[quote name=\'guestolo\' date=\'May 29 2005, 10:34 AM\']Can you make sure that this file doesn't exist
If it does, remove it
C:\WINDOWS\System32\vxgame4.exe <-file
I can't pinpoint what that CLSID is related too
That file does not exist
Can you do the following please
Go to MyDocuments folder and create a new folder
Right click an empty spot and select NEW>>Folder
Name it Backups
Next enter your Registry
START>>RUN>>type in regedit
Hit OK
In the registry
Navigate to the following key
HKEY_USERS\S-1-5-21-818225494-2651060331-2636784919-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{203B1C4D9-BC71-8916-38AD-9DEA5D213614}
You can do that by expanding(+) on the following
+HKEY_USERS
+S-1-5-21-818225494-2651060331-2636784919-1003
+Software
+Microsoft
+Windows
+CurrentVersion
+Explorer
+CLSID
Left click and Highlight {203B1C4D9-BC71-8916-38AD-9DEA5D213614}
and then right click on it and choose EXPORT
Name the key and Export to the Backups folder
and then right click on it and choose DELETE
Do the same for these entries in bold
HKEY_USERS\S-1-5-21-818225494-2651060331-2636784919-1003\Software\Classes\CLSID\{203B1C4D9-BC71-8916-38AD-9DEA5D213614}
HKEY_USERS\S-1-5-21-818225494-2651060331-2636784919-1003_Classes\CLSID\{203B1C4D9-BC71-8916-38AD-9DEA5D213614}
I could not locate that last one ^^^^^^^
The next one
Go to
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
EXPORT SharedTaskScheduler but DON'T delete it
Instead look on the right hand side for {203B1C4D9-BC71-8916-38AD-9DEA5D213614}
And right click on that entry and delete it
Now we have backups of that Clsid if we need them
but there no longer in the registry
After that
Do another scan with Hijackthis and put a check next to these entries:
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
After you have ticked the above entries, close All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
Restart the computer
Let me know how everythings running
Everything seems to be running well again. Thank you!
Keep those backups of the registry in the Backups folder for awhile
Let's make sure everything is running smooth and ensure there not needed
You said you ran Ad-Aware
If your running the free version, it has just been updated
I would suggest that you uninstall your version from Add/Remove programs
and download the newest version
You can get it here
http://www.download.com/3000-2144-10045910.html (http://\"http://www.download.com/3000-2144-10045910.html\")
Run a full system scan after it's installed and remove all Criticals
Restart the computer if anything cleaned
I will do this today.
Post back one last hijackthis log and let me know how things are going
You said I helped you a while back, I usually suggest installing some tools after your clean to help prevent these types of infections
What tools did you download for prevention?
[post=\"43118\"]<{POST_SNAPBACK}>[/post]
[/quote]
Could you re-advise what would be good for me to use? I have AVG running now. What more do you suggest? Many thanks. You're a lifesaver!