How JustAnswer Works:

  • Ask an Expert
    Experts are full of valuable knowledge and are ready to help with any question. Credentials confirmed by a Fortune 500 verification firm.
  • Get a Professional Answer
    Via email, text message, or notification as you wait on our site.
    Ask follow up questions if you need to.
  • 100% Satisfaction Guarantee
    Rate the answer you receive.

Ask Anthony Brewster Your Own Question

Anthony Brewster
Anthony Brewster, Consultant
Category: Computer
Satisfied Customers: 5365
Experience:  MICROSOFT PC SAFETY, WINDOWS LIVE ONECARE, WINDOWS GENUINE, & I.T. SPECIALIST
16299369
Type Your Computer Question Here...
Anthony Brewster is online now
A new question is answered every 9 seconds

Hi, Ive been trying to remove BPDSoftware box the comes on

Customer Question

Hi, I've been trying to remove BPDSoftware box the comes on every time I open my computer, what do I do?


Russell XXX@XXXXXX.XXX
Submitted: 5 years ago.
Category: Computer
Expert:  Anthony Brewster replied 5 years ago.
Hello, are you running XP or Vista?
Customer: replied 5 years ago.
Hi, running XP
Expert:  Anthony Brewster replied 5 years ago.
Thanks! Check your registry for this enter.

1) Click Start
2) Click Run
3) Type cmd and press enter

Now you should have your registry editor opened. Now, do this...


1) Click the + sign for HKEY_LOCAL_MACHINE
2) Click the + sign for SOFTWARE
3) Click the + sign for Microsoft
4) Click the + sign for Windows
5) Click the + sign for CurrentVersion
6) Click on the folder Run

Now, on the right-hand side, look for this BPS Software and right-click on delete it. Then close everything out and restart your computer.


BEST OF LUCK!
GOD BLESS!

:)
Customer: replied 5 years ago.
Hello, I am so sorry but I don't understand what to do when you say Click the + for, I did go to run and typed your instructions and the Windows black box opened, I don't know what to do in the box area, I am really sorry. Russell
Expert:  Anthony Brewster replied 5 years ago.
Im sorry i told you the wrong thing. Sorry....Check your registry for this enter.

1) Click Start
2) Click Run
3) Type regedit and press enter

Now you should have your registry editor opened. Now, do this...


1) Click the + sign for HKEY_LOCAL_MACHINE
2) Click the + sign for SOFTWARE
3) Click the + sign for Microsoft
4) Click the + sign for Windows
5) Click the + sign for CurrentVersion
6) Click on the folder Run

Now, on the right-hand side, look for this BPS Software and right-click on delete it. Then close everything out and restart your computer.
Customer: replied 5 years ago.

Again all I can say is I am sorry, I know nothing of computers, I followed your instructions and click every one listed and when I get to Click on the folder Run, I am lost where is it?

 

So Sorry,

Russell

Expert:  Anthony Brewster replied 5 years ago.
If you click on the folder run, look on the right hand side, there will be things listed there starting with Default...

:)
Customer: replied 5 years ago.

Okay got to the list on right side and BPD Software is not listed.

 

 

Russell

Expert:  Anthony Brewster replied 5 years ago.
hmmm. when did this problem start to begin with?
Customer: replied 5 years ago.
About a month, not quite sure.
Expert:  Anthony Brewster replied 5 years ago.
ok. Go back to the registry and check again under RUN but this time under HKEY_CURRENT_USER.



1) Click Start
2) Click Run
3) Type regedit and press enter

Now you should have your registry editor opened. Now, do this...


1) Click the + sign for HKEY_CURRENT_USER

2) Click the + sign for SOFTWARE
3) Click the + sign for Microsoft
4) Click the + sign for Windows
5) Click the + sign for CurrentVersion
6) Click on the folder Run

Now, on the right-hand side, look for this BPS Software and right-click on delete it. Then close everything out and restart your computer.
Customer: replied 5 years ago.
Did, not there either.
Expert:  Anthony Brewster replied 5 years ago.
Lets makes sure this is not some tpye of infection. Download/Save ComboFix and run it and then restart your computer after you get the log report.

(IMPORTANT) Click OK to continue on those popup messages from combofix, DO NOT disable the anti-virus, just click OK to go on and you might have 3 different OK boxes to pop up, and if it ask to download the recovery console just click no.



Try to run COMBOFIX and it will take about 5 minutes to complete tops. The Microsoft Level 2 Techs use this and nothing gets past it. This is a FREE scan and it does not install anything on your computer, it runs from the command prompt!


http://www.combofix.org/download.php

1) Save it to your desktop

2) Run It



When it is done, you will get a notepad with the report. If anything was deleted it will show you at the top like this....


(((((((((((((((((( other deletions )))))))))))))))))))

Here is you a guide just in case you want to see what happens.



http://www.bleepingcomputer.com/combofix/how-to-use-combofix

After that, close the notepad, restart your computer, and everything should be back to normal.



BEST OF LUCK!
GOD BLESS!

:)
Customer: replied 5 years ago.

Good Morning,

 

I ran the Combofix and it found 134 infections some 6to4v32, 4 are- markrt browser 7 atr SkyGuard 2009 and 21 are cookies, in order to remove want to buy the servive for one year at 9.95, (special) what should I do?

Customer: replied 5 years ago.

Follow up I did not buy and deleted the program, to get it free had to make a purchase.

I do hane norton.

 

Thanks,

 

Expert:  Anthony Brewster replied 5 years ago.
no, combofix is FREE, once you click on the link provided, it will tell you to save it and then you just run it,.
Customer: replied 5 years ago.

okay, I'll try it again, however, I must leave, be away for approx. 4 hrs. will do it latter this afternoon.

 

Thanks

Expert:  Anthony Brewster replied 5 years ago.
ok
Customer: replied 5 years ago.

I have the log, quite long, I need help how do I post this log as a reply to the topic, I don't know how or where.

 

Expert:  Anthony Brewster replied 5 years ago.
<p>The ONLY info that is important to us, the the one at the top under</p><p> </p><p> </p><p>((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))</p><p> </p><p> </p><p>Thanks!</p>
Customer: replied 5 years ago.
Yes, but what do I do with it, I saved the notepad to my desktop. Also the box stll comes on asking for the BPD Software CD.
Expert:  Anthony Brewster replied 5 years ago.
Ok Thanks. Try to open the notepad and copy the whole log and the paste it here and send it to me so i can find this software also and find out where it is to remove it. Thanks.

All you do is press ctrl+a to select all
Then you do this ctrl+c to copy it
Last you do this ctrl+v to paste it.


:)
Customer: replied 5 years ago.

Well here it is, it' long:

 

ComboFix 09-08-07.01 - Russell 08/07/2009 15:17.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1XXX-XX-XXXX.1201 [GMT -4:00]
Running from: c:\documents and settings\Russell\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
c:\program files\FunWebProducts
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\recycler\NPROTECT\00000000.DAT
c:\recycler\NPROTECT\00000001.DAT
c:\recycler\NPROTECT\00000002
c:\recycler\NPROTECT\00000003
c:\recycler\NPROTECT\00000004
c:\recycler\NPROTECT\00000005
c:\recycler\NPROTECT\00000006
c:\recycler\NPROTECT\00000007
c:\recycler\NPROTECT\00000009
c:\recycler\NPROTECT\00000011
c:\recycler\NPROTECT\00000012
c:\recycler\NPROTECT\00000013
c:\recycler\NPROTECT\00000014
c:\recycler\NPROTECT\00000017.DAT
c:\recycler\NPROTECT\00000018
c:\recycler\NPROTECT\00000019
c:\recycler\NPROTECT\00000020
c:\recycler\NPROTECT\00000021
c:\recycler\NPROTECT\00000022
c:\recycler\NPROTECT\00000023
c:\recycler\NPROTECT\00000024
c:\recycler\NPROTECT\00000026
c:\recycler\NPROTECT\00000027.DAT
c:\recycler\NPROTECT\00000028
c:\recycler\NPROTECT\00000029
c:\recycler\NPROTECT\00000030
c:\recycler\NPROTECT\00000031
c:\recycler\NPROTECT\00000032
c:\recycler\NPROTECT\00000034
c:\recycler\NPROTECT\00000035
c:\recycler\NPROTECT\00000036
c:\recycler\NPROTECT\00000037
c:\recycler\NPROTECT\00000038
c:\recycler\NPROTECT\00000039
c:\recycler\NPROTECT\00000040
c:\recycler\NPROTECT\00000041
c:\recycler\NPROTECT\00000042
c:\recycler\NPROTECT\00000043
c:\recycler\NPROTECT\00000044
c:\recycler\NPROTECT\00000045
c:\recycler\NPROTECT\00000048
c:\recycler\NPROTECT\00000049
c:\recycler\NPROTECT\00000050
c:\recycler\NPROTECT\00000051
c:\recycler\NPROTECT\00000053
c:\recycler\NPROTECT\00000054
c:\recycler\NPROTECT\00000056
c:\recycler\NPROTECT\00000057
c:\recycler\NPROTECT\00000059
c:\recycler\NPROTECT\00000060
c:\recycler\NPROTECT\00000061
c:\recycler\NPROTECT\00000062
c:\recycler\NPROTECT\00000063
c:\recycler\NPROTECT\00000064
c:\recycler\NPROTECT\00000065
c:\recycler\NPROTECT\00000066
c:\recycler\NPROTECT\00000067
c:\recycler\NPROTECT\00000068
c:\recycler\NPROTECT\00000069
c:\recycler\NPROTECT\00000070
c:\recycler\NPROTECT\00000071
c:\recycler\NPROTECT\00000072
c:\recycler\NPROTECT\00000073
c:\recycler\NPROTECT\00000074
c:\recycler\NPROTECT\00000075
c:\recycler\NPROTECT\00000076
c:\recycler\NPROTECT\00000077
c:\recycler\NPROTECT\00000078
c:\recycler\NPROTECT\00000079
c:\recycler\NPROTECT\00000080
c:\recycler\NPROTECT\00000082
c:\recycler\NPROTECT\00000083
c:\recycler\NPROTECT\00000084
c:\recycler\NPROTECT\00000085
c:\recycler\NPROTECT\00000086
c:\recycler\NPROTECT\00000087
c:\recycler\NPROTECT\00000088
c:\recycler\NPROTECT\00000089
c:\recycler\NPROTECT\00000090
c:\recycler\NPROTECT\00000091
c:\recycler\NPROTECT\00000093
c:\recycler\NPROTECT\00000094
c:\recycler\NPROTECT\00000095
c:\recycler\NPROTECT\00000097
c:\recycler\NPROTECT\00000098
c:\recycler\NPROTECT\00000101
c:\recycler\NPROTECT\00000102
c:\recycler\NPROTECT\00000103
c:\recycler\NPROTECT\00000104
c:\recycler\NPROTECT\00000106
c:\recycler\NPROTECT\00000108
c:\recycler\NPROTECT\00000109
c:\recycler\NPROTECT\00000110
c:\recycler\NPROTECT\00000111
c:\recycler\NPROTECT\00000112
c:\recycler\NPROTECT\00000113
c:\recycler\NPROTECT\00000114
c:\recycler\NPROTECT\00000115
c:\recycler\NPROTECT\00000116
c:\recycler\NPROTECT\00000117
c:\recycler\NPROTECT\00000118
c:\recycler\NPROTECT\00000119
c:\recycler\NPROTECT\00000121
c:\recycler\NPROTECT\00000122
c:\recycler\NPROTECT\00000123
c:\recycler\NPROTECT\00000125
c:\recycler\NPROTECT\00000126
c:\recycler\NPROTECT\00000127
c:\recycler\NPROTECT\00000128
c:\recycler\NPROTECT\00000130
c:\recycler\NPROTECT\00000131
c:\recycler\NPROTECT\00000132
c:\recycler\NPROTECT\00000133
c:\recycler\NPROTECT\00000134
c:\recycler\NPROTECT\00000135
c:\recycler\NPROTECT\00000137
c:\recycler\NPROTECT\00000138
c:\recycler\NPROTECT\00000139
c:\recycler\NPROTECT\00000140
c:\recycler\NPROTECT\00000141
c:\recycler\NPROTECT\00000143
c:\recycler\NPROTECT\00000144
c:\recycler\NPROTECT\00000145
c:\recycler\NPROTECT\00000146
c:\recycler\NPROTECT\00000147
c:\recycler\NPROTECT\00000148
c:\recycler\NPROTECT\00000149
c:\recycler\NPROTECT\00000150
c:\recycler\NPROTECT\00000151
c:\recycler\NPROTECT\00000152
c:\recycler\NPROTECT\00000153
c:\recycler\NPROTECT\00000157
c:\recycler\NPROTECT\00000158.dat
c:\recycler\NPROTECT\00000159.dat
c:\recycler\NPROTECT\00000160.dat
c:\recycler\NPROTECT\00000161.dat
c:\recycler\NPROTECT\00000162
c:\recycler\NPROTECT\00000163
c:\recycler\NPROTECT\00000164
c:\recycler\NPROTECT\00000165
c:\recycler\NPROTECT\00000166
c:\recycler\NPROTECT\00000167
c:\recycler\NPROTECT\00000168
c:\recycler\NPROTECT\00000169
c:\recycler\NPROTECT\00000170
c:\recycler\NPROTECT\00000171
c:\recycler\NPROTECT\00000172
c:\recycler\NPROTECT\00000174
c:\recycler\NPROTECT\00000176.dat
c:\recycler\NPROTECT\00000179
c:\recycler\NPROTECT\00000180.bat
c:\recycler\NPROTECT\00000181
c:\recycler\NPROTECT\00000182
c:\recycler\NPROTECT\00000183
c:\recycler\NPROTECT\00000184
c:\recycler\NPROTECT\00000185
c:\recycler\NPROTECT\00000186
c:\recycler\NPROTECT\00000187
c:\recycler\NPROTECT\00000189
c:\recycler\NPROTECT\00000190
c:\recycler\NPROTECT\00000192
c:\recycler\NPROTECT\00000193
c:\recycler\NPROTECT\00000194
c:\recycler\NPROTECT\00000197
c:\recycler\NPROTECT\00000198
c:\recycler\NPROTECT\00000199
c:\recycler\NPROTECT\00000200
c:\recycler\NPROTECT\00000201
c:\recycler\NPROTECT\00000202
c:\recycler\NPROTECT\00000203
c:\recycler\NPROTECT\00000205
c:\recycler\NPROTECT\00000206
c:\recycler\NPROTECT\00000207
c:\recycler\NPROTECT\00000208
c:\recycler\NPROTECT\00000209
c:\recycler\NPROTECT\00000210
c:\recycler\NPROTECT\00000211
c:\recycler\NPROTECT\00000212
c:\recycler\NPROTECT\00000213
c:\recycler\NPROTECT\00000214
c:\recycler\NPROTECT\00000215
c:\recycler\NPROTECT\00000216
c:\recycler\NPROTECT\00000217
c:\recycler\NPROTECT\00000218
c:\recycler\NPROTECT\00000219
c:\recycler\NPROTECT\00000220
c:\recycler\NPROTECT\00000221
c:\recycler\NPROTECT\00000222
c:\recycler\NPROTECT\00000223
c:\recycler\NPROTECT\00000224
c:\recycler\NPROTECT\00000225
c:\recycler\NPROTECT\00000226
c:\recycler\NPROTECT\00000227
c:\recycler\NPROTECT\00000228
c:\recycler\NPROTECT\00000229
c:\recycler\NPROTECT\00000230
c:\recycler\NPROTECT\00000231
c:\recycler\NPROTECT\00000232
c:\recycler\NPROTECT\00000233
c:\recycler\NPROTECT\00000234
c:\recycler\NPROTECT\00000235
c:\recycler\NPROTECT\00000236
c:\recycler\NPROTECT\00000237
c:\recycler\NPROTECT\00000238
c:\recycler\NPROTECT\00000239
c:\recycler\NPROTECT\00000240
c:\recycler\NPROTECT\00000241
c:\recycler\NPROTECT\00000242
c:\recycler\NPROTECT\00000243
c:\recycler\NPROTECT\00000244
c:\recycler\NPROTECT\00000245
c:\recycler\NPROTECT\00000246
c:\recycler\NPROTECT\00000247
c:\recycler\NPROTECT\00000248
c:\recycler\NPROTECT\00000250
c:\recycler\NPROTECT\00000251
c:\recycler\NPROTECT\00000252
c:\recycler\NPROTECT\00000253
c:\recycler\NPROTECT\00000255
c:\recycler\NPROTECT\00000258
c:\recycler\NPROTECT\00000259
c:\recycler\NPROTECT\00000260
c:\recycler\NPROTECT\00000261
c:\recycler\NPROTECT\00000262
c:\recycler\NPROTECT\00000263.dat
c:\recycler\NPROTECT\00000264
c:\recycler\NPROTECT\00000265.bad
c:\recycler\NPROTECT\00000266
c:\recycler\NPROTECT\00000267
c:\recycler\NPROTECT\00000268
c:\recycler\NPROTECT\00000269
c:\recycler\NPROTECT\00000270
c:\recycler\NPROTECT\00000276
c:\recycler\NPROTECT\00000278.md5
c:\recycler\NPROTECT\00000284.tlv
c:\windows\Installer\1f6dd6.msi
c:\windows\Installer\2a9c236.msi
c:\windows\Installer\3ade04c.msi
c:\windows\Installer\45550ed.msi
c:\windows\Installer\51f7b95.msi
c:\windows\patchw32.dll
c:\windows\pw32a.dll
c:\windows\system32\system
c:\windows\system32\system\msxml4.dll
c:\windows\system32\system\msxml4r.dll
c:\recycler\NPROTECT . . . . failed to delete
c:\recycler\NPROTECT\NPROTECT.LOG . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2009-07-07 to 2009-08-07 )))))))))))))))))))))))))))))))
.

2009-08-07 04:28 . 2009-08-07 11:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-08-07 04:26 . 2009-08-07 04:26 -------- d-----w- c:\program files\Common Files\iS3
2009-08-07 04:26 . 2009-08-07 12:26 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-07-31 17:47 . 2009-07-31 17:56 161665 ----a-w- c:\windows\hpqins00.dat
2009-07-31 17:45 . 2009-07-31 17:45 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-07-30 14:57 . 2009-07-30 14:57 45056 ----a-r- c:\documents and settings\Russell\Application Data\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2009-07-30 14:49 . 2004-03-14 07:43 135249 ----a-w- c:\windows\system32\hpzlnt10.dll
2009-07-30 14:32 . 2004-06-21 17:44 17176 ------w- c:\windows\hpomdl04.dat
2009-07-30 14:16 . 2009-07-30 15:13 104157 ----a-w- c:\windows\hpoins04.dat
2009-07-30 01:40 . 2009-08-04 12:40 -------- d-----w- c:\program files\fxsolutions
2009-07-30 00:59 . 2009-07-30 00:59 -------- d-----w- c:\program files\FX
2009-07-19 19:04 . 2009-07-19 19:04 10134 ----a-r- c:\documents and settings\Russell\Application Data\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
2009-07-19 18:21 . 2009-07-19 18:21 10134 ----a-r- c:\documents and settings\Russell\Application Data\Microsoft\Installer\{4CCC7F68-A437-4559-A840-F5E010934951}\ARPPRODUCTICON.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-07 19:30 . 2007-11-06 03:51 -------- d-----w- c:\documents and settings\Russell\Application Data\Skype
2009-08-07 19:30 . 2008-07-23 02:36 -------- d-----w- c:\documents and settings\Russell\Application Data\skypePM
2009-08-07 19:13 . 2007-09-18 21:07 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-08-07 06:37 . 2009-08-07 04:38 2416 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-08-07 04:38 . 2009-08-07 04:38 104 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-08-06 12:15 . 2007-09-18 00:07 67208 ----a-w- c:\documents and settings\Russell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-06 00:10 . 2008-01-29 01:26 -------- d-----w- c:\documents and settings\Russell\Application Data\Image Zone Express
2009-08-05 19:35 . 2007-09-19 21:46 -------- d-----w- c:\program files\Position Cost Averaging
2009-08-04 10:39 . 2007-09-18 21:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-31 17:34 . 2007-09-23 00:04 99736 ----a-w- c:\windows\CPEins05.dat
2009-07-31 00:26 . 2007-09-18 02:56 -------- d-----w- c:\documents and settings\Russell\Application Data\Professional
2009-07-30 15:31 . 2007-09-18 05:33 3458 ----a-w- c:\documents and settings\Russell\Application Data\SAS7_000.DAT
2009-07-30 15:09 . 2007-09-18 03:03 -------- d-----w- c:\program files\HP
2009-07-20 18:19 . 2008-09-16 15:13 -------- d-----w- c:\program files\Norton SystemWorks Basic Edition
2009-07-06 20:14 . 2009-07-01 16:16 -------- d-----r- c:\program files\Skype
2009-07-04 02:58 . 2009-07-04 02:58 -------- d-----w- c:\program files\Common Files\Skype
2009-07-04 02:58 . 2007-11-06 03:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-03 02:37 . 2007-09-23 01:45 -------- d-----w- c:\documents and settings\Russell\Application Data\Simple Star
2009-07-03 02:37 . 2007-09-23 01:46 -------- d-----w- c:\program files\Common Files\Simple Star Shared
2009-07-01 01:22 . 2007-09-18 01:35 -------- d-----w- c:\program files\Common Files\Real
2009-07-01 01:22 . 2009-07-01 01:22 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-01 01:07 . 2008-07-14 14:16 -------- d-----w- c:\program files\Logitech
2009-06-30 21:13 . 2008-07-14 14:16 -------- d-----w- c:\program files\Common Files\Logitech
2009-06-30 21:13 . 2007-09-14 20:41 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-29 16:12 . 2006-02-28 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-06-18 03:31 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2006-02-28 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2006-02-28 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-13 13:49 . 2009-06-13 13:49(NNN) NNN-NNNN----a-w- c:\documents and settings\Russell\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-06-09 12:15 . 2008-04-10 16:40 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-06-03 19:09 . 2006-02-28 12:00(NNN) NNN-NNNN----a-w- c:\windows\system32\quartz.dll
2007-09-20 02:08 . 2007-09-20 02:08 40 ---h--r- c:\program files\winx14.dl
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Actual Title Buttons"="c:\program files\Actual Title Buttons\ActualTitleButtonsCenter.exe" [2008-05-15 776192]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13(NNN) NNN-NNNN
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-06-19(NNN) NNN-NNNN
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-26 25604904]
"AOL Fast Start"="c:\program files\AOL 9.5\AOL.EXE" [2009-02-11 50472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"NSWosCheck"="c:\program files\Norton SystemWorks Basic Edition\osCheck.exe" [2007-09-18 25472]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2008-02-07 718704]
"AcctMgr"="c:\program files\Norton Password XXXXX\AcctMgr.exe" [2005-07-29 586896]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"HostManager"="c:\program files\Common Files\AOL\1190079269\ee\AOLSoftware.exe" [2008-11-06 41264]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-01-09 669840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-01 198160]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Russell^Start Menu^Programs^Startup^CCC.lnk]
path=c:\documents and settings\Russell\Start Menu\Programs\Startup\CCC.lnk
backup=c:\windows\pss\CCC.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"HP Status Server"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1190079269\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Schwab\\SSPro\\SSPro.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Common Files\\AOL\\1190079269\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Actual Title Buttons\\ActualTitleButtonsCenter.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\AOL 9.5\\waol.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"137:TCP"= 137:TCP:NetBIOS-ns
"138:TCP"= 138:TCP:netbios-ssn
"139:UDP"= 139:UDP:netbios-ssn
"445:UDP"= 445:UDP:netbios-ssn
"427:TCP"= 427:TCP:SLP Discovery
"427:UDP"= 427:UDP:SLP Discovery
"68:TCP"= 68:TCP:dhcp client
"161:TCP"= 161:TCP:SNMP
"5353:TCP"= 5353:TCP:mDNS
"9100:TCP"= 9100:TCP:pcl/pjl print
"9101:TCP"= 9101:TCP:debugging tcp recv/send
"9102:TCP"= 9102:TCP:debugging tcp send
"9103:TCP"= 9103:TCP:debugging udp recv/send
"9110:TCP"= 9110:TCP:echo
"9220:TCP"= 9220:TCP:generic gateway
"9290:TCP"= 9290:TCP:scan
"9500:TCP"= 9500:TCP:9500
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [1/23/2007 9:07 PM 39080]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [1/25/2008 9:47 PM 149352]
R2 MSSQL$VPINSTANCE;SQL Server (VPINSTANCE);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2/10/2007 5:29 AM 29178224]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\NORTON~1\NORTON~1\NPROTECT.EXE [11/3/2005 11:08 PM 95832]
R2 smtclman;SMT Client Manager;System32\smtclman.exe --> System32\smtclman.exe [?]
R2 SWIHPWMI;SWIHPWMI;c:\program files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [12/4/2006 4:13 PM 292384]
R2 swline;TSX Swingline Provider;c:\windows\system32\drivers\swline.sys [6/25/2008 10:05 PM 186176]
R3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/15/2009 7:47 AM 101936]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [9/14/2007 4:54 PM 36608]
R3 smtcore;SMT Provider Manager;c:\windows\system32\drivers\smtcore.sys [6/25/2008 10:05 PM 178496]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [9/14/2007 4:57 PM 33024]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {C7099049-4779-1634-2C83-372EE984396F} /qb
.
Contents of the 'Scheduled Tasks' folder

2009-06-01 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Russell.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 14:05]

2009-07-20 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Norton SystemWorks Basic Edition\OBC.exe [2007-09-18 12:22]

2009-08-07 c:\windows\Tasks\Symantec Drmc.job
- c:\program files\Common Files\Symantec Shared\SymDrmc.exe [2003-09-10 08:48]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-SITEguard - (no file)
ShellIconOverlayIdentifiers-{01CCCC8C-1D50-4b13-B96D-4B922DD3128B} - (no file)
HKCU-Run-Simple Star PhotoShow Media Manager - c:\progra~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
HKCU-Run-WebCamRT.exe - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-07 15:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1547161642-1757981266-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1564)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(5840)
c:\windows\system32\WININET.dll
c:\program files\Actual Title Buttons\atbemb.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\windows\system32\ieframe.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll

- - - - - - - > 'csrss.exe'(1532)
c:\program files\Actual Title Buttons\ConsoleHelper.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\VAScanner\comHost.exe
c:\progra~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Carbonite\Carbonite Backup\CarboniteService.exe
c:\windows\system32\IFXSPMGT.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\IfxPsdSv.exe
c:\windows\system32\smtclman.exe
c:\progra~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Verizon Wireless\venturi\Client\VentC.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\windows\system32\swloader.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\program files\AOL 9.5\waol.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\vssvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\msdtc.exe
c:\program files\AOL 9.5\shellmon.exe
.
**************************************************************************
.
Completion time: 2009-08-07 15:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-07 19:37

Pre-Run: 50,482,524,160 bytes free
Post-Run: 50,445,381,632 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /usepmtimer /NoExecute=OptIn

571 --- E O F --- 2009-07-30 07:01

Expert:  Anthony Brewster replied 5 years ago.
<p>Thanks! OMG that was SO MANY THINGS DELETED lol but a good thing for you! You were seriously infected.</p><p> </p><p>Also, if FAILED to delete 2 items which is strange because ComboFix is very powerful. The 2 infections are located within your System Restore. I need you to turn OFF system restore and then turn it back ON to clear them.</p><p> </p><p>1) Click Start</p><p>2) Right-Click My Computer</p><p>3) Click Properties</p><p>4) Click System Restore Tab</p><p> </p><p>Now all you have to do is uncheck the box, apply, ok and then go back and check the box, apply, and click ok and thats it. DONE!</p><p> </p><p>As far as the BPD, this could have something to do with your HP Printer Software. What is the model/series of your printer?</p><p> </p><p>Thanks!</p>
Customer: replied 5 years ago.
Hi, Okay I went to Internet Explorer and it did open, I'll try to follow your instructions, however I don't understand where to go. I'll try. Thanks
Customer: replied 5 years ago.
Okay I completed the System Restore instructions, I have a hp 2510 all-in-one printer also have a C6180 all-in-one printer at another location,
Expert:  Anthony Brewster replied 5 years ago.
Thank You! I also need to tell you that the NPROTECT refered to Norton, it protects these files somewhere but im thinking it is in the recycling bin, try to right-click on the recycling bin and if you see a clean norton thing there, please do that.



For your HP Printer, go here and download the most up-2-date driver.



http://h10025.www1.hp.com/ewfrf/wc/softwareCategory?product=303770&lc=en&cc=us&dlc=en&lang=en&cc=us





Please download ONLY the one thats reads (HP Officejet and Photosmart Full Feature Software and Drivers) and install the WHOLE package for me and then restart your computer and it should all be all set.



BEST OF LUCK!
GOD BLESS!



:)
Customer: replied 5 years ago.
I did all you said and the box still comes on when I start the computer, I guss maybe I should call HP for Tech support.
Expert:  Anthony Brewster replied 5 years ago.
<p>You can try yes. We had made a lot of process here and at least we did remove all of the infections. Here is the HP Tech Support info.</p><p> </p><p>1-800-474-6836</p><p> </p><p> </p><p>I will consult with other techs here on this issue and get back with you.</p><p> </p><p> </p><p>GOD BLESS!</p>
Customer: replied 5 years ago.
Okay, I will wait to hear from you, I am going to go ahead ans call HP, thanks for the number.
Expert:  Anthony Brewster replied 5 years ago.
<p>OK! I also want you to download and run the microsoft Autoruns. Here is the link...</p><p> </p><p> </p><p><a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx">http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx</a></p><p> </p><p> </p><p>When you get there, click on this (<a id="ctl00_mainContentContainer_ctl14" href="DANGEROUS URL REMOVED" onclick="javascript:Track('ctl00_mainContentContainer_ctl00|ctl00_mainContentContainer_ctl14',this);"><strong>Run Autoruns</strong></a> now from Live.Sysinternals.com) click on the blue run autoruns and run it.</p><p> </p><p>Once you have it running, click on Options and then click on Hide Microsoft and Windows Entries. Then, press F5 to refesh the list and now please go through it, and DELETE everything that reads (file not found) under the Image Path and at the same time, (look out) for the BPD Software and if found, DELETE it as well. </p><p> </p><p>To DELETE, (right-click) and click delete/remove.</p><p> </p><p> </p><p>BEST OF LUCK!<br />GOD BLESS!</p><p> </p><p>:)</p>

JustAnswer in the News:

 
 
 
Ask-a-doc Web sites: If you've got a quick question, you can try to get an answer from sites that say they have various specialists on hand to give quick answers... Justanswer.com.
JustAnswer.com...has seen a spike since October in legal questions from readers about layoffs, unemployment and severance.
Web sites like justanswer.com/legal
...leave nothing to chance.
Traffic on JustAnswer rose 14 percent...and had nearly 400,000 page views in 30 days...inquiries related to stress, high blood pressure, drinking and heart pain jumped 33 percent.
Tory Johnson, GMA Workplace Contributor, discusses work-from-home jobs, such as JustAnswer in which verified Experts answer people’s questions.
I will tell you that...the things you have to go through to be an Expert are quite rigorous.
 
 
 

What Customers are Saying:

 
 
 
  • My Expert answered my question promptly and he resolved the issue totally. This is a great service. I am so glad I found it I will definitely use the service again if needed. One Happy Customer New York
< Last | Next >
  • My Expert answered my question promptly and he resolved the issue totally. This is a great service. I am so glad I found it I will definitely use the service again if needed. One Happy Customer New York
  • I am very happy with my very fast response. Eric is very knowledgeable in the subject area. Thank you! RP Austin, TX
  • Hi John, Thank you for your expertise and, more important, for your kindness because they make me, almost, look forward to my next computer problem. After the next problem comes, I'll be delighted to correspond again with you. I'm told that I excel at programing. But system administration has never been one of my talents. So it's great to have an expert to rely on when the computer decides to stump me. God bless, Bill Bill M. Schenectady, New York
  • The Expert answered my Mac question and was patient. He answered in a thorough and timely manner, keeping the response on a level that could understand. Thank you! Frank Canada
  • Wonderful service, prompt, efficient, and accurate. Couldn't have asked for more. I cannot thank you enough for your help. Mary C. Freshfield, Liverpool, UK
  • This expert is wonderful. They truly know what they are talking about, and they actually care about you. They really helped put my nerves at ease. Thank you so much!!!! Alex Los Angeles, CA
  • Thank you for all your help. It is nice to know that this service is here for people like myself, who need answers fast and are not sure who to consult. GP Hesperia, CA
 
 
 

Meet The Experts:

 
 
 
  • Andy

    Computer Consultant

    Satisfied Customers:

    5311
    11yr exp, Comp Engg, Internet expert, Web developer, SEO
< Last | Next >
  • http://ww2.justanswer.com/uploads/EN/Engineer1010/2012-6-9_132423_jaj12a.64x64.jpg Andy's Avatar

    Andy

    Computer Consultant

    Satisfied Customers:

    5311
    11yr exp, Comp Engg, Internet expert, Web developer, SEO
  • http://ww2.justanswer.com/uploads/BA/barrenrock/2011-10-19_215925_JamesJAFinal.64x64.jpg James's Avatar

    James

    Sr. Computer Support Expert

    Satisfied Customers:

    8376
    20 years of experience building, fixing and servicing PCs and operating systems.
  • http://ww2.justanswer.com/uploads/zeyank/2009-09-26_154244_P8110079.png Ryan H.'s Avatar

    Ryan H.

    Computer Support Specialist

    Satisfied Customers:

    1741
    A+ Certified Technician - 10 Years experience working with all types of computer systems.
  • http://ww2.justanswer.com/uploads/JA/jadedangel57/2011-11-8_193134_janenewsm.64x64.jpg Jane Lefler's Avatar

    Jane Lefler

    Sr Prog Analyst / Technician

    Satisfied Customers:

    0
    Computer Programmer / Technician/ Consultant 16+ years
  • http://ww2.justanswer.com/uploads/RO/robmpreston/2013-9-23_233814_mijiFZm.64x64.jpg RPI Solutions's Avatar

    RPI Solutions

    Support Specialist

    Satisfied Customers:

    3476
    5+ Years in IT, BS in Computer Science
  • http://ww2.justanswer.com/uploads/BA/barunrath/2012-7-5_201954_Profilepic2.64x64.jpg B. Rath's Avatar

    B. Rath

    Computer Support Specialist

    Satisfied Customers:

    8671
    Certified Computer/Networking Support Specialist.
  • http://ww2.justanswer.com/uploads/FS/fszcze/2012-6-18_181848_500test.64x64.jpg Frederick S.'s Avatar

    Frederick S.

    Computer Specialist

    Satisfied Customers:

    7240
    Computer technician and founder of a home PC repair company.
 
 
 
Chat Now With A Tech Support Specialist
Anthony Brewster
Anthony Brewster
4757 Satisfied Customers
MICROSOFT PC SAFETY, WINDOWS LIVE ONECARE, WINDOWS GENUINE, & I.T. SPECIALIST