- Thread starter
- #21
A
Angel
PCR,
It was not in the chest. The first time it showed up, I deleted it. then
when I re-ran the Avast! it showed up again and I put it in the chest. BUT
it is not there!! Mystery!! Now what? Looks like Avast! did a false reading.
Could F-Prot be doing a false reading also? Now I am going to go through my
routine and find out what happens.
Angel
"Angel" <angel@noway.com> wrote in message
news:%23m5ZJQ%230HHA.464@TK2MSFTNGP02.phx.gbl...
> Hi PCR,
> I figured out how to use the browse and how to do it. I did it and
only
> one came up with something when I run the cab file F-Prot 4.3.2.48
> 2007.07.31 File is damaged. Now I will put the thing back and see what
> happens. I hope that it will come out not damaged. Wish me luck.
> Angel
>
> "Angel" <angel@noway.com> wrote in message
> news:eF2%23Ej80HHA.4928@TK2MSFTNGP05.phx.gbl...
> > Please explain what you mean by making a file? How is it done? Please
> > explain in more detail.
> > I found the thing under RunServices. So I know it is on the machine.
> > Angel
> >
> > "PCR" <pcrrcp@netzero.net> wrote in message
> > news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl...
> > Angel wrote:
> > | Hi PCR,
> > | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows.
> > | It is a multimedia keyboard.
> > | Smart Bridge is my SDL program.
> >
> > Alright. It shouldn't hurt to uncheck them just to test it. Some
programs
> > will include innocent pop-up ads. But probably it is something else.
Post
> > back to that other thread, then. There are good people in it!
> >
> > | There was only 1 LoadPowerProfile. I checked it out.
> >
> >
> > You should have this one, too...
> >
> > LoadPowerProfile Registry (Machine Run) Rundll32.exe
> > powrprof.dll,LoadCurrentPwrScheme
> >
> > To get it, use Notepad to make a file named "LPP.reg" from the
> following...
> >
> > ......Start after this dotted line.........
> > REGEDIT4
> >
> > [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
> > "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
> > [END]
> > ......End before this dotted line.........
> >
> > NOTE: You should get 5 lines. If more, there has been word-wrap. Don't
run
> > it, then. Post back, & I'll try something else.
> >
> > Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig
> to
> > confirm it is there. If so, you may delete "LPP.reg".
> >
> > | I did the Scans again Spybot found 3 drivecleaner.com cookies
> > | under the title of winsoftware.
> >
> > Those couldn't be the problem, if it still exists. Didn't hurt to get
rid
> of
> > the Cookies, though.
> >
> > | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm
> > | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki
> > | lounge. I deleted it. At the end of the scan, I had done a through
> > | one. This showed up in the results of the scan:
> > | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm.
> > | Infection:VBS:malware{HTML} Error occurred during moving file to
> > | chest. Before trying to move it I tried to delete it. How do I get
> > | rid of this malware? Now I think I found the culprit. Now lets get
> > | it out of my machine. Angel
> >
> > That was a false alarm, as I posted separately. And with new defs, it
goes
> > away. Can you undo what avast! did to the file(s)?
> >
> > | "PCR" <pcrrcp@netzero.net> wrote in message
> > | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl...
> > |> Angel wrote:
> > |> | PCR,
> > |> | I found the directions so here it is:
> > |> |
> > |> | SystemTray Registry (Machine Run) SysTray.Exe
> > |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe
> > |> | /autorun
> > |>
> > |> Those are fine.
> > |>
> > |> | Motive SmartBridge Registry (Machine Run)
> > |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
> > |>
> > |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I
> > |> said below. Reboot, & see whether it stops.
> > |>
> > |> | CHotKey Registry (Machine Run) mk9908.exe
> > |>
> > |> I'm not finding anything about pop-ups with mk9908.exe at Google.
> > |> Yours looks odd, though, in that it doesn't mention a folder. What
> > |> folder is mk9908.exe in? Are you sure it starts the way that line is
> > |> now?
> > |>
> > |> You can get the folder into that line using MSConfig. If it is a LFN
> > |> (Long File Name), you must surround it with quotes, or use the SFN
> > |> instead.
> > |>
> > |> | avast! Web Scanner Registry (Machine Run)
> > |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
> > |>
> > |> OK.
> > |>
> > |> | KB918547 Registry (Machine Service)
> > |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
> > |>
> > |> | KB891711 Registry (Machine
> > |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE
> > |>
> > |> | LoadPowerProfile
> > |> | Registry (Machine Service) Rundll32.exe
> > |> | powrprof.dll,LoadCurrentPwrScheme
> > |>
> > |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did
> > |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then,
> > |> re-check it.
> > |>
> > |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC
> > |> | PowerChute Personal Edition\mainserv.exe
> > |>
> > |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in,
> > |> but I chose not to install the software. It works fine that way, but
> > |> I must close down, myself, within 20 minutes. It saved me several
> > |> times.
> > |>
> > |> I doubt this would include pop-up ads. But, is it the last thing you
> > |> installed before they started? Then, maybe uncheck it at...
> > |>
> > |> "START button, Run, MSConfig, Startup tab"
> > |>
> > |> ..., reboot, & see whether they stop.
> > |>
> > |> | avast! Registry (Machine Service) C:\Program Files\Alwil
> > |> | Software\Avast4\ashServ.exe
> > |>
> > |> OK.
> > |>
> > |> | Angel
> > |> |
> > |> | "PCR" <pcrrcp@netzero.net> wrote in message
> > |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl...
> > |> |> Angel wrote:
> > |> |> | Meb,
> > |> |> | I thought it was me. I maybe should retype what I just
> > |> |> | typed to you. If this goes through I will.I tried to use PCR's
> > |> |> | email at the bottom of his posts. But no answer. I wonder if it
> > |> |> | is his real email. Mine is different than the one in my posts.
> > |> |>
> > |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you
> > |> |> posted to me, Angel, but now you know I have answered it.
> > |> |>
> > |> |> As Candlin & MEB verify, the NG possibly was under maintenance,
> > |> |> which does happen now/then. It used to happen more often. You
> > |> |> should sleep through it or go for a walk!
> > |> |>
> > |> |> For the OE icons/buttons, those are adjustable this way... Grab
> > |> |> the icon area or the menu area at the far left with the mouse.
> > |> |> You will see a two pointed arrow going horizontally through two
> > |> |> vertical lines after you start moving the mouse. Move the area up
> > |> |> or down, until the buttons show again.
> > |> |>
> > |> |> For the pop-ups, I think the others in the other thread are making
> > |> |> sense. As MEB said, post a HijackThis report, or at least...
> > |> |>
> > |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup
> > |> |> Programs".
> > |> |> (2) Use the Edit menu to Select All & Copy.
> > |> |> (3) Post it here or there.
> > |> |>
> > |> |> Hopefully, as Terhune may have said, these pop-ups are an
> > |> |> annoyance, but not a real threat. Then, once it is identified,
> > |> |> there could even be an entry at...
> > |> |>
> > |> |> "START, Settings, Control Panel, Add/Remove Programs,
> > |> |> Install/Uninstall tab"
> > |> |>
> > |> |> ... that will remove it.
> > |> |>
> > |> |> | Let me know if this is
> > |> |> | going through. I have another question, The top of my Outlook
> > |> |> | express has changed the buttons were along the top, now they
> > |> |> | are at the bottom. Are there any settings that need to be
> > |> |> | readjusted? Or is it from the troubles with the Pop ups that
> > |> |> | has caused anything. The buttons are in a drop down button only
> > |> |> | marked with a >>. When I do a post they are across the top
> > |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in
> > |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl...
> > |> |> |>
> > |> |> |> "Angel" <angel@noway.com> wrote in message
> > |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl...
> > |> |> |> | Hi,
> > |> |> |> | I have a dilemma. I tried to post 3 times today to the
> > |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is
> > |> |> |> | happening? Angel
> > |> |> |> |
> > |> |> |> |
> > |> |> |>
> > |> |> |> Good question, I have now tried six times to post a reply to
> > |> |> |> PCR in the firewalls discussion..
> > |> |> |>
> > |> |> |> --
> > |> |> |> MEB
> > |> |> |> http://peoplescounsel.orgfree.com
> > |> |> |> ________
> > |> |>
> > |> |> --
> > |> |> Thanks or Good Luck,
> > |> |> There may be humor in this post, and,
> > |> |> Naturally, you will not sue,
> > |> |> Should things get worse after this,
> > |> |> PCR
> > |> |> pcrrcp@netzero.net
> > |>
> > |> --
> > |> Thanks or Good Luck,
> > |> There may be humor in this post, and,
> > |> Naturally, you will not sue,
> > |> Should things get worse after this,
> > |> PCR
> > |> pcrrcp@netzero.net
> >
> > --
> > Thanks or Good Luck,
> > There may be humor in this post, and,
> > Naturally, you will not sue,
> > Should things get worse after this,
> > PCR
> > pcrrcp@netzero.net
> >
> >
>
>
It was not in the chest. The first time it showed up, I deleted it. then
when I re-ran the Avast! it showed up again and I put it in the chest. BUT
it is not there!! Mystery!! Now what? Looks like Avast! did a false reading.
Could F-Prot be doing a false reading also? Now I am going to go through my
routine and find out what happens.
Angel
"Angel" <angel@noway.com> wrote in message
news:%23m5ZJQ%230HHA.464@TK2MSFTNGP02.phx.gbl...
> Hi PCR,
> I figured out how to use the browse and how to do it. I did it and
only
> one came up with something when I run the cab file F-Prot 4.3.2.48
> 2007.07.31 File is damaged. Now I will put the thing back and see what
> happens. I hope that it will come out not damaged. Wish me luck.
> Angel
>
> "Angel" <angel@noway.com> wrote in message
> news:eF2%23Ej80HHA.4928@TK2MSFTNGP05.phx.gbl...
> > Please explain what you mean by making a file? How is it done? Please
> > explain in more detail.
> > I found the thing under RunServices. So I know it is on the machine.
> > Angel
> >
> > "PCR" <pcrrcp@netzero.net> wrote in message
> > news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl...
> > Angel wrote:
> > | Hi PCR,
> > | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows.
> > | It is a multimedia keyboard.
> > | Smart Bridge is my SDL program.
> >
> > Alright. It shouldn't hurt to uncheck them just to test it. Some
programs
> > will include innocent pop-up ads. But probably it is something else.
Post
> > back to that other thread, then. There are good people in it!
> >
> > | There was only 1 LoadPowerProfile. I checked it out.
> >
> >
> > You should have this one, too...
> >
> > LoadPowerProfile Registry (Machine Run) Rundll32.exe
> > powrprof.dll,LoadCurrentPwrScheme
> >
> > To get it, use Notepad to make a file named "LPP.reg" from the
> following...
> >
> > ......Start after this dotted line.........
> > REGEDIT4
> >
> > [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
> > "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
> > [END]
> > ......End before this dotted line.........
> >
> > NOTE: You should get 5 lines. If more, there has been word-wrap. Don't
run
> > it, then. Post back, & I'll try something else.
> >
> > Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig
> to
> > confirm it is there. If so, you may delete "LPP.reg".
> >
> > | I did the Scans again Spybot found 3 drivecleaner.com cookies
> > | under the title of winsoftware.
> >
> > Those couldn't be the problem, if it still exists. Didn't hurt to get
rid
> of
> > the Cookies, though.
> >
> > | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm
> > | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki
> > | lounge. I deleted it. At the end of the scan, I had done a through
> > | one. This showed up in the results of the scan:
> > | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm.
> > | Infection:VBS:malware{HTML} Error occurred during moving file to
> > | chest. Before trying to move it I tried to delete it. How do I get
> > | rid of this malware? Now I think I found the culprit. Now lets get
> > | it out of my machine. Angel
> >
> > That was a false alarm, as I posted separately. And with new defs, it
goes
> > away. Can you undo what avast! did to the file(s)?
> >
> > | "PCR" <pcrrcp@netzero.net> wrote in message
> > | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl...
> > |> Angel wrote:
> > |> | PCR,
> > |> | I found the directions so here it is:
> > |> |
> > |> | SystemTray Registry (Machine Run) SysTray.Exe
> > |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe
> > |> | /autorun
> > |>
> > |> Those are fine.
> > |>
> > |> | Motive SmartBridge Registry (Machine Run)
> > |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
> > |>
> > |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I
> > |> said below. Reboot, & see whether it stops.
> > |>
> > |> | CHotKey Registry (Machine Run) mk9908.exe
> > |>
> > |> I'm not finding anything about pop-ups with mk9908.exe at Google.
> > |> Yours looks odd, though, in that it doesn't mention a folder. What
> > |> folder is mk9908.exe in? Are you sure it starts the way that line is
> > |> now?
> > |>
> > |> You can get the folder into that line using MSConfig. If it is a LFN
> > |> (Long File Name), you must surround it with quotes, or use the SFN
> > |> instead.
> > |>
> > |> | avast! Web Scanner Registry (Machine Run)
> > |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
> > |>
> > |> OK.
> > |>
> > |> | KB918547 Registry (Machine Service)
> > |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
> > |>
> > |> | KB891711 Registry (Machine
> > |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE
> > |>
> > |> | LoadPowerProfile
> > |> | Registry (Machine Service) Rundll32.exe
> > |> | powrprof.dll,LoadCurrentPwrScheme
> > |>
> > |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did
> > |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then,
> > |> re-check it.
> > |>
> > |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC
> > |> | PowerChute Personal Edition\mainserv.exe
> > |>
> > |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in,
> > |> but I chose not to install the software. It works fine that way, but
> > |> I must close down, myself, within 20 minutes. It saved me several
> > |> times.
> > |>
> > |> I doubt this would include pop-up ads. But, is it the last thing you
> > |> installed before they started? Then, maybe uncheck it at...
> > |>
> > |> "START button, Run, MSConfig, Startup tab"
> > |>
> > |> ..., reboot, & see whether they stop.
> > |>
> > |> | avast! Registry (Machine Service) C:\Program Files\Alwil
> > |> | Software\Avast4\ashServ.exe
> > |>
> > |> OK.
> > |>
> > |> | Angel
> > |> |
> > |> | "PCR" <pcrrcp@netzero.net> wrote in message
> > |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl...
> > |> |> Angel wrote:
> > |> |> | Meb,
> > |> |> | I thought it was me. I maybe should retype what I just
> > |> |> | typed to you. If this goes through I will.I tried to use PCR's
> > |> |> | email at the bottom of his posts. But no answer. I wonder if it
> > |> |> | is his real email. Mine is different than the one in my posts.
> > |> |>
> > |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you
> > |> |> posted to me, Angel, but now you know I have answered it.
> > |> |>
> > |> |> As Candlin & MEB verify, the NG possibly was under maintenance,
> > |> |> which does happen now/then. It used to happen more often. You
> > |> |> should sleep through it or go for a walk!
> > |> |>
> > |> |> For the OE icons/buttons, those are adjustable this way... Grab
> > |> |> the icon area or the menu area at the far left with the mouse.
> > |> |> You will see a two pointed arrow going horizontally through two
> > |> |> vertical lines after you start moving the mouse. Move the area up
> > |> |> or down, until the buttons show again.
> > |> |>
> > |> |> For the pop-ups, I think the others in the other thread are making
> > |> |> sense. As MEB said, post a HijackThis report, or at least...
> > |> |>
> > |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup
> > |> |> Programs".
> > |> |> (2) Use the Edit menu to Select All & Copy.
> > |> |> (3) Post it here or there.
> > |> |>
> > |> |> Hopefully, as Terhune may have said, these pop-ups are an
> > |> |> annoyance, but not a real threat. Then, once it is identified,
> > |> |> there could even be an entry at...
> > |> |>
> > |> |> "START, Settings, Control Panel, Add/Remove Programs,
> > |> |> Install/Uninstall tab"
> > |> |>
> > |> |> ... that will remove it.
> > |> |>
> > |> |> | Let me know if this is
> > |> |> | going through. I have another question, The top of my Outlook
> > |> |> | express has changed the buttons were along the top, now they
> > |> |> | are at the bottom. Are there any settings that need to be
> > |> |> | readjusted? Or is it from the troubles with the Pop ups that
> > |> |> | has caused anything. The buttons are in a drop down button only
> > |> |> | marked with a >>. When I do a post they are across the top
> > |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in
> > |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl...
> > |> |> |>
> > |> |> |> "Angel" <angel@noway.com> wrote in message
> > |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl...
> > |> |> |> | Hi,
> > |> |> |> | I have a dilemma. I tried to post 3 times today to the
> > |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is
> > |> |> |> | happening? Angel
> > |> |> |> |
> > |> |> |> |
> > |> |> |>
> > |> |> |> Good question, I have now tried six times to post a reply to
> > |> |> |> PCR in the firewalls discussion..
> > |> |> |>
> > |> |> |> --
> > |> |> |> MEB
> > |> |> |> http://peoplescounsel.orgfree.com
> > |> |> |> ________
> > |> |>
> > |> |> --
> > |> |> Thanks or Good Luck,
> > |> |> There may be humor in this post, and,
> > |> |> Naturally, you will not sue,
> > |> |> Should things get worse after this,
> > |> |> PCR
> > |> |> pcrrcp@netzero.net
> > |>
> > |> --
> > |> Thanks or Good Luck,
> > |> There may be humor in this post, and,
> > |> Naturally, you will not sue,
> > |> Should things get worse after this,
> > |> PCR
> > |> pcrrcp@netzero.net
> >
> > --
> > Thanks or Good Luck,
> > There may be humor in this post, and,
> > Naturally, you will not sue,
> > Should things get worse after this,
> > PCR
> > pcrrcp@netzero.net
> >
> >
>
>