Greetings,
Before you post in this forum,please read and follow the instructions in this post: Guidelines for Posting in This Forum
Failure to follow these instructions will only result in delays of the cleaning and removal process.
If you ran other AntiVirus and/or AntiSpyware programs and have the logs available, please post them as well.
Our goal is to help you clean your PC and restore it to pre-infection condition wherever possible.
Thank You
![]() ![]() |
Apr 7 2008, 07:06 PM
Post
#1
|
|
|
New Member Group: Member Posts: 4 Joined: 7-April 08 Member No.: 24140 |
Hello,
I have a major problem. All of a sudden most of the applications in windows are useless. Each time I want to open it I get the error "classs not registered" And upon starting I also get the error "THis application failed to start because wininet.dll was not found..... I already tried the most logic solutions. Like re-installing the wininet.dll, but I can't get paste or unzip it in the system32 folder. acces denied or something? I don't know. I followed the steps here downloading adaware and spybot but they both freeze upon installing, giving the following errors "Runtime error (at 10:1166) Acces denie violation at adress 000000000000. I also get an error with spybot. hijackthis succeeded, you find the log below By the way I have Vista Ultimate I hope you find this problem thanks thomas Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:59:19, on 7/04/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16609) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\rundll32.exe C:\Program Files\Panda Security\Panda Antivirus 2008\ApVxdWin.exe C:\Windows\System32\rundll32.exe C:\Program Files\CyberLink\Shared files\brs.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe C:\Windows\system32\conime.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\wermgr.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\SearchFilterHost.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll O13 - Gopher Prefix: O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrvx86.exe O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe O23 - Service: Panda PSK service (PskSvcRetail) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PskSvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- End of file - 8401 bytes |
|
|
|
Apr 8 2008, 01:47 AM
Post
#2
|
|
![]() Master of Disaster Recovery Group: General Admin Posts: 15448 Joined: 24-March 03 From: Albuquerque, NM Member No.: 2879 |
Your log is clean.
THe error you describe is most likely beyond hte scope of this forum but we can at least try to see if the wininet error can be cleared. Its needs to be registered as well as being physically there. Try this... Start -> run, then enter regsvr32 %windows%/system32/wininet.dll -------------------- Happiness ain't a thing in itself--it's only a contrast with something that ain't pleasant. Mark Twain |
|
|
|
Apr 8 2008, 03:43 PM
Post
#3
|
|
|
New Member Group: Member Posts: 4 Joined: 7-April 08 Member No.: 24140 |
I tried your suggestion
But I received the following error message THe module regsvr32 %windows%/system32/wininet.dll failed to load. MAke sure the binary is stored at the specific path or debug it to check for problems with the binary or dependent.dll files I also want to ad that before my PC started malfunctioning i noticed the computer was working slower. And last week I used smitfraudfix because I had malware that I could not remove. "unidentified trojan....computer is infected... Hope you still have something up your sleeve? Already thanks for the qiuck reply Thomas |
|
|
|
Apr 8 2008, 07:52 PM
Post
#4
|
|
![]() Master of Disaster Recovery Group: General Admin Posts: 15448 Joined: 24-March 03 From: Albuquerque, NM Member No.: 2879 |
Try the command again, but this time as:
regsvr32 C:\WIndows\system32\wininet.dll And let me know if it works. If not, most likely the best path is to flatten and repave (Reformat and re-install) I'll check to see if I can find any other similar issue and if so, what was done. -------------------- Happiness ain't a thing in itself--it's only a contrast with something that ain't pleasant. Mark Twain |
|
|
|
Apr 8 2008, 09:03 PM
Post
#5
|
|
![]() Master of Disaster Recovery Group: General Admin Posts: 15448 Joined: 24-March 03 From: Albuquerque, NM Member No.: 2879 |
When did you install Panda? Did the problem start about the time you installed or updated Panda?
Where did you get the Panda installer? (from Panda web site, other major download site, warez site?) -------------------- Happiness ain't a thing in itself--it's only a contrast with something that ain't pleasant. Mark Twain |
|
|
|
Apr 8 2008, 09:18 PM
Post
#6
|
|
|
New Member Group: Member Posts: 4 Joined: 7-April 08 Member No.: 24140 |
The problems indeed started with an error from Panda.
By the way the new run command gave the same error, so it seems a reformat is the obvious choice. I will wait a couple of days for a miracle. Maybe a light at the end of the tunnel ? I found someone with the same problem on a Belgian (i'm also Belgian) website, ands strangely enough around the same time this error occured the link below is to that site http://www.pc-helpforum.be/f167/vista-wininet-dll-prob-9195/ If you want to pull the plug on this problem, can you give me a tip to retrieve the vital documents. Because I can't get in to the explorer, I started, through use of notepad, recovering one document at a time on my external hard drive. Again much thanks for the help. greetings THomas |
|
|
|
Apr 8 2008, 11:37 PM
Post
#7
|
|
![]() Master of Disaster Recovery Group: General Admin Posts: 15448 Joined: 24-March 03 From: Albuquerque, NM Member No.: 2879 |
THere is another user here with the same problem.
Uninstall Panda using Add/Remove Programs, then reboot and let me know what is happening. Panda is the common link in both logs. If Panda is indeed the problem, then check with their website to see if others are reporting the same issue. IBe sure you install an AV if you hold off on Panda. AVG, Avast, and Avira all offer good, free AV that will do in the interim. If you have trouble uninstalling Panda 2008, check this link: http://www.pandasecurity.com/homeusers/sup...&idIdioma=2 -------------------- Happiness ain't a thing in itself--it's only a contrast with something that ain't pleasant. Mark Twain |
|
|
|
Apr 10 2008, 07:45 AM
Post
#8
|
|
|
New Member Group: Member Posts: 4 Joined: 7-April 08 Member No.: 24140 |
Hello Lophatphuud,
The problem is solved, thanks to u. Muchos gracias I did skip one step in your advice. Instead of uninstalling Panda first, i went straight to the website of panda and there they gave a solution to the problem they have caused with one of their latest updates. If you are interested this is the link http://www.pandasoftware.be/nl/thuisgebrui...servicesupport/ De Panda Antivirus software kan op Windows Vista machines het bestand 'wininet.dll' identificeren als een bestand waar een virus in zit. Als gevolg hiervan wordt het bestand verwijderd. Dit kan voorkomen op Windows Vista computer die nog geen Service Pack 1 geïnstalleerd hebben. Inmiddels wordt het bestand niet meer als geïnfecteerd bestand geïdentificeerd. Om het probleem op te lossen dient u het 'wininet.dll' bestand terug te plaatsen, dit kan onder andere op volgende wijze: Start uw computer op in veilige modus met netwerkmogelijkheden. Om dit te doen drukt u tijdens het opstarten een aantal keer op de F8 toets. Kies in het menu voor de veilige modus met netwerkmogelijkheden. Eens de pc gestart is klikt u op het Start icoon en typt daar 'cmd.exe', druk dan op enter. In de opdrachtprompt geeft u dan het volgende in: 'ftp 62.99.76.3' en druk dan op enter Typ nu 'panda' gevolgd door een enter Type nogmaals 'panda' wederom gevolgd door een enter Eens u zich in de ftp map bevindt, typt u 'bin' gevolgd door enter Op de volgende regel typt u dan 'mget solution.exe' en druk enter. Als om bevestiging wordt gevraagd drukt u 'y' (of 'J') in. Geef nu 'quit' in en druk op enter. Typ nu 'solution.exe' en druk op enter. Once again thanks, if I ever come across you I'll buy you a beer (or 2) Greetings Thomas |
|
|
|
Apr 11 2008, 12:43 AM
Post
#9
|
|
![]() Master of Disaster Recovery Group: General Admin Posts: 15448 Joined: 24-March 03 From: Albuquerque, NM Member No.: 2879 |
Thanks.
Glad we got it solved. -------------------- Happiness ain't a thing in itself--it's only a contrast with something that ain't pleasant. Mark Twain |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 3rd September 2010 - 12:40 AM |