Author Topic: Winfix and Vundo Problems  (Read 10663 times)

Offline curtgiles

  • Newbie
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Winfix and Vundo Problems
« on: November 11, 2005, 07:18:28 PM »
I get WinFix pop-ups and my security system has notified me that gebcd.dll has been found on my computer. I think this has something to do with a trojan. Need help getting rid of it. I tried following directions to download VundoFix.exe from a previous post and all was well until it couldn't locate the HJT.exe file when I typed in the path C:\WINDOWS\system32\mllmm.dll.  My system is Windows XP Home and my security system is McAffe Virus Scan. Here is my last HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 7:17:19 PM, on 11/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: MSEvents Object - {79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A} - C:\WINDOWS\system32\gebcd.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O20 - Winlogon Notify: gebcd - C:\WINDOWS\system32\gebcd.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
« Last Edit: November 11, 2005, 07:24:16 PM by curtgiles »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Winfix and Vundo Problems
« Reply #1 on: November 12, 2005, 03:13:26 AM »
Download and save to your desktop
WinsockXPfix
Don't run this
We have it if we need it

Please download [color=\"red\"]VundoFix.exe[/color][/url] to your desktop.
    *Double-click
VundoFix.exe to extract the files
*This will create a VundoFix folder on your desktop.

Please print these instructions or save them too notepad for reference
RESTART your Computer in SAFE MODE without networking
You can do this by tapping the F8 key as the system is restarting, just before Windows loads, or use the link
I supplied for an alternative method

*Once in safe mode

Open the VundoFix folder and doubleclick on KillVundo.bat
  • You will first be presented with a warning.

It should look like this
Quote
[color=\"blue\"]VundoFix V2.15 by Atri
By using VundoFix you agree that you are doing so at your own risk
Press enter to continue....
[/color]

* At this point press enter one time.

* Next you will see:
Quote
[color=\"blue\"]Please Type in the filepath as instructed by the forum staff
and then press enter:[/color]

*At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\gebcd.dll

    *Press [color=\"red\"]Enter[/color] to continue with the fix.

    *Next you will see:
    Quote
    [color=\"blue\"]Please type in the second filepath as instructed by the forum
    staff then press enter: [/color]
    *At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\dcbeg.*
    [/list]
    • Press [color=\"red\"]Enter[/color] to continue with the fix.
      *The fix will run then HijackThis will open, if it does not open automatically please open it manually.
      *In HiJackThis, please place a check next to the following items and click FIX CHECKED:
        O2 - BHO: MSEvents Object - {79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A} - C:\WINDOWS\system32\gebcd.dll

        O20 - Winlogon Notify: gebcd - C:\WINDOWS\system32\gebcd.dll

      *After you have fixed these items, close Hijackthis.
      *Press enter to exit the program then manually reboot your computer.

      Back in Windows
      Access your add/remove programs and remove if found
      New.net Domains
      Reboot your computer again

      Then, please run this online virus scan:  [color=\"red\"]ActiveScan[/color][/url]
      Once loaded, choose to Scan "Local Disks"
      Once the scan is complete
      Save a report of what was found and fixed to desktop

      Copy the results of the ActiveScan and paste them here along with a new HijackThis log and the vundofix.txt file from the vundofix folder into this topic.

      NOTE: If you find New.dot net in your add/remove programs
      and after removing it you lose internet connection
      Run WinsockXP FIX that you saved earlier too desktop
      with all other windows closed
      then reboot your computer
      Don't run this unless needed

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline curtgiles

      • Newbie
      • *
      • Posts: 5
      • Karma: +0/-0
        • View Profile
      Winfix and Vundo Problems
      « Reply #2 on: November 13, 2005, 12:52:49 PM »
      OK, I followed all your instructions. Here are the Active Scan and HJT reports you requested. Thank you for your help.

      Incident                      Status                        Location                                                                                                                                                                                                                                                        

      Adware:Adware/Gator           No disinfected                C:\Program Files\Butterfly Oasis Screensaver\BO1Uninstaller.exe                                                                                                                                                                                                
      Adware:Adware/Trymedia        No disinfected                C:\RECYCLER\S-1-5-21-2003678500-1496761015-2155405273-1008\Dc12.exe                                                                                                                                                                                            
      Adware:adware/gator           No disinfected                C:\WINDOWS\GatorGainInstaller.log                                                                                                                                                                                                                              
      Spyware:Spyware/Virtumonde    No disinfected                C:\WINDOWS\SYSTEM32\pmnll.dll                                                                                                                                                                                                                                  


      Logfile of HijackThis v1.99.1
      Scan saved at 12:48:10 PM, on 11/13/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      C:\Program Files\Dell\Media Experience\PCMService.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      c:\progra~1\mcafee.com\vso\mcvsescn.exe
      C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\Program Files\McAfee.com\VSO\oasclnt.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      C:\Program Files\Picasa2\PicasaMediaDetector.exe
      C:\Program Files\Dell Support\DSAgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\FinePixViewer\QuickDCF.exe
      c:\program files\mcafee.com\agent\mcdetect.exe
      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\HJT.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
      O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
      O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
      O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
      O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
      O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
      O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
      O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
      O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      O4 - Global Startup: Exif Launcher.lnk = ?
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
      O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
      O15 - Trusted Zone: *.musicmatch.com (HKLM)
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
      O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
      « Last Edit: November 13, 2005, 12:53:57 PM by curtgiles »

      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Winfix and Vundo Problems
      « Reply #3 on: November 13, 2005, 01:07:45 PM »
      Can you do the following please
      Open Hijackthis>>Open the Misc tools section>>Open the Uninstall manager>>
      Click the SAVE LIST button
      Save the list to desktop and then copy and paste the whole contents back here

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline curtgiles

      • Newbie
      • *
      • Posts: 5
      • Karma: +0/-0
        • View Profile
      Winfix and Vundo Problems
      « Reply #4 on: November 13, 2005, 02:41:52 PM »
      Here is the Uninstall list from HJT.

      Adobe Acrobat - Reader 6.0.2 Update
      Adobe Acrobat and Reader 6.0.3 Update
      Adobe Reader 6.0.1
      Butterfly Oasis Screensaver
      Canon iP1600
      Canon Utilities Easy-PhotoPrint
      Dell Digital Jukebox Driver
      Dell Driver Reset Tool
      Dell Media Experience
      Dell Picture Studio v3.0
      Dell Support 5.0.0 (630)
      FinePixViewer Ver.4.1
      FUJIFILM USB Driver
      HijackThis 1.99.1
      ImageMixer VCD2 for FinePix
      Intel® 537EP V9x DF PCI Modem
      Intel® Extreme Graphics 2 Driver
      Intel® PRO Network Adapters and Drivers
      Intel® PROSet for Wired Connections
      Internet Explorer Default Page
      Jasc Paint Shop Photo Album 5
      Jasc Paint Shop Pro Studio, Dell Editon
      Java 2 Runtime Environment, SE v1.4.2_03
      McAfee Personal Firewall Plus
      McAfee Privacy Service
      McAfee SecurityCenter
      McAfee SpamKiller
      McAfee VirusScan
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1 Hotfix (KB886903)
      Microsoft Office Basic Edition 2003
      Microsoft Plus! Digital Media Edition Installer
      Microsoft Plus! Photo Story 2 LE
      MicroStaff WINASPI
      Modem Event Monitor
      Modem Helper
      Modem On Hold
      Mozilla Firefox (1.0.4)
      MSN
      Musicmatch for Windows Media Player
      Musicmatch® Jukebox
      NingPo MahJong Deluxe 1.04
      Panda ActiveScan
      Picasa 2
      PowerDVD 5.3
      Qualxserve Service Agreement
      QuickTime
      RAW FILE CONVERTER LE
      RealPlayer Basic
      Security Update for Step By Step Interactive Training (KB898458)
      Security Update for Windows XP (KB883939)
      Security Update for Windows XP (KB890046)
      Security Update for Windows XP (KB893756)
      Security Update for Windows XP (KB896358)
      Security Update for Windows XP (KB896422)
      Security Update for Windows XP (KB896423)
      Security Update for Windows XP (KB896424)
      Security Update for Windows XP (KB896428)
      Security Update for Windows XP (KB896688)
      Security Update for Windows XP (KB899587)
      Security Update for Windows XP (KB899588)
      Security Update for Windows XP (KB899591)
      Security Update for Windows XP (KB900725)
      Security Update for Windows XP (KB901017)
      Security Update for Windows XP (KB901214)
      Security Update for Windows XP (KB902400)
      Security Update for Windows XP (KB903235)
      Security Update for Windows XP (KB904706)
      Security Update for Windows XP (KB905414)
      Security Update for Windows XP (KB905749)
      Sonic DLA
      Sonic RecordNow!
      Sonic Update Manager
      SoundMAX
      Update for Windows XP (KB894391)
      Update for Windows XP (KB896727)
      Update for Windows XP (KB898461)
      WildTangent Web Driver
      Windows Installer 3.1 (KB893803)
      Windows Installer 3.1 (KB893803)
      Windows Media Format Runtime
      Windows Media Player 10
      Windows Media Player 10
      Windows XP Hotfix - KB834707
      Windows XP Hotfix - KB867282
      Windows XP Hotfix - KB873333
      Windows XP Hotfix - KB873339
      Windows XP Hotfix - KB885250
      Windows XP Hotfix - KB885626
      Windows XP Hotfix - KB885835
      Windows XP Hotfix - KB885836
      Windows XP Hotfix - KB886185
      Windows XP Hotfix - KB887472
      Windows XP Hotfix - KB887742
      Windows XP Hotfix - KB888113
      Windows XP Hotfix - KB888302
      Windows XP Hotfix - KB890047
      Windows XP Hotfix - KB890175
      Windows XP Hotfix - KB890859
      Windows XP Hotfix - KB890923
      Windows XP Hotfix - KB891781
      Windows XP Hotfix - KB893066
      Windows XP Hotfix - KB893086

      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Winfix and Vundo Problems
      « Reply #5 on: November 13, 2005, 04:12:44 PM »
      If this is the free version of Butterfly Oasis Screensaver, I suggest you access your add/remove programs and Remove it
      Here's a quote from the company
      Quote
      These software applications also occasionally display pop up ads on your computer screen based on your online activities. Alternatively, ad-free versions of the software titles distributed by GAIN Publishing are available for purchase (conditions apply).

      Also, if you didn't intentionally install
      WildTangent Web Driver
      Remove it too

      Download Pocket Killbox
      From one of these loactions
      http://www.downloads.subratam.org/KillBox.exe
      http://www.atribune.org/downloads/KillBox.exe
      In the event you have killbox, I need you too download this version
      Start Killbox
      Click on Tools in the menu bar and then click "Delete Temp Files"
       place a tick next to
      delete on reboot.

      Copy this whole list into the windows clipboard, all the Bolded below.
      Between the dotted lines
      By using the Ctrl + C keys on your keyboard

      ==============================
      C:\RECYCLER\S-1-5-21-2003678500-1496761015-2155405273-1008\Dc12.exe
      C:\WINDOWS\GatorGainInstaller.log
      C:\WINDOWS\SYSTEM32\pmnll.dll

      ==============================

      Back in Killbox go to > file > paste from clipboard,
      Click the red highlighted X button

      Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
      When it asks if you would like to Reboot now, click YES
      If you don't get that message, reboot manually.
      Click No at the Pending Operations prompt.

      Back in Windows

      Please go here and use Procedure 4 for removal on New.net
      http://www.newdotnet.com/removal.html
      Use Firefox to download the uninstaller
      Let this run if prompted it is malicious, it will do the job
      Save the uninstaller to desktop
      Close all other open windows and run it and then reboot

      Keep in mind, if you lose internet connection, you still have WinsockXP fix
      Which you will run and reboot ONLY if needed

      You should install these 2 spyware scanners
      yours to keep for free, hang onto these

      Download and Install Ad-Aware SE Personal 1.06

      Open Ad-Aware, ensure to click the  check for updates now link and Connect to download the latest updates
      Click START
      Click the radio button to Perform a Full system scan then click NEXT
      When it's finished scanning
      At this point you should either right click on the screen and and choose the "Select All" Objects option or individually put a checkmark in each objects checkbox
      click on the Next button. Ad-Aware SE will now present you with a confirmation box as to whether or not you would like to remove the objects you have just selected. Press the "OK" button

      RESTART your computer to finish the cleaning process
      ===================================

      Download and Install Spybot 1.4 from
      HERE
       or HERE

      After installation--Click the UPDATE button on the left
      SEARCH FOR UPDATES on the right
      Check, and download all updates
      Click the Search & Destroy button on the left
      Check for Problems---When the Scan is complete
      FIX all selected promblems in RED

      RESTART the computer to finish the cleaning process

      Back in Windows
      Run hijackthis again and post a fresh log

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline curtgiles

      • Newbie
      • *
      • Posts: 5
      • Karma: +0/-0
        • View Profile
      Winfix and Vundo Problems
      « Reply #6 on: November 13, 2005, 05:47:50 PM »
      Whew! That was a lot to do, but I got it done (I think I did everything right). Here is the latest HJT log.

      Logfile of HijackThis v1.99.1
      Scan saved at 5:45:34 PM, on 11/13/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\mcafee.com\agent\mcdetect.exe
      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      C:\WINDOWS\Explorer.EXE
      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
      c:\program files\mcafee.com\vso\mcvsshld.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      C:\Program Files\Dell\Media Experience\PCMService.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      c:\progra~1\mcafee.com\vso\mcvsescn.exe
      C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
      c:\program files\mcafee.com\agent\mcagent.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      C:\Program Files\Picasa2\PicasaMediaDetector.exe
      C:\Program Files\Dell Support\DSAgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\FinePixViewer\QuickDCF.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\HJT.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
      O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
      O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
      O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
      O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
      O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
      O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
      O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      O4 - Global Startup: Exif Launcher.lnk = ?
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
      O15 - Trusted Zone: *.musicmatch.com (HKLM)
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
      O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Winfix and Vundo Problems
      « Reply #7 on: November 13, 2005, 06:21:49 PM »
      Looks good
      Some final cleanup
      If everything is running better, please do the following
      You should disable system restore>>>reboot>> and then reenable it
      This will clear all your restore points and ensure you don't restore any nasties
      How to Disable and Re-enable System Restore feature

      Once System Restore is reenabled

      You should set up protection against future attacks
      SpywareBlaster 3.4 by JavaCool
      *Will block bad ActiveX Controls
      *Block Malevolent cookies in Internet Explorer and Firefox
      *Restrict actions of potentially dangerous sites in Internet Explorer
      After installation, Check for updates and then click the "Enable all protection"

      IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
      Here is a tutorial and download link
      TUTORIAL==Link to Tutorial
      Download link

      With both, Check for updates every couple of weeks
      Keep the link to IE-Spyad bookmarked so you can check for updates
      SpywareBlaster, after every update just simply click the "enable all protection"
      IE-Spyad is compatible with SP2 as well

      Let me know how everythings running and then I'll close this topic

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


      Offline curtgiles

      • Newbie
      • *
      • Posts: 5
      • Karma: +0/-0
        • View Profile
      Winfix and Vundo Problems
      « Reply #8 on: November 13, 2005, 07:23:26 PM »
      Initially I think there has been a great improvement in how my computer is running. I can't thank you enough. Well I guess I can with money although I think it is fantastic that you don't seem to consider it the primary concern. You have helped me with my pc problems and for that I say "thank you very much".

      Offline guestolo

      • Site Donator
      • Administrator
      • Hero Member
      • *****
      • Posts: 16034
      • Karma: +1/-0
        • View Profile
        • http://
      Winfix and Vundo Problems
      « Reply #9 on: November 13, 2005, 07:39:16 PM »
      Your welcome
      I forgot to add, if you removed the screensaver from add/remove programs
      You can delete this folder if found
      C:\Program Files\Butterfly Oasis Screensaver <-this folder

      I'll lock this topic as your problems appear resolved, if you need it reopened, please PM myself or the site admin and supply a link to this thread

      Stay safe  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

      Do you want to post your own logs from FRST?

      Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here