dlh6213 27 Posting Maven Team Colleague

There's still something running from C:\Documents and Settings\Julian*\Local Settings\Temp
(O2 - BHO: CATLEvents Object - {2527BEEF-1B3C-4D3B-98F0-7F3C1EB910A0} - C:\DOCUME~1\JULIAN~1\LOCALS~1\Temp\avajxaf.dat)

*Can't read the whole name

Be sure you have it set to "Show hidden files and folders," and uncheck "Hide protected operating system files"

If you still can't find it, I may have the wrong path; do a Search for avajxaf.dat; delete it and anything else within that Temp folder.

Run hijackthis, go to Config\Misc tools\Delete a file on reboot, and enter the following:

C:\WINDOWS\Tasks\faxjava.exe

When asked to reboot, click No.

Scan with hijackthis and have it fix the following entries. Close all windows before you hit the "Fix checked" button.

O2 - BHO: CATLEvents Object - {2527BEEF-1B3C-4D3B-98F0-7F3C1EB910A0} - C:\DOCUME~1\JULIAN~1\LOCALS~1\Temp\avajxaf.dat
O4 - HKLM\..\Run: [*faxjava] C:\WINDOWS\Tasks\faxjava.exe
O4 - HKLM\..\RunOnce: [*faxjava] C:\WINDOWS\Tasks\faxjava.exe rerun

Reboot

Go to Start, Run, and type in regedit.

Before you edit the registry, you should make a backup. At the top of the Registry window, click on the Registry menu, click Export Registry File. In the Export range panel, click All, then save your registry as Backup.

Go to HKEY_LOCAL_MACHINE, SOFTWARE, Microsoft, Windows, CurrentVersion, RunOnce. Click on RunOnce to highlight it and look in the right-hand pane for faxjava.exe and delete it (and nothing else).

Reboot again, close all browser windows, scan with HJT, and post a new log please.

dlh6213 27 Posting Maven Team Colleague

You can find the Key in your Registry:
http://www.windowsreinstall.com/ins...d_in_regist.htm

dlh6213 27 Posting Maven Team Colleague

I don't know if this will fix the problems you're having, but let's get your system clean then fix the problems (if they still exist).

Reboot into Safe Mode

Open Windows Explorer, click on Tools, Folder Options, View, and select "Show hidden files and folders," and uncheck "Hide protected operating system files".

For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
Cookies
History
Local Settings\Temp
Local Settings\Temporary Internet Files\Content.IE5

Delete the entire content of
C:\Windows\Temp folder
C:\Temp folder

Do a search for *.tmp and delete everything found (hopefully your search function will work in Safe Mode)

Empty your Recycle Bin

Scan with HJT, and have it fix the following entries:

O2 - BHO: CATLEvents Object - {2527BEEF-1B3C-4D3B-98F0-7F3C1EB910A0} - C:\DOCUME~1\JULIAN~1\LOCALS~1\Temp\avajxaf.dat
O4 - HKLM\..\Run: [*faxjava] C:\WINDOWS\Tasks\faxjava.exe
O4 - HKLM\..\RunOnce: [*faxjava] C:\WINDOWS\Tasks\faxjava.exe rerun

Close all windows, other then HJT, before hitting the Fix button

Go to C:\WINDOWS\Tasks and delete faxjava.exe

Reboot normally

Go to Windows Update for updates (this may fix your WMP)

Close all browser windows, scan with HJT, and post a new log please.

dlh6213 27 Posting Maven Team Colleague

This thread:
http://www.daniweb.com/techtalkforums/thread5690.html
Has a link to a free firewall which is better then the one that comes with XP.

It also has links to SpywareBlaster and SpywareGaurd, which will prevent many companies from putting the stuff on your computer that cause the pop-ups. Keep them updated!

As previously suggested, use run Ad-Aware SE and Spybot regularly to catch things that get past your protection (yes, it will happen).

An alternative browser, such as Firefox or Opera, are recommended because they are less prone to unwanted intrusions. You need to keep Internet Explorer, however, as this is the only browser that you can get your Windows Updates with. Keeping Windows and IE updated will also help prevent pop-ups.

dlh6213 27 Posting Maven Team Colleague
dlh6213 27 Posting Maven Team Colleague

Hey Firedad, sorry, but I forgot to post the link before (seems I do that a lot). Here it is:
http://www.daniweb.com/techtalkforums/thread5690.html

dlh6213 27 Posting Maven Team Colleague

I don't see anything serious in your log, are you still having problems?

Here are a few questionable things, have HJT fix these if you don't recognize/use them:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forum.aria-nightclub.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/
O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com/
O9 - Extra button: MedionShop - {E05EC57C-ECD9-431C-981D-15573E34076E} - http://www.medionshop.de/ (file missing) (HKCU)
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} - http://www.errorguard.com/installation/Install.cab

As far as the admin rights go, I'm not really sure. Are you the only user on this computer?

dlh6213 27 Posting Maven Team Colleague

Post a hijackthis log, maybe that will help pinpoint it.

dlh6213 27 Posting Maven Team Colleague

Okay, there's no problem with wmpcd.exe; I kind of thought that might stand for Windows Media Player CD, but I couldn't find any info on it -- must be something new with ver. 10.

I don't see anything else bad in your log; are you still having problems?

dlh6213 27 Posting Maven Team Colleague

Can you get in touch with your friend and see if he has the drivers that came with the motherboard? I think that would be the easiest way to get it working.

As a second option, if you could give us the make & model number of the mobo, perhaps someone here can locate the drivers you need.

("Piggysue," that's cute!)

dlh6213 27 Posting Maven Team Colleague

Internet Explorer is the only browser you can use to get Windows Updates (as far as I know).

Getting the updates may fix your problem with WMP.

Run these free online scans to see if they find anything else:
http://www.pandasoftware.com/active...n_principal.htm
http://www.trendmicro.com/en/home/us/enterprise.htm
http://www.ravantivirus.com/scan/indexie.php

Go to this thread and follow the other recommendations:
http://www.daniweb.com/techtalkforums/thread5690.html
Then post a hijackthis log here; hopefully we can figure out why IE isn't working.

dlh6213 27 Posting Maven Team Colleague

Looks like there are two threads going on this one (http://www.daniweb.com/techtalkforums/thread16521.html) and it looks like it's been resolved so I'm going to close this one.

dlh6213 27 Posting Maven Team Colleague

Download LSPfix from here
On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "osmim.dll" (and nothing else), and move them to the "Remove" pane. Then click Finish.


Go to Add/Remove Programs in your Control Panel and remove (if found):
MyQuickSearch
ISTsvc

Scan with HJT and have it fix the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.munky.com/
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: mqsBar BHO - {0E677221-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: My &Quick Search - {0E677229-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL
O4 - HKLM\..\Run: [CfIg6CBon] C:\WINDOWS\ufvhtit.exe
O4 - HKLM\..\Run: [-
] C:\WINDOWS\ufvhtit.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [tapi32] C:\WINDOWS\System32\tapi32.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O23 - Service: ISEXEng - Unknown - C:\WINDOWS\System32\angelex.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service - Unknown - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: ScriptBlocking Service …

dlh6213 27 Posting Maven Team Colleague

This is a new motherboard for me and an upgrade in a puter.

Nancy, this new motherboard should have come with a CD (or floppy disk) containing all the drivers needed, did you install the drivers from that disk? They may not be the most up-to-date drivers, but they should allow it to work. You could also try the website for the motherboard manufaturer to get updated drivers for it.

Do I dare ask why you call yourself 'Pigkisser'? :eek:

dlh6213 27 Posting Maven Team Colleague

Well, there's not enough there to tell for sure, but it looks like it could be WildTangent. The best way for us to know for sure would be for you to post a hijackthis log in the Virus forum. Follow the recommendations in this thread, which also has a link to hijackthis, then post your log in the Virus forum.

dlh6213 27 Posting Maven Team Colleague

Update your Avast Antivirus and run a full system scan

Run these free online scans as well:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://www.trendmicro.com/en/home/us/enterprise.htm
http://www.ravantivirus.com/scan/indexie.php

1. Download and install Ad-Aware SE (http://www.lavasoftusa.com/software/adaware/), keeping the default options. However, some of the settings will need to be changed before your first scan

2. Close ALL windows except Ad-Aware SE

3. Click on the ‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the Preferences/Settings window

A.) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

Under Definitions:
*Prompt to udate outdated definitions - set the number of days

B.) Click on the ‘Scanning’ button on the left and select in green :

Under Driver, Folders & Files:
*Scan Within Archives

Under Select drives & folders to scan -
*choose all hard drives

Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file

C.) Click on the ‘Advanced’ button on the left and select in green:

dlh6213 27 Posting Maven Team Colleague

Update your Panda Antivirus and run a full system scan

Run these free online scans as well:
http://www.trendmicro.com/en/home/us/enterprise.htm
http://www.ravantivirus.com/scan/indexie.php

1. Download and install Ad-Aware SE (http://www.lavasoftusa.com/software/adaware/), keeping the default options. However, some of the settings will need to be changed before your first scan

2. Close ALL windows except Ad-Aware SE

3. Click on the ‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the Preferences/Settings window

A.) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

Under Definitions:
*Prompt to udate outdated definitions - set the number of days

B.) Click on the ‘Scanning’ button on the left and select in green :

Under Driver, Folders & Files:
*Scan Within Archives

Under Select drives & folders to scan -
*choose all hard drives

Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file

C.) Click on the ‘Advanced’ button on the left and select in green:

Under Shell Integration:

dlh6213 27 Posting Maven Team Colleague

...sometimes when i startup windows i get a police siren sound coming from my motherboard. Do you know why this is?

There may be something else that could cause this, but it sounds to me like the bearings in a fan are giving out; if that's the case, you should replace it ASAP, especailly if it's your CPU fan.

dlh6213 27 Posting Maven Team Colleague

CTHELPER.EXE should probably be disabled; quote from sysinfo:

CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative’s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it.

You're playing poker on your "g/f's mom's computer"?

dlh6213 27 Posting Maven Team Colleague

See if the suggestions in this thread help:
http://www.daniweb.com/techtalkforums/thread8169.html

dlh6213 27 Posting Maven Team Colleague

I believe what you are referring to are called 'Molex' connectors, as seen here:
http://www.8ballshardware.com/articles/sunbeamrheo/molex.jpg

They can all be connected at the same time, the only problem may be if your power supply can't supply enough power if all devices happen to be running at the same time (not a very likely scenario).

The purpose of the two connectors at the end is to do exactly what you want to do, connect both a hard drive and a CD-ROM (or two hard drives, CD & DVD, etc.) that are next to each other:
http://www.grosbill.com/aides/techaide/montage/images/molex.jpg

dlh6213 27 Posting Maven Team Colleague

Thanks crunchie! :D

I didn't get it by the end of the year, but less then six months anyway ;)

You're getting pretty close to 3,000 there :eek:

dlh6213 27 Posting Maven Team Colleague

Do you know this is a pirated version or just suspect it? Has it been activated yet? If it has, it should be legit. If it hasn't, that should be your first step -- if it is pirated, they'll let you know. Here is a list of phone numbers to call to activate:
http://www.microsoft.com/licensing/resources/vol/numbers.mspx

dlh6213 27 Posting Maven Team Colleague

Follow the recommendations in this thread:
http://www.daniweb.com/techtalkforums/thread5690.html

After you've run AdAware SE & Spybot, scan with hijackthis, but don't fix anything with it yet. Save the log and post it in the Virus forum.

dlh6213 27 Posting Maven Team Colleague

Do you play Close Combat?

Open Windows Explorer, click on Tools, Folder Options, View, and select "Show hidden files and folders," and uncheck "Hide protected operating system files".

For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
Cookies
History
Local Settings\Temp
Local Settings\Temporary Internet Files\Content.IE5

Delete the entire content of
C:\Windows\Temp folder
C:\Temp folder

Do a search for *.tmp and delete everything found

Empty your Recycle Bin

Then, go to http://members.aol.com/toadbee/hoster.zip to download Hoster

Run it and press "Restore Original Hosts," press "OK," and Exit Program.

Close all browser windows, scan with HJT, and have it fix the following entries:

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe

If IANA (IP 192.168.0.254) is not your ISP, have HJT fix this entry too:
O17 - HKLM\System\CCS\Services\Tcpip\..\{954F771D-85DA-4E9F-8808-322BE1B483C2}: NameServer = 192.168.0.254

Close all browser windows, scan with HJT, and post a new log please.

dlh6213 27 Posting Maven Team Colleague

Sorry about the R1 & R0 entries; thanks DMR. I totally missed that O4 WildTangent one too.

dlh6213 27 Posting Maven Team Colleague

There's probably more, but your log is still kind of long. Start with this:

Close all browser windows, scan with HJT, and have it fix the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.wildtangent.com/webdrive...all/Install.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/s...stemsoappro.cab

Were you able to run Spybot in Safe Mode? If so, run it again in Normal mode.

Close all browser windows, scan with HJT, and post a new log please.

dlh6213 27 Posting Maven Team Colleague

Just about anything the 'shop' can do, you can probably do yourself (including retrieving your data), so don't go there yet.

I only used ME for a few months, and that was a long time ago, but I believe if you boot with the ME CD, there is some sort of Recovery option; does anyone else know about this?

dlh6213 27 Posting Maven Team Colleague

Have a look through this thread, in particular, the posts by The DJ:
http://www.daniweb.com/techtalkforums/thread16103.html

dlh6213 27 Posting Maven Team Colleague

Update your Norton Antivirus and run a full system scan

Run these free online scans as well:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://www.trendmicro.com/en/home/us/enterprise.htm
http://www.ravantivirus.com/scan/indexie.php

1. Download and install Ad-Aware SE (http://www.lavasoftusa.com/software/adaware/), keeping the default options. However, some of the settings will need to be changed before your first scan

2. Close ALL windows except Ad-Aware SE

3. Click on the ‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the Preferences/Settings window

A.) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

Under Definitions:
*Prompt to udate outdated definitions - set the number of days

B.) Click on the ‘Scanning’ button on the left and select in green :

Under Driver, Folders & Files:
*Scan Within Archives

Under Select drives & folders to scan -
*choose all hard drives

Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file

C.) Click on the ‘Advanced’ button on the left and select in green:

dlh6213 27 Posting Maven Team Colleague

Reboot into Safe Mode

Scan with these again:
CWShredder
Spybot
Hijackthis

Have HJT fix the following entries:

R3 - Default URLSearchHook is missing
O2 - BHO: DOMP Class - {4C1B116F-2860-46db-8E6C-B4BFC4DFD683} - C:\WINDOWS\ietlbass.dll

Go to
C:\WINDOWS and delete ietlbass.dll

Reboot normally, close all browser windows, scan with HJT, and post a new log please.

dlh6213 27 Posting Maven Team Colleague

Try this:

Reboot into Safe Mode

Open Windows Explorer, click on Tools, Folder Options, View; select "Show hidden files and folders," and uncheck "Hide protected operating system files".

For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
Cookies
History
Local Settings\Temp
Local Settings\Temporary Internet Files\Content.IE5

Delete the entire content of
C:\Windows\Temp folder
C:\Temp folder

Do a search for *.tmp and delete everything found

Empty your Recycle Bin

Scan with HJT, and have it fix the F2 entry with winsock (yes, again)

While still in Safe Mode, go to Start, Run, and type in regedit; click OK and the registry editor will open.

Before you edit the registry, you should make a backup. At the top of the Registry window, click on the Registry menu, click Export Registry File. In the Export range panel, click All, then save your registry as Backup

Go to:
HKEY_LOCAL_MACHINE, SOFTWARE, Microsoft, Windows NT (not Windows), CurrentVersion, IniFileMapping, system.ini

Highlight system.ini and look in the right-hand pane for winsock; if found, right-click on it and delete it.

Exit the Registry Editor

Reboot normally, close all browser windows, scan with HJT, and post a new log please. Also tell us if you still get the winsock error message.

dlh6213 27 Posting Maven Team Colleague

To see what's there, you need to also uncheck 'Hide protected operating system files (Recommended)' Then you will be able to see Page files, Swap files, Recycle Bin, and anything else in there. You should remember to 'recheck' it when you're done.

I had a similar problem back in November, and alc6379 suggested this (and it worked):

Try booting to the recovery console on your Windows XP CD. If you can get into it that way, you won't be using any swap space, and should be able to format it.

Thanks Alex!

Some words of caution on my last post:

First, make sure you have everything important to you backed up on some media outside of the computer (CD's, flash drive, external hard drive, etc.); you never know what could go wrong.

I don't know how many drives/partitions you have on this computer, but when you use the Recovery Console to format, your drive letters will most likely be off by one letter. For instance, if you choose e:\, that will probably be what you commonly know as your 'f' drive. Before you format any drive, use the dir (Directory) command to be sure the drive you are about to format is indeed the one you want formatted.

The Directory command would look like this:
e:\>dir Then, when you hit Enter, the contents of the drive will be listed. The one you are looking to format should only have a couple of small files listed.

dlh6213 27 Posting Maven Team Colleague

I need to be able to show 'Before' and 'After' photos side-by-side and I can't at present. I would appreciate any suggestions you may have.

If you just want to show two (or more) pictures side-by-side, you can use Paint for that; you can have as many Paint windows open as you like.

dlh6213 27 Posting Maven Team Colleague

I can make a suggestion for thumbnail views, but I don't know if there is any way to view multiple 'Windows Picture and Fax Viewer' windows.

First, open a window containing some folders. In the top Menu Bar, click on the View tab, and choose Thumbnails.

Then click on the Tools tab, and Folder Options. Once there, click on the View tab; near the top will be a button that says 'Apply to All Folders'; click on that button, and then click on OK, and now all your folders should open with Thumbnail views.

dlh6213 27 Posting Maven Team Colleague

There are a couple of discussions here that may help:

http://www.daniweb.com/techtalkforums/thread11309.html
http://www.daniweb.com/techtalkforums/thread12883.html

I've been using Norton for years without any problem, but I plan to replace it with SystemMechanic5 and AVG (antivirus) to see which I like better. There's another AV that Catweazle recommends in that second thread that I may try as well (eventually).

dlh6213 27 Posting Maven Team Colleague

Have SP2 and getting a clicking sound coming out of your speakers now? Check this thread:
http://www.daniweb.com/techtalkforums/thread16616.html

dlh6213 27 Posting Maven Team Colleague

To see what's there, you need to also uncheck 'Hide protected operating system files (Recommended)' Then you will be able to see Page files, Swap files, Recycle Bin, and anything else in there. You should remember to 'recheck' it when you're done.

I had a similar problem back in November, and alc6379 suggested this (and it worked):

Try booting to the recovery console on your Windows XP CD. If you can get into it that way, you won't be using any swap space, and should be able to format it.

Thanks Alex!

dlh6213 27 Posting Maven Team Colleague

Maybe we should all get a turn here :)

There's still stuff in Temp folders, please do the following:

Open Windows Explorer, click on Tools, Folder Options, View; select "Show hidden files and folders," and uncheck "Hide protected operating system files".

For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
Cookies
History
Local Settings\Temp
Local Settings\Temporary Internet Files\Content.IE5

Delete the entire contents of:
C:\Windows\Temp folder
C:\Temp folder

Do a search for *.tmp and delete everything found

Empty your Recycle Bin

Post a new log as requested by crunchie.

dlh6213 27 Posting Maven Team Colleague

Try this:

Reboot into Safe Mode

Open Windows Explorer, click on Tools, Folder Options, View; select "Show hidden files and folders," and uncheck "Hide protected operating system files".

For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
Cookies
History
Local Settings\Temp
Local Settings\Temporary Internet Files\Content.IE5

Delete the entire content of
C:\Windows\Temp folder
C:\Temp folder

Do a search for *.tmp and delete everything found

Empty your Recycle Bin

Scan with HJT, and have it fix the F2 entry with winsock (yes, again)

While still in Safe Mode, go to Start, Run, and type in regedit; click OK and the registry editor will open.

Before you edit the registry, you should make a backup. At the top of the Registry window, click on the Registry menu, click Export Registry File. In the Export range panel, click All, then save your registry as Backup

Go to:
HKEY_LOCAL_MACHINE, SOFTWARE, Microsoft, Windows NT (not Windows), CurrentVersion, IniFileMapping, system.ini

Highlight system.ini and look in the right-hand pane for winsock; if found, right-click on it and delete it.

Exit the Registry Editor

Reboot normally, close all browser windows, scan with HJT, and post a new log please. Also tell us if you still get the winsock error message.

dlh6213 27 Posting Maven Team Colleague

this is the error message.

KERNAL_STACK_INPAGE_ERROR

See if this helps at all:
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q315266

dlh6213 27 Posting Maven Team Colleague

Open Windows Explorer, click on Tools, Folder Options, View, and select "Show hidden files and folders," and uncheck "Hide protected operating system files".

For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
Cookies
History
Local Settings\Temp
Local Settings\Temporary Internet Files\Content.IE5

Delete the entire content of
C:\Windows\Temp folder
C:\Temp folder

Do a search for *.tmp and delete everything found

Then, go to http://members.aol.com/toadbee/hoster.zip to download Hoster

Run it and press "Restore Original Hosts," press "OK," and Exit Program.

Go to Windows Update to get the Critical Updates for your system. Hold off on SP2, however, until your sytem has been cleaned up.

Reboot, close all browser windows, scan with HJT, and post a new log please.

dlh6213 27 Posting Maven Team Colleague

There are a couple of things not related to malware that could also be causing the problem:

Overheating
Memory problem

Possible solutions:

Have you cleaned inside your computer lately? Use caution, and a wrist strap, when doing this to avoid damage. Make sure all the fans are clean, running, and not making any funny noises (Power Supply fan, CPU fan, and case fan).

Does your computer report the actual amount of RAM you have installed? Have you added any recently? Sometimes just removing RAM and reinstalling it helps.

dlh6213 27 Posting Maven Team Colleague

If it won't boot up at all anymore, the only way I know to back it up would be to put into a computer as a slave drive -- either in another computer you have, or in this one after you get a new drive installed and setup.

dlh6213 27 Posting Maven Team Colleague

One more thought, have you tried System Restore yet? That may help enough to at least let you install what you need to fix whatever is wrong.

dlh6213 27 Posting Maven Team Colleague

danniboy and dlh, thank you so much for the advice, here's my problem, lol. i took your advice, went to lavasoft to download the ad aware personal, but this popup that i've told you about comes on before it finishes downloading, so i've tried several times and i get kicked of the internet everytime and it says, download interrupted failed to finish or whatever. so......i went out today and bought a anti-virus program, tryed to install it several, several times and i cant get it to work either, so........please help me, lol. this is driving me crazy i cant figure out what to do next, seems i've tried so many things and nothing succeeds. thx again for the help, hopefully you'll know something else i can try. i appreciate your time, ty. mona.

Does this mean you were on the net without antivirus protection? :eek:

I don't know what program you purchased, but most will allow you to boot from the CD to do a scan; check and see if yours will do that.

If you can't install any programs that will help, or that will allow us to see what you have in order to assist you, Danniboy may be right, you may need to reinstall Windows. :(

You may wish to have a look at this thread for some protection advice:
http://www.daniweb.com/techtalkforums/thread16365.html

dlh6213 27 Posting Maven Team Colleague

I agree with oalee, I don't know of any malware that can damage hardware. It's either worn out, or has a manufacturing defect.

dlh6213 27 Posting Maven Team Colleague

XP can be used for 30 days without activating; sometime before the 30 days is up, it needs to be activated. Each XP CD can only be activated on one computer at a time. Even if it's a copy, the codes are embedded so it can't be activated on more then one computer (it would have to be removed from one computer before it could be activated on another).

dlh6213 27 Posting Maven Team Colleague

If you suspect a fan is not working properly, you should replace it before you have major problems.

Close all browser windows, scan with HJT, and have it fix the following entries:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O20 - AppInit_DLLs: KATRACK.DLL
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe (file missing)

I can't find any info on this one (in English), so if you don't know what is you can either have HJT fix it, or go to the C:\WINDOWS\Web folder to see if you can find out more about it: O8 - Extra context menu item: Read It! - C:\WINDOWS\Web\toyagt.htm

Is 'deacnet.wfu.edu' your ISP? If not, have HJT fix all three O17 entries

To help your computer boot faster, check here for recommendations on Service configurations:
http://www.blackviper.com/WinXP/servicecfg.htm
And here for more info on processes:
http://www.liutilities.com/products/wintaskspro/processlibrary/

Does anyone know why HJT is 'Unable to get Internet Explorer version!'?

dlh6213 27 Posting Maven Team Colleague

It's possible I could have overlooked something, but I don't see anything in your log that would cause a problem.

Why couldn't you boot into Safe Mode?

It's possible your hard drive could be giving out; you may want to back everything up, and get another hard drive, just in case.