Content Top
DAL Computer Help » Internet Security Help » Spyware, Adware, Viruses and HijackThis Logs » help-help-help

Recommended Fix

Click here to fix Windows Errors and Optimize Windows Performance

Need Computer Help?
Register Now for FREE

help-help-help

Reply
Thread Tools
Spyware, Adware, Viruses and HijackThis Logs
  #1 (permalink)  
Old 14-01-2005, 10:38 PM
Newbie
D-A-L Newbie
 
Join Date: Jan 2005
Posts: 2
Nia77 Is a beginner here at D-A-L
help-help-help

Hi, i'm not even on my own computer right now, it's so absolutely blown. I have no idea what else i can do, given its state. it was last night that IE started to slow down considerably, and then i was getting warnings about BHO's from my SpywareGuard, and then both of them crashed. Since then, nothing's gone right. IE is either a slogging mess or just quits (every thirty seconds..or maybe a whole couple minutes) with an average-looking error message, or maybe a 'msxml2r.exe has stopped responding.' The SpywareGuard, which has always worked really well for me, flashes a dozen 'netan32.dll' warnings, and then crashes itself. I don't know what the hell either msxml2r or netan32 is, by the way. Adaware comes up clean or, oh, wow, it crashes, too. Spybot manages to finish scanning, but then it freezes and quits, too. CWshredder, like adaware, told me congratulations on my squeaky-clean system, at which point i started to laugh. it's better than breaking something.

here is the hijack this log for the thing:

C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\System32\services.exe
C:\WINNT\System32\lsass.exe
C:\WINNT\System32\svhost.exe
C:\WINNT\System32\svhost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\GWMDMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\System32\dwwin.exe
C:\WINNT\System32\dwwin.exe
C:\WINNT\System32\dumprep.exe
C:\WINNT\System32\dumprep.exe
C:\WINNT\System32\dwwin.exe
C:\WINNT\System32\dwwin.exe
C:\WINNT\Documents and Settings\nia\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main, Start Page = http://en.wikipedia.org/wiki/Main_Page
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Quicktime Task] "C:\Program FIles\Quicktime\qttask.exe" - atboottime
O4 - HKLM\..\Run: [ashMaiSv] C:\PRGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [cltdic] C:\WINNT\System32\cltdic.exe
O4 - HKLM\..\Run: [036T3ml] nbstor.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program FIles\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINNT\System32\winupdtl.exe
O4 - HKLM\..\Run: [mxhtwnw] C:\WINNT\System32\qdqxhmpg.exe
O4 - HKLM\..\Run: [crtj.exe] C:\WINNT\System32\crtj.exe
O4 - HKLM\..\Run: [msnmsgr] “C:\Program Files\MSN Messenger\msnmsgr.exe” /background
O4 - HKLM\..\Run: [WinMX] C:\Program Files\WinMX\WinMX.exe –m
O4 - HKLM\..\Run: [msxml2r] C:\WINNT\System32\msxml2r.exe
O4 – Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 – Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 – Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Mesenger\MSMSGS.EXE
O12 – Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 – Trusted Zone: *.frame.crazywinnings.com
O16 – DPF: {9A9307A0-7DA4-4DAF-B042-5009F0A5519FF} (MsnMessengerSeupDownloadControl Class) – httop://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 – DPF: {D6016EE7-A8FF-11D1-B37E-A4759ECD7909} (AsPulse Class) – http://www.pulse3d.com/players/engli...layerAxWin.cab

thanks so much in advance to whomever decides to take pity on me...
Nia
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 15-01-2005, 12:12 AM
spud's Avatar
D-A-L Team Member (UK)
Loyal Contributor
 
Join Date: Aug 2004
Posts: 1,658
spud is just really nicespud is just really nicespud is just really nicespud is just really nicespud is just really nice
Re: help-help-help

welcome to dal the online computer help forum
owen is one of the moderaters on the forum and when he gets time he will have a look at your hjt log but please be patient as he has loads to do before he gets to yours


thanks
__________________
DOWNLOADS

NCFC rule

OWENS HELP

Yeti sports

Microsoft Help

latest DirectX 9c here

hijacthis

have a laugh


If it dont fit...force it. If ya cant force it...get a bigger hammer. If it breaks...it probably needed replacing anyway.

APPROVED MICROSOFT BETA TESTER
There are 10 kinds of people in the world:
Those who understand binary & those who don't.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 15-01-2005, 01:44 AM
Newbie
D-A-L Newbie
 
Join Date: Jan 2005
Posts: 2
Nia77 Is a beginner here at D-A-L
Re: help-help-help

thanks spud. i'm sure you've alleviated some of my panic yet to occur.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 17-01-2005, 09:04 PM
owen's Avatar
D-A-L Team Member (UK)
Loyal Contributor
 
Join Date: Jun 2004
Posts: 5,272
owen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furniture
Re: help-help-help

Close all browser windows, restart Hijack This and put a checkmark next to the following entries:

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [cltdic] C:\WINNT\System32\cltdic.exe
O4 - HKLM\..\Run: [036T3ml] nbstor.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINNT\System32\winupdtl.exe
O4 - HKLM\..\Run: [mxhtwnw] C:\WINNT\System32\qdqxhmpg.exe
O4 - HKLM\..\Run: [crtj.exe] C:\WINNT\System32\crtj.exe
O4 - HKLM\..\Run: [msxml2r] C:\WINNT\System32\msxml2r.exe
O15 – Trusted Zone: *.frame.crazywinnings.com

Click Fix Checked

Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders.

Delete the following files and folders. Search for and delete files without a specific location:
C:\WINNT\System32\cltdic.exe
nbstor.exe
C:\WINNT\System32\winupdtl.exe
C:\WINNT\System32\qdqxhmpg.exe
C:\WINNT\System32\crtj.exe
C:\WINNT\System32\msxml2r.exe

Reboot and post a fresh log
__________________
Owen,
My Website - I Security.org.uk

MALWARE: READ FIRST Procedures:
|_ SpyBot V1.4 _|_ Ad-Aware SE 1.06_|_ HijackThis Log __V1.99.1 _|


[*]Be patient and wait for a response, we'll do our best to help resolve your issue.
[*]When posting for help, start your own thread and stick to it. Don't start multiple threads or post in other peoples threads!

If we have helped you, please consider making a donation to help support the forum. All donations are greatly appreciated. You can also support the forum by placing a link to us on your personal website.

Useful Links:
Posting a Hijack This Log
Preposting and Prevention Info
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools

Forum Jump


All times are GMT +1. The time now is 02:49 AM.

Bottom Corner