Program identification & Safe Mode problems

I use Windows98 and I'm having 2 problems :
1) The last few days I've booted into Safe Mode and I ran Ad-Aware, and every day it found and eliminated six recurring CoolWebSearch registry entries.
Today, I didn't boot into Safe Mode, but I STILL have the Safe Mode-style (low quality) graphics, even after several re-boots.
I ran Ad-Aware again, and the six CWS entries are gone and it didn't turn up any malware. Does anyone know how I can try to restore my graphics to normal?

2) Every 5 minutes or so, I get a "McAfee Firewall alert" : two programs on my PC keep trying to access the net ; the programs were created exactly 2 hours apart in August of 2001 : one is "msdview32.exe" (3kb) & the other is "winuyv32.exe" (11kb). I downloaded FileAlyzer from the SpyBot website, and I looked at the files' Properties, but being a PC novice I don't know how to analyze the results.
How can I determine whether these programs came with Windows98 or if they are malware?
Thanks in advance for any help.

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited September 2004
    Welcome to Short Media. Yes, those two files are malware. Find and delete those two files. Then download HijackThis, scan with it, and post a log.
  • edited September 2004
    Thanks for answering. I was just wondering : how did you determine that those two files were malware? Thanks in advance.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    I personally use experience with Windows as my guide - those files are not normal windows files.

    Google also helps.
  • edited September 2004
    When I try to delete the 2 files, I get these 2 errror messages :

    #1 : "Error Deleting File :
    Cannot delete msdview32: Access is denied.
    Make sure the disk is not full or write-protected and that the file is not currently in use."

    #2 : "Error Deleting File :
    Cannot delete winuyv32.exe : The specified file is being used by Windows."
    When I hit Ctrl+Alt+Delete, I noticed that neither msdview32 nor winuyv32 is listed in the ''Close Program" box.

    Before I post my HijackThis log, is there some way to get the computer to allow me to delete the files? Thanks.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    Well, post the HJT log and we'll show you how to delete the files. You can either boot into DOS mode and delete them from there using the ATTRIB command to make them visible and the DEL command to delete them, or you can end the process in windows and delete them in the windows shell. EIther way, I'll need a HJT log to help you.
  • edited September 2004
    Thank you, I'll post my HJT log asap.
This discussion has been closed.