This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] lots of errors or viruses not really sure

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

StartupList report, 1/2/2009, 1:24:19 AM
StartupList version: 1.52.2
Started from : C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
ok im not sure where to post my problems but my once faster computer is now slowed down, it freezes up on me, tells me there are errors and when i do scans it says over 380 problems. this is my first step in trying to fix all these problems please help! and now today i have pop ups left and right that i never had b4. sometimes it will all of a sudden start opening up hundreds of windows or pages and the only way to get out of it all is to shut down the computer .
Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
UpdReg = C:\WINDOWS\Updreg.exe
RegisterDropHandler = C:\PROGRA~1\CANONC~1\TEXTBR~1\BIN\REGIST~1.EXE
LoadQM = loadqm.exe
Disc Detector = C:\Program Files\Creative\ShareDLL\CtNotify.exe
devldr16.exe = C:\WINDOWS\SYSTEM\devldr16.exe

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

SchedulingAgent = mstask.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Performance Center = C:\Program Files\Ascentive\Performance Center\APCMain.exe -m

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = C:\WINDOWS\NOTEPAD.EXE %1

————————————————–

C:\WINDOWS\WININIT.INI listing:
(Created 2/1/2009, 1:6:28)

[Rename]
NUL=c:\windows\cookies\[removed][3].txt
NUL=c:\windows\cookies\[removed][2].txt
NUL=C:\WINDOWS\TEMP\_iu14D2N.tmp
NUL=C:\WINDOWS\TEMP\A~NSISU_.EXE
NUL=C:\WINDOWS\TEMP\A~NSISU_.EXE
NUL=C:\WINDOWS\TEMP\A~NSISU_.EXE
NUL=C:\WINDOWS\TEMP\A~NSISU_.EXE
NUL=C:\WINDOWS\TEMP\~NSU.TMP\AU_.EXE
[rename]
NUL=C:\Program Files\Trend Micro\HijackThis\deer hunter 3
[rename]
NUL=C:\Program Files\Trend Micro\HijackThis\jigsaw usa special edition

————————————————–

C:\WINDOWS\WININIT.BAK listing:
(Created 1/1/2009, 21:2:28)

[rename]
NUL=C:\WINDOWS\TEMP\_iu14D2N.tmp
NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE

————————————————–

C:\AUTOEXEC.BAT listing:

SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

————————————————–

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Java\jre1.5.0_16\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

————————————————–

Enumerating Task Scheduler jobs:

Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Disk Cleanup.job
Disk Defragmenter.job
ErrorSmart Scheduled Scan.job

————————————————–

Enumerating Download Program Files:

[{11111111-1111-1111-1111-111111111123}]
CODEBASE = file://c:\Recycled\1.exe

[{11111111-1111-1111-1111-111111111732}]
CODEBASE = file://c:\progra~1\pl.exe

[{11111111-1111-1111-1111-111111113456}]
CODEBASE = file://c:\info6.cab

[{B9191F79-5613-4C76-AA2A-398534BB8999}]
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab

[MySpace Uploader Control]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MYSPACEUPLOADER.OCX
CODEBASE = http://lads.myspace.com/upload/MySpaceUploader1006.cab

[PopCapLoader Object]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\POPCAPLOADER.DLL
CODEBASE = http://games.pogo.com/online2/pogo/zuma/popcaploader_v5.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNPUPLD.DLL
CODEBASE = http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab

[PogoWebLauncher Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\POGOWE~1.OCX
CODEBASE = http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
UPnPMonitor: C:\WINDOWS\SYSTEM\UPNPUI.DLL
AUHook: C:\WINDOWS\SYSTEM\AUHOOK.DLL

————————————————–
End of report, 5,678 bytes
Report generated in 0.135 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hello and Welcome to the Forum.

Open HijackThis and select: Do a system scan and save a log file.

When the scan is finished, Click Edit> Select All> Edit> Copy> and paste its contents here [Add Reply].

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI