Question about Acer Aspire One PC Notebook

1 Answer

My notebook has a "huelar browser" worm that locks only one homepage. this time, it's redtube.com. also, setup.exe files cannot be run since it closes automatically, i have no way to install an antivi

This virus closes all setup.exe files i need to install in my notebook

Posted by on

1 Answer

  • Level 2:

    An expert who has achieved level 2 by getting 100 points

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

    Vice President:

    An expert whose answer got voted for 100 times.

  • Expert
  • 285 Answers

There's only one thingsyou can do, since you ca't install anything, and that is reinstalling the PC. It's fairly complicated, but I'll try to help. Here's the plan:
1. Backup whatever data you want to keep.
2. Then boot the notebook from whatever Operating System DVD you have (like a Windows XP CD)
3. Install the operating system, don't use repair functions. It will start unpacking some stuff. Somewhere later on, it will ask on which drive you want to install the OS.
4. Delete every partition on the harddisk. (read that menu, it says which keyboard keys you will need.
5. Create a new partition, as big as you want.
6. Format the partition (no quick-format!!)
7. The OS will install, and you will have a clean PC. You still have your backed up data, and you can't ust use it, because it may be infected with the virus. So you have to:
8. get a virus scanner from somewhere, plug in the USB stick or whatever the data is on, scan that stick, remove the viruses and then you can
9. use the data again. However, then you wll still need to install all the software you had installed on the PC before you reinstalled the Operating System. So you're not there yet, but intalin them isn't difficult, just a lot of work.

I hope this helps,
Yannick.

Posted on May 19, 2009

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

I got my CD RW infected by Win 32/ Auto Run Agent.YD worm. How can I clean and get back my documents free of virus?


First of all its good to have a Anti virus program like Avg or Avast go here to download them (choose one)

AVG free 2011
http://free.avg.com/au-en/download-avg-anti-virus-free (click avg free edition)

or

Avast 5
http://www.avast.com/free-antivirus-download (click free antivirus)

Now to scan your computer to get rid of virus's, spyware etc download these programs and make sure you run a scan once every two - three weeks

Malwarebytes - make sure you update this program everytime you use it and use the quick scan feature for a faster scan
http://software-files-l.cnet.com/s/software/11/92/03/46/mbam-setup-1.51.1.1800.exe?e=1313431360&h=20990b01d28e7911284352a086bb4da0&lop=link&ptype=1901&ontid=8022&siteId=4&edId=3&spi=49ffb02caee312dd17fc967558b7dd9c&pid=11920346&psid=10804572&fileName=mbam-setup-1.51.1.1800.exe

SuperAntispyware - This program is good for the hard to find virus's and spyware, use this if Malwarebytes didn't work or vice versa
http://downloads.superantispyware.com/downloads/SUPERAntiSpyware.exe

Spywareblaster search & destroy - This program runs in the background that blocks access from programs or users from the internet that seems bad and use can use the scan feature to make sure no one has got passed.
http://software-files-l.cnet.com/s/software/11/00/04/54/cnet_spybotsd162_exe.exe?e=1313432468&h=e8cec1169ccec15667372ceacc144746&lop=link&ptype=1901&ontid=8022&siteId=4&edId=3&spi=55007b9b5dac8e7e59dbd711aa6c85e5&pid=11000454&psid=10122137&fileName=cnet_spybotsd162_exe.exe

Hope this fixes your problem.

Aug 15, 2011 | Acer TravelMate 2300 Notebook

Tip

Lock your Mozilla Firefox Homepage from Hijackers permanently


I got soooo tried of toolbars like Ask and Google changing my startup tabs and then not being able to restore then even using session restore on TabMixPlus XPI for Firefox to I devised my own method to lock my desired tabs just for me now I share this with you all, note you can still install this XPI make sure that you set it to show homepage on restart so that if you use restart it will still work, as well as just closing the browser window using the usual red right-hand cross

The two modes of TabMixPlus showing Firefox Built in Session Restre and TabMixPlus Session Manager you can't use both at the same time >>

16477c5.jpg

This is a tried and tested 100% to lock your homepage from hijackers and give you the tabs that you want to start with time and time again I have set my two tabs to the Router control panel for Sky Sagem F@ST Router and my FixYa page, use your own...

First create a file called homepage.txt and place these line inside it and save it as a text file with the file extension *.txt

//
lockPref("network.proxy.type", 0);
lockPref("browser.startup.homepage", "http://192.168.0.1/sky_router_status.html|http://www.fixya.com/users/spideray");

If you want extra tabs add more pipelines | after the aspx then download this and to create a homepage.cfg file use 13 as the shift by value

http://home.comcast.net/%7Edabbink/dabbink/Download/ByteShifter.zip

b39e0d9.jpg

You then need to change the all.js in the C:Program FilesMozilla Firefox folder you need to add this line to the end to action you new file and save it

pref("general.config.filename", "homepage.cfg");

When you restart Firefox you will see that under the options tab the homepage will be greyed out OR locked.

ebadee9.jpg


For a second opinion check this using the about:config option in the MR Tech Toolkit XPI also worth installing I have used this since it was called local install way back. Then benefits of this method are 100% locked from hijackers and user definable whenever you want to change your homepage just copy and paste the new URLs that you want after each pipeline make sure that you create another cfg file before you start the browser it will fail unless it can read the homepage.cfg file you have been warned.

6a333ae.jpg

Here is my Sky Drive Link for an example that you can use HERE copy the entire folder to you Mozilla Folder then you can use it if you want to change the homepage.txt to add or remove tabs don't forget to Bit Shift it afterwards

on Mar 22, 2010 | Mozilla Firefox

1 Answer

Hi, i had huelar browser a virus which i think is eating my computer. now my computer won't alllow installations. i tried to run google chrome and some plugins also but wont work. what to do? please...


Goto hitmanpro.nl and download and run the right version. Remove everything it finds. Do the same with superantispyware.com and malwarebytes.com they will get rid of any leftovers and restore settings.

Aug 01, 2011 | HP Pavilion dv6000z Notebook

1 Answer

I can't logon my toshiba portege m400 - s5032x a error message shows up saying Isass.exe application error the application failed to initialize properly (0xc0000005). Click on ok to terminate the...


Your system is infected by Sasser worm.The Sasser worm infects machines via network connections. It can attack entire networks of computers or one single computer connected to the Internet. The worm exploits a known windows vulnerability that is easily patched, however few systems seem to have this patch installed. It attacks Windows 2000 and Windows XP machines along with Windows NT and Windows Server 2003.


The patch from Microsoft known as the MS04-011 Security Update fixes the following vulnerabilities:
LSASS Vulnerability 
LDAP Vulnerability 
PCT Vulnerability 
Winlogon Vulnerability 
Metafile Vulnerability 
Help and Support Center Vulnerability 
Utility Manager Vulnerability 
Windows Management Vulnerability 
Local Descriptor Table Vulnerability 
H.323 Vulnerability 
Virtual DOS Machine Vulnerability 
Negotiate SSP Vulnerability 
SSL Vulnerability 
ASN.1 “Double-Free” Vulnerability 

Download the Windows patches for this vulnerability.Here is the link below:

http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx



How Can I Remove the Sasser worm?

Follow these steps in removing the Sasser worm.

1) Disconnect your computer from the local area network or Internet

2) Terminate the running program
Open the Windows Task Manager by either pressing CTRL+ALT+DEL, selecting the Processes tab or selecting Task Manager and then the process tab on WinNT/2000/XP machines.
Locate one of the following programs (depending on variation), click on it and End Task or End Process

avserve.exe
avserve2.exe
skynetave.exe
any process running with the "_up.exe" suffix
Close Task Manager

3) Activate the Windows XP Firewall (if running Windows XP) or another firewall to prevent the worm from shutting your system down while downloading the patches. To activate the Windows XP firewall, follow these steps.
Click on Start, Control Panel
Double-click on Networking and Internet Connections, then click on Network Connnections
Right-click on the connection you use to access the Internet and choose Properties
Click on the Advanced Tab and check the box
"Protect my computer and network by limiting or preventing access to this computer from the Internet"
Click OK and close out of the Network and Control Panel

4) Remove the Registry entries
Click on Start, Run, Regedit
In the left panel go to 

HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>Current Version>Run
In the right panel, right-click and delete the following entry

"avserve.exe"="%Windir%\avserve.exe"
"avserve2.exe"="%Windir%\avserve2.exe"
"skynetave.exe"= "%Windows%\skynetave.exe"
Close the Registry Editor

5) Delete the infected files (for Windows ME and XP remember to turn off System Restore before searching for and deleting these files to remove infected backed up files as well)
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:\WINDOWS).
In the "Named" or "Search for..." box, type, or copy and paste, the file names:

avserve.exe
avserve2.exe
skynetave.exe
C:\win2.log
Click Find Now or Search Now.
Delete the displayed files.
Empty the Recycle bin

6) Reboot the computer and update your antivirus software, and run a thorough virus scan using your favorite antivirus program.

For Automatic Removal of Sasser, download the Symantec removal tool, you'll still need to download the patches above and install them, however this removal tool will stop the Sasser worm from running, remove the items in the registry, and delete the infected files.

Dec 27, 2009 | Toshiba Portege M400-S5032X Tablet PC

1 Answer

I need setup.exe to load GPS and it isn't on my computer.


Find the manufacturer's site, go to the download section, find your program, click download, select Save, not Run and wait for the download to end, close the browser and run the downloaded file.

Oct 26, 2009 | Dell Inspiron 1501 Notebook

3 Answers

Windows cannot find gphone.exe??


Gphone.exe is a file that an instant-message worm infects. This worm spreads through Google chat and Yahoo! Messenger. This “Gphone.exe” worm disables your antivirus security software, and downloads more crapware onto your PC.

To remove do this:
1. Block Gphone.exe sites: http://rnd009.googlepages.com/
2. Stop Gphone.exe processes: %Windir%\gphone.exe
%System%\gphone.exe
%System%\DEFAULT_NOT_SET.exe
C:\Documents and Settings\All Users\Desktop\gphone.exe
%Temp%\gphone.exe
%System%\gphone.exe
%DriveLetter%\New Folder.exe
%DriveLetter%\gphone.exe
[ROOT FOLDER]\New Folder.exe
[ROOT FOLDER]\gphone.exe Get rid of Gphone.exe files:

%DriveLetter%\autorun.inf
%Windir%\Tasks\At1.job
[ROOT FOLDER]\autorun.inf
C:\disk.txt
%System%\autorun.ini
%System%\setting.ini
%Temp%\log_[TIME AND DATE].txt


3. Delete Gphone.exe registry keys using regedit from start - run:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\”shared” = “[ROOT FOLDER]\New Folder.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Yahoo Messengger” = “%System%\gphone.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\”Shell” = “Explorer.exe gphone.exe”
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule\”AtTaskMaxHours” = “0′
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule\”NextAtJobId” = “2′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\”DisableTaskMgr” = “1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\”DisableRegistryTools” = “1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\”NofolderOptions” = “1′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\”Default_Page_URL” = “http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\”Default_Search_URL” = “http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\”Search Page” = “http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\”Start Page” = “http://rnd009.googlepages.com/google.html”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\”Start Page” = “http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\”HomePage” = “1′
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\”HomePage” = “1′ Note: In any Gphone.exe files I mention above, “%UserProfile%” is a variable referring to your current user’s profile folder. If you’re using Windows NT/2000/XP, by default this is “C:\Documents and Settings\[CURRENT USER]” (e.g., “C:\Documents and Settings\JoeSmith”). If you have any questions about manual Gphone.exe removal, go ahead and leave a comment.


How to delete Gphone.exe files in Windows XP and Vista:
1.Click your Windows Start menu, and then click “Search.”
2.A speech bubble will pop up asking you, “What do you want to search for?” Click “All files and folders.”
3.Type a Gphone.exe file in the search box, and select “Local Hard Drives.”
4.Click “Search.” Once the file is found, delete it.
How to stop Gphone.exe processes:
1.Click the Start menu, select Run.
2.Type taskmgr.exe into the the Run command box, and click “OK.” You can also launch the Task Manager by pressing keys CTRL + Shift + ESC.
3.Click Processes tab, and find Gphone.exe processes.
4.Once you’ve found the Gphone.exe processes, right-click them and select “End Process” to kill Gphone.exe.
How to remove Gphone.exe registry keys:
Because your registry is such a key piece of your Windows system, you should always backup your registry before you edit it. Editing your registry can be intimidating if you’re not a computer expert, and when you change or a delete a critical registry key or value, there’s a chance you may need to reinstall your entire system. Make sure your backup your registry before editing it.
1.Select your Windows menu “Start,” and click “Run.” An “Open” field will appear. Type “regedit” and click “OK” to open up your Registry Editor.
2.Registry Editor will open as a window with two panes. The left side Registry Editor’s window lets you select various registry keys, and the right side displays the registry values of the registry key you select.
3.To find a registry key, such as any Gphone.exe registry keys, select “Edit,” then select “Find,” and in the search bar type any of Gphone.exe’s registry keys.
4.As soon as Gphone.exe registry key appears, you can delete the Gphone.exe registry key by right-clicking it and selecting “Modify,” then clicking “Delete.”
How to delete Gphone.exe DLL files:
1.First locate Gphone.exe DLL files you want to delete. Open your Windows Start menu, then click “Run.” Type “cmd” in Run, and click “OK.”
2.To change your current directory, type “cd” in the command box, press your “Space” key, and enter the full directory where the Gphone.exe DLL file is located. If you’re not sure if the Gphone.exe DLL file is located in a particular directory, enter “dir” in the command box to display a directory’s contents. To go one directory back, enter “cd ..” in the command box and press “Enter.”
3.When you’ve located the Gphone.exe DLL file you want to remove, type “regsvr32 /u SampleDLLName.dll” (e.g., “regsvr32 /u jl27script.dll”) and press your “Enter” key.
That’s it. If you want to restore any Gphone.exe DLL file you removed, type “regsvr32 DLLJustDeleted.dll” (e.g., “regsvr32 jl27script.dll”) into your command box, and press your “Enter” key.
Did Gphone.exe change your homepage?
1.Click Windows Start menu > Control Panel > Internet Options.
2.Under Home Page, select the General > Use Default.
3.Type in the URL you want as your home page (e.g., “http://www.homepage.com”).
4.Select Apply > OK.
5.You’ll want to open a fresh web page and make sure that your new default home page pops up.
Gphone.exe Removal Tip
Is your computer acting funny after deleting any Gphone.exe files? I recommend using a program like File Recover from PC Tools. File Recover saves deleted files that otherwise can’t be recovered by Windows operating sytem.
Want to save time finding Gphone.exe files? Download Spyware Doctor, let it find the Gphone.exe files for you, and then manually delete Gphone.exe files.

Aug 04, 2009 | Microsoft Windows XP Professional With...

1 Answer

Autorun.inf doesn't open file in internet browser


Hello ksharp628,

I use a program called autorun.exe One limitation of the standard AutoRun facility is the fact that it will only run executable programs; it will not by itself open document files such as web pages or text files. AutoRun.exe is designed to circumvent this restriction: it will open any number of document files or start executable programs. Moreover, it is smart enough to use a sensible fall-back strategy if no documents can be opened, perhaps because the target system does not have the required support for those document types.

example of my autorun.inf
[autorun]
open=autorun.exe msn.html
action=Run MSN.com
icon=msn.ico

in root of thumb drive I have Autorun.exe Autorun.inf MSN.html and my ICON msn.ico wich i did a search for on my computer

I hade t make and msn.html

my edited msn.html file open in txt format
<meta HTTP-EQUIV="REFRESH" content="0; url=http://www.msn.com">

You can replace with what ever website you want and rename it to that.

This autrun.inf setup will popup the autrun box and ask you pick an option. this is as close to running the webpage when inserting the usb drive. The program comes with a .pdf on many options wich can be used with autorun.exe.

the link to the autrun.exe program is found below.

http://www.tarma.com/products/autorun/

Hope this helps you, take care.

May 05, 2009 | Dell Dimension 4600 PC Desktop

1 Answer

Windows cannot find 'gphone.exe'


Gphone.exe is worm which spreads via instant messengers. It usually affects Yahoo! Messenger and Google Talk applications. Gphone.exe send a message and invites victims to visit a website. If clicked upon, the link actually delivers a copy of Gphone.exe infection.

Most likely you have a security program that detected and removed the threat but windows is still trying to load the file on startup, thankfully it isnt able to because the threat is gone so windows is displaying that error message to let you know it was not able to load the file.

Go to Start > Run> type "msconfig" and press enter. click the startup tab and uncheck the box that says "gphone.exe". (it may have a long file or folder path in front like c:windowssystem32).

Go to this website if you need further removal instructions:
http://www.spywarevoid.com/remove-gphoneexe-gphoneexe-worm-removal.html

Jan 21, 2009 | Computers & Internet

2 Answers

Something is changing icons shape and left double click does work


It seems like a worm more or less a along vir detail below - you wlll have to scan and remove it using a good antivirus program:
Virus Profile: W32/Xiaoho.worm Name: W32/Xiaoho.worm Risk Assessment - Home Users: Low-Profiled - Corporate Users: Low-Profiled Date Discovered: 8/1/2007 Date Added: 8/1/2007 Origin: N/A Length: Varies Type: Virus SubType: Worm DAT Required: 5088
Virus Characteristics -- Update August 18, 2007 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://shanghaiist.com/2007/08/17/vicious_new_chi.php
To receive an extra.dat file for this threat please visit: https://www.webimmune.net/extra/getextra.aspx
This detection is for a worm which tries to copy itself to removable drives. It will destroy systems it's used on by infecting all .exe files and changing their icons to the Chinese character HAO.
Upon execution, the worm drops a copy of itself into the Windows System folder:
  • %SysDir%\exloroe.exe
The worm creates the following registry keys to activate itself:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{H9I12RB03-AB-B70-7-11d2-9CBD-0O00FS7AH6-9E2121BHJLK}\: "ïµí³éèöã"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{H9I12RB03-AB-B70-7-11d2-9CBD-0O00FS7AH6-9E2121BHJLK}\stubpath: "%SystemRoot%\system32\exloroe.exe"
It spreads by dropping files named autorun.inf and xiaohao.exe on removable drives and setting file attributes as hidden.
The worm infects .exe files by overwriting them or corrupting them beyond repair. This changes their icon to Chinese word HAO.
ico142876.jpg and changes active window title as "X14o-H4o":

Apr 21, 2008 | Computers & Internet

6 Answers

How can i remove virus worm/autoit permanently


its simple guys..!!!
if it asks for permission to access outlook..don't permit it because it is a smart virus and is going to spread it to all the people on your contact list...!!!
simply open task manager and end process tree of KHATRA.exe , gHost.exe , xplorer.exe and OUTLOOK.exe seperately...!!
then run your anti virus or download one if you don't have one..!!!
run a complete computer scan in detail..!!
then delete all files which are infected by the virus because the results contain only duplicate files which are created by the virus

Feb 04, 2008 | Acer TravelMate 2300 Notebook

Not finding what you are looking for?
Acer Aspire One  PC Notebook Logo

248 people viewed this question

Ask a Question

Usually answered in minutes!

Top Acer Computers & Internet Experts

Les Dickinson
Les Dickinson

Level 3 Expert

18392 Answers

Mohammed Ebrahim M
Mohammed Ebrahim M

Level 3 Expert

633 Answers

Steve Sweetleaf
Steve Sweetleaf

Level 3 Expert

1144 Answers

Are you an Acer Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...