This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unremovable dialog box on desktop and corrupted Googl

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello techies…

Compaq Presario desktop
XP Home SP2 (yes, I know that I need to install SP3 :blush: )
3.2GHz 512RAM Celeron D 120GB? HDD (says 104GB capacity under C:)
IE and Firefox both used by different users (older people: IE, younger people: Firefox hehe)

I have a computer with apparently the same issue as I had before on my laptop (which you were able to help resolve, ty). This has been going on for about a month.

The problem is that I have a dialog box which cannot be removed from the desktop.
The title bar on the dialog box says: clk_jdkhid:onov7yeaa1jgs.exe - Bad Image
The message in the dialog box says: The application or DLL C:\WINDOWS\system32\digeste.dll is not a valid Windows image. Please check this against your installation diskette.
"X-ing" out of the dialog box only brings it up again with a variation on the title bar name.

There has been a big white square in the middle of the desktop that won't go away, and anything I open will still have that square. There is no way to physically remove it as there is not an X or any dialog buttons. Can't even slide it out of the way.

The other issue that is very familiar to me is the fact that when I do a Google search and then click on a website, the address at the bottom of the screen starts with go.google.com but the intended website does not open, instead a window opened for StopZilla, which I can only assume is adware. I believe what started this issue was one of the users using IE clicked on a popup. Just this morning I tried using Firefox to google and what happened was what I described above.

I have read some of the strong recommendations by the Techs on this site so this is what I've done ahead of time:
I downloaded and ran the ERUNT program to back up the registry.
I saved a HiJackThis log.
I even generated a Startup List from HJT and saved it as well in case it's needed.

Before I post the HJT Log, I want to thank in advance the tech who will respond and help solve this issue.

Thank you! :notworthy:
Amber (lucella31)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:58:10 AM, on 2/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twex.exe,
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: C:\WINDOWS\system32\gsdrgfdrrgnd.dll - {D5BF4552-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\gsdrgfdrrgnd.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [axis web cake second] C:\Documents and Settings\All Users\Application Data\Book Slow Axis Web\Mfcd Film.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lrijh8s73jhbfgfd] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [EggsFlap] C:\DOCUME~1\COMPAQ~1\APPLIC~1\STOPOP~1\filmroad.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [lrijh8s73jhbfgfd] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [InetChk] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ms1233182025.exe work
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [db44o0arvhte8t0mk859dlbsesojqxde8nz6j81758rfzt] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\zid1y1gijra8.exe
O4 - HKCU\..\Run: [igb0h72z50v0o6nk0] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\dyp4p75q7c967.exe
O4 - HKCU\..\Run: [xvnmmk3wx8ns8mldu2jrmsatyuvekvr5sxdznev] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\h3602c48pd.exe
O4 - HKCU\..\Run: [p4vu95q1ipctkagro56dj8] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uuvvliomnp.exe
O4 - HKCU\..\Run: [wxfqufboq75viyfx9ftm59liz15edosvbyoo3hn4nmup] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\sir0k5.exe
O4 - HKCU\..\Run: [ri0l1d4y3sykzqyjvjv99tnud3k6ej7a] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\hgyjkvyno.exe
O4 - HKCU\..\Run: [ja3dofssyka39l6rz3gape62iw6e1qflr] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\lcfypdj9ne.exe
O4 - HKCU\..\Run: [monpi3x3upxoxjjpm4uv3yk8j] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\j2e9zt19.exe
O4 - HKCU\..\Run: [m84l6l122fzdgjiaymnhmt88rrfx3n8tsnq85opkq3p8f1o] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\iw65g1kvuvi9.exe
O4 - HKCU\..\Run: [hlfch0m975lwkd6rpq4oz] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\hshy3wf75qtc.exe
O4 - HKCU\..\Run: [bsspmzc96rojw65ja2y0] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\u9hq53qsp.exe
O4 - HKCU\..\Run: [r0lt7jdmjjxy4ldjsauvu2wv0tj7ryil0fd773qjns1fegsn1d] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\hzjdqwo3lxrau.exe
O4 - HKCU\..\Run: [glv2hkclc1jlnb3ibmjzkq6tfv82t9u1fsbidjwz9bav] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\dw0cgafzcz.exe
O4 - HKCU\..\Run: [i93y5qj3o1pk31rexmohyof0i] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\m7l1u4hw.exe
O4 - HKCU\..\Run: [g4zudm7fyq8zvyl3dyj6smzcom3fiwqq] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kulwc0d35y.exe
O4 - HKCU\..\Run: [hvbccddrkkzyoptfcfd0crx0iu4aww0xuhzxen4t7x8] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cynjw0yq.exe
O4 - HKCU\..\Run: [tou9odnxbia0n95rtdq7wuwuvyeke9n1bl] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\b47rp110bfuy.exe
O4 - HKCU\..\Run: [l9bsieqfhv967bo3casn2eba8159fea81oipds86rd1mswc9kj] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\widihi.exe
O4 - HKCU\..\Run: [vy9orx5shdmr1r06f7cra1g9ny20yty6yq32] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\zmrcn7.exe
O4 - HKCU\..\Run: [cohqyfzk5ivdof52rnji2gn286m17jqn4] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\len0n2ic.exe
O4 - HKCU\..\Run: [sysguard] C:\WINDOWS\sysguard.exe
O4 - HKCU\..\Run: [n6o48jf7hzxs6haje7jwovwpw71wvyfy6eeb] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\tmashvc4o.exe
O4 - HKCU\..\Run: [d3q9mvknakjpq2o09omnd4sb65hznn87z9bxqhad9g3r18w] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\pjhcqyr5.exe
O4 - HKCU\..\Run: [qnjb9eltc8cw200xipir0pcb] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\amsin29v9.exe
O4 - HKCU\..\Run: [p2ver8vz69ym4s0yl4] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\e3mczzvud1tns.exe
O4 - HKCU\..\Run: [r2xapfp5149kbhd] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cdbq3fnqf.exe
O4 - HKCU\..\Run: [ymi4bzhqu7f4j79wxmm1] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\f9ww5tpe.exe
O4 - HKCU\..\Run: [inbokr7vun08950t269i9ntmnr6tovj] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ve8zyyjzs6.exe
O4 - HKCU\..\Run: [rduwc7yodqobbd99] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uvw6rcro40s.exe
O4 - HKCU\..\Run: [vuejhe10x4ve] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\nbunoh.exe
O4 - HKCU\..\Run: [rnd6kzvmeb8] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\gav46h1nr.exe
O4 - HKCU\..\Run: [vyfrfcyhpwlbojyky] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\t3f0uhglq.exe
O4 - HKCU\..\Run: [n082nd4xssw9kn95i233eck] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uk9une21u0yyo.exe
O4 - HKCU\..\Run: [aezh5mp2uk9ygpew1sabunuoa0zltdnpxvd3ty0q8xs8hb] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\rk4cbuj.exe
O4 - HKCU\..\Run: [u6lvt7ctet57iof9] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ljyoee4w.exe
O4 - HKCU\..\Run: [fkio43938xlbrqkvygya6fvkd10lj] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\s2v8gcii3y3.exe
O4 - HKCU\..\Run: [v8kuufvwvi6] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\faknfx0d.exe
O4 - HKCU\..\Run: [xv06grof0fxxafxe7fs26er8kyez] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\nkwu8z.exe
O4 - HKCU\..\Run: [bhl7tqtjzzw3fhfzzce43hj0mwo1mgt4i] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\rgyupt9.exe
O4 - HKCU\..\Run: [bi6cco8o3ad3xa] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ox5ezshvn.exe
O4 - HKCU\..\Run: [pe2z1kt8ttube1g2istadc4xotonhqf1gp] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\j3b0rvje.exe
O4 - HKCU\..\Run: [l3redgffunx] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\acwf0vn.exe
O4 - HKCU\..\Run: [ofqshyhe5v] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\dwm2vrl.exe
O4 - HKCU\..\Run: [irgjq8amy] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\op7p0z.exe
O4 - HKCU\..\Run: [oi8qe7cypsofxc0ceh5kdar091o6isj3z4sg7pupgc4mom] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\zi9vmosndycoz.exe
O4 - HKCU\..\Run: [q4kzq86cesnohv9pco1kmonj4se0ruxpe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\tar88ox9qng1a.exe
O4 - HKCU\..\Run: [xxgmlvs58a95] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\h1jjp6ti4exgh.exe
O4 - HKCU\..\Run: [bo5l6zdz110p8iv] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\zjg3yw.exe
O4 - HKCU\..\Run: [gxdwxhxoj22bf2v4ifsm0i0bbuu8l] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\xvreou4g5.exe
O4 - HKCU\..\Run: [r73gmyk115m] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\eee6vk81g.exe
O4 - HKCU\..\Run: [fo4uxg55zy] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cqphlz24xuff.exe
O4 - HKCU\..\Run: [thb6reyavudemn] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\bv5qjxgi.exe
O4 - HKCU\..\Run: [tr8yvjuct4jvsmta2jlkgz2czscm5b] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\i99f0nfp7.exe
O4 - HKCU\..\Run: [mp1cxf2s70vr22vlb858xpapeu9o7yuhyn7] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\atavc5ip.exe
O4 - HKCU\..\Run: [pa6agq9t5t1uc] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\paac6eg.exe
O4 - HKCU\..\Run: [r1frgmgkb6eh34k8kbwmjl2vy4gg33627] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\qkfaxv07.exe
O4 - HKCU\..\Run: [jz74x0bn2xjbqlkn66normjnblvm] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\tzmujatr8.exe
O4 - HKCU\..\Run: [dka5boixkadgzuxhpr161s] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\en5xfi0yb.exe
O4 - HKCU\..\Run: [yi4qyh307jk] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\xoycw66mv53.exe
O4 - HKCU\..\Run: [cazlv2kmi7jbeei1bkbcdxvqxvlvnd1899j1b5qchxdc21hy] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\lqhv2g8fynmf.exe
O4 - HKCU\..\Run: [vmhd7ncc0h6erx] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\mhmtaxsqzhh3o.exe
O4 - HKCU\..\Run: [urp91l10u67v] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\w9hepqa815m69.exe
O4 - HKCU\..\Run: [tglb4merv9a9c] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\edad9ljhibad8.exe
O4 - HKCU\..\Run: [eltt44khp8podohm23jeu60ndu] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\pftwfc.exe
O4 - HKCU\..\Run: [jg11x5gfguqcjajba2wd4b7pj6wbv9br2z0ymsay3x] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\hw7bml.exe
O4 - HKCU\..\Run: [v2zhuk3te4r6on0jzqlrkvt7zhz2vealbgj] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\xjmcg7.exe
O4 - HKCU\..\Run: [baq56deznbq70xhc] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\mrhwzd97s.exe
O4 - HKCU\..\Run: [hh0lzaznr5mp2zp35jfzlrtw8v6zy] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\i25vmhw.exe
O4 - HKCU\..\Run: [f75to3bmg6hkew7gkrtbv7qan57103e9k7avqm2j7z3ek205pl] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\jlvm9vfduisu.exe
O4 - HKCU\..\Run: [vz3qor92miwajfgr6olisaq5nzxmnz4ewh3y5byew5v9xlmm] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\gpe6fzbi.exe
O4 - HKCU\..\Run: [pxnvtnmiajpk3t6yamcuvsb5b2oiy] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\yobtrl6gevr.exe
O4 - HKCU\..\Run: [boau7687ia5exj7y5f8qy3y0z2uh4cr1myrtt] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\t8e9a1t7yi.exe
O4 - HKCU\..\Run: [ayiq5vc92x3e6472utlwzgmm57gpuj9oo1ti9mkmer1] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\yvr79cltwo.exe
O4 - HKCU\..\Run: [wphdipcyhjlglnn32n2lljth9g] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\txx461hzt7b.exe
O4 - HKCU\..\Run: [hsbck44o6mugylfrpehsdcaor81224wx6t6em] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cvo574n4p.exe
O4 - HKCU\..\Run: [ubd7uqg8hdv] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\gc2nedgte.exe
O4 - HKCU\..\Run: [chsxfcmsmhowgw7v01g] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\dpepyg5ahawd.exe
O4 - HKCU\..\Run: [nupo0bvyqs3adtawj1] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\dux97xa7htj.exe
O4 - HKCU\..\Run: [k9slg4dq24v0555c2zppiiu12h3y8r3tvwcrpgz] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\nhzu68.exe
O4 - HKCU\..\Run: [qgfgtiyj1a6ydjv3pnmjf28tbg08e] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\jk6nb02yq.exe
O4 - HKCU\..\Run: [ytayax7kyefl9ntz3] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\l59n28j5.exe
O4 - HKCU\..\Run: [feh15akleh6gd3o90jrb3yibp28auqaxa6] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\t4qmnlgbupv.exe
O4 - HKCU\..\Run: [mps3wyhau1720] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\h7z9org22jds.exe
O4 - HKCU\..\Run: [nfbcd2z6lmd2w7ixhpqnghgpeuu4lea6ao2j9b0qsnu] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\s0kfagbn516.exe
O4 - HKCU\..\Run: [qdk4mkgqg6h6r5m5xbwx0fh6o7sj6htz0iyz3g1o6dhj67] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\t07qgdhtfjg.exe
O4 - HKCU\..\Run: [bv0e84o1znfkhaewhnckzc6u035cjipls9sg2mg9as] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ctm81hbv1w3u.exe
O4 - HKCU\..\Run: [a78lyyo4jxatfaf2zkrq5gv2tw09xphqmnlmb9wfsmyu42uc] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\jsttkt57h8.exe
O4 - HKCU\..\Run: [aoit5omllae0pbj7r0et94iaxou7ou8yb] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\n8qywnbdnx.exe
O4 - HKCU\..\Run: [ch6ksr6gw6qz0nu04gfq7e3x4e6ydb64mu9i1] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\umb6uwakffc.exe
O4 - HKCU\..\Run: [rgrklzosetdij0u8sp7np4f3fhc4] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\o9ag7frs9lcl.exe
O4 - HKCU\..\Run: [o2onxm0rci3d4x0yarwt44k5jq8lket] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\vi2o8pvw.exe
O4 - HKCU\..\Run: [i46nk4bahuzd2mkwhl1x1exuwsrhufq33zf9u0k] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cwnd6yum0.exe
O4 - HKCU\..\Run: [siymgr2b36iuedw1ff1r3ba55nion] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\t9r3uk.exe
O4 - HKCU\..\Run: [fgxfhnxy7abyjkujm] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\vpi35azy.exe
O4 - HKCU\..\Run: [ui766l39ou8tj] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\iwrbzhmujth.exe
O4 - HKCU\..\Run: [ws3bryxu2opo] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\vux9bt7bo2m.exe
O4 - HKCU\..\Run: [pcoymaywiszvqtsq24p20v1t] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\vqzaoj5.exe
O4 - HKCU\..\Run: [r2d560bek05gacir2] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\md54ukfwtv.exe
O4 - HKCU\..\Run: [y2zqvzevvgnvl0qe5ubijrzd7hpr73xhvudh44] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\jkh4ymvg.exe
O4 - HKCU\..\Run: [mev8kcx4owng84dawtg43moqnsunmc8z30x8g08avv1ylfvfu] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\z7knclaq.exe
O4 - HKCU\..\Run: [frykt685xno] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\egz60s30zlxj.exe
O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
O4 - HKCU\..\Run: [prlx0vheiitdu5vqd7iwsslhr479pn52b] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\drt71b.exe
O4 - HKCU\..\Run: [m0ahudejl45tbn0] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\jvkn6fvr.exe
O4 - HKCU\..\Run: [jfrlyru9qpl6zsi8cgi0d2pqs9a] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\bs3ow7blvp.exe
O4 - HKCU\..\Run: [ln86fwa3epbm9eeqruwoea0zsxcsy5a7gxfz5] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kwjfmzqhmd.exe
O4 - HKCU\..\Run: [hoyg74qktfjzvewr2wz74aae5iaeycgpuix1m] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kxgmruh9yjfr.exe
O4 - HKCU\..\Run: [gj053hp2k54hn09h2re6i7q] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ubkbp3ggqkr7m.exe
O4 - HKCU\..\Run: [g8k6s7uutgvz7jsm8z0fv8ihcminvyp2ey1wl70j8kwts0jb] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\vv4t0ew.exe
O4 - HKCU\..\Run: [nk64ch384wayxt] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\vwk0o96no.exe
O4 - HKCU\..\Run: [e8uahxbv27aqiy2xoatfuv2ns35v41igyrum58] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\fa58mimugf.exe
O4 - HKCU\..\Run: [fiwd27rbg9uz0tu43f5qe5uny3h6ckx5i53j5s2a8vi] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ekxh0wcbrak.exe
O4 - HKCU\..\Run: [p1sqmnk8ryz2k] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\gb8qxa292m8z.exe
O4 - HKCU\..\Run: [vvs8db30ba05dm9rsniy8tb] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\jv5x2o.exe
O4 - HKCU\..\Run: [z3k9h4oyv3o4hjzolc813edo50mv7prp97nal] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\bs9567d1.exe
O4 - HKCU\..\Run: [vt8dth7zuf6] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\s01vxbmf.exe
O4 - HKCU\..\Run: [vfcvgrnv65yrzs386nuumqbea] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ctcnhzagcz.exe
O4 - HKCU\..\Run: [updpriya8c3h2b72u4h88p3azdl580baq8k] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\e8ng4uob6u.exe
O4 - HKCU\..\Run: [ybfcsbkwzf4hn4qxo] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\io1lgobyt0.exe
O4 - HKCU\..\Run: [jemtabcufy] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\onov7yeaa1jg5.exe
O4 - HKCU\..\Run: [vmeq491x67700wds4v7u5n1c89s1kyhdkx39lac4rjn2enk8] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\f5b5n1jfb.exe
O4 - HKCU\..\Run: [daxcl2j2ddywvnjm37lnls] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\mng3bnkkp87z8.exe
O4 - HKCU\..\Run: [tvp084ehpgzf99c7nrgivaoghlhwdj9ajfahb0we39mw9hgdh] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\mszn14py88ut.exe
O4 - HKCU\..\Run: [hlyltimu53giqd86hj887t19vykogyu2tvof] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\sciq3iulnq.exe
O4 - HKCU\..\Run: [eukj05hhd5ohllazvaz7ekr9r9v9xh] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\p2nnx2.exe
O4 - HKCU\..\Run: [qe8db7i7qr02gs697q7jnnjit0tfmlwyyk32sb3krspz2s] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\idipdo.exe
O4 - HKCU\..\Run: [ds8k0ejxl0rv438sxh6kyteh7t6uqdef4tgqxzwyhstomv] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\p7676jiiuk6dc.exe
O4 - HKCU\..\Run: [fy4m3fw733uqe8xldd9clnax1hqq2a1tqsdiupyffytg15] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\xbz67errbquks.exe
O4 - HKCU\..\Run: [vob84ycroeas062t] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\w1u8gx7gawzw.exe
O4 - HKCU\..\Run: [e3cixw66ke7hbhjihlmsbzi1d5myezr1idjflz8r4wz3v] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\h3drmo9sdeind.exe
O4 - HKCU\..\Run: [a1hkcatvo1rumyznxe6] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\zv5za8ypf8.exe
O4 - HKCU\..\Run: [a0pav1dd1xbu9tne7advsowpj] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\yqj4sp2s.exe
O4 - HKCU\..\Run: [feo0qpy07c405mwyb65fl1bu2jgur99ye] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\jzok9j44oqaqn.exe
O4 - HKCU\..\Run: [hkzvfzq2s3azyrpyb35cuingd8x1scff5e] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\o3hjtedd5fyg3.exe
O4 - HKCU\..\Run: [dn522bdhvn8rwog7bia2qppjartqzbad] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\rdv3zuduy.exe
O4 - HKCU\..\Run: [okq8k0vuo4qjsc5ze00c5xjlq] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cfvm54fn13.exe
O4 - HKCU\..\Run: [h0939wxxph0kewj9jpas10b83jmqzomk7knh7s7jpvm] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kjol6zowi9.exe
O4 - HKCU\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [InetChk] C:\WINDOWS\TEMP\ms1234799339.exe work (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZUfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\dhcpmon32.dll,C:\WINDOWS\System32\ersvc32.dll,C:\WINDOWS\System32\ifsutil32.dll,C:\WINDOWS\System32\eventlog32.dll,C:\WINDOWS\System32\igmpagnt32.dll,C:\WINDOWS\System32\cc3250mt32.dll,C:\WINDOWS\System32\devenum32.dll,C:\WINDOWS\System32\cdfview32.dll,C:\WINDOWS\System32\devmgr32.dll,C:\WINDOWS\System32\cdm32.dll,C:\WINDOWS\System32\dfrgres32.dll,C:\WINDOWS\System32\certcli32.dll,C:\WINDOWS\System32\dgnet32.dll,C:\WINDOWS\System32\ciadmin32.dll,C:\WINDOWS\System32\dgrpsetu32.dll,C:\WINDOWS\System32\ciodm32.dll,C:\WINDOWS\System32\dgsetup32.dll,C:\WINDOWS\System32\clbcatq32.dll,C:\WINDOWS\System32\diactfrm32.dll,C:\WINDOWS\System32\cmpbk3232.dll,C:\WINDOWS\System32\digest32.dll,C:\WINDOWS\System32\cmsetACL32.dll,C:\WINDOWS\System32\dimap32.dll,C:\WINDOWS\System32\cnetcfg32.dll,C:\WINDOWS\System32\dinput832.dll,C:\WINDOWS\System32\colbact32.dll,C:\WINDOWS\System32\diskcopy32.dll,C:\WINDOWS\System32\comcat32.dll,C:\WINDOWS\System32\dmdlgs32.dll,C:\WINDOWS\System32\compstu
O20 - Winlogon Notify: 478cb1e8509 - C:\WINDOWS\System32\dhcpmon32.dll
O20 - Winlogon Notify: WinCtrl32 - WinCtrl32.dll (file missing)
O20 - Winlogon Notify: __c00F76EC - C:\WINDOWS\system32\__c00F76EC.dat (file missing)
O21 - SSODL: BoHzKXSRPOfb - {478CB1E9-ED26-1B43-7A53-C3226D5C5BC6} - C:\WINDOWS\system32\uq.dll
O22 - SharedTaskScheduler: erajhsf8743kjrngjnf - {D5BF4552-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\gsdrgfdrrgnd.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe

–
End of file - 21530 bytes
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Ok, here's what happened….nothing. I saved the SDFix and Combofix files to my flash drive as I am working off my laptop. I added the shortcuts of these programs to the desktop of the desktop PC. I double-clicked…nothing. So I tried clicking on the file on my flash drive….nothing. I went into SAFE MODE even though you didn't say to do that at first, thinking the files would open. Nope. I restarted the computer, clicked on a user, and now the desktop is frozen….after several minutes no icons appeared. Is there another way around this? Thanks!
don't run it from the flash drive, save it to the machine and run it that way

do this if it fails

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
So am I not to run SDFix? Also, I thought by sending the file as a shortcut to the desktop from my flash drive would make it "runnable". Is that incorrect? I guess it must first be DL'd to the HD before I can make a shortcut, right?
Ok, now I see what I did wrong. So you only want me to use Combo-Fix at this point? I don't do this in SAFE MODE though, right? That was only for after SDFix…
Ok…haven't heard back from ya but it's ok as I've been doing other things as well…I will do what you said originally with the two files (the new one the Combo-Fix) and get back to you with 3 logs…..SDFix, ComboFix, and a new HJT log. Amber
Well, I tried and tried but the computer kept freezing up so we called it quits. :pullhair: I just did a fresh install of XP to solve the problem. Thank you for trying to help, I really appreciate it. Please close this thread. Thank you! :thumbup: :wavey:
One more question….I was just curious what you saw in the HJT log that made you tell me to run SDFix and ComboFix. Was there a specific program or malware that you saw? What does SDFix and ComboFix help with? Thanks Rorschach. Amber
You had some backdoor infections, some typical stuff

Have a read of this

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read my guide on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI