Computer Repair and PC Support across the UK

As Featured in the Guardian

Free Computer Support Forum

Hardware Related Issues

Topic:

White Screen

Posted by: Linda S.      22 Jul 2009 @ 10:52
White Screen

Have Advent 5712, Vista Home Premium. About 10 mins after switching on computer, the screen goes white, nothing on it.If I access start, a box appears on bottom bar which allows me to close white window.How do I stop or cancel it coming up?

Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      22 Jul 2009 @ 18:00
RE: White Screen

The way to stop or cancel it is to find the root cause and address that. Next time it happens, press the Ctrl Shift and Esc keys simultaneously to launch Task Manager. Click the Applications tab (if necessary) and make a note of what applications are running. Then reply here listing them.

23 of 41 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      22 Jul 2009 @ 18:15
RE: White Screen

Thanks I'll try that. I have more details: The name in bottom bar says:Blank page window.When I right click on it, a board comes up with
Restore which you cannot click on
Move " " "
Size " " "
Minimize which I have option to click
Close " " "
I have been clicking on close and it disappears and goes back to normal desktop.
Next to where it says Blank,is the e internet symbol!!!!!!!!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Arjun A. PCIQ IT ProfessionalIT Professional in Slough, SL3      22 Jul 2009 @ 19:25
RE: White Screen

That seems to be an internet explorer problem.

1) Click on start
2) All programes

Then look for a folder called startup and see if it has explorer there, if it does, u can delete it and stop it from starting when windows does

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      22 Jul 2009 @ 20:03
RE: White Screen

Thanks Arjun. Did what you said.This is what it says under Start Up:Launch,One Note Screen Clipper, and OSD ( I dont know what OSD is?)No mention of Explorer!!!!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Arjun A. PCIQ IT ProfessionalIT Professional in Slough, SL3      22 Jul 2009 @ 21:17
RE: White Screen

Hi Linda,
Try this link.
http://download.cnet.com/NoAds/3000-7786_4-10139685.html

Download this programme and install it. Then run it, BUT DO NOT close the about blank window. Let windows boot up and start the programme. Then click on the window and click on block. Try that.

Let me know how you get on. If you need any further help, just drop a message back

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      22 Jul 2009 @ 21:34
RE: White Screen

Hang on a minute, Arjun. The CNET Editor's Review of the program you recommend is far from enthusiastic. It would be better to understand the cause of the problem than just trying to treat the symptom. Clearly some program is going wrong. It could be a legitimate program or it could be malware that has found its way onto the computer.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Arjun A. PCIQ IT ProfessionalIT Professional in Slough, SL3      22 Jul 2009 @ 22:27
RE: White Screen

Hi Alan. Yes your right. It could be either a proper programe that is not working properly or malware.

However this is an Internet explorer problem. And im thinking along the lines of malware/spyware/virus. But that programme works well, because i have had a similar problem before

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      22 Jul 2009 @ 22:36
RE: White Screen

1) Aruns tool suggestion is bad advice as modern versions of IE has a popup blocker - this piece of junk software dates from the days of IE5. You'd be better off installing the Google toolbar than this..
2) the problem is almost certainly malware related and you are not going to fix the problem without addressing that. The machine needs sanitising. The program Arun suggested is NOT going to do that

Given the nature of the symptoms I do not believe this one is a "do it yourself" fix - call in help

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      23 Jul 2009 @ 00:36
RE: White Screen

My Norton security scans every day and stops anything and everything, so dont think its a virus or similar. I was on MSG earlier and kept getting disconnected from the internet, and although i dont know much, from the way the computer is behaving would think it has something to do with the net. I get error pages whilst on web sites, Norton approved ones only. Only go on 1 or 2 anyway. I havnt tried the Task manager thing yet, so will try later today. will let you know if it helps. Thanks.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      23 Jul 2009 @ 01:07
RE: White Screen

" My Norton security scans every day and stops anything and everything "

it may scan every day, but it does not stop "anything and everything". In fact Norton may stop common virii, but it does little for more sophisticated studd (like rootkits, spyware, broswer hijacks). Most of the machines we have to clean have Norton or Symantec security software on them. I'm afraid you are suffering from the same misapprehension that assumes that because you've locked the door you won't get burgled...

By the way,if you follow Arjun's advice and disable explorer.exe from loading at startup, then Windows wont start. Serious piece of garbage information there: the executable for Internet Explorero is iexplore.exe, not explorer.exe

Explorer.exe is the windows interface shell. Stop it loading and you've got no windows

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      23 Jul 2009 @ 08:43
RE: White Screen

Linda
I see you have placed a work order with me - however I've had to decline the job s you are in London, while I am in north Lancashire.
Distance makes it unworkable. I have mailed the admins asking them to reallocate the job to someone more local, but if you hear nothing by lunchtime please place another work order on the system, but using the !quickmatch" feature rather than specifying a specific agent

thanks

Jon

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Michael D. PCIQ IT ProfessionalIT Professional in Chorley, PR6      23 Jul 2009 @ 09:19
RE: White Screen

Linda

The vast majority of computers I see which are infected with viruses have Norton installed, updated and "working". It is an exceptionally popular piece of anti-virus software, of course, which may be why I see so many machines with both Norton and viruses.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Arjun A. PCIQ IT ProfessionalIT Professional in Slough, SL3      23 Jul 2009 @ 09:48
RE: White Screen

Jon, Thanks mate for clearing that up. I ment iexplorer and not the explorer which contains the main windows.

Thanks once again, and being here among people like you, is really helping me improve my diagnosis and solutions which i give to others.

Thanks once again

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      23 Jul 2009 @ 11:36
RE: White Screen

Jon, sorry it was not me who placed a work order. I notice there is another Linda S on here, so maybe her!!! I have just turned on my computer, everything ok for 4 mins then the Blank page came on. Alan B, i tried the ctrl,shift,esc as you suggested and all that happened was, on the bottom bar, this came up: Internet Blank Page Window.I right clicked and as usual got the little box, as I stated above. So I clicked on close and and it went. It seem to come up 3 or 4 times a day.What is an internet blank page window?

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      23 Jul 2009 @ 13:41
RE: White Screen

Linda, it is not clear from your reply if Task Manager started. If not you almost certainly have a virus that has tampered with your system settings.

What could be happening is that some malware has infected Internet Explorer causing a pop-up Window. Something, maybe your Norton, is blocking the contents from loading but is not smart enough to stop it happening completely. Can we be completely clear, are you always running Internet Explorer (i.e. surfing the web) when this happens?

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      23 Jul 2009 @ 14:49
RE: White Screen

No Alan, it comes up when i switch on computer about 4 mins later, no programmes running.Came on last night when I was on Live MSG. I have just been on to Norton support who say that Messenger is causing the problem, he saw it for himself as he took over my computer. He told me to contact Microsoft and tell the. Thats a pain in the neck, trying to get them, except by phone, which costs a fortune.I'll try this evening when its cheaper, and I'll let you know what they say!! Thanks

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      23 Jul 2009 @ 15:31
RE: White Screen

I do not think that Microsoft offers telephone support for Windows Live programs like Windows Live Messenger. I could be wrong but it is a free program, after all. Let us know how you get on.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Robin N. PCIQ IT ProfessionalIT Professional in Watchet, TA23      23 Jul 2009 @ 17:15
RE: White Screen

My thoughts on this problem (sorry I've only just caught up with the thread)

1. Messenger is still a portal to the internet so it's virtually the same as using a browser and subject to similar fault conditions. Linda, have you tried setting messenger to NOT start up when windows starts? (Look in settings/connection)

2. Have you tried uninstalling Messenger from Add/Remove programs in Control Panel?

3. If either of these things result in your PC staying on after a reboot without falling to a white screen then you have almost solved the problem at zero expense. It may still be possible that malware is to blame and that will still need to be removed, but if it's simply a corrupt Messenger installation and everything seems normal after disabling / uninstalling it, then it will be a simple matter to download and re-install later to see if it's any better.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      23 Jul 2009 @ 17:26
RE: White Screen

Thanks Robin I will give it a try.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Barry  D.      23 Jul 2009 @ 20:22
RE: White Screen

Why not use msconfig and stop all the progs from loading and then see if it still happens? You can switch them back on one by one if that works so you can find the culprit.

I would also recommens spybot but be careful where you download it from I would recommend
http://download.cnet.com/Spybot-Search-amp-Destroy/3000-8022_4-10122137.html
or
http://www.filehippo.com/download_spybot_search_destroy/
and don't forget to update it and take a copy of the registry - it asks if you want to.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      23 Jul 2009 @ 20:41
RE: White Screen

Thanx Barry D. I've done as Robin N suggested and stopped Messenger from launching.So far so good, no Blank page!!If that doesnt work I will try your suggestion. I'm not very knowledgable about computers so the less I have to do the better.What would we do without all you guys! You are all much appreciated!!Will keep you posted.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      24 Jul 2009 @ 01:43
RE: White Screen

Linda
by disabling programs you are just papering over the cracks. I believe you have some serious malware on your machine
I strongly advise you get someone to look at this machine
If you object to paying for help, download, update and run Malwarebytes Antimalware tool and delete everything it finds
Then post back - we need to run HijackThis! afterwards - you'll get the details when you post back after the Malwarebytes program, which you can download from
http://www.malwarebytes.org/
(big blue button on left, labelled "download free version"
Note if you follow Barry D's advice and disable ALL with device manager, then all your security software will be disabled - so next time you go online you will get even more virused

Get someone in to sort this machine for you

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 11:08
RE: White Screen

Jon S. It is not that I object to paying, I am a Pensioner, and can't afford to do so at present!
I havn't disabled anything else!! I will try your suggestion! I'll get back to you.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 11:37
RE: White Screen

Jon S. Have just been to site you suggested, and there is no big blue button for free download.Just orange button saying download now????At the bottom of my laptop there is a small panel with symbols, 4 symbols, thefirst is swtchon showing green, second is wireless showing green 4th is int.con. showing green. The third symbol(I dont know what this is,looks like a battery with arrow) is flashing orange. I have never used comp on battery, always plug in.It says 98% on toolbar icon.Does the battery run down even though you plug in?? And is that flashing orange symbol in fact the battery. I really dont know how the computer companies can supply these without a manual, are we (newbies) supposed to guess at these things?? I await your reply. Thanks

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      24 Jul 2009 @ 13:14
RE: White Screen

I went to http://www.malwarebytes.org/ (by copying the link and pasting it into the address bar of my internet browser the pressing the Enter key. There IS a big blue button on the left of the screen that says 'Download free version'. I think you should try again.

Were you actually using the the Windows Live Messenger program you disabled to get rid of the white screen? Messenger is generally more popular with teenagers than pensioners.

I wouldn't get preoccupied with what all the lights on your computer fascia mean. They are only useful as indicators when your computer hardware isn't working properly. Your computer may have some software problems but there is nothing to suggest the hardware isn't working.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by:  .      24 Jul 2009 @ 13:25
RE: White Screen

Alan B. LOL Yes I was using MSG to talk to old school friends I had just found on FR, and none of them are teenagers!!!!!! I dont know what copy link and paste into address bar of Int.browser means. Can you tell me step by step exactly what to do? I may be a pensioner but, I am young at heart!!!!!!!!!! Thanks

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 15:17
RE: White Screen

ALAN B. Scap my last post. I managed to find it another way.
JON S. I downloaded Malware, the ran a full scan. The result was :3 Registry keys were infected.Adware My Web,current software user.Trojan BHQ Hkey classes root, and Trojan BHQ url search hook. There was an option to remove these and I clicked it.What next, or is that it???

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 16:03
RE: White Screen

BLANK WINDOW: Further to previous post: Having run the Malware and removed infected keys, I switched off and rebooted computed. After 4 mins it is still coming on!!!!! Although it doesn't come on at any other time, so far. Only after I switch on computer, desk top is up, 4mins later, there it is???????????????????????

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Steve R. PCIQ IT ProfessionalIT Professional in Wallsend, NE28      24 Jul 2009 @ 18:02
RE: White Screen

Hi Linda.

Having read through all the comments on this page and also done ssome background checking on the interent (whist at work) can i ask, are you running Windows vista with Internet Explorer 7 (the one that comes with vista) ?

If so, you are not alone, the problems you are experiencing are common with this setup, ALT+F4 will close the window and it won't re-appear again until you next switch the machine back on.

I have seen this issue before and resolved it by restoring the PC (using system restore) to a point when a number of updates were installed. It seems to be linked to an update and don't think it is spy/malware but as everyone above has said, running a scanner on a regular basis is always good advice.... i'll do some more digging and speak to some of my colleagues who work for Microsoft and see what i hear back. I'll be in touch.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Steve R. PCIQ IT ProfessionalIT Professional in Wallsend, NE28      24 Jul 2009 @ 18:10
RE: White Screen

Okay, that was quick..... My colleage at MS suggested following this procedure to eliminate at programs causing the issue.

http://support.microsoft.com/kb/331796

Copy and paste the above link into your browser window and click go.

Secondly, he also mentioned at the 4min delay may be the time taken to complete loading all the background tasks into memory.

You could also try using a 3rd party browser such as firefox and see if you get the same issues.....

Steve Rae

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 19:55
RE: White Screen

Steve: I have been on to Tech Guys, and Barry D had the right idea.In System Configurations Start box,I was told to eliminate programmes one by one until I find the one causing the Blank window to launch. So far, so good, No Blank window.I have narrowed it down to 4 progs.I still have to elininate these one by one.Also Tech Guy noticed that Norton was not in there and should have been!!This I have rectified with Norton.I will report back when I find out which of the 4 is causing the blank window to Launch......Thanks

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      24 Jul 2009 @ 20:03
RE: White Screen

Oh Linda, don't mention The Tech Guys here. They are not our friends! Don't tell me you got talked into buying some sort of service contract with them: and you a poor pensioner?!?

20 of 40 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      24 Jul 2009 @ 20:05
RE: White Screen

By the way, I bet you hold the record for the greatest number of PCIQ Professionals trying to help you!

20 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 20:28
RE: White Screen

ALAN B....No you are wrong.It cost me a phone call. I only got my computer in June,2009, so it is still under guarantee.I detect sarcasm in your report???I came to you guys first and am grateful for the help you all give.Norton help comes with the product.Microsoft dont give help! I phoned currys where I bought this laptop.THEY put me through to Tech Guys.I never take anything for granted and always appreciate help. I know virtually nothing about computers, I am doing my best here.I am sorry you feel that way!!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Michael D. PCIQ IT ProfessionalIT Professional in Chorley, PR6      24 Jul 2009 @ 21:40
RE: White Screen

Linda, Please don't take this comment as being at all cheeky, but if you bought a car you would find it came with a manual, but it would cover only the basics and wouldn't try to cover every possible problem. You would also learn to drive it, but not how to fix it.

Computers are very similar to cars:
Both are vital tools
Both are used every day
You don’t really know how they work
You hope neither of them suddenly crashes
Both are essentially tin boxes with Windows
Regular servicing reduces breakdowns of both.

Just as you'd put your broken car into the garage to have it expertly fixed, so you should do the same with a computer when necessary. Yes, it isn't cheap, but you spend much more time on your computer than in your car.

By disabling start-up programmes until you find the culprit you may have inadvertently disabled a critical piece of security software. (Personally I wouldn't count Norton in that list. I believe it does more harm than good as it lulls you into a false sense of security, but that's a whole new thread!)

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      24 Jul 2009 @ 21:43
RE: White Screen

Linda
please download Hijack This! from this link

http://majorgeeks.com/downloadget.php?id=5554&file=1&evp=4122712c2af084c815e5fd4f2b249d83

Please run and install it, it gives a menu
Select option 1, which is "do a system scan and save a log file"
Once you have created the log file, please open the file and copy and paste the contents here
Lets try and see just what is running on this machine

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 22:08
RE: White Screen

MICHAEL D.I wouldn't expect a brand new car or computer to go wrong after 5weeks use!No manual came with this computer.I did my own minor repairs on my car, when I had one.I only disabled start ups one at a time and then re-enabled them, I was told how to do it, and that it was ok to do it! I'm not completely stupid, i'm trying to learn!You guys are ganging up on a poor defenceless woman!!!!!!!!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      24 Jul 2009 @ 23:01
RE: White Screen

The Tech Guys form the technical support arm of the DSG Group, the company that owns the high street stores PC World, Comet and Currys. Both they and PCIQ are in the business of repairing computers, so we are business rivals. The DSG Group buy in computers from various smaller manufacturers and rebrand them as Advent, so when you complain about the lack of a manual the have the DSG Group to blame.

When you buy a new computer, you may be persuaded to pay extra for a telephone support package that promises you help and advice. But several of my clients have told me they tried this and could not get through or did not get good advice so I would not advise people to buy this 'extra' when they buy a computer.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      24 Jul 2009 @ 23:17
RE: White Screen

Alan: I did not purchase the support package when I bought this "computer".I wish now that I had saved longer and bought a brand that I recognised.Had I known that Advent was a curry's computer I would not have bought it!!I feel like throwing it in the river,but I dont live near one!
What I thought would be fun, so far has turned out to be hell.I have no-one to help me,but I am trying to learn from what you are all saying on here!! I need a miracle...OMG....

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      24 Jul 2009 @ 23:30
RE: White Screen

Linda
please try what I suggested in my last post
thanks

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      25 Jul 2009 @ 00:00
RE: White Screen

and by the way, that "Advent" is actually an ECS U51IL1. Like so many of their products, there is no support page for it on the ECS site

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Michael D. PCIQ IT ProfessionalIT Professional in Chorley, PR6      25 Jul 2009 @ 08:26
RE: White Screen

Linda, I can assure you we are not trying to gang up on you at all, and I appreciate that you are learning fast. As someone else has commented you have a record number of Techies all trying their best to help you. (Although this may be confusing the issue, they are all here with only the very best intentions.)

Sadly, you've bought the Lada of computers and not a Rolls Royce. You weren't to know that, of course, when you bought it.

The computer should have come with a manual - and there is a chance there is one loaded onto the hard drive or on a CD. But, the manual won't tell you how to fix it, only how to use it.

What you're attempting isn't a minor fix like changing a tyre. It's probably along the lines of a wheel bearing or broken piston ring.

The age of the computer doesn't matter if (as widely suspected) it has some malware or virus infection. To continue the car analogy, the garage wouldn't be responsible if you put diesel into the tank of your petrol car - even if no-one had ever told you not to do such a thing. The garage would simply assume you'd bought the car, you should know not to do this.

You've bought a computer with Norton anti-virus installed, yet it sounds like it has some sort of virus. (Obviously I can't be certain of this without seeing the machine.) No matter how good the computer, or the shop that sold it to you, they won't accept responsibility for what is a software issue.

You seem to be getting frustrated and angry at our best efforts to help you, for free. You should remember that we are simple Techies who spend our days talking to computers or other Techies, and communication isn't our strong point. (You should also understand that Microsoft called their operating system Windows simply because you feel like throwing the thing through the windows!)

The option of paid support is always available...

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      25 Jul 2009 @ 09:01
RE: White Screen

When you buy a car you know that you are going to have to pay more money to get it serviced/MOT'ed at regular intervals. The same, I'm afraid, is true of a computer. If your computer is running Norton then this is free for a year if you are lucky but more typically free for 60 days. Near the expiration date of the free period the program will start nagging you for a renewal and a renewal will cost typically £40 to £50 if you buy direct from Symantec (Norton). That is the price for another year, after that you pay again.

The good news is that there are alternatives to Norton that are both better and free!!! And you can learn to service your computer at home for free also, if you want to. Not everybody does.

Many of my clients like to use their computer but don't want to get involved in the nitty-gritty of keeping it running well. I can offer a thorough tune-up of both computer security and performance (with free security software) for about the same cost as you would pay annually to Norton.

Linda, you have three choices:
You can learn to service and take care of your computer yourself (with the aid of the professionals on this site).
Or you can pay a professional to do that and just get on with using the computer.
Or you can get frustrated and stop using it.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      25 Jul 2009 @ 11:41
RE: White Screen

Re: MY COMPUTER: Only windows Vista was installed on my computer when I bought it! I paid Currys £80 for the Norton, which I installed.Norton kept blocking the sending and receiving of my emails,so I contacted Norton, who uninstalled it and looked at it, then re-installed it, which solved the problem.I was told(obviously wrongly) that Norton and Mcafee were the best ones!!
I am not angry at the advice given here, just at the 1 or 2 sarcastic digs included!!
I would be interested to know what security I should get when Norton runs out, on your advice, I will not re-new with them.
I have found the cause of the white blank screen window.It was homepage that automatically loaded when I downloaded a wallpaper from the net!I will not be downloading any more stuff like that.
Maybe you cant remember back to the time when you had NEVER used a computer before, if you can,well that is me now!!I am being told to copy and paste, I don't know what that means.I have a book now and am reading it, so will learn. I'm sorry I'm such a pain,because in fact, I am a really nice person!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      25 Jul 2009 @ 13:03
RE: White Screen

Jon S:I went to the majorgeeks link and clicked on "Hijack this" free download,this then changed to"Error fix" which I downloaded!It scanned computer and came up with a load of stuff that I didnt need on the computer. There was an option to remove, which when I clicked on it said I had to pay first?????

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Michael D. PCIQ IT ProfessionalIT Professional in Chorley, PR6      25 Jul 2009 @ 14:18
RE: White Screen

Linda, we don't think you're a pain. If we did then we'd have stopped offering help some time ago. I can remember when I had never used a computer before - and I was amazed that someone else could solve my problems over the phone, without even seeing my computer! Wow!

Since then I have invested a lot of long hours, a great deal of money and bucket loads of blood sweat and tears. I often think it would have been simpler, cheaper and quicker to have paid a professional, but then I wouldn't have had the challenges, (or this career).

I did learn quickly not to download anything from the internet unless I completely trusted the site - and then to think twice! "If it looks good, then it probably isn't" - is the watchword on the WWW.

80 quid is very steep for Norton - even from Curry's. You may wish to double-check what you have bought - a 2 year licence, for instance?

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      25 Jul 2009 @ 14:36
RE: White Screen

Jon sent you a confusing web site with adverts that try to trick you into downloading the wrong thing. The correct place to download HijackThis from is here http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
The easiest option is to then click on the download executable link.

ErrorFix is something different entirely. Click on Control Panel - Programs - Uninstall a program and uninstall it

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      25 Jul 2009 @ 16:24
RE: White Screen

Alan B: I have just tried to uninstall Errorfix.A message comes up telling me that an unidentified programme is trying to change something on my computer. I clicked Allow, and a msg came up, preparing to INSTALL, not uninstall which I am trying to do. I cancelled. Am I do something wrong.I have uninstalled before and did not have these msgs come up ????I'll wait for your reply before trying again..Thanks....

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      25 Jul 2009 @ 16:56
RE: White Screen

Alan B: I downloaded the executable file,My system asked me to file it, I said yes but then got msg saying System denied write access to Host file.Hijack this may not be able to fix this.Then told me to edit file myself????????????
I have the results of the Highjack scan on a hijack notepad. This is at present minimized to my toolbar, as I dont know how to save it.What do I do now?? I await reply to both questions. Thanks

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      25 Jul 2009 @ 17:02
RE: White Screen

UPDATE ON ABOVE REPORT: I have saved the Log to one of my files......

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      25 Jul 2009 @ 20:15
RE: White Screen

Hi Linda

We'll ignore the problems with Error fix and the error message with HijackThis.

Open the HijackThis log file, select all, hold down the CTRL key and press C to copy. Then click the PCIQ message box to position the cursor in the box, hold down the CTRL key and press V to paste what you copied. This should create a message with the contents of your log, so post this to us and we will take a look.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 13:01
RE: White Screen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:34, on 25/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesSpare MessagingMessagingApp.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowssystem32wuauclt.exe
C:Program FilesInternet ExplorerIEUser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5H8BDVHLAHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7698 bytes

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 14:11
RE: White Screen

you are virused and appear to have multiple browser hijacks

the following (at least) represent malware infections

C:Program FilesSpare MessagingMessagingApp.exe

C:Program FilesOEMOSD_2.4osd.exe

R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:Program FilesSGPSAmtwb3sh.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll

O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll

O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll

O4 - HKLM..Run: [SpareMessaging] "C:Program FilesSpare MessagingMessagingApp.exe

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe

O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

Removing these is going to be painful

1) Download an run ATF-Cleaner from
http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25
Yo need to tick all the boxes and use it to remove all the temporary files in the system

2) Run Hijack This! again, this time selecting the second option "do a system scan only". Then tick all the lines I have shown above (except the first two) and use the program to remove them

3) Download and run Comboofix from
http://download.bleepingcomputer.com/sUBs/ComboFix.exe. You need to run this in save mode and use it to scan the machine

4) Download and update SuperAntiSpyware free edition from http://www.superantispyware.com/download.html
Do a full scan of the machine and delete everything it finds

Once you have done that, generate another Hijack This report and post back again

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 14:26
RE: White Screen

re combofix - I meant run it while the computer was in safe mode...

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 16:25
RE: White Screen

JonS:I went to the link you gave for the ATF Cleaner and it says on the page it is for XP and 2000 only???I have Vista Home Preium!!!!...

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 16:39
RE: White Screen

its OK to run it. He hasn't updated the site, but the programs is OK to run in Vista. It just skips a couple of folders in Vista

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 17:20
RE: White Screen

Jon: went I get on spyware.com and click download it goes onto another page saying spydoctor???

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 17:39
RE: White Screen

none of the links I gave you should take you to spyware.com which appears to be a "parked" website
And you do NOT want spydoctor

what is taking you to spyware.com??

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 17:39
RE: White Screen

Jon S: Have tried again, same thing goes to Spydoctor page????

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Robin N. PCIQ IT ProfessionalIT Professional in Watchet, TA23      26 Jul 2009 @ 17:42
RE: White Screen

Linda, lots of these download sites try to divert you into downloading their sponsored software. Sometimes you have to look at the small print between the lines to get what you actually went there for.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 17:47
RE: White Screen

Linda

Which of the links I gave you id taking you there? its is possibly the infection redirecting you
I gave you three things to download, which one is going wrong? If you can tell me that, then maybe I can point you at an alternative download location

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 18:53
RE: White Screen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:48:39, on 26/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:Windowssystem32igfxsrvc.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
C:Windowsehomeehmsas.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesIncrediMailinIMApp.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5XMST6KOWHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O20 - Winlogon Notify: !SASWinLogon - C:Program FilesSUPERAntiSpywareSASWINLO.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7653 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:48:39, on 26/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:Windowssystem32igfxsrvc.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
C:Windowsehomeehmsas.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesIncrediMailinIMApp.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5XMST6KOWHiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O20 - Winlogon Notify: !SASWinLogon - C:Program FilesSUPERAntiSpywareSASWINLO.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe
O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

--
End of file - 7653 bytes

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by:  .      26 Jul 2009 @ 18:59
RE: White Screen

JON S: I managed to find it, sorry couldn't get back to computer till now. I re-ran Hijack and the report is on here now!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 19:16
RE: White Screen

Nothing much has changed
the browser hijacks are still there. these entries

C:Program FilesOEMOSD_2.4osd.exe

O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} -
C:Program FilesPriceGong1.2.0PriceGongIE.dll

O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll

O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe

O23 - Service: Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

Linda
Have you actually run Combofix and Suparantispyware? Isee you have installed SaS but have you scanned the machine with it? Between that and Comboxifx I would expect these browser hijacks to be removed
Hijack This! should also remove them if you tick them and use the "clean" facility

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 19:28
RE: White Screen

JON S:I did everything as you said, each one downloaded and did whatever it was supposed to do. When the Superantispy had stopped scanning, there wereI think 104 things ( 3 items)Adware HB Helper, Browser Higjack deskbar, and tracking cookies. The report said that it was putting them in quarrantine. There was not an option to delete, like the previous one, where I did tick all boxes and ask it to delete.
The superAntispyware had to shut down computer to quarrantine, whilst computer was shutting down, Windows decided to install updates. Took ages and it rebooted vey slowly. When desk top returned, the super thing was not there, so I assumed it had finished. I then ran Hijack again.........

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 19:41
RE: White Screen

Jon S: The ATF Cleaner did not say delete on recollection, it said Remove and I clicked on it. There no boxes on either programe that actually said the word Delete!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 20:11
RE: White Screen

JON S: I have just done a quick scan with superantispyware and it came back "No harmful Software was detected. So it had quarrentened the 1o4 things found with the full scan. Does that mean that its ok now?It sai they were quarrantined in case they were needed to be activated later.I dont know what they are so wil not be activating them.......Thanks, await reply

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 20:19
RE: White Screen

OK
lets try and do this another way

1) click start > typein the search bar "msconfig" (without quotes), hit the return key. System Configuration utility runs
Select the "services" tab. Scroll down until you find two entries, one each corresponding to

OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe

Zwangi Service - Unknown owner - C:ProgramDatawangizwangi115.exe

Untick these and the click OK. Allow the machine to restart

2) After the restart we need to disable the browser hijacks. How we do that depends on whether you have internet explorer 7 or 8. Please post back with whichever it is

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 21:00
RE: White Screen

Jon S: I have done the msconfig. I did have 7 but whilst I was doing all that other stuff earlier, windows updated it to 8. Since then it is taking a longer time to turn back on and to launch the web page........

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 21:08
RE: White Screen

Jon S: My little symbol for the wireless at the top of screen doesnt come up anymore! And I,ve just had a box come up with yellow triangle with exclamation mark inside, saying Direct Port unable to open the device. Also i used to get a notice on screen when my caps lock was on, now it doesnt come up either????

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 21:38
RE: White Screen

Is the wireless actually connecting? If it is, don't bother about it. Otherwise use msconfig again an re-enable the OSD service and see it it comes back - maybe there was a misidentification there

Once you've done that we need to clean out internet explorer
click start > control panel
on the left hand green pane select "classic view"
A series of icons appears, click on "Internet Option"
Go to the extreme right hand tab - "Advanced" and then click the "Reset" button. This will diable ALL internet explorer plugins and toobars
Then go to the "Programs" tab and click the "add ons" button
You will see a list of programs, most - or all - of which will be disabled. We need to selectively re-enable SOME of thse
Things to enable
anything from your antivirus/security software
anything from microsoft
anything relating to Adobe, Java
If there is anything else there ask, but do NOT re-enable anything related to
PriceGong
Search Assitant
FastBroser
Zwangi
If you are given the option to uninstall those completely, please do so

Once you have done that reboot the computer and post another HijackThis! log


20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 22:12
RE: White Screen

Jon S.Im in programmes, there isnt button that says add ons, just one that says manage add ons.one which says Microsoft Office Word and the bottom one says set programs. if i click on manage addons,there is just a list of names and publishers ,status and file date, nowhere to enable anything??????Help

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 22:18
RE: White Screen

go into "manage addons"

you get a list of four items in blue on the left
Click on the top one, "Toolbars an Extensions"
In the right hand pane is a list of programs which should all show as disabled
You can enable each in turn by highlighting it and selecting "enable" - the button in the bottom right corner

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 22:35
RE: White Screen

JON S: This is a list of the ones still not enabled:
SEARCH ASSISTANT
GOOGLE TOOLBAR
GOOGLE TOOLBAR HELPER
GOOGLE TOOLBAR NOTIFIER BHO
GOOGLE DICTIONARY COMPRESSIO...
FAST BROWSER SEARCH TOOL BAR
FAST BROWSER SEARCH TOOLBAR HE
SEND TO ONE NOTE
RESEARCH
YAHOOTOOLBAR
YAHOO TOOLBAR HELPER
SINGLE INSTANCE CLASS

All the above are disabled. I do have stuff in One note by the way!! Should I enable any of the above, and what next?

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 22:48
RE: White Screen

Jon sorry missed PRICEGONGCTRL CLASS off that list also Disabled

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      26 Jul 2009 @ 23:04
RE: White Screen

JON should i enable any on that list i left you?????

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      26 Jul 2009 @ 23:05
RE: White Screen

the following are bad and should not be re-enabled
SEARCH ASSISTANT
FAST BROWSER SEARCH TOOL BAR
FAST BROWSER SEARCH TOOLBAR HE
SINGLE INSTANCE CLASS
PRICEGONGCTRL CLASS

The following are safe and should be enabled
SEND TO ONE NOTE
RESEARCH

The following are safe, but personally I would not re-enable them as they are just unneeded bloat
GOOGLE TOOLBAR
GOOGLE TOOLBAR HELPER
GOOGLE TOOLBAR NOTIFIER BHO
GOOGLE DICTIONARY COMPRESSIO...
YAHOOTOOLBAR
YAHOO TOOLBAR HELPER

After that, restart the machine
Does internet explorer now work OK?
Do you still have the white screen problem?

I suggest what you now do is update Norton 360 and run a FULL scan on the machine overnight. Once thats done, post another Hijack This log
also I suggest you now uninstall SuperAntiSpyware as its a bit clunky and slows the machine at startup: theres no advantage in keeping it on the machine now

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      27 Jul 2009 @ 00:22
RE: White Screen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:19:07, on 27/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Windowssystem32igfxsrvc.exe
C:Windowsehomeehmsas.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesIncrediMailinIMApp.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:UsersLindaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5PTYZ2MJ3HiJackThis[1].exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = Preserve
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe

--
End of file - 7099 bytes

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      27 Jul 2009 @ 00:48
RE: White Screen

still infected
the browser plugins I said NOT to re-enable, have been enabled

Run HijackThis again, using the second option and check the tick boxes against these entries
The use the "fix checked" button to remove them


O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll

O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll

O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll

O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dl

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      27 Jul 2009 @ 01:05
RE: White Screen

Jon S: I Have just looked at the boxes and the ones you said to disable ARE STILL DISABLED. I did everything you said, they ARE disabled!!! I even left off the google lot that you said you wouldnt put back. So I dont know why they should be showing, the report said it doesnt mean that there is something wrong but to just show list to someone who knows and not to start deleting! Whatever that means.Ive updated and ran Norton. No Problems.Browser is launching ok.The blank screen left 2 days ago. Ile run Hijack again!!!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      27 Jul 2009 @ 14:00
RE: White Screen

Jon S: Computer would not let me use fixed check button to delete those 4 programmes.page said it was removing them, then asked to scan, i clicked to scan and this msg came up on my computer:
"FOR SOME REASON YOUR SYSTEM DENIED WRITE ACCESS TO HOSTS FILE.IF ANY HIJACKED DOMAINS ARE IN THIS FILE, HIJACK MAY NOT BE ABLE TO FIX THIS.yOU WILL HAVE TO CREATE FILE YOURSELF.FOR VISTA USERS, EXIT HIGHJACK THIS, CLICK RIGHT ON HIGHJACK ICON
AND CHOOSE RUN AS ADMINISTRATOR"
There was no Highjack Icon to click on, so could not do this!!!!!
There was an alternative option to Click start and run and type notepad C:windowsSystem 32driversetchosts and press Enter.
I could not try this as when I click on Start, there is no Run!!!I looked all through programmes, there is no Run.used to be on my old computer,windows 98, but NO RUN on here!! I await reply.............

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      27 Jul 2009 @ 16:16
RE: White Screen

You'll be using Vista. The Run option is in the Accessories folder so click the Start button, then All Programs, then Accessories then Run

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      27 Jul 2009 @ 16:21
RE: White Screen

Oh, and you managed to start HijackThis somehow. Whatever you are double clicking to start it, click once with the Right mouse button then select Run as Adminisrator.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      27 Jul 2009 @ 17:40
RE: White Screen

Jon S: It isnt working!When I type in file and run, msg says cant get into it.I have saved Hijackthis into a file, I have the icon on my desk top, right clicking brings up options to open etc, no option to run as administrator.If I open and ask it to scan, the same msg comes up about the sytem denied write access. Ive tried to do what the msg said, several times, and neither of the options work??????? Those 4 you want deleted are still showing disabled.I cannot find a way to delete them.Can we not just leave them disabled????? I have a bad headache, as I am sure you must to over this, thanks for your patience!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      27 Jul 2009 @ 17:48
RE: White Screen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:44:39, on 27/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesIncrediMailinIMApp.exe
C:Windowsehomeehmsas.exe
C:UsersLindaAppDataLocalTempTemp3_HiJackThis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = Preserve
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:Program FilesPriceGong1.2.0PriceGongIE.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe

--
End of file - 6960 bytes

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      27 Jul 2009 @ 19:36
RE: White Screen

dont worry about the Hosts error message. It always happens in Vista and does not affect any of the items we are looking at here. Ignore it. Those four items are not in the Hosts file, they are BHO (Browser Help Objects)
Irrespective of their disabled status, we need to remove these files
I think the answer is going to be to physically delete them.

The actual locations of the files should be these
(note that this forum does not allow the use of backslashes, so I've used / instead.


C:/Program Files/PriceGong1.2.0/PriceGongIE.dll

C:/Program Files/SGPSA/BHO.dll

C:Program Files/Fast Browser Search/IEFBStoolbar.dll

We need to reboot the machine in safe mode, open up windows explorer, and navigate to the Program Files folder
Then one by one delete
1) the folder called PriceGong1.2 (or maybe just PriceGong
2) the folder called SGPA (I'm guessing here - it could be a single file called SGPSABHO.dll
3 the folder called Fast Browser Search

Once thats been done, we need to tidy up the registry
Download and install CCleaner from
http://www.filehippo.com/download_ccleaner/
(big green button, top right labelled "download latest version) During setup tick all the boxes EXCEPT the last one (about running from within Internet explorer - you dont want that option)
Once installed, run it. Select the button which says "registyr2 and the click "scan for issues"
When it finishes scanning, use the "fix selected issues" button. Scan and fix repeatedly until all the problems go away: it can take three or four scans
Once you've done that, you should be clean
Post back another HijackThis log and we should be done

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      28 Jul 2009 @ 12:43
RE: White Screen

JonS: When I attempted to open the file SGPSABHO to delete it, this message came up: YOU ARE ATTEMPTING TO OPEN A FILE TYPE APPLICATION EXTENSION (dll). THESE FILES ARE USED BY OPERATING SYSTEMS AND VARIOUS PROGRAMMES.EDITING OR MODIFYING THEM COULD DAMAGE YOUR SYSTEM.!!!!!!

Fast Browser has two files
Fbs Search Provider which is an XML document, and
Fbs Search Provider IE8, which is an Application.
WHICH ONE??????

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Alan B. PCIQ IT ProfessionalIT Professional in Cambridge, CB22      28 Jul 2009 @ 13:44
RE: White Screen

How does opening a file enable you to delete it? If the file is suspect the LAST thing you want to do is open it. Just right click the file, select delete and override any warnings that appear.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      28 Jul 2009 @ 14:04
RE: White Screen

Malwarebytes' Anti-Malware 1.39
Database version: 2492
Windows 6.0.6001 Service Pack 1

28/07/2009 13:58:33
mbam-log-2009-07-28 (13-58-33).txt

Scan type: Quick Scan
Objects scanned: 1
Time elapsed: 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

JON S: Right clicking on this BHO file brought up the same message about it damaging my system.
I did a maleware scan on this file, and this is the result. Price Gong has completely GONE.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      28 Jul 2009 @ 15:01
RE: White Screen

Iput my google bar back in as it blocks popups and i dont want them.
ccleaner I ran 4 times, it came up clean.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      28 Jul 2009 @ 15:21
RE: White Screen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:10:39, on 28/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Windowssystem32igfxsrvc.exe
C:Windowsehomeehmsas.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesIncrediMailinIMApp.exe
C:UsersLindaAppDataLocalTempTemp4_HiJackThis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = Preserve
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - (no file)
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:Program FilesFast Browser SearchIEFBStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe

--
End of file - 6921 bytes

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      28 Jul 2009 @ 19:51
RE: White Screen

JON S: Do I need to do anything else now??

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      28 Jul 2009 @ 20:46
RE: White Screen

yes you still need to delete:

SGPSABHO
If you are getting a warning message its because you are double clicking it. Use the RIGHT mouse button and click on it once. Then select delete


"Fast Browser has two files
Fbs Search Provider which is an XML document, and
Fbs Search Provider IE8, which is an Application.
WHICH ONE??????"
You need to delete BOTH of these


Now do you begin to see why at the beginning of this saga I suggested you call someone in to do this?
However, you're almost there now. Just three files to delete

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: L S.      28 Jul 2009 @ 21:35
RE: White Screen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:29:46, on 28/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Windowsehomeehmsas.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesIncrediMailinIMApp.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesWindows LiveContactswlcomm.exe
C:UsersLindaAppDataLocalTempTemp6_HiJackThis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = Preserve
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - (no file)
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe

--
End of file - 6964 bytes
NONE OF THOSE FILES ARE STILL LISTED IN THE PROGRAMME fILES. I'VE CHECKED. i STILL HAD THAT BOX COME UP WHEN RUNNING THE HIJACK LOG, ABOUT SYSTEM DENIED WRITE ACCESS AND TO EDIT MYSELF.

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      28 Jul 2009 @ 23:22
RE: White Screen

dont worry about that error message

looks like the problems are gone except for one

O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll

have you got a folder in "program file" with a name that begins SGPS...
hard to know exactly what it will read as the forum deletes the backslashes in the path.
Delete that folder, or all the files in it, and you're done

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      29 Jul 2009 @ 19:53
RE: White Screen

JON S: I deleted that file previously, I dont know why its still showing. I cant find it in program files, if I ask computer to find it, it comes back not found or no file. I definitely deleted it after Price gong. Ile have another look but I'm almost certain its not there anymore!!

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      29 Jul 2009 @ 20:15
RE: White Screen

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:05:37, on 29/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowsehomeehmsas.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesIncrediMailinIMApp.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:Windowssystem32MacromedFlashFlashUtil10b.exe
C:UsersLindaAppDataLocalTempTemp7_HiJackThis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = Preserve
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - (no file)
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll (file missing)
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe

--
End of file - 7044 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:05:37, on 29/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:Windowssystem32 askeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesTalkTalkinsprtcmd.exe
C:WindowsRtHDVCpl.exe
C:WindowsSystem32igfxpers.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesCommon FilesACD SystemsENDevDetect.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesThe TechGuysLaunchLaunch.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesOEMOSD_2.4osd.exe
C:Windowsehomeehmsas.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesIncrediMailinIMApp.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesGoogleGoogle ToolbarGoogleToolbarUser_32.exe
C:Windowssystem32MacromedFlashFlashUtil10b.exe
C:UsersLindaAppDataLocalTempTemp7_HiJackThis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = Preserve
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.aol.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton 360Engine3.0.0.135IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - (no file)
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:Program FilesSGPSABHO.dll (file missing)
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O3 - Toolbar: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [TalkTalk] "C:Program FilesTalkTalkinsprtcmd.exe" /P TalkTalk
O4 - HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Device Detector] "C:Program FilesCommon FilesACD SystemsENDevDetect.exe" -autorun
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe IE
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [IncrediMail] C:Program FilesIncrediMailinIncMail.exe /c
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Launch.lnk = ?
O4 - Global Startup: OSD.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MI1933~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MI1933~1Office12REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:Program FilesNorton 360Engine3.0.0.135coIEPlg.dll
O23 - Service: Google Update Service (gupdate1c9f115477fa260) (gupdate1c9f115477fa260) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:Program FilesNorton 360Engine3.0.0.135ccSvcHst.exe
O23 - Service: OSD Service (OsdService) - TODO: - C:Program FilesOEMOSD_2.4OsdService.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesTalkTalkinsprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftinssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:Program FilesCommon FilesSupportsoftin gsrvc.exe

--
End of file - 7044 bytes
JON S:The SGPSABHOdll I had already deleted!! But I found another one which just said SPGSA so now thats gone too!! Ive asked computer to look for those files and it said "WINDOWS CANNOT FIND IT, MAKE SURE YOUR TYPING CORRECT NAME"
Has now GONE< GONE GONE!! Please tell me that thats it!!!!!!!................L

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      29 Jul 2009 @ 21:29
RE: White Screen

Linda
looks like you've done it
The registry entries are still there, but the actual files have gone,so they can't harm anything
Well done on two counts
First for clearing the machine
Secondly for staying with us on what is now the longest thread on the forum

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      29 Jul 2009 @ 21:42
RE: White Screen

JON S: Thank you! I can't thank you enough for all your help. To think when I started this I didnt even know what copy and paste meant, so at least I learned something!!!! LOL....Sorry it took so long...and thanks to everyone else who gave advice.......Linda xx

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Jon S. PCIQ IT ProfessionalIT Professional in Morecambe, LA3      29 Jul 2009 @ 22:06
RE: White Screen

you also got a free tour around some of the more esoteric tools of our trade. As you can see, some are cryptic, some arcane and others just weird. But they work!
(unlike a lot of commercial security products...)
By the way, what we used was just the tip of the iceberg.

21 of 39 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post
Reply by: Linda S.      29 Jul 2009 @ 22:17
RE: White Screen

JON S: Lets hope I never get to see anymore of the iceberg!! The tip was enough!! Well, it did
sink the Titanic!!!
Hope I didn't give you grey hairs Jon!!.....L x

20 of 38 people found the above post helpful
Was this post helpful?  I thought this post was helpful  I thought this post was not helpful
Report this post

Do you need computer support?