I went into Start / Control Panel / System / Advanced / StartUp and Recovery / Settings. Then under "System Failure" uncheck "Automatically restart". I did not get any bluescreens. I ran adaware and sypbot and they found nothing. I also ran mcafee stinger 1.9 from a disk and it did not find anything.
I also removed avast anti virus program and from the registry. I cannot do a system restore as it is showing no dates to restore to. Yes it is on and has been on for over a month. I cannot boot into safe mode because there is no boot tab in msconfig. Hitting F8 at startup only brings up boot devices. Remote process control is still not running when you check under services in msconfig. I rebooted several times but I still cannot connect to internet, apc ups sotware will not load, etc. I also ran hijack this program and included is the log file from my pc:
StartupList report, 11/19/2003, 3:20:07 PM
StartupList version: 1.52
Started from : F:\unzipped\hijackthis\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\rundll32.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\explorer.exe
F:\unzipped\hijackthis\HijackThis.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = F:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MSConfig = F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
--------------------------------------------------
Shell & screensaver key from F:\WINDOWS\SYSTEM.INI:
Shell=
SCRNSAVE.EXE=
drivers=
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=F:\WINDOWS\System32\ssbezier.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - F:\Program Files\Popup Manager\PopupMgr_1.0.1.5.dll - {08E74C67-99A6-45C7-94DA-A397A8FD8082}
(no name) - F:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll - {206E52E0-D52E-11D4-AD54-0000E86C26F6}
(no name) - F:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - F:\Program Files\SysShield Tools\Internet Eraser\PKExt.dll - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80}
--------------------------------------------------
Enumerating Download Program Files:
[QuickTime Object]
CODEBASE =
http://www.apple.com/qtactivex/qtplugin.cab
[{0E5F0222-96B9-11D3-8997-00104BD12D94}]
CODEBASE =
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
[{4226E9B7-D637-40E8-893A-13298AB41477}]
CODEBASE =
http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
[CustomerCtrl Class]
InProcServer32 = F:\WINDOWS\Downloaded Program Files\customerclient.dll
CODEBASE =
http://cs5b.instantservice.com/jars/cus ... gned35.cab
[{9732FB42-C321-11D1-836F-00A0C993F125}]
CODEBASE =
http://www.pcpitstop.com/mhLbl.cab
[Update Class]
InProcServer32 = F:\WINDOWS\System32\iuctl.dll
CODEBASE =
http://v4.windowsupdate.microsoft.com/C ... 7142013889
[Shockwave Flash Object]
InProcServer32 = F:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE =
http://download.macromedia.com/pub/shoc ... wflash.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: F:\WINDOWS\system32\SHELL32.dll
CDBurn: F:\WINDOWS\system32\SHELL32.dll
WebCheck: F:\WINDOWS\System32\webcheck.dll
SysTray: F:\WINDOWS\System32\stobject.dll
Remote process control is still not running.