Windows XP Applications keep crashing

Joined
Jan 18, 2004
Messages
3
Reaction score
0
I have formatted and reloaded XP several times. My PC works fine for awhile then certain applications crash. Norton comes up and then closes. I run msconfig and that closes. I go into the control panel and click on add/remove programs and that crashes. I am at a loss. I have run my virus scan and nothing appears. I tried the one that was suggested in another forum problem and that doesn't pick up anything. Also, when in Outlook it will stop getting email from the server. HELP.:crazy:
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,739
Reaction score
1,204
I'm afaid we need a bit more info on your system?
 
Joined
Jan 18, 2004
Messages
3
Reaction score
0
I have a rebuild. It is Pentium III. New 80GB Western Digital EIDE Hard Drive. Only 192 MB Memory. I am not sure what is going on. It only seems to be when I try to do windows applications and the Norton. Everything else seem to work fine.
 
Joined
Jan 18, 2004
Messages
3
Reaction score
0
I ran the highjack software and here is my log. Do you see anything funny???

Logfile of HijackThis v1.97.7
Scan saved at 4:30:30 PM, on 1/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Verizon Online\VisualIPInsight\IPClient.exe
C:\Program Files\Verizon Online\VisualIPInsight\IPMon32.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\ipstack.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\Program Files\Verizon Online\VisualIPInsight\IPClient.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Rachel Bellis\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.asp?region=east&bw=dsl&cd=4.0&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredir.asp?region=east&bw=dsl&cd=4.0&bm=ho_home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPMon32.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [IP Stack] ipstack.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\RunServices: [IP Stack] ipstack.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38004.5642824074
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE16EA69-32C1-410B-9B8F-B83AF05D5281}: NameServer = 151.197.0.38 151.197.0.39
 
Joined
Dec 7, 2003
Messages
1,281
Reaction score
0
Rachael,

Format and reinstall windows and do your self a favour don't install system works, see how it runs without.

J
 
Joined
Jan 21, 2004
Messages
2
Reaction score
0
I came across this today on a windows 2000 machine and had to format it. The ipstack.exe is an unknown virus and is what is closing down Norton. It also closes regedit after a couple of seconds. If you disable the ipstack.exe in the services then you can get antivirus to work but as yet it will not detect it as a virus. If you forward ipstack.exe to your antivirus company then they will investigate it and write a pattern file to detect it.
Felix
 
Joined
Jan 21, 2004
Messages
1
Reaction score
0
How to clean

We discovered this virus a couple days ago and have sent it to Trend micro so they will include it in their pattern. We have developed steps to clean it manually tho.

you need to remove the files :

%windows%\%system32%\ipstack.exe
%windows%\%system32%\sys78.exe
%windows%\%system32%\sys78.exe.poly

also remove the 2 entries in the registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ipstack.exe

and

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sys78.exe


this virus appears to use a similar exploit to Blaster and Nachi. It sends out a tremendous loads of traffic on ports 139/tcp and 445/tcp. It also will shutdown most known antivirus and firewall programs as well as close msconfig, and regedit. I highly reccomend running all of the microsoft security updates after the virus is removed.

Hope this was helpful
 
Joined
Jan 22, 2004
Messages
1
Reaction score
0
i am having the same problem, i was able to find and remove the ipstack file, but there were no sys78.exe files...there is something else in the registry that keeps bringing ipstack.exe back though
 
Joined
Jan 21, 2004
Messages
2
Reaction score
0
I didn't have any sys78.exe files either. I couldn't see anything else that looked out of place on the system. I didn't delete the ipstack.exe, I disabled it from starting. Go to start then run then type services.msc then click OK. Double click the ipstack service and in the startup options, select disabled. Then click OK, then close the services control and shutdown the computer.This wont remove the virus or take the load of the CPU but on restart you should be able to get programs running.
Felix
 
Joined
Jan 22, 2004
Messages
1
Reaction score
0
I had a similar problem on an xp pro machine. Just about every application that was helpful closed after about a second. I was able to get task manager open long enuf to shutdown ipstack.exe but it just opened up again every time I did. I then restarted in safe mode (ipstack.exe ran in safe mode also) searched for files with ipstack in the name and found 2 1 in the windows directory called ipstack.exe and one in the system32 directory called something different (shoulda wrote it down DOH!!) but ipstack was in the name. I had to boot from a cd and delete ipstack.exe from a cmd prompt. I then restarted in safe mode did a regedit and searched for ipstack and found at least a dozen entries. I deleted them all and everthing works great now. I wrote to Norton and here was there response.


"We would like to inform you that the ipstack.exe is an unknown virus and is what is closing down the programs in your system. It also closes regedit after a couple of seconds. If you disable the ipstack.exe in the services then you can get antivirus to work but as yet it will not detect it as a virus."

Hope this helps
 
Joined
Jan 25, 2004
Messages
1
Reaction score
0
I have got IpStack.exe on my computer just after an update from XP home to XP pro and with my ADSL line connected at the same time (sigh !!!).
It is rather easy to remove it because in my case Ipstack dont run in safe mode !
So after booting in safe mode (F8) go to cmd line and delete it easily from the windows\system32 directory.
Also clean entries in the registy.
Everything is OK for me now.

Nota: I discovered a splendid alternative software to the windows task manager, whose name is PROCEXP (it's free !)and who allows to FREEZE any launched task. It worked greatly with the unkillable IPSTACK and confirmed that it was the virus (everything was OK after freezing !)

What a loss of time with these unknown viruses!!
 

gac

Joined
Jan 26, 2004
Messages
1
Reaction score
0
My neighbor had this issue. I went to Symantec and did the online scan because his Norton AV wouldn't run. W32.HLLW.Gaobot is the virus that it showed ipstack.exe to be infected with. The removal tool can be obtained at the link below. Run in safe mode and turn off system restore before starting.

I'm not sure why a search on ipstack.exe at symantec didn't show up any thing.

http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.removal.tool.html
 
Joined
Jan 30, 2004
Messages
1
Reaction score
0
I don't think this virus is the W32.HLLW.Gaobot, I downloaded the tool and it scanned my system and said it found nothing, even though I have the ipstack.exe file on my PC. I had to manually remove it as the above instructions. Does anyone know when the Antivirus companys are going to release a update for this??
 
Joined
Feb 3, 2004
Messages
2
Reaction score
0
I came across this virus on Windows XP pro a few days ago. I had the same problem with everything shutting down. After looking at what was running in my Task manager I noticed 'Ipstack'. I also ran Spybot's tools tab and looked under system startup and noticed 'Ipstack' loading up at startup. Upon removing it & restarting, 'Ipstack' kept running. I found that I couldn't end the process for it in the Task manager either. Eventually I found two files in the system 32 folder affiliated with this program : Ipstack & Ipstack.poly. I was only able to delete the Ipstack.poly.
I couldn't delete the other at all, so I RENAMED it, restarted the PC & went back and deleted it, THIS WORKED. (by renaming it, the startup files couldn't find their host program & therefore couldn't run the virus program allowing it to be deleted.)
Also there is a file in the prefetch folder, which can be found by searching for 'Ipstack and deleted
I also found the sys78.exe file also booting up at startup, not sure whether this is having any effect on the PC as yet, but I will be monitoring it. This possibly is affiliated with 'Ipstack'.

I have ran this file through an antivirus program called 'VET', which recognised it as a virus called : Win32.Agobot.GH
I found that the date this file was created was on the 18th Jan 2004, which is also the date that 'FED UP' first informed us of his dilemma.
I think that this virus might be getting passed around with P2P file share programs, such as Kazaa.

I hope this might help.
 
Joined
Feb 17, 2004
Messages
2
Reaction score
0
Dunno about files sharing

hello all, im just try to tell you what i have seen of the sys78.exe & IPstack virus/worm. I dont think it comes from p2p netoworks because my windows server 2000 just picked it up because i did not have the time to install av software. but i know that, that machine or the other two computers on the network do not have p2p applications. but i could be wrong because it sounds like it could be spred lots of ways.
 
Joined
Feb 17, 2004
Messages
2
Reaction score
0
after removal

i dont knowif any one ells had this problem but after the renaming of ipstack.exe and sys78.exe and sys78.exe.ploy. i cam across other one that semed to be taking up CPU time about every 10 sec it would spike. it turned outtobe two files called msnmsgr.exe and msnmsgr.exe.ploy i dont know if these have any relation ship to the sys78 problem but i thought i would post what i saw happening
 
Joined
Mar 20, 2004
Messages
2
Reaction score
0
I've got the same problem, applications keep crashing......i've reformated serval times.....no luck...i've searched fpr ipstack.exe but found nothing, also nothing in the reg.

What could the problem be?

PC: AMD 2200+, 256mb ram, windows xp
 
Joined
Mar 25, 2004
Messages
1
Reaction score
0
my regedit and flash 7 program won't stay open for more than 3 seconds before it closes. I couldn't find what everyone thought the problem was so here's my saved log. hope someone can help me out with this one.

Logfile of HijackThis v1.97.7
Scan saved at 3:52:50 AM, on 3/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\services.exe
C:\Program Files\Common Files\stardock\TrayServer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\WINDOWS\System32\SahAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\hphmon04.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\ClockSync\Sync.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Real\RealDownload\RealDownload.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=3
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=105833
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.cox.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=3
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\services.exe
F1 - win.ini: load=C:\WINDOWS\services.exe
F1 - win.ini: run=C:\WINDOWS\services.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\services.exe
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh309190.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {3D14D07F-D9D7-4E2F-B3A0-CC4156094744} - C:\WINDOWS\System32\dlanim.dll
O2 - BHO: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~2\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS\System32\btiein.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\btlink.dll
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SuperBar - {12294195-11B2-4B1C-A995-066D0BF360C7} - C:\Program Files\SuperBar\SuperBar.Dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [1A:Stardock TrayMonitor] "C:\Program Files\Common Files\stardock\TrayServer.exe"
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SBHC] C:\Program Files\SuperBar\sbhc.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [sysu] "C:\progra~1\ddm\sysu.exe"
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAgent.exe
O4 - HKLM\..\Run: [Services Controller] C:\WINDOWS\services.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - HKLM\..\RunServices: [Services Controller] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe /q
O4 - HKCU\..\Run: [Services Controller] C:\WINDOWS\services.exe
O4 - HKCU\..\RunServices: [Services Controller] C:\WINDOWS\services.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh309190.dll/201
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: JT's Blocks - http://download.games.yahoo.com/games/clients/y/blt1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Dots - http://download.games.yahoo.com/games/clients/y/dtt1_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://yog55.games.scd.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt1_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt0_x.cab
O16 - DPF: {00000000-CDDC-0704-0B53-2C8830E9FAEC} (IELoaderCtl Class) - http://install.global-netcom.de/ieloader.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50038/QDow.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1408.g.akamai.net/7/1408/99...W/win/061-0848.20031022.TtzS4/iTunesSetup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/v3/download/pdpplugin5094_hd3ptdmgainads.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.madonion.com/global/msc34.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} (MoneyTree Dialer) - http://cdn.climaxbucks.com/internet-optimizer/080703/UniDistIOcrack.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4301/mcfscan.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {F08555B0-9CC3-11D2-AA8E-000000000000} - http://d.crackedearth.com/cglbar.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - http://activex.microsoft.com/controls/iptdweb/ikcntrls.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://216.65.38.226/crack.CAB
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.paltalk.com/download/0.x/regdload.cab
O16 - DPF: {FC87A650-207D-4392-A6A1-82ADBC56FA64} (MultiDist) - http://xbs.climaxbucks.com/internet-optimizer/080703/MultiDist.CAB
 
Joined
Oct 4, 2004
Messages
1
Reaction score
0
fedup said:
I have formatted and reloaded XP several times. My PC works fine for awhile then certain applications crash. Norton comes up and then closes. I run msconfig and that closes. I go into the control panel and click on add/remove programs and that crashes. I am at a loss. I have run my virus scan and nothing appears. I tried the one that was suggested in another forum problem and that doesn't pick up anything. Also, when in Outlook it will stop getting email from the server. HELP.:crazy:
join the club I am on broadband basis, told it's my phone line.
John Wood-cowling.
 

Alf

Yank Upstart
Joined
Aug 30, 2004
Messages
3,193
Reaction score
6
Hey ogie, that sure be alot of typin you did!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top