Hi,

I need some help with getting my computer to work. Heres some information on what is wrong with it.

My computer does not work unless I'm in safe mode. Everytime I try to go into normal mode, my computer either A. shuts down continuously or B. Is frozen.

I've tried correcting the problem by running various scans, only when I try to download them the message:

"your security settings prohibit running activex controls on this page" pops up.

This message also pops up when I try to do other things.
I've read up some on how to fix that problem. Which would be to change security settings to medium. I did that 100 times, and try running the scans again. No luck, same thing pops up.

I've also enabled activex in the custom level security settings.

Also, when I try to sign into my email account, I get a message saying " this page cannot be dsiplayed". What is the cause of this? I have to say I have a very limited knowledge of computers and am trying to fix this thing solely based on information from forums. Any help with this anyone? I am enclosing a logfile of hijackthis.

Thanks in advance for any and all responses.

-Gizzard


Logfile of HijackThis v1.99.1
Scan saved at 11:04:09 AM, on 10/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\PivX\PreEmpt\loadsvc.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Gizzard\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [dnam] C:\WINDOWS\system32\d140113.a.Stub.EXE
O4 - HKLM\..\Run: [kdlcyc] C:\WINDOWS\System32\kdlcyc.exe
O4 - HKLM\..\Run: [sjaefiq] C:\WINDOWS\System32\dinysh\sjaefiq.exe
O4 - HKLM\..\Run: [pbsgajaj] C:\WINDOWS\System32\wdvkompr\pbsgajaj.exe
O4 - HKLM\..\Run: [pfuqpm] C:\WINDOWS\System32\xwegkqeq\pfuqpm.exe
O4 - HKLM\..\Run: [ncjasxq] C:\WINDOWS\System32\lfiss\ncjasxq.exe
O4 - HKLM\..\Run: [wqmjpqp] C:\WINDOWS\System32\kqckp\wqmjpqp.exe
O4 - HKLM\..\Run: [youxvftp] C:\WINDOWS\System32\ivudv\youxvftp.exe
O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
O4 - HKLM\..\Run: [ajkiwxny] c:\windows\system32\ajkiwxny.exe -start
O4 - HKLM\..\Run: [hdrnqc] C:\WINDOWS\System32\hdrnqc.exe
O4 - HKLM\..\Run: [qgcxsufz] c:\windows\system32\qgcxsufz.exe -start
O4 - HKLM\..\Run: [brfcqdy] c:\windows\system32\brfcqdy.exe -start
O4 - HKLM\..\Run: [kejmjw] C:\WINDOWS\System32\uaql\kejmjw.exe
O4 - HKLM\..\Run: [stdde] C:\WINDOWS\System32\uypekym\stdde.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [mmxp2passion.exe] C:\WINDOWS\System32\mmxp2passion.exe
O4 - HKLM\..\Run: [nyvp] C:\WINDOWS\System32\bnkpfnlm\nyvp.exe
O4 - HKLM\..\Run: [wpqkmn] C:\WINDOWS\System32\gdcws\wpqkmn.exe
O4 - HKLM\..\Run: [reepk] C:\WINDOWS\System32\harh\reepk.exe
O4 - HKLM\..\Run: [aqao] C:\WINDOWS\System32\pjgjt\aqao.exe
O4 - HKLM\..\Run: [lgmou] C:\WINDOWS\System32\hnykd\lgmou.exe
O4 - HKLM\..\Run: [fxjyt] C:\WINDOWS\System32\csvabk\fxjyt.exe
O4 - HKLM\..\Run: [jrbnov] C:\WINDOWS\System32\wijlyb\jrbnov.exe
O4 - HKLM\..\Run: [dcjud] C:\WINDOWS\System32\uchynuxd\dcjud.exe
O4 - HKLM\..\Run: [dtue] C:\WINDOWS\System32\xwrnsq\dtue.exe
O4 - HKLM\..\Run: [vwrtfu] C:\WINDOWS\System32\ufknhxh\vwrtfu.exe
O4 - HKLM\..\Run: [hhhx] C:\WINDOWS\System32\vjsaqg\hhhx.exe
O4 - HKLM\..\Run: [scnqxyuk] C:\WINDOWS\System32\vacpwwp\scnqxyuk.exe
O4 - HKLM\..\Run: [abnw] C:\WINDOWS\System32\hbnply\abnw.exe
O4 - HKLM\..\Run: [rrwkymy] C:\WINDOWS\System32\wevacoqw\rrwkymy.exe
O4 - HKLM\..\Run: [xuokspm] C:\WINDOWS\System32\nefxmxuj\xuokspm.exe
O4 - HKLM\..\Run: [doepu] C:\WINDOWS\System32\byco\doepu.exe
O4 - HKLM\..\Run: [ggdlpm] C:\WINDOWS\System32\cbhxsiqx\ggdlpm.exe
O4 - HKLM\..\Run: [hckn] C:\WINDOWS\System32\vmbvulo\hckn.exe
O4 - HKLM\..\Run: [urxktas] C:\WINDOWS\System32\lkscqgb\urxktas.exe
O4 - HKLM\..\Run: [arms] C:\WINDOWS\System32\spcy\arms.exe
O4 - HKLM\..\Run: [ebig] C:\WINDOWS\System32\hnfpf\ebig.exe
O4 - HKLM\..\Run: [oqorvbrn] C:\WINDOWS\System32\gyqop\oqorvbrn.exe
O4 - HKLM\..\Run: [cdhul] C:\WINDOWS\System32\rcmorrom\cdhul.exe
O4 - HKLM\..\Run: [uvci] C:\WINDOWS\System32\axuln\uvci.exe
O4 - HKLM\..\Run: [btxbf] C:\WINDOWS\System32\mjpcu\btxbf.exe
O4 - HKLM\..\Run: [rwhcw] C:\WINDOWS\System32\brrsmw\rwhcw.exe
O4 - HKLM\..\Run: [gcdgv] C:\WINDOWS\System32\mwkt\gcdgv.exe
O4 - HKLM\..\Run: [qpkjwnif] C:\WINDOWS\System32\lkaejix\qpkjwnif.exe
O4 - HKLM\..\Run: [qhurys] C:\WINDOWS\System32\cwpo\qhurys.exe
O4 - HKLM\..\Run: [tjhflg] C:\WINDOWS\System32\oexamv\tjhflg.exe
O4 - HKLM\..\Run: [hldkrwkj] C:\WINDOWS\System32\asrpsrl\hldkrwkj.exe
O4 - HKLM\..\Run: [ocqnnx] C:\WINDOWS\System32\emwmmwpj\ocqnnx.exe
O4 - HKLM\..\Run: [euxtl] C:\WINDOWS\System32\cummvf\euxtl.exe
O4 - HKLM\..\Run: [dvrgblg] C:\WINDOWS\System32\shohtxu\dvrgblg.exe
O4 - HKLM\..\Run: [rydqf] C:\WINDOWS\System32\kscps\rydqf.exe
O4 - HKLM\..\Run: [qehgilmy] C:\WINDOWS\System32\lqjsjb\qehgilmy.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [xfunl] C:\WINDOWS\System32\sxitmgkq\xfunl.exe
O4 - HKLM\..\Run: [paxrmtpr] C:\WINDOWS\System32\btwtpn\paxrmtpr.exe
O4 - HKLM\..\Run: [vubrqju] C:\WINDOWS\System32\sxveymny\vubrqju.exe
O4 - HKLM\..\Run: [tcepdjx] C:\WINDOWS\System32\uuwsl\tcepdjx.exe
O4 - HKLM\..\Run: [asgjrei] C:\WINDOWS\System32\jpffbiyh\asgjrei.exe
O4 - HKLM\..\Run: [fpuvw] C:\WINDOWS\System32\gujtpr\fpuvw.exe
O4 - HKLM\..\Run: [nitvovc] C:\WINDOWS\System32\bdkb\nitvovc.exe
O4 - HKLM\..\Run: [xsksucka] C:\WINDOWS\System32\hvsaa\xsksucka.exe
O4 - HKLM\..\Run: [mc-58-12-] C:\WINDOWS\System32\mc-58-12-
O4 - HKLM\..\Run: [adcomplusanalytic.exe] C:\WINDOWS\System32\adcomplusanalytic.exe
O4 - HKLM\..\Run: [tvs_b] c:\Program Files\tvs\tvs_ln.exe
O4 - HKLM\..\Run: [AntiAdware.exexeg] C:\WINDOWS\System32\AntiAdware.exexeg
O4 - HKLM\..\Run: [piplpbtq] C:\WINDOWS\System32\jqmpqgh\piplpbtq.exe
O4 - HKLM\..\Run: [vjyq] C:\WINDOWS\System32\odyoucps\vjyq.exe
O4 - HKLM\..\Run: [edqdehc] C:\WINDOWS\edqdehc.exe
O4 - HKLM\..\Run: [smbya] C:\WINDOWS\System32\xvoo\smbya.exe
O4 - HKLM\..\Run: [lrxhu] C:\WINDOWS\System32\ldyljwox\lrxhu.exe
O4 - HKLM\..\Run: [shnin] C:\DOCUME~1\Dewey\LOCALS~1\Temp\ftwrhtaw.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [dlsid] C:\WINDOWS\System32\yiayvhh\dlsid.exe
O4 - HKLM\..\Run: [njjqe] C:\WINDOWS\System32\nchgd\njjqe.exe
O4 - HKLM\..\Run: [kxixc] C:\WINDOWS\System32\nykwi\kxixc.exe
O4 - HKLM\..\Run: [dovueq] C:\WINDOWS\System32\qoyv\dovueq.exe
O4 - HKLM\..\Run: [nooqdxxd] C:\WINDOWS\System32\awjfgv\nooqdxxd.exe
O4 - HKLM\..\Run: [cxeim] C:\WINDOWS\System32\lgylj\cxeim.exe
O4 - HKLM\..\Run: [rcjg] C:\WINDOWS\System32\nvbxbrhh\rcjg.exe
O4 - HKLM\..\Run: [glhomhd] C:\WINDOWS\System32\murwfoay\glhomhd.exe
O4 - HKLM\..\Run: [vwohxf] C:\WINDOWS\System32\vwdp\vwohxf.exe
O4 - HKLM\..\Run: [ryom] C:\WINDOWS\System32\hnhmns\ryom.exe
O4 - HKLM\..\Run: [xciro] C:\WINDOWS\System32\usql\xciro.exe
O4 - HKLM\..\Run: [paokoogp] C:\WINDOWS\System32\llwqejuk\paokoogp.exe
O4 - HKLM\..\Run: [rallieg] C:\WINDOWS\System32\rkfgeyy\rallieg.exe
O4 - HKLM\..\Run: [vgikrg] C:\WINDOWS\System32\chpi\vgikrg.exe
O4 - HKLM\..\Run: [jiaawb] C:\WINDOWS\System32\ygtr\jiaawb.exe
O4 - HKLM\..\Run: [nmlajbl] C:\WINDOWS\System32\gsriuyx\nmlajbl.exe
O4 - HKLM\..\Run: [iaglojj] C:\WINDOWS\System32\vsigdy\iaglojj.exe
O4 - HKLM\..\Run: [jkmcvvq] C:\WINDOWS\System32\bbieffa\jkmcvvq.exe
O4 - HKLM\..\Run: [agvojsrj] C:\WINDOWS\System32\vcblcoin\agvojsrj.exe
O4 - HKLM\..\Run: [ttgg] C:\WINDOWS\System32\smpml\ttgg.exe
O4 - HKLM\..\Run: [alpi] C:\WINDOWS\System32\rtvi\alpi.exe
O4 - HKLM\..\Run: [oaaryiid] C:\WINDOWS\System32\ojfgnt\oaaryiid.exe
O4 - HKLM\..\Run: [lvnv] C:\WINDOWS\System32\avkx\lvnv.exe
O4 - HKLM\..\Run: [osglzdn] C:\WINDOWS\osglzdn.exe
O4 - HKLM\..\Run: [uedmc] C:\WINDOWS\System32\dxfo\uedmc.exe
O4 - HKLM\..\Run: [uujpoqtn] C:\WINDOWS\System32\jikqy\uujpoqtn.exe
O4 - HKLM\..\Run: [gvfpiqa] C:\WINDOWS\System32\ygnqxgcv\gvfpiqa.exe
O4 - HKLM\..\Run: [qpcxfo] C:\WINDOWS\System32\mwliaboe\qpcxfo.exe
O4 - HKLM\..\Run: [urpqp] C:\WINDOWS\System32\kkbd\urpqp.exe
O4 - HKLM\..\Run: [ppynr] C:\WINDOWS\System32\oqtw\ppynr.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [gtia] C:\WINDOWS\System32\mqmelsg\gtia.exe
O4 - HKLM\..\Run: [cixu] C:\WINDOWS\System32\ycukpk\cixu.exe
O4 - HKLM\..\Run: [jkfa] C:\WINDOWS\System32\lhvqc\jkfa.exe
O4 - HKLM\..\Run: [icltoqd] C:\WINDOWS\System32\hbais\icltoqd.exe
O4 - HKLM\..\Run: [vlkwani] C:\WINDOWS\System32\lpfmfbrb\vlkwani.exe
O4 - HKLM\..\Run: [rvsg] C:\WINDOWS\System32\yahrqq\rvsg.exe
O4 - HKLM\..\Run: [wvrlc] C:\WINDOWS\System32\svsub\wvrlc.exe
O4 - HKLM\..\Run: [skgkllcm] C:\WINDOWS\System32\cihbq\skgkllcm.exe
O4 - HKLM\..\Run: [yramdhm] C:\WINDOWS\System32\qlxnaghd\yramdhm.exe
O4 - HKLM\..\Run: [dmblv.exe] C:\WINDOWS\System32\dmblv.exe
O4 - HKLM\..\Run: [Zsys] C:\WINDOWS\System32\zsys.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: PreEmpt.lnk = C:\Program Files\PivX\PreEmpt\PreEmptST.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone:
O15 - Trusted Zone: (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\nosunel.mht!
O18 - Protocol: aim - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: shell - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - (no file)
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\osepro32.dll
O20 - Winlogon Notify: tcpG4T - tcpG4T.dll (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGV3ZXkA\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: PreEmpt (qfcoresvc) - PivX Solutions, Inc. - C:\Program Files\PivX\PreEmpt\loadsvc.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: uedmcdxfo - Unknown owner - C:\WINDOWS\System32\dxfo\uedmc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Dani AI

Generated

The symptoms described — a system that only runs stably in Safe Mode, repeated failures to run ActiveX controls despite changing IE security, and a HijackThis log littered with random autorun entries and modified notification/shell items — point to multiple persistent trojans/backdoors rather than a simple browser setting problem. As observed, this looks like a heavy compromise where surface fixes often fail because components reinstall or intercept network/IE activity.

Immediate triage: isolate the PC (disconnect network/wifi) and preserve only personal data (documents, pictures, mail stores). Do not copy program folders or .exe, .scr, *.vbs files. Disable System Restore before attempting removals (restore points commonly reintroduce malware on Windows XP). ActiveX/“page cannot be displayed” errors are commonly caused by malware altering IE settings, proxy/hosts entries, or installing a local filtering proxy — those symptoms usually clear only after the malicious software is removed.

Recommended cleanup path: the most reliable approach for infections this deep is an offline scan from a trusted rescue CD/USB (bootable antivirus/rescue environment) to find rootkits and files that load before Windows. After offline removal, run up-to-date anti-malware tools and a rootkit scanner from Safe Mode, then use Autoruns (Sysinternals) to inspect and remove any remaining startup entries. Manual registry edits (restoring the Winlogon/Shell value to Explorer.exe and deleting obvious malicious Run entries) work but carry risk and should be done only if comfortable with the registry. For many users, a confirmed full format-and-reinstall is the fastest, safest recovery.

Recovery steps after cleaning: change all passwords from a known-clean machine; scan any backed-up files before restoring; install current service packs/patches and a reputable AV with real-time protection. A fresh Autoruns/HijackThis report after these steps is the usual way to verify persistence items have been removed.

Recommended Answers

All 4 Replies

also, another quick example of not being able to run scans is one of the messages I get when I try:

Failed to load ActiveX control!
-- You must have administrative rights on this computer;
you also must have the Internet Explorer security settings to the Medium level

Just wanted to elaborate on not being able to sign into my email account, as it is really pissing me off. I have managed to get into the " normal computer mode" for the time being. But cannot sign into my email account, access other accounts and sign into usernames. Such as ebay and such. I try to sign in and get the message:

The page cannot be displayed
The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings.

Can anyone please tell me what to do to remedy this problem?

Thanks for the loads of helping information. But I've been able to correct the problem myself.

Thanks for the loads of helping information.

We are volunteers here, and provide help in our own spare time (of which we have precious little). The fact that your particular problem was not addressed within 14 hours is not unusual on this support forum or any other.

By the way- your system is very infected, judging from hte HJT log you posted. You may have solved the immediately visible symptoms, but I highly doubt that your system is entirely clean. Feel free to post a new HJT log if you'd like; we can tell you if it still shows signs of infections.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.