Jump to content

"program" error


Coreper
 Share

Recommended Posts

A friend of mine has got a problem, which has been occuring since Monday [morning]:

He gets this error message that "program" causes errors. The first error message occures before logging on. He can only click OK on that one. A second error message appears when logging on. That is a normal error message [its in the attachment]. After the first error message, the "program" is replaced by "program1" or "program2", etc. After that he gets messages when a webpage is loaded.

Please help

I dont have a clue what to do...

I attached screenshots of the error message

He will try to make a screenshot of the error message he gets before logging on.

Here is a list of software he has got installed [made with CCleaner]:

1310Tour

1310Trb

1310_Help

1310

Ad-Aware SE Personal

Adobe Acrobat 5.0

AiOSoftware

AiO_Scan

Ambrasoft Schoolpakket

ANNO 1602 Gold-Edition

Athlon 64 Processor Driver

Beveiligingsupdate for Windows Media Player 10 (KB911565)

Beveiligingsupdate for Windows Media Player 10 (KB917734)

Beveiligingsupdate for Windows XP (KB923689)

Beveiligingsupdate voor Windows Media Player 6.4 (KB925398)

Beveiligingsupdate voor Windows XP (KB890046)

Beveiligingsupdate voor Windows XP (KB893066)

Beveiligingsupdate voor Windows XP (KB893756)

Beveiligingsupdate voor Windows XP (KB896358)

Beveiligingsupdate voor Windows XP (KB896422)

Beveiligingsupdate voor Windows XP (KB896423)

Beveiligingsupdate voor Windows XP (KB896424)

Beveiligingsupdate voor Windows XP (KB896428)

Beveiligingsupdate voor Windows XP (KB896688)

Beveiligingsupdate voor Windows XP (KB899587)

Beveiligingsupdate voor Windows XP (KB899588)

Beveiligingsupdate voor Windows XP (KB899589)

Beveiligingsupdate voor Windows XP (KB899591)

Beveiligingsupdate voor Windows XP (KB900725)

Beveiligingsupdate voor Windows XP (KB901017)

Beveiligingsupdate voor Windows XP (KB901214)

Beveiligingsupdate voor Windows XP (KB902400)

Beveiligingsupdate voor Windows XP (KB904706)

Beveiligingsupdate voor Windows XP (KB905414)

Beveiligingsupdate voor Windows XP (KB905749)

Beveiligingsupdate voor Windows XP (KB905915)

Beveiligingsupdate voor Windows XP (KB908519)

Beveiligingsupdate voor Windows XP (KB908531)

Beveiligingsupdate voor Windows XP (KB911280)

Beveiligingsupdate voor Windows XP (KB911562)

Beveiligingsupdate voor Windows XP (KB911567)

Beveiligingsupdate voor Windows XP (KB911927)

Beveiligingsupdate voor Windows XP (KB912812)

Beveiligingsupdate voor Windows XP (KB912919)

Beveiligingsupdate voor Windows XP (KB913446)

Beveiligingsupdate voor Windows XP (KB913580)

Beveiligingsupdate voor Windows XP (KB914388)

Beveiligingsupdate voor Windows XP (KB914389)

Beveiligingsupdate voor Windows XP (KB916281)

Beveiligingsupdate voor Windows XP (KB917159)

Beveiligingsupdate voor Windows XP (KB917344)

Beveiligingsupdate voor Windows XP (KB917422)

Beveiligingsupdate voor Windows XP (KB917953)

Beveiligingsupdate voor Windows XP (KB918118)

Beveiligingsupdate voor Windows XP (KB918439)

Beveiligingsupdate voor Windows XP (KB918899)

Beveiligingsupdate voor Windows XP (KB919007)

Beveiligingsupdate voor Windows XP (KB920213)

Beveiligingsupdate voor Windows XP (KB920214)

Beveiligingsupdate voor Windows XP (KB920670)

Beveiligingsupdate voor Windows XP (KB920683)

Beveiligingsupdate voor Windows XP (KB920685)

Beveiligingsupdate voor Windows XP (KB921398)

Beveiligingsupdate voor Windows XP (KB921883)

Beveiligingsupdate voor Windows XP (KB922616)

Beveiligingsupdate voor Windows XP (KB922760)

Beveiligingsupdate voor Windows XP (KB922819)

Beveiligingsupdate voor Windows XP (KB923191)

Beveiligingsupdate voor Windows XP (KB923414)

Beveiligingsupdate voor Windows XP (KB923694)

Beveiligingsupdate voor Windows XP (KB923980)

Beveiligingsupdate voor Windows XP (KB924191)

Beveiligingsupdate voor Windows XP (KB924270)

Beveiligingsupdate voor Windows XP (KB924496)

Beveiligingsupdate voor Windows XP (KB924667)

Beveiligingsupdate voor Windows XP (KB925454)

Beveiligingsupdate voor Windows XP (KB925486)

Beveiligingsupdate voor Windows XP (KB926255)

Beveiligingsupdate voor Windows XP (KB926436)

Beveiligingsupdate voor Windows XP (KB927779)

Beveiligingsupdate voor Windows XP (KB927802)

Beveiligingsupdate voor Windows XP (KB928090)

Beveiligingsupdate voor Windows XP (KB928255)

Beveiligingsupdate voor Windows XP (KB928843)

Beveiligingsupdate voor Windows XP (KB929969)

BufferChm

BurnInTest v5.0 Standard

ccCommon

CCleaner (remove only)

CC_ccProxyMSI

CC_ccStart

Copy

CreativeProjectsTemplates

CreativeProjects

CueTour

CutePDF Writer 2.6

Destinations

Diner Dash 2

Director

DocProc

DocumentViewer

Dragon NaturallySpeaking 9

Fax

GTK+ 2.8.9 runtime environment

Harry Potter TM

HijackThis 1.99.1

HP Diagnostic Assistant

HP Image Zone 4.2

HP PSC & OfficeJet 4.2

HP Software Update

HPSystemDiagnostics

iFinger 2.0

IKEA Home Planner Kitchen

IMosaic

InstantShare

InterActual Player

J2SE Runtime Environment 5.0 Update 10

J2SE Runtime Environment 5.0 Update 11

J2SE Runtime Environment 5.0 Update 3

J2SE Runtime Environment 5.0 Update 4

J2SE Runtime Environment 5.0 Update 6

Java 2 Runtime Environment, SE v1.4.2_01

Kudos

LimeWire 4.9.30

LiveReg (Symantec Corporation)

LiveUpdate 2.6 (Symantec Corporation)

Macromedia Flash Player 8

Macromedia Shockwave Player

MDL Chime/Chime Pro for Internet Explorer

MediaTickets by OIN

Messenger Plus! 3

Microsoft .NET Framework 1.0 Hotfix (KB887998)

Microsoft .NET Framework 1.1 Dutch Language Pack

Microsoft .NET Framework 1.1

Microsoft AutoRoute 2002

Microsoft Office 2003 Web Components

Microsoft Office 97, Professional

Microsoft Office FrontPage 2003

Microsoft Office XP Web Components

Microsoft Picture It! Photo 7.0

Microsoft Windows Journal Viewer

Microsoft Word 2002

Microsoft Works 2003 Setup starten

Microsoft Zoo Tycoon

MSN Toolbar

MSRedist

MSXML 4.0 SP2 (KB925672)

MSXML 4.0 SP2 (KB927978)

MSXML 4.0 SP2 Parser and SDK

Na klar! Leerlingen-cd-rom 4 vwo

Nero Suite

Norton AntiSpam

Norton AntiSpam

Norton AntiVirus

Norton Internet Security (Symantec Corporation)

Norton Internet Security

Norton Internet Security

Norton Internet Security

Norton Internet Security

Norton Internet Security

Norton Internet Security

Norton Internet Security

Norton Internet Security

Norton Internet Security

Norton WMI Update

Nova 3HAVO VWO na

Nova Nieuwe Natuur- en Scheikunde 1-2 VMBO HAVO VWO

Nova Nieuwe Scheikunde Leerlingen-cd-rom 3 Havo Vwo

NVIDIA Drivers

NVIDIA DVD Decoder

NVIDIA Media Center extensions for display

NVIDIA Media Center extensions for DVD

Outerinfo

Overland

PhotoGallery

Populous: The Beginning

PrintScreen

ProductContext

PTV Gateway

QFolder

QuickProjects

Readme

Realtek AC'97 Audio

Risk II

Scan

Shockwave

SkinsHP1

Stronghold Crusader

Symantec Network Drivers Update

Symantec Script Blocking Installer

The GIMP 2.2.10

Tradewinds Legends

TrayApp

Tweak UI

Unload

Update voor Windows XP (KB894391)

Update voor Windows XP (KB896727)

Update voor Windows XP (KB898461)

Update voor Windows XP (KB900485)

Update voor Windows XP (KB910437)

Update voor Windows XP (KB916595)

Update voor Windows XP (KB920872)

Update voor Windows XP (KB922582)

Update voor Windows XP (KB929338)

Update voor Windows XP (KB931836)

Virtual Villagers

VU Leerling Bovenbouw

VU Leerling Onderbouw

WebFldrs XP

WebReg

Windows Genuine Advantage Notifications (KB905474)

Windows Genuine Advantage v1.3.0254.0

Windows Installer 3.1 (KB893803)

Windows Live Messenger

Windows XP Hotfix - KB873333

Windows XP Hotfix - KB873339

Windows XP Hotfix - KB885250

Windows XP Hotfix - KB885835

Windows XP Hotfix - KB885836

Windows XP Hotfix - KB886185

Windows XP Hotfix - KB887472

Windows XP Hotfix - KB887742

Windows XP Hotfix - KB888113

Windows XP Hotfix - KB888302

Windows XP Hotfix - KB890859

Windows XP Hotfix - KB891781

Windows XP Hotfix - KB893086

WinRAR

Wolters-Noordhoff Moderne Wiskunde/2 vwo PLUS

Wolters-Noordhoff Moderne Wiskunde/WiskDisk VWO A(B)-1

Wolters-Noordhoff Pulsar-Chemie/i-Puls vwo deel 1

WordWeb

Yahoo! Toolbar

here is a HijackThis log:

Logfile of HijackThis v1.99.1

Scan saved at 14:26:45, on 22-3-2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Ahead\InCD\InCDsrv.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe

C:\Program Files\Ahead\InCD\InCD.exe

C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

C:\Program Files\MessengerPlus! 3\MsgPlus.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\DOCUME~1\Vlijmen\APPLIC~1\CROSOF~1\rundll.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Microsoft Office\Office\OSA.EXE

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\MSN Messenger\usnsvc.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\Restore\rstrui.exe

C:\Documents and Settings\Vlijmen\Bureaublad\HijackThis.exe

C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.nl/0SENLNL/SAOS01

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://arnultovice.nl/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

R3 - Default URLSearchHook is missing

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {12E1FA17-1086-1C7E-A34B-68E34DEFA8ED} - C:\WINDOWS\system32\uyoybpla.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll

O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: iFinger plugin / Browser helper object - {A114D52B-870C-4F15-8021-B6D7F91A054B} - C:\PROGRA~1\iFinger\plugins\IE.ifp

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\nl\msntb.dll

O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\nl\msntb.dll

O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll (file missing)

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [sSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [Ooro] "C:\DOCUME~1\Vlijmen\APPLIC~1\CROSOF~1\rundll.exe" -vt ygw

O4 - HKCU\..\Run: [Jdhce] C:\Program Files\??crosoft.NET\w?wexec.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office Snelzoeken.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE

O4 - Global Startup: Office Opstarten.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

O4 - Global Startup: Snelstart HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: iFinger - {936E5D60-596C-11D3-BB96-00600816DF55} - C:\WINDOWS\system32\SHDOCVW.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/NL-NL/a-UNO1/GAME_UNO1.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe

O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe

O23 - Service: Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Link to comment
Share on other sites

well, he send me some more information, here is what i found out:

-the error message name keeps changing, because he is asked to change the name of the file... [i attached it]

i asked him to navigate to that folder [C:/Program], he couldnt find it, so i told him to typ the adress into his adress bar: it worked

in that folder there was only 1 file [program.txt {ProgramTXT.zip}]

i opened it so see what it was... and got to see some weird code... [like when you change a name from ***.exe to ***.txt]

i read it a bit and noticed this: "This program cannot be run in DOS mode." [a part in the code]

so i figured it was a exe file: i immediatly changed its file extension to .exe

then i scanned it with FileAlyzer:

"This file is PECompact compressed.

If you have not done so yet, you should use a tool like UnPECompact (by yoda/2f2) to decompress it."

i searched for it on google, softpedia and other recources, but didnt find anything...

then i found ExEinfo PE, which was also capable of decompressing...

i tried to decompress it: it worked, but only partially, so that was useless...

can someone post the HJT log in the HJT part of this forum? >> i havent got the right permissions [!?]

here are the other error messages:

program2qm1.jpgprogram3zm5.jpg

Link to comment
Share on other sites

here is the other file: Program.exe [its in ProgramEXE.zip]

btw: i thought up something which might kill this error:

since the error comes at the startup/logon, it most likely is added to the startup sequence

ill have him check it asap [with Autoruns]

btw: here is what ExEinfo PE finds:

000125D0 4D5A MZ 00009A54 ( ðØ )
00013A81 4D5A MZ 00005D06 ( Hë )
00015DAB 4D5A MZ 0000EA6C ( `¿ )
000162FF 4D5A MZ 00003740 ( 7¸ )
00019449 4D5A MZ 00003FD4 ( wµ )
00029E56 4D5A MZ 00002247 ( m )

--- End of file ---

--- Not found , sorry ---

and i noticed the images from the first post where gone:

here they are again:

program1io5.jpgprogramrapportak2.jpg

Link to comment
Share on other sites

STEP 1

Add/Remove Programs

Please go to Add/Remove Programs and uninstall/remove all of the following programs that are listed.

Oin

Yazzle by Oin

Purityscan by Oin

Snowballwars by Oin

All othe programs listed with 'Oin' or 'Outerinfo' in the name.

Zolero

Tizzletalk

MediaTickets

Cowabanga

STEP 2

Download and run an Uninstaller

Please now download and run this Uninstaller

http://www.outerinfo.com/OiUninstaller.exe

If you need a tutorial on how to do this please see here

http://www.outerinfo.com/howto.html

STEP 3

Install MVPS HOSTS File

Download the HOSTS File from here http://www.mvps.org/winhelp2002/hosts.zip

Unzip the hosts.zip to its own folder

Open the folder and double click mvps.bat

This will rename your present HOSTS file to HOSTS.MVP and will copy it to the correct location.

STEP 4

Download and run Deckards System Scanner

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.

Close all applications and windows.

Double-click on dss.exe to run it, and follow the prompts.

When the scan is complete, two text files will open - main.txt

Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post in your next reply.

STEP 5

Download AVG Anti Spyware

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.

http://www.ewido.net/en/download/

Install AVG Anti-Spyware by double clicking the installer.

Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.

On the main screen under Your Computer's security.

Click on Change state next to Resident shield. It should now change to inactive.

Click on Change state next to Automatic updates. It should now change to inactive.

Next to Last Update, click on Update now. (You will need an active internet connection to perform this)

Wait until you see the Update succesfull message.

Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.

Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.

If you are having problems with the updater, you can use this link to manually update ewido.

AVG Anti-Spyware manual updates.

Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Do not run a scan with this program until instructed to do so.

STEP 6

Download ATF Cleaner

Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:

Windows Temp

Current User Temp

All Users Temp

Cookies

Temporary Internet Files

Prefetch

Java Cache

*The other boxes are optional*

Then click the Empty Selected button.

Firefox:

Click Firefox at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:

Click Opera at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.

STEP 7

Run AVG Anti Spyware Scan

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.

Click on Scanner on the toolbar.

Click on the Settings tab.

Under How to act?

Click on Recommended Action and choose Quarantine from the popup menu.

Under How to scan?

All checkboxes should be ticked.

Under Possibly unwanted software:

All checkboxes should be ticked.

Under Reports:

Select Automatically generate report after every scan and uncheck Only if threats were found.

Under What to scan?

Select Scan every file.

Click on the Scan tab.

Click on Complete System Scan to start the scan process.

Let the program scan the machine.

When the scan has finished, follow the instructions below.

IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.

Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)

At the bottom of the window click on the Apply all Actions button. (3)

When done, click the Save Scan Report button. (4)

Click the Save Report as button.

Save the report to your Desktop.

Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.

Reboot the system.

STEP 8

Create an Uninstall List/fresh HijackThis Log

Open HijackThis

Click Open the Misc Tools section

Click Open Uninstall Manager

Click Save List...

Save the list to your Desktop

Under Other Stuff click the Back button

Now click the Scan button

Click the Save Log button, save it to your Desktop

Close HijackThis.

STEP 9

Report Back

Please now post back to me:-

The Deckards System Scanner logs - main.txt and also the extra.txt

The AVG Anti Spyware Report

The fresh HijackThis Log

An Uninstall List using HijackThis.

I will review this new information and post any further necessary steps as soon as possible.

_________________

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy