Over 1 million tech questions and answers.

I Thought I Should Pass This On!

Q: I Thought I Should Pass This On!

Hello,This happened to me yesterday, quote from Adware Report, [/Flooder.akeFlooder.Ake is a brand new threat that began to appear on people's computers on December 6th, 2006.The symptoms of infection are an alert window which pops up reading "threat found, trojan horse, heal now". Clicking this popup quarantines a system file, which then restarts the computer and pops up the alert again. The computer is then stuck in an infinite loop. It appears at this time that neither restoring the file from quarantine nor restoring the system using a Windows restore point will fix the computer. Only a complete reinstall of the operating system will work.This problem only seems to be impacting users of the antivirus program, AVG. Initial indications are that this not a true virus, but rather a bug in AVG that results in damage to system critical files.If you are experiencing problems associated with flooder.ake, please post any pertinent information below. If you have a screenshot that we may share with our readers, please post a URL where we may find it. Thank you!Step-by-Step Fix1. Boot your computer to Safe mode. Power on (or restart) your computer, keep pressing F8 key until the Startup menu appears and choose "Windows in Safe Mode".2. In the Windows Safe mode, navigate to following folder:C:\WINDOWS\system32\drivers\3. Rename rename the following files to avoid furhter deleting of "winlogon.exe".AVGCLEAN.SYS -> AVGCLEAN.SY_AVGRSXP.SYS -> AVGRSXP.SY_4. Launch Registry Editor (regedit.exe) and remove the "__delete" value in the right pane from this key:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgClean5. Restart the computer back to Windows normal mode6. Update your AVG program to latest virus base version. Launch AVG or open AVG Control Center and press F9 key to update your AVG.7. Then rename the SYS files back to their original namesAVGCLEAN.SY_ -> AVGCLEAN.SYSAVGRSXP.SY_ -> AVGRSXP.SYS8. Restart your computer for to get AVG Resident shield loaded again ]I was lucky, I have Windows SP2, it looks like people without the service packs are experiencing some major difficulties. I went to the AVG web site and there is no mention of this problem there as of yet.I hope this helps someone,have a great day,Wink

RELEVANCY SCORE 200
Preferred Solution: I Thought I Should Pass This On!

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: I Thought I Should Pass This On!

The existence of this false positive appears to be limited to certain versions of Windows XP without Service Packs, and the problem has been quickly fixed by a new definition file. (I would like to thank members of the BC Staff and TeMerc for further researching the problem mentioned in Wink's post).In the AVG Forum, Radek Janata, a member of the Grisoft Team, responded as follows:?Unfortunately, this issue is caused by the false detection on particular version of "winlogon.exe" file. The false detection has been immediately fixed, however several users may have updated their AVG to this virus update containing this false definition. In order to solve this unpleasant issue, please proceed as follows: 1. Boot your computer to Safe mode. Power on (or restart) your computer, keep pressing F8 key until the Startup menu appears and choose "Windows in Safe Mode". 2. In the Windows Safe mode, navigate to following folder:C:\WINDOWS\system32\drivers\ 3. Rename rename the following files to avoid furhter (sic) deleting of "winlogon.exe". AVGCLEAN.SYS -> AVGCLEAN.SY_ AVGRSXP.SYS -> AVGRSXP.SY_ 4. Launch Registry Editor (regedit.exe) and remove the "__delete" value in the right pane from this key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgClean 5. Restart the computer back to Windows normal mode 6. Update your AVG program to latest virus base version. Launch AVG or open AVG Control Center and press F9 key to update your AVG. 7. Then rename the SYS files back to their original names AVGCLEAN.SY_ -> AVGCLEAN.SYS AVGRSXP.SY_ -> AVGRSXP.SYS 8. Restart your computer for to get AVG Resident shield loaded again The problem should be solved now. Please note that this issue may happen on a very old Windows XP systems without any Service Packs. This issue doesn't appear on Windows XP Service Pack 1 or Service Pack 2. Therefore we strongly recommend to update your Windows XP to Service Pack 2, not only to get your computer secure. Visit [www.windowsupdate.com] to get the latest critical security patches for your operating system.Please accept our apologies for this inconvenience."Further discussion may be found in this AVG Forum thread:http://forum.grisoft.cz/freeforum/search.p...hor=1,subject=1Regards,John_

Read other 8 answers
RELEVANCY SCORE 65.6

http://www.us-cert.gov/cas/techalerts/TA04-261A.html

Just in case some of you are using Mozilla and Firefox...
 

A:Thought I pass this on....

Breaking News! Carnegie Mellon has received a $20 million gift from the Bill & Melinda Gates Foundation to help fund construction of a new building dedicated to expanding the horizons of computer science!Click to expand...
....c,mon man , think we are blind or what . ...maybe a couple of "fixes " which mozilla can do in a day , micro-suck takes months and neglects to alert any of their users ....i believe this to be a biased article which they alone probably published .........
 

Read other 3 answers
RELEVANCY SCORE 46.4

Hi All,
I tested the following attacks in Microsoft Advanced Threat Analytics and found them
not to be working.

Bruteforce Attack Pass-The-Ticket Pass-The-Hash Sensitive account exposed Using Plain-Text Authentication
I have tested other attacks like Reconnaissance
using DNS, Broken Trust, Honey Token account suspicious activities but they are working perfectly fine. I don't know
what's the issue with the above 4.
For
1. Bruteforce Attack:
I used thc-hydra-windows and triggered a dictionary attack using a list of passwords.

2. Pass-The-Ticket:
I used mimikatz to steal the kerberos ticket from a PC on which Admin is logged on. Impersonating an attacker, I copied the .kirbi file and Injected that file(using mimikatz again) to another PC on which a domain user is logged in.

3. Pass-The-Hash:
(Same as above)
4. Sensitive account exposed in plain text authentication:
I used mimikatz command 'sekurlsa :: logonpasswords' and was able to get passwords of all the users who logged on to that PC. But this was also not detected by MATA.

Please help me with the above issues. If possible, provide the tools using which I can trigger and detect those attacks.
Regards 

Read other answers
RELEVANCY SCORE 46.4

I'm getting the famous enter admin pass on boot (no BIOS update, laptop been off for a year (no OS atm) and I just started trying to fix it.  The error code I get is: [ 54549743 ] I hope that helps get my mobo unlocked!











Solved!
View Solution.

A:HP-2000 Enter Admin Pass/Power on Pass at Boot

@PoetheProgrammr? Enter    41421385 Regards, DP-K

Read other 2 answers
RELEVANCY SCORE 46.4

Ok so i am furious with Micro$oft now! the other day i was FORCED to change my microsoft account after much nagging i did so and i dont like changing logins too much. (this was a week ago)
now for some random reason on earth without my permission my windows login also changed login passwords to the microsoft account. I DONT WANT THAT! that password is too long and complicated for someone who locks his computer every 5 minutes or so. why did this just kick in now? i changed M$ account pass over a week ago and today it decides to change windows login?! can i change JUST my local windows login separate from microsoft login?
if i try to change pass from settings it it goes online and says you cant use password that has been used before.

A:Can i change windows login pass without changing microsoft pass too?

Originally Posted by xdarkmario


Ok so i am furious with Micro$oft now! the other day i was FORCED to change my microsoft account after much nagging i did so and i dont like changing logins too much. (this was a week ago)
now for some random reason on earth without my permission my windows login also changed login passwords to the microsoft account. I DONT WANT THAT! that password is too long and complicated for someone who locks his computer every 5 minutes or so. why did this just kick in now? i changed M$ account pass over a week ago and today it decides to change windows login?! can i change JUST my local windows login separate from microsoft login?
if i try to change pass from settings it it goes online and says you cant use password that has been used before.



Don't go for a password. Use the PIN option That's just what you need and it's really a great thing as well.

Read other 4 answers
RELEVANCY SCORE 46

I have recently installed ATA (1.8.6645.28499). It is now in to the second week of its learning phase and it is raising a considerable number of false pass-the-hash alerts when users initiate Citrix sessions from their usual PC using pass-thru authentication,
eg a typical alert would be:
Bloggs,Fred's hash was stolen from one of the computers previously logged into by Bloggs,Fred and used from xx1234
Clearly this is spurious - in each case the user is initiating a Citrix session from their
own PC and the xx1234 represents a Citrix server in the farm in every case.
1) Why am I only receiving a handful of related PTH alerts each day when I have many thousands of Citrix users, all authenticating in the same manner?
2) How can I supress these alerts?
What I effectively want to say is 'IF the suspected PTH is being triggered BY the user on their OWN PC and the target server is in our Citrix farm' then ignore it. I can't see a way of setting an exclusion range like this for PTH events though?
Thanks

Read other answers
RELEVANCY SCORE 45.2

i have a hp touchsmart 610-1000 i forgot my power on password i need some help to get on my computer

A:i have a touchsmart 610-1000 cant get pass the power on pass...

 Hi, Attach the completed model number, for example 610-1031f How Do I Find My Model Number or Product Number?

Read other 3 answers
RELEVANCY SCORE 43.6

Hello everyone! Can you help me with a (hopefully) simple problem?
I have a Access 2003 SQL Pass-thru query that I need to prompt the user for Begin Date and End date, then put these values in the query. I read the Help, but I still don't understand HOW!
Questions: (BTW, this query is being generated from the Switchboard)
1. How do I prompt the user for the dates in Access? I can't use parameters and I don't understand how to use a prompt otyher than that.
2. How do I get those user responses into the query below
3. How do I write the querydef?

The SQL query is attached

Thanks!
Emil
 

A:Prompt&Pass value to pass-thru query

Read other 16 answers
RELEVANCY SCORE 40.8

I removed Simple pass and validity software, and I am still required to enter the master password that simplepass asked me to set up, I uninstalled all drivers, and software, and removed all remnants from registry, and I am still required to enter the password at login, i have done the netplwiz thing,  and bios says password is clear, so how do i remove this password requirement that i didnt have before i installed simplepass.

Read other answers
RELEVANCY SCORE 34

I recently brought a new pc, I have been wanting one for ages and haven't had the money. However Argos gave me the opportunity to pay the £500 over a year period with a special 0% interest card. I would have prefer to build my own but I'm terrible at saving so the card really helped me. I looked at the specs and thought for the money I'm paying surely I'm gonna get decent fps.

The specs are
CPU and Memory:
AMD A10 quad core.
A10-7850k.
Processor speed 3.7GHz.
DVD optical drives:
Dual layer.
Graphics:
Shared graphics.
AMD Radeon HD .
The only games I play are league of legends and occasionally CSGO. On high setting I was getting around 42 fps on league and in team fights dropping to 25. As well as that when changing the graphic setting ( eg medium low very low) the fps doesn't change it stays between the 40-50 mark. I wasn't expecting when buying the pc to have 200+ fps but I thought it would be better than that. I use to play on a ****** i3 laptop that had similar fps to that so you can see my disappoint when I will be spending £500 for this. I just wanna know if there is any point in me keeping this or is there something that is wrong. I just want a bit of help cause I don't quite understand why its performing so poorly?
 

Read other answers
RELEVANCY SCORE 34

I had a WinAntiSpyware virus on my computer and I thought I had fixed it by coming on here. It laid dormant for a few days and now it's back once again. Haven't clicked on anything it justed started popping up random crap again tonight. What should I give you guys or do first to get started on getting rid of this thing forever.
 

A:Thought it was gone, but....

Read other 16 answers
RELEVANCY SCORE 34

Hello,

First off, here are my specs of my computer:

AMD Athlon x4 465
Radeon 6850 HD 1 Gig
4 gigs Ram
Seagate 1 TB HDD
Windows 7

About 2 months ago, I was having problems with my computer. At the time, I had an old 350 gig HDD installed.. What started to happen was the harddrive would start clicking and as soon as it did, it would make doing simple things such as browsing the net, to playing games, a chore. Id go to browse the net and the harddrive would start clicking and even making a noise that sounded like a dying spaceship, and the window would freeze. It would also do the same thing when i'd play games. Play a game, the game would freeze, and then the harddrive would start making noises. I first thought that my graphics card was messing up but I checked temps, stability, ran benchmark stability tests and it didn't pick up anything..The harddrive was about 7 years old and has given me problems in the past so I guessed that it was my harddrive.

I bought a 1 TB (Which is in there currently) and installed Windows 7 fresh and with that it seemed to have fixed the problem. Everything worked fine, no sounds from the harddrive or anything. Everything was fast, no problems... On to browsing and playing games again.

WELL just last night, (2 months after the first problem with the old HDD) my screen froze while I was playing a game, and sure enough I heard the NEW harddrive clicking.. I was a bit taken back, however computers DO crash from time to time, so I restart... Read more

A:Thought it was HDD but now not sure..

Read other 7 answers
RELEVANCY SCORE 34

What's the difference between copying t(o a CD, for example) and buring to a CD?
 

A:Have never really thought about this...

Nothing. Burning is the act of placing something on a CD. Loosely - lasers/hot/ouch!
 

Read other 3 answers
RELEVANCY SCORE 34

I have the 2nd Thought Trojan and none of the spyware removers I have tried seem to clear it. Here is my hijackthis log - any help would be appreciated

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:29:15 PM, on 12/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
R1 - HKLM\Software\Mic... Read more

Read other answers
RELEVANCY SCORE 34

I have a friends computer that she had been having problems with. So, I thought (what was I thinking) that I could fix the problem. NOT!

There is a WebSiteViewer on her computer thats disconnecting her connection. Its a pain. I thought I could get rid of it but no luck! Can someone H-E-L-P!
 

A:I thought I could help, now I need help!

Read other 16 answers
RELEVANCY SCORE 34

and they PULL me back in! (ok, all apologies to the Godfather..) but if I see this Bargain Buddy dog in my taskbar tray for ONE MORE DAY, i am going to scream

here is my HT log - can anyone help me get rid of this Forever??

Logfile of HijackThis v1.98.2
Scan saved at 10:56:51 AM, on 12/5/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Snapfish\SNAPFI~1\data\xtras\mssysmgr.exe
C:\Sierra\Planner\PLNRnote.... Read more

A:Thought i was out...

Read other 9 answers
RELEVANCY SCORE 34

Never really failed at sorting out issues like this before, normally a bit of googling and common sense sorts them out. But this time I am stuck, so I turn to the mighty power of these forums......
I have what looks like the NTOS.exe problems, but none of the fixes I have read on here seem to have worked.
The major issue I have is that I only have VNC access to the machine, which is making it that much harder to cure, as I cannot boot into safe mode.

So far, I have tried the solution in this thread: http://forums.techguy.org/malware-removal-hijackthis-logs/517747-ntos-exe-run-file-popping.html

But to no avail.

Here is the latest Hijack this log, after everything I have done so far.

PHP:

Logfile of HijackThis v1.99.1
Scan saved at 19
:31:55on 25/07/2008
Platform
Windows XP SP2 (WinNT 5.01.2600)
Read more

Read other answers
RELEVANCY SCORE 34

Hello again guys,

I AGAIN have received some rough crap on my system. Nothing wants to respond, but the funny thing is, there is not a lot of CPU or memory being used up. Here is my HJT, and thanks in advance for helping out.

The only way to even access the internet is to boot up with Linux.

PS - I know, I know, I need to format......TG23
----------------------------------------------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:18:11 PM, on 6/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5335.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: Adob... Read more

A:Thought I had It.....DOH!

I have scanned with Kapersky (installed), scanned with Trend micro ONLINE scanner, scanned using Ad-aware, and AOL's scanner.
 

Read other 3 answers
RELEVANCY SCORE 34

i been trying to play eq2 and been getting the window saying failed to create d3d. did some research and found out I need to go to this file C:\Program Files\Sony Online Entertainment\Installed Games\EverQuest II\eq2_default.ini and C:\Program Files\Sony Online Entertainment\Installed Games\EverQuest II\eq2_recent.ini and make sure this is in both files:
cl_screenwidth 1024
cl_screenheight 768
well this worked for a while but now my changes wont save how do i make that happen? when i copy paste or type in changes press X to exit click yes to save changes reopen files and changes werent saved when i try to start game i get error message again thanx much ahead of time for help recieved
 

A:thought i had it

failed to create d3dClick to expand...

That looks more like a video driver or DirectX problem.
I would start by downloading/installing current video card drivers.
You haven't posted any system information, so we really can't go much further.

A DxDiag.txt would be helpful:
http://library.techguy.org/wiki/DXDiag
 

Read other 2 answers
RELEVANCY SCORE 34

Every time I try to use Windows Media Player or run any media file, I get a pop-up box about a Second Thought Installation, and it will never let me access the file. I am running Windows ME. HJT log:

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\AIM\AIM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?c=3c00&s=consumer&LC=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?c=3c00&s=consumer&LC=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http:... Read more

A:Second Thought

Read other 7 answers
RELEVANCY SCORE 34

I was just wondering what is your guys thought's on IE 8 compared to google chrome or Firefox? I used Firefox but after they came out with IE 8 it seemed to be just as fast (for the version of firefox I had) so I switch back. I did like Chrome but it seemed a little to Simplistic for me.

A:Thought's on IE 8

I like the IE8 which I use practically all the time. For a few things I also use Opera - I like their quick links starting page. I have tried Chrome and FF but they did not convince me. Both are pretty invasive and I guess FF is good if one uses a lot of the add-ons or plug-ins. But I like my stuff in the vanilla flavor and hate to keep track of all these extras.
As far as speed is concerned, I never noticed anything negative with the IE8 - in fact it is faster than Opera - at least on my systems.

Read other 9 answers
RELEVANCY SCORE 34

I've noticed a lot of monitor problems on the forum. Has anyone ever thought that all these monitor problems may be that someone from the 'other side' is trying to communicate with us? Has anyone noticed any 'weird' patterns to these outages?

If so, then try communicating with them. For example: type the words, "Is there anyone there?" and then see what happens.

If not, then it's obviously a very physical hardware problem. Get a new one.
 

A:Anyone thought of this....

Read other 15 answers
RELEVANCY SCORE 34

Whenever I open Windows Media Player, I get a download called "Second Thought". It automaticlly downloads icons to my desktop and locks up the computer. I have run Norton, SpyBot and Adware and still get this problem. Has anyone had similar problems with this? Thanks for any advice.
 

A:Second Thought

get HiJack This http://www.majorgeeks.com/download3155.html, put
it in a permanent folder (C:\HJT) , run it , DO NOT fix anything, post the
log here.

Make sure AdAware is the SE version
 

Read other 1 answers
RELEVANCY SCORE 34

I starte using Firefox, along with Fasterfox a few months back, and I am very happy, have never had problem, other than it took a while (not long, a couple of weeks maybe) before Fasterfox was upgraded to work with Firefox 2.0. Anyway, there is no way in hell I will ever go back to IE

FIREFOX PWNS IE7!!

Read other answers
RELEVANCY SCORE 34

Hi!

My machine has been running great. I've been very careful about internet searches and haven't downloaded anything that wasn't scanned first and from a reputable source.

All of a sudden my computer is running very slow, especially when I access the internet. I keep getting notices that whatever I'm using is "not responding." It's taken 20 minutes to get this thread written.

Six days ago, I couldn't get the machine to boot. I upgraded to Windows 10 early on, and it's been running fine. That morning, the blue Windows 10 screen said, Unable to load Windows, or something similar, and I had it try to repair itself. No luck. After 3 days, of trying, I finally got an option to try System Restore. It took a day for it to load, and then that night, had booted itself. The slow, not responding, issues have been since then. My machine is definitely whacked out.

Tech Support Guy System Info Utility version 1.0.0.4
OS Version: Microsoft Windows 10 Pro, 64 bit
Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz, Intel64 Family 6 Model 60 Stepping 3
Processor Count: 4
RAM: 8143 Mb
Graphics Card: NVIDIA GeForce GT 720, 1024 Mb
Hard Drives: C: 919 GB (595 GB Free);
Motherboard: Dell Inc., 0KWVT8
Antivirus: Windows Defender, Enabled and Updated

THANK YOU!!!
 

A:I never thought I'd be here again.....

Read other 16 answers
RELEVANCY SCORE 34

hi, i just got ad-wear and it seems to be helping... but i have second thought that keeps popping up and won't leave. i dont know what it does i dont know what it puts on my computer.. and i dont know how to get rid of it so.... if someone can help me please i would really apperiate it. thanks so much - samantha
 

A:Second Thought

Read other 9 answers
RELEVANCY SCORE 34

Subject: Fw: VERY IMPORTANT
> >
> >
> > During the next several weeks be VERY cautious about opening or
> > launching any e-mails that refer to the World Trade Center or 9/11 in
> > any way, regardless of who sent it.
> > PLEASE FORWARD TO ALL YOUR FRIENDS AND FAMILY.
> > For those that don't know, 'WTC' stands for the World Trade Center.
>This
> > is very dangerous because people will open it right away, thinking
>it's
> > a story relating to 9-11.
> > Do not open "WTC Survivor"...It is a virus that will erase your whole
> > "C" drive. It will come to you in the form of an E-mail from a
> > familiar person. I repeat, a friend sent it to me, but called and
> > warned me before I opened it.
> > He was not so lucky and now he can't even start his computer! Forward
> > this to everyone in your address book. I would rather receive this
> > 25 times than not at all. If you receive an email called "WTC
> > Survivor" do not open it. Delete it right away! This virus removes
> > all dynamic link libraries (.dll files) from your computer.
> > PLEASE FORWARD THIS MESSAGE
 

A:Thought you should all know this

Read other 10 answers
RELEVANCY SCORE 34

log was clean yet still getting full page pop ups dont get it here is a new log
Logfile of HijackThis v1.99.1
Scan saved at 9:47:18 PM, on 7/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\windows\system\hpsysdrv.exe
C:\Windows\system32\HpSrvUI.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\anjqao.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\MMDiag.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [hp Silent Service] C... Read more

A:thought we had it

another real fast question is there anywhere that I can get a test to see how much RAM I have I added a new stick yet havent seen results wondering if it is working. Thanks again for the help
 

Read other 3 answers
RELEVANCY SCORE 34

I had a popup that said I had sec.thought.G in C:/sys_ai_client_loader.exe

I ran ad-aware, spybot, Avg and Norton's. THey all said all clear. I then ran CWshredder and hijack this. Here is the log. Am I ok??

Thanks,
Vicky

Logfile of HijackThis v1.97.7
Scan saved at 12:42:57 PM, on 5/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\ps2.exe
C:\PROGRA~1\QUICKENW\QAGENT.EXE
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\Program Files\STOPzilla!\Stopzilla.exe
C:\Program Files\Common Files\Dpi\dpi.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\Sy... Read more

A:Help with sec.thought.G

Well, your log looks clean, and the file doesn't look like a valid windows file you are safe to delete it.

One thing I will mention though is WeatherBug is a form of spyware (allows software to be installed with its own installation.)
 

Read other 1 answers
RELEVANCY SCORE 34

I got this Second Thought software automatically installed on my comp. How can I get rid of it? I cant seem to be able to...
 

A:Second Thought

Please do this. Go here http://www.tomcoyote.org/hjt/ and download Hijack This. Un Zip it and click on the Hijackthis.exe.

Click the "Scan" button when the scan is finished the scan button will become "Save Log" click that and save the log.

Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.

Do NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required. Someone here will be glad to advise you on what to fix.
 

Read other 1 answers
RELEVANCY SCORE 34

I'm sure I'm being too cautious, but anyhow:

An icon suddenly appeared on my desktop entitled Second Thought. I have no idea where it came from and the name is not familiar to me. When I double clicked on it to see what it is, I got an error message (with the X) headed “C:\Program Files\STC\STCV/exe” and also an error message (with a !) headed “ERROR STARTING PROGRAM” and stating: “The “C:\Program Files\STC\STCV/exe” file appears to be corrupt. Reinstall the file,and then try again.”

Properties for the Second Thought state it was created and modified on Friday, August 22, 2003, 6:30PM

It was this past Friday that I downloaded and installed Clipmate, but that happened close to 8:00 PM.

When I search in Find for Second Thought, all it shows is a shortcut item in Desktop.

I am wondering if this is some kind of way of getting a virus into my system. And if so what I should now do. I have the Avg antivirus program. When I ran it, it detected no viruses.

Thanks for any comments. grandpaw7
 

A:Second Thought

Read other 16 answers
RELEVANCY SCORE 34

OK I'm using a crap emachines model T2692 from a few years back, roughly 5, and before you even let the words, "Buy a new computer" exit your lips, understand I have no money to and need to make this computer work. All there is to it. Now for my problem.
For a while I was having a problem with restarting. I knew I had some corrupted files and around the time this started I can accurately say I was an idiot. Well I just dealt with it seeing as it wa somewhat rarely happening. Well then it got to restarting more frequently. this became a problem when it was restarting during defrag and the doing other diagnostic tasks. I tried booting into safe mode and it worked for the most part, occasionally restarting. Well then I noticed that XP has the lovely option of turing off the automatic restart upon system failure. I did this and now it usually blue screens but still occasionally restarts. I still at that time didn't understand what the blue screen was telling me. Well for the past little bit (note that this has been goign on for quite a while) I've been goign to Empire College for my AA in IT with a Microsoft concentration. Understand that that doesn't mean much yet seeing as I've only been in for about 2/15 months (it's an accelerated school) but I'm now coming to some conclusions as to possible problems.
First I tried reinstalling XP clean because my computer wasn't even loading up at all without restarting and it would just restart indeffinately. I did t... Read more

A:Well... I need help... (Who'd have thought?)

Hi Serenity-Angel and welcome to TSF !

Here are your system specs.

I would look at the cpu temp, fan speeds, psu voltages (+3.3, +5 and +12V) and memory.

You should find the first ones in the BIOS in the hardware monitor or pc health screen. Report what you see there. If your voltages don't show in the BIOS then use sensorsview pro (latest version here) to monitor them within Windows.

Open your case and tell us about your power supply brand, model and wattage (on a sticker on the side of the PSU block). Clean any dust you could see on your fans and heatsinks using a can of compressed air.

Run memtest86+ on your memory to check that the RAM sticks are not faulty. Unzip and burn the bootable image file using a burning software that can handle .iso files. Enter the BIOS at startup and set boot priority to CD-rom first. Leave memtest run overnight or at least do 3 full passes on your memory. It's advised that you test one memory stick at a time, removing the others from their slot. Report if it finds any error. Double-check memtest's results with windiag as it runs different tests.

Read other 3 answers
RELEVANCY SCORE 34

The online items I bugged you guys about so much over the past few weeks work great. I got 1 GB of RAM and a 320 GB hard drive.
There's a problem with the hard drive though. It's not a physical problem (if it was, this question would already be void...), but one of interface.
Before buying the stuff, I used everest for system statistics. From that, I thought I had a perfect match. An IDE Ultra ATA drive to match the IDE Ultra ATA drive I had.
Well, it turns out that I actually had a Serial ATA drive. I was stupid to only look into the machine once for RAM while inquiring about the stuff. I should have unscrewed my primary drive and looked in there. I didn't, and I believed Everest when it told me I had IDE Ultra ATA.
At first, I didn't see any problems with the drive, other than the slow speed it showed when I was transferring stuff to it. It was a backup drive, after all. But now, I realize that it's possible to get a refund on the drive and use the warranty. I'm within 30 days. I want something faster. I want matching interfaces.
The drive is not damaged at all. It actually has some screws in it I put in, although it came with none (OEM). I can just wipe it clean with a program and send for a refund, but the costs of shipping the thing and getting an adequate replacement will definitely be more than I paid at first.
Before I try, tell me if there's a reason I can't go through with it, or a way for me to make the drive faster.
 

A:Thought it was over, but...

You won't notice much of a difference with the SATA drive. The harddrive can't even saturate a PATA bus, never mind a SATA bus. If you don't change the spindle speed and don't dwell on it you'll never know the difference.
 

Read other 3 answers
RELEVANCY SCORE 33.6

Ok i checked Spy S&D and HiJackTHIS to see if it would nail it. No dice. And I searched the registry to find this 2nd thought thing. No dice. HELP ME!
 

A:2nd thought program WON'T GO AWAY!

Read other 9 answers
RELEVANCY SCORE 33.6

It has been a hard battle on my part, but I need some help from some experts. Just when I thought I had it fixed they pop up again.

Cohibas- Dunhills (Dominicans of course) for the person that helps solve my issues (with my computer of course).

My Hijack This Log file;

Logfile of HijackThis v1.97.7
Scan saved at 10:58:52 PM, on 12/16/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\antispyware\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explo... Read more

A:Pop ups, thought I had them cleaned...but

Read other 8 answers
RELEVANCY SCORE 33.6

Alright, I thought I could figure this mess out by myself, but here I am. I first noticed a problem with excessive pop-up's and programs installing themselves on my computer. I downloaded Ad-aware and SpyBot, downloaded the updates, ran them seperately and deleted everything it found.

I was told this would rid me of my problem...however, it's gotten worse. Here are a few of the problems I am having with my system.

- My browser automatically reloads a page when I open it up
- All of my passwords are wiped clean, regardless of requesting to stay permanently logged in (i.e. hotmail, some message boards, etc)
- At sites asking for passwords, and sometimes other sites, I keep getting a CA Root Certificate popping up. (If I choose "no," my page will not load...if I choose "yes," I get double pop-ups and my password isn't stored)
- I believe it has affected me ability to view anything using Java, my college website uses it and the page won't load using Internet Explorer, it only opens within AOL

The first thing I noticed when these problems started was that a program Second Thought installed itself in my computer. Why would anyone possibly want Adware or Spyware on their computer? Are you kidding me? I tried uninstalling it and it said it had completed the uninstallation; however, the program remained there until I cleaned up using Spybot.

I don't know a thing about viruses, spyware, or adware. All I know is that I can't afford ... Read more

A:It all started with Second Thought...

Read other 11 answers
RELEVANCY SCORE 33.6

I had some trojans and malware on my PC. I got some antiviruses and anti-spyware programs and removed them. But, I messed something in the registry I guess or it is the reminants of the malwares, Iexplorer haults when I open or close it (I open my computer instead). That is my HT log:

Logfile of HijackThis v1.99.1
Scan saved at 12:38:44 ?, on 21/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\WINDOWS\system32\ZoomingHook.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS... Read more

Read other answers
RELEVANCY SCORE 33.6

Sorry to bug you guys again. I got the same 4 things back again that spybot can't remove. i'm including the log from there. appreciate any help. I hope I was supposed to start a new thread.
 

A:Thought it was solved!!!

guess the log would help eh lol sorry bout that
FunWebProducts: Settings (Registry key, fixing failed)
HKEY_USERS\.DEFAULT\Software\Fun Web Products

FunWebProducts: Settings (Registry key, fixing failed)
HKEY_USERS\S-1-5-19\Software\Fun Web Products

FunWebProducts: Settings (Registry key, fixing failed)
HKEY_USERS\S-1-5-20\Software\Fun Web Products

FunWebProducts: Settings (Registry key, fixing failed)
HKEY_USERS\S-1-5-18\Software\Fun Web Products

DSO Exploit: Data source object exploit (Registry change, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, fixed)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, fixed)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, fixed)
HKEY_USERS\S-1-5-21-790525478-515967899-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3
--- Spybot - Search & Destroy version: 1.3 .1TX (build: 20040801) ---

2004-05-12 blindman.exe (1.0.0.0)
2004-05-12 TeaTimer.exe (1.3.0.12)
2004-05-12 Update.exe (1.3.0.0)
2004-08-30 ... Read more

Read other 3 answers
RELEVANCY SCORE 33.6

I have been getting bsod and full screen game freezes and after many support calls, it was narrowed down to memory, partly pilot error as I did not have the Bios configured right. We (gskill tech) and I configured the bios and re-ran memtest86. This yielded fewer errors, and the memory was RMA'd. Now that the new sticks are installed, the memtest goes 100% coverage with no errors, (yippie). The test manual says that the test should run for days with no errors if there is no hardware (or other) issues, so I tried it overnight.

IN the morning, the machine would not wake up. I had to hard reset it, and I turned off the 'sleep function" in power mgnt, and tried again for 3 hours, and again, the machine would not wake up, but I did find crash info, bucket ID : bad stack. I am including the files you requested, but I had to split the big one... next post will have the last file

thanks for your time,
Dave

A:I Thought I had it licked

here is the health report

let me know if there is anything else you need

thanks again,
Dave

Read other 1 answers
RELEVANCY SCORE 33.6

Here is my latest hijack this log. please help. have run adaware and avg free.
Logfile of HijackThis v1.98.2
Scan saved at 7:20:25 PM, on 12/1/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\PV92Tray.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ares Lite Edition\AresLite.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Common Files\Aol\aoltpspd.exe
C:\Documents and Settings\scott and hannah\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://infinity01.netfirms.com/... Read more

A:second thought virus need help

Your log is clean. Where is the virus being found?
 

Read other 1 answers
RELEVANCY SCORE 33.6

I am so excited I found this page!

I am running Windows 98SE and have these icons on my desktop everytime I start up. Since they've popped up, I've been having problems with Internet Explorer (I can only open the browser from Explorer and no longer from any of my icons on the desktop or Start Menu) and Adobe Acrobat Reader (it freezes/stops responding while "Initializing weblink.api). I dont know if any of this is related, but through your site, I found out about HiJackThis, how to run it, and here's my log:

I've copied and printed other responses but I am not comfortable with just following the rules from someone else's log. Please help!

Thanks, in advance.
Logfile of HijackThis v1.97.7
Scan saved at 4:12:45 PM, on 4/20/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP2 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\IOMEGA\DRIVEICONS\IMGICON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\WT\UPDATER\WCMDMGR.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\STCLOADER.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\WI... Read more

A:myPCsearch and second thought, too

Read other 11 answers
RELEVANCY SCORE 33.6

Hi,

I'm having problems getting rid of Second Thought and myPCsearch. I've tried using Spybot and Ad-aware to delete these programs without success. (Basically, upon reboot Second Thought and myPCsearch appear back on my desktop. ) I found out about HijackThis so I ran the program and created a log:

Logfile of HijackThis v1.97.7
Scan saved at 5:49:06 PM, on 6/17/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\Cpqdiag\Cpqdfwag.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\atiptaxx.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\WINNT\System32\ltmsg.exe
C:\WINNT\System32\PRPCUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ClearSearch\Loader.exe... Read more

A:Help getting rid of Second Thought/myPCsearch!!

First, please make a new folder to put your HijackThis.exe into. Anywhere on your hard drive is fine other than your Desktop or the Temp folder. We suggest you use C:\Program Files\HijackThis but feel free to use any name or folder you like. Unzip HijackThis again and save the contents (Hijackthis.exe) to the new folder you made. Then navigate to it and run HijackThis from there. This is to ensure it makes the necessary backups for recovery if needed.

Run Hijack This again and put a check by these. Close all windows except Hijack This and click Fix checked"

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll

O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\Program Files\ClearSearch\CSIE.DLL

O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)

O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINNT\bxxs5.dll

O2 - BHO: NavErrRedir Class - {01CD4DDA-166D-4831-A373-ACCC27E1BB9D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL

O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)

O2 - BHO: PowerSearch - {4E7BD74F-2B8D-469E-D4FF-ED78A787AD2D} - C:\PROGRA~1\POWERS~1\Toolbar\pwrstraf.dll

O2 - BHO: (no name) - {7509BA33-C640-4CAA-83C8-FBC89F2C97C6} - C:\WINNT\System32\itpxmontr.dll

O3 - Toolbar: (no name) ... Read more

Read other 1 answers
RELEVANCY SCORE 33.6

I can't get rid of this stuff. I've run ad-aware and spybot, I've tried uninstalling second thought but it doesn't work. I ran hijackthis and the log file is attached. I don't know what to do next. I have 3 computers on my network w/ this problem. Please help if you can. thank you.

Logfile of HijackThis v1.97.7
Scan saved at 10:52:07 AM, on 6/18/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\Windows\Cpqdiag\Cpqdfwag.exe
C:\PROGRA~1\Compaq\COMPAQ~2\CPQWEB~1\WebDmi.exe
C:\Program Files\Compaq\LCRMS\LCRMS.EXE
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Windows\System32\nvsvc32.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\Windows\System32\wm.exe
C:\PROGRA~1\Compaq\COMPAQ~2\cpqdmi.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\Promon.exe
C:\Program Files\Compaq\Compaq EAB Software\cpqek.exe
C:\PROGRA~1\Compa... Read more

A:myPCsearch / second thought

I had this too. Second thought is a virus called adware.secondthought. If you are getting pop ups like it i know how you feel. here is a solution go to http://securityresponse.symantec.com/avcenter/venc/data/adware.secondthought.html
then try running ad-aware because thats what i did. you might have to reinstal windows media player because i had to. It brought up a download second thought thing and put it back in the registry. You will also have things in your program files that you need to remove. I hope this helps.
 

Read other 1 answers
RELEVANCY SCORE 33.6

please help. i cant get rid of the second thought trojan, or the people on page trojan, ive run spysweeper about 20 times, and this is driving me insane.im computer retarded so please dont laugh at me, i just really need some help
 

A:2nd thought trojan PLEASE help.

Read other 16 answers
RELEVANCY SCORE 33.6

hi....jus got on this as im now so lost! we ended up with second thought on our comp n have managed to delete most of the associated files except 2 called 'wstcodec' and 'stclient.dll' both located in the drivers part of system 32. Iv tryed to delete them but they jus keep appearing again. Iv downloaded loads of stuff like AVG, spybot, trojan remover 2 name but a few but theyre still there.....can any1 help me plz.

thnx bex xxxxxx
 

A:[Solved] Second thought

Read other 8 answers
RELEVANCY SCORE 33.6

Hi,

I have a PC w/ Windows 2000 and I am connected through comcast. Today I noticed second thought and myPCsearch on my desktop and when I search something on the web it directs me to Lycos search engine. I also keep getting all these pop ups about my "computer may be infected" along with a bunch of other pop ups asking if I want to download stuff. I just had my hard disk replaced a couple of months ago and now I get this, this stinks. I thank you in advance for all your help.
Godbless
 

A:Second thought, myPCsearch, etc...

Hi, We will really need to see a HijackThis logfile which shows all the bad, and some of the good, things running...

Get HJT here, read the Copy/Paste directions, and follow them. You do need to create a new folder, name it something creative like HJT on your C: drive, or in MY Documents folder, some permanent folder....so that it stores backups that once in ahwile can be needed.
Direct download, it just pops up the file download box, save it TO the folder you created::::

http://www.spywareinfo.com/~merijn/downloads.html

There is an .exe form, which will not need unzipping, or a .zip type if you know how to work with them...
In any case, READ the Copy/Paste directions, which are here:

http://s89223352.onlinehome.us/mirror/hjt/

Open a blank Reply here at your thread, after you have run HJT, and saved the logfile into Notepad, have the Notepad logfile open, and Copy/Paste the entire contents into your blank reply for review.
 

Read other 1 answers