View Single Post
Old 12-01-2005, 12:38 AM   #10 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,355
OS: N/A


Did you use to have Panda security products installed on this machine? If so, how long has it been since you removed it?

Please have Hijackthis fix these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: (no name) - {965A592F-8EFA-4250-8630-7960230792F1} - (no file)
O4 - HKLM\..\Run: [ICQ Messenger] ICQLite.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [ICQ Messenger] ICQLite.exe
O4 - HKCU\..\Run: [h0x2ROj2j] sysfts.exe



Then reboot into Safe Mode to search/delete these:
  • ICQLite.exe
  • sysfts.exe

Whilst in Safe Mode, please do a HIjackthis scan & save the resultant log.

In your next reply, I would require you to tell post 2 HJT logs. One from Safe Mode & the other from Normal Mode.


Let's see what we can dig up about th emysterious behaviour of your cdroms.

Please go to Start > Run - type in eventvwr & click Ok
In the ensuing Window, you would see a left & right pane.
You will see Application, Security & System listed in the left pane.

In the left pane click on Application.

Click the gray title “Type” at the top of the source name column in the right pane to sort by type name, look for "Error". Double-click on the most recent 3, and evaluate the event description for any indication of the cause of the problem. Make note of the Description, EventID and Source of these Event Properties.Click on the button below the two arrows in the upper right corner. This will copy the event information to the clipboard. Paste the information for each event here

Repeat the above step for System

Also look for any events that may pertain to cdroms.
__________________

Question - what have you done for the community today?
sUBs is offline