+ Reply to Thread
Page 2 of 3
FirstFirst 1 2 3 LastLast
Results 11 to 20 of 22
  1. #11
    Senior Member
    Join Date
    May 2005
    Posts
    1,017

    Default Re: need help reinstalling windows

    Sorry, to search for the file your just goto your

    Start>Search>File of Folders>All files and folders>

    Now type the word "Hosts" into the box labeled "All or part of the file name"

    change the "look in" part to "Local Hard drives (C"

    then click search, and it should find a file called hosts which you can open up with notepad

  2. #12
    Junior Member
    Join Date
    Jun 2006
    Posts
    12

    Unhappy Re: need help reinstalling windows

    Quote Originally Posted by Tech-Master
    Sorry, to search for the file your just goto your

    Start>Search>File of Folders>All files and folders>

    Now type the word "Hosts" into the box labeled "All or part of the file name"

    change the "look in" part to "Local Hard drives (C"

    then click search, and it should find a file called hosts which you can open up with notepad
    i don't believe this i have tried 2 open the search but it came up has a blank screen i could do a search which is a pain in the backside,i have even tried 2 install norton internet security this morning but i can't even finish the installation i think i will have 2 get some 1 in 2 have a look

  3. #13
    Senior Member
    Join Date
    May 2005
    Posts
    1,017

    Default Re: need help reinstalling windows

    Ok before you call someone in , just try one more thing for me first.

    can you download "hijackthis" software, (link is in right column on this page, under free tools) and follow these instructions carefully

    Install hijackthis on your pc, but change the install path to C:\hijack rather then the default one,

    Run the program and click on "Do a system scan and save a log file", this will open up your log file in notepad, cut and paste the contents of your log file and post it back to me here.

    I will take a look and see if i can spot any problems.

    thanks

  4. #14
    Junior Member
    Join Date
    Jun 2006
    Posts
    12

    Talking Re: need help reinstalling windows

    right ok i have done what u have ask i will have 2 sent it 2 u in 2 halves i hope u r ready 4 this.

    Logfile of HijackThis v1.99.1
    Scan saved at 15:36:45, on 06/28/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton GoBack\GBPoll.exe
    C:\Program Files\KService\KService.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\vsnpstd2.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\program files\common files\system\mplay64.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Browser Mouse\mouse32a.exe
    C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Mini Oddie\MiniOddie.exe
    C:\Program Files\AIM\aim.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\PROGRA~1\INCRED~1\bin\IMApp.exe
    C:\Program Files\PromptCast\PromptCast.exe
    C:\WINDOWS\kdx\KHost.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\SoftKey\Calendar Creator 4.0\CCSCHED.EXE
    C:\Program Files\Climate Change Experiment\cpdnbbcmgr.exe
    C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
    C:\Program Files\Climate Change Experiment\boinc.exe
    C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Climate Change Experiment\projects\bbc.cpdn.org\hadcm3trans_5.08_ windows_intelx86.exe
    C:\Program Files\Climate Change Experiment\projects\bbc.cpdn.org\hadcm3transum_5.0 8_windows_intelx86.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Documents and Settings\nicola\My Documents\unzipped\hijackthis[1]\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link...//uk.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - <default> - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\mllmj.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\toolbar.dll
    O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\msudd32.dll
    O3 - Toolbar: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\toolbar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus -

  5. #15
    Junior Member
    Join Date
    Jun 2006
    Posts
    12

    Default Re: need help reinstalling windows

    this is the second half

    {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MPlay64] c:\program files\common files\system\mplay64.exe /noerrorinfo
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
    O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MP3Collection] rundll32.exe C:\WINDOWS\System32\MSA64CHK.dll,DllMostrar Matrix_HTML:MP3Collection:t
    O4 - HKCU\..\Run: [Mini Oddie] C:\Program Files\Mini Oddie\MiniOddie.exe
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [PromptCast] C:\Program Files\PromptCast\PromptCast.exe
    O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
    O4 - HKCU\..\Run: [PuppyluvNB.exe] C:\DOWNLO~1\PUPPYL~1.EXE /r
    O4 - Startup: Calendar Creator Scheduler.lnk = C:\Program Files\SoftKey\Calendar Creator 4.0\CCSCHED.EXE
    O4 - Startup: Climate Change Experiment Manager.lnk = C:\Program Files\Climate Change Experiment\cpdnbbcmgr.exe
    O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZZ
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?404a7670b4cf47ce93b0341d3a944a
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?404a7670b4cf47ce93b0341d3a944a
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
    O9 - Extra button: MP3Collection - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\system32\MP3Collection (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
    O15 - Trusted Zone: http://click.getmirar.com (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {DFD181E0-5E2F-11CE-A449-00AA004A803D} - file://C:\PROGRAM FILES\ENGLISH NATURE\html\mspert10.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...90/mcfscan.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: iniwin32.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: mllmj - C:\WINDOWS\system32\mllmj.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton GoBack\GBPoll.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

  6. #16
    Senior Member
    Join Date
    May 2005
    Posts
    1,017

    Default Re: need help reinstalling windows

    Ok great, its going to take a while to study, but i will post back my findings and further instructions as soon as i can.

    thanks

  7. #17
    Junior Member
    Join Date
    Jun 2006
    Posts
    12

    Default Re: need help reinstalling windows

    C:\Documents and Settings\jade\Cookies\jade@ehg-etoys.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-hasbro.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-hitent.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-hollywood.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-mothercare.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-playboy.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-telewest.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-tigerdirect2.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@server.lon.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@image.masterstats[1].txt -> TrackingCookie.Masterstats : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@data2.perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@data4.perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@overture[1].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@reduxads.valuead[2].txt -> TrackingCookie.Valuead : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@web-stat[2].txt -> TrackingCookie.Web-stat : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@www.web-stat[1].txt -> TrackingCookie.Web-stat : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@free.wegcash[2].txt -> TrackingCookie.Wegcash : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@programs.wegcash[2].txt -> TrackingCookie.Wegcash : No action taken.
    C:\Documents and Settings\jade\Cookies\jade@yadro[1].txt -> TrackingCookie.Yadro : No action taken.
    C:\WINDOWS\SYSTEM32\mllmj.dll -> Trojan.Crypt.o : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD10.tmp\UWFX6_0001_N69M1503NetInst aller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD11.tmp\UWFX6_0001_N69M1503NetInst aller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD2.tmp\UWFX6_0001_N69M0903NetInsta ller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD4.tmp\UWFX6_0001_N69M0903NetInsta ller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD5.tmp\UWFX6_0001_N69M0903NetInsta ller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD6.tmp\UWFX6_0001_N69M1503NetInsta ller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD7.tmp\UWFX6_0001_N69M1503NetInsta ller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD8.tmp\UWFX6_0001_N69M1503NetInsta ller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\ICD9.tmp\UWFX6_0001_N69M1503NetInsta ller.exe -> Trojan.Fakealert : No action taken.
    C:\Documents and Settings\jade\Local Settings\Temp\NI.UWA6P_0001_N68M2301\setup.exe -> Trojan.Fakealert : No action taken.
    C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP373\A0172377.exe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX6_0001_N69M0903NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX6_0001_N69M1503NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWFX6_0001_N69M0903NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWFX6_0001_N69M1503NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWFX6_0001_N69M0903NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWFX6_0001_N69M1503NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.4\UWFX6_0001_N69M1503NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UWFX6_0001_N69M1503NetInstaller.e xe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\UWFX6_0001_N69M0903NetInstaller.exe -> Trojan.Fakealert : No action taken.
    C:\WINDOWS\Downloaded Program Files\UWFX6_0001_N69M1503NetInstaller.exe -> Trojan.Fakealert : No action taken.
    C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP368\A0156133.exe -> Trojan.LowZones.dm : No action taken.
    C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP377\A0175879.exe -> Trojan.LowZones.dm : No action taken.
    C:\WINDOWS\SYSTEM32\intell321.exe -> Trojan.Small.ev : No action taken.
    C:\pj.exe -> Trojan.Small.ev : No action taken.
    C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP376\A0172657.dll -> Trojan.Small.hr : No action taken.
    C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP396\A0185653.dll -> Trojan.Small.hr : No action taken.
    C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll -> Trojan.Small.hr : No action taken.
    C:\WINDOWS\i386\jscript.dl_/jscript.dll -> Trojan.Small.hr : No action taken.


    ::Report end

  8. #18
    Junior Member
    Join Date
    Jun 2006
    Posts
    12

    Default Re: need help reinstalling windows

    good luck with looking at all of this,sorry about this but i would like 2 say thanx 4 helping me

  9. #19
    Senior Member
    Join Date
    May 2005
    Posts
    1,017

    Default Re: need help reinstalling windows

    Ok, we are getting somewhere now, you have quite a lot of problems, you will need to following these instructions now, some of it is repeated from before but do it anyway.

    Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

    Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.

    -----------------

    DISABLE ANTISPYWARE PROTECTION

    Please disable your Windows Defender Real-time Protection, as it may hinder the removal of some entries.
    • Open Windows Defender.
    • Click on Tools, General Settings.
    • Scroll down and uncheck Turn on real-time protection (recommended).
    • After you uncheck this, click on the Save button and close Windows Defender.
    --------------------

    DOWNLOADS

    Download and install CleanUp! but do not run it yet.

    *WARNING* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.

    -----------------

    Download Ewido Anti-Malware
    • Install Ewido Anti-Malware
    • Double-click the icon on Desktop to launch Ewido
    You will need to update Ewido to the latest definition files.
    • On the top of the main screen click Shield
    • Click the word active to change it to inactive
    • On the top of the main screen click Update.
    • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
    If you are having problems with the updater, you can use this link to manually update Ewido
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    • Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    When you have finished updating, EXIT Ewido anti-spyware. Do Not run a scan just yet, we will shortly.

    ---------------------

    Please download E2TakeOut by RubbeR DuckY from here:

    http://www.malwarebytes.org/E2TakeOut.zip
    • Extract the file to your Desktop
    • Double click E2TakeOut.exe
    • Click the Begin Removal button
    • Wait until the program is finished scanning
    • Once done, it will produce a popup stating that the infection has been found and you need to reboot you computer to complete the removal
    • Reboot your computer
    • Once your computer has rebooted E2TakeOut will open and produce a report
    • Please copy/paste that report into your next reply.
    ------------------

    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to run it.
    • Put a check next to Run VundoFix as a task.
    • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
    • When VundoFix re-opens, click the Scan for Vundo button.
    • Once it's done scanning, click the Remove Vundo button.
    • You will receive a prompt asking if you want to remove the files, click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will shutdown your computer, click OK.
    • Turn your computer back on.
    • Please post the contents of C:\vundofix.txt and a new HiJackThis log in your reply.
    -----------------------

    DISCONNECT FROM THE INTERNET

    Please disconnect from the Internet by turning off your modem until we run the online scan later in the fix. One of the infections on your system spreads via modem connections.

    -----------------

    UNREGISTER DLL

    Click Start > Run

    Type the following text in the run box and click OK:



    Quote:
    regsvr32 /u "C:\WINDOWS\system32\msa64chk.dll"



    Please click OK to any dialog box that appears.


    -------------------


    SAFE MODE

    Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers.

    -----------------------

    ADD/REMOVE PROGRAMS

    Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs (if they exist):

    Neopets
    MyWebSearch
    MySearchBar
    Viewpoint
    Viewpoint Toolbar


    ----------------

    FIXES WITH HIJACK THIS

    Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (make sure you do not miss any)

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - <default> - (no file)
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\toolbar.dll
    O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\msudd32.dll
    O3 - Toolbar: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\toolbar.
    O4 - HKLM\..\Run: [MPlay64] c:\program files\common files\system\mplay64.exe /noerrorinfo
    O4 - HKCU\..\Run: [MP3Collection] rundll32.exe C:\WINDOWS\System32\MSA64CHK.dll,DllMostrar Matrix_HTML:MP3Collection:t
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...arch.jhtml?p=ZZ
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
    O9 - Extra button: MP3Collection - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\system32\MP3Collection (file missing)
    O15 - Trusted Zone: http://click.getmirar.com (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)


    Please remember to close all other windows, including browsers then click Fix checked.

    --------------------

    FILE DELETIONS

    Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.

    C:\PROGRAM FILES\Neopets
    C:\WINDOWS\system32\msudd32.dll
    c:\program files\common files\system\mplay64.exe
    C:\WINDOWS\System32\MSA64CHK.dll
    C:\Program Files\Viewpoint
    C:\Program Files\MyWebSearch
    C:\WINDOWS\system32\MP3Collection


    -------------------------


    CLEANUP!

    Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
    *Click "Options..."
    *Move the arrow down to "Custom CleanUp!"
    *Put a check next to the following:
    • Empty Recycle Bins
    • Delete Cookies
    • Delete Prefetch files
    • Cleanup! All Users
    • Click on the “Temporary Files” and uncheck the box for “Scan drives for file matching” if it’s checked.
    Click OK
    Press the CleanUp! button to start the program. DO NOT reboot/logoff when prompted.

    -------------------------

    EWIDO

    Run Ewido with it's updated definitions...it's important that all windows must be closed)
    • Click Scanner
    • Click on the Scan tab
    • Click Complete System Scan to begin scanning.

      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).
    Restart in normal mode.

    ------------------

    ONLINE SCAN

    Reconnect to the Internet and perform an online scan with Internet Explorer with Panda ActiveScan

    Click on the "Free To Use ActiveScan" located on the top right hand corner
    1. Click Check Now and a "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
    2. Enter your e-mail address, country, and state & click Scan Now * The download of the 8 MB Panda's ActiveX control will take place *
    Begin the scan by selecting My Computer
    • If it finds any malware, it will offer you a report.
    • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
    • Click on See report then click Save report
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
    * Turn off the real time scanner of any existing antivirus program while performing the online scan


    Paste the Panda Scan report here together with a new HiJackThis log, Ewido's log, the log from C:\vundofix.txt and the log from E2TakeOut.

  10. #20
    Junior Member
    Join Date
    Jun 2006
    Posts
    12

    Default Re: need help reinstalling windows

    hi there.i would like 2 say a very big thanx u 2 u 4 trying 2 help me out but i have now had the system cleaned and it is all working well.
    i don't know what 2 say 2 u but u have been a great help i will remember u in the future,take care and thanx very much (a big hug)

Similar Threads

  1. formatting/reinstalling
    By mucker2 in forum Windows XP Help
    Replies: 5
    Last Post: 28-01-2008, 07:49 PM
  2. Strange probs' after reinstalling XP
    By Benson in forum Windows XP Help
    Replies: 1
    Last Post: 04-08-2007, 10:49 PM
  3. Re: need help reinstalling windows
    By john in forum Windows XP Help
    Replies: 1
    Last Post: 20-12-2006, 05:49 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts