Lets try this… download Silent Runners. In IE, right click on the link and choose Save As. Double click SilentRunners.vbs(AV might give you a warning about this file… just let it run), and post the resulting log please.
here is the silent runners log,
tanx,
"Silent Runners.vbs", revision 38, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
———-
This report excludes default entries except where indicated.
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
———-
Download RKFiles. Extract(unzip) the contents to a folder.
Boot into Safe Mode. Browse to where you extracted RKFiles. Double click RKFiles.bat. Let it run. The scan will take a while. When it is done, the command box should close.
Reboot Windows normally. RKFiles created a log… C:\log.txt
hi, sorry took so long,, obligations , ya know, kids can get in the way , haha,
anyway ,,
here is the rk log,
thanks again for taking the time to help me out,,,
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder…………
————————
C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
Files Found in all users startup Folder…………
————————
Files Found in all users windows Folder…………
————————
C:\WINDOWS\tsc.exe: UPX!
C:\WINDOWS\videoc.ocx: UPX!
C:\WINDOWS\vsapi32.dll: UPX!t4
Finished
bye
i let my sys , run unbooted since the last effort, today when i return to the sys, all auto scans had run, with instances of infection,
pest patrol picked up abetterinternet
avg sheild picked up 4 instances of agent go and agent hw
also picked out gx and go from sys restore volume info,
avg also alerted about 30 times when i opened spy subtract, half i was move to the vault , but the other half referenced sys volume , and the only option available was continue,, i would imagine they are also restore files,
spy subtract came up with refreces to pointroll.com,effective.1.inc, and bhjk_coolwebsearch,
anti vir has 7 warning messages
ad aware has found 6 critical objects abcsearch.com,centrport.net, servingsys.com, 207.net, adspointroll.com, and bs.serving_sys.com.
could all these problems be stored in sys back up files ,
i did look for the files that avg found , and they are in windows, they look like sat dishes and are called channels, i didnot delet them yet,
i ran hjt, and it shows nothing,
im stumped,,,
Quite possible they are being detected from a restore point. Might also be a reg entry or two. I'm not seeing anything bad in the logs you've posted.
Reset your System Restore Point. To do this:
1. Right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Check the "Turn off System Restore" or "Turn off System Restore on all drives"
Reboot your computer, follow the steps above, this time unchecking the "Turn off System Restore" and reboot.
Let me know how it goes after that. [external image: Posted Image]
k, ill let you know, ill do a scan with all the progs and let you know tomorrow or late tonight,,
i do have one problem so far thats taken up some time,,
my printer files were corrupted or deleted ,,, so i have to reinstall,,, but when i try, i get the error cant start spool,, and im not sure how to set a dependency up ,
i didnt have to origially ,, just threw in the cd and away it went never a worry ,,, aaararrrggggghh,
are these files available for download, or something, in admin services, i can start the rpc locator, but unable to start the print spool,, i get an error 1075 , the dependincy does not exist or has been makerd for deletion,, i searched it , but have had no luck, i guess i just dont know how, any advice on this one,
also, when i try to install , i get a file in the task manager, wowexec.exe is this fishy,,,
thanks,,,
ohhhhhhh thanks man,,,,,,,,
cry with joy ,, loss of frustration,, for now any way , that fix did the printer well,,,
i just printed a test page ,,
now i gotta print a few invoices for the last week or so, then ill run the diagonistics,,,,,,
thanks again,,
i got a treat for you when were all done here,
check out www.4knife .com,, pick something out,,,,, eh,,
well, its been a couple of days,,,, and things seem to be good,
i have run all spyware and antivirus progs with no warnings,
does this mean we are done,,
i do get a couple of warnings from antivir saying some windows comp are locked
is there a way to check all windows files to see if there missing or currupt,,
You can check for corrupt/missing files by putting your WinXP disc in the drive. Then clicking Start>Run, type in sfc /scannow hit Enter.
Note: There is a space in between sfc and /scannow.
If any are found they should be replaced/overwritten.
I really haven't had any experience with AntiVir, so I'm not sure if those warnings are bad or not. Maybe sift through their website about it.
As nothing else is showing in your logs… I am going to give you my All Clean speech! Some of this you've already done, so…
To clean up anything that may have been left behind, I suggest doing a couple online virus scans. A couple good ones are Panda ActiveScan and TrendMicro HouseCall. Let them fix anything they find. Reboot between each scan.
If you don't have them, download Ad-Aware and Spybot S&D. Visit this page for proper configuration of Spybot and Ad-Aware. Run and scan with both, letting them fix whatever they find. Remember to reboot between each scan.
Now that your computer is clean, its a good time to reset your System Restore point. This will ensure a clean backup to fall upon if you ever need it. To do this:
Right-click My Computer, and then click Properties.
Click the System Restore tab.
Check the "Turn off System Restore" or "Turn off System Restore on all drives"
Reboot your computer, follow the steps above, this time unchecking the "Turn off System Restore" and reboot.
I recommend downloading and installing SpywareBlaster, SpywareGuard, and IE-SPYAD as well. You can get them from the links in my sig. The programs are free and can be updated… so please do so. Installing these will go a long way in preventing reinfection.
If you don't have one, I recommend installing a Firewall. I'm sure you've heard of ZoneAlarm.
Check out the links in my sig named How'd I get Infected and Understanding Spyware as well, some good information for you.
Other than that, remember to update Windows frequently, update your protection programs, scan often and…
thanks so much for your help and advice,,,
great to have a site like this to go to when trouble comes to town,,
i will be making a dontation to tomcoyote.org,
if you surf over to my web site, www.4knife.com,
check out some of the pocket knives there , pick one out , and either post it here , or send me your email from the site, with your choice,
dont buy through the site,, just let me ship it out, my treat,.
its the least i can do for such a great volunteer,,,,,
thanks again,,
To clean up anything that may have been left behind, I suggest doing a couple online virus scans. A couple good ones are Panda ActiveScan and TrendMicro HouseCall. Let them fix anything they find. Reboot between each scan.
If you don't have them, download Ad-Aware and Spybot S&D;. Visit this page for proper configuration of Spybot and Ad-Aware. Run and scan with both, letting them fix whatever they find. Remember to reboot between each scan.
Now that your computer is clean, its a good time to reset your System Restore point. This will ensure a clean backup to fall upon if you ever need it. To do this:
Right-click My Computer, and then click Properties.
Click the System Restore tab.
Check the "Turn off System Restore" or "Turn off System Restore on all drives"
Reboot your computer, follow the steps above, this time unchecking the "Turn off System Restore" and reboot.
I recommend downloading and installing SpywareBlaster, SpywareGuard, and IE-SPYAD as well. You can get them from the links in my sig. The programs are free and can be updated… so please do so. Installing these will go a long way in preventing reinfection.
If you don't have one, I recommend installing a Firewall. I'm sure you've heard of ZoneAlarm.
Check out the links in my sig named How'd I get Infected and Understanding Spyware as well, some good information for you.
Other than that, remember to update Windows frequently, update your protection programs, scan often and…
Surf Safe!
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI