0

I am using windows xo pro sp1. When I am on a site I need to stay on and click refresh IE6 will work for awhile and then it will go to page cannot be displayed, at the bottom is cannot find server or dns error. I thought at first something was corrupt, so I reformatted and installed the same os. It started this again before any programs were reinstalled. When it does this I can close that page and try and reopen IE6 but I get the same error. The only way it will work is to reboot and everything goes along fine for a little while, then I get the error. I can't even log off and log back in again to get it to work. I know my connection to the internet is okay, because I can still get mail in and msn messenger is working fine, just IE6 has died.
Does anyone know what is causing this or how to sure it?

14
Contributors
43
Replies
45
Views
13 Years
Discussion Span
Last Post by infinit3
0

Did you update your IE6 at M$'s site? There are a few updates to be had after a reformat.

Yes all updates are current.
It did this after reformatting, before the updates were done, and still did the same thing after the updates were completed.
Thanks

0

Yes all updates are current.
It did this after reformatting, before the updates were done, and still did the same thing after the updates were completed.
Thanks

Maybe your DHCP server is not renewing your lease? Next time you get the DNS error, open up a DOS box and type in ipconfig /all
to see if you still have an IP...or anything other than 169.254.x.x

One suggestion is to hard code with static IP and DNS servers instead of relying on DHCP.

0

Maybe your DHCP server is not renewing your lease? Next time you get the DNS error, open up a DOS box and type in ipconfig /all
to see if you still have an IP...or anything other than 169.254.x.x

One suggestion is to hard code with static IP and DNS servers instead of relying on DHCP.

Whenever I have problems connecting to the net, I do check my IP address - if it's 169 etc I do release and renew it. With a 169 number I cannot access anything at all - and as I said when the browser goes down I can still chat on msn messenger and get the mail in and send it out.
Thanks so much for this help Chanto

0

Whenever I have problems connecting to the net, I do check my IP address - if it's 169 etc I do release and renew it. With a 169 number I cannot access anything at all - and as I said when the browser goes down I can still chat on msn messenger and get the mail in and send it out.
Thanks so much for this help Chanto

Does your web browser connect thru a web proxy server or are you running some sort of web caching software? firewall software? Check the proxy setting under Tools --> Advanced --> Connection. If haven't yet, click off all proxy settings to see if that'll fix it or not.

0

Does your web browser connect thru a web proxy server or are you running some sort of web caching software? firewall software? Check the proxy setting under Tools --> Advanced --> Connection. If haven't yet, click off all proxy settings to see if that'll fix it or not.

All proxy settings are turned off. I'm using PC Cillin for my AV and firewall.
Web caching software? I don't think so - not familiar with this.
Thanks for trying to help me on this.

0

Your next step should be to check for spyware, at least to eliminate the possibility.
Download HijackThis from http://209.133.47.200/~merijn/files/HijackThis.exe & unzip it into it's own, permanent folder, not a temporary one. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file & paste it into the body of your post. DO NOT FIX ANYTHING YET.

0

Your next step should be to check for spyware, at least to eliminate the possibility.
Download HijackThis from http://209.133.47.200/~merijn/files/HijackThis.exe & unzip it into it's own, permanent folder, not a temporary one. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file & paste it into the body of your post. DO NOT FIX ANYTHING YET.

I hope this helps :)
Thanks

Logfile of HijackThis v1.97.7
Scan saved at 9:16:39 AM, on 4/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe
C:\Program Files\TuneUp Utilities 2004\MemOptimizer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DC++\DCPlusPlus.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HighJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mysearchnow.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2004\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKLM\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Christine"
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Christine"
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FLASHGET\jc_link.htm
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 - Extra button: NeoTrace It! (HKCU)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38077.313275463
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

0

You have a CWS infection. Download CWShredder from http://209.133.47.200/~merijn/files/CWShredder.exe & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs & windows, including IE, before running CWShredder. Reboot after doing this & post another log please.

Also you should uninstall Messenger Plus as it comes with Lop. You can reinstall it manually & refuse the 3rd party sponsor.

0

You have a CWS infection. Download CWShredder from http://209.133.47.200/~merijn/files/CWShredder.exe & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs & windows, including IE, before running CWShredder. Reboot after doing this & post another log please.

Also you should uninstall Messenger Plus as it comes with Lop. You can reinstall it manually & refuse the 3rd party sponsor.

Here is the new log after doing what you told me to do :)

Logfile of HijackThis v1.97.7
Scan saved at 12:23:03 PM, on 4/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe
C:\Program Files\TuneUp Utilities 2004\MemOptimizer.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\HighJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2004\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 - Extra button: NeoTrace It! (HKCU)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38077.313275463
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

0

Close all (browser) windows & have HJT fix these entries=

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)

And that's clean after that. Still have the problem??

0

Close all (browser) windows & have HJT fix these entries=

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)

And that's clean after that. Still have the problem??

Thank you so much Crunchie - you're amazing ;)
I did get rid of this file :)
I'll run my normal 'stuff' for the rest of the day and I will let you know in the morning if it's all fixed.
I will never be able to thank you enough if you've cured this mess.

0

Thank you so much Crunchie - you're amazing ;)
I did get rid of this file :)
I'll run my normal 'stuff' for the rest of the day and I will let you know in the morning if it's all fixed.
I will never be able to thank you enough if you've cured this mess.

Hi Crunchie
It did great until a few minutes ago....4.25pm The same thing happened, I was so disappointed.......but it did last about three hours this afternoon.
Do you have any other ideas?
Thanks so much for helping me on this.

0

Hi Crunchie
It did great until a few minutes ago....4.25pm The same thing happened, I was so disappointed.......but it did last about three hours this afternoon.
Do you have any other ideas?
Thanks so much for helping me on this.

Can you post another log plz.

0

Try this:

Go to START>>RUN and type in:

rundll32 setupwbv.dll,IE6Maintenance

... that will repair any problems with IE

0

Can you post another log plz.

Yesterday afternoon - I did the updates (thinking this might help - and also upgraded to XP Pro SP1a). Then a few minutes ago the browser did the same thing, and I had to reboot to get it back, this is the second time today.
My hubbies machine is running windows 2000 and its sitting there on the same page, just working away nicely. I just don't like 2000.

Here is the new log file you asked for. Oh I ran hickjackthis earlier today - and that file you asked me to get rid of was back again, so I deleted it once more, before sending this to you - I checked and it hasn't return.

Thanks so much for your help.


Logfile of HijackThis v1.97.7
Scan saved at 10:32:03 AM, on 4/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\WINDOWS\System32\taskswitch.exe
C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe
C:\Program Files\TuneUp Utilities 2004\MemOptimizer.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\HighJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [PowerMenu] "%systemroot%\system32\powermenu.exe" -hideself on
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2004\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FLASHGET\jc_link.htm
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: NeoTrace It! (HKCU)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38077.313275463
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

0

Try this:

Go to START>>RUN and type in:

rundll32 setupwbv.dll,IE6Maintenance

... that will repair any problems with IE

Thanks Lori
Let me see what Crunchie says and then I might try this, if he thinks I should.

0

Ok.

I too read logs, and see these things - you can too ask him if you like:

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file) "THIS IS FLASH GET" - it causes problems with IE and you can read that here

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime "this is a massive resource hog"

O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FLASHGET\jc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FLASHGET\jc_link.htm

Make sure that ALL windows are closed before fixing anything with Hijack This.

If any of the above comes back after fix, reboot to safe mode, and fix from there.

Did you uninstall Messenger Plus as advised before? This is important for you to do if you did not.

You also have a mass of tools/utilites you are using - you can't ever be sure that they are aiding to your problem - and therefore I always recommend the uninstallation of them until all is solved. Therefore, if it were me, I would get rid of: Cool Switch, PowerMenu, System Mechanic Popup Stopper, TuneUp MemOptimizer, and Window Washer.

I would then make sure ALL problems are fixed - eliminate the use of the PopUp stopper and instead utilize the Google Toolbar, or the Avant Browser. Then if you must have the above utilities, reinstall them and test things after each is put on.

The above is just MY technical assessment on your issues... Get a second opinion if that makes you more comfortable since I am new to this forum ;)

0

The above is just MY technical assessment on your issues... Get a second opinion if that makes you more comfortable since I am new to this forum.

I second your evaluation, and add one. Unless you have a strong need for it, disable or remove:

O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe

It's a chipset/motherboard monitor that is a resource hog. If you like that sort of thing, disable it and try Motherboard Monitor instead--but I would just plain remove it, myself.

0

Ok.

I too read logs, and see these things - you can too ask him if you like:

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file) "THIS IS FLASH GET" - it causes problems with IE and you can read that here

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime "this is a massive resource hog"

O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FLASHGET\jc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FLASHGET\jc_link.htm

Make sure that ALL windows are closed before fixing anything with Hijack This.

If any of the above comes back after fix, reboot to safe mode, and fix from there.

Did you uninstall Messenger Plus as advised before? This is important for you to do if you did not.

You also have a mass of tools/utilites you are using - you can't ever be sure that they are aiding to your problem - and therefore I always recommend the uninstallation of them until all is solved. Therefore, if it were me, I would get rid of: Cool Switch, PowerMenu, System Mechanic Popup Stopper, TuneUp MemOptimizer, and Window Washer.

I would then make sure ALL problems are fixed - eliminate the use of the PopUp stopper and instead utilize the Google Toolbar, or the Avant Browser. Then if you must have the above utilities, reinstall them and test things after each is put on.

The above is just MY technical assessment on your issues... Get a second opinion if that makes you more comfortable since I am new to this forum ;)

First off Lori - I apologise if I sounded like I didn't trust you - that wasn't the case. I do appreciate you taking the time to help me on this.
I did in fact uninstall msn plus and reinstall it like I was told to.
I haven't a clue how to get rid of cool switch - power menu - I don't know where they came from.
Did you mean uninstall window washer? I thought it did a great job of cleaning - or so I was told wrong.
I will get the avant browser - and until then I would like to use popup stopper, plus I don't know a thing about the google toolbar - does this stop popups?

I have run another highjackthis after cleaning up and rebooting...here it is....
I did try the repair on IE6 and got this message:
error loading rundll32 setupwbv.dll,IE6Maintenance
the specified module could not be found.
As you can tell I am going cuckoo with this mess.
Once again many many apologises to you.
Oh this PC is a P4 2.2 with 512DDR

Logfile of HijackThis v1.97.7
Scan saved at 7:46:29 PM, on 4/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe
C:\HighJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe"
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38077.313275463

0

I haven't a clue how to get rid of cool switch - power menu - I don't know where they came from.

PowerMenu is easy, though it doesn't seem to be a problem. Just delete the icon from the Startup folder and remove the directory it "lives" in. CoolSwitch is part of the Windows XP PowerToys suite, and should be removeable from the Add/Remove Programs menu.

The Google toolbar has a good pop-up stopper, among other things.

The only line that seems to remain is:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

0

PowerMenu is easy, though it doesn't seem to be a problem. Just delete the icon from the Startup folder and remove the directory it "lives" in. CoolSwitch is part of the Windows XP PowerToys suite, and should be removeable from the Add/Remove Programs menu.
The Google toolbar has a good pop-up stopper, among other things.
The only line that seems to remain is:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

well everything that had 'powertoys' in add and remove has gone.

I have got rid of the popup stopper - and have got google as my home page and installed the toolbar....I honestly had never seen or heard of it before.

Do you mean to get rid of this?
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =Thanks

Here is the latest highjack this log....there still looks like a lot in it - ;)

Logfile of HijackThis v1.97.7
Scan saved at 8:46:57 PM, on 4/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\WINDOWS\System32\msiexec.exe
C:\HighJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
O4 - HKLM..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
O4 - HKLM..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38077.313275463

Edited by deceptikon: Fixed formatting

0

Hello again :)

Ok - first, Google toolbar does block pop-ups. You can get it here if you choose that over the Avant Browser.

You can keep all those utilites, including WindowWasher - I just tell users to uninstall them when we are troubleshooting problems. Then to reinstall after all problems are solved ;)

NOW BACK TO IE:

Here are some more ways to fix this without needing to install IE:

Empty Temporary Internet Files
The database which controls the Temporary Internet Files can go corrupt. The effect will be considerable slow downs and extensive usage of the CPU. A broken file cache can also block Internet Explorer from saving images in other formats than BMP. To solve this one need to clear this file cache.

Sometimes clearing the Temporary Internet Files cache can solve problems with loading of web pages. To clear the Temporary Internet Files go here :

Control Panel -> Internet Options -> General Tab -> Temporary Internet Files -> Delete Files...

Controlling the Temporary Internet Files
Both Internet Explorer and Outlook Express can have trouble with a large Temporary Internet File cache. Leading to problems in loading web pages and sending emails with large attachements.

To configure the amount of space assigned to the Temporary Internet Files go here (Assign about 10 MByte) :

Control Panel -> Internet Options -> General Tab -> Temporary Internet Files -> Settings...

You can also move the Temporary Internet Files so they don't cause file fragmentation, because of the files is constantly created and deleted.

Control Panel -> Internet Options -> General Tab -> Temporary Internet Files -> Settings... -> Move Folder

Delete the cookies
Cookies are used by websites to identify you and might be used for storing passwords or spying on your actions. Cookies can become corrupted and affect the access to a web-site. Only solution is to delete the corrupted cookies, which can be located in the directory containing Temporary Internet Files

Restore Internet-Security-Policy to default

Control Panel -> Internet Options -> Security-tab -> Select "Internet" -> Press "Default Level"-button

Restore Internet Explorer Options to default
Control Panel -> Internet Options -> Advanced-tab -> Press "Restore Defaults"-button

You might want to consider in to uncheck "Enable third-party browser extensions (requires restart)" to disable funny 3rd party plugins, but it will also keep other valid programs from integrating with Internet Explorer.

Close all instances of Internet Explorer, click Start, point to Settings, and then click Control Panel.
Double-click Internet Options.
Click the Advanced tab.
Under Browsing, click to clear the Enable third-party browser extensions (requires restart) check box.
Restart Internet Explorer.

Restore Internet Explorer as the default browser

Control Panel -> Internet Options -> Programs-tab -> Tick "Internet Explorer should check to see if it is the default" and press Apply-button

Check that the HOSTS file do not contain any entries
If having trouble accessing certain sites or pictures, then it might be caused by the hosts file blocking access.

The HOSTS file is usually found here:

Windows XP = C:\Winnt\System32\Drivers\etc\

The HOSTS file can be used to ban access to certain domains. This is useful when not wanting to load stuff from certain domains like banners and and advertisers, which in the end will lead to quicker browsing. It can also be blocking the domains you need to get to. If you think this may be it, PM me, and we can look further into it :)

Re-Register some DLLs which IE uses
Open a command prompt or use Start-Button -> Run.. to execute each of the below lines.

regsvr32 Shdocvw.dll
regsvr32 Shell32.dll
regsvr32 Oleaut32.dll
regsvr32 Ole32.dll
regsvr32 Actxprxy.dll
regsvr32 Mshtml.dll
regsvr32 Urlmon.dll
regsvr32 Inseng.dll
regsvr32 Browseui.dll
regsvr32 Msjava.dll
regsvr32 Jscript.dll


Restore some DLLs which IE uses

Shdocvw.dll
Shell32.dll
Oleaut32.dll
Actxprxy.dll
Mshtml.dll
Urlmon.dll
Inseng.dll
Browseui.dll

Lets try some of those and see where that gets us ;)

0

Sorry about the double info ---- I was typing out the above while Michael was replying :)

... and this is STILL there:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

0

Sorry about the double info ---- I was typing out the above while Michael was replying :)

... and this is STILL there:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

Hi Lori
I gave this a break for awhile before I slung it out the door. I reregister the dll's and all went well ( suprised me as I have never done this before) - but when it came to this :-
Restore some DLLs which IE uses
Shdocvw.dll
Shell32.dll
Oleaut32.dll
Actxprxy.dll
Mshtml.dll
Urlmon.dll
Inseng.dll
Browseui.dll

I ran into this "Editing or modifying them could damage your system. If you still want to open the file click open otherwsie click cancel.
So I cancelled - I have never done this before and didn't want to make things worse without your help.

Was this a normal warning? If you still want me to do it - please tell me how :)
I came close to reformatting and going back to ME or 98SE today - and hubby had a fit, after what the program cost. Plus he bought me office 2003 pro - that wouldn't cause the problem would it?
He's not totally happy with me right now.
Thank you so much.

0

How are things going after reregistering?

If it is still not working THEN we can go forward - LMK :)

0

How are things going after reregistering?

If it is still not working THEN we can go forward - LMK :)

Hi Lori
It's still doing it - just as bad :(

Thanks SO much for helping me.

0

Can you please run both AdAware (please update first) and Hijack This again and post BOTH result logs for me -- I want to work with fresh stuff after the above changes :)

0

Hi Lori
Here are the two files you requested.
Hope it tells you something :)


Lavasoft Ad-aware Professional Build 158
Logfile created on :Monday, April 19, 2004 11:58:41 AM
Using reference-file :0R150 05.07.2003
______________________________________________________
Ad-aware Settings
=========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry


Listing running processes

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 4-19-2004 3:27:56 PM
BasePriority : Normal


#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 4-19-2004 3:27:59 PM
BasePriority : High


#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-19-2004 3:27:59 PM
BasePriority : Normal
FileSize : 97 KB
FileVersion : 5.1.2600.1224 (xpsp2.030516-0318)
ProductVersion : 5.1.2600.1224
Copyright : Microsoft Corporation. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft Windows Operating System
Created on : 5/19/2003 6:09:48 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 5/19/2003 6:09:48 PM

#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-19-2004 3:27:59 PM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
Copyright : Microsoft Corporation. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft Windows Operating System
Created on : 8/29/2002 1:41:26 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 8/29/2002 1:41:26 PM

#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-19-2004 3:28:00 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
Copyright : Microsoft Corporation. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft Windows Operating System
Created on : 9/3/2002 10:53:32 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/3/2002 10:53:32 PM

#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 4-19-2004 3:28:00 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
Copyright : Microsoft Corporation. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft Windows Operating System
Created on : 9/3/2002 10:53:32 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/3/2002 10:53:32 PM

#:7 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-19-2004 3:28:01 PM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
Copyright : Microsoft Corporation. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft Windows Operating System
Created on : 9/3/2002 10:53:26 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/3/2002 10:53:26 PM

#:8 [tmntsrv.exe]
FilePath : C:\Program Files\Trend Micro\PC-cillin 2003\
ThreadCreationTime : 4-19-2004 3:28:03 PM
BasePriority : Normal
FileSize : 204 KB
FileVersion : 10.0.4.1114
ProductVersion : 10.0.4
Copyright : Copyright (C) 1995-2003 Trend Micro Incorporated. All rights reserved.
CompanyName : Trend Micro Incorporated.
FileDescription : Tmntsrv
InternalName : Tmntsrv
OriginalFilename : Tmntsrv.exe
ProductName : Trend Pc-cillin 10.04
Created on : 9/16/2003 8:05:08 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/16/2003 8:05:08 PM

#:9 [tmproxy.exe]
FilePath : C:\Program Files\Trend Micro\PC-cillin 2003\
ThreadCreationTime : 4-19-2004 3:28:03 PM
BasePriority : Normal
FileSize : 272 KB
FileVersion : 10.0.4.1114
ProductVersion : 10.0.4
Copyright : Copyright (C) 1995-2003 Trend Micro Incorporated. All rights reserved.
CompanyName : Trend Micro Incorporated.
FileDescription : tmproxy
InternalName : tmproxy
OriginalFilename : tmproxy.exe
ProductName : Trend Pc-cillin 10.04
Created on : 9/16/2003 8:09:02 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/16/2003 8:09:02 PM

#:10 [pccpfw.exe]
FilePath : C:\Program Files\Trend Micro\PC-cillin 2003\
ThreadCreationTime : 4-19-2004 3:28:04 PM
BasePriority : Normal
FileSize : 632 KB
FileVersion : 10.0.4.1114
ProductVersion : 10.0.4
Copyright : Copyright (C) 1995-2003 Trend Micro Incorporated. All rights reserved.
CompanyName : Trend Micro Incorporated.
FileDescription : PCCPFW
InternalName : PCCPFW
OriginalFilename : PCCPFW.exe
ProductName : Trend Pc-cillin 10.04
Created on : 9/16/2003 8:00:36 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/16/2003 8:00:36 PM

#:11 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 4-19-2004 3:28:06 PM
BasePriority : Normal
FileSize : 973 KB
FileVersion : 6.00.2800.1221 (xpsp2.030511-1403)
ProductVersion : 6.00.2800.1221
Copyright : Microsoft Corporation. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft Windows Operating System
Created on : 5/12/2003 1:12:10 AM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 5/12/2003 1:12:10 AM

#:12 [pccguide.exe]
FilePath : C:\Program Files\Trend Micro\PC-cillin 2003\
ThreadCreationTime : 4-19-2004 3:28:08 PM
BasePriority : Normal
FileSize : 632 KB
FileVersion : 10.0.4.1114
ProductVersion : 10.0.4
Copyright : Copyright (C) 1995-2003 Trend Micro Incorporated. All rights reserved.
CompanyName : Trend Micro Incorporated.
FileDescription : PCCGuide
InternalName : PCCGuide
OriginalFilename : PCCGuide
ProductName : Trend Pc-cillin 10.04
Created on : 9/16/2003 8:08:50 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/16/2003 8:08:50 PM

#:13 [pccclient.exe]
FilePath : C:\Program Files\Trend Micro\PC-cillin 2003\
ThreadCreationTime : 4-19-2004 3:28:10 PM
BasePriority : Normal
FileSize : 708 KB
FileVersion : 10.0.4.1114
ProductVersion : 10.0.4
Copyright : Copyright (C) 1995-2003 Trend Micro Incorporated. All rights reserved.
CompanyName : Trend Micro Incorporated.
FileDescription : PCCClient
InternalName : PCCClient
OriginalFilename : PCCClient
ProductName : Trend Pc-cillin 10.04
Created on : 9/16/2003 7:59:42 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 9/16/2003 7:59:42 PM

#:14 [msgplus.exe]
FilePath : C:\Program Files\Messenger Plus! 2\
ThreadCreationTime : 4-19-2004 3:28:10 PM
BasePriority : Normal
FileSize : 136 KB
FileVersion : 2, 54, 0, 74
ProductVersion : 2, 54, 0, 74
Copyright : Copyright (C) 2001-2003
CompanyName : Patchou
FileDescription : Messenger Plus!
InternalName : MsgPlus
OriginalFilename : MsgPlus.exe
ProductName : Messenger Plus! 2
Created on : 4/13/2004 4:37:25 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 4/13/2004 4:37:26 PM

#:15 [dcplusplus.exe]
FilePath : C:\Program Files\DC++\
ThreadCreationTime : 4-19-2004 3:28:13 PM
BasePriority : Normal
FileSize : 892 KB
FileVersion : 0, 4, 0, 1
ProductVersion : 0, 4, 0, 1
Copyright : Copyright 2001-2003 Jacek Sieka
FileDescription : DC++
InternalName : DC++
OriginalFilename : DCPlusPlus.exe
ProductName : DC++
Created on : 3/27/2004 11:04:28 PM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 3/27/2004 11:04:30 PM

#:16 [ad-aware.exe]
FilePath : C:\Program Files\Ad-aware 6\
ThreadCreationTime : 4-19-2004 3:58:25 PM
BasePriority : Normal
FileSize : 760 KB
FileVersion : 6.0.1.158
ProductVersion : 6.0.0.0
Copyright : Copyright Lavasoft Sweden
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Professional
Created on : 4/9/2004 12:54:31 AM
Last accessed : 4/19/2004 4:00:00 AM
Last modified : 1/27/2003 2:42:22 PM

Memory scan result :

New objects : 0
Objects found so far: 0


Started registry scan

Registry scan result :

New objects : 0
Objects found so far: 0


Started deep registry scan

Deep registry scan result :

New objects : 0
Objects found so far: 0

11:58:59 AM Scan complete

Summary of this scan

Total scanning time :00:00:18:672
Objects scanned :20074
Objects identified :0
Objects ignored :0
New objects :0


Logfile of HijackThis v1.97.7

Scan saved at 11:59:47 AM, on 4/19/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe

C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe

C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe

C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe

C:\Program Files\Messenger Plus! 2\MsgPlus.exe

C:\Program Files\DC++\DCPlusPlus.exe

C:\HighJackThis\HijackThis.exe

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"

O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"

O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"

O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html

O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm

O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html

O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38077.313275463

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.