During the process of removing malware from your computer, there are times you may need to use
specialized fix tools. Certain embedded files that are part of these specialized fix tools may be detected by your antivirus or anti-malware scanner as a
RiskTool, Hacking tool, Potentially unwanted tool, a virus or a Trojan when that is not the case.
These tools have been carefully created and tested by security experts so if your antivirus or anti-malware program flags them as malware, then it is a
False Positive. Antivirus scanners cannot distinguish between
good and
malicious use of such programs; therefore, they may alert you or even automatically remove them. In these cases, the removal of these files can have
unpredictable results and unintentional results.To avoid any problems while using a
specialized fix tool, it is very important that you temporarily disable your antivirus and/or anti-malware programs before using the
specialized fix tool.
When your system has been cleaned, it is important that you enable your security programs to avoid reinfection.
Please disable the following programs:
Disable Windows Defender- Click Start > Programs > Windows Defender or launch from the system tray icon.
- Click on Tools
- Click on General Settings
- Scroll down to Real-time protection options
- Uncheck Turn on Real-time protection (recommended)
- Click Save
- Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defender's page, uncheck under Administrator Options, use Windows Defender and then Save.
- Exit the program.
Note: After all of the fixes are complete, it is very important that you enable Real-time Protection again.Step 2You will be removing the program from your startup but you will not be removing the program itself.Please run
HijackThis and click
Scan. Place checks next to the following entries:
You have
jusched.exe running at Startup. It checks with Sun's Java updates site to see if newer Java versions are available. This program is not required to start automatically. You can do this manually by visiting
http://java.sun.com or just run the Java Plug-In Control Panel. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" OneTouch.EXE (MaxtorOneTouch) process can be removed to free up resources without compromising system performance. One Touch keyboard driver. Required if you use the additional keys. onetouch.exe is a process belonging to the OneTouch backup system and allows this product to be accessed when pushing the button on your external Maxtor disk drive. This is a valid program but it is not required to run on startup. Whether or not you need to run this program on startup must be decided by you. If you feel that you want this program starting automatically so that you have it available as needed, then do not disable it. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe MXOALDR.EXE ( Maxtor OneTouch) process can be removed to free up resources without compromising system performance. Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions. This is a valid program but it is not required to run on startup. Whether or not you need to run this program on startup must be decided by you. If you feel that you want this program starting automatically so that you have it available as needed, then do not disable it. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXEATIPtaxx.exe is the tray bar process for your ATI graphics card drivers. It gives you easy access to your graphic card settings. It is the control panel for the ATI series of video cards allowing access to such features as display resolution, color depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimized their settings. This process can be removed to free up system resources. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exeSSBkgdUpdate.exe (ScanSoft OmniPage) process can be removed to free up resources without compromising system performance. ScanSoft OmniPage auto updater. Can be disabled using the main program's options. This program is also installed with other Nuance products. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -bootpptd40nt.exe (PaperPort PTD) process can be removed to free up resources without compromising system performance. "PaperPort" software associated with scanners. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"IndexSearch.exe (ScanSoft PaperPort scanner) process can be removed to free up resources without compromising system performance. IndexSearch.exe is normally a file that comes from a company named Scansoft. They typically use this file name in their paperport scanner software, as a scanner software program. Associated with PaperPort scanner software from ScanSoft. This is a valid program but it is not required to run on startup. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe BrStDvPt.exe (Brother MFC printer/copier/scanner) process can be removed to free up resources without compromising system performance. BrStDvPt.exe is a file that was most likely installed at some time after you purchased your computer. The exact disk location is C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe so you can verify it is not spyware related. This is from Brother Industries, and its purpose is to work with your printers and scanners to check or set the default printer on your computer. This is a valid program but it is not required to run on startup. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe brctrcen.exe (Brother Scan, Copy & Fax Control Center) process can be removed to free up resources without compromising system performance. Brother Scan, Copy & Fax Control Center. System Tray program installed by the drivers for Brother MFC Multi-Function printers (Printer/Scanner/Photocopier/Fax) which enables the user to perform scanning, faxing, and copying functions directly from their PC. This program enables you to do more things than you can do from the printer's own Control Pad. Typically you can scan directly to file, scan to email, scan to fax (if you have a fax modem in your PC or if your Brother Multi-Function printer has faxing capabilities), scan to Word Processor via OCR conversion, manage photocopying jobs, or fax from your PC. This is a valid program but it is not required to run on startup. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun apdproxy.exe (adobe photo downloader) process can be removed to free up resources without compromising system performance. Apdproxy.exe is software program that is from Adobe. This software is graphics related software and it is part of the Adobe Photoshop. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"nerocheck.exe (Nero CD writing or Nero CD/DVD software) is a process associated with the Nero CD writing or Nero CD/DVD software. It is used to install or control the Nero driver nerocd2k.sys application. This process should not be removed while using the Nero CD Writing software. This program constantly checks for known drivers that can conflict with our Nero/Nero Express/NeroVision Express software. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe You have
QuickTime running at Startup. This is QuickTime's system tray icon and not necessary for the program to function properly. It is considered to be a resource hog. qttask.exe produced by Apple, installs a tray bar icon which links to the Apple QuickTime video streaming tool. This program is a non-essential system process, and is installed for ease of use. You will still be able to start it manually if you need it. You can fix this with HijackThis, but you will need to change the setting in QuickTime Player itself to keep it from resetting itself. Item(s) to fix in HijackThis:
O4 ‑ HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" ‑atboottimeThere is a small program that will prevent QuickTime from resetting itself.
Please download
Engraph-QuickTime-Killer This is a free utility from EnGraph software. For more information about EnGraph, go to
http://www.engraph.com. This application is intended for people that use or consume Sprint Video Mail, as Sprint uses QuickTime for viewing thier movies. (or anybody that hates QuickTime) Of course, as soon as QuickTime is ran, it adds itself to startup, which is very annoying to me. This application will remove QuickTime from start up and kill any running QuickTime processes. This application runs silently at start up and closes itself as soon as it takes care of QuickTime.
You have
iTunesHelper.exe running at Startup. iTunesHelper.exe is a process belonging to Itunes MP3 streaming tool by Apple which allows you to play MP3's. This process speeds up iTunes when it starts, and the program also monitors for connected iPod devices. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe You have
realsched.exe (RealPlayer's autoupdate program) running at Startup. This is RealPlayer's autoupdate program and is not necessary for the program to function properly. realsched.exe is a program which schedules for manual update checks for Real Networks products. This is a non-essential process. Disabling or enabling this is down to user preference however disabling may prevent notification of updates. It is considered to be a resource hog. You will still be able to start it manually if you need it. You can fix this with HijackThis, but you will need to change the setting in RealPlayer itself to keep it from resetting itself. Item(s) to fix in HijackThis:
O4 ‑ HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" ‑osbootYou have
reader_sl.exe running at Startup. This is a process associated with the Adobe Reader. It is used to decrease the load time for the reader when a PDF document is selected. This is a non-essential process. You will still be able to start it manually if you need it. You can fix this with HijackThis. Item(s) to fix in HijackThis:
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"msmsgs.exe (MSN Messenger Internet chat tool) is the main process relating to the MSN Messenger Internet chat tool installed by default on most Windows computers. The
Windows Messenger (IM, MSN Messenger) from Microsoft provides
Online Chat and
Instant Messaging. If you don't use
Windows Messenger, you can
- Rename the "Messenger" folder.
- Uninstall, Stop, Disable or Remove "Windows Messenger (IM, MSN Messenger)".
A tray bar is also installed alongside this process for easy access to its features which include Internet chat, file sharing and audio/video conferencing. This is a non-essential process. Disabling or enabling it is down to user preference. process can be removed to free up resources without compromising system performance. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe NMBgMonitor.exe (Nero Scout) process can be removed to free up resources without compromising system performance. NMBgMonitor.exe is related to Nero Scout. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"usbshare.exe (Belkin) process can be removed to free up resources without compromising system performance. USB sharing switch (Lin-X-Cel) used to share one device between 2 computers. Allows use of Ctrl-f11 key to grab the device. Users Choice (application need to be run at startup, but is not system critical). Whether or not you need to run this program on startup must be decided by you. If you feel that you want this program starting automatically so that you have it available as needed, then do not disable it. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - Global Startup: F1U201.401.lnk = ? (This is
O4 - Startup: F1U201.401.lnk = C:\Program Files\Belkin\F1U201.401\usbshare.exe)
osa.exe or Osa9.exe launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it (Osa9.exe is the Office 2000 variant). This program is not required to start automatically as you can run it when you need to. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEBrMfcWnd.exe (Brother scanner status monitor) process can be removed to free up resources without compromising system performance. brmfcwnd.exe is a process installed alongside Brother Printers and provides additional configuration options for these devices. Brother scanner status monitor - can be started manually. This is a valid program but it is not required to run on startup. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exewzqkpick.exe (WinZip) process can be removed to free up resources without compromising system performance. wzqkpick.exe is the tray bar process for WinZip. The process is used to access WinZip from the tray bar. To save resources this process can safely be removed. If you use the WinZip system tray icon, you should leave this process running. Otherwise, this process is not required for the WinZip application to work correctly. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEAppleMobileDeviceService.exe (Apple Mobile Device) process can be removed to free up resources without compromising system performance. Used by iTunes to communicate with the Apple iPhone when it is connected to your computer. This is a valid program, but it is up to you whether or not you want it to run on startup. Whether or not you need to run this program on startup must be decided by you. If you feel that you want this program starting automatically so that you have it available as needed, then do not disable it. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. Many users have reported this process slows their boot time.
To change the service to Manual.
- Right-click on My Computer and choose Manage.
- Expand the Services and Applications section and click on Services.
- On the right-side of the screen, find the entry for Apple Mobile Device and double-click on it.
- Change the Startup Type: to Manual.
- Hit the OK button and close the Computer Management screen.
It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeati2evxx.exe is the ATI External Event Utility for your ATI display drivers. It manages the ATI Hotkey feature. This process can be removed to free up resources without compromising system performance. ati2evxx.exe is a process which provides optional features that the majority of us really do not use. The XT's overdrive feature uses this. If you have an XT you'll probably want to leave this on. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources.
To change the service to Manual.
- Right-click on My Computer and choose Manage.
- Expand the Services and Applications section and click on Services.
- On the right-side of the screen, find the entry for Ati HotKey Poller and double-click on it.
- Change the Startup Type: to Manual.
- Hit the OK button and close the Computer Management screen.
Many users have reported this process slows their boot time. It may be worthwhile to fix it with HijackThis. Item(s) to fix in HijackThis:
O23 - Service: Ati HotKey Poller - Unknown owner – C:\WINDOWS\system32\Ati2evxx.exe ipodservice.exe is a process belonging to Apple's iTunes peer-to-peer download tool. The ipodservice.exe process is a utility used to download mp3 files for your iPod. If you do not use it, or do not have an iPod, you can safely disable this process. This process can be removed to free up resources without compromising system performance. It is advised that you disable this program so that it does not take up necessary resources. To disable
ipodservice, click
Start > Settings > Control Panel > Performance and Maintenance > Administrative Tools > Services. Find the
IpodService, Right-click and select
Properties. Change the setting in
StartUp type: to
Disabled or click
Start > Run. Type
services.msc Find the
IpodService, Right-click and select
Properties. Change the setting in
StartUp type to
Disabled to disable the service. Item(s) to fix in HijackThis:
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe Close all browsers and other windows except for
HijackThis, and click
Fix Checked to have
HijackThis fix the entries you checked.
Please post a new HijackThis log.