chucker Posted June 18, 2007 Report Share Posted June 18, 2007 I am getting the following error message when trying to log onto a user account on Windows XP : C:\WINDOWS\system32\noajfivfbz\services.exe. Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item. I then click OK and get the following message : Could not load or run C:\WINDOWS\system32\noajfivfbz\services.exe specified in the registry. Make sure the file exsists on your computer or remove the ref to it in your registry. I have tried to find the file but it does not exsist in the directory quoted and do not know where , or if , to remove it from the registry. This is coming up on a Limited user account on windows XP only and my admin account is working fine.Any ideas would be greatly appreciated. Quote Link to comment Share on other sites More sharing options...
Boris Posted June 18, 2007 Report Share Posted June 18, 2007 That folder name "noajfivfbz" sounds very dubious to me ???Have you scanned for Viruses/trojans/malware ? Quote Link to comment Share on other sites More sharing options...
chucker Posted June 18, 2007 Author Report Share Posted June 18, 2007 That folder name "noajfivfbz" sounds very dubious to me ???Have you scanned for Viruses/trojans/malware ?Yes have scanned using AVG and found the following :C:\documents and settings\\desktop\wr-1.exec:\windows\retadpu.exec:\windows\retadpu32.exe.tmpit appears that my son opened an exe file sent to him which I suspect has caused this. have removed them all using AVG but still getting the error message on my sons account only. Not sure how to progress . Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 18, 2007 Report Share Posted June 18, 2007 That error message is occuring because the virus has been removed, but the entry to load it has not. You may need to manually remove the errorenous entries.For more info about removing entries from the startup, see here:http://www.windowsstartup.comOf course, you will also want to run another virus scan just to be sure. You can also use an online scanner for a second opinion. http://www.pandasoftware.com/products/ActiveScan.htmhttp://housecall.trendmicro.com/ Quote Link to comment Share on other sites More sharing options...
Alan2273 Posted June 18, 2007 Report Share Posted June 18, 2007 Post a HJT (High jack this) log at this site.http://www.bleepingcomputer.com/tutorials/...al42.html#RDiag Quote Link to comment Share on other sites More sharing options...
chucker Posted June 18, 2007 Author Report Share Posted June 18, 2007 Have captured Log as suggested but cannot start new forum topic as getting following error message :Sorry, you do not have permission to start a topic in this forumHave attached log below :Logfile of HijackThis v1.99.1Scan saved at 20:02:08, on 18/06/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16473)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\WINDOWS\system32\CTSvcCDA.EXEC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\vsnpstd3.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Java\jre1.6.0_01\bin\jusched.exeC:\Program Files\btbb_wcm\McciTrayApp.exeC:\Program Files\QuickTime\qttask.exeC:\PROGRA~1\Yahoo!\browser\ybrwicon.exeC:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exeC:\PROGRA~1\Yahoo!\browser\ycommon.exeC:\WINDOWS\system32\rundll32.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\BT Home Hub\Help\bin\mpbtn.exeC:\WINDOWS\system32\MsPMSPSv.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\BT Home Hub\Help\bin\BTHelp.exeC:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXEC:\Program Files\Microsoft Office\Office10\OUTLOOK.EXEC:\Program Files\Microsoft Office\Office10\WINWORD.EXEC:\Program Files\Common Files\Microsoft Shared\Speech\sapisvr.exeC:\Documents and Settings\Neal Johnson\My Documents\My Received Files\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exeO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dllO2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dllO3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dllO4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exeO4 - HKLM\..\Run: [startupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe"O4 - HKLM\..\Run: [services] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [PPWebCap] "C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [uniblue RegistryBooster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /SO4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dllO9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Oliver\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/..._1/yregucfg.cabO16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CABO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dllO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1161006755078O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cabO16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/bbdesktop/...tivePreQual.cabO16 - DPF: {F2D35D99-63B1-46D3-970C-6E22320D5DCB} (kSoloCntrlIE Class) - http://www.xfactorchallenge.co.uk/getPlugin.doO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: AVG7 alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeO23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXEO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted June 19, 2007 Report Share Posted June 19, 2007 Sorry, we don't have the resources in this forum to analyze HJT logs. You need to post it in a forum that explicitly invites visitors to post HJT logs.Please read this post carefully, go through the Malware Removal and Prevention article, and follow each step. If the problem still exists, run a new HJT and post the result at this forum.You may not get an instant reply, as there are a lot of people seeking help there. But eventually one of the first-responders will get to your HJT log.P.S. You will need to register at castlecops.com in order to post in the HJT forum. Quote Link to comment Share on other sites More sharing options...
chucker Posted June 19, 2007 Author Report Share Posted June 19, 2007 Will do . Just following the advise in castlecops . Watch this space :D Quote Link to comment Share on other sites More sharing options...
Michael___ Posted June 19, 2007 Report Share Posted June 19, 2007 Considering that it is your kid's profile that is corrupt, you could just back up his Documents, Desktop, and Favorites and then delete and recreate his profile. That would probably be quicker than the troubleshooting, especially if he doesnt have a ton of non-default settings in his profile. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.