republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Do you trust the uninstaller?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
(topic move) Hard drive space disappearing, reappearing »
« (topic move) couldnt open disk multi(0)disk(0)rdisk(0). . .  
AuthorAll Replies


smileatus

@Dial1.Atl

 reply to h00ch
Re: aproposfix

Worked great! I tried two other fixes I found on other forums: Making sure the Plug and Play service was running; and setting the permissions for the Enum registry entry, but neither got my Device Manager back. However aproposfix did the trick. Here is the log:

Log of AproposFix v1

************

Running from directory:
C:\_Rick\Fix\aproposfix

************

Registry entries found:

[HKEY_LOCAL_MACHINE\Software\C7XXtAGsMVn5]
@="wNT2s\\2abbabbcb6INROXYabbaqdb6w\\\\3bSYSTEMhgbDRIVERSbKBDREAMScSYS"
"Device"="\\\\.\\Winroxy"
"DriverPath"="C:\\WINNT\\system32\\drivers\\kbdreams.sys"
"DriverName"="IntSENS"
"HideUninstallerName"="C:\\Program Files\\Qui star\\rex00133.exe"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="http://adchannel.contextplus.net/legal-note/nonbranded.html"
"PartnerId"="CP.GH2"
"InstallationId"="{Xc932d82-081e-1297-1588-6e2ed72e8e3d}"
"PageFiltering"=dword:00000002
"ClientName"="C:\\Program Files\\Qui star\\gpttpqfe.exe"
"AutoUpdater"="C:\\WINNT\\system32\\ddmernat.exe"
"Version"="2.0.128"
"CrMnTmt"=dword:0036ee80

************

Removing hidden service:
Service IntSENS removed.

Removing hidden folder:

Deleting files:

Deletion of file C:\WINNT\system32\drivers\kbdreams.sys succeeded!
Deletion of file C:\WINNT\system32\ddmernat.exe succeeded!

Backing up files:
Done!

Removing registry entries:

REGEDIT4

[-HKEY_CURRENT_USER\Software\C7XXtAGsMVn5]
[-HKEY_LOCAL_MACHINE\Software\C7XXtAGsMVn5]

Done!

Finished!


CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL

smileatus, that's what you had. Fixed now

This line:
"ServerAddress"="adchannel.contextplus.net"

And this line (random named folder in Program files):
C:\\Program Files\\Qui star

Clear signs of the Apropos Adware with Rootkit that this fix was designed for. Your log looks good and you should be ok now.

Ya'll can thank Swandog46 for this fix - he wrote it
--
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2006
Proud Member of ASAP (Alliance of Security Analysis Professionals)
Thread is
Forums » Up and Running » Security » Security(topic move) Hard drive space disappearing, reappearing »
« (topic move) couldnt open disk multi(0)disk(0)rdisk(0). . .  


Friday, 27-Nov 07:57:47 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [115] Time Warner Cable Fires Broadside At Broadcasters
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [64] In-Flight Internet Headed For Bumpy Landing?
· [56] Thanksgiving Open Thread
· [38] ICANN Slams DNS Redirection
· [36] Senators Want ACTA Made Public
· [35] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· Newegg Black Friday Sale started [Users Find Hot Deals]
· Windows 7 boot manager editing questions [Microsoft Help]
· SSD [Computer Hardware Discussion/Reviews]
· Bell Response to PIPEDA Request [TekSavvy]
· Only firefox accesses Internet? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Not strictly "Home" related - but WOW anyways... [Home Repair & Improvement]
· Whats the big deal about being "Old School"....? [World of Warcraft]
· Slow speeds in the evenings [TekSavvy]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]