error messages [RESOLVED] |
![]() ![]() |
error messages [RESOLVED] |
Dec 17 2007, 11:00 AM
Post
#1
|
|
|
New Member ![]() Posts: 3 OS: xp |
Recently I had a virus and many adware problems. Eventually, I think I was able to fix the problem (thanx to this website). But now, everytime I open up my computer, I always get an error message saying "shmpencs.dll could not be found". Is it because there are still some adwares in my machine? Thank you Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:55:03, on 2007-12-17 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Bell\Gestionnaire de securite\Fws.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\essspk.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\BellCanada\McciTrayApp.exe C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe C:\Program Files\SPAMfighter\SFAgent.exe C:\Program Files\Fichiers communs\Authentium\AntiVirus\dvpapi.exe C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\Program Files\SPAMfighter\sfus.exe C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\Program Files\internet explorer\iexplore.exe C:\PROGRA~1\WinZip\winzip32.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\DOCUME~1\client\LOCALS~1\Temp\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://accesd.desjardins.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: {ec943fa7-2554-8a48-6604-e9a45d9d5570} - {0755d9d5-4a9e-4066-84a8-45527af349ce} - C:\WINDOWS\System32\xhpvsyuh.dll (file missing) O2 - BHO: (no name) - {17A895B6-1DC5-401A-A2A1-203169C483B7} - C:\Program Files\Messenger\hokes83122.dll (file missing) O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Gestionnaire de securite\pkR.dll O2 - BHO: (no name) - {4431091A-C524-4ED0-9F53-FE92E030FAA5} - C:\Program Files\Messenger\hokes4444.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: 0 - {8CFCEB6C-16BF-4404-9F81-09E8A439778E} - C:\Program Files\Windows NT\lavumav.dll (file missing) O2 - BHO: (no name) - {B1A1FA45-108D-3955-DA2F-31E677F35998} - C:\WINDOWS\System32\ijhzop.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: The voipwet - {224E1433-F086-4BB1-B791-AF87F7629D93} - C:\WINDOWS\voipwet.dll (file missing) O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe O4 - HKLM\..\Run: [BI1HelperStartUp] C:\PROGRA~1\BEACHI~1\BI1HEL~1.EXE /partner BI1 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [BellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe" O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60 O4 - HKLM\..\Run: [a033cce8] rundll32.exe "C:\WINDOWS\System32\shmpencs.dll",b O4 - HKCU\..\Run: [SoundMan] " SOUNDMAN.EXE" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O16 - DPF: TruePass EPF 7,0,100,730 - https://blrscr3.egs-seg.gc.ca/applets/entru...sapplet-epf.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1154312457090 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Fichiers communs\Authentium\AntiVirus\dvpapi.exe O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe O24 - Desktop Component 0: (no name) - C:\Program Files\Windows NT\profsybypr.html -- End of file - 5802 bytes |
|
|
Dec 22 2007, 03:40 PM
Post
#2
|
|
![]() Malware Slayer Extraordinaire! Posts: 11,510 From: Mass, USA :) OS: XP |
Welcome to Geekstogo, My name is Excal and I will be helping you.
Please create a permanent folder and move hijackthis.exe into it. The reason for this is because HijackThis creates backups and they may be deleted if they are in a temp-folder. How to make a permanent folder:
After you done that: Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below: O4 - HKLM\..\Run: [a033cce8] rundll32.exe "C:\WINDOWS\System32\shmpencs.dll",b Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis. Reboot and let me know if you still have the error. Excal |
|
|
Dec 22 2007, 03:58 PM
Post
#3
|
|
|
New Member ![]() Posts: 3 OS: xp |
Thank you so much Excal, the problem is solved!
Thanks again! I hope you get paid well for this |
|
|
Dec 22 2007, 04:47 PM
Post
#4
|
|
![]() Malware Slayer Extraordinaire! Posts: 11,510 From: Mass, USA :) OS: XP |
Glad it fixed it
We don't get paid for this, we are volunteers. Once in a while we get donations, but thats it Have a happy holidays Great job, it appears your computer is clean If you have unhidden you “hidden files and folders”, ensure you rehide them back to the way they were. Now that your system is Malware Free, it is important to reset your system Restore. Click Here to learn how to. I recommend that you Defrag your computer before setting your Restore points: Go to start>all programs>accessories>system tools>Disk Defragmentor Make sure it set to the proper drive (default should be your main driver) and click on defragment Might I suggest the following Free Spyware programs, if you don't already have them, for added security, you can download them at the following links. These programs work great for detection: Ad-aware SE Spybot S&D Microsoft Anti-Spyware If you are unhappy with your current antivirus and want to replace it or if you dont already have one, I suggest one of these free programs: *Note - do not use more than one anti-virus program as it will more than likely cause conflict. AVG Avast AntiVir The following free programs are great for prevention: SpywareBlaster 3.4 Spywareguard IE/Spyad A Firewall is a must! Here are 3 good free versions: (do not have more than one firewall running on your system) Sygate Kerio ZoneLabs There are other options other than Internet Explorer for a browser, which some say have better security. Two of them are: Firefox Opera If you decide to keep Internet Explorer, This site is a great source for tightening up security on It's settings. Make sure that you keep your Operating System and IE updated with the latest Critical Security Updates from Microsoft...they usually come out once a month, on the 2nd Tuesday of each month. Be sure and give the Temp folders a cleaning out now and then as well, Make sure after you clean your Temp files to empty out your Recycle bin as well. For ease use the following program: Cleanup Run "Cleanup" and when it has finished, Reboot To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial and use the tools provided. Also read So how did I get infected in the first place? |
|
|
Dec 28 2007, 10:04 AM
Post
#5
|
|
![]() Malware Slayer Extraordinaire! Posts: 11,510 From: Mass, USA :) OS: XP |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
15 / 1,624 | 27th May 2005 - 11:05 AM Nomsumpisces started - last by greyknight17 |
|||||
![]() |
36 / 638 | 13th September 2008 - 05:20 PM xKiseki started - last by andrewuk |
|||||
![]() |
26 / 1,502 | 8th December 2008 - 08:21 AM kashmanx7 started - last by Rorschach112 |
|||||
![]() |
10 / 258 | 7th December 2008 - 03:46 AM argggggg started - last by miekiemoes |
|||||
|
Time is now: 8th January 2009 - 03:22 AM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |