Negligible MRU Varients

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by boneyeye, Dec 18, 2004.

  1. boneyeye

    boneyeye Corporal

    Hi,
    For the past 2mths. Adware has found 2 MRUs , which I have deleted but recur again.
    1)HKEY_USERS: DEFAULT\soft 2Hits
    \windows\current version\explorer\runmru
    2)HKEY_LOCAL_MACHINE:soft 1Hit
    \microsoft\direct draw\most recent application
    This is after completing weekly maintainance of:Emptying Temp.Int.files. Tune Up, Scan Disk, Disk/Swapfile/Defrag.Windows Update, Virus Check, SFC, Spybot .
    I also did all that thread 35407 advised for Win98SE. The Trend Micro Online Scan did not work for me at all. I also did everything in thread 38752. Learned a lot but alas no cure. All programs are updated weekly by me . The above situation occurs after about 1hr browsing and then the curser goes "beserk" and menus flashing "on" and "off" Browser goes off completly but Iam still connected to net. I hope someone can help please.Specs: Win98SE,
    IE6.0,Ram192MB, AVG Virus Scan, Zone Alarm "on".
    Thanks Boneyeye
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. boneyeye

    boneyeye Corporal



    Edit by chaslang: Inline log changed to attachment
     

    Attached Files:

    • hjt.txt
      File size:
      3.3 KB
      Views:
      0
    Last edited by a moderator: Dec 19, 2004
  4. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    My sincere apologies for sendind log as above, but it was the only way it would work as it was my 8th attempt for some unknown reason text and log together in one post was crashing my browser and sending curser "beserk" as 1st post. Also CPU: AMD K6 3DNow. Thanks again.
    Boneyeye.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what you mean "for some unknown reason text and log together in one post was crashing my browser and sending curser" . Do you mean when you attached the log file your cursor immediately goes "beserk"?

    There is nothing wrong in your log other than a minor item which could be fixed:
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)

    It only related to the Acrobat Reader pluging for IE. I doubt it is the cause of your problems.

    Are you sure you don't have a hardware problem with your mouse? Do you have another you could try? Do the problems happen in safe mode too.

    I want to be sure I have the proper registry keys you had broken up the lines earlier.

    HKEY_USERS: DEFAULT\soft 2Hits\windows\current version\explorer\runmru
    HKEY_LOCAL_MACHINE:soft 1Hit\microsoft\direct draw\most recent application

    They don't look correct to me. You always need to convey exact information. Does it really say soft 2Hits and soft 1Hit? I think that was what you wrote and you wound up corrupting the actual registry key path. I think you meant:
    \HKEY_USER\.DEFAULT\Software\Microsoft\Windows\Current Version\Explorer\Runmru
    \HKEY_LOCAL_MACHINE\Software\Microsoft\Direct Draw\MostRecentApplication

    What were the hits in those paths?

    You do realize the MRU's are just a history of what was most recently used and they are not really a problem?
     
  6. boneyeye

    boneyeye Corporal

    HI Chaslang,
    TY for last post and in answer to 1st.question re: text in post 4 and log in post 3,which would not fit on the one post. That was why I had to seperate the two, but I realise now that it was possibly because of the way I could only save the log. And, good news. I tried another working mouse and everything works normally. So, thank you so much. as usual you were right. We need not bother re registry keys now as you explained the obvious: MRUs are just history(a fact I did not know). Now I would like to wish you and yours and all the good folks at MG a very merry XMas and a jolly and peaceful New Year. Again TY for all your help in 2004 and hoping I will not have to bother you until sometime in 2005. Bye for now.


    Boneyeye
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boneyeye,

    You're welcome. I'm happy that we got that worked out.

    Thanks for the Holiday wishes! And I wish the same for you and your family!

    ** Happy Holidays **
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds