1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Paytime, and other annoyances.

Discussion in 'Virus & Other Malware Removal' started by BlueStar, Jan 24, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. BlueStar

    BlueStar Thread Starter

    Joined:
    Aug 14, 2004
    Messages:
    18
    Hello there.

    It seems like I only come on here whenever I have a problem. You guys have fixed me up before, and I hope you can provide me with some assistance again.

    Okay, I was online checking out some cracks for my windows blinds. I went onto a site and it entirely froze up my computer. My AVG kept going off and going haywire with "Virus Detected". So, I figured I"d download some hijack this. I found some of the key entries for this, I deleted the file (but not in safe mode, oops.). I think I've got myself in quite a mess. I can't go onto my computer without it freezing now. I have done an MSCONFIG, and all of that kind of stuff. I'm attempting to install firefox, perhaps it's not going to attack that. But, I've ran into a bunch of unsupported issues (with flipping back and forth with a floppy, only to have the floppy not read the disk anymore.) with issues with the internet, and oh man, has it ever been a mess.

    Anyhow, here's the hijack this logfile. Please help me!!!

    Logfile of HijackThis v1.99.1
    Scan saved at 4:59:05 PM, on 1/24/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\winsysban2.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    c:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\WINDOWS\system32\taskswitch.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\DOCUME~1\Darryl\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd2.exe
    O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban2.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Microsoft Office] C:\WINDOWS\system32\msvcp.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm
    O8 - Extra context menu item: Use as &Display Picture - C:\Program Files\IEDP2\IEDP.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127947723574
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1127947717155
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: wbsys.dll MsgPlusLoader.dll
    O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
     
  2. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Fix these with HJT – mark them, close IE, click fix checked

    O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd2.exe
    O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban2.exe

    DownLoad http://www.downloads.subratam.org/KillBox.zip

    Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

    Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

    C:\windows\winsysupd2.exe
    C:\windows\winsysban2.exe

    Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

    START – RUN – type in %temp% OK - Edit – Select all – File – Delete

    Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

    Empty the recycle bin
    Boot

    Download the trial version of Ewido Security Suite http://www.ewido.net/en/download/ (W2K/XP Only)
    · Install ewido.
    · During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    · Launch ewido
    · It will prompt you to update click the OK button and it will go to the main screen
    · On the left side of the main screen click update
    · Click on Start and let it update.
    · DO NOT run a scan yet. You will do that later in safe mode.

    Restart your computer into safe mode now. Perform the following steps in safe mode:
    (Start tapping F8 at the first black screen after power up)

    Run Ewido:
    · Click on scanner
    · Click Complete System Scan and the scan will begin.
    · During the scan it will prompt you to clean files, click OK
    · When the scan is finished, look at the bottom of the screen and click the Save report button.
    · Save the report to your C: Drive
    This will take some time to run!
    Boot to normal mode
    Post that log and a new HiJack log


    Please give feedback on what worked/didn’t work and the current status of your system
     
  3. BlueStar

    BlueStar Thread Starter

    Joined:
    Aug 14, 2004
    Messages:
    18
    Hello there,

    Thank you for all the help. Right now, the computer is pretty stable. It's not freezing up, I don't think. It's way too early to tell yet.

    Here are the scans you requested.

    HIJACKTHIS:

    Logfile of HijackThis v1.99.1
    Scan saved at 6:26:01 PM, on 1/24/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\WINDOWS\system32\taskswitch.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\DOCUME~1\Darryl\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm
    O8 - Extra context menu item: Use as &Display Picture - C:\Program Files\IEDP2\IEDP.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127947723574
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1127947717155
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: wbsys.dll MsgPlusLoader.dll
    O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


    SCAN REPORT FROM EWIDO:

    ---------------------------------------------------------
    ewido anti-malware - Scan report
    ---------------------------------------------------------

    + Created on: 6:21:28 PM, 1/24/2006
    + Report-Checksum: 6B5DBF9E

    + Scan result:

    HKU\S-1-5-21-299502267-1935655697-1957994488-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
    HKU\S-1-5-21-299502267-1935655697-1957994488-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup
    C:\WINDOWS\system32\msvcp.exe -> Proxy.Xorpix.n : Cleaned with backup
    C:\Documents and Settings\Darryl\Local Settings\Temporary Internet Files\Content.IE5\Y23MBLGE\winsysban[1].exe -> Hijacker.VB.kc : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Ysbweb : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][3].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\Darryl\Cookies\[email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\Darryl\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-393d648-18323733.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup
    :mozilla.13:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    :mozilla.14:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    :mozilla.15:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.19:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.20:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
    :mozilla.28:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
    :mozilla.32:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
    :mozilla.36:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
    :mozilla.37:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    :mozilla.58:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
    :mozilla.69:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    :mozilla.70:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
    :mozilla.73:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
    :mozilla.74:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
    :mozilla.88:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.89:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.94:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.95:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.96:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.97:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.98:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.100:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.101:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.102:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.103:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.104:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.105:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.107:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
    :mozilla.108:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
    :mozilla.109:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
    :mozilla.137:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
    :mozilla.140:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.144:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.165:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.166:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.167:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.168:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.169:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.170:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.171:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.172:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.200:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.201:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.209:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.210:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.211:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.222:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.224:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.227:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.245:C:\Documents and Settings\Darryl\Application Data\Mozilla\Firefox\Profiles\64cxqdp6.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    C:\!KillBox\winsysupd2.exe -> Hijacker.StartPage.ahg : Cleaned with backup
    C:\!KillBox\winsysban2.exe -> Hijacker.VB.kc : Cleaned with backup


    ::Report End
     
  4. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Log looks fine

    You should remove Limewire or you will surely be back again

    Get all of these and/or verify you have the current versions

    SpywareBlaster 3.5.1 http://majorgeeks.com/download2859.html
    SpyBot V1.4 http://www.majorgeeks.com/download2471.html
    AdAware SE 1.06 http://www.majorgeeks.com/download506.html
    MS AntiSpy - http://www.microsoft.com/downloads/...a2-6a57-4c57-a8bd-dbf62eda9671&displaylang=en (XP and W2K only)

    DownLoad them (they are free), install them, check each for their
    definition updates
    and then run AdAware, MS AntiSpy (W2k/XP) and Spybot, fixing anything
    they say.

    In SpywareBlaster - Always enable all protection after updates
    In SpyBot - After an update run immunize
     
  5. BlueStar

    BlueStar Thread Starter

    Joined:
    Aug 14, 2004
    Messages:
    18
    Hi again,

    Sorry, grrr. This computer is enough of a hassle. I will do the rest of that when I have enough time to do so, otherwise the computer will shut down. Read below:

    Now, when I logged back into the computer to do some browsing and stuff like that, this popup came up and asked me to reboot, because it was shutting down.

    This is the error, basically;

    "Please shut down all programs, to avoid lost data. This shut down has been initiated by the NT\Authority."
    It gives a countdown, and then it says

    "The system process "c:\Windows\System32\Services.exe"

    Then gives this number about microsoft. 16737417674, like an error message. (The error is off the screen, so I can't quote it word for word, and it only gives about 45 seconds.)

    Sorry for being such a pest!
     
  6. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
  7. BlueStar

    BlueStar Thread Starter

    Joined:
    Aug 14, 2004
    Messages:
    18
    I ran the tool you had linked me up to, and the blaster worm was not found. Perhaps could it be something I disabled in MSCONFIG? I don't have Norton or anything like that installed anymore. This was a computer that was given to me, and I did see reminence of norton and symantec in there.

    Any idea what it may be? I've given up. I've ran my adaware, and my avg, and uninstalled limewire. I should update the anti-spyware for microsoft, but I'm keeping that computer offline for now, until I get all of these things under control and I reinstall my firewall.

    I'm open to any suggestions.
     
  8. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    * Click here to download smitRem.exe.
    • Save the file to your desktop.
    • It is a self extracting file.
    • Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
    • Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.

    * Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.

    * Restart your computer into safe mode now. Perform the following steps in safe mode:

    * Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
    Wait for the tool to complete and disk cleanup to finish.

    * Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

    * Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar. If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.

    * Restart back into Windows normally now.

    http://www.kaspersky.com/virusscanner - Online scan

    When the scan is finished Save the results from the scan!

    Post a new HiJackThis log along with the results from Kaspersky scan
     
  9. BlueStar

    BlueStar Thread Starter

    Joined:
    Aug 14, 2004
    Messages:
    18
    Alright, so this is the tricky part.

    Everytime I plug in my wireless, it will give me that error message.

    Something in c:\windows\system32\services.exe is interfering.

    I am doing the kaspersky online virus scan right now, and there has been no problems thusfar, the popup window came up counted down a minute, and then turned off, while doing this virus scan.

    This is really weird, perhaps there's something that I had done. I was trying to network my desktop and my other desktop (which is wireless), could this result in any problems with this particular exe file in system32?
     
  10. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Need the exact error message

    That countdown is indaciticve of the blaster prob but yousaid the tools founed nothing

    that services file is a legit file in that location
     
  11. BlueStar

    BlueStar Thread Starter

    Joined:
    Aug 14, 2004
    Messages:
    18
    The file that is infected is C:\drsmartload1.exe. Unfortunately, I couldn't save the text file, because kaspersky froze up on me.

    Logfile of HijackThis v1.99.1
    Scan saved at 3:13:46 PM, on 1/25/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\WINDOWS\system32\taskswitch.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
    C:\DOCUME~1\Darryl\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    C:\DOCUME~1\Darryl\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm
    O8 - Extra context menu item: Use as &Display Picture - C:\Program Files\IEDP2\IEDP.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127947723574
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1127947717155
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: wbsys.dll MsgPlusLoader.dll
    O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe



    As for the legit error; It's the same one I described. I thought the blaster virus had a countdown of 30 seconds, not one minute. Sometimes it will countdown and not restart on me, othertimes, it will.
     
  12. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Delete that file
     
  13. BlueStar

    BlueStar Thread Starter

    Joined:
    Aug 14, 2004
    Messages:
    18
    The error message that comes up says:
    At the top it says "System Shutdown"

    Please save any work, and log off. Your system will shut down.
    NTAuthority\system
    Gives a countdown of 1 minute

    Then says:
    Something about NT Authority

    "C:\Windows\System32\Services.exe has terminated unexpectantly with status code: 1673741674"
     
  14. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
  15. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/436936

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice