Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: HELP!Dont know what it is!!

  1. #1
    Join Date
    Sep 2007
    Posts
    6

    HELP!Dont know what it is!!

    every time i login to my computer this ACProtect hing pops up!

    this is what it looks like: http://img292.imageshack.us/img292/7816/helpyl0.jpg

    it pops back up about 4 times.

    (i also have been experiencing freezing issues around the same time ACProtect started poping up)

    any wAY I FOLLOWED guide lines and i scanned my pc with the suggested scanners and they all detect nothing.




    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 1220 PM 9/23/2007

    + Scan result:



    Nothing found.



    ::Report end
    ---------------
    Attached Files Attached Files

  2. #2
    Join Date
    Sep 2007
    Posts
    6
    scan 2 days prior. i removedthese things i think

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 8:51:51 PM 9/21/2007

    + Scan result:



    C:\WINDOWS\system32\gtdownls_95.ocx -> Adware.Gdown : No action taken.
    C:\WINDOWS\Downloaded Program Files\gsda.dll -> Not-A-Virus.Downloader.Win32.SpyGame : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@bet.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@brightcove.112. 2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@buycom.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@nielsen.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@bet.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@brightcove.112. 2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@kelleybluebook. 112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@waterfrontmedia .112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@getmusicfree.aa value[2].txt -> TrackingCookie.Aavalue : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@4.adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@ads.adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@3.adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@ads.adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@ads.addynamix[2].txt -> TrackingCookie.Addynamix : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@rotator.adjuggl er[1].txt -> TrackingCookie.Adjuggler : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@cc.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@citi.bridgetrac k[2].txt -> TrackingCookie.Bridgetrack : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@www.burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@com[1].txt -> TrackingCookie.Com : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@searchportal.in formation[1].txt -> TrackingCookie.Information : No action taken.
    C:\Documents and Settings\Debra\Cookies\debra@sec1.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@sales.liveperso n[1].txt -> TrackingCookie.Liveperson : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@realmedia[2].txt -> TrackingCookie.Realmedia : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@realmedia[1].txt -> TrackingCookie.Realmedia : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@revenue[2].txt -> TrackingCookie.Revenue : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@revsci[2].txt -> TrackingCookie.Revsci : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@ads.revsci[2].txt -> TrackingCookie.Revsci : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@revsci[2].txt -> TrackingCookie.Revsci : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@statcounter[1].txt -> TrackingCookie.Statcounter : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@anad.tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@anat.tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@login.tracking1 01[2].txt -> TrackingCookie.Tracking101 : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@reduxads.valuea d[1].txt -> TrackingCookie.Valuead : No action taken.
    C:\Documents and Settings\Debra\Cookies\debra@m.webtrends[1].txt -> TrackingCookie.Webtrends : No action taken.
    C:\Documents and Settings\Guest\Cookies\guest@m.webtrends[1].txt -> TrackingCookie.Webtrends : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@m.webtrends[2].txt -> TrackingCookie.Webtrends : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@m.webtrends[1].txt -> TrackingCookie.Webtrends : No action taken.
    C:\Documents and Settings\SHARONDA\Cookies\sharonda@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
    C:\Documents and Settings\Johnavon\Cookies\johnavon@zedo[1].txt -> TrackingCookie.Zedo : No action taken.


    ::Report end

  3. #3
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Sorry we seem to have missed this.
    Have you looked in Add/Remove for this program ACProtect? If you find it, uninstall it.
    Give me a bit and I will go through your log.

  4. #4
    Join Date
    Sep 2007
    Posts
    6
    Quote Originally Posted by jholland1964 View Post
    Sorry we seem to have missed this.
    Have you looked in Add/Remove for this program ACProtect? If you find it, uninstall it.
    Give me a bit and I will go through your log.
    its doesnt come up in add/remove preograms.

    my mom thinks i put a virus on the computer and shes mad at me........im trying to solve the problem because she's going to make me buy her a new computer......

    I appreciate the help,take all the time u need.

  5. #5
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Nothing in the scan by AVG was removed. Note this at the end of each and every line;
    No action taken.
    You are not going to have to buy a new computer, but you are going to have to do a scan with HiJackThis and save the log and post it here so I can better see what is going on. You can find the link for HiJackThis here
    Follow the instructions for install EXACTLY. Run the scan and post back here with the log.
    Do this ASAP so that we can get rid of whatever infections are on the computer and before they cause anymore infections.

  6. #6
    Join Date
    Aug 2006
    Location
    255.255.255.666
    Posts
    2,056
    There is quite possibly a Explorer Shell Hook residing in the following folder:

    C:\Windows\System32\win32GI\svchost.exe
    If that is indeed the case, that will have to be killed and removed first.

    See, if the win32GI folder can be deleted at all. Try CleanupXP+ in Safe Mode with Command Prompt, it should do the trick.

    Edit by Judy;
    ~TL forgot his link to CleanupXP+
    Scroll down to post #4 on the link above to download and read instructions on how to use this program.

  7. #7
    Join Date
    Sep 2007
    Posts
    6
    Quote Originally Posted by TurcoLoco View Post
    There is quite possibly a Explorer Shell Hook residing in the following folder:

    If that is indeed the case, that will have to be killed and removed first.

    See, if the win32GI folder can be deleted at all. Try CleanupXP+ in Safe Mode with Command Prompt, it should do the trick.

    Edit by Judy;
    ~TL forgot his link to CleanupXP+
    Scroll down to post #4 on the link above to download and read instructions on how to use this program.
    i booted in safe mode with command promt.

    entered "Desktop\CleanupXP.exe"

    it ran.

    was that all i suppose to do?

    ACProtect is still on my pc...HELP!!!!mom is getting at me.


    sorry for late responses. please and thank u!

  8. #8
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok then follow my instructions on post #5. Go to the link I gave there follow the instructions and THEN do a scan with HiJackThis and post that log here....there is no "magic bullet" here, you have to do all the steps. We don't even know what is causing the trouble exactly because you won't follow the steps as given.

  9. #9
    Join Date
    Sep 2007
    Posts
    6
    Logfile of HijackThis v1.99.1
    Scan saved at 4:41:07 PM, on 10/4/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\HP Mouse\panel.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\ALCMTR.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\WINDOWS\AGRSMMSG.exe
    c:\windows\system\hpsysdrv.exe
    C:\Documents and Settings\Johnavon\Desktop\New Folder (2)\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: (no name) - >û - (no file)
    O2 - BHO: (no name) - rsion - (no file)
    O2 - BHO: (no name) - `>û - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - à=û - (no file)
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [BJCFD] "C:\Program Files\BroadJump\Client Foundation\CFD.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: NewShortcut1.lnk = ?
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca...C_2.1.2.76.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} - http://www.linksysfix.com/netcheck/5...l/gtdownls.cab
    O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/W...gPublisher.exe
    O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://livenj02.custhelp.com/8102-b4.../java/RntX.cab
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = usps.gov
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = usps.gov
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    Attached Files Attached Files

  10. #10
    Join Date
    Aug 2006
    Location
    255.255.255.666
    Posts
    2,056
    Quote Originally Posted by jesusplays View Post
    i booted in safe mode with command promt.

    entered "Desktop\CleanupXP.exe"

    it ran.

    was that all i suppose to do?

    ACProtect is still on my pc...HELP!!!!mom is getting at me.


    sorry for late responses. please and thank u!
    From your reply I can tell you did NOT follow the steps as mentioned on the post but that is fine, I rather have Judy work on this with you in the traditional manner before resorting to unorthodox tools like CleanupXP+ and AnalyzerXP.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •