Tech Support Guy banner
Status
Not open for further replies.
1 - 15 of 15 Posts

·
Registered
Joined
·
18 Posts
Discussion Starter · #1 ·
Trying to help out mom with her computer. It frequently freezes up and or becomes very, very slow to respond. Most times we have to unplug it from the wall to turn it off. Just today the CD drawer opened by itself. She says that the CD drive is not recognized, although I have not tested it myself.

It is a Gateway computer
Windows ME 4.90.3000
IE 6.0

She has Norton Anti Virus 2003 and it is kept updated. She has run the anti-virus full system scan recently and nothing was found. Cookies and history have been deleted. Scan disk will only complete half way before being restarted. Nothing I know of is being run in the background. Disk defragmenter was run and 99% completed before the computer shut down.

I ran Highjack This and this is the log:
Logfile of HijackThis v1.99.1
Scan saved at 3:40:16 PM, on 7/11/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gbronline.com/gbr_prod/city.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/ext/gw/home.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/ext/gw/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gbronline.com/gbr_prod/city.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gbronline.com/gbr_prod/city.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\PROGRAM FILES\GBR XTREME SPEED\PRPL_IEPOPUPBLOCKER.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [OEMRUNONCE] c:\windows\options\cabs\oemrun.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://gateway.yahoo.com
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://www.gateway.com/support/contact/serial/gwCID.CAB
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - http://www107.coolsavings.com/download/cscmv5X.cab
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net

Please let me know of anymore information you may need to help me fix this problem of freezing up.

Stephanie
 

·
Trusted Advisor
Joined
·
85,511 Posts
Dlearyous:

Click Start - Run, type in MSCONFIG, then click OK - Startup(tab).

Make sure there is a checkmark in:

ScanRegistry

SystemTray

StateMgr


Remove the checkmark from:

loadpowerprofile(both entries)

oemrun.exe

mstask.exe

Money Express.exe


Once that's done, click Apply - OK, then reboot.

During reboot, a message will appear about your computer running in selective startup mode. Just ignore it, place a checkmark in it, then click OK.

----------------------------------------------------------------

Click Start - Search - Files And Folders, select the C: drive to look in, type in:

*.TMP

then click Search. When the list of files appear, click Edit - Select All - File - Delete - Yes.

Repeat the steps with:

C:\TEMP\*.*

C:\WINDOWS\TEMP\*.*


If you receive a warning about a program not working if you delete these files, ignore the message. This is all junk, so get rid of it.

Reboot afterwards.

----------------------------------------------------------------

Post a new log here after you've done the above.

----------------------------------------------------------------

You definitely want to install and run the programs that BluesHarp28 advised you of. These are spyware detection-and-removal programs that everyone should have and use.

Make sure that Ad-Aware and Spybot are up-to-date with the latest files before you use them. Run Ad-Aware first and Spybot second.

----------------------------------------------------------------
 

·
Registered
Joined
·
18 Posts
Discussion Starter · #5 ·
Here is my new log from HijackThis after following your instructions.

I am still having problems with my tab key (not allowing me to type in text box fields unless I click it with a mouse) and the CD ROM is not recognizing CDs. Any ideas for those problems? Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 1:11:44 PM, on 7/13/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CONNECT TO GBRONLINE\DIALER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gbronline.com/gbr_prod/city.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/ext/gw/home.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/ext/gw/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gbronline.com/gbr_prod/city.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gbronline.com/gbr_prod/city.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\PROGRAM FILES\GBR XTREME SPEED\PRPL_IEPOPUPBLOCKER.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://gateway.yahoo.com
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://www.gateway.com/support/contact/serial/gwCID.CAB
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - http://www107.coolsavings.com/download/cscmv5X.cab
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
 

·
Trusted Advisor
Joined
·
85,511 Posts
Go back into the MSCONFIG "Startup" tab, remove the checkmark from:

PCHSchd.exe

click Apply - OK, then reboot.

----------------------------------------------------------------

I'm not a hardware expert, so I can't help you with your CDROM drive.

---------------------------------------------------------------
 

·
Registered
Joined
·
18 Posts
Discussion Starter · #7 ·
This is my log from the Spyware Doctor. Can I manually go in and delete the

Scan Results:
scan start: 7/15/2005 11:45:15 PM
scan stop: 7/15/2005 11:57:53 PM
scanned items: 45839
found items: 108
found and ignored: 0
tools used: General Scanner, Process Scanner, Hosts scanner, LSP Scanner, Registry Scanner, Cookie Scanner, Browser Defaults, Favorites and ZoneMap Scanner, ActiveX Scanner, Disk Scanner

Infection Name Location Risk
CoolSavings HKLM\software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/CpnMgr.dll Medium
CoolSavings HKLM\software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/CpnMgr.dll## Medium
CoolSavings HKLM\software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/CpnMgr.dll##.Owner Medium
CoolSavings HKLM\software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/CpnMgr.dll##{549F957E-2F89-11D6-8CFE-00C04F52B225} Medium
CoolSavings HKLM\software\microsoft\windows\currentversion\shareddlls##C:\WINDOWS\Downloaded Program Files\CpnMgr.dll Medium
CoolSavings HKCR\cpnmgr.cmv5 Medium
CoolSavings HKCR\cpnmgr.cmv5## Medium
CoolSavings HKCR\cpnmgr.cmv5\CLSID Medium
CoolSavings HKCR\cpnmgr.cmv5\CLSID## Medium
CoolSavings HKCR\cpnmgr.cmv5\CurVer Medium
CoolSavings HKCR\cpnmgr.cmv5\CurVer## Medium
CoolSavings HKCR\cpnmgr.cmv5.3 Medium
CoolSavings HKCR\cpnmgr.cmv5.3## Medium
CoolSavings HKCR\cpnmgr.cmv5.3\CLSID Medium
CoolSavings HKCR\cpnmgr.cmv5.3\CLSID## Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225} Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}## Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0 Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0## Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\FLAGS Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\FLAGS## Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\0 Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\0## Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\0\win32 Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\0\win32## Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\HELPDIR Medium
CoolSavings HKCR\typelib\{549f9571-2f89-11d6-8cfe-00c04f52b225}\1.0\HELPDIR## Medium
Tracking Cookie(s) [email protected]_5x7j[1].txt Medium
Tracking Cookie(s) [email protected][4].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected]_3m5w[1].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected]_8f3u[1].txt Medium
Advertising [email protected][2].txt Low
Advertising [email protected][5].txt Low
Advertising [email protected][2].txt Low
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected]rics[1].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Specific911 Hijack [email protected][1].txt High
Tracking Cookie(s) [email protected][4].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Advertising [email protected][3].txt Low
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][4].txt Medium
Advertising [email protected][2].txt Low
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected]_8i4s[1].txt Medium
Tracking Cookie(s) [email protected][4].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Advertising [email protected][2].txt Low
Advertising [email protected][1].txt Low
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Advertising [email protected][2].txt Low
Tracking Cookie(s) [email protected][1].txt Medium
Rogue Anti-Spyware Products [email protected][2].txt High
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Tracking Cookie(s) [email protected][1].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Advertising [email protected][2].txt Low
Tracking Cookie(s) [email protected][3].txt Medium
Tracking Cookie(s) [email protected][2].txt Medium
Advertising [email protected][3].txt Low
Tracking Cookie(s) [email protected][1].txt Medium
Advertising [email protected][5].txt Low
Tracking Cookie(s) [email protected][1].txt Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225} Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\ProgID Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\VersionIndependentProgID Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Programmable Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\InprocServer32 Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Control Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Insertable Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\ToolboxBitmap32 Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\MiscStatus Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\MiscStatus\1 Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\TypeLib Medium
CoolSavings HKCR\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Version Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225} Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\ProgID Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\VersionIndependentProgID Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Programmable Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\InprocServer32 Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Control Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Insertable Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\ToolboxBitmap32 Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\MiscStatus Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\MiscStatus\1 Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\TypeLib Medium
CoolSavings HKLM\Software\Classes\CLSID\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Version Medium
CoolSavings HKLM\Software\Microsoft\Code Store Database\Distribution Units\{549F957E-2F89-11D6-8CFE-00C04F52B225} Medium
CoolSavings HKLM\Software\Microsoft\Code Store Database\Distribution Units\{549F957E-2F89-11D6-8CFE-00C04F52B225}\DownloadInformation Medium
CoolSavings HKLM\Software\Microsoft\Code Store Database\Distribution Units\{549F957E-2F89-11D6-8CFE-00C04F52B225}\InstalledVersion Medium
CoolSavings HKLM\Software\Microsoft\Code Store Database\Distribution Units\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Contains Medium
CoolSavings HKLM\Software\Microsoft\Code Store Database\Distribution Units\{549F957E-2F89-11D6-8CFE-00C04F52B225}\Contains\Files Medium
PurityScan C:\WINDOWS\Application Data\dm.ini Elevated
CoolSavings C:\WINDOWS\Downloaded Program Files\CpnMgr.dll Medium
Lop.com C:\WINDOWS\Twunk001.MTX High

I've deleted my cookies, can I go in and delete the other high threat ones through Windows or do I have to buy the upgrade to Spyware Doctor?

Thanks!
 

·
Registered
Joined
·
18 Posts
Discussion Starter · #9 ·
I have downloaded and run the adaware and spybot programs. I am still having problems with the computer freezing up. (The CDrom is not working and it will sometimes act like it is trying to read a CD when there is none inserted. Does that have anything to do with it?)
 

·
Registered
Joined
·
18 Posts
Discussion Starter · #11 ·
Thanks, I will try that. My other post didn't make it (computer froze up, of course) but I mistakenly downloaded spydoctor on the spybot webpage. I've fixed my mistake and downlaoded and run spybot. I will try the CWshredder again, it froze up when I tried it.
 

·
Trusted Advisor
Joined
·
85,511 Posts
Before you run Ad-aware SE Personal 1.06 and Spybot - Search & Destroy 1.4, make sure to run their update function and get them up-to-date with the latest files. Whenever you run them both, run Ad-Aware and Spybot second.
 

·
Registered
Joined
·
18 Posts
Discussion Starter · #13 ·
When using the EasyCleaner, do I delete ALL the uneccesary files and invalid entries, or should I compare them to something and select only certain ones?

Thanks for your guidance!
Stephanie
 

·
Trusted Advisor
Joined
·
85,511 Posts
Delete all the unnecessary files and invalid registry entries, then close EasyCleaner, then reboot.

As previously stated, just use the "Registry" and "Unnecessary" functions and don't mess with the other functions.
 
1 - 15 of 15 Posts
Status
Not open for further replies.
Top