multiple errors

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

coker-cola

Thread Starter
Joined
Nov 30, 2001
Messages
13
HELP!!!
I have multiple errors occurring constantly, they range from unknow to explore to real player and rudall32

examples: explore Kernel [email protected]:bff724CL
explore [email protected] 0167:780027ba
explore [email protected]:7C251D58
real play Kernel [email protected] 0167:bff7b9f6
scanregw [email protected]:7fb91876
unknown @ 0000:69707845
ypage unknown @0000:00dda283
these happen when opening internet or as internet is being used
also screen often freezes when using internet
I would be grateful for any help you may give.....but must warn you that I am novice at best!!!... thanks again in advance
 
Joined
Feb 28, 2001
Messages
11,584
coker-cola
Welcome to TSG!
Seems like you have quite a problem going on here. The best place to start is lets make sure you do not have other programs such as spyware or viruses interferring with your system.
Go to http://www.lavasoftusa.com/downloads.html and download the main program, then follow the instructions to set it up and run it. If Spyware is found post back what it found and let us take a look at it. Do not automatically remove web3000 or new.net if it is found.
Also go to http://housecall.antivirus.com/housecall/start_corp.asp
and run a virus scan.
If any virus is found please let us know so we can advise how to remove.
After you receive a clean bill of health from spyware and viruses then we should be able to start to fix all those errors.
Dave
 

coker-cola

Thread Starter
Joined
Nov 30, 2001
Messages
13
in addition to all the different the errors, at start up system can't find windows\ umaxis 11.386 did the spyware check and found something like 72 items .....the list is forth coming Scan initialized on 1/19/02 4:12:28 PM.
(AAW release 5.62, referencefile 087-22.09.2001)
=================================================


Started memory scan
====================
Running processes:

#:1 Name: C:\WINDOWS\SYSTEM\KERNEL32.DLL
----------------------------
Threads:5
ProcID:4279199061
ParentProcID:2123335433
BasePriority:High

#:2 Name: C:\WINDOWS\SYSTEM\MSGSRV32.EXE
----------------------------
Threads:1
ProcID:4294875693
ParentProcID:4279199061
BasePriority:Normal

#:3 Name: C:\WINDOWS\SYSTEM\SPOOL32.EXE
----------------------------
Threads:2
ProcID:4294877749
ParentProcID:4294875693
BasePriority:Normal

#:4 Name: C:\WINDOWS\SYSTEM\MPREXE.EXE
----------------------------
Threads:4
ProcID:4294881409
ParentProcID:4294875693
BasePriority:Normal

#:5 Name: C:\WINDOWS\SYSTEM\MSTASK.EXE
----------------------------
Threads:2
ProcID:4294897141
ParentProcID:4294881409
BasePriority:Normal

#:6 Name: C:\ANTI VIRUS\TREND PC-CILLIN 98\IOMON98.EXE
----------------------------
Threads:5
ProcID:4294847137
ParentProcID:4294881409
BasePriority:Normal

#:7 Name: C:\ANTI VIRUS\TREND PC-CILLIN 98\WEBTRAP.EXE
----------------------------
Threads:5
ProcID:4294855673
ParentProcID:4294847137
BasePriority:Normal

#:8 Name: C:\WINDOWS\SYSTEM\mmtask.tsk
----------------------------
Threads:1
ProcID:4294813557
ParentProcID:4294875693
BasePriority:Normal

#:9 Name: C:\WINDOWS\EXPLORER.EXE
----------------------------
Threads:26
ProcID:4294774609
ParentProcID:4294875693
BasePriority:Normal

#:10 Name: C:\WINDOWS\TASKMON.EXE
----------------------------
Threads:4
ProcID:4294746809
ParentProcID:4294774609
BasePriority:Normal

#:11 Name: C:\WINDOWS\SYSTEM\SYSTRAY.EXE
----------------------------
Threads:5
ProcID:4294752109
ParentProcID:4294774609
BasePriority:Normal

#:12 Name: C:\WINDOWS\SYSTEM\ATITASK.EXE
----------------------------
Threads:4
ProcID:4294708637
ParentProcID:4294774609
BasePriority:Normal

#:13 Name: C:\WINDOWS\SYSTEM\ATICWD32.EXE
----------------------------
Threads:4
ProcID:4294717933
ParentProcID:4294774609
BasePriority:Normal

#:14 Name: C:\MAC TO PC\MACOPENER\MACNAME.EXE
----------------------------
Threads:4
ProcID:4294726229
ParentProcID:4294774609
BasePriority:Normal

#:15 Name: C:\WINDOWS\SYSTEM\STIMON.EXE
----------------------------
Threads:6
ProcID:4294724525
ParentProcID:4294774609
BasePriority:Normal

#:16 Name: C:\WINDOWS\SYSTEM\PRINTRAY.EXE
----------------------------
Threads:4
ProcID:4294736409
ParentProcID:4294774609
BasePriority:Normal

#:17 Name: C:\PROGRAM FILES\SAVENOW\SAVENOW.EXE
----------------------------
Threads:10
ProcID:4294675861
ParentProcID:4294774609
BasePriority:Normal
Warning! SAVENOW : savenow.exe (savenow.exe)

"savenow.exe" unload successfull!


#:18 Name: C:\WINDOWS\LOADQM.EXE
----------------------------
Threads:7
ProcID:4294696137
ParentProcID:4294774609
BasePriority:Normal

#:19 Name: C:\PROGRAM FILES\WEBHANCER\PROGRAMS\WHAGENT.EXE
----------------------------
Threads:15
ProcID:4294697265
ParentProcID:4294774609
BasePriority:Normal
Warning! WEBHANCER : whagent.exe (whagent.exe)

"whagent.exe" unload successfull!


#:20 Name: C:\PROGRAM FILES\EXCITE\PLATFORM\EXAUTOUP.EXE
----------------------------
Threads:7
ProcID:4294703653
ParentProcID:4294681901
BasePriority:Normal

#:21 Name: C:\PROGRAM FILES\EXCITE\PLATFORM\EXSHELL.EXE
----------------------------
Threads:8
ProcID:4294658977
ParentProcID:4294681901
BasePriority:Normal

#:22 Name: C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
----------------------------
Threads:9
ProcID:4294664733
ParentProcID:4294774609
BasePriority:Normal

#:23 Name: C:\HARDWARE\ATI\ATIDESK\ATISCHED.EXE
----------------------------
Threads:4
ProcID:4294623505
ParentProcID:4294774609
BasePriority:Normal

#:24 Name: C:\ACCOUNTING\QUICKENW\QWDLLS.EXE
----------------------------
Threads:4
ProcID:4294591909
ParentProcID:4294774609
BasePriority:Normal

#:25 Name: C:\PROGRAM FILES\INTEL\CREATESHARE\PROGRAM\PC CAMERA GAMES\PROGRAM\RFTRAY.EXE
----------------------------
Threads:5
ProcID:4294519313
ParentProcID:4294774609
BasePriority:Normal

#:26 Name: C:\WINDOWS\SYSTEM\WMIEXE.EXE
----------------------------
Threads:3
ProcID:4294528557
ParentProcID:4294752109
BasePriority:Normal

#:27 Name: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
----------------------------
Threads:11
ProcID:4294560753
ParentProcID:4294774609
BasePriority:Normal

#:28 Name: C:\WINDOWS\SYSTEM\PSTORES.EXE
----------------------------
Threads:3
ProcID:4294231345
ParentProcID:4294307425
BasePriority:Normal

#:29 Name: C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
----------------------------
Threads:4
ProcID:4294187753
ParentProcID:4294307425
BasePriority:Normal

#:30 Name: C:\WINDOWS\SYSTEM\DDHELP.EXE
----------------------------
Threads:6
ProcID:4294174581
ParentProcID:4294307425
BasePriority:Realtime

#:31 Name: C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
----------------------------
Threads:12
ProcID:4294172449
ParentProcID:4294774609
BasePriority:Normal

#:32 Name: C:\PROGRAM FILES\LAVASOFT AD-AWARE\AD-AWARE.EXE
----------------------------
Threads:4
ProcID:4294038661
ParentProcID:4294774609
BasePriority:Normal

Memory scan result:
Total modules found:32
Suspicious modules found:2


Started registry scan
======================
Cydoor key:HKEY_USERS\.default\software\cydoor\
Cydoor key:HKEY_USERS\.default\software\cydoor services\
WebHancer key:HKEY_CLASSES_ROOT\clsid\{c900b400-cdfe-11d3-976a-00e02913a9e0}\
WebHancer key:HKEY_CLASSES_ROOT\interface\{c89435b0-cdfe-11d3-976a-00e02913a9e0}\
OnFlow key:HKEY_LOCAL_MACHINE\software\classes\clsid\{0cef79d8-d373-11d3-a7d3-00062962bf17}\
OnFlow key:HKEY_LOCAL_MACHINE\software\classes\ieonflow.ieonflow1\
OnFlow key:HKEY_LOCAL_MACHINE\software\classes\ieonflow.ieonflow1.7\
OnFlow key:HKEY_LOCAL_MACHINE\software\classes\typelib\{0cef79cb-d373-11d3-a7d3-00062962bf17}\
Cydoor key:HKEY_CURRENT_USER\software\cydoor\
Cydoor key:HKEY_LOCAL_MACHINE\software\cydoor\
Cydoor key:HKEY_CURRENT_USER\software\cydoor services\
WebHancer key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c900b400-cdfe-11d3-976a-00e02913a9e0}\
OnFlow key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\onflow\
SaveNow key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\savenow\
WebHancer key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\webhancer agent\
OnFlow key:HKEY_LOCAL_MACHINE\software\onflow\
WebHancer key:HKEY_LOCAL_MACHINE\software\webhancer\
SaveNow key:HKEY_LOCAL_MACHINE\software\whenu\
SaveNow key:HKEY_LOCAL_MACHINE\software\whenu\savenow\
WebHancer key:HKEY_CLASSES_ROOT\typelib\{c8cb3870-cdfe-11d3-976a-00e02913a9e0}\
WebHancer key:HKEY_CLASSES_ROOT\whiehelperobj.whiehelperobj\
WebHancer key:HKEY_CLASSES_ROOT\whiehelperobj.whiehelperobj.1\
SaveNow key:HKEY_CLASSES_ROOT\wusn.1\
SaveNow key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\savenow
WebHancer key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\webhancer agent
WebHancer value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\webhdll.dll
WebHancer value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\webhdll.dll
WebHancer value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\webhdll.dll
WebHancer value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\webhdll.dll
WebHancer value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\webhdll.dll
WebHancer value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\webhdll.dll


Started extended registry scan
===============================
OnFlow key:CLSID\{0CEF79D8-D373-11D3-A7D3-00062962BF17}
WebHancer key:CLSID\{c900b400-cdfe-11d3-976a-00e02913a9e0}


Registry scan result:
Suspicious keys found :33


Started folder scan
====================
Warning, no disk in drive (A)

Now processing drive (C), 3 remaining.
WebHancer file:C:\WINDOWS\WEBHDLL.DLL
WebHancer file:C:\WINDOWS\WHAGENT.INF
WebHancer file:C:\WINDOWS\whInstaller.exe
WebHancer file:C:\WINDOWS\whInstaller.ini
Aureate folder:C:\WINDOWS\SYSTEM\AdCache
OnFlow folder:C:\WINDOWS\TEMP\onflow
WebHancer folder:C:\WINDOWS\TEMP\webhancer
OnFlow folder:C:\Program Files\Internet Explorer\PLUGINS\Onflow
OnFlow folder:C:\Program Files\onflow
SaveNow folder:C:\Program Files\SaveNow
WebHancer folder:C:\Program Files\webHancer
Finished processing Drive(C), 1635 folders total.

Now processing drive (D), 2 remaining.
Finished processing Drive(D), 1637 folders total.

Now processing drive (E), 1 remaining.
Finished processing Drive(E), 1647 folders total.

Now processing drive (F), 0 remaining.
Finished processing Drive(F), 1648 folders total.

Folder scan result:
Folders processed:6567
Suspicious folders found:7


Started file scan
==================
Cydoor file:C:\WINDOWS\SYSTEM\cd_clint.dll
Doubleclick file:C:\WINDOWS\Cookies\[email protected][1].txt
Doubleclick file:C:\WINDOWS\Cookies\[email protected][1].txt
OnFlow file:C:\WINDOWS\TEMP\of_stub_ins_w_2045.exe
SaveNow file:C:\WINDOWS\TEMP\SaveNowInst.exe
WebHancer file:C:\WINDOWS\WEBHDLL.DLL
WebHancer file:C:\WINDOWS\WHAGENT.INF
WebHancer file:C:\WINDOWS\whInstaller.exe
WebHancer file:C:\WINDOWS\whInstaller.ini
OnFlow file:C:\Program Files\Internet Explorer\PLUGINS\onflowreport.exe
OnFlow file:C:\Program Files\Internet Explorer\PLUGINS\ieonflow.dll
OnFlow file:C:\Program Files\Internet Explorer\PLUGINS\NPONFLOW.DLL
OnFlow file:C:\Program Files\Internet Explorer\PLUGINS\onflowplayer0.dll
OnFlow file:C:\Program Files\Internet Explorer\PLUGINS\onflowreport.exe
OnFlow file:C:\Program Files\Netscape\Communicator\Program\Plugins\nponflow.dll
OnFlow file:C:\Program Files\Netscape\Communicator\Program\Plugins\onflowplayer0.dll
OnFlow file:C:\Program Files\onflow\uninstall onflow.exe
SaveNow file:C:\Program Files\SaveNow\savenow.db
SaveNow file:C:\Program Files\SaveNow\SaveNow.exe
SaveNow file:C:\Program Files\SaveNow\savenow.htm
WebHancer file:C:\Program Files\webHancer\Programs\WBHSHARE.DLL
WebHancer file:C:\Program Files\webHancer\Programs\WHAGENT.EXE
WebHancer file:C:\Program Files\webHancer\Programs\whAgent.ini
WebHancer file:C:\Program Files\webHancer\Programs\WHIEHLPR.DLL
WebHancer file:C:\Program Files\webHancer\Programs\WHIESHM.DLL

File scan result:
Suspicious files found:29



Scanning finished
==================
Suspicious modules found:2
Suspicious keys found :33
Suspicious folders found:7
Suspicious files found:29
==========================
Spyware components ignored:0
Total spyware components found:71


I know this is a major list and apologize, however I am struggling big time.....I am newbie to all this and need step by step comands thank you for your patients
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top