Jump to content

startup error


PS3

Recommended Posts

gday everyone,

 

every time when i startup my computer and its finished loading to the windows screen i have this error message coming up. i have no idea what it means and i have run all the spyware and virus programs but that doesnt seem to work.

 

what shall i do?

 

i have attached a picture to what it says.

 

thanks

post-5180-1153270401_thumb.jpg

post-5180-1153270401_thumb.jpg

Link to comment
Share on other sites

ah, i see that now.

theres no way of telling really, id say if you dont figure it out, post a log.

 

EDIT: and let them know of your problem. they may be able to find the program thats doing this to you.

Link to comment
Share on other sites

thanks for that.

 

is this what you wanted?

 

Logfile of HijackThis v1.99.1

Scan saved at 6:03:20 PM, on 19/07/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5450.0004)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\CNNIC\Cdn\cdnup.exe

C:\Program Files\baigoo\bgoomain.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\Google Talk\googletalk.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\NTService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\iTunes\iTunes.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Bruiza\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.177a.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.177a.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.177a.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.msn.com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.acer.com.au/

O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll

O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - (no file)

O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe

O4 - HKLM\..\Run: [bgoomain.exe] C:\Program Files\baigoo\bgoomain.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart

O4 - HKCU\..\Run: [caishowmanage] C:\Program Files\CaiShow Tech\CaiShow\UpdateManager.EXE

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O8 - Extra context menu item: >>???ŷ???<< - res://C:\Program Files\MMSAssist\Mmsass~1.dll/mms.htm

O8 - Extra context menu item: Access Internet Keyword - C:\Program Files\CNNIC\Cdn\cnnic.htm

O8 - Extra context menu item: Add to QQ Customized Panel - C:\Program Files\Tencent\QQ\AddPanel.htm

O8 - Extra context menu item: Add to QQ Emoticons - C:\Program Files\Tencent\QQ\AddEmotion.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Send picture by MMS - C:\Program Files\Tencent\QQ\SendMMS.htm

O8 - Extra context menu item: Send the Picture by QQ MMS - C:\Program Files\Tencent\QQ\SendMMS.htm

O9 - Extra button: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll

O9 - Extra 'Tools' menuitem: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll

O11 - Options group: [CDNCLIENT] Chinese Navigation

O17 - HKLM\System\CCS\Services\Tcpip\..\{0ED293F3-3B6C-4BB1-98F3-9FEC9BEAA9A9}: NameServer = 203.194.56.150 203.194.27.57

O17 - HKLM\System\CS3\Services\Tcpip\..\{0ED293F3-3B6C-4BB1-98F3-9FEC9BEAA9A9}: NameServer = 203.194.56.150 203.194.27.57

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Sample NT Service (SampleService) - Ceramiche Ariostea - C:\WINDOWS\NTService.exe

O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe

Link to comment
Share on other sites

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.177a.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.177a.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.177a.com

 

I'm far from an expert on HJT logs but that appears to be at least part of the problem. 177a is a browser hijacker. You should run a full virus scan and dowload and run Ewido (ideally run both in safe mode with system restore turned off) see if they remove it. Then post a new HJT log in the Hijack This thread HERE

 

I'll let the more knowledgeable members analyze the log a little more fully.

Link to comment
Share on other sites

You should hit CTRL+ALT+DEL (Task Manager) and see if it's listed under the Applications tab. (Is that Skype in the tray? That's my first guess.)

Click here if CCleaner Issues are re-appearing

 

DjLizard.net

DjLizard.net wiki

Dial-a-fix

Dial-a-fix tips

DjLizard.net software support forum

 

Do you live in Bradenton, Sarasota, Tampa, or St. Petersburg, Florida? Visit Digital Doctors where I work :)

Link to comment
Share on other sites

yeah, thanks for that.

 

i do have the AdAware SE Personal. and i also have Adware 6. Adware 6 was just on the desktop.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.