Browser problems & strange error messages - Page 2
Page 2 of 2 FirstFirst 12
Results 16 to 26 of 26

Thread: Browser problems & strange error messages

  1. #16
    Join Date
    May 2007
    Posts
    108
    Time to boot has also increased...

  2. #17
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Let's finish cleaning procedure, first...

    1. Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.

    2. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    3. Restart computer.

    4. Turn System Restore on.

    5. Make sure, Windows Updates are current.

    6. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    7. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    8. Run defrag at your convenience.

    9. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

  3. #18
    Join Date
    May 2007
    Posts
    108
    Thnx - I'll have a go... be a few hours. Meantime the error message popup I'm getting is:

    i explore.exe - application error
    The instruction of "0x032ca220" referenced memory at "0x032ca220" The memory could not be read.Click OK to terminate the program

  4. #19
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    We'll continue, when you're done with previous steps.

  5. #20
    Join Date
    May 2007
    Posts
    108
    I have completed all that, and defragmented c drive - except for windows updates as I have no way presently to backup all my files. Error popups still appear and problems with documents still (I had a Word doc crash on me and lost some data)



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:05:09 PM, on 6/28/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\metc\mysql\bin\mysqld-nt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\System32\PAStiSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Windows Live\Mail\wlmail.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
    C:\Documents and Settings\Jonathan\My Documents\Security, Virus & Spyware Protection\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QlbCtrl] &#37;ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
    O4 - HKLM\..\Run: [EnGraph QuickTimeKiller] C:\Program Files\EnGraph\QuickTimeKiller\QuickTimeKiller.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
    O15 - Trusted Zone: http://ajmyers.4java.ca
    O15 - Trusted Zone: http://www.coolinvestor.com
    O15 - Trusted Zone: http://*.eblackbox.net
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
    O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://www.schaeffersresearch.com/download/CfxIEAx.cab
    O16 - DPF: {24BACF02-5676-11D3-B8DE-00105A17A9E6} (ChartFX Internet Financial Client 4.0) - http://www.schaeffersresearch.com/Do...4Financial.cab
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
    O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigner.hgtv.com/images/app/view22rte.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: metc-mysql - Unknown owner - C:\metc\mysql\bin\mysqld-nt.exe
    O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
    O24 - Desktop Component 0: (no name) - http://www.psychonomics.com/bg1e2.jpg
    O24 - Desktop Component 1: (no name) - http://static11.digitallook.com/dlme...erplots_sm.gif

    --
    End of file - 9289 bytes

  6. #21
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Since the computer is clean, I propose, you start separate topic in Windows section about other issues. Only limited number of people are allowed to reply in THIS forum. You'll get more attention.
    Make sure, you post a link to this thread.

  7. #22
    Join Date
    May 2007
    Posts
    108
    OK - I'll do that... as I'm still getting all these strage problems. I had great difficulty getting on this page in fact.. page wouldn't open from the link in the email and then multiple pages tried to open, new brwser windows flashing open in quick succession. Eventually I got here! In the past that's generally been a virus problem but if it's not then I'll try your suggestion. Perhaps Windows is corrupted somewhere?

    Thanks for all your help.

  8. #23
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Please download DrWeb CureIt (http://www.freedrweb.com/) & save it to your desktop.

    Scan with DrWeb-CureIt as follows:

    * Double-click on drweb-cureit.exe and then click Start. Click OK in a pop-up window allowing Express Scan
    o This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
    * Once the short scan has finished, Click Options > Change settings
    * Choose the Scan tab and uncheck Heuristic analysis and click OK
    * Back at the main window, select the Complete scan button.
    * Then click the Green Arrow Start Scanning button on the right and the scan will start.
    o Click Yes to all if it asks if you want to cure/move any file(s).
    * When the scan is done...
    * In the Dr.Web CureIt menu on top left, click File and choose Save report list.
    * Save the DrWeb.csv report to your Desktop.
    * Exit Dr.Web Cureit.


    * Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.

    * After reboot. Leave the Dr. Web CureIt log on the desktop.

    Copy and paste that log in the next reply. You can use Notepad to open the DrWeb.cvs report.

    NOTE. During the scan a pop-up window will appear, asking you to buy a full version. Simply close the pop-up window.

  9. #24
    Join Date
    May 2007
    Posts
    108
    a good suggestion - it caught a few things and 'cured' them though problems still occuring

    SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Jonathan\My Documents\Security, Virus & Spyware Protection\SDFix.exe;Tool.Prockill;;
    SDFix.exe\SDFix\apps\HPFix.reg;C:\Documents and Settings\Jonathan\My Documents\Security, Virus & Spyware Protection\SDFix.exe;Trojan.StartPage.1505;;
    SDFix.exe;C:\Documents and Settings\Jonathan\My Documents\Security, Virus & Spyware Protection;Archive contains infected objects;Moved.;
    SlgClientServicesRedists.exe\data002;C:\Program Files\HP Games\Cake Mania\SlgClientServicesRedists.exe;Adware.SpywareStorm;;
    SlgClientServicesRedists.exe;C:\Program Files\HP Games\Cake Mania;Archive contains infected objects;Moved.;
    AOLCINST.EXE\core.cab\GTDOWNAO_106.ocx;C:\Program Files\Online Services\Aol\United States\AOL90\COMPS\COACH\AOLCINST.EXE;Adware.Gdown;;
    AOLCINST.EXE;C:\Program Files\Online Services\Aol\United States\AOL90\COMPS\COACH;Archive contains infected objects;Moved.;
    SP31524.exe/musicnow1.exe\data008;C:\SWSetup\AOLMN\SP31524.exe/musicnow1.exe;Trojan.Click.2093;;
    \musicnow1.exe;C:\SWSetup\AOLMN;Archive contains infected objects;;
    SP31524.exe;C:\SWSetup\AOLMN;Archive contains infected objects;Moved.;
    cakemania-setup.exe/data030\data002;C:\SWSetup\HPGame\games\cakemania-setup.exe/data030;Adware.SpywareStorm;;
    data030;C:\SWSetup\HPGame\games;Archive contains infected objects;;
    cakemania-setup.exe;C:\SWSetup\HPGame\games;Archive contains infected objects;Moved.;
    A0000465.exe\data002;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8\A0000465.exe;Adware.SpywareStorm;;
    A0000465.exe;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8;Archive contains infected objects;Moved.;
    A0000466.EXE\core.cab\GTDOWNAO_106.ocx;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8\A0000466.EXE;Adware.Gdown;;
    A0000466.EXE;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8;Archive contains infected objects;Moved.;
    A0000467.exe/musicnow1.exe\data008;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8\A0000467.exe/musicnow1.exe;Trojan.Click.2093;;
    \musicnow1.exe;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8;Archive contains infected objects;;
    A0000467.exe;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8;Archive contains infected objects;Moved.;
    A0000468.exe/data030\data002;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8\A0000468.exe/data030;Adware.SpywareStorm;;
    data030;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8;Archive contains infected objects;;
    A0000468.exe;C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP8;Archive contains infected objects;Moved.;

  10. #25
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    I still suggest, you start new topic at Windows section.

  11. #26
    Join Date
    May 2007
    Posts
    108
    will do... thnx again

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •