Explorer is crashing and restarting ?????

Dec 6, 2007
im trying to fix a friends computer and the explorer crashes every few seconds and then restarts itself over and over it does this until i crash explorer and then all i can do is run programs threw task manager and the new task iv try everything ran like 5 anti virus scans and like 3 ad aware scans heres the log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:17:44 PM, on 12/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAV.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\ZZ31RMHH\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: (no name) - {B1DE8B17-63DB-195C-8B26-39E676F40DB0} - C:\WINDOWS\system32\wpkvvplo.dll (file missing)
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\cbxvusr.dll
O2 - BHO: (no name) - {C177ABE9-B518-470E-A0BD-03741C46A2AB} - C:\WINDOWS\system32\pmnnk.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125787942\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\200712213912_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Mqhouly] "C:\Documents and Settings\Owner\My Documents\F?nts\n?tepad.exe"
O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Essentials Manager\V CAST Music Monitor.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: cbxvusr - C:\WINDOWS\SYSTEM32\cbxvusr.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\WindowsUpdate\xuwueqi.html
End of file - 6756 bytes

thankx for the help
I would delete all googletoolbar entries, hate the damn thing causes problems.

Delete the following
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll

O2 - BHO: (no name) - {B1DE8B17-63DB-195C-8B26-39E676F40DB0} - C:\WINDOWS\system32\wpkvvplo.dll (file missing)

O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\cbxvusr.dll

O2 - BHO: (no name) - {C177ABE9-B518-470E-A0BD-03741C46A2AB} - C:\WINDOWS\system32\pmnnk.dll

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll

O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\200712213912_mcappins.exe /v=3 /cleanup

O4 - HKCU\..\Run: [Mqhouly] "C:\Documents and Settings\Owner\My Documents\F?nts\n?tepad.exe"

O20 - Winlogon Notify: cbxvusr - C:\WINDOWS\SYSTEM32\cbxvusr.dll
using regedit? well alst night i tryd to do a system restore and i know it never works but i tryd and it re brought back everything i belive so heres the new list

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:37:51 AM, on 12/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125787942\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\200712213912_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Mqhouly] "C:\Documents and Settings\Owner\My Documents\F?nts\n?tepad.exe"
O4 - HKCU\..\Run: [Turbo Searcher] "C:\Program Files\Turbo Searcher\TurboSearcher.exe" /minimized
O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Essentials Manager\V CAST Music Monitor.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\WindowsUpdate\xuwueqi.html

End of file - 5819 bytes

ill get rid of all that stuff i hate them too but hey what can u do about the stupid ppl dling stupid things
then after clean up

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:26:37 AM, on 12/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Essentials Manager\V CAST Music Monitor.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\WindowsUpdate\xuwueqi.html

End of file - 4146 bytes
then this is from a program called sd fix that

System Report

Run on Fri 12/07/2007 at 03:30 AM

Microsoft Windows XP [Version 5.1.2600]

Current user is an administrator

Running Processes:

\SystemRoot\System32\smss.exe [740]
\??\C:\WINDOWS\system32\csrss.exe [1020]
\??\C:\WINDOWS\system32\winlogon.exe [1184]
C:\WINDOWS\system32\services.exe [1312]
C:\WINDOWS\system32\lsass.exe [1372]
C:\WINDOWS\system32\svchost.exe [600]
C:\WINDOWS\system32\svchost.exe [992]
C:\WINDOWS\System32\svchost.exe [1276]
C:\WINDOWS\system32\svchost.exe [1644]
C:\WINDOWS\System32\svchost.exe [288]
C:\WINDOWS\System32\svchost.exe [696]
C:\WINDOWS\system32\spoolsv.exe [2004]
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [1216]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe [1264]
C:\WINDOWS\system32\hkcmd.exe [1660]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [1680]
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe [1684]
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [1852]
C:\Program Files\QuickTime\qttask.exe [1652]
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe [1952]
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe [1944]
C:\Program Files\Messenger\msmsgs.exe [464]
C:\Program Files\AIM\aim.exe [860]
C:\WINDOWS\System32\svchost.exe [816]
C:\WINDOWS\System32\alg.exe [888]
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe [1224]
C:\WINDOWS\system32\taskmgr.exe [276]
E:\HiJackThis.exe [1600]


804D7000: \WINDOWS\system32\ntoskrnl.exe
806EC000: \WINDOWS\system32\hal.dll
F9762000: \WINDOWS\system32\KDCOM.DLL
F9672000: \WINDOWS\system32\BOOTVID.dll
F9213000: ACPI.sys
F9202000: pci.sys
F9262000: isapnp.sys
F982A000: pciide.sys
F9766000: intelide.sys
F9272000: MountMgr.sys
F91E3000: ftdisk.sys
F94EA000: PartMgr.sys
F9282000: VolSnap.sys
F91CB000: atapi.sys
F9292000: disk.sys
F91AB000: fltmgr.sys
F9199000: sr.sys
F9182000: KSecDD.sys
F916F000: WudfPf.sys
F90E2000: Ntfs.sys
F90B5000: NDIS.sys
F909A000: Mup.sys
F94C2000: \SystemRoot\System32\DRIVERS\intelppm.sys
F8E41000: \SystemRoot\System32\DRIVERS\ialmnt5.sys
F8E2D000: \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
F95E2000: \SystemRoot\System32\DRIVERS\usbuhci.sys
F8E0A000: \SystemRoot\System32\DRIVERS\USBPORT.SYS
F95EA000: \SystemRoot\System32\DRIVERS\usbehci.sys
F94D2000: \SystemRoot\System32\DRIVERS\bcm4sbxp.sys
F95F2000: \SystemRoot\System32\DRIVERS\fdc.sys
F92C2000: \SystemRoot\System32\DRIVERS\i8042prt.sys
F95FA000: \SystemRoot\System32\DRIVERS\kbdclass.sys
F9602000: \SystemRoot\System32\DRIVERS\mouclass.sys
F92D2000: \SystemRoot\System32\DRIVERS\serial.sys
F971A000: \SystemRoot\System32\DRIVERS\serenum.sys
F8DF6000: \SystemRoot\System32\DRIVERS\parport.sys
F92E2000: \SystemRoot\System32\DRIVERS\imapi.sys
F92F2000: \SystemRoot\System32\DRIVERS\cdrom.sys
F9302000: \SystemRoot\System32\DRIVERS\redbook.sys
F8DD3000: \SystemRoot\System32\DRIVERS\ks.sys
F960A000: \SystemRoot\SYSTEM32\DRIVERS\GEARAspiWDM.sys
F8D42000: \SystemRoot\system32\drivers\smwdm.sys
F8D1E000: \SystemRoot\system32\drivers\portcls.sys
F9312000: \SystemRoot\system32\drivers\drmk.sys
F976E000: \SystemRoot\system32\drivers\aeaudio.sys
F9981000: \SystemRoot\System32\DRIVERS\audstub.sys
F9322000: \SystemRoot\System32\DRIVERS\rasl2tp.sys
F9722000: \SystemRoot\System32\DRIVERS\ndistapi.sys
F8D07000: \SystemRoot\System32\DRIVERS\ndiswan.sys
F9332000: \SystemRoot\System32\DRIVERS\raspppoe.sys
F9342000: \SystemRoot\System32\DRIVERS\raspptp.sys
F9612000: \SystemRoot\System32\DRIVERS\TDI.SYS
F8CF6000: \SystemRoot\System32\DRIVERS\psched.sys
F9352000: \SystemRoot\System32\DRIVERS\msgpc.sys
F961A000: \SystemRoot\System32\DRIVERS\ptilink.sys
F9622000: \SystemRoot\System32\DRIVERS\raspti.sys
F9362000: \SystemRoot\System32\DRIVERS\termdd.sys
F9770000: \SystemRoot\System32\DRIVERS\swenum.sys
F8C67000: \SystemRoot\System32\DRIVERS\update.sys
F9732000: \SystemRoot\System32\DRIVERS\mssmbios.sys
F9372000: \SystemRoot\System32\Drivers\NDProxy.SYS
F9392000: \SystemRoot\System32\DRIVERS\usbhub.sys
F9774000: \SystemRoot\System32\DRIVERS\USBD.SYS
F962A000: \SystemRoot\System32\DRIVERS\flpydisk.sys
F8F2B000: \SystemRoot\System32\Drivers\VETFDDNT.SYS
F977C000: \SystemRoot\System32\Drivers\Fs_Rec.SYS
F0A2E000: \SystemRoot\System32\Drivers\VETEFILE.SYS
F8F23000: \SystemRoot\System32\Drivers\VET-REC.SYS
F963A000: \SystemRoot\System32\Drivers\VET-FILT.SYS
F9642000: \SystemRoot\System32\Drivers\VETMONNT.SYS
F09EE000: \SystemRoot\System32\Drivers\VETEBOOT.SYS
F9972000: \SystemRoot\System32\Drivers\Null.SYS
F977E000: \SystemRoot\System32\Drivers\Beep.SYS
F964A000: \SystemRoot\System32\drivers\vga.sys
F9780000: \SystemRoot\System32\Drivers\mnmdd.SYS
F9782000: \SystemRoot\System32\DRIVERS\RDPCDD.sys
F9652000: \SystemRoot\System32\Drivers\Msfs.SYS
F965A000: \SystemRoot\System32\Drivers\Npfs.SYS
F8F07000: \SystemRoot\System32\DRIVERS\rasacd.sys
F09BB000: \SystemRoot\System32\DRIVERS\ipsec.sys
F0963000: \SystemRoot\System32\DRIVERS\tcpip.sys
F093B000: \SystemRoot\System32\DRIVERS\netbt.sys
F091A000: \SystemRoot\System32\DRIVERS\ipnat.sys
F08F8000: \SystemRoot\System32\drivers\afd.sys
F93D2000: \SystemRoot\System32\DRIVERS\wanarp.sys
F9512000: \SystemRoot\System32\DRIVERS\USBSTOR.SYS
F93F2000: \SystemRoot\System32\DRIVERS\netbios.sys
F08CD000: \SystemRoot\System32\DRIVERS\rdbss.sys
F0836000: \SystemRoot\System32\DRIVERS\mrxsmb.sys
F9452000: \SystemRoot\System32\Drivers\Fips.SYS
F0813000: \SystemRoot\System32\Drivers\Fastfat.SYS
F07FB000: \SystemRoot\System32\Drivers\dump_atapi.sys
F97A0000: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000: \SystemRoot\System32\win32k.sys
F8C43000: \SystemRoot\System32\drivers\Dxapi.sys
F9532000: \SystemRoot\System32\watchdog.sys
BF9C3000: \SystemRoot\System32\drivers\dxg.sys
F98F4000: \SystemRoot\System32\drivers\dxgthk.sys
BF9E3000: \SystemRoot\System32\ialmdnt5.dll
BF9D5000: \SystemRoot\System32\ialmrnt5.dll
BFA02000: \SystemRoot\System32\ialmdev5.DLL
BFA2E000: \SystemRoot\System32\ialmdd5.DLL
F069F000: \SystemRoot\System32\DRIVERS\ndisuio.sys
F0386000: \SystemRoot\system32\drivers\wdmaud.sys
F044B000: \SystemRoot\system32\drivers\sysaudio.sys
F93C2000: \SystemRoot\System32\Drivers\Cdfs.SYS
F00D3000: \SystemRoot\System32\DRIVERS\mrxdav.sys
F980C000: \SystemRoot\System32\Drivers\ParVdm.SYS
EFEA1000: \SystemRoot\System32\DRIVERS\srv.sys
EFCE6000: \SystemRoot\system32\drivers\kmixer.sys
F01B0000: \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\catchme.sys
7C900000: \WINDOWS\system32\ntdll.dll

Files Created/Modified - 60 Days:


Dec 6 2007 3:10:10a 8,312 A.... "C:\caavsetup.log"
Nov 18 2007 1:22:08p 263,494 A.... "C:\hpfr5700.log"
Dec 7 2007 3:20:46a 399,507,456 A.SH. "C:\pagefile.sys"
Dec 6 2007 4:25:22p 1,803 A.... "C:\rapport.txt"


Dec 7 2007 3:21:46a 0 A.... "C:\WINDOWS\0.log"
Dec 6 2007 3:09:46a 111,728 A.... "C:\WINDOWS\AVShlExt.dll"
Dec 7 2007 3:20:48a 2,048 A.S.. "C:\WINDOWS\bootstat.dat"
Nov 19 2007 5:06:14p 1,409 A.... "C:\WINDOWS\QTFont.for"
Dec 5 2007 8:39:38p 54,156 A..H. "C:\WINDOWS\QTFont.qfn"
Dec 7 2007 3:20:12a 2,736 A.... "C:\WINDOWS\SchedLgU.Txt"
Dec 2 2007 1:26:50p 0 A.... "C:\WINDOWS\Sti_Trace.log"
Dec 6 2007 3:09:46a 115,824 A.... "C:\WINDOWS\UnVet32.exe"
Dec 7 2007 3:21:34a 159 A.... "C:\WINDOWS\wiadebug.log"
Dec 7 2007 3:21:28a 49 A.... "C:\WINDOWS\wiaservc.log"
Dec 7 2007 3:28:22a 1,316,191 A.... "C:\WINDOWS\WindowsUpdate.log"
Dec 6 2007 12:56:22p 749 A..HR "C:\WINDOWS\WindowsShell.Manifest"
C:\Program Files\

Nov 22 2007 8:10:36a 787,696 A.... "C:\Program Files\CCleaner\CCleaner.exe"
Dec 2 2007 12:47:32p 111,005 A.... "C:\Program Files\CCleaner\uninst.exe"
Dec 6 2007 3:13:24a 300,680 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\arclib.dll"
Dec 7 2007 3:22:38a 63,816 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\boot.dat"
Dec 6 2007 3:12:56a 94,208 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\cafix.exe"
Dec 6 2007 3:09:46a 328,816 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAV.exe"
Dec 6 2007 3:09:46a 87,152 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVCmd.exe"
Dec 6 2007 3:09:46a 74,864 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVCtx.exe"
Dec 6 2007 3:09:46a 185,456 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRid.exe"
Dec 6 2007 3:09:46a 230,512 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
Dec 6 2007 3:09:46a 193,920 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\InoScan.dll"
Dec 6 2007 3:09:46a 259,184 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\iSafe.exe"
Dec 6 2007 3:12:56a 1,353,016 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafeEngine.dll"
Dec 6 2007 3:09:46a 128,112 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\LicReg.exe"
Dec 6 2007 3:13:24a 167,936 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\usetup.exe"
Dec 6 2007 3:09:46a 28,032 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\vdmdbg.dll"
Dec 7 2007 3:22:38a 13,311,272 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\vet.dat"
Dec 6 2007 3:12:56a 1,353,016 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\vete.dll"
Dec 6 2007 3:09:46a 201,840 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe"
Dec 6 2007 3:09:46a 9,328 A.... "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetNTMsg.dll"
Oct 31 2007 8:30:30a 45,056 A.... "C:\Program Files\Outerinfo\FF\components\FF.dll"
Dec 2 2007 1:04:30p 51 A.... "C:\Program Files\Webroot\Spy Sweeper\Logs\alkep.dat"
Dec 2 2007 1:04:30p 51 A.... "C:\Program Files\Webroot\Spy Sweeper\Logs\alrem.dat"
Dec 2 2007 1:04:30p 240 A.... "C:\Program Files\Webroot\Spy Sweeper\Quarantine\F_related[1]__htm.dat"
Dec 2 2007 1:19:04p 166 A.... "C:\Program Files\Webroot\Spy Sweeper\Quarantine\qr.dat"
Dec 5 2007 8:07:54p 19,456 A.... "C:\Program Files\CA\SharedComponents\CAUpdate\Plugins\AvBaseCAU1.dll"
Dec 5 2007 8:07:54p 34,304 A.... "C:\Program Files\CA\SharedComponents\CAUpdate\Plugins\InoEngCAU1.dll"
Dec 5 2007 8:05:36p 18,944 A.... "C:\Program Files\CA\SharedComponents\CAUpdate\Plugins\ITMCommonCAU.dll"
Dec 5 2007 8:07:54p 34,304 A.... "C:\Program Files\CA\SharedComponents\CAUpdate\Plugins\VetEngCAU1.dll"

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, Rootkit scan 2007-12-07 03:28:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

IPC error: 2 The system cannot find the file specified.
scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

Run Values:

"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"HP Software Update"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"CaAvTray"="\"C:\\Program Files\\CA\\eTrust EZ Armor\\eTrust EZ Antivirus\\CAVTray.exe\""
"CAVRID"="\"C:\\Program Files\\CA\\eTrust EZ Armor\\eTrust EZ Antivirus\\CAVRID.exe\""





"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"

Bot Check:

DISPLAY_NAME : Security Center

SERVICE_NAME: sharedaccess
DISPLAY_NAME : Windows Firewall/Internet Connection Sharing (ICS)

SERVICE_NAME: wuauserv
DISPLAY_NAME : Automatic Updates

SERVICE_NAME: srservice
DISPLAY_NAME : System Restore Service



[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions]





HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\environment
ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe
Path REG_EXPAND_SZ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
windir REG_EXPAND_SZ %SystemRoot%
OS REG_SZ Windows_NT
CLASSPATH REG_SZ .;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
QTJAVA REG_SZ C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip


SecurityProviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll

Authentication Packages:

Authentication Packages REG_MULTI_SZ msv1_0\0C:\WINDOWS\system32\pmnnk.dll\0\0

Non-Default IFEO Debugger:

Non-Default Installed Components:

Non-Default Safeboot Minimal:

File Associations:

@="\"%1\" %*"

@="\"%1\" %*"

@="\"%1\" %*"

@="\"%1\" %*"

@="C:\\WINDOWS\\system32\\mshta.exe \"%1\" %*"

@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" -nohome"

@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" -nohome"

@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" -nohome"

@="regedit.exe %1"

@="regedit.exe \"%1\""

@="\"%1\" /S"

@="%SystemRoot%\system32\NOTEPAD.EXE %1"

So now that the wheel on my mouse is overheated, is your problem fixed, still exists, what happened?
Were you able to resolve this? I just ran into this problem within the last few days, maybe I can help.
Just to get through the basics...
Did you try Safe Mode?
Did you try Last Known Good configuration?
Did you try deleting temp files? (Usually doesn't fix anything, but I've seen some people with literally over 100,000 temp files).
Did you try reinstalling the latest Windows XP Service Pack?
By any chance was this a custom built computer? I had a problem similar to this a few years back. It was due to incompatible ram with the board. The ram was of the right type for the board however it had a conflict with it. Might want to check that. Also might want to see if your ram is bad.

Test one stick at a time (have only one stick at a time on the motherboard)

There is a point in wisdom and knowledge that when you reach it, you exceed what is considered possible - Jason Schoon

Go to your internet options and select the Advance tab. Click the Reset button. Doing this clears your form data and Username & passwords. You do not lose your Favorites.
If you look at your registry in the following location:

Authentication Packages REG_MULTI_SZ msv1_0\0C:\WINDOWS\system32\pmnnk.dll\0\0

you see the file pmnnk.dll this is the culprit.
There will be 2 files you need to delete
"pmnnk.dll" and "pmnnk.exe" in your system32 folder

The registry entries will also need to be changed the value for the authenication packages should only be msv1_0

these entries should be in all ControlSet Hives and will also need modified.

after that search the registry for all instances of "pmnnk" and delete only those values

You will not be able to do this within windows not even safe mode. You will need a bootable CD to access the drive and registry. UBCD has worked for me with this infection

Hope this helps
