Spyware Warrior Spyware Warrior
Help with Spyware, Hijacking & Other Internet Nuisances
 
FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

Unknown processes in Task Manager.

 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Spyware Warrior Forum Index -> Archived Spyware Removal Help Topics
View previous topic :: View next topic  
Author Message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Tue Dec 21, 2004 1:57 pm    Post subject: Unknown processes in Task Manager. Reply with quote

There are two processes of the same name "prutcct.exe" in my Task Manager under the Processes tab and I can't turn them off. I usually google filenames before uninstalling and stuff, but I couldn't find anything on these, just a few HJT logs, but I wasn't sure if I should get rid of them or not.

I was clearing out my Temp and Temporary Internet Files folders and in my Temp folder, there were files called ~DF1588, ~DF5F63, and ~DF6419 that couldn't be removed because of sharing violations. I don't know what could be using them; I was wondering if it's bad that these temp files are being used and if they could be being used by spy- or adware.

I was running Ad-Aware before and every time, on this computer, at the end of the scan when I'm ready to select and remove files, my mouse (or the cursor at least) goes crazy and it begins selecting things by itself. I think things are being quarantined -- I think I saw the bar with "Quarantining objects..." for a few seconds. I have no idea why this happens. It only does that when I'm done scanning with Ad-Aware. Anyway, after it does that, I'm able to select and remove stuff, but I don't know what objects were being quarantined or whatever when my mouse went crazy. Any idea what's going on?

Well, here's my HJT log:

Logfile of HijackThis v1.99.0
Scan saved at 4:31:05 PM, on 12/21/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\PackethSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\AIM95\aim.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Steam\Steam.exe
C:\WINNT\system32\wuauclt.exe
C:\My Documents\download\ljammiel\winamp\winamp.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\prutcct.exe
C:\WINNT\system32\prutcct.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINNT\system32\taskmgr.exe
C:\HJT\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {B5918F09-3F24-2EC5-E7D9-A6F1F26EAC9F} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINNT\Downloaded Program Files\CONFLICT.2\lexbar.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\My Documents\download\ljammiel\winamp\winampa.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [prutcct] C:\WINNT\system32\prutcct.exe
O4 - Startup: Watch.lnk = C:\WINNT\twain_32\A4S2600X\WATCH.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: NuasisCallerCollabApplet_2,0,1,0,1364,1091038611 - http://jetty-help.afford.com/Collab/CallerApplet.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - http://desktop.sboe.org/Citrix/ICAWEB/en/ica32/wficac.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.kungfuchess.com/activex/web665.cab
O16 - DPF: {72ED8878-6E16-4EA1-BDD6-3B21EF676E45} (CVTrace Control) - http://www.seevideo.co.kr/pub/cvideox/trace/cvtrace.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.14.22/ttinst.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.reference.com/tools/toolbar/lexico.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINNT\system32\npkcsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINNT\System32\PackethSvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

Thanks!
Back to top
View user's profile Send private message AIM Address
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Wed Dec 22, 2004 1:49 pm    Post subject: Reply with quote

Hello torankusu, thank you for waiting. I am currently examining your log and will return with recommendations later.
Back to top
View user's profile Send private message
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Wed Dec 22, 2004 3:13 pm    Post subject: Reply with quote

Hello torankusu, thank you for submitting your Hijackthis log. Please review ALL of the following steps before proceeding. It is advised to print this page since there probably will be times where you will not have internet access.

The prutcct malware is known for tampering with Adaware and Spybot when you run them. Since you mention trouble ending the process with Task Manager, lets get it in Safe Mode.

Reboot your computer into Safe Mode by following these steps:

Windows 2000/XP:
To use the F8 method

1. Start Windows, or if it is running, shut Windows down, and then turn off the computer.
2. Restart the computer. During the boot up sequence, begin tapping the F8 key on your keyboard. Continue to do so until the Windows Advanced Options menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
3. Using the arrow keys on the keyboard, scroll to and select the Safe mode menu item, and then press Enter.

Go to "Control Panel" and then to "Add/Remove Programs". Remove the following programs if you see them:
WebSearch Toolbar
WebSearch Tools
Search Assistant
Win-Tools Easy Installer


Now open Hijackthis and press "Do a System Scan Only". Place a checkmark in the boxes next to the items listed below if they appear. When you have marked the appropriate items for removal, close all open browsers and windows besides Hijackthis. Then hit the "Fix" button, and close Hijackthis when it is done.

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {B5918F09-3F24-2EC5-E7D9-A6F1F26EAC9F} - (no file)

O4 - HKCU\..\Run: [prutcct] C:\WINNT\system32\prutcct.exe

O16 - DPF: NuasisCallerCollabApplet_2,0,1,0,1364,1091038611 - http://jetty-help.afford.com/Collab/CallerApplet.cab

O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - http://desktop.sboe.org/Citrix/ICAWEB/en/ica32/wficac.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe

O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.kungfuchess.com/activex/web665.cab

O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.14.22/ttinst.cab

O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab

Now Enable Show Hidden Files and Folders with these steps:

Windows 2000
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

Search for the following files or folders, and delete them if found (some may have been deleted in previous steps):
C:\WINNT\system32\prutcct.exe <---File
C:\Program Files\Toolbar <---Folder
C:\Program Files\Common Files\WinTools <---Folder

Now exit Safe Mode by rebooting normally.

Post a new HijackThis log and let me know how things are running.
Back to top
View user's profile Send private message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Sun Dec 26, 2004 1:06 am    Post subject: Reply with quote

Hey Blinn, thanks for replying.

I did what you said; went into safe mode and stuff. I went to Control Panel, but the things you listed (WebSearch Toolbar, WebSearch Tools, Search Assistant, Win-Tools Easy Installer) weren't there. I checked everything you said when running HJT. I did not find prutcct.exe in C:\WNNT\system32, but I did find something like prudcct or something. I forget what it was exactly. Oh yeah, when I ran HJT again, instead of finding "O4 - HKCU\..\Run: [prutcct] C:\WINNT\system32\prutcct.exe", the second prutcct was "prudcct" (or however it was spelled). I clicked it.

C:\Program Files\Toolbar <---Folder

and

C:\Program Files\Common Files\WinTools <---Folder

were nowhere to be found.

In my first log, was there something that indicated these are somewhere on my computer?

Thanks.
Back to top
View user's profile Send private message AIM Address
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Sun Dec 26, 2004 1:59 am    Post subject: Reply with quote

hello Torankusu, hope you had a Merry Christmas Smile

Yes, there is a line in the first log that sometimes comes with other stuff which I did not see. I included all those items (the control panel items for instance) just in case, but didn't expect you would find them since there is no indication they are there. Everything is fine with what you did so far Big Thumb Up

Anyway, there is a little more work to be done, so post up a new HJT log Smile
Back to top
View user's profile Send private message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Sun Dec 26, 2004 8:11 pm    Post subject: Reply with quote

Hey, hope you had a good one, too. ;D

And I KNEW I forgot something... a second log. Here it is:

Logfile of HijackThis v1.99.0
Scan saved at 11:07:46 PM, on 12/26/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\PackethSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Steam\Steam.exe
c:\program files\steam\steamapps\phux0r_j00@hotmail.com\counter-strike\hl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\hijackthis.exe

R3 - URLSearchHook: (no name) - {B5918F09-3F24-2EC5-E7D9-A6F1F26EAC9F} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - Startup: Watch.lnk = C:\WINNT\twain_32\A4S2600X\WATCH.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {72ED8878-6E16-4EA1-BDD6-3B21EF676E45} (CVTrace Control) - http://www.seevideo.co.kr/pub/cvideox/trace/cvtrace.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINNT\system32\npkcsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINNT\System32\PackethSvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

I have another question. Every time I run Ad-Aware, it finds 4 Registry Keys, but when I delete the selected items, they're still there when I scan again. They're for BargainBuddy. I can't get rid of 'em. Any ideas?
Back to top
View user's profile Send private message AIM Address
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Sun Dec 26, 2004 10:14 pm    Post subject: Reply with quote

hi again, just a few stragglers and things left.

Go to "Control Panel" and then to "Add/Remove Programs". Remove the following programs if you see them:
AWS\Weatherbug <---Please see here about weatherbug.

Open Hijackthis and press "Do a System Scan Only". Place a checkmark in the boxes next to the items listed below if they appear. When you have marked the appropriate items for removal, close all open browsers and windows besides Hijackthis. Then hit the "Fix" button, and close Hijackthis when it is done.

R3 - URLSearchHook: (no name) - {B5918F09-3F24-2EC5-E7D9-A6F1F26EAC9F} - (no file)

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

Search for the following files or folders, and delete them if found (some may have been deleted in previous steps):
C:\Program Files\AWS <---folder

I see both Norton and AVG anti-viruses are on your computer. Make sure that only one of those programs is actively guarding your computer to avoid potential conflicts.

Regarding BargainBuddy, I see no indication of it in your log so it might be remnants (although that wouldn't explain why they keep coming back). Check Add/remove programs to see if BargainBuddy is listed, and see if there is a BargainBuddy folder in C:\Program Files. Download, update, and scan with Spybot Search & Destroy, a great companion to Adaware. Run another Adaware scan and let me know if those 4 entries are still there.

reboot your computer, and post up a new Hijackthis log, you are nearly there! Very Happy
Back to top
View user's profile Send private message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Sun Jan 23, 2005 7:02 am    Post subject: Reply with quote

Hey, sorry for the superlong delay in replying. Confused This computer hasn't worked for a while... not sure why, heh. Time for my sister to get a job (and get a new computer), haha. Anyway. Here's a new log:

Logfile of HijackThis v1.99.0
Scan saved at 9:33:45 AM, on 1/23/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\PackethSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\hijackthis.exe

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - Startup: Watch.lnk = C:\WINNT\twain_32\A4S2600X\WATCH.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {72ED8878-6E16-4EA1-BDD6-3B21EF676E45} (CVTrace Control) - http://www.seevideo.co.kr/pub/cvideox/trace/cvtrace.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINNT\system32\npkcsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINNT\System32\PackethSvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

I just ran SS&D and it came up with the following:

FreeScratchAndWin
DownloadWare
DyFuCA.InternetOptimizer
DyFuCA
eAcceleration
eXact Advertising.BargainsBuddy
ISearchTech.PowerScan
ISearchTech.SideFind

I fixed everything except the Bargain Buddy thing. It said it was in use so it asked if SS&D could run when I restart the computer. I clicked OK, but when I restarted it, it still couldn't fix it. When I tried exiting out, SS&D began scanning again (not sure why) and I wasn't expecting it to, but again, it couldn't remove Bargain Buddy. It's still there when I run Ad-Aware, too. =/
Back to top
View user's profile Send private message AIM Address
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Mon Jan 24, 2005 12:53 pm    Post subject: Reply with quote

hi Torankusu, welcome back its been a while! I'm out of town at the moment, good thing I got bored and decided to drop by the forums really quick. I am on a friend's computer, so apologies if the advice below isn't as polished looking since I am typing it all by hand. The log looks good, except for one thing. You have 2 virus scanners running real-time on the machine. This can lead to stability problems, please disable the auto-protect function on either AVG or Norton.

For Bargain Buddy, I think I get what is happening, Norton's unerase protection may be keeping you from getting rid of it.

"Right-click" on the Recycle Bin, and choose the "Empty Norton Protected Files" option. Go ahead and give Spybot or Adaware another try after that, and see if you still find Bargain Buddy.

IF it is still there after dumping your Norton Protected files, run Spybot in Safe Mode:

Windows 2000/XP:
To use the F8 method

1. Restart the computer.
2. During the boot up sequence, begin tapping the F8 key on your keyboard until the menu appears.
3. Using the arrow keys on the keyboard, select "Safe mode", and then press Enter.

Once you're into Safe Mode run Spybot and see if that gets rid of it. Reboot normally to exit Safe Mode.

Please post a new Hijackthis log so I can verify one of the AV's is turned off. Also inform me of how you do with Bargain Buddy.
Back to top
View user's profile Send private message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Fri Feb 04, 2005 10:29 pm    Post subject: Reply with quote

Hmm, for some reason, it gets stuck when loading into Safe Mode. When I select Safe Mode from the menu and it shows all those file names or paths (or both? I don't remember now), it doesn't go further than this one file -- I forget what it was called... I think it was something like Mup? I actually had to go out for a family get-together and left it on, so I don't know if it eventually went through because when I got back a few minutes ago, I see someone restarted the computer in Normal mode. All I know is that for the first few minutes that I waited, it didn't do anything. Confused

I could ask someone if it worked or not later (everyone's sleeping).
Back to top
View user's profile Send private message AIM Address
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Sat Feb 05, 2005 12:28 am    Post subject: Reply with quote

Ok, thanks for the update. Your last Hijackthis log was clean, but feel free to send me a new one if you wish. The primary symptom of Bargain Buddy is a brown and white dog icon sitting in your system tray (lower right, where the clock is). Is the dog present?

Let's try it from the beginning as if Bargain Buddy was fully there. I see no trace whatsoever of Bargain Buddy in your log, so don't get discouraged if you don't find the stuff below.

Go to "Control Panel" and then to "Add/Remove Programs". Remove the following programs if you see them on the list:
Bargain Buddy
Bullseye Network
Cashback
Navisearch


Search for the following folders, and delete them if found:
C:\Program Files\Bargain Buddy
C:\Program Files\Bullseye Network
C:\Program Files\Cashback
C:\Program Files\Navisearch

Go ahead and run Spybot and Adaware after updating each of them.

Lets clean out your system of temp files. Go to "Start", "Run". Type in "cleanmgr" (without quotes) and hit "ok". Let it scan your computer for removable files, then checkmark the following boxes: Temporary Files, Temporary Internet Files, and Recycle Bin. Hit "Ok" to clean out those directories.

Next right-click your Recycle Bin and empty your Norton Protected Files.

Reboot.

Let me know if you still find those Bargain Buddy entries afterwards. If so, can you tell me exact file information of whatever Spybot picks up? In the list of files detected, you can expand each entry to show more information.
Back to top
View user's profile Send private message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Sun Feb 27, 2005 1:41 am    Post subject: Reply with quote

I'm sorry about these huge delays between posts. Aside from me not having much time to use the computer, my sister's computer is kinda weird (the logs I've been posting are from her PC). It shuts down for no reason (or none that we know of). We once ran this program (SisoftSandra) that tells you all the system info and stuff and it said it was overheating, but nothing feels hot inside. We actually took the case off and have a fan blowing at it Rolling Eyes , but it still says it's really hot. Hmm, the last time we checked that was a while ago, but I believe that it said that the temperature was 77º C, haha. Anyway, sometimes it won't even start up. I know getting a new computer seems like a good idea, but we're kinda stuck with these [old] computers for a little bit and my sister's against formatting her computer, sooo I've just been trying to get her computer ad- and spyware free and getting rid of stuff we don't need for now.

Her computer isn't starting up right now otherwise I'd post another log, but I just wanted to explain and apologize before this thread gets locked up.
Back to top
View user's profile Send private message AIM Address
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Sun Feb 27, 2005 1:14 pm    Post subject: Reply with quote

Don't worry, I am kind of catching on to expecting the delays, not a problem! Besides, I do not have moderating powers so I can't lock the thread anyway Wink .

At this point I would say spyware shouldn't be your top worry (the log is looking pretty good), it looks like you have major hardware issues. What are the specs of this machine, 77 degrees is really high! You might want to post this problem in the General Discussion or Talk About forums so you can get more input onto cooling this down. This forum is restricted in who can post, but anyone can post in those forums and there are a lot of knowledgable people posting in those forums.
Back to top
View user's profile Send private message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Fri Apr 08, 2005 10:16 pm    Post subject: Reply with quote

My sister finally gave in; we're formatting her stupid computer! Puhahaha. ::kicks it::

Thanks a lot, though, Blinn. Very Happy

I'm sure it won't be too long before I'm back here again, though, pasting more logs from my sister's computer. Haha. ;x
Back to top
View user's profile Send private message AIM Address
Blinn
Warrior Guru


Joined: 10 Nov 2004
Last Visit: 15 Apr 2009
Posts: 424
Location: San Francisco, CA

PostPosted: Sat Apr 09, 2005 11:25 am    Post subject: Reply with quote

Well sorry I couldn't be of more use. Hopefully a format will do the trick. Good luck!
Back to top
View user's profile Send private message
torankusu
Warrior


Joined: 18 Jul 2004
Last Visit: 31 Jul 2010
Posts: 67
Location: Secaucus, NJ, USA

PostPosted: Sun Apr 10, 2005 9:20 am    Post subject: Reply with quote

Aww, you were a lot of help. Smile

Thanks. =D
Back to top
View user's profile Send private message AIM Address
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Spyware Warrior Forum Index -> Archived Spyware Removal Help Topics All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group