Black Screen Problem seems to have returned

  1. #1
    chickenlil is offline Junior Member

    Re: Hijack this -8/27/06 (RESOLVED)

    Hi there - I haven't had a problem now in over 2 weeks, but today the running speed slowed down considerably, and now I have had an incident of the screen going black again. Below is the error message. I am going to run the Kaspersky scan again. The latest device drivers are installed, and I have already worked on the Hardware Acceleration slider. I am not pleased to have this happening again...should I run Hijack this and post?
    Thanks for any suggestions!

    LiL


    Error type Windows stop error (A message appears on a blue screen with error code information)
    Solution available? Yes
    What does this error mean? You received this message because a device driver installed on your computer caused the Windows operating system to stop unexpectedly. This type of error is referred to as a "stop error." A stop error requires you to restart your computer.
    Cause A video adapter device driver
    Computer symptoms A message appears on a blue screen with error code information:

    STOP 0x000000EA THREAD_STUCK_IN_DEVICE_DRIVER
    - or -
    STOP: 0x100000EA THREAD_STUCK_IN_DEVICE_DRIVER_M


  2. #2
    chickenlil is offline Junior Member
    I will do the Hijack this as soon as I can get clear of some open programs.
    Here is the Kaspersky scan - I haven't done anything about it yet.
    I assume I should go into safe mode and delete these files, as I did before?
    Let me know before I do anything.
    Thanks,
    LiL


    Scan Statistics:
    Total number of scanned objects: 58699
    Number of viruses found: 1
    Number of infected objects: 2 / 0
    Number of suspicious objects: 0
    Duration of the scan process: 00:57:47

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c914ad206418 3727772b3bdbfd4ee6b8_680fce1e-5b19-4f1f-bb9f-408e1495b4f6 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\AVG7\Log\emc.log Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\call256.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\callmember256.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\chat512.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\chatmsg1024.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\chatmsg256.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\chatmsg512.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\contactgroup256.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\index2.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\profile256.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\user1024.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\user16384.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\user256.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Application Data\Skype\lupowitz2075\voicemail256.dbb Object is locked skipped
    C:\Documents and Settings\Linda XP\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Linda XP\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\Local Settings\History\History.IE5\MSHist012006091520060 916\index.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\Local Settings\Temp\~DF7DEA.tmp Object is locked skipped
    C:\Documents and Settings\Linda XP\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\ntuser.dat Object is locked skipped
    C:\Documents and Settings\Linda XP\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\iolo\System Mechanic 5 Professional\Undo\Manual\{6CC4A570-A73C-43D8-88CA-D603BC6DF503}\{27DFA078-CB9C-4CD2-9572-529A409C4648}.tmp/{27DFA078-CB9C-4CD2-9572-529A409C4648}.tmp Infected: Trojan-Downloader.Win32.Small.apm skipped
    C:\Program Files\iolo\System Mechanic 5 Professional\Undo\Manual\{6CC4A570-A73C-43D8-88CA-D603BC6DF503}\{27DFA078-CB9C-4CD2-9572-529A409C4648}.tmp ZIP: infected - 1 skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{353530CC-3D5F-4C9C-A910-6A8C2F288BBE}\RP7\change.log Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB833987$\sxs.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\browser.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
    C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  3. #3
    VopThis is offline Senior Member (Canada)
    Kaspersky only found two (2?) infected quarantine items that still reside in 'System Mechanic'. Try locating and removing those items in that application, first, once you are sure there is no reason that you may need such quarantine/backup items back.

    C:\Program Files\iolo\System Mechanic 5 Professional\Undo\Manual\{6CC4A570-A73C-43D8-88CA-D603BC6DF503}\{27DFA078-CB9C-4CD2-9572-529A409C4648}.tmp/{27DFA078-CB9C-4CD2-9572-529A409C4648}.tmp Infected: Trojan-Downloader.Win32.Small.apm skipped
    C:\Program Files\iolo\System Mechanic 5 Professional\Undo\Manual\{6CC4A570-A73C-43D8-88CA-D603BC6DF503}\{27DFA078-CB9C-4CD2-9572-529A409C4648}.tmp ZIP: infected - 1 skipped

  4. #4
    chickenlil is offline Junior Member
    OK, I will take a look at that.
    PS It just blanked out again, while I was checking email. first mouse locks up, then screen goes black.

    PPS Any reason I need the IPod service, I don't have an IPod or a Mac. ? Nor I-Tunes...

    Here's the Hijack This log I just ran:

    Logfile of HijackThis v1.99.1
    Scan saved at 9:01:02 PM, on 9/15/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Downlo~1\MyWebEx\319\atnthost.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\system32\LVComS.exe
    C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\Spyware Doctor\swdoctor.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_Update.exe
    C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe
    C:\HJT\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [TVTool] "C:\Program Files\TVTool\TVTool.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\system32\LVComS.exe
    O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr. exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - Startup: Slide.exe.lnk = C:\Program Files\Slide\Slide.exe
    O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
    O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_Update.exe
    O4 - Global Startup: WebEx PCNow.LNK = ?
    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com...n/preview.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...67&clcid=0x409
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1121721148452
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mwmus.webex.com/mwmus/tool/s...ck/ieatgpc.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\Downlo~1\MyWebEx\319\atnthost.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

    LiL in New Mexico

  5. #5
    VopThis is offline Senior Member (Canada)
    PS It just blanked out again, while I was checking email. first mouse locks up, then screen goes black.
    There is no evidence of any HJT issues. Your error message certainly appears to suggest driver related issues. Most particularly, this all sounds like screensaver conflict related issues:

    http://www.google.ca/search?hl=en&q=...G=Search&meta=

    Your orginal problems featured an undesirable 'downloaded program file' item in your HJT log. You may still have undesirable screensaver leftovers from this service. Try changing or selecting none for your current settings re: wallpaper, background, and screensaver to see if that makes any difference.

    PPS Any reason I need the IPod service, I don't have an IPod or a Mac. ? Nor I-Tunes...
    I have no specific answer for that at this time. It may now be bundled with 'quicktime' download. May want to inquiry in the XP Forum before taking any optional action on this.

  6. #6
    chickenlil is offline Junior Member
    Save 20% on AVG Internet Security 2012 Suite!
    Hi - I did a search for scr files, and found only one, on Picasa2 - which is
    a photoediting/organizer software - apparently has a screen saver, though I
    don't know why. I clicked on the screen saver icon and it blacks out the
    screen, all right! Anyway, I deleted that, so we'll see if it changes. Also
    shut down the Windows screensaver. As for the infected files in iola/system
    mechanic 5 -they must be hidden files (quarantined) and I can't find them.
    Thanks!



    This advice from a friend:

    >> well, the scr file is just a way to try to track down what happened - so
    >> writing down the name of any scr files that might correlate date-wise is
    >> just so we can research the name and see - the scr file all by itself is
    >> harmless but it might have been attached to something else first - like
    >> if
    >> you see gone.scr then you know you got a certain other virus/trojan bad
    >> guy at some point... like that, so that's why writing down the name...
    >>
    >> or you might have a legit scr file that is corrupted or uses a memory
    >> address that freaks out your computer!
    >> ie conflicts with something else running in memory, that's one of the
    >> downfalls of running stuff like that, i never run screen savers, never
    > ever
    >>

+ Reply to Thread