I have this icon in my taskbar that keeps popping up and it really gets annoying it says system alert and when u click on it , it opens up a web page, I have downloaded HJT and here is my log,, PLease help as soon as possible,, thank you
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:20:26 AM, on 7/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS.1\System32\smss.exe
C:\WINDOWS.1\system32\winlogon.exe
C:\WINDOWS.1\system32\services.exe
C:\WINDOWS.1\system32\lsass.exe
C:\WINDOWS.1\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS.1\System32\svchost.exe
C:\WINDOWS.1\system32\spoolsv.exe
C:\WINDOWS.1\Explorer.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm?rev=10238
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1180471111670
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181139321000
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.gamehouse.com/realarcade-webgames/bejeweled2/popcaploader.cab
O22 - SharedTaskScheduler: biocomputing - {98ca7898-6029-41ab-8f67-ea4f5e1afc22} - C:\WINDOWS.1\system32\myqlejy.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 4392 bytes

Recommended Answers

All 8 Replies

==Download SmitfraudFix (by S!Ri) from http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract the content (a folder named SmitfraudFix) to your Desktop.
- Restart your computer in safe mode.
- Open the SmitfraudFix folder and double-click smitfraudfix.cmd, select option #2 [type 2 and Enter]
You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer Y and Enter [which will remove the desktop background and clean registry keys associated with the infection].
The tool will next check if wininet.dll is infected- if it is you will be prompted to replace the file ; type Y and press "Enter".
It will also create a log named rapport.txt in the root of your drive, eg: Local Disk C:\
Reboot into normal Windows.
[You may also have to restore your desktop background...
If so, go Start >run, type regedit and <enter>. Navigate to this key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
Please export that key: in the left pane highlight system with a lclick, go File, export... , save as bluewall with file type .txt. Close regedit and post that txt file.]
Combofix:
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.
Post the logs from Smitfraudfix, ComboFix and a new HT log.

I did try the smitfraudfix,, it did not work but the combofix did.. I thank you so very much... here is the txt from that


"Mr & Mrs Al Rhoden" - 2007-07-11 9:59:29 - ComboFix 07-07-10.1 - Service Pack 2 FAT32


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS.1\system32\myqlejy.dll


((((((((((((((((((((((((( Files Created from 2007-06-11 to 2007-07-11 )))))))))))))))))))))))))))))))


2007-07-11 09:57 51,200 --a------ C:\WINDOWS.1\nircmd.exe
2007-07-11 09:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.1\APPLIC~1\WinZip
2007-07-11 09:45 9,393,768 --a------ C:\Program Files\winzip111.exe
2007-07-10 20:40 76,560 --a------ C:\WINDOWS.1\system32\drivers\tmcomm.sys
2007-07-10 18:18 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-07-10 17:47 <DIR> d-------- C:\DOCUME~1\MR&MRS~1\APPLIC~1\InstallShield
2007-07-10 15:24 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-07-10 14:14 <DIR> d-------- C:\Program Files\hi
2007-07-10 11:06 77,312 --a------ C:\WINDOWS.1\ua2.dll
2007-07-10 10:20 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-10 09:59 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-07-10 07:42 <DIR> d-------- C:\Program Files\Windows Defender
2007-07-09 11:50 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.1\APPLIC~1\PC Tools
2007-07-09 10:17 <DIR> d-------- C:\DOCUME~1\MR&MRS~1\.housecall6.6
2007-07-09 09:24 <DIR> d-------- C:\DOCUME~1\MR&MRS~1\APPLIC~1\Google
2007-07-09 09:19 626,688 --a------ C:\WINDOWS.1\system32\msvcr80.dll
2007-07-09 09:14 <DIR> d-------- C:\Program Files\Google
2007-07-09 09:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.1\APPLIC~1\Google
2007-07-09 08:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.1\APPLIC~1\TEMP
2007-06-23 23:24 9,464 --------- C:\WINDOWS.1\system32\drivers\cdralw2k.sys
2007-06-23 23:24 9,336 --------- C:\WINDOWS.1\system32\drivers\cdr4_xp.sys
2007-06-23 23:24 43,528 --------- C:\WINDOWS.1\system32\drivers\PxHelp20.sys
2007-06-23 23:24 129,784 --------- C:\WINDOWS.1\system32\pxafs.dll
2007-06-17 15:58 <DIR> d-------- C:\WINDOWS.1\system32\LogFiles
2007-06-17 15:58 <DIR> d-------- C:\WINDOWS.1\system32\drivers\UMDF
2007-06-13 12:04 <DIR> d-------- C:\WINDOWS.1\SxsCaPendDel


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-05 00:31:28 21,822,168 ----a-w C:\Program Files\AdbeRdr80_en_US.exe
2007-05-31 14:02:24 278,528 ----a-w C:\WINDOWS.1\system32\livesnth.dll
2007-05-31 00:49:52 -------- d-----w C:\Program Files\Common Files\xing shared
2007-05-31 00:49:36 -------- d-----w C:\Program Files\Common Files\Real
2007-05-31 00:49:22 -------- d-----w C:\Program Files\Real
2007-05-31 00:43:42 -------- d-----w C:\DOCUME~1\MR&MRS~1\APPLIC~1\Real
2007-05-29 20:51:08 -------- d-----w C:\Program Files\Panicware
2007-05-29 20:50:56 488,032 ----a-w C:\Program Files\PopUpStopperFree.exe
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS.1\system32\inetcomm.dll
2007-05-09 18:21:22 335 ----a-w C:\WINDOWS.1\nsreg.dat
2007-05-09 18:12:06 1,632 ----a-w C:\WINDOWS.1\system32\d3d8caps.dat
2007-05-09 17:55:54 21,640 ----a-w C:\WINDOWS.1\system32\emptyregdb.dat
2007-04-25 14:21:16 144,896 ----a-w C:\WINDOWS.1\system32\schannel.dll
2007-04-18 16:12:24 2,854,400 ----a-w C:\WINDOWS.1\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS.1\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS.1\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS.1\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS.1\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS.1\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS.1\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS.1\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS.1\system32\wups2.dll
2007-04-17 02:44:20 271,224 ----a-w C:\WINDOWS.1\system32\mucltui.dll
2007-04-17 02:43:40 208,248 ----a-w C:\WINDOWS.1\system32\muweb.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-30 20:49]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS.1^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS.1\pss\Google Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopUpStopperFreeEdition]
"C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide


Contents of the 'Scheduled Tasks' folder
2007-07-10 14:15:06 C:\WINDOWS.1\tasks\Windows Update.job
2007-07-11 14:00:42 C:\WINDOWS.1\tasks\MP Scheduled Scan.job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-11 10:00:48
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-11 10:01:25
C:\ComboFix-quarantined-files.txt ... 2007-07-11 10:01

--- E O F ---
here are the quarintined files

2007-05-09 13:49      8704    --a------    C:\Qoobox\Quarantine\C\WINDOWS.1\system32\myqlejy.dll.vir


Folder PATH listing
Volume serial number is 3440-10F6
C:\QOOBOX
\---Quarantine
    +---Registry_backups
    \---C
        \---WINDOWS.1
            \---system32
                    myqlejy.dll.vir

Lisa, please delete the smitfraudfix folder in C:\ and the zip file, dl a new copy and start it in normal mode as before, but this time run the check, ie enter 1 [not 2], cos I would like to see the log...
Also rename hijackthis.exe to hiscan.exe and post a fresh log pls.
Delete c:\qoobox folder and contents.

here is the scan from smitfraudfix...
SmitFraudFix v2.202

Scan done at 8:24:32.14, Thu 07/12/2007
Run from
C:\Documents and Settings\Mr & Mrs Al Rhoden\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS.1\System32\smss.exe
C:\WINDOWS.1\system32\winlogon.exe
C:\WINDOWS.1\system32\services.exe
C:\WINDOWS.1\system32\lsass.exe
C:\WINDOWS.1\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS.1\System32\svchost.exe
C:\WINDOWS.1\system32\spoolsv.exe
C:\WINDOWS.1\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS.1\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS.1


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS.1\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS.1\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS.1\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS.1\system32\LogFiles

here is the log file from hiscan.exe
Logfile of HijackThis v1.99.1
Scan saved at 8:27:57 AM, on 7/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS.1\System32\smss.exe
C:\WINDOWS.1\system32\winlogon.exe
C:\WINDOWS.1\system32\services.exe
C:\WINDOWS.1\system32\lsass.exe
C:\WINDOWS.1\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS.1\System32\svchost.exe
C:\WINDOWS.1\system32\spoolsv.exe
C:\WINDOWS.1\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Mr & Mrs Al Rhoden\Desktop\hiscan.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm?rev=10240
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.prevx.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.prevx.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.prevx.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1180471111670
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181139321000
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS.1\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS.1\system32\WPDShServiceObj.dll

Thank you for that, Lisa. Looks like you're clean to go and play again.
By the way, you do realise that you have two windows installations in C:\ ? Windows and Windows.1? You could safely remove the unused one.
Cheers.

Thank you for that, Lisa. Looks like you're clean to go and play again.
By the way, you do realise that you have two windows installations in C:\ ? Windows and Windows.1? You could safely remove the unused one.
Cheers.

This computer was given to my husband and I from the sergeant at the National Guard Armory and I don't know exactly what is on here, How do I get rid of the one? and how do I know which one I am using?.. When the sergeant gave us this computer his girlfriend locked everything up and he couldn't even access his own files or get on the internet, he then found out she was cheating on him with another military man, so he got rid of her and now we just found yesterday that he got married to someone else and its been less than 4 months he has been with this other woman.. talk about jumping into stuff...LOL..

now I see I am using windows 1 ..how do i get rid of the other one?

Hehe.... er... thank you for that backgrounding ... :) [du wanna find the secret stuff?]
Just for a start could I see your boot.ini file? Go control panel > system, advanced tab, start up and recovery settings. Hit the edit button and post that notepad that opens.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.