|
Footslog's Web Boards
![]() Windows XP
![]() Memory
|
| next newest topic | next oldest topic |
| Author | Topic: Memory |
|
Shensai Member |
And now I can no longer use "Save Target As..." when trying to download. IP: Logged |
|
Shensai Member |
Sorry it's been so long, but I seem to be unable to retrieve a log from either site you sent me to. Is this something saved in a hidden log somewhere in my system? IP: Logged |
|
Josh1 Administrator |
I don’t know if you can get online even with networking support with AOL. Well we could try and kill every process that is running, expect what is needed, to try and get rid of the bad stuff. So lets try this, in windows go to start run then type msconfig, then go to selective startup hit apply and okay, reboot the computer and then try to get online and run the scans. If that does not work I will think of something else. ------------------ Powered by Intelligent Computing Solutions. For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Shensai Member |
Sorry it has been so long, but I have been trying to get on-line in safe-mode and I've been unsuccessful. I re-boot using F8, then use safe-mode with network support, then try to go on-line but my system keeps telling me it is either busy or invalid. I have checked everything the troubleshooting guide mentions (this is AOL by the way) and everything is in order. What am I doing wrong? IP: Logged |
|
Josh1 Administrator |
Yes when you boot your computer up, before the Windows XP splash screen press the F8 key when you get to the menu go to safe mode with networking support, then youcan get online and run the scans. ------------------ Powered by Intelligent Computing Solutions. For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Shensai Member |
How would one go about running housecall in safe-mode? Am I able to go on-line during this mode? IP: Logged |
|
Josh1 Administrator |
Yea you have some backdoor and Trojans on your machine, so go here and run the virus scan housecall.antivirus.com/housecall/start_corp.asp ands delete any files found. Then go here and run the Spyware scan www.trendmicro.com/spyware-scan make sure you run both of these scans in safe mode. Then post the results. ------------------ Powered by Intelligent Computing Solutions. For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Shensai Member |
I have since deleted this file. Still can't get my memory back. I am even unable to de-frag my drive for there isn't enough room. IP: Logged |
|
Shensai Member |
I also went to the Virus Total Site and had that file scanned. Here is the results if it helps...
IP: Logged |
|
Shensai Member |
I'm not sure as to what it could be, and yes, I have been using the get right program for quite a while with no ill effects to my system. IP: Logged |
|
Josh1 Administrator |
Well I don’t know what these are, do you algchk.exe" = "C:\WINDOWS\system32\algchk.exe" [null data] And do you use the Get Right download manager? ------------------ Powered by Intelligent Computing Solutions. For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Josh1 Administrator |
Okay let me have a look at this and again on Tuesday or Wednesday I will have my results. ------------------ Powered by Intelligent Computing Solutions. For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Shensai Member |
Here is what the program gave me. Hope you can make it out. Sorry it took me so long. "Silent Runners.vbs", revision 46, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
Active Desktop is disabled at this entry:
C:\Documents and Settings\Scott\Start Menu\Programs\Startup C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\ {FB5F1910-F110-11D2-BB9E-00C04F795683}\
Acronis Scheduler2 Service, AcrSch2Svc, "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" ["Acronis"]
HKLM\System\CurrentControlSet\Control\Print\Monitors\
IP: Logged |
|
Josh1 Administrator |
I cannot find anything with that log, could you run this tool? http://www.silentrunners.org/sr_download.html How to use this tool http://www.silentrunners.org/sr_scriptuse.html ------------------ Powered by Intelligent Computing Solutions. For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Josh1 Administrator |
Okay I will have a look at the log and get back to you On Tuesday, is that okay with you? ------------------ For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Shensai Member |
Here is what I have from the log;
Running processes: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = - IP: Logged |
|
Josh1 Administrator |
Yea sounds like a virus, if you want go ahead and post your hijack log here and we can take a look at it ------------------ For every problem, there is a solution. Please give what you can to the Hurricane relief http://www.microsoft.com/mscorp/citizenship/giving/relief.asp IP: Logged |
|
Shensai Member |
I normally have around 42% free space on my system. As of recently I now only have 12%. I have tried removing several files to free up room, but it seems to have no effect. I have run housecall.antivirus and also hijackthis to which I have saved a log account (I have no idea what any of that gibberish means). What am I doing wrong? Help? IP: Logged |
All times are CT (US) | next newest topic | next oldest topic |
![]() |
|