This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost.exe and explorer.exe using too much ram

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ken, I hope I have not done something wrong but I did a rescan on AVG before reading your new replies because I thought I have really fowled up my account here by posting in 2 different forums. In anycase, the reason why nothing was getting fixed was because I did not click on the Apply All Actions button in AVG. But this time I did click on the Apply All Actions button and I think some of the things have been cleaned. So here is a new AVG report. ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 8:58:27 PM 1/6/2007 + Scan result: C:\WINDOWS\system32\rfscanax.dll -> Adware.AdwareSheriff : Cleaned. D:\owner d drive\AOL Downloads\gozilla.exe -> Adware.EZula : Cleaned. C:\WINDOWS\ho5.exe -> Dropper.Delf.ux : Cleaned. :mozilla.80:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.54:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@sonycorporate.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.15:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.16:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.32:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.25:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.26:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.27:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.28:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.67:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.35:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.84:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.17:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.23:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.24:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.86:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.82:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.83:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.66:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.18:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.19:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.20:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.21:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.22:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.36:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.37:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.63:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\backupAccount\Cookies\backupaccount@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\WINDOWS\system32\csynb.exe -> Trojan.Small.fb : Cleaned. C:\WINDOWS\system32\dmgsv.exe -> Trojan.Small.fb : Cleaned. ::Report end Also, I did not do a fresh HJT scan as of yet because I just rebooted to windows with shutting off all my startup files just in case if there are any malicuos files still on my system, but I will post a new HJT shortly. Also would you like me to run that other program, fixwareout?
Bob, :D

Glad you got AVG running, its a great program and yours to keep. After the trial you will still be able to check for updates, run scans and remove what it finds, you will just lose the background guard feature.

Avg cleaned some leftovers from Smitfraud. Yes, you still need to run both those programs. The reason I said in my first reply that your log was clean is because it was..BUT besides Smitfraud, you have two rootkit infections on your system. Its a wonder your computer is even running at all. A Rootkit is an infection that is written to hide from windows so its very hard to detect and remove. They do not show up on a HJT log so most times your log appears clean but your still infected. You are still infected with Wareout and the Gromozon Rootkit infections.

Keep in mind that as volunteers, we access this forum whenever we can. If I am not right back to you its because I am either at work or involved with family. I will be back on line in the am, so take your time and run those programs and post the reports.
Ken, I have so far doing everything in the exact order you have explained. So far I was able to download FixWareout completely run the tool, and created a log. I then made sure that "obtain dns servers automatically", altthough it was located differently. Then when to the command prompt and flushed the dns. It reported as a success. Then I tried downloading the Gromozon removal tool, but it reported: "info.prevx.com could not be found. please check the name and try again". So this is where I have stopped, and I will wait for you tommorow. In the meantime, here is the FixWareout log Fixwareout Last edited 1/1/2006 Post this report in the forums please … Prerun check »»»»» HKLM run and Winlogon System values C:\WINDOWS\system32\cszvu.exe will be moved to C:\WINDOWS\temp\cszvu.ren at reboot. »»»»» System restarted … Reg Entries that were deleted HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}56AFDCBB5715-19FB-3544-2A22-99617C66{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\vsgmd HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\0mdm HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\1mdm HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion "dpid" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion "pid" … Random Runs removed from HKLM … PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. »»»»» Searching by size/names… »»»»» Search five digit cs, dm kd and jb files. This WILL/CAN also list Legit Files, Submit them at Virustotal Other suspects. »»»»» Misc files. »»»»» Checking for older varients covered by the Rem3 tool. »»»»» Postrun check »»»»» HKLM run »»»»» Winlogon System value "system"="" »»»»»

Maybe the link was posted incorrectly, this worked for me, I was able to download it to my desktop.

http://www.prevx.com/gromozon.asp


Good Morning Ken :)
I do not think I am getting the link as a broken link. Usually when I click on a broken link, I get a 404 page error. However, with FireFox 1.04, I get an alet box where you have to click on the ok button to get rid of the box, and the alert says "www.prevx.com could not be found. please check the name and try again", as oppose to a 404 web page error. And when I try opening the link in IE, I get this loaded instead…

"Sorry. We can't find www.prevx.com
Try retyping the URL in the browser address bar above. Or, search the Web.
Search the Web:

Did you mean: www.devx.com?

Sponsored LinksPrevx1 Strong PC Security
www.prevx.com Prevx stops/cleans up more threats than other top PC security products
Free Downloads - Software
www.pctools.com Free Downloads of PC Tools to improve performance - 5 Star Rated.
Free AntiVirus Download
www.antivirusresource.com Download latest version of Norton AntiVirus now. 100% free download"


I even tried searching on google for the tool, and the samething happens. I wonder if this is why I cannot access www.castlecops.com or is it so that Castle Cops web site has actually been shut down?

This sounds all familluar of when I had the coolweb search virus. However, I flushed my DNS. Or could it be that the rootkit is reassigning another fraud DNS?


Let me give you some background about me. Back in sometime late 2004, I was infected with coolweb search virus. I had someone help me remove the virus, but then my desktop was hijeack on May 8 2005. I will never forget this day becuase it was known as the Mother's Day present virus as I call it. I call it this because that was the day of Mother's Day, and when the virus was released to the internet. When I got that virus, I could never get my router to configure properly and it would keep blocking me from the internet entirely, and I have never been able to get it to work since.

Why I think I am the king of getting infected is because I like to chat on newsgroups and after reading some of the protection stuff, it states that you should clean out the junk which I rarely do because I like using the history tool, and of course it never was a good idea to install gozila. I found out later that it is a spyware junky tool. I also have so many favorites that I had to create folders. I am a graphic designer and I am always looking for new ideas, and when I see a website I like, I add it to my favorites. I have now learned that this is not the safe way to go, and once I get this fixed I am going to be extra careful. At least for one thing, I hardly do any online personal transactions.

well enough blabling away, do you have any suggestion. When I looked at the other forum before I had chosen which one to choose from, I noticed blender thinks I should try Blacklight. Do you think this might help?
We need to run that tool, not being able to access that site maybe a windows problem related to your router, don't know. I cannot attach the file on account of the file type. It is 720kb so may fit on a floppy or burn it to a disk from another computer. BUT, you need to run that tool to remove the rootkit. Blacklight is just a information tool, it may or maynot show it, it;s not a removal tool.


Did you mean: www.devx.com?

Nope its prevx.com
Goog afternoon Ken,
The part that you thought I asked "did you mean devx.com" was not me asking, it was what Interent Explore was showing as a suggestion. The other thing, as to my router, I am not saying it is blocking me from accessing that website. I am saying that after the desktop infection in May of 2005, my router was completely blocking me from being coonected to the internet, so I had to disconnect it.

Next, I tried disabling all services, but then I did not have a intenet access. I wonder if comcast knows what services need to be loaded in order to connect to the internet, or if this would not do of anygood anyways. I will have to think about how I could get this file considering I do not have access to another computer. However, after searching at Symantec website, this rootkit is equivalant to the linkoptimizer rootkit, and it stated that it could even block the gromozon remover tool from being executed. here is there statement….

# May prevent the execution of security and anti-rootkit programs that contain the following strings in the file description or properties:

* avzantivirus
* svv
* avz
* antihook
* blacklight
* gromozon
* gmer
* prevx
* rootkit
* sophosant-rootkit
* rootkitrevealer – I first tried that one before posting my problem here, and yup it blocked it.
* icesword
* avganti-rootkit
* rootkituncover
* sophosanti-rootkit
* clrav
* avzanti-virus

# Attempts to block Internet connections to domains which contain any of the following strings:

* wilderssecurity. here is another website that I cannot access
* castlecops. — I cannot believe this and here I thought castle cops shutdown.
* suspectfile.
* antispywareremoval.
* pctools.
* paretologic.
* scan-it-clean-it.
* trojaner-board
* prevx. – here is the website we are trying to access
* pcalsicuro.
* 2-spyware.
* protecus.
* hwupgrade.
Bob, It looks like the Gromozon is indeed preventing you from accessing the prevx site. The only way around it right now that I know of is to try and use a friends pc to download that file. Its small, a quick download. Let me know if you can do this… I will see if there are other ways or sites that it can be downloaded from.
Ken,

the tool worked, but I saw one access denial. here is the log of gromozon
Removal tool loaded into memory
————————————
Executing rootkit removal engine….
————————————
Disabling rootkit file: \\?\C:\WINDOWS\system32\com5.ale
\\?\C:\WINDOWS\system32\com5.ale
Resetting file permissions…
Clearing attributes…
Access denied - C:\_cleaned.tmp
Removing file…
Rootkit removed! Cleaning up…

Removing temp files…
Scanning: C:\WINDOWS
Scanning: C:\Program Files\Common Files


Trojan.Gromozon Removed!


.. and here is the hjtlog.
Logfile of HijackThis v1.99.1
Scan saved at 3:05:31 PM, on 1/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\hphmon06.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [dmgsv.exe] C:\WINDOWS\system32\dmgsv.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

also, previous times, meaning before this infection, I could never get rid of all the links that run the lexmark tools. I do not have that printer anymore, but I cannot get rid of the locations of where all of these files are located on my system.
Also, I just noticed in the HJT log there is still one virus that I know of…. O4 - HKLM\..\Run: [dmgsv.exe] C:\WINDOWS\system32\dmgsv.exe
Bob,

Good work :thumbup:

Go to Start> Printers and Faxes and if your Lexmark is still listed, right click on it and delete it. Then go to to the Add-Remove Programs in the Control Panel and uninstall anything Lexmark related. Then to to C:\Program Files and delete any folders Lexmark related.


That is one questionable entry, when google turns up nothing it usually is bad.

Remove it with HJT.
O4 - HKLM\..\Run: [dmgsv.exe] C:\WINDOWS\system32\dmgsv.exe

Then go here and delete the file
C:\WINDOWS\system32\dmgsv.exe

If after removing Lexmark, if this is still present, delete it to.
C:\WINDOWS\system32\LEXBCES.EXE


How are things running now???
I am doing some cleanup right now. My computer is running much smoother but not perfect. Also I think I have a problem that I need to ask you. C:\Document and Settings\Administrator this folder and sub folders have been recreated on the date of 05/08/2005. I do not know what to do, but I bet you this is why I can never logon to this account in safe mode. I always have to logon to the account that I have created as administrator. When I logon on to the windows default adminsitrator account in safe mode, it always freezes the computer. Is there a way to recreate this account? I am thinking since it matches that date I mentioned when my desktop was hijacked, it means that folder might be infected. What are your thoughts about this?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI