Options
Pls help
Dear all,
Below are those log file fm HJT. It is the problem of Homesearch assistent,
shopping wizard, search extend
Logfile of HijackThis v1.98.2
Scan saved at 2:38:03 PM, on 8/10/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\netxg.exe
C:\Program Files\Reflection\rtsserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-au\msnappau.exe
C:\WINNT\system32\sysyo32.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Optus\FACSys Desktop Client\facsys.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\Program Files\Reflection\R8win.exe
C:\Program Files\Reflection\R8win.exe
C:\Program Files\Reflection\R8win.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\cworasar.APL\LOCALS~1\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = file://bkktha04/thaweb/ThailandIntranet/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by APL Limited
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = apl-proxy.apl.com:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {09F5E596-DA96-B567-83C4-E8B9D79433B9} - C:\WINNT\system32\d3nf.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.0002.1001\en-au\msntb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-au\msnappau.exe"
O4 - HKLM\..\Run: [sysyo32.exe] C:\WINNT\system32\sysyo32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [winpopup] C:\WINNT\winupie.exe
O4 - HKCU\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - Global Startup: FACSys Desktop Client.lnk = C:\Program Files\Optus\FACSys Desktop Client\facsys.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.3com.com
O15 - Trusted Zone: www.401k.com
O15 - Trusted Zone: www.acslogistics.com
O15 - Trusted Zone: www.adobe.com
O15 - Trusted Zone: aplweb.apl.com
O15 - Trusted Zone: www.apl.com
O15 - Trusted Zone: www.cnet.com
O15 - Trusted Zone: www.nol.com.sg
O15 - Trusted Zone: www.commerce.net
O15 - Trusted Zone: www.compaq.com
O15 - Trusted Zone: support.dell.com
O15 - Trusted Zone: www.dell.com
O15 - Trusted Zone: www.excite.com
O15 - Trusted Zone: infoseek.go.com
O15 - Trusted Zone: www.hp.com
O15 - Trusted Zone: www.ibm.com
O15 - Trusted Zone: www.pc.ibm.com
O15 - Trusted Zone: cbs.marketwatch.com
O15 - Trusted Zone: www.mbc.com
O15 - Trusted Zone: www.mcafeeb2b.com
O15 - Trusted Zone: www.msn.com
O15 - Trusted Zone: www.nai.com
O15 - Trusted Zone: www.netscape.com
O15 - Trusted Zone: www.nolweb.com
O15 - Trusted Zone: www.pkware.com
O15 - Trusted Zone: www.raging.com
O15 - Trusted Zone: www.wellness2000.net
O15 - Trusted Zone: www.windows95.com
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/initial.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://delivery.inet-traffic.com/intdel.exe
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} - http://155.14.78.203/main/Install/en/US/CentraDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = D1.AD.APL.COM
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EDFBA8D-1109-4154-8C6C-A76B586042A6}: Domain = apl.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EDFBA8D-1109-4154-8C6C-A76B586042A6}: NameServer = 155.14.231.8,155.14.64.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = D1.AD.APL.COM
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = D1.AD.APL.COM
hv tried to use adaware n spybot fr this problem. Unfortunately, it
has still been shown same problem recently.
Pls help to advise which one should be deleted to solve said problem.
Thanks in advance fr yr kind advice.
Below are those log file fm HJT. It is the problem of Homesearch assistent,
shopping wizard, search extend
Logfile of HijackThis v1.98.2
Scan saved at 2:38:03 PM, on 8/10/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\netxg.exe
C:\Program Files\Reflection\rtsserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-au\msnappau.exe
C:\WINNT\system32\sysyo32.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Optus\FACSys Desktop Client\facsys.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\Program Files\Reflection\R8win.exe
C:\Program Files\Reflection\R8win.exe
C:\Program Files\Reflection\R8win.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\cworasar.APL\LOCALS~1\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = file://bkktha04/thaweb/ThailandIntranet/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by APL Limited
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = apl-proxy.apl.com:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {09F5E596-DA96-B567-83C4-E8B9D79433B9} - C:\WINNT\system32\d3nf.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.0002.1001\en-au\msntb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-au\msnappau.exe"
O4 - HKLM\..\Run: [sysyo32.exe] C:\WINNT\system32\sysyo32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [winpopup] C:\WINNT\winupie.exe
O4 - HKCU\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - Global Startup: FACSys Desktop Client.lnk = C:\Program Files\Optus\FACSys Desktop Client\facsys.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.3com.com
O15 - Trusted Zone: www.401k.com
O15 - Trusted Zone: www.acslogistics.com
O15 - Trusted Zone: www.adobe.com
O15 - Trusted Zone: aplweb.apl.com
O15 - Trusted Zone: www.apl.com
O15 - Trusted Zone: www.cnet.com
O15 - Trusted Zone: www.nol.com.sg
O15 - Trusted Zone: www.commerce.net
O15 - Trusted Zone: www.compaq.com
O15 - Trusted Zone: support.dell.com
O15 - Trusted Zone: www.dell.com
O15 - Trusted Zone: www.excite.com
O15 - Trusted Zone: infoseek.go.com
O15 - Trusted Zone: www.hp.com
O15 - Trusted Zone: www.ibm.com
O15 - Trusted Zone: www.pc.ibm.com
O15 - Trusted Zone: cbs.marketwatch.com
O15 - Trusted Zone: www.mbc.com
O15 - Trusted Zone: www.mcafeeb2b.com
O15 - Trusted Zone: www.msn.com
O15 - Trusted Zone: www.nai.com
O15 - Trusted Zone: www.netscape.com
O15 - Trusted Zone: www.nolweb.com
O15 - Trusted Zone: www.pkware.com
O15 - Trusted Zone: www.raging.com
O15 - Trusted Zone: www.wellness2000.net
O15 - Trusted Zone: www.windows95.com
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/initial.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://delivery.inet-traffic.com/intdel.exe
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} - http://155.14.78.203/main/Install/en/US/CentraDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = D1.AD.APL.COM
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EDFBA8D-1109-4154-8C6C-A76B586042A6}: Domain = apl.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EDFBA8D-1109-4154-8C6C-A76B586042A6}: NameServer = 155.14.231.8,155.14.64.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = D1.AD.APL.COM
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = D1.AD.APL.COM
hv tried to use adaware n spybot fr this problem. Unfortunately, it
has still been shown same problem recently.
Pls help to advise which one should be deleted to solve said problem.
Thanks in advance fr yr kind advice.
0
Comments
Look for a service called "Network Security Service"... If it's there, click on it, click properties, and set the thing to "disabled" and then STOP the service.
If you do not have that service, I want you to manually do a hard-power down or restart on your computer. Do not select shutdown from your menu, just reach over and shut it off, then back on, or hit the restart button on your case. When it starts to boot, tap the F8 key to get the boot options menu, and select SAFE MODE.
If you did have the "Network Security Service, and you stopped it, then you can either do the hard reboot or a normal reboot through the Start menu. Reboot the computer into SAFE MODE.
(Make sure to let me know which situation applied to you.)
Either way, once you are in SAFE MODE, run HijackThis, and FIX these entries:
***NOTE: This Hijack appears to have the ability to rename its files, apparently when the computer is shutdown or the task has been ended. If you have rebooted your computer since you posted this log, check Hijack This to make sure that the file names are indentical to what you have posted. Otherwise, you need to post a new log, and NOT SHUT DOWN YOUR COMPUTER until you have gotten a reply from one of us as to what files you need to remove.*****
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINNT\akcgf.dll/index.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\akcgf.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\akcgf.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by APL Limited
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {09F5E596-DA96-B567-83C4-E8B9D79433B9} - C:\WINNT\system32\d3nf.dll
O4 - HKLM\..\Run: [sysyo32.exe] C:\WINNT\system32\sysyo32.exe
O4 - HKCU\..\Run: [winpopup] C:\WINNT\winupie.exe
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/initial.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://delivery.inet-traffic.com/intdel.exe
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} - http://155.14.78.203/main/Install/en/US/CentraDownloader.cab
Next, stay in SAFE MODE, and locate all of the .exe files and .dll files mentioned above. Make sure you are set to show hidden files and folders on your system, instructions to do that are in the link above "Steps to take before posting a Hijack This log."
These are the files you need to look for:
C:\WINNT\akcgf.dll
C:\WINNT\system32\d3nf.dll
C:\WINNT\system32\sysyo32.exe
C:\WINNT\winupie.exe
Move these files to a new folder called :C:\Quarantine. Rename the the .exe's to .xxx. and the dll's to .ddd. That way you can always replace them if it somehow turns out that one or more of these are necessary files....which is not likely, but quarantining is safer than deleting them.
Now, reboot normally, and check things out. Come let us know how it worked. Run a new HJT scan, and post the log here for further review.
Dexter...