Does anyone know what RebateNation.exe is and how to get rid of it???? :eek:
chef 0 Newbie Poster
Dani AI
Generated
Useful next steps (concise, practical, and safe) to follow after the HijackThis work already done by and the troubleshooting by and others. The symptoms you describe (Rebate_Nation entries present, HijackThis fixes applied, then the Internet dies after a few minutes) strongly point to either (a) a leftover autostart / Layered Service Provider (LSP) / context‑menu component still hooking networking, or (b) Winsock / TCP‑IP corruption caused by an adware removal. Start with non-destructive inspection tools, then move to targeted repairs. Autoruns will show every autostart location (Run keys, shell extensions, Winsock providers) in one list and is the right next tool to use. (learn.microsoft.com)
Immediate checklist to try (do these in order; collect logs if you post for help):
- Boot to Safe Mode (or Safe Mode with Networking when you need downloads).
- Run RKill (to stop rogue processes if anything blocks scanners).
- Run Autoruns, check “Hide Microsoft entries,” search for anything with “Rebate” or unknown vendors and uncheck/remove those entries (remember the context‑menu entry that showed up in HijackThis).
- Use Process Explorer / TCPView (or run
netstat -b -n -o) while reproducing the failure to find the process creating connections; terminate that process before deleting files. (technibble.com)
Repair the network stack (only after stopping/removing the offending process):
- Flush DNS and reset TCP/IP + Winsock, then reboot. Example commands:
ipconfig /flushdns netsh int ip reset c:\resetlog.txt netsh winsock resetMicrosoft documents these resets and warns that resetting Winsock may require reinstalling some networking software afterwards. Back up important settings first. (support.microsoft.com)
Finish with scans and fallback options:
- Run up‑to‑date AdwCleaner and Malwarebytes full scans to remove PUPs/toolbars. If connectivity still drops, reinstall the NIC driver (Device Manager), try Last Known Good, or consider a repair install / clean image after backing up data. Keep and paste logs from Autoruns, HijackThis and TCPView when asking for further help. (help.malwarebytes.com)
If any step fails or a specific file/process name is found (for example anything still named RebateNation*), post the exact process name and Autoruns report so the cleanup can be narrowed to that binary and its registry keys.
Recommended Answers
Jump to Post— Dark_Omen 5Have no idea, sounds like spyware, may won't to uninstall. I looked it up on-line and on another forum someone said it was spyware. Get Ad aware or spyware search & destroy
Jump to Post— Dark_Omen 5Oh yeah ad-aware and spybot search & destroy will get rid of it for you.
Jump to Post— mikeandike22 18goto the program files and delete the rebates nation folders or if it wont let you quarantine the folder. then goto start<run< and type regedt32 (make a system restore point before doing this.) then goto either hkey_local_machine <software or hkey_current_user<software and look for a folder named rebates nation.
Jump to Post— DuncanIdaho 2Rebate Nation is an autotracker distributed by a company affiliated with Target, Dell, and a number of other companies. It offers easy automatic fast rebates on online purchases from it's affiliates, and the autotracker program automatically calculates the rebate and it is sent to you with no effort on your …
Jump to Post— DuncanIdaho 2If it started recently, you could always try loading a system restore point from a time prior to when the darned thing appeared.
All 23 Replies
Dark_Omen 5 Posting Pro
Have no idea, sounds like spyware, may won't to uninstall. I looked it up on-line and on another forum someone said it was spyware. Get Ad aware or spyware search & destroy
Dark_Omen 5 Posting Pro
Oh yeah ad-aware and spybot search & destroy will get rid of it for you.
chef 0 Newbie Poster
I have run both the adaware and spy bot and these two files are still there...any other suggestions????
mikeandike22 18 Nearly a Posting Virtuoso
goto the program files and delete the rebates nation folders or if it wont let you quarantine the folder. then goto start<run< and type regedt32 (make a system restore point before doing this.) then goto either hkey_local_machine <software or hkey_current_user<software and look for a folder named rebates nation.
DuncanIdaho 2 Unverified User
Rebate Nation is an autotracker distributed by a company affiliated with Target, Dell, and a number of other companies. It offers easy automatic fast rebates on online purchases from it's affiliates, and the autotracker program automatically calculates the rebate and it is sent to you with no effort on your part.
Personally, I wouldn't want it on my machine. I'm also skeptical of their practices, since they have no accessible instructions on their website for removing it.
First thing I'd check is: Open up your Control Panel, go to Add/Remove Programs, and see if you can find RebateNation Autotracker in there, if you find it, remove it.
I've, so far, been unable to find english instructions for how to remove it, (in fact, I've found exactly one page with instructions, and it is in Norwegian or something).
I hope I've helped.
chef 0 Newbie Poster
Thanks for all the input.....but I am still unable to remove or find it following all of your helpful advice......what now??? Does ne one know what to do next??? Thanks in advance.....
DuncanIdaho 2 Unverified User
If it started recently, you could always try loading a system restore point from a time prior to when the darned thing appeared.
chef 0 Newbie Poster
The system restore feature only goes back two months...is this normal??...and this has been going on longer than that....
DuncanIdaho 2 Unverified User
Mine goes back 4 months. System Restore can only hold so much data, and is limited by the percentage of your hard drive it is set to use. Mine has 12% of 80 gigs (x2) to work with, it sounds to me yours has less to work with, so you have fewer restore points.
I hope someone else here can tell you how to get rid of Rebate Nation. It may be unlikely, though, unless someone here is willing to put it on their machine to find out how to remove it.
The only other advice I can give you is this:
Go to:
Pick 'Contact Us', and fill out the little form, ask them to tell you how to remove it. If they will not tell you, then contact every merchant they deal with, (Target, Dell, etc),and complain about RebateNation's practices. My bet, though, is that they'll tell you. They are working with some big name companies there, and big name companies are not going to want slimeware outfits affiliated with them, so give it a shot, and let us know how you fare.
Best of luck to you.
edit: At the time of this writing, RebateNation's website seems to be down. However it was working yesterday, so it should come back soon.
crunchie 990 Most Valuable Poster Team Colleague Featured Poster
Download HijackThis from & unzip it into it's own, permanent folder, (Not a temporary folder or the desktop (in a folder on the desktop is fine) & not directly on your hard drive).
If you have anything disabled in MsConfig, please re-enable it/them.
Start HJT & with all browser windows closed, press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire contents of the text file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
chef 0 Newbie Poster
Here it is....also now I am only able to stay on the internet for about 5 minutes before it crashes and the only way to get back on is to restart the computer...ne thoughts on this?????
Logfile of HijackThis v1.98.2
Scan saved at 9:19:59 PM, on 9/6/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Rebate_Nation\RebateNation0.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Rebate_Nation\RebateNation1.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\paul\My Documents\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoomail.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKLM\..\Run: [RebateNation0] "C:\Program Files\Rebate_Nation\RebateNation0.exe"
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [HXIUL.EXE] C:\Program Files\Cosmi\HelpExpress\paul\HXIUL.EXE
O4 - HKCU\..\Run: [HELPEXP.EXE] C:\Program Files\Cosmi\HelpExpress\paul\Client\HelpExp.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Rebate Nation - file://C:\Program Files\Rebate_Nation\Sy5300\Tp5300\scri5300a.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {D62B5127-8D03-4175-BA71-E0041595DA4B} (UDConnect Class) - http://03.sharedsource.org/html/TriacomUD_1.0.0.3ie.cab?
O21 - SSODL: URLREWIN - {CA2DB500-5ECF-11D2-B28F-0080C8383C7B} - c:\windows\system32\shmswnrc.dll
DuncanIdaho 2 Unverified User
Woot! Crunchie to the rescue! :)
crunchie 990 Most Valuable Poster Team Colleague Featured Poster
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O4 - HKLM\..\Run: [RebateNation0] "C:\Program Files\Rebate_Nation\RebateNation0.exe"
O8 - Extra context menu item: Rebate Nation - file://C:\Program Files\Rebate_Nation\Sy5300\Tp5300\scri5300a.htm
O16 - DPF: {D62B5127-8D03-4175-BA71-E0041595DA4B} (UDConnect Class) - http://03.sharedsource.org/html/Tri..._1.0.0.3ie.cab?
-Triacom Soluciones Dialer
Reboot into safe mode following the instructions & navigate to & delete the following if found:
C:\Program Files\Rebate_Nation-folder
Reboot normally.
Uninstall "HelpExpress" and "Attune" by going to Add/Remove Programs."
Post a new log please.
chef 0 Newbie Poster
Ok...I was able to do as you instructed except for removing "helpexpress" and "attune" b/c I was unable to locate them in the add/remove Programs as well as by using the search feature...nothing...here is the new hijackthis log....I appreciate all the help.....Chef
Logfile of HijackThis v1.98.2
Scan saved at 1:23:26 PM, on 9/7/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\paul\My Documents\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoomail.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKLM\..\Run: [RebateNation0] "C:\Program Files\Rebate_Nation\RebateNation0.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [HXIUL.EXE] C:\Program Files\Cosmi\HelpExpress\paul\HXIUL.EXE
O4 - HKCU\..\Run: [HELPEXP.EXE] C:\Program Files\Cosmi\HelpExpress\paul\Client\HelpExp.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O21 - SSODL: URLREWIN - {CA2DB500-5ECF-11D2-B28F-0080C8383C7B} - c:\windows\system32\shmswnrc.dll
chef 0 Newbie Poster
Addendum.....I am still unable to stay on the internet for more than a few minutes (using both IE and Mozilla)...and after I rebooted into normal mode I now have a window that says I am currently in Diagnostic or Selective Startup Mode and that I should run in Normal mode.....even though I did not change this setting....what to do?????
crunchie 990 Most Valuable Poster Team Colleague Featured Poster
Rebate_nation is still on your comp.
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
O4 - HKLM\..\Run: [RebateNation0] "C:\Program Files\Rebate_Nation\RebateNation0.exe"
O4 - HKCU\..\Run: [HXIUL.EXE] C:\Program Files\Cosmi\HelpExpress\paul\HXIUL.EXE
O4 - HKCU\..\Run: [HELPEXP.EXE] C:\Program Files\Cosmi\HelpExpress\paul\Client\HelpExp.exe
Reboot into safe mode following the instructions & navigate to & delete the following if found:
C:\Program Files\Rebate_Nation-folder
C:\Program Files\Cosmi\HelpExpress-folder
Reboot normally after doing the above then post a fresh log please.
I am not familiar with XP, but I believe there should be a radio button to select which start-up mode you desire. Select the normal mode. Anyone else with XP please jump in :).
chef 0 Newbie Poster
OK...I fixed the 3 items in hijackthis but could not locate the 2 program files to delete....please advise....thanks!!!!
Logfile of HijackThis v1.98.2
Scan saved at 9:22:40 AM, on 9/8/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Documents and Settings\paul\My Documents\hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoomail.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O21 - SSODL: URLREWIN - {CA2DB500-5ECF-11D2-B28F-0080C8383C7B} - c:\windows\system32\shmswnrc.dll
chef 0 Newbie Poster
Thanks so much for all the help!!! I am still having the problem with the internet though (only able to stay on for a few minutes)...ne suggestions??
crunchie 990 Most Valuable Poster Team Colleague Featured Poster
Has me beat. Perhaps some of our more experienced members have an answer for you?
DuncanIdaho 2 Unverified User
Could you explain/describe this 'crash' you're having? Is the machine actually locking up? Do you get an error message? Or do you just become unable to use the internet? Will the machine run fine in all other ways?
How are you connecting to the net? Dial up? Cable? DSL? Do you have a router and an ethernet card? Or DSL/Cable USB modem? Any information you can give in this area will tell us a lot, and could help someone figure out what's going on.
Something could have messed with your drivers, or messed with your network settings. Or any number of things. A bit more info could uncover something.
chef 0 Newbie Poster
What happens is that I am unable to access any web pages after a few minutes....all other sysytems work fine and it happens when I am using both Mozilla and IE....I am connected via cable using a DSL/Cable modem...I have checked with the isp provider and it is not on thier end....other than that I simply do not know...any help is greatly appreciated and let me know if you or any one needs more info....Thanks
DuncanIdaho 2 Unverified User
Is your modem connected to a network card in your computer? Or a USB port?
If it's connected to a network card, I'd consider removing the drivers for the network card by removing it in Device Manager. When you reboot, you will have to reinstall the drivers, and then, Windows will automatically reinstall networking protocols. If you are lucky, one of these files are what has been messed with, and restoring Networking to it's default state will fix it. Hopefully. Cross your fingers.
So you know, this is a longshot at best, but you seem to be in a desperate position, it's beginning to look like 'reinstall time', and I take it you'd rather find some other way to fix this.
If it's a USB modem, I have no real experience with them, I can't think of anything suitable short of deleting all TCP/IP networking protocols, and reinstalling them from scratch.
Got yourself a real stumper of a problem here, gotta say it, Chef. :(
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.