Unsolved

This post is more than 5 years old

23 Posts

1511

September 26th, 2005 12:00

Some MS Applications not working

Dell Inspiron 5150

System Restore/Help & Support/Dell Support Center/Windows Media Player not opening

Media Player error: instruction at "0x591c2522" referenced memory at "0x595c2a4c" memory not being    "read" 

 

Logfile of HijackThis v1.99.1

Scan saved at 5:42:46 PM, on 9/23/2005

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe

C:\Program Files\Dell\AccessDirect\dadapp.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe

C:\Program Files\Network Associates\Common Framework\FrameworkService.exe

C:\Program Files\Dell\AccessDirect\DadTray.exe

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\WINDOWS\System32\DSentry.exe

C:\Program Files\Network Associates\VirusScan\Mcshield.exe

C:\Program Files\Dell\Media Experience\PCMService.exe

C:\Program Files\Icons\SetIcon.exe

C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\windows\temp\6.exe

C:\WINDOWS\system32\fxssvc.exe

C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe

C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE

C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe

C:\Program Files\Bquzanz\Bpif.exe

C:\Program Files\Internet Optimizer\optimize.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

C:\HJT\hijackthis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://empnads.com/servlet/ajrotator/119752/0/viewHTML?zone=enternet

R3 - Default URLSearchHook is missing

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet

O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe

O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"

O4 - HKLM\..\Run: [SetIcon] C:\Program Files\Icons\SetIcon.exe

O4 - HKLM\..\Run: [Realplayer One] realplay.exe

O4 - HKLM\..\Run: [Messenger] C:\WINDOWS\System32\msgrsv32.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: :emotion-14: C:\windows\temp\6.exe

O4 - HKLM\..\Run: [salm] c:\temp\salm.exe

O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"

O4 - HKLM\..\Run: [hcj] C:\WINDOWS\hcj.exe

O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka67.exe

O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE

O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey

O4 - HKLM\..\Run: [Rwrjy] C:\Program Files\Bquzanz\Bpif.exe

O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"

O4 - HKLM\..\RunServices: [Realplayer One] realplay.exe

O4 - HKCU\..\Run: [Window Monitor] winmon32.exe

O4 - HKCU\..\Run: [NAV Auto Updates] slserves.exe

O4 - HKCU\..\Run: [Norton AntiVirus Sys] NAVsys32.exe

O4 - HKCU\..\Run: [Win32 Wmls Driver] winitr32.exe

O4 - HKCU\..\Run: [Sysino] lsess.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\RunServices: [Window Monitor] winmon32.exe

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

O4 - Global Startup: Digital Line Detect.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe

O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe

O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe

O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

 

2 Intern

 • 

5.9K Posts

September 27th, 2005 23:00


Download the Hoster from:


http://www.funkytoad.com/

Unpack to your desktop and run it.  If you have green print at the top then just press Restore Original Hosts then OK. 
IF you have red print then press make Hosts Writeable first.
 

Get DelDomain.inf from:
 
http://www.mvps.org/winhelp2002/restricted.htm  and then right click on it and Install. 

 

Download and install ccleaner.exe from http://www.ccleaner.com. Don't let
it clean anything yet. 

Download the killbox:

http://www.bleepingcomputer.com/files/killbox.php

Extract it to your desktop and run it.


Where it says Full Path of File to Delete you need to type or copy (Hightlight and Ctrl + c)
and Paste (move to the killbox and place the cursor in the box and Ctrl + V):

C:\WINDOWS\etb

Then check the Delete on Reboot box and DELTREE  then the red button.  Agree you want to remove the file but do not let it reboot yet.


Repeat for:

C:\Program Files\Bquzanz


let it reboot after the last one.

Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.

Run HijackThis and just do a Scan only. Check then Fix Checked the following:

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://empnads.com/servlet/ajrotator/119752/0/viewHTML?zone=enternet

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [Realplayer One] realplay.exe

O4 - HKLM\..\Run: [Messenger] C:\WINDOWS\System32\msgrsv32.exe

O4 - HKLM\..\Run: :emotion-14: C:\windows\temp\6.exe

O4 - HKLM\..\Run: [salm] c:\temp\salm.exe

O4 - HKLM\..\Run: [hcj] C:\WINDOWS\hcj.exe

O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka67.exe

O4 - HKLM\..\Run: [Rwrjy] C:\Program Files\Bquzanz\Bpif.exe

O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"

O4 - HKLM\..\RunServices: [Realplayer One] realplay.exe

O4 - HKCU\..\Run: [Window Monitor] winmon32.exe

O4 - HKCU\..\Run: [NAV Auto Updates] slserves.exe

O4 - HKCU\..\Run: [Norton AntiVirus Sys] NAVsys32.exe

O4 - HKCU\..\Run: [Win32 Wmls Driver] winitr32.exe

O4 - HKCU\..\Run: [Sysino] lsess.exe


O4 - HKCU\..\RunServices: [Window Monitor] winmon32.exe
 

Run ccleaner.exe, uncheck everything on the first page except the two entries
with Temporary and then Run Cleaner.

 

Reboot into regular mode


Run another HijackThis log and post it as a reply. Let's
see how we did.

Ron

23 Posts

September 28th, 2005 06:00

I'm not sure about the instruction "check then fix checked the following"
 
Not sure what exactly to do here.
 
Thanks for your support.

2 Intern

 • 

5.9K Posts

September 28th, 2005 13:00

Run Hijackthis and do a SCAN only.  check the box in front of each of the entries I told you about then hit the Fix Checked button.
 
Ron

23 Posts

September 29th, 2005 09:00

I ran ccleaner.exe after the scan. This is the second hijackthis log.

Thanks again for your help.

Logfile of HijackThis v1.99.1
Scan saved at 11:26:52 AM, on 9/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\HJT\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ccleaner.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eircom.net/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

 

2 Intern

 • 

5.9K Posts

September 29th, 2005 12:00

Log looks clean now.  Do the applications you mentioned at the beginning work now?
 
Ron

23 Posts

September 30th, 2005 06:00

No I'm afraid not. I've tried opening them in safe mode and in normal startup but it's still the same.

Help & Support does not open, system restore opens with a blank page on second click and media

player comes up with a fault and will not run. This all happened after getting some viruses on my 

pc. Thanks again for your help.   

2 Intern

 • 

5.9K Posts

September 30th, 2005 16:00

Try bringing up system restore from the command line:
 
Start, Run, %systemroot%\system32\restore\rstrui.exe , Ok
 
Do you see anything different?
 
Ron

23 Posts

October 3rd, 2005 12:00

I tried it from 'start/run' but it is the very same as before

2 Intern

 • 

5.9K Posts

October 4th, 2005 19:00

Start, Run, sigverif, OK.  When the program comes up press Start.  When it finishes do you see a log of files listed?  Is wininet.dll on the list?  If it's not too many what files does it see?
 
Start, Run, cmd, OK. This should bring up a black cmd screen.  Type:
 
sfc /scannow
 
Does it run through without complaint?  Or does it ask for the XP CD?  Just  hit  cancel if you don't have the CD.
 
You can try reinstalling Window Media Player
 
and see if that will run.
 
I'l have to do some research on an XP system to see what else is required for System Restore.
 
 

23 Posts

October 6th, 2005 14:00

The following files were seen:

oembios.bin  oembios.dat  oembios.sig  omci.sys

ad2kgelp.ini  ad2kregp.dll  ad2kuigp.dll  adpdf7.ppd 

ps5ui.dll  pscripts.dll

sfc/scannow ran through without complaint.

Any further help appreciated.

 

23 Posts

October 6th, 2005 14:00

The following files were seen:

oembios.bin

23 Posts

October 6th, 2005 14:00

The following files were seen:

oembios.bin 

No Events found!

Top