cromwell_4 Posted July 20, 2005 Report Share Posted July 20, 2005 I have discovered CoolWebSearch on a users computer when running AdAware. I have tried to remove it but IE will launch a search site. McAfee Virus Guard detects se.dll but this keeps reappearing.I found a post with instructions on manually removing this but cannot update AboutBuster, and get an error after it has run - runtime error 339 - component 'comtl32.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.Here is the hijack logLogfile of HijackThis v1.99.1Scan saved at 14:55:55, on 20/07/2005Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\ibmpmsvc.exeC:\WINNT\system32\Ati2evxx.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeC:\WINNT\floplock.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\program files\notes\ntmulti.exeC:\WINNT\system32\NALNTSRV.EXEC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\system32\TpKmpSVC.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\System32\mspmspsv.exeC:\WINNT\system32\svchost.exeC:\PROGRA~1\Xpoint\xpadmin\xpadmin.exeC:\PROGRA~1\Xpoint\agent\Xpagent.exeC:\WINNT\System32\wm.exeC:\PROGRA~1\Xpoint\EEClient\xpclient.exeC:\NOVELL\ZENRC\wuser32.exeC:\WINNT\system32\cmd.exeC:\PROGRA~1\Xpoint\SAS\jre\bin\javaw.exeC:\NOVELL\ZENRC\WUOLService.exeC:\WINNT\system32\Ati2evxx.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\ltmsg.exeC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeC:\WINNT\System32\dpmw32.exeC:\WINNT\system32\NWTRAY.EXEC:\Program Files\Network Associates\Common Framework\UpdaterUI.exeC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\WINNT\AGRSMMSG.exeC:\Program Files\IBM\Messages By IBM\ibmmessages.exeC:\Program Files\Xpoint\PE\Skin\rrpcsb.exeC:\WINNT\system32\RunDll32.exeC:\Program Files\Xpoint\PE\pcrecsa.exeC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeC:\WINNT\system32\TpShocks.exeC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\WINNT\system32\internat.exeC:\Program Files\WinZip\WZQKPICK.EXEC:\WINNT\system32\rundll32.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Microsoft Office\Office\WINWORD.EXEC:\Program Files\Microsoft Office\Office\WINWORD.EXEC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\aboutbuster\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\richarnl\LOCALS~1\Temp\se.dll/space.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\richarnl\LOCALS~1\Temp\se.dll/space.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blankR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blankR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blankR1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blankR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.51.87.140:8080R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 170.230.*;213.62.*;62.185.95.179;*.cpb.com;*.soups.com;<local>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: (no name) - {B9D65F0D-A3C3-408D-BA0B-2C4A6139387C} - C:\WINNT\system32\hhnj.dllO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exeO4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.regO4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [TP4EX] tp4ex.exeO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeO4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGINO4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exeO4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exeO4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXEO4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exeO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exeO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [uC_Start] C:\IBMTools\Updater\ucstartup.exeO4 - HKLM\..\Run: [Rapid Restore] C:\Program Files\Xpoint\PE\Skin\rrpcsb.exeO4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitorO4 - HKLM\..\Run: [bMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXEO4 - HKLM\..\Run: [bMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitorO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeO4 - HKLM\..\Run: [TpShocks] TpShocks.exeO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helperO4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\richarnl\LOCALS~1\Temp\se.dll,DllInstallO4 - HKCU\..\Run: [internat.exe] internat.exeO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exeO4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dllO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dllO11 - Options group: [JAVA_IBM] Java (IBM)O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO14 - IERESET.INF: START_PAGE_URL=about:blankO16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://dccamus01.soups.com/qp2.cabO16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-3.ibm.com/pc/support/access/sdc...ad/IbmEgath.cabO16 - DPF: {95E52A86-61B2-11D6-976A-00B0D09A3628} (ProjectBPSInterface3.BPSInterface3) - http://worldpanel.tns-global.com/Worldpane...SInterface3.CABO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CCS\Services\Tcpip\..\{3A22ECFD-1D48-4F30-A047-F4AB3D5657DC}: Domain = europe.soups.comO17 - HKLM\System\CCS\Services\Tcpip\..\{E6B6CEA5-4CF2-4550-9CCB-E7A8F1B20603}: Domain = europe.soups.comO17 - HKLM\System\CCS\Services\Tcpip\..\{E6B6CEA5-4CF2-4550-9CCB-E7A8F1B20603}: NameServer = 170.230.236.46,170.230.236.36O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO18 - Filter: text/html - {FA713029-439F-41FE-A74E-6EE1BD142EEE} - C:\WINNT\system32\hhnj.dllO18 - Filter: text/plain - {FA713029-439F-41FE-A74E-6EE1BD142EEE} - C:\WINNT\system32\hhnj.dllO23 - Service: Peregrine Listener 6.0.1 (agtlsnr601) - Peregrine Systems, Inc. - C:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exeO23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exeO23 - Service: Client Access Express Remote Command (Cwbrxd) - IBM Corporation - C:\WINNT\CWBRXD.EXEO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: floppylock - Unknown owner - C:\WINNT\floplock.exeO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\system32\ibmpmsvc.exeO23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exeO23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exeO23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exeO23 - Service: Multi-user Cleanup Service - Unknown owner - C:\program files\notes\ntmulti.exeO23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINNT\system32\NALNTSRV.EXEO23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exeO23 - Service: Xpoint PCRadmin Server (PCRadminServer) - Unknown owner - C:\PROGRA~1\Xpoint\PE\pcradmin.exeO23 - Service: PictureTaker - LANovation - C:\WINNT\System32\PCTKRNT.SYSO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINNT\system32\PsaSrv.exeO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exeO23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINNT\System32\wm.exeO23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exeO23 - Service: Xpoint Admin Server (XPadminServer) - Unknown owner - C:\PROGRA~1\Xpoint\xpadmin\xpadmin.exeO23 - Service: Xpoint Agent Server (xpAgentServer) - Unknown owner - C:\PROGRA~1\Xpoint\agent\Xpagent.exeHoping you can help, as there are 2 users who have the same problem. I have installed Mozilla Firefox as a temporary solution.Many thanks,Claire (newbie!!) Link to post Share on other sites
therock247uk Posted July 20, 2005 Report Share Posted July 20, 2005 Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.This will likely be a few step process in removing the malware that has infected your system. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further.You have a nasty CoolWebSearch infection. First we will need to download a few tools that will help us in the removal of your problem.Download about:buster by RubbeRDuckY Here.Download CWShredder Here.Download SpSeHjfix Here.Download and install CleanUp! HereSave all of these files somewhere you will remember like to the Desktop.Unzip SpSeHjfix to its own folder (ie c:\SpSeHjfix)Run the CleanUp! installer. You dont need to do anything with it right now.Update About:BusterUnzip the contents of AboutBuster.zip and an AboutBuster directory will be created.Navigate to the AboutBuster directory and double-click on AboutBuster.exe.Click "OK" at the prompt with instructions.Click "Update" and then "Check For Update" to begin the update process.If any updates exist please download them by clicking "Download Update" then click the X to close that window.Now close About:BusterUpdate CWShredderOpen CWShredder and click I AGREEClick Check For UpdateClose CWShredderBoot into Safe Mode:Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.Please run about:buster by RubbeRDuckY:Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.Click Yes to allow it to shutdown explorer.exe.It will begin to check your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.When it has finished, click Save Log. Make sure you save it as I may need a copy of it later.Reboot your computer into safe mode againRun about:buster again following the same instructions as above, this time without the restart at the endNow run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. Now run SpSeHjfix. A log will be saved in the same folder that you put the exe into. Please post the results of that log in your next reply.Now run CleanUp!. Click CleanUp and allow it to delete all the temporary files.Reboot your computer into normal windows.Please run an on-line virus scan at Kaspersky OnLine Scan or if that doesnt work, you can use TrendMicro or BitDefender. (Please post the results of the scan(s) in your next reply)After all that, please post back with how things went as well as the logs requested and a new HiJackThis log.Good Luck Link to post Share on other sites
cromwell_4 Posted July 21, 2005 Author Report Share Posted July 21, 2005 Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.This will likely be a few step process in removing the malware that has infected your system. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further.You have a nasty CoolWebSearch infection. First we will need to download a few tools that will help us in the removal of your problem.Download about:buster by RubbeRDuckY Here.Download CWShredder Here.Download SpSeHjfix Here.Download and install CleanUp! HereSave all of these files somewhere you will remember like to the Desktop.Unzip SpSeHjfix to its own folder (ie c:\SpSeHjfix)Run the CleanUp! installer. You dont need to do anything with it right now.Update About:BusterUnzip the contents of AboutBuster.zip and an AboutBuster directory will be created.Navigate to the AboutBuster directory and double-click on AboutBuster.exe.Click "OK" at the prompt with instructions.Click "Update" and then "Check For Update" to begin the update process.If any updates exist please download them by clicking "Download Update" then click the X to close that window.Now close About:BusterUpdate CWShredderOpen CWShredder and click I AGREEClick Check For UpdateClose CWShredderBoot into Safe Mode:Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.Please run about:buster by RubbeRDuckY:Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.Click Yes to allow it to shutdown explorer.exe.It will begin to check your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.When it has finished, click Save Log. Make sure you save it as I may need a copy of it later.Reboot your computer into safe mode againRun about:buster again following the same instructions as above, this time without the restart at the endNow run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. Now run SpSeHjfix. A log will be saved in the same folder that you put the exe into. Please post the results of that log in your next reply.Now run CleanUp!. Click CleanUp and allow it to delete all the temporary files.Reboot your computer into normal windows.Please run an on-line virus scan at Kaspersky OnLine Scan or if that doesnt work, you can use TrendMicro or BitDefender. (Please post the results of the scan(s) in your next reply)After all that, please post back with how things went as well as the logs requested and a new HiJackThis log.Good Luck<{POST_SNAPBACK}> Link to post Share on other sites
cromwell_4 Posted July 21, 2005 Author Report Share Posted July 21, 2005 I was unable to update AboutBuster - An error has occurred while updating. I ran v4.0I was unable to update CWShredder - Unable to check for updates. I ran v2.12I have added log file for about busterCWShredder found a file - I have added a screen shotI have added log file for SpSeHjfix Sp.html - se.dll - hijack fix - this appeared after rebooting the PC into normal windows. I rebooted againI was unable to run any of the 3 virus scans as they wanted IE and not Mozilla Firefox.I have clicked on IE icon and nothing happens.I used My Computer to gain access to address bar and browsed to the Trendmicro scan which is currently running undefined- I selected virus and spy wareI have aslo run McAfee Virus scan and no infected files have been found.I have added the hijack file as requestedHow do I get IE to launch again?Thanks for you help so far,Clairelogs.zip Link to post Share on other sites
therock247uk Posted July 21, 2005 Report Share Posted July 21, 2005 Can you post the Hijackthis log here in a reply. Not attach Link to post Share on other sites
cromwell_4 Posted July 22, 2005 Author Report Share Posted July 22, 2005 Logfile of HijackThis v1.99.1Scan saved at 17:20:18, on 21/07/2005Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\ibmpmsvc.exeC:\WINNT\system32\Ati2evxx.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeC:\WINNT\floplock.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\program files\notes\ntmulti.exeC:\WINNT\system32\NALNTSRV.EXEC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\system32\TpKmpSVC.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\System32\mspmspsv.exeC:\WINNT\system32\svchost.exeC:\PROGRA~1\Xpoint\xpadmin\xpadmin.exeC:\PROGRA~1\Xpoint\agent\Xpagent.exeC:\WINNT\System32\wm.exeC:\NOVELL\ZENRC\wuser32.exeC:\PROGRA~1\Xpoint\EEClient\xpclient.exeC:\WINNT\system32\cmd.exeC:\PROGRA~1\Xpoint\SAS\jre\bin\javaw.exeC:\NOVELL\ZENRC\WUOLService.exeC:\WINNT\system32\Ati2evxx.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\ltmsg.exeC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeC:\WINNT\System32\dpmw32.exeC:\WINNT\system32\NWTRAY.EXEC:\Program Files\Network Associates\Common Framework\UpdaterUI.exeC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\WINNT\AGRSMMSG.exeC:\Program Files\IBM\Messages By IBM\ibmmessages.exeC:\Program Files\Xpoint\PE\Skin\rrpcsb.exeC:\WINNT\system32\RunDll32.exeC:\Program Files\Xpoint\PE\pcrecsa.exeC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeC:\WINNT\system32\TpShocks.exeC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\WINNT\system32\internat.exeC:\Program Files\WinZip\WZQKPICK.EXEC:\Program Files\Network Associates\VirusScan\scan32.exeC:\aboutbuster\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.51.87.140:8080R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 170.230.*;213.62.*;62.185.95.179;*.cpb.com;*.soups.com;<local>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exeO4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.regO4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [TP4EX] tp4ex.exeO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeO4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGINO4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exeO4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exeO4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXEO4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exeO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exeO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [uC_Start] C:\IBMTools\Updater\ucstartup.exeO4 - HKLM\..\Run: [Rapid Restore] C:\Program Files\Xpoint\PE\Skin\rrpcsb.exeO4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitorO4 - HKLM\..\Run: [bMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXEO4 - HKLM\..\Run: [bMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitorO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeO4 - HKLM\..\Run: [TpShocks] TpShocks.exeO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helperO4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKCU\..\Run: [internat.exe] internat.exeO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exeO4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dllO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dllO11 - Options group: [JAVA_IBM] Java (IBM)O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO14 - IERESET.INF: START_PAGE_URL=about:blankO16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://dccamus01.soups.com/qp2.cabO16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-3.ibm.com/pc/support/access/sdc...ad/IbmEgath.cabO16 - DPF: {95E52A86-61B2-11D6-976A-00B0D09A3628} (ProjectBPSInterface3.BPSInterface3) - http://worldpanel.tns-global.com/Worldpane...SInterface3.CABO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CCS\Services\Tcpip\..\{3A22ECFD-1D48-4F30-A047-F4AB3D5657DC}: Domain = europe.soups.comO17 - HKLM\System\CCS\Services\Tcpip\..\{E6B6CEA5-4CF2-4550-9CCB-E7A8F1B20603}: Domain = europe.soups.comO17 - HKLM\System\CCS\Services\Tcpip\..\{E6B6CEA5-4CF2-4550-9CCB-E7A8F1B20603}: NameServer = 170.230.236.46,170.230.236.36O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO23 - Service: Peregrine Listener 6.0.1 (agtlsnr601) - Peregrine Systems, Inc. - C:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exeO23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exeO23 - Service: Client Access Express Remote Command (Cwbrxd) - IBM Corporation - C:\WINNT\CWBRXD.EXEO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: floppylock - Unknown owner - C:\WINNT\floplock.exeO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\system32\ibmpmsvc.exeO23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exeO23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exeO23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exeO23 - Service: Multi-user Cleanup Service - Unknown owner - C:\program files\notes\ntmulti.exeO23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINNT\system32\NALNTSRV.EXEO23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exeO23 - Service: Xpoint PCRadmin Server (PCRadminServer) - Unknown owner - C:\PROGRA~1\Xpoint\PE\pcradmin.exeO23 - Service: PictureTaker - LANovation - C:\WINNT\System32\PCTKRNT.SYSO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINNT\system32\PsaSrv.exeO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exeO23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINNT\System32\wm.exeO23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exeO23 - Service: Xpoint Admin Server (XPadminServer) - Unknown owner - C:\PROGRA~1\Xpoint\xpadmin\xpadmin.exeO23 - Service: Xpoint Agent Server (xpAgentServer) - Unknown owner - C:\PROGRA~1\Xpoint\agent\Xpagent.exe Link to post Share on other sites
therock247uk Posted July 22, 2005 Report Share Posted July 22, 2005 1. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 2. Then post a new Hijackthis log here in a reply. Link to post Share on other sites
cromwell_4 Posted July 26, 2005 Author Report Share Posted July 26, 2005 Here is the new hijack this log.Logfile of HijackThis v1.99.1Scan saved at 13:56:40, on 26/07/2005Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\ibmpmsvc.exeC:\WINNT\system32\Ati2evxx.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeC:\WINNT\floplock.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\program files\notes\ntmulti.exeC:\WINNT\system32\NALNTSRV.EXEC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\system32\TpKmpSVC.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\System32\mspmspsv.exeC:\WINNT\system32\svchost.exeC:\PROGRA~1\Xpoint\xpadmin\xpadmin.exeC:\PROGRA~1\Xpoint\agent\Xpagent.exeC:\WINNT\System32\wm.exeC:\PROGRA~1\Xpoint\EEClient\xpclient.exeC:\NOVELL\ZENRC\wuser32.exeC:\WINNT\system32\cmd.exeC:\PROGRA~1\Xpoint\SAS\jre\bin\javaw.exeC:\NOVELL\ZENRC\WUOLService.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\Ati2evxx.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\ltmsg.exeC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeC:\WINNT\System32\dpmw32.exeC:\WINNT\system32\NWTRAY.EXEC:\Program Files\Network Associates\Common Framework\UpdaterUI.exeC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\WINNT\AGRSMMSG.exeC:\Program Files\IBM\Messages By IBM\ibmmessages.exeC:\Program Files\Xpoint\PE\Skin\rrpcsb.exeC:\WINNT\system32\RunDll32.exeC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeC:\WINNT\system32\TpShocks.exeC:\Program Files\Xpoint\PE\pcrecsa.exeC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\WINNT\system32\internat.exeC:\Program Files\WinZip\WZQKPICK.EXEC:\aboutbuster\HijackThis.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.51.87.140:8080R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 170.230.*;213.62.*;62.185.95.179;*.cpb.com;*.soups.com;<local>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exeO4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.regO4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [TP4EX] tp4ex.exeO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exeO4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGINO4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exeO4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exeO4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXEO4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exeO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exeO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [uC_Start] C:\IBMTools\Updater\ucstartup.exeO4 - HKLM\..\Run: [Rapid Restore] C:\Program Files\Xpoint\PE\Skin\rrpcsb.exeO4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitorO4 - HKLM\..\Run: [bMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXEO4 - HKLM\..\Run: [bMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitorO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeO4 - HKLM\..\Run: [TpShocks] TpShocks.exeO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helperO4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKCU\..\Run: [internat.exe] internat.exeO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exeO4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dllO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dllO11 - Options group: [JAVA_IBM] Java (IBM)O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO14 - IERESET.INF: START_PAGE_URL=about:blankO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cabO16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://dccamus01.soups.com/qp2.cabO16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-3.ibm.com/pc/support/access/sdc...ad/IbmEgath.cabO16 - DPF: {95E52A86-61B2-11D6-976A-00B0D09A3628} (ProjectBPSInterface3.BPSInterface3) - http://worldpanel.tns-global.com/Worldpane...SInterface3.CABO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CCS\Services\Tcpip\..\{3A22ECFD-1D48-4F30-A047-F4AB3D5657DC}: Domain = europe.soups.comO17 - HKLM\System\CCS\Services\Tcpip\..\{E6B6CEA5-4CF2-4550-9CCB-E7A8F1B20603}: Domain = europe.soups.comO17 - HKLM\System\CCS\Services\Tcpip\..\{E6B6CEA5-4CF2-4550-9CCB-E7A8F1B20603}: NameServer = 170.230.236.46,170.230.236.36O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.cpb.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = eu.cpb.com,cpb.com,europe.soups.com,soups.comO23 - Service: Peregrine Listener 6.0.1 (agtlsnr601) - Peregrine Systems, Inc. - C:\PROGRA~1\PEREGR~1\DESKTO~1\bin\iftlsnr.exeO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exeO23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exeO23 - Service: Client Access Express Remote Command (Cwbrxd) - IBM Corporation - C:\WINNT\CWBRXD.EXEO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: floppylock - Unknown owner - C:\WINNT\floplock.exeO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\system32\ibmpmsvc.exeO23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exeO23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exeO23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exeO23 - Service: Multi-user Cleanup Service - Unknown owner - C:\program files\notes\ntmulti.exeO23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINNT\system32\NALNTSRV.EXEO23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exeO23 - Service: Xpoint PCRadmin Server (PCRadminServer) - Unknown owner - C:\PROGRA~1\Xpoint\PE\pcradmin.exeO23 - Service: PictureTaker - LANovation - C:\WINNT\System32\PCTKRNT.SYSO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINNT\system32\PsaSrv.exeO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exeO23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINNT\System32\wm.exeO23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exeO23 - Service: Xpoint Admin Server (XPadminServer) - Unknown owner - C:\PROGRA~1\Xpoint\xpadmin\xpadmin.exeO23 - Service: Xpoint Agent Server (xpAgentServer) - Unknown owner - C:\PROGRA~1\Xpoint\agent\Xpagent.exe Link to post Share on other sites
therock247uk Posted July 27, 2005 Report Share Posted July 27, 2005 Your log is clean Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:Spywareblaster <= SpywareBlaster will prevent spyware from being installed.Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.To protect yourself further: IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computerGoogle Toolbar <= Get the free google toolbar to help stop pop up windows.I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.Credit to PGPhantom for canned speech. Link to post Share on other sites
Recommended Posts