:
Hi John,
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html
Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html
Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/
After the scan run disk cleanup on your drive.
2- Download the Hijackthis and send the report to one of many
forums for analysis and troubleshooting:
http://www.merijn.org/index.php
When all else fails, HijackThis v2.0.2
(
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis) is
the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. Post
your log to
http://aumha.net/viewforum.php?f=30,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7, or other appropriate
forums for expert analysis, not here.
Or you can send me the Hijacklog here: to_you_ross(at)yahoo.co.uk
Events Error Analysis inline:
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 17/01/2008
Time: 12:20:18
User: N/A
Computer: TRADING
Description:
The PC Tools Security Service service failed to start due to the following
error:
The service did not respond to the start or control request in a timely
fashion.
Spyware doctor application is hanging on Shutdown, due to the application
damaged or system lack of disk space and memory.
=========================================
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 17/01/2008
Time: 12:20:18
User: N/A
Computer: TRADING
Description:
Timeout (30000 milliseconds) waiting for the PC Tools Security Service
service to connect.
The Spyware doctor not able to connect to the internet and get updates.
This can be caused by faulty or mismatched RAM, or a damaged pagefile
=========================================================
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 17/01/2008
Time: 12:20:18
User: N/A
Computer: TRADING
Description:
The PC Tools Auxiliary Service service failed to start due to the following
error:
The service did not respond to the start or control request in a timely
fashion.
= The Application didn't release the memory in usage back to the system
causing the error to occur in the event viewer and the application to hang!.
=====================================================
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 16/01/2008
Time: 22:07:30
User: N/A
Computer: TRADING
Description:
TCP/IP has reached the security limit imposed on the number of concurrent
TCP connect attempts.
Remove the limit on TCP connection attempts
http://www.speedguide.net/read_articles.php?id=1497
==================================
Event Type: Error
Event Source: Application Hang
Event Category: None
Event ID: 1001
Date: 11/01/2008
Time: 13:49:05
User: N/A
Computer: TRADING
Description:
Fault bucket 482051222.
Bad RAM or corrupt pagefile?.
================================
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 04/01/2008
Time: 02:26:21
User: NT AUTHORITY\SYSTEM
Computer: TRADING
Description:
Windows saved user TRADING\John Lester registry while an application or
service was still using the registry during log off. The memory used by the
user's registry has not been freed. The registry will be unloaded when it is
no longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
= It depends on the running service at the time?.
HTH.
nass