Windows Me and user.exe again....

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

DrKadusch

Thread Starter
Joined
Jan 31, 2005
Messages
4
I have read a lot of suggestions on this site and tried them all, but I still get 'xxxxxxxx has caused an error in user.exe'. Now I have downloaded the Hijackthis and want to show the listing from running it. Here it comes:

Logfile of HijackThis v1.99.0
Scan saved at 15:38:17, on 2005-01-31
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\PROGRAM\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM\EFFICIENT NETWORKS\ENTERNET 300\APP\ENTERNET.EXE
C:\PROGRAM\HEWLETT-PACKARD\DIGITAL IMAGING\UNLOAD\HPQCMON.EXE
C:\PROGRAM\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\PROGRAM\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\KDX\KHOST.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\WINDOWS\CSERV32.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\MSBB.EXE
C:\PROGRAM\PHILIPS TOUCAM CAMERA\GAMECAM SE\PROGRAM\RFTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - URLSearchHook: PerfectNavBHO Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - C:\PROGRAM\PERFEC~1\BHO\PERFEC~1.DLL
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.atg.se"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\a1llmcgs.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\a1llmcgs.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - C:\PROGRAM\PERFEC~1\BHO\PERFEC~1.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM\MYWAY\MYBAR\1.BIN\MYBAR.DLL
O2 - BHO: (no name) - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\SYSTEM\peront.dll
O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program\QuickSearch\QuickSearchBar3_28.dll
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program\NewDotNet\newdotnet6_38.dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM\MYWAY\MYBAR\1.BIN\MYBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program\QuickSearch\QuickSearchBar3_28.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [AudioHQ] C:\Program\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [reminder.exe] C:\program\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [$EnterNet] C:\PROGRAM\EFFICIENT NETWORKS\ENTERNET 300\APP\EnterNet.exe -AutoStart
O4 - HKLM\..\Run: [CamMonitor] C:\Program\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RealTray] C:\Program\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [updmgr] C:\Program\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\KDX\KHOST.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Error Nuker] C:\Program\Error Nuker\bin\ErrorNuker.exe autostart
O4 - HKLM\..\Run: [WINDOWSCSERV32] C:\WINDOWS\CSERV32.EXE
O4 - HKLM\..\Run: [cxwn] C:\WINDOWS\cxwn.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRAM\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [msbb] c:\windows\msbb.exe
O4 - HKLM\..\Run: [ifqxorut] C:\WINDOWS\ifqxorut.exe
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [Ares Galaxy FasterDownload] "C:\PROGRAM\DCPLUS FASTERDOWNLOADS\DCPLUS FASTERDOWNLOADS.EXE" -tray
O4 - Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Reality Fusion GameCam SE.lnk = C:\Program\Philips ToUcam Camera\GameCam SE\Program\RFTray.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program\MultiPoker\MultiPoker.exe
O9 - Extra 'Tools' menuitem: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program\MultiPoker\MultiPoker.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = sebank.se
O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\SYSTEM\peront.dll
O18 - Filter: text/plain - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\SYSTEM\peront.dll

By for now

DrKadusch
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
81,767
I'll let someone else more experienced than me examine and fix your HijackThis log.

---------------------------------------------------------------

One thing that I do notice in your log though is that you have too many unnecessary programs loading during startup and running in the background. This causes longer startup times, reduced system resources, reduction of overall performance, and increased risks of freezes and error messages.

If you want to research the items in your startup list and decide which ones to disable, using the "Search" option at this site will help you greatly.

Other than:

ScanRegistry

SystemTray

StateMgr

Antivirus program entries

Firewall program entries


Windows ME needs very few other programs to be enabled in the MSCONFIG "Startup" tab.

---------------------------------------------------------------

You need to move HijackThis out of the C:\WINDOWS\TEMP folder and place it somewhere else.

Part of your regular computer maintenance should be running a "Search" and deleting everything that appears under:

*.TMP

C:\TEMP\*.*

C:\WINDOWS\TEMP\*.*

If you leave HijackThis where it is, it'll get deleted in the process.

----------------------------------------------------------------
 

DrKadusch

Thread Starter
Joined
Jan 31, 2005
Messages
4
flavallee said:
I'll let someone else more experienced than me examine and fix your HijackThis log.

---------------------------------------------------------------

One thing that I do notice in your log though is that you have too many unnecessary programs loading during startup and running in the background. This causes longer startup times, reduced system resources, reduction of overall performance, and increased risks of freezes and error messages.

If you want to research the items in your startup list and decide which ones to disable, using the "Search" option at this site will help you greatly.

Other than:

ScanRegistry

SystemTray

StateMgr

Antivirus program entries

Firewall program entries


Windows ME needs very few other programs to be enabled in the MSCONFIG "Startup" tab.

---------------------------------------------------------------

You need to move HijackThis out of the C:\WINDOWS\TEMP folder and place it somewhere else.

Part of your regular computer maintenance should be running a "Search" and deleting everything that appears under:

*.TMP

C:\TEMP\*.*

C:\WINDOWS\TEMP\*.*

If you leave HijackThis where it is, it'll get deleted in the process.

----------------------------------------------------------------
 

DrKadusch

Thread Starter
Joined
Jan 31, 2005
Messages
4
Hi, I have gone through MSCONFIG and disabled a lot of programs after checking with sysinfo.org. Now the user.exe-message has disappeared and the PC is running a bit faster.
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
81,767
Good! :) You'll find out that keeping the startup load as small as possible will make that computer run better and have less problems. (y)
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top