Unsolved

This post is more than 5 years old

13 Posts

1532

November 22nd, 2006 12:00

every thing opens in note pad

every thing opens in note pad,
and when the windows updata trys to install i get the blue screen of death, i have disabled the updata
here is the log
 
Logfile of HijackThis v1.99.1
Scan saved at 10:19:36 PM, on 11/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dellsearchedit.myway.com/samisc/dellsidebar.jhtml?p=DA
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ap.dell.com/content/default.aspx?c=au&l=en&s=gen
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www1.ap.dell.com/content/default.aspx?c=au&l=en&s=gen
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ttool] C:\WINDOWS\9129837.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?88ac059969704a75bc11fe6644ad340a
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?88ac059969704a75bc11fe6644ad340a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Nick Larcombe\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152335492250
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
 

13 Posts

November 29th, 2006 04:00

Logfile of HijackThis v1.99.1
Scan saved at 2:52:12 PM, on 11/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\McAfee.com\Personal Firewall\MpfConsole.exe
C:\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\svchost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dellsearchedit.myway.com/samisc/dellsidebar.jhtml?p=DA
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ap.dell.com/content/default.aspx?c=au&l=en&s=gen
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www1.ap.dell.com/content/default.aspx?c=au&l=en&s=gen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?88ac059969704a75bc11fe6644ad340a
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?88ac059969704a75bc11fe6644ad340a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Nick Larcombe\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152335492250
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
 
pc is running a bit slow and every thing is still opening in note pad

10.4K Posts

November 30th, 2006 12:00

NickL210

When you say everything opens in notepad, I'm assuming this happens on start up?

Do you get this message anywhere when it happens?
  • [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787


Or something similar?

Do you get any error messages at all?
 
bamajim   Graduate of Malware Removal University
 

13 Posts

December 3rd, 2006 09:00

 ø   º ´ Í!¸ LÍ!This program cannot be run in DOS mode.
$       ¢8<÷æYR¤æYR¤æYR¤õQ;¤äYR¤ãU]¤ýYR¤ãU
¤tYR¤hQ
¤áYR¤eQ ¤÷YR¤æYS¤ãXR¤ãU2¤ÌYR¤
R ¤çYR¤ãU ¤çYR¤RichæYR¤                        PE  L cZ3C        à
 `   P      üª      p    @                      À                                       <× ´    P èg                                                          ¿ H            p                           .text   CS      `                    `.rdata  þ|   p   €   p              @  @.data   ˜U   ð   @   ð              @  À.rsrc   èg   P   p   0              @  @                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                U‹ìjÿhëYC d¡    Pd‰%    ƒì ƒ} t ƒ} u
¸W €é‰   ‹E Ç     j èÙp ƒÄ ‰EäÇEü    ƒ}ä t
‹Mäè„   ‰Eàë ÇEà    ‹Mà‰MèÇEüÿÿÿÿ‹Uè‰Uðƒ}ð u ¸ €ë2‹EðPèo&  ‹M Q‹MðèÓ   ‰Eìƒ}ì | ‹U ‹Eð‰ ‹MðQèI&  ‹Eì‹Môd‰
   ‹å]ÃÌÌÌÌÌÌÌÌU‹ìƒì ƒ} u ¸W €ëx‹E Ç     ÇEü    MüQhè‡C j j ‹U Rÿ üsC ‰Eøƒ}ø | ƒ}ü u ‹Eøë=‹E P‹M Qh tC èþu ƒÄ T Rh`tC ‹Eü‹ ‹UüRÿQ ‰Eø‹Eü‹ ‹UüRÿQ ‹Eø‹å]ÃÌU‹ìƒì ƒ} u
¸W €é   ‹E Ç     ÇEø    MøQj ÿ ôsC ‰Eðƒ}ø u ‹Eðéå   ÇEü    UüR‹E Pÿ øsC ‰Eðƒ}ü u ‹Mø‹ ‹EøPÿR ‹Eðé³   ÇEì    MìQ‹UüR‹Eø‹ ‹UøRÿQ ‰Eð‹Eü‹ ‹UüRÿQ ‹Eø‹ ‹UøRÿQ ƒ}ì u ‹EðërÇEô    EôPhè‡C ‹Mì‹ ‹EìPÿ ‰Eð‹Mì‹ ‹EìPÿR ƒ}ô u ‹Eðë=‹M Q‹U Rh°tC èÑt ƒÄ D Ph uC ‹Mô‹ ‹EôPÿR ‰Eð‹Mô‹ ‹EôPÿR ‹Eð‹å]ÃÌÌÌÌU‹ìƒ} t ƒ} u ¸ @ €ë4‹E Ç     ‹M Q‹U RhPuC èmt ƒÄ D Ph uC ‹M ‹ ‹E PÿR ]ÃÌÌÌÌU‹ìQ‰Mü‹Müè : ‹EüÇ@     ‹MüƒÁ ‹ «C ‰ ¡ «C ‰A ‹ «C ‰Q ¡ «C ‰A ‹MüÇA     ‹Eü‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹Eüƒx t ‹Mü‹Q R¹˜&D è?$  ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì$‰MähðuC ‹E PèyY ƒÄ ‹Mä‰A ‹Uäƒz u
¸ @ €é   høuC ‹E PèOY ƒÄ ‰Eüƒ}ü t}èÞ   ‰Eì‹Mü‰Mèƒ}è u ÇEà    ë;‹UèRÿ rC ƒÀ ‰Eô‹EôÑàƒÀ ƒàüèVs ‰eÜ‹EìP‹MôQ‹UèR‹EÜPèž   ‰Eà‹Mà‰Mø‹UäƒÂ R‹EøPÿ ðsC ‹MüQ¹˜&D èf#  h vC ‹U Rè¸X ƒÄ ‰Eüƒ}ü t(‹Eü ¾ ƒù1u ‹Uä‹B ƒÈ ‹Mä‰A ‹UüR¹˜&D è$#  h vC ‹E PèvX ƒÄ ‰Eüƒ}ü t(‹Mü ¾ ƒú1u ‹Eä‹H ƒÉ ‹Uä‰J ‹EüP¹˜&D èâ"  3À eÜ‹å] ÌÌÌÌÌÌÌU‹ìjÿh ZC d¡    Pd‰%    ƒìP MÜèí³  MàèE   ÇEü    j ÿ èsC …À} ÇEР   ÇEüÿÿÿÿ MàèL   ‹EÐéD   EÌP‹M èHo ‹ ‰MÜë j UÈR MÜèÓ   EÄP‹M èç   P MÜèn{ ¶È…É „¥   MÜè‹   ‹ ‰U؃}Ø „‰   ‹MØèT!  …Àt}ÇEÔ    EÔPh؇C ‹MØèè   Pè"ûÿÿƒÄ ƒ}Ô tVÇEð    MðQ‹UÔ‹ ‹MÔQÿP ƒ}ð u-‹MØè4S  P M¨èû   ÆEü U¨R Màè»   ÆEü M¨è   ‹EÔ‹ ‹UÔRÿQ é-ÿÿÿ‹E Pè%   ƒÄ Màèj   ¶È…Éu$ UàRj hf   ¹˜&D è~!  Pÿ ÀsC Màè   ÿ tC ÇE¤    ÇEüÿÿÿÿ Màè   ‹E¤‹Môd‰
   ‹å] U‹ìƒì EüPj ‹M QhÐ @ j j ÿ rC ‰Eøƒ}ø t ‹UøRÿ rC ¸    ë ‹E Pè~   ƒÄ 3À‹å]ÃÌÌÌÌÌU‹ìjÿh ZC d¡    Pd‰%    ƒì j è(j ƒÄ ‰EìÇEü    ƒ}ì t
‹Mìè   ‰Eèë ÇEè    ‹Eè‰EðÇEüÿÿÿÿ‹Eð‹Môd‰
   ‹å]ÃÌÌÌÌÌÌÌÌÌU‹ìƒì$ Müè’±  EôP‹M è&m ‹ ‰Mü UðR‹M èÕ   P Müè\y ¶À…Àt? Müè}   ‹ ‰Mø‹UüR EìP‹M è8¢ ƒ}ø t ‹MøQèy   UèR‹M èÍl ‹ ‰Eü륋M ‰Mà‹Uà‰Uäƒ}ä t j ‹MäèÚ   ‰EÜë ÇEÜ    ‹å]ÃÌÌÌÌÌÌÌÌÌÌU‹ìƒì Møèâ°  èÍþÿÿ‰Eüƒ}ü u 3À鎠  EðP‹M èal ‹ ‰Møë j UìR Møèì   EèP‹M è   P Møè‡x ¶È…Ét2ÇEô    UôR Møè   ‹ Pè•÷ÿÿƒÄ ƒ}ô t MôQ‹Müè   뤋MüèÆ   …Àv ‹Eüë ‹UüRè¤þÿÿƒÄ 3À‹å]ÃÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹Müè1  ‹E ƒà t ‹MüQèŽi ƒÄ ‹Eü‹å] ÌÌÌÌU‹ìƒì ‰MøQ‹Ìè É ‹Møè ²  j j ‹Møè{   ‹E P‹Møè?   ‹Eø‹å] ÌÌÌÌÌÌU‹ìQ‰Müj j ‹MüèM   ‹å]ÃÌÌÌÌÌÌÌÌÌU‹ìƒì ‰MøQ‹Ìè/É ‹Møè§±  j ‹Møè½   ‹Eø‹å]ÃÌÌÌÌÌÌU‹ìQ‰Mü‹Müè!   ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹MüèÁ   ÷Ø À@‹å]ÃÌÌÌÌÌÌÌÌU‹ìƒì V‰Mô‹Môèž   ‹ð‹Môè4   ;ðs ‹E Pj ‹Mô‹Q R‹Môè+   ‹Mô‰A ë ‹U R EüP‹MôèC   ‹ Q UøR‹Môè”   ^‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰MøQ‹ÌèOÈ ‹Møèǰ  j ‹Møè½   ‹Eø‹å]ÃÌÌÌÌÌÌU‹ìƒì ‰Mü‹Eüƒx u ÇEø    ë ‹Mü‹Uü‹A +B Áø ‰Eø‹Eø‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì V‰Mô‹Môè®ÿÿÿ‹ð‹Môè”   ;ðs ‹E Pj ‹Mô‹Q R‹Môèk¯  ‹Mô‰A ë ‹U R EüP‹Môèc   ‹ Q UøR‹Môè”   ^‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹Müè¡6 ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰Mø‹Eø‹ ‰Mü‹MøèG   ‹U ‹Eü‰ ‹E ‹å] ÌÌÌÌÌÌU‹ìQ‰Mü‹E Pè€   ƒÄ P‹M Q‹Müè0   ‹å] ÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰Mø ¶E …Àu ëE‹Møƒy r<‹Uø‹B ‰Eüƒ} v ‹M Q‹UüR‹EøƒÀ PèÑ   ƒÄ ‹Mø‹Q ƒÂ R‹EüP‹MøèØÆ ‹MøÇA    ‹U R‹Møè²   ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌU‹ì 유  Ç…hÿÿÿ”   …hÿÿÿPÿ rC ƒ½xÿÿÿ u ƒ½lÿÿÿ r Ç…dÿÿÿ @ ë
Ç…dÿÿÿ }@ ‹ dÿÿÿQhPðC è    ÿ PðC ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ì‹E P‹M Qÿ rC ] ÌÌÌÌÌÌÌÌÌÌÌU‹ì¸    ]ÃÌÌÌÌÌÌU‹ìÿ PðC ]ÃÌÌÌÌÌU‹ìQƒ} t ƒ} u 3Àë2‹E fÇ   ‹M Q‹U Rjÿ‹E Pj ‹M Qÿ ôqC ‰Eüƒ}ü u 3Àë ‹E ‹å] ÌÌÌÌU‹ìƒì ‰Mü‹Eüƒx u ÇEø    ë ‹Mü‹Uü‹A +B ™¹    ÷ù‰Eø‹Eø‹å]ÃÌÌÌÌÌÌÌU‹ìQ‰Mü‹Eü‹H Q‹M èÚ{ ‹E ‹å] ÌU‹ìƒì ‰Mü‹Eüƒx u ÇEø    ë ‹Mü‹Uü‹A +B ™¹    ÷ù‰Eø‹Eø‹å]ÃÌÌÌÌÌÌÌU‹ìƒì ‰Mð‹Mðè¯ÿÿÿ…Àu ÇEì    ë EøP‹Mðè¶f P M è   ‰Eì‹Mì‰Mü‹U Rj ‹E P‹Mðè   ‹MüQ‹U R EôP‹Mðè~f ‹Èè·
 ‹E ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹EüÇ@     ‹MüÇA     ‹UüÇB     ƒ} u 2ÀëI‹Müè9   ;E s
‹Müèl   ë0‹E P‹Müè¾   ‹Mü‰A ‹Uü‹Eü‹H ‰J ‹U kÒ ‹Eü P ‹Mü‰Q ° ‹å] ÌÌU‹ìQ‰Mü‹Eüƒx t<‹Mü‹Q R‹Eü‹H Q‹Müèê   ‹Uü‹Eü‹J +H ‹Á™¹    ÷ùP‹Uü‹B P‹MüèÄà ‹MüÇA     ‹UüÇB     ‹EüÇ@    ‹å]ÃÌÌU‹ìQ‰Mü‹EüP‹M Q‹U R‹E Pè   ƒÄ ‹E kÀ E ‹å] ÌÌU‹ìƒì ‰Mü‹Eüƒx u ÇEø    ë ‹Mü‹Uü‹A +B Áø ‰Eø‹Eø‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰Mð‹Mðè¿úÿÿ…Àu ÇEì    ë EøP‹MðèÖd P M è=°  ‰Eì‹Mì‰Mü‹U Rj ‹E P‹Mðè¢   ‹MüQ‹U R EôP‹Mðèžd ‹Èè§   ‹E ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹EüÇ@     ‹MüÇA     ‹UüÇB     ƒ} u 2ÀëI‹Müè   ;E s
‹MüèŒ   ë0‹E P‹Müè ¯  ‹Mü‰A ‹Uü‹Eü‹H ‰J ‹Uü‹B ‹M ˆ‹Eü‰P ° ‹å] ÌÌU‹ìQ‰Mü‹Eü‹ ƒÁ ‹Uü‰
‹Eü‹å]ÃÌÌÌÌÌU‹ìQ‰Mü‹E P‹Müè­
 ¶È…Ét ‹U R‹Müè   ‹M +ÈQ‹UüR‹MüèH   ë=j ‹E P‹Müèø   ¶È…Ét%‹U R‹E P‹Müèá   Pè‹   ƒÄ ‹M Q‹MüèŒ   ‹Eü‹å] ÌÌÌU‹ìƒì ‰Mø‹M è ;E s ‹Møè ` ‹M èj +E ‰Eü‹E ;Eüs ‹M ‰Mü‹Uø;U u%¡ vC P‹M MüQ‹Møè™   ‹U Rj ‹Møè‹   ëBj ‹EüP‹MøèK   ¶È…Ét-‹UüR‹M è8   E P‹Møè,   PèÖ   ƒÄ ‹EüP‹Møè×   ‹Eø‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰Mü‹Eüƒx r ‹Mü‹Q ‰Uøë ‹EüƒÀ ‰Eø‹Eø‹å]ÃÌÌÌU‹ìƒì ‰Mø‹Eø‹H ;M s ‹Møè _ ‹Uø‹B +E ;E s ‹Mø‹Q +U ‰U ƒ} vH‹Eø‹H +M +M Q‹Møè ÿÿÿ E E P‹Møèpÿÿÿ E Pè7   ƒÄ ‹Uø‹B +E ‰Eü‹MüQ‹Møè    ‹Eø‹å] ÌÌÌU‹ìƒì ‰MøÆEÿ ‹Eø‹M ‰H UÿR‹Møè ÿÿÿ E Pèµ   ƒÄ ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰Mü‹MüèÏ   ;E s ‹Müè€^ ‹Eü‹H ;M s ‹Uü‹B P‹M Q‹Müèä   ëJ ¶U …Òt2ƒ} s,‹Eü‹M ;H s ‹U ‰Uøë ‹Eü‹H ‰Mø‹UøRj ‹Müè*øÿÿë ƒ} u
j ‹Müè8ÿÿÿ3À;E À÷Ø‹å] ÌÌÌÌÌÌÌÌÌU‹ì‹E ‹M Š ˆ ]ÃÌU‹ìQ‰Mü‹MüèÑ   ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹EüP‹M Q‹U Rèø
 ƒÄ ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ì‹E Pè¤c ƒÄ ]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìjÿh8ZC d¡    Pd‰%    Qƒì ùÿÿ‹ð‹MÀè0ÿÿÿ+Æ;E s
‹MÀèa   é©   ‹MÀèäøÿÿ E 9EÐ ƒh   ‹uÐÑî‹MÀèûþÿÿ+Æ;EÐs ÇE¼    ë ‹MÐÑé MЉM¼‹U¼‰UЋMÀè¢øÿÿ E 9EÐs ‹MÀè’øÿÿ E ‰EЋEÐP‹MÀèP   ‰EÈ‹MȉMÌÆEü ‹UÈR‹E P‹MÀ‹Q R‹MÀèü   ‰E¸‹E¸‰EÌ MÔQ‹U R‹EÌP‹MÀèïùÿÿ‰E´‹M´‰MÌ‹UÌR‹EÀ‹H Q‹U R‹MÀè¿   ë)‹EÌP‹MÈQ‹MÀè]þÿÿ‹UÐR‹EÈP‹MÀèM½ j j è¯b ÇEü    ‹MÀèå÷ÿÿ E ‰E ‹MÀƒy t:‹UÀ‹B P‹MÀ‹Q R‹MÀè þÿÿ‹EÀ‹MÀ‹@ +A ™¹    ÷ùP‹UÀ‹B P‹MÀèì¼ ‹MÐkÉ MÈ‹UÀ‰J ‹E kÀ EÈ‹MÀ‰A ‹UÀ‹EȉB é-   ‹MÀ‹A +E ™¹    ÷ù;E ƒ¯   ‹U kÒ U R‹EÀ‹H Q‹U R‹MÀèÙ   ÆEü EÔP‹MÀ‹A +E ™¹    ÷ù‹U +ÐR‹EÀ‹H Q‹MÀè»øÿÿë(‹U kÒ ‹EÀ P R‹M kÉ M Q‹MÀè:ýÿÿj j èœa ÇEü    ‹U kÒ ‹EÀ P ‹MÀ‰Q UÔR‹E kÀ ‹MÀ‹Q +ÐR‹E Pè|   ƒÄ ëd‹MÀ‹Q ‰UÄ‹EÀ‹H Q‹UÄR‹E kÀ ‹MÄ+ÈQ‹MÀè   ‹UÀ‰B ‹EÄP‹M kÉ ‹UÄ+ÑR‹E Pè`   ƒÄ MÔQ‹U kÒ U R‹E Pè   ƒÄ ÇEüÿÿÿÿ MÔèôñÿÿ‹Môd‰
   _^[‹å] ÌU‹ìƒì ‰MøQ‹Ì‹E PèkÇ ‹Møè££  j j ‹Møè ôÿÿ‹
vC Qj ‹U R‹Møè¢ùÿÿ‹Eø‹å] ÌÌÌÌÌÌÌÌÌU‹ì‹E P‹M Q‹U Rè¼` ƒÄ ]ÃÌÌÌÌÌÌÌU‹ì‹E P‹M Q‹U RèÜc ƒÄ ]ÃÌÌÌÌÌÌÌU‹ìjÿhhZC d¡    Pd‰%    ƒìH‰M¬h vC M°èåðÿÿÇEü    E°P MÌè’   hôÃC MÌQèÿ_ ‹Môd‰
   ‹å]ÃÌÌÌÌÌÌU‹ìQ‰Müj ‹E Pè^
 ƒÄ ‹å] ÌÌÌÌÌU‹ìQ‰Mü‹MüèA   ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìjÿhPZC d¡    Pd‰%    Qƒì$SVW‰eð‰MØ‹E ‹ ‰Mì‹MØè›öÿÿ‰Eèƒ} u éÆ   ‹MØè•ñÿÿ‹ð‹MØè‹ÿÿÿ+Æ;E s
‹MØèüþÿÿé    ‹MØèoñÿÿ E 9Eè ƒf   ‹uèÑî‹MØèVÿÿÿ+Æ;Eès ÇEÔ    ë ‹UèÑê Uè‰UÔ‹EÔ‰Eè‹MØè-ñÿÿ E 9Eès ‹MØè ñÿÿ E ‰Eè‹MèQ‹MØè+¦  ‰Eà‹Uà‰UäÇEü    ‹EàP‹M Q‹UØ‹B P‹MØèÄ– ‰EЋMЉMä UìR‹E P‹MäQ‹MØè§   ‰EÌ‹ỦUä‹EäP‹MØ‹Q R‹E P‹MØè‡– ë)‹MäQ‹UàR‹MØè¥   ‹EèP‹MàQ‹MØèå¸ j j èG^ ÇEüÿÿÿÿ‹MØèmðÿÿ E ‰E ‹U؃z t5‹EØ‹H Q‹UØ‹B P‹MØèX   ‹MØ‹UØ‹A +B Áø P‹MØ‹Q R‹MØè‰¸ ‹Eè‹Mà ‹E؉P ‹M ‹Uà Š‹M؉A ‹UØ‹Eà‰B é&   ‹MØ‹Q +U Áú ;U ƒ­   ‹E ‹M R‹EØ‹H Q‹U R‹MØè«• ÇEü    EìP‹MØ‹Q +U Áú ‹E +ÂP‹MØ‹Q R‹MØè Ÿ  ë(‹EØ‹H ‹U ‘P‹M ‹U ŠP‹MØèŽŸ  j j è@] ÇEüÿÿÿÿ‹MØ‹Q ‹E ‚‹U؉J EìP‹M Áá ‹UØ‹B +ÁP‹M Qè ¥  ƒÄ ëd‹UØ‹B ‰EÜ‹MØ‹Q R‹EÜP‹M Áá ‹UÜ+ÑR‹MØèó” ‹M؉A ‹UÜR‹E Áà ‹MÜ+ÈQ‹U Rèd   ƒÄ EìP‹M ‹U ŠP‹M Qè*¥  ƒÄ ‹Môd‰
   _^[‹å] ÌÌÌÌU‹ìƒì ‰Mø‹Eø‹ ‰Mü‹U R Müè ’ ‹ ‹M ‰ ‹E ‹å] ÌÌÌU‹ìƒì ‰Mø‹Eø‹ ‰Mü‹U R Müèó   ‹ ‹M ‰ ‹E ‹å] ÌÌÌU‹ìƒì ‰Mø‹Eø‹ ‰Mü‹U R Müèã   ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹E P‹Müè    ‹MüÇ ¨«C ‹Eü‹å] ÌÌÌÌÌÌÌÌÌÌÌU‹ìjÿh˜ZC d¡    Pd‰%    Q‰Mð‹E P‹Mðè³b ÇEü    ‹MðÇ œ«C ‹U ƒÂ R‹MðƒÁ è¦úÿÿÇEüÿÿÿÿ‹Eð‹Môd‰
   ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰Mø‹Møè_   ‰Eüƒ}ü w ÇEô    ë ‹Eüƒè ‰Eô‹Eô‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìjÿh€ZC d¡    Pd‰%    Qƒì SVW‰eð‰Mä‹E ƒÈ ‰Eè‹MäèŠÿÿÿ;Eès ‹M ‰MèëC‹Uä‹J Ñé‹Eè3Ò¾    ÷ö;Ás+‹Uä‹r Ñî‹MäèUÿÿÿ+Æ‹Mä9A w ‹Uä‹B Ñè‹Mä A ‰EèÇEü    ‹UèƒÂ R‹Mäèt   ‰Eà‹Eà‰EìëI‰eð‹M ‰MèÆEü ‹UèƒÂ R‹MäèM   ‰EÜ‹E܉Eìë j j ‹Mäè¦íÿÿj j è8Z ÇEü    ¸ð-@ ÃÇEüÿÿÿÿƒ} v ‹M Q‹Mäè×óÿÿP‹UìRè}ùÿÿƒÄ j j ‹Mäè^íÿÿ‹Eä‹Mì‰H ‹Uä‹Eè‰B ‹M Q‹Mäè`ôÿÿ‹Môd‰
   _^[‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹Müèqóÿÿ9E r ‹Müèdóÿÿ‹Mü A ;E w 2Àë ° ‹å] ÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹MüƒÁ è    ‹å]ÃÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹Müè óÿÿ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹Müè!   ‹E ƒà t ‹MüQè^S ƒÄ ‹Eü‹å] ÌÌÌÌU‹ìjÿh˜ZC d¡    Pd‰%    Q‰Mð‹EðÇ œ«C ÇEü    ‹MðƒÁ èÙéÿÿÇEüÿÿÿÿ‹Mðè ` ‹Môd‰
   ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‰MøÇEüI’$ ƒ}ü v ‹Eü‰Eôë ÇEô    ‹Eô‹å]ÃÌÌÌÌU‹ìƒì ‰MøÇEüÿÿÿ?ƒ}ü v ‹Eü‰Eôë ÇEô    ‹Eô‹å]ÃÌÌÌÌU‹ìQ‰Mü‹E kÀ ‹Mü ‹Uü‰ ‹Eü‹å] U‹ìQ‰Mü‹Eü‹M ‹ + ™¹    ÷ù‹å] ÌU‹ìQ‰Müj ‹E PèÞ   ƒÄ ‹å] ÌÌÌÌÌU‹ìƒì ‰MøÇEüÿÿÿÿƒ}ü v ‹Eü‰Eôë ÇEô    ‹Eô‹å]ÃÌÌÌÌU‹ìQ‹E P‹M Qèï ƒÄ ˆEÿŠUÿR‹E P‹M Q‹U R褠  ƒÄ ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹E P‹Müè    ‹MüÇ ¨«C ‹Eü‹å] ÌÌÌÌÌÌÌÌÌÌÌU‹ìjÿh˜ZC d¡    Pd‰%    Q‰Mð‹Mðèé] ÇEü    ‹EðÇ œ«C ‹M Q‹MðƒÁ è-öÿÿÇEüÿÿÿÿ‹Eð‹Môd‰
   ‹å] ÌÌÌU‹ìQ E P M Qè ƒÄ ˆEÿŠUÿR‹E P‹M Q‹U R‹E Pè   ƒÄ ‹å]ÃÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹EüÇ ¨«C ‹Müèˆýÿÿ‹å]ÃÌÌÌÌU‹ìQ‰Mü‹MüèÑÿÿÿ‹E ƒà t ‹MüQè®P ƒÄ ‹Eü‹å] ÌÌÌÌU‹ìQ E P M Qè Ž ƒÄ ˆEÿŠUÿR‹E P‹M Q‹U Rè   ƒÄ ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹EüP‹M Q‹U R‹E Pè   ƒÄ ‹å] ÌÌÌÌÌÌÌÌÌÌÌU‹ìë ‹E ƒÀ ‰E ‹M ;M t ‹U R‹M èΠ  ëá]ÃÌÌÌÌÌÌÌÌÌÌU‹ìQ E P M Qèï ƒÄ ˆEÿŠUÿR‹E P‹M Q‹U Rèä   ƒÄ ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ì‹E kÀ PèkN ƒÄ ]ÃÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‹E P‹M Qè ƒÄ ˆEÿŠUÿR‹E P‹M Q‹U Rè´   ƒÄ ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ì‹E Pè N ƒÄ ]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹E P‹Müè
  ‹å] ÌÌÌÌÌÌÌU‹ìQ‰Müjÿj ‹E P‹MüèÉíÿÿ‹å] ÌÌÌU‹ìjÿh°ZC d¡    Pd‰%    QQSVW‰eð‹E ‰EìÇEü    ë ‹M ƒé ‰M ‹U ƒÂ ‰U ƒ} v ‹E P‹M Q‹M è)   ëÖë*ë ‹UìƒÂ ‰Uì‹Eì;E t ‹MìQ‹M è&   ëáj j è6T ÇEüÿÿÿÿ‹Môd‰
   _^[‹å]ÃÌÌÌU‹ìë ‹E ƒÀ ‰E ‹M ;M t ‹U R‹M èÞ   ëá]ÃÌÌÌÌÌÌÌÌÌÌU‹ìQ E P M Qè Œ ƒÄ ˆEÿŠUÿR‹E P‹M Q‹U R‹E Pèð   ƒÄ ‹å]ÃÌÌÌÌÌÌÌÌÌU‹ì‹E ;E t ‹M ƒé ‰M ‹U ƒê ‰U ‹E P‹M è‡þÿÿëØ‹E ]ÃU‹ìQ‹E +E Áø ‰Eü‹MüÁá Q‹U R‹EüÁà ‹M +ÈQèÔV ƒÄ ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹E P‹M Qè   ƒÄ ‹å] ÌÌÌU‹ìQ‰Mü‹E Pèp   ƒÄ ‹å] ÌÌÌÌÌÌÌU‹ìë ‹E ƒè ‰E ‹M ƒÁ ‰M ƒ} v ‹U ‹E ‹ ‰
ëÜ]ÃÌÌÌÌÌU‹ìjÿhÀZC d¡    Pd‰%    QQSVW‰eð‹E ‰EìÇEü    ë ‹M ƒÁ ‰M ‹U ƒÂ ‰U ‹E ;E t ‹M Q‹U R‹M è7ÿÿÿëÔë*ë ‹EìƒÀ ‰Eì‹Mì;M t ‹UìR‹M è4ÿÿÿëáj j èDR ÇEüÿÿÿÿ‹E ‹Môd‰
   _^[‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìjÿháZC d¡    Pd‰%    ƒì ‹E Pj èJ   ƒÄ ‰EìÇEü    ƒ}ì t ‹M Q‹Mìèûðÿÿ‰Eèë ÇEè    ‹Uè‰UðÇEüÿÿÿÿ‹Môd‰
   ‹å]ÃÌÌÌÌU‹ì‹E ]ÃÌÌÌÌÌÌÌÌU‹ìj ‹M è#   ]ÃÌU‹ìQ‰Mü‹EüƒÀ ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹Müèaâÿÿ‹E ƒà t ‹MüQèŽK ƒÄ ‹Eü‹å] ÌÌÌÌU‹ìQ‰Mü‹Eü‹@ ƒà ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌU‹ì‹M èu« Pÿ ðqC ] ÌÌÌÌÌÌÌÌÌÌU‹ìƒì ‹M èR« Pÿ ìqC ‰Eüƒ}ü u(‹E ‰Eô‹Mô‰Møƒ}ø t j ‹Møè    ‰Eðë ÇEð    ‹Eü‹å] ÌU‹ìQ‰Mü‹MüèÁÛÿÿ‹E ƒà t ‹MüQèÎJ ƒÄ ‹Eü‹å] ÌÌÌÌU‹ìQ‰Müƒ} t ‹E Pè`X ƒÄ ‹å] ÌU‹ìQ‰Mü‹Eü‹@ ‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹EüÇ     ‹MüÇA     ‹Eü‹å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌU‹ìQ‰Mü‹å]ÃÌÌÌÌÌU‹ìƒì ‰MôÇEø    ÇEü    EüP‹MôƒÁ Qj h(vC ‹U R‹Môè‹   …Àu ÇEø    ë0‹EôÇ@ d   j j ‹MôƒÁ Qj h4vC ‹U R‹Môè   ÷Ø À@‰Eøƒ}ø tN EüP‹MôQj h@vC ‹U R‹Môè-   …Àu ‹Eô‹Mô‹ ;Q | ‹EôÇ     ÇEø    ë ‹MôÇ     ÇEø    ‹Eø‹å] ÌU‹ìƒì
 
plus alot more

10.4K Posts

December 4th, 2006 00:00

NickL210

Thats strange, but it gave me a clue, maybe, we will see

1. We need to make sure we can hidden files and folders
To enable the viewing of Hidden and System files follow these steps:
  • Right click on Start and select Explore.
    Select the Tools menu and click Folder Options.
    After the new window appears select the View tab.
    Put a checkmark in the checkbox labeled Display the contents of system folders.
    Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
    Remove the checkmark from the checkbox labeled Hide protected operating system files.
    Click Yes To confirm
    Press the Apply button and then the OK button.

2. You have a suspicious file I need some more info on

Please upload this file to Jotti's Online Virus Scan
  • C:\WINDOWS\system32\CmdLineExt03.dll

  • Click " Browse" at the top of the page
    - Navigate to (Locate)
    • C:\WINDOWS\system32\CmdLineExt03.dll

    - Click " Open" Then the "Submit" and let the scan finish
    - Scroll down to the bottom of the page to find the results
    - Copy/paste the results in your next reply.
bamajim   Graduate of Malware Removal University
 




13 Posts

December 4th, 2006 05:00

AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found Misc/BEAV_ADWARE
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

10.4K Posts

December 4th, 2006 19:00

NickL210

I have a couple of questions, before we proceed

1. When you boot up, and this thing opens in notepad, in the blue title bar at the top of notepad, it should give a file name. Does it? and what is that name?

2. Does this happen in Safe Mode as well as normal mode?

3. When you Click Start->>Run->>type in taskmgr.exe->>O.K. does that cause notepad to open?

4. When you Rt click Start->>Explore, does that invoke notepad to open?

Please reply with the results
 
bamajim   Graduate of Malware Removal University

 

0 events found

No Events found!

Top