caperjack 875 I hate 20 Questions Team Colleague

as it shuts down i get a message that says something like cannot read from vx000000x1 or some crap like that. (2 512s)

post the full crappy error message might help :)

caperjack 875 I hate 20 Questions Team Colleague

Post a fresh hijackthis log ,don't fix anything with it yet !:)

caperjack 875 I hate 20 Questions Team Colleague

If using AD-AWare set it up like this so it scans deeper!:)
Might i suggest Ad-Aware
Download the latest version of Ad-Aware at http://www.lavasoftusa.com/support/download/

After installing AAW, and before running the program, you NEED to FIRST update the reference file following these instructions. http://www.lavahelp.com/howto/updref/index.html

Now do the following:

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."

Press "Scan Now"

- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:

Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"

Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.

Finally, close Ad-Aware, and reboot.
That ought to get rid of most of your spyware.

caperjack 875 I hate 20 Questions Team Colleague

Hi ,make sure allbrowser windows are closed and run hijack and check the box nex to these and have hijack FIX them .

If yahoo is you main start and search page leave these, but fix if it isn't.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cus...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/cus...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cus...//www.yahoo.com


If you didn't add this to your Host file ,Fix it

O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com

Fix these
O4 - HKLM\..\Run: [Winsock2 driver] MVDXDLSY.EXE

O4 - HKCU\..\RunOnce: [Winsock2 driver] MVDXDLSY.EXE

Reboot into safe mode hitting f8 on bootup and search and find and delete this file === MVDXDLSY.EXE,
First but please if you will zip it and email it to me at this address .Dodger97@hotmail.com

Reboot and run hijack and post a new log thanks

caperjack 875 I hate 20 Questions Team Colleague

So do all other programs install without a problem.

caperjack 875 I hate 20 Questions Team Colleague

Your post title is missleading ,as you have surround sound ,just not in musicmatch and windows sounds !:)I don't use either sorry,as i like WMP

caperjack 875 I hate 20 Questions Team Colleague

Do you ahve a virus scan program .If Yes do a scan ,also run the online scan in my signature .
If you want you could get HIJACKTHIS in my signature and run it don't fix anything yet
, and post a log ,
How to download and use hijackthis -- http://www.netstar.me.uk/hjt/hjt.html

caperjack 875 I hate 20 Questions Team Colleague

try running a virus scan!:)

caperjack 875 I hate 20 Questions Team Colleague

I think you could start by removing newdotnet via add/remove programs if its not there then remove it in hijackthis
Then run hijack again and fix these !
O3 - Toolbar: DashBar Toolbar - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - C:\PROGRAM FILES\DASHBAR\DASHBAR15.DLL (file missing)

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\SYSTEM\BRIDGE.DLL",Load


O4 - HKLM\..\Run: [systray] C:\WINDOWS\SYSTEM\A.EXE

and this if its still there after removing it from add/remove programs it shouldn't be there
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup

Then reboot into safe mode [hitting f8 on bootup ] and delete the following files if found .
C:\WINDOWS\SYSTEM\ BRIDGE.DLL-- file only
C:\WINDOWS\SYSTEM\ A.EXE ---file only
to find the above files you may need to show hidden files .
How to show hidden files .
http://www.xtra.co.nz/help/0,,4155-1916458,00.html#2

then post a new log .

caperjack 875 I hate 20 Questions Team Colleague

caperjack: how much RAM do you have? As I said, if you already have a lot of physical ram, then the page file isn't needed as it just wastes HD space.

896meg ,its not about harddrive space it's about windows being able to axcess quicker what it keeps in the swap/page file.quicker if it in ram than if it on the hdd

caperjack 875 I hate 20 Questions Team Colleague

I got the same error. Was wondering if you could help ASAP? Thanks

HiJackThis Log File::

Logfile of HijackThis v1.97.7
Scan saved at 17:42:48, on 26/02/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\zHotkey.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\blss\blss.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\DOCUME~1\Family\APPLIC~1\sglstied.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\WINDOWS\System32\SahAgent.exe
C:\WINDOWS\System32\IEDriver\IEDriver.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\Ntn1.exe
C:\Program Files\BigFix\BigFix.exe
C:\PROGRA~1\COMMON~2\ADDRES~1\comwiz.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\cidaemon.exe
C:\unzipped\hijackthis1977\HijackThis.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.blazefind.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
O1 - Hosts: auto.search.msn.com
O1 - Hosts: search.netscape.com
O1 - Hosts: ieautosearch
O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRA~1\COMMON~2\ADDRES~1\cnbabe.dll
O3 - Toolbar: &Radio - …

caperjack 875 I hate 20 Questions Team Colleague

i i was wondering what these might be?

Safe to uncheck.

caperjack 875 I hate 20 Questions Team Colleague

I never ever noticed the difference when i did that or when i turned it off alltogether and use my ram .

caperjack 875 I hate 20 Questions Team Colleague

i have 9,0 installed

if you have 9 then you don't need 8

caperjack 875 I hate 20 Questions Team Colleague

You could try this link ,I haven't yet but will ,just founf it .
http://www.broomeman.com/support/wsiedown.html

caperjack 875 I hate 20 Questions Team Colleague

Im sorry i was thinking tweakUI

caperjack 875 I hate 20 Questions Team Colleague

might I suggest Ad-Aware
Download the latest version of Ad-Aware at http://www.lavasoftusa.com/support/download/

After installing AAW, and before running the program, you NEED to FIRST update the reference file following these instructions. http://www.lavahelp.com/howto/updref/index.html

Now do the following:

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."

Press "Scan Now"

- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:

Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"

Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.

Finally, close Ad-Aware, and reboot.
That ought to get rid of most of your spyware.

caperjack 875 I hate 20 Questions Team Colleague

Let me get this strait ,you think that Microsofts Tweek XP will tweek Mozilla.

caperjack 875 I hate 20 Questions Team Colleague

have you ever use Spybot or Ad-aware ,if not look in my signature[adware tools] and download ,install and update and run them one at a time .

caperjack 875 I hate 20 Questions Team Colleague

there are a number of things in the log that need fixing ,but i have to go to work now ,will get time later to help you with it .

Also don't run hijack from the zip unzip to its own folder so it will be able to make backups
C:\unzipped\hijackthis[1]\HijackThis.exe

caperjack 875 I hate 20 Questions Team Colleague

before doing anything in the registry ,make sure you backup the registry /with it open go to file /export and copy the backup somewhere safe ,i usuall name it the date i made the backup .also i deleted reference to old programs al the time .haven't had a problem with doing it since 1997,had more problems using reg Cleaners :)

caperjack 875 I hate 20 Questions Team Colleague

open the case and look on the board for a name or go here and download a nd install aida32 http://www.aida32.hu/aida32-download.php
go to the motherboard section it should list what it is .

caperjack 875 I hate 20 Questions Team Colleague

personially i love the links option and use it daily

caperjack 875 I hate 20 Questions Team Colleague

did you sign in on a friends comput and forget to sign out

caperjack 875 I hate 20 Questions Team Colleague

that depends on how many program you plan on installing and how much stuff you think you migh be saving .i have mine 50/50

caperjack 875 I hate 20 Questions Team Colleague

follow these directions you will not have that problem again.

1. Start /Run ,type in ,regedit, navigate to HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar
2. Locate the string "LinksFolderName", right click on it and select modify and set the value to a blank string.
3. Exit regedit
4. Now delete the Links folder

caperjack 875 I hate 20 Questions Team Colleague

on the first partition is my choice ,because when you load the program on the second partition it still hase to load system files ,and the system folder will be on the first partition ,thus windows will ahve to work to find the file ,kepping the second for data and video or music .

caperjack 875 I hate 20 Questions Team Colleague

get the google popup stopper .
http://toolbar.google.com/?fix=en

Also post a hijack log if you wish itsa tell all as to what you computer is running .

caperjack 875 I hate 20 Questions Team Colleague

no problem .

caperjack 875 I hate 20 Questions Team Colleague

Those are all good windows files .the carpserve one is associated with your a Zoltrix modem ,ccApp.exe ,and ccEvtMgr.exe are norton ,csrss.exe is client server releated .lsass.exe is legit system file ,but some can be virus releated if they are in the wrong folder,it gets complicated !!.If you are worried about viruses run a online virus scan .
http://housecall.trendmicro.com/

And this [popups about popup and how to get rid of them .]can be stopped by getting stop the messenger fro the GRC site mentioned in TallCool1 post

caperjack 875 I hate 20 Questions Team Colleague

i ran a adaware scan a few days ago then came back and updated it and WHOA!

138 something files found and i got this message when i tried to clean it up what should i do?

YouShouldn't/don't run both programs at the same time .
You should be able to remove wildtangent via the ADD/REMOVE Programs in the control panel

caperjack 875 I hate 20 Questions Team Colleague

Trezier ,the answer to you ? as did they run another adware program is easy in the attached photo,of AD-Aware , Spybot[icon on the toolbar ] is running also

caperjack 875 I hate 20 Questions Team Colleague

can you right click the toolbar and unlock ,and then click on the address bar and drag the address bar down to the edge .

caperjack 875 I hate 20 Questions Team Colleague

Get and run and SPYBOT and AD-Aware ,and update and run them first!!!from my signature ! then get SWSHredder and hit FIX when you run it not Scan ,then post back a new log .

caperjack 875 I hate 20 Questions Team Colleague

Both are very graphic intence games ,you need more fire power to run them !Me Thinks!:)

caperjack 875 I hate 20 Questions Team Colleague

when you reinstall windows are you install ing the blasterworm patch before you go online ,if not you could be getting the blaster worm as soon as you connect computer to the intenet

caperjack 875 I hate 20 Questions Team Colleague

Start/All Programs/Accessories/System tools /System restor and go back to a date before you install the offending program

Sooy didn't see it say win2000 was the OS in use , anywhere

caperjack 875 I hate 20 Questions Team Colleague

the slots are different for these two types of ram so unless you board has both slots it can't work .I just downloaded a manual for you board and it only supports SDRAM!

caperjack 875 I hate 20 Questions Team Colleague

No win 98 or ME will not see the NTFS ,NTFS is more stable and the single file size can be upto 2Gigs .thats the main difference to my knowledge.one way or the other it wouldn't matter what one you use ,thats my opinion !:)

caperjack 875 I hate 20 Questions Team Colleague

Go to start/run ,tpe in MSCONFIG,and uncheck the programs you don't want running or right click on the programs icon down by the clock and most have options you can check so as not to start when booting computer .

caperjack 875 I hate 20 Questions Team Colleague

what kind of popups are they . 2 things in you log that look suspicious

O4 - HKCU\..\Run: [Lerm] C:\Documents and Settings\Steven\Application Data\cacp.exe
O4 - HKCU\..\Run: [WNST] C:\WINDOWS\System32\wnsapisv.exe
can't find any info on them and that makes them suspicious,do you ahve any idea what they are

caperjack 875 I hate 20 Questions Team Colleague

just a tip you say I have the same problem to ,that means I have to re-read all the other messages to seee what the problem was ,so what is you problem

caperjack 875 I hate 20 Questions Team Colleague

I've checked log and it looks ok now except for this one thing .

Run hijack and fix this --
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


don't worry about the haldex folder is must be gone

caperjack 875 I hate 20 Questions Team Colleague

this showe me that you are running hijack from a temp folder ,you need to unzip it to a folder of its own C:\HJ\
C:\Documents and Settings\Ruth Ankrah.BABY\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

caperjack 875 I hate 20 Questions Team Colleague

Kazaa ,loads 3rd party spyware that will need to be uninstall also.

caperjack 875 I hate 20 Questions Team Colleague

post you log .

caperjack 875 I hate 20 Questions Team Colleague

how do perform a system restore

Start/All Programs/Accessories/System tools /System restor and go back to a date before you install the offending program

caperjack 875 I hate 20 Questions Team Colleague

I don't know the answer to you problem but it could well be a virus !!
What happens when you click on the norton icon in start/all programs .

caperjack 875 I hate 20 Questions Team Colleague

Get KazaaBeGone from the link in my signature and remove kazaa then get Kazaa lite or Winmx

caperjack 875 I hate 20 Questions Team Colleague

Sorry I can't keep track of all the different people posting logs in a thread created by someone else ,you need to start your own thread with your problem and also I work all day and reall don't have time for too many logs as they are verry time cosuming .
As for rapit blaster it's A varity spyware /adware.and you have more than one !!
http://www.onlinepcfix.com/spyware/spyware.htm