Guest Angel Posted July 30, 2007 Posted July 30, 2007 Hi, I have a dilemma. I tried to post 3 times today to the string, "Error Alert?" NO SUCCESS So trying again!! What is happening? Angel
Guest MEB Posted July 30, 2007 Posted July 30, 2007 Re: Trying to post, no success. "Angel" <angel@noway.com> wrote in message news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... | Hi, | I have a dilemma. I tried to post 3 times today to the string, "Error | Alert?" NO SUCCESS So trying again!! What is happening? | Angel | | Good question, I have now tried six times to post a reply to PCR in the firewalls discussion.. -- MEB http://peoplescounsel.orgfree.com ________
Guest Angel Posted July 30, 2007 Posted July 30, 2007 Re: Trying to post, no success. Meb, I thought it was me. I maybe should retype what I just typed to you. If this goes through I will.I tried to use PCR's email at the bottom of his posts. But no answer. I wonder if it is his real email. Mine is different than the one in my posts. Let me know if this is going through. I have another question, The top of my Outlook express has changed the buttons were along the top, now they are at the bottom. Are there any settings that need to be readjusted? Or is it from the troubles with the Pop ups that has caused anything. The buttons are in a drop down button only marked with a >>. When I do a post they are across the top as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > > "Angel" <angel@noway.com> wrote in message > news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > | Hi, > | I have a dilemma. I tried to post 3 times today to the string, > "Error > | Alert?" NO SUCCESS So trying again!! What is happening? > | Angel > | > | > > Good question, I have now tried six times to post a reply to PCR in the > firewalls discussion.. > > -- > MEB > http://peoplescounsel.orgfree.com > ________ > > >
Guest Hugh Candlin Posted July 30, 2007 Posted July 30, 2007 Re: Trying to post, no success. "Angel" <angel@noway.com> wrote in message news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > Hi, > I have a dilemma. I tried to post 3 times today to the string, "Error > Alert?" NO SUCCESS So trying again!! What is happening? > Angel There does seem to be a problem, but it isn't at your end. My posts normally show up instantly. Not today. Granted, the problem will probably have to have been fixed for this reply to show up, so it probably won't do you much good, but, what the hay, you never know............. -- "You can fool some of the people all of the time, and those are the ones you want to concentrate on."
Guest PCR Posted July 30, 2007 Posted July 30, 2007 Re: Trying to post, no success. Angel wrote: | Meb, | I thought it was me. I maybe should retype what I just typed to | you. If this goes through I will.I tried to use PCR's email at the | bottom of his posts. But no answer. I wonder if it is his real email. | Mine is different than the one in my posts. I was dead asleep &/or on my 1st or 2nd walk of the day when you posted to me, Angel, but now you know I have answered it. As Candlin & MEB verify, the NG possibly was under maintenance, which does happen now/then. It used to happen more often. You should sleep through it or go for a walk! For the OE icons/buttons, those are adjustable this way... Grab the icon area or the menu area at the far left with the mouse. You will see a two pointed arrow going horizontally through two vertical lines after you start moving the mouse. Move the area up or down, until the buttons show again. For the pop-ups, I think the others in the other thread are making sense. As MEB said, post a HijackThis report, or at least... (1) "START button, Run, MSInfo32, Software Environment, Startup Programs". (2) Use the Edit menu to Select All & Copy. (3) Post it here or there. Hopefully, as Terhune may have said, these pop-ups are an annoyance, but not a real threat. Then, once it is identified, there could even be an entry at... "START, Settings, Control Panel, Add/Remove Programs, Install/Uninstall tab" .... that will remove it. | Let me know if this is | going through. I have another question, The top of my Outlook | express has changed the buttons were along the top, now they are at | the bottom. Are there any settings that need to be readjusted? Or is | it from the troubles with the Pop ups that has caused anything. The | buttons are in a drop down button only marked with a >>. When I do a | post they are across the top as they were. Angel | "MEB" <meb@not here@hotmail.com> wrote in message | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> |> "Angel" <angel@noway.com> wrote in message |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> | Hi, |> | I have a dilemma. I tried to post 3 times today to the |> | string, "Error Alert?" NO SUCCESS So trying again!! What is |> | happening? Angel |> | |> | |> |> Good question, I have now tried six times to post a reply to PCR in |> the firewalls discussion.. |> |> -- |> MEB |> http://peoplescounsel.orgfree.com |> ________ -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest Angel Posted July 30, 2007 Posted July 30, 2007 Re: Trying to post, no success. Hi PCR, I forgot how which keys to use to get it to you. Please recap You are permitted to take a break. I took a few. Angel "PCR" <pcrrcp@netzero.net> wrote in message news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > Angel wrote: > | Meb, > | I thought it was me. I maybe should retype what I just typed to > | you. If this goes through I will.I tried to use PCR's email at the > | bottom of his posts. But no answer. I wonder if it is his real email. > | Mine is different than the one in my posts. > > I was dead asleep &/or on my 1st or 2nd walk of the day when you posted > to me, Angel, but now you know I have answered it. > > As Candlin & MEB verify, the NG possibly was under maintenance, which > does happen now/then. It used to happen more often. You should sleep > through it or go for a walk! > > For the OE icons/buttons, those are adjustable this way... Grab the icon > area or the menu area at the far left with the mouse. You will see a two > pointed arrow going horizontally through two vertical lines after you > start moving the mouse. Move the area up or down, until the buttons show > again. > > For the pop-ups, I think the others in the other thread are making > sense. As MEB said, post a HijackThis report, or at least... > > (1) "START button, Run, MSInfo32, Software Environment, Startup > Programs". > (2) Use the Edit menu to Select All & Copy. > (3) Post it here or there. > > Hopefully, as Terhune may have said, these pop-ups are an annoyance, but > not a real threat. Then, once it is identified, there could even be an > entry at... > > "START, Settings, Control Panel, Add/Remove Programs, Install/Uninstall > tab" > > ... that will remove it. > > | Let me know if this is > | going through. I have another question, The top of my Outlook > | express has changed the buttons were along the top, now they are at > | the bottom. Are there any settings that need to be readjusted? Or is > | it from the troubles with the Pop ups that has caused anything. The > | buttons are in a drop down button only marked with a >>. When I do a > | post they are across the top as they were. Angel > | "MEB" <meb@not here@hotmail.com> wrote in message > | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > |> > |> "Angel" <angel@noway.com> wrote in message > |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > |> | Hi, > |> | I have a dilemma. I tried to post 3 times today to the > |> | string, "Error Alert?" NO SUCCESS So trying again!! What is > |> | happening? Angel > |> | > |> | > |> > |> Good question, I have now tried six times to post a reply to PCR in > |> the firewalls discussion.. > |> > |> -- > |> MEB > |> http://peoplescounsel.orgfree.com > |> ________ > > -- > Thanks or Good Luck, > There may be humor in this post, and, > Naturally, you will not sue, > Should things get worse after this, > PCR > pcrrcp@netzero.net > >
Guest Angel Posted July 30, 2007 Posted July 30, 2007 Re: Trying to post, no success. PCR, I found the directions so here it is: SystemTray Registry (Machine Run) SysTray.Exe ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe /autorun Motive SmartBridge Registry (Machine Run) C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe CHotKey Registry (Machine Run) mk9908.exe avast! Web Scanner Registry (Machine Run) C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE KB918547 Registry (Machine Service) C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE KB891711 Registry (Machine Service) c:\windows\SYSTEM\KB891711\KB891711.EXE LoadPowerProfile Registry (Machine Service) Rundll32.exe powrprof.dll,LoadCurrentPwrScheme APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe avast! Registry (Machine Service) C:\Program Files\Alwil Software\Avast4\ashServ.exe Angel "PCR" <pcrrcp@netzero.net> wrote in message news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > Angel wrote: > | Meb, > | I thought it was me. I maybe should retype what I just typed to > | you. If this goes through I will.I tried to use PCR's email at the > | bottom of his posts. But no answer. I wonder if it is his real email. > | Mine is different than the one in my posts. > > I was dead asleep &/or on my 1st or 2nd walk of the day when you posted > to me, Angel, but now you know I have answered it. > > As Candlin & MEB verify, the NG possibly was under maintenance, which > does happen now/then. It used to happen more often. You should sleep > through it or go for a walk! > > For the OE icons/buttons, those are adjustable this way... Grab the icon > area or the menu area at the far left with the mouse. You will see a two > pointed arrow going horizontally through two vertical lines after you > start moving the mouse. Move the area up or down, until the buttons show > again. > > For the pop-ups, I think the others in the other thread are making > sense. As MEB said, post a HijackThis report, or at least... > > (1) "START button, Run, MSInfo32, Software Environment, Startup > Programs". > (2) Use the Edit menu to Select All & Copy. > (3) Post it here or there. > > Hopefully, as Terhune may have said, these pop-ups are an annoyance, but > not a real threat. Then, once it is identified, there could even be an > entry at... > > "START, Settings, Control Panel, Add/Remove Programs, Install/Uninstall > tab" > > ... that will remove it. > > | Let me know if this is > | going through. I have another question, The top of my Outlook > | express has changed the buttons were along the top, now they are at > | the bottom. Are there any settings that need to be readjusted? Or is > | it from the troubles with the Pop ups that has caused anything. The > | buttons are in a drop down button only marked with a >>. When I do a > | post they are across the top as they were. Angel > | "MEB" <meb@not here@hotmail.com> wrote in message > | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > |> > |> "Angel" <angel@noway.com> wrote in message > |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > |> | Hi, > |> | I have a dilemma. I tried to post 3 times today to the > |> | string, "Error Alert?" NO SUCCESS So trying again!! What is > |> | happening? Angel > |> | > |> | > |> > |> Good question, I have now tried six times to post a reply to PCR in > |> the firewalls discussion.. > |> > |> -- > |> MEB > |> http://peoplescounsel.orgfree.com > |> ________ > > -- > Thanks or Good Luck, > There may be humor in this post, and, > Naturally, you will not sue, > Should things get worse after this, > PCR > pcrrcp@netzero.net > >
Guest PCR Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Angel wrote: | PCR, | I found the directions so here it is: | | SystemTray Registry (Machine Run) SysTray.Exe | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe /autorun Those are fine. | Motive SmartBridge Registry (Machine Run) | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I said below. Reboot, & see whether it stops. | CHotKey Registry (Machine Run) mk9908.exe I'm not finding anything about pop-ups with mk9908.exe at Google. Yours looks odd, though, in that it doesn't mention a folder. What folder is mk9908.exe in? Are you sure it starts the way that line is now? You can get the folder into that line using MSConfig. If it is a LFN (Long File Name), you must surround it with quotes, or use the SFN instead. | avast! Web Scanner Registry (Machine Run) | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE OK. | KB918547 Registry (Machine Service) | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE | KB891711 Registry (Machine | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE | LoadPowerProfile | Registry (Machine Service) Rundll32.exe | powrprof.dll,LoadCurrentPwrScheme Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did you uncheck one at "START button, Run, MSConfig, Startup tab"? Then, re-check it. | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC | PowerChute Personal Edition\mainserv.exe Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, but I chose not to install the software. It works fine that way, but I must close down, myself, within 20 minutes. It saved me several times. I doubt this would include pop-up ads. But, is it the last thing you installed before they started? Then, maybe uncheck it at... "START button, Run, MSConfig, Startup tab" ...., reboot, & see whether they stop. | avast! Registry (Machine Service) C:\Program Files\Alwil | Software\Avast4\ashServ.exe OK. | Angel | | "PCR" <pcrrcp@netzero.net> wrote in message | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... |> Angel wrote: |> | Meb, |> | I thought it was me. I maybe should retype what I just typed to |> | you. If this goes through I will.I tried to use PCR's email at the |> | bottom of his posts. But no answer. I wonder if it is his real |> | email. Mine is different than the one in my posts. |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you |> posted to me, Angel, but now you know I have answered it. |> |> As Candlin & MEB verify, the NG possibly was under maintenance, which |> does happen now/then. It used to happen more often. You should sleep |> through it or go for a walk! |> |> For the OE icons/buttons, those are adjustable this way... Grab the |> icon area or the menu area at the far left with the mouse. You will |> see a two pointed arrow going horizontally through two vertical |> lines after you start moving the mouse. Move the area up or down, |> until the buttons show again. |> |> For the pop-ups, I think the others in the other thread are making |> sense. As MEB said, post a HijackThis report, or at least... |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup |> Programs". |> (2) Use the Edit menu to Select All & Copy. |> (3) Post it here or there. |> |> Hopefully, as Terhune may have said, these pop-ups are an annoyance, |> but not a real threat. Then, once it is identified, there could even |> be an entry at... |> |> "START, Settings, Control Panel, Add/Remove Programs, |> Install/Uninstall tab" |> |> ... that will remove it. |> |> | Let me know if this is |> | going through. I have another question, The top of my Outlook |> | express has changed the buttons were along the top, now they are at |> | the bottom. Are there any settings that need to be readjusted? Or |> | is it from the troubles with the Pop ups that has caused anything. |> | The buttons are in a drop down button only marked with a >>. When |> | I do a post they are across the top as they were. Angel |> | "MEB" <meb@not here@hotmail.com> wrote in message |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> |> |> |> "Angel" <angel@noway.com> wrote in message |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> | Hi, |> |> | I have a dilemma. I tried to post 3 times today to the |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is |> |> | happening? Angel |> |> | |> |> | |> |> |> |> Good question, I have now tried six times to post a reply to PCR |> |> in the firewalls discussion.. |> |> |> |> -- |> |> MEB |> |> http://peoplescounsel.orgfree.com |> |> ________ |> |> -- |> Thanks or Good Luck, |> There may be humor in this post, and, |> Naturally, you will not sue, |> Should things get worse after this, |> PCR |> pcrrcp@netzero.net -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest Angel Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Hi PCR, The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. It is a multimedia keyboard. Smart Bridge is my SDL program. There was only 1 LoadPowerProfile. I checked it out. I did the Scans again Spybot found 3 drivecleaner.com cookies under the title of winsoftware. Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm C:\Program Files\common files\Microsoft Shared\Stationary\Tiki lounge. I deleted it. At the end of the scan, I had done a through one. This showed up in the results of the scan: C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. Infection:VBS:malware{HTML} Error occurred during moving file to chest. Before trying to move it I tried to delete it. How do I get rid of this malware? Now I think I found the culprit. Now lets get it out of my machine. Angel "PCR" <pcrrcp@netzero.net> wrote in message news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... > Angel wrote: > | PCR, > | I found the directions so here it is: > | > | SystemTray Registry (Machine Run) SysTray.Exe > | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe /autorun > > Those are fine. > > | Motive SmartBridge Registry (Machine Run) > | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe > > I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I > said below. Reboot, & see whether it stops. > > | CHotKey Registry (Machine Run) mk9908.exe > > I'm not finding anything about pop-ups with mk9908.exe at Google. Yours > looks odd, though, in that it doesn't mention a folder. What folder is > mk9908.exe in? Are you sure it starts the way that line is now? > > You can get the folder into that line using MSConfig. If it is a LFN > (Long File Name), you must surround it with quotes, or use the SFN > instead. > > | avast! Web Scanner Registry (Machine Run) > | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE > > OK. > > | KB918547 Registry (Machine Service) > | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE > > | KB891711 Registry (Machine > | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE > > | LoadPowerProfile > | Registry (Machine Service) Rundll32.exe > | powrprof.dll,LoadCurrentPwrScheme > > Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did you > uncheck one at "START button, Run, MSConfig, Startup tab"? Then, > re-check it. > > | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC > | PowerChute Personal Edition\mainserv.exe > > Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, but I > chose not to install the software. It works fine that way, but I must > close down, myself, within 20 minutes. It saved me several times. > > I doubt this would include pop-up ads. But, is it the last thing you > installed before they started? Then, maybe uncheck it at... > > "START button, Run, MSConfig, Startup tab" > > ..., reboot, & see whether they stop. > > | avast! Registry (Machine Service) C:\Program Files\Alwil > | Software\Avast4\ashServ.exe > > OK. > > | Angel > | > | "PCR" <pcrrcp@netzero.net> wrote in message > | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > |> Angel wrote: > |> | Meb, > |> | I thought it was me. I maybe should retype what I just typed to > |> | you. If this goes through I will.I tried to use PCR's email at the > |> | bottom of his posts. But no answer. I wonder if it is his real > |> | email. Mine is different than the one in my posts. > |> > |> I was dead asleep &/or on my 1st or 2nd walk of the day when you > |> posted to me, Angel, but now you know I have answered it. > |> > |> As Candlin & MEB verify, the NG possibly was under maintenance, which > |> does happen now/then. It used to happen more often. You should sleep > |> through it or go for a walk! > |> > |> For the OE icons/buttons, those are adjustable this way... Grab the > |> icon area or the menu area at the far left with the mouse. You will > |> see a two pointed arrow going horizontally through two vertical > |> lines after you start moving the mouse. Move the area up or down, > |> until the buttons show again. > |> > |> For the pop-ups, I think the others in the other thread are making > |> sense. As MEB said, post a HijackThis report, or at least... > |> > |> (1) "START button, Run, MSInfo32, Software Environment, Startup > |> Programs". > |> (2) Use the Edit menu to Select All & Copy. > |> (3) Post it here or there. > |> > |> Hopefully, as Terhune may have said, these pop-ups are an annoyance, > |> but not a real threat. Then, once it is identified, there could even > |> be an entry at... > |> > |> "START, Settings, Control Panel, Add/Remove Programs, > |> Install/Uninstall tab" > |> > |> ... that will remove it. > |> > |> | Let me know if this is > |> | going through. I have another question, The top of my Outlook > |> | express has changed the buttons were along the top, now they are at > |> | the bottom. Are there any settings that need to be readjusted? Or > |> | is it from the troubles with the Pop ups that has caused anything. > |> | The buttons are in a drop down button only marked with a >>. When > |> | I do a post they are across the top as they were. Angel > |> | "MEB" <meb@not here@hotmail.com> wrote in message > |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > |> |> > |> |> "Angel" <angel@noway.com> wrote in message > |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > |> |> | Hi, > |> |> | I have a dilemma. I tried to post 3 times today to the > |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is > |> |> | happening? Angel > |> |> | > |> |> | > |> |> > |> |> Good question, I have now tried six times to post a reply to PCR > |> |> in the firewalls discussion.. > |> |> > |> |> -- > |> |> MEB > |> |> http://peoplescounsel.orgfree.com > |> |> ________ > |> > |> -- > |> Thanks or Good Luck, > |> There may be humor in this post, and, > |> Naturally, you will not sue, > |> Should things get worse after this, > |> PCR > |> pcrrcp@netzero.net > > -- > Thanks or Good Luck, > There may be humor in this post, and, > Naturally, you will not sue, > Should things get worse after this, > PCR > pcrrcp@netzero.net > >
Guest Angel Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. PCR, I did the Avast! through/w archives. The same virus showed up again and I put it in the chest.The name: C:\Program Files\common files\Microsoft shared\Stationary\Tiki Lounge. It then proceeded on to the end and the same archive, C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS malware{HTML} error occurred during moving to the chest. I clicked on to scan it. The window came up that "The operation is not supported for this type of archive. Cannot process " C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find files and folders search for it. It was a Zip file and it showed to have a virus when I scanned it. The same thing happened. I unzipped it and the same thing happened when I found the file which was a gif. The date on it was before this computer was built. 6/23/1999. I think all the files in that folder were that same date. It looks like the CAB 49 is damaged by the virus. Am I right? Now what to do about it? Angel "Angel" <angel@noway.com> wrote in message news:OsVGQPy0HHA.2484@TK2MSFTNGP06.phx.gbl... > Hi PCR, > The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. It is > a multimedia keyboard. > Smart Bridge is my SDL program. > There was only 1 LoadPowerProfile. I checked it out. > I did the Scans again Spybot found 3 drivecleaner.com cookies under > the title of winsoftware. > Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm > C:\Program Files\common files\Microsoft Shared\Stationary\Tiki lounge. I > deleted it. At the end of the scan, I had done a through one. This showed up > in the results of the scan: C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. > Infection:VBS:malware{HTML} Error occurred during moving file to chest. > Before trying to move it I tried to delete it. How do I get rid of this > malware? Now I think I found the culprit. Now lets get it out of my > machine. > Angel > > "PCR" <pcrrcp@netzero.net> wrote in message > news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... > > Angel wrote: > > | PCR, > > | I found the directions so here it is: > > | > > | SystemTray Registry (Machine Run) SysTray.Exe > > | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe /autorun > > > > Those are fine. > > > > | Motive SmartBridge Registry (Machine Run) > > | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe > > > > I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I > > said below. Reboot, & see whether it stops. > > > > | CHotKey Registry (Machine Run) mk9908.exe > > > > I'm not finding anything about pop-ups with mk9908.exe at Google. Yours > > looks odd, though, in that it doesn't mention a folder. What folder is > > mk9908.exe in? Are you sure it starts the way that line is now? > > > > You can get the folder into that line using MSConfig. If it is a LFN > > (Long File Name), you must surround it with quotes, or use the SFN > > instead. > > > > | avast! Web Scanner Registry (Machine Run) > > | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE > > > > OK. > > > > | KB918547 Registry (Machine Service) > > | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE > > > > | KB891711 Registry (Machine > > | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE > > > > | LoadPowerProfile > > | Registry (Machine Service) Rundll32.exe > > | powrprof.dll,LoadCurrentPwrScheme > > > > Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did you > > uncheck one at "START button, Run, MSConfig, Startup tab"? Then, > > re-check it. > > > > | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC > > | PowerChute Personal Edition\mainserv.exe > > > > Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, but I > > chose not to install the software. It works fine that way, but I must > > close down, myself, within 20 minutes. It saved me several times. > > > > I doubt this would include pop-up ads. But, is it the last thing you > > installed before they started? Then, maybe uncheck it at... > > > > "START button, Run, MSConfig, Startup tab" > > > > ..., reboot, & see whether they stop. > > > > | avast! Registry (Machine Service) C:\Program Files\Alwil > > | Software\Avast4\ashServ.exe > > > > OK. > > > > | Angel > > | > > | "PCR" <pcrrcp@netzero.net> wrote in message > > | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > > |> Angel wrote: > > |> | Meb, > > |> | I thought it was me. I maybe should retype what I just typed to > > |> | you. If this goes through I will.I tried to use PCR's email at the > > |> | bottom of his posts. But no answer. I wonder if it is his real > > |> | email. Mine is different than the one in my posts. > > |> > > |> I was dead asleep &/or on my 1st or 2nd walk of the day when you > > |> posted to me, Angel, but now you know I have answered it. > > |> > > |> As Candlin & MEB verify, the NG possibly was under maintenance, which > > |> does happen now/then. It used to happen more often. You should sleep > > |> through it or go for a walk! > > |> > > |> For the OE icons/buttons, those are adjustable this way... Grab the > > |> icon area or the menu area at the far left with the mouse. You will > > |> see a two pointed arrow going horizontally through two vertical > > |> lines after you start moving the mouse. Move the area up or down, > > |> until the buttons show again. > > |> > > |> For the pop-ups, I think the others in the other thread are making > > |> sense. As MEB said, post a HijackThis report, or at least... > > |> > > |> (1) "START button, Run, MSInfo32, Software Environment, Startup > > |> Programs". > > |> (2) Use the Edit menu to Select All & Copy. > > |> (3) Post it here or there. > > |> > > |> Hopefully, as Terhune may have said, these pop-ups are an annoyance, > > |> but not a real threat. Then, once it is identified, there could even > > |> be an entry at... > > |> > > |> "START, Settings, Control Panel, Add/Remove Programs, > > |> Install/Uninstall tab" > > |> > > |> ... that will remove it. > > |> > > |> | Let me know if this is > > |> | going through. I have another question, The top of my Outlook > > |> | express has changed the buttons were along the top, now they are at > > |> | the bottom. Are there any settings that need to be readjusted? Or > > |> | is it from the troubles with the Pop ups that has caused anything. > > |> | The buttons are in a drop down button only marked with a >>. When > > |> | I do a post they are across the top as they were. Angel > > |> | "MEB" <meb@not here@hotmail.com> wrote in message > > |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > > |> |> > > |> |> "Angel" <angel@noway.com> wrote in message > > |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > > |> |> | Hi, > > |> |> | I have a dilemma. I tried to post 3 times today to the > > |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is > > |> |> | happening? Angel > > |> |> | > > |> |> | > > |> |> > > |> |> Good question, I have now tried six times to post a reply to PCR > > |> |> in the firewalls discussion.. > > |> |> > > |> |> -- > > |> |> MEB > > |> |> http://peoplescounsel.orgfree.com > > |> |> ________ > > |> > > |> -- > > |> Thanks or Good Luck, > > |> There may be humor in this post, and, > > |> Naturally, you will not sue, > > |> Should things get worse after this, > > |> PCR > > |> pcrrcp@netzero.net > > > > -- > > Thanks or Good Luck, > > There may be humor in this post, and, > > Naturally, you will not sue, > > Should things get worse after this, > > PCR > > pcrrcp@netzero.net > > > > > >
Guest PCR Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Angel wrote: | PCR, | I did the Avast! through/w archives. The same virus showed up | again and I put it in the chest.The name: C:\Program Files\common | files\Microsoft shared\Stationary\Tiki Lounge. It then proceeded on | to the end and the same archive, | C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS | malware{HTML} error occurred during moving to the chest. I clicked | on to scan it. The window came up that "The operation is not | supported for this type of archive. Cannot process " | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find | files and folders search for it. It was a Zip file and it showed to | have a virus when I scanned it. The same thing happened. I unzipped | it and the same thing happened when I found the file which was a gif. | The date on it was before this computer was built. 6/23/1999. I think | all the files in that folder were that same date. It looks like the | CAB 49 is damaged by the virus. Am I right? Now what to do about | it? Angel Uhuh! I got the SAME avast! alert, myself, today about "Tiki Lounge.htm", which is a 1999 file. I'm hoping it is a false alarm, like the one I had before! I also did a Thorough Scan & included archives. But my .cabs are on another partition. I went looking & did find... Cabinet WIN98_49.CAB 04-23-1999 10:22:00p A--- 393 tiki.htm .... and was puzzled NOT to find "Tiki Lounge.htm". But let me scan that cab now... YEP! Just as you say... avast! finds the same "Virus/Worm" in tiki.htm! It looks to me that these are the same file, but with a different name... TIKILO~1 HTM 393 04-23-99 10:22p Tiki Lounge.htm Let me send that one to... http://www.virustotal.com/xhtml/index_en.html It will be scanned by 30 virus detectors! I'll report back! By the way, did avast! announce to you that a new version is available? I didn't click to take it, but will go to investigate that too. | "Angel" <angel@noway.com> wrote in message | news:OsVGQPy0HHA.2484@TK2MSFTNGP06.phx.gbl... |> Hi PCR, |> The mk9908.exe is the drive for my Keyboard. It is in |> C:\Windows. It is a multimedia keyboard. |> Smart Bridge is my SDL program. |> There was only 1 LoadPowerProfile. I checked it out. |> I did the Scans again Spybot found 3 drivecleaner.com cookies |> under the title of winsoftware. |> Avast! found a virus. Malware type VBS: Malware{HTML} Virus |> worm C:\Program Files\common files\Microsoft Shared\Stationary\Tiki |> lounge. I deleted it. At the end of the scan, I had done a through |> one. This showed up in the results of the scan: |> C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. |> Infection:VBS:malware{HTML} Error occurred during moving file to |> chest. Before trying to move it I tried to delete it. How do I get |> rid of this malware? Now I think I found the culprit. Now lets get |> it out of my machine. Angel |> |> "PCR" <pcrrcp@netzero.net> wrote in message |> news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... |> > Angel wrote: |> > | PCR, |> > | I found the directions so here it is: |> > | |> > | SystemTray Registry (Machine Run) SysTray.Exe |> > | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe |> > | /autorun |> > |> > Those are fine. |> > |> > | Motive SmartBridge Registry (Machine Run) |> > | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe |> > |> > I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig |> > as I said below. Reboot, & see whether it stops. |> > |> > | CHotKey Registry (Machine Run) mk9908.exe |> > |> > I'm not finding anything about pop-ups with mk9908.exe at Google. |> > Yours looks odd, though, in that it doesn't mention a folder. What |> > folder is mk9908.exe in? Are you sure it starts the way that line |> > is now? |> > |> > You can get the folder into that line using MSConfig. If it is a |> > LFN (Long File Name), you must surround it with quotes, or use the |> > SFN instead. |> > |> > | avast! Web Scanner Registry (Machine Run) |> > | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE |> > |> > OK. |> > |> > | KB918547 Registry (Machine Service) |> > | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE |> > |> > | KB891711 Registry (Machine |> > | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE |> > |> > | LoadPowerProfile |> > | Registry (Machine Service) Rundll32.exe |> > | powrprof.dll,LoadCurrentPwrScheme |> > |> > Those 3 are fine. You should have 2 of LoadPowerProfile, though. |> > Did you uncheck one at "START button, Run, MSConfig, Startup tab"? |> > Then, re-check it. |> > |> > | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC |> > | PowerChute Personal Edition\mainserv.exe |> > |> > Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, |> > but I chose not to install the software. It works fine that way, |> > but I must close down, myself, within 20 minutes. It saved me |> > several times. |> > |> > I doubt this would include pop-up ads. But, is it the last thing |> > you installed before they started? Then, maybe uncheck it at... |> > |> > "START button, Run, MSConfig, Startup tab" |> > |> > ..., reboot, & see whether they stop. |> > |> > | avast! Registry (Machine Service) C:\Program Files\Alwil |> > | Software\Avast4\ashServ.exe |> > |> > OK. |> > |> > | Angel |> > | |> > | "PCR" <pcrrcp@netzero.net> wrote in message |> > | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... |> > |> Angel wrote: |> > |> | Meb, |> > |> | I thought it was me. I maybe should retype what I just |> > |> | typed to you. If this goes through I will.I tried to use |> > |> | PCR's email at the bottom of his posts. But no answer. I |> > |> | wonder if it is his real email. Mine is different than the |> > |> | one in my posts. |> > |> |> > |> I was dead asleep &/or on my 1st or 2nd walk of the day when you |> > |> posted to me, Angel, but now you know I have answered it. |> > |> |> > |> As Candlin & MEB verify, the NG possibly was under maintenance, |> > |> which does happen now/then. It used to happen more often. You |> > |> should sleep through it or go for a walk! |> > |> |> > |> For the OE icons/buttons, those are adjustable this way... Grab |> > |> the icon area or the menu area at the far left with the mouse. |> > |> You will see a two pointed arrow going horizontally through two |> > |> vertical lines after you start moving the mouse. Move the area |> > |> up or down, until the buttons show again. |> > |> |> > |> For the pop-ups, I think the others in the other thread are |> > |> making sense. As MEB said, post a HijackThis report, or at |> > |> least... |> > |> |> > |> (1) "START button, Run, MSInfo32, Software Environment, Startup |> > |> Programs". |> > |> (2) Use the Edit menu to Select All & Copy. |> > |> (3) Post it here or there. |> > |> |> > |> Hopefully, as Terhune may have said, these pop-ups are an |> > |> annoyance, but not a real threat. Then, once it is identified, |> > |> there could even be an entry at... |> > |> |> > |> "START, Settings, Control Panel, Add/Remove Programs, |> > |> Install/Uninstall tab" |> > |> |> > |> ... that will remove it. |> > |> |> > |> | Let me know if this is |> > |> | going through. I have another question, The top of my |> > |> | Outlook express has changed the buttons were along the top, |> > |> | now they are at the bottom. Are there any settings that need |> > |> | to be readjusted? Or is it from the troubles with the Pop ups |> > |> | that has caused anything. The buttons are in a drop down |> > |> | button only marked with a >>. When I do a post they are |> > |> | across the top as they were. Angel "MEB" <meb@not |> > |> | here@hotmail.com> wrote in message |> > |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> > |> |> |> > |> |> "Angel" <angel@noway.com> wrote in message |> > |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> > |> |> | Hi, |> > |> |> | I have a dilemma. I tried to post 3 times today to |> > |> |> | the string, "Error Alert?" NO SUCCESS So trying again!! |> > |> |> | What is happening? Angel |> > |> |> | |> > |> |> | |> > |> |> |> > |> |> Good question, I have now tried six times to post a reply |> > |> |> to PCR in the firewalls discussion.. |> > |> |> |> > |> |> -- |> > |> |> MEB |> > |> |> http://peoplescounsel.orgfree.com |> > |> |> ________ |> > |> |> > |> -- |> > |> Thanks or Good Luck, |> > |> There may be humor in this post, and, |> > |> Naturally, you will not sue, |> > |> Should things get worse after this, |> > |> PCR |> > |> pcrrcp@netzero.net |> > |> > -- |> > Thanks or Good Luck, |> > There may be humor in this post, and, |> > Naturally, you will not sue, |> > Should things get worse after this, |> > PCR |> > pcrrcp@netzero.net -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest Angel Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Thanks PCR, I use the software from APC because sometimes we have power outages if only for a moment. With the software it will automatically shut down the computer if needed with no loss of files and you do not get the Blue screen that says that you have not shut down properly. I forgot to mention that in the previous email reply to the files in the Misinfo file. Angel "PCR" <pcrrcp@netzero.net> wrote in message news:%23o2S5h70HHA.728@TK2MSFTNGP05.phx.gbl... > Angel wrote: > | PCR, > | I did the Avast! through/w archives. The same virus showed up > | again and I put it in the chest.The name: C:\Program Files\common > | files\Microsoft shared\Stationary\Tiki Lounge. It then proceeded on > | to the end and the same archive, > | C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS > | malware{HTML} error occurred during moving to the chest. I clicked > | on to scan it. The window came up that "The operation is not > | supported for this type of archive. Cannot process " > | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find > | files and folders search for it. It was a Zip file and it showed to > | have a virus when I scanned it. The same thing happened. I unzipped > | it and the same thing happened when I found the file which was a gif. > | The date on it was before this computer was built. 6/23/1999. I think > | all the files in that folder were that same date. It looks like the > | CAB 49 is damaged by the virus. Am I right? Now what to do about > | it? Angel > > Uhuh! I got the SAME avast! alert, myself, today about "Tiki > Lounge.htm", which is a 1999 file. I'm hoping it is a false alarm, like > the one I had before! I also did a Thorough Scan & included archives. > But my .cabs are on another partition. I went looking & did find... > > Cabinet WIN98_49.CAB > 04-23-1999 10:22:00p A--- 393 tiki.htm > > ... and was puzzled NOT to find "Tiki Lounge.htm". But let me scan that > cab now... YEP! Just as you say... avast! finds the same "Virus/Worm" in > tiki.htm! It looks to me that these are the same file, but with a > different name... > > TIKILO~1 HTM 393 04-23-99 10:22p Tiki Lounge.htm > > Let me send that one to... > http://www.virustotal.com/xhtml/index_en.html > > It will be scanned by 30 virus detectors! I'll report back! > > By the way, did avast! announce to you that a new version is available? > I didn't click to take it, but will go to investigate that too. > > | "Angel" <angel@noway.com> wrote in message > | news:OsVGQPy0HHA.2484@TK2MSFTNGP06.phx.gbl... > |> Hi PCR, > |> The mk9908.exe is the drive for my Keyboard. It is in > |> C:\Windows. It is a multimedia keyboard. > |> Smart Bridge is my SDL program. > |> There was only 1 LoadPowerProfile. I checked it out. > |> I did the Scans again Spybot found 3 drivecleaner.com cookies > |> under the title of winsoftware. > |> Avast! found a virus. Malware type VBS: Malware{HTML} Virus > |> worm C:\Program Files\common files\Microsoft Shared\Stationary\Tiki > |> lounge. I deleted it. At the end of the scan, I had done a through > |> one. This showed up in the results of the scan: > |> C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. > |> Infection:VBS:malware{HTML} Error occurred during moving file to > |> chest. Before trying to move it I tried to delete it. How do I get > |> rid of this malware? Now I think I found the culprit. Now lets get > |> it out of my machine. Angel > |> > |> "PCR" <pcrrcp@netzero.net> wrote in message > |> news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... > |> > Angel wrote: > |> > | PCR, > |> > | I found the directions so here it is: > |> > | > |> > | SystemTray Registry (Machine Run) SysTray.Exe > |> > | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe > |> > | /autorun > |> > > |> > Those are fine. > |> > > |> > | Motive SmartBridge Registry (Machine Run) > |> > | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe > |> > > |> > I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig > |> > as I said below. Reboot, & see whether it stops. > |> > > |> > | CHotKey Registry (Machine Run) mk9908.exe > |> > > |> > I'm not finding anything about pop-ups with mk9908.exe at Google. > |> > Yours looks odd, though, in that it doesn't mention a folder. What > |> > folder is mk9908.exe in? Are you sure it starts the way that line > |> > is now? > |> > > |> > You can get the folder into that line using MSConfig. If it is a > |> > LFN (Long File Name), you must surround it with quotes, or use the > |> > SFN instead. > |> > > |> > | avast! Web Scanner Registry (Machine Run) > |> > | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE > |> > > |> > OK. > |> > > |> > | KB918547 Registry (Machine Service) > |> > | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE > |> > > |> > | KB891711 Registry (Machine > |> > | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE > |> > > |> > | LoadPowerProfile > |> > | Registry (Machine Service) Rundll32.exe > |> > | powrprof.dll,LoadCurrentPwrScheme > |> > > |> > Those 3 are fine. You should have 2 of LoadPowerProfile, though. > |> > Did you uncheck one at "START button, Run, MSConfig, Startup tab"? > |> > Then, re-check it. > |> > > |> > | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC > |> > | PowerChute Personal Edition\mainserv.exe > |> > > |> > Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, > |> > but I chose not to install the software. It works fine that way, > |> > but I must close down, myself, within 20 minutes. It saved me > |> > several times. > |> > > |> > I doubt this would include pop-up ads. But, is it the last thing > |> > you installed before they started? Then, maybe uncheck it at... > |> > > |> > "START button, Run, MSConfig, Startup tab" > |> > > |> > ..., reboot, & see whether they stop. > |> > > |> > | avast! Registry (Machine Service) C:\Program Files\Alwil > |> > | Software\Avast4\ashServ.exe > |> > > |> > OK. > |> > > |> > | Angel > |> > | > |> > | "PCR" <pcrrcp@netzero.net> wrote in message > |> > | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > |> > |> Angel wrote: > |> > |> | Meb, > |> > |> | I thought it was me. I maybe should retype what I just > |> > |> | typed to you. If this goes through I will.I tried to use > |> > |> | PCR's email at the bottom of his posts. But no answer. I > |> > |> | wonder if it is his real email. Mine is different than the > |> > |> | one in my posts. > |> > |> > |> > |> I was dead asleep &/or on my 1st or 2nd walk of the day when you > |> > |> posted to me, Angel, but now you know I have answered it. > |> > |> > |> > |> As Candlin & MEB verify, the NG possibly was under maintenance, > |> > |> which does happen now/then. It used to happen more often. You > |> > |> should sleep through it or go for a walk! > |> > |> > |> > |> For the OE icons/buttons, those are adjustable this way... Grab > |> > |> the icon area or the menu area at the far left with the mouse. > |> > |> You will see a two pointed arrow going horizontally through two > |> > |> vertical lines after you start moving the mouse. Move the area > |> > |> up or down, until the buttons show again. > |> > |> > |> > |> For the pop-ups, I think the others in the other thread are > |> > |> making sense. As MEB said, post a HijackThis report, or at > |> > |> least... > |> > |> > |> > |> (1) "START button, Run, MSInfo32, Software Environment, Startup > |> > |> Programs". > |> > |> (2) Use the Edit menu to Select All & Copy. > |> > |> (3) Post it here or there. > |> > |> > |> > |> Hopefully, as Terhune may have said, these pop-ups are an > |> > |> annoyance, but not a real threat. Then, once it is identified, > |> > |> there could even be an entry at... > |> > |> > |> > |> "START, Settings, Control Panel, Add/Remove Programs, > |> > |> Install/Uninstall tab" > |> > |> > |> > |> ... that will remove it. > |> > |> > |> > |> | Let me know if this is > |> > |> | going through. I have another question, The top of my > |> > |> | Outlook express has changed the buttons were along the top, > |> > |> | now they are at the bottom. Are there any settings that need > |> > |> | to be readjusted? Or is it from the troubles with the Pop ups > |> > |> | that has caused anything. The buttons are in a drop down > |> > |> | button only marked with a >>. When I do a post they are > |> > |> | across the top as they were. Angel "MEB" <meb@not > |> > |> | here@hotmail.com> wrote in message > |> > |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > |> > |> |> > |> > |> |> "Angel" <angel@noway.com> wrote in message > |> > |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > |> > |> |> | Hi, > |> > |> |> | I have a dilemma. I tried to post 3 times today to > |> > |> |> | the string, "Error Alert?" NO SUCCESS So trying again!! > |> > |> |> | What is happening? Angel > |> > |> |> | > |> > |> |> | > |> > |> |> > |> > |> |> Good question, I have now tried six times to post a reply > |> > |> |> to PCR in the firewalls discussion.. > |> > |> |> > |> > |> |> -- > |> > |> |> MEB > |> > |> |> http://peoplescounsel.orgfree.com > |> > |> |> ________ > |> > |> > |> > |> -- > |> > |> Thanks or Good Luck, > |> > |> There may be humor in this post, and, > |> > |> Naturally, you will not sue, > |> > |> Should things get worse after this, > |> > |> PCR > |> > |> pcrrcp@netzero.net > |> > > |> > -- > |> > Thanks or Good Luck, > |> > There may be humor in this post, and, > |> > Naturally, you will not sue, > |> > Should things get worse after this, > |> > PCR > |> > pcrrcp@netzero.net > > -- > Thanks or Good Luck, > There may be humor in this post, and, > Naturally, you will not sue, > Should things get worse after this, > PCR > pcrrcp@netzero.net > >
Guest PCR Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. PCR wrote: | Angel wrote: || PCR, || I did the Avast! through/w archives. The same virus showed up || again and I put it in the chest.The name: C:\Program Files\common || files\Microsoft shared\Stationary\Tiki Lounge. It then proceeded on || to the end and the same archive, || C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS || malware{HTML} error occurred during moving to the chest. I clicked || on to scan it. The window came up that "The operation is not || supported for this type of archive. Cannot process " || C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find || files and folders search for it. It was a Zip file and it showed to || have a virus when I scanned it. The same thing happened. I unzipped || it and the same thing happened when I found the file which was a gif. || The date on it was before this computer was built. 6/23/1999. I think || all the files in that folder were that same date. It looks like the || CAB 49 is damaged by the virus. Am I right? Now what to do about || it? Angel | | Uhuh! I got the SAME avast! alert, myself, today about "Tiki | Lounge.htm", which is a 1999 file. I'm hoping it is a false alarm, | like the one I had before! I also did a Thorough Scan & included | archives. But my .cabs are on another partition. I went looking & did | find... | | Cabinet WIN98_49.CAB | 04-23-1999 10:22:00p A--- 393 tiki.htm | | ... and was puzzled NOT to find "Tiki Lounge.htm". But let me scan | that cab now... YEP! Just as you say... avast! finds the same | "Virus/Worm" in tiki.htm! It looks to me that these are the same | file, but with a different name... | | TIKILO~1 HTM 393 04-23-99 10:22p Tiki Lounge.htm | | Let me send that one to... | http://www.virustotal.com/xhtml/index_en.html | | It will be scanned by 30 virus detectors! I'll report back! | | By the way, did avast! announce to you that a new version is | available? I didn't click to take it, but will go to investigate that | too. Here is the result... Complete scanning result of "Tiki Lounge.htm", processed in VirusTotal at 07/31/2007 23:55:33 (CET). [ file data ] * name: Tiki Lounge.htm * size: 370 * md5.: c5f4869d1805078ae115a7c5464b605f * sha1: b3990474983e89fa1af5d46cace22cc1a4494d39 [ scan result ] AhnLab-V3 2007.7.31.1/20070731 found nothing AntiVir 7.4.0.54/20070731 found nothing Authentium 4.93.8/20070731 found nothing Avast 4.7.1029.0/20070731 found nothing <<Interesting! .... My version is 4.7.1001 May 2007 .... Can that be the new one avast! is offering? .... Hmmm! EVEN my version doesn't find the virus anymore, .... with just new definitions...!... .........Quote Summary.txt......... Vps: Updated (previous version: 000762-4, updated version: 000762-5) .........EOQ................................ I guess we are clear, Angel-- put the file back where it came from! AVG 7.5.0.476/20070731 found nothing BitDefender 7.2/20070731 found nothing CAT-QuickHeal 9.00/20070731 found nothing ClamAV 0.91/20070731 found nothing DrWeb 4.33/20070731 found nothing eSafe 7.0.15.0/20070731 found nothing eTrust-Vet 31.1.5019/20070731 found nothing Ewido 4.0/20070731 found nothing F-Prot 4.3.2.48/20070731 found nothing F-Secure 6.70.13030.0/20070731 found nothing FileAdvisor 1/20070731 found nothing Fortinet 2.91.0.0/20070731 found nothing Ikarus T3.1.1.8/20070731 found nothing Kaspersky 4.0.2.24/20070731 found nothing McAfee 5087/20070731 found nothing Microsoft 1.2704/20070731 found nothing NOD32v2 2430/20070731 found nothing Norman 5.80.02/20070731 found nothing Panda 9.0.0.4/20070731 found nothing Prevx1 V2/20070731 found nothing Rising 19.34.12.00/20070731 found nothing Sophos 4.19.0/20070726 found nothing Sunbelt 2.2.907.0/20070731 found nothing Symantec 10/20070731 found nothing TheHacker 6.1.7.159/20070731 found nothing VBA32 3.12.2.2/20070731 found nothing VirusBuster 4.3.26:9/20070731 found nothing Webwasher-Gateway 6.0.1/20070731 found nothing __________________________________________________ VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Do not reply to this message. It has been generated by an automatic address that will not handle any reply. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
Guest PCR Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Angel wrote: | Thanks PCR, | I use the software from APC because sometimes we have power | outages if only for a moment. With the software it will automatically | shut down the computer if needed with no loss of files and you do not | get the Blue screen that says that you have not shut down properly. I | forgot to mention that in the previous email reply to the files in That's worthwhile, if you are not at the computer when the outage hits. Otherwise, even without the software installed, the UPS works, & you get 20 minutes to close up yourself. You do have to have the monitor plugged into one of the uninterruptible sockets, of course, to see what you're doing. Mine has 3 of those & another 3 that are surge protected only. | the Misinfo file. Angel | | "PCR" <pcrrcp@netzero.net> wrote in message | news:%23o2S5h70HHA.728@TK2MSFTNGP05.phx.gbl... |> Angel wrote: |> | PCR, |> | I did the Avast! through/w archives. The same virus showed up |> | again and I put it in the chest.The name: C:\Program Files\common |> | files\Microsoft shared\Stationary\Tiki Lounge. It then proceeded on |> | to the end and the same archive, |> | C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS |> | malware{HTML} error occurred during moving to the chest. I clicked |> | on to scan it. The window came up that "The operation is not |> | supported for this type of archive. Cannot process " |> | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find |> | files and folders search for it. It was a Zip file and it showed to |> | have a virus when I scanned it. The same thing happened. I unzipped |> | it and the same thing happened when I found the file which was a |> | gif. The date on it was before this computer was built. 6/23/1999. |> | I think all the files in that folder were that same date. It looks |> | like the CAB 49 is damaged by the virus. Am I right? Now what |> | to do about |> | it? Angel |> |> Uhuh! I got the SAME avast! alert, myself, today about "Tiki |> Lounge.htm", which is a 1999 file. I'm hoping it is a false alarm, |> like the one I had before! I also did a Thorough Scan & included |> archives. But my .cabs are on another partition. I went looking & |> did find... |> |> Cabinet WIN98_49.CAB |> 04-23-1999 10:22:00p A--- 393 tiki.htm |> |> ... and was puzzled NOT to find "Tiki Lounge.htm". But let me scan |> that cab now... YEP! Just as you say... avast! finds the same |> "Virus/Worm" in tiki.htm! It looks to me that these are the same |> file, but with a different name... |> |> TIKILO~1 HTM 393 04-23-99 10:22p Tiki Lounge.htm |> |> Let me send that one to... |> http://www.virustotal.com/xhtml/index_en.html |> |> It will be scanned by 30 virus detectors! I'll report back! |> |> By the way, did avast! announce to you that a new version is |> available? I didn't click to take it, but will go to investigate |> that too. |> |> | "Angel" <angel@noway.com> wrote in message |> | news:OsVGQPy0HHA.2484@TK2MSFTNGP06.phx.gbl... |> |> Hi PCR, |> |> The mk9908.exe is the drive for my Keyboard. It is in |> |> C:\Windows. It is a multimedia keyboard. |> |> Smart Bridge is my SDL program. |> |> There was only 1 LoadPowerProfile. I checked it out. |> |> I did the Scans again Spybot found 3 drivecleaner.com |> |> cookies under the title of winsoftware. |> |> Avast! found a virus. Malware type VBS: Malware{HTML} Virus |> |> worm C:\Program Files\common files\Microsoft |> |> Shared\Stationary\Tiki lounge. I deleted it. At the end of the |> |> scan, I had done a through one. This showed up in the results of |> |> the scan: C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. |> |> Infection:VBS:malware{HTML} Error occurred during moving file to |> |> chest. Before trying to move it I tried to delete it. How do I get |> |> rid of this malware? Now I think I found the culprit. Now lets |> |> get it out of my machine. Angel |> |> |> |> "PCR" <pcrrcp@netzero.net> wrote in message |> |> news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> > Angel wrote: |> |> > | PCR, |> |> > | I found the directions so here it is: |> |> > | |> |> > | SystemTray Registry (Machine Run) SysTray.Exe |> |> > | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe |> |> > | /autorun |> |> > |> |> > Those are fine. |> |> > |> |> > | Motive SmartBridge Registry (Machine Run) |> |> > | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe |> |> > |> |> > I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig |> |> > as I said below. Reboot, & see whether it stops. |> |> > |> |> > | CHotKey Registry (Machine Run) mk9908.exe |> |> > |> |> > I'm not finding anything about pop-ups with mk9908.exe at |> |> > Google. Yours looks odd, though, in that it doesn't mention a |> |> > folder. What folder is mk9908.exe in? Are you sure it starts |> |> > the way that line is now? |> |> > |> |> > You can get the folder into that line using MSConfig. If it is a |> |> > LFN (Long File Name), you must surround it with quotes, or use |> |> > the SFN instead. |> |> > |> |> > | avast! Web Scanner Registry (Machine Run) |> |> > | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE |> |> > |> |> > OK. |> |> > |> |> > | KB918547 Registry (Machine Service) |> |> > | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE |> |> > |> |> > | KB891711 Registry (Machine |> |> > | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE |> |> > |> |> > | LoadPowerProfile |> |> > | Registry (Machine Service) Rundll32.exe |> |> > | powrprof.dll,LoadCurrentPwrScheme |> |> > |> |> > Those 3 are fine. You should have 2 of LoadPowerProfile, though. |> |> > Did you uncheck one at "START button, Run, MSConfig, Startup |> |> > tab"? Then, re-check it. |> |> > |> |> > | APC_SERVICE Registry (Machine Service) C:\Program |> |> > | Files\APC\APC PowerChute Personal Edition\mainserv.exe |> |> > |> |> > Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged |> |> > in, but I chose not to install the software. It works fine that |> |> > way, but I must close down, myself, within 20 minutes. It saved |> |> > me several times. |> |> > |> |> > I doubt this would include pop-up ads. But, is it the last thing |> |> > you installed before they started? Then, maybe uncheck it at... |> |> > |> |> > "START button, Run, MSConfig, Startup tab" |> |> > |> |> > ..., reboot, & see whether they stop. |> |> > |> |> > | avast! Registry (Machine Service) C:\Program Files\Alwil |> |> > | Software\Avast4\ashServ.exe |> |> > |> |> > OK. |> |> > |> |> > | Angel |> |> > | |> |> > | "PCR" <pcrrcp@netzero.net> wrote in message |> |> > | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... |> |> > |> Angel wrote: |> |> > |> | Meb, |> |> > |> | I thought it was me. I maybe should retype what I just |> |> > |> | typed to you. If this goes through I will.I tried to use |> |> > |> | PCR's email at the bottom of his posts. But no answer. I |> |> > |> | wonder if it is his real email. Mine is different than the |> |> > |> | one in my posts. |> |> > |> |> |> > |> I was dead asleep &/or on my 1st or 2nd walk of the day when |> |> > |> you posted to me, Angel, but now you know I have answered it. |> |> > |> |> |> > |> As Candlin & MEB verify, the NG possibly was under |> |> > |> maintenance, which does happen now/then. It used to happen |> |> > |> more often. You should sleep through it or go for a walk! |> |> > |> |> |> > |> For the OE icons/buttons, those are adjustable this way... |> |> > |> Grab the icon area or the menu area at the far left with the |> |> > |> mouse. You will see a two pointed arrow going horizontally |> |> > |> through two vertical lines after you start moving the mouse. |> |> > |> Move the area up or down, until the buttons show again. |> |> > |> |> |> > |> For the pop-ups, I think the others in the other thread are |> |> > |> making sense. As MEB said, post a HijackThis report, or at |> |> > |> least... |> |> > |> |> |> > |> (1) "START button, Run, MSInfo32, Software Environment, |> |> > |> Startup Programs". |> |> > |> (2) Use the Edit menu to Select All & Copy. |> |> > |> (3) Post it here or there. |> |> > |> |> |> > |> Hopefully, as Terhune may have said, these pop-ups are an |> |> > |> annoyance, but not a real threat. Then, once it is |> |> > |> identified, there could even be an entry at... |> |> > |> |> |> > |> "START, Settings, Control Panel, Add/Remove Programs, |> |> > |> Install/Uninstall tab" |> |> > |> |> |> > |> ... that will remove it. |> |> > |> |> |> > |> | Let me know if this is |> |> > |> | going through. I have another question, The top of my |> |> > |> | Outlook express has changed the buttons were along the top, |> |> > |> | now they are at the bottom. Are there any settings that |> |> > |> | need to be readjusted? Or is it from the troubles with the |> |> > |> | Pop ups that has caused anything. The buttons are in a |> |> > |> | drop down button only marked with a >>. When I do a |> |> > |> | post they are across the top as they were. Angel "MEB" |> |> > |> | <meb@not here@hotmail.com> wrote in message |> |> > |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> |> > |> |> |> |> > |> |> "Angel" <angel@noway.com> wrote in message |> |> > |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> > |> |> | Hi, |> |> > |> |> | I have a dilemma. I tried to post 3 times today to |> |> > |> |> | the string, "Error Alert?" NO SUCCESS So trying again!! |> |> > |> |> | What is happening? Angel |> |> > |> |> | |> |> > |> |> | |> |> > |> |> |> |> > |> |> Good question, I have now tried six times to post a reply |> |> > |> |> to PCR in the firewalls discussion.. |> |> > |> |> |> |> > |> |> -- |> |> > |> |> MEB |> |> > |> |> http://peoplescounsel.orgfree.com |> |> > |> |> ________ |> |> > |> |> |> > |> -- |> |> > |> Thanks or Good Luck, |> |> > |> There may be humor in this post, and, |> |> > |> Naturally, you will not sue, |> |> > |> Should things get worse after this, |> |> > |> PCR |> |> > |> pcrrcp@netzero.net |> |> > |> |> > -- |> |> > Thanks or Good Luck, |> |> > There may be humor in this post, and, |> |> > Naturally, you will not sue, |> |> > Should things get worse after this, |> |> > PCR |> |> > pcrrcp@netzero.net |> |> -- |> Thanks or Good Luck, |> There may be humor in this post, and, |> Naturally, you will not sue, |> Should things get worse after this, |> PCR |> pcrrcp@netzero.net -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest PCR Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Angel wrote: | Hi PCR, | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. | It is a multimedia keyboard. | Smart Bridge is my SDL program. Alright. It shouldn't hurt to uncheck them just to test it. Some programs will include innocent pop-up ads. But probably it is something else. Post back to that other thread, then. There are good people in it! | There was only 1 LoadPowerProfile. I checked it out. You should have this one, too... LoadPowerProfile Registry (Machine Run) Rundll32.exe powrprof.dll,LoadCurrentPwrScheme To get it, use Notepad to make a file named "LPP.reg" from the following... .......Start after this dotted line......... REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [END] .......End before this dotted line......... NOTE: You should get 5 lines. If more, there has been word-wrap. Don't run it, then. Post back, & I'll try something else. Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig to confirm it is there. If so, you may delete "LPP.reg". | I did the Scans again Spybot found 3 drivecleaner.com cookies | under the title of winsoftware. Those couldn't be the problem, if it still exists. Didn't hurt to get rid of the Cookies, though. | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki | lounge. I deleted it. At the end of the scan, I had done a through | one. This showed up in the results of the scan: | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. | Infection:VBS:malware{HTML} Error occurred during moving file to | chest. Before trying to move it I tried to delete it. How do I get | rid of this malware? Now I think I found the culprit. Now lets get | it out of my machine. Angel That was a false alarm, as I posted separately. And with new defs, it goes away. Can you undo what avast! did to the file(s)? | "PCR" <pcrrcp@netzero.net> wrote in message | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... |> Angel wrote: |> | PCR, |> | I found the directions so here it is: |> | |> | SystemTray Registry (Machine Run) SysTray.Exe |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe |> | /autorun |> |> Those are fine. |> |> | Motive SmartBridge Registry (Machine Run) |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe |> |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I |> said below. Reboot, & see whether it stops. |> |> | CHotKey Registry (Machine Run) mk9908.exe |> |> I'm not finding anything about pop-ups with mk9908.exe at Google. |> Yours looks odd, though, in that it doesn't mention a folder. What |> folder is mk9908.exe in? Are you sure it starts the way that line is |> now? |> |> You can get the folder into that line using MSConfig. If it is a LFN |> (Long File Name), you must surround it with quotes, or use the SFN |> instead. |> |> | avast! Web Scanner Registry (Machine Run) |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE |> |> OK. |> |> | KB918547 Registry (Machine Service) |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE |> |> | KB891711 Registry (Machine |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE |> |> | LoadPowerProfile |> | Registry (Machine Service) Rundll32.exe |> | powrprof.dll,LoadCurrentPwrScheme |> |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then, |> re-check it. |> |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC |> | PowerChute Personal Edition\mainserv.exe |> |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, |> but I chose not to install the software. It works fine that way, but |> I must close down, myself, within 20 minutes. It saved me several |> times. |> |> I doubt this would include pop-up ads. But, is it the last thing you |> installed before they started? Then, maybe uncheck it at... |> |> "START button, Run, MSConfig, Startup tab" |> |> ..., reboot, & see whether they stop. |> |> | avast! Registry (Machine Service) C:\Program Files\Alwil |> | Software\Avast4\ashServ.exe |> |> OK. |> |> | Angel |> | |> | "PCR" <pcrrcp@netzero.net> wrote in message |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... |> |> Angel wrote: |> |> | Meb, |> |> | I thought it was me. I maybe should retype what I just |> |> | typed to you. If this goes through I will.I tried to use PCR's |> |> | email at the bottom of his posts. But no answer. I wonder if it |> |> | is his real email. Mine is different than the one in my posts. |> |> |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you |> |> posted to me, Angel, but now you know I have answered it. |> |> |> |> As Candlin & MEB verify, the NG possibly was under maintenance, |> |> which does happen now/then. It used to happen more often. You |> |> should sleep through it or go for a walk! |> |> |> |> For the OE icons/buttons, those are adjustable this way... Grab |> |> the icon area or the menu area at the far left with the mouse. |> |> You will see a two pointed arrow going horizontally through two |> |> vertical lines after you start moving the mouse. Move the area up |> |> or down, until the buttons show again. |> |> |> |> For the pop-ups, I think the others in the other thread are making |> |> sense. As MEB said, post a HijackThis report, or at least... |> |> |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup |> |> Programs". |> |> (2) Use the Edit menu to Select All & Copy. |> |> (3) Post it here or there. |> |> |> |> Hopefully, as Terhune may have said, these pop-ups are an |> |> annoyance, but not a real threat. Then, once it is identified, |> |> there could even be an entry at... |> |> |> |> "START, Settings, Control Panel, Add/Remove Programs, |> |> Install/Uninstall tab" |> |> |> |> ... that will remove it. |> |> |> |> | Let me know if this is |> |> | going through. I have another question, The top of my Outlook |> |> | express has changed the buttons were along the top, now they |> |> | are at the bottom. Are there any settings that need to be |> |> | readjusted? Or is it from the troubles with the Pop ups that |> |> | has caused anything. The buttons are in a drop down button only |> |> | marked with a >>. When I do a post they are across the top |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> |> |> |> |> |> "Angel" <angel@noway.com> wrote in message |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> |> | Hi, |> |> |> | I have a dilemma. I tried to post 3 times today to the |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is |> |> |> | happening? Angel |> |> |> | |> |> |> | |> |> |> |> |> |> Good question, I have now tried six times to post a reply to |> |> |> PCR in the firewalls discussion.. |> |> |> |> |> |> -- |> |> |> MEB |> |> |> http://peoplescounsel.orgfree.com |> |> |> ________ |> |> |> |> -- |> |> Thanks or Good Luck, |> |> There may be humor in this post, and, |> |> Naturally, you will not sue, |> |> Should things get worse after this, |> |> PCR |> |> pcrrcp@netzero.net |> |> -- |> Thanks or Good Luck, |> There may be humor in this post, and, |> Naturally, you will not sue, |> Should things get worse after this, |> PCR |> pcrrcp@netzero.net -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest Angel Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Hi PCR, I have it set for automatic updates. After I got the 2nd update yesterday, the virus was found when I did the through scan w/archives. Since I had been getting those messages and smut page showing up I have been doing this. It takes longer to do the scan, a lot longer!! The difference is only that yours is in DOS format. It seems to be the same file. The dates are different about a month. I bought my computer June 1, 2000 and it was on it when I got it. Angel "PCR" <pcrrcp@netzero.net> wrote in message news:eyHvRB80HHA.536@TK2MSFTNGP06.phx.gbl... PCR wrote: | Angel wrote: || PCR, || I did the Avast! through/w archives. The same virus showed up || again and I put it in the chest.The name: C:\Program Files\common || files\Microsoft shared\Stationary\Tiki Lounge. It then proceeded on || to the end and the same archive, || C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS || malware{HTML} error occurred during moving to the chest. I clicked || on to scan it. The window came up that "The operation is not || supported for this type of archive. Cannot process " || C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find || files and folders search for it. It was a Zip file and it showed to || have a virus when I scanned it. The same thing happened. I unzipped || it and the same thing happened when I found the file which was a gif. || The date on it was before this computer was built. 6/23/1999. I think || all the files in that folder were that same date. It looks like the || CAB 49 is damaged by the virus. Am I right? Now what to do about || it? Angel | | Uhuh! I got the SAME avast! alert, myself, today about "Tiki | Lounge.htm", which is a 1999 file. I'm hoping it is a false alarm, | like the one I had before! I also did a Thorough Scan & included | archives. But my .cabs are on another partition. I went looking & did | find... | | Cabinet WIN98_49.CAB | 04-23-1999 10:22:00p A--- 393 tiki.htm | | ... and was puzzled NOT to find "Tiki Lounge.htm". But let me scan | that cab now... YEP! Just as you say... avast! finds the same | "Virus/Worm" in tiki.htm! It looks to me that these are the same | file, but with a different name... | | TIKILO~1 HTM 393 04-23-99 10:22p Tiki Lounge.htm | | Let me send that one to... | http://www.virustotal.com/xhtml/index_en.html | | It will be scanned by 30 virus detectors! I'll report back! | | By the way, did avast! announce to you that a new version is | available? I didn't click to take it, but will go to investigate that | too. Here is the result... Complete scanning result of "Tiki Lounge.htm", processed in VirusTotal at 07/31/2007 23:55:33 (CET). [ file data ] * name: Tiki Lounge.htm * size: 370 * md5.: c5f4869d1805078ae115a7c5464b605f * sha1: b3990474983e89fa1af5d46cace22cc1a4494d39 [ scan result ] AhnLab-V3 2007.7.31.1/20070731 found nothing AntiVir 7.4.0.54/20070731 found nothing Authentium 4.93.8/20070731 found nothing Avast 4.7.1029.0/20070731 found nothing <<Interesting! .... My version is 4.7.1001 May 2007 .... Can that be the new one avast! is offering? .... Hmmm! EVEN my version doesn't find the virus anymore, .... with just new definitions...!... .........Quote Summary.txt......... Vps: Updated (previous version: 000762-4, updated version: 000762-5) .........EOQ................................ I guess we are clear, Angel-- put the file back where it came from! AVG 7.5.0.476/20070731 found nothing BitDefender 7.2/20070731 found nothing CAT-QuickHeal 9.00/20070731 found nothing ClamAV 0.91/20070731 found nothing DrWeb 4.33/20070731 found nothing eSafe 7.0.15.0/20070731 found nothing eTrust-Vet 31.1.5019/20070731 found nothing Ewido 4.0/20070731 found nothing F-Prot 4.3.2.48/20070731 found nothing F-Secure 6.70.13030.0/20070731 found nothing FileAdvisor 1/20070731 found nothing Fortinet 2.91.0.0/20070731 found nothing Ikarus T3.1.1.8/20070731 found nothing Kaspersky 4.0.2.24/20070731 found nothing McAfee 5087/20070731 found nothing Microsoft 1.2704/20070731 found nothing NOD32v2 2430/20070731 found nothing Norman 5.80.02/20070731 found nothing Panda 9.0.0.4/20070731 found nothing Prevx1 V2/20070731 found nothing Rising 19.34.12.00/20070731 found nothing Sophos 4.19.0/20070726 found nothing Sunbelt 2.2.907.0/20070731 found nothing Symantec 10/20070731 found nothing TheHacker 6.1.7.159/20070731 found nothing VBA32 3.12.2.2/20070731 found nothing VirusBuster 4.3.26:9/20070731 found nothing Webwasher-Gateway 6.0.1/20070731 found nothing __________________________________________________ VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Do not reply to this message. It has been generated by an automatic address that will not handle any reply. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
Guest Angel Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. I do not know if what Avast! did can be undone. How would you do it? Angel "PCR" <pcrrcp@netzero.net> wrote in message news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl... Angel wrote: | Hi PCR, | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. | It is a multimedia keyboard. | Smart Bridge is my SDL program. Alright. It shouldn't hurt to uncheck them just to test it. Some programs will include innocent pop-up ads. But probably it is something else. Post back to that other thread, then. There are good people in it! | There was only 1 LoadPowerProfile. I checked it out. You should have this one, too... LoadPowerProfile Registry (Machine Run) Rundll32.exe powrprof.dll,LoadCurrentPwrScheme To get it, use Notepad to make a file named "LPP.reg" from the following... .......Start after this dotted line......... REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [END] .......End before this dotted line......... NOTE: You should get 5 lines. If more, there has been word-wrap. Don't run it, then. Post back, & I'll try something else. Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig to confirm it is there. If so, you may delete "LPP.reg". | I did the Scans again Spybot found 3 drivecleaner.com cookies | under the title of winsoftware. Those couldn't be the problem, if it still exists. Didn't hurt to get rid of the Cookies, though. | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki | lounge. I deleted it. At the end of the scan, I had done a through | one. This showed up in the results of the scan: | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. | Infection:VBS:malware{HTML} Error occurred during moving file to | chest. Before trying to move it I tried to delete it. How do I get | rid of this malware? Now I think I found the culprit. Now lets get | it out of my machine. Angel That was a false alarm, as I posted separately. And with new defs, it goes away. Can you undo what avast! did to the file(s)? | "PCR" <pcrrcp@netzero.net> wrote in message | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... |> Angel wrote: |> | PCR, |> | I found the directions so here it is: |> | |> | SystemTray Registry (Machine Run) SysTray.Exe |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe |> | /autorun |> |> Those are fine. |> |> | Motive SmartBridge Registry (Machine Run) |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe |> |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I |> said below. Reboot, & see whether it stops. |> |> | CHotKey Registry (Machine Run) mk9908.exe |> |> I'm not finding anything about pop-ups with mk9908.exe at Google. |> Yours looks odd, though, in that it doesn't mention a folder. What |> folder is mk9908.exe in? Are you sure it starts the way that line is |> now? |> |> You can get the folder into that line using MSConfig. If it is a LFN |> (Long File Name), you must surround it with quotes, or use the SFN |> instead. |> |> | avast! Web Scanner Registry (Machine Run) |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE |> |> OK. |> |> | KB918547 Registry (Machine Service) |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE |> |> | KB891711 Registry (Machine |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE |> |> | LoadPowerProfile |> | Registry (Machine Service) Rundll32.exe |> | powrprof.dll,LoadCurrentPwrScheme |> |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then, |> re-check it. |> |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC |> | PowerChute Personal Edition\mainserv.exe |> |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, |> but I chose not to install the software. It works fine that way, but |> I must close down, myself, within 20 minutes. It saved me several |> times. |> |> I doubt this would include pop-up ads. But, is it the last thing you |> installed before they started? Then, maybe uncheck it at... |> |> "START button, Run, MSConfig, Startup tab" |> |> ..., reboot, & see whether they stop. |> |> | avast! Registry (Machine Service) C:\Program Files\Alwil |> | Software\Avast4\ashServ.exe |> |> OK. |> |> | Angel |> | |> | "PCR" <pcrrcp@netzero.net> wrote in message |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... |> |> Angel wrote: |> |> | Meb, |> |> | I thought it was me. I maybe should retype what I just |> |> | typed to you. If this goes through I will.I tried to use PCR's |> |> | email at the bottom of his posts. But no answer. I wonder if it |> |> | is his real email. Mine is different than the one in my posts. |> |> |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you |> |> posted to me, Angel, but now you know I have answered it. |> |> |> |> As Candlin & MEB verify, the NG possibly was under maintenance, |> |> which does happen now/then. It used to happen more often. You |> |> should sleep through it or go for a walk! |> |> |> |> For the OE icons/buttons, those are adjustable this way... Grab |> |> the icon area or the menu area at the far left with the mouse. |> |> You will see a two pointed arrow going horizontally through two |> |> vertical lines after you start moving the mouse. Move the area up |> |> or down, until the buttons show again. |> |> |> |> For the pop-ups, I think the others in the other thread are making |> |> sense. As MEB said, post a HijackThis report, or at least... |> |> |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup |> |> Programs". |> |> (2) Use the Edit menu to Select All & Copy. |> |> (3) Post it here or there. |> |> |> |> Hopefully, as Terhune may have said, these pop-ups are an |> |> annoyance, but not a real threat. Then, once it is identified, |> |> there could even be an entry at... |> |> |> |> "START, Settings, Control Panel, Add/Remove Programs, |> |> Install/Uninstall tab" |> |> |> |> ... that will remove it. |> |> |> |> | Let me know if this is |> |> | going through. I have another question, The top of my Outlook |> |> | express has changed the buttons were along the top, now they |> |> | are at the bottom. Are there any settings that need to be |> |> | readjusted? Or is it from the troubles with the Pop ups that |> |> | has caused anything. The buttons are in a drop down button only |> |> | marked with a >>. When I do a post they are across the top |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> |> |> |> |> |> "Angel" <angel@noway.com> wrote in message |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> |> | Hi, |> |> |> | I have a dilemma. I tried to post 3 times today to the |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is |> |> |> | happening? Angel |> |> |> | |> |> |> | |> |> |> |> |> |> Good question, I have now tried six times to post a reply to |> |> |> PCR in the firewalls discussion.. |> |> |> |> |> |> -- |> |> |> MEB |> |> |> http://peoplescounsel.orgfree.com |> |> |> ________ |> |> |> |> -- |> |> Thanks or Good Luck, |> |> There may be humor in this post, and, |> |> Naturally, you will not sue, |> |> Should things get worse after this, |> |> PCR |> |> pcrrcp@netzero.net |> |> -- |> Thanks or Good Luck, |> There may be humor in this post, and, |> Naturally, you will not sue, |> Should things get worse after this, |> PCR |> pcrrcp@netzero.net -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest Angel Posted July 31, 2007 Posted July 31, 2007 Re: Trying to post, no success. Please explain what you mean by making a file? How is it done? Please explain in more detail. I found the thing under RunServices. So I know it is on the machine. Angel "PCR" <pcrrcp@netzero.net> wrote in message news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl... Angel wrote: | Hi PCR, | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. | It is a multimedia keyboard. | Smart Bridge is my SDL program. Alright. It shouldn't hurt to uncheck them just to test it. Some programs will include innocent pop-up ads. But probably it is something else. Post back to that other thread, then. There are good people in it! | There was only 1 LoadPowerProfile. I checked it out. You should have this one, too... LoadPowerProfile Registry (Machine Run) Rundll32.exe powrprof.dll,LoadCurrentPwrScheme To get it, use Notepad to make a file named "LPP.reg" from the following... .......Start after this dotted line......... REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [END] .......End before this dotted line......... NOTE: You should get 5 lines. If more, there has been word-wrap. Don't run it, then. Post back, & I'll try something else. Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig to confirm it is there. If so, you may delete "LPP.reg". | I did the Scans again Spybot found 3 drivecleaner.com cookies | under the title of winsoftware. Those couldn't be the problem, if it still exists. Didn't hurt to get rid of the Cookies, though. | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki | lounge. I deleted it. At the end of the scan, I had done a through | one. This showed up in the results of the scan: | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. | Infection:VBS:malware{HTML} Error occurred during moving file to | chest. Before trying to move it I tried to delete it. How do I get | rid of this malware? Now I think I found the culprit. Now lets get | it out of my machine. Angel That was a false alarm, as I posted separately. And with new defs, it goes away. Can you undo what avast! did to the file(s)? | "PCR" <pcrrcp@netzero.net> wrote in message | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... |> Angel wrote: |> | PCR, |> | I found the directions so here it is: |> | |> | SystemTray Registry (Machine Run) SysTray.Exe |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe |> | /autorun |> |> Those are fine. |> |> | Motive SmartBridge Registry (Machine Run) |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe |> |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I |> said below. Reboot, & see whether it stops. |> |> | CHotKey Registry (Machine Run) mk9908.exe |> |> I'm not finding anything about pop-ups with mk9908.exe at Google. |> Yours looks odd, though, in that it doesn't mention a folder. What |> folder is mk9908.exe in? Are you sure it starts the way that line is |> now? |> |> You can get the folder into that line using MSConfig. If it is a LFN |> (Long File Name), you must surround it with quotes, or use the SFN |> instead. |> |> | avast! Web Scanner Registry (Machine Run) |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE |> |> OK. |> |> | KB918547 Registry (Machine Service) |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE |> |> | KB891711 Registry (Machine |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE |> |> | LoadPowerProfile |> | Registry (Machine Service) Rundll32.exe |> | powrprof.dll,LoadCurrentPwrScheme |> |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then, |> re-check it. |> |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC |> | PowerChute Personal Edition\mainserv.exe |> |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, |> but I chose not to install the software. It works fine that way, but |> I must close down, myself, within 20 minutes. It saved me several |> times. |> |> I doubt this would include pop-up ads. But, is it the last thing you |> installed before they started? Then, maybe uncheck it at... |> |> "START button, Run, MSConfig, Startup tab" |> |> ..., reboot, & see whether they stop. |> |> | avast! Registry (Machine Service) C:\Program Files\Alwil |> | Software\Avast4\ashServ.exe |> |> OK. |> |> | Angel |> | |> | "PCR" <pcrrcp@netzero.net> wrote in message |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... |> |> Angel wrote: |> |> | Meb, |> |> | I thought it was me. I maybe should retype what I just |> |> | typed to you. If this goes through I will.I tried to use PCR's |> |> | email at the bottom of his posts. But no answer. I wonder if it |> |> | is his real email. Mine is different than the one in my posts. |> |> |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you |> |> posted to me, Angel, but now you know I have answered it. |> |> |> |> As Candlin & MEB verify, the NG possibly was under maintenance, |> |> which does happen now/then. It used to happen more often. You |> |> should sleep through it or go for a walk! |> |> |> |> For the OE icons/buttons, those are adjustable this way... Grab |> |> the icon area or the menu area at the far left with the mouse. |> |> You will see a two pointed arrow going horizontally through two |> |> vertical lines after you start moving the mouse. Move the area up |> |> or down, until the buttons show again. |> |> |> |> For the pop-ups, I think the others in the other thread are making |> |> sense. As MEB said, post a HijackThis report, or at least... |> |> |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup |> |> Programs". |> |> (2) Use the Edit menu to Select All & Copy. |> |> (3) Post it here or there. |> |> |> |> Hopefully, as Terhune may have said, these pop-ups are an |> |> annoyance, but not a real threat. Then, once it is identified, |> |> there could even be an entry at... |> |> |> |> "START, Settings, Control Panel, Add/Remove Programs, |> |> Install/Uninstall tab" |> |> |> |> ... that will remove it. |> |> |> |> | Let me know if this is |> |> | going through. I have another question, The top of my Outlook |> |> | express has changed the buttons were along the top, now they |> |> | are at the bottom. Are there any settings that need to be |> |> | readjusted? Or is it from the troubles with the Pop ups that |> |> | has caused anything. The buttons are in a drop down button only |> |> | marked with a >>. When I do a post they are across the top |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> |> |> |> |> |> "Angel" <angel@noway.com> wrote in message |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> |> | Hi, |> |> |> | I have a dilemma. I tried to post 3 times today to the |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is |> |> |> | happening? Angel |> |> |> | |> |> |> | |> |> |> |> |> |> Good question, I have now tried six times to post a reply to |> |> |> PCR in the firewalls discussion.. |> |> |> |> |> |> -- |> |> |> MEB |> |> |> http://peoplescounsel.orgfree.com |> |> |> ________ |> |> |> |> -- |> |> Thanks or Good Luck, |> |> There may be humor in this post, and, |> |> Naturally, you will not sue, |> |> Should things get worse after this, |> |> PCR |> |> pcrrcp@netzero.net |> |> -- |> Thanks or Good Luck, |> There may be humor in this post, and, |> Naturally, you will not sue, |> Should things get worse after this, |> PCR |> pcrrcp@netzero.net -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest Angel Posted August 1, 2007 Posted August 1, 2007 Re: Trying to post, no success. PCR, How did you use the program? I found the program but I do not know what file to type in the upload bar and what choice in options , if any. I want to see if mine turns out the same as yours. Angel "PCR" <pcrrcp@netzero.net> wrote in message news:urmdeL80HHA.5772@TK2MSFTNGP02.phx.gbl... Angel wrote: | Thanks PCR, | I use the software from APC because sometimes we have power | outages if only for a moment. With the software it will automatically | shut down the computer if needed with no loss of files and you do not | get the Blue screen that says that you have not shut down properly. I | forgot to mention that in the previous email reply to the files in That's worthwhile, if you are not at the computer when the outage hits. Otherwise, even without the software installed, the UPS works, & you get 20 minutes to close up yourself. You do have to have the monitor plugged into one of the uninterruptible sockets, of course, to see what you're doing. Mine has 3 of those & another 3 that are surge protected only. | the Misinfo file. Angel | | "PCR" <pcrrcp@netzero.net> wrote in message | news:%23o2S5h70HHA.728@TK2MSFTNGP05.phx.gbl... |> Angel wrote: |> | PCR, |> | I did the Avast! through/w archives. The same virus showed up |> | again and I put it in the chest.The name: C:\Program Files\common |> | files\Microsoft shared\Stationary\Tiki Lounge. It then proceeded on |> | to the end and the same archive, |> | C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS |> | malware{HTML} error occurred during moving to the chest. I clicked |> | on to scan it. The window came up that "The operation is not |> | supported for this type of archive. Cannot process " |> | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find |> | files and folders search for it. It was a Zip file and it showed to |> | have a virus when I scanned it. The same thing happened. I unzipped |> | it and the same thing happened when I found the file which was a |> | gif. The date on it was before this computer was built. 6/23/1999. |> | I think all the files in that folder were that same date. It looks |> | like the CAB 49 is damaged by the virus. Am I right? Now what |> | to do about |> | it? Angel |> |> Uhuh! I got the SAME avast! alert, myself, today about "Tiki |> Lounge.htm", which is a 1999 file. I'm hoping it is a false alarm, |> like the one I had before! I also did a Thorough Scan & included |> archives. But my .cabs are on another partition. I went looking & |> did find... |> |> Cabinet WIN98_49.CAB |> 04-23-1999 10:22:00p A--- 393 tiki.htm |> |> ... and was puzzled NOT to find "Tiki Lounge.htm". But let me scan |> that cab now... YEP! Just as you say... avast! finds the same |> "Virus/Worm" in tiki.htm! It looks to me that these are the same |> file, but with a different name... |> |> TIKILO~1 HTM 393 04-23-99 10:22p Tiki Lounge.htm |> |> Let me send that one to... |> http://www.virustotal.com/xhtml/index_en.html |> |> It will be scanned by 30 virus detectors! I'll report back! |> |> By the way, did avast! announce to you that a new version is |> available? I didn't click to take it, but will go to investigate |> that too. |> |> | "Angel" <angel@noway.com> wrote in message |> | news:OsVGQPy0HHA.2484@TK2MSFTNGP06.phx.gbl... |> |> Hi PCR, |> |> The mk9908.exe is the drive for my Keyboard. It is in |> |> C:\Windows. It is a multimedia keyboard. |> |> Smart Bridge is my SDL program. |> |> There was only 1 LoadPowerProfile. I checked it out. |> |> I did the Scans again Spybot found 3 drivecleaner.com |> |> cookies under the title of winsoftware. |> |> Avast! found a virus. Malware type VBS: Malware{HTML} Virus |> |> worm C:\Program Files\common files\Microsoft |> |> Shared\Stationary\Tiki lounge. I deleted it. At the end of the |> |> scan, I had done a through one. This showed up in the results of |> |> the scan: C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. |> |> Infection:VBS:malware{HTML} Error occurred during moving file to |> |> chest. Before trying to move it I tried to delete it. How do I get |> |> rid of this malware? Now I think I found the culprit. Now lets |> |> get it out of my machine. Angel |> |> |> |> "PCR" <pcrrcp@netzero.net> wrote in message |> |> news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> > Angel wrote: |> |> > | PCR, |> |> > | I found the directions so here it is: |> |> > | |> |> > | SystemTray Registry (Machine Run) SysTray.Exe |> |> > | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe |> |> > | /autorun |> |> > |> |> > Those are fine. |> |> > |> |> > | Motive SmartBridge Registry (Machine Run) |> |> > | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe |> |> > |> |> > I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig |> |> > as I said below. Reboot, & see whether it stops. |> |> > |> |> > | CHotKey Registry (Machine Run) mk9908.exe |> |> > |> |> > I'm not finding anything about pop-ups with mk9908.exe at |> |> > Google. Yours looks odd, though, in that it doesn't mention a |> |> > folder. What folder is mk9908.exe in? Are you sure it starts |> |> > the way that line is now? |> |> > |> |> > You can get the folder into that line using MSConfig. If it is a |> |> > LFN (Long File Name), you must surround it with quotes, or use |> |> > the SFN instead. |> |> > |> |> > | avast! Web Scanner Registry (Machine Run) |> |> > | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE |> |> > |> |> > OK. |> |> > |> |> > | KB918547 Registry (Machine Service) |> |> > | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE |> |> > |> |> > | KB891711 Registry (Machine |> |> > | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE |> |> > |> |> > | LoadPowerProfile |> |> > | Registry (Machine Service) Rundll32.exe |> |> > | powrprof.dll,LoadCurrentPwrScheme |> |> > |> |> > Those 3 are fine. You should have 2 of LoadPowerProfile, though. |> |> > Did you uncheck one at "START button, Run, MSConfig, Startup |> |> > tab"? Then, re-check it. |> |> > |> |> > | APC_SERVICE Registry (Machine Service) C:\Program |> |> > | Files\APC\APC PowerChute Personal Edition\mainserv.exe |> |> > |> |> > Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged |> |> > in, but I chose not to install the software. It works fine that |> |> > way, but I must close down, myself, within 20 minutes. It saved |> |> > me several times. |> |> > |> |> > I doubt this would include pop-up ads. But, is it the last thing |> |> > you installed before they started? Then, maybe uncheck it at... |> |> > |> |> > "START button, Run, MSConfig, Startup tab" |> |> > |> |> > ..., reboot, & see whether they stop. |> |> > |> |> > | avast! Registry (Machine Service) C:\Program Files\Alwil |> |> > | Software\Avast4\ashServ.exe |> |> > |> |> > OK. |> |> > |> |> > | Angel |> |> > | |> |> > | "PCR" <pcrrcp@netzero.net> wrote in message |> |> > | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... |> |> > |> Angel wrote: |> |> > |> | Meb, |> |> > |> | I thought it was me. I maybe should retype what I just |> |> > |> | typed to you. If this goes through I will.I tried to use |> |> > |> | PCR's email at the bottom of his posts. But no answer. I |> |> > |> | wonder if it is his real email. Mine is different than the |> |> > |> | one in my posts. |> |> > |> |> |> > |> I was dead asleep &/or on my 1st or 2nd walk of the day when |> |> > |> you posted to me, Angel, but now you know I have answered it. |> |> > |> |> |> > |> As Candlin & MEB verify, the NG possibly was under |> |> > |> maintenance, which does happen now/then. It used to happen |> |> > |> more often. You should sleep through it or go for a walk! |> |> > |> |> |> > |> For the OE icons/buttons, those are adjustable this way... |> |> > |> Grab the icon area or the menu area at the far left with the |> |> > |> mouse. You will see a two pointed arrow going horizontally |> |> > |> through two vertical lines after you start moving the mouse. |> |> > |> Move the area up or down, until the buttons show again. |> |> > |> |> |> > |> For the pop-ups, I think the others in the other thread are |> |> > |> making sense. As MEB said, post a HijackThis report, or at |> |> > |> least... |> |> > |> |> |> > |> (1) "START button, Run, MSInfo32, Software Environment, |> |> > |> Startup Programs". |> |> > |> (2) Use the Edit menu to Select All & Copy. |> |> > |> (3) Post it here or there. |> |> > |> |> |> > |> Hopefully, as Terhune may have said, these pop-ups are an |> |> > |> annoyance, but not a real threat. Then, once it is |> |> > |> identified, there could even be an entry at... |> |> > |> |> |> > |> "START, Settings, Control Panel, Add/Remove Programs, |> |> > |> Install/Uninstall tab" |> |> > |> |> |> > |> ... that will remove it. |> |> > |> |> |> > |> | Let me know if this is |> |> > |> | going through. I have another question, The top of my |> |> > |> | Outlook express has changed the buttons were along the top, |> |> > |> | now they are at the bottom. Are there any settings that |> |> > |> | need to be readjusted? Or is it from the troubles with the |> |> > |> | Pop ups that has caused anything. The buttons are in a |> |> > |> | drop down button only marked with a >>. When I do a |> |> > |> | post they are across the top as they were. Angel "MEB" |> |> > |> | <meb@not here@hotmail.com> wrote in message |> |> > |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... |> |> > |> |> |> |> > |> |> "Angel" <angel@noway.com> wrote in message |> |> > |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... |> |> > |> |> | Hi, |> |> > |> |> | I have a dilemma. I tried to post 3 times today to |> |> > |> |> | the string, "Error Alert?" NO SUCCESS So trying again!! |> |> > |> |> | What is happening? Angel |> |> > |> |> | |> |> > |> |> | |> |> > |> |> |> |> > |> |> Good question, I have now tried six times to post a reply |> |> > |> |> to PCR in the firewalls discussion.. |> |> > |> |> |> |> > |> |> -- |> |> > |> |> MEB |> |> > |> |> http://peoplescounsel.orgfree.com |> |> > |> |> ________ |> |> > |> |> |> > |> -- |> |> > |> Thanks or Good Luck, |> |> > |> There may be humor in this post, and, |> |> > |> Naturally, you will not sue, |> |> > |> Should things get worse after this, |> |> > |> PCR |> |> > |> pcrrcp@netzero.net |> |> > |> |> > -- |> |> > Thanks or Good Luck, |> |> > There may be humor in this post, and, |> |> > Naturally, you will not sue, |> |> > Should things get worse after this, |> |> > PCR |> |> > pcrrcp@netzero.net |> |> -- |> Thanks or Good Luck, |> There may be humor in this post, and, |> Naturally, you will not sue, |> Should things get worse after this, |> PCR |> pcrrcp@netzero.net -- Thanks or Good Luck, There may be humor in this post, and, Naturally, you will not sue, Should things get worse after this, PCR pcrrcp@netzero.net
Guest Angel Posted August 1, 2007 Posted August 1, 2007 Re: Trying to post, no success. Hi PCR, I figured out how to use the browse and how to do it. I did it and only one came up with something when I run the cab file F-Prot 4.3.2.48 2007.07.31 File is damaged. Now I will put the thing back and see what happens. I hope that it will come out not damaged. Wish me luck. Angel "Angel" <angel@noway.com> wrote in message news:eF2%23Ej80HHA.4928@TK2MSFTNGP05.phx.gbl... > Please explain what you mean by making a file? How is it done? Please > explain in more detail. > I found the thing under RunServices. So I know it is on the machine. > Angel > > "PCR" <pcrrcp@netzero.net> wrote in message > news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl... > Angel wrote: > | Hi PCR, > | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. > | It is a multimedia keyboard. > | Smart Bridge is my SDL program. > > Alright. It shouldn't hurt to uncheck them just to test it. Some programs > will include innocent pop-up ads. But probably it is something else. Post > back to that other thread, then. There are good people in it! > > | There was only 1 LoadPowerProfile. I checked it out. > > > You should have this one, too... > > LoadPowerProfile Registry (Machine Run) Rundll32.exe > powrprof.dll,LoadCurrentPwrScheme > > To get it, use Notepad to make a file named "LPP.reg" from the following... > > ......Start after this dotted line......... > REGEDIT4 > > [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] > "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" > [END] > ......End before this dotted line......... > > NOTE: You should get 5 lines. If more, there has been word-wrap. Don't run > it, then. Post back, & I'll try something else. > > Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig to > confirm it is there. If so, you may delete "LPP.reg". > > | I did the Scans again Spybot found 3 drivecleaner.com cookies > | under the title of winsoftware. > > Those couldn't be the problem, if it still exists. Didn't hurt to get rid of > the Cookies, though. > > | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm > | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki > | lounge. I deleted it. At the end of the scan, I had done a through > | one. This showed up in the results of the scan: > | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. > | Infection:VBS:malware{HTML} Error occurred during moving file to > | chest. Before trying to move it I tried to delete it. How do I get > | rid of this malware? Now I think I found the culprit. Now lets get > | it out of my machine. Angel > > That was a false alarm, as I posted separately. And with new defs, it goes > away. Can you undo what avast! did to the file(s)? > > | "PCR" <pcrrcp@netzero.net> wrote in message > | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... > |> Angel wrote: > |> | PCR, > |> | I found the directions so here it is: > |> | > |> | SystemTray Registry (Machine Run) SysTray.Exe > |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe > |> | /autorun > |> > |> Those are fine. > |> > |> | Motive SmartBridge Registry (Machine Run) > |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe > |> > |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I > |> said below. Reboot, & see whether it stops. > |> > |> | CHotKey Registry (Machine Run) mk9908.exe > |> > |> I'm not finding anything about pop-ups with mk9908.exe at Google. > |> Yours looks odd, though, in that it doesn't mention a folder. What > |> folder is mk9908.exe in? Are you sure it starts the way that line is > |> now? > |> > |> You can get the folder into that line using MSConfig. If it is a LFN > |> (Long File Name), you must surround it with quotes, or use the SFN > |> instead. > |> > |> | avast! Web Scanner Registry (Machine Run) > |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE > |> > |> OK. > |> > |> | KB918547 Registry (Machine Service) > |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE > |> > |> | KB891711 Registry (Machine > |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE > |> > |> | LoadPowerProfile > |> | Registry (Machine Service) Rundll32.exe > |> | powrprof.dll,LoadCurrentPwrScheme > |> > |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did > |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then, > |> re-check it. > |> > |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC > |> | PowerChute Personal Edition\mainserv.exe > |> > |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, > |> but I chose not to install the software. It works fine that way, but > |> I must close down, myself, within 20 minutes. It saved me several > |> times. > |> > |> I doubt this would include pop-up ads. But, is it the last thing you > |> installed before they started? Then, maybe uncheck it at... > |> > |> "START button, Run, MSConfig, Startup tab" > |> > |> ..., reboot, & see whether they stop. > |> > |> | avast! Registry (Machine Service) C:\Program Files\Alwil > |> | Software\Avast4\ashServ.exe > |> > |> OK. > |> > |> | Angel > |> | > |> | "PCR" <pcrrcp@netzero.net> wrote in message > |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > |> |> Angel wrote: > |> |> | Meb, > |> |> | I thought it was me. I maybe should retype what I just > |> |> | typed to you. If this goes through I will.I tried to use PCR's > |> |> | email at the bottom of his posts. But no answer. I wonder if it > |> |> | is his real email. Mine is different than the one in my posts. > |> |> > |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you > |> |> posted to me, Angel, but now you know I have answered it. > |> |> > |> |> As Candlin & MEB verify, the NG possibly was under maintenance, > |> |> which does happen now/then. It used to happen more often. You > |> |> should sleep through it or go for a walk! > |> |> > |> |> For the OE icons/buttons, those are adjustable this way... Grab > |> |> the icon area or the menu area at the far left with the mouse. > |> |> You will see a two pointed arrow going horizontally through two > |> |> vertical lines after you start moving the mouse. Move the area up > |> |> or down, until the buttons show again. > |> |> > |> |> For the pop-ups, I think the others in the other thread are making > |> |> sense. As MEB said, post a HijackThis report, or at least... > |> |> > |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup > |> |> Programs". > |> |> (2) Use the Edit menu to Select All & Copy. > |> |> (3) Post it here or there. > |> |> > |> |> Hopefully, as Terhune may have said, these pop-ups are an > |> |> annoyance, but not a real threat. Then, once it is identified, > |> |> there could even be an entry at... > |> |> > |> |> "START, Settings, Control Panel, Add/Remove Programs, > |> |> Install/Uninstall tab" > |> |> > |> |> ... that will remove it. > |> |> > |> |> | Let me know if this is > |> |> | going through. I have another question, The top of my Outlook > |> |> | express has changed the buttons were along the top, now they > |> |> | are at the bottom. Are there any settings that need to be > |> |> | readjusted? Or is it from the troubles with the Pop ups that > |> |> | has caused anything. The buttons are in a drop down button only > |> |> | marked with a >>. When I do a post they are across the top > |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in > |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > |> |> |> > |> |> |> "Angel" <angel@noway.com> wrote in message > |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > |> |> |> | Hi, > |> |> |> | I have a dilemma. I tried to post 3 times today to the > |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is > |> |> |> | happening? Angel > |> |> |> | > |> |> |> | > |> |> |> > |> |> |> Good question, I have now tried six times to post a reply to > |> |> |> PCR in the firewalls discussion.. > |> |> |> > |> |> |> -- > |> |> |> MEB > |> |> |> http://peoplescounsel.orgfree.com > |> |> |> ________ > |> |> > |> |> -- > |> |> Thanks or Good Luck, > |> |> There may be humor in this post, and, > |> |> Naturally, you will not sue, > |> |> Should things get worse after this, > |> |> PCR > |> |> pcrrcp@netzero.net > |> > |> -- > |> Thanks or Good Luck, > |> There may be humor in this post, and, > |> Naturally, you will not sue, > |> Should things get worse after this, > |> PCR > |> pcrrcp@netzero.net > > -- > Thanks or Good Luck, > There may be humor in this post, and, > Naturally, you will not sue, > Should things get worse after this, > PCR > pcrrcp@netzero.net > >
Guest Angel Posted August 1, 2007 Posted August 1, 2007 Re: Trying to post, no success. PCR, It was not in the chest. The first time it showed up, I deleted it. then when I re-ran the Avast! it showed up again and I put it in the chest. BUT it is not there!! Mystery!! Now what? Looks like Avast! did a false reading. Could F-Prot be doing a false reading also? Now I am going to go through my routine and find out what happens. Angel "Angel" <angel@noway.com> wrote in message news:%23m5ZJQ%230HHA.464@TK2MSFTNGP02.phx.gbl... > Hi PCR, > I figured out how to use the browse and how to do it. I did it and only > one came up with something when I run the cab file F-Prot 4.3.2.48 > 2007.07.31 File is damaged. Now I will put the thing back and see what > happens. I hope that it will come out not damaged. Wish me luck. > Angel > > "Angel" <angel@noway.com> wrote in message > news:eF2%23Ej80HHA.4928@TK2MSFTNGP05.phx.gbl... > > Please explain what you mean by making a file? How is it done? Please > > explain in more detail. > > I found the thing under RunServices. So I know it is on the machine. > > Angel > > > > "PCR" <pcrrcp@netzero.net> wrote in message > > news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl... > > Angel wrote: > > | Hi PCR, > > | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. > > | It is a multimedia keyboard. > > | Smart Bridge is my SDL program. > > > > Alright. It shouldn't hurt to uncheck them just to test it. Some programs > > will include innocent pop-up ads. But probably it is something else. Post > > back to that other thread, then. There are good people in it! > > > > | There was only 1 LoadPowerProfile. I checked it out. > > > > > > You should have this one, too... > > > > LoadPowerProfile Registry (Machine Run) Rundll32.exe > > powrprof.dll,LoadCurrentPwrScheme > > > > To get it, use Notepad to make a file named "LPP.reg" from the > following... > > > > ......Start after this dotted line......... > > REGEDIT4 > > > > [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] > > "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" > > [END] > > ......End before this dotted line......... > > > > NOTE: You should get 5 lines. If more, there has been word-wrap. Don't run > > it, then. Post back, & I'll try something else. > > > > Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig > to > > confirm it is there. If so, you may delete "LPP.reg". > > > > | I did the Scans again Spybot found 3 drivecleaner.com cookies > > | under the title of winsoftware. > > > > Those couldn't be the problem, if it still exists. Didn't hurt to get rid > of > > the Cookies, though. > > > > | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm > > | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki > > | lounge. I deleted it. At the end of the scan, I had done a through > > | one. This showed up in the results of the scan: > > | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. > > | Infection:VBS:malware{HTML} Error occurred during moving file to > > | chest. Before trying to move it I tried to delete it. How do I get > > | rid of this malware? Now I think I found the culprit. Now lets get > > | it out of my machine. Angel > > > > That was a false alarm, as I posted separately. And with new defs, it goes > > away. Can you undo what avast! did to the file(s)? > > > > | "PCR" <pcrrcp@netzero.net> wrote in message > > | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... > > |> Angel wrote: > > |> | PCR, > > |> | I found the directions so here it is: > > |> | > > |> | SystemTray Registry (Machine Run) SysTray.Exe > > |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe > > |> | /autorun > > |> > > |> Those are fine. > > |> > > |> | Motive SmartBridge Registry (Machine Run) > > |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe > > |> > > |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I > > |> said below. Reboot, & see whether it stops. > > |> > > |> | CHotKey Registry (Machine Run) mk9908.exe > > |> > > |> I'm not finding anything about pop-ups with mk9908.exe at Google. > > |> Yours looks odd, though, in that it doesn't mention a folder. What > > |> folder is mk9908.exe in? Are you sure it starts the way that line is > > |> now? > > |> > > |> You can get the folder into that line using MSConfig. If it is a LFN > > |> (Long File Name), you must surround it with quotes, or use the SFN > > |> instead. > > |> > > |> | avast! Web Scanner Registry (Machine Run) > > |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE > > |> > > |> OK. > > |> > > |> | KB918547 Registry (Machine Service) > > |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE > > |> > > |> | KB891711 Registry (Machine > > |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE > > |> > > |> | LoadPowerProfile > > |> | Registry (Machine Service) Rundll32.exe > > |> | powrprof.dll,LoadCurrentPwrScheme > > |> > > |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did > > |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then, > > |> re-check it. > > |> > > |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC > > |> | PowerChute Personal Edition\mainserv.exe > > |> > > |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, > > |> but I chose not to install the software. It works fine that way, but > > |> I must close down, myself, within 20 minutes. It saved me several > > |> times. > > |> > > |> I doubt this would include pop-up ads. But, is it the last thing you > > |> installed before they started? Then, maybe uncheck it at... > > |> > > |> "START button, Run, MSConfig, Startup tab" > > |> > > |> ..., reboot, & see whether they stop. > > |> > > |> | avast! Registry (Machine Service) C:\Program Files\Alwil > > |> | Software\Avast4\ashServ.exe > > |> > > |> OK. > > |> > > |> | Angel > > |> | > > |> | "PCR" <pcrrcp@netzero.net> wrote in message > > |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > > |> |> Angel wrote: > > |> |> | Meb, > > |> |> | I thought it was me. I maybe should retype what I just > > |> |> | typed to you. If this goes through I will.I tried to use PCR's > > |> |> | email at the bottom of his posts. But no answer. I wonder if it > > |> |> | is his real email. Mine is different than the one in my posts. > > |> |> > > |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you > > |> |> posted to me, Angel, but now you know I have answered it. > > |> |> > > |> |> As Candlin & MEB verify, the NG possibly was under maintenance, > > |> |> which does happen now/then. It used to happen more often. You > > |> |> should sleep through it or go for a walk! > > |> |> > > |> |> For the OE icons/buttons, those are adjustable this way... Grab > > |> |> the icon area or the menu area at the far left with the mouse. > > |> |> You will see a two pointed arrow going horizontally through two > > |> |> vertical lines after you start moving the mouse. Move the area up > > |> |> or down, until the buttons show again. > > |> |> > > |> |> For the pop-ups, I think the others in the other thread are making > > |> |> sense. As MEB said, post a HijackThis report, or at least... > > |> |> > > |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup > > |> |> Programs". > > |> |> (2) Use the Edit menu to Select All & Copy. > > |> |> (3) Post it here or there. > > |> |> > > |> |> Hopefully, as Terhune may have said, these pop-ups are an > > |> |> annoyance, but not a real threat. Then, once it is identified, > > |> |> there could even be an entry at... > > |> |> > > |> |> "START, Settings, Control Panel, Add/Remove Programs, > > |> |> Install/Uninstall tab" > > |> |> > > |> |> ... that will remove it. > > |> |> > > |> |> | Let me know if this is > > |> |> | going through. I have another question, The top of my Outlook > > |> |> | express has changed the buttons were along the top, now they > > |> |> | are at the bottom. Are there any settings that need to be > > |> |> | readjusted? Or is it from the troubles with the Pop ups that > > |> |> | has caused anything. The buttons are in a drop down button only > > |> |> | marked with a >>. When I do a post they are across the top > > |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in > > |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > > |> |> |> > > |> |> |> "Angel" <angel@noway.com> wrote in message > > |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > > |> |> |> | Hi, > > |> |> |> | I have a dilemma. I tried to post 3 times today to the > > |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is > > |> |> |> | happening? Angel > > |> |> |> | > > |> |> |> | > > |> |> |> > > |> |> |> Good question, I have now tried six times to post a reply to > > |> |> |> PCR in the firewalls discussion.. > > |> |> |> > > |> |> |> -- > > |> |> |> MEB > > |> |> |> http://peoplescounsel.orgfree.com > > |> |> |> ________ > > |> |> > > |> |> -- > > |> |> Thanks or Good Luck, > > |> |> There may be humor in this post, and, > > |> |> Naturally, you will not sue, > > |> |> Should things get worse after this, > > |> |> PCR > > |> |> pcrrcp@netzero.net > > |> > > |> -- > > |> Thanks or Good Luck, > > |> There may be humor in this post, and, > > |> Naturally, you will not sue, > > |> Should things get worse after this, > > |> PCR > > |> pcrrcp@netzero.net > > > > -- > > Thanks or Good Luck, > > There may be humor in this post, and, > > Naturally, you will not sue, > > Should things get worse after this, > > PCR > > pcrrcp@netzero.net > > > > > >
Guest Angel Posted August 1, 2007 Posted August 1, 2007 Re: Trying to post, no success. PCR, Well, earlier the Avast! did the automatic update. I just got done doing the through w/Archives. Guess what? Nothing, no virus showed up and the error for Win98_49 thing didn't show up. Now we have to figure out if the F-Prot virus scan was right. Was it damaged or not. Angel "Angel" <angel@noway.com> wrote in message news:eXO1dX%230HHA.1100@TK2MSFTNGP06.phx.gbl... > PCR, > It was not in the chest. The first time it showed up, I deleted it. then > when I re-ran the Avast! it showed up again and I put it in the chest. BUT > it is not there!! Mystery!! Now what? Looks like Avast! did a false reading. > Could F-Prot be doing a false reading also? Now I am going to go through my > routine and find out what happens. > Angel > > "Angel" <angel@noway.com> wrote in message > news:%23m5ZJQ%230HHA.464@TK2MSFTNGP02.phx.gbl... > > Hi PCR, > > I figured out how to use the browse and how to do it. I did it and > only > > one came up with something when I run the cab file F-Prot 4.3.2.48 > > 2007.07.31 File is damaged. Now I will put the thing back and see what > > happens. I hope that it will come out not damaged. Wish me luck. > > Angel > > > > "Angel" <angel@noway.com> wrote in message > > news:eF2%23Ej80HHA.4928@TK2MSFTNGP05.phx.gbl... > > > Please explain what you mean by making a file? How is it done? Please > > > explain in more detail. > > > I found the thing under RunServices. So I know it is on the machine. > > > Angel > > > > > > "PCR" <pcrrcp@netzero.net> wrote in message > > > news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl... > > > Angel wrote: > > > | Hi PCR, > > > | The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. > > > | It is a multimedia keyboard. > > > | Smart Bridge is my SDL program. > > > > > > Alright. It shouldn't hurt to uncheck them just to test it. Some > programs > > > will include innocent pop-up ads. But probably it is something else. > Post > > > back to that other thread, then. There are good people in it! > > > > > > | There was only 1 LoadPowerProfile. I checked it out. > > > > > > > > > You should have this one, too... > > > > > > LoadPowerProfile Registry (Machine Run) Rundll32.exe > > > powrprof.dll,LoadCurrentPwrScheme > > > > > > To get it, use Notepad to make a file named "LPP.reg" from the > > following... > > > > > > ......Start after this dotted line......... > > > REGEDIT4 > > > > > > [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] > > > "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" > > > [END] > > > ......End before this dotted line......... > > > > > > NOTE: You should get 5 lines. If more, there has been word-wrap. Don't > run > > > it, then. Post back, & I'll try something else. > > > > > > Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or MSConfig > > to > > > confirm it is there. If so, you may delete "LPP.reg". > > > > > > | I did the Scans again Spybot found 3 drivecleaner.com cookies > > > | under the title of winsoftware. > > > > > > Those couldn't be the problem, if it still exists. Didn't hurt to get > rid > > of > > > the Cookies, though. > > > > > > | Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm > > > | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki > > > | lounge. I deleted it. At the end of the scan, I had done a through > > > | one. This showed up in the results of the scan: > > > | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. > > > | Infection:VBS:malware{HTML} Error occurred during moving file to > > > | chest. Before trying to move it I tried to delete it. How do I get > > > | rid of this malware? Now I think I found the culprit. Now lets get > > > | it out of my machine. Angel > > > > > > That was a false alarm, as I posted separately. And with new defs, it > goes > > > away. Can you undo what avast! did to the file(s)? > > > > > > | "PCR" <pcrrcp@netzero.net> wrote in message > > > | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... > > > |> Angel wrote: > > > |> | PCR, > > > |> | I found the directions so here it is: > > > |> | > > > |> | SystemTray Registry (Machine Run) SysTray.Exe > > > |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe > > > |> | /autorun > > > |> > > > |> Those are fine. > > > |> > > > |> | Motive SmartBridge Registry (Machine Run) > > > |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe > > > |> > > > |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I > > > |> said below. Reboot, & see whether it stops. > > > |> > > > |> | CHotKey Registry (Machine Run) mk9908.exe > > > |> > > > |> I'm not finding anything about pop-ups with mk9908.exe at Google. > > > |> Yours looks odd, though, in that it doesn't mention a folder. What > > > |> folder is mk9908.exe in? Are you sure it starts the way that line is > > > |> now? > > > |> > > > |> You can get the folder into that line using MSConfig. If it is a LFN > > > |> (Long File Name), you must surround it with quotes, or use the SFN > > > |> instead. > > > |> > > > |> | avast! Web Scanner Registry (Machine Run) > > > |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE > > > |> > > > |> OK. > > > |> > > > |> | KB918547 Registry (Machine Service) > > > |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE > > > |> > > > |> | KB891711 Registry (Machine > > > |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE > > > |> > > > |> | LoadPowerProfile > > > |> | Registry (Machine Service) Rundll32.exe > > > |> | powrprof.dll,LoadCurrentPwrScheme > > > |> > > > |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did > > > |> you uncheck one at "START button, Run, MSConfig, Startup tab"? Then, > > > |> re-check it. > > > |> > > > |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC > > > |> | PowerChute Personal Edition\mainserv.exe > > > |> > > > |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, > > > |> but I chose not to install the software. It works fine that way, but > > > |> I must close down, myself, within 20 minutes. It saved me several > > > |> times. > > > |> > > > |> I doubt this would include pop-up ads. But, is it the last thing you > > > |> installed before they started? Then, maybe uncheck it at... > > > |> > > > |> "START button, Run, MSConfig, Startup tab" > > > |> > > > |> ..., reboot, & see whether they stop. > > > |> > > > |> | avast! Registry (Machine Service) C:\Program Files\Alwil > > > |> | Software\Avast4\ashServ.exe > > > |> > > > |> OK. > > > |> > > > |> | Angel > > > |> | > > > |> | "PCR" <pcrrcp@netzero.net> wrote in message > > > |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... > > > |> |> Angel wrote: > > > |> |> | Meb, > > > |> |> | I thought it was me. I maybe should retype what I just > > > |> |> | typed to you. If this goes through I will.I tried to use PCR's > > > |> |> | email at the bottom of his posts. But no answer. I wonder if it > > > |> |> | is his real email. Mine is different than the one in my posts. > > > |> |> > > > |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when you > > > |> |> posted to me, Angel, but now you know I have answered it. > > > |> |> > > > |> |> As Candlin & MEB verify, the NG possibly was under maintenance, > > > |> |> which does happen now/then. It used to happen more often. You > > > |> |> should sleep through it or go for a walk! > > > |> |> > > > |> |> For the OE icons/buttons, those are adjustable this way... Grab > > > |> |> the icon area or the menu area at the far left with the mouse. > > > |> |> You will see a two pointed arrow going horizontally through two > > > |> |> vertical lines after you start moving the mouse. Move the area up > > > |> |> or down, until the buttons show again. > > > |> |> > > > |> |> For the pop-ups, I think the others in the other thread are making > > > |> |> sense. As MEB said, post a HijackThis report, or at least... > > > |> |> > > > |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup > > > |> |> Programs". > > > |> |> (2) Use the Edit menu to Select All & Copy. > > > |> |> (3) Post it here or there. > > > |> |> > > > |> |> Hopefully, as Terhune may have said, these pop-ups are an > > > |> |> annoyance, but not a real threat. Then, once it is identified, > > > |> |> there could even be an entry at... > > > |> |> > > > |> |> "START, Settings, Control Panel, Add/Remove Programs, > > > |> |> Install/Uninstall tab" > > > |> |> > > > |> |> ... that will remove it. > > > |> |> > > > |> |> | Let me know if this is > > > |> |> | going through. I have another question, The top of my Outlook > > > |> |> | express has changed the buttons were along the top, now they > > > |> |> | are at the bottom. Are there any settings that need to be > > > |> |> | readjusted? Or is it from the troubles with the Pop ups that > > > |> |> | has caused anything. The buttons are in a drop down button only > > > |> |> | marked with a >>. When I do a post they are across the top > > > |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in > > > |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... > > > |> |> |> > > > |> |> |> "Angel" <angel@noway.com> wrote in message > > > |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... > > > |> |> |> | Hi, > > > |> |> |> | I have a dilemma. I tried to post 3 times today to the > > > |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is > > > |> |> |> | happening? Angel > > > |> |> |> | > > > |> |> |> | > > > |> |> |> > > > |> |> |> Good question, I have now tried six times to post a reply to > > > |> |> |> PCR in the firewalls discussion.. > > > |> |> |> > > > |> |> |> -- > > > |> |> |> MEB > > > |> |> |> http://peoplescounsel.orgfree.com > > > |> |> |> ________ > > > |> |> > > > |> |> -- > > > |> |> Thanks or Good Luck, > > > |> |> There may be humor in this post, and, > > > |> |> Naturally, you will not sue, > > > |> |> Should things get worse after this, > > > |> |> PCR > > > |> |> pcrrcp@netzero.net > > > |> > > > |> -- > > > |> Thanks or Good Luck, > > > |> There may be humor in this post, and, > > > |> Naturally, you will not sue, > > > |> Should things get worse after this, > > > |> PCR > > > |> pcrrcp@netzero.net > > > > > > -- > > > Thanks or Good Luck, > > > There may be humor in this post, and, > > > Naturally, you will not sue, > > > Should things get worse after this, > > > PCR > > > pcrrcp@netzero.net > > > > > > > > > > > >
Guest Brian A. Posted August 1, 2007 Posted August 1, 2007 Re: Trying to post, no success. Win98SE cab files: tiki.gif is the Win98_49.cab tiki.htm is in the Win98_49.cab tiki.avb is in Win98_59.cab Win98 cab files: tiki.gif is in Win98_60.cab tiki.htm is in Win98_61.cab tiki.avb is in Win98_50.cab -- Brian A. Sesko { MS MVP_Shell/User } Conflicts start where information lacks. http://basconotw.mvps.org/ Suggested posting do's/don'ts: http://www.dts-l.org/goodpost.htm How to ask a question: http://support.microsoft.com/kb/555375 "Angel" <angel@noway.com> wrote in message news:OH4YSqz0HHA.5884@TK2MSFTNGP02.phx.gbl... > PCR, > I did the Avast! through/w archives. The same virus showed up again and > I put it in the chest.The name: C:\Program Files\common files\Microsoft > shared\Stationary\Tiki Lounge. It then proceeded on to the end and the same > archive, C:\WINDOWS\OPTIONS\WIN98_49CAB\tiki.htm Infection:VBS > malware{HTML} error occurred during moving to the chest. I clicked on to > scan it. The window came up that "The operation is not supported for this > type of archive. Cannot process " > C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm" file. I did a find files and > folders search for it. It was a Zip file and it showed to have a virus when > I scanned it. The same thing happened. I unzipped it and the same thing > happened when I found the file which was a gif. The date on it was before > this computer was built. 6/23/1999. I think all the files in that folder > were that same date. It looks like the CAB 49 is damaged by the virus. Am I > right? Now what to do about it? > Angel > > "Angel" <angel@noway.com> wrote in message > news:OsVGQPy0HHA.2484@TK2MSFTNGP06.phx.gbl... >> Hi PCR, >> The mk9908.exe is the drive for my Keyboard. It is in C:\Windows. It > is >> a multimedia keyboard. >> Smart Bridge is my SDL program. >> There was only 1 LoadPowerProfile. I checked it out. >> I did the Scans again Spybot found 3 drivecleaner.com cookies under >> the title of winsoftware. >> Avast! found a virus. Malware type VBS: Malware{HTML} Virus worm >> C:\Program Files\common files\Microsoft Shared\Stationary\Tiki lounge. I >> deleted it. At the end of the scan, I had done a through one. This showed > up >> in the results of the scan: C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. >> Infection:VBS:malware{HTML} Error occurred during moving file to chest. >> Before trying to move it I tried to delete it. How do I get rid of this >> malware? Now I think I found the culprit. Now lets get it out of my >> machine. >> Angel >> >> "PCR" <pcrrcp@netzero.net> wrote in message >> news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... >> > Angel wrote: >> > | PCR, >> > | I found the directions so here it is: >> > | >> > | SystemTray Registry (Machine Run) SysTray.Exe >> > | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe /autorun >> > >> > Those are fine. >> > >> > | Motive SmartBridge Registry (Machine Run) >> > | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe >> > >> > I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig as I >> > said below. Reboot, & see whether it stops. >> > >> > | CHotKey Registry (Machine Run) mk9908.exe >> > >> > I'm not finding anything about pop-ups with mk9908.exe at Google. Yours >> > looks odd, though, in that it doesn't mention a folder. What folder is >> > mk9908.exe in? Are you sure it starts the way that line is now? >> > >> > You can get the folder into that line using MSConfig. If it is a LFN >> > (Long File Name), you must surround it with quotes, or use the SFN >> > instead. >> > >> > | avast! Web Scanner Registry (Machine Run) >> > | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE >> > >> > OK. >> > >> > | KB918547 Registry (Machine Service) >> > | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE >> > >> > | KB891711 Registry (Machine >> > | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE >> > >> > | LoadPowerProfile >> > | Registry (Machine Service) Rundll32.exe >> > | powrprof.dll,LoadCurrentPwrScheme >> > >> > Those 3 are fine. You should have 2 of LoadPowerProfile, though. Did you >> > uncheck one at "START button, Run, MSConfig, Startup tab"? Then, >> > re-check it. >> > >> > | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC >> > | PowerChute Personal Edition\mainserv.exe >> > >> > Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, but I >> > chose not to install the software. It works fine that way, but I must >> > close down, myself, within 20 minutes. It saved me several times. >> > >> > I doubt this would include pop-up ads. But, is it the last thing you >> > installed before they started? Then, maybe uncheck it at... >> > >> > "START button, Run, MSConfig, Startup tab" >> > >> > ..., reboot, & see whether they stop. >> > >> > | avast! Registry (Machine Service) C:\Program Files\Alwil >> > | Software\Avast4\ashServ.exe >> > >> > OK. >> > >> > | Angel >> > | >> > | "PCR" <pcrrcp@netzero.net> wrote in message >> > | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... >> > |> Angel wrote: >> > |> | Meb, >> > |> | I thought it was me. I maybe should retype what I just typed to >> > |> | you. If this goes through I will.I tried to use PCR's email at the >> > |> | bottom of his posts. But no answer. I wonder if it is his real >> > |> | email. Mine is different than the one in my posts. >> > |> >> > |> I was dead asleep &/or on my 1st or 2nd walk of the day when you >> > |> posted to me, Angel, but now you know I have answered it. >> > |> >> > |> As Candlin & MEB verify, the NG possibly was under maintenance, which >> > |> does happen now/then. It used to happen more often. You should sleep >> > |> through it or go for a walk! >> > |> >> > |> For the OE icons/buttons, those are adjustable this way... Grab the >> > |> icon area or the menu area at the far left with the mouse. You will >> > |> see a two pointed arrow going horizontally through two vertical >> > |> lines after you start moving the mouse. Move the area up or down, >> > |> until the buttons show again. >> > |> >> > |> For the pop-ups, I think the others in the other thread are making >> > |> sense. As MEB said, post a HijackThis report, or at least... >> > |> >> > |> (1) "START button, Run, MSInfo32, Software Environment, Startup >> > |> Programs". >> > |> (2) Use the Edit menu to Select All & Copy. >> > |> (3) Post it here or there. >> > |> >> > |> Hopefully, as Terhune may have said, these pop-ups are an annoyance, >> > |> but not a real threat. Then, once it is identified, there could even >> > |> be an entry at... >> > |> >> > |> "START, Settings, Control Panel, Add/Remove Programs, >> > |> Install/Uninstall tab" >> > |> >> > |> ... that will remove it. >> > |> >> > |> | Let me know if this is >> > |> | going through. I have another question, The top of my Outlook >> > |> | express has changed the buttons were along the top, now they are at >> > |> | the bottom. Are there any settings that need to be readjusted? Or >> > |> | is it from the troubles with the Pop ups that has caused anything. >> > |> | The buttons are in a drop down button only marked with a >>. When >> > |> | I do a post they are across the top as they were. Angel >> > |> | "MEB" <meb@not here@hotmail.com> wrote in message >> > |> | news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... >> > |> |> >> > |> |> "Angel" <angel@noway.com> wrote in message >> > |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... >> > |> |> | Hi, >> > |> |> | I have a dilemma. I tried to post 3 times today to the >> > |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What is >> > |> |> | happening? Angel >> > |> |> | >> > |> |> | >> > |> |> >> > |> |> Good question, I have now tried six times to post a reply to PCR >> > |> |> in the firewalls discussion.. >> > |> |> >> > |> |> -- >> > |> |> MEB >> > |> |> http://peoplescounsel.orgfree.com >> > |> |> ________ >> > |> >> > |> -- >> > |> Thanks or Good Luck, >> > |> There may be humor in this post, and, >> > |> Naturally, you will not sue, >> > |> Should things get worse after this, >> > |> PCR >> > |> pcrrcp@netzero.net >> > >> > -- >> > Thanks or Good Luck, >> > There may be humor in this post, and, >> > Naturally, you will not sue, >> > Should things get worse after this, >> > PCR >> > pcrrcp@netzero.net >> > >> > >> >> > >
Guest Brian A. Posted August 1, 2007 Posted August 1, 2007 Re: Trying to post, no success. "PCR" <pcrrcp@netzero.net> wrote in message news:eyHvRB80HHA.536@TK2MSFTNGP06.phx.gbl... Here is the result... Complete scanning result of "Tiki Lounge.htm", processed in VirusTotal at 07/31/2007 23:55:33 (CET). [ file data ] * name: Tiki Lounge.htm * size: 370 * md5.: c5f4869d1805078ae115a7c5464b605f * sha1: b3990474983e89fa1af5d46cace22cc1a4494d39 [ scan result ] AhnLab-V3 2007.7.31.1/20070731 found nothing AntiVir 7.4.0.54/20070731 found nothing Authentium 4.93.8/20070731 found nothing I hope you don't have anything Authentium installed on your system, it's harder to get rid of than most viruses. I've helped a few out with it and believe you-me, it's no cakewalk picnic. -- Brian A. Sesko { MS MVP_Shell/User } Conflicts start where information lacks. http://basconotw.mvps.org/ Suggested posting do's/don'ts: http://www.dts-l.org/goodpost.htm How to ask a question: http://support.microsoft.com/kb/555375
Guest Gary S. Terhune Posted August 1, 2007 Posted August 1, 2007 Re: Trying to post, no success. Angel, Pick one of the CAB files that F-Prot says is "damaged". Then use WinZip to Extract all the files from that CAB file to a new folder. If you're successful, then there's nothing wrong with the file. -- Gary S. Terhune MS-MVP Shell/User http://www.grystmill.com "Angel" <angel@noway.com> wrote in message news:%23J31uD$0HHA.4184@TK2MSFTNGP06.phx.gbl... > PCR, > Well, earlier the Avast! did the automatic update. I just got done doing > the through w/Archives. Guess what? Nothing, no virus showed up and the > error for Win98_49 thing didn't show up. Now we have to figure out if the > F-Prot virus scan was right. Was it damaged or not. > Angel > > "Angel" <angel@noway.com> wrote in message > news:eXO1dX%230HHA.1100@TK2MSFTNGP06.phx.gbl... >> PCR, >> It was not in the chest. The first time it showed up, I deleted it. > then >> when I re-ran the Avast! it showed up again and I put it in the chest. >> BUT >> it is not there!! Mystery!! Now what? Looks like Avast! did a false > reading. >> Could F-Prot be doing a false reading also? Now I am going to go through > my >> routine and find out what happens. >> Angel >> >> "Angel" <angel@noway.com> wrote in message >> news:%23m5ZJQ%230HHA.464@TK2MSFTNGP02.phx.gbl... >> > Hi PCR, >> > I figured out how to use the browse and how to do it. I did it and >> only >> > one came up with something when I run the cab file F-Prot 4.3.2.48 >> > 2007.07.31 File is damaged. Now I will put the thing back and see what >> > happens. I hope that it will come out not damaged. Wish me luck. >> > Angel >> > >> > "Angel" <angel@noway.com> wrote in message >> > news:eF2%23Ej80HHA.4928@TK2MSFTNGP05.phx.gbl... >> > > Please explain what you mean by making a file? How is it done? Please >> > > explain in more detail. >> > > I found the thing under RunServices. So I know it is on the > machine. >> > > Angel >> > > >> > > "PCR" <pcrrcp@netzero.net> wrote in message >> > > news:uLHrwQ80HHA.1188@TK2MSFTNGP04.phx.gbl... >> > > Angel wrote: >> > > | Hi PCR, >> > > | The mk9908.exe is the drive for my Keyboard. It is in > C:\Windows. >> > > | It is a multimedia keyboard. >> > > | Smart Bridge is my SDL program. >> > > >> > > Alright. It shouldn't hurt to uncheck them just to test it. Some >> programs >> > > will include innocent pop-up ads. But probably it is something else. >> Post >> > > back to that other thread, then. There are good people in it! >> > > >> > > | There was only 1 LoadPowerProfile. I checked it out. >> > > >> > > >> > > You should have this one, too... >> > > >> > > LoadPowerProfile Registry (Machine Run) Rundll32.exe >> > > powrprof.dll,LoadCurrentPwrScheme >> > > >> > > To get it, use Notepad to make a file named "LPP.reg" from the >> > following... >> > > >> > > ......Start after this dotted line......... >> > > REGEDIT4 >> > > >> > > [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] >> > > "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" >> > > [END] >> > > ......End before this dotted line......... >> > > >> > > NOTE: You should get 5 lines. If more, there has been word-wrap. >> > > Don't >> run >> > > it, then. Post back, & I'll try something else. >> > > >> > > Then, R-Clk "LPP.reg", & select "Merge". Go look in MSInfo32 or > MSConfig >> > to >> > > confirm it is there. If so, you may delete "LPP.reg". >> > > >> > > | I did the Scans again Spybot found 3 drivecleaner.com cookies >> > > | under the title of winsoftware. >> > > >> > > Those couldn't be the problem, if it still exists. Didn't hurt to get >> rid >> > of >> > > the Cookies, though. >> > > >> > > | Avast! found a virus. Malware type VBS: Malware{HTML} Virus > worm >> > > | C:\Program Files\common files\Microsoft Shared\Stationary\Tiki >> > > | lounge. I deleted it. At the end of the scan, I had done a through >> > > | one. This showed up in the results of the scan: >> > > | C:\WINDOWS\OPTIONS\CABS\WIN98_49CAB\tiki.htm. >> > > | Infection:VBS:malware{HTML} Error occurred during moving file to >> > > | chest. Before trying to move it I tried to delete it. How do I get >> > > | rid of this malware? Now I think I found the culprit. Now lets get >> > > | it out of my machine. Angel >> > > >> > > That was a false alarm, as I posted separately. And with new defs, it >> goes >> > > away. Can you undo what avast! did to the file(s)? >> > > >> > > | "PCR" <pcrrcp@netzero.net> wrote in message >> > > | news:OVE5qKx0HHA.4652@TK2MSFTNGP05.phx.gbl... >> > > |> Angel wrote: >> > > |> | PCR, >> > > |> | I found the directions so here it is: >> > > |> | >> > > |> | SystemTray Registry (Machine Run) SysTray.Exe >> > > |> | ScanRegistry Registry (Machine Run) c:\windows\scanregw.exe >> > > |> | /autorun >> > > |> >> > > |> Those are fine. >> > > |> >> > > |> | Motive SmartBridge Registry (Machine Run) >> > > |> | C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe >> > > |> >> > > |> I doubt that is causing pop-up ads. Maybe uncheck it in MSConfig >> > > as > I >> > > |> said below. Reboot, & see whether it stops. >> > > |> >> > > |> | CHotKey Registry (Machine Run) mk9908.exe >> > > |> >> > > |> I'm not finding anything about pop-ups with mk9908.exe at Google. >> > > |> Yours looks odd, though, in that it doesn't mention a folder. What >> > > |> folder is mk9908.exe in? Are you sure it starts the way that line > is >> > > |> now? >> > > |> >> > > |> You can get the folder into that line using MSConfig. If it is a > LFN >> > > |> (Long File Name), you must surround it with quotes, or use the SFN >> > > |> instead. >> > > |> >> > > |> | avast! Web Scanner Registry (Machine Run) >> > > |> | C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE >> > > |> >> > > |> OK. >> > > |> >> > > |> | KB918547 Registry (Machine Service) >> > > |> | C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE >> > > |> >> > > |> | KB891711 Registry (Machine >> > > |> | Service) c:\windows\SYSTEM\KB891711\KB891711.EXE >> > > |> >> > > |> | LoadPowerProfile >> > > |> | Registry (Machine Service) Rundll32.exe >> > > |> | powrprof.dll,LoadCurrentPwrScheme >> > > |> >> > > |> Those 3 are fine. You should have 2 of LoadPowerProfile, though. > Did >> > > |> you uncheck one at "START button, Run, MSConfig, Startup tab"? > Then, >> > > |> re-check it. >> > > |> >> > > |> | APC_SERVICE Registry (Machine Service) C:\Program Files\APC\APC >> > > |> | PowerChute Personal Edition\mainserv.exe >> > > |> >> > > |> Hmm. I have an APC UPS (Uninterruptible Power Supply) plugged in, >> > > |> but I chose not to install the software. It works fine that way, > but >> > > |> I must close down, myself, within 20 minutes. It saved me several >> > > |> times. >> > > |> >> > > |> I doubt this would include pop-up ads. But, is it the last thing > you >> > > |> installed before they started? Then, maybe uncheck it at... >> > > |> >> > > |> "START button, Run, MSConfig, Startup tab" >> > > |> >> > > |> ..., reboot, & see whether they stop. >> > > |> >> > > |> | avast! Registry (Machine Service) C:\Program Files\Alwil >> > > |> | Software\Avast4\ashServ.exe >> > > |> >> > > |> OK. >> > > |> >> > > |> | Angel >> > > |> | >> > > |> | "PCR" <pcrrcp@netzero.net> wrote in message >> > > |> | news:O0SZ6Ov0HHA.748@TK2MSFTNGP04.phx.gbl... >> > > |> |> Angel wrote: >> > > |> |> | Meb, >> > > |> |> | I thought it was me. I maybe should retype what I just >> > > |> |> | typed to you. If this goes through I will.I tried to use >> > > PCR's >> > > |> |> | email at the bottom of his posts. But no answer. I wonder if > it >> > > |> |> | is his real email. Mine is different than the one in my >> > > posts. >> > > |> |> >> > > |> |> I was dead asleep &/or on my 1st or 2nd walk of the day when >> > > you >> > > |> |> posted to me, Angel, but now you know I have answered it. >> > > |> |> >> > > |> |> As Candlin & MEB verify, the NG possibly was under maintenance, >> > > |> |> which does happen now/then. It used to happen more often. You >> > > |> |> should sleep through it or go for a walk! >> > > |> |> >> > > |> |> For the OE icons/buttons, those are adjustable this way... Grab >> > > |> |> the icon area or the menu area at the far left with the mouse. >> > > |> |> You will see a two pointed arrow going horizontally through two >> > > |> |> vertical lines after you start moving the mouse. Move the area > up >> > > |> |> or down, until the buttons show again. >> > > |> |> >> > > |> |> For the pop-ups, I think the others in the other thread are > making >> > > |> |> sense. As MEB said, post a HijackThis report, or at least... >> > > |> |> >> > > |> |> (1) "START button, Run, MSInfo32, Software Environment, Startup >> > > |> |> Programs". >> > > |> |> (2) Use the Edit menu to Select All & Copy. >> > > |> |> (3) Post it here or there. >> > > |> |> >> > > |> |> Hopefully, as Terhune may have said, these pop-ups are an >> > > |> |> annoyance, but not a real threat. Then, once it is identified, >> > > |> |> there could even be an entry at... >> > > |> |> >> > > |> |> "START, Settings, Control Panel, Add/Remove Programs, >> > > |> |> Install/Uninstall tab" >> > > |> |> >> > > |> |> ... that will remove it. >> > > |> |> >> > > |> |> | Let me know if this is >> > > |> |> | going through. I have another question, The top of my > Outlook >> > > |> |> | express has changed the buttons were along the top, now they >> > > |> |> | are at the bottom. Are there any settings that need to be >> > > |> |> | readjusted? Or is it from the troubles with the Pop ups that >> > > |> |> | has caused anything. The buttons are in a drop down button > only >> > > |> |> | marked with a >>. When I do a post they are across the > top >> > > |> |> | as they were. Angel "MEB" <meb@not here@hotmail.com> wrote in >> > > |> |> | message news:uQgQEdt0HHA.1168@TK2MSFTNGP02.phx.gbl... >> > > |> |> |> >> > > |> |> |> "Angel" <angel@noway.com> wrote in message >> > > |> |> |> news:ehw8x5s0HHA.4652@TK2MSFTNGP05.phx.gbl... >> > > |> |> |> | Hi, >> > > |> |> |> | I have a dilemma. I tried to post 3 times today to > the >> > > |> |> |> | string, "Error Alert?" NO SUCCESS So trying again!! What >> > > is >> > > |> |> |> | happening? Angel >> > > |> |> |> | >> > > |> |> |> | >> > > |> |> |> >> > > |> |> |> Good question, I have now tried six times to post a reply >> > > to >> > > |> |> |> PCR in the firewalls discussion.. >> > > |> |> |> >> > > |> |> |> -- >> > > |> |> |> MEB >> > > |> |> |> http://peoplescounsel.orgfree.com >> > > |> |> |> ________ >> > > |> |> >> > > |> |> -- >> > > |> |> Thanks or Good Luck, >> > > |> |> There may be humor in this post, and, >> > > |> |> Naturally, you will not sue, >> > > |> |> Should things get worse after this, >> > > |> |> PCR >> > > |> |> pcrrcp@netzero.net >> > > |> >> > > |> -- >> > > |> Thanks or Good Luck, >> > > |> There may be humor in this post, and, >> > > |> Naturally, you will not sue, >> > > |> Should things get worse after this, >> > > |> PCR >> > > |> pcrrcp@netzero.net >> > > >> > > -- >> > > Thanks or Good Luck, >> > > There may be humor in this post, and, >> > > Naturally, you will not sue, >> > > Should things get worse after this, >> > > PCR >> > > pcrrcp@netzero.net >> > > >> > > >> > >> > >> >> > >
Recommended Posts