1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Annoying error when restarted.

Discussion in 'Virus & Other Malware Removal' started by JesticleS, Sep 21, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. JesticleS

    JesticleS Thread Starter

    Joined:
    Sep 21, 2003
    Messages:
    11
    When I restart my PC, I get this error in the below picture.

    I don't know what it means, plus it is very annoying.

    I would like to make it stop giving me this error.

    If anone has any ideas, let them flow.

    Thanks
     

    Attached Files:

  2. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
    Hi and welcome.

    Can you post your startup items....start button, run, then type msinfo32 and hit ok...go to software, startups, edit, select all, edit, copy and come back and paste.
     
  3. JesticleS

    JesticleS Thread Starter

    Joined:
    Sep 21, 2003
    Messages:
    11
    Thanks for the help!

    Here is startup stuff :).

    AIM c:\program files\aim95\aim.exe -cnetwait.odl HYPERACT-C3OKOK\Bob HKU\S-1-5-21-1202660629-2077806209-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Adobe Gamma Loader c:\progra~1\common~1\adobe\calibr~1\adobeg~1.exe All Users Common Startup
    BJCFD c:\program files\broadjump\client foundation\cfd.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    ClrSchLoader c:\program files\clearsearch\loader.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    GStartup c:\program files\common files\gmt\gmt.exe /startup All Users Common Startup
    Intes KeyChange c:\progra~1\intesk~1\keycha~1.exe All Users Common Startup
    McAfee Guardian "c:\program files\mcafee\mcafee shared components\guardian\cmgrdian.exe" /su All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    McAfee.InstantUpdate.Monitor "c:\program files\mcafee\mcafee shared components\instant updater\rulaunch.exe" /startmonitor HYPERACT-C3OKOK\Bob HKU\S-1-5-21-1202660629-2077806209-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    MsnMsgr "c:\program files\msn messenger\msnmsgr.exe" /background HYPERACT-C3OKOK\Bob HKU\S-1-5-21-1202660629-2077806209-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    PopUpStopperFreeEdition "c:\program files\panicware\pop-up stopper free edition\psfree.exe" HYPERACT-C3OKOK\Bob HKU\S-1-5-21-1202660629-2077806209-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    RealTray c:\program files\real\realplayer\realplay.exe systemboothideplayer All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    WinAgent c:\docume~1\bob\locals~1\temp\joi2.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    WinZip Quick Pick c:\progra~1\winzip\wzqkpick.exe All Users Common Startup
    WinampAgent "c:\program files\winamp\winampa.exe" All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    desktop desktop.ini NT AUTHORITY\SYSTEM Startup
    desktop desktop.ini HYPERACT-C3OKOK\Bob Startup
    desktop desktop.ini .DEFAULT Startup
    desktop desktop.ini All Users Common Startup
    svced c:\windows\system32\svced.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
     
  4. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
  5. JesticleS

    JesticleS Thread Starter

    Joined:
    Sep 21, 2003
    Messages:
    11
    K, the first link you gave me could not be found. But the second link, I did as you told and here is my scan log. (it wont let me attach, so I will paste)


    Thanks for your help so far sir.


    Logfile of HijackThis v1.97.2
    Scan saved at 3:31:14 PM, on 9/24/2003
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
    C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
    C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
    C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
    C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
    C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
    C:\WINDOWS\System32\svced.exe
    C:\Program Files\Winamp\Winampa.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\ClearSearch\Loader.exe
    C:\Program Files\AIM95\aim.exe
    C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
    C:\Program Files\Intes KeyChange\KeyChange.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\unzipped\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.*****palace.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r1.attbi.com;<local>
    O2 - BHO: (no name) - {00000580-C637-11D5-831C-00105AD6ACF0} - C:\WINDOWS\MSView.DLL
    O2 - BHO: (no name) - {00000EF1-34E3-4633-87C6-1AA7A44296DA} - C:\WINDOWS\System32\mpz300.dll
    O2 - BHO: (no name) - {39AF31DD-EAFC-45EA-A56C-385B52E25CC0} - c:\windows\iexplorr22.dll
    O2 - BHO: (no name) - {4CEBBC6B-5CEE-4644-80CF-38980BAE93F6} - c:\windows\iexplorr23.dll
    O2 - BHO: (no name) - {6085FB5B-C281-4B9C-8E5D-D2792EA30D2F} - (no file)
    O2 - BHO: (no name) - {6B12DABB-0B7C-44FA-B0B3-4BAFF3790256} - c:\windows\iexplorr24.dll
    O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
    O2 - BHO: (no name) - {BC0D2038-2DE5-4A6F-92BC-B18A3E0DE32A} - c:\windows\iexplorr11.dll
    O2 - BHO: Url Catcher - {CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1} - C:\PROGRA~1\BARGAI~1\bin2\apuc.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
    O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
    O4 - HKLM\..\Run: [svced] C:\WINDOWS\System32\svced.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
    O4 - HKLM\..\Run: [WinAgent] C:\DOCUME~1\Bob\LOCALS~1\Temp\Joi2.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Intes KeyChange.lnk = C:\Program Files\Intes KeyChange\KeyChange.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2B2B5A1-B48C-4886-A318-723916A01024} (SBFullInst Control) - http://www.spyblast.com/download/SBFullWU.cab
     
  6. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
    Let's move you to security, there's some stuff there that needs to go.......
     
  7. JesticleS

    JesticleS Thread Starter

    Joined:
    Sep 21, 2003
    Messages:
    11
    security? ok sounds good. Thanks
     
  8. KeithKman

    KeithKman

    Joined:
    Dec 28, 2002
    Messages:
    1,983
    Do this in order:

    1) Open Internet Explorer -> Tools -> Internet Options -> delete cookies, delete files (select off-line content), clear history. Then click ok and exit Internet Explorer.


    2) Read http://tomcoyote.org/SPYBOT/index1.html then download and run SpyBot. Make sure to get the updates for SpyBot before you have it scan your computer. After you scan and remove anything SpyBot finds, make sure to click the Immunize button and OK and then click the Immunize button in the right pane.


    3) Run one of the following free Anti-Virus programs here:

    http://housecall.trendmicro.com - I found this to work the best.

    http://www.pandasoftware.com/activescan

    http://www.ravantivirus.com/scan


    4) Re-post HiJackThis Log...
     
  9. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/166391

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice