businessman
Topic Starter
Hello! I so hope you guys can help me
I'm pretty knowledgeable about PCs and my PC in particular, its a custom build one I built back in February of this year
Lately, as of 3 days prior to this post, I seem to be having a strange problem with my browsers, JUST my browsers, I think…
Like some of the other posts I read on this forum (which is I'm posting here), my IE and Firefox started getting these strange popups from random search sites and dating services. Stuff like yellowpages.com, fling.com, fubar.com, travel services, and other stuff. It's always the same 6-8 sites over and over. this is one of the addresses I saw:
Link to redirection removed: LDT
I noticed the 85.12.43.xx is always the same with the last 2 numbers changing depending on the popup. Also, at random, sites I go to have these antivirus ads in place of gifs and pics on the pages, esp. on my bookmarked pages, sites where I know a certain image or link should be will be filled with these offers to inspect for viruses.
Now, this is cool, cause I ran everything I have on my computer. I have AVG 8.0, Lavasoft AdAware, just recently downloaded Avira antivirus to try that (after the first 2 were used), defragmented, disk checker and all the regular cookie and temp file cleaning. Funny part is my comp is running really smooth, it was already ok, but its extra buttery
Now here's where I'm lost. I have a multi boot system with 2 500 gig Sata hard drives. The first drive has a evenly split partition with 250 gigs of partition for my Windows XP 64 bit, 250 gigs on partition has Windows Vista Ultimate, and the second hard drive has Windows XP Pro alone. I use the first hard drive for hardcore media applications (XP 64) and multimedia thru Windows media center (Vista), meaning I rarely pop on those unless I need to do something specific. I mainly use the 2nd hard drive, which is all my files I transferred from the first, with the XP Pro cause that was my original OS before I got the other 2. All my software is on there.
Getting back to the issue, been running these scans for the last 2 days with all options checked, full system scans. Each program found a problem here or there, and I quarantined deleted anything each one found each time. Right now I'm on my Vista desktop posting because for some strange reason My browsers on XP Pro don't work. I've tried deleting and redownloading the browsers but they still stall. It's bad to the point where my own bookmarks won't even load. I tried searching the same sites on my other 2 desktops and they have no problem. Funny thing is, like I said, I'm on my Vista right now cause this very forum won't even access on XP Pro. BUT, some of my bookmarks still work. I tried testing my connection, unplugging my router and turning off my modem for a while to reset mt IP, but still the same stalling. Also, after running the scans, I unplugged my router to see if the problem continued, and sure enough, IE keeps trying to connect to addresses like the one above offline, popping up at random. I see the same addresses trying to connect each time.
OH, IT GETS BETTER!
I came to the forum and read up on the Hijackthis tool and Malwarebytes software.
When I ran the hijack tool and hit analyze, IT FREEZES
When I run Malwarebytes on quick scan IT FREEZES
I cant run those 2 programs for some reason. I could however use the ATF cleaner and I did get the inital logfile and startup list file from XP Pro though:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:12:44 PM, on 7/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\brsvc01a.exe
G:\WINDOWS\system32\brss01a.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\RUNDLL32.EXE
G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
G:\WINDOWS\system32\Rundll32.exe
G:\Program Files\PowerISO\PWRISOVM.EXE
G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
G:\Program Files\Common Files\Real\Update_OB\realsched.exe
G:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\WINDOWS\system32\Rundll32.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Windows Media Player\WMPNSCFG.exe
G:\Program Files\Real\RealPlayer\RealPlay.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Digidesign\Drivers\MMERefresh.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\Firefox Files\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
O2 - BHO: (no name) - {3A1E046A-67FE-4364-A2E0-83B6633DDBCE} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {B4977567-6B39-4AFA-9CD2-47A20209F5FE} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [PWRISOVM.EXE] G:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "G:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DigidesignMMERefresh] G:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [XboxStat] "g:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BM0f3a5b64] Rundll32.exe "G:\WINDOWS\system32\aweiooxg.dll",s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] G:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://G:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://G:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://G:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://G:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: hgGvutSI - hgGvutSI.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - G:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - G:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - G:\WINDOWS\system32\Brmfrmps.exe (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - G:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - G:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - G:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe
–
End of file - 7196 bytes
________________________________________________________________________________
____________________________________________________
StartupList report, 7/20/2008, 2:18:18 PM
StartupList version: 1.52.2
Started from : G:\Firefox Files\HiJackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16674)
* Using default options
==================================================
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\brsvc01a.exe
G:\WINDOWS\system32\brss01a.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\RUNDLL32.EXE
G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
G:\WINDOWS\system32\Rundll32.exe
G:\Program Files\PowerISO\PWRISOVM.EXE
G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
G:\Program Files\Common Files\Real\Update_OB\realsched.exe
G:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\WINDOWS\system32\Rundll32.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Windows Media Player\WMPNSCFG.exe
G:\Program Files\Real\RealPlayer\RealPlay.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Digidesign\Drivers\MMERefresh.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\WINDOWS\system32\dumprep.exe
G:\WINDOWS\system32\dwwin.exe
G:\WINDOWS\system32\dumprep.exe
G:\WINDOWS\system32\dwwin.exe
G:\Firefox Files\HiJackThis.exe
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = G:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
M-Audio Taskbar Icon = G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
P17Helper = Rundll32 P17.dll,P17Helper
PWRISOVM.EXE = G:\Program Files\PowerISO\PWRISOVM.EXE
QuickTime Task = "G:\Program Files\QuickTime\QTTask.exe" -atboottime
GrooveMonitor = "G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
Adobe Reader Speed Launcher = "G:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
SunJavaUpdateSched = "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
TkBellExe = "G:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
DigidesignMMERefresh = G:\Program Files\Digidesign\Drivers\MMERefresh.exe
XboxStat = "g:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
iTunesHelper = "G:\Program Files\iTunes\iTunesHelper.exe"
BM0f3a5b64 = Rundll32.exe "G:\WINDOWS\system32\aweiooxg.dll",s
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
ctfmon.exe = G:\WINDOWS\system32\ctfmon.exe
WMPNSCFG = G:\Program Files\Windows Media Player\WMPNSCFG.exe
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
=
————————————————–
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" %*
————————————————–
Shell & screensaver key from G:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=G:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Browser Helper Objects:
BitComet ClickCapture - G:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
(no name) - (no file) - {3A1E046A-67FE-4364-A2E0-83B6633DDBCE}
(no name) - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - (no file) - {B4977567-6B39-4AFA-9CD2-47A20209F5FE}
————————————————–
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
————————————————–
Enumerating Download Program Files:
[Java Plug-in 1.6.0_07]
InProcServer32 = G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
CODEBASE = http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
————————————————–
Enumerating Winsock LSP files:
NameSpace #4: G:\Program Files\Bonjour\mdnsNSP.dll
————————————————–
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: G:\Documents and Settings\Jammer\Local Settings\temp\FW1.htm||G:\Documents and Settings\Jammer\Local Settings\temp\ose00000.exe||G:\Documents and Settings\Jammer\Local Settings\temp\FW1.htm||G:\Documents and Settings\Jammer\Local Settings\temp\ose00000.exe
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: G:\WINDOWS\system32\SHELL32.dll
CDBurn: G:\WINDOWS\system32\SHELL32.dll
WebCheck: G:\WINDOWS\system32\webcheck.dll
SysTray: G:\WINDOWS\system32\stobject.dll
WPDShServiceObj: G:\WINDOWS\system32\WPDShServiceObj.dll
————————————————–
End of report, 6,873 bytes
Report generated in 0.016 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
________________________________________________________________________________
___________________________________________________
Sorry to add so much, just trying to be thorough. SInce its online help I want to get as much right the FIRST time as possible so you can proceed with the most info
All my updates on all 3 desktops are up to date, even the scanning programs are up to date, esp. since I've been using them. I just dont understand why the browsers alone dont work. OH, I tried one more test, I have some online games I play, while playing them during this issue I have had no interrupts in connection. My connection doesnt drop like some peoples, it doesnt restart my comp on its own or anything, it just prevents me from searching ANYTHING thru IE or firefox. half my bookmarks and anything I type in the search or address bars just freezes, and i cant fully run the 2 programs provided by this site for some strange reason.
Please if you have any further ideas or solutions, post back as soon as you can
Thank you!!!
I'm pretty knowledgeable about PCs and my PC in particular, its a custom build one I built back in February of this year
Lately, as of 3 days prior to this post, I seem to be having a strange problem with my browsers, JUST my browsers, I think…
Like some of the other posts I read on this forum (which is I'm posting here), my IE and Firefox started getting these strange popups from random search sites and dating services. Stuff like yellowpages.com, fling.com, fubar.com, travel services, and other stuff. It's always the same 6-8 sites over and over. this is one of the addresses I saw:
Link to redirection removed: LDT
I noticed the 85.12.43.xx is always the same with the last 2 numbers changing depending on the popup. Also, at random, sites I go to have these antivirus ads in place of gifs and pics on the pages, esp. on my bookmarked pages, sites where I know a certain image or link should be will be filled with these offers to inspect for viruses.
Now, this is cool, cause I ran everything I have on my computer. I have AVG 8.0, Lavasoft AdAware, just recently downloaded Avira antivirus to try that (after the first 2 were used), defragmented, disk checker and all the regular cookie and temp file cleaning. Funny part is my comp is running really smooth, it was already ok, but its extra buttery
Now here's where I'm lost. I have a multi boot system with 2 500 gig Sata hard drives. The first drive has a evenly split partition with 250 gigs of partition for my Windows XP 64 bit, 250 gigs on partition has Windows Vista Ultimate, and the second hard drive has Windows XP Pro alone. I use the first hard drive for hardcore media applications (XP 64) and multimedia thru Windows media center (Vista), meaning I rarely pop on those unless I need to do something specific. I mainly use the 2nd hard drive, which is all my files I transferred from the first, with the XP Pro cause that was my original OS before I got the other 2. All my software is on there.
Getting back to the issue, been running these scans for the last 2 days with all options checked, full system scans. Each program found a problem here or there, and I quarantined deleted anything each one found each time. Right now I'm on my Vista desktop posting because for some strange reason My browsers on XP Pro don't work. I've tried deleting and redownloading the browsers but they still stall. It's bad to the point where my own bookmarks won't even load. I tried searching the same sites on my other 2 desktops and they have no problem. Funny thing is, like I said, I'm on my Vista right now cause this very forum won't even access on XP Pro. BUT, some of my bookmarks still work. I tried testing my connection, unplugging my router and turning off my modem for a while to reset mt IP, but still the same stalling. Also, after running the scans, I unplugged my router to see if the problem continued, and sure enough, IE keeps trying to connect to addresses like the one above offline, popping up at random. I see the same addresses trying to connect each time.
OH, IT GETS BETTER!
I came to the forum and read up on the Hijackthis tool and Malwarebytes software.
When I ran the hijack tool and hit analyze, IT FREEZES
When I run Malwarebytes on quick scan IT FREEZES
I cant run those 2 programs for some reason. I could however use the ATF cleaner and I did get the inital logfile and startup list file from XP Pro though:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:12:44 PM, on 7/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\brsvc01a.exe
G:\WINDOWS\system32\brss01a.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\RUNDLL32.EXE
G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
G:\WINDOWS\system32\Rundll32.exe
G:\Program Files\PowerISO\PWRISOVM.EXE
G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
G:\Program Files\Common Files\Real\Update_OB\realsched.exe
G:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\WINDOWS\system32\Rundll32.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Windows Media Player\WMPNSCFG.exe
G:\Program Files\Real\RealPlayer\RealPlay.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Digidesign\Drivers\MMERefresh.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\Firefox Files\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
O2 - BHO: (no name) - {3A1E046A-67FE-4364-A2E0-83B6633DDBCE} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {B4977567-6B39-4AFA-9CD2-47A20209F5FE} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [PWRISOVM.EXE] G:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "G:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DigidesignMMERefresh] G:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [XboxStat] "g:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BM0f3a5b64] Rundll32.exe "G:\WINDOWS\system32\aweiooxg.dll",s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] G:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://G:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://G:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://G:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://G:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: hgGvutSI - hgGvutSI.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - G:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - G:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - G:\WINDOWS\system32\Brmfrmps.exe (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - G:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - G:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - G:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe
–
End of file - 7196 bytes
________________________________________________________________________________
____________________________________________________
StartupList report, 7/20/2008, 2:18:18 PM
StartupList version: 1.52.2
Started from : G:\Firefox Files\HiJackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16674)
* Using default options
==================================================
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\brsvc01a.exe
G:\WINDOWS\system32\brss01a.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\RUNDLL32.EXE
G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
G:\WINDOWS\system32\Rundll32.exe
G:\Program Files\PowerISO\PWRISOVM.EXE
G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
G:\Program Files\Common Files\Real\Update_OB\realsched.exe
G:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\WINDOWS\system32\Rundll32.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Windows Media Player\WMPNSCFG.exe
G:\Program Files\Real\RealPlayer\RealPlay.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Digidesign\Drivers\MMERefresh.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\WINDOWS\system32\dumprep.exe
G:\WINDOWS\system32\dwwin.exe
G:\WINDOWS\system32\dumprep.exe
G:\WINDOWS\system32\dwwin.exe
G:\Firefox Files\HiJackThis.exe
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = G:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
M-Audio Taskbar Icon = G:\WINDOWS\System32\M-AudioTaskBarIcon.exe
P17Helper = Rundll32 P17.dll,P17Helper
PWRISOVM.EXE = G:\Program Files\PowerISO\PWRISOVM.EXE
QuickTime Task = "G:\Program Files\QuickTime\QTTask.exe" -atboottime
GrooveMonitor = "G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
Adobe Reader Speed Launcher = "G:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
SunJavaUpdateSched = "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
TkBellExe = "G:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
DigidesignMMERefresh = G:\Program Files\Digidesign\Drivers\MMERefresh.exe
XboxStat = "g:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
iTunesHelper = "G:\Program Files\iTunes\iTunesHelper.exe"
BM0f3a5b64 = Rundll32.exe "G:\WINDOWS\system32\aweiooxg.dll",s
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
ctfmon.exe = G:\WINDOWS\system32\ctfmon.exe
WMPNSCFG = G:\Program Files\Windows Media Player\WMPNSCFG.exe
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
=
————————————————–
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" %*
————————————————–
Shell & screensaver key from G:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=G:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Browser Helper Objects:
BitComet ClickCapture - G:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
(no name) - (no file) - {3A1E046A-67FE-4364-A2E0-83B6633DDBCE}
(no name) - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - (no file) - {B4977567-6B39-4AFA-9CD2-47A20209F5FE}
————————————————–
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
————————————————–
Enumerating Download Program Files:
[Java Plug-in 1.6.0_07]
InProcServer32 = G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
CODEBASE = http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
————————————————–
Enumerating Winsock LSP files:
NameSpace #4: G:\Program Files\Bonjour\mdnsNSP.dll
————————————————–
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: G:\Documents and Settings\Jammer\Local Settings\temp\FW1.htm||G:\Documents and Settings\Jammer\Local Settings\temp\ose00000.exe||G:\Documents and Settings\Jammer\Local Settings\temp\FW1.htm||G:\Documents and Settings\Jammer\Local Settings\temp\ose00000.exe
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: G:\WINDOWS\system32\SHELL32.dll
CDBurn: G:\WINDOWS\system32\SHELL32.dll
WebCheck: G:\WINDOWS\system32\webcheck.dll
SysTray: G:\WINDOWS\system32\stobject.dll
WPDShServiceObj: G:\WINDOWS\system32\WPDShServiceObj.dll
————————————————–
End of report, 6,873 bytes
Report generated in 0.016 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
________________________________________________________________________________
___________________________________________________
Sorry to add so much, just trying to be thorough. SInce its online help I want to get as much right the FIRST time as possible so you can proceed with the most info
All my updates on all 3 desktops are up to date, even the scanning programs are up to date, esp. since I've been using them. I just dont understand why the browsers alone dont work. OH, I tried one more test, I have some online games I play, while playing them during this issue I have had no interrupts in connection. My connection doesnt drop like some peoples, it doesnt restart my comp on its own or anything, it just prevents me from searching ANYTHING thru IE or firefox. half my bookmarks and anything I type in the search or address bars just freezes, and i cant fully run the 2 programs provided by this site for some strange reason.
Please if you have any further ideas or solutions, post back as soon as you can
Thank you!!!