Articles

Solved Program not responding- Slow

December 27, 2012 at 11:30:25
Specs: Windows XP

I have seen many replies to program not responding here and on Tom's hardware but no clear answer that I can find.

I often get program not responding with IE and now when trying to paste in Word. only solution seems to be a restart VERY slow to reboot and doesn't always solve the proplem.
I especially need the paste function. I have tried Malwarbytes and scanned with Avast.and have indexing services set at stop.

Are there any free programs to fix this? or something simple that I can do?
Thank you in advance. I've been helped here many times. I am 79 yrs old and been a computer user about 14 yrs so I'm fairly conversant but please bear with me if I need extra explanation


See More: Program not responding- Slow

Report •


#1
December 27, 2012 at 11:51:03

Run msconfig & uncheck whatever programs you don't need to load at boot time, click apply or OK, reboot, click OK again. You can disable all if you don't know what is what.

How do you know when a politician is lying? His mouth is moving.


Report •

#2
December 27, 2012 at 13:15:14

Seems to have helped with the slow boot but Word is still not responding. Help- please

Report •

#3
December 27, 2012 at 14:43:59
✔ Best Answer

Got your PM. Sorry no easy fix. Do general housekeeping such as running CCleaner and defrag. Also make sure the case vents, fans and CPU heat sink are not chogged up with dust.

If it was just the Paste issue in Word then maybe uninstall and re-install MS Office (if you have Office disk) would help. However, as you seem to have more than just one issue I suspect it is the general slowness that is causing the paste problem.

You could install HijackThis (green icon top right):
http://www.filehippo.com/download_h...
I haven't installed it for some years but unless things have changed do not RUN the download, you just put it into a pre-created spare folder (called HJT or something) rather than the desktop. To run it either double click the exe file or make a convenient shortcut to it on the desktop. Copy/Paste the log on here and we can see if anything obvious pops up.

There could be a virus around despite your checks.


Always pop back and let us know the outcome - thanks


Report •

Related Solutions

#4
December 27, 2012 at 15:32:21

What version of Microsoft word or Microsoft Office are you using?

Report •

#5
December 27, 2012 at 15:39:47

I think it's Office 2000. I've forgotten how to find out the version
I am downloading High Jack this now. I guess it's downloading- Says it is

Report •

#6
December 27, 2012 at 15:54:18

To find version, open a word document, go to help > About. That works for finding most program versions. If it's 2000 that should run on XP.

Always pop back and let us know the outcome - thanks


Report •

#7
December 27, 2012 at 16:05:27

*I have the disk, I'ts 2000.
Has worked on the unit at least 6 yrs
I have a newer version, Don't know the year

Got HiJack this to download. this the log;
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:44:18 PM, on 12/27/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\Program Files\Yahoo!\Companion\Installs\cpn6\ytbb.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll
R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: CrossriderApp0003491 - {11111111-1111-1111-1111-110011341191} - C:\Program Files\Vid-Saver\Vid-Saver.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/1503...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - http://h20270.www2.hp.com/ediags/gm...
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/1503...
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Unknown owner - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe (file missing)
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: VideoAcceleratorService - SpeedBit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 9539 bytes
By the way, I can type and save a Word Doc. but can't paste to it
I CAN copy and paste to email


Report •

#8
December 28, 2012 at 10:54:33

Your system is infected with malware. Get rid of all the toolbars - Yahoo, Google, AVG.

Download, install, & run CCleaner-Slim. Remove everthing it finds:

http://www.piriform.com/ccleaner/bu...

Once you've done that, download & install Malwarebytes Antimalware. Update it then run a full scan (not quick scan) from safe mode.

http://www.filehippo.com/download_m...


Report •

#9
December 28, 2012 at 11:07:29

What is best way to get rid of toolbars?
I have had CCleaner installed for a long time but i don't recognise CCleaner-slim. What is it? Will it automatically install if I re-download it?
When you say run CCleaner, Do you mean the cleaner only and not registry?
Can I reinstall toolbars after cleaning?
Yahoo is my email and makes it easy to acces email and facebook

Report •

#10
December 28, 2012 at 11:08:35

O2 - BHO: CrossriderApp0003491 - {11111111-1111-1111-1111-110011341191} - C:\Program Files\Vid-Saver\Vid-Saver.dll (file missing)

http://www.pcpitstop.com/libraries/...

According to that ^^ site, vid-saver is a virus.
___________________________

Also, I'm not a fan of toolbars. They are not secure & I would uninstall them.

How do you know when a politician is lying? His mouth is moving.


Report •

#11
December 28, 2012 at 13:22:53

Run HJT, tick the following and let it remove them:

O2 - BHO: CrossriderApp0003491 - {11111111-1111-1111-1111-110011341191} - C:\Program Files\Vid-Saver\Vid-Saver.dll (file missing)

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing

O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - (no file)

O23 - Service: Apple Mobile Device - Unknown owner - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (file missing)

O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe (file missing)

O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe (file missing)

All of the above have files missing so there is no point having them around. I assume you are no longer using AVG.

When you have done this, run HJT and post the new log because I only had a quick look and might want to delve further into some of them. Nothing too worrying as far as I have gone.

I agree with guapo about toolbars - best remove any that you don't really need. Some might appear in "Control Panel > Add-Remove Programs", others might be in Internet Explorer add-ons (or those of other browsers if you have any).

If you already have CCleaner then you don't need the Slim version. With the latter it doesn't offer you any add on goodies that you don't need (un-ticking them when you install the full version does the same thing).

I generally don't suggest folk use registry cleaners as there is always a risk that something valid will get removed too (even though the CCleaner one is one of the safest). They remove invalid entries but these are usually ignored by the system anyway so have no affect on performance. If you are happy to accept this risk (probably slight) then go ahead.

Always pop back and let us know the outcome - thanks


Report •

#12
December 28, 2012 at 15:18:10


Will do. I need to go to my other computer with printer. Will get back
Question- Why is it more "dangerous" to use a toolbar i.e. Google, than accessing it from a desktop Icon?

Report •

#13
December 28, 2012 at 15:57:39

Re #12

It's just that toolbars generally tend to be spyware and often malware too. Some are worse than others.

Perhaps "dangerous" would be a strong word for the Google toolbar, after all Google itself spies on you at the best of times.

I like Google's search engine but prefer not to have anything else to do with that outfit. That is just my personal opinion, although I am not alone - see here:
http://duckduckgo.com/?q=is+google+...

Always pop back and let us know the outcome - thanks


Report •

#14
December 28, 2012 at 16:39:26

No-one seems to have asked one of the most pertinent questions here and that is "What are your system specifications?"

Part of your slowness problem may be because of limitations of your hardware such as type & power of your processor and amount of ram.
I agree with the other responders on uninstalling toolbars from your browser and on running HJT and Malwarebytes. A starting point for me is always to check & maximise the hardware potential. Adding more ram can be of great benefit if you currently have 512mb or less which would not be uncommon in an XP machine.

You might also open up Task Manager and check what programs & processes are running. http://www.blackviper.com/ has a good listing of processes and you can get some idea of processes that are safe/advisable to turn off which can also help improve system performance.
Windows also uses a file called Prefetch to call up commonly used programs so that they start faster when you click on them. Problem is once something finds it's way into prefetch it stays there for ever even if you never use that program again.
It is safe to delete the contents of the Prefetch folder. Windows will rebuild it over time. Don't delete the folder, just the contents. path is C:\WINDOWS\Prefetch

Goin' Fishin' (Some day)


Report •

#15
December 28, 2012 at 17:51:23

Richard59

I agree with everything you've said except the prefetch bit. This area is commonly misunderstood.

Firstly it refreshes itself automatically when the number of entries reach 128+ and goes back down to about 32 (the latest ones).

Secondly it only stores information related to used programs, to speed their start up. Unless a program is called it uses no resources whatsoever, all entries for other programs are disregarded.

Thirdly, It is a tad unwise to delete the Layout.ini file because has been known to not return, which wrecks prefetch. I see no reason to tinker in this area (it is there to speed things up) but if you must do so then only delete the .PF files that are old or for install/uninstall. That will make way for newer ones.

EDIT See this:
http://www.edbott.com/weblog/2005/0...

Always pop back and let us know the outcome - thanks


Report •

#16
December 28, 2012 at 17:57:08

Thanks Derek. I learn sumthin new evry day.

Goin' Fishin' (Some day)


Report •

#17
December 28, 2012 at 18:01:16

Re #16

Aha - don't we all.

Always pop back and let us know the outcome - thanks


Report •

#18
December 28, 2012 at 18:12:31

Richard
Derek has been helping me for some time and knows my computer. He didn't need to ask ram etc. I have 1 G ram and 1G harddrive. Less than 50% used.

Thank you, Derek and the others who have helped me. You can never know how much it's appreciated


Report •

#19
December 28, 2012 at 18:22:49

We are all pleased to help.

Just to clarify, Richard59 is a respected helper - I've seen him around these parts many times. Unfortunately computers are complex, so things can slip past any of us. Even Mary Poppins was only practically perfect LOL.

Always pop back and let us know the outcome - thanks


Report •

#20
December 28, 2012 at 22:02:51

To make sure you remove all bad toolbars run AdwCleaner.
Download AdwCleaner from this link:
AdwCleaner from this link:
http://www.bleepingcomputer.com/dow...
AdwCleaner Usage Instructions:
Using AdwCleaner is very simple. Simply download the program and run it. You will then be presented with a screen that contains a Search and Delete button. The Search button will cause AdwCleaner to search your computer for unwanted programs and then display a log showing the various files, folders, and registry entries used by these programs.
To delete these unwanted programs simply click on the Delete button, which will cause AdwCleaner to reboot your computer and remove the files and registry entries associated with the various adware that you are removing. On reboot, AdwCleaner will display a log showing the files, folders, and registry entries that were removed.
Please include the log in your next reply.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#21
December 28, 2012 at 22:10:23

I would also remove this entry with HJT:

R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#22
December 29, 2012 at 08:32:12

I couldn't find delete button after I did the search so I went back and hit delete, The computer did not reboot.This is the file after I had selected the ignore button in HJT for those reccommended be removed
And had hit delete in AWdCleaner
# AdwCleaner v2.103 - Logfile created 12/29/2012 at 08:04:12
# Updated 25/12/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : student - LOU
# Boot Mode : Normal
# Running from : C:\Documents and Settings\student\Desktop\AdwCleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\searchplugins\Conduit.xml
File Found : C:\Documents and Settings\student\Local Settings\Application Data\funmoods-speeddial.crx
File Found : C:\END
File Found : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
File Found : C:\user.js
File Found : C:\WINDOWS\system32\conduitEngine.tmp
File Found : C:\WINDOWS\Tasks\OpenCandyHelper.job
File Found : C:\WINDOWS\Tasks\OpenCandyHelperRun.job
File Found : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
Folder Found : C:\DOCUME~1\student\LOCALS~1\Temp\avg@toolbar
Folder Found : C:\DOCUME~1\student\LOCALS~1\Temp\CT3226470
Folder Found : C:\Documents and Settings\All Users\Application Data\AVG Secure Search
Folder Found : C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
Folder Found : C:\Documents and Settings\All Users\Application Data\Babylon
Folder Found : C:\Documents and Settings\All Users\Application Data\boost_interprocess
Folder Found : C:\Documents and Settings\All Users\Start Menu\Programs\Babylon
Folder Found : C:\Documents and Settings\student\Application Data\AVG Secure Search
Folder Found : C:\Documents and Settings\student\Application Data\Babylon
Folder Found : C:\Documents and Settings\student\Application Data\BabylonToolbar
Folder Found : C:\Documents and Settings\student\Application Data\Funmoods
Folder Found : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\CT3226470
Folder Found : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\CT3247201
Folder Found : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\extensions\{1930e38a-deef-4cf4-9bfb-9c4ea3689a9d}
Folder Found : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\extensions\{d7afcb11-48b7-4a75-86b4-91d1e3b20f35}
Folder Found : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\Smartbar
Folder Found : C:\Documents and Settings\student\Application Data\OpenCandy
Folder Found : C:\Documents and Settings\student\Application Data\PriceGong
Folder Found : C:\Documents and Settings\student\Application Data\searchquband
Folder Found : C:\Documents and Settings\student\Application Data\Searchqutoolbar
Folder Found : C:\Documents and Settings\student\Local Settings\Application Data\APN
Folder Found : C:\Documents and Settings\student\Local Settings\Application Data\AskToolbar
Folder Found : C:\Documents and Settings\student\Local Settings\Application Data\AVG Secure Search
Folder Found : C:\Documents and Settings\student\Local Settings\Application Data\Babylon
Folder Found : C:\Documents and Settings\student\Local Settings\Application Data\Conduit
Folder Found : C:\Documents and Settings\student\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Folder Found : C:\Program Files\Ask.com
Folder Found : C:\Program Files\AVG Secure Search
Folder Found : C:\Program Files\Babylon
Folder Found : C:\Program Files\BabylonToolbar
Folder Found : C:\Program Files\Common Files\AVG Secure Search
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\Free Offers from Freeze.com
Folder Found : C:\Program Files\Funmoods
Folder Found : C:\Program Files\Search Toolbar
Folder Found : C:\Program Files\Searchqu Toolbar
Folder Found : C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registry] *****

Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\ConduitSearchScopes
Key Found : HKCU\Software\Cr_Installer
Key Found : HKCU\Software\Crossrider
Key Found : HKCU\Software\Headlight
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Found : HKCU\Software\PriceGong
Key Found : HKCU\Software\SmartBar
Key Found : HKCU\Software\Softonic
Key Found : HKLM\Software\Babylon
Key Found : HKLM\Software\BabylonToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0003491.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0003491.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0003491.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0003491.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3226470
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3247201
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\Freeze.com
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Found : HKU\S-1-5-21-414633253-2918307282-3606858363-1005\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKU\S-1-5-21-414633253-2918307282-3606858363-1005\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Found : HKU\S-1-5-21-414633253-2918307282-3606858363-1005\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v [Unable to get version]

File : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\prefs.js

Found : user_pref("CT3226470.1000082.isDisplayHidden", "true");
Found : user_pref("CT3226470.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description[...]
Found : user_pref("CT3226470.3226470a129832954440787518000000paramsGK0", "eyJ1cGRhdGVSZXFUaW1lIjoxMzUwODYwNT[...]
Found : user_pref("CT3226470.CT3226470ads1", "JTdCJTIyYWRzJTIyJTNBJTVCJTdCJTIyYWlkJTIyJTNBJTIyMzY3MzIlMjIlMk[...]
Found : user_pref("CT3226470.CT3226470current_term", "AA==");
Found : user_pref("CT3226470.CT3226470sdate", "MjE=");
Found : user_pref("CT3226470.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3226470.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Found : user_pref("CT3226470.FirstTime", "true");
Found : user_pref("CT3226470.FirstTimeFF3", "true");
Found : user_pref("CT3226470.RSS_Pub_Config", "eyJzZXR0aW5ncyI6eyJpY29uIjoiaHR0cDovL3N0b3JhZ2UuY29uZHVpdC5jb[...]
Found : user_pref("CT3226470.RSSapp3226470a129832954440787518000000embeddedVersion", "Mi40LjA=");
Found : user_pref("CT3226470.RSSapp3226470a129832954440787518000000lastReportTime", "MTM1MDg2MDUzMzMyNSA=");
Found : user_pref("CT3226470.RSSapp3226470a129832954440787518000000newFeeds", "bmV3RmVlZHM=");
Found : user_pref("CT3226470.UserID", "UN66065693742988193");
Found : user_pref("CT3226470.addressBarTakeOverEnabledInHidden", "true");
Found : user_pref("CT3226470.autoDisableScopes", -1);
Found : user_pref("CT3226470.cbcountry_001", "VVM=");
Found : user_pref("CT3226470.cbfirsttime", "U2F0IE9jdCAyMCAyMDEyIDE4OjAxOjU5IEdNVC0wNzAwIChQYWNpZmljIERheWxp[...]
Found : user_pref("CT3226470.defaultSearch", "false");
Found : user_pref("CT3226470.embeddedsData", "[{\"appId\":\"129832954438287509\",\"apiPermissions\":{\"cross[...]
Found : user_pref("CT3226470.enableAlerts", "never");
Found : user_pref("CT3226470.enableSearchFromAddressBar", "true");
Found : user_pref("CT3226470.firstTimeDialogOpened", "true");
Found : user_pref("CT3226470.fixPageNotFoundError", "true");
Found : user_pref("CT3226470.fixPageNotFoundErrorInHidden", "true");
Found : user_pref("CT3226470.fixUrls", true);
Found : user_pref("CT3226470.installId", "conduitinstaller.exe");
Found : user_pref("CT3226470.installType", "conduitnsisintegration");
Found : user_pref("CT3226470.isCheckedStartAsHidden", true);
Found : user_pref("CT3226470.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3226470.isFirstTimeToolbarLoading", "false");
Found : user_pref("CT3226470.isNewTabEnabled", false);
Found : user_pref("CT3226470.isPerformedSmartBarTransition", "true");
Found : user_pref("CT3226470.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Found : user_pref("CT3226470.migrateAppsAndComponents", true);
Found : user_pref("CT3226470.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"\",\"[...]
Found : user_pref("CT3226470.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Found : user_pref("CT3226470.openThankYouPage", "false");
Found : user_pref("CT3226470.openUninstallPage", "true");
Found : user_pref("CT3226470.search.searchAppId", "129832954438287509");
Found : user_pref("CT3226470.search.searchCount", "0");
Found : user_pref("CT3226470.searchInNewTabEnabled", "false");
Found : user_pref("CT3226470.searchInNewTabEnabledInHidden", "true");
Found : user_pref("CT3226470.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3226470.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Found : user_pref("CT3226470.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Found : user_pref("CT3226470.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Found : user_pref("CT3226470.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Found : user_pref("CT3226470.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Found : user_pref("CT3226470.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-cnet_lastUpdate", "1350860626853");
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-cnnbrk_lastUpdate", "1350860627235");
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-computeractive_lastUpdate", "13508606273[...]
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-dailymirror_lastUpdate", "1350860627295"[...]
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-google_lastUpdate", "1350860626795");
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-techcrunch_lastUpdate", "1350860626563")[...]
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-time_lastUpdate", "1350860627810");
Found : user_pref("CT3226470.serviceLayer_services_app.twitter.user-wired_lastUpdate", "1350860627753");
Found : user_pref("CT3226470.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1350462592645");
Found : user_pref("CT3226470.serviceLayer_services_appsMetadata_lastUpdate", "1350860604943");
Found : user_pref("CT3226470.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1350462601910");
Found : user_pref("CT3226470.serviceLayer_services_login_10.13.1.89_lastUpdate", "1350860607339");
Found : user_pref("CT3226470.serviceLayer_services_optimizer_lastUpdate", "1350781302009");
Found : user_pref("CT3226470.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1350462602379");
Found : user_pref("CT3226470.serviceLayer_services_searchAPI_lastUpdate", "1350860607621");
Found : user_pref("CT3226470.serviceLayer_services_serviceMap_lastUpdate", "1350860603170");
Found : user_pref("CT3226470.serviceLayer_services_toolbarContextMenu_lastUpdate", "1350462602166");
Found : user_pref("CT3226470.serviceLayer_services_toolbarSettings_lastUpdate", "1350860605235");
Found : user_pref("CT3226470.serviceLayer_services_translation_lastUpdate", "1350860603500");
Found : user_pref("CT3226470.settingsINI", true);
Found : user_pref("CT3226470.shouldFirstTimeDialog", "true");
Found : user_pref("CT3226470.smartbar.CTID", "CT3226470");
Found : user_pref("CT3226470.smartbar.Uninstall", "0");
Found : user_pref("CT3226470.smartbar.toolbarName", "PDFSpin ");
Found : user_pref("CT3226470.startPage", "false");
Found : user_pref("CT3226470.toolbarBornServerTime", "17-10-2012");
Found : user_pref("CT3226470.toolbarCurrentServerTime", "22-10-2012");
Found : user_pref("CT3226470.url_history0001", "aHR0cDovL3d3dy5wZGZjb3JlLmNvbS9wMDJfYWR2YW5jZWRvY3JmcmVlL2hv[...]
Found : user_pref("CT3226470_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...]
Found : user_pref("CT3247201.1000082.isPlayDisplay", "true");
Found : user_pref("CT3247201.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description[...]
Found : user_pref("CT3247201.1000234.TWC_TMP_city", "FAIR OAKS");
Found : user_pref("CT3247201.1000234.TWC_TMP_country", "US");
Found : user_pref("CT3247201.1000234.TWC_locId", "USCA0362");
Found : user_pref("CT3247201.1000234.TWC_location", "Fair Oaks, CA");
Found : user_pref("CT3247201.1000234.TWC_region", "US");
Found : user_pref("CT3247201.1000234.TWC_temp_dis", "f");
Found : user_pref("CT3247201.1000234.TWC_wind_dis", "mph");
Found : user_pref("CT3247201.1000234.weatherData", "{\"icon\":\"28.png\",\"temperature\":\"61°F\",\"temperat[...]
Found : user_pref("CT3247201.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3247201.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Found : user_pref("CT3247201.FirstTime", "true");
Found : user_pref("CT3247201.FirstTimeFF3", "true");
Found : user_pref("CT3247201.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT324[...]
Found : user_pref("CT3247201.UserID", "UN83132851619460141");
Found : user_pref("CT3247201.addressBarTakeOverEnabledInHidden", "true");
Found : user_pref("CT3247201.autoDisableScopes", -1);
Found : user_pref("CT3247201.browser.search.defaultthis.engineName", true);
Found : user_pref("CT3247201.defaultSearch", "true");
Found : user_pref("CT3247201.embeddedsData", "[{\"appId\":\"10000002\",\"apiPermissions\":{\"crossDomainAjax[...]
Found : user_pref("CT3247201.enableAlerts", "always");
Found : user_pref("CT3247201.enableSearchFromAddressBar", "true");
Found : user_pref("CT3247201.firstTimeDialogOpened", "true");
Found : user_pref("CT3247201.fixPageNotFoundError", "true");
Found : user_pref("CT3247201.fixPageNotFoundErrorInHidden", "true");
Found : user_pref("CT3247201.fixUrls", true);
Found : user_pref("CT3247201.hxxp___pinterest_aot_im.isEnabled", "Y");
Found : user_pref("CT3247201.installId", "air1D.exe");
Found : user_pref("CT3247201.installType", "ConduitNSISIntegration");
Found : user_pref("CT3247201.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3247201.isNewTabEnabled", true);
Found : user_pref("CT3247201.isPerformedSmartBarTransition", "true");
Found : user_pref("CT3247201.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Found : user_pref("CT3247201.keyword", true);
Found : user_pref("CT3247201.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"\",\"[...]
Found : user_pref("CT3247201.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Found : user_pref("CT3247201.openThankYouPage", "false");
Found : user_pref("CT3247201.openUninstallPage", "true");
Found : user_pref("CT3247201.search.searchAppId", "10000002");
Found : user_pref("CT3247201.search.searchCount", "0");
Found : user_pref("CT3247201.searchInNewTabEnabledInHidden", "true");
Found : user_pref("CT3247201.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3247201.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Found : user_pref("CT3247201.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Found : user_pref("CT3247201.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Found : user_pref("CT3247201.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Found : user_pref("CT3247201.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Found : user_pref("CT3247201.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Found : user_pref("CT3247201.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data[...]
Found : user_pref("CT3247201.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1350353764654");
Found : user_pref("CT3247201.serviceLayer_services_appsMetadata_lastUpdate", "1350860612284");
Found : user_pref("CT3247201.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1350353764673");
Found : user_pref("CT3247201.serviceLayer_services_login_10.10.27.6_lastUpdate", "1350860611934");
Found : user_pref("CT3247201.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1350353764363");
Found : user_pref("CT3247201.serviceLayer_services_searchAPI_lastUpdate", "1350860612184");
Found : user_pref("CT3247201.serviceLayer_services_serviceMap_lastUpdate", "1350860611707");
Found : user_pref("CT3247201.serviceLayer_services_toolbarContextMenu_lastUpdate", "1350353764115");
Found : user_pref("CT3247201.serviceLayer_services_toolbarSettings_lastUpdate", "1350860612251");
Found : user_pref("CT3247201.serviceLayer_services_translation_lastUpdate", "1350860612358");
Found : user_pref("CT3247201.settingsINI", true);
Found : user_pref("CT3247201.shouldFirstTimeDialog", "false");
Found : user_pref("CT3247201.smartbar.CTID", "CT3247201");
Found : user_pref("CT3247201.smartbar.Uninstall", "0");
Found : user_pref("CT3247201.smartbar.homepage", true);
Found : user_pref("CT3247201.smartbar.toolbarName", "InternetHelper1.5 ");
Found : user_pref("CT3247201.toolbarBornServerTime", "23-9-2012");
Found : user_pref("CT3247201.toolbarCurrentServerTime", "22-10-2012");
Found : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3247201&SearchSource=1[...]
Found : user_pref("Smartbar.ConduitSearchEngineList", "InternetHelper1.5 Customized Web Search");
Found : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3247201[...]
Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3247201");
Found : user_pref("browser.search.defaultenginename", "Claro Search");
Found : user_pref("browser.search.order.1", "Claro Search");
Found : user_pref("browser.search.selectedEngine", "InternetHelper1.5 Customized Web Search");
Found : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3247201&SearchSource=13");
Found : user_pref("extensions.BabylonToolbar_i.newTab", true);
Found : user_pref("extensions.BabylonToolbar_i.newTabUrl", "about:home");
Found : user_pref("extensions.claro.admin", false);
Found : user_pref("extensions.claro.aflt", "babsst");
Found : user_pref("extensions.claro.cntry", "US");
Found : user_pref("extensions.claro.dfltLng", "en");
Found : user_pref("extensions.claro.envrmnt", "production");
Found : user_pref("extensions.claro.excTlbr", false);
Found : user_pref("extensions.claro.hdrMd5", "AF2D8C744192B324C55729C0718F8F98");
Found : user_pref("extensions.claro.hmpg", false);
Found : user_pref("extensions.claro.id", "320d180e0000000000000016ec19e711");
Found : user_pref("extensions.claro.instlDay", "15630");
Found : user_pref("extensions.claro.instlRef", "sst");
Found : user_pref("extensions.claro.lastVrsnTs", "1.6.4.117:29:57");
Found : user_pref("extensions.claro.mntrvrsn", "1.3.1");
Found : user_pref("extensions.claro.newTab", false);
Found : user_pref("extensions.claro.prdct", "claro");
Found : user_pref("extensions.claro.prtnrId", "claro");
Found : user_pref("extensions.claro.sg", "none");
Found : user_pref("extensions.claro.smplGrp", "none");
Found : user_pref("extensions.claro.tlbrId", "claro");
Found : user_pref("extensions.claro.vrsn", "1.6.4.1");
Found : user_pref("extensions.claro.vrsnTs", "1.6.4.117:29:57");
Found : user_pref("extensions.claro.vrsni", "1.6.4.1");
Found : user_pref("extensions.claro_i.smplGrp", "none");
Found : user_pref("extensions.claro_i.vrsnTs", "1.6.4.117:29:57");
Found : user_pref("extensions.crossriderapp3491.3491.InstallationThankYouPage", true);
Found : user_pref("extensions.crossriderapp3491.3491.InstallationTime", 1350433171);
Found : user_pref("extensions.crossriderapp3491.3491.InstallationUserSettings.searchUserConifrmation", false[...]
Found : user_pref("extensions.crossriderapp3491.3491.InstallationUserSettings.setHomepage", false);
Found : user_pref("extensions.crossriderapp3491.3491.InstallationUserSettings.setNewTab", false);
Found : user_pref("extensions.crossriderapp3491.3491.InstallationUserSettings.setSearch", false);
Found : user_pref("extensions.crossriderapp3491.3491.active", true);
Found : user_pref("extensions.crossriderapp3491.3491.addressbar", "");
Found : user_pref("extensions.crossriderapp3491.3491.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG_NEW&&[...]
Found : user_pref("extensions.crossriderapp3491.3491.backgroundver", 11);
Found : user_pref("extensions.crossriderapp3491.3491.can_run_bg_code", true);
Found : user_pref("extensions.crossriderapp3491.3491.certdomaininstaller", "");
Found : user_pref("extensions.crossriderapp3491.3491.changeprevious", false);
Found : user_pref("extensions.crossriderapp3491.3491.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie.InstallationTime.value", "1350433171");
Found : user_pref("extensions.crossriderapp3491.3491.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 [...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_aoi.value", "1350433171");
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_blocklist.expiration", "Tue Oct 16 2012 17:[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_blocklist.value", "%22nonexistantdomain.com[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_country_code.expiration", "Tue Oct 23 2012 [...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_country_code.value", "%22US%22");
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 [...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_crr.value", "1350443433");
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 [...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_hotfix20111102645.value", "%221%22");
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_installer_params.value", "%7B%22source_id%2[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_parent_zoneid.value", "%2214019%22");
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_pc_20120828.value", "1350443453276");
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_product_id.value", "%221140%22");
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie._GPL_zoneid.value", "%2294258%22");
Found : user_pref("extensions.crossriderapp3491.3491.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[...]
Found : user_pref("extensions.crossriderapp3491.3491.cookie.dbtest.value", "1350434896889");
Found : user_pref("extensions.crossriderapp3491.3491.description", "Vid-Saver allows you to download your fa[...]
Found : user_pref("extensions.crossriderapp3491.3491.domain", "");
Found : user_pref("extensions.crossriderapp3491.3491.enablesearch", false);
Found : user_pref("extensions.crossriderapp3491.3491.fbremoteurl", "");
Found : user_pref("extensions.crossriderapp3491.3491.group", 0);
Found : user_pref("extensions.crossriderapp3491.3491.homepage", "");
Found : user_pref("extensions.crossriderapp3491.3491.iframe", false);
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.InstallerIdentifiers.expiration", "Fri Feb 0[...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.InstallerIdentifiers.value", "%7B%22installe[...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_appVer.value", "54");
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_lastVersion.expiration", "Fri Feb [...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_lastVersion.value", "0");
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_meta.value", "%7B%7D");
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_nextCheck.expiration", "Tue Oct 16[...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_nextCheck.value", "true");
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.Resources_queue.value", "%7B%7D");
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.SoftwareDetected.expiration", "Fri Feb 01 20[...]
Found : user_pref("extensions.crossriderapp3491.3491.internaldb.SoftwareDetected.value", "%7B%22AnySoftware%[...]
Found : user_pref("extensions.crossriderapp3491.3491.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...]
Found : user_pref("extensions.crossriderapp3491.3491.manifesturl", "");
Found : user_pref("extensions.crossriderapp3491.3491.name", "Vid-Saver");
Found : user_pref("extensions.crossriderapp3491.3491.newtab", "");
Found : user_pref("extensions.crossriderapp3491.3491.opensearch", "");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_1000014.ver", 6);
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_1000015.name", "GPL Background (BG)");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_1000015.ver", 3);
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_13.code", "(function(a){a.selectedText=f[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_13.name", "CrossriderAppUtils");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_13.ver", 2);
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_14.name", "CrossriderUtils");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_14.ver", 2);
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_15.code", "(function(f){var u={};var e=M[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_15.name", "FacebookFFIE");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_15.ver", 1);
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_16.code", "(function(f,b){if(typeof(b)==[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_16.name", "FFAppAPIWrapper");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_16.ver", 3);
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_17.code", "if(typeof window!==\"undefine[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_17.name", "jQuery");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_17.ver", 3);
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_47.code", "(function(){appAPI.ready=func[...]
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_47.name", "resources_background");
Found : user_pref("extensions.crossriderapp3491.3491.plugins.plugin_47.ver", 1);
Found : user_pref("extensions.crossriderapp3491.3491.plugins_lists.plugins_0", "17,14,16,47,1000015");
Found : user_pref("extensions.crossriderapp3491.3491.plugins_lists.plugins_1", "17,14,13,16,15,1000014");
Found : user_pref("extensions.crossriderapp3491.3491.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...]
Found : user_pref("extensions.crossriderapp3491.3491.pluginsversion", 15);
Found : user_pref("extensions.crossriderapp3491.3491.publisher", "215 Apps");
Found : user_pref("extensions.crossriderapp3491.3491.searchstatus", 0);
Found : user_pref("extensions.crossriderapp3491.3491.setnewtab", false);
Found : user_pref("extensions.crossriderapp3491.3491.settingsurl", "");
Found : user_pref("extensions.crossriderapp3491.3491.thankyou", "hxxp://vid-saver.com/thankyou.html");
Found : user_pref("extensions.crossriderapp3491.3491.updateinterval", 360);
Found : user_pref("extensions.crossriderapp3491.3491.ver", 54);
Found : user_pref("extensions.crossriderapp3491.adsOldValue", -1);
Found : user_pref("extensions.crossriderapp3491.apps", "3491");
Found : user_pref("extensions.crossriderapp3491.bic", "13a6c191b1857a8647dce442dc6d74a8");
Found : user_pref("extensions.crossriderapp3491.cid", 3491);
Found : user_pref("extensions.crossriderapp3491.firstrun", false);
Found : user_pref("extensions.crossriderapp3491.hadappinstalled", true);
Found : user_pref("extensions.crossriderapp3491.installationdate", 1350433316);
Found : user_pref("extensions.crossriderapp3491.lastcheck", 22507222);
Found : user_pref("extensions.crossriderapp3491.lastcheckitem", 22507391);
Found : user_pref("extensions.crossriderapp3491.modetype", "production");
Found : user_pref("extensions.crossriderapp3491.reportInstall", true);
Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3247201&SearchSource=2&q=[...]

-\\ Google Chrome v19.0.1084.52

File : C:\Documents and Settings\student\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [32516 octets] - [29/12/2012 08:04:12]

########## EOF - C:\AdwCleaner[R1].txt - [32577 octets] ##########


Report •

#23
December 29, 2012 at 08:38:01

This is the HJT file after hitting the ignote button
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:34:17 AM, on 12/29/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\Program Files\Yahoo!\Companion\Installs\cpn8\ytbb.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\DAP\DAP.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/1503...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - http://h20270.www2.hp.com/ediags/gm...
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/1503...
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Unknown owner - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: VideoAcceleratorService - SpeedBit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 8880 bytes


Report •

#24
December 29, 2012 at 08:41:18

Chim chim ckim charee or something like that Ha

Report •

#25
December 29, 2012 at 08:56:23

WHATEVER DID IT= The paste function works in Word now Computer is still slow Anything else I should do to improve computer performance.?
I don't know which of all you wonderful people to select as best answer
THANKS
TO ALL

Report •

#26
December 29, 2012 at 10:00:02

I'll leave the AWdCleaner log for MrGoodguy to check over as he is more experienced with that program than I am. The HJT log looks cleaner now, so if he is happy with that too then so am I.

After we are sure the computer is virus free we can look at why it is slow, if necessary.

Always pop back and let us know the outcome - thanks


Report •

#27
December 29, 2012 at 10:49:40

AdwCleaner log looks great, picked up a lot of stuff :)
I would like you to run ESET's online scanner now for anything we missed?
http://www.eset.com/online-scanner-...

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#28
December 29, 2012 at 12:18:43

ESET "NO THREATS FOUND"
Can anything be done to improve speed or do I just live with it? It's not as if the computer were unusable
I haven't seen the "program not responding recently either. Something may have solved that also

Report •

#29
December 29, 2012 at 12:23:40

We need to remove the infection and damage first, then we can move on to your speed up issues. You are doing a great job. :)

Now to fix a few things:
Download Tweaking's - All In One tool from this link:
http://www.tweaking.com/content/pag...
Run tool, on the first page go to far right tab Start repairs, it will ask to make a restore point please allow this.

Check mark the following fixes only;
Reset File Permissions
Reset Registry Permissions
Register System Files
Remove Policies Set By Infection

On the far right click the Start button. Warning do not fix anything else please.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#30
December 29, 2012 at 12:39:29

Collou,
In post#22 - "I couldn't find delete button after I did the search so I went back and hit delete, The computer did not reboot."

So you did the AdwCleaner scan (search), but it would not allow deletion of things found? Nor did it reboot after it finished?
We need to rescan with AdwCleaner.

Have a look at this Britec - YouTube clip and find the part about AdwCleaner only. Time frame 4:40

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#31
December 29, 2012 at 13:11:20

I re-downloade Adwcleaner and clicked search. This gave me a log record but no where can I find a delete button except on the same page as search. what am i doing wrong?
Also your link to Britec doesn't work. I'm not sue if I can view Utube anyway and my speakers are not working. Have to ask you about that another time

Report •

#32
December 29, 2012 at 13:15:49

That is correct, just close the unsaved log and click the Delete button and it will begin the cleanup. It will then ask to reboot to continue cleaning allow this. It will then restart your pc, finishing off the cleaning and saving the log.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#33
December 29, 2012 at 13:25:22

Post #30 Sorry I missed the link :)
Britec - Youtube clip http://www.youtube.com/watch?v=dvnG...
Time Frame 4.40

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#34
December 29, 2012 at 13:30:31

Ok, so i did as instructed. ADwCleaner deleted files and system rebooted. So where go from here?I'm going to proceed to tweakings, Hope this is correct step

Report •

#35
December 29, 2012 at 13:35:28

"Ok, so i did as instructed. ADwCleaner deleted files and system rebooted." - Excellent :) Can you post the log please.

Post #21 - Did you remove this entry?
R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll

Post #29 - Have you run the Windows Repair Tool - All In One?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#36
December 29, 2012 at 14:18:19

I must have removed it, don't see it there in HJT
Forgive me for being dense but where do I find Windows repair tool? I don't think I ran it but I'm getting punchy

Report •

#37
December 29, 2012 at 14:21:30

"I must have removed it, don't see it there in HJT" - Just went through the new HJT log, and yes its gone :)

"where do I find Windows repair tool?" - Post # 29 has the link and instructions.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#38
December 29, 2012 at 14:25:08

"I'm getting punchy" - If you wan't to go to bed that's fine :) We can help when you get back?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#39
December 29, 2012 at 14:33:56

It's not that I need to go to bed bed but i think i need a break. It's only about 2:30 Pm here in Ca.
I saw that you are in New Zealand. correct? What time is it there?
I love this forum. Derek is in England, I've had help from Canada and of course the U.S
I'll check back in, in about an hour, if that fits your time frame.I'm often up til 4:00 in the morning so whatever fits you , fits me

Report •

#40
December 29, 2012 at 14:39:36

I saw that you are in New Zealand. correct? What time is it there?
Yes New Zealand is home :) And it's 11.40am here.

Yes take a break I will check back in an hour also, i'm off to have a coffee and some lunch :)

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#41
December 29, 2012 at 16:30:16

I'm baaack
Here is the new ADW file
# AdwCleaner v2.104 - Logfile created 12/29/2012 at 16:27:00
# Updated 29/12/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : student - LOU
# Boot Mode : Normal
# Running from : C:\Documents and Settings\student\Desktop\AdwCleaner_1_1.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v [Unable to get version]

File : C:\Documents and Settings\student\Application Data\Mozilla\Firefox\Profiles\24zc3dbo.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v19.0.1084.52

File : C:\Documents and Settings\student\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [32647 octets] - [29/12/2012 08:04:12]
AdwCleaner[R2].txt - [32708 octets] - [29/12/2012 08:17:37]
AdwCleaner[R3].txt - [33310 octets] - [29/12/2012 13:06:52]
AdwCleaner[R4].txt - [33371 octets] - [29/12/2012 13:18:54]
AdwCleaner[S2].txt - [33601 octets] - [29/12/2012 13:19:57]
AdwCleaner[R5].txt - [1200 octets] - [29/12/2012 16:27:00]

########## EOF - C:\AdwCleaner[R5].txt - [1260 octets] ##########


Report •

#42
December 29, 2012 at 16:31:54

I downloaded the folder Tweak but when I open all files I don't see the page you referred to.The first option is a folder titled registry backup tool

Report •

#43
December 29, 2012 at 16:43:48

Here is the BleepingComputers download link to the tool and instruction for use with screenshots.
http://www.bleepingcomputer.com/dow...
We are only using the Start Repairs tab far right.

Check mark the following fixes only;
Reset File Permissions
Reset Registry Permissions
Register System Files
Remove Policies Set By Infection

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#44
December 29, 2012 at 16:54:41

How do i get it to download without all the 7Zip and other offerings?
I can't get to the correct file

Report •

#45
December 29, 2012 at 17:05:38

Right click the zip folder and extract all. (There are no other offerings)
Inside the unzipped folder look for the Repair_Windows.exe Tweaking.com icon. Click the icon to Run the tool. - It should just open to the homepage of the tool.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#46
December 29, 2012 at 17:07:37

If your pc can't open a 7zip file it will ask to install it. Please allow this. It is safe to do so. Just do not accept any toolbar offers :)

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#47
December 29, 2012 at 18:22:16

I think I did a no-no. I started the repair of only the 4 items you suggested. After a while I noticed the warning "disable anti virus" This I did and restarted the repair. About half way through I got" PSE..exe Application error" application failed to initialize Click Ok to terminate" which I did. The program continued. But a short time later I got "PSEexe at 0x00402b46 memory not read Click Ok to terminate Program continued for about a minue, then reverted back to the start page. I did do a restore point and backup before I started the repair . Hope I haven't done something irreversible

Report •

#48
December 29, 2012 at 18:37:59

In this case you could have left your AV on, during the fix.
Restart your pc and see if that fixes the error? It's not part of the Windows Repair tool.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#49
December 29, 2012 at 18:41:29

So do you want me to restart tweaking? I have already rebooted

Report •

#50
December 29, 2012 at 18:42:40

Yes, please start the Repair tool.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#51
December 29, 2012 at 19:12:16

It got through 2 of 4 and then reverted to the start page- What now?

Report •

#52
December 29, 2012 at 19:14:23

How is the pc running other than that problem?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#53
December 29, 2012 at 19:25:25

Well, the only thing I have done is checked my email and opened facebook one time since we started here.
As far as I know Ok except slow. I do have another problem that I tried to find a solution for some time back.The "send to disappeared.My Dvr drives don't appear in Send to so I can't burn any disks.After trying many things, it was reccommended that I do a xp rpair. I never got around to doing it. because i understand I would have to re-update everything. Any suggestions? It would be nice to have back.

Report •

#54
December 29, 2012 at 19:32:44

I don't know what's going on with the last post. It won't let me edit it. But this what I wrote Well, the only thing I have done is checked my email and opened facebook one time since we started here.
As far as I know Ok except slow. I do have another problem that I tried to find a solution for some time back.The "send to disappeared.My Dvr drives don't appear in Send to so I can't burn any disks.After trying many things, it was reccommended that I do a xp rpair. I never got around to doing it. because i understand I would have to re-update everything. Any suggestions? It would be nice to have back.
Looks lke I've been hacked My post are not My posts are not showing and I dont know who the new person is

Report •

#55
December 29, 2012 at 19:38:22

"Ok except slow." - Lets look at the slowness.

For faster boot time run Bootvis from this link:
http://www.softpedia.com/get/Tweak/...

Two links for advice on speeding up Windowsxp:
http://www.wikihow.com/Dramatically...
http://www.auslogics.com/en/article...

Auslogics Disk Defrag software, when it scans select the Optimize and Defrag option:
http://auslogics-disk-defrag.en.sof...

"The "send to disappeared.My Dvr drives don't appear in Send to so I can't burn any disks." - I have no idea on that one? So will let Derek continue helping you or maybe another helper has a solution?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#56
December 29, 2012 at 20:30:08

It was Dereks solution to do xp repair Just thought you might have a simple. fix I''d never secoond guess him. He has been a life saver for me.
Something strange happened just before this post- When i tried to reply all my previous posts went wacky. Only partially there. I tried to edit and send a reply couldn't do it. I had to re-boot to get back in here.I thought I saw an unknown name (helper) pop up but I don't see him/her now. Wonder if I I might have somehow contracted a virus while Avast was temorraly disabled

Report •

#57
December 29, 2012 at 20:40:46

You guys are utterly mazing. Your knowledge, Where to go for fixes, your knowlwdge about them and how to use them All that and more PLUS your patience and time spent with me. I can never thank you enough

I'm callling it quits for tonight. Guess about everything has been done that can be done


Report •

#58
December 29, 2012 at 20:48:39

"Wonder if I I might have somehow contracted a virus while Avast was temorraly disabled" - Update and run a full scan with Malwarebytes.

"You guys are utterly mazing. Your knowledge, Where to go for fixes, your knowlwdge about them and how to use them All that and more PLUS your patience and time spent with me. I can never thank you enough" - Thank you for the kind words :) For a 79 y.o. pc user, you are the amazing one!

"I'm calling it quits for tonight. Guess about everything has been done that can be done" - We will keep an eye out for you, and will try and find a fix for you.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#59
December 30, 2012 at 09:32:06

If there are any issues after you've run MalwareBytes just shout back.

Always pop back and let us know the outcome - thanks


Report •

#60
December 30, 2012 at 10:04:43

I have a REAL PROBLEM I am posting this from a different computer than the one with the problem The problem got progressively worse as I wrote this.

The last thing I was doing lst night was using the Tweak program. It Stalled before it could complete all it was supposed to do. I had inadvertently clicked the 7Zip download button, I’ sure this is the source of my problem.
This morning when I booted up I got IE to open one time. Now it won’t open at all. When I click on it all I get is “create shortcut, rename” Then it creates a shortcut and the IE icon disappears from desktop. When I tried to search Google,, a line of many 7’s is what showed. I tried to use adda nd remove oto remove 7 Zip- Said cannot uninstall, May have already been removed. .I went to Start/control ; panel again to try to remove to try to remove- Now- Add/Remove currently install is blank
I tried to go to run to doa restore. Run will not open. All programs will not open.

I’m sending this from second computer.
Again IE will not open so I CAN”T ACCESS EMAIL OR ANYTHING ELSE>
I did create a new Hijack This file for you to look at but I can’t send it to you.

I’m hoping a tool can be downloaded to disk from this computer and hoping that it would open on Computer #1.
I know I’m rambling but I need HELP As I wrote this things have gotten worse. Now I can’t turn off or restart from START when I click “restart or turn off” nothiing happens.

I did a scan, both quick anf ull, using Avast get "NO THREATS FOUND'"
I unplugged the computer hoping a reboot might fix something. Now It won’t boot at all. Just a blue screen and Windows Xp
I know I have rambled but I NEED HELP


Report •

#61
December 30, 2012 at 11:32:32

Is the blue screen showing any error numbers or causes?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#62
December 30, 2012 at 11:44:02

no it is not

Report •

#63
December 30, 2012 at 11:45:23

Can you get into safe mode at all?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#64
December 30, 2012 at 11:48:50

I have not tried. Keep clicking F8 right?

Report •

#65
December 30, 2012 at 11:52:14

Yes tapping F8 on boot is correct.
Do you have anything on this pc you really need to recover?
Do you have a Windows CD?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#66
December 30, 2012 at 11:59:54

I don't know what you mean " that I really need to recover" I'd like to recover everything except the last I suppose I don't HAVE to recover all but-----
YES< I CAN GET INTO SAFE MODE

Report •

#67
December 30, 2012 at 12:06:36

"Yes tapping F8 on boot is correct." - Are you able to open Safe Mode?

"Do you have anything on this pc you really need to recover?" - Recover important pictures, documents etc? Or can everything be lost?

"Do you have a Windows CD?" - You normally get a copy of your Windows install,
so you can reinstall Windows if it gets damaged or is in need of repair?

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#68
December 30, 2012 at 12:08:07

Run a full Malwarebytes scan from Safe Mode.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#69
December 30, 2012 at 12:31:49

I don't have Malwarebytes saved anywhere. How do I access it?
I tried to boot from safe mode using last good settings that worked -No luck

Report •

#70
December 30, 2012 at 12:44:09

Download the latest version of Malwarebytes from your clean pc to a flash drive, then install it onto the infected pc.
http://www.malwarebytes.org/product...

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#71
December 30, 2012 at 13:36:33

Ok I've downloaadeed Malwarebytes to an external HD but how do I install it on the other pc when it won't boot?
I unplugged it several time and got it go through consistency etc Thought it was going to boot but nope
It won't boot from safe mode. I get a whole list of things but it doesn't boot. I haven't tried Safe mode with networking. The only thing i have done is click on Safe mode and click enter As you can see I don't know what I'm doing

Report •

#72
December 30, 2012 at 14:20:40

Can you do one simple thing on the dodgy computer - it might not help but it's worth a try because it is very easy to do.

Disconnect the power lead from the computer. Next hold the power off/on button in for about 20 seconds. Put the power back in and see if it then boots up.

EDIT:
Sorry, remind me - is it a tower or a desktop computer?
What MrGoodguy meant was are there any important files you need to recover (in case we have to use big guns on it)?

Always pop back and let us know the outcome - thanks


Report •

#73
December 30, 2012 at 15:50:59

I thought it was going to work. Got to press F1 to continue but that was it
I have, I think a complete backup of all files on an external HD. t least that's what I intended when I put them there. I have never opened the file. There ae a few file from more recently but none very imporant, I guess and as far that is concerned, I have most of the same files on this unit as the other
Please tell me that an xp repair will do the job not a reinstall' I have 2 Xp disks but don't know if they work
I'm watching the last 15 min of a 49er football game so will check back after that

Report •

#74
December 30, 2012 at 16:11:41

Best check that external HD on another computer before we go any further.

This is the repair install procedure:
http://michaelstevenstech.com/XPrep...

Bit of a mouthful I'm afraid and it relies on the XP disk and drive being OK.
The first step is to ensure your CD/DVD is ahead of the HD in BIOS. If you don't know how to get there and do that we'll need your exact computer name and model.

One quick way to see if the BIOS is already set that way is to pop one of your XP disks in then power off and on again. If it tries to boot but nothing is any different then it needs to be set. If you get a Windows install screen it is already set right, so you back out of it for now - we don't want an extra install.

EDIT:
Bedtime now.

Always pop back and let us know the outcome - thanks


Report •

#75
December 30, 2012 at 19:07:36

I printed the How to so I will have that in hand.
I inserted xp disk It cmae back to blue screen This is strange because when everything was working, I once inserted XP and the Install appeared. Might be this disk?
Are you still up? How long will you be or when will you be available next.? It's 7:07 Pm here
the computer is Acer Power S280
It is a desktop
I checked the external HD on this computer- Works fine

Report •

#76
December 30, 2012 at 19:13:35

Touch of insomnia......

Try this instead (Last known good configuration):
http://www.computerhope.com/issues/...

Back to bed.

Always pop back and let us know the outcome - thanks


Report •

#77
December 30, 2012 at 19:57:19

Didnt work. What is Directory services estore (windows domain controller only)?
Should I try that-? This is most frustrating
if you are still up about what time will you be available?

Report •

#78
December 30, 2012 at 20:35:02

Lets try Safe Mode with Command Prompt. If command prompt opens type ‘explorer.exe‘ and press the Enter key, wait for Windows Explorer to open. If it starts Windows? Look in ‘My Computer’ browse to your removable drives for Malwarebytes.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#79
December 31, 2012 at 08:21:25

In #77 you say it "didn't work". Was the option available and what exactly happened when you tried it? Nothing at all or some error message?

If #78 doesn't help here is another option - System Restore from Command Prompt:
http://support.microsoft.com/kb/304449
The command at #5 has to be "exactly" as shown. "Directory services restore" is much the same as this and command prompt has a slightly better chance of working.

You still might have to do the Repair but we are trying easier options first.

I should be around, on and off, for the next 8 or 9 hours. We can't be too predictable because we have to slot this activity into our spare time as best we can.

Always pop back and let us know the outcome - thanks


Report •

#80
December 31, 2012 at 10:09:56

I tried using safe mode -safe- command prompt- I get the same blue screen each time. No error measage appears. Only Windows XP
Neither XP disk will get as far as the Install stage- Again only blue screen

The computer is Acer Power S280
There is no rush needed to fix this problem. next year is Ok with me me I greatly appreciate all the time you have put in already
Again, Thanks- Happy New Year


Report •

#81
December 31, 2012 at 11:06:50

Just to recap - is this right?:

Whatever you type in command prompt produces some kind of blue screen with XP on it. Same thing happens with either XP disk. There is a blue screen which is quite familiar to us - this one:
http://www.bing.com/images/search?q...
What you are describing sounds different. Any more info you can give on it?

Is it true to say that no Safe Mode option works?

Seems you need to attempt the repair option given earlier. This will only work if one of your disks is a good one (and if it lets us).

Otherwise a fresh install should do it but this loses everything and still requires a good XP disk. I hope you know your product key (possibly written on the case).

There is one more point to add. We are assuming this is a software fault because it happened just after you were running a program. There is still the possibility that by coincidence you hit a hardware problem. One way to help prove this is to run a Puppy Linux CD on it. If this runs and you can view your HD contents using it, then it will give us more confidence in the hardware. If you want to try this first before attempting the repair I will give you the info.

Always pop back and let us know the outcome - thanks


Report •

#82
December 31, 2012 at 11:43:01

Yes, the blue screen is different than the one shown. All I get is a blue screen with Windows Xp printed on it- nothing else.
What is Lenux Puppy CD.? I don't have one. If there are no additional problems incurred by using it, I think I would like to give it a go- if it's a free program. I am totally broke
No safe mode works.
I have product key from case
By the way, If these two computers had been networked, would both have been infected or damaged?
If I put one of the xp disks in this computer and allow it to boot will this prove that it's OK? and is there any chance fo harming this unit by doing so?

Report •

#83
December 31, 2012 at 11:59:32

Not sure what your blue screen is - the only other one I can think of is the light blue Welcome screen but this doesn't have XP on it. There is a black screen with XP on it that runs before the welcome screen. Maybe what you are seeing is from your computer manufacturer.

Virus cross infection is always possible but right now it seems you have a serious issue on this computer, which previously seemed as if it had been cleaned up.

If you just allow the computer to boot to an XP disk you might end up with the complications of a dual install. The repair (#74) would be a better bet.

All a Puppy Linux CD (free) would do is help prove whether or not it is a software or hardware fault - it doesn't touch Windows. From the order of events it seems to be a software fault. Running Puppy would be an idea if the repair doesn't run either.

See how you get on with the repair.

Always pop back and let us know the outcome - thanks


Report •

#84
December 31, 2012 at 12:07:28

Since the disks will not boot, I assume the order needs to be changed in Bios.?
I don't know how to do this

Report •

#85
December 31, 2012 at 12:32:08

Managed to find a BIOS manual. Could be worth download so we can refer to it as necessary. Don't be put off by the quantity of information - we only need a very small part of it:
http://www.manualslib.com/download/...

To get into BIOS you tap Del key while booting (it probably mentions it on the screen - referring to Setup). This will be yet another blue screen with white letters - a menu screen. See if you can get into it. If so Exit from it without saving anything for now (Esc key). In the meantime I'll see if I can find the boot order section, if you don't find it first.

Always pop back and let us know the outcome - thanks


Report •

#86
December 31, 2012 at 12:47:35

Select Advanced BIOS features (page 36 of manual). At the bottom it says how to move around BIOS and select things.
Next see Page 41 of manual - Hard Disk Boot Priority.
Then see First, Second and Third Boot Devices.

We want CDROM and Floppy at first or second, with hard disk as third.
If you click on them they can be changed.

If you get anything wrong then Esc your way out (ie without saving) and try again.
Only save (F10 key) when you have the boot order the way you want it.

Always pop back and let us know the outcome - thanks


Report •

#87
December 31, 2012 at 12:50:52

I see that the manual is for Acer Aspire SA 80
My computer is Acer Power 280 Is it the same for both?

Report •

#88
December 31, 2012 at 12:54:40

Yep, it says so on the small print on that page.

Always pop back and let us know the outcome - thanks


Report •

#89
December 31, 2012 at 13:00:39

OK will download and print

Report •

#90
December 31, 2012 at 13:03:28

I'm going to have to break off for a while. New Years eve here (3 hours to go) and my wife needs my company. Maybe MrGoodguy can step in on this part for a while if he is around.

Always pop back and let us know the outcome - thanks


Report •

#91
December 31, 2012 at 13:08:45

I also see that the download uses 7 Zip I think this where my latest proplems began when I was downloading something ( Can't remeber now what)- Is it safe?

Report •

#92
December 31, 2012 at 13:11:48

See you in 2013 Happy New Year
As I said earlier, There's no rush for this fix
Have fun. I understand London puts on quite a show. The only show I will see, is the stars. up here in the mountains if it's not cloudy

Report •

#93
December 31, 2012 at 13:14:47

7Zip is fine and safe and wasn't the cause of your problems :) 7Zip is a very common tool for use on zipped files.

Please reply and let us know if our help worked. Your feedback helps others. Maybe you?


Report •

#94
December 31, 2012 at 16:23:26

Back here in 2013 - around again for a while before bedtime looms again.

Yep, I use 7Zip myself, its fine....

So its back to #86 unless there are any other ideas around.

Always pop back and let us know the outcome - thanks


Report •

#95
January 1, 2013 at 05:31:37

One xp disk seemed to begin to work properly When I got to install-Repair, I chose Repair- This is what came up " Insert CD windows XP Professional Services Pack 1- CD" (which I don't have) when I press enter without it nothing happens.
I see I can download it but It seems to be used for reinstall and not for repair, Is this correct?

Using the other disk, I don't even get that far, This is what it says "Inf file setup TXTsetup sf is missing or crrupt 32768"
So the question is can the download be used for repair?

I wonder if my problem could be hardware related after all. Computer seems to be a bit noisy. Never noticed it before and could be my imagiation. Can Lenux that you mentioned check it out including the HD? If so, maybe I can download it and hope that my burner works on this machine


Report •

#96
January 1, 2013 at 08:53:48

It seems you've now got the boot order sorted and that probably the 2nd XP disk is faulty. You have to also keep the disks matching what you have on there (either XP Home, or XP Pro). If you are sure about this then insert the good XP disk you appear to have when asked. It is OK to use any XP disk that matches your system but you use your own product key if requested. You can't download XP only updates (which you can't do until the system is working again).

Linux will give us a clue whether this is hardware or software. Now your boot order is sorted that should run once you've produced it. I'll make a second post about doing that. See #97 below.

Another possibility is a clean install but we ought to see if the repair will work first.

Always pop back and let us know the outcome - thanks


Report •

#97
January 1, 2013 at 08:56:51

See #96 above first.

LINUX LIVE CD INFO (from a general note of mine).

I use Puppy Linux 4.3.1. as it is simple and saves nothing to the HD, so I will use that as my example:

On a working computer, first download the file pup-431.iso from here:
http://iso.linuxquestions.org/downl...

DO NOT RUN the file but save it somewhere instead. This is known as an image (.iso). You then have to burn a CD from the image, which does NOT mean just burning the download onto the CD. Most burning software has an "image burning" feature and you use this to create a CD from the downloaded image. In the unlikely event that your burning software has no such feature there are various free programs which will do this. For example, ImgBurn, which you can get here:
http://filehippo.com/download_imgburn/
With this program, when you run it you select "Write image file to disk".

Once you have a CD you put it in the drive of the faulty computer then power on and Linux should start loading. If it still starts Windows it is because the CD drive loads after the HD. To fix this you go into BIOS and set the CD ahead of the HD and Save settings - best leave it that way. How you get to BIOS varies with computers but often it is either a case of tapping F2 or Del key while booting.

Puppy is slow first time but during shutdown you can get it to Save your settings back onto the CD, so that it boots faster next time. It runs between RAM and the HD so it does not change anything in Windows, which will work quite normally when you boot without the CD.

The Linux desktop has your drive icons at the bottom left. Everything is single click. It is possible to view your Windows files on the HD and copy them onto a flash drive by drag and drop. Obviously you don't delete any Windows files from then HD unless you really intend to do so. Note that Linux shows the HD file structure exactly "as is" (unlike Windows which often presents you with what MS want you to imagine).

It takes a lot of words to describe all this but it is much easier than in sounds.

Always pop back and let us know the outcome - thanks


Report •

#98
January 1, 2013 at 09:14:08

But, as I said, before the Ok disk would not continue It required XP Professional Service Pack 1 CD. I can download service pack which I think includes 3 but will that solve this part of the problem.? Or is it only used for install not repair?

I'm worried about losing this computer to, The last time I shut down/restart it came up with a blank blue screen, I had to unplug to get it to boot. I know I need more memory here but thats for later


Report •

#99
January 1, 2013 at 11:16:16

I take it that the original install was XP Pro (not Home).

I think two things are getting a bit mixed up here. You can download "XP Pro service pack 1" which is an update that installs to a working computer which has had no service packs installed. You can't download a complete XP Pro CD (with or without a service pack). If you could nobody would ever need to buy XP. It is possible on a working machine to merge a service pack download with an XP Pro CD onto a new CD. Could prove a bit heady but we can try if you wish.

If you you have a friend with an XP Pro CD SP1 or later, that would do it without any hassle.

In summary you have to either borrow an XP Pro CD which already includes service pack 1, or create one using an original XP disk and a service pack1 download.

Always pop back and let us know the outcome - thanks


Report •

#100
January 1, 2013 at 13:07:49

I obviosly don't don't know what I'm doing. Please don't give up on me
I've spent the past 2 Hrs trying to burn to CD- Service Pack 3 which I downloaded.
Each time I get an error saying that the disk might have a problem or something like that. I thought since the Repair required SP 1, I might as well downloand 3 and insert it when the computer we are trying to fix called for SP 1 I,m going to continue to try.

Report •

#101
January 1, 2013 at 13:26:41

No, I'm not about to give up.

The download service packs are for applying to a working computer, in order to update it to include that service pack. You don't even need to burn them onto CD you just double click the file on the computer you are intending to update.

Obviously you are in a different situation because your computer is NOT working.

For the repair you need to lay your hands on a complete Windows XP Pro disk which already contains SP1 or later. If you have an XP disk without any service packs, the alternative is to take that CD and the download (SP1), then merge the two together to make a completely new XP CD which contains SP1 or later. This is what your dud computer is asking for. I can give you this procedure if you wish.

Better confirm that your original installation was XP Pro. Also that any XP CD's you have are the same. For the repair you cannot use XP Home CD in place of XP Pro (or vice versa). This could be where things are going wrong.

Don't waste your time putting that download on CD - it will not help. It wants a complete XP CD with SP1 or later for the repair, not a service pack update for a working computer.

Always pop back and let us know the outcome - thanks


Report •

#102
January 1, 2013 at 15:02:44

Let's list the options (first see any posts above you've missed and clarify XP Home -v- XP Pro for your computer installation and your XP disks). I'm assuming you now have the CD drive ahead of the HD in BIOS.

Firstly, we could knock up a Puppy Linux disk. This will NOT fix your computer but it will help us decide whether this is a software or hardware fault. It would be unfortunate if we were chasing software when by some mischance your hardware has gone awry. It would require you to burn a CD on your other computer (which seems to be giving you some trouble). The info is in post #97.

Secondly we could merge one of your XP disks with a download of SP1 or later, then run the Repair. This also means burning a CD on the other computer, using a procedure I have not yet given. We are not absolutely certain if either of your XP disks are OK - one of them seems defunct.

Thirdly we could use one of your XP disks to set up Windows afresh (losing everything and requiring activation). No disk burning, but again it depends on whether you have a good Win XP disk. You don't need SP1 for this - we can get SP3 update once the computer is running. There will probably be issues requiring drivers and updates. You won't even have a virus checker at first.

My own feeling is to try to avoid the third option unless there is no alternative. Probably I would go for Puppy just to ensure we are not barking up the wrong tree, then go for the second option (if the hardware looks OK).

However, I'm happy for you to decide.

It's a great pity that "last known good configuration" didn't work (#76) - it is so easy.
You can try it once more if you wish. It shouldn't need a CD.

Always pop back and let us know the outcome - thanks


Report •

#103
January 1, 2013 at 15:27:27

Seem like I'm not strting the New Year off too well
When I try to burn anything, On this computer I get data base file CDRW.32 bdb is missing. I tried a couple places to download it,
Then I called what appears to be Acer, thinking the best place would be directly from them. After going throught the paces I was put on a chat with a supposed helper. Bottom line, they wanted $199.00- I had allowed them to access my computer and they controled my files. I had to unplug to get rid of them. I immediately did a system restore, in case thay may have corrupted my system. they claim to have found al kinds of problems. I don't believe they are a legitimate Acer Site

So in order to burn anything I have to somehow.get CDRW32 bdb installed on this computer.-One Dern thing after the other.Any Ideas?
I am certain both of these computers have XP Pro


Report •

#104
January 1, 2013 at 15:48:09

Oh dear, you did the right thing to back out then run the restore. I did find a download but it was on a foreign website so I don't think I should point you there.

Might be worth checking to see if system restore fixed the problem.

Otherwise, try going to Device Manager, uninstall the CD/DVD drive then reboot. This will reload the software and there is a chance it will fix it.

I really don't know much about this, so rather than clutter up this already complex thread I would raise a new post if the problem remains. That will attract fresh helpers (nobody looks at old threads like this unless they have been involved).

Always pop back and let us know the outcome - thanks


Report •

#105
January 1, 2013 at 15:58:09

My friend, who was a friend of my son's when they were in grammer school together and is now father of a 14 year old (Time flies on wonder people get old, if they don't die first) tells me No problem, he can send me the disk I need.
So it will be a few days. It will have to be mailed to me.
I can probable do a repair on this one too. To recapture the file I mentioned in last post?
Maybe correct any other problems while I'm at it?


Report •

#106
January 1, 2013 at 16:18:40

It will probably have to be XP Pro SP1 or later to do the repair on the one this thread. It would do a complete re-install with it, whatever SP version.

Running Puppy would be good but without CD burning facilities we are stuck.

As for the missing file I'm a bit unsure. From what I read it looked like it was for a third party program (although I might be wrong). I'm anxious to keep one computer working. The suggestion I gave, uninstall CD drive from Device Manger, will not do any harm and might fix it.

Always pop back and let us know the outcome - thanks


Report •

#107
January 1, 2013 at 17:57:13

I've been doing a bit more thinking and delving. You probably have XP Pro SP1 on the non-working computer but one of the XP disks you tried had no service packs on it at all.

You should be able to use any XP Pro full CD for Repair provided it includes SP1 or later. What it probably didn't like was an older disk. I have amended one or two of my previous posts with this in mind.

Computers often object to you asking them to go "backwards" (if you know what I mean). With luck the disk you are awaiting will do the trick.

As this computer is not working I would do the Repair on this one first and leave the better one until later (if necessary). By then you will be more conversant with doing it and there is little to lose on this machine right now.

Always pop back and let us know the outcome - thanks


Report •

#108
January 4, 2013 at 10:31:58

I' haven't recieved a disk yet. Hoping I will. Th uninstall didn't do anything for the CD' I had the sae or a similuar problem with the other computer. maybe when I get it up and running I will do a repair on this one too.
I really worried about losing this one, When try to do a restart frrom start button. It'w won't re boot without unplugging it. So far I can manage that way and will try not to need to re boot or shut down

Report •

#109
January 4, 2013 at 12:06:34

Let us know if/when you get the CD - we are still watching this thread. Best leave the better machine for now and see if we can get this one going first.

Always pop back and let us know the outcome - thanks


Report •

#110
January 4, 2013 at 18:50:25

OK,At least it will stilll boot. I'm haivg trouble finding a disk. My son's friend says he might be able to locate one next week. I hope. Otherwise I'll keep looking
Thanks for staying with me.

Report •

#111
January 9, 2013 at 17:58:10

An XP Pro disk with SP 2 and and a disk with SP3 update was mailed to me yesterday.
I should have them Fri or Sat.
Should I go ahead with the Repair when I get them or wait for further instructioons from you?

Report •

#112
January 9, 2013 at 23:23:58

Go ahead with the repair.

Always pop back and let us know the outcome - thanks


Report •

#113
January 14, 2013 at 10:37:19

Did the xp repair. Everything seems to be working fine- Thanks again. It wasn't as difficult as I expected
i think we can close this one out

Report •

#114
January 14, 2013 at 11:16:09

Now that's very good to hear - I'm pleased for you.

Not sure if you can select a Best Answer from this lot but if you do it will mark this post as solved.


Report •


Ask Question