MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: sound not working / Ipfu32 / about:blank
April 02, 2020, 03:24:26 AM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
April 02, 2020, 03:24:26 AM

Login with username, password and session length
 Featured Sites:
News
New  Got pics of your modded PC or want to show off your cool desktop, visit our new Show & Tell forum!
  0 Members and 1 Guest are viewing this topic.
Pages: [1] 2 3 Go Down Print
Author Topic: sound not working / Ipfu32 / about:blank  (Read 3714 times)
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« on: May 26, 2005, 08:18:36 AM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version:win98
Problem Application Name & Version:
Problem Hardware Make & Model: ESS Allegro-1 PCI AudioDrive
Error Messages: "Status: Driver is enabled but inactive due to an unknown problem."



compaq presario 533mhz  
not sure if this is needed:   Authentic AMD / AMD-K6 3D Processor / 184MB RAM

hey im hoping someone can help me out. My computers constantly having problems but just yesterday all these problems came at once.  My monitors display settings were changed (everything to low quality i believe), no sound will work, had a lot of trouble getting into it...

i fixed the display problem (it happened a few weeks ago and i found a fix on this site or another like it, by deleting the drivers..resetting and windows reinstalled them..)

for the explorer problems i reset it to the last version, it went back to an old version of IE, then i reinstalled the new one.. that seemed to fix some problems

i reinstalled the sound drivers through quickrestore multiple times but it didnt fix the problem



Logfile of HijackThis v1.99.1
Scan saved at 1:09:38 AM, on 26/05/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\ptsnoop.exe
C:\WINDOWS\IPFU32.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\SYSTEM\APPUY32.EXE
C:\WINDOWS\SYSTEM\APPUY32.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SDKYT.EXE
C:\WINDOWS\SYSTEM\ADDXZ32.EXE
C:\WINDOWS\IEZH32.EXE
C:\WINDOWS\MSYV32.EXE
C:\WINDOWS\SYSTEM\SDKMR32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\IPEO32.EXE
C:\WINDOWS\PROFILES\USER\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {1827F199-DD3F-2E2B-50AB-908D49CDED6E} - C:\WINDOWS\SYSTEM\NTKJ.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [IPFU32.EXE] C:\WINDOWS\IPFU32.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [APPUY32.EXE] C:\WINDOWS\SYSTEM\APPUY32.EXE /s
O4 - HKLM\..\RunServices: [SDKYT.EXE] C:\WINDOWS\SDKYT.EXE /s
O4 - HKLM\..\RunServices: [ADDXZ32.EXE] C:\WINDOWS\SYSTEM\ADDXZ32.EXE /s
O4 - HKLM\..\RunServices: [IEZH32.EXE] C:\WINDOWS\IEZH32.EXE /s
O4 - HKLM\..\RunServices: [MSYV32.EXE] C:\WINDOWS\MSYV32.EXE /s
O4 - HKLM\..\RunServices: [SDKMR32.EXE] C:\WINDOWS\SYSTEM\SDKMR32.EXE /s
O4 - HKLM\..\RunServices: [IPEO32.EXE] C:\WINDOWS\IPEO32.EXE /s
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=1c00&lc=1009 (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=1c00&lc=1009 (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=1c00&lc=1009 (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.iframedollars.biz
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted IP range: 213.159.117.202
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_01) -





« Last Edit: May 26, 2005, 09:00:10 AM by Ageless » Logged

this picture-box thinks its smarter then me
Ageless
Dark Overlord of the Universe
Global Moderator
Hero Member
*****

Karma: +4/-1
Offline Offline

Gender: Male
Posts: 1779



Bookmark and Share

View Profile
« Reply #1 on: May 26, 2005, 08:59:53 AM »

Okay, I am moving this one to the Security & Viruses forum first, to have your system cleaned. Cactus or Pancake, when you're done cleaning the system, could you move this thread back to the Hardware devices Problems forum? Thank you. Smiley
Logged

Jord.
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #2 on: May 26, 2005, 09:32:48 AM »

sorry if i posted this in the wrong section
Logged

this picture-box thinks its smarter then me
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #3 on: May 26, 2005, 09:38:47 AM »

should i not be sending people files if my comp is messed up, specifically .mp3/.rar
Logged

this picture-box thinks its smarter then me
Cactus
Security & Virus Specialist
Global Moderator
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 4327


Bookmark and Share

View Profile
« Reply #4 on: May 27, 2005, 12:39:47 AM »

Hey wrongone .. Smiley

Set Windows to show Hidden files and folders
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.



**(Always create a Folder for HiJackThis anywhere but your Temp/Temporary Internet Folders. This is where it will save the backup files needed if there's a problem.)**

 Goto START>RUN
Type or Copy/Paste the line below into the Run Box:

regsvr32 /u NTKJ.DLL



Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)


IPFU32.EXE
APPUY32.EXE
SDKYT.EXE
ADDXZ32.EXE
IEZH32.EXE
MSYV32.EXE
SDKMR32.EXE
IPEO32.EXE


Close all other open Windows and have HiJackThis Fix:



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lnwwi.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {1827F199-DD3F-2E2B-50AB-908D49CDED6E} - C:\WINDOWS\SYSTEM\NTKJ.DLL

O4 - HKLM\..\Run: [IPFU32.EXE] C:\WINDOWS\IPFU32.EXE

O4 - HKLM\..\RunServices: [APPUY32.EXE] C:\WINDOWS\SYSTEM\APPUY32.EXE /s
O4 - HKLM\..\RunServices: [SDKYT.EXE] C:\WINDOWS\SDKYT.EXE /s
O4 - HKLM\..\RunServices: [ADDXZ32.EXE] C:\WINDOWS\SYSTEM\ADDXZ32.EXE /s
O4 - HKLM\..\RunServices: [IEZH32.EXE] C:\WINDOWS\IEZH32.EXE /s
O4 - HKLM\..\RunServices: [MSYV32.EXE] C:\WINDOWS\MSYV32.EXE /s
O4 - HKLM\..\RunServices: [SDKMR32.EXE] C:\WINDOWS\SYSTEM\SDKMR32.EXE /s
O4 - HKLM\..\RunServices: [IPEO32.EXE] C:\WINDOWS\IPEO32.EXE /s

O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=1c00&lc=1009 (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=1c00&lc=1009 (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=1c00&lc=1009 (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.iframedollars.biz
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted IP range: 213.159.117.202

O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_01) -



Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab)  

C:\WINDOWS\SYSTEM\NTKJ.DLL
C:\WINDOWS\IPFU32.EXE
C:\WINDOWS\SYSTEM\APPUY32.EXE
C:\WINDOWS\SDKYT.EXE
C:\WINDOWS\SYSTEM\ADDXZ32.EXE
C:\WINDOWS\IEZH32.EXE
C:\WINDOWS\MSYV32.EXE
C:\WINDOWS\SYSTEM\SDKMR32.EXE
C:\WINDOWS\IPEO32.EXE



Now, empty all your TEMP Folders / Temporary Internet Files Folder and then empty your "Recycle Bin"


Download CCLEANER
http://www.ccleaner.com/

Under Windows tab check Internet Explorer, Windows Explorer, and System.
Then click Run Cleaner.


Reboot.



Before opening your browser goto START>CONTROL PANEL>INTERNET OPTIONS and make sure your Homepage is correct,if not ,type the URL you would like in the HomePage box.



Now re-run HJT and post a new logfile back here.


Cactus  
Logged

**PLEASE**.....do not post your hijack log in someone else's thread. Start a separate thread HERE! Thank you.

cactus@mytechsupport.ca

My System Specs

Avg Antivirus::Ad-Aware::Spybot::Windows Update::Recuva
Malwarebytes::SUPERAntiSpywareFREE
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #5 on: May 27, 2005, 02:52:10 AM »

hi, ok i started following your directions but when i started up hijackthis to fix the things you listed the name of the .dll has changed, i probably should just follow the directions you posted with the new dll but i dont want to take any chances

im also confused by this "**(Always create a Folder for HiJackThis anywhere but your Temp/Temporary Internet Folders. This is where it will save the backup files needed if there's a problem.)** "

is there a function in HJT to do this.. right now i just made a folder on the desktop titled "HiJackThis"

heres a new HJT LOG, i also have a lot of new running processes

Logfile of HijackThis v1.99.1
Scan saved at 7:56:57 PM, on 26/05/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\MSYV32.EXE
C:\WINDOWS\MSKB.EXE
C:\WINDOWS\SYSNE32.EXE
C:\WINDOWS\D3QE.EXE
C:\WINDOWS\NETHO32.EXE
C:\WINDOWS\SYSFQ32.EXE
C:\WINDOWS\SYSTEM\SYSYE.EXE
C:\WINDOWS\MFCQU32.EXE
C:\WINDOWS\CREI.EXE
C:\WINDOWS\SYSTEM\SYSCQ32.EXE
C:\WINDOWS\SYSTEM\APPBA.EXE
C:\WINDOWS\WINBI32.EXE
C:\WINDOWS\SYSTEM\IELO32.EXE
C:\WINDOWS\SYSTEM\D3EJ.EXE
C:\WINDOWS\SYSTEM\APPQI.EXE
C:\WINDOWS\NETCP.EXE
C:\WINDOWS\SYSTEM\IEZA.EXE
C:\WINDOWS\SYSTEM\MSOL.EXE
C:\WINDOWS\APIAW.EXE
C:\WINDOWS\SYSTEM\APISE32.EXE
C:\WINDOWS\SYSTEM\MFCZT32.EXE
C:\WINDOWS\NTRK32.EXE
C:\WINDOWS\SYSTEM\MSCY.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\ptsnoop.exe
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\MSKB.EXE
C:\WINDOWS\SYSTEM\ADDXZ32.EXE
C:\WINDOWS\IEZH32.EXE
C:\WINDOWS\SYSTEM\APPBA.EXE
C:\WINDOWS\SYSTEM\ATLRI32.EXE
C:\WINDOWS\MSKT.EXE
C:\WINDOWS\SYSTEM\ADDXZ32.EXE
C:\WINDOWS\SYSTEM\CROD32.EXE
C:\WINDOWS\SYSTEM\ADDXZ32.EXE
C:\WINDOWS\SYSTEM\MSCY.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\PROFILES\USER\DESKTOP\HIJACKTHIS.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\IPFU32.EXE
C:\WINDOWS\IEZH32.EXE
C:\WINDOWS\SYSTEM\IELO32.EXE
C:\WINDOWS\IEZH32.EXE
C:\WINDOWS\SYSTEM\CRFX32.EXE
C:\WINDOWS\SYSTEM\ADDXZ32.EXE
C:\WINDOWS\SYSTEM\MSCY.EXE
C:\WINDOWS\SYSTEM\APISE32.EXE
C:\WINDOWS\SYSTEM\MSOL.EXE
C:\WINDOWS\SYSTEM\APIWE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\usqep.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\usqep.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\usqep.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\usqep.dll/sp.html#22321
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\usqep.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\usqep.dll/sp.html#22321
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\usqep.dll/sp.html#22321
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {7C21C212-81D1-B7EA-61A6-AB846BFBEAA2} - C:\WINDOWS\SYSTEM\NTEN.DLL
O2 - BHO: Class - {B49E6A75-1B03-C95C-E3B9-0C5243421C8C} - C:\WINDOWS\SYSTEM\WINHB32.DLL
O2 - BHO: Class - {12869A5D-0FF9-B9AA-8BD8-9337FB04C5C6} - C:\WINDOWS\CRSN32.DLL
O2 - BHO: Class - {054FA522-3449-3E70-B480-5C8348478A0A} - C:\WINDOWS\JAVALT32.DLL
O2 - BHO: Class - {9E0AF542-3DF8-3ADE-8A55-5B85421AE8A8} - C:\WINDOWS\SYSTEM\ADDQG32.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [IPFU32.EXE] C:\WINDOWS\IPFU32.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [APPUY32.EXE] C:\WINDOWS\SYSTEM\APPUY32.EXE /s
O4 - HKLM\..\RunServices: [SDKYT.EXE] C:\WINDOWS\SDKYT.EXE /s
O4 - HKLM\..\RunServices: [ADDXZ32.EXE] C:\WINDOWS\SYSTEM\ADDXZ32.EXE /s
O4 - HKLM\..\RunServices: [IEZH32.EXE] C:\WINDOWS\IEZH32.EXE /s
O4 - HKLM\..\RunServices: [MSYV32.EXE] C:\WINDOWS\MSYV32.EXE /s
O4 - HKLM\..\RunServices: [SDKMR32.EXE] C:\WINDOWS\SYSTEM\SDKMR32.EXE /s
O4 - HKLM\..\RunServices: [IPEO32.EXE] C:\WINDOWS\IPEO32.EXE /s
O4 - HKLM\..\RunServices: [MSKB.EXE] C:\WINDOWS\MSKB.EXE /s
O4 - HKLM\..\RunServices: [SYSNE32.EXE] C:\WINDOWS\SYSNE32.EXE /s
O4 - HKLM\..\RunServices: [D3QE.EXE] C:\WINDOWS\D3QE.EXE /s
O4 - HKLM\..\RunServices: [NETHO32.EXE] C:\WINDOWS\NETHO32.EXE /s
O4 - HKLM\..\RunServices: [SYSFQ32.EXE] C:\WINDOWS\SYSFQ32.EXE /s
O4 - HKLM\..\RunServices: [SYSYE.EXE] C:\WINDOWS\SYSTEM\SYSYE.EXE /s
O4 - HKLM\..\RunServices: [MFCQU32.EXE] C:\WINDOWS\MFCQU32.EXE /s
O4 - HKLM\..\RunServices: [CREI.EXE] C:\WINDOWS\CREI.EXE /s
O4 - HKLM\..\RunServices: [SYSCQ32.EXE] C:\WINDOWS\SYSTEM\SYSCQ32.EXE /s
O4 - HKLM\..\RunServices: [APPBA.EXE] C:\WINDOWS\SYSTEM\APPBA.EXE /s
O4 - HKLM\..\RunServices: [WINBI32.EXE] C:\WINDOWS\WINBI32.EXE /s
O4 - HKLM\..\RunServices: [IELO32.EXE] C:\WINDOWS\SYSTEM\IELO32.EXE /s
O4 - HKLM\..\RunServices: [D3EJ.EXE] C:\WINDOWS\SYSTEM\D3EJ.EXE /s
O4 - HKLM\..\RunServices: [APPQI.EXE] C:\WINDOWS\SYSTEM\APPQI.EXE /s
O4 - HKLM\..\RunServices: [NETCP.EXE] C:\WINDOWS\NETCP.EXE /s
O4 - HKLM\..\RunServices: [IEZA.EXE] C:\WINDOWS\SYSTEM\IEZA.EXE /s
O4 - HKLM\..\RunServices: [MSOL.EXE] C:\WINDOWS\SYSTEM\MSOL.EXE /s
O4 - HKLM\..\RunServices: [APIAW.EXE] C:\WINDOWS\APIAW.EXE /s
O4 - HKLM\..\RunServices: [APISE32.EXE] C:\WINDOWS\SYSTEM\APISE32.EXE /s
O4 - HKLM\..\RunServices: [MFCZT32.EXE] C:\WINDOWS\SYSTEM\MFCZT32.EXE /s
O4 - HKLM\..\RunServices: [NTRK32.EXE] C:\WINDOWS\NTRK32.EXE /s
O4 - HKLM\..\RunServices: [MSCY.EXE] C:\WINDOWS\SYSTEM\MSCY.EXE /s
O4 - HKLM\..\RunServices: [ATLRI32.EXE] C:\WINDOWS\SYSTEM\ATLRI32.EXE /s
O4 - HKLM\..\RunServices: [MSKT.EXE] C:\WINDOWS\MSKT.EXE /s
O4 - HKLM\..\RunServices: [CROD32.EXE] C:\WINDOWS\SYSTEM\CROD32.EXE /s
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=1c00&lc=1009 (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=1c00&lc=1009 (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=1c00&lc=1009 (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=1c00&lc=1009 (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.iframedollars.biz
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted IP range: 213.159.117.202
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_01) -



Logged

this picture-box thinks its smarter then me
Cactus
Security & Virus Specialist
Global Moderator
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 4327


Bookmark and Share

View Profile
« Reply #6 on: May 27, 2005, 03:53:44 AM »

Run the fix again .. Lips Sealed

Just change the .DLL file name to usqep.dll

Delete ALL the new processes as well as the files above)(find the .exe files) ....

O4 - HKLM\..\RunServices: [APPUY32.EXE] C:\WINDOWS\SYSTEM\APPUY32.EXE /s
O4 - HKLM\..\RunServices: [SDKYT.EXE] C:\WINDOWS\SDKYT.EXE /s
O4 - HKLM\..\RunServices: [ADDXZ32.EXE] C:\WINDOWS\SYSTEM\ADDXZ32.EXE /s
O4 - HKLM\..\RunServices: [IEZH32.EXE] C:\WINDOWS\IEZH32.EXE /s
O4 - HKLM\..\RunServices: [MSYV32.EXE] C:\WINDOWS\MSYV32.EXE /s
O4 - HKLM\..\RunServices: [SDKMR32.EXE] C:\WINDOWS\SYSTEM\SDKMR32.EXE /s
O4 - HKLM\..\RunServices: [IPEO32.EXE] C:\WINDOWS\IPEO32.EXE /s
O4 - HKLM\..\RunServices: [MSKB.EXE] C:\WINDOWS\MSKB.EXE /s
O4 - HKLM\..\RunServices: [SYSNE32.EXE] C:\WINDOWS\SYSNE32.EXE /s
O4 - HKLM\..\RunServices: [D3QE.EXE] C:\WINDOWS\D3QE.EXE /s
O4 - HKLM\..\RunServices: [NETHO32.EXE] C:\WINDOWS\NETHO32.EXE /s
O4 - HKLM\..\RunServices: [SYSFQ32.EXE] C:\WINDOWS\SYSFQ32.EXE /s
O4 - HKLM\..\RunServices: [SYSYE.EXE] C:\WINDOWS\SYSTEM\SYSYE.EXE /s
O4 - HKLM\..\RunServices: [MFCQU32.EXE] C:\WINDOWS\MFCQU32.EXE /s
O4 - HKLM\..\RunServices: [CREI.EXE] C:\WINDOWS\CREI.EXE /s
O4 - HKLM\..\RunServices: [SYSCQ32.EXE] C:\WINDOWS\SYSTEM\SYSCQ32.EXE /s
O4 - HKLM\..\RunServices: [APPBA.EXE] C:\WINDOWS\SYSTEM\APPBA.EXE /s
O4 - HKLM\..\RunServices: [WINBI32.EXE] C:\WINDOWS\WINBI32.EXE /s
O4 - HKLM\..\RunServices: [IELO32.EXE] C:\WINDOWS\SYSTEM\IELO32.EXE /s
O4 - HKLM\..\RunServices: [D3EJ.EXE] C:\WINDOWS\SYSTEM\D3EJ.EXE /s
O4 - HKLM\..\RunServices: [APPQI.EXE] C:\WINDOWS\SYSTEM\APPQI.EXE /s
O4 - HKLM\..\RunServices: [NETCP.EXE] C:\WINDOWS\NETCP.EXE /s
O4 - HKLM\..\RunServices: [IEZA.EXE] C:\WINDOWS\SYSTEM\IEZA.EXE /s
O4 - HKLM\..\RunServices: [MSOL.EXE] C:\WINDOWS\SYSTEM\MSOL.EXE /s
O4 - HKLM\..\RunServices: [APIAW.EXE] C:\WINDOWS\APIAW.EXE /s
O4 - HKLM\..\RunServices: [APISE32.EXE] C:\WINDOWS\SYSTEM\APISE32.EXE /s
O4 - HKLM\..\RunServices: [MFCZT32.EXE] C:\WINDOWS\SYSTEM\MFCZT32.EXE /s
O4 - HKLM\..\RunServices: [NTRK32.EXE] C:\WINDOWS\NTRK32.EXE /s
O4 - HKLM\..\RunServices: [MSCY.EXE] C:\WINDOWS\SYSTEM\MSCY.EXE /s
O4 - HKLM\..\RunServices: [ATLRI32.EXE] C:\WINDOWS\SYSTEM\ATLRI32.EXE /s
O4 - HKLM\..\RunServices: [MSKT.EXE] C:\WINDOWS\MSKT.EXE /s
O4 - HKLM\..\RunServices: [CROD32.EXE] C:\WINDOWS\SYSTEM\CROD32.EXE /s

Don't worry about what's not there...just what is .. Smiley
Then run HJT and have it FIX everything in the first fix and the new entries...

Post back with a new HJT logfile AFTER you've followed my instructions.

Cactus  
Logged

**PLEASE**.....do not post your hijack log in someone else's thread. Start a separate thread HERE! Thank you.

cactus@mytechsupport.ca

My System Specs

Avg Antivirus::Ad-Aware::Spybot::Windows Update::Recuva
Malwarebytes::SUPERAntiSpywareFREE
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #7 on: May 28, 2005, 10:57:45 AM »

Hi, ok ive followed your instructions.. some of this is confusing to me.
i have been having a very hard time getting into the comp in anything but safe mode, CTRL+ALT+DEL was showing over thirty items since that last HJT log i posted, i ended up removing them in the msconfig when i was trying to get into the computer.

Also when i was trying to open MY COMPUTER or an IE window it would just sit there and i noticed on the CTRL+ALT+DEL that whenver i tried to open these a program called 'Apiwe' would appear...
i set my IE back to the previous version and that is the only way i could get here..
heres a new HJT log (i havent restarted the comp since i removed that last set of files (your last post)) incase that matters. i was thinking i should post this while its working.



Logfile of HijackThis v1.99.1
Scan saved at 3:56:39 AM, on 28/05/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\NTAD.EXE
C:\WINDOWS\SYSTEM\IEZO32.EXE
C:\WINDOWS\APIHC.EXE
C:\WINDOWS\SYSTEM\JAVAND32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\ptsnoop.exe
C:\WINDOWS\SYSTEM\APIWE.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\IEZO32.EXE
C:\WINDOWS\SYSTEM\JAVAND32.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\PROFILES\USER\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?s=consumer&LC=1009&c=1c00
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {8BCAECE1-BD48-E057-0435-F351137FC682} - C:\WINDOWS\SYSTEM\SDKSG32.DLL
O2 - BHO: Class - {8A23479F-D9DB-E989-D3B6-E5D9FF6BBE17} - C:\WINDOWS\SYSTEM\APPNM32.DLL
O2 - BHO: Class - {8849FD03-210F-3BC3-0713-DAC7CE7DD7AA} - C:\WINDOWS\D3FI.DLL
O2 - BHO: Class - {15E28534-5479-FF48-C0C0-53B853647C17} - C:\WINDOWS\SYSTEM\ATLJW.DLL
O2 - BHO: Class - {91ACFEB4-563E-7346-F46B-988AF1C8F8C5} - C:\WINDOWS\JAVAGT.DLL
O2 - BHO: Class - {0E36A5AB-890B-6E21-77B4-9D92E1DFBE39} - C:\WINDOWS\SDKGD32.DLL
O2 - BHO: Class - {0787AF5E-2A35-7962-F5DD-88D3489DCC09} - C:\WINDOWS\SYSTEM\MSGU32.DLL
O2 - BHO: Class - {EC44E2F0-346B-DBED-097E-C957FC674BF9} - C:\WINDOWS\SYSTEM\SYSAD32.DLL
O2 - BHO: Class - {762649A9-5928-B1E9-E457-DCA1D5648F18} - C:\WINDOWS\SYSTEM\JAVAAX32.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [APIWE.EXE] C:\WINDOWS\SYSTEM\APIWE.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [NTAD.EXE] C:\WINDOWS\SYSTEM\NTAD.EXE /s
O4 - HKLM\..\RunServices: [IEZO32.EXE] C:\WINDOWS\SYSTEM\IEZO32.EXE /s
O4 - HKLM\..\RunServices: [APIHC.EXE] C:\WINDOWS\APIHC.EXE /s
O4 - HKLM\..\RunServices: [JAVAND32.EXE] C:\WINDOWS\SYSTEM\JAVAND32.EXE /s
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted IP range: 213.159.117.202
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab

Logged

this picture-box thinks its smarter then me
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #8 on: May 28, 2005, 10:59:53 AM »

One more thing incase this is affecting something...
when i start the computer, around the windows loading screen.. the screen is black and it says something like "an entry in your _____ is invalid"  then it lists these
"c:\>P=Program Group, c:\>WaveBloc,  c:\>[default]"

Logged

this picture-box thinks its smarter then me
Cactus
Security & Virus Specialist
Global Moderator
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 4327


Bookmark and Share

View Profile
« Reply #9 on: May 28, 2005, 03:07:27 PM »

Ok let's do this again wrongone .. Wink

Set Windows to show Hidden files and folders
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.



Goto START>RUN
Type or Copy/Paste these lines below into the Run Box 1 at a time Pressing OK after each:


regsvr32 /u SDKSG32.DLL
regsvr32 /u APPNM32.DLL
regsvr32 /u D3FI.DLL
regsvr32 /u ATLJW.DLL
regsvr32 /u JAVAGT.DLL
regsvr32 /u SDKGD32.DLL
regsvr32 /u MSGU32.DLL
regsvr32 /u SYSAD32.DLL
regsvr32 /u JAVAAX32.DLL

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)


JAVAND32.EXE
APIHC.EXE
IEZO32.EXE
NTAD.EXE
APIWE.EXE



Close all other open Windows and have HiJackThis Fix:



R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?s=consumer&LC=1009&c=1c00
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {8BCAECE1-BD48-E057-0435-F351137FC682} - C:\WINDOWS\SYSTEM\SDKSG32.DLL
O2 - BHO: Class - {8A23479F-D9DB-E989-D3B6-E5D9FF6BBE17} - C:\WINDOWS\SYSTEM\APPNM32.DLL
O2 - BHO: Class - {8849FD03-210F-3BC3-0713-DAC7CE7DD7AA} - C:\WINDOWS\D3FI.DLL
O2 - BHO: Class - {15E28534-5479-FF48-C0C0-53B853647C17} - C:\WINDOWS\SYSTEM\ATLJW.DLL
O2 - BHO: Class - {91ACFEB4-563E-7346-F46B-988AF1C8F8C5} - C:\WINDOWS\JAVAGT.DLL
O2 - BHO: Class - {0E36A5AB-890B-6E21-77B4-9D92E1DFBE39} - C:\WINDOWS\SDKGD32.DLL
O2 - BHO: Class - {0787AF5E-2A35-7962-F5DD-88D3489DCC09} - C:\WINDOWS\SYSTEM\MSGU32.DLL
O2 - BHO: Class - {EC44E2F0-346B-DBED-097E-C957FC674BF9} - C:\WINDOWS\SYSTEM\SYSAD32.DLL
O2 - BHO: Class - {762649A9-5928-B1E9-E457-DCA1D5648F18} - C:\WINDOWS\SYSTEM\JAVAAX32.DLL


O4 - HKLM\..\Run: [APIWE.EXE] C:\WINDOWS\SYSTEM\APIWE.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [NTAD.EXE] C:\WINDOWS\SYSTEM\NTAD.EXE /s
O4 - HKLM\..\RunServices: [IEZO32.EXE] C:\WINDOWS\SYSTEM\IEZO32.EXE /s
O4 - HKLM\..\RunServices: [APIHC.EXE] C:\WINDOWS\APIHC.EXE /s
O4 - HKLM\..\RunServices: [JAVAND32.EXE] C:\WINDOWS\SYSTEM\JAVAND32.EXE /s



Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab)  

C:\WINDOWS\SYSTEM\SDKSG32.DLL
C:\WINDOWS\SYSTEM\APPNM32.DLL
C:\WINDOWS\D3FI.DLL
C:\WINDOWS\SYSTEM\ATLJW.DLL
C:\WINDOWS\JAVAGT.DLL
C:\WINDOWS\SDKGD32.DLL
C:\WINDOWS\SYSTEM\MSGU32.DLL
C:\WINDOWS\SYSTEM\SYSAD32.DLL
C:\WINDOWS\SYSTEM\JAVAAX32.DLL

C:\WINDOWS\SYSTEM\JAVAND32.EXE
C:\WINDOWS\APIHC.EXE
C:\WINDOWS\SYSTEM\IEZO32.EXE
C:\WINDOWS\SYSTEM\NTAD.EXE
C:\WINDOWS\SYSTEM\APIWE.EXE

Now, empty all your TEMP Folders / Temporary Internet Files Folder and then empty your "Recycle Bin" and Reboot.



Before opening your browser goto START>CONTROL PANEL>INTERNET OPTIONS and make sure your Homepage is correct,if not ,type the URL you would like in the HomePage box.

Download CCLEANER
http://www.ccleaner.com/

Under Windows tab check Internet Explorer, Windows Explorer, and System.
Then click Run Cleaner.

Now re-run HJT and post a new logfile back here.


Cactus  
Logged

**PLEASE**.....do not post your hijack log in someone else's thread. Start a separate thread HERE! Thank you.

cactus@mytechsupport.ca

My System Specs

Avg Antivirus::Ad-Aware::Spybot::Windows Update::Recuva
Malwarebytes::SUPERAntiSpywareFREE
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #10 on: May 28, 2005, 06:53:57 PM »

ok here we go ,sorry if im making this harder then it should be Sad
(by the way, when i fixed those things with HJT i got some errors and ended up having to restart my comp)

heres the new log

Logfile of HijackThis v1.99.1
Scan saved at 11:59:49 AM, on 28/05/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\PROFILES\USER\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {DE14263E-454E-2928-B90B-682429F8C6CD} - C:\WINDOWS\SYSTEM\IEEP32.DLL
O2 - BHO: (no name) - {8AF47D04-CF67-11D9-A204-00802C01794F} - C:\WINDOWS\SYSTEM\AIMALAA.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted IP range: 213.159.117.202
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab

Logged

this picture-box thinks its smarter then me
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #11 on: May 28, 2005, 06:57:06 PM »

cactus i got a question for ya
what exactly does "Now, empty all your TEMP Folders / Temporary Internet Files Folder" imply... im on a old IE so when i go to the IE properties theres no 'delete cookies' button, should i be doing that and if so how do i do it on older IE versions
thanks


Logged

this picture-box thinks its smarter then me
Cactus
Security & Virus Specialist
Global Moderator
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 4327


Bookmark and Share

View Profile
« Reply #12 on: May 28, 2005, 07:16:15 PM »

Running CCLEANER got most of them .. Wink

Goto START > RUN

type %temp% (including the %)

Delete the entire contents of the temp folder


Also Disk Clean Up

To start Disk Clean Up, click 'Start' > 'Programs' > 'Accessories' > 'System Tools' > 'Disk Cleanup'.  

Select the drive you'd like to cleanup (usually C:\ or the letter drive windows is installed in) and click OK.  

Make sure all options are selected/checked.  

Click OK   and YES and let cleanup do it's work.  

When cleanup is complete, the window will disappear and close automatically.

If you haven't done the fix yet,please do then delete what you can.
Don't worry about what you CANNOT find but rather concentrate on what you CAN.

Post back with fresh HJT logfile when your done.

Cactus  
Logged

**PLEASE**.....do not post your hijack log in someone else's thread. Start a separate thread HERE! Thank you.

cactus@mytechsupport.ca

My System Specs

Avg Antivirus::Ad-Aware::Spybot::Windows Update::Recuva
Malwarebytes::SUPERAntiSpywareFREE
wrongone
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 27


Bookmark and Share

View Profile
« Reply #13 on: May 28, 2005, 07:22:10 PM »

im sorry cactus but im confused

"If you haven't done the fix yet,please do then delete what you can."

what fix are you referring to? ive done the HJT fixes you outlined.
Logged

this picture-box thinks its smarter then me
Cactus
Security & Virus Specialist
Global Moderator
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 4327


Bookmark and Share

View Profile
« Reply #14 on: May 28, 2005, 07:33:33 PM »

Ok great .. can you post the new HJT logfile .. Grin

Cactus  
Logged

**PLEASE**.....do not post your hijack log in someone else's thread. Start a separate thread HERE! Thank you.

cactus@mytechsupport.ca

My System Specs

Avg Antivirus::Ad-Aware::Spybot::Windows Update::Recuva
Malwarebytes::SUPERAntiSpywareFREE
Pages: [1] 2 3 Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page November 20, 2018, 05:03:36 AM