soompi forums: Computer is acting weird - soompi forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2

Computer is acting weird

#1 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 15 November 2009 - 03:33 PM

Every time I close the internet browser, this pops up

and then this.

At first, I thought it was a one time thing, but it keeps happening.
Does anyone know what's wrong with my computer? Or how to fix it?
I also ran the anti-virus program a lot, just to check it wasn't a virus, but nothing came up.
So, I have no idea what it is.

Thanks. (Sorry for the big pictures ><)
0

#2 User is offline   jas0n 

  • Member
  • Pip
  • Group: Members
  • Posts: 235
  • Joined: 27-August 09

Posted 15 November 2009 - 04:44 PM

Sounds like you have a Google or another named toolbar/add-on installed inside your Internet Explorer. I suggest uninstalling the toolbar/add-on through the Control Panel to see the results. If that doesn't work, then you can right-click on My Computer > Advanced, then click on Data Execution Prevention tab and check the first caption: Enable DEP for Essential windows programs and service.

If you prefer to tackle the problem down one by one, then open up Internet Explorer, go to Internet Options > Programs and click on Manage add-ons. Disable all the add-ons and manually enable one by one until you see the problem, then you will know what causes it.
0

#3 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 15 November 2009 - 06:47 PM

Thank you smile.gif I'm trying what you told me to do right now ^^

it worked for like 5 minutes..
and then it's starting again..
i'll try deleting the toolbar..
0

#4 User is offline   jas0n 

  • Member
  • Pip
  • Group: Members
  • Posts: 235
  • Joined: 27-August 09

Posted 15 November 2009 - 07:32 PM

QUOTE (m1sh_glooor1a @ Nov 15 2009, 06:47 PM) <{POST_SNAPBACK}>
Thank you smile.gif I'm trying what you told me to do right now ^^

it worked for like 5 minutes..
and then it's starting again..
i'll try deleting the toolbar..


Hopefully after uninstalling, it'll work.
Let me know the result when you delete the toolbar.
0

#5 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 15 November 2009 - 08:54 PM

QUOTE (jas0n @ Nov 15 2009, 07:32 PM) <{POST_SNAPBACK}>
Hopefully after uninstalling, it'll work.
Let me know the result when you delete the toolbar.


deleting the toolbar didn't help..
i tried disabling all the add-ons.. and it still doesn't work.

now, i really don't know what the problem is.
0

#6 User is offline   jas0n 

  • Member
  • Pip
  • Group: Members
  • Posts: 235
  • Joined: 27-August 09

Posted 15 November 2009 - 09:10 PM

Try using ComboFix as I've heard it helps solve this problem.

Download, install, and clean.
http://combofix.org/
0

#7 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 15 November 2009 - 09:35 PM

QUOTE (jas0n @ Nov 15 2009, 09:10 PM) <{POST_SNAPBACK}>
Try using ComboFix as I've heard it helps solve this problem.

Download, install, and clean.
http://combofix.org/


And this will work?
I looked up this program and it looks dangerous.
I think I'm going to damage my computer more than it already it.. :T
0

#8 User is offline   awdark 

  • Cookie Monster
  • Icon
  • Group: Administrators
  • Posts: 9,593
  • Joined: 04-October 05

Posted 16 November 2009 - 09:06 AM

You should try malwarebytes anti-spyware first, just get the free one and see what it finds. It doesn't sound like you really tried any of the normal spyware methods yet. There is also Super AntiSpyware which is free and you should try that as well.

The Data Execution Prevention is an internal "antivirus" and is supposed to stop programs that are potential risks.
0

#9 User is offline   froggy604 

  • Asian Music Video Game Fanatic
  • Pip
  • Group: Members
  • Posts: 617
  • Joined: 22-October 05

Posted 16 November 2009 - 01:01 PM

You can try doing a system restore to a time when your IE was working properly.

Start>All programs>Accessories>System tools>System restore
0

#10 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 18 November 2009 - 10:25 PM

I'm running the Malwarebytes right now smile.gif
I'll tell you how it goes.. hopefully it's something i can fix...
I'm sooo bad with computers and viruses/spywares -____-
0

#11 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 19 November 2009 - 11:14 PM

ok. so this is my update.

I finished the scan. and these are the results.
I got rid of the 3 things.



Malwarebytes' Anti-Malware 1.41
Database version: 3195
Windows 5.1.2600 Service Pack 3

11/19/2009 6:58:53 AM
mbam-log-2009-11-19 (06-58-53).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 316837
Time elapsed: 2 hour(s), 26 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\AD-Safe\Adsafe.exe2 (Rogue.Installer) -> Quarantined and deleted successfully.


and i didn't update this before..
but the pop up after closing the browser changed.
it says this, now, after the "send/don't send" thing


and then i clicked "click here" and these two screens came up.



does this mean anything? i don't think anything is wrong with my computer..
something is just wrong with the internet explorer.
what do you guys think?
0

#12 User is offline   awdark 

  • Cookie Monster
  • Icon
  • Group: Administrators
  • Posts: 9,593
  • Joined: 04-October 05

Posted 20 November 2009 - 11:03 PM

I think what might have happened was your internet explorer got infected, so it wouldn't run. Then cleaning it deleted files causing the internet explorer to get corrupted. I guess you can try to download IE and reinstall it http://www.microsoft.com/windows/Internet-...er/default.aspx
0

#13 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 21 November 2009 - 01:35 AM

^ I did what you told me to and re-downloaded the internet..
But, the same thing is still popping up.

I don't think there's anything I can do..
0

#14 User is offline   NPB-XK 

  • Sometimes Not High
  • Pip
  • Group: Members
  • Posts: 3,618
  • Joined: 06-September 07

Posted 21 November 2009 - 11:56 AM

There's ALWAYS something you can do... tongue.gif
I wanna find the right problem...

Open your "My Computer", then unhide your files and folders by going to Tools>Folder Options>View tab>Check "Show hidden files and folders" and then APPLY and OK.

According to your screenshot, I'd guide you to go to:
C:\Documents and Settings\Gloria\Local Settings\Temp
Delete everything inside Temp folder just for the heck of it.

After that, download hijackthis:
http://download.cnet.com/Trend-Micro-Hijac...4-10227353.html

Install, open it and scan with a log file. It will be done quickly. A log in notepad will pop up. Copy everything inside and post them here.

Let's see what we'll have to do to fix conflicts with IE.
Status: Creepy Stalker - [411][FetishBook]
Posted Image
My name is NPB, I live in an igloo, I eat pancakes with maple syrup, I own a beaver, I don't like Justin Bieber, I ride a female moose to work and I'm Asian Posted Image. Eh. I'm a Poutine-Eater.
0

#15 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 21 November 2009 - 12:12 PM

It is okay to delete everything from the TEMP folder?

This is the log I got after running Hijack This

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:08:07 PM, on 11/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google 업데이터.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1258832713109
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/activex/dmcc2.c...ersion=1,0,0,10
O16 - DPF: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} (BugsInstallEx Control) - http://install.bugs.co.kr/install/BugsInstallerEx.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: application/xhtml+xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: application/xhtml+xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple ¸ð¹UAI Aaºn (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour ¼­ºn½º (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Gloria/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/Gloria/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 13978 bytes


I was looking through what might be wrong..
and I though it was this:
C:\DOCUME~1\Gloria\LOCALS~1\Temp\WERbdd8.dir00\iexplore.exe.mdmp
C:\DOCUME~1\Gloria\LOCALS~1\Temp\WERbdd8.dir00\appcompat.txt

I was looking online and found this: http://forums.maddoktor2.com/index.php?showtopic=1996
would delete the contents of this folder first:
C:\DOCUME~1\zohar\LOCALS~1\Temp

Then clean up the rest of the temp stuff:

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


You can also try this to see if any malware shows up:

Click here http://www.mwti.net/antivirus/free_utilities.asp to download mwavscan. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.

Would that help??
0

#16 User is offline   NPB-XK 

  • Sometimes Not High
  • Pip
  • Group: Members
  • Posts: 3,618
  • Joined: 06-September 07

Posted 21 November 2009 - 11:58 PM

Ohhh... Nice link... Let's keep that for later... Apparently, people couldn't delete those folders anyway (error is given). Plus, I found no infection from the log, so I suspect nothing "deadly" from Temp folder anymore...

So now, let's eliminate the BHOs... Scan with hijackthis again and check these following lines:

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll

By then, click FIX CHECKED.
Close it.

Now, copy this following:
iexplore -extoff
Press win+r
(or go to start menu and "run")
Paste that thing and press enter.
It should open Internet Explorer without extension. Does it work? If it does, let's try to open it normally. If it doesn't, tell me.
Status: Creepy Stalker - [411][FetishBook]
Posted Image
My name is NPB, I live in an igloo, I eat pancakes with maple syrup, I own a beaver, I don't like Justin Bieber, I ride a female moose to work and I'm Asian Posted Image. Eh. I'm a Poutine-Eater.
0

#17 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 22 November 2009 - 04:22 PM

Oh smile.gif
I think it works now! smile.gif

So I can't use the Yahoo Toolbar anymore?
or is it okay to re-download it?
0

#18 User is offline   NPB-XK 

  • Sometimes Not High
  • Pip
  • Group: Members
  • Posts: 3,618
  • Joined: 06-September 07

Posted 22 November 2009 - 08:49 PM

QUOTE (m1sh_glooor1a @ Nov 22 2009, 07:22 PM) <{POST_SNAPBACK}>
Oh smile.gif
I think it works now! smile.gif

So I can't use the Yahoo Toolbar anymore?
or is it okay to re-download it?


It's ok to re-download it. smile.gif
Status: Creepy Stalker - [411][FetishBook]
Posted Image
My name is NPB, I live in an igloo, I eat pancakes with maple syrup, I own a beaver, I don't like Justin Bieber, I ride a female moose to work and I'm Asian Posted Image. Eh. I'm a Poutine-Eater.
0

#19 User is offline   m1sh_glooor1a 

  • Member
  • Pip
  • Group: Members
  • Posts: 378
  • Joined: 28-February 07

Posted 22 November 2009 - 09:11 PM

Thank you so much smile.gif

You help me soo much through these past couple day ^^

Okay.
So I have one more question.
I re-downloaded the yahoo toolbar and it's doing it again.

Is there any other type of toolbar that i can use that has the same features as the yahoo toolbar?

It's weird because I use the yahoo toolbar on my laptop and this doesn't happen.
It only happens on my desktop.

This post has been edited by m1sh_glooor1a: 22 November 2009 - 09:27 PM

0

#20 User is offline   NPB-XK 

  • Sometimes Not High
  • Pip
  • Group: Members
  • Posts: 3,618
  • Joined: 06-September 07

Posted 22 November 2009 - 09:30 PM

You're welcome!
I didn't put much effort on this problem so I don't feel like I've helped much! Your screenshots and cooperation for the log really eased my task to find out the problem. smile.gif I just wrote down whatever I had in mind... this is why I never care about solutions found on google or the link you gave there... laugh.gif

So yeah, as a last resort of any computer problem, there's me! (I expect some PM again xD)

*Edited*
Whaaaat? xD Problem is back from that Yahoo toolbar? What kind of feature you want/like from that?
Status: Creepy Stalker - [411][FetishBook]
Posted Image
My name is NPB, I live in an igloo, I eat pancakes with maple syrup, I own a beaver, I don't like Justin Bieber, I ride a female moose to work and I'm Asian Posted Image. Eh. I'm a Poutine-Eater.
0

Share this topic:


  • (2 Pages)
  • +
  • 1
  • 2

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users