Jump to content

Error Box


Recommended Posts

ok...recently i've been getting these error boxes that are like 1inch by 1inch and the only option i have is to click ok...it usually comes up about 3 times a day and says things like PID: 0 ,[system Process] tyoe: 0...just to list a few, and when the box pops up the error comes up with like 50 boxes right after each other with different errors i guess....i just hold esc to clear them all...any ideas on how to fix this or whats causing it to do it....thanks in advance  :mad2:

Link to post
Share on other sites

Logfile of HijackThis v1.99.1

Scan saved at 1:08:58 AM, on 8/1/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:














C:Program FilesCommon FilesSymantec SharedccProxy.exe

C:Program FilesCommon FilesSymantec SharedccSetMgr.exe

C:Program FilesSymantec Client SecuritySymantec AntiVirusDefWatch.exe

C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE

C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe


C:Program FilesSymantec Client SecuritySymantec AntiVirusRtvscan.exe

C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe

C:Program FilesSymantec Client SecuritySymantec Client FirewallSymSPort.exe




C:Program FilesCommon Filesslmssslmss.exe

C:Program FilesNetropaOSD.exe

C:Program FilesCommon FilesSymantec SharedccApp.exe






C:Program FilesBrotherControlCenter2brctrcen.exe


C:Program FilesJavajre1.5.0_02binjusched.exe


C:Program FilesGoogleGmail Notifiergnotify.exe

C:Program FilesRoxioEasy CD Creator 6DragToDiscDrgToDsc.exe

C:Program FilesRoxioEasy CD Creator 6AudioCentralRxMon.exe


C:program fileslg usb drive2.9lg usb.exe



C:Program FilesNikonNkView6NkvMon.exe

C:Program FilesRoxioEasy CD Creator 6AudioCentralPlaylist.exe

C:Program FilesAIMaim.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:Documents and SettingsOwnerLocal SettingsTemphijackthisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://start.Earthlink.net/

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =

R3 - URLSearchHook: UB Class - {00000000-15D9-4736-AB29-131578A45F2B} - C:WINDOWSsystem32wsrchc3.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)


O4 - HKLM..Run: [igfxTray] C:WINDOWSSystem32igfxtray.exe

O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSSystem32hkcmd.exe

O4 - HKLM..Run: [slmss] C:Program FilesCommon Filesslmssslmss.exe

O4 - HKLM..Run: [fash] C:WINDOWSfash.exe

O4 - HKLM..Run: [aqadcup] C:WINDOWSaqadcup.exe

O4 - HKLM..Run: [QSXS] C:WINDOWSEvftac.exe

O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"

O4 - HKLM..Run: [vptray] C:PROGRA~1SYMANT~2SYMANT~2VPTray.exe

O4 - HKLM..Run: [uwzztnl] C:WINDOWSOzcu.exe

O4 - HKLM..Run: [WildTangent CDA] RUNDLL32.exe "C:Program FilesWildTangentAppsCDAcdaEngine0400.dll",cdaEngineMain

O4 - HKLM..Run: [Jawa322] C:WINDOWSjawa32.exe

O4 - HKLM..Run: [Jwlf] C:WINDOWSuckvjq.exe

O4 - HKLM..Run: [wmv] C:WINDOWSsystem32winmonv.exe

O4 - HKLM..Run: [setDefPrt] C:Program FilesBrotherBrmfl04aBrStDvPt.exe

O4 - HKLM..Run: [ControlCenter2.0] C:Program FilesBrotherControlCenter2brctrcen.exe /autorun

O4 - HKLM..Run: [Windows Svchost Authority] slsass.exe

O4 - HKLM..Run: [sunJavaUpdateSched] C:Program FilesJavajre1.5.0_02binjusched.exe

O4 - HKLM..Run: [Rzvdnu] C:WINDOWSsvchost.exe

O4 - HKLM..Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:Program FilesGoogleGmail Notifiergnotify.exe

O4 - HKLM..Run: [Jawa32awa32] C:WINDOWSjawa32.exe

O4 - HKLM..Run: [userFaultCheck] %systemroot%system32dumprep 0 -u

O4 - HKLM..Run: [RoxioEngineUtility] "C:Program FilesCommon FilesRoxio SharedSystemEngUtil.exe"

O4 - HKLM..Run: [RoxioDragToDisc] "C:Program FilesRoxioEasy CD Creator 6DragToDiscDrgToDsc.exe"

O4 - HKLM..Run: [RoxioAudioCentral] "C:Program FilesRoxioEasy CD Creator 6AudioCentralRxMon.exe"

O4 - HKLM..Run: [iisvers] C:WINDOWSiisvers.exe

O4 - HKLM..Run: [LG US] c:program fileslg usb drive2.9lg usb.exe sys_auto_run C:Program FilesLG USB Drive2.9

O4 - HKLM..Run: [wsrv32] C:WINDOWSwsrv32.exe

O4 - HKLM..RunServices: [Windows Svchost Authority] slsass.exe

O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [Jawa32] C:WINDOWSjawa32.exe

O4 - HKCU..Run: [Yahoo! Pager] C:Program FilesYahoo!Messengerypager.exe -quiet

O4 - HKCU..Run: [Jawa322] C:WINDOWSjawa32.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE

O4 - Global Startup: NkvMon.exe.lnk = C:Program FilesNikonNkView6NkvMon.exe

O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present

O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:program filesgoogleGoogleToolbar1.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Transfer with Image Converter 2 - C:Program FilesSonyImage Converter 2menu.htm

O8 - Extra context menu item: Translate into English - res://c:program filesgoogleGoogleToolbar1.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_02binnpjpi150_02.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_02binnpjpi150_02.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:Program FilesAIMaim.exe

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:Program FilesPartyPokerPartyPoker.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:Program FilesPartyPokerPartyPoker.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O15 - Trusted Zone: *.af.mil

O15 - Trusted Zone: *.musicmatch.com

O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab

O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - http://www.2nd-thought.com/files/install011.exe

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab

O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab

O20 - Winlogon Notify: igfxcui - C:WINDOWSSYSTEM32igfxsrvc.dll

O20 - Winlogon Notify: NavLogon - C:WINDOWSSystem32NavLogon.dll

O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:WINDOWSSYSTEM32Brmfrmps.exe" -service (file missing)

O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:WINDOWSsystem32brsvc01a.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe

O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccProxy.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:Program FilesSymantec Client SecuritySymantec AntiVirusDefWatch.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE

O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:WINDOWSNhksrv.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:Program FilesSymantec Client SecuritySymantec AntiVirusSavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:Program FilesSymantec Client SecuritySymantec AntiVirusRtvscan.exe

O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:Program FilesSymantec Client SecuritySymantec Client FirewallSymSPort.exe

i think thats what you needed....but i have no idea what to delete and such....

edit: actually looking through them i see some of the errors that pop up like slass.exe...

Link to post
Share on other sites

I've reviewed your hijackthis log.. First of all, please download and do a spyware scan on your pc using Ad-aware. It is going to find some things.. I believe the following files are spyware and if ad-aware or AVG doesn't detect them, please remove them by scanning again with hijackthis, clicking on the box beside them and clicking on the fix button afterwards:



Link to post
Share on other sites

You may also find that you'll have to boot in safe mode and manually delete that file. Possible anyway.

That was the only way I could get rid of a similar file on my niece's computer.

That's true.. However, Ad-aware deletes files that cannot be deleted during current scan on next system start-up.. I believe a screen like disk check (blue screen) comes up before the welcome to windows screen and the files get deleted, or something similar to this.. If ad-aware cannot delete the file, safe mode is the only other option :)

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Create New...