pnolan cannot access system restore

edited February 2006 in Spyware & Virus Removal
Hello,

I don't know if this is spyware or what.
I cannot watch videos or animated cards.

and more importantly, I cannot get to sytem restore. when I click on it, the page is blank.

I did run spybot and ad-aware, deleted 54 critical objects.

still have the problem.

Please tell me what i can do to fix this.

below is a HJT log

thank you

pnolan

Logfile of HijackThis v1.99.0
Scan saved at 9:59:06 PM, on 10/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ME\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.excite.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.excite.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.excite.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.excite.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121295658015
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Trend Micro Central Control Component - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

Comments

  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited November 2005
    Hi!

    If you still require assistance for this problem please post a new hijackthis log.
  • edited November 2005
    Hi!

    If you still require assistance for this problem please post a new hijackthis log.


    ok, thanks Sam,

    here is the new log:


    Logfile of HijackThis v1.99.0
    Scan saved at 11:30:16 PM, on 11/13/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\System32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\DIGStream\digstream.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Yahoo!\Messenger\YPager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\ME\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.excite.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.excite.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.excite.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.excite.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121295658015
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Trend Micro Central Control Component - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Trend Micro Real-time Service - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
  • zero-counterzero-counter Linux Lubber San Antonio Member
    edited November 2005
    pnolan wrote:
    Hello,

    I don't know if this is spyware or what.
    I cannot watch videos or animated cards.

    and more importantly, I cannot get to sytem restore. when I click on it, the page is blank.
    Your log looks good. Ensure that you have admin priveleges. As far as the videos and animations, your codecs may be blown away, file association with a program has been reset, or a combination of both. What file types are in question specifically?
    If need be, you can download a codec pack like this one below to give you access to your media once again:
    http://www.free-codecs.com/download/K_Lite_Codec_Pack.htm
    When you install it, use the option so that you can view all types. Then after installing, see if the videos are working.

    As far as system restore is concerned here is some advice I can offer.
    This would be the first and most relevant step I am advocating, followed by others, in order of relevance...

    KB Article 313853
    SYMPTOMS
    When you run the System Restore tool on a Windows XP-based computer, the calendar on the left side of the "Choose a Restore Point" window is not displayed.

    CAUSE
    This behavior can occur if the file association for Hypertext Markup Language (HTML) component (.htc) files is not in the registry.

    RESOLUTION
    WARNING: If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.

    To resolve this behavior, verify that the following keys are in the registry. If one of the registry keys is not present, create the key, and then add the values that belong to the corresponding key:
    HKEY_CLASSES_ROOT\.htc
    Value name: Content Type
    Value data: text/x-component

    HKEY_LOCAL_MACHINE\Software\Classes\.htc
    Value name: Content Type
    Value data: text/x-component

    HKEY_CLASSES_ROOT\MIME\Database\Content Type\text/x-component
    Value name: CLSID
    Value data: {3050f4f8-98b5-11cf-bb82-00aa00bdce0b}

    Create a second entry with the following values:
    Value name: Extension
    Value data: .htc

    HKEY_CLASSES_ROOT\CLSID\{3050f4f8-98b5-11cf-bb82-00aa00bdce0b}
    Value name ="Microsoft Html Component"

    HKEY_CLASSES_ROOT\CLSID\{3050f4f8-98b5-11cf-bb82-00aa00bdce0b}\InProcServer32
    Value name: Default
    Value data: "C:\Windows\System32\Mshtml.dll"

    Create a second entry with the following values:
    Value name: "ThreadingModel"
    Value data: "Apartment"
    NOTE: This procedure assumes that Windows XP is installed in the C:\Windows folder. Make sure to change C:\Windows to the appropriate <windows_folder> if Windows XP is installed in a different location.

    To merge all of the information at one time, you can copy and paste the following text into a text editor, such as Notepad, and then save it as a .reg file.

    NOTE: You must copy all of the following text to ensure that this procedure works as expected.

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\.htc]
    "Content Type"="text/x-component"
    @=&quot;htcfile"

    [HKEY_CLASSES_ROOT\MIME\Database\Content Type\text/x-component]
    "CLSID"="{3050f4f8-98b5-11cf-bb82-00aa00bdce0b}"
    "Extension"=".htc"

    [HKEY_CLASSES_ROOT\CLSID\{3050f4f8-98b5-11cf-bb82-00aa00bdce0b}]
    @=&quot;Microsoft Html Component"
    [HKEY_CLASSES_ROOT\CLSID\{3050f4f8-98b5-11cf-bb82-00aa00bdce0b}\InProcServer32]
    @=&quot;C:\\WINDOWS\\System32\\mshtml.dll"
    "ThreadingModel"="Apartment""

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htc]
    "Content Type"="text/x-component"
    @=&quot;htcfile"


    After you finish the preceding steps, you can use the System Restore tool. However, when you use the System Restore tool to restore an earlier configuration, the registry fix is removed from the Windows registry. To make sure that the problem does not occur again after you restore the earlier configuration, repeat the preceding steps to fix the System Restore tool, create a new System Restore point, and label it to indicate that it contains the System Restore fix. After you do this, you can use the System Restore tool at any time to restore the System Restore point that contains the fix without damaging the System Restore tool.

    Make sure that the System Restore service is running. To do this, use one of the following methods:
    Look in Control Panel. To do this, follow these steps:
    1. Click Start, click Run, and then type compmgmt.msc in the Open box.
    2. Expand Services, and then click System Restore Services.

    Open a command prompt window. To do this, follow these steps:
    1. Click Start, click Run, and then type CMD.
    2. Press ENTER, and then type Net Start at the command prompt to make sure that the System Restore service is up and is running.

    View the event logs to investigate System Restore service errors. To do this, follow these steps:
    1. Click Start, click Control Panel, and then click Performance and Maintenance.
    2. Click Administrative Tools, click Computer Management, double-click Event Viewer, and then click System.
    3. Click the Source tab to sort by name, and then look for "sr" or "srservice." Double-click each of these services, and then evaluate the event description for any indication of the cause of the problem.

    Additionally, you can try entering safemode and accessing system restore that way. If you still cannot access system restore, then disable it. Then unhide protected operating system files and give yourself full permissions to the system volume information folder on the root drive. Delete the folder labeled _restore*. Then remove your user from the permissions list for the System Volume Information and rehide the folder. Reboot the computer and then re-enable system restore. Try entering system restore at that time.
    Then reboot the system and run the HJT again. If the problem persists, let us know.
  • edited November 2005
    Dear Zero Counter ,

    thank you very much for all of your efforts to help.
    it turns out it was a windows update I had installed.

    if I remember correctly, it was this one KB896688

    I removed it, and system restore is once again accessible.

    and videos and flash animation can once again be seen.

    now I occasionally get a prompt to install winfixer.
    if I click cancel or the corner x, it still tries to install it.

    have you heard of this one before?
    any way to stop that from happening?

    it seems like a windows product would allow you the option of installing or not. and if you said no, leave it at that. this acts like some kinda bug.



    thanks again

    Paul

    p.s. did I originally post this correctly? I was a little confused on how to start a thread for a new problem.
  • TroganTrogan London, UK
    edited November 2005
    Sorry to jump in!


    You posted correctly :)


    Download SpywareBlaster 3.4. It stops all Active X's from getting into your computer.

    http://short-media.com/download.php?dc=69


    See if that helps :)
  • edited February 2006
    thanks Trojan,

    I just got back here and saw your note.
    I already had 3.4 but
    I downloaded version 3.5.1 and set it up.
    hopefully that will help stop some of the garbage.

    thanks again
  • edited February 2006
    how do I close a thread?
  • skywalker45skywalker45 Bloomington, IN. USA
    edited February 2006
    Are you finished with this thread? If so I'll close it for you.
  • edited February 2006
    yes i am finished with this thread.

    is there not a way for me to close a thread I opened?

    thanks

    pnolan
  • TroganTrogan London, UK
    edited February 2006
    Yes, there is a way you can close your own thread.

    Under Additional Options, look for something that says "Close Thread"...

    I'l let you close this thread ;)
This discussion has been closed.