<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>without explorere.exe in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22507453</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 20:13:57 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 20:13:57 EDT</lastBuildDate>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22593147</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hopefully that got it all then, but the ComboFix log would have been a better view. When you do go there, please let me know in advance so I have an idea when you will be posting.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22593147</guid>
<pubDate>Mon, 22 Jun 2009 19:01:57 EDT</pubDate>
</item>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22583121</link>
<description><![CDATA[<A HREF="/useremail/u/176306"><b>yazdzik</b></A> : Thanks, Joker - <br><br>This is a little like giving wireless help in ATU - <br><br>Except I know that once the victim is connected, it will work for at least 24 hours. ;)<br><br>The worst part is, convincing anyone not to run as privileged user, particularly teens whose every visit to the web is fraught with "do you want to install xyz now?"  <br><br>Will post hj log next time I visit NY, combo fix was not necessary, I think, since explorer.exe and everything else I tried now work.<br><br>I did install the console, though, as I do that on every windows pc I work on.  <br><br>You are the best.<br><br>Regards,<br>Martin<br><small>--<br>Life is a series of return dates.  There is but one final argument, its eloquence determines who we were, and whether who we were had meaning.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22583121</guid>
<pubDate>Sat, 20 Jun 2009 13:34:46 EDT</pubDate>
</item>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22582411</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : There is still work to do though.<br><br>If you followed the last instructions, there will be a ComboFix log that you need to post, along with a new HijackThis log. There is likely still work to do based on the log, and after that is taken care of, ComboFix will need to be uninstalled.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22582411</guid>
<pubDate>Sat, 20 Jun 2009 10:09:39 EDT</pubDate>
</item>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22581674</link>
<description><![CDATA[<A HREF="/useremail/u/176306"><b>yazdzik</b></A> : Dear Joker, <br><br>Renaming the files worked, at which point, editing the registry, which is a task I loathe, to point to the explorer.exe where it really is finished the job.<br><br>There is no way to say thank you that is not a understatement.  Now, if my son learnt his lesson, all will be well.<br><br>Superb job of helping the barely literate, and a model of kindness with your patience.<br><br>Sincerely,<br><br>Martin<br><small>--<br>Life is a series of return dates.  There is but one final argument, its eloquence determines who we were, and whether who we were had meaning.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22581674</guid>
<pubDate>Sat, 20 Jun 2009 01:11:43 EDT</pubDate>
</item>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22510180</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>I have both sdfix and mbam installers on the desktop, can apparently run the executable via task manager yet nothing installs.<hr></blockquote><br><br>Did the MBAM install program run successfully and install the program and it just won't run (is the folder C:\Program Files\Malwarebytes' Anti-Malware there?), or did it not even install?<br><br>There was a reason I said:<br> <blockquote><small>quote:</small><hr>don't use a USB/Flash drive, it can spread infection<hr></blockquote><br><br>You need to quarantine that flash drive and not use it in any other computer at the moment, or you risk infecting any system you insert it into.<br><br>If MBAM didn't install, rename the installer program to a random name of your choosing and see if it will install. once installed, go to C:\Program Files\Malwarebytes' Anti-Malware and rename mbam.exe to a random name, and see if it will run. If it will, please follow the previous instructions on it's use.<br><br>If none of that works, try installing MBAM in Safe mode.<br><br>Download Bill Castner's <b>FixPolicies.exe</b>, a self-extracting ZIP archive, to your Desktop  from here: <br><textarea name="code" class="text" cols=50 rows=10>http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe&#012;</textarea><!--end code block-->- Double-click FixPolicies.exe.<br>- Click the "Install" button on the bottom toolbar of the box that will open.<br>- The program will create a new Folder called FixPolicies.<br>- Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.<br>- A black box will briefly appear and then close.<br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. <br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Please post a new HijackThis log, the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22510180</guid>
<pubDate>Sun, 07 Jun 2009 09:09:01 EDT</pubDate>
</item>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22508202</link>
<description><![CDATA[<A HREF="/useremail/u/176306"><b>yazdzik</b></A> : For the record,<br><br>the hiack this stuff you told me to delete was deleted, but explorer.exe does not load -<br><br>this leads me to suspect something else is wrong, though what, I cannot tell. <br><br>(I am a coward, run linux with a separate home partition to avoid just this kind of thing ;) )<br><br>At any rate, I am thoroughly confused as to why explorer does not run.<br><br>Most of all, I cannot see why I can copy the files, running as admin in safe mode, the cli says the programme is executed, but, of course, nothing has been done, i e, no folders, nor files created from mbam or sd.<br><br>Many thanks, and more apologies,<br><br>Martin<br><small>--<br>Life is a series of return dates.  There is but one final argument, its eloquence determines who we were, and whether who we were had meaning.</small><br><br>HT log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:21:35 PM, on 6/6/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\WINDOWS\system32\CTsvcCDA.exe<br>C:\Program Files\Dell Network Assistant\hnm_svc.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\taskmgr.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2080320<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://google.com/" >google.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll<br>O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"<br>O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"<br>O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [F5D9050] C:\Program Files\Belkin\F5D9050\Belkinwcui.exe<br>O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"<br>O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"<br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.1\THGuard.exe"<br>O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler<br>O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe<br>O4 - HKUS\S-1-5-21-4281090102-2936424967-3577067745-501\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup (User 'Guest')<br>O4 - HKUS\S-1-5-21-4281090102-2936424967-3577067745-501\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Guest')<br>O4 - HKUS\S-1-5-21-4281090102-2936424967-3577067745-501\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (User 'Guest')<br>O4 - HKUS\S-1-5-21-4281090102-2936424967-3577067745-501\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Guest')<br>O4 - HKUS\S-1-5-21-4281090102-2936424967-3577067745-501\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Guest')<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &raquo;<A HREF="http://lads.myspace.com/upload/MySpaceUploader1006.cab" >lads.myspace.com/upload/MySpaceU&middot;&middot;&middot;1006.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br>O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe<br>O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br>O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br>O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br>O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br>O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br><br>--<br>End of file - 8944 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22508202</guid>
<pubDate>Sat, 06 Jun 2009 18:21:07 EDT</pubDate>
</item>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22507982</link>
<description><![CDATA[<A HREF="/useremail/u/176306"><b>yazdzik</b></A> : I nevre maek typso -<br><br>_<br><br>Now seriously,  I tried running mbam from the desktop a while back, and nothing happens, to wit, nothing.<br><br>Likewise, I just added sdfix to the desktop via copy and paste from a flash drive and nothing.  task manager says the process is running.  Do they depend upon explorer for their interface?<br><br>Thus, right at the moment, I have both sdfix and mbam installers on the desktop, can apparently run the executable via task manager yet nothing installs.<br><br>trojan hunter, for instance, installed and ran, as did ccleaner, and, of course, hijack this, which has always been on his pc.<br><br>I am become more curious as to why the programmes do not run, or if they do they are not seen, via an interface, to be running.<br><br>Sorry for this mess.<br><br>Peace,<br><br>Martin<br><small>--<br>Life is a series of return dates.  There is but one final argument, its eloquence determines who we were, and whether who we were had meaning.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22507982</guid>
<pubDate>Sat, 06 Jun 2009 17:19:59 EDT</pubDate>
</item>

<item>
<title>Re: without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22507880</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi yazdzik<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br>Several of the items you need to remove are backdoor applications that can allow attackers to access your computer, stealing passwords and personal data. I highly recommend that <b>from a clean, uninfected system</b> you immediately change all the passwords on any systems you access from this system. If you do any on-line banking, or store any financial information on this system, you should immediately call your financial institution and advise them of the situation so you can secure your accounts. <br><br>Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. If it were on my PC I would not hesitate for a moment to do so. Please read these for more information:<br><br><A HREF="http://www.dslreports.com/faq/10451">How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud?</a><br><br><A HREF="http://www.dslreports.com/faq/10063">When Should I Format, How Should I Reinstall</a><br><br>Should you decide not to follow that advice, we will of course do our best to clean the computer of any infections that we can see but, as I already stated, we can in no way guarantee it to be trustworthy.<br><br>If you want to try to disinfect the system:<br><br>I'm not sure what won't run when you say explorer.exe won't run, if you mean Windows Explorer won't run, and you can't open My Computer, or you also can't even go to the program menu's, such as Start > Programs > Accessories > Notepad, for instance.<br><br>Why are you trying to clean the system remotely? Can your son not access the Internet with Internet Explorer or Firefox (or another browser if installed)? It will be much easier for him to do this than for you to try to do it remotely, particularly since he will have to be in Safe mdoe at some points.<br><br>If he can't access the Internet at all, the best thing to do would be for him to have someone with a working system print out this topic for him, and download the needed files and burn them to CD or DVD for him (don't use a USB/Flash drive, it can spread infection). Since he can't run explorer in normal mode (he may be able to in Safe mode), in normal mode any program will need to be run from either the Run line, or by opening a Command window to type the command (Start > Programs > Access ories > Command Prompt. If he wants to run a program called xyz.exe that's saved to the Desktop, he can run that wil the command (either from Run or in a Command window):<br>%desktop%\xyz.exe<br><br>If he can't open Windows Explorer to copy the file to the desktop, this will copy the file from CD drive to the Desktop (the use of D: here assumes the D: is the CD drive letter, if not you will need to change it.<br><br>copy D:\XYZ.exe C:\docume~1\MAXIMI~1\Desktop<br><br>To run that file, you would use:<br>C:\docume~1\MAXIMI~1\Desktop\XYZ.exe<br><br>When you see MAXIMI~1, that's the short file/folder name for the user profile. The folder name starts with the letters MAXIMI and is followed by some additional characters.<br><br>Why has the system never been updated to Windows XP Service Pack 3? Without that, and all security updates since then, the system is unnecessarily vulnerable to numerous exploits. <b>Don't</b> do that now though, as updating an infected system can result in an unrecoverable mess.<br><br>I notice that you have Spybot's TeaTimer running.  While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes.  So please <b>disable TeaTimer</b> by doing the following:<br>1) Run Spybot-S&D<br>2) Go to the Mode menu, and make sure "Advanced Mode" is selected<br>3) On the left hand side, choose Tools -> Resident<br>4) Uncheck "Resident TeaTimer" and OK any prompts<br><br>When everything is done and your log is clean again, you can enable it again.<br>If teatimer gives you a warning afterwords that some changes were made, allow this instead of blocking it.<br>Please don't forget this step to disable teatimer.<br><br>Download SDFix and save it to your Desktop.<br><textarea name="code" class="text" cols=50 rows=10>http://downloads.andymanchesta.com/RemovalTools/SDFix.exe&#012;</textarea><!--end code block-->Double click <b>SDFix.exe</b> and it will extract the files to %systemdrive% <br>(Drive that contains the Windows Directory, typically C:\SDFix) <br><br>Please then reboot your computer in <b>Safe Mode</b> by doing the following:<br>- Restart your computer<br>- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;<br>- Instead of Windows loading as normal, the Advanced Options Menu should appear;<br>- Select the first option, to run Windows in Safe Mode, then press <b>Enter</b>.<br>- Choose your usual account.<br>- Open the extracted SDFix folder and double click <b>RunThis.bat</b> to start the script. <br>If you can't do that, go to Start > Run and type:<br><b>C:\sdfix\sdfix.exe</b><br>- Type <b>Y</b> to begin the cleanup process.<br>- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. <br>- Press any Key and it will restart the PC. <br>- When the PC restarts the Fixtool will run again and complete the removal process then display <b>Finished</b>, press any key to end the script and load your desktop icons.<br>- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as <b>Report.txt</b> <br>(Report.txt will also be copied to Clipboard ready for posting back on the forum).<br>- Finally paste the contents of the Report.txt back on the forum in your next reply.<br><br>Please download Malwarebytes' Anti-Malware from <br><br><textarea name="code" class="text" cols=50 rows=10>http://www.malwarebytes.org/mbam-download.php&#012;</textarea><!--end code block--><br>Double Click mbam-setup.exe to install the application.<br>- Make sure a checkmark is placed next to <b>Update Malwarebytes' Anti-Malware</b> and <b>Launch Malwarebytes' Anti-Malware</b>, then click Finish.<br>- If an update is found, it will download and install the latest version.<br>- Once the program has loaded, select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,<br>O2 - BHO: C:\WINDOWS\system32\rwhbfb873unjdfdg.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\rwhbfb873unjdfdg.dll (file missing)<br>O4 - HKLM\..\Run: [OpenSSL] C:\WINDOWS\system32\open_ssl_irc.exe<br>O4 - HKLM\..\Run: [Windows Update Server] wnupdate.exe<br>O4 - HKLM\..\Run: [Lsuwid] rundll32.exe "C:\WINDOWS\igerakipejoxi.dll",e<br>O4 - HKLM\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br>O4 - HKLM\..\RunServices: [Windows Configuration Loader] winsyscfg32.exe<br>O4 - HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br>O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\MAXIMI~1\LOCALS~1\Temp\csrssc.exe<br>O4 - HKUS\S-1-5-18\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'Default user')<br>O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1<br>O20 - AppInit_DLLs: WIKI.DLL<br>O20 - Winlogon Notify: mamgguqb - mamgguqb.dll (file missing)<br>O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\rwhbfb873unjdfdg.dll (file missing)<br>O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - C:\WINDOWS\system32\gseb37dkjgfgf.dll (file missing)<br>O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)<br>O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Using Windows Exporer (I expect it will be working by this point), delete the following files if still there:<br>C:\WINDOWS\system32\<b>ntos.exe</b><br>C:\WINDOWS\system32\<b>open_ssl_irc.exe</b><br>C:\WINDOWS\system32\<b>wnupdate.exe</b><br>C:\WINDOWS\<b>igerakipejoxi.dll</b><br>C:\WINDOWS\System32\<b>rs32net.exe</b><br>C:\WINDOWS\System32\<b>winsyscfg32.exe</b><br>C:\Documents and settings\MAXIMI~1\Localsettings\Temp\<b>csrssc.exe</b><br>C:\WINDOWS\TEMP\<b>csrssc.exe</b><br>C:\WINDOWS\System32\<b>WIKI.DLL</b><br>C:\WINDOWS\System32\<b>mamgguqb.dll</b><br>C:\WINDOWS\system32\<b>rwhbfb873unjdfdg.dll</b><br>C:\WINDOWS\system32\<b>gseb37dkjgfgf.dll</b><br>C:\WINDOWS\system32\<b>ext.exe</b><br><br>Please restart your system and post a new HijackThis log, the log from MBAM, and note any errors encountered.<br><br>When you post your HijackThis log, if you are using Notepad, please turn off Word Wrap. That is probably what caused all the extra line breaks (the double-spacing) in your log.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22507880</guid>
<pubDate>Sat, 06 Jun 2009 16:43:29 EDT</pubDate>
</item>

<item>
<title>without explorere.exe</title>
<link>http://www.dslreports.com/forum/remark,22507453</link>
<description><![CDATA[<A HREF="/useremail/u/176306"><b>yazdzik</b></A> : Dear Friends in Security,<br><br>Sadly, my son, now living 130 miles away, asked me "why is my computer....?"<br><br>Since, although explorer.exe is present, but will not run, all I could do is run avg from the task thing, and get this hijack this log.<br><br>Admittedly, I have not run a windows box for, well, a long time, so please forgive my ignorance.<br><br>Inline log is:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br><br>Scan saved at 1:58:59 PM, on 6/6/2009<br><br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br><br>MSIE: Internet Explorer v7.00 (7.00.6000.16762)<br><br>Boot mode: Normal<br><br>Running processes:<br><br>C:\WINDOWS\System32\smss.exe<br><br>C:\WINDOWS\system32\winlogon.exe<br><br>C:\WINDOWS\system32\services.exe<br><br>C:\WINDOWS\system32\lsass.exe<br><br>C:\WINDOWS\system32\svchost.exe<br><br>C:\WINDOWS\System32\svchost.exe<br><br>C:\WINDOWS\system32\svchost.exe<br><br>C:\WINDOWS\system32\spoolsv.exe<br><br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br><br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br><br>C:\Program Files\Bonjour\mDNSResponder.exe<br><br>C:\WINDOWS\system32\CTsvcCDA.exe<br><br>C:\Program Files\Dell Network Assistant\hnm_svc.exe<br><br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br><br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br><br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br><br>C:\WINDOWS\system32\nvsvc32.exe<br><br>C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br><br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br><br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br><br>C:\WINDOWS\system32\taskmgr.exe<br><br>C:\WINDOWS\system32\ctfmon.exe<br><br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2080320<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://google.com/" >google.com/</A><br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2080320" >partnerpage.google.com/smallbiz.&middot;&middot;&middot;=2080320</A><br><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br><br>R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll<br><br>F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,<br><br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br><br>O2 - BHO: C:\WINDOWS\system32\rwhbfb873unjdfdg.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\rwhbfb873unjdfdg.dll (file missing)<br><br>O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll<br><br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br><br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br><br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br><br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br><br>O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br><br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br><br>O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"<br><br>O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"<br><br>O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe<br><br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br><br>O4 - HKLM\..\Run: [F5D9050] C:\Program Files\Belkin\F5D9050\Belkinwcui.exe<br><br>O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"<br><br>O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"<br><br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br><br>O4 - HKLM\..\Run: [OpenSSL] C:\WINDOWS\system32\open_ssl_irc.exe<br><br>O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe<br><br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br><br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br><br>O4 - HKLM\..\Run: [Windows Update Server] wnupdate.exe<br><br>O4 - HKLM\..\Run: [Lsuwid] rundll32.exe "C:\WINDOWS\igerakipejoxi.dll",e<br><br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br><br>O4 - HKLM\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br><br>O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br><br>O4 - HKLM\..\RunServices: [Windows Configuration Loader] winsyscfg32.exe<br><br>O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br><br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br><br>O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br><br>O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler<br><br>O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"<br><br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br><br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br><br>O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"<br><br>O4 - HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe<br><br>O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\MAXIMI~1\LOCALS~1\Temp\csrssc.exe<br><br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br><br>O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe<br><br>O4 - HKUS\S-1-5-18\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')<br><br>O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'Default user')<br><br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br><br>O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1<br><br>O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html<br><br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br><br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br><br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br><br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br><br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll<br><br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br><br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br><br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br><br>O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &raquo;<A HREF="http://lads.myspace.com/upload/MySpaceUploader1006.cab" >lads.myspace.com/upload/MySpaceU&middot;&middot;&middot;1006.cab</A><br><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br><br>O20 - AppInit_DLLs: WIKI.DLL<br><br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br><br>O20 - Winlogon Notify: mamgguqb - mamgguqb.dll (file missing)<br><br>O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\rwhbfb873unjdfdg.dll (file missing)<br><br>O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - C:\WINDOWS\system32\gseb37dkjgfgf.dll (file missing)<br><br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br><br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br><br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br><br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br><br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br><br>O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe<br><br>O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)<br><br>O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe<br><br>O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)<br><br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br><br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br><br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br><br>O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe<br><br>O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe<br><br>O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe<br><br>O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br><br>O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br><br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br><br>O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br><br>O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)<br><br>--<br><br>End of file - 10502 bytes<br><br>Obviously, I am lost in the process, as the things which require ie, thus any of the things like panda, cannot be run.  Plus, without explorer.exe, I cannot get him able to unlock his network manager to allow me to view his files sach as the avg log.<br><br>I full well understand if there is no help available under the circumstances.<br><br>Very best wishes,<br><br>martin yazdzik<br><small>--<br>Life is a series of return dates.  There is but one final argument, its eloquence determines who we were, and whether who we were had meaning.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22507453</guid>
<pubDate>Sat, 06 Jun 2009 14:27:54 EDT</pubDate>
</item>

</channel>
</rss>
