TheTechGuide Forum

General Category => Tech Clinic => Topic started by: Edward on April 29, 2005, 10:14:38 PM

Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 29, 2005, 10:14:38 PM
Everytime i search on spybot search and destroyer it always has a CoolWWWSearch... how do i get rid of it!
HiJackThisLog


Logfile of HijackThis v1.99.1
Scan saved at 11:14:21 PM, on 4/29/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\USER\My Documents\HJT\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash (http://\"http://www.rr.com/flash\")
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: ConferenceRoom Java Client - http://mail.igl.net:8000/java/cr.cab (http://\"http://mail.igl.net:8000/java/cr.cab\")
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/ht1_x.cab\")
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/pote_x.cab\")
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971C.../bridge-c10.cab (http://\"http://static.windupdates.com/cab/6247971CanadaInc/ie/bridge-c10.cab\")
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 (http://\"http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409\")
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab (http://\"http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab\")
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/qtinstall.info.app...llInstaller.exe (http://\"http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe\")
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114828616128 (http://\"http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1114828616128\")
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab (http://\"http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab\")
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab (http://\"http://fdl.msn.com/zone/datafiles/heartbeat.cab\")
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 29, 2005, 10:31:28 PM
From my signature below download and save to desktop CWShredder.exe

Do another scan with Hijackthis and put a check next to these entries:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971C.../bridge-c10.cab (http://\"http://static.windupdates.com/cab/6247971C.../bridge-c10.cab\")
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/qtinstall.info.app...llInstaller.exe (http://\"http://appldnld.m7z.net/qtinstall.info.app...llInstaller.exe\")


After you have ticked the above entries, close All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Run CWShredder.exe and click the FIX button, let it fix what it finds

Restart your computer

Open Spybot>>Search for updates, if any download all of them
After the scan is complete, if CoolWWWsearch is still found
Right click in the results area and save the results to desktop
Post the results back here with a fresh Hijackthis log
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 12:12:01 AM
Well thank you... Spybot did not find any CoolWWWSearch...But for some reason now my computer seems really slow and messing up.. I would save soemthing to the desktop and then after delete it.. it will still be on the desktop, then when i right lcick and click refresh it's gone.. wierd ehhh??

Well heres a new log.

Logfile of HijackThis v1.99.1
Scan saved at 1:11:48 AM, on 4/30/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\USER\My Documents\HJT\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash (http://\"http://www.rr.com/flash\")
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: ConferenceRoom Java Client - http://mail.igl.net:8000/java/cr.cab (http://\"http://mail.igl.net:8000/java/cr.cab\")
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/ht1_x.cab\")
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/pote_x.cab\")
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 (http://\"http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409\")
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab (http://\"https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab\")
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab (http://\"http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab\")
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114828616128 (http://\"http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1114828616128\")
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab (http://\"http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab\")
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab (http://\"https://www-secure.symantec.com/techsupp/asa/SymAData.cab\")
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab (http://\"http://fdl.msn.com/zone/datafiles/heartbeat.cab\")
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 12:30:20 AM
Can you try restarting your computer again
See if everything's back to Normal

I see an entry for Norton's AV running on your computer but I don't see the actual AV software running
Do you still have Norton's installed??

You better have an AV running, especially since I see LimeWire running in your running processes
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 12:47:19 AM
Yes i was gonna ask that next! my nortons antivirus is 2003.. when i click on Nortons it doesn't do anything...Also when i try removing it says

error 1606.  Could not access network location "::\Documents and settings\All Users\desktop

I have no clue what that means. All i know is my nortons doesn't work anymore andi can't even remove it either.
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 12:55:01 AM
Take a look at this link from Symantec's
You may want to create a fresh System Restore point before proceeding
If you don't intend on reinstalling Norton's and need a free solution, let me know
Symantec's support (http://\"http://service1.symantec.com/support/nav.nsf/8d071816eedd7cac88256c0e005a96e5/9b4dabf484e0f2ac88256c2f007f88db?opendocument&src=bar_sch_nam\")
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 01:17:26 AM
Ok i think it's gone but... we have 2 more problems... i don't have an AV now... and!!! for some reason when i click start then hover over All programs nothing comes up...

Logfile of HijackThis v1.99.1
Scan saved at 2:17:08 AM, on 4/30/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\USER\My Documents\HJT\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash (http://\"http://www.rr.com/flash\")
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: ConferenceRoom Java Client - http://mail.igl.net:8000/java/cr.cab (http://\"http://mail.igl.net:8000/java/cr.cab\")
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/ht1_x.cab\")
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/pote_x.cab\")
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 (http://\"http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409\")
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab (http://\"https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab\")
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab (http://\"http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab\")
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114828616128 (http://\"http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1114828616128\")
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab (http://\"http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab\")
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab (http://\"https://www-secure.symantec.com/techsupp/asa/SymAData.cab\")
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab (http://\"http://fdl.msn.com/zone/datafiles/heartbeat.cab\")
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 01:40:28 AM
Did you restart your computer after uninstalling Norton's AV?

You still have a couple entries in your log related to it
It doesn't seem totally removed
Take a look at this link to totally remove it from your system
Symantec Support (http://\"http://service1.symantec.com/SUPPORT/nav.nsf/docid/2002122115120906?OpenDocument&ExpandSection=1&Src=#_Section1\")

Remember to restart your computer afterwards

If you need a free AV after you have it totally un-installed Norton's
Go to this link
http://free.grisoft.com/doc/2/lng/us/tpl/v5 (http://\"http://free.grisoft.com/doc/2/lng/us/tpl/v5\")
Scroll down too
AVG Free Edition installation files
File   Version
avg70free_308a468.exe <--Click this link
Save the installer to desktop

After installation, restart the computer if prompted and then ensure it's fully up to date and run a full system scan
Let it fix what ever it finds and restart your computer again afterwards

Post back with one last hijackthis log afterwards

NOTE: Can you check this out for your Start>All programs problems
Right click an empty spot on the bottom Taskbar
Select Properties>>>Start Menu Tab
Customize>>Advanced tab
Ensure there is a check in "Open Submenus when I pause on them with my mouse"
Click OK>>APPLY>>OK
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:08:02 AM
ok i found the problem about the start menu thing... i switched it to classic and when i hover over programs it says Empty!!! i don't know why maybe we can fix it hopefully!!!
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:19:31 AM
Heres a fresh log still waiting on how to fix the start menu thing... Maybe when i was trying to delete Nortons with the windows install clean up maybe i deleted a wrong thing???

Logfile of HijackThis v1.99.1
Scan saved at 3:16:59 AM, on 4/30/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\USER\My Documents\HJT\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash (http://\"http://www.rr.com/flash\")
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: ConferenceRoom Java Client - http://mail.igl.net:8000/java/cr.cab (http://\"http://mail.igl.net:8000/java/cr.cab\")
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/ht1_x.cab\")
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab (http://\"http://download.games.yahoo.com/games/clients/y/pote_x.cab\")
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 (http://\"http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409\")
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab (http://\"https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab\")
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab (http://\"http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab\")
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114828616128 (http://\"http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1114828616128\")
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab (http://\"http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab\")
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab (http://\"https://www-secure.symantec.com/techsupp/asa/SymAData.cab\")
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab (http://\"http://fdl.msn.com/zone/datafiles/heartbeat.cab\")
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 02:32:55 AM
Well, I hope that you followed the link closely when using the Windows Installer utility
Did you follow Norton's link and check out the registry first before using the tool to remove Norton's when you got the
error 1606. Could not access network location ???

We may have to try a system restore if your not sure what you did
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 02:34:14 AM
Did you try switching back out of classic view and try what I posted earlier?
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:34:20 AM
Well i may have deleted something that was similar.. i actually think i did...  How do we do system restore?????
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:35:23 AM
yeah i came out of classic but it still doesn't work..
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 02:36:14 AM
Quote
Did you follow Norton's link and check out the registry first before using the tool to remove Norton's when you got the
error 1606. Could not access network location ???
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:37:54 AM
i followed the link but there was 1 file that was that same... i think it was WMI or soemthing and it was the  same thing so i just deleted it not looking clostley enough.
But i don't think it was the same just a tad different.
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 02:41:07 AM
Ok hold Edward, I'm off to bed right away here
You didn't answer my question twice now
Also, I asked to to make a new System Restore point before doing this

Did you look in the REGISTRY first before following Solution 2 on Norton's link

Here is what it says to do for Solution 1

Code: [Select]
# Click Start > Run.
# In the Run dialog box, type the following, and then click OK:

regedit
# In the Registry Editor window, go to the following location:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
# In the right pane, double-click Common Programs.
# In the Value Data box, delete all text before \Start Menu\Programs, and then type the following:

%ALLUSERSPROFILE%

When you have made this change, the entry should look like the following example:

%ALLUSERSPROFILE%\Start Menu\Programs
# Click OK.
# Repeat steps 4 through 7, but change each of the Value Data items in the right-pane to contain %ALLUSERSPROFILE%.
Although not every computer will contain all of these values, the following example is what you should see once you have completed this process:

    * Common AppData should have the value %ALLUSERSPROFILE%\Application Data
    * Common Desktop should have the value %ALLUSERSPROFILE%\Desktop
    * Common Documents should have the value %ALLUSERSPROFILE%\Documents
    * Common Favorites should have the value %ALLUSERSPROFILE%\Favorites
    * Common Programs should have the value %ALLUSERSPROFILE%\Start Menu\Programs
    * Common Start Menu should have the value %ALLUSERSPROFILE%\Start Menu
    * Common Startup should have the value %ALLUSERSPROFILE%\Start Menu\Programs\Startup
    * Common Templates should have the value %ALLUSERSPROFILE%\Templates
    * Recent should have the value %USERPROFILE%\recent

# Close the Registry Editor window.
# Restart your computer.
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:43:42 AM
i did all that...
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:44:58 AM
yes i looked in the registry first.  but i didn't need to change anything because it was all already %ALLUSERPROFILE%
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 03:01:02 AM
Yesssssss i found the problem in the registry i relooked at all of the files and 1 said %ALLUSERPROFILES%  when it's sopose to be %ALLUSER(S)PROFILES%  now i have my start menu back!! TY questelo for all ur help!
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 03:11:11 AM
Hee hee, yah it can fool ya  /biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />

I'll post a followup tomorrow to ensure you stay clean, Have to get some sleep  /blink.gif\' class=\'bbc_emoticon\' alt=\':blink:\' />

For now can you do the following please

Do another scan with Hijackthis and put a check next to these entries:

O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)

After you have ticked the above entries, close All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Restart your computer

Remember to check for updates with AVG and run a full system scan
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 10:58:03 AM
Alright questelo i have 1 more thing.. it's small.. but when i first turn on my comp before it says Microsoft windows Xp professional theres always alittle grey bar at the bottom just before it... i want to know if i can get rid of it? cuz it really starting to get irritating.. idk why but friends computers don't do that and only mine does...So can i get rid of it?? hopefully! Or if i restart to.
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 11:14:40 AM
Also questelo to make sure im pretty fully protected how do i get SP2??
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 12:53:21 PM
Ok questelo i c ur back can u help me alittle plz
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 01:31:34 PM
Ok, the protection part to your computer

This is what I suggest Edward

If everything is running better

You should disable system restore---restart your computer--enable system restore
This will clear all your restore points and ensure you don't restore any nasties
Once reenabled it will create a fresh restore point
How to Disable and Re-enable System Restore feature (http://\"http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm\")

Once back in Windows and System Restore is reenabled

You should set up protection against future attacks

SpywareBlaster 3.3 by JavaCool (http://\"http://www.javacoolsoftware.com/spywareblaster.html\")
*Will block bad ActiveX Controls
*Block Malevolent cookies in Internet Explorer and Firefox
*Restrict actions of potentially dangerous sites in Internet Explorer


IE-Spyad---IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
Here is a tutorial and download link
TUTORIAL==Link to Tutorial (http://\"http://www.bleepingcomputer.com/forums/index.php?showtutorial=53\")
Download link (http://\"https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD\")

With both, Check for updates every couple of weeks
Keep the link to IE-Spyad bookmarked so you can check for updates
SpywareBlaster, after every update just simply enable all protection
IE-Spyad is compatible with XP SP2 also
The reason I mention XP SP2>>you mentioned your in need of Windows updates
and you are, this is important in keeping your system secure

Here's what I suggest
If your version of Windows is legit, definitely update
Before installing Service pack2 I usually recommend running an Online virus scan
at either
Housecall's or Panda's
http://www.pandasoftware.com/activescan/co...n_principal.htm (http://\"http://www.pandasoftware.com/activescan/com/activescan_principal.htm\")
http://housecall.trendmicro.com/ (http://\"http://housecall.trendmicro.com/\")
This is just a double check to ensure you don't have no Malware hiding on your computer
Since you installed AVG7 and ran a scan, you shouldn't have to run the online scans
But keep those links bookmarked, never hurts to do a double check once in a while

==Make sure you check for updates with Ad-Aware and run a scan
If you are running the latest version of Spybot>>Which is Spybot 1.3 that should do
If you would also like to run Ad-Aware, let me know and I'll supply you with a link

Restart the computer
Empty those temp folders, do a Disk CleanUp
START>>RUN>>type in cleanmgr
Hit OK
or, better yet
==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows Cleanup (http://\"http://downloads.stevengould.org/cleanup/CleanUp40.exe\")
Give the link time to load or try it twice, it may be busy
==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
Log off and back on again

Defrag your Hard Drive>>Best done in Safe mode
START>>All Programs>>Accessories>>System Tools>>Disk Defragmenter

Create a fresh restore point
START>>All programs>>Accessories>>System Tools>>System Restore
Create a New Restore Point>>Name it and click Create

Now that your system is prepared
Print off the info from Microsoft to Recover your system in case of a bad install
Don't let this frighten you, Just keep it on hand in case you need it
I've never had to do this on any SP2 I installed
http://support.microsoft.com/default.aspx?...=windowsxpsp2kb (http://\"http://support.microsoft.com/default.aspx?kbid=875355&product=windowsxpsp2kb\")

Temporarily Disable any Security software
 before visiting so it won't interfere with the installation

Visit Windows updates and Install all Critical Updates and Service Packs
Don't install the Recommended updates(Unless wanted)
Restart your computer when prompted and revisit Windows updates until you have all Critical updates (High Priority) installed
When your satisfied you have them all installed
Restart your computer one last time

Back in Windows, Run Windows CleanUp! one more time
Restart the computer again, don't just log off and on

That should do it, your all updated

Read this link
http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx (http://\"http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx\")
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:24:20 PM
grrr this is insane i can't get windows XP Service Pack 2... It Says The product key used to install Microsoft Windows may not be valid.  For more information about why you have received this error message, and steps you can ake to resolves this issue visit www.howtotell.com.
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on April 30, 2005, 02:28:19 PM
That part I can't help you with, if your version of Windows XP is not a store bought legit version, or didn't come with your computer when bought
Check out the link supplied
www.howtotell.com
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:30:21 PM
Ok 1 more thing i asked u when i first turn on my comp before it says Microsoft windows Xp professional theres always alittle grey bar at the bottom just before it... i want to know if i can get rid of it? cuz it really starting to get irritating.. idk why but friends computers don't do that and only mine does...So can i get rid of it?? hopefully! Or if i restart to. aobut earlier u might have not seen.
Title: Omg!!! CoolWWWSearch!!!!!
Post by: Edward on April 30, 2005, 02:33:06 PM
Oh also i got my win xp professional from a friend and his works fine.. He has SP2 i just called him. Oh and if the product key wasn't real then how do i have windows Xp professional now??? wouldn't it say invalid product key or something?
Title: Omg!!! CoolWWWSearch!!!!!
Post by: guestolo on May 01, 2005, 03:16:51 AM
Stay safe Edward
Apparently, you don't understand what I mean by Illegal software
If you obtained XP from your friend and didnt' pay for a legal copy
Well, that's illegal
There are ways around the legality of XP, but don't ask for it here
Stay safe
This topic is now closed