Free PC Support
PC Help Forums from the Experts at Technical-Assistance.co.uk
 
Google
 
Search The Web Search This Site
 RSS FeedRSS Feed   FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Server Busy
Goto page 1, 2, 3, 4  Next
 
This topic is locked: you cannot edit posts or make replies.    Free PC Support Forum Home -> Helproom
Author Message
terryw



Joined: 19 Sep 2007
Posts: 79
Location: Liverpool

PostPosted: Thu Oct 25, 2007 4:21 pm    Post subject: Server Busy Reply with quote

When am surfing the net i get a little message with a explanation mark saying server busy. I then get 2 options to "switch to" or "retry" I have to click retry loads of times for it to go, and then when it does go i get a pop up in Internet Explorer.

But i use Firefox as my default browser.

Any ideas???
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
SoftStag



Joined: 05 Feb 2006
Posts: 2049
Location: UK

PostPosted: Thu Oct 25, 2007 6:16 pm    Post subject: Reply with quote

It sounds like you may have some spyware installed. The error message sounds like a vb message, and this would not normally be there. Run a Spyware checker to see if there is anything malicious installed.
_________________
"Microsoft programs are generally bug-free. If you visit the Microsoft hotline, you'll literally have to wait weeks if not months until someone calls in with a bug in one of our programs. 99.99% of calls turn out to be user mistakes. I know not a single less irrelevant reason for an update than bugfixes. The reasons for updates are to present more new features."
-- Bill Gates, on code stability, from Focus Magazine
Back to top
View user's profile Send private message Visit poster's website
terryw



Joined: 19 Sep 2007
Posts: 79
Location: Liverpool

PostPosted: Thu Oct 25, 2007 6:35 pm    Post subject: Reply with quote

Do you know anywhere were i could get a free spyware checker, i use Mcfee security but i have a few problems with some parts of it, well...it has no firewall because of a Symantec problem, but will a seperate spyware checker find out if i have spyware on my PC
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
SoftStag



Joined: 05 Feb 2006
Posts: 2049
Location: UK

PostPosted: Thu Oct 25, 2007 6:41 pm    Post subject: Reply with quote

You can use the AVG Free Spyware checker. This should find any spyware on your system.
_________________
"Microsoft programs are generally bug-free. If you visit the Microsoft hotline, you'll literally have to wait weeks if not months until someone calls in with a bug in one of our programs. 99.99% of calls turn out to be user mistakes. I know not a single less irrelevant reason for an update than bugfixes. The reasons for updates are to present more new features."
-- Bill Gates, on code stability, from Focus Magazine
Back to top
View user's profile Send private message Visit poster's website
terryw



Joined: 19 Sep 2007
Posts: 79
Location: Liverpool

PostPosted: Thu Oct 25, 2007 6:48 pm    Post subject: Reply with quote

Thanks i will try that now Very Happy
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
terryw



Joined: 19 Sep 2007
Posts: 79
Location: Liverpool

PostPosted: Fri Oct 26, 2007 11:32 am    Post subject: Reply with quote

I downloaded the Spyware, run the scan found 200 Spyware, removed them but i still get the Server Busy message. It slows the PC down when it appears.
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
SoftStag



Joined: 05 Feb 2006
Posts: 2049
Location: UK

PostPosted: Fri Oct 26, 2007 5:35 pm    Post subject: Reply with quote

Download and run HijackThis, then paste the results in your post for us to look at.
_________________
"Microsoft programs are generally bug-free. If you visit the Microsoft hotline, you'll literally have to wait weeks if not months until someone calls in with a bug in one of our programs. 99.99% of calls turn out to be user mistakes. I know not a single less irrelevant reason for an update than bugfixes. The reasons for updates are to present more new features."
-- Bill Gates, on code stability, from Focus Magazine
Back to top
View user's profile Send private message Visit poster's website
terryw



Joined: 19 Sep 2007
Posts: 79
Location: Liverpool

PostPosted: Sat Oct 27, 2007 1:45 pm    Post subject: Reply with quote

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:43:46, on 27/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\D1.tmp
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Terry\APPLIC~1\TSKS~1\dvdplay.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\wcvs.exe
C:\WINDOWS\System32\wfvs.exe
C:\WINDOWS\system32\drivers\ssdp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\T?sks\r?gsvr32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\D1.tmp
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\D1.tmp
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
O2 - BHO: (no name) - {623B6BF2-F33A-8D96-1A14-8A8DCA22D09A} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9BED4B04-DBC1-FA6F-BB2E-F98A45F625CA} - C:\WINDOWS\system32\lzqultny.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {BD92D75E-1098-3E35-EC5B-3E766A3A01C7} - (no file)
O2 - BHO: (no name) - {BDC1895F-11CC-6732-EC5B-3E766A3A01C4} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [File Mapping Services] hp-1003.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [msvccc66] svcchosst.exe
O4 - HKLM\..\Run: [Microsoft Update] C:\WINDOWS\System32\mdm.exe
O4 - HKLM\..\Run: [Windows Update] ssms.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKLM\..\Run: [Topic MSNGR32] MSNGR32.com
O4 - HKLM\..\Run: [PC Tilecom] Tilecompc.com
O4 - HKLM\..\Run: [Windows Service Discovery Protocol Service] "C:\WINDOWS\system32\ssdp.exe" *
O4 - HKLM\..\Run: [TileFree] Tilecomfree.com
O4 - HKLM\..\Run: [Windows Simple Service Discovery Protocol] "C:\WINDOWS\system32\drivers\ssdp.exe" *
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Server Peer Verification Service] "C:\WINDOWS\system32\wspvs.exe" *
O4 - HKLM\..\Run: [Windows Server Client Verification Service] "C:\WINDOWS\system32\wscvs.exe" *
O4 - HKLM\..\Run: [Windows Protocol Deployment System Service] "C:\WINDOWS\System32\wpdss.exe" *
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [Windows File Verification Service] "C:\WINDOWS\System32\wfvs.exe" *
O4 - HKLM\..\Run: [Microsoft (R) Windows Network Service Monitor] C:\WINDOWS\system32\D1.tmp
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Starter] C:\WINDOWS\System32\STARTER.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Windows Certificate Verification Service] "C:\WINDOWS\wcvs.exe" *
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [File Mapping Services] hp-1003.exe
O4 - HKLM\..\RunServices: [msvccc66] svcchosst.exe
O4 - HKLM\..\RunServices: [Windows Update] ssms.exe
O4 - HKLM\..\RunServices: [Topic MSNGR32] MSNGR32.com
O4 - HKLM\..\RunServices: [PC Tilecom] Tilecompc.com
O4 - HKLM\..\RunServices: [TileFree] Tilecomfree.com
O4 - HKCU\..\Run: [Lyh] C:\WINDOWS\System32\n?tdde.exe
O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1047.dll,InstantAccess
O4 - HKCU\..\Run: [Nbae] "C:\WINDOWS\ASEMBL~1\arpa.exe" -vt ndrv
O4 - HKCU\..\Run: [Yggm] C:\WINDOWS\?icrosoft\l?ass.exe
O4 - HKCU\..\Run: [File Mapping Services] hp-1003.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Tchr] "C:\DOCUME~1\Terry\APPLIC~1\TSKS~1\dvdplay.exe" -vt ndrv
O4 - HKCU\..\Run: [Mfazqqcy] "C:\Program Files\Common Files\T?sks\r?gsvr32.exe"
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\RunServices: [Windows Update] fdos.exe
O4 - HKCU\..\RunServices: [File Mapping Services] hp-1003.exe
O4 - HKUS\S-1-5-18\..\Run: [MSN Updater] msnms.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [win32 update service] svchostt.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Update] fdos.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsft Config 32] msconfig32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [File Mapping Services] hp-1003.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] C:\WINDOWS\System32\mdm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Discovery Protocol Service] "C:\WINDOWS\system32\ssdp.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Simple Service Discovery Protocol] "C:\WINDOWS\system32\drivers\ssdp.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Server Peer Verification Service] "C:\WINDOWS\system32\wspvs.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Server Client Verification Service] "C:\WINDOWS\system32\wscvs.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Protocol Deployment System Service] "C:\WINDOWS\System32\wpdss.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows File Verification Service] "C:\WINDOWS\System32\wfvs.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Certificate Verification Service] "C:\WINDOWS\wcvs.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [win32 update service] svchostt.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Windows Update] fdos.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSN Updater] msnms.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [win32 update service] svchostt.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Windows Update] fdos.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O23 - Service: McAfee Application Installer Cleanup (0190791193161565) (0190791193161565mcinstcleanup) - Unknown owner - C:\DOCUME~1\Terry\LOCALS~1\Temp\019079~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Windows Network Service Monitor (nsmss) - Unknown owner - C:\WINDOWS\system32\D1.tmp
O23 - Service: PCTEL Speaker Phone (pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Windows Certificate Verification Service (wcvs) - Unknown owner - C:\WINDOWS\wcvs.exe
O23 - Service: Windows File Verification Service (wfvs) - Unknown owner - C:\WINDOWS\System32\wfvs.exe
O23 - Service: Windows Management Service (wms) - Unknown owner - C:\WINDOWS\System32\wms.exe (file missing)
O23 - Service: Windows Simple Service Discovery Protocol (wssdp) - Unknown owner - C:\WINDOWS\system32\drivers\ssdp.exe

--
End of file - 14391 bytes
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
SoftStag



Joined: 05 Feb 2006
Posts: 2049
Location: UK

PostPosted: Sun Oct 28, 2007 5:35 pm    Post subject: Reply with quote

OK, looks like you still have some nasties in there. Please try the following:

Arrow Press Ctrl, Alt and Delete together, and select Task Manager
Arrow Click on the Processes tab
Arrow Find D1.tmp and select End Task
Arrow Find wcvs.exe and select End Task
Arrow Find wfvs.exe and select End Task
Arrow Find ssdp.exe and select End Task
Arrow Find r?gsvr32.exe and select End Task
Arrow Run HijackThis and perform a scan
Arrow Put a tick in the following lines:
- F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\D1.tmp
- F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\D1.tmp
- O2 - BHO: (no name) - {623B6BF2-F33A-8D96-1A14-8A8DCA22D09A} - (no file)
- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
- O2 - BHO: (no name) - {9BED4B04-DBC1-FA6F-BB2E-F98A45F625CA} - C:\WINDOWS\system32\lzqultny.dll
- O2 - BHO: (no name) - {BD92D75E-1098-3E35-EC5B-3E766A3A01C7} - (no file)
- O2 - BHO: (no name) - {BDC1895F-11CC-6732-EC5B-3E766A3A01C4} - (no file)
- O4 - HKLM\..\Run: [File Mapping Services] hp-1003.exe
- O4 - HKLM\..\Run: [msvccc66] svcchosst.exe
- O4 - HKLM\..\Run: [Windows Update] ssms.exe
- O4 - HKLM\..\Run: [Topic MSNGR32] MSNGR32.com
- O4 - HKLM\..\Run: [PC Tilecom] Tilecompc.com
- O4 - HKLM\..\Run: [Windows Service Discovery Protocol Service] "C:\WINDOWS\system32\ssdp.exe" *
- O4 - HKLM\..\Run: [TileFree] Tilecomfree.com
- O4 - HKLM\..\Run: [Windows Simple Service Discovery Protocol] "C:\WINDOWS\system32\drivers\ssdp.exe" *
- O4 - HKLM\..\Run: [Windows Server Peer Verification Service] "C:\WINDOWS\system32\wspvs.exe" *
- O4 - HKLM\..\Run: [Windows Server Client Verification Service] "C:\WINDOWS\system32\wscvs.exe" *
- O4 - HKLM\..\Run: [Windows Protocol Deployment System Service] "C:\WINDOWS\System32\wpdss.exe" *
- O4 - HKLM\..\Run: [Windows File Verification Service] "C:\WINDOWS\System32\wfvs.exe" *
- O4 - HKLM\..\Run: [Microsoft (R) Windows Network Service Monitor] C:\WINDOWS\system32\D1.tmp
- O4 - HKLM\..\Run: [Windows Certificate Verification Service] "C:\WINDOWS\wcvs.exe" *
- O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
- O4 - HKLM\..\RunServices: [File Mapping Services] hp-1003.exe
- O4 - HKLM\..\RunServices: [msvccc66] svcchosst.exe
- O4 - HKLM\..\RunServices: [Windows Update] ssms.exe
- O4 - HKLM\..\RunServices: [Topic MSNGR32] MSNGR32.com
- O4 - HKLM\..\RunServices: [PC Tilecom] Tilecompc.com
- O4 - HKLM\..\RunServices: [TileFree] Tilecomfree.com
- O4 - HKCU\..\Run: [Lyh] C:\WINDOWS\System32\n?tdde.exe
- O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1047.dll,InstantAccess
- O4 - HKCU\..\Run: [Nbae] "C:\WINDOWS\ASEMBL~1\arpa.exe" -vt ndrv
- O4 - HKCU\..\Run: [Yggm] C:\WINDOWS\?icrosoft\l?ass.exe
- O4 - HKCU\..\Run: [File Mapping Services] hp-1003.exe
- O4 - HKCU\..\Run: [Mfazqqcy] "C:\Program Files\Common Files\T?sks\r?gsvr32.exe"
- O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
- O4 - HKCU\..\RunServices: [Windows Update] fdos.exe
- O4 - HKCU\..\RunServices: [File Mapping Services] hp-1003.exe
- O4 - HKUS\S-1-5-18\..\Run: [MSN Updater] msnms.exe (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [win32 update service] svchostt.exe (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows Update] fdos.exe (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Microsft Config 32] msconfig32.exe (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [File Mapping Services] hp-1003.exe (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows Service Discovery Protocol Service] "C:\WINDOWS\system32\ssdp.exe" * (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows Simple Service Discovery Protocol] "C:\WINDOWS\system32\drivers\ssdp.exe" * (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows Server Peer Verification Service] "C:\WINDOWS\system32\wspvs.exe" * (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows Server Client Verification Service] "C:\WINDOWS\system32\wscvs.exe" * (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows Protocol Deployment System Service] "C:\WINDOWS\System32\wpdss.exe" * (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows File Verification Service] "C:\WINDOWS\System32\wfvs.exe" * (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\Run: [Windows Certificate Verification Service] "C:\WINDOWS\wcvs.exe" * (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\RunOnce: [win32 update service] svchostt.exe (User 'SYSTEM')
- O4 - HKUS\S-1-5-18\..\RunServices: [Windows Update] fdos.exe (User 'SYSTEM')
- O4 - HKUS\.DEFAULT\..\Run: [MSN Updater] msnms.exe (User 'Default user')
- O4 - HKUS\.DEFAULT\..\RunOnce: [win32 update service] svchostt.exe (User 'Default user')
- O4 - HKUS\.DEFAULT\..\RunServices: [Windows Update] fdos.exe (User 'Default user')
- O23 - Service: Windows Network Service Monitor (nsmss) - Unknown owner - C:\WINDOWS\system32\D1.tmp
- O23 - Service: Windows Certificate Verification Service (wcvs) - Unknown owner - C:\WINDOWS\wcvs.exe
- O23 - Service: Windows File Verification Service (wfvs) - Unknown owner - C:\WINDOWS\System32\wfvs.exe
- O23 - Service: Windows Management Service (wms) - Unknown owner - C:\WINDOWS\System32\wms.exe (file missing)
- O23 - Service: Windows Simple Service Discovery Protocol (wssdp) - Unknown owner - C:\WINDOWS\system32\drivers\ssdp.exe
Arrow Select Fix

HijackThis should fix these entries. Now reboot the computer and run HijackThis again. Post your new log and we can see how it looks.
_________________
"Microsoft programs are generally bug-free. If you visit the Microsoft hotline, you'll literally have to wait weeks if not months until someone calls in with a bug in one of our programs. 99.99% of calls turn out to be user mistakes. I know not a single less irrelevant reason for an update than bugfixes. The reasons for updates are to present more new features."
-- Bill Gates, on code stability, from Focus Magazine
Back to top
View user's profile Send private message Visit poster's website
terryw



Joined: 19 Sep 2007
Posts: 79
Location: Liverpool

PostPosted: Sun Oct 28, 2007 11:17 pm    Post subject: Reply with quote

OK i done the above but when i selected the process and pressed end process, the process simply moved in the list of processes. Is this what should happen?

I will still post the HiJack this results after i rebooted my PC in the following reply.
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
terryw



Joined: 19 Sep 2007
Posts: 79
Location: Liverpool

PostPosted: Sun Oct 28, 2007 11:43 pm    Post subject: Reply with quote

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\D1.tmp
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wcvs.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\wfvs.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\drivers\ssdp.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Terry\APPLIC~1\TSKS~1\dvdplay.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\D1.tmp
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\D1.tmp
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {99B81803-8296-FE65-BB2E-F98A45F624C4} - C:\WINDOWS\system32\xpz.dll
O2 - BHO: (no name) - {9BED4B04-DBC1-FA6F-BB2E-F98A45F625CA} - C:\WINDOWS\system32\lzqultny.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Update] C:\WINDOWS\System32\mdm.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Starter] C:\WINDOWS\System32\STARTER.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [Microsoft (R) Windows Network Service Monitor] C:\WINDOWS\system32\D1.tmp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Tchr] "C:\DOCUME~1\Terry\APPLIC~1\TSKS~1\dvdplay.exe" -vt ndrv
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] C:\WINDOWS\System32\mdm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [File Mapping Services] hp-1003.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Update] C:\WINDOWS\System32\mdm.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [File Mapping Services] hp-1003.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O23 - Service: McAfee Application Installer Cleanup (0190791193161565) (0190791193161565mcinstcleanup) - Unknown owner - C:\DOCUME~1\Terry\LOCALS~1\Temp\019079~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Windows Network Service Monitor (nsmss) - Unknown owner - C:\WINDOWS\system32\D1.tmp
O23 - Service: PCTEL Speaker Phone (pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Windows Certificate Verification Service (wcvs) - Unknown owner - C:\WINDOWS\wcvs.exe
O23 - Service: Windows File Verification Service (wfvs) - Unknown owner - C:\WINDOWS\System32\wfvs.exe
O23 - Service: Windows Management Service (wms) - Unknown owner - C:\WINDOWS\System32\wms.exe (file missing)
O23 - Service: Windows Simple Service Discovery Protocol (wssdp) - Unknown owner - C:\WINDOWS\system32\drivers\ssdp.exe

--
End of file - 10942 bytes

By the way thanks for the help Laughing
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
SoftStag



Joined: 05 Feb 2006
Posts: 2049
Location: UK

PostPosted: Mon Oct 29, 2007 6:12 pm    Post subject: Reply with quote

No, the processes shouldn't move when you End Task on them. They are being stubborn, and some things are still there!

Try this:

Arrow Restart the computer and go in to Safe Mode (as the computer boots up, tap the F8 key until you get a menu and slect Safe Mode). Once there check again for those processes. Hopefully they won't be running, if they are try to End Task on them again.
Arrow Delete the following files:
- C:\WINDOWS\system32\D1.tmp
- C:\WINDOWS\wcvs.exe
- C:\WINDOWS\System32\wfvs.exe
- C:\WINDOWS\system32\lzqultny.dll
- C:\WINDOWS\system32\ssdp.exe
- C:\WINDOWS\system32\wspvs.exe
- C:\WINDOWS\system32\wscvs.exe
- C:\WINDOWS\System32\wpdss.exe
- C:\WINDOWS\wcvs.exe
- C:\Program Files\SpywareBot\SpywareBot.exe
- C:\WINDOWS\System32\n?tdde.exe
- C:\WINDOWS\ASEMBL~1\arpa.exe
- C:\WINDOWS\?icrosoft\l?ass.exe
- C:\Program Files\Common Files\T?sks\r?gsvr32.exe
- C:\WINDOWS\system32\drivers\ssdp.exe
- C:\WINDOWS\System32\lssas.exe

Arrow Search for the following files and delete these:
- hp-1003.exe
- svcchosst.exe
- ssms.exe
- MSNGR32.com
- Tilecompc.com
- Tilecomfree.com
- p2esocks_1047.dll
- arpa.exe
- fdos.exe
- msnms.exe
- svchostt.exe
- msconfig32.exe

Arrow Run HijackThis and put a tick in to the following:
- F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\D1.tmp
- F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\D1.tmp
- O2 - BHO: (no name) - {99B81803-8296-FE65-BB2E-F98A45F624C4} - C:\WINDOWS\system32\xpz.dll
- O2 - BHO: (no name) - {9BED4B04-DBC1-FA6F-BB2E-F98A45F625CA} - C:\WINDOWS\system32\lzqultny.dll (file missing)
- O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
- O4 - HKLM\..\Run: [Microsoft (R) Windows Network Service Monitor] C:\WINDOWS\system32\D1.tmp
- O4 - HKUS\S-1-5-18\..\RunServices: [File Mapping Services] hp-1003.exe (User 'SYSTEM')
- O4 - HKUS\.DEFAULT\..\RunServices: [File Mapping Services] hp-1003.exe (User 'Default user')
- O23 - Service: McAfee Application Installer Cleanup (0190791193161565) (0190791193161565mcinstcleanup) - Unknown owner - C:\DOCUME~1\Terry\LOCALS~1\Temp\019079~1.EXE (file missing)
- O23 - Service: Windows Network Service Monitor (nsmss) - Unknown owner - C:\WINDOWS\system32\D1.tmp
- O23 - Service: Windows Certificate Verification Service (wcvs) - Unknown owner - C:\WINDOWS\wcvs.exe
- O23 - Service: Windows File Verification Service (wfvs) - Unknown owner - C:\WINDOWS\System32\wfvs.exe
- O23 - Service: Windows Management Service (wms) - Unknown owner - C:\WINDOWS\System32\wms.exe (file missing)
- O23 - Service: Windows Simple Service Discovery Protocol (wssdp) - Unknown owner - C:\WINDOWS\system32\drivers\ssdp.exe

Arrow Select Fix
Arrow Reboot in to Normal Mode, then run HijackThis and post another log.
_________________
"Microsoft programs are generally bug-free. If you visit the Microsoft hotline, you'll literally have to wait weeks if not months until someone calls in with a bug in one of our programs. 99.99% of calls turn out to be user mistakes. I know not a single less irrelevant reason for an update than bugfixes. The reasons for updates are to present more new features."
-- Bill Gates, on code stability, from Focus Magazine
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
This topic is locked: you cannot edit posts or make replies.    Free PC Support Forum Home -> Helproom All times are GMT
Goto page 1, 2, 3, 4  Next
Page 1 of 4

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

 



Powered by phpBB © 2001, 2005 phpBB Group

2005 - 2017 All Rights Reserved www.technical-assistance.co.uk
Terms and Conditions