1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

(Solved) Windows ME shutdown

Discussion in 'Earlier Versions of Windows' started by redalert95, Oct 19, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    I have a Dell Optiplex GX1, 500 mhz, with Widows ME.

    When I do Start, Shut down, Shutdown computer, the computer will shut down and sometimes ask me to close a program and gives me 3 options, End Task, Wait, and Cancel. I press End Task and the computer shuts down. But wether or not it asks me this when ever i turn on my computer it starts a ScanDisk. My dad as well as other people have told me that this isnt good for the computer.

    Please Help me

    Either post a reply or e-mail me @ [email protected]

    Thank you
     
  2. Davey7549

    Davey7549

    Joined:
    Feb 28, 2001
    Messages:
    11,584
    redalert95
    Welcome to TSG!
    The answer.... No it is not good for your system to terminate a process that is refusing to shutdown in time.


    What process is the offending one? Maybe we can find out why it is refusing timely shutdown.
    Also if you wait does it shutdown? If so how long does it take?

    Is this process Rnapp by chance?

    Dave
     
  3. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    i have never installed Rnapp ont the computer, the Title Bar does not say the name of the program. THe Shut down usually takes about the average amount of time to shut down even after i press End Task.

    Hope we can get this fix, its a used computer but formatted and i have only had it less than a year
     
  4. Davey7549

    Davey7549

    Joined:
    Feb 28, 2001
    Messages:
    11,584
    redalert95
    Rnapp is part of Windows dial up networking and not installed as an independent application. Before you shutdown do a ctrl,alt,del to open task manager and see what is running in process. Is Rnapp one of them?

    Another way to see which one is crabby is by process of elimination. Using task manager end all tasks except Explorer and then shutdown. Does that fix the shutdown? If so then restart and end task on small groups of items except explorer and shutdown. By doing this you can isolate the offending app.

    There are also shutdown delays that can be incorporated and also the exit sound file being corrupt can cause a hang.

    Dave
     
  5. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    i do not have dial up net work but @ shutdown there were these programs running : Explorer, Rundll32, Osa, Dact, Systray, Logwatt95. When I closed Rundll32 and shut down my computer froze. I havent tried any of hte other ones yet
     
  6. Davey7549

    Davey7549

    Joined:
    Feb 28, 2001
    Messages:
    11,584
    redalert95
    Yes I forgot about Rundll32 sorry!!!
    If none of the others are involved in the shutdown problem then we will have to explore what is requiring rundll32 to be running because it may be the offending program!

    Dave
     
  7. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    ok ill continue my process of elimination and if it works the dame with only explorer and rundll32 runing we will pursue it

    well @ least we got a breakthrough!!! :):):):)
     
  8. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    YES, I am now 99% sure that it is rundll32 that is causing the problem, when I end it using ctrl, alt, delete, it seems to come up again!!! If I close it and then immedeatly shut down it seems to come up to!!! I will be ending my session on my computer soon so we may have to explore this issue. Also I checked and Rundll32 is not running on my dad's computer!!! So I am pretty sure it is the offending program
     
  9. Davey7549

    Davey7549

    Joined:
    Feb 28, 2001
    Messages:
    11,584
    redalert95
    Do this then when you have time.
    Download, setup, run and post results back here using the instruction for HiJack this.

    HiJack this Instructions

    Dave
     
  10. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    Logfile of HijackThis v1.97.3
    Scan saved at 4:06:10 PM, on 10/20/2003
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v5.50 (5.50.4134.0100)

    Running processes:
    C:\WINDOWS.000\SYSTEM\KERNEL32.DLL
    C:\WINDOWS.000\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS.000\SYSTEM\mmtask.tsk
    C:\WINDOWS.000\SYSTEM\MPREXE.EXE
    C:\WINDOWS.000\SYSTEM\MSTASK.EXE
    C:\WINDOWS.000\SYSTEM\STIMON.EXE
    C:\WINDOWS.000\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS.000\EXPLORER.EXE
    C:\WINDOWS.000\TASKMON.EXE
    C:\WINDOWS.000\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS.000\LOGWAT95.EXE
    C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
    C:\WINDOWS.000\SYSTEM\WMIEXE.EXE
    C:\WINDOWS.000\APPLICATION DATA\DACT.EXE
    C:\WINDOWS.000\SYSTEM\WINSERVN.EXE
    C:\MICROSOFT OFFICE\OFFICE\OSA.EXE
    C:\WINDOWS.000\RUNDLL32.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
    C:\WINDOWS.000\SYSTEM\PSTORES.EXE
    C:\WINDOWS.000\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
    C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchbar.findthewebsiteyouneed.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.kazaa-lite.ws/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kazaa-lite.ws/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.kazaa-lite.ws/results.php?show=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.kazaa-lite.ws/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.kazaa-lite.ws/results.php?show=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kazaa-lite.ws/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kazaa-lite.ws/
    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL
    O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS.000\SYSTEM\BTIEIN.DLL
    O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {49E0E0F0-5C30-11D4-945D-000000000000} - C:\PROGRA~1\SMARTS~1\SMARTS~1.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: &Smart Stopper - {C4370071-9FF8-4442-B9C7-F849AC0789CA} - C:\PROGRA~1\SMARTS~1\SMARTS~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS.000\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS.000\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS.000\taskmon.exe
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS.000\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [MS Updates] C:\WINDOWS.000\MSCACHE.EXE
    O4 - HKLM\..\Run: [LogWatch] C:\WINDOWS.000\LogWat95.exe
    O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE"
    O4 - HKLM\..\Run: [System32] System32.exe
    O4 - HKLM\..\Run: [Messenger Plus] "C:\WEBSITE STUFF\MESSENGER PLUS\MESSPLUS.exe" -silent
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [TB_setup] C:\WINDOWS\TEMP\TB_ANI~1.EXE /dcheck
    O4 - HKLM\..\Run: [stcloader] C:\WINDOWS.000\SYSTEM\stcloader.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS.000\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS.000\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [System32] System32.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Website\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Hawr] C:\WINDOWS.000\Application Data\dact.exe
    O4 - HKCU\..\Run: [ContentService] C:\WINDOWS.000\SYSTEM\winservn.exe
    O4 - Startup: Office Startup.lnk = C:\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Microsoft Find Fast.lnk = C:\Microsoft Office\Office\FINDFAST.EXE
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .qt: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37870.7667708333
    O16 - DPF: {AE6CEFA8-1223-4337-8D94-977268FF9AA0} (DownloadUL Class) - http://www.********com/includes/Download_UL.cab
    O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50023/QDow.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab


    those are the results of the scan. hope that this is what you wanted, I have never used Hijack This before
     
  11. Davey7549

    Davey7549

    Joined:
    Feb 28, 2001
    Messages:
    11,584
    Redalert95

    You have some nasties on your system including a virus.....

    Do this Go to this Website and run a free online scan allow housecall to remove anything found.

    The rerun Hijack this and see if items listed below are still present. If so place checkmarks to select for removal and have hijack fix them but run and fix virus first!!!!!!!

    ------------------------------------------------------

    See Note below for this one------> C:\WINDOWS.000\LOGWAT95.EXE

    Not sure on this If you do not know what viewer it is then leave HiJack remove it----> C:\WINDOWS.000\APPLICATION DATA\DACT.EXE

    Remove items below........
    C:\WINDOWS.000\SYSTEM\WINSERVN.EXE


    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchbar.findthewebsiteyouneed.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL
    O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS.000\SYSTEM\BTIEIN.DLL
    O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL



    Virus------> O4 - HKLM\..\Run: [System32] System32.exe


    O4 - HKLM\..\Run: [TB_setup] C:\WINDOWS\TEMP\TB_ANI~1.EXE /dcheck

    O4 - HKLM\..\Run: [stcloader] C:\WINDOWS.000\SYSTEM\stcloader.exe

    O4 - HKCU\..\Run: [ContentService] C:\WINDOWS.000\SYSTEM\winservn.exe
    -------------------------------------------------------------------------

    Note....... If you are using Unicenter products then leave alone otherwise follow instructions to remove.
    Logwatnt Logwat95.exe

    Logwatnt.exe

    (Computer Associates) Essential software fix issued by Computer Associates to users of Unicenter products. It corrects memory leaks and access violation errors in the licensing modules of the products involved (for example : CA Visual Objects 2.5, ControlIT, Remotely Possible).

    Recommendation :
    If you are still using a relevant Computer Associates product, keep it, otherwise delete it with Starter.
    ---------------------------------------------------------------

    Dave
     
  12. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    Oh Jeez

    Thanks for the heads up, runnin the virus checker and hiJack again.
     
  13. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    alright HouseCall found 2 viruses:(

    ADW TENGET.A and TROJ BISKOO.A both were "non-cleanable" im running a newly aquired virus checker to see if it can delete it. The first one should be easy enoguht to get rid of as that it is is Temporary Internet files. The other is in mscache.exe so we will see about that one
     
  14. Davey7549

    Davey7549

    Joined:
    Feb 28, 2001
    Messages:
    11,584
    Do not worry if they are cleanable just remove them or let housecalls do it automatically.

    Dave
     
  15. redalert95

    redalert95 Thread Starter

    Joined:
    Oct 19, 2003
    Messages:
    256
    does this HiJack This log look better???

    Logfile of HijackThis v1.97.3
    Scan saved at 8:17:30 PM, on 10/20/2003
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v5.50 (5.50.4134.0100)

    Running processes:
    C:\WINDOWS.000\SYSTEM\KERNEL32.DLL
    C:\WINDOWS.000\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS.000\SYSTEM\mmtask.tsk
    C:\WINDOWS.000\SYSTEM\MPREXE.EXE
    C:\WINDOWS.000\SYSTEM\MSTASK.EXE
    C:\WINDOWS.000\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
    C:\WINDOWS.000\EXPLORER.EXE
    C:\WINDOWS.000\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS.000\TASKMON.EXE
    C:\WINDOWS.000\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS.000\LOGWAT95.EXE
    C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
    C:\WINDOWS.000\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
    C:\WINDOWS.000\APPLICATION DATA\DACT.EXE
    C:\WINDOWS.000\SYSTEM\WINSERVN.EXE
    C:\MICROSOFT OFFICE\OFFICE\OSA.EXE
    C:\WINDOWS.000\RUNDLL32.EXE
    C:\WINDOWS.000\RUNDLL32.EXE
    C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {49E0E0F0-5C30-11D4-945D-000000000000} - C:\PROGRA~1\SMARTS~1\SMARTS~1.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: &Smart Stopper - {C4370071-9FF8-4442-B9C7-F849AC0789CA} - C:\PROGRA~1\SMARTS~1\SMARTS~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS.000\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS.000\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS.000\taskmon.exe
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS.000\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [MS Updates] C:\WINDOWS.000\MSCACHE.EXE
    O4 - HKLM\..\Run: [LogWatch] C:\WINDOWS.000\LogWat95.exe
    O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE"
    O4 - HKLM\..\Run: [System32] System32.exe
    O4 - HKLM\..\Run: [Messenger Plus] "C:\WEBSITE STUFF\MESSENGER PLUS\MESSPLUS.exe" -silent
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [TB_setup] C:\WINDOWS\TEMP\TB_ANI~1.EXE /dcheck
    O4 - HKLM\..\Run: [stcloader] C:\WINDOWS.000\SYSTEM\stcloader.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS.000\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS.000\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [System32] System32.exe
    O4 - HKLM\..\RunServices: [avgamsvr.exe] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Website\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Hawr] C:\WINDOWS.000\Application Data\dact.exe
    O4 - Startup: Office Startup.lnk = C:\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Microsoft Find Fast.lnk = C:\Microsoft Office\Office\FINDFAST.EXE
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .qt: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37870.7667708333
    O16 - DPF: {AE6CEFA8-1223-4337-8D94-977268FF9AA0} (DownloadUL Class) - http://www.********com/includes/Download_UL.cab
    O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50023/QDow.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/0fb5e03023def1/housecall.antivirus.com/housecall/xscan53.cab
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/173089

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice