Hi Guys! Haven't been around here for awhile becuase I don't like to bother much with hijack logs, but I've been battling this for days and cannot get rid of ti with the stuff I already learned here, so here I am.

This is the log I took before I borrowed this computer from my Sis:

Logfile of HijackThis v1.99.1
Scan saved at 11:14:44 AM, on 8/27/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SBUTILS\SBWEBHOST.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\HPZTSB10.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
C:\PROGRAM FILES\HP\HPCORETECH\HPCMPMGR.EXE
C:\PROGRAM FILES\DROPBOX\DROPBOX\DROPBOX.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\BACKWEB\BACKWEB\PROGRAM\BWDELAY.EXE
C:\MY DOCUMENTS\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [DJRegFix] regedit /s c:\hp\djregfix.reg
O4 - HKLM\..\Run: [HPLogiFinder] \WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb10.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\PROGRAM FILES\HP\HPCORETECH\HPCMPMGR.EXE"
O4 - HKLM\..\Run: [DropBoxUtility] "C:\Program Files\DropBox\DropBox\DropBox.exe" /s
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [PavProc] "C:\Program Files\Common Files\Panda Software\PavShld\PavPrS9x.exe"
O4 - HKCU\..\Run: [MoneyStartUp] C:\Program Files\Microsoft Money\System\Money Startup.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com

And these are the two errors I get whenever I go online (my modem works perfectly well but then I get kicked out because something is not letting the sofware work to connnect me to Google or whatever)>

Iexplore has caused an error in Wininet.dll

And if I use Firefox (which I prefer) it gives me this error as an explanation for kicking me out and breaking the connection:

Firefox has caused an error in run32.dll

So I know I have a critter. :rolleyes:
I survived a few days by just going into save mode, and then start, run, %temp% and deleting everything in there. But the machine began to rebel on me and now I'm getting this error. The last computer shop where I took my computer took out my firewall and pop-up blocker and now I'm dead in the water, so to speak. I cannot currently afford to buy a firewall, so I need to tips to survive till I can. (I'm sick and can't work as much as I used to.):o

Thank you very much for your help.

2
Contributors
6
Replies
7
Views
11 Years
Discussion Span
Last Post by goodtaste

Hi goodtaste,

I don't see a sign of an infection. But from my own experience with 98/SE/ME I know that they like to get wrecked after some time. Anyway, your computer seems to be a Sony Vaio, since I found SBWEBHOST.EXE in your log. Read here why the content of this folder C:\WINDOWS\SYSTEM\SBUTILS\... is considered as spyware. But since it was there all the time, this has most likely nothing to do with your problem.

Then I don't know what "Dropbox" is, but it doesn't seem to be nasty. Maybe it was installed recently and since it's a running process, maybe this one is part of your problem?

Hi Xpenetrator! Thank you for answering me so soon. I don't have a Sony Vaio (I wish I did!!") I have an HP from the box. But this is the first time I had so much trouble. I've had spyware before, but to make Mozila fail and IE fail, this is a first, so I thought it was something really bad. Dropbox is one of those free software thingies that are used to exchange photos online with your friends (like Photobucket, and others). Maybe my machine doesn't like it????:o

I don't understand it.

Hi goodtaste,

I don't see a sign of an infection. But from my own experience with 98/SE/ME I know that they like to get wrecked after some time. Anyway, your computer seems to be a Sony Vaio, since I found SBWEBHOST.EXE in your log. Read here why the content of this folder C:\WINDOWS\SYSTEM\SBUTILS\... is considered as spyware. But since it was there all the time, this has most likely nothing to do with your problem.

Then I don't know what "Dropbox" is, but it doesn't seem to be nasty. Maybe it was installed recently and since it's a running process, maybe this one is part of your problem?

You're welcome. :) What exactly are the error messages? It should say something like "Internet Exploder has caused an page fault error in... " Can you click somewhere on the error message windows to get more info? Then try to remember what you did/installed/tweaked or tampered with before the errors came up?

Dropbox is one of those free software thingies that are used to exchange photos online with your friends (like Photobucket, and others). Maybe my machine doesn't like it????

If you installed that thingie just before the trouble started, maybe it really doesn't like it. Every software that connects to the internet for any reason is suspect to be the cause of the problem. If you can deinstall them safely to see if something changes, give it a try.

AFAIK Windows ME doesn't take version checking too seriously, too. This means every installation of some software can overwrite essential system files with newer, older or tweaked ones, causing a lot of trouble which is generally a pain in the button to investigate. This leads me to the last question for now: Did you ever update your ME? If yes, when and what and how?

BTW, You'll find some software recommendation threads in these forums and you will find links to free software firewalls there, too. Ah...yes..."Zonealarm" is very popular and free. (Doesn't mean that it's good, but better than nothing anyway ;))

You are right, it is the DropBox thingy. I need it though, so what I have learned is the following (just in case you get anyone else with this problem) if I move too quickly to go online and don't give the Dropbox thingy time to load before I go tot he internet, I get that problem, if I let it load until the little camera symbol appears on the bar where the start button is, then I have no problems. Funny isn't it? Something so simple causing me so much trouble as to not letting me load either Mozilla or IE!!! But that has been the only thing I have observed. When you pointed out to me the new software, I got it.

Thanks!

You're welcome and I thank you, too for sharing your insights here and reporting your problem solved.

Thanks to you, guys! I've learned tons over here. :)

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.