i have this computer showing a warning message at startup that says "Command is not a valid 32 bit program". when i try to use CMD to do some Pings it refuses and says "ping.com is not a valid win32 application".
i follow the guide "before posting self help" and install spybot and AVG spyware, spybot found several RED entries and i fix them, all but one of them fix with no problem, and says that after reboot will fix the last one, after that i get a lot of messages at restart, then shut it down and restart in safe mode, scan with AVGAS, found some items, when i click "Quarantine", AVGAS freeze up, have to restart.
so here is my HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 6:04:04 PM, on 1/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsCtrls.EXE
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\AVENGINE.EXE
c:\program files\panda software\panda antivirus + firewall 2007\firewall\PSHOST.EXE
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Microsoft Encarta\Encarta 2007 Biblioteca Premium\EDICT.EXE
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\panda software\panda antivirus + firewall 2007\WebProxy.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\SoftwareDistribution\Download\0a7407b49e4a15c0b9a45c0426de5360\update\update.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.condominiovistabella.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\regedit /s C:\pav.reg,C:\WINDOWS\system32\pavdr.exe,C:\WINDOWS\system32\userinit.exe,
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Complemento del Asistente para Internet de Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O2 - BHO: (no name) - {E2C2208B-CC1F-E995-3E8C-E77B47F978E2} - (no file)
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - (no file)
O3 - Toolbar: Asistente para Internet de Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [E07EDXRC_2172546] "C:\Program Files\Microsoft Encarta\Encarta 2007 Biblioteca Premium\EDICT.EXE" -m
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD4261] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFD341.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9455] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB543.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9368] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB4D.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6528] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB543.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2323] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB4D.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2724] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB10C.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3612] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB10C.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3031] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB0BB.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6464] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DFB0BB.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6665] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF9E6A.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9496] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF9E6A.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4040] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF9E14.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7799] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF9E14.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3942] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF8C61.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD120] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF8C61.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5644] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF6B25.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7353] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF6B25.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7044] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF60E5.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5142] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF60E5.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7542] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF5E7.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD408] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF5E7.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6670] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF5AEF.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7718] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF44DB.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB426] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF3541.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD642] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF3541.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3420] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF31F2.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3115] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF31F2.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB679] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF2E0D.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8529] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF2E0D.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7487] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF2310.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3452] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF2310.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3647] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF140F.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1115] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF140F.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB21] command /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF1302.tmp_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6448] cmd /c del "C:\Documents and Settings\NI\Local Settings\Temp\~DF1302.tmp_tobedeleted"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Barra de búsqueda de Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\System32\CTsvcCDA.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsCtrls.EXE
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda software\panda antivirus + firewall 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
also want to add that Windows XP stop updating, has a lot of updates that already downloaded but when i try to install them, they fail.
Thanks in advance for any help/reply… will keep looking for reply tomorrow.
Enrique Guillen R.
Guatemala