PhilliePhan 171 Central Scrutinizer Team Colleague

I like external hard drive + DVD backup for stuff I really want to save. Both my brother and a friend have had external hard drives get dropped on the floor and stop working - in my friend's case, he had to have the data recovered by a shop that specialized in such matters. Ugh.
It is pretty darn easy to build images of large numbers of files and burn them to DVD that way.

PP :)

PhilliePhan 171 Central Scrutinizer Team Colleague

Just wanted to add my $.02...

My solution is to build an .ISO (image) of the files I want to transfer and then burn the ISO to DVD.
You can use the freeware ImgBurn to both build the ISO and burn it.
Works great.

PP :)

PhilliePhan 171 Central Scrutinizer Team Colleague

MalwareBytes Anti-Malware is NOT an anti-virus program! Rather, it is designed to be used in concert with a resident AV such as Avira or Kaspersky and the like.

PhilliePhan 171 Central Scrutinizer Team Colleague

I would suggest ruling the touchpad out 100% by disabling it in Windows:
http://www.pcworld.com/article/204693/Disable_Your_Laptops_Touchpad_While_You_Type_Windows_7_Edition.html

Give that a go and let us know if the trouble persists.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

I'm not sure what you are getting at.

Locate.com searches using the 8.3 file names, but there are a ridiculous number of switches and macros you can use to weed out the stuff you don't want.

The OP could simply run Locate.com with no switches and get the output he desires. The /L switch would give the long file name. Better yet, locate /O:"&W" would provide a bare list in long name form.
I used it mainly with batch files to pinpoint files created during a certain time and then to filter that list. Great for malware hunting.

But I'm rambling. As far as wild card searches go, I've always been able to filter out the stuff I don't want either via the switches and macros or via a few extra commands.

I am not as up-to-date as I used to be, so I don't know if there is a better alternative to Locate.com floating around these days, but somehow I doubt it :) - at least not free....

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Hey guys,

Sorry I missed this thread, but one of my favorite old freeware tools (Charles Dyes's Locate.com) ought to do the trick.
It is ridiculously useful!

Here's how to use it:
ftp://ftp.scientificlinux.org/linux/fermi/obsolete/90rolling/i386/misc/superduperrescue/fermi/FREEDOS/FDOS/DOC/LOCATE/LOCATE.TXT

Finding it for download may be a bit harder - If all else fails, I can provide a copy.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi jaydee2,

Give AVG Remover a try to see if that does the trick.

Best Luck :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

As far as I know, Softpedia offers only the service pack (SP3) for download and not a free version of Windows.

PP:)

PhilliePhan 171 Central Scrutinizer Team Colleague

Just to add:
If you believe her machine is infected with malware, then you should not start with service pack(s) - You need to make sure the machine is free of malware before installing the service packs.

--- You could try to run some of the tools in the* Read Me* Sticky and post the scanlogs, but we really don't have a lot of qualified volunteers to read the logs any more.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Thanks again for all your help! :-)

Happy to try to help! :)
I definitely prefer Firefox / Opera / Chrome or any other alternative browser to IE. I like Firefox the best as far as being able to customize it with a million add-ons.

Unfortunately, switching browsers is not really a solution to the problem.
Let me know if IE keeps opening on its own or if Firefox starts exhibiting this behavior.

-- Did you get any error message when uninstalling combofix?

PP :)

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi Claudia,

I do not see anything there that could be responsible for your IE issues.
-- Please follow the steps in the linky below to remove combofix from your machine:
Uninstall Combofix
Let me know if you have any trouble with this since you did not run combofix from the Desktop.

Have you tried any of my other suggestions? If not, give these a go:
Reset IE as per the linky and see if that helps. I suggest doing this manually as per the link rather than downloading the automated fix.

If that fails, Install Firefox and make sure it is set as your default browser and then let me know if IE still opens on its own or whether Firefox now opens on its own.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Semantics.

No. Not at all.
But, if that's your interpretation, so be it.

PhilliePhan 171 Central Scrutinizer Team Colleague

It can be used to enable/disable programs to start automatically.

Yeah. That's called diagnostic startup for a reason. :)

Meh. It's not worth arguing about.
My friend chaslang sums it up pretty well here Dealing with Startup Processes.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Msconfig is a diagnostic tool and not a "startup manager."

You should try something such as CodeStuff's Starter to manage your unwanted startups.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

However while searching through my programs I discovered that I have two Internet Explorer icons on under Computer\Local Disk(C:)\Program Files and the other under Computer\Local Disk (C:)\Program Files (x86).

That is normal for your computer (64-bit Win7). No worries there.

Also recently my HP Connection Manager has been given me an error message when it tries to launch. I Not really sure what the program does but perhaps this is causing an issue or has been comprised.

I do not know - I do not think it is part of the problem. What is the error message?

when it hit up against a file during the scan that caused Iexplorer to launch it didn't complete the scan
Did you see what file that was? That would help if we could pin it down.

Let's also go ahead and run combofix and see what shakes out.
Please follow the steps in this linky very carefully and run combofix as it directs.
Please post the resulting log for me and we'll work from there. Let me know if you run into any problems along the way.

PP:)

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi Claudia,

The log doesn't show any obvious culprit. If a separate program is launching IE, it is not showing.
I doubt it is malware, but let's try one more scan:
Please run the ESET Online Scanner and post the scanlog for me.

If that comes back completely clean, you can try a couple more things:
-- Reset IE as per the linky and see if that stops the problem. I suggest using doing this manually as per the linky rather than downloading the automated fix.
-- If that fails, please Install Firefox and be sure to set Firefox as your Default Browser.
Then, let me know if IE still opens by itself (or, if Firefox opens by itself) and we'll go from there.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Have i got a virus or not?

No. Not a virus.

Your keyboard "cleaning" probably resulted in a few stuck keys including the "Win" key that triggers other shortcuts or "Hotkeys."
Hotkey List

You can verify this by trying a different keyboard.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

If that is the case, then it must be a setting or support issue with CD-Text. This means one of two culprits: Burning program or Optical drive.
If you are using all of the same programs and settings, it could very well be the drive. Perhaps the firmware needs to be updated or a setting needs to be changed. You ought to be able to ID your drive model and manufacturer and look up whether the drive supports CD-Text.

I am really not too familiar with CD-Text, but this sounds like something you might be able to pin down through trial and error.
Sorry I can't be more help :)

PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Thank you so much in advance for helping me out and getting this resolved. I really appreciate it.

Hi Claudia,

Happy to try to help :)

Those scanlogs look clean to me.
Let's see if we can isolate what is launching Internet Explorer.

Please download Process Explorer from the linky below.
http://download.sysinternals.com/files/ProcessExplorer.zip

-- Extract the Process Explorer Folder from the ZIP and onto the Desktop.
-- Open the foder and run Procexp.exe.

Just leave PE open and running until Internet Explorer launches on its own. Once IE opens, you should be able to see it reflected in the Process Explorer window. If you were to launch IE yourself in the usual manner, it will be located in the tree under Explorer.exe (which is Windows Explorer).
If something else launches it, IE will be in that tree, under the program that launched it.

Anyhoo, once Internet Explorer launches on its own, please click the File tab in in the upper left of the Process Explorer window and select Save As and save the log to the desktop as PE Log 1 and please post that for me.

Let's see if that shows us what is launching IE.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Can you run the scans in the linky below and post the requested logs?

http://www.daniweb.com/hardware-and-software/microsoft-windows/viruses-spyware-and-other-nasties/threads/134865/read-me-before-posting-a-request-for-assistance

We no longer have any regular volunteers in this section, but I'll have a look as time permits.
Ideally, I'd just like to see an updated MBAM scanlog along with the DDS scanlog. If you can post the error messages you mentioned as well, that might help too.

-- Also, you should probably ditch ARO 2012. Registry cleaners are generally unnecessary and often do more harm than good. The other things it does can be done manually or with better, and free, tools.... Just my $.02 there.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Are you making "mp3" CDs? If you burn the mp3s to CD as "data," the tags should be fine.

If not, then the issue could be with CD Text not being supported somewhere along the line.....

PP:)

PhilliePhan 171 Central Scrutinizer Team Colleague

is there any way that I can do this?

That is not really feasible. A well-protected computer will shut that down before it has a chance to run.
Since there has been so much malware over the years that propagated via flash drive and autorun, security measures today commonly disable and actively block it.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

I now have a usable keyboard. I used to have to hook up another keyboard to be able to type. Now I won't have to - thank you!!! ** :-) **

Thanks for the feedback, Karen.
Glad you finally got it sorted out! :)

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi Glenn,

Welcome aboard!

PP:)

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi Jenn,

Burning the ISO to CD is best rather than going the USB route.
Once you have the Ubuntu CD burned, pop it into the ill compy and fire it up. You ought to be able to boot the CD without having to adjust the BIOS.
Your compy should give you the choice to boot from optical drive (or it may go ahead and boot Ubuntu automatically).
Anyhoo, select the option to Try Ubuntu without any change to your computer - We do not want to install Ubuntu.

Then, click the Places tab and navigate to the files you want to copy and you should be able to Copy&Paste or Drag&Drop them to your external hard drive.

Let me know if you have any problems. Once you get your files copied, we can have a whack at cleaning the machine.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi Nanci,

What did the log say after you ran the System Readiness Tool?
-- C:\Logs\CBS

If that doesn't give you a lead on why the fix failed, I'd just go ahead with the Recovery Partition option - a repair install may not fix the issue and, since you've backed up the customer's data, you may as well save more headaches and just go with the destructive recovery.

Just my $.02

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

System Restore is not a viable option at this point given that the machine hangs on boot - That's why I wanted to use the Ubuntu boot CD to gain access.
But, you are on the right track as it is likely a corrupted registry causing the problem.

Frankly, in cases such as this, utilizing the recovery partition or OS disk to reinstall OS is fastest/easiest way to proceed. Jenn can use the Ubunto CD to transfer all the data she wants to save to her external HD before reinstalling windows.
If she comes back, I'll be happy to talk her through it :)

PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi Jenn,

There's still plenty we can do - depends which way you want to go. Lately, I prefer reformat with rootkitted malware. It's faster and a complete fix.
But, that's not always feasible these days.

Let's try a few things first. At the very least, we can get all of your important data transferred to external hard drive before we try any sort of destructive recovery.

---- Do you have a Windows OS disk?

---- On a working compy, please go here and download Ubunto Desktop -->
http://www.ubuntu.com/download/desktop

Download the 32-bit .iso file and burn it to CD as per the steps here (if you don't already have a preferred method for burning .iso) -->
http://www.ubuntu.com/download/help/burn-a-cd-on-windows

We can go from there. Let me know how the above goes.

I'll be around off and on over the weekend. I am not as active these days in the forum, but I'll keep an eye on this thread.

Cheers :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Hi Jenn,

-- What is your OS? 7/XP/Vista? 64 or 32 bit?

**Give Malwarebytes another try and see if it runs. **
-- If not, we'll have to go ahead and reboot your machine and then try MBAM again.
-- If that fails, reboot to Safe Mode by tapping F8 on reboot and try to run MBAM in safe mode.

Let me know how you fare with the above. If MBAM does run, please post the scanlog for me. If no, then we'll take another tack.

Also, do you have another computer you can use to burn a CD?
Let me know.

Best Luck :)
PP

PhilliePhan 171 Central Scrutinizer Team Colleague

Welcome and congratulations to all! :)