|
Question : run a dll as an app keeps appearing when I want to do ANY window operation!
|
|
I have a customers computer that is causing me great grief. First of all, it had the begal.n virus (which I was able to get rid of using the program from symantec as well as ran a check with a bootable floppy from AVG to be sure it was clean). It also wont let me get into msconfig nor anything in the control panel so I can try and clean up the rest of this machine. I believe it is infected with a lot of spyware, and when I try to run adaware, spybot or any other program I get 'cant run a dll as an app error'. I thought I'd try going into msconfig, but I get the dll error there. I even tried this in safe mode. Help please! I also tried creating a new user profile in safe mode and get the dll error. Im lost here. Thanks in advance!
|
|
Answer : run a dll as an app keeps appearing when I want to do ANY window operation!
|
|
Turn off ur System restore and fix the following entries......
======================================================== R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://easy-search.biz R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://easy-search.biz R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.webroot.com/php/disp0201.php?pc=64150&rc=1&mo=2&oc=26&ps=R R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank O2 - BHO: (no name) - {20239CAD-9608-49E2-8E0D-DAAD7E58BF82} - C:\WINDOWS\System32\lgckec.dll O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\Documents and Settings\owner_2\Application Data\winit\winit.dll O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\SYSTEM32\XTAWJ.EXE O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\sdkqh32.dll,Install O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\jopnyc.exe O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\gxwnbht.exe O4 - HKLM\..\Run: [DjrL.exe] C:\documents and settings\owner_2\local settings\temp\DjrL.exe O4 - HKLM\..\Run: [B4693369] C:\WINDOWS\System32\fjqzezyj.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [intlgntc] C:\WINDOWS\System32\intlgntc.exe O4 - HKLM\..\Run: [Microsoft Update Machine] javaw.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\RunServices: [sounoft] sounoft.exe O4 - HKLM\..\RunServices: [soundcontrl] soundcontrl.exe O4 - HKLM\..\RunServices: [8F7BBF0F] C:\WINDOWS\System32\fjqzezyj.exe O4 - HKLM\..\RunServices: [Microsoft Update Machine] javaw.exe O4 - HKCU\..\Run: [winupd.exe] C:\WINDOWS\System32\winupd.exe O4 - HKCU\..\Run: [Plug and Play] C:\WINDOWS\wininet32.exe O4 - HKCU\..\Run: [Remote Packet Capture Protocol v.2.0] C:\WINDOWS\runwin32.exe O4 - Startup: AutoPlay.exe O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0080AD08A326} - http://activex.liveupdate.com/controls/cres.cab O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//paxan/main.chm::/load.exe O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://E:\content\include\XPPatchInstaller.CAB O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partners/aolim/install.cab O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50151/QDow_AS2.cab O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - ms-its:mhtml:file://c:\nosuch.mht!http://www.n28.net/n001/mt/mt.chm::/MediaTicketsInstaller.cab =======================================================================
|
|
|
|