help me please URGENT!!! BIG PROBLEM NEED HELP A.S.A.P.

  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

hi I really had a bad problem first of all when I turnned of my dad's laptop(windows vista) a folder appears (C:\Users\francis\Documents) then has a black background at the folder's back... the START MENU,taskbar and all the desktop icons did not appear,,in short its all black then I tried doing this ( ctrl + alt + delete ,so the task manager appears then I clicked NEW TASK and type explorer)after that the START MENU,taskbar and all the desktop icons appeared... so my question is WHY EVERYTIME I TURN MY DAD"S LAPTOP ON the documents folder automatically opens (C:\Users\francis\Documents)and has black backround and the START MENU,taskbar and all the desktop icons did not appear... DOES IT MEAN I HAVE TO OPEN THE TASK MANAGER AND RUN the "EXPLORER" SO THAT I CAN ACCESS THE LAPTOP PROPERLY??? please help me... please
  • righteous_trespasser
  • Scuffle
  • Genius
  • User avatar
  • Posts: 6231
  • Loc: South-Africa

Post 3+ Months Ago

Well ken it seems like you have a little problem there ... have you checked for virusses/spyware etc yet? Do you have an anti virus. What I'd suggest is for you to follow the instructions posted here.

Also, firstly, check in "Start>All Programs>Startup" ... is there a shortcut to "My Documents" in there? that might be why it shows up ...

And one topic is enough bro, no need to post more than one topic ... everyone can see the one that is already here. And also no need to SHOUT THE WHOLE TIME.
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

First of all, when you have a problem, don't double post and DON'T USE ALL CAPS. People are here to help you, so it's enough you post once.

Regarding your problem, it may be a virus. I think the shell entry in your registry (which is usually explorer.exe) has been replaced with something else. Could you post a list of processes that are running on your computer?
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

there no "My Documents" in the startup and yes it has anti Virus (AVG)sorry for the shouting but how can I make this work properly (PROPERY= working fine all icons and startup programs work)anyways in SYSTEM CONFIGURATION which one should I use (NORMAL STARTUP,DIAGNOSTIC STARTUP,OR SELECTIVE STARTUP)
  • righteous_trespasser
  • Scuffle
  • Genius
  • User avatar
  • Posts: 6231
  • Loc: South-Africa

Post 3+ Months Ago

LOUD NOISES!!!!

Okay, is AVG up to date with all its definitions? have you scanned the system yet?

And which "system configuration" are you talking about here?
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

sorry,,,now the pc is working fine only during the startup the folder appears and its all black i will try to scan if there is any virus and if there is it will be healed and it should work fine,am i right???

casablanca wrote:
First of all, when you have a problem, don't double post and DON'T USE ALL CAPS. People are here to help you, so it's enough you post once.

Regarding your problem, it may be a virus. I think the shell entry in your registry (which is usually explorer.exe) has been replaced with something else. Could you post a list of processes that are running on your computer?
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Go to Task Manager and select New Task. Type "cmd" to open Command Prompt. Over there, type "tasklist" and post the output here. The list of processes might help in identifying if you have any viruses on your system.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

the startup system configuration and I think the AVG is up to date
righteous_trespasser wrote:
LOUD NOISES!!!!

Okay, is AVG up to date with all its definitions? have you scanned the system yet?

And which "system configuration" are you talking about here?
  • righteous_trespasser
  • Scuffle
  • Genius
  • User avatar
  • Posts: 6231
  • Loc: South-Africa

Post 3+ Months Ago

you won't know until you've scanned it ... so? ... what are you waiting for? press that "scan now" button ...
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

how can i post it here it cannot be copied

casablanca wrote:
Go to Task Manager and select New Task. Type "cmd" to open Command Prompt. Over there, type "tasklist" and post the output here. The list of processes might help in identifying if you have any viruses on your system.
  • righteous_trespasser
  • Scuffle
  • Genius
  • User avatar
  • Posts: 6231
  • Loc: South-Africa

Post 3+ Months Ago

so use your imagination ... "ALT+PrtScr" ... upload that to imageshack and give us a link ...
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Right-click the title bar of the window, select Edit > Mark, select the text and press Enter to copy it.

Once you do that, also type this command and paste the output:
Code: [ Select ]
reg query "hklm\software\microsoft\windows nt\currentversion\winlogon"
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

Microsoft Windows [Version 6.0.6000]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Windows\system32>tasklist

Image Name PID Session Name Session# Mem Usage
========================= ======== ================ =========== ============
System Idle Process 0 Services 0 28 K
System 4 Services 0 416 K
smss.exe 388 Services 0 536 K
csrss.exe 452 Services 0 4,300 K
wininit.exe 500 Services 0 2,860 K
csrss.exe 512 Console 1 7,648 K
services.exe 544 Services 0 4,192 K
lsass.exe 560 Services 0 6,376 K
lsm.exe 568 Services 0 2,948 K
winlogon.exe 720 Console 1 4,060 K
svchost.exe 740 Services 0 5,448 K
svchost.exe 800 Services 0 6,624 K
svchost.exe 844 Services 0 14,072 K
svchost.exe 896 Services 0 9,092 K
svchost.exe 924 Services 0 50,300 K
svchost.exe 964 Services 0 17,028 K
audiodg.exe 1028 Services 0 9,684 K
SLsvc.exe 1060 Services 0 3,460 K
svchost.exe 1104 Services 0 7,760 K
svchost.exe 1232 Services 0 9,564 K
spoolsv.exe 1404 Services 0 6,092 K
svchost.exe 1428 Services 0 7,612 K
taskeng.exe 1800 Console 1 8,876 K
dwm.exe 1832 Console 1 57,504 K
explorer.exe 1308 Console 1 47,116 K
AppleMobileDeviceService. 1852 Services 0 2,536 K
avgamsvr.exe 1984 Services 0 548 K
avgupsvc.exe 1712 Services 0 884 K
avgrssvc.exe 1760 Services 0 2,884 K
avgemc.exe 1332 Services 0 1,824 K
avgrssvc.exe 1568 Services 0 16,392 K
svchost.exe 700 Services 0 3,188 K
CLCapSvc.exe 1628 Services 0 5,752 K
svchost.exe 2036 Services 0 5,588 K
LSSrvc.exe 1080 Services 0 2,488 K
svchost.exe 916 Services 0 2,280 K
svchost.exe 1112 Services 0 3,136 K
svchost.exe 1068 Services 0 3,036 K
svchost.exe 1040 Services 0 4,200 K
svchost.exe 1580 Services 0 1,680 K
SearchIndexer.exe 1608 Services 0 20,940 K
XAudio.exe 1012 Services 0 1,868 K
hpqwmiex.exe 1016 Services 0 3,788 K
CLSched.exe 2364 Services 0 3,992 K
taskeng.exe 2748 Services 0 4,100 K
MSASCui.exe 2940 Console 1 9,872 K
SynTPEnh.exe 2948 Console 1 4,136 K
QPService.exe 3048 Console 1 8,208 K
QLBCTRL.exe 3072 Console 1 4,564 K
WiFiMsg.exe 3148 Console 1 3,548 K
HPWAMain.exe 3184 Console 1 4,104 K
rundll32.exe 3192 Console 1 3,216 K
jusched.exe 3200 Console 1 2,652 K
avgcc.exe 3236 Console 1 976 K
WmiPrvSE.exe 3256 Services 0 3,840 K
hpwuSchd2.exe 3296 Console 1 2,504 K
winampa.exe 3336 Console 1 3,612 K
iTunesHelper.exe 3352 Console 1 5,808 K
realsched.exe 3380 Console 1 196 K
sidebar.exe 3388 Console 1 28,580 K
ehtray.exe 3400 Console 1 956 K
mRouterConfig.exe 3408 Console 1 4,632 K
YahooMessenger.exe 3556 Console 1 21,812 K
ehmsas.exe 3600 Console 1 3,140 K
btdna.exe 3612 Console 1 5,952 K
VeohClient.exe 3636 Console 1 14,748 K
BTTray.exe 3668 Console 1 7,008 K
hpqtra08.exe 3812 Console 1 8,172 K
HPQTOA~1.EXE 2744 Console 1 4,064 K
mRouterRuntime.exe 3172 Console 1 5,360 K
hpqste08.exe 3440 Console 1 5,056 K
BTStackServer.exe 2100 Console 1 7,448 K
iPodService.exe 3960 Services 0 3,724 K
HPHC_Service.exe 4460 Services 0 9,164 K
svchost.exe 1792 Services 0 3,556 K
ieuser.exe 5764 Console 1 9,916 K
iexplore.exe 6036 Console 1 101,488 K
winampTbServer.exe 3308 Console 1 6,972 K
hpswp_clipbook.exe 5780 Console 1 4,168 K
msconfig.exe 5860 Console 1 8,784 K
avgwb.dat 2392 Console 1 65,848 K
SearchProtocolHost.exe 3736 Services 0 6,512 K
SearchFilterHost.exe 1204 Services 0 4,432 K
taskmgr.exe 4352 Console 1 11,928 K
cmd.exe 5476 Console 1 2,280 K
tasklist.exe 4116 Console 1 4,552 K
WmiPrvSE.exe 4608 Services 0 5,444 K

C:\Windows\system32>
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

these are the results
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

these are the results


Microsoft Windows [Version 6.0.6000]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Windows\system32>tasklist

Image Name PID Session Name Session# Mem Usage
========================= ======== ================ =========== ============
System Idle Process 0 Services 0 28 K
System 4 Services 0 416 K
smss.exe 388 Services 0 536 K
csrss.exe 452 Services 0 4,300 K
wininit.exe 500 Services 0 2,860 K
csrss.exe 512 Console 1 8,904 K
services.exe 544 Services 0 4,180 K
lsass.exe 560 Services 0 6,448 K
lsm.exe 568 Services 0 2,968 K
winlogon.exe 720 Console 1 4,060 K
svchost.exe 740 Services 0 5,428 K
svchost.exe 800 Services 0 6,640 K
svchost.exe 844 Services 0 12,452 K
svchost.exe 896 Services 0 9,184 K
svchost.exe 924 Services 0 56,320 K
svchost.exe 964 Services 0 17,636 K
audiodg.exe 1028 Services 0 9,728 K
SLsvc.exe 1060 Services 0 3,504 K
svchost.exe 1104 Services 0 8,040 K
svchost.exe 1232 Services 0 9,684 K
spoolsv.exe 1404 Services 0 6,424 K
svchost.exe 1428 Services 0 7,576 K
taskeng.exe 1800 Console 1 8,896 K
dwm.exe 1832 Console 1 57,080 K
explorer.exe 1308 Console 1 42,800 K
AppleMobileDeviceService. 1852 Services 0 2,536 K
avgamsvr.exe 1984 Services 0 544 K
avgupsvc.exe 1712 Services 0 884 K
avgrssvc.exe 1760 Services 0 2,884 K
avgemc.exe 1332 Services 0 1,824 K
avgrssvc.exe 1568 Services 0 16,428 K
svchost.exe 700 Services 0 3,216 K
CLCapSvc.exe 1628 Services 0 5,752 K
svchost.exe 2036 Services 0 5,576 K
LSSrvc.exe 1080 Services 0 2,488 K
svchost.exe 916 Services 0 2,280 K
svchost.exe 1112 Services 0 3,160 K
svchost.exe 1068 Services 0 3,036 K
svchost.exe 1040 Services 0 4,200 K
svchost.exe 1580 Services 0 1,756 K
SearchIndexer.exe 1608 Services 0 20,768 K
XAudio.exe 1012 Services 0 1,868 K
hpqwmiex.exe 1016 Services 0 3,788 K
CLSched.exe 2364 Services 0 3,992 K
taskeng.exe 2748 Services 0 4,100 K
MSASCui.exe 2940 Console 1 9,932 K
SynTPEnh.exe 2948 Console 1 4,136 K
QPService.exe 3048 Console 1 8,196 K
QLBCTRL.exe 3072 Console 1 4,568 K
WiFiMsg.exe 3148 Console 1 3,548 K
HPWAMain.exe 3184 Console 1 4,108 K
rundll32.exe 3192 Console 1 3,220 K
jusched.exe 3200 Console 1 2,656 K
avgcc.exe 3236 Console 1 1,116 K
WmiPrvSE.exe 3256 Services 0 3,840 K
hpwuSchd2.exe 3296 Console 1 2,604 K
winampa.exe 3336 Console 1 3,612 K
iTunesHelper.exe 3352 Console 1 5,808 K
realsched.exe 3380 Console 1 192 K
sidebar.exe 3388 Console 1 27,828 K
ehtray.exe 3400 Console 1 956 K
mRouterConfig.exe 3408 Console 1 4,632 K
YahooMessenger.exe 3556 Console 1 33,696 K
ehmsas.exe 3600 Console 1 3,144 K
btdna.exe 3612 Console 1 5,968 K
VeohClient.exe 3636 Console 1 14,500 K
BTTray.exe 3668 Console 1 7,016 K
hpqtra08.exe 3812 Console 1 8,284 K
HPQTOA~1.EXE 2744 Console 1 4,068 K
mRouterRuntime.exe 3172 Console 1 5,360 K
hpqste08.exe 3440 Console 1 5,056 K
BTStackServer.exe 2100 Console 1 7,448 K
iPodService.exe 3960 Services 0 3,724 K
HPHC_Service.exe 4460 Services 0 9,180 K
svchost.exe 1792 Services 0 3,556 K
ieuser.exe 5764 Console 1 9,988 K
iexplore.exe 6036 Console 1 103,240 K
winampTbServer.exe 3308 Console 1 7,036 K
hpswp_clipbook.exe 5780 Console 1 4,168 K
avgwb.dat 2392 Console 1 68,288 K
SearchProtocolHost.exe 2428 Services 0 8,224 K
SearchFilterHost.exe 4900 Services 0 4,464 K
taskmgr.exe 4772 Console 1 10,228 K
cmd.exe 5832 Console 1 1,952 K
tasklist.exe 5632 Console 1 4,504 K
WmiPrvSE.exe 3088 Services 0 5,412 K

C:\Windows\system32>reg query "hklm\software\microsoft\windows nt\currentver
\winlogon"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe C:\WINDOWS\Config\csrss.exe
Userinit REG_SZ C:\Windows\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
AutoRestartShell REG_DWORD 0x1
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 0x1
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD 0x80000027
AutoLogonCount REG_DWORD 0x1

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPE
sions
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Not
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Aut
onChecked

C:\Windows\system32>
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

You already posted this output. Could you try the other command that I had given above?

You do seem to have a lot of processes running. Whenever you're dealing with a problem, it's best to close all other programs, for example, in your case, Yahoo Messenger and Winamp Agent.

Also, you seem to have a lot of svchost processes running - that may be a bad sign, since many viruses use that name.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

so far there are still no threast but somthing was changed
file======Result/Infection====Path
shell32======change===========C:/Windows/system32/shell32.dll
ntoskrnl=====change===========C:/Windows/system32/ntoskrnl.exe
is that godd???

righteous_trespasser wrote:
you won't know until you've scanned it ... so? ... what are you waiting for? press that "scan now" button ...
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

A change to those two files doesn't sound good - one is the OS kernel and the other deals with most of the stuff on your desktop - I think you should post a HJT log - see this post
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

this is the second command and i already closed yahoo and winamp

C:\Windows\system32>reg query "hklm\software\microsoft\windows nt\currentversion
\winlogon"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe C:\WINDOWS\Config\csrss.exe
Userinit REG_SZ C:\Windows\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
AutoRestartShell REG_DWORD 0x1
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 0x1
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD 0x80000027
AutoLogonCount REG_DWORD 0x1

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExten
sions
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\AutoLog
onChecked

C:\Windows\system32>
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

so what must I do to it??

casablanca wrote:
A change to those two files doesn't sound good - one is the OS kernel and the other deals with most of the stuff on your desktop - I think you should post a HJT log - see this post
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

That explains it - you do have a virus. The "Shell" value is supposed to be Explorer.exe but it's Config\csrss.exe. Download this utility and run it. Then, open task manager and kill csrss.exe - there might be two of them, one belongs to Windows and the other is the virus.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

how to kill them??

casablanca wrote:
That explains it - you do have a virus. The "Shell" value is supposed to be Explorer.exe but it's Config\csrss.exe. Download this utility and run it. Then, open task manager and kill csrss.exe - there might be two of them, one belongs to Windows and the other is the virus.
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Go to the Processes tab in Task Manager, find csrss.exe and click End Process.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

its says access denied
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

That one belongs to Windows. Is there only one csrss.exe? Try killing all of them.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

you said theres two i think its winlogon.exe i think its the 2nd virus
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

That's also part of Windows, unless there's more than one winlogon too.
Many viruses use the names of existing Windows programs such as csrss, lsass, userinit, winlogon, svchost.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

i tried to click "Show proccesses from all user then there are two of or crss.exe,one winlogon,one lsass and almost 15 svchost i tried to end one of th crss then the pc shut down and restrat
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Well, did you run the utility I posted? Since you mentioned your computer restarted anyway, did the desktop come back?
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

no the deskytop did not appear
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Well then, follow the instructions and post a HijackThis log: mswindows-forum/highjackthis-and-spyware-removal-resources-and-tips-t31034.html
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

they cannot be killed what should i do
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

then i download somthing what should i do (do a system scan and save a logfile or do a system scan only
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

please help me,is thi virus going to broke my dad's pc??? i might be scolded OMG help me urgent
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Save a log file and post it here.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

HERE IT IS

Logfile of HijackThis v1.99.1
Scan saved at 6:37:53 PM, on 21/5/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\francis\Program Files\DNA\btdna.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Users\francis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wimp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\winamp toolbar\WinampTbServer.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Users\francis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FNH6RHPG\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://sg.rd.yahoo.com/customize/ie/def ... yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://sg.rd.yahoo.com/customize/ie/def ... yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://sg.rd.yahoo.com/customize/ie/def ... yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.imesh.com/sidebar.html?src=ssb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://sg.rd.yahoo.com/customize/ie/def ... yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: XBTP01621 - {C66AF7F0-2CF6-48cb-9F94-04EC2504B4FC} - C:\PROGRA~1\IMESHA~1\IMESHM~1\MediaBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh applications\iMesh MediaBar\MediaBar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [mRouterConfig] "C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe"
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\francis\Program Files\DNA\btdna.exe"
O4 - Startup: Wimp.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0224820945
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

so what's next???
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

should i do the taskkill in the command prompt?
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Select and fix this entry using HJT:

Code: [ Select ]
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

please reply to me please... thanks im sooo freakin' out olready
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Unfortunately there aren't too many people online right now, so if I'm not able to help you fix your problem, you'll have to wait.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

i dont get it the tried to click fix checked button but it says nothing was cheked so do i have to check it all??
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

No, just check the F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe entry and click fix.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

then whats next??
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

nothing appeared??
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

https://ssl.perfora.net/tools.radiospla ... ckThis.exe

or

http://tomcoyote.com/hjt/
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

which should i use
??
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Restart and try your luck. That's all the help I can do at the moment. If you're still having a problem, then wait for someone else to help.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

wait one last question i restarted it and it was working fine but as i open the task manager there is still csrss.exe and stuff so is the pc ok or somthing??? please ans me
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

As long as there's only one csrss.exe it's fine - that is part of Windows. So if your desktop has come back, I think your PC is okay.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

and i tried to scan it still the same appeared so what does that mean???
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

actually there are two csrss.exe so is it ok??
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

Well I don't know. If you're having any more problems, someone else should be able to help you out.
  • franciskenz
  • Beginner
  • Beginner
  • franciskenz
  • Posts: 40

Post 3+ Months Ago

ok anyways thanks
  • grinch2171
  • Moderator
  • Genius
  • User avatar
  • Posts: 6819
  • Loc: Martinsburg, WV

Post 3+ Months Ago

First of all relax.

Secondly perform the following tasks.

Reboot the computer into Safe Mode. To do this restart the computer and press F8 during the boot process. Run HiJack This and select the following entries and click the Fix button.
Quote:
C:\Users\francis\Program Files\DNA\btdna.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.imesh.com/sidebar.html?src=ssb

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\francis\Program Files\DNA\btdna.exe"

O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html


Once done restart your computer normally and see if things are back to normal.
  • righteous_trespasser
  • Scuffle
  • Genius
  • User avatar
  • Posts: 6231
  • Loc: South-Africa

Post 3+ Months Ago

grinch2171 wrote:
First of all relax.

lol.
  • casablanca
  • Proficient
  • Proficient
  • User avatar
  • Posts: 483

Post 3+ Months Ago

grinch2171 wrote:
First of all relax.

:) Why didn't I think of that before?
  • spork
  • Brewmaster
  • Silver Member
  • spork
  • Posts: 6299
  • Loc: Seattle, WA

Post 3+ Months Ago

// edit: oops.
  • righteous_trespasser
  • Scuffle
  • Genius
  • User avatar
  • Posts: 6231
  • Loc: South-Africa

Post 3+ Months Ago

in the first reply in this thread I wrote:
What I'd suggest is for you to follow the instructions posted here.
  • grinch2171
  • Moderator
  • Genius
  • User avatar
  • Posts: 6819
  • Loc: Martinsburg, WV

Post 3+ Months Ago

spork wrote:
Read and follow these directions.


spork, this has already been done and I already gave him a list of entries to fix. It usually helps to read through the whole thread before chiming in.
  • spork
  • Brewmaster
  • Silver Member
  • spork
  • Posts: 6299
  • Loc: Seattle, WA

Post 3+ Months Ago

grinch2171 wrote:
It usually helps to read through the whole thread before chiming in.

Indeed it does. Point taken.
  • grinch2171
  • Moderator
  • Genius
  • User avatar
  • Posts: 6819
  • Loc: Martinsburg, WV

Post 3+ Months Ago

;)

Post Information

  • Total Posts in this topic: 62 posts
  • Users browsing this forum: No registered users and 31 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 1998-2016. Ozzu® is a registered trademark of Unmelted, LLC.