This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] help please

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I had a trojan in April that I got help here cleaning up. Computer has been somewhat slow lately, but not alarmingly so. Today my hubby came and got me telling me the puter crashed and had started recovery. When recovered I had to re load Mcafee, MS office, my printer. None of my pictures or documents appeared to be in the computer, but I can do searches and find the files - so my stuff is on this computer somewhere. I'm worried I may be re-infected or infected with something else. I did just run a mcafee scan and it identified something called RemAdm-PSkill, which I removed. Here is my Hijack this log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:13:18 PM, on 8/15/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdMgr.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0305201250370959) (0305201250370959mcinstcleanup) - McAfee, Inc. - C:\DOCUME~1\HP_ADM~1.YOU\LOCALS~1\Temp\030520~1.EXE
O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 9556 bytes
Hi wilma1313,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Do you have an HP or Compaq computer? If so, it came installed with HP's Backweb program. Backweb has a file called killwind.exe usually found in the C:\HP\bin folder. McAfee has for some reason started flagging it as RemAdm-PSKill. If your AV deleted the program, I don't think you should be concerned. It isn't likely that it is a program you would ever want/need. The killwind.exe program is a utility for stopping processes. This utility is used by HP or Compaq technicians if they connect remotely to your computer using the Backweb program.

Meanwhile, that doesn't explain the missing files. Let's check a couple things.

Id like to see the log from Malwarebytes' Antimalware. Please start the program, then click on the logs tab. Double click on the .txt file and copy/paste the information here.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hi TomK. Here is the malware log alwarebytes' Anti-Malware 1.40 Database version: 2631 Windows 5.1.2600 Service Pack 2 8/15/2009 7:48:51 PM mbam-log-2009-08-15 (19-48-28).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 248321 Time elapsed: 1 hour(s), 11 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected As for Kaspersky, it was flashing on and off and eventually rearranged my computer screen. My start button ended up top right of the screen instead of bottom left, everything was flashing on and off and you couldn't view the site correctly after over an hour of scanning and 37% done everything froze and had to restart. There was 1 infected file found, it will not let me view or save the report – just says 1 infected file. The whole program is acting weird, and I have to quit messing with it, enable my virus and firewall stuff again, and go to bed. I did disable all that as Kaspersky said to. One thing not mentioned originally. After I posted, I restarted my computer after either adding back some software, or more likely deleting some – dont' actually remember why the restart. Anyway when the puter came back on I had many black dialog boxes with c promt popping up all over the screen and disappearing. It was very weird. Didn't happen when restarted tonight though. Thanks for the help! I can try to run Kaspersky tomorrow night after I get outta work. Maybe it will work better.
wilma1313,

Let's not mess with Kaspersky right now. Let's gather some more information:

Download RootRepeal.zip and unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
I get this message when I went to download. Don't know if that is common, or some weird thing happening because of my computer right now. Will keep trying. bandwidth or page view limit for this site has been exceeded and the page cannot be viewed at this time. Once the site is below the limit, it will once again begin serving as normal.
wilma1313,

Sounds like a site problem rather than a problem with your system.

Here are some updated download locations.

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from one of the following locations and save it to your desktop.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • In the Select Scan dialog, check:
    • Drivers
    • Processes
    • SSDT
    • Hidden Services
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
Hi TomK. No problems tonight, was a site problem this morn. Here are the logs. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/20 20:21 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP2 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0x9B770000 Size: 749568 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0x9A5AA000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: c:\windows\temp\mcmsc_ofxxiw15tiz7eff Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_g0js19w7lgr5bhf Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_gxavee5snqiwnmd Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_qugpj0btxszsota Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_xbbzgxppylyecxa Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_xj7l7cjumlccxhs Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\mcafee_e2kgwj5hbtvohvi Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\mcafee_rz7crbjl3xsbnoj Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\mcmsc_1tqwx49armymqcz Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_6q9pkbh0q9ty2ag Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_8gkdctu8pjruida Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_dh37aaxsnfxzcwh Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\mcmsc_cxes7tuivmbwrje Status: Allocation size mismatch (API: 4096, Raw: 0) DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 21:33:21.32 on Thu 08/20/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1432 [GMT -5:00] AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Messenger\msmsgs.exe C:\Garmin\gStart.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe svchost.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\svchost.exe -k netsvcs C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\wuauclt.exe c:\windows\system\hpsysdrv.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\DISC\DISCover.exe C:\Program Files\DISC\DiscUpdMgr.exe C:\Program Files\DISC\DiscStreamHub.exe C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Internet Explorer\iexplore.exe c:\PROGRA~1\mcafee\msc\mcshell.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [gStart] c:\garmin\gStart.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode mRun: [RTHDCPL] RTHDCPL.EXE mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe mRun: [DMAScheduler] "c:\program files\hp digitalmedia archive\DMAScheduler.exe" mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [] mRun: [PCDrProfiler] mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [Reminder] "c:\windows\creator\Remind_XP.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll Trusted Zone: trymedia.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-7-8 214024] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-8-28 210216] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-6-29 359952] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-6-29 144704] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-6-29 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-6-29 35272] S2 navapsvc;Norton AntiVirus Auto-Protect Service;"c:\program files\norton internet security\norton antivirus\navapsvc.exe" –> c:\program files\norton internet security\norton antivirus\navapsvc.exe [?] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-8-15 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-6-29 40552] S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-6-29 606736] =============== Created Last 30 ================ 2009-08-20 20:20 0 a——- c:\documents and settings\hp_administrator.your-4dacd0ea75\settings.dat 2009-08-18 04:46 268,648 a——- c:\windows\system32\mucltui.dll 2009-08-18 04:46 208,744 a——- c:\windows\system32\muweb.dll 2009-08-18 04:46 27,496 a——- c:\windows\system32\mucltui.dll.mui 2009-08-16 18:15 17,536 a——- c:\windows\system32\drivers\grmn0200.sys 2009-08-16 18:15 16,512 a——- c:\windows\system32\drivers\grmn0400.sys 2009-08-16 18:15 11,776 a——- c:\windows\system32\drivers\grmn1200.sys 2009-08-16 13:58 –d—– c:\windows\system32\CatRoot_bak 2009-08-15 21:29 –dsh— c:\documents and settings\hp_administrator.your-4dacd0ea75\IECompatCache 2009-08-15 21:27 –dsh— c:\documents and settings\hp_administrator.your-4dacd0ea75\PrivacIE 2009-08-15 21:25 –dsh— c:\documents and settings\hp_administrator.your-4dacd0ea75\IETldCache 2009-08-15 19:59 272,128 ——– c:\windows\system32\drivers\bthport.sys 2009-08-15 19:59 272,128 ——– c:\windows\system32\dllcache\bthport.sys 2009-08-15 19:58 2,136,064 ——– c:\windows\system32\dllcache\ntkrnlmp.exe 2009-08-15 19:58 2,180,480 ——– c:\windows\system32\dllcache\ntoskrnl.exe 2009-08-15 19:58 2,015,744 ——– c:\windows\system32\dllcache\ntkrpamp.exe 2009-08-15 19:58 2,057,728 ——– c:\windows\system32\dllcache\ntkrnlpa.exe 2009-08-15 19:57 453,632 ——– c:\windows\system32\dllcache\mrxsmb.sys 2009-08-15 19:55 –d—– c:\windows\system32\PreInstall 2009-08-15 19:22 518 a——- c:\windows\FdlistDA.EQS 2009-08-15 18:27 –d—– c:\docume~1\hp_adm~1.you\applic~1\Printer Info Cache 2009-08-15 18:20 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-15 18:20 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-15 18:20 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-15 17:09 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll 2009-08-15 17:09 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll 2009-08-15 17:09 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll 2009-08-15 17:09 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2009-08-15 17:09 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll 2009-08-15 17:09 101,376 ——– c:\windows\system32\dllcache\iecompat.dll 2009-08-15 16:51 25,856 a——- c:\windows\system32\drivers\usbprint.sys 2009-08-15 16:51 31,616 a——- c:\windows\system32\drivers\usbccgp.sys 2009-08-15 16:46 –d—– c:\windows\system32\SoftwareDistribution 2009-08-15 16:26 –d—– c:\windows\system32\LogFiles 2009-08-15 16:19 7,123 a——- c:\windows\system32\Config.MPF 2009-08-15 16:18 –dshr– c:\windows\system32\dllcache 2009-08-15 16:16 120,136 a——- c:\windows\system32\drivers\Mpfp.sys 2009-08-15 16:13 34,248 a——- c:\windows\system32\drivers\mferkdk.sys 2009-08-15 15:35 –d—– c:\windows\system32\wbem\Repository 2009-08-15 15:34 –d—– c:\docume~1\hp_adm~1.you\applic~1\Symantec 2009-08-15 15:33 –d—– c:\docume~1\hp_adm~1.you\applic~1\HPQ 2009-08-15 15:18 –dsh— c:\documents and settings\hp_administrator.your-4dacd0ea75\UserData 2009-08-15 15:11 204,800 a——- c:\windows\system32\HPZipr12.dll 2009-08-15 15:11 94,208 a——- c:\windows\system32\HPZipt12.dll 2009-08-15 15:11 69,632 a——- c:\windows\system32\HPZipm12.exe 2009-08-15 15:11 65,536 a——- c:\windows\system32\HPZinw12.exe 2009-08-15 15:11 57,344 a——- c:\windows\system32\HPZisn12.dll 2009-08-15 15:11 278,584 a——- c:\windows\system32\HPZidr12.dll 2009-08-15 15:08 16,496 a—-r– c:\windows\system32\drivers\HPZipr12.sys 2009-08-15 15:08 49,664 a—-r– c:\windows\system32\drivers\HPZid412.sys 2009-08-15 15:08 77,824 a—-r– c:\windows\system32\HPZIDS01.dll 2009-08-15 15:08 38,400 a——- c:\windows\system32\hpz3l054.dll 2009-08-15 15:06 282,624 a—-r– c:\windows\system32\HPZc3212.dll 2009-08-15 15:06 21,568 a—-r– c:\windows\system32\drivers\HPZius12.sys 2009-08-15 15:06 254,026 a—-r– c:\windows\system32\hpovst09.dll 2009-08-15 15:06 827,392 a—-r– c:\windows\system32\hpotiop2.dll 2009-08-15 15:06 659,456 a—-r– c:\windows\system32\hpowiax2.dll 2009-08-15 15:06 15,104 a——- c:\windows\system32\drivers\usbscan.sys 2009-08-15 15:06 15,104 a——- c:\windows\system32\dllcache\usbscan.sys 2009-08-15 15:06 –dsh— C:\cmdcons 2009-08-15 15:06 –d—– c:\windows\setupupd 2009-08-15 15:03 1,953 a–shr– c:\windows\system32\drivers\103C_HP_CPC_RC663AA-ABA a1640n_YC_0Pavi_QMXF636_E64NAemMPA3_48_IBuckeye_SASUSTek Computer INC._V1.05_B3.16_T070430_WXP2_L409_M2039_J250_7Intel_8Core2 6300_91.87_#061121_N8086104C_Z14F12F20_G808629A2.MRK 2009-08-15 14:59 61,480 a——- c:\documents and settings\hp_administrator.your-4dacd0ea75\GoToAssistDownloadHelper.exe 2009-08-15 14:59 –d—– c:\docume~1\hp_adm~1.you\applic~1\Malwarebytes 2009-08-15 14:59 –d—– c:\docume~1\hp_adm~1.you\applic~1\Intuit 2009-08-15 14:59 –d—– c:\documents and settings\hp_administrator.your-4dacd0ea75\WINDOWS 2009-08-15 14:59 –d—– c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75 ==================== Find3M ==================== 2009-08-15 15:17 118,704 a——- c:\windows\hpoins09.dat 2009-08-05 04:11 204,800 ——– c:\windows\system32\mswebdvd.dll 2009-08-05 04:11 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll 2009-07-29 10:23 119,808 ——– c:\windows\system32\t2embed.dll 2009-07-29 10:23 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-07-28 23:53 82,432 ——– c:\windows\system32\fontsub.dll 2009-07-28 23:53 82,432 ——– c:\windows\system32\dllcache\fontsub.dll 2009-07-19 18:48 11,067,392 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-19 08:18 5,937,152 ——– c:\windows\system32\dllcache\mshtml.dll 2009-07-17 13:55 58,880 a——- c:\windows\system32\atl.dll 2009-07-17 13:55 58,880 ——– c:\windows\system32\dllcache\atl.dll 2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 10:08 286,720 ——– c:\windows\system32\dllcache\wmpdxm.dll 2009-07-13 10:08 5,537,792 ——– c:\windows\system32\dllcache\wmp.dll 2009-07-10 08:42 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-07-08 13:44 214,024 a——- c:\windows\system32\drivers\mfehidk.sys 2009-07-08 13:44 79,816 a——- c:\windows\system32\drivers\mfeavfk.sys 2009-07-08 13:44 40,552 a——- c:\windows\system32\drivers\mfesmfk.sys 2009-07-08 13:44 35,272 a——- c:\windows\system32\drivers\mfebopk.sys 2009-07-03 12:09 915,456 a——- c:\windows\system32\wininet.dll 2009-07-03 12:09 915,456 ——– c:\windows\system32\dllcache\wininet.dll 2009-07-03 12:09 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll 2009-07-03 12:09 206,848 ——– c:\windows\system32\dllcache\occache.dll 2009-07-03 12:09 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll 2009-07-03 12:09 184,320 ——– c:\windows\system32\dllcache\iepeers.dll 2009-07-03 12:09 386,048 ——– c:\windows\system32\dllcache\iedkcs32.dll 2009-07-03 06:01 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-25 03:44 298,496 a——- c:\windows\system32\kerberos.dll 2009-06-25 03:44 168,448 a——- c:\windows\system32\schannel.dll 2009-06-25 03:44 133,632 a——- c:\windows\system32\msv1_0.dll 2009-06-25 03:44 59,392 a——- c:\windows\system32\wdigest.dll 2009-06-25 03:44 56,320 a——- c:\windows\system32\secur32.dll 2009-06-25 03:44 724,480 ——– c:\windows\system32\lsasrv.dll 2009-06-25 03:44 724,480 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 03:44 298,496 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 03:44 168,448 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 03:44 133,632 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 03:44 59,392 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-25 03:44 56,320 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-22 06:49 117,248 a——- c:\windows\system32\mqtgsvc.exe 2009-06-22 06:49 19,968 a——- c:\windows\system32\mqbkup.exe 2009-06-22 06:49 117,248 ——– c:\windows\system32\dllcache\mqtgsvc.exe 2009-06-22 06:49 19,968 ——– c:\windows\system32\dllcache\mqbkup.exe 2009-06-22 06:49 4,608 a——- c:\windows\system32\mqsvc.exe 2009-06-22 06:49 4,608 ——– c:\windows\system32\dllcache\mqsvc.exe 2009-06-22 06:48 91,776 a——- c:\windows\system32\drivers\mqac.sys 2009-06-22 06:48 91,776 ——– c:\windows\system32\dllcache\mqac.sys 2009-06-22 06:34 92,544 ——– c:\windows\system32\drivers\ksecdd.sys 2009-06-22 06:34 92,544 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-12 06:50 80,896 ——– c:\windows\system32\tlntsess.exe 2009-06-12 06:50 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe 2009-06-12 06:50 76,288 ——– c:\windows\system32\telnet.exe 2009-06-12 06:50 76,288 ——– c:\windows\system32\dllcache\telnet.exe 2009-06-10 09:21 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-06-10 09:21 84,992 ——– c:\windows\system32\avifil32.dll 2009-06-10 01:32 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-10 01:32 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll 2009-06-05 02:42 655,872 ——– c:\windows\system32\mstscax.dll 2009-06-05 02:42 655,872 ——– c:\windows\system32\dllcache\mstscax.dll 2009-06-03 14:24 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 14:24 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll ============= FINISH: 21:33:42.40 ===============

Attachments:

wilma1313,

This is from your event viewer:

The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.

I suggest that you do that.

Shut down all programs.

  • Click Start, and then Run.
  • In Open, type cmd, and then press ENTER.
  • type chkdsk C:/r, and then press ENTER.

Let this run undisturbed.

Let me know what it is says when it is done.
Is there anyway to find out what it said after that scan? I went to bed before it finished figuring the info would be on screen when I got up and its not. Didn't realize I had to be sitting here to see it. Also before doing the scan, on start I had black boxes open again, only 2 this time. One was empty and 2 said something about an error which I didn't catch before it disappeared.
wilma1313, Sorry. I thought it would give you a results screen that you would have to press any key to continue. What I want is a clean run. If it found errors to fix, I would want you to run it again until you get a clean run. So… would you please run it again and verify no errors?
Hi, I can't get this last task done. I tried again this morning and it finished faster than I anticipated, so I missed the results. Tonight I scanned again and was able to catch the end. The results display for about 3 seconds and then the system restarts. I was sitting here with a pen and paper and it doesn't stay up long enough to even read the screen. No clue what the results of the scan are, there was a whole screen of information but no time to see it. What else can be done? Thanks
wilma1313,

Let's move forward.

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 13

Then please give me new DDS logs.
wilma1313,

Let's not worry about installing the updated Java for a little bit.

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

Then go ahead and run DDS and post the logs.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI