1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

[solved]Viruses & spyware...need help big time!

Discussion in 'Virus & Other Malware Removal' started by hottesttotty, Sep 1, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    Wow, do I have a mess! First of all, let me say I am running winXP pro, and am VERY new to it, so I'm feeling lost to start with! :eek: There are two accounts set up, both with admin permissions, but one thing I'm wondering is when I run my anti virus and ad aware, spybot, etc.... am I checking the whole computer, or just one user? In other words, should I run everything from both accounts? The reason I ask is I noticed a difference in AVG scan results from different users....as I will try to now explain!

    It started this morning when my dh was looking for desktop wallpaper....a window popped up for him to download something (of course he doesn't remember WHAT!! :mad: ) and he clicked OK. Suddenly there's viruses and spyware all over! The first 3 scans were done from his user account, and the results were as follows:

    1st AVG Scan result

    several files not able to be opened/scanned
    VIRUS Revop.C (in temp. int. files)
    VIRUS Downloader.Dyfica.2.AA (in temp. int. files)
    VIRUS Dropper.Delf.3.L (in C:\TEMP\INSTAL~1.EXE)

    All of the above viruses were supposedly moved to the virus vault following scan.

    2nd AVG Scan Result

    still same files not able to be opened/scanned
    NO VIRUSES DETECTED

    3rd AVG Scan Result

    still same files not able to be opened/scanned
    VIRUS Trojan horse Revop.C (in temp. int. files)

    Again, the above virus supposedly moved to virus vault after scan.

    Then I got on here and looked through there. Seeing that the viruses were all in temp. int. files I deleted all those in both users, and then ran ad aware and spybot under both users. I then ran AVG a 4th time, but from MY user account.

    4th AVG Scan Result

    still same files not able to be opened/scanned
    VIRUS Trojan horse Downloader.Alchemic.A
    VIRUS Trojan horse Downloader.Agent.AS

    Both of the above viruses were found in MY docs and setting\local settings\TEMP, one as "alchem.exe" and the other as "POLMX.EXE". This time, it said the Alchemic.A was "healed" and the Agent.AS was moved to virus vault.

    I then ran Hijack This, and this is the most recent log file:

    Logfile of HijackThis v1.97.3
    Scan saved at 9:43:13 AM, on 9/1/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\Program Files\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winad Client\Winad.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Winad Client\WinClt.exe
    C:\WINDOWS\System32\devldr32.exe
    C:\Program Files\OpenOffice.org1.1.2\program\soffice.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Documents and Settings\Mark\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yourcountyhomepage.com/wi_pepin.htm
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [USSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1.2\SSaver\Ussshreg.exe /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\Run: [pfxswgoms] C:\WINDOWS\System32\rtsvyj.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: OpenOffice.org 1.1.2.lnk = C:\Program Files\OpenOffice.org1.1.2\program\quickstart.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...13b668fec7d7:270d2288487988400edd713985bb0eab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38164.2018171296
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab



    Last, but not least, I am getting the following error message in what appears to be a dos window when switching between users:

    "C:\Windows\System32\rtsvyj.exe
    C:\Windows\System32\autoexec.NT
    The system file is not suitable for running ms-dos and Microsoft Windows applications. Choose 'close' to terminate the application."

    WHEW....sorry for such a long post, but there's just so much that's going on I wanted to make sure I explained it thoroughly! :eek:
     
  2. zemdarin

    zemdarin

    Joined:
    Dec 14, 2003
    Messages:
    107
    Hi
    If you click on the url in my signature I think you will find all the information you need.
     
  3. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    Seems to be lots of good info there, but any suggestions on where specifically I should be directing my attention? I have already done alot of the things I see mentioned, what might I be missing?
     
  4. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    Another note, I can't print now either, and a new error message is popping up when I log off a user: "The application failed to initialize because the window station is shutting down." This message just pops up quick and then disappears, and I get back to the XP log in screen. Another thing I've noticed is that when I'm in my dh's user settings, the XP graphics don't work, just looks like the old standard windows.

    Anyone have any more suggestions? Please?? ;) First day with the kids back to school & this is how I get to "enjoy" my peace and quiet! :( BUMMER!
     
  5. zemdarin

    zemdarin

    Joined:
    Dec 14, 2003
    Messages:
    107
    I think you may have the sasser virus on your computer. If you have Ad-Aware or Spy-Bot run them and see. If not you know where you can get them
     
  6. forddude

    forddude

    Joined:
    Jul 13, 2004
    Messages:
    51
    Please, read my signature!!!!
     
  7. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    hottesttotty, The version of HJT you are using is very old. Please download the new one 1.98.2 and post another log. Click here and go to the downloads section.
     
  8. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    Thanks cybertech.....I got the new version, and will post the log below. I did want to mention tho, that I deleted temp files and have come up with two clean virus scans since doing so. I also updated AdAware, which removed a few more things and then did the LONG windows XP SP2 update last night. Things seem to be running ok now, but there is still a couple questionable things in the new hjt log. Please advise.... ;)

    Logfile of HijackThis v1.98.2
    Scan saved at 10:08:45 PM, on 9/2/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\Program Files\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winad Client\Winad.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yourcountyhomepage.com/wi_pepin.htm
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [USSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1.2\SSaver\Ussshreg.exe /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1094096688510
     
  9. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    Well, I guess I spoke too soon.....there is still a virus....."dropper.delf.3.L". AVG says it's in the virus vault now again, but it came from C:\TEMP\INSTAL~1.EXE .

    Now, on the web rebates thing, I know this is one of the things I should get rid of, but when I've tried to delete it, it tells me it's running, so do I just go to msconfig & stop it & then go back and try to delete the folder/files?
     
  10. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    This is what I've done so far this morning.......I turned of system restore, then deleted all files in C:\TEMP and then disabled web rebates, ran file search for web rebates and deleted all found files, then ran ad aware and spybot again, restarted, ran AVG, which came up clean, then restarted again, enabled system restore, and then ran this new hjt log:

    Logfile of HijackThis v1.98.2
    Scan saved at 10:00:03 AM, on 9/3/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\Program Files\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winad Client\Winad.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Winad Client\WinClt.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yourcountyhomepage.com/wi_pepin.htm
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [USSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1.2\SSaver\Ussshreg.exe /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1094096688510

    Anything else I can do?
     
  11. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Run HJT again and put a check in the following:

    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe

    Close all applications and browser windows before you click "fix checked".

    Restart in safe mode

    Open Windows Explorer. Go to Tools, Folder Options and click on the View tab. Make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click "Apply to all folders"
    Click "Apply" then "OK".

    Delete this folder:
    C:\Program Files\Winad Client

    Press CTRL+ALT+Delete and end task on all WebRebates*.exe files running. Now you should be able to delete that folder also.

    Empty your recycle bin.

    Reboot.
     
  12. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    Thanks Cybertech! :) Followed all your instructions above, plus removed some unnecessary start ups when I switched out of safemode, and here's the new hjt log:

    Logfile of HijackThis v1.98.2
    Scan saved at 12:56:24 PM, on 9/3/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\Program Files\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yourcountyhomepage.com/wi_pepin.htm
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1094096688510

    How's it look? ;)
     
  13. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Looks good! Did you kill of webrebates?
     
  14. hottesttotty

    hottesttotty Thread Starter

    Joined:
    Dec 12, 2001
    Messages:
    542
    It appears so.....I can't find anything relating to it, except the unchecked entry in msconfig/startup. Can anyone tell me how to get rid of those listings? Then we SHOULD be "all clear"! ;)

    Thanks again, by they way! This place rocks!!
     
  15. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
    Hi Cybertech, thanks for the pm ;)

    Vice President Cheney is in town today and I've spent the last hour and a half stuck on a closed freeway :mad:

    He'd better have something good to say :D

    It won't hurt to leave them there if they are unchecked. To get rid of them would take a registry edit and without knowing your experience, I would hesitate to play around there.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - [solved]Viruses spyware need
  1. jennys95
    Replies:
    1
    Views:
    659
  2. rjay13
    Replies:
    0
    Views:
    290
  3. dano_61
    Replies:
    14
    Views:
    921
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/268973

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice