I may have a real bad promblem
« on: July 10, 2009, 08:01:34 AM »
earlier I was on check mail and look for sites for  NTLDR Missing or Corrupted to try to fix my husband old computer. I found this site Fixing NTLDR Missing or Corrupted. now I need to fine that on a microsoft site. my husband got on for a short while and it worked fine. I got back on open my opera browser. I needed to get up to do some thing right quick. when I came back it was like a new pattern wallpaper. it was kind of a basic designed with a lot of littler square that were a golden in color. i had to turn it off the hard way. i forgot to tell you there was no icons on the desk a little bit
i turn it back on it was a blank screen with little marks and spaces. marks like   ll lloll lll i turn it off waited longer and now it is working. but when i was doing my mail you could see most of the email but could not see the words like reply send delete. they were not there. i did a HJ i am sending it right now. it says something about a worm. please help.
thanks Sharon


Re: I may have a real bad promblem
« Reply #1 on: July 10, 2009, 08:02:07 AM »
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:40:58 PM, on 7/9/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\TechTracker\VersionTracker Pro\VersionTrackerPro.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =;;;;;localhost;*;*;*;*;*;;*;*;*;*;;;*;*;<local>;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VersionTrackerPro.lnk = ?
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) -
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c9cb4226c992a0) (gupdate1c9cb4226c992a0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - (no file)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

End of file - 8465 bytes


Re: I may have a real bad promblem
« Reply #2 on: July 10, 2009, 07:43:14 PM »
 :)  Hi Sharon :

 Is that a HijackThis log from your husband's computer ? It looks like the Log
 from your computer that you Posted a few days ago, where I and Others
 commented on !?

 When it comes to your husband's computer, I feel you should seek the help of
 experinced, certified, Volunteer "Microsoft Most Valuable Professional(s)"
 found on the Support Forums at . They are best qualified
 to solve that "NTLDR Missing or Corrupted " . They have experience and
 training to use highly specialized "Tools" and programs to get your husband's
 computer functioning properly .


Re: I may have a real bad promblem
« Reply #3 on: July 10, 2009, 09:31:44 PM »
     I did not mean to say it was from his computer. I am sorry I did not make my sell clear. it was from my computer and I am looikg for that driver to put on his computer till I can get that driver on a disk and try to install in to his. you cannot get even close to the desktop.   I can only get a black screen saying the driving is missing. my sister and nephew were here for a couple of days and was told to fine the driver on a microsoft site. save it to a disk. then try to install in his. I have found a microsoft site that I am waiting for a reply to try in help me fix his

on my computer looking for information on how to fix his that is what happen to mine. mine is a HP windows vista. does that explane it better.thank you Sharon


Re: I may have a real bad promblem
« Reply #4 on: July 10, 2009, 09:40:15 PM »
I will try to be more clear from now on. I dont have a lot of schooling and I {des-less-ic} and cant spell. the site you sent I will look at too but weill wait to see what


Re: I may have a real bad promblem
« Reply #5 on: July 10, 2009, 09:43:06 PM »
I will try to be more clear from now on. I dont have a lot of schooling and I {des-less-ic} and cant spell. the site you sent I will look at too but weil wait to see what reply I get from this site
thanks Sharon


Re: I may have a real bad promblem
« Reply #6 on: July 11, 2009, 02:41:12 AM »

i am kind of scared because I don't know if I should be or not becauseof the worm that was mention in the hj i am waiting for a reply's to see if i need to delete that worm that it mentions in hj.

I will try to be more clear from now on. I dont have a lot of schooling and I {des-less-ic} and cant spell. the site you sent I will look at too but weill wait to see what


Re: I may have a real bad promblem
« Reply #7 on: July 11, 2009, 05:04:00 PM »
when I re-red your last post right now. I did not catch that you said it look like my HJ from the time before. it was not. it was sent that day just before I posted it. this is the line that scare me. I have not heard back from the forum you sent me to who you thought could help me better. the one line from the HJ that scare me is this one

O2 - BHO: IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
thanks Sharon


Re: I may have a real bad promblem
« Reply #8 on: July 11, 2009, 05:54:08 PM »

O2 - BHO: IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
thanks Sharon

Hi, this might be related to the avg linkscanner program.Have you used this program before?
hope this helps


Re: I may have a real bad promblem
« Reply #9 on: July 11, 2009, 06:19:34 PM »
you could not have wrote at a better time because I should not have any Avg or Norton at all on this computer. I just got threw writing A new question.the question is go here and you can read it.  Norton was on when the computer came home i unstalled it put the paid version of avg in and later unstalled that and put avast in. here is where to go. should i delete this threw HJ
thanks Sharon


Re: I may have a real bad promblem
« Reply #10 on: July 12, 2009, 08:40:04 AM »
I just thought you all might like to go what it happen, soo I am setting you what I wrote at bleepingcomputer.  also the other part of the question on a different forum. i thing there 2 different post here and one on another forum. maybe i will get a reply from some one now thanks Sharon

[font="Arial Black"][/font]
I am not sure if I am supposed to post here because I am posting another log for you to help me with, or if I should start another question. 1st I will send this and then the log.
this is a line that has me worried but my avast scanner has not found a virus, but as you see the word worm so I am not sure. then I no these two can go.

O2 - BHO: IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
then these two I know can go. i am not concern about them just the one that Say's worm.

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = and this one too. right after I send this I will copy paste the hole log next.;*;;;*;

I need to tell you some more now 1st. this computer came with a Norton and I don't like Norton and well never use it again. I unstalled it and put in an paid version of AVG. less then a year I unstalled AVG. i don't think I ever had it installed right for many reason. I wand up with virus from time to time and it did not help because I thought I was helping the problems of the computer to being fixed but I was causing more. what I thought was helping turn out to be rogue. this site help me out the last time. the computer was nice and clean, but I not sure now. can you help me again? right after i send this i well copy past the HJ log then send it.
thanks Sharon sham1313
I think I know why a lot of times what was causing it back then. after I unstalled 1st the Norton scanner I did not know I should have used the removal tool. only after the AVG was installed and unstalled i did the removal tool for both of them. not sure how many times. then I use them both. the norton and the avg. I was sure it was all gone no More Norton and no more avg, and till I saw this. I check the security and saw these words. AVG firewall on and windows firewall off.
AVG is not suppose to be on this computer at all
hope you can help. thanks Sharon


Re: I may have a real bad promblem
« Reply #11 on: July 12, 2009, 11:54:03 AM »

Hi Sharon,

WormRadar is not a worm but it is part of a program called LinkScanner. Is that program name familiar to you?
If it is from AVG, as someone else mentioned, then it should have been removed when you removed AVG. Have you used the AVG removal tool before? Uninstalling AVG is not enough. The removal tool must be used.

An analysis of your HJT log log shows the following minor problems :

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
Unnecessary (deactivated) entry that can be fixed.  This entry is related to Yahoo Companion.

O2 - BHO: IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
Unnecessary (deactivated) entry that can be fixed. This entry is related to LinkScanner.
Perhaps this was successfully uninstalled but the registry entry was left behind.

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
Unnecessary (deactivated) entry that can be fixed. Related to Windows Live Messenger.

O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - (no file)
To be fixed if the entry 'HP Smart Select ' is unknown.
Unnecessary (deactivated) entry that can be fixed.

Overview of running tasks :

System task   
Desktop Window Manager

System task   
Task Scheduler Engine

System task   
Microsoft Windows Explorer

Hewlett Packard Software Update Scheduler

Avast AntiVirus

Sun Java Update Scheduler

HP QuickPlay

Apple Itunes

Microsoft Media Center Tray Icon


Windows Media Player Network Sharing Service Confi

Hewlett Packard Imaging

System task   
Microsoft Media Center State Aggregator Service

Unknown task            (VersionTracker Pro alerts you when new updates for software and drivers are available.
Unknown task   

System task   
Task Scheduler Engine

Secunia Personal Software Inspector

System task   
Microsoft Synchronization Manager

Opera Browser

HP Imaging



Microsoft Internet Explorer

Microsoft Internet Explorer

Google Toolbar

Merijn Hijackthis



Re: I may have a real bad promblem
« Reply #12 on: July 12, 2009, 07:15:58 PM »

there were 2 replys i have not red it because this is alread typed i am gong to send any way

       WormRadar link scanner no I have not this is the 1st time I  have seen the two words together. I have only seen the word linkscanner. I always think of URL when I see link, but I do not know the program linkscanner.  it says scanner so it musk scan some thing, but what I  do not know or why. next question is the one that needs deleted or fixed you mark them all and click fix it to do both in HJ right?

        O9 - Extra button: HP Smart Select  now I know that one is about printer. a while back I did a recovery manager so the printer had to be re-installed. for a while it was not all the way installed but it is now.

        I guess I have not wrote this down for this post that I have started. I  thought I had. nortin was on this computer when  we 1st got it. I do not like and will not even try nortin again. first thing I did was unstalled it. not at that time I did not know I had to use a removal tool. with out knowing that I installed the paid version of AVG. I never did get it installed right for more reason then one. before I installed avast I found out I was to use a removal tool for both of then so 1st I use the norton removal tool and then the AVG. on the AVG it said you may need to do it more then. by the time I follow all then instrution I was given and and used both removal many many times. I was told I should have to only use it once but when I followed up with what other said to do i was told to do next AVG would show up in a HJ or some thing els. and would use the removal tool again and sense AVG was showing up I used the norton removal tool too.

     I think I have answered what you have ask and believe I told you what els to catch you up. I need to write a little bit more because I think I should say one more think and i cannot recall right now.  i do now.  what it was this.    I was looking for a      driver for my husband old toshiba to try and fix it. I need to get up and do some thing. when I came back to this computer the screen look like a different basic wallpaper with a lot of small goldish tan square's with no icons at all on the desktop. I tried ctrl alt delete but after many Try's task manager did not come up. tapping esc did nothing so i try to turn it off the hard. at first it did not work but later it did. then I waited and turn back on, this and saw some thing like this  ll lloll lll i. then I turn off and waited at least 30 mins turn it on and it started. I thing that happen because AVG firewall is on and windows. using the removal tool did not do it back then when i did use the removal tool many many many times and it is still there I hope there  is a easy way to get rid of AVG all together and double check on making sure nortin is completely gone as well.

         I just remember I wrote some thing like that on a different forum because who was helping me here said me a URL and said I should ask the question at this URL.               
     I think that is all i hope you can understand what I just wrote
thanks big time. Sharon


Your Husband's computer
« Reply #13 on: July 12, 2009, 07:36:00 PM »
 :)  Hi Sharon :

 This Post by me is ONLY regarding your husband's computer . There has been a
 recent reply to your Post on the forums by Maurice Nagger . To do
 what he asked on your husband's computer, you need to do the following :

 1. Download OTL by OldTimer, saving it to your husband's desktop:

Close all open windows on the Task Bar. Click the OTL icon (for Vista, right click the icon and Run as Administrator) to start the program.
In the lower right corner of the Top Panel, checkmark "LOP Check" and checkmark "Purity Check".
Now click Run Scan at Top left and let the program run uninterrupted. The scan may take 5-10 minutes.
Do not TOUCH your keyboard until the scan completes!
It will produce two (2) logs on your desktop, one will pop up called OTL.txt; the other will be named Extras.txt.
Exit Notepad. Remember where you've saved these 2 files as we will need both of them shortly!
Exit OTL by clicking the X at top right.

2. Download Security Check by screen317 and SAVE it to your husband's Desktop:

Double-click on SecurityCheck.exe and follow the on-screen instructions inside the black box.
A Notepad document named checkup.txt should then open automatically; close Notepad & saving the file to your desktop. We will need this log, too.
« Last Edit: July 12, 2009, 07:38:29 PM by Spiritsongs »


Re: I may have a real bad promblem
« Reply #14 on: July 12, 2009, 10:37:41 PM »
i can not get to my husband desktop that is why i need to fine the driver on a microsoft site save it to a disk and put the disk in my husband computer and install it. the last 2 guestion i have ask was want to save some thing on a disk and i don't mine trying to learn different ways. it is is so much easier if i can save to a disk. i just cannot fine a microsoft site with that driver. there our other sites that have it but i need a microsoft site on my husband computer when you turn it on you see a black screen with some words and it says it is missing that driver. i think 4 times it will say click a certain key and a few words comes up. 4 times then it will say it is missing that file again. i am going to have to stoping soon or i will really start making a lot of mistake

yes i red the other reply already and i am not sure tottally sure the nest post i put there is what they ask for but i should know this evening or in the morning

here a little of a copy paste i think will be the right place to under stand

        I guess I have not wrote this down for this post that I have started. I  thought I had. nortin was on this computer when  we 1st got it. I do not like and will not even try nortin again. first thing I did was unstalled it. not at that time I did not know I had to use a removal tool. with out knowing that I installed the paid viersion of AVG. I never did get it installed right for more reason then one. before I installed avast I found out I was to use a removal tool for both of then so 1st I use the norton removal tool and then the AVG. on the AVG it said you may need to do it more then. by the time I follow all then instrution I was givin and and used both removal many many times. I was told I should have to only use it once but when I followed up with what other said to do i was told to do next AVG would show up in a HJ or some thing els. and would use the removal tool again and sense AVG was showing up I used the norton removal tool too.