Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93116 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Problems remaining after virus removal


  • Please log in to reply
234 replies to this topic

#166 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 04:38 PM

i cant work out what stuff needs copying on to here from that program ..? ive saved the file as you stated but i cant find it now and i cant see how to add it to this reply, theres no browse or upload buttons.

Edited by pulsebabe, 07 November 2010 - 04:39 PM.

    Advertisements

Register to Remove


#167 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 04:43 PM

Name,Value,Section,Enabled,Description,Company "00TCrdMain","%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe","Registry - Machine Run","1","TOSHIBA Flash Cards","TOSHIBA Corporation" "Adobe ARM","C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe","Registry - Machine Run","1","Adobe Reader and Acrobat Manager","Adobe Systems Incorporated" "avgnt",""C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min","Registry - Machine Run","1","Antivirus System Tray Tool (AntiVir Desktop)","Avira GmbH" "cfFncEnabler.exe","cfFncEnabler.exe","Registry - Machine Run","1","cfFncEnabler","Toshiba Corporation" "HotKeysCmds","C:\Windows\system32\hkcmd.exe","Registry - Machine Run","1","hkcmd Module (Intel® Common User Interface)","Intel Corporation" "HSON","%ProgramFiles%\TOSHIBA\TBS\HSON.exe","Registry - Machine Run","1","HotStartOn (TOSHIBA Button Support)","TOSHIBA Corporation" "msnmsgr",""C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background","Registry - User Run","1","Windows Live Messenger","Microsoft Corporation" "NDSTray.exe","NDSTray.exe","Registry - Machine Run","1","ConfigFree™ Task tray menu (ConfigFree™ Tray)","TOSHIBA CORPORATION" "Persistence","C:\Windows\system32\igfxpers.exe","Registry - Machine Run","1","persistence Module (Intel® Common User Interface)","Intel Corporation" "RtHDVCpl","RtHDVCpl.exe","Registry - Machine Run","1","HD Audio Control Panel","Realtek Semiconductor" "Sidebar","C:\Program Files\Windows Sidebar\sidebar.exe /autoRun","Registry - User Run","1","Windows Sidebar (Microsoft® Windows® Operating System)","Microsoft Corporation" "SunJavaUpdateSched",""C:\Program Files\Common Files\Java\Java Update\jusched.exe"","Registry - Machine Run","1","Java™ Update Scheduler (Java™ Platform SE Auto Updater 2 0)","Sun Microsystems, Inc." "SynTPEnh","C:\Program Files\Synaptics\SynTP\SynTPEnh.exe","Registry - Machine Run","1","Synaptics TouchPad Enhancements (Synaptics Pointing Device Driver)","Synaptics, Inc." "Toshiba TEMPO","C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe","Registry - Machine Run","1","Toshiba TEMPRO","Toshiba Europe GmbH" "TPwrMain","%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE","Registry - Machine Run","1","TOSHIBA Power Saver","TOSHIBA Corporation" "Windows Defender","%ProgramFiles%\Windows Defender\MSASCui.exe -hide","Registry - Machine Run","1","Windows Defender User Interface (Windows Defender)","Microsoft Corporation" "WinPatrol","C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot","Registry - Machine Run","1","WinPatrol System Monitor ( WinPatrol Monitor)","BillP Studios"

#168 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 07 November 2010 - 04:45 PM

None of that is any use. What is needed is the list of applications that start at boot time, what is shown in the window when you run it. After that, click on FIle then Save as Plain Text. Save it to your Desktop. Then open that and copy that information and paste it here. For instance, on my Win 7 Pro X64 system, this is what it shows:

Name,Value,Section,Enabled,Description,Company
"","","Registry - Machine Run","1","",""
"","","Registry - Machine Run","0","",""
"Adobe ARM",""C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"","Registry - Machine Run","1","Adobe Reader and Acrobat Manager","Adobe Systems Incorporated"
"Adobe Reader Speed Launcher",""C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"","Registry - Machine Run","1","Adobe Acrobat SpeedLauncher (Adobe Acrobat)","Adobe Systems Incorporated"
"BVRPLiveUpdate",""C:\Program Files (x86)\Avanquest update\Engine\Setup.exe" -s /PATCH,/REBOOT,/SRCUPDATEC:\PROGRA~3\AVANQU~1\POWERD~1\LIVEUP~1\LISTOF~1.DAT","Registry - Machine Run","1","",""
"DesktopOK",""D:\tools\DesktopOK.exe" -bg -startup","Registry - User Run","1","DesktopOK 2.17","Nenad Hrg SoftwareOK"
"ERUNT AutoBackup.lnk","C:\Program Files (x86)\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow","Startup - Current User","1","",""
"Microsoft Office.lnk","C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE -b -l","Startup - All Users","1","Microsoft Office XP component (Microsoft Office XP)","Microsoft Corporation"
"PDHookServer","D:\PowerDesk\PDHookServer.exe","Registry - User Run","1","",""
"Sidebar","C:\Program Files\Windows Sidebar\sidebar.exe /autoRun","Registry - User Run","1","Windows Desktop Gadgets (Microsoft® Windows® Operating System)","Microsoft Corporation"
"SunJavaUpdateSched",""C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"","Registry - Machine Run","1","Java™ Update Scheduler (Java™ Platform SE Auto Updater 2 0)","Sun Microsystems, Inc."
"TrueImageMonitor.exe","C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe","Registry - Machine Run","1","Acronis True Image Monitor (Acronis True Image)","Acronis"

That's what Doug is looking for.

Rich
 

Die with memories, not dreams. – Unknown


#169 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 04:47 PM

ame,Value,Section,Enabled,Description,Company "00TCrdMain","%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe","Registry - Machine Run","1","TOSHIBA Flash Cards","TOSHIBA Corporation" "Adobe ARM","C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe","Registry - Machine Run","1","Adobe Reader and Acrobat Manager","Adobe Systems Incorporated" "avgnt",""C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min","Registry - Machine Run","1","Antivirus System Tray Tool (AntiVir Desktop)","Avira GmbH" "cfFncEnabler.exe","cfFncEnabler.exe","Registry - Machine Run","1","cfFncEnabler","Toshiba Corporation" "HotKeysCmds","C:\Windows\system32\hkcmd.exe","Registry - Machine Run","1","hkcmd Module (Intel® Common User Interface)","Intel Corporation" "HSON","%ProgramFiles%\TOSHIBA\TBS\HSON.exe","Registry - Machine Run","1","HotStartOn (TOSHIBA Button Support)","TOSHIBA Corporation" "msnmsgr",""C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background","Registry - User Run","1","Windows Live Messenger","Microsoft Corporation" "NDSTray.exe","NDSTray.exe","Registry - Machine Run","1","ConfigFree™ Task tray menu (ConfigFree™ Tray)","TOSHIBA CORPORATION" "Persistence","C:\Windows\system32\igfxpers.exe","Registry - Machine Run","1","persistence Module (Intel® Common User Interface)","Intel Corporation" "RtHDVCpl","RtHDVCpl.exe","Registry - Machine Run","1","HD Audio Control Panel","Realtek Semiconductor" "Sidebar","C:\Program Files\Windows Sidebar\sidebar.exe /autoRun","Registry - User Run","1","Windows Sidebar (Microsoft® Windows® Operating System)","Microsoft Corporation" "SunJavaUpdateSched",""C:\Program Files\Common Files\Java\Java Update\jusched.exe"","Registry - Machine Run","1","Java™ Update Scheduler (Java™ Platform SE Auto Updater 2 0)","Sun Microsystems, Inc." "SynTPEnh","C:\Program Files\Synaptics\SynTP\SynTPEnh.exe","Registry - Machine Run","1","Synaptics TouchPad Enhancements (Synaptics Pointing Device Driver)","Synaptics, Inc." "Toshiba TEMPO","C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe","Registry - Machine Run","1","Toshiba TEMPRO","Toshiba Europe GmbH" "TPwrMain","%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE","Registry - Machine Run","1","TOSHIBA Power Saver","TOSHIBA Corporation" "Windows Defender","%ProgramFiles%\Windows Defender\MSASCui.exe -hide","Registry - Machine Run","1","Windows Defender User Interface (Windows Defender)","Microsoft Corporation" "WinPatrol","C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot","Registry - Machine Run","1","WinPatrol System Monitor ( WinPatrol Monitor)","BillP Studios"

Edited by pulsebabe, 07 November 2010 - 04:48 PM.


#170 Doug

Doug

    Retired Administrator -Tech Team

  • Tech Team
  • 10,057 posts

Posted 07 November 2010 - 04:48 PM

Mine gets saved in C:\Program Files\CodeStuff\Starter\Data\Starters Nov7.txt

The Browse and Upload functions should appear at the bottom of the Compose Box you use when typing your next reply.
If you are using Quick Reply, they might not appear.

This Tech Tip, may be useful to you: (it's about uploading an image file, but the steps are the same for a text file)
http://forums.whatth...showtopic=96285
The help you receive here is free.
If you wish, you may Donate to help keep us online.

#171 Doug

Doug

    Retired Administrator -Tech Team

  • Tech Team
  • 10,057 posts

Posted 07 November 2010 - 04:51 PM

Yes, pulsebabe, that information is most likely from your StartUps, and we can use it. It is just real hard to sort through it for the helper like me. I asked you to save and post in Plain Text, because it is easier for you, even though much harder for me to sort. No problem.... I'll sort it.
The help you receive here is free.
If you wish, you may Donate to help keep us online.

#172 Doug

Doug

    Retired Administrator -Tech Team

  • Tech Team
  • 10,057 posts

Posted 07 November 2010 - 04:59 PM

ame,Value,Section,Enabled,Description,Company
"00TCrdMain","%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe","Registry - Machine Run","1","TOSHIBA Flash Cards","TOSHIBA Corporation"
"Adobe ARM","C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe","Registry - Machine Run","1","Adobe Reader and Acrobat Manager","Adobe Systems Incorporated"
"avgnt",""C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min","Registry - Machine Run","1","Antivirus System Tray Tool (AntiVir Desktop)","Avira GmbH"
"cfFncEnabler.exe","cfFncEnabler.exe","Registry - Machine Run","1","cfFncEnabler","Toshiba Corporation"
"HotKeysCmds","C:\Windows\system32\hkcmd.exe","Registry - Machine Run","1","hkcmd Module (Intel® Common User Interface)","Intel Corporation"
"HSON","%ProgramFiles%\TOSHIBA\TBS\HSON.exe","Registry - Machine Run","1","HotStartOn (TOSHIBA Button Support)","TOSHIBA Corporation"
"msnmsgr",""C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background","Registry - User Run","1","Windows Live Messenger","Microsoft Corporation"
"NDSTray.exe","NDSTray.exe","Registry - Machine Run","1","ConfigFree™ Task tray menu (ConfigFree™ Tray)","TOSHIBA CORPORATION"
"Persistence","C:\Windows\system32\igfxpers.exe","Registry - Machine Run","1","persistence Module (Intel® Common User Interface)","Intel Corporation"
"RtHDVCpl","RtHDVCpl.exe","Registry - Machine Run","1","HD Audio Control Panel","Realtek Semiconductor"
"Sidebar","C:\Program Files\Windows Sidebar\sidebar.exe /autoRun","Registry - User Run","1","Windows Sidebar (Microsoft® Windows® Operating System)","Microsoft Corporation"
"SunJavaUpdateSched",""C:\Program Files\Common Files\Java\Java Update\jusched.exe"","Registry - Machine Run","1","Java™ Update Scheduler (Java™ Platform SE Auto Updater 2 0)","Sun Microsystems, Inc."
"SynTPEnh","C:\Program Files\Synaptics\SynTP\SynTPEnh.exe","Registry - Machine Run","1","Synaptics TouchPad Enhancements (Synaptics Pointing Device Driver)","Synaptics, Inc."
"Toshiba TEMPO","C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe","Registry - Machine Run","1","Toshiba TEMPRO","Toshiba Europe GmbH"
"TPwrMain","%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE","Registry - Machine Run","1","TOSHIBA Power Saver","TOSHIBA Corporation"
"Windows Defender","%ProgramFiles%\Windows Defender\MSASCui.exe -hide","Registry - Machine Run","1","Windows Defender User Interface (Windows Defender)","Microsoft Corporation"
"WinPatrol","C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot","Registry - Machine Run","1","WinPatrol System Monitor ( WinPatrol Monitor)","BillP Studios"

Pulsebabe,

Open CodeStuff Starters to the Startups(tab)
Remove the Checkmark/tick from in front of the items that I have indicated above in Bold
The help you receive here is free.
If you wish, you may Donate to help keep us online.

#173 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 04:59 PM

i just did what ztruker said to do, but its exactly the same info as previously posted.

#174 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 05:01 PM

is this any better?

Attached Files



#175 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 05:04 PM

i always have msn open up so would prefer to keep that on start up and i thought it was decided earlier that to enable adobe downloads automatically that it was ok for that to remain in start up too? everything else removed.

Edited by pulsebabe, 07 November 2010 - 05:20 PM.

    Advertisements

Register to Remove


#176 Doug

Doug

    Retired Administrator -Tech Team

  • Tech Team
  • 10,057 posts

Posted 07 November 2010 - 05:22 PM

Of course. It's your machine. And you are the one deciding how to use it. Leave those two items, if you wish. Or For this "experiment", disable them temporarily at this time by removing the checkmark/tick and then later re-Enable them by placing the Checkmark/tick back in place. My purpose in this sequence is to determine whether or not reducing the actively running applications and processes, will produce a better result for you. Better Result meaning a machine that performs without lag and opens applications promptly.
The help you receive here is free.
If you wish, you may Donate to help keep us online.

#177 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 05:24 PM

ok done temporarily! what next....?

#178 Doug

Doug

    Retired Administrator -Tech Team

  • Tech Team
  • 10,057 posts

Posted 07 November 2010 - 05:36 PM

Our next step is going to be out-of-sequence with the other procedures that I've already suggested above (Processes) & (Services)
_________________________________________

You are presently running Avira AntiVirus <-- good utility and highly recommended :thumbup:

Your machine also has Windows Defender running active.

Windows Defender runs in the background and can conflict with other anti-malware utilities.

Therefore, I recommend that you Disable Windows Defender and also STOP the Service for Windows Defender.

Using CodeStuf Starters - Startup(tab) remove the checkmark/tick from in front of Windows Defender

Next

Press the Vista Start Orb
Click on Run
(Type)services.msc

Browse down the list until you find Windows Defender
Right-click on Windows Defender - the change the status to STOP and the Startup Type to Manual
The help you receive here is free.
If you wish, you may Donate to help keep us online.

#179 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 05:38 PM

defender was switched off automatically when i installed avira last week? strange that its still running. lee recommended avira - i used to have avg. ive right clicked on wd but the stop; option is faded out, only start is highlighted - that says to me its already stopped? after ive done all that, what next?

Edited by pulsebabe, 07 November 2010 - 05:41 PM.


#180 pulsebabe

pulsebabe

    Silver Member

  • Authentic Member
  • PipPipPip
  • 303 posts

Posted 07 November 2010 - 05:46 PM

i constantly keep getting a new tab opening up automatically asking me to download windows live messenger 2011. it got downloaded onto my system last week, any idea how i stop the tab opening up on its own, its getting a nuisance?

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users