Coreper Posted March 22, 2007 Report Share Posted March 22, 2007 A friend of mine has got a problem, which has been occuring since Monday [morning]:He gets this error message that "program" causes errors. The first error message occures before logging on. He can only click OK on that one. A second error message appears when logging on. That is a normal error message [its in the attachment]. After the first error message, the "program" is replaced by "program1" or "program2", etc. After that he gets messages when a webpage is loaded.Please helpI dont have a clue what to do...I attached screenshots of the error messageHe will try to make a screenshot of the error message he gets before logging on.Here is a list of software he has got installed [made with CCleaner]:1310Tour1310Trb1310_Help1310Ad-Aware SE PersonalAdobe Acrobat 5.0AiOSoftwareAiO_ScanAmbrasoft SchoolpakketANNO 1602 Gold-EditionAthlon 64 Processor DriverBeveiligingsupdate for Windows Media Player 10 (KB911565)Beveiligingsupdate for Windows Media Player 10 (KB917734)Beveiligingsupdate for Windows XP (KB923689)Beveiligingsupdate voor Windows Media Player 6.4 (KB925398)Beveiligingsupdate voor Windows XP (KB890046)Beveiligingsupdate voor Windows XP (KB893066)Beveiligingsupdate voor Windows XP (KB893756)Beveiligingsupdate voor Windows XP (KB896358)Beveiligingsupdate voor Windows XP (KB896422)Beveiligingsupdate voor Windows XP (KB896423)Beveiligingsupdate voor Windows XP (KB896424)Beveiligingsupdate voor Windows XP (KB896428)Beveiligingsupdate voor Windows XP (KB896688)Beveiligingsupdate voor Windows XP (KB899587)Beveiligingsupdate voor Windows XP (KB899588)Beveiligingsupdate voor Windows XP (KB899589)Beveiligingsupdate voor Windows XP (KB899591)Beveiligingsupdate voor Windows XP (KB900725)Beveiligingsupdate voor Windows XP (KB901017)Beveiligingsupdate voor Windows XP (KB901214)Beveiligingsupdate voor Windows XP (KB902400)Beveiligingsupdate voor Windows XP (KB904706)Beveiligingsupdate voor Windows XP (KB905414)Beveiligingsupdate voor Windows XP (KB905749)Beveiligingsupdate voor Windows XP (KB905915)Beveiligingsupdate voor Windows XP (KB908519)Beveiligingsupdate voor Windows XP (KB908531)Beveiligingsupdate voor Windows XP (KB911280)Beveiligingsupdate voor Windows XP (KB911562)Beveiligingsupdate voor Windows XP (KB911567)Beveiligingsupdate voor Windows XP (KB911927)Beveiligingsupdate voor Windows XP (KB912812)Beveiligingsupdate voor Windows XP (KB912919)Beveiligingsupdate voor Windows XP (KB913446)Beveiligingsupdate voor Windows XP (KB913580)Beveiligingsupdate voor Windows XP (KB914388)Beveiligingsupdate voor Windows XP (KB914389)Beveiligingsupdate voor Windows XP (KB916281)Beveiligingsupdate voor Windows XP (KB917159)Beveiligingsupdate voor Windows XP (KB917344)Beveiligingsupdate voor Windows XP (KB917422)Beveiligingsupdate voor Windows XP (KB917953)Beveiligingsupdate voor Windows XP (KB918118)Beveiligingsupdate voor Windows XP (KB918439)Beveiligingsupdate voor Windows XP (KB918899)Beveiligingsupdate voor Windows XP (KB919007)Beveiligingsupdate voor Windows XP (KB920213)Beveiligingsupdate voor Windows XP (KB920214)Beveiligingsupdate voor Windows XP (KB920670)Beveiligingsupdate voor Windows XP (KB920683)Beveiligingsupdate voor Windows XP (KB920685)Beveiligingsupdate voor Windows XP (KB921398)Beveiligingsupdate voor Windows XP (KB921883)Beveiligingsupdate voor Windows XP (KB922616)Beveiligingsupdate voor Windows XP (KB922760)Beveiligingsupdate voor Windows XP (KB922819)Beveiligingsupdate voor Windows XP (KB923191)Beveiligingsupdate voor Windows XP (KB923414)Beveiligingsupdate voor Windows XP (KB923694)Beveiligingsupdate voor Windows XP (KB923980)Beveiligingsupdate voor Windows XP (KB924191)Beveiligingsupdate voor Windows XP (KB924270)Beveiligingsupdate voor Windows XP (KB924496)Beveiligingsupdate voor Windows XP (KB924667)Beveiligingsupdate voor Windows XP (KB925454)Beveiligingsupdate voor Windows XP (KB925486)Beveiligingsupdate voor Windows XP (KB926255)Beveiligingsupdate voor Windows XP (KB926436)Beveiligingsupdate voor Windows XP (KB927779)Beveiligingsupdate voor Windows XP (KB927802)Beveiligingsupdate voor Windows XP (KB928090)Beveiligingsupdate voor Windows XP (KB928255)Beveiligingsupdate voor Windows XP (KB928843)Beveiligingsupdate voor Windows XP (KB929969)BufferChmBurnInTest v5.0 StandardccCommonCCleaner (remove only)CC_ccProxyMSICC_ccStartCopyCreativeProjectsTemplatesCreativeProjectsCueTourCutePDF Writer 2.6DestinationsDiner Dash 2DirectorDocProcDocumentViewerDragon NaturallySpeaking 9FaxGTK+ 2.8.9 runtime environmentHarry Potter TMHijackThis 1.99.1HP Diagnostic AssistantHP Image Zone 4.2HP PSC & OfficeJet 4.2HP Software UpdateHPSystemDiagnosticsiFinger 2.0IKEA Home Planner KitchenIMosaicInstantShareInterActual PlayerJ2SE Runtime Environment 5.0 Update 10J2SE Runtime Environment 5.0 Update 11J2SE Runtime Environment 5.0 Update 3J2SE Runtime Environment 5.0 Update 4J2SE Runtime Environment 5.0 Update 6Java 2 Runtime Environment, SE v1.4.2_01KudosLimeWire 4.9.30LiveReg (Symantec Corporation)LiveUpdate 2.6 (Symantec Corporation)Macromedia Flash Player 8Macromedia Shockwave PlayerMDL Chime/Chime Pro for Internet ExplorerMediaTickets by OINMessenger Plus! 3Microsoft .NET Framework 1.0 Hotfix (KB887998)Microsoft .NET Framework 1.1 Dutch Language PackMicrosoft .NET Framework 1.1Microsoft AutoRoute 2002Microsoft Office 2003 Web ComponentsMicrosoft Office 97, ProfessionalMicrosoft Office FrontPage 2003Microsoft Office XP Web ComponentsMicrosoft Picture It! Photo 7.0Microsoft Windows Journal ViewerMicrosoft Word 2002Microsoft Works 2003 Setup startenMicrosoft Zoo TycoonMSN ToolbarMSRedistMSXML 4.0 SP2 (KB925672)MSXML 4.0 SP2 (KB927978)MSXML 4.0 SP2 Parser and SDKNa klar! Leerlingen-cd-rom 4 vwoNero SuiteNorton AntiSpamNorton AntiSpamNorton AntiVirusNorton Internet Security (Symantec Corporation)Norton Internet SecurityNorton Internet SecurityNorton Internet SecurityNorton Internet SecurityNorton Internet SecurityNorton Internet SecurityNorton Internet SecurityNorton Internet SecurityNorton Internet SecurityNorton WMI UpdateNova 3HAVO VWO naNova Nieuwe Natuur- en Scheikunde 1-2 VMBO HAVO VWONova Nieuwe Scheikunde Leerlingen-cd-rom 3 Havo VwoNVIDIA DriversNVIDIA DVD DecoderNVIDIA Media Center extensions for displayNVIDIA Media Center extensions for DVDOuterinfoOverlandPhotoGalleryPopulous: The BeginningPrintScreenProductContextPTV GatewayQFolderQuickProjectsReadmeRealtek AC'97 AudioRisk IIScanShockwaveSkinsHP1Stronghold CrusaderSymantec Network Drivers UpdateSymantec Script Blocking InstallerThe GIMP 2.2.10Tradewinds LegendsTrayAppTweak UIUnloadUpdate voor Windows XP (KB894391)Update voor Windows XP (KB896727)Update voor Windows XP (KB898461)Update voor Windows XP (KB900485)Update voor Windows XP (KB910437)Update voor Windows XP (KB916595)Update voor Windows XP (KB920872)Update voor Windows XP (KB922582)Update voor Windows XP (KB929338)Update voor Windows XP (KB931836)Virtual VillagersVU Leerling BovenbouwVU Leerling OnderbouwWebFldrs XPWebRegWindows Genuine Advantage Notifications (KB905474)Windows Genuine Advantage v1.3.0254.0Windows Installer 3.1 (KB893803)Windows Live MessengerWindows XP Hotfix - KB873333Windows XP Hotfix - KB873339Windows XP Hotfix - KB885250Windows XP Hotfix - KB885835Windows XP Hotfix - KB885836Windows XP Hotfix - KB886185Windows XP Hotfix - KB887472Windows XP Hotfix - KB887742Windows XP Hotfix - KB888113Windows XP Hotfix - KB888302Windows XP Hotfix - KB890859Windows XP Hotfix - KB891781Windows XP Hotfix - KB893086WinRARWolters-Noordhoff Moderne Wiskunde/2 vwo PLUSWolters-Noordhoff Moderne Wiskunde/WiskDisk VWO A(B)-1Wolters-Noordhoff Pulsar-Chemie/i-Puls vwo deel 1WordWebYahoo! Toolbarhere is a HijackThis log:Logfile of HijackThis v1.99.1Scan saved at 14:26:45, on 22-3-2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\WINDOWS\eHome\ehRecvr.exeC:\WINDOWS\eHome\ehSched.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeC:\WINDOWS\system32\dllhost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\ehome\ehtray.exeC:\WINDOWS\SOUNDMAN.EXEC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\eHome\ehmsas.exeC:\Program Files\Java\jre1.5.0_11\bin\jusched.exeC:\Program Files\Ahead\InCD\InCD.exeC:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exeC:\Program Files\MessengerPlus! 3\MsgPlus.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\Program Files\HP\hpcoretech\hpcmpmgr.exeC:\Program Files\Common Files\InstallShield\UpdateService\issch.exeC:\DOCUME~1\Vlijmen\APPLIC~1\CROSOF~1\rundll.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\Microsoft Office\Office\OSA.EXEC:\Program Files\HP\Digital Imaging\bin\hpqgalry.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\MSN Messenger\usnsvc.exeC:\Program Files\Internet Explorer\iexplore.exeC:\WINDOWS\system32\Restore\rstrui.exeC:\Documents and Settings\Vlijmen\Bureaublad\HijackThis.exeC:\WINDOWS\system32\NOTEPAD.EXER1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.nl/0SENLNL/SAOS01R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://arnultovice.nl/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = KoppelingenR3 - Default URLSearchHook is missingO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: (no name) - {12E1FA17-1086-1C7E-A34B-68E34DEFA8ED} - C:\WINDOWS\system32\uyoybpla.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dllO2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: iFinger plugin / Browser helper object - {A114D52B-870C-4F15-8021-B6D7F91A054B} - C:\PROGRA~1\iFinger\plugins\IE.ifpO2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\nl\msntb.dllO2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\nl\msntb.dllO3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll (file missing)O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exeO4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /ConsumerO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exeO4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exeO4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"O4 - HKLM\..\Run: [sSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -bootO4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startupO4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStartO4 - HKCU\..\Run: [Ooro] "C:\DOCUME~1\Vlijmen\APPLIC~1\CROSOF~1\rundll.exe" -vt ygwO4 - HKCU\..\Run: [Jdhce] C:\Program Files\??crosoft.NET\w?wexec.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: Microsoft Office Snelzoeken.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXEO4 - Global Startup: Office Opstarten.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXEO4 - Global Startup: Snelstart HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: iFinger - {936E5D60-596C-11D3-BB96-00600816DF55} - C:\WINDOWS\system32\SHDOCVW.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dllO12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dllO16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cabO16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cabO16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/NL-NL/a-UNO1/GAME_UNO1.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exeO23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exeO23 - Service: Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe Quote Link to comment Share on other sites More sharing options...
-pops- Posted March 22, 2007 Report Share Posted March 22, 2007 Checking on things that bring up 0xc0000005 errors (on your screen shot) gives:http://support.microsoft.com/kb/q240023/http://support.microsoft.com/kb/818888There are quite a few more which can be Googled using 0xc0000005 as the keyword. Quote Link to comment Share on other sites More sharing options...
Coreper Posted March 22, 2007 Author Report Share Posted March 22, 2007 i already checked thatit didnt seem to give any usefull help [since his memory is fine]it might seem weird, but that error code seems to be useless... Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted March 22, 2007 Report Share Posted March 22, 2007 Couple entries in your HJT log worry me. Best to have it checked over by the folks at http://www.malwareremoval.comThe "program" error may have something to do with some malware only being partially removed. Quote Link to comment Share on other sites More sharing options...
Coreper Posted March 24, 2007 Author Report Share Posted March 24, 2007 well, he send me some more information, here is what i found out:-the error message name keeps changing, because he is asked to change the name of the file... [i attached it]i asked him to navigate to that folder [C:/Program], he couldnt find it, so i told him to typ the adress into his adress bar: it workedin that folder there was only 1 file [program.txt {ProgramTXT.zip}]i opened it so see what it was... and got to see some weird code... [like when you change a name from ***.exe to ***.txt]i read it a bit and noticed this: "This program cannot be run in DOS mode." [a part in the code]so i figured it was a exe file: i immediatly changed its file extension to .exethen i scanned it with FileAlyzer:"This file is PECompact compressed.If you have not done so yet, you should use a tool like UnPECompact (by yoda/2f2) to decompress it."i searched for it on google, softpedia and other recources, but didnt find anything...then i found ExEinfo PE, which was also capable of decompressing...i tried to decompress it: it worked, but only partially, so that was useless...can someone post the HJT log in the HJT part of this forum? >> i havent got the right permissions [!?]here are the other error messages: Quote Link to comment Share on other sites More sharing options...
Coreper Posted March 24, 2007 Author Report Share Posted March 24, 2007 here is the other file: Program.exe [its in ProgramEXE.zip]btw: i thought up something which might kill this error:since the error comes at the startup/logon, it most likely is added to the startup sequenceill have him check it asap [with Autoruns]btw: here is what ExEinfo PE finds:000125D0 4D5A MZ 00009A54 ( ðØ )00013A81 4D5A MZ 00005D06 ( Hë )00015DAB 4D5A MZ 0000EA6C ( `¿ )000162FF 4D5A MZ 00003740 ( 7¸ )00019449 4D5A MZ 00003FD4 ( wµ )00029E56 4D5A MZ 00002247 ( m )--- End of file ------ Not found , sorry ---and i noticed the images from the first post where gone:here they are again: Quote Link to comment Share on other sites More sharing options...
Coreper Posted March 26, 2007 Author Report Share Posted March 26, 2007 anyone? Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted March 26, 2007 Report Share Posted March 26, 2007 I still suggest posting a HijackThis log at http://www.malwareremoval.com/The errors can be delt with, but I am fairly sure there is an infection that needs to be delt with. Quote Link to comment Share on other sites More sharing options...
Coreper Posted March 27, 2007 Author Report Share Posted March 27, 2007 could you post it there, if you are a member already?i dont like to register for the smallest things... Quote Link to comment Share on other sites More sharing options...
Alan2273 Posted March 27, 2007 Report Share Posted March 27, 2007 My brother has posted it for you as he is a member.I will copy & paste the results for you. Quote Link to comment Share on other sites More sharing options...
Coreper Posted March 28, 2007 Author Report Share Posted March 28, 2007 thanks!i really appreciate that! Quote Link to comment Share on other sites More sharing options...
Alan2273 Posted March 29, 2007 Report Share Posted March 29, 2007 STEP 1 Add/Remove Programs Please go to Add/Remove Programs and uninstall/remove all of the following programs that are listed. Oin Yazzle by Oin Purityscan by Oin Snowballwars by Oin All othe programs listed with 'Oin' or 'Outerinfo' in the name. Zolero Tizzletalk MediaTickets Cowabanga STEP 2 Download and run an Uninstaller Please now download and run this Uninstaller http://www.outerinfo.com/OiUninstaller.exe If you need a tutorial on how to do this please see here http://www.outerinfo.com/howto.html STEP 3 Install MVPS HOSTS File Download the HOSTS File from here http://www.mvps.org/winhelp2002/hosts.zip Unzip the hosts.zip to its own folder Open the folder and double click mvps.bat This will rename your present HOSTS file to HOSTS.MVP and will copy it to the correct location.STEP 4 Download and run Deckards System Scanner Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges. Close all applications and windows. Double-click on dss.exe to run it, and follow the prompts. When the scan is complete, two text files will open - main.txt Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post in your next reply.STEP 5 Download AVG Anti Spyware Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder. http://www.ewido.net/en/download/ Install AVG Anti-Spyware by double clicking the installer. Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked. On the main screen under Your Computer's security. Click on Change state next to Resident shield. It should now change to inactive. Click on Change state next to Automatic updates. It should now change to inactive. Next to Last Update, click on Update now. (You will need an active internet connection to perform this) Wait until you see the Update succesfull message. Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows. Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes. If you are having problems with the updater, you can use this link to manually update ewido. AVG Anti-Spyware manual updates. Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update. Do not run a scan with this program until instructed to do so. STEP 6 Download ATF Cleaner Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop. Double-click ATF Cleaner.exe to open it Under Main choose: Windows Temp Current User Temp All Users Temp Cookies Temporary Internet Files Prefetch Java Cache *The other boxes are optional* Then click the Empty Selected button. Firefox: Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt. Opera: Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt. Click Exit on the Main menu to close the program. STEP 7 Run AVG Anti Spyware Scan Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan. Click on Scanner on the toolbar. Click on the Settings tab. Under How to act? Click on Recommended Action and choose Quarantine from the popup menu. Under How to scan? All checkboxes should be ticked. Under Possibly unwanted software: All checkboxes should be ticked. Under Reports: Select Automatically generate report after every scan and uncheck Only if threats were found. Under What to scan? Select Scan every file. Click on the Scan tab. Click on Complete System Scan to start the scan process. Let the program scan the machine. When the scan has finished, follow the instructions below. IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button. Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2) At the bottom of the window click on the Apply all Actions button. (3) When done, click the Save Scan Report button. (4) Click the Save Report as button. Save the report to your Desktop. Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes. Reboot the system. STEP 8 Create an Uninstall List/fresh HijackThis Log Open HijackThis Click Open the Misc Tools section Click Open Uninstall Manager Click Save List... Save the list to your Desktop Under Other Stuff click the Back button Now click the Scan button Click the Save Log button, save it to your Desktop Close HijackThis.STEP 9 Report Back Please now post back to me:- The Deckards System Scanner logs - main.txt and also the extra.txt The AVG Anti Spyware Report The fresh HijackThis Log An Uninstall List using HijackThis.I will review this new information and post any further necessary steps as soon as possible._________________ Quote Link to comment Share on other sites More sharing options...
Coreper Posted March 30, 2007 Author Report Share Posted March 30, 2007 i send it to him a few hours agoill let you know when he is done Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.