1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Need help reviewing Hijackthis log.

Discussion in 'Windows - Virus and spyware problems' started by melanieG, Jul 12, 2007.

  1. melanieG

    melanieG Member

    Joined:
    Jul 12, 2007
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    I ran F-Secure and it didn't find anything but it gave me this:07/13/07 14:01:34 [Info]: BlackLight Engine 1.0.64 initialized
    07/13/07 14:01:34 [Info]: OS: 5.1 build 2600 (Service Pack 2)
    07/13/07 14:01:34 [Note]: 7019 4
    07/13/07 14:01:34 [Note]: 7005 0
    07/13/07 14:01:36 [Note]: 7006 0
    07/13/07 14:01:37 [Note]: 7011 400
    07/13/07 14:01:37 [Note]: 7026 0
    07/13/07 14:01:37 [Note]: 7026 0
    07/13/07 14:01:39 [Note]: FSRAW library version 1.7.1022
    07/13/07 14:08:00 [Note]: 2000 1012
    07/13/07 14:08:00 [Note]: 2000 1012
    07/13/07 14:12:15 [Note]: 7007 0

    I do have the RUN option under start and all options under control panel.
    When I startup my computer, I get to the welcome screen where I have to select a user. Windows created an administrator account for me although I was already the administrator. Now, I have two user accounts. I can't delete the one that windows created so I disabled it. You're not supposed to be able to do that but it allowed me to. I receive a message that it's disabled, I have to click ok, then I have to click on my user account for it to load my settings. Is there any way to merge my setting to the other so that I don't have to do that? Back to the task at hand...

    I uninstalled all norton and Yahoo security. I should have waited to run the dss, I apologize. I'm not sure why I only get one list now. The other is just a blur.

    Here is a new one:
    Deckard's System Scanner v20070711.54
    Run by MelG on 2007-07-13 at 14:22:16
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------



    -- HijackThis (run as MelG.exe) ------------------------------------------------

    Logfile of HijackThis v1.99.1
    Scan saved at 2:22:19 PM, on 7/13/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Documents and Settings\Melanie\Desktop\dss.exe
    C:\PROGRA~1\HIJACK~1\MelG.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: CPrintEnhancer Object - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
    O4 - HKLM\..\Run: [QD FastAndSafe] C:\PROGRA~1\NORTON~1\NORTON~2\QDCSFS.exe /scheduler
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1183096465625
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1183096419671
    O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - http://www.sandlotgames.com/w4/slgwebinstall.cab
    O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/53/install/gtdownls.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
    O17 - HKLM\System\CCS\Services\Tcpip\..\{724C7420-F180-476A-8941-3D731DC9ED93}: NameServer = 68.94.156.1,68.94.157.1
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe


    -- Files created between 2007-06-13 and 2007-07-13 -----------------------------

    2007-07-12 11:07:56 0 d-------- C:\WINDOWS\CAVTemp
    2007-07-12 11:01:51 0 d-------- C:\Documents and Settings\All Users\Application Data\CA
    2007-07-12 10:08:10 0 dr-h----- C:\Documents and Settings\Melanie\Recent
    2007-07-12 09:56:42 0 d-------- C:\Program Files\CCleaner
    2007-07-09 10:01:00 0 d-------- C:\WINDOWS\system32\ASPRO
    2007-07-07 23:22:12 1156 --a------ C:\WINDOWS\mozver.dat
    2007-07-03 06:36:57 0 d-------- C:\Documents and Settings\Melanie.MEL\Application Data\Help
    2007-07-02 08:32:10 0 d-------- C:\Program Files\QuickTime
    2007-07-01 10:10:15 0 --a------ C:\WINDOWS\nsreg.dat
    2007-07-01 10:09:47 0 d-------- C:\Documents and Settings\Melanie\Application Data\Mozilla
    2007-06-28 12:17:31 0 d-------- C:\Documents and Settings\Melanie\Application Data\Uniblue
    2007-06-27 10:32:44 69632 --a------ C:\WINDOWS\system32\asprouni.exe <Not Verified; Panda Software; Panda Software ASPRODesinstalador>
    2007-06-22 21:42:11 0 d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
    2007-06-22 19:23:05 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
    2007-06-22 14:59:53 0 d-------- C:\Documents and Settings\LocalService\Desktop
    2007-06-22 09:14:46 0 d-------- C:\WINDOWS\system32\drivers\AU_Backup
    2007-06-21 19:47:26 0 d-------- C:\info
    2007-06-21 19:08:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
    2007-06-20 14:30:23 0 d-------- C:\Documents and Settings\Melanie.MEL\Application Data\Identities
    2007-06-20 14:29:28 0 d--h----- C:\Documents and Settings\Melanie.MEL\Templates <TEMPLA~1>
    2007-06-20 14:29:28 0 dr------- C:\Documents and Settings\Melanie.MEL\Start Menu
    2007-06-20 14:29:28 0 dr-h----- C:\Documents and Settings\Melanie.MEL\SendTo
    2007-06-20 14:29:28 0 dr-h----- C:\Documents and Settings\Melanie.MEL\Recent
    2007-06-20 14:29:28 0 d--h----- C:\Documents and Settings\Melanie.MEL\PrintHood
    2007-06-20 14:29:28 0 d--h----- C:\Documents and Settings\Melanie.MEL\NetHood
    2007-06-20 14:29:28 0 dr------- C:\Documents and Settings\Melanie.MEL\My Documents
    2007-06-20 14:29:28 0 d--h----- C:\Documents and Settings\Melanie.MEL\Local Settings
    2007-06-20 14:29:28 0 dr------- C:\Documents and Settings\Melanie.MEL\Favorites
    2007-06-20 14:29:28 0 d-------- C:\Documents and Settings\Melanie.MEL\Desktop
    2007-06-20 14:29:28 0 d---s---- C:\Documents and Settings\Melanie.MEL\Cookies
    2007-06-20 14:29:28 0 dr-h----- C:\Documents and Settings\Melanie.MEL\Application Data
    2007-06-20 14:29:28 0 d---s---- C:\Documents and Settings\Melanie.MEL\Application Data\Microsoft
    2007-06-20 14:29:27 1310720 --ah----- C:\Documents and Settings\Melanie.MEL\NTUSER.DAT
    2007-06-19 17:08:42 0 d-------- C:\Program Files\Kaspersky Lab
    2007-06-19 17:08:16 0 d-------- C:\KAV
    2007-06-14 18:57:31 26768 --a------ C:\WINDOWS\system\ctl3d.dll <Not Verified; Microsoft Corporation; 3D Windows Control>
    2007-06-14 18:57:21 0 d-------- C:\WINDOWS\MVUNINST
    2007-06-14 18:57:14 0 d-------- C:\Program Files\3M
    2007-06-13 19:52:58 0 d-------- C:\Documents and Settings\Melanie\.housecall6.6


    -- Find3M Report ---------------------------------------------------------------

    2007-07-13 14:14:36 0 d-------- C:\Program Files\Yahoo!
    2007-07-13 14:14:13 0 d-------- C:\Program Files\Common Files\Scanner
    2007-07-13 12:39:08 0 d-------- C:\Program Files\Common Files\Symantec Shared
    2007-07-13 12:38:37 0 d-------- C:\Program Files\Norton SystemWorks
    2007-07-09 10:35:57 0 d-------- C:\Program Files\Apple Software Update
    2007-07-02 08:47:51 0 d-------- C:\Program Files\Trend Micro
    2007-06-28 12:13:51 0 d-------- C:\Program Files\Common Files\Sandlot Shared
    2007-06-25 13:29:17 0 d--h----- C:\Program Files\InstallShield Installation Information
    2007-06-21 10:23:17 0 d-------- C:\Documents and Settings\Melanie\Application Data\Symantec
    2007-06-21 07:29:09 0 d-------- C:\Program Files\Windows NT
    2007-06-19 22:53:24 0 d-------- C:\Program Files\101 AVI MPEG WMV Converter
    2007-06-19 15:03:34 0 d-------- C:\Program Files\Messenger
    2007-06-15 13:53:16 0 d-------- C:\Program Files\Offline Course Player
    2007-06-15 13:52:13 0 d-------- C:\Program Files\iPod
    2007-06-14 10:54:33 0 d-------- C:\Program Files\Common Files\Adobe
    2007-06-06 21:36:18 0 d-------- C:\Documents and Settings\Melanie\Application Data\Image Zone Express
    2007-05-29 14:04:04 0 d-------- C:\Documents and Settings\Melanie\Application Data\Adobe
    2007-05-23 07:58:23 0 d-------- C:\Program Files\InterVideo
    2007-05-21 06:52:49 11096 --a------ C:\Documents and Settings\Melanie\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
    2007-05-20 19:50:55 0 d-------- C:\Program Files\Bradford
    2007-05-20 19:49:48 0 d-------- C:\Program Files\TaxCut06
    2007-05-20 15:34:19 0 d-------- C:\Program Files\Common Files\Sonic Shared
    2007-05-20 15:33:08 0 d-------- C:\Program Files\Common Files\HP
    2007-05-20 15:32:34 0 d-------- C:\Program Files\Hewlett-Packard
    2007-05-20 13:46:47 0 d-------- C:\Program Files\Common Files\Download Manager
    2007-05-20 13:38:45 0 d-------- C:\Program Files\Easy MPEG AVI DIVX WMV RM to DVD
    2007-05-20 13:29:23 0 d-------- C:\Program Files\Avex
    2007-05-15 10:48:47 0 d-------- C:\Program Files\Common Files\AnswerWorks 4.0
    2007-05-15 07:55:36 0 d-------- C:\Program Files\Advanced Registry Optimizer


    -- Registry Dump ---------------------------------------------------------------

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    {AE84A6AA-A333-4B92-B276-C11E2212E4FE} C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "QD FastAndSafe"="C:\\PROGRA~1\\NORTON~1\\NORTON~2\\QDCSFS.exe /scheduler"
    "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
    "nwiz"="nwiz.exe /install"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "disableregistrytools"=dword:00000000
    "disabletaskmgr"=dword:00000000

    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
    Authentication Packages REG_MULTI_SZ msv1_0\0\0
    Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
    Notification Packages REG_MULTI_SZ scecli\0\0


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Gamma Loader.lnk"
    "backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
    "item"="Adobe Gamma Loader"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
    "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\Adobe\\READER~1.0\\Reader\\READER~1.EXE "
    "item"="Adobe Reader Speed Launch"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Synchronizer.lnk"
    "backup"="C:\\WINDOWS\\pss\\Adobe Reader Synchronizer.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\Adobe\\READER~1.0\\Reader\\ADOBEC~1.EXE "
    "item"="Adobe Reader Synchronizer"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AT&T Self Support Tool.lnk"
    "backup"="C:\\WINDOWS\\pss\\AT&T Self Support Tool.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\SBCSEL~1\\bin\\matcli.exe -boot"
    "item"="AT&T Self Support Tool"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Google Updater.lnk"
    "backup"="C:\\WINDOWS\\pss\\Google Updater.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOOGLE~1.EXE -systray -startup"
    "item"="Google Updater"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk"
    "backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe "
    "item"="HP Digital Imaging Monitor"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Image Zone Fast Start.lnk"
    "backup"="C:\\WINDOWS\\pss\\HP Image Zone Fast Start.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqthb08.exe -s"
    "item"="HP Image Zone Fast Start"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk"
    "backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE "
    "item"="InterVideo WinCinema Manager"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
    "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\MICROS~3\\Office\\OSA9.EXE -b -l"
    "item"="Microsoft Office"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Post-it® Software Notes Lite.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Post-it® Software Notes Lite.lnk"
    "backup"="C:\\WINDOWS\\pss\\Post-it® Software Notes Lite.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\3M\\PSN2Lite\\Psn2Lite.exe -RegRun"
    "item"="Post-it® Software Notes Lite"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\QuickBooks Update Agent.lnk"
    "backup"="C:\\WINDOWS\\pss\\QuickBooks Update Agent.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\COMMON~1\\Intuit\\QUICKB~1\\QBUpdate\\qbupdate.exe "
    "item"="QuickBooks Update Agent"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Service Manager.lnk"
    "backup"="C:\\WINDOWS\\pss\\Service Manager.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\MI6841~1\\80\\Tools\\Binn\\sqlmangr.exe /n"
    "item"="Service Manager"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk"
    "backup"="C:\\WINDOWS\\pss\\WinZip Quick Pick.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE "
    "item"="WinZip Quick Pick"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Melanie^Start Menu^Programs^Startup^Adobe Gamma.lnk]
    "path"="C:\\Documents and Settings\\Melanie\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
    "backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
    "location"="Startup"
    "command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
    "item"="Adobe Gamma"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"=""
    "hkey"="HKCU"
    "command"=""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="apdproxy"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Reader_sl"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AROReminder]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ARO"
    "hkey"="HKCU"
    "command"="C:\\Program Files\\Advanced Registry Optimizer\\ARO.exe -rem"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AuthConsoleStart]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"=""
    "hkey"="HKLM"
    "command"=""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="avp"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="CFD"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTCLiveUpdate]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="LiveUpdate"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\LiveUpdate\\LiveUpdate.exe\" /autostart"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ccApp"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ccRegVfy"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eBayToolbar]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="eBayTBDaemon"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\eBay\\eBay Toolbar2\\eBayTBDaemon.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileZilla Server Interface]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="FileZilla Server Interface"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\FileZilla Server\\FileZilla Server Interface.exe\""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="GoogleDesktop"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gramburn]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="readme chin"
    "hkey"="HKCU"
    "command"="C:\\DOCUME~1\\Melanie\\APPLIC~1\\CASHST~1\\readme chin.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="HPWuSchd2"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ICQLite"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\ICQLite\\ICQLite.exe -minimize"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ISUSPM"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\ISUSPM.exe\" -startup"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="issch"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="iTunesHelper"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="dumprep 0 -k"
    "hkey"="HKLM"
    "command"="%systemroot%\\system32\\dumprep 0 -k"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="MotiveSB"
    "hkey"="HKLM"
    "command"="C:\\PROGRA~1\\SBCSEL~1\\SMARTB~1\\MotiveSB.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="msmsgs"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="NeroCheck"
    "hkey"="HKLM"
    "command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="NvCpl"
    "hkey"="HKLM"
    "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="NvMcTray"
    "hkey"="HKLM"
    "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="nvraidservice"
    "hkey"="HKLM"
    "command"="C:\\WINDOWS\\system32\\nvraidservice.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OLPSYNCH]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="OlpSynch"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Offline Course Player\\OlpSynch.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="qttask"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Registry Toolkit]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="RegToolkit"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Registry Toolkit\\RegToolkit.exe /scan"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="SDTrayApp"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Spyware Doctor\\SDTrayApp.exe\""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\site ford roam vc]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Eggs 1"
    "hkey"="HKLM"
    "command"="C:\\Documents and Settings\\All Users\\Application Data\\DEBUGFLAPSITEFORD\\Eggs 1.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="SOUNDMAN"
    "hkey"="HKLM"
    "command"="SOUNDMAN.EXE"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="jusched"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="mobsync"
    "hkey"="HKLM"
    "command"="%SystemRoot%\\system32\\mobsync.exe /logon"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Trend Micro AntiVirus 2007]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="tavui"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Trend Micro\\AntiVirus 2007\\tavui.exe -1 --delay 15"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="RegistryBooster"
    "hkey"="HKCU"
    "command"="C:\\Program Files\\Uniblue\\RegistryBooster 2\\RegistryBooster.exe /S"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewpointPhotosDeviceConnect]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="FotomatDeviceConnect"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Common Files\\Viewpoint\\Toolbar Runtime\\3.7.0\\FotomatDeviceConnect.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="YahooMessenger"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "SQLAgent$MICROSOFTSMLBIZ"=dword:00000003
    "iPodService"=dword:00000003

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0



    -- End of Deckard's System Scanner: finished at 2007-07-13 at 14:22:39 ---------



     
  2. melanieG

    melanieG Member

    Joined:
    Jul 12, 2007
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    I noticed that Norton is still listed. I went to programs and there is still stuff in there. I deleted them from my programs list, then went to windows explorer. I tried to delete the folder but it gets as far as NPComsrv.DLL and tells me I can't delete it, access is denied.
     
  3. Fredil

    Fredil Regular member

    Joined:
    Jul 19, 2006
    Messages:
    390
    Likes Received:
    0
    Trophy Points:
    26
    Please reboot your computer into Safe Mode:

    1. Reboot your computer.
    2. As soon as it starts booting, press the F8 key. You may get an error if this is done too soon, just reboot and try again.
    3. You may get a message about boot drivers, just press ESC and keep tapping F8.
    4. At the Advanced Options menu, use the arrow keys and navigate to Safe Mode. Press Enter and log in as you usually would.

    Try to delete the Norton folder again. Then, reboot back to normal.

    How's your computer? If there are still problems we will have to scan more thoroughly.
     
  4. Auttaja

    Auttaja Guest

  5. melanieG

    melanieG Member

    Joined:
    Jul 12, 2007
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    Fredl, I just finished deleting all of Norton and symantec files. I went through Windows explorer deleted the folder successfully, then went into regedit under HKEY CU & LM to remove Symantec. I see no change in my computer thus far. There is still something hiding somewhere. Or maybe it's the permanent damage that I have to live with? You mentioned scanning a little more in depth, fire away.
     
  6. Fredil

    Fredil Regular member

    Joined:
    Jul 19, 2006
    Messages:
    390
    Likes Received:
    0
    Trophy Points:
    26
    @Auttaja - See, the uninstaller leaves behind LOTS of registry keys and folders.

    @melanieG - Norton isn't causing the problems - but it's like improperly removed malware - sits there doing nothing whatsoever, wasting space.

    Install another antivirus program - a computer without one will keep getting infected. AntiVir (http://www.free-av.com) is pretty good, has excellent heuristics and the highest detection rate of any free antivirus. Sometimes it gets kind of annoying, but that's cause it rocks so much :D

    Don't edit the registry on a regular basis, you could screw something up :) The registry scripts I gave you should have done it.

    What happens when you try to edit msconfig?

    There's not much more left to try... you likely don't have a rootkit, as can be confirmed by the BlackLight scan... let's try another scan for rootkits, since you don't seem to have any other recognizable mawlare.

    Please download AVG Anti-Rootkit. Install it, and do a scan with it. It should tell you if hidden objects are found. It should also create a log, post that log in a reply please.

    Do you have your original Windows XP Installation CD? I'm not looking to reformat - try to avoid that unless we have absolutely no other options.

    Edit - just thought of something else of interest. Please open your start menu > Run. In the box, type system.ini. A notepad window should open - DO NOT CHANGE ANYTHING!! Copy the contents of that window and post it into your reply.
     
    Last edited: Jul 14, 2007
  7. windmaker

    windmaker Member

    Joined:
    Jul 15, 2007
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    why would you add yet another AV ?

    have the last bit of Nortons AV been removed ?

    Part of Nortons AV
    Have/had LOP infection
    resident AV ?
    CA through Yahoo as well
     
  8. Fredil

    Fredil Regular member

    Joined:
    Jul 19, 2006
    Messages:
    390
    Likes Received:
    0
    Trophy Points:
    26
    An anti-rootkit is not an AV.
     
  9. windmaker

    windmaker Member

    Joined:
    Jul 15, 2007
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    Didn't say it was
    I was referring to
     
  10. melanieG

    melanieG Member

    Joined:
    Jul 12, 2007
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    Hi Fredl. I apologize for my delay in keeping up with this. I downloaded and ran the avg and no rootkits were found. Also downloaded and installed the antivirus you suggested, nothing found.

    Here is the info form system.ini: ; for 16-bit app support
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    [mci]
    [driver32]
    [386enh]
    woafont=dosapp.FON
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
     
  11. Fredil

    Fredil Regular member

    Joined:
    Jul 19, 2006
    Messages:
    390
    Likes Received:
    0
    Trophy Points:
    26
    You have me stumped...

    Reboot into Safe Mode and delete this folder:

    C:\Documents and Settings\All Users\Application Data\DEBUGFLAPSITEFORD

    You will have to enable Hidden Files via Start > Control Panel > Folder Options > View.

    How is the computer running?
     
  12. melanieG

    melanieG Member

    Joined:
    Jul 12, 2007
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    I'm about to perform that deletion. I wanted to tell you the most annoying thing about my computer is the mouse problem. If I idel for more that a couple of minutes, sometimes not even that, it locks up, I have to hit control+Alt+ delete. I don't have to delete anything, I just have to do it. It also starts acting even more strange by acting as if I have right clicked permanently on the desktop, then I have to click my choice of action. So if I want open my email, I have to click "open outlook express" I really hate that!!!
     
  13. Fredil

    Fredil Regular member

    Joined:
    Jul 19, 2006
    Messages:
    390
    Likes Received:
    0
    Trophy Points:
    26
    Hmm... can you go to Start > Control Panel > Mouse > Buttons. Make sure that both the checkboxes are un-checked. Also, make sure the correct drivers for your mouse are installed (they usually come in a CD when you bought your mouse). I'm not an expert with mice, so you might have to post in the hardware forum :)
     

Share This Page