Topic:Control Panel vanished! Remainpoint:0
   
PostTime:12/16/2008 1:20:08 PM FloorTop
Lv is 1
Avatar
Level:
1
Professional point:
0
Experience:
0
Thread:
117
Post:
467
Total online time:
0M
Joined date:
4/19/2007 8:49:00 AM
Last Visit:
4/19/2007 8:49:19 AM
Status:
Offline
Hello,

OK I don't know anything about pooters but here is the problem I am having. Last week I kept on getting pop-ups saying that my computer was making unauthorised copies of files and that Windows Defender had found harmful files. Now I don't have a Control Panel. When I try to do things like add or remove programs it comes up with a little window that says: This operation has been cancelled due to restrictions in effect on this computer. Please contact system administrator. Looking through other posts I believe the first step is to run a Hijack This thing and post the log so here it is. Your help would be appreciated!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:20:58, on 25/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\AOL\1171580365\ee\aolsoftware.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Jasmine\Application Data\My-disgo\MyKey disgo.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co.uk/web?isinit=true&query=%s
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171580365\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [My-disgo] C:\Documents and Settings\Jasmine\Application Data\My-disgo\MyKey disgo.exe
O4 - HKCU\..\Run: [BackupNotify] C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0b\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZNxuk101YYGB
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q304&bd=pavilion&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache...up1.0.0.15.exe
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.co.uk/SnapfishUKActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1154726821515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1170438148859
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by133fd.bay133.hotmail.msn.co...x/HMAtchmt.ocx
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 11177 bytes
 
     
   
Gender PostTime:12/16/2008 2:29:59 PM Point:0 | Floor# 1
Lv is 1
portrait
Level:
1
Professional point:
5
Experience:
19
Thread:
290
Post:
993
Total online time:
19M
Joined date:
4/28/2007 11:08:00 PM
Last Visit:
12/17/2008 12:44:18 AM
Status:
Offline
Thanks for your replies. Hope you don't get blown away!
 
     
   
Gender PostTime:12/16/2008 5:30:48 PM Point:0 | Floor# 2
Lv is 1
portrait
Level:
1
Professional point:
0
Experience:
2
Thread:
130
Post:
439
Total online time:
2M
Joined date:
4/19/2007 8:51:00 AM
Last Visit:
5/21/2007 7:02:58 AM
Status:
Offline
No I hadn't installed ERUNT when it came up.
 
     
   
Gender PostTime:12/16/2008 6:48:55 PM Point:0 | Floor# 3
Lv is 1
portrait
Level:
1
Professional point:
3
Experience:
8
Thread:
285
Post:
966
Total online time:
8M
Joined date:
4/28/2007 11:55:00 PM
Last Visit:
12/16/2008 11:44:45 PM
Status:
Offline
Quote:
Originally Posted by Jasmine14
No I hadn't installed ERUNT when it came up.
Ok. Continue with the rest of the instructions. If Windows Defender intervenes, disable Real Time Protection until we finish with the cleanup.

To disable Real-Time Protection:
  • Go to "Tools" "General Settings"
  • Scroll down to "Real-time protection options"
  • Uncheck "Turn on real-time protection (recommended)"
  • Remember to reactivate this feature when we have finished all our work.

This may vary as I don't have the latest version.
 
     
   
Gender PostTime:12/16/2008 8:10:24 PM Point:0 | Floor# 4
Lv is 1
portrait
Level:
1
Professional point:
87
Experience:
35
Thread:
282
Post:
936
Total online time:
35M
Joined date:
4/28/2007 11:15:00 PM
Last Visit:
12/16/2008 11:26:43 PM
Status:
Offline
Hello again,

OK so when I rebooted in safe mode, I couldn't do the start>control panel, remove programs bit because my control panel didn't show up. I looked in the start menu's properties bit and it wasn't there either. Here is the LOP report thingie:

LOP Report
25/09/2007 21:34:29.45

Volume in drive C has no label.
Volume Serial Number is 0C66-4644

Directory of C:\Documents and Settings\Jasmine\Application Data

14/10/2005 13:10 <DIR> Adobe
18/06/2006 17:20 1,062 AdobeDLM.log
16/12/2006 15:38 <DIR> AdobeUM
26/02/2005 21:44 <DIR> AOL
30/09/2004 00:00 <DIR> APPLEC~1 Apple Computer
01/09/2005 15:44 <DIR> ArcSoft
01/09/2005 15:52 <DIR> Canon
18/06/2006 17:20 0 dm.ini
04/04/2007 12:02 122,648 DRVCLE~1.EXE drvcleaner.exe
27/09/2005 17:22 82,288 GDIPFO~1.DAT GDIPFONTCACHEV1.DAT
16/03/2006 17:11 <DIR> Google
28/02/2005 23:33 <DIR> Help
30/09/2004 05:28 <DIR> IDENTI~1 Identities
30/03/2007 23:15 1,100,074 Install.dat
07/03/2005 21:02 <DIR> INTERV~1 InterVideo
22/09/2007 19:31 1 ipc.dll
26/02/2005 21:58 <DIR> MACROM~1 Macromedia
04/09/2005 22:21 <DIR> MCAFEE~1.COM McAfee.com Personal Firewall
25/02/2005 12:58 <DIR> MICROS~2 Microsoft Web Folders
26/02/2005 18:02 <DIR> My-disgo
23/12/2006 16:34 <DIR> MySpace
20/04/2007 09:39 322,872 PRIVPR~1.EXE privprotect.exe
05/06/2007 11:57 <DIR> Snapfish
29/09/2004 23:45 <DIR> Sonic
29/09/2004 22:53 <DIR> Sun
30/09/2004 00:01 <DIR> Symantec
09/04/2007 15:18 153 SYSDOC~1.EXE sysdoctor.exe
22/09/2007 20:20 <DIR> ultra
25/02/2007 00:06 <DIR> VIEWPO~1 Viewpoint
19/09/2007 17:38 31,952 wklnhst.dat
26/02/2005 21:49 <DIR> YOU'VE~1 You've Got Pictures Screensaver
9 File(s) 1,661,050 bytes
22 Dir(s) 41,031,921,664 bytes free
Volume in drive C has no label.
Volume Serial Number is 0C66-4644

Directory of C:\Documents and Settings\All Users\Application Data

20/11/2006 22:00 <DIR> Adobe
15/02/2007 23:59 <DIR> AOL
02/07/2007 21:09 <DIR> Apple
28/06/2007 21:08 <DIR> APPLEC~1 Apple Computer
27/01/2006 15:29 <DIR> BVRPSO~1 BVRP Software
29/09/2004 23:58 605 HPZINS~1.LOG hpzinstall.log
04/03/2007 21:32 <DIR> McAfee.com
02/10/2005 21:23 <DIR> MCAFEE~1.COM McAfee.com Personal Firewall
15/04/2007 13:20 1,756 QTSBAN~1 QTSBandwidthCache
30/09/2004 00:00 <DIR> QUICKT~1 QuickTime
30/09/2004 05:28 <DIR> SBSI
30/03/2005 19:46 <DIR> Symantec
26/02/2005 21:48 <DIR> VIEWPO~1 Viewpoint
02/02/2007 18:56 <DIR> WINDOW~1 Windows Genuine Advantage
26/02/2006 00:25 <DIR> Zylom
2 File(s) 2,361 bytes
13 Dir(s) 41,031,921,664 bytes free
Volume in drive C has no label.
Volume Serial Number is 0C66-4644

Directory of C:\Program Files

25/09/2007 19:20 <DIR> .
25/09/2007 19:20 <DIR> ..
14/10/2005 13:16 <DIR> Adobe
29/09/2004 22:52 <DIR> ANALOG~1 Analog Devices
16/02/2007 00:01 <DIR> AOL
26/02/2005 21:40 <DIR> AOL9~1.0 AOL 9.0
17/08/2005 18:29 <DIR> AOL9~1.0A AOL 9.0a
29/04/2007 16:18 <DIR> AOL9~1.0B AOL 9.0b
07/09/2005 17:18 <DIR> AOLCOM~1 AOL Companion
17/09/2005 17:36 <DIR> AOLTOO~1 AOL Toolbar
30/09/2004 05:31 <DIR> Apoint2K
05/08/2007 21:51 <DIR> APPLES~1 Apple Software Update
04/09/2007 14:57 <DIR> ATITEC~1 ATI Technologies
25/07/2005 00:23 <DIR> BBCTHR~1 BBC THREE Facepull
27/01/2006 17:39 <DIR> Canon
02/07/2007 21:09 <DIR> COMMON~1 Common Files
30/09/2004 05:28 <DIR> COMPLU~1 ComPlus Applications
30/09/2004 00:17 <DIR> EASYIN~1 Easy Internet signup
31/03/2007 00:56 <DIR> ENIGMA~1 Enigma Software Group
03/09/2005 11:06 <DIR> EPSON
08/02/2006 23:05 <DIR> EZFace
03/12/2005 22:42 <DIR> FUNWEB~1 FunWebProducts
16/03/2006 17:10 <DIR> Google
06/04/2005 17:15 <DIR> HASBRO~1 Hasbro Interactive
29/09/2004 23:57 <DIR> HEWLET~1 Hewlett-Packard
29/09/2004 23:57 <DIR> HP
26/02/2005 04:49 <DIR> HPQ
15/08/2007 16:21 <DIR> INTERN~1 Internet Explorer
26/02/2005 04:49 <DIR> INTERV~1 InterVideo
05/08/2007 21:54 <DIR> iPod
01/03/2006 23:54 <DIR> IRFANV~1 IrfanView
20/08/2007 19:54 <DIR> iTunes
29/09/2004 22:53 <DIR> Java
26/02/2005 21:49 <DIR> Learn2.com
27/01/2006 15:16 <DIR> LIVEUP~1 LiveUpdate
01/01/2006 23:37 <DIR> LOVECH~1 LoveChessTheGreekEraDemo
06/08/2006 18:10 <DIR> Maxis
08/01/2007 17:25 <DIR> McAfee
04/03/2007 21:33 <DIR> McAfee.com
16/03/2005 04:08 <DIR> MESSEN~1 Messenger
26/02/2005 01:18 <DIR> MI3AA1~1 Microsoft ActiveSync
26/02/2005 05:10 <DIR> MI2493~1 Microsoft AutoRoute
26/02/2005 05:17 <DIR> MIF408~1 Microsoft Encarta
25/02/2005 12:58 <DIR> MICROS~1 microsoft frontpage
26/02/2005 05:09 <DIR> MICAC0~1 Microsoft Money
26/02/2005 01:18 <DIR> MICROS~4 Microsoft Office
26/02/2005 05:16 <DIR> MI7D8A~1 Microsoft Picture It! 9
25/02/2005 13:03 <DIR> MIAF9D~1 Microsoft Visual Studio
26/02/2005 05:05 <DIR> MICROS~2 Microsoft Works
26/02/2005 04:54 <DIR> MICROS~3 Microsoft Works Suite 2004
27/01/2006 15:15 <DIR> MOBILE~1 mobile PhoneTools
30/09/2004 05:28 <DIR> MOVIEM~1 Movie Maker
30/09/2004 05:28 <DIR> MSN
30/09/2004 05:28 <DIR> MSNGAM~1 MSN Gaming Zone
04/03/2007 21:39 <DIR> MSNMES~1 MSN Messenger
02/02/2007 22:07 <DIR> MSXML4~1.0 MSXML 4.0
23/12/2006 23:35 <DIR> MySpace
17/08/2005 18:29 <DIR> n-CASE
30/09/2004 05:28 <DIR> NETMEE~1 NetMeeting
30/09/2004 00:17 <DIR> ONLINE~1 Online Services
22/06/2007 01:10 <DIR> OUTLOO~1 Outlook Express
19/07/2007 22:43 <DIR> QUICKT~1 QuickTime
26/02/2005 21:41 <DIR> Real
29/09/2004 23:44 <DIR> RECORD~1 RecordNow!
01/09/2005 15:38 <DIR> ScanSoft
29/09/2004 23:44 <DIR> Sonic
30/03/2005 19:46 <DIR> Symantec
19/10/2005 12:39 <DIR> thriXXX
25/09/2007 19:20 <DIR> TRENDM~1 Trend Micro
26/02/2005 21:48 <DIR> VIEWPO~1 Viewpoint
07/09/2005 11:58 <DIR> VOYAGE~1 VoyagerModemDrivers
29/12/2006 20:54 <DIR> VOYAGE~2 VoyagerTest
30/03/2007 23:24 <DIR> WINDOW~4 Windows Defender
02/02/2007 22:09 <DIR> WINDOW~1 Windows Media Player
30/09/2004 05:28 <DIR> WINDOW~2 Windows NT
30/09/2004 05:28 <DIR> xerox
25/09/2007 19:31 <DIR> XOFTSP~1 XoftSpySE
27/12/2005 14:50 <DIR> Yahoo!
0 File(s) 0 bytes
78 Dir(s) 41,031,909,376 bytes free
Volume in drive C has no label.
Volume Serial Number is 0C66-4644

Directory of C:\WINDOWS\Tasks

05/08/2007 21:51 284 APPLES~1.JOB AppleSoftwareUpdate.job
25/09/2007 21:30 414 SYMANT~1.JOB Symantec NetDetect.job
2 File(s) 698 bytes
0 Dir(s) 41,031,913,472 bytes free
 
     
   
Gender PostTime:12/16/2008 8:39:25 PM Point:0 | Floor# 5
Lv is 1
portrait
Level:
1
Professional point:
0
Experience:
0
Thread:
110
Post:
419
Total online time:
0M
Joined date:
4/19/2007 8:55:00 AM
Last Visit:
4/19/2007 8:54:40 AM
Status:
Offline
Quote:
Originally Posted by Jasmine14
Just to let you know I got a pop up that says:

iexplore.exe application error.

The instruction at "0x7e19af3" referenced memory at "0x7dc48950". The memory could not be "read". Click on OK to terminate the program.

Does this have anything to do with what we're doing right now?
Was that while installing ERUNT?
 
     
   
Gender PostTime:12/16/2008 9:04:21 PM Point:0 | Floor# 6
Lv is 1
portrait
Level:
1
Professional point:
0
Experience:
2
Thread:
130
Post:
439
Total online time:
2M
Joined date:
4/19/2007 8:51:00 AM
Last Visit:
5/21/2007 7:02:58 AM
Status:
Offline
There is a storm in the area. Will be back later.
 
     
   
Gender PostTime:12/16/2008 10:38:18 PM Point:0 | Floor# 7
Lv is 1
portrait
Level:
1
Professional point:
0
Experience:
26
Thread:
136
Post:
449
Total online time:
26M
Joined date:
4/19/2007 8:52:00 AM
Last Visit:
4/20/2007 6:47:58 AM
Status:
Offline
OK the control panel is back but when I try to remove My Web search (smiley central) through the add/remove programs it comes up with a window that says:

RUNDLL

Error loading C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsbar.dll
Specified module could not be found.
 
     
   
Gender PostTime:12/16/2008 10:59:06 PM Point:0 | Floor# 8
Lv is 1
portrait
Level:
1
Professional point:
78
Experience:
9
Thread:
286
Post:
947
Total online time:
9M
Joined date:
4/29/2007 12:17:00 AM
Last Visit:
12/16/2008 11:26:07 PM
Status:
Offline
Just to let you know I got a pop up that says:

iexplore.exe application error.

The instruction at "0x7e19af3" referenced memory at "0x7dc48950". The memory could not be "read". Click on OK to terminate the program.

Does this have anything to do with what we're doing right now?
 
     
   
Gender PostTime:12/16/2008 11:07:44 PM Point:0 | Floor# 9
Lv is 1
portrait
Level:
1
Professional point:
3
Experience:
8
Thread:
285
Post:
966
Total online time:
8M
Joined date:
4/28/2007 11:55:00 PM
Last Visit:
12/16/2008 11:44:45 PM
Status:
Offline
Quote:
Originally Posted by Jasmine14
OK the control panel is back but when I try to remove My Web search (smiley central) through the add/remove programs it comes up with a window that says:

RUNDLL

Error loading C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsbar.dll
Specified module could not be found.
That is due to an entry in the registry. Post a fresh Hijackthis log.
 
     
   
Gender PostTime:12/16/2008 11:27:07 PM Point:0 | Floor# 10
Lv is 1
portrait
Level:
1
Professional point:
94
Experience:
11
Thread:
294
Post:
1009
Total online time:
11M
Joined date:
4/29/2007 2:38:00 AM
Last Visit:
12/17/2008 12:46:59 AM
Status:
Offline
Hello,

When installing ERUNT it says:

setup will create the program's shortcuts in the following start menu folder. To continue press next. If you would like a different folder click browse.

What should I type here? It won't let me no to it like in number 2 of your instructions.
 
     
1 2

Sorry, you are not login, click here to login

 

About us | Advertise | Contact us | Partner | Bug Report|Suggesting box|Donation
Home | Forum | Affiliate program| Remote help | Setting | Search | Document | Help | Download|Message

 

Start new topicAdvanced search