This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can't start up internet with add-ons.

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can't give too much detail for this is my dad's computer, sorry about that, but I've used it for a bit.


Whenever I pop up Internet Explorer, I get that error window with "Debug", "Send Error Report", and "Don't Send".


It works with add-ons diabled though.

He says it just started doing this on Tuesday.

Otherwise, there aren't any other problems that I've noticed.

It's not very high priority, so don't rush to help me or anything, I've got all the time in the world, haha.

Here's the log;


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:39:33 PM, on 8/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Monsoon Multimedia\HAVA\Common\havasvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\DivX\DivX Codec\divxsm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gamefaqs.com/
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Shared\lib.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: Defender Pro Defrag.lnk = C:\Program Files\Defender Pro\Defender Pro Defrag\bin\defenderProDefragCtrl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Filter hijack: text/html - {bbf3a763-6e4b-4ec2-8bc1-ab683e9da1a7} - C:\WINDOWS\system32\xwreg32.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HAVA Service (havasvc) - Monsoon Multimedia Inc. - C:\Program Files\Monsoon Multimedia\HAVA\Common\havasvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8878 bytes
Due, in part, to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Sec-Info2.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a file in it - double click Sec-info2.vbs to run it.
Once you have been informed that the script has completed, a text file called Sec-Info.txt should be created in the same folder - you may need to wait a couple of seconds for it to appear..
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Rooter.exe from here and save it to your Desktop.
  • Double-click it to start the tool.
  • Click the Scan button to… well… scan - obvious really!
  • Once complete, a Notepad file containing the report will open; a copy of which can be found at C:\Rooter$\Rooter.txt - assuming your main drive is C: of course.
  • Please post the contents of Rooter.txt in your next reply.
Oddly enough, I can start the internet with add-ons now but I'll do this for there are numerous other problems now. I got the Kaspersky Online Scanner 7, but when it got to 100%, the status changes to "failed" and I get this error message; "Update has failed. Program has failed to start. Close the Kaspersky Online Scanner 7.0 window and open it again to install the program. You must be online to update the Kaspersky Online Scanner 7 database. With the latest database updates, you can find new viruses and other threats. Please go online to use Kaspersky Online Scanner 7. [ERROR: Key is expired]" I've closed it and opened it multiple times and it's still giving me the error message. I'll try restarting. EDIT; Have restarted, but now I get this silly "Antispyware 2010" obvious malware. Damnit. Malwarebyte's Anti-Malware is scanning (I should've done that right away when I first used this computer, but I forgot, how stupid of me.) and it already detects 10 objects infected. I'll finish that scan then try to proceed with the KOS7 again. EDIT 2; Alright, I removed the above junk but now, I have to start without add-ons again. KOS7 requires Java version 1.5 or later, which is an "add-on". I'll try restarting the computer. EDIT 3; No-go. I guess I'll just keep checking every day and hope that by luck (just like last time), I get to use add-ons again.
When you post a reply I get an email notifying me of that, when you edit it, I don't - so please don't edit. Kav is having some problems at the minute, so don't worry about it not running. It was supposed to be fixed, but it appears that issues still remain.
Run MBAM and select the Logs Tab. Each log has the time and date attached to it - let me have the one that corresponds to the latest scan you have just completed.
Sorry about that, most forums frown upon double posting. Malwarebytes' Anti-Malware 1.38 Database version: 2336 Windows 5.1.2600 Service Pack 3 8/16/2009 2:18:07 AM mbam-log-2009-08-16 (02-18-07).txt Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|) Objects scanned: 311777 Time elapsed: 2 hour(s), 0 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\system volume information\_restore{dde3eb95-4b24-44d8-ad38-1f974b96c2f0}\RP133\A0048025.exe (Rogue.MalwareSweeper) -> Quarantined and deleted successfully.
Alright. Sec Info Script run: 8/25/2009 4:23:15 PM ~~~~~~~~~~~~~~~~~~~~~~~~ The Windows Firewall is disabled. ~~~~~~~~~~~~~~~~~~~~~~~~ The Security Center Anti-Virus Alerts are disabled. The Security Center Firewall Alerts are disabled. ~~~~~~~~~~~~~~~~~~~~~~~~ Number of Restore Points found: 77 ~~~~~~~~~~~~~~~~~~~~~~~~ Unistall List; 32 Bit HP CIO Components Installer 7-Zip 4.65 AC3Filter (remove only) Adobe Flash Player 10 ActiveX Adobe Reader 7.0 Adobe Shockwave Player 11.5 Agere Systems PCI Soft Modem AIM 6 AIM Toolbar Apple Software Update ArcSoft Print Creations ArcSoft Print Creations - Album Page ArcSoft Print Creations - Funhouse ArcSoft Print Creations - Greeting Card ArcSoft Print Creations - Photo Book ArcSoft Print Creations - Photo Calendar ArcSoft Print Creations - Scrapbook ArcSoft Print Creations - Slimline Card CCScore Choice Guard Compaq Connections Compaq Organize Critical Update for Windows Media Player 11 (KB959772) CyberLink PhotoNow CyberLink PowerDirector DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Web Player Download Updater (AOL LLC) Easy Internet Sign-up Enhanced Multimedia Keyboard Solution ESSBrwr ESSCDBK ESScore ESSgui ESSini ESSPCD ESSPDock ESSTOOLS essvatgt Garmin City Navigator North America NT 2009.11 Update Garmin Communicator Plugin Garmin USB Drivers Garmin WebUpdater Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer HAVA Software HAVA Software Help and Support Additions HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB945060-v3) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB961118) HP Customer Participation Program 10.0 HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3 HP Imaging Device Functions 10.0 HP Photosmart Essential 2.5 HP Smart Web Printing HP Solution Center 10.0 HP Update InstallMgr InterVideo WinDVD Player Java 2 Runtime Environment, SE v1.4.2_03 Java™ 6 Update 15 Kodak EasyShare software MagicDisc 2.7.106 Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Default Manager Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Plus! Digital Media Edition Installer Microsoft Search Enhancement Pack Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works MSN Toolbar MSN Toolbar MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) netbrdg Norton Security Scan OBD-PC Link OfotoXMI PCDADDIN PCDHELP PC-Doctor for Windows Python 2.2 pywin32 extensions (build 203) QuickTime RealPlayer Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Segoe UI SFR SHASTA Shop for HP Supplies SiS VGA Utilities skin0001 SKINXSDK SmartSound Quicktracks Plugin Sonic Express Labeler Sonic RecordNow! staticcr SUPER © Version 2009.bld.35 (Jan 5, 2009) tooltips Ulead Straight-to-Disc SDK Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.762 Viewpoint Media Player VLC media player 1.0.0 VPRINTOL Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0) Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Service Pack 3 WIRELESS Rooter; Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows XP Home Edition (5.1.2600) Service Pack 3 [32_bits] - x86 Family 15 Model 28 Stepping 0, AuthenticAMD . [wscsvc] (Security Center) RUNNING (state:4) [SharedAccess] RUNNING (state:4) Windows Firewall -> Disabled ! . Internet Explorer 7.0.5730.13 . C:\ [Fixed-NTFS] .. ( Total:144 Go - Free:82 Go ) D:\ [Fixed-FAT32] .. ( Total:4 Go - Free:0 Go ) E:\ [CD_Rom] F:\ [CD_Rom] G:\ [Removable] H:\ [Removable] I:\ [Removable] J:\ [Removable] . Scan : 16:27.15 Path : C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temporary Internet Files\Content.IE5\ZZXGYIKI\Rooter[1].exe User : Compaq_Owner ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (468) ______ \??\C:\WINDOWS\system32\csrss.exe (540) ______ \??\C:\WINDOWS\system32\winlogon.exe (564) ______ C:\WINDOWS\system32\services.exe (608) ______ C:\WINDOWS\system32\lsass.exe (620) ______ C:\WINDOWS\system32\svchost.exe (772) ______ C:\WINDOWS\system32\svchost.exe (848) ______ C:\WINDOWS\System32\svchost.exe (928) ______ C:\WINDOWS\system32\svchost.exe (1012) ______ C:\WINDOWS\system32\svchost.exe (1112) ______ C:\WINDOWS\Explorer.EXE (1248) ______ C:\WINDOWS\system32\spoolsv.exe (1368) ______ C:\WINDOWS\system32\svchost.exe (1460) ______ C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (1492) ______ C:\Program Files\Monsoon Multimedia\HAVA\Common\havasvc.exe (1520) ______ C:\WINDOWS\system32\svchost.exe (1544) ______ C:\Program Files\Java\jre6\bin\jqs.exe (1564) ______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (1596) ______ C:\WINDOWS\System32\svchost.exe (1636) ______ C:\WINDOWS\System32\svchost.exe (1652) ______ C:\Program Files\CyberLink\Shared files\RichVideo.exe (1680) ______ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (1720) ______ C:\WINDOWS\system32\svchost.exe (1832) ______ C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (1880) ______ C:\Program Files\Viewpoint\Common\ViewpointService.exe (1900) ______ C:\windows\system\hpsysdrv.exe (432) ______ C:\WINDOWS\AGRSMMSG.exe (436) ______ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (464) ______ C:\HP\KBD\KBD.EXE (496) ______ C:\Program Files\Java\jre6\bin\jusched.exe (960) ______ C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (1024) ______ C:\Program Files\AIM6\aim6.exe (1044) ______ C:\WINDOWS\system32\ctfmon.exe (964) ______ C:\Program Files\Messenger\msmsgs.exe (1132) ______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (1140) ______ C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe (1928) ______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (2112) ______ C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (2128) ______ C:\Program Files\MagicDisc\MagicDisc.exe (2140) ______ C:\Program Files\AIM6\aolsoftware.exe (2376) ______ C:\WINDOWS\system32\svchost.exe (2488) ______ C:\WINDOWS\System32\alg.exe (3388) ______ C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (1364) ______ C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (1792) ______ C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (2500) ______ C:\Program Files\Internet Explorer\iexplore.exe (952) ______ C:\Program Files\Internet Explorer\iexplore.exe (168) ______ C:\Program Files\Trend Micro\HijackThis\HijackThis.exe (2904) ______ C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temporary Internet Files\Content.IE5\ZZXGYIKI\Rooter[1].exe (2340) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:5225439744) \Device\Harddisk0\Partition2 –[ MBR ]– (Start_Offset:5225472000 | Length:154805575680) . ———————-\\ Scheduled Tasks . C:\WINDOWS\Tasks\AppleSoftwareUpdate.job C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\EasyShare Registration Task.job C:\WINDOWS\Tasks\Norton Security Scan for Compaq_Owner.job C:\WINDOWS\Tasks\SA.DAT C:\WINDOWS\Tasks\User_Feed_Synchronization-{750BAB6A-66E1-4086-B94A-3EACF7512C2F}.job . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 16:27.30 . C:\Rooter$\Rooter_1.txt - (25/08/2009 | 16:27.30)
The PC appears to have neither an anti-virus program nor a third-party firewall. As both of these are the minimum necessary for safe surfing, the best advice I can offer is to back up any important data and then reformat and reinstall. I can supply links to free software for when you've got things back up and running again if you wish.
I can do that, but… How exactly would one "reformat and reinstall"? Oh, and would it leave programs there (as in, the icons, but I still have to reinstall them, I remember it did that last time I did a system restore or something of the sort)?
System Restore is a limited "rewind" of a PC, and isn't appropriate in this case. A reformat and reinstall involves either the use of a Windows disc that came with the PC or a partition on the hard drive that contains the same data. This enables you to turn your PC back to the time that it was first booted up and enables you to have a clean start with the system.
If you have any questions, the nice people in this part of the forum will be able to help. Just start a fresh thread there and explain your situation and they should be able to walk you through the whole process.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI