boot, no matter what I did. Once it froze, Ctr-Alt-Del would hang up for awhile and then I would get a continous error without being able to get into task manager. All I could do is a hard restart. I uninstalled Symantec NIS (after trying numerous other things) and the freezing up went away for a time being, however I noticed weird things with Firefox, such as not all of my bookmarks displayed in the toolbar, giving me an alert every page i navigate to about notification of secure/encrypted page. Also i found a new folder "playmp3z" in the start menu. The following day the freezing began again, except this time I can do most of my everyday tasks such as Internet surfing, word processing, etc. The system now crashes every time i try any antivirus or anti-spyware scan both on and off line. The only one that does not crash the system is Deckard's System Scan, the logs of which are attached as per instructions (it did freeze briefly/became unresponsive but recovered by itself). I can't get Panda online scan to open--all I get is a blank page when clicking on Scan Your PC Now. No new spyware or programs that i've noticed except the "playmp3z" in program directory which i cannot uninstall with add/remove. Also, Windows Update returns "error 8024A000" which is also new--have never had an issue with the Update before.
My system: Dell XPS m1330, Win Vist... Read more

A:System freezes during scan; weird issues

Hello. Can someone please help me with this issue? Thank you for the help

Read other 1 answers
RELEVANCY SCORE 56.8

I think I am ready to put my head through a wall on this......!! It's been terribly frustrating and I will be indebted to anyone that can tell me what this all means!

Randomly, things will freeze up out of nowhere while I am doing nothing. I am running Vista (64) and using Firefox (current version, updated). In my startup, I run Avira (AV) and Windows Firewall...nothing. My first sign something is going to start is when I go to log onto my own profile, the "WELCOME" splash thingy just keeps going and going and going. Eventually, I get to my desktop. Forget trying to click on anything, when I am able to, it doesn't matter WHAT it is, it is "not responding". It is a vicious cycle! But again, it is random....it happens sometimes and other times, it doesn't.

When it is happening, if I go into safe mode, I have no issues AT ALL. NONE!

Running scan disk when it is happening results in this EACH AND EVERY TIME!

92 reparse records processed

deleting entry netrasa_inf_loc in index $130 of file 1413
1 unindexed filed processed
recovering orphaned file (I can't read my writing....is it file I wrote?) (37699).

This is completely greek language to me.....


To top it off, my touch pad has gone bad and my battery is acting truly bizarre. sometimes I will get the "plugged in, not charging" thing.....sometimes it takes FOREVER for the battery to fully charge..and then, when I unplug, the thing instantly goes down to maybe ... Read more

A:Scan Disk...netrasa.inf_loc, other windows issues?

" No issues in Safemode.." = anti-virus &/ or 3rd party firewall present (may be old/ inactive..?); another driver issue

Run msinfo32 - save as an NFO file
START | type msinfo32 | save w/ default NFO file ext

Zip it up & attach.

Regards. . .

jcgriff2

.

Read other 4 answers
RELEVANCY SCORE 56.8

I removed Easy Scan using Malwarebytes. Now I have brower hijack issues. Please review my hjt log and let me know which items to fix.

Thank you.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:37:02 AM, on 1/1/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\NeatWorks\exec\NeatWorksDatabaseController.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Microsoft\Search Enhancem... Read more

A:removed Easy Scan. Now have browser hijack issues

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will ap... Read more

Read other 3 answers
RELEVANCY SCORE 55.6

I have some problems with my keyboard. I know that this not an issue with the keyboard, since I have tried two keyboards. One wired, one wireless. Anyway, the problems are that sometimes keys take 5-10 seconds to respond, keys sometimes hang, and that keys sometimes completely stop responding. Remember, all 3 of these problems occur no matter which I try to use. The two keyboards I have tried are the SteelSeries Apex (Wired) and the Logitech K520 (Wireless). More details about keyboards (probably unnecessary):
Apex:
-Customizable color options, also has effects that fade into different colors
-4 profiles with keys to switch (acts like different keyboardsno changes to USB hub)
-2 USB 2.0 Ports
-Takes 2 USB slots
-SteelSeries logo button between right ALT and document (correct word) button
K520:
-Battery Indicator
-Meh, other than that, just an average keyboard with a number pad
EDIT: Ran sfc /scannow, no problems.

A:Various keyboard issues (Not a problem with keyboard)

Originally Posted by evantig


I have some problems with my keyboard. I know that this not an issue with the keyboard, since I have tried two keyboards. One wired, one wireless. Anyway, the problems are that sometimes keys take 5-10 seconds to respond, keys sometimes hang, and that keys sometimes completely stop responding. Remember, all 3 of these problems occur no matter which I try to use. The two keyboards I have tried are the SteelSeries Apex (Wired) and the Logitech K520 (Wireless). More details about keyboards (probably unnecessary):
Apex:
-Customizable color options, also has effects that fade into different colors
-4 profiles with keys to switch (acts like different keyboardsno changes to USB hub)
-2 USB 2.0 Ports
-Takes 2 USB slots
-SteelSeries logo button between right ALT and document (correct word) button
K520:
-Battery Indicator
-Meh, other than that, just an average keyboard with a number pad



The Wired keyboards can be either PS/2 [round purple plug] or USB. The Wireless probably used a USB transceiver/dongle.

Since you say the problem is not the keyboard but you don't say whether those same keyboards have been tested on other computers my best guess is the either the keyboards are bad, unlikely for all 3 at the same time, or that the keyboard controller on the motherboard for the ports is bad. My first diagnostic is to shut the computer down and pull the power cord from the back of it, wait a minute and plug it back in and try a... Read more

Read other 4 answers
RELEVANCY SCORE 55.6

Hi everyone.

I have been experiencing serious keyboard issues since Friday on my dell inspiron 1420 laptop.

Goes like this:

Only the keys 5 and 6 work in the numbers row
windows button does not work
Most of the time i can type with my all my letters, but sometimes, pressing letters such as D, E, W executes the windows shortcuts automatically.
For instance, usually to head back to my desktop I use "windows button + D" - with my current problem sometimes only pressing on D will activate that shortcut - and this goes for all windows shortcuts basically making it impossible for me to use my keyboard.

Then sometimes my whole system is going haywire i.e volumes going up and down for no reason, windows that are closing and opening, pages refreshing, exporer opening up for no reason etc. - as if there was a faulty electronics problem randomly activating those buttons.

I have tried to load my system in safe mode but the problem still remains.
I have also just re-installed windows 7 and the problem still remains.

I am almost sure this is a hardware problem - faulty electronics regarding keyboard control

I dont think this is a virus or a malaware issue because re-installing windows did not help.

On another note, while cheking theweb for solution, it has been brought to my attention that other people have this problem (number keys not working except the 5 and 6 ones) and I have yet to find a solution or an explination.

Can anyone help me out?
... Read more

A:Serious keyboard issues - keyboard has a mind of its own

Have you tried plugging in an external USB keyboard to see if it exhibits the same problem?

If it turns out to be the keyboard, they are available on Ebay and fairly cheap to buy. They aren't difficult to install, usually just a couple of screws.

Here's an example of one on Ebay: New-Keyboard-Dell-Inspiron-1420

Read other 2 answers
RELEVANCY SCORE 55.6

I'm having problems with a keyboard on a different system than this - It's an ABit BH-6 with a Pentium 3 550. The keyboard simply will not work. I tried it on this system and it works fine. It's completely dead - not even the caps, scroll and num lock lights work. Yes, it is plugged in. Are the PS/2 ports on my system board not working? A simple PS/2 - USB adapter will fix this. Is it something in the keyboard that makes it uncompatible with the board? It's not a device problem in Windows - I can't use it outside of it either (Like hitting del to enter my CMOS). Anyone have this same problem??
 

A:Keyboard Issues

Originally posted by Vehementi
Yes, it is plugged in. Are the PS/2 ports on my system board not working? A simple PS/2 - USB adapter will fix this. Is it something in the keyboard that makes it uncompatible with the board? It's not a device problem in Windows - I can't use it outside of it either (Like hitting del to enter my CMOS). Anyone have this same problem?? Click to expand...

Sounds very much like a dead ps/2 port to me...
If it had been something else, you should've noticed it when you switched the keyboard from one 'puter to another.... (BTW: you did test with another keyboard on the BH-6?)
 

Read other 6 answers
RELEVANCY SCORE 55.6

I play a videogame called Spore, and there is an assymetry feature in the creator, it requires me to hold A. I want to know how to disable my computer freezing the mouse when keys are held down.

A:Keyboard issues

Welcome to Seven Forums
You can go to control panel >keyboard and adjust the speed of the delay, I don't see a place to disable it completely.
If I remember correctly in XP you would get a sticky key error and could make changes then but in Seven it looks as if you could adjust the speed in which it allows you to hold down a key, now I don't know how this is going to effect the rest of your game play but you might want to give it a try.

Perhaps someone else may have a better ideal
Fabe

Read other 1 answers
RELEVANCY SCORE 55.6

already reboot my hp elitebook windows 7 but some of the keys in the keyboard is still not working. Also tried uninstallin the keyboard in device manager but still the same need some help...

Read other answers
RELEVANCY SCORE 55.6

Hi all, I've had my P53 workstation for a few months now, and it seems to be randomly missing key presses. I originally thought it might be a problem with my typing, but a quick Google search showed me the same problem has been experienced by some on other Thinkpads of the same generation. Has anyone had the same problem? Is there any solution I can try before returning it? The problem is quite infrequent, but frequent enough to be noticeable and letters disappear when I write a long text. Thanks.

Read other answers