Question

run a dll as an app keeps appearing when I want to do ANY window operation!

Asked by: mchyzik

I have a customers computer that is causing me great grief.  First of all, it had the begal.n virus (which I was able to get rid of using the program from symantec as well as ran a check with a bootable floppy from AVG to be sure it was clean).  It also wont let me get into msconfig nor anything in the control panel so I can try and clean up the rest of this machine.  I believe it is infected with a lot of spyware, and when I try to run adaware, spybot or any other program I get 'cant run a dll as an app error'.  I thought I'd try going into msconfig, but I get the dll error there.  I even tried this in safe mode.  Help please!  I also tried creating a new user profile in safe mode and get the dll error.  Im lost here.  Thanks in advance!

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2004-07-28 at 18:27:14ID21075137
Tags

dll

,

app

,

run

Topic

Windows XP Operating System

Participating Experts
3
Points
500
Comments
59

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Infected by Spyware (SysAI/Apropos?) and Spybot/…
    Would appreciate help ASAP inasmuch as this is a co-worker's work PC and it has scrambled her productivity. She was suddenly having problems with popups and PC was extremely slow doing anything, Task Manager showed CPU at 100% so I suspected spyware. Looked at running proce...
  2. VX2 Spyware Infection...
    Ok i have spyware on my system that seams virtually un-removiable, the dreaded VX2. I know i have come across this before and i ended up doing a re-format to remove it. Well this time it's on my system (i suspect my roomate) and i really dont' want to reinstall the system f...
  3. is avg free spyware
    is avg free spyware? soimeone said it collects data, and if it is, then what about the pro version: spyware too?

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: SheharyaarSaahilPosted on 2004-07-28 at 18:30:44ID: 11663036

Hello mchyzik =)

Can u run this tool,,, let me check if this is really a virus destruction or u have written the error incorrectly :)

Download HijackThis, run it and Post the Log File here:
http://www.wilderssecurity.com/supportfiles/HijackThis1980.exe

 

by: CoolATIGuyPosted on 2004-07-28 at 18:33:56ID: 11663058

What OS?

CoolATIGuy

 

by: CoolATIGuyPosted on 2004-07-28 at 18:35:37ID: 11663067

 

by: mchyzikPosted on 2004-07-28 at 18:43:09ID: 11663094

OS is XPHome
Here is the log from Hijakthis:

Logfile of HijackThis v1.97.7
Scan saved at 9:41:22 PM, on 7/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://easy-search.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://easy-search.biz
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.webroot.com/php/disp0201.php?pc=64150&rc=1&mo=2&oc=26&ps=R
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {20239CAD-9608-49E2-8E0D-DAAD7E58BF82} - C:\WINDOWS\System32\lgckec.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\Documents and Settings\owner_2\Application Data\winit\winit.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\hp\drivers\keyboard\PS2.EXE
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\SYSTEM32\XTAWJ.EXE
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\sdkqh32.dll,Install
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [sounoft] sounoft.exe
O4 - HKLM\..\Run: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\jopnyc.exe
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\gxwnbht.exe
O4 - HKLM\..\Run: [DjrL.exe] C:\documents and settings\owner_2\local settings\temp\DjrL.exe
O4 - HKLM\..\Run: [B4693369] C:\WINDOWS\System32\fjqzezyj.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [intlgntc] C:\WINDOWS\System32\intlgntc.exe
O4 - HKLM\..\Run: [Microsoft Update Machine] javaw.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [sounoft] sounoft.exe
O4 - HKLM\..\RunServices: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\RunServices: [8F7BBF0F] C:\WINDOWS\System32\fjqzezyj.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] javaw.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [winupd.exe] C:\WINDOWS\System32\winupd.exe
O4 - HKCU\..\Run: [Plug and Play] C:\WINDOWS\wininet32.exe
O4 - HKCU\..\Run: [Remote Packet Capture Protocol v.2.0] C:\WINDOWS\runwin32.exe
O4 - Startup: AutoPlay.exe
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O9 - Extra button: Control Pad (HKLM)
O9 - Extra 'Tools' menuitem: Control Pad (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0080AD08A326} - http://activex.liveupdate.com/controls/cres.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//paxan/main.chm::/load.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://E:\content\include\XPPatchInstaller.CAB
O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partners/aolim/install.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50151/QDow_AS2.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - ms-its:mhtml:file://c:\nosuch.mht!http://www.n28.net/n001/mt/mt.chm::/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37949.4211805556
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_5_0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

 

by: mchyzikPosted on 2004-07-28 at 18:44:28ID: 11663097

coolAT guy, its not happening with just XP restore.. sorry. That does not help me at all.

 

by: SheharyaarSaahilPosted on 2004-07-28 at 18:47:23ID: 11663106

Turn off ur System restore and fix the following entries......

========================================================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://easy-search.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://easy-search.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.webroot.com/php/disp0201.php?pc=64150&rc=1&mo=2&oc=26&ps=R
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
O2 - BHO: (no name) - {20239CAD-9608-49E2-8E0D-DAAD7E58BF82} - C:\WINDOWS\System32\lgckec.dll
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\Documents and Settings\owner_2\Application Data\winit\winit.dll
O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\SYSTEM32\XTAWJ.EXE
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\sdkqh32.dll,Install
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\jopnyc.exe
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\gxwnbht.exe
O4 - HKLM\..\Run: [DjrL.exe] C:\documents and settings\owner_2\local settings\temp\DjrL.exe
O4 - HKLM\..\Run: [B4693369] C:\WINDOWS\System32\fjqzezyj.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [intlgntc] C:\WINDOWS\System32\intlgntc.exe
O4 - HKLM\..\Run: [Microsoft Update Machine] javaw.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [sounoft] sounoft.exe
O4 - HKLM\..\RunServices: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\RunServices: [8F7BBF0F] C:\WINDOWS\System32\fjqzezyj.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] javaw.exe
O4 - HKCU\..\Run: [winupd.exe] C:\WINDOWS\System32\winupd.exe
O4 - HKCU\..\Run: [Plug and Play] C:\WINDOWS\wininet32.exe
O4 - HKCU\..\Run: [Remote Packet Capture Protocol v.2.0] C:\WINDOWS\runwin32.exe
O4 - Startup: AutoPlay.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0080AD08A326} - http://activex.liveupdate.com/controls/cres.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//paxan/main.chm::/load.exe
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://E:\content\include\XPPatchInstaller.CAB
O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partners/aolim/install.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50151/QDow_AS2.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - ms-its:mhtml:file://c:\nosuch.mht!http://www.n28.net/n001/mt/mt.chm::/MediaTicketsInstaller.cab
=======================================================================

 

by: CoolATIGuyPosted on 2004-07-28 at 18:48:03ID: 11663109

Sorry, guess I should have looked closer at that link. :-(

CoolATIGuy

 

by: SheharyaarSaahilPosted on 2004-07-28 at 18:51:05ID: 11663118

If u cannot access System Restore, then leave it,,,, and fix the above entries, Restart ur machine and perform some online virus scans !!!!

CHECK FOR ONLINE VIRUS SCAN:
--------------------------------------
1. http://us.mcafee.com/root/mfs/default.asp?cid=9059
2. http://security.symantec.com/
3. http://housecall.trendmicro.com/
4. http://www.pandasoftware.com/activescan/com/activescan_principal.htm
5. http://www.pcpitstop.com/antivirus/default.asp

then download these tools and install Adaware and Spybot !!!!!
========================================================
AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot  ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.spychecker.com/program/coolwebshredder.html
ToolBar Cop >> http://www.mvps.org/sramesh2k/toolbarcop.htm
Stinger >> http://vil.nai.com/vil/stinger
========================================================
After that Follow these Instructions:

1. First turn Off ur System Restore
2. Boot into safemode and Login as Administrator
3. Run the AntiVirus tool and delete all viruses it found
4. Run the Spyware Removal tools and delete everything they detect
5. Then goto C:\Documents and Settings\ur usernmae\Local Settings\Temp and delete all files present here
6. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temporary Internet Files, and delete the folder of ContentIE
7. Goto C:\Documents and Settings\ur usernmae\Cookies, and delete all cookies present here.
8. Reboot back in Normal Mode and check if problems are gone
9. If YES then Great, otherwise run the Hijakcthis scan, and post the LOG file here
10. After making sure that every junk stuff is deleted, and System is Clean, Turn On the System Restore again !!!

 

by: mchyzikPosted on 2004-07-28 at 18:52:42ID: 11663127

I cant turn off system restore, get that darn dll message again.  I also get a bunch of dr. watson errors that I want to get rid of.

 

by: SheharyaarSaahilPosted on 2004-07-28 at 18:55:05ID: 11663135

see my second post :)

and if after fixing those entries, u still get those errors, then try a SFC scan,,,,,,
Goto START>RUN and type  sfc /scannow
u will need ur WinXP CD in order to fix the corrupted windows system files, if found by scan.

and if still nothing helps u, then go ahead and perform a Repair so that atleast we can run some programs =\

How to Perform an In-Place Upgrade (Reinstallation) of Windows XP:
http://support.microsoft.com/?kbid=315341

Or this site explains a Repair with pics:
http://www.webtree.ca/windowsxp/repair_xp.htm

 

by: timothyfryerPosted on 2004-07-28 at 19:03:15ID: 11663162

You may not be able to fix the sp.html about:blank hijacker with hijackthis.  That's the one that brings up a search page that you can't get out of.  CWShredder might get it depending upon the variant but also probably not.  For the ones that hijacthis doesn't kill, you might be able to download process explorer from http://sysinternals.com and kill more virus processes that way which would allow you to delete their executables and dlls without having to go into the rc.  If you kill enough of them, then you might get msconfig back, but if not, you can go into the registry and delete the startup entries in the run  and runservice keys that are likely launching some of them.

 

by: mchyzikPosted on 2004-07-29 at 16:11:23ID: 11672302

I removed the items you stated to with Hijackthis.  I still can not run anything in normal/safe mode without getting the dll error.  Help!

 

by: SheharyaarSaahilPosted on 2004-07-29 at 16:14:52ID: 11672326

then refer to my last post =\

 

by: mchyzikPosted on 2004-07-29 at 16:21:29ID: 11672355

I was able to get ad-aware to run in safe mode. Any other app in safe mode just does not run (no erro), but I get the dll when trying to run anything in normal mode.  Imalso getting a bunch of 'backup' files in safe mode everytime I look there are more!
I will go to sysinternals.com and try that next.  I am just afraid if I put this PC on the network it would infect the rest of my machines.  I have internet running through a server (I have to, using a satallite connection for internet).

 

by: timothyfryerPosted on 2004-07-29 at 16:53:21ID: 11672631

I would definitely make sure that your other machines aren't exposed to the sp.html startup page virus.  Some versions of that haven't been fixed yet and I eventually had to abondon a good XP installation because of it.  It's wicked.

 

by: mchyzikPosted on 2004-07-29 at 17:38:52ID: 11672829

how do I know if the sick PC has it?  Also, where in the registry can I stop some of the programs from starting? (provided I can get in it).  Im trying to get an online antivirus to work, so far they dont.  How do I make it so my other machines are not exposed.  I have a firewall on them.

 

by: mchyzikPosted on 2004-07-29 at 17:42:44ID: 11672852

I got sysinternals up.. now what do I do with it?  It lists all the processes... what do I keep? What do I kill?  THe read me file won't come up, but the program did...

 

by: mchyzikPosted on 2004-07-29 at 17:53:27ID: 11672893

I worked through sysinternals and can now run some spyware cleaners... still trying to get any antivirus to run.. but its being difficult.  The programs start, then close up.

 

by: timothyfryerPosted on 2004-07-29 at 17:58:59ID: 11672921

If you can hold on for a few minutes I'll try to post a list of the processes and modules that need to be running for xp to run.  Everything else you could presumbably kill except your browser.

 

by: mchyzikPosted on 2004-07-29 at 18:24:57ID: 11673058

Spysweeper found 403 traces of 46 software spywares and cleaned them.  Im running ad-aware now.  Spybot wont load which I wish it would since it has its own 'built in' msconfig for me to use!

 

by: timothyfryerPosted on 2004-07-29 at 18:26:05ID: 11673069

These are the processes that are running on my computer.  You should be able to kill everything except these and still be online and running.  The svchost.exe processes are hosts to multiple service processes.  Sometimes viruses run in there also. When you highlight a process, you will see the modules (dll's) it contains in the lower window, if you don't, go to the view tab and select DLL's in the Lower Pane View instead of Handles and make sure the Lower Pane View entry above it has a checkmark so that you will have a lower split window. When you highlight a process, look at the dll's that are running under it in the lower window and see if there are any that don't have a Microsoft name listed.  These would be suspects.  You can then do a wildcard search on the computer *.* which should list every file in the computer, although you really need to download a good search tool because ms native search won't list all the files and won't tell you it isn't.  Agent Ransack is free and very thorough for search.  Likewise, Registrar Lite is very thorough for registry.  Regedit and Regedt32 are very bad about missing items in searches.  To do a wildcard of the whole computer in Agent Ransack, just leave the search field blank and click search.  Then sort by name, then find your suspect files, note the timestamps and then sort by timestamp and see what other files have the same timestamp.You can then google the filenames and see if they correlate to any viruses.

CSRSS.exe
explorer.exe
Isass.exe
Services.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
SMSS.exe
System Idle Process
System
Winlogon.exe
procexp.exe  (process explorer)
iexplore.exe (or your browser name)

 

by: timothyfryerPosted on 2004-07-29 at 18:29:05ID: 11673079

Alot of spyware is designed to stop you from contacting online scanners and prevent local scanners from running. My theory is that if you can kill the spyware process, you might be able to start the antivirus programs and remove the virus.  What I definitely would not do is reboot because you will just reload everything thats set to run at startup.

 

by: mchyzikPosted on 2004-07-29 at 18:50:38ID: 11673165

There is one process that wont kill: tfswctrl.exe... othewise all is clean like you stated above.  Im trying to install Norton now... will try online scanners again if this does not work. Thank you so much.. I'll keep you posted!

 

by: mchyzikPosted on 2004-07-29 at 18:58:17ID: 11673198

Getting a microsoft register server error.. it encountered a problem and needs to close... says anything I was working on will be lost.  Im back to square one.  I need to find a way to get antivirus to install / run!  Getting tired and cranky with myself now   :)

 

by: SheharyaarSaahilPosted on 2004-07-29 at 19:00:58ID: 11673205

I will again say that atleast do a REPAIR,,,,, so that original registries and windows system files can get restored =|
after that u will be able to run online virus scans, install av tools and anything to get rid of the rest junk material !!!!

 

by: timothyfryerPosted on 2004-07-29 at 19:04:35ID: 11673221

WinTasks Process Library
Looks like windows native burner possibly.  Also, earlier I said that dlls without Microsoft names were suspect.  That doesn't mean that spyware hasn't infested a Microsoft dll.  Dll's can be modified rather easily and while Windows File Protection is supposed to protect the system files from being changed, it probably works about as well as other Windows stuff.  I've hacked into explorer and changed the logo and hacked into mshtml.dll and changed stuff and Windows File Protection didn't notice the difference though not sure if I ever ran SFC against the hacked versions to see if it picked them up.  You might also try that though, run System File Checker to see if it catches any modified windows files.


tfswctrl - tfswctrl.exe - Process Information
Process File: tfswctrl or tfswctrl.exe
Process Name: DLA Packet Writing Software
Description: Application that is used to write data to CDs directly from Windows applications, without using the actual CD Writing software.
Company: Hewlett-Packard
System Process: No
Security Risk ( Virus/Trojan/Worm/Adware/Spyware ): No
Common Errors: N/A


 

by: timothyfryerPosted on 2004-07-29 at 19:19:37ID: 11673298

I didn't understand what server they were referring to. Did it give specifics.
 

 

by: timothyfryerPosted on 2004-07-29 at 19:28:15ID: 11673322

Also ShehaaryarSahill, do you have to reinstall programs after repair install.  I've done so few and so long ago I can't remember.

 

by: SheharyaarSaahilPosted on 2004-07-29 at 19:35:55ID: 11673340

yes,,,,,, those ones which use reigstry settings for their operations, like Office, Norton, Mcafee, Real Player etc etc
coz a Reinstall replaces the present reigstries with the default ones, and thus deletes all the information stored by these programs !!!!!

 

by: mchyzikPosted on 2004-07-30 at 04:26:06ID: 11675688

I'd like to not have to do a repair and then lose all the applications.  I'd like to get some data off here first that my customer wants saved... but need to burn it on CDR since the files are large.  

 

by: timothyfryerPosted on 2004-07-30 at 05:23:22ID: 11676138

The repair install shouldn't destroy any data.  But as SheharyaarSaahil said, you have to reinstall the apps. One of the files that you mentioned above that was still running was the native ms burner I think.  Are you sure you can't burn with that.  Also, what was the server you mentioned earlier.  Did it have a specific name that you could see before it went down.

 

by: timothyfryerPosted on 2004-07-30 at 05:24:56ID: 11676151

It looked like you had a pretty good handle on it all the way up until the server error.

 

by: SheharyaarSaahilPosted on 2004-07-30 at 06:39:44ID: 11676872

Yes, u can still access the hard drive, so move all ur required data to either to second partition, or put in a separate folder in C: drive...... coz repair will replace the My Documents folder, C:\Windows and registries !!!!!!
will not delete\replace anything else !!!!!!

 

by: mchyzikPosted on 2004-08-01 at 07:02:43ID: 11687798

The error I constantly get when ever I try to access any control panel apps is:  Run a DLL as an App. Run a DLL as ann App has encountered a problem and needs to close, we are sorry for the inconvenience.  Please tell MS about this problem.

I am now going to move the customers 'data' to another folder and try a 'repair' of the OS.  I will keep you all posted!

 

by: timothyfryerPosted on 2004-08-01 at 07:35:20ID: 11687895

Maybe rundll.exe is corrupt.

 

by: mchyzikPosted on 2004-08-01 at 09:54:37ID: 11688622

Is there a way for me to find what the XPHome registration number is on this computer?  There is no sticker and I want to be able to have it if I need to do a restore.  THe system information program will not work, and I also tried Belark.  I have an OEM XP Home CD that I use to do recovery/repairs.

 

by: timothyfryerPosted on 2004-08-01 at 09:57:31ID: 11688637

 

by: mchyzikPosted on 2004-08-01 at 10:11:07ID: 11688697

Thank you, that tool worked great!  Saved it in my bag of tricks!

 

by: mchyzikPosted on 2004-08-02 at 06:18:17ID: 11693289

OK, I ended up doing a new install of XP with my OEM disk... nothing else worked. I installed it to the C drive and left the D drive in tact (D is the 'recovery' drive for HP since they dont issue CD's anymore).  I also made a 'backup' directory on D for my clients data.  Now the problem is that I can't get back any HP applications nor drivers that are needed for this machine.  THis is a Pavillion 522n.  I simply want this machine to work normally again, even if it is back to square one.  HP said by hitting the f10 key it would do its own system recover but that failed.  Any suggestions?  I am indesparate need for all the MultiMedia (video, etc) drivers.

 

by: SheharyaarSaahilPosted on 2004-08-02 at 14:45:41ID: 11698737

>> OK, I ended up doing a new install of XP with my OEM disk

are u sure that u did a Legal work here...... means if u have used the OEM disk of another system on this laptop..... i dont think that it can be termed as a GOOD thing =|

 

by: mchyzikPosted on 2004-08-02 at 15:08:49ID: 11698916

There was no recovery CD with system, all I want to do is use the XP registration number they had before that I have and use it again since I had to reinstall the OS.... same system.  This should not be illegal.  And this is a PC, not a laptop.  What else could I do?

 

by: timothyfryerPosted on 2004-08-02 at 15:50:34ID: 11699117

I don't see any ethical problem with putting your legally purchased copy of xp onto any machine that you want to put it on.  You just have to raise your right hand and swear that you won't put it on any other machines also.  I'll wait a second while you swear...................OK, now that your finished swearing, I looked around but didn't see the process for activating the recovery process.  I'm sure it 's out there somewhere though.  I did track down the driver download page for the machine which is the link below.  I also ran across a couple of references to a one time option to download the recovery cd's but I didn't find the website.  If this customer never received recovery cd's with his machine and never downloaded any, then you might be able to download them free from hp by providing the machine's serial number on an online download site.  Also, I reloaded my aunt's hp at one point, and after discovering that she had no cds, I called hp to complain and the telephone service rep pulled up half dozen or so scripted rebuttals and then, after checking with his supervisor to make sure the sky wasn't going to fall in, agreed to send the set for $10.00.  Eight cds in all. If customer can wait, you might want to go that route.  When I have a chance I'll look further for the recovery cd download page, but personally, I don't think you'll miss anything if you just replace the basic drivers which may be all on the download page in the link below.  I had an hp at a previous job and the supplemental disk had a couple off things on it that were ok but alot of it was worthless, like Backweb and Wild Tangent Games and crap like that.  The cd burner may be  the only thing you really have to have, and you might be able to get an update for that online.  

I'll keep looking for something you can use.  All of this nonsense is about Microsoft, being our favorite monopolist, using it's monopolistic power to pressure the vendors into not providing hard media with the machines.  Just like every other big business, they are trying to build a limitation into the lifespan of the product to improve their sales.  Microsoft is doing it under the guise of reducing piracy, which I guess they think sounds better to the public.


http://h10025.www1.hp.com/ewfrf/wc/softwareList?product=83455&lang=en&cc=us&lc=en&dlc=en&os=228

 

by: mchyzikPosted on 2004-08-02 at 16:04:40ID: 11699208

THank you so much for all your persistance with this timothyflyer!  THis is the 3rd HP that I have had recovery issues this year and HP is really getting me angry!  I did go to their site and they do not have the drivers (specifially I am looking for video drivers).  I called HP and they said for $35 I can purchase the CD's.. I tried to get a discount but it did not work.  Maybe I am not mean enough!  I really hate HPs!  I actually went to all the web pages you went to.. no there is no download anymore I found out from their site.  I went to your URL and I have the same one and there are no drivers on it that would help.  I may have to suck up to HP and purchase the CD's. I'll call my customer and see if they created the recovery CDs like they were supposed to when they first turned on the machine.  If not, I will have to charge them.  THe only problem I am having with the OEM copy of XP is that it wont register and I never get a 'live' person on the Microsoft phone line to tell them what I am trying to do!  I had done this once and was able to get to a live person with a compaq machine a few months ago,, but now they changed the process perhaps.

Any more suggestions?  I looked up the motherboard, ASUS P4GLA and there are no video drivers on the site.  Going nuts here!

 

by: timothyfryerPosted on 2004-08-02 at 16:09:49ID: 11699237

I'll look around and get back with you in a few minutes.  I'm assuming the ASUS board is onboard video.
I built a machine for a friend awhile back on a real tight budget and bought an Abit board that I think was designed specifically for the oem's.  Finding ANYTHING for it was a nightmare unless your fluent in Chinese.  

 

by: mchyzikPosted on 2004-08-02 at 16:30:33ID: 11699352

I found the motherboard on their website but I did not see any 'video or multimedia' drivers.  I can't get the video to go better than medium 16 bit at 640X480.

 

by: mchyzikPosted on 2004-08-02 at 16:35:43ID: 11699385

some guy on another forum says he had to download the video from intel to fix it.. Im going there now..

 

by: timothyfryerPosted on 2004-08-02 at 16:37:25ID: 11699398

From the looks of it, I would say it was a proprietary build.  Got 24 googles on p4gla, 500 something on   p4 gla   at which point I noticed correlation between gl and intel and somehow ended up at this site with guy with same problem and he solved it this way- I guess the video drivers are in the chipset drivers but not sure.  If you can't make it out from the excerpt, I would go to the forum and read the whole thread for more clues. The excerpt is for the same machine as yours a 522n
I'm going to have to run now but I'll check back later to see if I can help on anything.
http://forum.osnn.net/archive/index.php/t-25340.html

from link above
Ok.. I was able to figure it out. What you have to do with machines like this after you reformat and delete there partition and start from scratch. You have to find out the chipset because HP's customer care won't know what the video card and or driver because it's on board. You have to find the "chipset" from either hp or going through your BIOS. Then you have to go to your chipset makers website, in this case it was intel. There chipset for this machine was "Intel 845GL" after going there you have to go though the letters on intels website to finally get to this chipsets drivers. Install and reboot. What a huge pain in the ass this was to find this, but if you have an HP and lose all your info, do what I did here..

 

by: mchyzikPosted on 2004-08-02 at 16:48:48ID: 11699461

I got it and it worked.. now for the other drivers!

 

by: mchyzikPosted on 2004-08-02 at 16:50:32ID: 11699470

All I need now according to the device manager is the MultiMedia Audio Controller and the USB Controller...

 

by: mchyzikPosted on 2004-08-02 at 17:31:23ID: 11699690

I cant find the USB nor the audo drivers.. suggestions? Please?

 

by: timothyfryerPosted on 2004-08-02 at 17:34:02ID: 11699703

Just got back in, I'll look.

 

by: mchyzikPosted on 2004-08-02 at 17:39:37ID: 11699718

Im on driverguide.com now ... this is not fun at all!
I am loading some software now that equates to what HP had on this system, like DVD players and CD burning software... man, I hate HP systems!

 

by: timothyfryerPosted on 2004-08-02 at 18:22:17ID: 11699927

 

by: timothyfryerPosted on 2004-08-02 at 18:27:52ID: 11699951

Also look at #8.  I don't know if you have and Intel audio chip or not so don't know if you'll have to search more or not.

 

by: timothyfryerPosted on 2004-08-02 at 18:35:17ID: 11699985

Also, the hp driver download page link I posted earlier had burner updates on it.  Alot of times, the update is the complete program so assuming the update doesn't freak on  the xp pid, you might be able to replace the burner program (RecordNow).  There are programs that can change that pid also though I haven't used one.

 

by: timothyfryerPosted on 2004-08-02 at 18:51:40ID: 11700069

 

by: mchyzikPosted on 2004-08-03 at 09:36:15ID: 11706697

I was able to finally get the sound drivers installed!  I went to the device manager and let it search on the internet for the drivers and it worked!  Now I am checking out everything else before I close this issue.  Thanks to all who hellped!  Tim, you put a lot of time into this for me, and I do appreciate it!

 

by: timothyfryerPosted on 2004-08-03 at 19:26:29ID: 11711906

XP found a driver on the internet? **************** ALERT THE MEDIA ********************
My experience is that XP can't find it's own windows drivers when they're in the same folder.
Ha!!!!!!

 

by: mchyzikPosted on 2004-08-04 at 06:41:58ID: 11715389

I was just as surprised as you are!  This is the first time XP ever found the right driver going onto the internet in the 3 years I have been working with it!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...