This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help Please!

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Still could not get ravantivirus to run.

Logfile of HijackThis v1.98.2
Scan saved at 9:51:47 AM, on 11/21/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\khooker.exe
C:\Program Files\Caere\OmniPagePro90\opware32.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\PCI Audio Applications\Mixer.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows CE Services\WCESCOMM.EXE
C:\Program Files\Franklin Electronic Publishers\eBookMan Desktop Manager\EbmMgr.exe
C:\Program Files\PrintKey2000\Printkey2000.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Franklin Electronic Publishers\eBookMan Desktop Manager\webcomp\webcomp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
C:\WINDOWS\System32\ofps.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HighJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\Dual Wheel Mouse\4dmain.exe
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [OmniPage] C:\Program Files\Caere\OmniPagePro90\opware32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Mixer.exe /startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Windows CE Services\WCESCOMM.EXE"
O4 - Startup: Mobipocket Web Companion.lnk = C:\Program Files\Franklin Electronic Publishers\eBookMan Desktop Manager\webcomp\webcomp.exe
O4 - Global Startup: eBookMan Monitor.lnk = ?
O4 - Global Startup: Printkey2000.lnk = C:\Program Files\PrintKey2000\Printkey2000.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Windows CE Services\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Windows CE Services\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Windows CE Services\INetRepl.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://pubgis.co.pinellas.fl.us/ActiveX/ver6/mgaxctrl.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - file://E:\Bin\html\files\MotivePreQual.cab

Thanks again for your expertise.
offfni
Ok, those scans look good. The "suspicious entries" in the RKDetector log are all related to TrojanHunter and NAV, they have to do with the methods those programs use to protect themselves and other legitimate processes on your computer.

You have run some good scanners and, although some would not work properly, no malware problems were found. At this point we will proceed as if the problem is not caused by malicious software but rather by a problem with your system.

The first thing to do is let the system check itself for problems. I believe when you tried the System File Checker utility earlier that the problem may have been improper syntax when entering the command. Please follow this procedure:

First
Insert the Windows XP Installation CD into your CD drive (this is a single CD, not the restore CD set that comes with a new computer). If it autoruns just close the window that opens.

Next
You can enter the following command in the run box (Start>Run) or at the command prompt (Start>All Programs>Accesories>Command Prompt).
Notice that there is a space between the letter "C" and the "/".

SFC /SCANNOW

If you cannot access the CD from the malfunctioning computer then copy the I386 folder from it to your removable drive, it is about 475MB. If you only have a factory install CD set then look for an I386 folder on it and copy that to your thumb drive. When you tell the SFC dialog box where to find the information point it at the folder or drive that contains the I386 folder, not directly at the folder itself (you need to be one level up from it). For example, you would use only the bold portion of the following paths.
C:\I386
C:\Windows\temp\I386
You can point it to the CD in the same way without copying the files to another drive if your computer is accessing the CD ok.

Shortly before the problem started had you installed any programs or done any program or windows updates? Did you have any problems where the power was interuppted or you had to manually shut down windows (by holding in the power button or unplugging the computer)?
rand1038, found the file on the CD, could not move it to anywhere, multiple tries. Cannot run sfc /scannow from the run choice, doesn't respone to the command. Could not run from command prompt, doesn't respond. Found i386 on the CD but cannot move it anywhere. History of computer. Had Bagel and cleared it first of this year. reinstalled XP and the computer ran without a problem. Suddenly started losing things. Ability to send E-mail,can receive. Cannot print from IE. Task bars missing. Unable to link from anywhere. Did not download or install anything prior to this happening. For a long time ads on MSN home would not load, text would. Now the ads load. The only thing downloaded since the begining of the problem is scan files or files related to viruses or fixing virus.problem. Also cannot move files from one place to another. Initially had to get HJT on a removable drive then it was a while before I could cut and paste the scan to HJT. This is why I assumed it was malware related. offfni
rand1038, found the file on the CD, could not move it to anywhere, multiple tries. Cannot run sfc /scannow from the run choice, doesn't respone to the command. Could not run from command prompt, doesn't respond. Found i386 on the CD but cannot move it anywhere. History of computer. Had Bagel and cleared it first of this year. reinstalled XP and the computer ran without a problem. Suddenly started losing things. Ability to send E-mail,can receive. Cannot print from IE. Task bars missing. Unable to link from anywhere. Did not download or install anything prior to this happening. For a long time ads on MSN home would not load, text would. Now the ads load. The only thing downloaded since the begining of the problem is scan files or files related to viruses or fixing malware problems. Also cannot move files from one place to another. Initially had to get HJT on a removable drive then it was a while before I could cut and paste the scan to HJT. This is why I assumed it was malware related. offfni
As I was leaving the computer I decided to try run again and it ran sfc /scannow from the same entry as before. When it finished nothing showed on the screen. Is there a log somewhere. Guess nothing was found because nothing was relayed. This is one of the reasons I thought it was malware, things work or don't work with no relation to happenings. This was the first time run has worked in over two months. Going to try search because it dodn't work either.
If System File Checker (SFC) was able to access the files it needs, it will not show anyting beyond the progress dialog. Are you able to use regedit? If you cannot get to it from the run box (by typing regedit), you can go to C:\windows\system32\regedit.exe and double click the file to run it. Let me know if that works as we will want to take a look at some registry settings. If it doesn't work, try REGEDT32.exe and see if that does (notice the missing "I") Does the computer run any better since running the System File Checker?
rand1038,
When I started the computer today it appears to be faster. The open sites at the bottom has returned, I can access my assistant, and several other problems have disappared or appared. I'm still trying things out.

Latest HJT log.
Logfile of HijackThis v1.98.2
Scan saved at 5:48:06 PM, on 11/22/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\System32\ofps.exe
C:\Program Files\Caere\OmniPagePro90\opware32.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\PCI Audio Applications\Mixer.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Windows CE Services\WCESCOMM.EXE
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Franklin Electronic Publishers\eBookMan Desktop Manager\EbmMgr.exe
C:\Program Files\PrintKey2000\Printkey2000.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Franklin Electronic Publishers\eBookMan Desktop Manager\webcomp\webcomp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HighJackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\Dual Wheel Mouse\4dmain.exe
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [OmniPage] C:\Program Files\Caere\OmniPagePro90\opware32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Mixer.exe /startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Windows CE Services\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Mobipocket Web Companion.lnk = C:\Program Files\Franklin Electronic Publishers\eBookMan Desktop Manager\webcomp\webcomp.exe
O4 - Global Startup: eBookMan Monitor.lnk = ?
O4 - Global Startup: Printkey2000.lnk = C:\Program Files\PrintKey2000\Printkey2000.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Windows CE Services\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Windows CE Services\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Windows CE Services\INetRepl.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://pubgis.co.pinellas.fl.us/ActiveX/ver6/mgaxctrl.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - file://E:\Bin\html\files\MotivePreQual.cab
I see that you are running eTrust, Norton and Zone Alarm. Judging from your running processes you have two firewalls and two antivirus running. That is generally not a good idea. What exactly is the configuration you are using for these programs? It is possible that this could be contributing to your problems and certainly will slow down your computer's performance and internet surfing. All those programs load system drivers at boot time which will increase the time it takes windows to boot and could cause conflicts resulting in other problems. I recommend that you disable eTrust and Zone Alarm from running at startup (go to the program options in each programs control panel and uncheck the option to load at system start (boot). I am not giving any recommendation here as to which of these programs is the best to use but given that you have Norton's AV and Firewall enabled it would be easiest to leave that as is and disable the other two for now. Keep us posted on how everything is working. If you are still having problems please be as specific as possible about what they are and when they occur. I'm glad to hear that things seem to be running better.
Rand1038, Most of the computer is back, could even use the e-mail link to get here. Zone Alarm and e-trust are my usual virus and firewall. norton was put on to help when the problems started and I was unable to remove it. It was not activated according to their scans. Still curious as to what started this. Things didn't happen in a short time but little problems started or would slow things down until they didn' work at all. Panda scan that never was able to run, would freeze the screen, ran today but found nothing. Things came and went like sfc /scannow did yesterday, al of a sudden it worked. This would happen to other programs in no order, one day they worked the next day they wouldn't, then it would reverse. Any suggestions as to what happenend. Thanks again for your time and expertise. offfni
Went back and read your prevous post and according to the computer norton firewall and virus are not activated. would not scan for virus with one button scan. Could this be a problem or glich.
It is possibly a glitch. If Zone Alarm and eTrust are working properly then configure norton to not start automatically. I think that with ZA and eTrust running, you really don't need Nortons Firewall or AV features. How is everything else working?
rand1038, Checked NAV and it was not turned on, system was but av was not. Does the scan say something different? Everything seems to be working as far as I know. Slightly slower than normal but much faster than before wyou fixed the problem. Still want to know if you can give a reason for the actions of the computer if it was not malware, and how can I prevent this from happeneing again. Many thanks again for your and siggyx's time and expertise. offfni

Still curious as to what started this. Things didn't happen in a short time but little problems started or would slow things down until they didn' work at all.

Thats hard to say offni. It is possible that a system file got corrupted and things snowballed from there. Narrowing something like this down to a root cause so long after it started is virtually impossilble.

Checked NAV and it was not turned on, system was but av was not. Does the scan say something different?

There are some files running that suggest that NAV is active. It may be worth uninstalling Norton and then using selective install to only install the parts you use (selecting not to install any AV or Firewall components). Create a new System Restore point before doing so (Start>Programs>Accessories>System Tools>System Restore, select the Create a Restore Point button).

As far a prevention goes, here are some tips.

Many of the programs that peoples computers become infected with use vulnerabilities that are discovered in the Windows Operating System. Microsoft issues patches to fix these problems as they are discovered so one of the most important keys to keeping your computer clean is visiting Windows Update on a regular basis.

I recommend you read How did I get infected in the first place and follow Tony's advice. He will tell you about some ways to make your computer more secure and link to some excellent free tools to help with that.

Beware of programs that say they will clean your registry or fix problems for you. These type of programs can cause more problems than they fix. Only use them if advised to do so by someone you trust as a competant computer advisor.

Some things you can do to help keep things running smooth are to visit windows update at least once a week to see if there are any updates, scan often with your antivirus, spybot s&d and ad-aware and empty your temp files on a regular basis.
I use System Security Suite to help keep things cleaned up. I set it up like this. Notice I don't check mark Auto Completed Forms or Auto Completed Passwords.

[external image: Posted Image]

Run it before you install a new program or scan for problems (it will make the scan faster too, less files to be checked).

Make sure you have System Restore enabled.

Glad to have been able to help you offni. :D
rand1038, You were right NAV did finally show up on a boot. Gone now. Everything seems to be working. Some things slower than I remember, and somethings faster. Will follow your suggestions for prevention. Any last assignments? How can I get you if something happens? Thanks again for your time and expertise, and please make sure siggyx gets a thank you also. A token for the cause will be comming. offfni

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI