Computing.Net > Forums > Windows 95/98 > info32. is missing at boot

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

info32. is missing at boot

Reply to Message Icon

Name: eallace
Date: October 29, 2003 at 04:22:03 Pacific
OS: Win98
CPU/Ram: Intel/ 64MB ram
Comment:

Logfile of HijackThis v1.97.3
Scan saved at 8:40:30 PM, on 28/10/03
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\WINSERVICES.exe
C:\WINDOWS\SYSTEM\MOUSECNTL.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\FAXTALK COMMUNICATOR\FTCTRL32.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\COMMONNAME\TOOLBAR\WINNET.exe
C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.exe
C:\WINDOWS\STARTER.exe
C:\PROGRAM FILES\DOWNLOADWARE\DW.exe
C:\PROGRAM FILES\SAVE\SAVE.exe
C:\WINDOWS\SYSTEM\MSINSTALL\DLU32\DLUCA\DLUCA.exe
C:\PROGRAM FILES\DELFIN\PROMULGATE\PGMONITR.exe
C:\PROGRAM FILES\INTERNET OPTIMIZER\OPTIMIZE.exe
C:\WINDOWS\SYSTEM\MSCNT.exe
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.exe
C:\PROGRAM FILES\PRIMESOFT\SAFESEARCH\SAFESEARCH.exe
C:\PROGRAM FILES\KAZAA\KAZAA.exe
C:\PROGRAM FILES\WEBDIALER\OD-STND499.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.exe
C:\PROGRAM FILES\WINZIP\WZQKPICK.exe
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.exe
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.exe
C:\PROGRAM FILES\PRECISIONTIME\PRECISIONTIME.exe
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.exe
C:\PROGRAM FILES\FAXTALK COMMUNICATOR\FAPIEXE.exe
C:\PROGRAM FILES\COMMON FILES\GMT\GMT.exe
C:\WINDOWS\SYSTEM\TCPSVS32.exe
C:\WINDOWS\TEMP\EACDOWNLOAD\DEFSCAN_INSTALL.exe
C:\PROGRAM FILES\COMMON FILES\EACCELERATION\EANTHTUTOR\EANTHTUTOR.exe
C:\PROGRAM FILES\WINZIP\WINZIP32.exe
C:\PROGRAM FILES\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://acc.count-all.com/--/?seojz (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://acc.count-all.com/---/?seojz (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://acc.count-all.com/--/?seojz (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://acc.count-all.com/-/?seojz (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://acc.count-all.com/--/?seojz (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://acc.count-all.com/---/?seojz (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://acc.count-all.com/--/?seojz (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://acc.count-all.com/-/?seojz about:blank
(obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.commonname.com/english/toolbar/sidebar.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://acc.count-all.com/--/?seojz (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://acc.count-all.com/--/?seojz (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://acc.count-all.com/--/?seojz (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://acc.count-all.com/---/?seojz (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,Search =
http://acc.count-all.com/--/?seojz (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
http://acc.count-all.com/--/?seojz (obfuscated)
R3 - URLSearchHook: (no name) - _{D6DFF6D8-B94B-4720-B730-1C38C7065C3B} -
(no file)
R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} -
  C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL (file missing)
F1 - win.ini: run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSINFO\info32.exe
c:\windows\system\mousecntl.exe
O1 - Hosts: 3510794918 auto.search.msn.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} -
  C:\WINDOWS\DOWNLOADED PROGRAM FILES\YCOMP5_1_6_0.DLL (file missing)
O2 - BHO: (no name) - {760A9DDE-1433-4A7C-8189-D6735BB5D3DD} -
  C:\WINDOWS\TEMP\EZSEARCH.DLL (file missing)
O2 - BHO: (no name) - {D14641FA-445B-448E-9994-209F7AF15641} -    (file
missing)
O2 - BHO: (no name) - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} -   C:\PROGRAM
FILES\MEDIALOADS ENHANCED\ME1.DLL (file missing)
O2 - BHO: (no name) - {6ACD11BD-4CA0-4283-A8D8-872B9BA289B6} -   C:\PROGRAM
FILES\ACCELERATION SOFTWARE\STOPSIGN\WEBCBROWSE0.DLL (file missing)
O2 - BHO: (no name) - {665ACD90-4541-4836-9FE4-062386BB8F05} -   C:\PROGRAM
FILES\FLT\FLT.DLL (file missing)
O2 - BHO: (no name) - {2662BDD7-05D6-408F-B241-FF98FACE6054} -   C:\PROGRAM
FILES\XUPITER\XTUPDATE.DLL (file missing)
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -   C:\Program
Files\NewDotNet\newdotnet4_80.dll (file missing)
O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} -
  C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL (file missing)
O2 - BHO: (no name) - {0A5CF411-F0BF-4AF8-A2A4-8233F3109BED} -
  C:\PROGRA~1\SEARCH~1\STOOLBAR.DLL (file missing)
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} -   C:\PROGRAM
FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL (file missing)
O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} -   C:\PROGRAM
FILES\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL (file missing)
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} -
  C:\WINDOWS\NEM214.DLL (file missing)
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} -
  C:\WINDOWS\WSEM216.DLL (file missing)
O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} -   C:\PROGRAM
FILES\COMMONNAME\TOOLBAR\CNBABE.DLL (file missing)
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000001} -
C:\WINDOWS\SYSTEM\SAFESEARCH.DLL
O3 - Toolbar: ez Search Bar - {CCE83E45-30B2-4BAE-B1F5-25D128D27A43} -
C:\WINDOWS\TEMP\EZSEARCH.DLL
O3 - Toolbar: Xupiter - {57E69D5A-6539-4d7d-9637-775DE8A385B4} - C:\PROGRAM
FILES\XUPITER\XUPITERTOOLBAR.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Search Toolbar - {6A85D97D-665D-4825-8341-9501AD9F56A3} -
C:\PROGRA~1\SEARCH~1\STOOLBAR.DLL
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} -
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O3 - Toolbar: Yahoo! Compagnon - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\WINDOWS\DOWNLOADED PROGRAM FILES\YCOMP5_1_6_0.DLL
O3 - Toolbar: SafeSearch - {00000000-0000-0000-0000-000000000001} -
C:\WINDOWS\SYSTEM\SAFESEARCH.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [VoodooBanshee] rundll32.exe
3DfxVBps.dll,BansheeLoadSettings
O4 - HKLM\..\Run: [3Cmlink] C:\WINDOWS\SYSTEM\3cmlnkW.exe
O4 - HKLM\..\Run: [CallControl 4.5] C:\PROGRAM FILES\FAXTALK
COMMUNICATOR\FTCtrl32.exe /autoload
O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.exe"
O4 - HKLM\..\Run: [WebScan] C:\PROGRAM FILES\ACCELERATION
SOFTWARE\ANTI-VIRUS\DEFSCANGUI.exe -k
O4 - HKLM\..\Run: [WinServices] C:\WINDOWS\SYSTEM\WinServices.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee
VirusScan\alogserv.exe
O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\TOOLBAR\winnet.exe
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program
Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\SAVE\Save.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\DEFALERT.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.exe
/LOADQUIET
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Norton
AntiVirus\POPROXY.exe
O4 - HKLM\..\Run: [dluca] c:\windows\system\msinstall\dlu32\dluca\dluca.exe
/noconnect
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [PromulGate] "C:\Program
Files\DelFin\PromulGate\PgMonitr.exe"
O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.exe
O4 - HKLM\..\Run: [Mscnt] c:\windows\system\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet
Optimizer\optimize.exe"
O4 - HKLM\..\Run: [SafeSearch] c:\program
files\primesoft\safesearch\safesearch.exe
O4 - HKLM\..\Run: [xxxAction_ca] c:\program
files\comsoft\dialers\xxxaction_ca\xxxaction_ca.exe /noconnect
O4 - HKLM\..\Run: [Tapicfg.exe] \tapicfg.exe
O4 - HKLM\..\Run: [DEFSCAN_INSTALL.EXE]
C:\WINDOWS\TEMP\EACDOWNLOAD\DEFSCAN_INSTALL.exe -k
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common
Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [WinServices] C:\WINDOWS\SYSTEM\WinServices.exe
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program
Files\McAfee\McAfee VirusScan\AVSYNMGR.exe
O4 - HKLM\..\RunServices: [Mousecntl] c:\windows\system\mousecntl.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe"
/background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
-quiet
O4 - HKCU\..\Run: [od-stnd499] c:\program files\Webdialer\od-stnd499.exe -m
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft
Office\Office\OSA.exe
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft
Office\Office\MSOFFICE.exe
O4 - Startup: PrecisionTime.lnk = C:\Program
Files\PrecisionTime\PrecisionTime.exe
O4 - Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Startup: NRunOnce.lnk = C:\Program Files\Norton AntiVirus\NRunOnce.exe
O8 - Extra context menu item: Bookmark This Page - C:\Program
Files\CommonName\Toolbar\createbookmark.htm
O8 - Extra context menu item: Add A Page Note - C:\Program
Files\CommonName\Toolbar\createnote.htm
O8 - Extra context menu item: Email This Link - C:\Program
Files\CommonName\Toolbar\emaillink.htm
O8 - Extra context menu item: Search using CommonName - C:\Program
Files\CommonName\Toolbar\navigate.htm
O8 - Extra context menu item: &Add animation to IncrediMail Style Box -
C:\PROGRA~1\INCRED~1\bin\WebMenuImg.htm
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra 'Tools' menuitem: Block This Page (HKLM)
O9 - Extra button: PrivateNet Bar (HKLM)
O9 - Extra 'Tools' menuitem: PrivateNet Bar (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O11 - Options group: [CommonName] CommonName
O12 - Plugin for .pdf: C:\Program
Files\Sympatico\Communicator\Program\PLUGINS\nppdf32.dll
O12 - Plugin for .ofb: C:\PROGRA~1\INTERN~1\PLUGINS\NPONFLOW.DLL
O12 - Plugin for .qt: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} -
http://64.157.10.150/diallerfiles/030369.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products
Installer Start) -
http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Compagnon) -
http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} -
http://akamai.downloadv3.com/binaries/IA/ia.cab
O16 - DPF: {94742E3F-D9A1-4780-9A87-2FFA43655DA2} -
http://akamai.downloadv3.com/binaries/DialHTML/EGDHTML_pack.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments
Control) - http://lw15fd.law15.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} (Loader Class) -
http://start.online-dialer.com/MaConnect.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = bebn.com
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = bebn.com
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
204.101.110.20,204.101.110.21
O19 - User stylesheet: C:\WINDOWS\Web\win.def
O19 - User stylesheet: C:\WINDOWS\default.css (HKLM)



Sponsored Link
Ads by Google

Response Number 1
Name: Tufenuf
Date: October 29, 2003 at 04:50:53 Pacific
Reply:

eallace, Download, install, read the directions, then update & run Ad-aware & Spybot Search & Destroy which are Free and can be downloaded at the links below.

Ad-aware

Spybot Search & Destroy

You may also want to download & run the CWSredder file at the link below.

CWShredder

If you still have a problem after running these programs go the the Security and Virus Board and post a new HijackThis log there.

Tufenuf


0

Response Number 2
Name: mesich
Date: October 29, 2003 at 05:27:29 Pacific
Reply:

Hi Eallace, Tufenuf, hello everyone,

That is quite some list. I would do as Tufenuf stated and run the above 3 programs to remove the numerous spyware/adware on the computer.

I would also run an updated antivirus program as it is also infected with the Yaha.k virus.

A good online scanner is Housecall

Best Regards,
Mesich


0

Response Number 3
Name: Vollen
Date: November 14, 2003 at 09:59:14 Pacific
Reply:

My god you are infected. Don't install the regular KAZAA program! Don't you realize that it infects you with spyware, adware, and malware? Don't you realize there is a CLEAN version of that, but that the regular Kazaa program from DOWNLOAD.COM or KAZAA.COM infects you? That is the WORST program next to the crappy MORPHEUS that also infects you with parasite-ware and browser hijackers. NEVER install those apps, learn to get a clean p2p program like WINMX or eMULE or shareaza or Klite that does not infect you with scum, but is clean. No wonder you are having problems. The one named OPTIMIZE.exe in your list is ALSO a parasite piece of infection. It is known as the DyFuCa parasite. NEW.NET hijacker is infesting your system and that came from you putting KAZAA on your machine. So is that EASY SEARCH crap. And don't think your Norton antivirus is protecting you, it lets it pass like a hard-up doorman lets sluts into a girl-starved danceclub. Antivirus programs do not detect or catch these types of programs at all.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Microsoft emails Unknown Adapter



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: info32. is missing at boot

NTLDR is missing Win9x boot error www.computing.net/answers/windows-95/ntldr-is-missing-win9x-boot-error/135732.html

NTLDR is missing but I have win 98 www.computing.net/answers/windows-95/ntldr-is-missing-but-i-have-win-98/135819.html

win.com file missing at the setup on win www.computing.net/answers/windows-95/wincom-file-missing-at-the-setup-on-win/70652.html