This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]My Problem

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First off HJT

Logfile of HijackThis v1.99.1
Scan saved at 8:23:35 PM, on 7/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\AOL\1129442703\ee\AOLSoftware.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\America Online 9.0f\waol.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Joe\Desktop\Stuff\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0f\AOL.EXE" -b
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {360E40AA-EE8B-4101-BA67-0CAD3F7A48DD} (Nyoko Downloader Class) - http://www.riverbelle.com/download_helper/Nyoko.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - http://a.download.toontown.com/sv1.0.20.18/ttinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/zuma/popcaploader_v5.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - http://download.mcafee.com/molbin/iss-loc/…692/mcfscan.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

Secondly Combofix

"Joe" - 2007-07-26 18:17:54 [GMT -5:00] - ComboFix 07-07-24 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-06-26 to 2007-07-26 )))))))))))))))))))))))))))))))


2007-07-26 13:16 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2007-07-26 13:14 d——– C:\Program Files\Microsoft Works
2007-07-26 13:12 d——– C:\Program Files\Microsoft.NET
2007-07-26 13:09 d——– C:\WINDOWS\SHELLNEW
2007-07-26 13:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-07-26 09:54 524,288 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-26 09:54 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Desperate Housewives
2007-07-24 15:47 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
2007-07-23 19:31 d——– C:\DOCUME~1\Joe\APPLIC~1\Google
2007-07-23 19:18 d——– C:\Program Files\Google
2007-07-23 19:18 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-23 18:11 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-23 15:28 d——– C:\Program Files\eMusic Download Manager
2007-07-23 07:17 d——– C:\Downloads
2007-07-22 23:55 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-07-22 15:02 d——– C:\Program Files\Enigma Software Group
2007-07-15 22:48 d——– C:\Program Files\iPod
2007-07-15 22:48 d——– C:\DOCUME~1\Joe\APPLIC~1\Apple Computer
2007-07-15 22:47 d——– C:\Program Files\iTunes
2007-07-15 22:46 d——– C:\Program Files\QuickTime
2007-07-15 22:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-15 22:45 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-15 22:45 d——– C:\Program Files\Common Files\Apple
2007-07-15 22:45 d——– C:\Program Files\Apple Software Update
2007-07-15 22:45 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-07 22:41 d——– C:\Program Files\Hotmail & MSN Password Recovery


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-26 17:57:58 ——– d—–w C:\DOCUME~1\Joe\APPLIC~1\OpenOffice.org2
2007-07-26 14:19:07 ——– d—–w C:\Program Files\Paltalk Messenger
2007-07-26 14:03:58 ——– d—–w C:\Program Files\Common Files\aolshare
2007-07-25 08:10:08 ——– d—–w C:\Program Files\Nstorm
2007-07-24 21:41:40 10 —-a-w C:\WINDOWS\popcinfo.dat
2007-07-23 23:58:39 ——– d—–w C:\DOCUME~1\Joe\APPLIC~1\AdobeUM
2007-07-23 20:28:01 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-23 12:17:41 ——– d—–w C:\DOCUME~1\Joe\APPLIC~1\GetRightToGo
2007-07-23 04:33:57 ——– d—–w C:\Program Files\RegScrubXP
2007-07-22 22:34:11 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-07-16 05:16:12 ——– d—–w C:\DOCUME~1\Joe\APPLIC~1\Wal-Mart Digital Photo Viewer
2007-07-10 04:54:18 ——– d—–w C:\Program Files\Pet Vet
2007-06-28 23:39:26 ——– d—–w C:\Program Files\SecondLife
2007-06-21 00:24:44 ——– d—–w C:\Program Files\Bullfrog
2007-06-13 21:39:53 ——– d—–w C:\Program Files\EA GAMES
2007-06-13 21:36:51 ——– d—–w C:\Program Files\Common Files\EasyInfo
2007-06-10 01:28:07 ——– d—–w C:\Program Files\Oberon Media
2007-06-10 01:26:02 ——– d—–w C:\Program Files\Cartoon Network
2007-06-07 17:16:32 ——– d—–w C:\DOCUME~1\Joe\APPLIC~1\Wal-Mart Digital Photo Manager
2007-06-07 16:47:01 ——– d—–w C:\Program Files\Common Files\HP
2007-06-07 16:46:57 ——– d—–w C:\Program Files\Wal-Mart
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-02-27 13:00:52 20 —-a-w C:\Program Files\Sims2Pack Clean Installer.ini
2006-01-25 19:48:58 20,921,040 —-a-w C:\Program Files\AdbeRdr705_enu_full.exe
2006-01-24 22:41:42 7,050,552 —-a-w C:\Program Files\psa30se_en_us.exe
2006-01-24 22:16:57 762,512 —-a-w C:\Program Files\ytb612_efgsip.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 13:05]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 19:18]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 23:02]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 18:00]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 09:38]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 13:52]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="C:\Program Files\America Online 9.0f\AOL.exe" [2005-07-12 06:17]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Joe^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
path=C:\Documents and Settings\Joe\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.0.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
"C:\Program Files\America Online 9.0f\AOL.EXE" -b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1129442703\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

R1 MPFIREWL;MPFIREWL;C:\WINDOWS\system32\Drivers\MpFirewall.sys
R2 ASCTRM;ASCTRM;C:\WINDOWS\system32\drivers\ASCTRM.sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver;C:\WINDOWS\system32\drivers\msmpu401.sys
R3 SiS7018;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\ac97sis.sys
R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
S3 odserv;Microsoft Office Diagnostics Service;"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
S3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys


Contents of the 'Scheduled Tasks' folder
2007-07-25 01:55:01 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-26 18:25:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-07-26 18:28:25
C:\ComboFix-quarantined-files.txt … 2007-07-26 18:26
C:\ComboFix2.txt … 2007-07-23 21:21
C:\ComboFix3.txt … 2007-07-23 18:20

— E O F —

There you go Happy Birthday! It's all I could afford at this time. You never did say how old you are. LOL I am curious.
Good evening,

Sorry that I have confused you.

Let's see where we are. You have notepad open with that text pasted in it. OK

1. Now close Notepad and it will prompt you to choose a place to save it: Choose your Desktop

2. Name to use for the file : "delete.bat" <===Use the quote marks like I did

3. on your desk, there now should be a little blue wheel icon named delete.bat<==You have now created your firstt batch file or bat file

4. Now click on the icon, you may briefly see a little black screen popup, maybe not. This works in the background to delete that service that I asked you about.

5. Now that that is done, please run ComboFix again and save the report because I need you to post it in your next reply.

6. Now run HijackThis, scan and produce a log. Please post this log also.

7. Logs to post:
  • ComboFix.txt
  • HijackThis log


See ya later,


Trevuren
All that is already done. I figured it out myself after I posted about it. I am not a complete idiot when it comes to computers just a partial one. LOL The above logs were ran AFTER I did the delete.bat thing.
Those two logs are clear and that's a good thing. Do you want my age in human years or in dog years?

Please read the entire post before doing anything.


Go HERE and Download System Repair Engineer by smallfrogs
http://www.kztechs.com/eng/index.html

Save it to your Desktop
Right Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREng->>Click Run
At the main Window, in the left Pane,Select Smart Scan
At the next window make sure all of the boxes are checked and Select Scan
When the scan is complete Select Save reports
Save it to your desktop and Close the tool
Double Click SREngLog.txt copy and paste that log as a reply to this thread


1. Do not run any other options with this tool unless instructed to do so.
2. If, when the program opens, you get some popup windows from the tool, just close the windows and continue with the instructions.
3. If you notice any items in "red" in your log, after the scan, or any message appear during the scan, please take note of them and post them with the reply.
4. It will probably take a good day before I can get a "brain" to help with the diagnosis. Your case is starting to draw attention.

Take care,

Trevuren
I'll take it in human years……and I don't seem to have many episodes of the restarting by its self anymore. I am trying to remember when it did it last. Also the issue with it wanting to reboot with the last known config doesn't happen much when I restart it. Edited to add: I just restarted it and had NO problem getting to desktop. It is a little slow after clicking on the AOL icon until the program loads to where I can enter the screen name/password….but other than that things seem to work fine for the moment. LOL
Okay I have done it…..and BTW you haven't told me how old you are. Am I being helped by a teenager..LOL? It doesn't matter to me but I am curious.

Here is the log:

2007-07-27,00:19:57

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
	All Boot Items (Including Registry, Startup Folders, Services and so on)
	Browser Add-ons
	Runing Processes (Including process model information)
	File Associations
	Winsock Provider
	Autorun.Inf
	HOSTS File
	Process Privileges Scan


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
	<"C:\Program Files\America Online 9.0f\AOL.EXE" -b>  [(Verified)"Americ]
	  [(Verified)]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
	  [McAfee, Inc]
	<"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask>  [McAfee, Inc.]
	  [McAfee, Inc.]
	  [(Verified)"McAfee, Inc."]
	<"C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup>  [InstallShield Software Corporation]
	<"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe">  [Hewlett-Packard Company]
	  [ATI Technologies, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
	  [(Verified)]
	  [(Verified)]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
	<>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
	  [(Verified)]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
	  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
	  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
	  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
	<%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
	<%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
	<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
	  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
	  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
	  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
	<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
	  [Microsoft Corporation]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	<; "C:\Program Files\America Online 9.0f\AOL.EXE" -b>  [(Verified)"Americ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	<; C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe>  [N/A]
	<; C:\Program Files\Common Files\AOL\ACS\AOLDial.exe>  [(Verified)AOL LLC]
	<; C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe>  [Corel, Inc.]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	<; C:\WINDOWS\system32\ctfmon.exe>  [(Verified)]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	<; C:\Program Files\Common Files\AOL\1129442703\ee\AOLSoftware.exe>  [(Verified)AOL LLC]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	<; "C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	<; "C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Inc.]
	<; C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER>  [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	<; C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet>  [Yahoo! Inc.]

==================================
Startup Folders
N/A

==================================
Services
[AOL Connectivity Service / AOL ACS][Running/Auto Start]
  <"C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe">
[AOL TopSpeed Monitor / AOL TopSpeedMonitor][Running/Auto Start]
  
[Apple Mobile Device / Apple Mobile Device][Running/Auto Start]
  <"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe">
[Application Management / AppMgmt][Stopped/Manual Start]
  %SystemRoot%\System32\appmgmts.dll>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  %SystemRoot%\System32\hidserv.dll>
[McAfee WSC Integration / McDetect.exe][Running/Auto Start]
  
[McAfee.com McShield / McShield][Running/Auto Start]
  
[McAfee Task Scheduler / McTskshd.exe][Running/Auto Start]
  
[McAfee SecurityCenter Update Manager / mcupdmgr.exe][Stopped/Manual Start]
  
[McAfee Personal Firewall Service / MpfService][Running/Auto Start]
  
[Pml Driver HPZ12 / Pml Driver HPZ12][Stopped/Manual Start]
  

==================================
Drivers
[ati2mtag / ati2mtag][Running/Manual Start]
  
[catchme / catchme][Stopped/Manual Start]
  <\??\C:\DOCUME~1\Joe\LOCALS~1\Temp\catchme.sys>
[HCF_MSFT / HCF_MSFT][Running/Manual Start]
  
[IEEE-1284.4 Driver HPZid412 / HPZid412][Running/Manual Start]
  
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12][Running/Manual Start]
  
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12][Running/Manual Start]
  
[MPFIREWL / MPFIREWL][Running/System Start]
  
[NaiAvFilter1 / NaiAvFilter1][Running/Manual Start]
  
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys>
[Secdrv / Secdrv][Running/Auto Start]
  
[SiS300i / SiS300i][Stopped/Manual Start]
  
[Service for AC'97 Sample Driver (WDM) / SiS7018][Running/Manual Start]
  
[SIS AGP Bus Filter / sisagp][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\sisagp.sys>
[SiS PCI Fast Ethernet Adapter Driver / SISNIC][Running/Manual Start]
  
[WAN Miniport (ATW) / wanatw][Running/Manual Start]
  

==================================
Browser Add-ons
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 
[PaltalkWebLogin]
  {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} 
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} 
[Java Plug-in 1.6.0_02]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} 
[Send to OneNote from Internet Explorer button]
  {2670000A-7350-4f3c-8081-5663EE0C6C49} 
[&Research]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} 
[Real.com]
  {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} 
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} 
[Yahoo! Toolbar]
  {EF99BD32-C1FB-11D2-892F-0090271D4F88} 
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} 
[Nyoko Downloader Class]
  {360E40AA-EE8B-4101-BA67-0CAD3F7A48DD} 
[McAfee.com Operating System Class]
  {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} 
[HouseCall Control]
  {74D05D43-3236-11D4-BDCD-00C04F9A3B61} 
[Groove Control]
  {77E32299-629F-43C6-AB77-6A1E6D7663F6} 
[Java Plug-in 1.6.0_02]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} 
[Snapfish File Upload ActiveX Control]
  {90051A81-3018-4826-8B38-DD60B6B53F9C} 
[Crucial cpcScan]
  {A90A5822-F108-45AD-8482-9BC8B12DD539} 
[a-squared Scanner]
  {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} 
[Java Plug-in 1.6.0_02]
  {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} 
[Java Plug-in 1.6.0_02]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} 
[PopCapLoader Object]
  {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} 
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} 
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} 
[Shockwave ActiveX Control]
  {233C1507-6A77-46A4-9443-F871F945D258} 
[RhapsodyPlayerEngineCtrl Class]
  {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} 
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} 
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[PaltalkWebLogin]
  {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} 
[InstallShield Update Service Agent]
  {5B7524C8-2446-40E9-9474-94A779DBA224} 
[Microsoft Shell UI Helper]
  {64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} 
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} 
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} 
[Groove Control]
  {77E32299-629F-43C6-AB77-6A1E6D7663F6} 
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2} 
[XML HTTP 4.0]
  {88D969C5-F192-11D4-A65F-0040963251E5} <%SystemRoot%\system32\MSXML4.dll, N/A>
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} 
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[Microsoft Office 12 Authorization Control]
  {C9712B19-838B-45A5-ABF2-9A315DDDED50} 
[AUDIO__MID Moniker Class]
  {CD3AFA74-B84F-48F0-9393-7EDC34128127} 
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} 
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} 
[QuickTimeCheck Class]
  {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} 
[PopCapLoader Object]
  {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} 
[Quantum Streaming IE VersionManager Class]
  {E3E02F12-2ADB-478C-8742-5F0819F9F0F4} <"C:\Documents and Settings\Joe\Application Data\Move Networks\ie_bin\qsp2ie07051001.dll", N/A>
[Quantum Streaming IE Player Class]
  {e473a65c-8087-49a3-affd-c5bc4a10669b} <"C:\Documents and Settings\Joe\Application Data\Move Networks\ie_bin\qsp2ie07051001.dll", N/A>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, N/A>
[Yahoo! Toolbar]
  {EF99BD32-C1FB-11D2-892F-0090271D4F88} 
[XML DOM Document 3.0]
  {F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>

==================================
Running Processes
[PID: 2016 / Joe][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
	[C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
	[C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
	[C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
	[C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
	[C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
	[C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
	[C:\Program Files\America Online 9.0f\idleproc.dll]  [America Online, Inc., 9.02.000]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll]  [Sun Microsystems, Inc., 8.0.0.8976]
	[C:\Program Files\OpenOffice.org 2.0\program\uwinapi.dll]  [Sun Microsystems, Inc., 8.0.0.8975]
	[C:\Program Files\OpenOffice.org 2.0\program\stlport_vc7145.dll]  [STLport Consulting, Inc., 4.5.2003.0120]
	[C:\Program Files\OpenOffice.org 2.0\program\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
[PID: 2060 / Joe][C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe]  [McAfee Security, 7.1.0.113]
	[C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
	[C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
	[C:\PROGRA~1\McAfee.com\PERSON~1\Localized.DLL]  [McAfee Security, 7.1.0.113]
	[C:\WINDOWS\system32\MPFAPI.dll]  [McAfee, 7.1.0.113]
[PID: 2084 / Joe][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2096 / Joe][C:\Program Files\HP\hpcoretech\hpcmpmgr.exe]  [Hewlett-Packard Company, 2.1.1.0]
	[C:\Program Files\HP\hpcoretech\HPVCR70.dll]  [Microsoft Corporation, 7.00.9466.0]
	[C:\WINDOWS\system32\MSXML4.dll]  [Microsoft Corporation, 4.20.9841.0]
	[C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
	[C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
[PID: 2108 / Joe][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5120]
	[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.5120]
	[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.ENU]  [ATI Technologies, Inc., 6.14.10.5120]
	[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  [ATI Technologies, Inc., 6.14.10.5120]
[PID: 2236 / Joe][C:\Program Files\America Online 9.0f\waol.exe]  [America Online, Inc., 9.02.000]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\America Online 9.0f\waol.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\supersub.dll]  [America Online, Inc., 9.02.000]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\America Online 9.0f\Xpcs.dll]  [America Online, Inc., 3.7.4.2651]
	[C:\Program Files\America Online 9.0f\Xprt3.dll]  [America Online, Inc., 3.7.4.2651]
	[C:\Program Files\America Online 9.0f\zlib.dll]  [, 1.1.4]
	[C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
	[C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
	[C:\Program Files\America Online 9.0f\xmlparse.dll]  [N/A, ]
	[C:\Program Files\America Online 9.0f\xmltok.dll]  [N/A, ]
	[C:\Program Files\America Online 9.0f\comm.dll]  [America Online, Inc., 9.02.001]
	[C:\Program Files\America Online 9.0f\Xptl.dll]  [America Online, Inc., 3.7.4.2651]
	[C:\Program Files\America Online 9.0f\manager.dll]  [America Online, Inc., 9.02.002]
	[C:\Program Files\America Online 9.0f\SYNCCORE.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\ProxyMgr.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TAI.dll]  [America Online, Inc., 1, 3, 20, 0]
	[C:\Program Files\America Online 9.0f\APPDATA.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\acfBase.DLL]  [America Online, 1, 0, 0, 1]
	[C:\Program Files\America Online 9.0f\resource.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll]  [AOL LLC, 3.3.14.1]
	[C:\Program Files\Common Files\AOL\ACS\AcsCmn.dll]  [AOL LLC, 4.7.14.1			 ]
	[C:\Program Files\America Online 9.0f\TOOL\imfdecode.rct]  [America Online, Inc., 9.02.002]
	[C:\Program Files\America Online 9.0f\TOOL\coretool.rct]  [America Online, Inc., 9.02.002]
	[C:\Program Files\America Online 9.0f\DUNZIP32.dll]  [Inner Media, Inc., 4.00.04]
	[C:\Program Files\America Online 9.0f\TOOL\mip.tol]  [America Online, Inc., 9.02.002]
	[C:\Program Files\America Online 9.0f\ABOOK.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TOOL\rich.rct]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TOOL\actvx.rct]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TOOL\sec.cct]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TOOL\chat.tol]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TOOL\htmlview.tol]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TOOL\www.tol]  [America Online, Inc., 9.02.002]
	[C:\Program Files\America Online 9.0f\TOOL\lvi.tol]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\COOLAPI.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\idleproc.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\TOOL\talk.tol]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\cool\CoolBucky.dll]  [America Online, Inc., 3.7.4.2652]
	[C:\Program Files\America Online 9.0f\cool\CoolSocket.dll]  [America Online, Inc., 3.7.4.2652]
	[C:\Program Files\America Online 9.0f\cool\CoolBos.dll]  [America Online, Inc., 3.7.4.2652]
	[C:\Program Files\America Online 9.0e\AMH.dll]  [America Online, Inc., 9.00.000]
	[C:\Program Files\America Online 9.0f\MIMEHook.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream_0305000D.dll]  [Viewpoint Corporation, 3, 5, 0, 13]
	[C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr_0305000D.dll]  [Viewpoint Corporation, 3, 5, 0, 13]
	[C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll]  [Viewpoint Corporation, 3, 5, 0, 28]
	[C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll]  [Viewpoint Corporation, 3, 2, 2, 26]
	[C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll]  [Viewpoint Corporation, 3, 4, 0, 67]
	[C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll]  [Viewpoint Corporation, 3, 2, 2, 26]
	[C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
	[C:\WINDOWS\system32\jgpl400.dll]  [Johnson-Grace Company, 054]
	[C:\WINDOWS\system32\jgdw400.dll]  [America Online, 106]
	[C:\WINDOWS\system32\IEFRAME.dll]  [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
	[C:\Program Files\America Online 9.0f\cool\CoolTih.dll]  [America Online, Inc., 3.7.4.2652]
	[C:\Program Files\America Online 9.0f\cool\CoolPeer.dll]  [America Online, Inc., 3.7.4.2652]
	[C:\Program Files\America Online 9.0f\Components\Tier2Svc.dll]  [, 1, 0, 0, 1]
	[C:\Program Files\Common Files\AOL\ACF\ActCntxt.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\Common Files\AOL\ACF\StaActvr.dll]  [America Online, Inc., 9.02.000]
	[C:\Program Files\America Online 9.0f\Components\DataSvcs.dll]  [, 1, 0, 0, 1]
	[C:\Program Files\America Online 9.0f\cool\CoolPortMagic.dll]  [America Online, Inc., 3.7.4.2652]
	[C:\Program Files\Common Files\AOL\TopSpeed\2.0\tai2.dll]  [America Online, Inc., 1, 3, 32, 0]
	[C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
	[C:\WINDOWS\system32\MSXML4.dll]  [Microsoft Corporation, 4.20.9841.0]
	[C:\Program Files\America Online 9.0e\sa.dll]  [America Online, Inc., 9.00.000]
	[C:\WINDOWS\system32\MFPlat.DLL]  [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
	[C:\WINDOWS\System32\quartz.dll]  [, ]
	[C:\WINDOWS\system32\msdmo.dll]  [, ]
	[C:\WINDOWS\system32\WMVDECOD.dll]  [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
	[C:\WINDOWS\System32\devenum.dll]  [, ]
	[C:\WINDOWS\system32\wmpeffects.dll]  [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
	[C:\WINDOWS\system32\wmpps.dll]  [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
	[C:\Program Files\Common Files\AOL\Flasha.ocx]  [Macromedia, Inc., 6,0,80,0]
	[C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 3620 / Joe][C:\Program Files\America Online 9.0f\shellmon.exe]  [America Online, Inc., 9.02.000]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 4028 / Joe][C:\Program Files\Common Files\AOL\1129442703\ee\aolsoftware.exe]  [America Online, Inc., 1.5.6.1]
	[C:\Program Files\Common Files\AOL\1129442703\ee\xprt5.dll]  [AOL LLC, 5.2.3.5014]
	[C:\Program Files\Common Files\AOL\1129442703\ee\AOLSvcMgr.dll]  [America Online, Inc., 1.5.6.1]
	[C:\Program Files\Common Files\AOL\1129442703\ee\Xprt4.dll]  [America Online, Inc., 4.3.3.4334]
	[C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll]  [AOL LLC, 3.3.14.1]
	[C:\Program Files\Common Files\AOL\1129442703\ee\AOLHostMgr.dll]  [America Online, Inc., 1.5.6.1]
	[c:\program files\common files\aol\1129442703\ee\services\os\ver5_2_1_1\OS.dll]  [AOL LLC, 5.2.1.1]
	[c:\program files\common files\aol\1129442703\ee\services\os\ver5_2_1_1\AOLIdleMon.dll]  [AOL LLC, 5.2.1.1]
	[c:\program files\common files\aol\1129442703\ee\services\basics\ver8_0_4_1\basics.dll]  [America Online, Inc., 8.0.4.1]
	[c:\program files\common files\aol\1129442703\ee\services\notification\ver6_2_6_1\Notify.dll]  [America Online, Inc., 6.2.6.1]
	[c:\program files\common files\aol\1129442703\ee\services\localStorage\ver7_1_5_2\clsSvc.dll]  [AOL LLC, 7.1.5.2]
	[c:\program files\common files\aol\1129442703\ee\services\metrics\ver3_6_15_1\cmls.dll]  [America Online, Inc., 3.6.15.1]
	[c:\program files\common files\aol\1129442703\ee\services\aolsystrayservice\ver3_0_16_1\AOLSysTrayService.dll]  [AOL LLC, 3.0.16.1]
	[c:\program files\common files\aol\1129442703\ee\services\suiteframework\ver4_1_6_1\suiteFramework.dll]  [AOL LLC., 4.1.6.1]
[PID: 2136 / Joe][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
	[C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
[PID: 1136 / Joe][C:\Documents and Settings\Joe\Desktop\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
	[C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
	[C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16473 (vista_gdr.070420-1500)]
	[C:\Program Files\America Online 9.0f\idleproc.dll]  [America Online, Inc., 9.02.000]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Documents and Settings\Joe\Desktop\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
	[C:\WINDOWS\system32\asfsipc.dll]  [Microsoft Corporation, 1.1.00.3917]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1	   localhost

==================================
Process Privileges Scan
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 2016, C:\WINDOWS\EXPLORER.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 2084, C:\WINDOWS\SYSTEM32\CTFMON.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 2096, C:\PROGRAM FILES\HP\HPCORETECH\HPCMPMGR.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 2108, C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE]

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================

There was nothing in red after the scan.
The morning update: It didn't stall upon booting up and make me use the last known good config. I hasn't shut its self off for a day now. It is slow loading webpages but other than that it is running good.
That is really good news and SREng didn't bring up too much either. ( I am over 21)

A. Please UNINSTALL the following program: Viewpoint

B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\popcinfo.dat

Folder::
C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
C:\Program Files\Viewpoint

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{360E40AA-EE8B-4101-BA67-0CAD3F7A48DD}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
Sorry I haven't gotten back to you on this problem. I have other problems in life that have taken over for the moment. Last weekend my car overheated while on the interstate with the family (infant granddaughter included) in it and now we have to either pay $3000 to get it fixed or get a new car. I have been shopping online for a new car that we can afford. Also I am reduced to driving the future son-in-laws Mitsubishi Lancer with the racing engine…….vaaaaaaaarrrrrrroooooooom! It is a stick shift and I am the only one in the house who can drive one, so guess who gets to drive everyone else around all day long? You got it! The future son-in-law drives a semi for a living so I have to be ready to pick him up at a moments notice when he gets into town…….the other night it was 3 am when he called for a ride. LOL You don't happen to have a spare oh lets say $5000 just laying around your house, do ya? LOL I am joking of course. Hopefully I will get back to the computer either tomorrow after the trucker gets home or this weekend….rest assured I haven't forgotten you. You have been extremely nice to me and I appreciate that a great deal. Nita
Real Life always seems to get in the way of fun LOL. I think you have had your share of troubles for a while. Give the lady a rest! Take care, Trevuren
I am sorry it has taken me so long to get back with you. I am still carless and forced to drive the future son-in-laws Lancer with a racing engine. LOL It's a stick shift and I am the only one other than him that knows how to drive it so I am the taxi driver for everyone.

On to the computer. I am happy to report that I am not having any of the other problems that I had before…..however….I have to reinstall my virus software again because it is missing something. Also I am trying to access a radio station in Atlanta that my friend is on but I can't listen live though my Windows Media Player. He says the "listen live" connection is working on their end.

The URL for them is: Edited for privacy by Trevuren—- then do a site search for "listen online". When I try to listen I get the following message or something close to it:

Windows media player cannot connect to the server….then something about either it's not working on their end (which they said it was) or something about my proxy settings (but I messed around with them today according to the windows help site and it still don't work.

As far as what you requested I do in the last post of instructions I will do them tomorrow during the afternoon because I have to go to the doctor in the morning. It is hot & humid here so I won't be going out after that…..I don't have any money anyway. LOL

Nita

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI