This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Help

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.0

Scan saved at 6:19:05 PM, on 1/23/05

Platform: Windows 98 Gold (Win9x 4.10.1998)

MSIE: Internet Explorer v5.00 (5.00.2314.1000)

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL

C:\WINDOWS\SYSTEM\MSGSRV32.EXE

C:\WINDOWS\SYSTEM\MPREXE.EXE

C:\WINDOWS\SYSTEM\mmtask.tsk

C:\WINDOWS\SYSTEM\MSTASK.EXE

C:\WINDOWS\SYSTEM\SA3DSRV.EXE

C:\COMPAQ\ACCESS\ENCOMPASS\MONITOR.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM\DDHELP.EXE

C:\WINDOWS\TASKMON.EXE

C:\MOUSE\SYSTEM\EM_EXEC.EXE

C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEAUI.EXE

C:\COMPAQ\INTERNET\CISRVR.EXE

C:\WINDOWS\SYSTEM\FBYZAWN.EXE

C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE

C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE

C:\WINDOWS\SYSTEM\RNAAPP.EXE

C:\WINDOWS\SYSTEM\TAPISRV.EXE

C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE

C:\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://if.searchcentrix.com/sidecat.jsp?p=…052494158141113

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirec…&s=search&i=enu

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirec…&s=search&i=enu

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirec…&s=search&i=enu

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://if.searchcentrix.com/sidecat.jsp?p=…052494158141113

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

O2 - BHO: GSIM - {4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} - C:\WINDOWS\GSIM.DLL

O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\SYSTB.DLL

O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGRAB.DLL

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun

O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe

O4 - HKLM\..\Run: [SystemTray] SysTray.Exe

O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

O4 - HKLM\..\Run: [Essdc] essdc.exe

O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe

O4 - HKLM\..\Run: [AtiKey] Atitask.exe

O4 - HKLM\..\Run: [SXGDSENU] SXGDSENU.exe

O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe

O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe /NORESTART

O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe

O4 - HKLM\..\Run: [CPQEASYACC] "C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\Cpqeaui.exe"

O4 - HKLM\..\Run: [Compaq Internet Setup] C:\Compaq\Internet\InetWizard.exe /RUN

O4 - HKLM\..\Run: [CISrvr Program] C:\COMPAQ\INTERNET\CISRVR.EXE

O4 - HKLM\..\Run: [CPQ BackWeb Monitor] C:\CPQS\TOOLS\BackMon.exe

O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\McAfee\VirusScan\VSECOMR.EXE

O4 - HKLM\..\Run: [OEMCLEANUP] c:\windows\OPTIONS\oemreset.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe

O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe

O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\SYSTEM\scchost.exe

O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe

O4 - HKLM\..\Run: [phqhqtkbxbe] C:\WINDOWS\SYSTEM\fbyzawn.exe

O4 - HKLM\..\Run: [BELT] C:\WINDOWS\BELT.exe

O4 - HKLM\..\Run: [WebRebates0] "C:\PROGRAM FILES\WEB_REBATES\WebRebates0.exe"

O4 - HKLM\..\Run: [satmat] C:\WINDOWS\SATMAT.exe

O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe

O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe

O4 - HKLM\..\RunServices: [EncMonitor] c:\compaq\access\Encompass\Monitor.exe

O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe

O4 - HKCU\..\Run: [DPNADDR] C:\WINDOWS\SYSTEM\DPNADDR.EXE

O4 - HKCU\..\Run: [MSFS32] C:\WINDOWS\SYSTEM\MSFS32.EXE

O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

O4 - Startup: Microsoft Find Fast.lnk = ..\..\..\..\Program Files\Microsoft Office\Office\FINDFAST.EXE

O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

O8 - Extra context menu item: Ebates - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm

O8 - Extra context menu item: Web Rebates - file://C:\PROGRAM FILES\WEB_REBATES\Sy1150\Tp1150\scri1150a.htm

O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm

O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm

O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)

O12 - Plugin for .bat: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll

O12 - Plugin for .mov: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPQTW32.DLL

O12 - Plugin for .exe: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll

O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPSWF32.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp

O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/downlo…19106/flash.cab

O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
Hi Jim, Welcome to TomCoyote forums. It is nice to know what your problem is, gives us something to look for. Thanks.

1) Please use notepad instead of wordpad to save your log so it will not be double spaced.

2) Your browser, Internet Explorer is outdated and thus less safe. I suggest you visit Windows Updates via IE > Tools > Windows Updates and then download and install all critical updates suggested by Windows.

3) I see no Antivirus software running in the log, if my observations are correct, please download and install one of the free versions in the following links. I suggest the first one, AVG.
http://free.grisoft.com/freeweb.php
http://www.avast.com/eng/avast_4_home.html
http://store.ca.com/dr/v2/ec_main.entry25?…5715&CID=179825

4) I see no firewall running either, if this is correct I strongly suggest you install one. Here are some free ones, and I suggest ZoneAlarm.
http://www.zonelabs.com/store/content/comp…reeDownload.jsp
http://smb.sygate.com/products/spf_standard.htm

5) I want to be sure you are posting the complete log. Look at the bottom and make sure there is nothing below this item:
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
That is being cut off when you copy/paste to the thread.

6) You do have a large about of adware on board, please follow these directions:
We need to run our big guns for cleaning out malware. Ad-aware and Spybot can get the areas we can't reach with the HJT tool. I am going to give you links to tutorials and it is important that you take the time to review the information, then to download, update, configure exactly as in the tutorials and remove what is suggested in the tutorials. Make notes of anything these two programs can't remove, the exact name and location of the item. Run Spybot first, if you receive any DSO Exploit notifications, ignore them and please do not activate TeaTimer at this time, once you are clean you may activate it. If Spybot removes anything reboot before running Ad-aware SE Personal.
Spybot:
http://www.bleepingcomputer.com/forums/tutorial43.html
Ad-aware:
http://www.bleepingcomputer.com/forums/tutorial48.html

7) Run this free online virus/trojan scan and if it locates anything have it clean or fix all items. If there is anything that can't be fixed, please note that as well as anything the two scans above could not remove.
http://www.pandasoftware.com/activescan/co…n_principal.htm

8) Run clean manager, remove all the Temp files and Temp internet files located, empty the recycle bin and restart the computer. Use the following two links for information about how to stay in this same thread.
When replying to your topic, please use the
http://forums.tomcoyote.org/style_images/1/t_reply.gif
button NOT the
http://forums.tomcoyote.org/style_images/1/t_new.gif
button.
Using notepad, post a new log along with any information from that scans and any feedback you think we should have.

Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php
Thanks for the reply. I am doing this third party. The infected computer belongs to my sister. She is able to email but nothing else. The browser will not search or download and gives a "invalid argument" error. Windows Explorer has also been effected and will not copy, paste or move files. The only way I could get the Hijack This software on the computer was to copy the file from disk using DOS commands. I emailed her Spybot .exe installation program. Hopefully she will be able to install it. I will have her check the last line on the log to see if anything was missed. Your further assistance will be greatly appreciated. Thanks - Jim
OK, Jim, I can relate, my sister is visiting me now. You can see why she is having problems. Even though we much prefer to use the automated tools as they get to areas HJT can not, I will help you out and do a removal of what I can. This would probably free her up to download, etc. I would suggest to her to stay offline as much as possible until she gets an antivirus program in place, and AVG by Grisoft is a good free one. The firewall can wait a little (do it asap) Zone Alarm is free and I run it on all of my computers and install it on any clients who need a free one. Basically I am saying if you can get AVG installed to give her some protections, then let me know if that is a complete log and I will give you instructions for a manual removal. We can remove enough so she can function then you can work on the other issues. Ad-aware and Spybot should still be installed and run along with the online scan as soon as possible. Keep me posted, I will set up removal instructions for HJT a little later in the day. Thanks…pskelley
Here is the log file since running Spybot:

Logfile of HijackThis v1.99.0
Scan saved at 7:11:06 PM, on 1/25/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.00 (5.00.2314.1000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SA3DSRV.EXE
C:\COMPAQ\ACCESS\ENCOMPASS\MONITOR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEAUI.EXE
C:\COMPAQ\INTERNET\CISRVR.EXE
C:\WINDOWS\SYSTEM\FBYZAWN.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS
SHARED\WKCALREM.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://if.searchcentrix.com/sidecat.jsp?p=…052494158141113
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
=
http://red.clientapps.yahoo.com/customize/…gr6/*http://www.
yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://if.searchcentrix.com/sidecat.jsp?p=…052494158141113
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/…gr6/*http://www.
yahoo.com
O2 - BHO: GSIM - {4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} -
C:\WINDOWS\GSIM.DLL
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} -
C:\WINDOWS\SYSTB.DLL (file missing)
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} -
C:\WINDOWS\BTGRAB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no
file)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Essdc] essdc.exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [SXGDSENU] SXGDSENU.exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button
Support\eaclean.exe /NORESTART
O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe
O4 - HKLM\..\Run: [CPQEASYACC] "C:\PROGRAM FILES\COMPAQ\EASY ACCESS
BUTTON
SUPPORT\Cpqeaui.exe"
O4 - HKLM\..\Run: [Compaq Internet Setup]
C:\Compaq\Internet\InetWizard.exe
/RUN
O4 - HKLM\..\Run: [CISrvr Program] C:\COMPAQ\INTERNET\CISRVR.EXE
O4 - HKLM\..\Run: [CPQ BackWeb Monitor] C:\CPQS\TOOLS\BackMon.exe
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program
Files\McAfee\VirusScan\VSECOMR.EXE
O4 - HKLM\..\Run: [OEMCLEANUP] c:\windows\OPTIONS\oemreset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\SYSTEM\scchost.exe
O4 - HKLM\..\Run: [phqhqtkbxbe] C:\WINDOWS\SYSTEM\fbyzawn.exe
O4 - HKLM\..\Run: [BELT] C:\WINDOWS\BELT.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\PROGRAM
FILES\WEB_REBATES\WebRebates0.exe"
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\SATMAT.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe
O4 - HKLM\..\RunServices: [EncMonitor]
c:\compaq\access\Encompass\Monitor.exe
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft
Money\System\reminder.exe
O4 - HKCU\..\Run: [DPNADDR] C:\WINDOWS\SYSTEM\DPNADDR.EXE
O4 - HKCU\..\Run: [MSFS32] C:\WINDOWS\SYSTEM\MSFS32.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program
Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Microsoft Find Fast.lnk = ..\..\..\..\Program
Files\Microsoft
Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program
Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O8 - Extra context menu item: Web Rebates - file://C:\PROGRAM
FILES\WEB_REBATES\Sy1150\Tp1150\scri1150a.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program
Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} -
file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm
(file
missing) (HKCU)
O12 - Plugin for .bat: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O12 - Plugin for .mov: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\NPQTW32.DLL
O12 - Plugin for .exe: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O12 - Plugin for .swf: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\NPSWF32.dll
O14 - IERESET.INF:
SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} -
http://download.abetterinternet.com/downlo…19106/flash.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} -
file://c:\counter.cab
Jim, I am going to give you the malware fix with HJT. I am online now as you can see in the event you have any questions, since you will have to guide her through it. Once she has completed the steps, a new log will let us know what is left to be done. Mention to her is something is not there it was removed by Spybot. I also need to mention that I can't see Spybot in the log? Thanks…pskelley


Hi Jim, There is quite a bit to remove manually, make sure she knows it is very important to follow the directions completely. This computer is very infected with adware and trojan/viruses.

We need to stop the running processes, click on Ctrl, Alt and Delete at the same time to open Task Manager, then highlite and end process on each of these items:
FBYZAWN.EXE
scchost.exe (be careful, make sure it is this exact spelling: SCChost.exe)
wupdt.exe
Alive SYstem
Win Server Updt
phqhqtkbxbe
BELT
BELT.exe
WEB_REBATES
SATMAT.exe
DPNADDR
MSFS32
FINDFAST.EXE
(anything that looks like any of these)

We need to enable hidden files, use the following link to do this for this Operating System:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Scan with HijackThis and put a check in front of each of these line items, careful not to miss any:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://if.searchcentrix.com/sidecat.jsp?p=…052494158141113
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirec…&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirec…&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirec…&s=search&i=enu
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://if.searchcentrix.com/sidecat.jsp?p=…052494158141113
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: GSIM - {4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} - C:\WINDOWS\GSIM.DLL
SearchCentrix adware variant
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\SYSTB.DLL
IEPlugin variant
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGRAB.DLL
Transponder variant
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\SYSTEM\scchost.exe
Added as a result of the KEYLOGGER.BC VIRUS!
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
IEPlugin adware
O4 - HKLM\..\Run: [phqhqtkbxbe] C:\WINDOWS\SYSTEM\fbyzawn.exe
(does not identity, as such is a random named trojan)
O4 - HKLM\..\Run: [BELT] C:\WINDOWS\BELT.exe
searchv.com Spyware
O4 - HKLM\..\Run: [WebRebates0] "C:\PROGRAM FILES\WEB_REBATES\WebRebates0.exe"
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\SATMAT.exe
Transponder parasite updater/installer
O4 - HKCU\..\Run: [DPNADDR] C:\WINDOWS\SYSTEM\DPNADDR.EXE
O4 - HKCU\..\Run: [MSFS32] C:\WINDOWS\SYSTEM\MSFS32.EXE
O4 - Startup: Microsoft Find Fast.lnk = ..\..\..\..\Program Files\Microsoft Office\Office\FINDFAST.EXE
O8 - Extra context menu item: Ebates - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm
O8 - Extra context menu item: Web Rebates - file://C:\PROGRAM FILES\WEB_REBATES\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O14 - IERESET.INF: SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/downlo…19106/flash.cab
-Stop-Popup-Ads-Now Variant
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
-Adult Content Dialer

Close all programs but HJT and all browser windows, then click on "Fix Checked"

RIGHT click on Start then click on Explore. In the tree that opens, locate and delete these files or folders:

C:\Program Files\Microsoft Office\Office\FINDFAST.EXE >>> file

C:\PROGRAM FILES\WEB_REBATES >>> folder

C:\WINDOWS\BELT.exe >>> file

C:\WINDOWS\SATMAT.exe >>> file

C:\WINDOWS\SYSTEM\DPNADDR.EXE >>> file

C:\WINDOWS\SYSTEM\FBYZAWN.EXE >>> file

C:\WINDOWS\SYSTEM\MSFS32.EXE >>> file

C:\WINDOWS\SYSTEM\scchost.exe >>> file (scchost.exe)
(make sure of the spelling for the above item)

C:\WINDOWS\wupdt.exe >>> file

Clean Like this:
Start, Run type "cleanmgr" without the quotes then ok. Check and remove anything windows locates.

Empty the recycle bin and restart the computer. Stay in this thread and post a new log along with any comment you think we should have.

(As I said, I am at my computer now if you have questions, post them)

Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php
She went as far as she could. What should we try next?? Here is a copy of her email to me. Thanks - Jim Okay I did all this and still no luck. When I started the only prog from the list running was FBYZAWN.EXE so I closed that. I also double checked everything else that was running to make sure they were legit. I could not enable hidden files with the link because as usual we can not access the site he provided. After doing the scan, I checked everthing listed except O4 - HKLM\..\Run: [Win Server Updt]> C:\WINDOWS\wupdt.exe> IEPlugin adware and > O8 - Extra context menu item: Web Rebates -> file://C:\PROGRAM which did not appear on the scan.Then I deleted everything except- > C:\PROGRAM FILES\WEB_REBATES >>> folder, > C:\WINDOWS\SYSTEM\DPNADDR.EXE >>> file (found application extension- .dll file but no .exe) and > C:\WINDOWS\SYSTEM\scchost.exe >>> file (scchost.exe) I used the find feature also and made sure I wasn't just missing these. Thanks for all your help but I think this is doomed. -Jeni
Here is the new log. Thanks - Jim

Logfile of HijackThis v1.99.0
Scan saved at 10:50:00 AM, on 1/28/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.00 (5.00.2314.1000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SA3DSRV.EXE
C:\COMPAQ\ACCESS\ENCOMPASS\MONITOR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEAUI.EXE
C:\COMPAQ\INTERNET\CISRVR.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS
SHARED\WKCALREM.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Essdc] essdc.exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [SXGDSENU] SXGDSENU.exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button
Support\eaclean.exe /NORESTART
O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe
O4 - HKLM\..\Run: [CPQEASYACC] "C:\PROGRAM FILES\COMPAQ\EASY ACCESS
BUTTON
SUPPORT\Cpqeaui.exe"
O4 - HKLM\..\Run: [Compaq Internet Setup]
C:\Compaq\Internet\InetWizard.exe
/RUN
O4 - HKLM\..\Run: [CISrvr Program] C:\COMPAQ\INTERNET\CISRVR.EXE
O4 - HKLM\..\Run: [CPQ BackWeb Monitor] C:\CPQS\TOOLS\BackMon.exe
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program
Files\McAfee\VirusScan\VSECOMR.EXE
O4 - HKLM\..\Run: [OEMCLEANUP] c:\windows\OPTIONS\oemreset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe
O4 - HKLM\..\RunServices: [EncMonitor]
c:\compaq\access\Encompass\Monitor.exe
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft
Money\System\reminder.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program
Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program
Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program
Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O12 - Plugin for .bat: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O12 - Plugin for .mov: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\NPQTW32.DLL
O12 - Plugin for .exe: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O12 - Plugin for .swf: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\NPSWF32.dll
Hello Jim, Before we look into updated browsers and such, let's take a last look at the log.
I see no antivirus protection in the log, unless you have other plans, here are the names of three free ones, I do suggest AVG, the first one.

http://free.grisoft.com/freeweb.php
http://www.avast.com/eng/avast_4_home.html
http://store.ca.com/dr/v2/ec_main.entry25?…5715&CID=179825

I also see no firewall, I use ZoneAlarm free version on all of my computers and suggest it when one is needed, but here are two to choose from:
http://www.zonelabs.com/store/content/comp…reeDownload.jsp
http://smb.sygate.com/products/spf_standard.htm

I do not know what homepage your sister uses but I will bet the R1 items which are search plugins from Compaq are not required after this much time. I see Yahoo and will leave it, if she does not use Yahoo, delete it also.

If these are not needed Scan with HJT and check them:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99

Close all programs but HJt an all browser windows then click on "Fix Checked"
Empty the recycle bin and restart the computer.


Jim, you are doing a heck of a job. I want to say that opportunites are available for free training in spyware removal to learn more about your computer and perhaps help others. If you are ever interested let us know.
Very important are the items above, antivirus and firewall. Your log is basically clean and I want to give you information to help now, but I would still like to see another log. I think also it is important to update her browser. Many new security issues are addressed in the newest version. I also want to mention that having an older Compaq Presario myself (7360) I am aware that many of the old Compaq programs are no longer needed and just use space and resources. A search of the items at http://www.google.com/ will return information if you wish to find out what can be removed.

I personally run these freeware programs: Ad-aware SE Personal, Spybot S&D 1.3, SpywareBlaster, SpywareGuard and IE-Spyad. Let's have you hear it from the experts, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help keep you clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Post a new log for a final look, include any queries you have I can help with.
Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
I would be interested in helping others but BIG BROTHER is watching at work where I have a high speed connection and print capability. We have had a major crack-down on non-business related internet use. They have installed software that can track everything we do. Oh well…

Here is her latest message. I emailed her the antivirus software, but it was too big for her mail box. I will try again.

I can't download any of the programs suggested. Also I reran hijack and
checked those 3 items to fix again. However, after restarting, they
reappear
on the log. They were included during the original fix and came back
then
too.

Logfile of HijackThis v1.99.0
Scan saved at 6:22:15 PM, on 1/28/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.00 (5.00.2314.1000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SA3DSRV.EXE
C:\COMPAQ\ACCESS\ENCOMPASS\MONITOR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEAUI.EXE
C:\COMPAQ\INTERNET\CISRVR.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS
SHARED\WKCALREM.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirec…edir.dll?c=1c99
&s=search&i=enu
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Essdc] essdc.exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [SXGDSENU] SXGDSENU.exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button
Support\eaclean.exe /NORESTART
O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe
O4 - HKLM\..\Run: [CPQEASYACC] "C:\PROGRAM FILES\COMPAQ\EASY ACCESS
BUTTON
SUPPORT\Cpqeaui.exe"
O4 - HKLM\..\Run: [Compaq Internet Setup]
C:\Compaq\Internet\InetWizard.exe
/RUN
O4 - HKLM\..\Run: [CISrvr Program] C:\COMPAQ\INTERNET\CISRVR.EXE
O4 - HKLM\..\Run: [CPQ BackWeb Monitor] C:\CPQS\TOOLS\BackMon.exe
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program
Files\McAfee\VirusScan\VSECOMR.EXE
O4 - HKLM\..\Run: [OEMCLEANUP] c:\windows\OPTIONS\oemreset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe
O4 - HKLM\..\RunServices: [EncMonitor]
c:\compaq\access\Encompass\Monitor.exe
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft
Money\System\reminder.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program
Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program
Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program
Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O12 - Plugin for .bat: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O12 - Plugin for .mov: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\NPQTW32.DLL
O12 - Plugin for .exe: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O12 - Plugin for .swf: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\NPSWF32.dll
Hi Jim, Let's see what we can do about these issue. I suggest a new computer. :P

I can't download any of the programs suggested


Seriously, It will be so helpful to know what messages she is receiving when she tries to download. It could be so many things, including a lack of space on the hard drive. Let me mention again that until she gets antivirus protection and a working firewall to limit her online time and to be very careful. Only go to sites she knows is safe and open no email from anyone she does not know, and do not open any email attachments at all from anyone. Just because they are addressed from a friend, does not mean they are.

Let's see what we can find out, have her do this, point at MyComputer and right click, choose Properties then click the Performance Tab. On the second line, we want to know what % of her System Resources are free. Close this to the Desktop, then Open MyComputer (double click usually) look for the C drive, point at it and RIGHT click, then choose Properties. On the General Tab we wish to know how much used and free space she has. Once she has recorded this information, there is a button right there for Disk Cleanup, have her click and let it run, takes a little while, then do what windows suggest in the way of removing junk located and not needed. Then have her click on the Tools Tab (still in C drive Properties) and first run Check Now, to check the disk for errors. When that is complete, the last Button is to Defrag her hard drive. Jim, unless she uses Task Manager to end process on all running processes but what is needed to boot the computer and run it (a bit hard for a novice) the only other way to run Defrag is in Safe Mode.
I suggest you show her how to do this, and once she is there she should run Defrag and it will complete the process much more quickly. If a disk is in bad shape, it can take hours as everytime a running program starts, the process starts over. Even a running screensaver will cause this. Here is a little information that may help:
http://plaza.kwantlen.ca/sites/iet.nsf/pag…scandisk-defrag
http://www.5starsupport.com/info/techinfo.htm especially this page:
http://www.5starsupport.com/info/techinfo.htm#disk-cleanup It is important to run Defrag last, after all junk has been removed and it has been scanned for errors.

Also I reran hijack and
checked those 3 items to fix again. However, after restarting, they
reappear
on the log. They were included during the original fix and came back
then
too.


I want you to assure her she is doing a great job, in fact let her know the computer is CLEAN of all malware, and her issues at this time are for some other reason. I will try to help to the point I have used my limited Windows 98 knowledge, then I will direct you to experts in that area. Those three items are installed by Compaq to keep her seeing Compaq adds along with the seach ability. They are not bad, I was only trying to clean what is unneccessary from her computer. Suggest she point at the active link in any of those three lines and she will see this is true. I have not seen something that is not malware resist this hard before. My suggestion would be once other issues are resolved that you have her take her computer to Safe Mode at boot up and try to remove those lines with HJT at that point. Do save this for later as I am sure she is stressed enough now. If you require instructions for entering Safe Mode, they are in this link: http://www.pchell.com/support/safemode.shtml

At some point I also think the large amount of junk that Compaq installs OEM needs to be looked at and what is not needed removed. I found after a year on my Presario that some items were discontinued by Compaq and it got worse when HP took over. I think if you contact Compaq tech support with a list of the Compaq programs on the computer they will tell you which ones you can safely remove. I hope some of this information helps.

Thanks…pskelley
TomCoyote forum
Classroom Advanced
The following is the message she is getting. Also when I was on her computer, I tried to turn down the security settings. The slide bar was set at the highest point. Each time I attempted this operation, the computer froze and I had to reboot.
Thanks - Jim

Okay I scanned the c drive and defraged. When I try to get my email it
asks
me for security permission and to allow cookies then says: Internet
Explorer
cannot open the internet site
http://us.f535.mail.yahoo.com/ym/login/.rand=5h7110egq55ch.
Invalid Arguement
When I try to go to a website the message is usually the same unless
nothing
loads (like on Chicago Faucets- there was no error message but it was
just a
white screen.)

Thanks
Jen
Hi Jim, As I explained, we are getting out of my area. I am willing to try to help, but I am getting none of the information I asked for in my last post. Please look over that post, then look at the information you gave me. I also need to see a log, to make sure followup with things like AV software, etc. and that no new infections are causing the problems. I understand it is hard to do this third party, but once I have a clean log, I am basically finished with my work. I will do what I can do, but you will have to work with me to see that I get the information I need to consider what may be causing the issues and to decide if I can help you with it at all. It may be that we should make sure the log is clean and she has basic security protection in place and suggest she seek local help. I am not sure that this might not be the route to go. Thanks…pskelley

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI