URGENT HELP PLEASE! NSIS Media Extension problems ....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Maggie_61, Aug 19, 2006.

  1. Maggie_61

    Maggie_61 Private First Class

    Hi MAJORGEEKS GUYS !!!

    I already read your articles on NSIS Media.

    I got it and tried to find a solution.

    My most serious problem was that I could not open your page to write to you... The site’s pages were blank. Now I am trying to post 2 attachments and I cannot do it. I cannot open the icon to insert them ... Why ??

    With my attachments I wanted to show you that:

    The home page had your logo and was empty with the site's colour. The forum's page had your logo, your site’s colour and blank... it could not be downloaded, it stopped downloading before ending… This happens in IE6 and FIREFOX. In IE the problem is worst... I write to you now in OPERA.

    After the attack, my fonts became very small, I changed them through DISPLAY but some of them I cannot …. (What I can do for this, please?)

    Your advices on NSIS Media Extension did not work for me and for three days I read all the sites for help I found in Google. Finally I downloaded the program TROJANHUNTER. It finds the explorer.exe file, changes its name and kills it! The problem was partially resolved though...

    Everything you read on the help sites for NSIS MEDIA EXTENSION happened with me too. I had the NSIS files with dll's I could not delete, inside COMMON FILES and MOZILLA FIREFOX (PROGRAM FILES). Also, I could not remove the program NSIS MEDIA from ADD/REMOVE. After two days I did it... !!

    At first I had the curious pop-ups too! In Chinese and in Greek …!!! One site says to open the file NSIS in NOTEPAD, delete it all and then save it as TEXT. The popups after this were a small blank line on upper left of my screen…. But existed…

    In one of my many efforts, I clicked on NSIS UNISTALL (as I wrongly read to do in one site, in order to remove the program...). Afterwards I read that somewhere in my system something is left there, and I am afraid ....

    IS MY PC AFFECTED WITH A VIRUS IF I COPY ALL MY FILES AND DATA TO AN EXTERNAL USB HARD DRIVE, WHICH HAS OTHER FILES ?? I DON’T WANT TO INFECT THIS DISK TOO…. !!!

    HOW CAN I REINSTALL IE6 & MOZILLA FIREFOX TO SOLVE MY PROBLEM ?? I found no new patches for these two…


    Also I read in SPYSWEEPER Help that I have to take care of my ebanking, changing password and protect my data. What YOU think ??

    I uninstalled and reinstalled the latest version of FIREFOX but nothing changed, some sites as yours …won’t open… SO THE VIRUS IS IN MY SYSTEM !!!!

    I try very hard to AVOID FORMATTING AND REINSTALL WINDOWS AGAIN !!!!

    PLEASE HEEEEEEEEEEEEEELP MEEEEEEEEE …………. !!!!!!!!!!!!


    Thanks,
    Maggie


    **** P.S. The Trojan Horse was found by WEBROOT SPY SWEEPER and no other program found it before !!!!!!!!!!!!

    Also, now I work in OPERA your sites freezes and I can’t post my message… I have to log out several times… and close and reopen OPERA… I AM IN TROUBLE I THINK …. !!!!
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • CounterSpy - ONLY IF you were not able to run Windows Defender
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • HijackThis
     
  3. Maggie_61

    Maggie_61 Private First Class

    I did most of the things you said. I will do the rest now, thanks.

    My system has restarted and then when it opened I got the message that my pc recovered from A SERIOUS WINDOWS PROBLEM !!!!

    I have an IBM and this is not the first time...

    In OPERA I cannot open the attachment icon to attach my files !! ... I smell problem ....

    Can I copy-paste them in my message when I finish ??

    Maggie
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    IF you can not attach them, then go a head a paste teh logs, and I will convert them to attachments. Paste 3 more than 3 logs to a thread.
     
  5. Maggie_61

    Maggie_61 Private First Class

    Please read carefully my whole first message.

    Somewhere in my system is a virus...!!

    The problem still exists in browsers IE6 and FIREFOX. I cannot open some pages... OPERA freezes too… There are other problems in OFFICE also…..

    If my pc looks so clean with the scans I just did, what is the solution ????


    HEEEEEEEEEEEELP !!!!!!!!

    Thanks,
    Maggie
     

    Attached Files:

    • HJT.log
      File size:
      12.1 KB
      Views:
      1
    Last edited by a moderator: Aug 20, 2006
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I read your first post. I can't locate a virus on a system unless I have a starting point in which to look for it. Which is the purpose of the logs that were rerquested.

    You are running GetRunKeys and ShowNew directly from the ZIP archive, which is precisely what the directions tell you not to do. FOLLOW DIRECTIONS.

    Unzip both GetRunKeys and ShowNew to their OWN directories and run them from that location.

    You renamed hijackthis to analyse.exe.exe. Don't do this, remove the last .exe

    Post the logs from GetRunKeys and ShowNew along with a fresh Hijackthis log after you have properly followed directions.

    I you still can not attach the logs, copy & paste the logs into your reply. I will convert them to attachments.
     
  7. Maggie_61

    Maggie_61 Private First Class

    I read your first post. I can't locate a virus on a system unless I have a starting point in which to look for it. Which is the purpose of the logs that were rerquested.

    You are running GetRunKeys and ShowNew directly from the ZIP archive, which is precisely what the directions tell you not to do. FOLLOW DIRECTIONS.

    Unzip both GetRunKeys and ShowNew to their OWN directories and run them from that location.

    You renamed hijackthis to analyse.exe.exe. Don't do this, remove the last .exe

    Post the logs from GetRunKeys and ShowNew along with a fresh Hijackthis log after you have properly followed directions.

    I you still can not attach the logs, copy & paste the logs into your reply. I will convert them to attachments.


    **********************************************

    No, dear Shadow, I did exactly what you said regarding GetRunKeys and ShowNew. GetRunKeys text is empty! I just did it in the proper way today, as I did yesterday...

    Regarding ShowNew, I copied-pasted the log yesterday and I copy it once more here.

    CAN I DO SOMETHING TODAY, BEFORE I FORMAT MY DISK TOMORROW MORNING ???? :confused: :confused:

    Thanks!
     

    Attached Files:

    Last edited by a moderator: Aug 21, 2006
  8. Maggie_61

    Maggie_61 Private First Class

    Here is my correct HIJACK THIS.

    Sorry... I am not a genious... :)

    ***************************************************

    Logfile of HijackThis v1.99.1
    Scan saved at 8:48:56 μμ, on 21/8/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\msdtc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\FSRremoS.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\Pelmiced.exe
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\WinFax\WFXSWTCH.exe
    C:\WINDOWS\system32\wfxsnt40.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\SPAMfighter\SFAgent.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    C:\Program Files\TrojanHunter 4.5\THGuard.exe
    C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
    C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Program Files\NoAdware4\NoAdware4.exe
    C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
    C:\Program Files\Lenovo\Rescue and Recovery\adm\IUService.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\WinFax\WFXCTL32.EXE
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\system32\WFXSVC.EXE
    C:\Program Files\WinFax\WFXMOD32.EXE
    C:\WINDOWS\system32\mqsvc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\Program Files\HJT\analyse.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Systran40pemls.IEPlugIn - {D3919E62-D6A5-11D6-AC3E-00B0D094B576} - C:\Program Files\Systran\4_0\PersonalWOI\IEPlugIn.dll
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTCH.exe
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [FineReader7NewsReaderPro] "C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe"
    O4 - HKLM\..\Run: [TVT Scheduler Proxy] "C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe"
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
    O4 - HKCU\..\Run: [NoAdware4] "C:\Program Files\NoAdware4\NoAdware4.exe" :Scan:
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Configuration Wizard.lnk = C:\Program Files\WinFax\WTNSETUP.EXE
    O4 - Global Startup: Controller.LNK = C:\Program Files\WinFax\WFXCTL32.EXE
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/controles/AvDetInst.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {231ED520-8AE2-46B8-830A-23BF937C9FA4} (B_Link.BL_RTxaa) - http://www.reporter.gr/RT-xaa/RTxaa_UC.CAB
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/download/scanner/en-us/wlscbase3401.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{2117C2FC-E352-434D-9A9A-72E09E37C026}: NameServer = 195.170.0.1,195.170.2.2
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
    O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\adm\IUService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
     
  9. Maggie_61

    Maggie_61 Private First Class

    Runkeys.txt is empty...

    This is what the CMD.EXE says in DOS when I open the bat file. I copy it here...

    CAN I SAVE MY PC TODAY ? :confused:

    MY PC SHUTS DOWN AND RESTARTS and I get the message: RECOVERED FROM A SERIOUS WINDOWS ERROR...

    I think I have to format it unless YOU SAVE me TODAY ..... :)

    Thanks,
    Maggie

    ****************************************************

    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.

    C:\xrkey00.txt



    C:\xrkey01.txt



    C:\xrkey02.txt



    C:\xrkey03.txt



    C:\xrkey04.txt



    C:\xrkey05.txt



    C:\xrkey06.txt



    C:\xrkey07.txt



    C:\xrkey08.txt



    C:\xrkey10.txt



    C:\xrkey11.txt


    'grep' is not recognized as an internal or external command,
    operable program or batch file.
    'grep' is not recognized as an internal or external command,
    operable program or batch file.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions given in the download link for GetRunKey. You MUST extract ALL files from the ZIP file into the same folder. You did not do this and that is why grep.exe cannot be found. You MUST NOT try to run GetRunKey.bat from inside the ZIP either.

    You are doing the same thing for ShowNew. If you do not extract the files from the ZIP file, the batch files will not run correctly. We can tell by you logs and the error message that you are not extracting the files from the ZIP.
     
  11. Maggie_61

    Maggie_61 Private First Class

    Sorry guys but I am not a computer expert .... :) :)

    I am unemployed for two years and I try hard to save money from the computer technician coming tomorrow ......


    ***************************************

    NEWFILES:
     

    Attached Files:

    Last edited by a moderator: Aug 21, 2006
  12. Maggie_61

    Maggie_61 Private First Class

    GETRUNKEYS:


    Edit by chaslang: Inline runkeys.txt log attached
     

    Attached Files:

    Last edited by a moderator: Aug 21, 2006
  13. Maggie_61

    Maggie_61 Private First Class

    Dear chaslang,

    As I wrote to Shadow your site does not allow me to insert attachments!

    Please notice that Shadow and Halo edited my messages and created attachments from the copy-paste I made...

    Can someone please, please help me NOW ? Urgent .... It is one o'clock after midnight here and I try to avoid pay my pc technician tomorrow... :)

    I try just now to upload them, but along with your colleagues attachments my space is 64.1 KB and your site does not allow me to create them.... please edit them .... :)

    Thanks!

    P.S. I just deleted all my previous attachments to create space, but I cannot go into advanced mode...
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs, you downloaded an installed 1 Click PC Fix 2006 v3.2 on August 18th. Goto Add/Remove programs and uninstall this.

    Are the below programs free trials or paid versions?
    NoAdware v4.0
    PC-Doctor for Windows
    PC Inspector File Recovery
    Rescue and Recovery
    SPAMfighter
    Spy Sweeper"
    TrojanHunter 4.5"
     
  15. Maggie_61

    Maggie_61 Private First Class


    NoAdware v4.0 FREE
    PC-Doctor for Windows MY IBM PC PROGRAM - INCLUDED IN MY MACHINE
    PC Inspector File Recovery FREE DOWNLOAD
    Rescue and Recovery IBM PC PROGRAM - DOWNLOADED FROM IBM SITE
    SPAMfighter FREE
    Spy Sweeper I BOUGHT IT - REGISTERED
    TrojanHunter 4.5 FREE

    MY BROWSERS ARE GOING MAD.... MY PC RESTARTS WITH THE ERROR I WROTE EVERY FEW MINUTES.... I am going crazy here... I deleted the program you said.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I hope you meant you uninstalled the program I named. Uninstalling and deleting do not have the same meaning.

    You should also uninstall all of the below to avoid hogging all of your system resources as possible conflicts betweent the programs. Only Uninstall what I request and nothings else.
    NoAdware v4.0
    PC Inspector File Recovery
    SPAMfighter
    TrojanHunter 4.5
    SpywareGuard
    Windows Defender

    Then delete the below files. Use safe mode to delete them if necessary:
    C:\1clickpcfix2006.exe
    C:\SPYWARE_DOCTOR_sdsetup.exe
    C:\WINDOWS\system32\1155819831.exe
    C:\WINDOWS\system32\streamhlp.dll

    Then reboot and tell us how things are working.
     
  17. Maggie_61

    Maggie_61 Private First Class



    Of course I do it from Add/Remove... sorry for the wrong word :)

    I said incorreclty: I BOUGHT NoAdware. ....expensive.... can I keep it ?

    I will do EXACTLY as you say... My pc shutsdown and restarts all the time....

    "RECOVERED FROM A SERIOUS WINDOWS ERROR" !!!

    Do you think I can save it ?

    Many thanks !
     
  18. Maggie_61

    Maggie_61 Private First Class


    I unistalled and deleted everything as you say, but still the browsers dont work....

    I have to see if the pc will shutdown....

    Can I KEEP NOADWARE since I bought it ?? :confused:
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Even if you did buy NoAdware, you must not keep it installed. Only one realtime blocking application should be used. Spy Sweeper is a better choice. Keep it.
     
  20. Maggie_61

    Maggie_61 Private First Class

    I am going to format and restore my PC now... I could not avoid it .... :(

    I have an IBM. It restores all the files and the PROGRAMS too.... I am waiting for the technician...

    Many thanks to all of you... :) :)

    Maggie
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Good luck. After you get up and running make sure you follow the steps in he below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds