1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

problems with startup

Discussion in 'Virus & Other Malware Removal' started by cubbycuddly, Jan 27, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. cubbycuddly

    cubbycuddly Thread Starter

    Joined:
    Dec 1, 2001
    Messages:
    230
    Hi,

    I've got a big problem with starting up and my startuplist. On booting up scandisk will stop responding and its followed by a blank dark blue screen. I have had to insert my startupdisk and type in scanreg /restore to make windows load, three times since yesterday.

    Could someone look at my startuplist, below, and tell me what I need to keep and what needs to be disabled to hopefully get my PC working properly again?

    Thanks.

    cubbycuddly



    All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    *StateMgr c:\windows\system\restore\statemgr.exe All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    dla c:\windows\system\dla\tfswctrl.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    FileFreedom c:\program files\filefreedom\filefreedom.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    InCD c:\program files\ahead\incd\incd.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    IncrediMail c:\progra~1\incred~1\bin\incredimail.exe /c All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    InstantAccess c:\progra~1\textbr~1.0\bin\instan~1.exe /h All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    KAZAA c:\program files\grokster\grokster.exe /systray All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    LexmarkPrinTray printray.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    LexStart lexstart.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    LifeScape Media Detector c:\program files\picasa\picasamediadetector.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    LoadPowerProfile rundll32.exe powrprof.dll,loadcurrentpwrscheme All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    LoadPowerProfile rundll32.exe powrprof.dll,loadcurrentpwrscheme All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    LoadQM loadqm.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Magitime c:\program files\magitime\magitime.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    media_manager c:\program files\ebkrdr\mediaman.exe .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    minilog c:\windows\system\zonelabs\minilog.exe -service All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    MMTray c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    MSMSGS "c:\program files\messenger\msmsgs.exe" /background .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    My Search Bar Eq "c:\program files\mysearch\bar\s4bareq.exe" /r All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    NavRegReminder "c:\windows\temp\navbrowser.exe" /r /i "c:\windows\temp\navload.ini" All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    New.net Startup rundll32 c:\progra~1\newdot~1\newdot~1.dll,newdotnetstartup All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    PANDASCHEDULER "c:\program files\panda software\panda antivirus platinum\pavsched.exe" All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    PC Booster c:\program files\inkline global\pc booster\pcbooster.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    PCHealth c:\windows\pchealth\support\pchschd.exe -s All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    QuickTime Task c:\windows\system\qttask.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    RealJukeboxSystray "c:\program files\real\realjukebox\tsystray.exe" .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    RealJukeboxSystray c:\program files\real\realjukebox\tsystray.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    RealTray c:\program files\real\realplayer\realplay.exe systemboothideplayer All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    RegisterDropHandler c:\progra~1\textbr~1.0\bin\regist~1.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    RegisterDropHandler c:\progra~1\textbr~1.0\bin\regist~1.exe All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    RoboForm "c:\program files\siber systems\ai roboform\robotaskbaricon.exe" All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    SAgent2ExePath c:\program files\common files\epson\ebapi\sagent2.exe All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    SCANINICIO "c:\program files\panda software\panda antivirus platinum\inicio.exe" All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    ScanRegistry c:\windows\scanregw.exe /autorun All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Scheduled Maintenance c:\program files\iolo\system mechanic\scheduled_maintenance.exe .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    SchedulingAgent mstask.exe All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    sharedprem c:\windows\system\sharedprem.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    SSDPSRV c:\windows\system\ssdpsrv.exe All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    StillImageMonitor c:\windows\system\stimon.exe All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    Stomp DLA "c:\program files\stomp\dla\dlatray.exe" /t All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    SystemTray systray.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    TaskMonitor c:\windows\taskmon.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Tiny Trainer Intro c:\progra~1\tmentor\tinytr~1\intro.exe .DEFAULT Startup
    tkonnect c:\program files\tiscali\tkonnect\tkonnect.exe updatemode .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    TrueVector c:\windows\system\zonelabs\vsmon.exe -service All Users HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    WinampAgent "c:\program files\winamp3\winampa.exe" All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    WindowBlinds c:\program files\object desktop\windowblinds\wbload.exe auto .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    WinDSNX c:\windows\system\cryptui.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Yahoo! Pager c:\program files\yahoo!\messenger\ypager.exe -quiet .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    ZoneAlarm c:\progra~1\zonela~1\zoneal~1\zoneal~1.exe All Users Common Startup
     
  2. rugrat

    rugrat

    Joined:
    Dec 16, 2001
    Messages:
    1,869
    I see some spyware and one trojan. See here for the trojan info,
    http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_DSNX.A&VSect=T
    Then go here,
    http://housecall.trendmicro.com/
    and run an online scan.

    You also have new.net running, go to the control panel and open add/remove programs and remove it from there. Then reboot.

    Then go here, http://www.lurkhere.com/~nicefiles/
    and download Startup list 1.51 and run it. Copy and paste the results back here. It will make it easier for us to read.

    I am going to ask a moderator to move this to security where you should get better answers about the rest of the startups.

    Let us know
     
  3. cubbycuddly

    cubbycuddly Thread Starter

    Joined:
    Dec 1, 2001
    Messages:
    230
    Hi,

    I can't see an entry for new.net in add/remove.

    I am running the online scan now and also have ran spybot which found a new.net registry entry.

    here is the startuplist

    StartupList report, 27/01/2003, 16:10:11
    StartupList version: 1.51
    Started from : C:\UNZIPPED\STARTUPLIST[1]\STARTUPLIST.EXE
    Detected: Windows ME (Win9x 4.90.3000)
    Detected: Internet Explorer v6.00 (6.00.2600.0000)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\MINILOG.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\FILEFREEDOM\FILEFREEDOM.EXE
    C:\PROGRAM FILES\TEXTBRIDGE CLASSIC 2.0\BIN\INSTANTACCESS.EXE
    C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOTASKBARICON.EXE
    C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
    C:\WINDOWS\SYSTEM\DLA\TFSWCTRL.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\INKLINE GLOBAL\PC BOOSTER\PCBOOSTER.EXE
    C:\WINDOWS\SYSTEM\LEXBCES.EXE
    C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\TISCALI\TKONNECT\TKONNECT.EXE
    C:\PROGRAM FILES\IOLO\SYSTEM MECHANIC\SCHEDULED_MAINTENANCE.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
    C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
    C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
    C:\PROGRAM FILES\TEXTBRIDGE CLASSIC 2.0\EREG\REMIND32.EXE
    C:\PROGRAM FILES\TMENTOR\MENTOR FOR WINME\MINITRAY.EXE
    C:\PROGRAM FILES\GETRIGHT\GETRIGHT.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\OPERA\OPERA.EXE
    C:\UNZIPPED\STARTUPLIST[1]\STARTUPLIST.EXE

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\WINDOWS\Start Menu\Programs\StartUp]
    Tiny Trainer Intro.lnk = C:\Program Files\tMentor\Tiny Trainer\intro.exe
    Weather1.lnk = C:\Program Files\Weather1\Weather1.exe
    WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    MICROSOFT WORKS CALENDAR REMINDERS.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
    CAMIO VIEWER.LNK = C:\Program Files\Jasc Software Inc\After Shot\IXApplet.exe
    Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    REMINDER-SCANSOFT PRODUCT REGISTRATION.LNK = C:\Program Files\TextBridge Classic 2.0\Ereg\REMIND32.EXE
    MENTOR TRAY ICON.LNK = C:\Program Files\tMentor\Mentor for WinMe\minitray.exe
    MICROSOFT OFFICE.LNK = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    GETRIGHT - TRAY ICON.LNK = C:\Program Files\GetRight\getright.exe

    Shell folders Common Startup:
    [C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
    ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
    NEVER OFFLINE TASKTRAY SUPPORT.LNK = C:\Program Files\Never Offline\NOL_Tray.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    NavRegReminder = "C:\WINDOWS\TEMP\NAVBROWSER.EXE" /r /i "C:\WINDOWS\TEMP\NavLoad.ini"
    TaskMonitor = C:\WINDOWS\taskmon.exe
    RealTray = C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
    KAZAA = C:\PROGRAM FILES\GROKSTER\GROKSTER.EXE /SYSTRAY
    LoadQM = loadqm.exe
    QuickTime Task = C:\WINDOWS\SYSTEM\QTTASK.EXE
    FileFreedom = C:\PROGRAM FILES\FILEFREEDOM\FILEFREEDOM.EXE
    InstantAccess = C:\PROGRA~1\TEXTBR~1.0\BIN\INSTAN~1.EXE /h
    RegisterDropHandler = C:\PROGRA~1\TEXTBR~1.0\BIN\REGIST~1.EXE
    RealJukeboxSystray = C:\PROGRAM FILES\REAL\REALJUKEBOX\TSYSTRAY.EXE
    RoboForm = "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    InCD = C:\Program Files\Ahead\InCD\InCD.exe
    IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncrediMail.exe /c
    sharedprem = C:\WINDOWS\system\sharedprem.EXE
    MMTray = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    My Search Bar Eq = "C:\PROGRAM FILES\MYSEARCH\BAR\S4BAREQ.EXE" /r
    Stomp DLA = "C:\Program Files\Stomp\DLA\dlatray.exe" /t
    dla = C:\WINDOWS\system\dla\tfswctrl.exe
    Magitime = C:\Program Files\Magitime\magitime.exe
    (Default) =
    LifeScape Media Detector = C:\Program Files\Picasa\PicasaMediaDetector.exe
    SystemTray = SysTray.Exe
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    LexStart = Lexstart.exe
    LexmarkPrinTray = PrinTray.exe
    PC Booster = C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    WinampAgent = "C:\Program Files\Winamp3\winampa.exe"
    SCANINICIO = "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
    ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
    MSConfigReminder = C:\WINDOWS\SYSTEM\msconfig.exe /reminder

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    SAgent2ExePath = C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    SSDPSRV = C:\WINDOWS\SYSTEM\ssdpsrv.exe
    RegisterDropHandler = C:\PROGRA~1\TEXTBR~1.0\BIN\REGIST~1.EXE
    TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    minilog = C:\WINDOWS\SYSTEM\ZoneLabs\MINILOG.EXE -service
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    SchedulingAgent = mstask.exe
    *StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
    StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
    PANDASCHEDULER = "C:\Program Files\Panda Software\Panda Antivirus Platinum\Pavsched.exe"

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    RealJukeboxSystray = "C:\PROGRAM FILES\REAL\REALJUKEBOX\tsystray.exe"
    MSMSGS = "C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE" /background
    Yahoo! Pager = C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    tkonnect = C:\PROGRAM FILES\TISCALI\TKONNECT\TKONNECT.EXE updatemode
    Scheduled Maintenance = C:\PROGRAM FILES\IOLO\SYSTEM MECHANIC\Scheduled_Maintenance.exe
    WindowBlinds = C:\Program Files\Object Desktop\WindowBlinds\wbload.exe auto

    --------------------------------------------------

    C:\AUTOEXEC.BAT listing:

    SET windir=C:\WINDOWS
    SET winbootdir=C:\WINDOWS
    SET COMSPEC=C:\WINDOWS\COMMAND.COM
    SET PATH=C:\PROGRA~1\PANDAS~1\PANDAA~1;C:\WINDOWS;C:\WINDOWS\COMMAND
    SET PROMPT=$p$g
    SET TEMP=C:\WINDOWS\TEMP
    SET TMP=C:\WINDOWS\TEMP

    --------------------------------------------------

    C:\WINDOWS\WINSTART.BAT listing:

    C:\WINDOWS\TMPCPYIS.BAT
    DEL C:\PQSC\PROGRAM\*.dll
    DEL C:\PQSC\PROGRAM\*.exe
    RD C:\PQSC\PROGRAM
    RD C:\PQSC
    DEL C:\WINDOWS\WINSTART.BAT

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    (no name) - (no file) - {1678F7E1-C422-11D0-AD7D-00400515CAAA}
    (no name) - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll - {724d43a9-0d85-11d4-9908-00400523e39a}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    ScanDisk.job
    Tune-up Application Start.job
    PCHealth Scheduler for Data Collection.job
    Disk Defragmenter.job
    1 Copernic Intra-Daily ~Default User.job
    2 Copernic Daily ~Default User.job
    3 Copernic Weekly ~Default User.job
    4 Copernic Monthly ~Default User.job
    Video Reminder.job
    Symantec NetDetect.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    [YInstStarter Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
    CODEBASE = http://download.yahoo.com/dl/installs/yinst.cab

    [plug Class]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\CHARGI~1.DLL
    CODEBASE = http://dist02.chargitdial.com/chargitplug.dll

    [QuickTime Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
    CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

    [Shockwave ActiveX Control]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

    [IntraLaunch.MainControl]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\INTRALAUNCH.OCX
    CODEBASE = file://D:\IntraLaunch.CAB

    [HouseCall Control]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
    CODEBASE = http://a840.g.akamai.net/7/840/537/2003011601/housecall.antivirus.com/housecall/xscan53.cab

    [CV3 Class]
    InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
    CODEBASE = http://windowsupdate.microsoft.com/R1108/V31Controls/x86/mil/en/actsetup.cab

    [AV Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PAV.DLL
    CODEBASE = http://www.pcpitstop.com/antivirus/PCPAV.CAB

    [RdxIE Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\IE_GROKSTER.DLL
    CODEBASE = http://www.grokster.com/rdx/RdxIE.cab

    --------------------------------------------------
    End of report, 9,875 bytes
    Report generated in 0.115 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  4. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    Here's you original question, and I responded:

    http://forums.techguy.org/showthread.php?s=&postid=698682#post698682

    I don't really think it helps if you start another thread with the same question without responding to my reaction.

    I suggest you first run SpyBot as suggested, and subsequently visit Pacman's site to weed out the superfluous startup entries.

    You can do it!

    These are spy/foistware and need to go for a start:

    Weather1.lnk = C:\Program Files\Weather1\Weather1.exe
    FileFreedom = C:\PROGRAM FILES\FILEFREEDOM\FILEFREEDOM.EXE
    sharedprem = C:\WINDOWS\system\sharedprem.EXE
    My Search Bar Eq = "C:\PROGRAM FILES\MYSEARCH\BAR\S4BAREQ.EXE" /r
     
  5. cubbycuddly

    cubbycuddly Thread Starter

    Joined:
    Dec 1, 2001
    Messages:
    230
    Tonyklein,

    your not the only person here to offer information.

    also yours is not gospel and a variety of information is the spice of life!!!!
     
  6. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    Yeah, whatever... :p
     
  7. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    cubbycuddly, although variety may spice your life, at TSG, we discourage duplicate thread posting:
    So I hope you will avoid that in the future. Closing this one per the Rules.

    Further responses to this problem should be made here:

    http://forums.techguy.org/showthread.php?s=&postid=698682#post698682
     
  8. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/115520

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice