After reboot 3 "Error loading" messages pop up...

View previous topic View next topic Go down

After reboot 3 "Error loading" messages pop up...

Post by CG79 on 5th May 2009, 11:35 pm

After running my Super AntiSpyware program, it asks that I reboot. After my computer restarts and desktop is back up, for about a week or so I have been getting 3 gray boxes popping up that say...

"Error loading C:\WINDOWS\System32\gafupizu.dll
The specified module could not be found. "

The two others say the same but with mabemiri.dll and fapiyori.dll in place of gafupizu.dll.

I have no idea what these are and what they mean, but I know it probably shouldn't be happening. also been having some freezeups, and slow loading times here and there... please help me figure this out!

CG79
Intermediate
Intermediate

Posts Posts : 53
Joined Joined : 2008-12-09
OS OS : Windows XP
Points Points : 29424
# Likes # Likes : 0

View user profile

Back to top Go down

Re: After reboot 3 "Error loading" messages pop up...

Post by Belahzur on 5th May 2009, 11:43 pm


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245079
# Likes # Likes : 1

View user profile

Back to top Go down

Re: After reboot 3 "Error loading" messages pop up...

Post by CG79 on 6th May 2009, 4:16 am

DDS (Ver_09-03-16.01) - NTFSx86
Run by Crystal at 0:14:49.93 on Wed 05/06/2009
Internet Explorer: 6.0.2800.1106
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.255.30 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\AOL\1235098084\ee\AOLSoftware.exe
C:\Program Files\Microsoft Money\System\reminder.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Documents and Settings\Crystal\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [Reminder] c:\program files\microsoft money\system\reminder.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [AdobeUpdater] c:\program files\common files\adobe\updater5\AdobeUpdater.exe
uRun: [AOL Fast Start] "c:\program files\aol 9.1\AOL.EXE" -b
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" -"http://games.myspace.com/MySpace2.0/App/GameShell.aspx?cx=600000&cn=SD%3dXKJ9tGTeb37Oi5%2bb5HiJuQxd1tXUNK52DPFiRxLsxljxbFW02eziIFhuSy%2fWMZmO%26LT%3d0%26CL%3dC%26TO%3d1227397556%26A%3d7dWdLpI%2b3EDa%2bqUUoVl1znZQDPs%3d%26SA%3d7dWdLpI%2b3EDa%2bqUUoVl1znZQDPs%3d&rx=1200000&rn=SD%3dXKJ9tGTeb37Oi5%2bb5HiJuQxd1tXUNK52DPFiRxLsxljxbFW02eziIFhuSy%2fWMZmO%26LT%3d0%26CL%3dR%26TO%3d1227398156%26A%3d6J5rjaQ1sb7u3entEeFZ%2fnPhZMs%3d%26SA%3d6J5rjaQ1sb7u3entEeFZ%2fnPhZMs%3d&ui=jYBvpJRaVHwTgeIFf3epwsieKA8%3d&ux=86400000&un=DA%3d%26SD%3dXKJ9tGTeb37Oi5%2bb5HiJuQxd1tXUNK52DPFiRxLsxljxbFW02eziIFhuSy%2fWMZmO%26LT%3d0%26CL%3dU%26TO%3d1227483356%26A%3d0J2A%2fzbjtsVorS8AKHa7E1dXHxY%3d%26SA%3d0J2A%2fzbjtsVorS8AKHa7E1dXHxY%3d&room=c738e3ce-1869-4bab-ab39-83caed5f488d&code=113399323&channel=110343720&lc=en&refid=&device=-1&carrier=-1&isOmitChat=0&isOmitAddToProfile=0"
mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe
mRun: [MCAgentExe] c:\program files\mcafee.com\agent\mcagent.exe
mRun: [MCUpdateExe] c:\progra~1\mcafee.com\agent\mcupdate.exe
mRun: [VirusScan Online] c:\progra~1\mcafee.com\vso\mcvsshld.exe
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [WorksFUD] c:\program files\microsoft works\wkfud.exe
mRun: [Microsoft Works Portfolio] c:\program files\microsoft works\WksSb.exe /AllUsers
mRun: [mmtask] c:\program files\musicmatch\musicmatch jukebox\mmtask.exe
mRun: [diagent] "c:\program files\creative\sblive\diagnostics\diagent.exe" startup
mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP
mRun: [HostManager] c:\program files\common files\aol\1235098084\ee\AOLSoftware.exe
mRun: [felukuliho] Rundll32.exe "c:\windows\system32\mabemiri.dll",s
mRun: [b8f30010] rundll32.exe "c:\windows\system32\gafupizu.dll",b
mRun: [CPMbbc0338c] Rundll32.exe "c:\windows\system32\fapiyori.dll",a
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
StartupFolder: c:\docume~1\crystal\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
mPolicies-explorer: =
IE: &Search - ?p=ZKxdm021NVUS
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - [You must be registered and logged in to see this link.]
DPF: Microsoft XML Parser for Java - [You must be registered and logged in to see this link.]
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - [You must be registered and logged in to see this link.]
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - [You must be registered and logged in to see this link.]
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - [You must be registered and logged in to see this link.]
DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} - [You must be registered and logged in to see this link.]
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - [You must be registered and logged in to see this link.]
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [You must be registered and logged in to see this link.]
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - [You must be registered and logged in to see this link.]
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: c:\windows\system32\lerizoke.dll c:\windows\system32\fapiyori.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli c:\windows\system32\lerizoke.dll

================= FIREFOX ===================

FF - ProfilePath -

============= SERVICES / DRIVERS ===============

R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2008-2-12 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2008-2-12 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2008-2-12 27776]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2008-2-12 10760]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2008-2-29 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-2-29 55024]
R2 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2008-2-12 4960]
R3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [2008-1-22 23296]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]

=============== Created Last 30 ================

2009-05-04 12:09 --d----- C:\ASTROLOG
2009-04-27 20:19 121 ---sh--- c:\windows\system32\uzipufag.ini
2009-04-27 20:19 383 ---sh--- c:\windows\system32\hewayope.exe
2009-04-11 01:23 --d----- c:\windows\system32\SoftwareDistribution
2009-04-10 20:20 186,136 a------- c:\windows\system32\wuaueng1.dll
2009-04-10 20:20 213,528 a------- c:\windows\system32\wuaucpl.cpl
2009-04-10 20:20 167,704 a------- c:\windows\system32\wuauclt1.exe
2009-04-08 01:14 --d----- c:\program files\Trend Micro

==================== Find3M ====================

2009-04-27 20:19 58,368 a--sh--- c:\windows\system32\fawehuja.exe
2009-02-10 15:04 360,580 a------- c:\windows\eSellerateEngine.dll

============= FINISH: 0:15:39.62 ===============

CG79
Intermediate
Intermediate

Posts Posts : 53
Joined Joined : 2008-12-09
OS OS : Windows XP
Points Points : 29424
# Likes # Likes : 0

View user profile

Back to top Go down

Re: After reboot 3 "Error loading" messages pop up...

Post by Belahzur on 6th May 2009, 1:16 pm

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\windows\system32\uzipufag.ini
    c:\windows\system32\hewayope.exe
    c:\windows\system32\fawehuja.exe

    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "felukuliho"=-
    "b8f30010"=-
    "CPMbbc0338c"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=-
    "AppInit_DLLs"=""
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00


  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245079
# Likes # Likes : 1

View user profile

Back to top Go down

Re: After reboot 3 "Error loading" messages pop up...

Post by CG79 on 6th May 2009, 2:57 pm

========== FILES ==========
c:\windows\system32\uzipufag.ini moved successfully.
c:\windows\system32\hewayope.exe moved successfully.
c:\windows\system32\fawehuja.exe moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\felukuliho deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\b8f30010 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CPMbbc0338c deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLs"|"" /E : value set successfully!
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\\"Notification Packages"|hex(7):73,63,65,63,6c,69,00,00 /E : value set successfully!

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05062009_105213

CG79
Intermediate
Intermediate

Posts Posts : 53
Joined Joined : 2008-12-09
OS OS : Windows XP
Points Points : 29424
# Likes # Likes : 0

View user profile

Back to top Go down

Re: After reboot 3 "Error loading" messages pop up...

Post by Belahzur on 6th May 2009, 3:07 pm

The errors should be gone now.

We can remove OTMoveIt now.

  • Please double-click OTMoveIt3.exe to run it again.
  • Press the green CleanUp! button.
  • Press Yes cleanup process prompt, do the same for the reboot prompt.
How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245079
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum