• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
Warden

res://vhjqc.dll/index.html#96676

13 posts in this topic

Hi, I have been unable to get rid of this issue. I can't delete files ipwq.exe and sysua.exe. Every time I remove them from the registry and fix homepage and other issues they reappear. Sorry if I am slow. Homepage is always res://vhjqc.dll/index.html#96676. Any help would be greatly appreciated. Thanks in advance. Here is HJT log.

 

 

 

Logfile of HijackThis v1.98.0

Scan saved at 5:13:40 PM, on 7/7/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\nslsvice.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe

C:\Program Files\lotus\notes\ntmulti.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\ltmsg.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

C:\Program Files\Compaq\EAB\EABSERVR.EXE

C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

C:\WINDOWS\sysua.exe

C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe

C:\WINDOWS\system32\addnj.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vhjqc.dll/sp.html#96676

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://vhjqc.dll/index.html#96676

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://vhjqc.dll/index.html#96676

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vhjqc.dll/sp.html#96676

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vhjqc.dll/sp.html#96676

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://vhjqc.dll/index.html#96676

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = google.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = google.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dll?p....0&plcid=0x0409

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - C:\WINDOWS\system32\mfcfo.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

O4 - HKLM\..\Run: [sysua.exe] C:\WINDOWS\sysua.exe

O4 - HKLM\..\RunOnce: [addnj.exe] C:\WINDOWS\system32\addnj.exe

O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

Share this post


Link to post
Share on other sites

Thanks Ducky, here is the first log from aboutbuster.

 

About:Buster Version 1.25

Removed! : C:\WINDOWS\airpsh.dat

Removed! : C:\WINDOWS\akoskx.dat

Removed! : C:\WINDOWS\atgfuh.dat

Removed! : C:\WINDOWS\bqoqmi.dat

Removed! : C:\WINDOWS\bwrbpo.dat

Removed! : C:\WINDOWS\bxcllc.dat

Removed! : C:\WINDOWS\canhgj.dat

Removed! : C:\WINDOWS\erfjzi.dat

Removed! : C:\WINDOWS\guyxmp.dat

Removed! : C:\WINDOWS\gxgtfa.dat

Removed! : C:\WINDOWS\hgvwxr.dat

Removed! : C:\WINDOWS\ilrpcf.dat

Removed! : C:\WINDOWS\jdifzr.dat

Removed! : C:\WINDOWS\koklxl.dat

Removed! : C:\WINDOWS\kxhctg.dat

Removed! : C:\WINDOWS\lbhhjy.dat

Removed! : C:\WINDOWS\lfijri.dat

Removed! : C:\WINDOWS\lsdwja.dat

Removed! : C:\WINDOWS\meadee.dat

Removed! : C:\WINDOWS\mqsfep.dat

Removed! : C:\WINDOWS\mtfbrp.dat

Removed! : C:\WINDOWS\mveecq.dat

Removed! : C:\WINDOWS\mzgvwa.dat

Removed! : C:\WINDOWS\nhxapw.dat

Removed! : C:\WINDOWS\nnbugk.dat

Removed! : C:\WINDOWS\nptdyu.dat

Removed! : C:\WINDOWS\ntshcw.dat

Removed! : C:\WINDOWS\n_bllzel.dat

Removed! : C:\WINDOWS\n_rxsujh.dat

Removed! : C:\WINDOWS\ofcyib.dat

Removed! : C:\WINDOWS\owdnqg.dat

Removed! : C:\WINDOWS\owkdpd.dat

Removed! : C:\WINDOWS\pawjln.dat

Removed! : C:\WINDOWS\qanppc.dat

Removed! : C:\WINDOWS\sdgmcj.dat

Removed! : C:\WINDOWS\sysua.exe

Removed! : C:\WINDOWS\tejylg.dat

Removed! : C:\WINDOWS\tjehks.dat

Removed! : C:\WINDOWS\umahlo.dat

Removed! : C:\WINDOWS\unjxeb.dat

Removed! : C:\WINDOWS\vxosoe.dat

Removed! : C:\WINDOWS\vyznsf.dat

Removed! : C:\WINDOWS\vzhojq.dat

Removed! : C:\WINDOWS\wiyobl.dat

Removed! : C:\WINDOWS\wjkjnl.dat

Removed! : C:\WINDOWS\ygslml.dat

Removed! : C:\WINDOWS\yxihx.dat

Removed! : C:\WINDOWS\yxihxy.dat

Removed! : C:\WINDOWS\zglcnz.dat

Removed! : C:\WINDOWS\zyffwo.dat

Removed! : C:\WINDOWS\System32\addnj.exe

Removed! : C:\WINDOWS\System32\bllze.dat

Error Removing! : C:\WINDOWS\System32\mfcfo.dll

Removed! : C:\WINDOWS\System32\uoewr.dat

Attempted Clean Of Temp folder.

Removed LEGACY___NS_Service_3 Key

Removed __NS_Service_3 Key

Removed Uninstall Key (HSA)

Removed Uninstall Key (SE)

Removed Uninstall Key (SW)

Pages Reset... Done!

 

Now here is the new HJT log.

 

Logfile of HijackThis v1.98.0

Scan saved at 5:29:11 PM, on 7/7/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\nslsvice.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe

C:\Program Files\lotus\notes\ntmulti.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\ltmsg.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

C:\Program Files\Compaq\EAB\EABSERVR.EXE

C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = google.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = google.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dll?p....0&plcid=0x0409

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - C:\WINDOWS\system32\mfcfo.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

 

Again, thanks for the prompt response. Greatly appreciated.

Share this post


Link to post
Share on other sites

Reboot into safe mode and run About:Buster one more time. Then restart in normal mode. Start up internet explorer. Goto Tools then Internet Options. Tick the 'Programs' tab. Click the button that sais 'Reset Web Settings...'

 

Restart once more and post a new Hijack This log.

Share this post


Link to post
Share on other sites

Okay, I did as you instructed. I have included the aboutbuster log in safe mode. Here it is

 

About:Buster Version 1.25

Removed! : C:\WINDOWS\apphfy.dat

Removed! : C:\WINDOWS\bawlfk.dat

Removed! : C:\WINDOWS\cimfeo.dat

Removed! : C:\WINDOWS\dwukcu.dat

Removed! : C:\WINDOWS\xrsbzd.dat

Removed! : C:\WINDOWS\znqzxn.dat

Removed! : C:\WINDOWS\System32\bllze.dat

Removed! : C:\WINDOWS\System32\javalg.exe

Removed! : C:\WINDOWS\System32\mfcfo.dll

Removed! : C:\WINDOWS\System32\mfcph.exe

Removed! : C:\WINDOWS\System32\msie32.exe

Removed! : C:\WINDOWS\System32\sdkkn32.exe

Removed! : C:\WINDOWS\System32\uoewr.dat

Attempted Clean Of Temp folder.

Removed LEGACY___NS_Service_3 Key

Removed __NS_Service_3 Key

Removed Uninstall Key (HSA)

Removed Uninstall Key (SE)

Removed Uninstall Key (SW)

Pages Reset... Done!

 

Now here is the HJ log after returning to normal mode.

 

Logfile of HijackThis v1.98.0

Scan saved at 6:10:01 PM, on 7/7/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\nslsvice.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\ltmsg.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

C:\Program Files\Compaq\EAB\EABSERVR.EXE

C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe

C:\Program Files\lotus\notes\ntmulti.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\system32\userinit.exe

C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dll?p....0&plcid=0x0409

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - C:\WINDOWS\system32\mfcfo.dll (file missing)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

Share this post


Link to post
Share on other sites

Hey! Ok looks good. Run hijack this and tick the boxes next to these items.

 

 

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - C:\WINDOWS\system32\mfcfo.dll (file missing)

 

Then close all windows and hit fix checked. Go into C:\Windows and C:\Windows\System32. Find a file called notepad.exe.bak. If the file exists delete Notepad.exe and rename notepad.exe.bak to Notepad.exe. Do the same in both directories. Dont delete notepad.exe unless notepad.exe.bak exists.

Share this post


Link to post
Share on other sites

Okay, did as instructed. No notepad.exe.bak in either c/windows or sys32 folder just notepad.exe. I think that may have done it. I have included another hjt log just in case.

 

Logfile of HijackThis v1.98.0

Scan saved at 6:30:17 PM, on 7/7/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\nslsvice.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\ltmsg.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

C:\Program Files\Compaq\EAB\EABSERVR.EXE

C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe

C:\Program Files\lotus\notes\ntmulti.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe

O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe

 

Again, thanks so much for your help. Can't tell ou how much i appreciate it.

Share this post


Link to post
Share on other sites

Got another one for you. just wondering where a donation could be placed for your expert help. Also, can this be prevented from happening again? Ad-Aware kept saying it was CWS but the shredder never got rid of the issue. Also, should I start a new posting for a non-boot issue in a different forum? Again, thanks so much. Quite a headache.

Share this post


Link to post
Share on other sites

To donate to this forum hit 'Donate to This site' in the menu way above near the banner.

 

 

Also, should I start a new posting for a non-boot issue in a different forum?

 

Post the problem in here. Ill see what i can do.

Edited by RubbeR DuckY

Share this post


Link to post
Share on other sites

My computer, running 2000 Pro was running okay until this morning. I powered down before hittiing the office. When I arrived at the office and turned on the computer I got a blue screen that informed me

 

*** STOP: 0x0000001E (0xC0000005, 0xED1B28CB, 0x00000001, 0x00000004)

 

KMODE_EXCEPTION_NOT_HANDLED

 

It goes on to suggest rebooting if it is the first time, changing or disabling drivers, or checking for BIIOS updates. Every time I reboot I get the same screen. When I try safe mode I can't log in. My passwd no longer works. Anybody have any ideas or clues? I have data on here I need for a report. Any help or suggestions would be greatly appreciated. Thanks in advance for any help.

Share this post


Link to post
Share on other sites

Im not really a tech so i cant help you. Looks like somethings wrong with your boot options or your bios.

 

See if someone else will help you on a tech forum or look up the error. Sorry thats all the advice i can give.

 

:unsure:

Share this post


Link to post
Share on other sites

No worries at all. I appreciate all of your previous help. I posted it in PC Issues, no responses yet, but maybe soon. Again, thanks so much for your prompt assistance. Have a great night.

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0