#1
|
|||
|
|||
two problems really
first off:
really slow opening pages so i d/l and ran hijack Logfile of HijackThis v1.96.4 Scan saved at 22:00:40, on 05/09/2003 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\system32\drivers\dcfssvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\USB\Manager.exe C:\WINDOWS\System32\carpserv.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Program Files\ClearSearch\Loader.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\er\Local Settings\Temp\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = 203 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tiscali.co.uk/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,AutoConfigURL = http://proxycfg.marketscore.com/genc...=1&nsv=5.2.4.5 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.co.uk/ R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = https://signup.e2binternet.com/cdsignup/ O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [USB] C:\Program Files\USB\Manager.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Global Startup: Microsoft Office.lnk = C:\program files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: ICQ Lite (HKLM) O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O10 - Broken Internet access because of LSP provider 'csloa.dll' missing O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/ O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/game...ts/y/wt0_x.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/24fddcdfe8c146f...p/RdxIE601.cab O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/soft...ch/alaunch.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} - http://www.cracks.st/mp3.exe O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Te...loads/outc.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{C4843ACC-E0E5-48B5-88F8-F54BCC49F328}: NameServer = 212.74.112.67 212.74.114.129 .....that is a save of the log. Secondly I have A problem with my Dell Inspiron 2500 laptop. I keep getting error message 'no dial tone' when trying to connect online. To try to correct this iI have renewed the modem to phone cable.......carried out a system restore to before it started happening....... checked modem diagnostic(all ok/communicating fine)... unchecked 'wait for dial tone'...and placed ,,,, before the dialing number. Anyone got any other ideas on how to fix it? it runs on win millen edition and is a darn good lappy usually!!! many thanks. x |
#2
|
||||
|
||||
Hi tonella - you have spyware on your PC which is more than likely causing your problem.
Download Spybot - Search & Destroy from here. If you already have Spybot on your PC, make sure that it is the latest version and go online and make sure that you have installed the latest updates. After installing, launch Spybot from the Desktop Icon (Easy Mode),click on the Search For Updates button, search for and install all updates. Now click on the Check for Problems button and the scan will start. Any Red entries indicate spyware problems that should be fixed to avoid security and/or privacy problems. This is the only kind of problem that is preselected to be fixed. If, after running the scan, Spybot displays red entries, click on the Fix Selected Problems button. Now click on the Immunize button to protect your PC from known pests and exit. If you have chosen to install an icon in your Quick Launch bar, Spybot will launch in Advanced Mode. I do not recommend this option for first time users of Spybot. NOTE: SSD will sometimes not be able to remove all active components in the first 'run'. In that case you will get a dialog asking you to run SSD at next start. Click yes and reboot. SSD will activate before the system puts these components 'in use', and it will then be able to 'fix' the rest. When you have rebooted, run Hijack This again and post a new log. Please post your problem with your laptop in the WinME Forum. You will have better luck there |
#3
|
|||
|
|||
ok i will go do that now......i have adaware is that not similar to spybot?
|
#4
|
|||
|
|||
after scan/reboot/scan......
Logfile of HijackThis v1.96.4
Scan saved at 10:30:40, on 06/09/2003 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\system32\drivers\dcfssvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\USB\Manager.exe C:\WINDOWS\System32\carpserv.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\WINDOWS\System32\ctfmon.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\ER\Local Settings\Temp\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = 203 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tiscali.co.uk/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.co.uk/ R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = https://signup.e2binternet.com/cdsignup/ O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [USB] C:\Program Files\USB\Manager.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Global Startup: Microsoft Office.lnk = C:\program files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: ICQ Lite (HKLM) O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O10 - Broken Internet access because of LSP provider 'csloa.dll' missing O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/ O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/game...ts/y/wt0_x.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/24fddcdfe8c146f...p/RdxIE601.cab O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/soft...ch/alaunch.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Te...loads/outc.cab is this any better? xx |
#5
|
||||
|
||||
Quote:
Next, run Hijack This again and this time, select the below entries and click on Fix Selected. Reboot afterwards. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = 203 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = https://signup.e2binternet.com/cdsignup/ When you have rebooted, let us know if you notice any improvement. |
#6
|
|||
|
|||
Quote:
thanks. yes it all seems to be faster now. foir example these pages loaded much quicker. the link to winsock d/l is faulty btw, but i got it somewhere else. thanks for your help and time AnnMarie xx |
#7
|
|||
|
|||
Hi
since doing all those fixes......i am unsure whether this is just a plain coincidence or related. i am getting a --------------------------- msimn.exe - Application Error --------------------------- The instruction at "0x77f83907" referenced memory at "0x009a443c". The memory could not be "written". Click on OK to terminate the program --------------------------- OK --------------------------- everytime i shut down outlook express 6. have you heard of this before? i/ll post this in applications forum too. Tonella xx |
#8
|
||||
|
||||
Hi tonella - no, the problem is not related to the changes we have made. I'll offer some suggestions in The Applications Forum otherwise it will get rather confusing.
|
Bookmarks |
«
Previous Topic
|
Next Topic
»
Topic Tools | |
|
|
Similar Topics | ||||
Topic | Topic Starter | Forum | Replies | Last Post |
Flashplayer Problems and General Problems | white17 | Windows XP | 9 | October 4th, 2008 03:54 PM |
Vista boot problems, partition problems | cHiNgY1788 | Windows Vista | 1 | May 23rd, 2007 01:45 AM |
Lagging problems and Audio Problems/HJT Attached. | lucaspgordon | Malware Removal | 10 | August 21st, 2006 03:17 PM |
Problems amongst Problems adware/spyware and virus | roc slaughter | Malware Removal | 12 | April 26th, 2006 09:42 PM |
problems downloading using Rapdishare - suspect proxy servers problems - Help. | Jaaay | Internet / Browsers | 2 | February 3rd, 2006 05:10 PM |
All times are GMT +1. The time now is 11:18 PM.