1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Windows XP Problems - I think :(

Discussion in 'Virus & Other Malware Removal' started by JakesMom, Jan 19, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    Sorry, I'm quite new to this trying to fix the computer myself thing. I've got a Dell with Windows XP Home Edition. It's doing some hinkey things: It refuses to load adaware from download or from a disk. It'll let me put it on the computer, but it won't let me run it. Sometimes it will let me access the internet, sometimes it will give me an hourglass for a couple of seconds and then go back to my regular cursor and do nothing. I've got Mozilla on it which helped with the popups, but I still get a few. I've got Spyware Doctor on it and enabled. Wasn't sure where to start??? Any help would be greatly appreciated.

    **I've run Spyware Blaster & it finds some, but I can't delete them without buying it? CCleaner removed some files. CW Shredders says it finds nothing. Internet keeps timing me out until I reboot and it will work for about 15 minutes. Still won't let me install Adaware?? Do I need to run a HIJACK log??**

    Thanks
    Vickie (Jakesmom)
     
  2. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    Oh Goody! Now my icons are gone. Tried F8 and going to Last good config. But that didn't work either. Thinking about breaking out the hammer!!!:confused:
     
  3. stantley

    stantley

    Joined:
    May 22, 2005
    Messages:
    7,091
    Do you have McAfee installed, if you do the new version conflicts with AdAware.
     
  4. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    MCAfee is there, but it's old - like 2004. Not being used, can't uninstall it?
     
  5. stantley

    stantley

    Joined:
    May 22, 2005
    Messages:
    7,091
  6. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    Logfile of HijackThis v1.99.1
    Scan saved at 11:53:42 AM, on 1/19/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    E:\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: Shell=Explorer.exe,wbcml_hp.exe,servgina.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\wbcml_hp.exe,C:\Documents and Settings\JJ\Application Data\Explorer\wbcml_hp.exe,C:\Documents and Settings\JJ\Application Data\Explorer\servgina.exe,C:\WINDOWS\System32\servgina.exe
    O2 - BHO: (no name) - {40A2988E-C954-4DDE-BD08-453191805BB9} - C:\WINDOWS\SYSTEM32\durvilz.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\SYSTEM32\qjb.dll
    O2 - BHO: (no name) - {A4A9D49A-9872-4877-A10C-DE744F1D5658} - C:\WINDOWS\System32\rflfgvyg.dll
    O2 - BHO: (no name) - {F62F6230-A86A-478B-B08F-BACE7B86E20e} - C:\WINDOWS\System32\rflfgvyg.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    O4 - HKLM\..\Run: [LMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
    O4 - HKLM\..\Run: [Microsoft Windows System] mqvjcrun.exe
    O4 - HKLM\..\Run: [ajhsmbjc] C:\WINDOWS\System32\ajhsmbjc.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Update Component] C:\WINDOWS\System32\servgina.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
    O4 - HKLM\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
    O4 - HKLM\..\RunServices: [Microsoft Windows System] mqvjcrun.exe
    O4 - HKLM\..\RunOnce: [srshost.exe] C:\WINDOWS\system32\srshost.exe /k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ajhsmbjc] C:\WINDOWS\System32\ajhsmbjc.exe
    O4 - HKCU\..\Run: [Update Component] C:\WINDOWS\System32\servgina.exe
    O4 - HKCU\..\Run: [WinMedia] C:\361101032253072.exe
    O4 - HKCU\..\Run: [iwfm] C:\PROGRA~1\COMMON~1\iwfm\iwfmm.exe
    O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
    O4 - HKCU\..\RunOnce: [srshost.exe] C:\WINDOWS\system32\srshost.exe /k
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.spamblockerutility....ility/programs/4.8.0.0/spamblockerutility.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/chuzzle/popcaploader_v6.cab
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: fppprngn - C:\WINDOWS\SYSTEM32\fppprngn.dll
    O20 - Winlogon Notify: ghfcgvwt - C:\WINDOWS\SYSTEM32\ghfcgvwt.dll
    O20 - Winlogon Notify: hchpvblt - C:\WINDOWS\SYSTEM32\hchpvblt.dll
    O20 - Winlogon Notify: ieqmhdbk - C:\WINDOWS\SYSTEM32\ieqmhdbk.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: jtnlxcwh - C:\WINDOWS\SYSTEM32\jtnlxcwh.dll
    O20 - Winlogon Notify: ktubqhax - C:\WINDOWS\SYSTEM32\ktubqhax.dll
    O20 - Winlogon Notify: luffpuwa - C:\WINDOWS\SYSTEM32\luffpuwa.dll
    O20 - Winlogon Notify: njqffwcd - C:\WINDOWS\SYSTEM32\njqffwcd.dll
    O20 - Winlogon Notify: pfmgtfah - C:\WINDOWS\SYSTEM32\pfmgtfah.dll
    O20 - Winlogon Notify: qjgxxkuc - C:\WINDOWS\SYSTEM32\qjgxxkuc.dll
    O20 - Winlogon Notify: qmtppidl - C:\WINDOWS\SYSTEM32\qmtppidl.dll
    O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll
    O20 - Winlogon Notify: rpccd - C:\WINDOWS\System32\rpccd.dll
    O20 - Winlogon Notify: vgvwkfyc - C:\WINDOWS\SYSTEM32\vgvwkfyc.dll
    O21 - SSODL: IEFilter - {A0CC9241-380D-4847-ACE5-6CF129D6C3FE} - C:\WINDOWS\system32\IEFilter.dll
    O21 - SSODL: Connection Explorer - {ECDD31AC-55F5-416A-BDB2-37780E8DE794} - C:\WINDOWS\System32\qosnxt32.dll (file missing)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Sko\command.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
     
  7. stantley

    stantley

    Joined:
    May 22, 2005
    Messages:
    7,091
    Yes, you have some problems. Why don't you click on the red exclaimation point at the top the post and ask for this to be moved to Security where it will get quicker attention.
     
  8. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    Okay, I asked for it to be moved to security. Do I need to be doing something else? Sorry, I'm seriously a Beginner here :) Thanks
     
  9. stantley

    stantley

    Joined:
    May 22, 2005
    Messages:
    7,091
    Nope, a HJT expert will help you the rest of the way.
     
  10. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    Okay, thank you.
     
  11. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Run HijackThis and click Open the Misc Tools section
    Click Open Uninstall Manager, Save list and save the log to your Desktop.
    A list of programs will open in Notepad. Post the contents of the log here in your next reply.
     
  12. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    Sorry it took me so long to get back. Small family fiasco this weekend! :) Okay, let me start by saying I'm not very computer literate. I ran Hijack This and did a scan and saved my log, which is posted below. I didn't however see anything that said Misc Tools???? My icons are back this morning though:confused: Thanks

    Logfile of HijackThis v1.99.1
    Scan saved at 6:25:16 AM, on 1/22/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\Sko\command.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Documents and Settings\JJ\Application Data\Explorer\servgina.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\Program Files\Network Monitor\netmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\mqvjcrun.exe
    C:\Program Files\Ipwindows\ipwins.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\Program Files\Common Files\{B8F93263-0890-1033-0731-030512200001}\Update.exe
    C:\361101032253072.exe
    C:\Program Files\MySpace\IM\MySpaceIM.exe
    C:\Program Files\Hijackthis\HijackThis.exe
    C:\Program Files\SpywareBot\SpywareBot.exe
    C:\Program Files\SpywareBot\Scheduler.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\cidaemon.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: Shell=Explorer.exe,wbcml_hp.exe,servgina.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\wbcml_hp.exe,C:\Documents and Settings\JJ\Application Data\Explorer\wbcml_hp.exe,C:\Documents and Settings\JJ\Application Data\Explorer\servgina.exe,C:\WINDOWS\System32\servgina.exe
    O2 - BHO: (no name) - {40A2988E-C954-4DDE-BD08-453191805BB9} - C:\WINDOWS\SYSTEM32\durvilz.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\SYSTEM32\qjb.dll
    O2 - BHO: (no name) - {A4A9D49A-9872-4877-A10C-DE744F1D5658} - C:\WINDOWS\System32\rflfgvyg.dll
    O2 - BHO: (no name) - {F62F6230-A86A-478B-B08F-BACE7B86E20e} - C:\WINDOWS\System32\rflfgvyg.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    O4 - HKLM\..\Run: [LMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
    O4 - HKLM\..\Run: [Microsoft Windows System] mqvjcrun.exe
    O4 - HKLM\..\Run: [ajhsmbjc] C:\WINDOWS\System32\ajhsmbjc.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
    O4 - HKLM\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
    O4 - HKLM\..\Run: [Update Component] C:\WINDOWS\System32\servgina.exe
    O4 - HKLM\..\RunServices: [Microsoft Windows System] mqvjcrun.exe
    O4 - HKLM\..\RunOnce: [srshost.exe] C:\WINDOWS\system32\srshost.exe /k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ajhsmbjc] C:\WINDOWS\System32\ajhsmbjc.exe
    O4 - HKCU\..\Run: [WinMedia] C:\361101032253072.exe
    O4 - HKCU\..\Run: [iwfm] C:\PROGRA~1\COMMON~1\iwfm\iwfmm.exe
    O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
    O4 - HKCU\..\Run: [Update Component] C:\WINDOWS\System32\servgina.exe
    O4 - HKCU\..\RunOnce: [srshost.exe] C:\WINDOWS\system32\srshost.exe /k
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.spamblockerutility....ility/programs/4.8.0.0/spamblockerutility.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/chuzzle/popcaploader_v6.cab
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: fppprngn - C:\WINDOWS\SYSTEM32\fppprngn.dll
    O20 - Winlogon Notify: ghfcgvwt - C:\WINDOWS\SYSTEM32\ghfcgvwt.dll
    O20 - Winlogon Notify: hchpvblt - C:\WINDOWS\SYSTEM32\hchpvblt.dll
    O20 - Winlogon Notify: ieqmhdbk - C:\WINDOWS\SYSTEM32\ieqmhdbk.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: jtnlxcwh - C:\WINDOWS\SYSTEM32\jtnlxcwh.dll
    O20 - Winlogon Notify: ktubqhax - C:\WINDOWS\SYSTEM32\ktubqhax.dll
    O20 - Winlogon Notify: luffpuwa - C:\WINDOWS\SYSTEM32\luffpuwa.dll
    O20 - Winlogon Notify: njqffwcd - C:\WINDOWS\SYSTEM32\njqffwcd.dll
    O20 - Winlogon Notify: pfmgtfah - C:\WINDOWS\SYSTEM32\pfmgtfah.dll
    O20 - Winlogon Notify: qjgxxkuc - C:\WINDOWS\SYSTEM32\qjgxxkuc.dll
    O20 - Winlogon Notify: qmtppidl - C:\WINDOWS\SYSTEM32\qmtppidl.dll
    O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll
    O20 - Winlogon Notify: rpccd - C:\WINDOWS\System32\rpccd.dll
    O20 - Winlogon Notify: vgvwkfyc - C:\WINDOWS\SYSTEM32\vgvwkfyc.dll
    O21 - SSODL: IEFilter - {A0CC9241-380D-4847-ACE5-6CF129D6C3FE} - C:\WINDOWS\system32\IEFilter.dll
    O21 - SSODL: Connection Explorer - {ECDD31AC-55F5-416A-BDB2-37780E8DE794} - C:\WINDOWS\System32\qosnxt32.dll (file missing)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Sko\command.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
     
  13. stantley

    stantley

    Joined:
    May 22, 2005
    Messages:
    7,091
    When you start up HJT go to the bottom right and click on 'Config', then follow the rest of cybertech's instructions.
     
  14. JakesMom

    JakesMom Thread Starter

    Joined:
    Jan 19, 2007
    Messages:
    12
    Sorry. Here's the list:

    ABBYY FineReader 5.0 Sprint
    Adobe Acrobat 4.0
    AOL Instant Messenger
    BCM V.92 56K Modem
    Broadcom Management Programs
    CardRd81
    CCHelp
    CCleaner (remove only)
    CCScore
    Command
    Cool Edit 96
    CR2
    Dell Digital Jukebox Driver
    Dell Picture Studio - Dell Image Expert
    Dell ResourceCD
    Dell Solution Center
    Dell Support 5.0.0 (766)
    Easy CD Creator 5 Basic
    ESSAdpt
    ESSANUP
    ESSBrwr
    ESSCAM
    ESSCDBK
    ESScore
    ESSCT
    ESSgui
    ESShelp
    ESSini
    ESSPCD
    ESSPDock
    ESSSONIC
    ESSTUTOR
    ESSvpaht
    ESSvpot
    Google Toolbar for Internet Explorer
    Hijackthis 1.99.1
    HijackThis 1.99.1
    HLPCCTR
    HLPIndex
    HLPPDOCK
    HLPRFO
    Intel(R) Extreme Graphics Driver
    IpWins
    J2SE Runtime Environment 5.0 Update 6
    Kodak EasyShare software
    KSU
    Lexmark X125
    Macromedia Flash Player 8
    McAfee.com SecurityCenter
    McAfee.com VirusScan Online
    Microsoft .NET Framework 1.1
    Modem Helper
    Morpheus 5.1 (remove only)
    Mozilla Firefox (1.5.0.9)
    MUSICMATCH® Jukebox
    MySpaceIM
    Network Monitor
    Notifier
    OTtBP
    OTtBPSDK
    Paint Shop Pro 7
    PCDLNCH
    PokerStars
    QuickTime
    RealOne Player
    SFR
    SFR2
    SpySubtract
    SpywareBlaster v3.5.1
    SpywareBot 1.4.1.4
    TargetSaver
    VCAMCEN
    VPRINTOL
    Weather Services
    Web Browser Component Manager
    WordPerfect Office 11
     
  15. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Go to Add/Remove programs and remove these:
    IpWins
    Network Monitor
    SpywareBot 1.4.1.4
    TargetSaver

    After removing those restart the machine.

    Download (save) combofix from one of these two sites:
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log for you.

    Note:
    Do not mouseclick combofix's window while it's running. That may cause it to stall.

    Please post a new hijackthis log with the log from combofix in your next reply.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/536555

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice