Jump to content


Photo

MS Word VERY slow


  • This topic is locked This topic is locked
57 replies to this topic

#1 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 05 September 2006 - 09:04 AM

Hi,
Microsoft Word has been starting up VERY VERY slowly. I had posted in the sofware forum and was referred here. The computer is otherwise running fine.
Thanks.

http://forums.spywar...showtopic=77815

Updated HJT Log Mon Sep 11:

Logfile of HijackThis v1.99.1
Scan saved at 7:25:39 AM, on 9/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\HPOVDX05.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Bill\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk.disabled
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP OfficeJet Series 700 Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
O4 - Global Startup: Microsoft Office.lnk.disabled
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Edited by Flowers, 11 September 2006 - 05:27 AM.


#2 SWI Support Robot

SWI Support Robot

    Helper robot

  • SWI Bot
  • PipPipPipPipPip
  • 23,533 posts

Posted 08 September 2006 - 05:30 AM

Welcome to SWI. We apologize for the delay; our helpers have been very busy.
If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.

Thank you for your patience.

[this is an automated reply]
This is an automated message. It does not count as help.

#3 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 11 September 2006 - 09:32 AM

Hi,

Hi,

Print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
  • Close all open Explorer windows and browsers
  • Run HijackThis
  • Click on the Scan button and when complete
  • Put a check beside all of the items listed below
  • Click on the "Fix Checked" button
  • When complete and all files removed, close the application.
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - Global Startup: Microsoft Office.lnk.disabled


Restart the computer to reset the registry.

Locate the file normal.dot and rename it Oldnormal.dot
Information on this file see:
http://en.wikipedia....wiki/Normal.dot

If the problem persists.

NOTE: this is a 30-day trial of the program. This means that after 30 days the "background guard" protection will de-activate. However, this version can continue to be updated and used as an on-demand scanner forever.

Download, install, and update the trial version of Ewido anti-spyware
  • Load Ewido and then click the Update tab at the top. Under Manual Update click Start update.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Close Ewido. Do not run it yet.
Please reboot your computer into Safe Mode. To boot into Safe Mode, please restart your computer. Tap F8 before Windows loads. Select Safe Mode on the screen that appears.
  • In Safe Mode, load Ewido and click on the Scanner tab at the top. Click the "Settings" tab and then change the recommended action to Quarantine and click Automatically generate report after every scan. Click back to the "Scan" tab and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
  • Ewido will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right hand side.
  • Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
  • Restart back into Normal Mode.
Submit the ewido log with a fresh HijackThis log. Let me know what problem persist.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#4 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 12 September 2006 - 06:49 AM

Word is still insanely slow.

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 8:39:35 AM 9/12/2006

+ Scan result:



:mozilla.131:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.323:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.324:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.325:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.326:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.160:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.161:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.311:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
:mozilla.312:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
:mozilla.336:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.337:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.338:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
C:\Documents and Settings\Bill\Cookies\bill@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.239:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup (quarantined).
:mozilla.240:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup (quarantined).
:mozilla.241:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup (quarantined).
:mozilla.150:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.258:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.259:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.260:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.261:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.265:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.266:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.267:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.109:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.121:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.94:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.95:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.96:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.289:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.290:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.291:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.302:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.303:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\5cc35m3m.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 8:47:27 AM, on 9/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\HPOVDX05.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bill\Desktop\HijackThis DO NOT TOUCH.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk.disabled
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP OfficeJet Series 700 Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

#5 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 13 September 2006 - 06:50 AM

Your log is clean. So is the ewido scan.
Do not think it's malware.
Do you have many files in your different folders used by Word.

You may wish to run and let me see this result.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: Posted Image
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    Posted Image
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#6 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 13 September 2006 - 09:44 AM

I followed the steps, and there was 1 adware item found. I saved the report list and rebooted. I tried to open the saved file. I am getting the message "unable to read file" when it attempts to open in Excel.

#7 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 14 September 2006 - 08:41 AM

Can you try to open the file with NotePad.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#8 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 14 September 2006 - 02:50 PM

Yes. It is completely blank.

#9 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 15 September 2006 - 06:25 AM

Lets try this last scan. If still having problems with Words only I suggest you reinstall the program.

Please perform an online virus scan with F-Secure Online Scanner.

Please navigate (using Internet Explorer, other browsers won't work) to the following site: http://support.f-sec...home/ols3.shtml
  • Click the F-Secure Online Scanner Next Generation Beta link.
  • When prompted, choose to install the software.
  • After the software has installed, click Accept.
  • Click Custom Scan and check the option for Scan inside archives, then click Start.
  • The necessary databases will then be downloaded, and the scan will then start automatically. Please be patient as this scan will take a while to complete.
  • If any infections are found then once the scan has finished the "cleaning" screen will be displayed. Choose Automatic cleaning (recommended).
  • After cleaning has finished, then the Finish screen will be displayed. Choose Show Report.
  • In order to post the report, press CTRL+A on your keyboard to highlight all the text. Then copy and paste that information into this thread, along with a new HijackThis log.

nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#10 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 16 September 2006 - 10:20 AM

Hi,
I did uninstall and reinstall Word before posting here, but it didn't help. See here
http://forums.spywar...showtopic=77815

Here's the report...

Scanning Report
Saturday, September 16, 2006 09:55:17 - 12:15:42

Computer name: BILL
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
Result: 2 malware found
Diaremover (spyware)

* System (Disinfected)

Tracking Cookie (spyware)

* System (Disinfected)

Statistics
Scanned:

* Files: 33912
* System: 5016
* Not scanned: 21

Actions:

* Disinfected: 2
* Renamed: 0
* Deleted: 0
* None: 0
* Submitted: 0

Files not scanned:

* C:\HIBERFIL.SYS
* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb1.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts1.zip\sbRecovery.ini
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts2.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts3.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts4.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts5.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts6.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch1.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch2.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch3.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch4.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch5.zip\bar/History/search
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch6.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWebSearch7.zip\sbRecovery.reg
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusOverride.zip\sbRecovery.reg

Options
Scanning engines:

* F-Secure AVP: 6.0.171, 2006-09-15
* F-Secure Libra: 2.4.1, 2006-09-15
* F-Secure Orion: 1.2.37, 2006-09-14
* F-Secure Blacklight: 1.0.31, 0000-00-00
* F-Secure Pegasus: 1.19.0, 2006-08-14
* F-Secure Draco: 1.0.35, 0259-24-212

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
* Scan inside archives
* Use Advanced heuristics

#11 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 16 September 2006 - 12:32 PM

Diaremover (spyware) that was found and delete is from the Smitfraud family of malware.
Let me see what may still be in the registry.

Print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.

Please download SmitfraudFix (by S!Ri)
Extract all the content (to a folder named SmitfraudFix) on your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#12 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 18 September 2006 - 07:28 AM

"SubscribedURL"="file:///C:/DOCUME~1/BILL/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg"
"FriendlyName"=""

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

#13 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 19 September 2006 - 08:34 AM

Is the last log complete?

If not please repost.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#14 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 19 September 2006 - 01:02 PM

Is the last log complete?

If not please repost.


Yes, that is the complete log.

#15 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 19 September 2006 - 03:01 PM

That is stange since it should start with this.

SmitFraudFix v2.81

Scan done at 9:07:20.65, Mon 08/28/2006
Run from C:\Documents and Settings\Adam Troxell\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


To continue are you sure this file is OK?
C:/DOCUME~1/BILL/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
Where did it come from.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#16 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 20 September 2006 - 06:21 AM

I have no idea what happened, but ran it again and got the following.

I don't know what the clip_image is.


SmitFraudFix v2.92

Scan done at 8:15:58.10, Wed 09/20/2006
Run from C:\Documents and Settings\Bill\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Bill\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BILL\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="file:///C:/DOCUME~1/BILL/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg"
"SubscribedURL"="file:///C:/DOCUME~1/BILL/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg"
"FriendlyName"=""

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

#17 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 20 September 2006 - 02:12 PM

Lets fix the registry.

; Purpose: Remove traces in the registry.
;
; Instructions: Copy and paste this text IN BOLD into a text editor such as Notepad.
;
; Save this text as Fix.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"=-
"SubscribedURL"=-
"FriendlyName"=""



; Double-click on Fix.reg. When it asks you to merge the information to the registry click Yes.

If you need help on "How to Make a .Reg File"
See: http://nellie2.malwa...al.com/file.htm
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#18 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 21 September 2006 - 05:32 PM

OK, did that.

#19 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 22 September 2006 - 06:17 AM

Is Words still slow?

Are you using it for E-mail purposes?
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#20 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 22 September 2006 - 07:42 AM

Yes, extremely slow.

I'm not using it for email.

#21 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 22 September 2006 - 02:08 PM

Well it does not look like malware.

Do you keep many files in your Words folders, I mean 100 or more.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#22 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 23 September 2006 - 05:30 AM

Well it does not look like malware.

Do you keep many files in your Words folders, I mean 100 or more.


I didn't feel it was malware.

What do you mean by "Words folders?" I probably have more than 100 .doc files saved in various topic folders.

#23 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 23 September 2006 - 05:55 AM

I just found this...
http://www.word.mvps...OpeningWord.htm

It says to "Run, and type winword.exe /a". When I tried that Word opened and closed without a problem.

It then says to try renaming Normal.dot However, I can't find a normal.dot. I ran a files and folders search for normal, and there is no normal.dot

Edited by Flowers, 23 September 2006 - 06:03 AM.


#24 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 23 September 2006 - 06:48 AM

In my post No. 3 I suggested this.

Locate the file normal.dot and rename it Oldnormal.dot
Information on this file see:
http://en.wikipedia....wiki/Normal.dot


If you followed these instructions normally a new normal.dot should have been recreated as per the link/article you found.

You can try to create a new file.

Open Word save a blank file and name it normal.dot save it in c:\Program Files\Microsoft Office\templates folder.

If your Microsoft Office is located in an other location than c:\Program files folder make sure you save it in the \templates folder.
Close Word and try it.

If this does not solve you problem then it may be as suggested in the article a Registry item that is corrupted.
Let me know the version of Words you are using and will take it from there.

Also A printer issue. That can be solved by removing the printer (Add/remove hardware) and reinstalling it.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#25 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 23 September 2006 - 07:15 AM

Hi again...

OK, I just created a normal.dot

I also uninstalled and reinstalled the printer. No luck. I seem to think I did that before with no success. Deja vu.

I am using MS Office Word 2003.

#26 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 24 September 2006 - 02:03 PM

Ok lets try this. The article you found does not refer to Word 2003.

(Word 2002):
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Options\
“STARTUP-PATH”

Now I suspect that Words 2003 is located in

HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options\

I may be wrong
So execute this.

From the Start run menu execute
REGEDIT.EXE
This will open the Windows Registry.
Navigate to HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options\

or

HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Options\
or any other for that mater.

Tell we which one is found.
Do not remove anything yet. Just close the Registry tool.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#27 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 25 September 2006 - 10:59 AM

Ummmm, in the registry tool I found both...

HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options\

AND

HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Options\

11 has one extra item. "startupdialog"

#28 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 26 September 2006 - 07:40 AM

I need to be sure what I'm doing so please bear with me. I believe that you startup path may be the cause of your long waiting to word to start.

Download the Registry Search Tool from here:
http://www.billsway....les/RegSrch.zip

Unzip to your Desktop and double click on regsrch.vbs
(if you have script protection, please allow this to run)

In the dialog that opens enter the following:
HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options\

Press 'OK'

The search will run for a while then alert you when it is finished.

Press 'OK' and copy the contents of the WordPad window and post in this thread.


On your side, check the start up path.

You can find out where the factory preset Startup path is by looking in the C:\Program Files\Microsoft Office\Office\ directory (or equivalent, if you installed Word somewhere else) for a folder named Startup, or startupdialog as seen in the registry key.
If you have such a folder make sure the normal.dot file is also in that folder.
p.s. make sure that the path is referencing version 2003 or your program.

Let me know.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#29 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 28 September 2006 - 05:48 AM

Regarding step one, "No instance of HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options\ found"

Regarding step two, there was no normal.dot in that folder. I just added it.

#30 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 28 September 2006 - 08:19 AM

Repeat the search but remove the last back slash.

HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#31 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 28 September 2006 - 11:59 AM

Same thing without the backslash. No instances found.

#32 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 29 September 2006 - 06:29 AM

You found it and told me about it in post no 27.

Open Regedit and navigate to
HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options

Highlight the options on the Left Pane.

From the Menu Selete Registry and export the file.

Save it as myword.reg

Open myword.reg with notepad and post the results.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#33 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 30 September 2006 - 07:15 AM

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options]
"PROGRAMDIR"="C:\\Program Files\\Microsoft Office\\OFFICE11\\"
"FirstRun"=dword:00000000
"StartupDialog"=dword:00000000
"WordMailACOptions"=hex:00,01,01,01,01,01,01,01,00,01,01,01,01,01,01,01,01,01,\
01,00,01,00,01,00,01,01,01,01,01,01,00,02,00,03,01,03,01,03,01,03,00,03,01,\
02,00,03,01,03,01,03,01,03,01,00,00,23,01

[HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options\OutlookEditor]
@=""

#34 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 30 September 2006 - 01:49 PM

Your registry items are correct.

Read this Microsoft article.

http://support.micro...-...&sid=global
How to reset user options and registry settings in Microsoft Office Word 2003, in Microsoft Word 2002, and in Microsoft Word 2000

Start at:
Repair Word (Office)
Execute the instructions.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#35 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 01 October 2006 - 04:57 AM

OK, I followed all of the instructions from "repair word" on down the page. The only thing I didn't do was #4 in the add-ins section because I could not find that folder.

There is no change in Word. It is still excruciatingly slow.

#36 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 01 October 2006 - 07:28 AM

A few questions.

Do you have any other version of Word on your computer?

Did you use an upgrade disk to go from your previous version to 2003?

How many .dot (not .doc) files do you have associated with this program?

Did you try to move all of them out of the context of word by moving them to a temp folder on your control panel. Try this if you did not. See if the program improves.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#37 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 01 October 2006 - 09:27 AM

A few questions.

Do you have any other version of Word on your computer?

Did you use an upgrade disk to go from your previous version to 2003?

How many .dot (not .doc) files do you have associated with this program?

Did you try to move all of them out of the context of word by moving them to a temp folder on your control panel. Try this if you did not. See if the program improves.


No other version of Word.

It was not an upgrade disk.

There are a number of .dots I don't know what you mean to create a temp folder on the control panel. I just moved to a folder on the desktop but that didn't help.

#38 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 01 October 2006 - 02:50 PM

; Purpose: Remove traces in the registry.
;
; Instructions: Copy and paste this text IN BOLD into a text editor such as Notepad.
;
; Save this text as removeW10.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Options]



; Double-click on removeW10.reg. When it asks you to merge the information to the registry click Yes.

Question.

Do you start word from a shortcut icon.
If yes then look a the properties of the icon and make sure the path is good.

if still having problem run this scan.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: Posted Image
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    Posted Image
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply. You can use Notepad to open the DrWeb.cvs report.

nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#39 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 01 October 2006 - 06:18 PM

My emails in Outlook are now all GONE. How do I recover this important info?

Drweb log:
A0051694.ocx;C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP680;Adware.Gdown;Incurable.Moved.;
A0051974.exe;C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP684;Tool.Prockill;Incurable.Moved.;
A0052438.exe;C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP689;Tool.Prockill;Incurable.Moved.;

Yes, I sometimes, not always, start word from a shortcut.

FWIW, Word shows "running virus scan" as it starts up.

Edited by Flowers, 01 October 2006 - 07:47 PM.


#40 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 02 October 2006 - 06:13 AM

This is why I asked if you still had an other word running.
Something happed when you installed the new word 2003.

Let's hope that this will restore your e-mail.


; Purpose: Recreate the key.
;
; Instructions: Copy and paste this text IN BOLD into a text editor such as Notepad.
;
; Save this text as NewFix.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Options\]
"STARTUP-PATH"



; Double-click on NewFix.reg. When it asks you to merge the information to the registry click Yes.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#41 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 02 October 2006 - 09:10 AM

I did that next step. No help. Getting nowhere with the original problem, and now creating new problems.

As I already told you when you asked if I had another version of word installed, the answer is no.

Now when I close out of Word or outlook I keep being prompted about normal.dot

(I open Word and attempt to close...without typing anything)

"Normal.dot was being edited by another Word session. If you save this document with the original name, you will overwrite any changes made in the other session. Do you want to save the document using the other name anyway?" I've tried answering yes, no and cancel. I keep being prompted. If I state yes, I get "the file is read only".

I also keep getting "This program is not responding."

#42 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 02 October 2006 - 09:50 AM

Search for normal.dot file and if more than one copy rename all except one file to normal.dot.old
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#43 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 02 October 2006 - 12:22 PM

Only 1 normal.dot came up on a search.

#44 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 02 October 2006 - 02:13 PM

Where is it located. I remember asking you to change the location. Can your return it to it's original location.

If still having difficulties in accessing your e-mail you may have to reinstall your previous version of WORD
Can you do that?
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#45 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 02 October 2006 - 03:31 PM

OK, I moved it back to it's original location and am no longer being prompted on that.

As far as reinstalling previous version of Word, I don't understand what you mean.

#46 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 03 October 2006 - 07:45 AM

It may be the only way to get your e-mail back.

From what I understand you have word 2002, and you install word 2003 with a new installation disk rather than using an upgrade. That could be the reason you are having difficulties at start up. Not sure.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#47 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 03 October 2006 - 12:09 PM

Huh?

I would like to get my email back. I just don't know what you are suggesting in order to do that. I would also like to correct the original problem I came here with.

I ordered my computer without Office or Word. It did not come with any Word installed. I needed it, so I went to the store, and I purchased the 2003 edition. It used to work fine. I have never had 2002. I have the 2003 CD.

#48 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 04 October 2006 - 07:14 AM

If you did not have any prior word installation why did this item in your computer.
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Options\

It's from an previous version.

Your current version is
HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Options\


Can you restore your system to a prior date. Go back as far as you can but not prior to you installing Word.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#49 Flowers

Flowers

    Member

  • Full Member
  • Pip
  • 31 posts

Posted 04 October 2006 - 11:22 AM

I'm telling you I did not have a prior version of Word on my computer. This is a fact. If that appears, it is because it either installed itself after 2003 was on the computer, or was part of the 2003 CD. The computer did not come with Word. I did not install Word 2002. If you are lost about what to do, please tell me. But please don't keep insisting on something that isn't true.

Edited by Flowers, 04 October 2006 - 11:25 AM.


#50 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,276 posts

Posted 05 October 2006 - 07:05 AM

I can only relate to what I see in these messages. I did not mean to be sarcastic or else.

The last thing I can suggest is to repair word. If the key came from your 2003 cd it should be recreated.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760




Member of UNITE
Support SpywareInfo Forum - click the button