This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Troubled with computer problems

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My taskbar/screen problem has been acting up too, and the clock went back to the time ComboFix adjusted it to.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:06, on 2-27-2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.homestarrunner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [System Mechanic Popup Blocker] "C:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsyx.html

–
End of file - 9152 bytes



Adobe Flash Player ActiveX
Adobe Reader 6.0
Any Video Converter 2.0.7
Apple Software Update
Authentium AntiVirus SDK - 2
AVG 7.5
CCleaner (remove only)
Easy Internet Sign-up
GIMP 2.4.4
HijackThis 2.0.2
HP Deskjet Preloaded Printer Drivers
HP Instant Support
HP Photo & Imaging 3.0
HP Photo and Imaging 2.0 - Photosmart Cameras
HP Software Update
HPImageZone
Intel® Extreme Graphics Driver
IntelliMover Data Transfer Demo
iolo AntiVirus
iolo Personal Firewall
iolo technologies' System Mechanic Professional 7
iTunes
Java 2 Runtime Environment, SE v1.4.1_02
Java Web Start
Kaspersky Online Scanner
KBD
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft Visual J# .NET Redistributable Package 1.1
Microsoft Works 7.0
NVIDIA Gart Driver
NVIDIA Windows 2000/XP Display Drivers
OmniPass
PC-Doctor for Windows
Photosmart 140,240,7200,7600,7700,7900 Series
PowerDVD
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
QuickTime
RecordNow!
S3Display
S3Gamma2
S3Info2
S3Overlay
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB912919)
Skype™ 3.5
Sonic Update Manager
Spybot - Search & Destroy
toolkit
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB910437)
Updates from HP
Weblink
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB824146
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB918899
Windows XP Hotfix - KB925486
Windows XP Hotfix (SP2) [See q329256 for more information]
Windows XP Hotfix (SP2) Q327979
Windows XP Hotfix (SP2) Q329112
Windows XP Hotfix (SP2) Q329909
Windows XP Hotfix (SP2) Q331958
Windows XP Hotfix (SP2) Q811789
Yahoo! Install Manager
Yahoo! Messenger
Ok we still have 2 anti Virus programs running,.
We need to uninstall one of them.

Either uninstall

Authentium AntiVirus SDK - 2

or

AVG 7.5

___________________________

I see your still only running service pack 1.
Microsoft quit supporting that service pack back in october.
You need to visit.
http://www.update.microsoft.com/windowsupd…mp;thankspage=5

And update to service pack 2.
This update contains many security updates along with fixes.
You can not recieve updates with only service pack 1 installed.

____________________________


Let's see what combo fix sees.


1. Download Combo fix from one of these locations. ( Please save it to your desktop )
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe


combofix.exe

2.Close all open windows
3. Double click combofix.exe & follow the prompts.
4. When finished, it shall produce a log for you. Post that log in your next reply . (c:\comboFix.txt)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combo fix in order to be effecient is going to disconect you from the internet. If when it is done and you can't get back on the internet just restart the computer.


_________________________________________

You have a line in your log :

O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsyx.html

Do you know what that file is ?





_________________________
In your next reply I would like to see:
  • The report from ComboFix
  • Do you know what that file is I asked about
  • What exactly is Microsofts works doing wrong ?
Authentium AntiVirus SDK 2 is related to iolo antivirus. I tried removing it, but it will neither remove. While AVG 7.5 is one of the most productive antivirus programs I've come acrossed, I don't want to have to rid of that one.

C:\Program Files\ComPlus Applications\profsyx.html is not located on my computer. The folder "ComPlus Applications" doesn't exist. I don't know what it is, nor am I able to find it on my computer.

Microsoft Word isn't allowing text to be typed. I can try to type on Microsoft Word but nothing will happen. As I reported before, it was functioning correctly after everything appeared to be fixed, but it randomly acted up yesterday, along with my computer screen freezing and some other programs not functioning too.

Here's the ComboFix log file:


ComboFix 08-02-25.3 - Owner 2008-02-28 1:14:29.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.

2008-02-27 23:40 . 2008-02-27 23:40 d——– C:\WINDOWS\LastGood
2008-02-21 19:28 . 2008-02-21 19:28 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-21 19:28 . 2008-02-21 19:28 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-21 19:19 . 2008-02-21 19:19 d——– C:\Program Files\CCleaner
2008-02-21 19:18 . 2008-02-21 19:18 671,968 –a—— C:\Program Files\ccsetup205_slim.exe
2008-02-21 04:57 . 2008-02-21 04:57 d——– C:\Documents and Settings\Owner\.thumbnails
2008-02-21 04:55 . 2008-02-27 17:28 d——– C:\Documents and Settings\Owner\.gimp-2.4
2008-02-21 04:52 . 2008-02-21 04:52 d——– C:\Program Files\GIMP-2.0
2008-02-21 04:51 . 2008-02-21 04:51 16,865,248 –a—— C:\Program Files\gimp-2.4.4-i686-setup.exe
2008-02-18 17:22 . 2008-02-18 17:22 d——– C:\Program Files\Trend Micro
2008-02-18 17:22 . 2008-02-18 17:22 812,344 –a—— C:\Program Files\HJTInstall.exe
2008-02-18 13:35 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-02-18 13:35 . 2007-07-30 19:19 207,736 –a—— C:\WINDOWS\system32\muweb.dll
2008-02-10 13:09 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-02-08 21:28 . 2008-02-27 17:15 d——– C:\Documents and Settings\Owner\Application Data\gtk-2.0

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-27 20:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\AVG7
2008-02-10 19:38 ——— d—–w C:\Program Files\Microsoft Works
2008-02-09 10:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\iolo
2008-01-27 02:01 ——— d—–w C:\Program Files\Pinnacle
2008-01-16 06:16 132,608 —-a-w C:\Program Files\VundoFix.exe
2008-01-15 09:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-15 04:43 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-15 03:21 ——— d—–w C:\Documents and Settings\NetworkService\Application Data\AVG7
2008-01-15 03:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-15 02:31 32,981,120 —-a-w C:\Program Files\avg75free_516a1225.exe
2008-01-13 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 10:55 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-01-13 10:51 7,467,056 —-a-w C:\Program Files\spybotsd15.exe
2008-01-13 04:26 ——— d—–w C:\Documents and Settings\Owner\Application Data\Skype
2007-12-29 08:36 ——— d—–w C:\Program Files\Sonic RecordNow!
2007-12-29 08:36 ——— d—–w C:\Program Files\RecordNow!
2007-12-29 08:36 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2007-12-29 08:36 ——— d—–w C:\Program Files\Common Files\Sonic
2007-11-10 03:25 23,876,904 —-a-w C:\Program Files\SkypeSetup.exe
2007-10-17 03:43 436,360 —-a-w C:\Program Files\msgr8us.exe
2007-08-21 03:33 13,749,450 —-a-w C:\Program Files\any-video-converter-free.exe
2007-08-06 09:18 357,424 —-a-w C:\Program Files\msicuu2.exe
2007-08-06 08:50 50,005,304 —-a-w C:\Program Files\iTunesSetup.exe
2007-06-23 18:47 491,120 —-a-w C:\Program Files\ioloav_dm.exe
2007-02-12 08:21 480,368 —-a-w C:\Program Files\iolofw_dm.exe
2007-01-31 10:27 12,754,672 —-a-w C:\Program Files\MP10Setup.exe
2005-07-29 22:24 472 –sha-r C:\WINDOWS\UmFuZHkgUmFnYW4\oAIRtJ40oAIBsqb.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 22:25 24576]
"NVIEW"="nview.dll" [2003-05-03 00:19 835654 C:\WINDOWS\system32\nview.dll]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2002-07-17 19:00 200767]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe" [2007-11-03 11:45 820072]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 16:43 4670704]
"System Mechanic Popup Blocker"="C:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe" [2007-11-03 11:45 641384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51 118784]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 08:23 90112]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-14 00:53 49152]
"HPHUPD05"="c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 04:03 49152]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 03:55 483328]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 21:02 61440]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 09:01 155648]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 22:42 212992]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-05-03 00:19 4640768]
"nwiz"="nwiz.exe" [2003-05-03 00:19 323584 C:\WINDOWS\system32\nwiz.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 17:57 81920]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe" [2007-11-03 11:45 820072]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-27 19:14 271672]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24 286720]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-14 21:20 579072]
"iolo Personal Firewall"="C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe" [2007-11-03 11:23 1471328]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55 155648]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2006-01-23 15:42 196608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SMRequiresRestart"="" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-14 21:21 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-06-13 05:08:16 233472]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\ComPlus Applications\profsyx.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

R0 XPacket;iolo Personal Firewall Driver;C:\WINDOWS\System32\xpacket.sys [2007-05-18 15:08]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 19:41:19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 01:19:22
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll

PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.1106]
-> C:\WINDOWS\System32\iavlsp.dll
.
Completion time: 2008-02-28 1:21:44
ComboFix2.txt 2008-02-20 23:07:32
.
2008-01-27 03:00:21 — E O F —
______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsyx.html

Close that.



_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\UmFuZHkgUmFnYW4\oAIRtJ40oAIBsqb.vbs


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html





Next
__________________________________

Open note pad and copy the text in the box exactly to notepad.


Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"=-

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"FriendlyName"="My Current Home Page"

Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.



Then click on the FILE menu and select save as
Save the file as regfix.reg. Save the file to the desktop.
IMPORTANT: make sure to save the file as "all types" and NOT as a text file.

Now double click the file on the desktop
When asked if you want this to merge with the registry.
Click YES! ou may delete that file now.

___________________________________________


1 - Event Viewer
Go to Start > Settings > Control Panel > Administrative Tools > Event Viewer
Look in the Application and System logs for errors (signified by a red circle with a white cross) that coincide with the time of the problem. Try to sort through the times for me.
Double-click each of these error symbols to reveal more information.
Post back with the Event ID number(s) and Source information.

___________________________________________

Sometimes malware can effect some programs although I haven't seen any evidence of it in your logs.
A quick and simple fix may be to try and reinstall Microsoft word.



Next reply I need to see,

The event log

The report from Jottis.

Let me know if you were able to reinstall Microsoft word.
Deleting O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsyx.html caused my desktop wallpaper/background to vanish. Jottis report: File: oAIRtJ40oAIBsqb.vbs_ Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: 387edbb90a5275d1b464eb31f3162c40 Packers detected: - Bit9 reports: Low threat detected (more info) Scanner results Scan taken on 29 Feb 2008 00:41:47 (GMT) A-Squared Found nothing AntiVir Found ADSPY/Isearch ArcaVir Found nothing Avast Found VBS:Malware-gen AVG Antivirus Found nothing BitDefender Found Adware.Isearch.D ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found Adware/Isearch Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found VBS/CommAd.A Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing The time of these problems happened in-between Monday night and early Tuesday. (anywhere from 11 PM to 5 AM) I wasn't on my computer the whole time but when I came back to it, I noticed the freezing because I had to use ctrl+alt+delete to unfreeze it, and Microsoft word suddenly stopped working when I was just using it hours prior to returning to my computer. Also another program, GIMP, which was working perfectly fine after you helped me the first time, wouldn't work correctly either. But anyways, here's some logs in-between that time frame: System: Event Source: SideBySide Event ID: 59 Date: 2-26-2008 Time: 0:16 (*this error kept reoccuring every few minutes*) Event Source: Service Control Manager Event ID: 7026 Date: 2-26-2008 Time: 0:42 Event Source: Service Control Manager Event ID: 7022 Date: 2-26-2008 Time: 0:42 Event Source: Srv Event ID: 2019 Date: 2-26-2008 Time: 2:41 (*that was probably around, or close to, the time i noticed it*) Application: Event Source: Application Hang Event ID: 1002 Date: 2-26-2008 Time: 2:52 (*this is when GIMP started messing up*) Event Source: Application Error Event ID: 1000 Date: 2-26-2008 Time: 4:52 The Srv time and the time GIMP started messing up is rather close. As for reinstalling Microsoft word, I don't think that's going to solve the issue. Seeing how it's effecting just other programs aside from that, such as GIMP.
Open HJT click on
config…
Then click on backups

Place a tick by O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsyx.html

and choose restore.
This will place this/these back where they were originally


___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.



___________________________________
Search for and remove
Now I want you to search for and delete the following folder and all it's contents if present. If you need help finding them.
Click start /search/ all files and folders/ look for More advanced options. once in there select the first 3 boxes.
Please just remove the files/folders I listed in BOLD



C:\WINDOWS\UmFuZHkgUmFnYW4\oAIRtJ40oAIBsqb.vbs


_____________________________________

I've done some research for you on your errors: The firast thing in 2 of them is to update both windows and office (word).

Event Source: SideBySide
Event ID: 59

The first thing they want you to do in their instructions is to install service pack 2 for windows from :
http://www.microsoft.com/windowsxp/sp2/how.mspx

Can you do this ?

http://www.microsoft.com/downloads/details…en#Instructions


___________________________________

Event Source: Service Control Manager
Event ID: 7022
Date: 2-26-2008
Time: 0:42

http://support.microsoft.com/kb/319127



click start/run and copy this in exactly.

regedit /e desktop\spooler.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler"

This will place a notepad file on your desktop called spooler.txt.
Open that and copy the contenets in your next reply for me.



____________________________________


Application:
Event Source: Application Hang
Event ID: 1002
Date: 2-26-2008
Time: 2:52
(*this is when GIMP started messing up*)

For this one SP2 for office seems to have fixed it for a few.

http://www.microsoft.com/downloads/details…;DisplayLang=en


_______________________________________

As you can see running an unpatched version of windows and office has many other drawbacks besides security issues.

Please get windows and office updated if you can and post back letting mer know what you were able to update.
My desktop wallpaper returned after restart, I don't think it had any effect on it really, so I didn't restore. Unless you think it's vital to do so. I successfully deleted oAIRtJ40oAIBsqb.vbs I updated to Windows service pack 2 successfully, but this didn't erase any of the problems. I've yet to install Microsoft Visual C++ 2005 Redistributable Package and Office 2003 Service Pack 2. Again, unless you think it's vital to do so. and here's the spooler.txt contents: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler] "DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00 "Description"="Loads files to memory for later printing." "DisplayName"="Print Spooler" "ErrorControl"=dword:00000001 "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,e8,47,0c,\ 00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00 "Group"="SpoolerGroup" "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,70,00,6f,00,6f,00,6c,00,73,00,76,00,2e,00,65,00,78,00,65,00,00,00 "ObjectName"="LocalSystem" "Start"=dword:00000002 "Type"=dword:00000110 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Performance] "Close"="PerfClose" "Collect"="PerfCollect" "Collect Timeout"=dword:000007d0 "Library"="winspool.drv" "Object List"="1450" "Open"="PerfOpen" "Open Timeout"=dword:00000fa0 "WbemAdapFileSignature"=hex:12,6c,5c,67,9c,9d,52,12,37,ca,57,4b,78,a2,8d,55 "WbemAdapFileTime"=hex:60,2f,ad,8e,ab,7d,c3,01 "WbemAdapFileSize"=dword:00020400 "WbemAdapStatus"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Security] "Security"=hex:01,00,14,80,78,00,00,00,84,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,48,00,03,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\ 05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ 20,02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,\ 01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Enum] "0"="Root\\LEGACY_SPOOLER\\0000" "Count"=dword:00000001 "NextInstance"=dword:00000001
EDIT Do not replace the 024 line as long as your desktop has reappeared.


As is my limited knowledge to work on removing Malware I'm not 100 % convinced your issue is malware.
But I will continue looking until I am 110% sure it isn't.

I do believe it is important you install Service pack 2 for office from

http://www.microsoft.com/downloads/details…;DisplayLang=en

I know your thinking you have gotten by this far without it. But in researching your issue this seems to have cleared it for a few people.

__________________________
Deckard's System Scanner
Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply

___________________________

Please post :The reports from Deckards system scanner.
It wouldn't install service pack 2 for office, it said the known file type or something could not be found on my computer.


Deckard's System Scanner v20071014.68
Run by [removed] on 2008-02-29 21:13:58
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
43: 2008-03-01 03:14:19 UTC - RP43 - Deckard's System Scanner Restore Point
42: 2008-03-01 00:46:05 UTC - RP42 - Installed Windows XP Service Pack 2.
41: 2008-03-01 00:26:52 UTC - RP41 - Software Distribution Service 3.0
40: 2008-02-29 23:42:20 UTC - RP40 - Installed Windows XP KB917422.
39: 2008-02-29 23:41:28 UTC - RP39 - Installed Windows XP KB921883.


– First Restore Point –
1: 2008-02-26 00:30:26 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 247 MiB (512 MiB recommended).


– HijackThis (run as Owner.exe) ———————————————–

logfile has no content; running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-29 21:15:25
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
C:\Program Files\Softex\OmniPass\omniServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\alg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system\hpsysdrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd.exe
C:\WINDOWS\system32\hphmon05.exe
C:\hp\KBD\kbd.exe
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.homestarrunner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [System Mechanic Popup Blocker] "C:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll
O10 - Unknown file in Winsock LSP: C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\iavlsp.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O18 - Protocol: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: dvpapi - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional 7\IoloSGCtrl.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\omniServ.exe


–
End of file - 8997 bytes

– HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ———–

backup-20080219-193631-115 O2 - BHO: (no name) - {ADC9012A-9E83-4F28-9594-42AFE97959FD} - C:\WINDOWS\System32\mljgf.dll (file missing)
backup-20080219-193631-247 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
backup-20080219-193631-293 O2 - BHO: (no name) - {844F5BD9-6B7E-49B9-90F2-931590FC7558} - C:\WINDOWS\System32\ssqpn.dll (file missing)
backup-20080219-193631-382 O2 - BHO: (no name) - {D4576C73-52BD-4401-B966-5A128C4433D4} - C:\WINDOWS\System32\vturpqo.dll (file missing)
backup-20080219-193631-493 O4 - HKLM\..\Run: [ac139351] rundll32.exe "C:\WINDOWS\System32\jufcjcuu.dll",b
backup-20080219-193631-552 O2 - BHO: (no name) - {13D2E5C1-36B3-40BA-BAA1-D205BBCA011E} - C:\WINDOWS\System32\pmkjg.dll (file missing)
backup-20080219-193631-581 O2 - BHO: (no name) - {E3AFDE3A-64F7-695C-DE28-48E603F30FB6} - C:\WINDOWS\System32\ivdxae.dll
backup-20080219-193631-947 O2 - BHO: (no name) - {54469524-22B0-2812-C149-5E07E2D4ECEB} - C:\WINDOWS\System32\ebam.dll (file missing)
backup-20080219-193631-968 O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
backup-20080219-193631-992 R3 - URLSearchHook: (no name) - {54469524-22B0-2812-C149-5E07E2D4ECEB} - C:\WINDOWS\System32\ebam.dll (file missing)
backup-20080219-193632-147 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
backup-20080219-193632-982 O20 - Winlogon Notify: vturpqo - vturpqo.dll (file missing)
backup-20080228-183854-645 O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsyx.html

– File Associations ———————————————————–

.js - JSFile - shell\open\command - NOTEPAD.EXE %1
.reg - regfile - shell\open\command - NOTEPAD.EXE %1
.scr - scrfile - shell\open\command - NOTEPAD.EXE %1
.vbs - VBSFile - shell\open\command - NOTEPAD.EXE %1


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 XPacket (iolo Personal Firewall Driver) - c:\windows\system32\xpacket.sys
One small issue I see. I also see that your running 248 MB of memory where as at least double that is recommended. I know once again your thinking it has ran fine like this for a while. I am thinking all of a sudden you have placed a strain on the machine that is causing slow downs.
I am going to ask some other experts to take a look to be certain I haven't missed anything just to be sure. :thumbup:



________________________
Click start > Run > in the empty edit box copy&paste this line :

"%userprofile%\desktop\dss.exe" /daft

Read the disclaimer and click OK.
  • Click on the Scan button.
  • Place a checkmark next to the following entries in case they appear:

.bat
.cmd
.inf
.ini
.reg
.txt
.vbs
  • Click the Fix button.
  • Re-scan and save a logfile. By default, it will save as daft.txt
  • I'll need that log later.
If everything is ok again, it should display the "all associations ok message"

Post back with the contents of daft.txt.
DAFT Log saved on 2008-02-29 21:58:54 ———————————————————————– .js - JSFile - shell\open\command - NOTEPAD.EXE %1 .scr - scrfile - shell\open\command - NOTEPAD.EXE %1
I would also like to know the exact error your receiving when trying to update office. This may require that you try to install it again. Get to the error and write it down exactly as is.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI