Re: SYSTEM ERRORS WHLE RUNNING FreeFixer

102 wyświetlenia
Przejdź do pierwszej nieodczytanej wiadomości

Roger Karlsson

nieprzeczytany,
14 mar 2013, 18:16:5514.03.2013
do freefix...@googlegroups.com
Hello Connie,

I think that the item that could not be deleted is an Internet Explorer
toolbar button added by Babylon. Currently FreeFixer does not scan
toolbar buttons, so it will not appear in the scan result. I'll add that
scan location in FreeFixer 1.04.

If you don't want to wait for FreeFixer 1.04, which I hopefully have
ready for release next week, you can try Hijackthis. I think Hijackthis
can delete toolbar buttons. You can download Hijackthis here:

http://www.bleepingcomputer.com/download/hijackthis/

Hope that solved the problem.

/Roger

On 2013-03-13 11:11, Connie wrote:
>
> FreeFixer v1.03 log
> http://www.freefixer.com/
> Operating system: Windows XP Service Pack 3
> Log dated 2013-03-13 05:00
>
>
> Winlogon Notify (11 whitelisted)
> igfxcui, C:\WINDOWS\system32\igfxsrvc.dll
>
> Basic Internet Explorer settings
> HKCU\..\Main, Start Page = http://www.google.com/
> HKCU\..\Desktop\General, Wallpaper = C:\WINDOWS\Soap Bubbles.bmp
>
> Registry Startups (5 whitelisted)
> HKLM\..\Run, AllShare Play = C:\Program Files\Samsung\AllShare
> Play\utils\AllShare Play Launcher.exe
> HKLM\..\Run, QuickTime Task = "C:\Program Files\QuickTime\qttask.exe"
> -atboottime
>
> Processes (30 whitelisted)
> C:\Program Files\Samsung\AllShare Framework
> DMS\1.3.06\AllShareFrameworkManagerDMS.exe
> C:\Program Files\Samsung\AllShare Framework
> DMS\1.3.06\AllShareFrameworkDMS.exe
> C:\Program Files\FreeFixer\freefixer.exe
>
> Services (49 whitelisted)
> AllShare Framework DMS, AllShare Framework DMS, c:\program
> files\samsung\allshare framework
> dms\1.3.06\allshareframeworkmanagerdms.exe
> AllShare Play Service, AllShare Play Service, c:\program
> files\samsung\allshare play\allshare play.exe
>
> Explorer.exe Modules (106 whitelisted)
> C:\Documents and Settings\Administrator\Application
> Data\Dropbox\bin\DropboxExt.17.dll
> C:\Program Files\Illustrate\dBpoweramp\dBShell.dll
>
> IExplorer.exe Modules (91 whitelisted)
> C:\Documents and Settings\Administrator\Application
> Data\Dropbox\bin\DropboxExt.17.dll
>
> Drivers (35 whitelisted)
> SASDIFSV, SASDIFSV, c:\program files\superantispyware\sasdifsv.sys
> SASKUTIL, SASKUTIL, c:\program files\superantispyware\saskutil.sys
>
> Windows XP Firewall authorized apps (5 whitelisted)
> C:\Program Files\VideoLAN\VLC\vlc.exe
> C:\Program Files\FrostWire 5\FrostWire.exe
> C:\Program Files\Foxit Software\PDF Editor\PDFEdit.exe
> C:\Program Files\Samsung\AllShare Framework
> DMS\1.3.06\AllShareFrameworkDMS.exe
> C:\Documents and Settings\Administrator\Application
> Data\Dropbox\bin\Dropbox.exe
> C:\Program Files\Samsung\AllShare Play\AllShare Play.exe
>
> Csrss.exe virtual memory files (38 whitelisted)
> C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\DMSManager.dll
> C:\Program Files\Samsung\AllShare Framework
> DMS\1.3.06\AllShareFrameworkDMS.exe
> C:\Program Files\Illustrate\dBpoweramp\GetPopupInfo.exe
> C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\us.dll
>
> History
> -HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser,
> {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}
> -HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser,
> {2318C2B1-4965-11D4-9B18-009027A5CD4F}
> -c:\Documents and Settings\Administrator\Local Settings\temp\busunint.exe
> -c:\Documents and Settings\Administrator\Local Settings\temp\uninst1.exe
> -c:\Documents and Settings\Administrator\Local Settings\Application
> Data\Google\Chrome\User
> Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll
> -c:\Documents and Settings\Administrator\Local Settings\Application
> Data\Google\Chrome\User
> Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\BUSolution.dll
> -c:\Documents and Settings\Administrator\Local
> Settings\temp\nsg39.tmp\nsProcess.dll
> -c:\Documents and Settings\All Users\Application
> Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe
> (on reboot)
> -c:\Documents and Settings\All Users\Application
> Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-19.0.dll
> (on reboot)
> -c:\Documents and Settings\All Users\Application
> Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll
> (on reboot)
> -c:\Documents and Settings\All Users\Application
> Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
> (on reboot)
> -c:\Documents and Settings\Administrator\Local
> Settings\temp\nsd20.tmp\Time.dll
> -c:\Documents and Settings\Administrator\Local
> Settings\temp\nsc1E.tmp\Time.dll
> -c:\Documents and Settings\Administrator\Local
> Settings\temp\nsr17.tmp\Time.dll
> -c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll
> (on reboot)
> -C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\0931BE05-BAB0-7891-B587-8AABC4AFBA4E\MyBabylonTB.exe
> -C:\Documents and Settings\All Users\Application
> Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\components\BrowserProtect-19.0.dll
> (on reboot)
> -C:\Documents and Settings\All Users\Application
> Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
> (on reboot)
> -C:\Documents and Settings\All Users\Application
> Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe
> (on reboot)
> -HKLM\SYSTEM\CurrentControlSet\Services\ntcdrdrv
>
> The following errors occurred during the scan:
> Problems opening folder 'c:\Documents and Settings\Administrator\My
> Documents\My Music\Mary J. Blige\??«???2»??' to enumerate files.
> FindFirstFile failed. System error message: The filename, directory
> name, or volume label syntax is incorrect. Error code: 123.
> Problems opening folder 'c:\Qoobox\BackEnv' to enumerate files.
> FindFirstFile failed. System error message: Access is denied. Error
> code: 5.
>
> End of FreeFixer log
> I CAN NOT REMOVE THIS FROM ITEM FROM MY COMPUTER - PLEASE HELP
> Name: Translate this web page with Babylon
> Publisher: Not Available
> Type: Browser Extension
> Version: Not available
> File date:
> Date last accessed: Today, March 13, 2013, 7 minutes ago
> Class ID: {F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
> Use count: 27
> Block count: 362
> File: Not available
> Folder: Not available
>
> --
> You received this message because you are subscribed to the Google
> Groups "FreeFixer User Forum" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to freefixer-for...@googlegroups.com.
> To post to this group, send email to freefix...@googlegroups.com.
> Visit this group at http://groups.google.com/group/freefixer-forum?hl=en.
> For more options, visit https://groups.google.com/groups/opt_out.
>
>

Odpowiedz wszystkim
Odpowiedz autorowi
Przekaż
Nowe wiadomości: 0