Tabula Rasa Posted October 13, 2005 Report Share Posted October 13, 2005 Hey Guys!I was wondering if you could help me with a little problem.I have 2 different harddrives - C & D - and since yesterday everytime I open the D Folder (through My Computer) it gives me this message:(This is in Danish but basically it says "Explorer.exe has found an error...")Then when I click on the blue link right above send/don't send (The one that reads "Skal du klikke her") - the one that I should click if I wanna see the data in the errorrepport, I get this:..Now even though I get the popup I can still browse around the D folder and rename, move, copy, open stuff.. But when I click the "send" or the "do not send" buttons, Windows shuts down the folder and my computer freezes for a few seconds.... I have some media files there but when I open them through a media player I DONT get the popup...Does anyone know what's going on, cause it drives me CRAZY!... I can post a HiJack This log if you think that helps..Thanks in advance! Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted October 13, 2005 Report Share Posted October 13, 2005 Hi, and welcome to the forum! :) Infection with some kind of malware is certainly the first thing that comes to mind. Yes, please post a Hijackthis log; someone will then move it to the Hijackthis forum.Hey Guys!I assume that you mean the girls as well, as we have some highly skilled girls here too. Quote Link to comment Share on other sites More sharing options...
Tabula Rasa Posted October 13, 2005 Author Report Share Posted October 13, 2005 Yeah I mean "guys" as in "hey people"Anyway here is my HiJack This log.... For the record just 2 minutes ago I opened my recycle bin and got the same pop-up. (And once again I remind that I live in Denmark, so some of the folders in the log are in Danish).Logfile of HijackThis v1.97.7Scan saved at 07:05:56, on 13-10-2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Programmer\Fælles filer\Symantec Shared\ccProxy.exeC:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exeC:\WINDOWS\system32\gearsec.exeC:\Programmer\Norton Internet Security\ISSVC.exeC:\Programmer\Norton Internet Security\Norton AntiVirus\navapsvc.exeC:\WINDOWS\system32\VTtrayp.exeC:\WINDOWS\system32\VTTimer.exeC:\Programmer\Fælles filer\Symantec Shared\ccApp.exeC:\Programmer\CyberLink\PowerDVD\PDVDServ.exeC:\Programmer\Fælles filer\Logitech\QCDriver2\LVCOMS.EXEC:\Programmer\Logitech\ImageStudio\LogiTray.exeC:\Programmer\Java\jre1.5.0_02\bin\jusched.exeC:\Programmer\QuickTime\qttask.exeC:\Programmer\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exeC:\WINDOWS\system32\ctfmon.exeC:\Programmer\Google\Google Desktop Search\GoogleDesktop.exeC:\Programmer\Logitech\ImageStudio\LowLight.exeC:\Programmer\Microsoft AntiSpyware\gcasDtServ.exeC:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exeC:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exeC:\WINDOWS\System32\svchost.exeC:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exeC:\Programmer\Google\Google Desktop Search\GoogleDesktopIndex.exeC:\Programmer\Google\Google Desktop Search\GoogleDesktopCrawl.exeC:\Programmer\Internet Explorer\iexplore.exeC:\Programmer\Internet Explorer\iexplore.exeC:\Programmer\MixMeister Pro 6\MMPRO.exeC:\Programmer\Microsoft Office\Office10\EXCEL.EXEC:\WINDOWS\system32\drwtsn32.exeC:\WINDOWS\system32\drwtsn32.exeC:\WINDOWS\explorer.exeC:\Programmer\Messenger\msmsgs.exeC:\Documents and Settings\Sina\Skrivebord\Scan Systems\HiJack This\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charmed-net.de/en/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://64.224.195.203/ubb/ultimatebb.php?ubb=forum&f=2R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = HyperlinksO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dllO2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dllO2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dllO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmer\Fælles filer\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton Internet Security\Norton AntiVirus\NavShExt.dllO3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dllO4 - HKLM\..\Run: [VTTrayp] VTtrayp.exeO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exeO4 - HKLM\..\Run: [LVCOMS] C:\Programmer\Fælles filer\Logitech\QCDriver2\LVCOMS.EXEO4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programmer\Logitech\ImageStudio\ISStart.exeO4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programmer\Logitech\ImageStudio\LogiTray.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_02\bin\jusched.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Programmer\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exeO4 - HKLM\..\Run: [ulead Quick-Drop] "C:\Programmer\Ulead Systems\Ulead DVD MovieFactory 4.0 Disc Creator TBYB\Ulead Quick-Drop 1.0\Quick-Drop.exe" WINDOWCALLO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [Google Desktop Search] "C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" /startupO4 - Global Startup: Adobe Gamma Loader.lnk = ?O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXEO8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: &Translate English Word - res://c:\programmer\google\GoogleToolbar1.dll/cmwordtrans.htmlO8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)O9 - Extra button: AIM (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)O10 - Unknown file in Winsock LSP: c:\programmer\google\google desktop search\googledesktopnetwork1.dllO10 - Unknown file in Winsock LSP: c:\programmer\google\google desktop search\googledesktopnetwork1.dllO10 - Unknown file in Winsock LSP: c:\programmer\google\google desktop search\googledesktopnetwork1.dllO12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1109958844187O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{AE4D2F7E-1224-4CB6-BA62-E809492D459A}: NameServer = 212.*.*.*,212.*.*.* Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted October 13, 2005 Report Share Posted October 13, 2005 Please see here to obtain the latest version (1.99.1) of HijackThis. There are also instructions on how to use it, and where to post it here.Please start a new topic in this forum so the experts can analyze your log. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.