|
Theme Problems with Vista
|
|
Topic Started: Nov 11 2008, 03:31 PM (1,312 Views)
|
|
Phlip
|
Nov 16 2008, 07:34 AM
Post #31
|
- Posts:
- 51
- Group:
- Members
- Member
- #41
- Joined:
- April 30, 2008
|
There was nothing about VistaOSX in msconfig.
Even if there WAS, I still wouldn't know if I had removed it because I deleted the docklets.
|
|
Oh my ѕσυℓ. ™ © ®
|
| |
|
FearKiller
|
Nov 16 2008, 10:29 AM
Post #32
|
- Posts:
- 16
- Group:
- Members
- Member
- #45
- Joined:
- November 11, 2008
|
Ok. So what about the "VistaOSX09" folder on the C drive?
C:\VistaOSX09\
Is that still in existence? Did you check under the "Autoruns" tab in System Explorer for startup items related to VistaOSX? Can you post the HiJackThis log?
|
 FearKiller.net ~ FearKiller Boards ~ FearKiller Blog
|
| |
|
Phlip
|
Nov 16 2008, 10:42 AM
Post #33
|
- Posts:
- 51
- Group:
- Members
- Member
- #41
- Joined:
- April 30, 2008
|
- FearKiller
- Nov 16 2008, 10:29 AM
C:\VistaOSX09\
Is that still in existence? Did you check under the "Autoruns" tab in System Explorer for startup items related to VistaOSX? Can you post the HiJackThis log? Yes, but it doesn't work properly. Yeah, nothing related to VistaOSX What would be the log? There's no window titled with the word log on it.
|
|
Oh my ѕσυℓ. ™ © ®
|
| |
|
FearKiller
|
Nov 16 2008, 10:57 AM
Post #34
|
- Posts:
- 16
- Group:
- Members
- Member
- #45
- Joined:
- November 11, 2008
|
Rename the "VistaOSX09" folder to "VistaOSX09.BAK" and try in Safe Mode if it won't let you in regular Windows.
After you install Trend Micro's HiJackThis you'll want to select the option that says, "Do a system scan and save a logfile." Once the scan is done, it will pop up a notepad with the log file inside. Just copy and paste all the contents of the log file here so that we can go through it.
|
 FearKiller.net ~ FearKiller Boards ~ FearKiller Blog
|
| |
|
Phlip
|
Nov 16 2008, 11:01 AM
Post #35
|
- Posts:
- 51
- Group:
- Members
- Member
- #41
- Joined:
- April 30, 2008
|
Renamed the file folder. Contents of notepad:
- Code:
-
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:41:08, on 16/11/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal
Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Windows\System32\rundll32.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe C:\Windows\System32\spool\drivers\w32x86\3\E_FATICDE.EXE C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe C:\VistaOSX09\RKLauncher.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Windows\System32\mobsync.exe C:\Windows\System32\rundll32.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe c:\program files\logitech\quickcam\lu\lulnchr.exe C:\program files\logitech\quickcam\lu\LogitechUpdate.exe C:\Program Files\System Explorer\SystemExplorer.exe C:\Program Files\Paint.NET\PaintDotNet.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.packardbell.com/?id=9067 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\Windows\TEMP\E_S5AEC.tmp" /EF "HKCU" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: Dock.lnk = C:\VistaOSX09\RKLauncher.exe O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
-- End of file - 8762 bytes
|
|
Oh my ѕσυℓ. ™ © ®
|
| |
|
FearKiller
|
Nov 16 2008, 12:56 PM
Post #36
|
- Posts:
- 16
- Group:
- Members
- Member
- #45
- Joined:
- November 11, 2008
|
Great, it does show up. Now, run HiJackThis again and select the, "Do a system scan only" this time. Once it goes through its scan just find the following entry in the list.
- Code:
-
O4 - Startup: Dock.lnk = C:\VistaOSX09\RKLauncher.exe
Click the check box to select the item and then click the "Fix Checked" button. Answer yes to all the are you sure yada yada yada pop-ups. Restart the PC and let me know if the VistaOSX dock is gone.
|
 FearKiller.net ~ FearKiller Boards ~ FearKiller Blog
|
| |
|
Phlip
|
Nov 16 2008, 12:59 PM
Post #37
|
- Posts:
- 51
- Group:
- Members
- Member
- #41
- Joined:
- April 30, 2008
|
Done. But there was only one pop-up. As I said, since I deleted the docklets, I won't be able to tell whether it's gone or not.
Gonna restart now.
|
|
Oh my ѕσυℓ. ™ © ®
|
| |
|
FearKiller
|
Nov 16 2008, 02:46 PM
Post #38
|
- Posts:
- 16
- Group:
- Members
- Member
- #45
- Joined:
- November 11, 2008
|
Ok now I'm confused... Didn't you say the dock was still showing up? If the dock is no longer showing up and no signs of VistaOSX are on your system, then you're pretty much good to go. Since the program didn't have a proper uninstaller, you won't see anything that says something along the lines of uninstalling VistaOSX.
|
 FearKiller.net ~ FearKiller Boards ~ FearKiller Blog
|
| |
|
Phlip
|
Nov 16 2008, 02:49 PM
Post #39
|
- Posts:
- 51
- Group:
- Members
- Member
- #41
- Joined:
- April 30, 2008
|
All I did was delete the items on the dock. What I'd like to do is know that I have it uninstalled as I may aswell have some extra space or w/e.
|
|
Oh my ѕσυℓ. ™ © ®
|
| |
| 1 user reading this topic (1 Guest and 0 Anonymous)
|