View Full Version: A2J, Squat, Raspy, Clay, etc etc etc

Faith, Hope, and Love > Computers & Technology > A2J, Squat, Raspy, Clay, etc etc etc

Pages: [1] 2


Title: A2J, Squat, Raspy, Clay, etc etc etc


andiesmama - September 13, 2007 01:06 AM (GMT)
What can you tell me about the virus MSVCTVRL.DLL?

Norton's caught it, called it an "Infoseeker"? So, I scanned with Spybot & Adaware which didn't catch it. Scanned with Norton's and it got it, but said it couldn't delete it. So I looked up some info on it, and Symantic site suggested I do the Norton's scan in safe mode. So I did.

Now Norton's isn't alerting me to the virus anymore, but when I pulled up IE, I got a pop up that said something "couldn't open because file MSVCTVRL.DLL not found", so I just kept clicking "ok" until it went away. Same popup when I tried to open Norton's & run it again, but kept clicking the "ok" and it eventually went away.

Am re-scanning as we speak with Norton's to see if, in fact, it's really gone.

But how can I get rid of those annoying pop-ups?

I'm so confused..........I hate computers............... :wall:

andiesmama - September 13, 2007 01:59 AM (GMT)
STILL running Norton's.

I tried to get into ChaCha (uses Java and the best version that works on it is the version 5, update 12 NOT the most recent one), Java wouldn't run. No error message or anything, got the "java" popup window, then it went away, then nothing. ChaCha didn't load up.

So, went to the Java site, tried to REdownload it and got a "runtime" error, then a bunch of error boxes kept popping up.

Don't ask me what they said, I didn't write it down but if you need that info, I can try it again and get it for you.

:wall: :wall: :wall: :wall:

Keneke - September 13, 2007 02:09 AM (GMT)
:blink:

Addicted2~Jesus - September 13, 2007 02:59 AM (GMT)
I'll do a lil research on it here in a min, but if you see this, open your start menu, go to run, type in msconfig an hit enter. Go to the start up tab an take a screen shot of what's listed there. Dependin on how much stuff you have there runnin when windows starts you might havta screen shot, then scroll down an shoot agin. It sounds as though you've got a bug that was dependant on this dll file, since norton got rid of the file, that particular program is now of course havin trouble. So we'll havta git rid of whatever created that program in the first place. Do you happen to have the utility called .... uh.. lol I think it's called "highjackthis" That don't sound right does it? I'll havta look I cain't member the thin.

This particular dll doesn't ring a bell, so we'll havta see whose usin that file. Do you recall where it said that file was located? Wether windows system, er system32 folders etc?

andiesmama - September 13, 2007 03:02 AM (GMT)
I think it said system32, not sure.

Norton's just got done, THAT says it's clean.

I'll do that screenshot thing tomorrow.......Ty's home and it's :quote: bed :quote: time......... B)

Addicted2~Jesus - September 13, 2007 03:03 AM (GMT)
oh btw... you've done some of the piliminary stuff right? Dumped your temp files, both windows an IE as well as cookies etc? Do you have admin rights in safe mode? Easier to dump large amounts of files there if need be. Can you think of any sites you've been to recently that were questionable? Gotta find whose put what togeather an then where.

Addicted2~Jesus - September 13, 2007 03:05 AM (GMT)
For the time bein though, you could go to start > run type msconfig, an jes uncheck ALL of the boxes listed there, restart your puter.. this is in case you don't shut it off at night, if you do no biggy, but you wouldn't want the thin whatever it is to be tryin to download stuff all night.

The most likely reason norton hasn't found anythin else is because that particular whatever you have hasn't been added as a potenital problem to any of the security updates. Jes havta wait an see though.

Addicted2~Jesus - September 13, 2007 03:40 AM (GMT)
Mmmmm it's not lookin real good at the moment, but it looks like it's like I was afraid of, it's jes to new to have any real info on it.

1. COVERT ANALYSIS OF: MSVCTVRL.DLL
File Names Used: 1
Paths Used: 1
Common File Name: MSVCTVRL.DLL
Common Path: %WINDIR%\SYSTEM32\
Vendor Information: No Vendor details specified
File Name Structure: Irregular
File and Path Structure: Normal
2. RELATIONSHIP ANALYSIS OF: MSVCTVRL.DLL
No relationship details available for this object
3. ACTIVITY ANALYSIS OF: MSVCTVRL.DLL
No activity has yet been observed for this object
4. PROPAGATION ANALYSIS OF: MSVCTVRL.DLL
Object Propagation Rate: Very Low (minimal spread)
Copyright Prevx Limited 2005, 2006

Check an see wether er not Norton managed to save a copy of the file into a vault er the like. I hope it hasn't deleted it, from what I've seen of some of folks night mares, they ain't even foolin wit it, their jes formattin an reinstallin. Not an option at current I grant you. There's jes not any real information on this particular file, other then I can say I don't recongnize it an it's not a system file from any vendor that I know of as of yet either. Goin to do a bit more lookin round, but if it is indeed a malware er the like, norton may have chewed up the wrong file an we might need to git it back jes to fix the problems. It will eventually be removed, but might need to use it for a bit.

clayman - September 13, 2007 05:12 AM (GMT)
I think A2J's got you on the right path. THe name of the program is HijackThis. Had to use it too many times on my mom & dad's computers. They're always getting into crap. That's why I hate going to Corpus!

andiesmama - September 13, 2007 11:35 AM (GMT)
Okay, looked in the Norton's backup section and this is what it lists as removed yesterday:

msvctvrl.dll -- Infostealer -- WINDOWS\system32 (this one is listed twice, I guess because I ran Norton's twice?)
tmpDC07.tmp -- Infostealer -- Documents & settings\Deb\Local Settings\Temp


Getting ready to try & do that screen shot.

How do I do that hijack this thing? Just download it & let it run?

andiesmama - September 13, 2007 11:38 AM (GMT)
Okay, brain freeze (haven't done it for awhile), but how do I do a screen shot? I know it's with the Print Screen button somehow.......

andiesmama - September 13, 2007 11:47 AM (GMT)
Okay, here's what I got when I ran Hijack this:

QUOTE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:44:28 AM, on 9/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DIGStream\PlayhouseDisneyDownloadManager.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Deb\Local Settings\Temporary Internet

Files\Content.IE5\K567SPY3\HiJackThis[1].exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.gateway.com/g/startpage.html?Ch...ys=DTP&M=GT4022
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ChaCha Search Toolbar - {4E7BD74F-2B8D-469E-88BC-BC28F89AAE3C} -

C:\PROGRA~1\CHACHA~1\CHACHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton

AntiVirus\NavShExt.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} -

c:\windows\system32\BAE.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program

Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ChaCha Search Toolbar - {4E7BD74F-2B8D-469E-88BC-BC28F89AAE3C} -

C:\PROGRA~1\CHACHA~1\CHACHA~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program

Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software

Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe

/uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PlayhouseDisneyDownloadManager] C:\Program

Files\DIGStream\PlayhouseDisneyDownloadManager.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" 

-osboot
O4 - HKLM\..\Run: [hcsystray] C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - HKLM\..\Run: [Viewbar] C:\Program Files\AGLOCO Viewbar\Viewbar.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat

7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O8 - Extra context menu item: ChaCha Search - file://C:\Documents and

Settings\Deb\Application Data\CHACHATOOLBAR\SelectedContextSearch_ChaCha Search.htm
O8 - Extra context menu item: ChaCha Search with guide - file://C:\Documents and

Settings\Deb\Application Data\CHACHATOOLBAR\SelectedContextSearch_ChaCha Search with

guide.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -

http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program

Files\Monopoly Here and Now\Images\stg_drm.ocx
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation

Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) -

http://zone.msn.com/bingame/trix/default/T...nx.1.0.0.87.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) -

http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -

http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

http://by135fd.bay135.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -

http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) -

http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdat..._site.cab?11633

59696212
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) -

http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {8C63DABA-CBA8-4B5D-A0F7-AE00F2920929} (Bridge Installer) -

http://cdn2.zone.msn.com/Bingame/BRDG/data...s/heartbeat.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) -

http://games.bigfishgames.com/en_mysteryso...mesLauncher.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) -

http://a19.g.akamai.net/7/19/7125/4058/ftp...psi/Coupons.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (ZPA_HRTZ Object) -

http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab58570.cab
O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857D} -

https://support.gateway.com/eSupport/static...e.WebLaunch.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) -

https://media.pineconeresearch.com/ActiveX/...loadcontrol.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -

https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -

http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C7E002D6-324B-4500-883D-84B620FD8640} (Bridge Installer) -

http://cdn2.zone.msn.com/Bingame/BRDG/data...6/heartbeat.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) -

http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program

Files\Monopoly Here and Now\Images\armhelper.ocx
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} -

http://a532.g.akamai.net/f/532/6712/5m/vir...er/install/inst

aller.exe
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) -

http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) -

http://zone.msn.com/bingame/dash/default/D...sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -

http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -

http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -

http://h30155.www3.hp.com/ediags/hpfix/aio.../qdiagh.cab?326
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program

Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program

Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation -

C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation -

C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation -

C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New

Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton

AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -

C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 14171 bytes

andiesmama - September 13, 2007 11:48 AM (GMT)
Whatever you see that I need to delete, let me know.....it looks like a weird alien language to me....... :blink:

andiesmama - September 13, 2007 11:54 AM (GMT)
I also did "Generate Startup Log" from hijack this, does it help?

QUOTE
StartupList report, 9/13/2007, 7:53:27 AM
StartupList version: 1.52.2
Started from : C:\Program Files\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DIGStream\PlayhouseDisneyDownloadManager.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
hp psc 1000 series.lnk = ?
hpoddt01.exe.lnk = ?
Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk = ?
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ehTray = C:\WINDOWS\ehome\ehtray.exe
readericon = C:\Program Files\Digital Media Reader\readericon45G.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
CHotkey = zHotkey.exe
High Definition Audio Property Page Shortcut = HDAShCut.exe
RTHDCPL = RTHDCPL.EXE
Alcmtr = ALCMTR.EXE
Logitech Hardware Abstraction Layer = KHALMNPR.EXE
(Default) =
HPDJ Taskbar Utility = C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
HPHUPD05 = C:\Program

Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
HP Component Manager = "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
HP Software Update = "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
HPHmon05 = C:\WINDOWS\system32\hphmon05.exe
OM_Monitor = C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
MSKDetectorExe = C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
PlayhouseDisneyDownloadManager = C:\Program

Files\DIGStream\PlayhouseDisneyDownloadManager.exe
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
hcsystray = C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
Viewbar = C:\Program Files\AGLOCO Viewbar\Viewbar.exe
SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

LDM = C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopMessenger.exe
OM_Monitor = C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
updateMgr = C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=
SCRNSAVE.EXE=C:\WINDOWS\system32\gtw_logo.scr
drivers=

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\PROGRA~1\CHACHA~1\CHACHA~1.DLL - {4E7BD74F-2B8D-469E-88BC-BC28F89AAE3C}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll -

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll -

{BDF3E430-B101-42AD-A544-FADC6B084872}
Browser Address Error Redirector - c:\windows\system32\BAE.dll -

{CA6319C0-31B7-401E-A518-A07C3DB8F777}

--------------------------------------------------

Enumerating Task Scheduler jobs:

FRU Task #Hewlett-Packard#hp psc 1200 series#1158454495.job
HP Usg Daily.job
Norton AntiVirus - Scan my computer - Deb.job

--------------------------------------------------

Enumerating Download Program Files:

[StagingUI Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\StagingUI.ocx
CODEBASE = http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab

[SpinTop DRM Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\stg_drm.ocx
CODEBASE = file://C:\Program Files\Monopoly Here and Now\Images\stg_drm.ocx

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/pub/shock...director/sw.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/pub/shock...director/sw.cab

[CPlayFirstTriJinxControl Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.87.dll
CODEBASE = http://zone.msn.com/bingame/trix/default/T...nx.1.0.0.87.cab

[MSN Games – Buddy Invite]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ZBuddy.ocx
CODEBASE = http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab

[Snapfish Activia]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\SnapfishActivia1000.ocx
CODEBASE = http://www1.snapfish.com/SnapfishActivia.cab

[{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}]
CODEBASE = http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://by135fd.bay135.hotmail.msn.com/resources/MsnPUpld.cab

[ZonePAChat Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ZPAChat.ocx
CODEBASE = http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab

[AtlAtomadersCtlAttrib Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\Atomaders.dll
CODEBASE = http://zone.msn.com/bingame/amad/default/atomaders.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE =

http://update.microsoft.com/microsoftupdat..._site.cab?11633

59696212

[UnoCtrl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\game_uno1.dll
CODEBASE = http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab

[Bridge Installer]
InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.1\hrtbeat.ocx
CODEBASE = http://cdn2.zone.msn.com/Bingame/BRDG/data...s/heartbeat.cab

[SpinTop Games Launcher]
InProcServer32 = C:\WINDOWS\DOWNLO~1\SPINTO~1.DLL
CODEBASE =

http://games.bigfishgames.com/en_mysteryso...mesLauncher.cab

[cpbrkpie Control]
InProcServer32 = C:\WINDOWS\cpbrkpie.ocx
CODEBASE = http://a19.g.akamai.net/7/19/7125/4058/ftp...psi/Coupons.cab

[ZPA_HRTZ Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\zpa_hrtz.ocx
CODEBASE = http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab58570.cab

[{97BB6657-DC7F-4489-9067-51FAB9D8857D}]
CODEBASE = https://support.gateway.com/eSupport/static...e.WebLaunch.cab

[InetDownload Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\WMDownload.dll
CODEBASE = https://media.pineconeresearch.com/ActiveX/...loadcontrol.cab

[Get_ActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\HPGETD~1.OCX
CODEBASE = https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx

[MSN Games - Installer]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ZIntro.ocx
CODEBASE = http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab

[Bridge Installer]
InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.2\hrtbeat.ocx
CODEBASE = http://cdn2.zone.msn.com/Bingame/BRDG/data...6/heartbeat.cab

[CBankshotZoneCtrl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\zpa_pool.dll
CODEBASE = http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab

[ArmHelper Control]
InProcServer32 = ./Images/armhelper.ocx
CODEBASE = file://C:\Program Files\Monopoly Here and Now\Images\armhelper.ocx

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx
CODEBASE = http://fpdownload.macromedia.com/get/flash...ent/swflash.cab

[{D27CDB6E-AE6D-11CF-96B8-444553550000}]
CODEBASE = http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab

[{D4323BF2-006A-4440-A2F5-27E3E7AB25F8}]
CODEBASE =

http://a532.g.akamai.net/f/532/6712/5m/vir...er/install/inst

aller.exe

[MSN Games – Game Communicator]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\StProxy.dll
CODEBASE = http://zone.msn.com/binframework/v10/StProxy.cab55579.cab

[CPlayFirstDinerDashControl Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\DinerDash.1.0.0.94.dll
CODEBASE = http://zone.msn.com/bingame/dash/default/D...sh.1.0.0.94.cab

[PopCapLoader Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\popcaploader.dll
CODEBASE = http://zone.msn.com/bingame/popcaploader_v10.cab

[HeartbeatCtl Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\hrtbeat.ocx
CODEBASE = http://fdl.msn.com/zone/datafiles/heartbeat.cab

[QDiagHUpdateObj Class]
InProcServer32 = C:\WINDOWS\system32\qdiagh.ocx
CODEBASE = http://h30155.www3.hp.com/ediags/hpfix/aio.../qdiagh.cab?326

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
End of report, 13,396 bytes
Report generated in 0.031 seconds

Command line options:
  /verbose  - to add additional info on each section
  /complete - to include empty sections and unsuspicious data
  /full    - to include several rarely-important sections
  /force9x  - to include Win9x-only startups even if running on WinNT
  /forcent  - to include WinNT-only startups even if running on Win9x
  /forceall - to include all Win9x and WinNT startups, regardless of platform
  /history  - to list version history only

andiesmama - September 13, 2007 12:05 PM (GMT)
I found this forum talking about it, but it's all WAY over my head~

http://forum.aumha.org/viewtopic.php?t=291...c4f5a7ac696e1a9

Okay, I'm done for now, I've got a headache. Thanks for the help you've already given me, I appreciate your time! Hopefully you guys can help me figure out what to do to get it outta here.

........and then I'll owe you a beer or two or three......... :nod:

squatpuke - September 13, 2007 02:26 PM (GMT)
.
.
AM....what's the prob.

I see you online here at FHL...so you're obviously online.

Is this still a problem?



One of the first things I would do is ditch IE...download Firefox and add an extension called "no-script"....I guarentee that no internet nasty will get by you w/o your permission.

If IE is broke or missing files, perhaps you can put in your windows disk and do a repair....Also, do you have XP's system restore turned on?

Might also be a good idea to scan your registry....START|RUN|"regedit" and search for that particular DLL.

I probably won't be able to read much more...been pretty busy at work. I'll try to check in when I can....sorry.

andiesmama - September 13, 2007 02:44 PM (GMT)
Yes, still a problem, I get a

"This application has failed to start because msvctvrl.dll was not found. Re-installing the program may fix this problem."

pop-up when I try to go into Norton's as well as trying to run ChaCha (which uses Java, it's Java that's not opening, not ChaCha itself). On Norton's, I keep clicking the "ok" button and it eventually lets me in, but not on the java one.

I turned off system restore when I ran Norton's in safe mode, now I can't get back into the system file to turn it back on.

I'll have to look for the disk to see if I can just put everything back on again, unless somebody has some other ideas.

I'm not going to do ANYthing until I hear back from one of you guys, tho.

andiesmama - September 13, 2007 02:48 PM (GMT)
Thanks, Squat-bro, I know you're busy like all the other guys and I appreciate your time more than I can say! :) Don't apologize.........unless you really want to.........

Anyhow, I've found my Windows CD in case you all think I just need to start over from scratch.

:dunno:

Keneke - September 13, 2007 03:00 PM (GMT)
I agree with a previous poster who shall remain unnamed :P

Get Firefox/Mozilla... It's less of a 'threat' to mean ppl to destroy such as IE or Netscape...


Hope the rest gets figured out...
:unsure:

Sarah - September 13, 2007 03:24 PM (GMT)
Louis is out working this morning but will catch up with this thread when he gets home.

andiesmama - September 13, 2007 03:29 PM (GMT)
Thanks Sarah.......warn him, he's got alot of reading to catch up on!

Tell him to send me a bill..... :nod:

Update: Heading out to Best Buy to buy an external drive (is that right?) to save the pictures & documents we've got on this one so we can reinstall. We've got one already, but it's an old one and wasn't too big, so it's full. Time to get another one anyhow.

rasplundjr - September 13, 2007 05:22 PM (GMT)
Good spyware adware tools are
AdAware from lavasoft www.lavasoft.com
Spybot do a search for Search and destroy at google it's safer.netwroking something or other
Superantispyware - real nice tool... I like it....


Hijack this is greek to me I run the file and paste the log file intoa forum at Major Geek.com and do what they tell me....

squatpuke - September 13, 2007 08:41 PM (GMT)
.
.
rather than an external drive....USB Keys are cheaper and no moving parts. Get a large enough size to save everything.


Not sure I would give on this one yet....


So if I'm reading right...Norton is the one giving you the error message? Have you called them and talked to any friendly Abu type characters?


You could also uninstall and reinstall Norton....


I'm going to google this dll a bit....brb.

andiesmama - September 13, 2007 09:21 PM (GMT)
I get that popup when I try to run Norton's as well as Java.

Addicted2~Jesus - September 13, 2007 09:26 PM (GMT)
Sqaut.... READ what is written my brother.... it is not jes Norton, an from the research I've done, it can be a whole host of other exe's that fail because of this file that no one knows anythin bout.

Secondly... People!! Do NOT advise a user EVER that is havin a problem wit thier puter to git rid of IE. There ARE times when this is advantageous, but this is NOT one of those times. Whatever the bug etc is Deb's got may have been tracked on via IE but IE isn't the problem at the moment.

Drives me nuts I hear thins like:

complaint: my puter won't boot

soultion: Oh git Firefox!!!

:rolleyes:

Ok Deb, I went through your log, unfortuneately I didn't see any redirects, any malware, no spam, infact I couldn't find anythin a miss, no browser hijacks er anythin else. I was hopin to find sumthin there. I admit I am not an expert on log files etc, an have done what Raspy has done as well, but anythin I didn't recongnize I looked up. You have a ton of imaginin software runnin, media this an that, hp photo, a couple other photo thins goin. You really don't need those thins to run ever time you start your puter.

So I'd disable them from the start up as they are only costin you resoruces, I also seen you had a hotkey sumthin er nother runnin, if you are not usin that particular keyboard, it doesn't need to load either. Don't worry, by disablin these items on your start menu will not delete er git rid of em, an if you see sumthin you jes havta have in your taskbar on boot up, jes enable it agin.

So click start > run > type msconfig, hit enter. Go to the start up tab, disable all those thins that you jes don't use ever time the puter starts, leave of course norton etc. Click apply an restart your puter.

Also, boot into safe mode, F8 on startup to git to the menu, delete Your temp files, as well as your internet temp files. C:\windows\temp, an your internet temp files, C:\Documents and Settings\Deb\Local Settings If you have hidden folders hidden, then you need to either enable them, er type out the address in your window, to enable them go to the top an click tools > folder options > click on the tab view. An under hidden files an folders, click show hidden files. Then you can go in an delete em manually witout usin a broswer.

Dump your cookies. You'll loose your history in the address bar, automatic logins etc.

I think you said you do not have a system restore point right now because norton asked you to git rid of em. If you do have one, jes delete the thin because it's liable to have some form of infection anyways.

I would not jes yet format an reinstall windows, not jes yet. This dll is some what new an I cain't find anythin out bout it, nor can anyone else I've talked to er looked up. I would click start > search > all files an folders, an type in that name as it was. Tell it to search. Once you find it, provided it's in a vault er other such, then you can manually go git the dll an place it back into the windows\system32. Yes I'm askin you to replace an unknown an potentially dangerous file into your windows folder agin. But I truly believe norton took out a symptom an not the problem here. Then I'd upgrade to latest defintions of spybot an adaware an run these, an make sure you do full scans, an it would be better if you did these in safe mode.

Since I seen you've got the genuine windows crap runnin, then you qualify for their anti-spyware stuff as well, I have a copy I can email to you ... uh I think... I don't think it was to big, might havta look but can see anyways. It's not half bad, a lil bothersome wit wantin to update, but in conjunction wit the others it'll keep you really clean.

Have you also btw, told spybot to immunize your system? An does your norton have an included firewall? If you enable that firewall, if I recall correctly I may be off. It may be teatimer I'm thinkin of, but if anythin wishes to contact the internet it'll ask you if you give it your permission. This can be annoyin for a lil while til we, er someone sorts this out, but you could block everthin goin out if you don't know what it is.

I haven't given up, but this dll is news to me, an apperently news to everone else as well.

andiesmama - September 13, 2007 09:33 PM (GMT)
Louis...... :hug:

Thanks for all your hard work, especially after working all day! I printed out what you wrote and am getting started on it now.

Ty said if this fixes our computer, he'll take you out fishing next time you're in our area..... B)

Addicted2~Jesus - September 13, 2007 09:40 PM (GMT)
Don't worry bout tryin to replace that one dll file that norton removed, it may not be needed at the moment, but the rest of that is jes general maintance anyways. An it does not look like it will actually fix the problem at the moment, the idea bout stickin that deleted dll back in was so you weren't limited in your abilities til a work around could be found. I'm researchin one right now, they didn't have it up there last night so I'm jes doin a bit of checkin.

Addicted2~Jesus - September 13, 2007 10:02 PM (GMT)
Well, the work around seems to be workin well for folks. Now all you need is an uninfected imm32.dll. an need to replace your current file. You wouldn't need to run that .cmd file an it's really easy to do anyways, jes followin the instructions that feller gave would do it.

I'll check an see if there is a downloadable imm32.dll around, if not, has Ty got his laptop round? if they are the same OS then it should be ok to use etc etc. DLL's can be a nightmare at times, but this one seems to be a pretty easy deal. An you should feel lucky, your one of the first to end up wit this bug. It's pert near brand new hehe.

Addicted2~Jesus - September 13, 2007 10:08 PM (GMT)
http://www.freedrive.com/files/3r5qws9y2akg0s/imm32.zip

Here is the file, Sarah's layin down after havin cut the grass, but I think she has yahoo er sumthin to send a direct connect file to you, but jes in case here is one (provided this damn free drive thin will actually work)

andiesmama - September 14, 2007 12:21 AM (GMT)
Okay, back up a second & let me tell you what all I did.

Actually, I went down that long list you typed & did everything. The problem was that Norton's kept taking OUT that MSVCTVRL.DLL file, so I ended up disabling Norton's and then putting it back in the SYSTEM32 file.

Now everything works great!! I downloaded Java it works fine now and I can actually work on ChaCha now!

So, here are my questions:

1) Should I go back into my System folder and turn back on the "system restore" thingie?

2) Do I still need to download that other file you're talking about in your last post?

3) Will Sarah give you a big kiss on the lips for me for fixing my computer? B) :P

Addicted2~Jesus - September 14, 2007 12:33 AM (GMT)
Ok, well the fix is to go ahead an allow norton to remove that file. Only you need to ALSO replace your IMM32.DLL file as well. The bug you got ahold of is more then likely one that injected piss poor code into your current file. So ....

Download the file, place it on your desk top. Er better still, jes extract it to your C: drive. Some place you can EASILY find it when you boot into safe mode. Shut down all other apps, windows etc. Allow norton to agin remove the file, delete it etc, the first dll, the mssumthin.dll file. Then reboot into safe mode.

Naviagte to your C:\windows\system32 folder. Find your CURRENT IMM32.dll an rename it to sumthin like IMM32OLD.dll. Move your NEW IMM32.DLL file that you downloaded into the folder.

Then reboot your system normally. This should remove the bug an any associated problems wit it. Do NOT delete the old file that you have renamed as IMM32OLD.dll. This is a safety net in the event this doesn't fix the problem. Then we can take a stab at sumthin else.

See currently, you've restored this bug, which is fine in a way, because like I said I was tryin to make it so you could at least operate online until a fix was sought out. So it isn't important to restore the file etc. Now that this fix has been provin to work, go ahead an do this fix. Do not add a system restore point right now, leave it turned off an deleted at the moment, er else it could simply include the bug when you restore later for whatever reason.

To recap

Download the file, extract it somewhere you will be able to find it when in safe mode.

Shut down all apps.

Allow Norton to delete the file agin, er manually delete the file er rename it.

Reboot the system into safe mode

Navigate to C:\windows\system32

Locate IMM32.dll an rename it to IMM32OLD.dll

Place the NEW IMM32.DLL file in the folder.

Reboot the system normally.

Then let us know if there are any other probs.

andiesmama - September 14, 2007 02:28 AM (GMT)
I just finished with all of that, and I think it worked!

:yay: :faint:

I so appreciate your help, you just don't know.

Is there anything else I need to do now that it's working again? To clean anything up, etc?

Addicted2~Jesus - September 14, 2007 02:34 AM (GMT)
Naw, jes confirm some stuff, search your puter wit the start > search > all files etc an make sure that one .dll is not in any of the system folders, if it's sittin in the vault of norton er whatever it's fine. Let it run for a day er so, make sure there's no troubles then you can turn on system restore agin.

Any time you can take thins off your start up screen the more system resoruces you can free up. An if you need er want the program, like some of the image stuff etc then you jes click on the short cut an it loads it up anyways.

I'm glad thins worked out well for you.

squatpuke - September 14, 2007 03:30 PM (GMT)
QUOTE (Addicted2~Jesus @ Sep 13 2007, 02:26 PM)
Sqaut.... READ what is written my brother.... it is not jes Norton, an from the research I've done, it can be a whole host of other exe's that fail because of this file that no one knows anythin bout.

Secondly... People!! Do NOT advise a user EVER that is havin a problem wit thier puter to git rid of IE.  There ARE times when this is advantageous, but this is NOT one of those times.  Whatever the bug etc is Deb's got may have been tracked on via IE but IE isn't the problem at the moment.

Drives me nuts I hear thins like:

complaint: my puter won't boot

soultion: Oh git Firefox!!!

.
.
I don't recall ever saying "get rid" of IE...however, it's VERY possible to NOT USE IE and instead use Firefox. Sheesh.

:doh:

Secondly, the very fix louise used was from a link I posted on the other thread, only w/o the thousand word attached opinion.

:doh:


Anyway....I feel kinda slighted here....

1) I get slammed for incorrectly telling AM to get RID of IE...
2) My fix gets stolen....
3) Dirty, stinky truck driver gets a kiss....(on the mouth no less)



I'm left here wondering...."WHAT THE HECK"?

:dunno:

clayman - September 14, 2007 03:40 PM (GMT)
QUOTE (squatpuke @ Sep 14 2007, 09:30 AM)
QUOTE (Addicted2~Jesus @ Sep 13 2007, 02:26 PM)
Sqaut.... READ what is written my brother.... it is not jes Norton, an from the research I've done, it can be a whole host of other exe's that fail because of this file that no one knows anythin bout.

Secondly... People!! Do NOT advise a user EVER that is havin a problem wit thier puter to git rid of IE.  There ARE times when this is advantageous, but this is NOT one of those times.  Whatever the bug etc is Deb's got may have been tracked on via IE but IE isn't the problem at the moment.

Drives me nuts I hear thins like:

complaint: my puter won't boot

soultion: Oh git Firefox!!!

.
.
I don't recall ever saying "get rid" of IE...however, it's VERY possible to NOT USE IE and instead use Firefox. Sheesh.

:doh:

Secondly, the very fix louise used was from a link I posted on the other thread, only w/o the thousand word attached opinion.

:doh:


Anyway....I feel kinda slighted here....

1) I get slammed for incorrectly telling AM to get RID of IE...
2) My fix gets stolen....
3) Dirty, stinky truck driver gets a kiss....(on the mouth no less)



I'm left here wondering...."WHAT THE HECK"?

:dunno:

Awww! Poor baby! :hug:

But - no. I'm not going to kiss you on the lips or anywhere else. :naughty:

andiesmama - September 14, 2007 03:56 PM (GMT)
All right Squat, sheesh..................your wife can kiss you on the lips, too~

But who's to say that YOU'RE not dirty & stinky as well, hmmmmmmm??? :naughty: :P

andiesmama - September 14, 2007 03:56 PM (GMT)
Question remains: Should I dump IE and get Firefox? Or not?

squatpuke - September 14, 2007 04:45 PM (GMT)
QUOTE (andiesmama @ Sep 14 2007, 08:56 AM)
Question remains: Should I dump IE and get Firefox? Or not?

.
.
Keep IE, but only if you want to pickup more spyware and viruii.....

andiesmama - September 14, 2007 04:52 PM (GMT)
QUOTE (squatpuke @ Sep 14 2007, 12:45 PM)
QUOTE (andiesmama @ Sep 14 2007, 08:56 AM)
Question remains:  Should I dump IE and get Firefox?  Or not?

.
.
Keep IE, but only if you want to pickup more spyware and viruii.....

:smack:

Of COURSE I don't want that, Goofy!

Is Firefox easy to use? What do I do, just download it somewhere and it'll take over, or do I need to "turn off" IE somewhere so Firefox will work.

Talk me through it, oh knowledgeable one..... B)

Addicted2~Jesus - September 14, 2007 05:19 PM (GMT)
Poor Sqaut... I wasn't tryin to bash you any... but it's a huge soap box thin for me really... ie is a fine browser SO LONG AS you use it wisely etc. Jes a program sittin there isn't goin to track on crap. You've got to go an do sumthin to git screwed wit it. So any time someones got a problem that's the first thin everone screams bout, oh you gotta git firefox.... personnaly, I think it's a pile of crap as far as a web browser goes. That's jes my personal opinion.

an I admit, I didn't give enough credit where credit was due. The night this began I spoke to a feller on that site, but at that time there wasn't any ideas bout what it was er anythin else. If you look at dates/times etc. While I was out... actually workin for a livin... not sittin in some air condition office pushin buttons..... they come up wit the fix an your right, the link you posted had the info in it to fix it. I personnaly wouldn't have expected Deb to try an figure it out by their piss poor instructions. Which is why I did the walk through, forgive me oh great slated one for I have trampeled upon you....

No, you do not havta git rid of IE to use firefox er anythin else. It's a matter of personal opinion. Yes firefox is a more secure browser cause of active x controls bla bla bla but it's an entirely different browser, an if you don't like change, you won't like firefox. Plus... an sqaut would know bout this, not me. But wasn't there some disaster in regards to the mail through firefox? Some sort of a conflict wit outlook an firefox er sumthin, this may not be an ordeal now though I donno.

I'd look up some screen shots of firefox an see if it's sumthin you'd wanna play wit. An I'd also immunize your system wit spybot, an install teatimer. These lil thins will help control any junk you track on.

I do apologise Sqaut, I wasn't tryin to bash you, an jes because I love you so much, next time I'm through Flagstaff, I'll leave you another present under that light pole ;)

Btw, Deb had posted a link to that site before you did in here, I didn't mention anythin to er, because at the time, no one knew anythin bout it, which is why I told er to be patent, cause there jes wasn't a current fix out there for it. In the end, it doesn't appear to be a mean bug er the like, didn't really do any real harm so I don't think it's a huge problem, but that's what norton did, attacked some of the symptoms witout cleanin thins up after wards. Which is why you found out you had a problem.




Hosted for free by InvisionFree