Author Topic: ¿PSTRIP?  (Read 2313 times)

Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« on: April 24, 2005, 09:42:48 AM »
      
« Last Edit: May 01, 2005, 06:08:23 PM by gateway1986 »

Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #1 on: April 24, 2005, 09:46:46 AM »
Everytime the computer is resterted the "Found New Hardware Wizard" starts up for "SecuROM User Access Service". What is "SecuROM User Access Service" and why is the computer doing this?

Logfile of HijackThis v1.99.1
Scan saved at 10:44:46 AM, on 4/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
C:\Program Files\SysShield Tools\Internet Eraser\cseraser.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\exec.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.frontiernet.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPKbho.dll
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\pkext.dll
O3 - Toolbar: AbsoluteShield - {EE9DD090-902D-4623-9360-FB7D8666202B} - C:\Program Files\SysShield Tools\Internet Eraser\AbsoluteBar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [IE Privacy Keeper] "C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" -stcleanup
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Startup: AbsoluteShield Internet Eraser.lnk = C:\Program Files\SysShield Tools\Internet Eraser\cseraser.exe
O4 - Global Startup: Adobe Reader

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #2 on: April 24, 2005, 11:10:06 AM »
PTStrip>>May be related too Powerstrip.exe
User preference to have installed
http://entechtaiwan.net/util/ps.shtm

SecuROM User Access Service>>Used by Virtual CD emulators such as Alcohol 120%
They both appear to be third party programs that you have failed to install properly
I would go to the respective sites and find the correct installation methods

Concerning your log, are you still a user of NetZero?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #3 on: April 24, 2005, 12:16:40 PM »
      
« Last Edit: May 01, 2005, 06:11:06 PM by gateway1986 »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #4 on: April 24, 2005, 12:24:53 PM »
Can you do a search for PStrip on your computer
Where do you find it?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #5 on: April 24, 2005, 12:26:08 PM »
[quote name=\'guestolo\' date=\'Apr 24 2005, 01:24 PM\']Can you do a search for PStrip on your computer
Where do you find it?
[post=\"36748\"]<{POST_SNAPBACK}>[/post]
[/quote]
nowhere

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #6 on: April 24, 2005, 12:29:03 PM »
Just for a double check
Can you open Hijackthis>>Open Misc tools section>>Open Uninstall manager>>
Click the "SAVE LIST" button

Save and copy and paste back the text file that opens

EDIT>>Could you also
Could you Download GetServices.zip
Unzip it to a folder
Double click on the Getservice.bat file to run it. This will create and open a text file named getservice.txt in the same folder.
getservice.txt will list all active Services

Post the getservices.txt
« Last Edit: April 24, 2005, 12:32:52 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #7 on: April 24, 2005, 12:37:50 PM »
3D Groove Playback Engine
ABBYY FineReader 5.0 Sprint
AbsoluteShield Internet Eraser Lite
Ad-Aware SE Personal
Adobe Reader 7.0
AOL Instant Messenger
Cartoonist 1.0
Conexant D850 56K V.9x DFVc Modem
Dell ResourceCD
Easy CD Creator 5 Basic
Eraser
Family Tree Maker
GMail Drive Shell Extension
HijackThis 1.99.1
Intel® Extreme Graphics Driver
iTunes
J2SE Runtime Environment 5.0 Update 2
Lexmark X74-X75
McAfee SecurityCenter
McAfee VirusScan
Microsoft Age of Empires Gold
MSN Messenger 7.0
MSN Music Assistant
NetZero
QuickTime
RealArcade
RealPlayer
SAM xp
SoundMAX
Spybot - Search & Destroy 1.3
Steam
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WordPerfect Office 2002
WordPerfect Office 2002
Xfire (remove only)
Yahoo! Messenger
ZoneAlarm

Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #8 on: April 24, 2005, 12:39:42 PM »
      
« Last Edit: May 01, 2005, 06:07:28 PM by gateway1986 »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #9 on: April 24, 2005, 01:57:31 PM »
I see this in your Getservices.txt file
SERVICE_NAME: UserAccess7
(null)
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 4 DISABLED
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINDOWS\system32\UAService7.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : SecuROM User Access Service (V7)
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

What's the last thing you remember installing before getting these prompts on startup
We could probably delete the file and the service entries in the registry, but that might not be the best way to tackle this

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #10 on: April 24, 2005, 08:00:40 PM »
[quote name=\'guestolo\' date=\'Apr 24 2005, 02:57 PM\']I see this in your Getservices.txt file
SERVICE_NAME: UserAccess7
(null)
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 4 DISABLED
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINDOWS\system32\UAService7.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : SecuROM User Access Service (V7)
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem

What's the last thing you remember installing before getting these prompts on startup
We could probably delete the file and the service entries in the registry, but that might not be the best way to tackle this
[post=\"36770\"]<{POST_SNAPBACK}>[/post]
[/quote]
I don't recall installing anything.
Let's try and delete the file and service entries.
Can you please explain what to do to delete them?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #11 on: April 24, 2005, 08:52:07 PM »
I'm not sure what program would of installed that service
So we won't delete it yet
 May have been a game or burning software you installed, I'm not sure
It appears to be stopped, but can try the following

Go to START>>>RUN>>>type in services.msc
Hit OK
In the next window, look on the right hand side for this service
name---- SecuROM User Access Service (V7)

Double click on it--- STOP the service--If running
In the drop down menu, change the startup type to Disabled

Next: navigate too
C:\WINDOWS\system32\UAService7.exe
Right click on UAService7.exe and rename it too UAService7.ex_

You may have to show extensions for know file names
* Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.
Restart your computer and let's see if the add/new hardware comes up

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #12 on: April 24, 2005, 10:32:35 PM »
[quote name=\'guestolo\' date=\'Apr 24 2005, 09:52 PM\']I'm not sure what program would of installed that service
So we won't delete it yet
 May have been a game or burning software you installed, I'm not sure
It appears to be stopped, but can try the following

Go to START>>>RUN>>>type in services.msc
Hit OK
In the next window, look on the right hand side for this service
name---- SecuROM User Access Service (V7)

Double click on it--- STOP the service--If running
In the drop down menu, change the startup type to Disabled

Next: navigate too
C:\WINDOWS\system32\UAService7.exe
Right click on UAService7.exe and rename it too UAService7.ex_

You may have to show extensions for know file names
* Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.
Restart your computer and let's see if the add/new hardware comes up
[post=\"36889\"]<{POST_SNAPBACK}>[/post]
[/quote]
UAService7.exe is nowhere to be found.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #13 on: April 24, 2005, 10:35:26 PM »
Go back to where you unchecked hide know extensions for file types and show hidden files and folders and look again

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #14 on: April 25, 2005, 02:29:04 PM »
[quote name=\'guestolo\' date=\'Apr 24 2005, 11:35 PM\']Go back to where you unchecked hide know extensions for file types and show hidden files and folders and look again
[post=\"36908\"]<{POST_SNAPBACK}>[/post]
[/quote]
UAService7.exe is nowhere to be found.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #15 on: April 25, 2005, 02:44:13 PM »
Let's try this

Download:  Registry Search Tool from this link
http://billsway.com/vbspage/

Unzip and double-click "RegSrch.vbs"
Note: if your Antivirus or another program prompts about running a ".vbs" file, allow the script to run

In the open field copy and paste the below in bold then hit OK

UserAccess7

Wait for the results and post them back here

Do the same for this entry
SecuROM User Access Service

Also, Open Notepad (START>>>RUN>>>type in notepad)
Hit OK
Copy the contents of the CODE box to notepad
In Notepad click FILE>>SAVE AS

Name the file as find.bat
Save this on the desktop
Code: [Select]
dir C:\WINDOWS\system32\UAService7.exe /a h > files.txt
notepad files.txt
Double click on find.bat, a text file will open, can you post the contents back here

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #16 on: April 25, 2005, 08:00:00 PM »
[quote name=\'guestolo\' date=\'Apr 25 2005, 03:44 PM\']Let's try this

Download:  Registry Search Tool from this link
http://billsway.com/vbspage/

Unzip and double-click "RegSrch.vbs"
Note: if your Antivirus or another program prompts about running a ".vbs" file, allow the script to run

In the open field copy and paste the below in bold then hit OK

UserAccess7

Wait for the results and post them back here

REGEDIT4
RegSrch.vbs © Bill James

Registry search results for string "UserAccess7" 4/25/2005 8:52:16 PM

NOTE: This file will be deleted when you close WordPad.
You must manually save this file to a new location if you want to refer to it again later.
(If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_USERACCESS7]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_USERACCESS7\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_USERACCESS7\0000\LogConf]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_USERACCESS7\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UserAccess7]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UserAccess7\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_USERACCESS7]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_USERACCESS7\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_USERACCESS7\0000\LogConf]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UserAccess7]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UserAccess7\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_USERACCESS7]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_USERACCESS7\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_USERACCESS7\0000\LogConf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_USERACCESS7\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UserAccess7]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UserAccess7\Security]


Do the same for this entry
SecuROM User Access Service

REGEDIT4
RegSrch.vbs © Bill James

Registry search results for string "SecuROM User Access Service" 4/25/2005 8:54:03 PM

NOTE: This file will be deleted when you close WordPad.
You must manually save this file to a new location if you want to refer to it again later.
(If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_USERACCESS7\0000]
"DeviceDesc"="SecuROM User Access Service (V7)"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UserAccess7]
"DisplayName"="SecuROM User Access Service (V7)"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_USERACCESS7\0000]
"DeviceDesc"="SecuROM User Access Service (V7)"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UserAccess7]
"DisplayName"="SecuROM User Access Service (V7)"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_USERACCESS7\0000]
"DeviceDesc"="SecuROM User Access Service (V7)"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UserAccess7]
"DisplayName"="SecuROM User Access Service (V7)"


Also, Open Notepad (START>>>RUN>>>type in notepad)
Hit OK
Copy the contents of the CODE box to notepad
In Notepad click FILE>>SAVE AS

Name the file as find.bat
Save this on the desktop
Code: [Select]
dir C:\WINDOWS\system32\UAService7.exe /a h > files.txt
notepad files.txt
Double click on find.bat, a text file will open, can you post the contents back here[/i][/u]
[post=\"37032\"]<{POST_SNAPBACK}>[/post]
[/quote]
Didn't really understand the italic and underlined info/\

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
¿PSTRIP?
« Reply #17 on: April 25, 2005, 10:04:54 PM »
Just what it says

Open up a Notepad file
START>>RUN>>Type in notepad
Hit OK

In the blank notepad file copy and paste the whole contents of what is inside the CODE box in my last post
After you have pasted that over

In the notepad file click FILE>>SAVE AS
Give it a name as find.bat
Save this too the desktop

Double click on find.bat and a text file will open
Copy and paste that info back here

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline gateway1986

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
¿PSTRIP?
« Reply #18 on: April 25, 2005, 10:36:51 PM »
[quote name=\'guestolo\' date=\'Apr 25 2005, 11:04 PM\']Just what it says

Open up a Notepad file
START>>RUN>>Type in notepad
Hit OK

In the blank notepad file copy and paste the whole contents of what is inside the CODE box in my last post
After you have pasted that over

In the notepad file click FILE>>SAVE AS
Give it a name as find.bat
Save this too the desktop

Double click on find.bat and a text file will open
Copy and paste that info back here
[post=\"37152\"]<{POST_SNAPBACK}>[/post]
[/quote]
I did what you said, but it closes itself the minute I open it.