1
   

HELP, my computer don´t start in normal mode the HJT is here

 
 
Reply Tue 15 Feb, 2005 03:59 am
I´ve had a lot of problems with lockups and crashes without any reason and now my computer doesn´t even start in normal mode and another thing, now when I only can start in safe mode,my computer is not connected to the internet so I don´t have the most "fresh" one beacuse the problem just popped up 1,2 hours ago so please look at this one and I see if the problem will be solved anyway, thank you.... :


Logfile of HijackThis v1.99.0
Scan saved at 10:58:15, on 2005-02-15
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM\F-SECURE\COMMON\FSMA32.EXE
C:\PROGRAM\F-SECURE\COMMON\FSMB32.EXE
C:\PROGRAM\F-SECURE\COMMON\FCH32.EXE
C:\PROGRAM\F-SECURE\COMMON\FNRB32.EXE
C:\PROGRAM\F-SECURE\COMMON\FAMEH32.EXE
C:\PROGRAM\F-SECURE\COMMON\FSGK32.EXE
C:\PROGRAM\F-SECURE\COMMON\FIH32.EXE
C:\PROGRAM\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM\D-TOOLS\DAEMON.EXE
C:\PROGRAM\SLYSOFT\CLONECD\CLONECDTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM\INKLINE GLOBAL\PC BOOSTER\PCBOOSTER.EXE
C:\PROGRAM\F-SECURE\COMMON\FSM32.EXE
C:\PROGRAM\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM\BOUNCER\BOUNCER.EXE
C:\PROGRAM\WINDOWS MEDIASPELAREN\WMPLAYER.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM\SPYWAREGUARD\DLPROTECT.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRAM\SPYBOT~1\SDHELPER.DLL
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program\GetRight\xx2gr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM\YAHOO!\COMPANION\INSTALLS\CPN1\YCOMP5_5_7_0.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [PC Booster] C:\Program\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [Bouncer RunStartup] C:\PROGRAM\BOUNCER\LiveUpdate.exe 211
O4 - HKLM\..\Run: [PC Adware-Spyware Removal] C:\PROGRAM\PC ADWARE-SPYWARE REMOVAL\PCADWARESPYWAREREMOVAL.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [fsaa] C:\Program\F-Secure\Common\fsaa.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\Program\F-Secure\Common\FSMA32.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\PROGRAM\TUNEUP UTILITIES 2004\MEMOPTIMIZER.EXE" autostart
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program\SpywareGuard\sgmain.exe
O4 - Startup: Genväg till (D).lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Download with GetRight - C:\Program\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_01\bin\npjpi150_01.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system\zonelabs\vetredir.dll' missing
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 663 • Replies: 7
No top replies

 
timberlandko
 
  1  
Reply Tue 15 Feb, 2005 01:32 pm
You might wanna give this a try:

Start your computer in regular safe mode. Go to "Add/Remove Programs", and remove any programs you know you installed around the time the problem started happening. One to look for in particular is "Virtual Bouncer"- if it, or something very similar, is in "Add/Remove", use the "Custom Uninstall" option, and pay attention to what is offered - you don't want to remove stuff not directly associated with the sucker.
While still in safemode, restart HighJackThis. Have it "Fix" the following:

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime

O4 - HKLM\..\Run: [Bouncer RunStartup] C:\PROGRAM\BOUNCER\LiveUpdate.exe 211

Now, search-for-and-delete-if-found any files or folders named or containing "VBouncer", "VirtualBouncer" or anything very similar. These may include:

"downloaded program files\bundleouter1132031209.exe",
"vbouncerinner.exe"
"virtualbouncer.exe",
"virtual bouncer\virtual bouncer.lnk".

Before starting the search, click "More advanced options" and make sure "Search" is enabled for "Hidden files and folders" and "System Files and Folders".

Go to Start>Run, enter (without the quotes} "regedit", click "OK", and navigate to HKEY_CURRENT_USER\software\. Look for "vb and vba program settings\vbouncer", and if found delete it.

If you updated any drivers around the time the problem started, also go to Device Manager and either roll them back or uninstall them.

Open Spybot S&D, have it run a full scan and instruct it to fix everything it finds. When it has completed, if it does not ask to run on next boot, run it one more time anyway and again let it fix whatever, if anything it finds. If it does ask to run on next boot, boot back into regular safemode, and let it run and let it fix whatever it wants to. Reboot back into regular safe mode and run it one more time, again letting it fix whatever if anything it finds.

Empty your temporary internet files, delete your cookies, (from your browser's toolbar, select "Tools>Internet Options", or select "Internet Options" from Settings>Control Panel) and empty the contents - but do not delete the parent folder itself - of your "Temp" folder and your "C:\Windows\temp" folders (Right-click "My Computer", select "Explore", navigate to "Temp" to get to that folder - open it and delete all its contents. Now do the same thing, navigating to your "Windows" folder, open it, find its "temp" folder, and delete all the contents).


Power off your machine, unplug it from the wall, and wait at least a full minute, then power it back on. Start your machine in safe mode by tapping the F8 key during power-up. When presented with the boot menuu, select "Safe Mode Command Prompt Only", then hit "Enter". At the command prompt, type:

cd\windows\command and hit "Enter"

At the "C:\" prompt, type:

scanreg /restore (be sure to include the space between "scanreg" and the forward slash), then hit "Enter"

You should be presented with a list of five "saved" registries - make sure the one you select is dated prior to the date of the onset of your problem, and has the word "Started" next to the date. A few moments should pass, then you should see a notification that a properly working registry has been restored. Hit "Enter" to reboot, and see what happens. If you can boot normally, rerun HiJackThis, connect to the internet, and post the new log to this thread.
0 Replies
 
daddymurphy
 
  1  
Reply Wed 16 Feb, 2005 06:50 am
Thanks a bunch....
Thanks very, very, very much timberlandko for your help and that you took time to help me with this, but now I have installed Windows2000 professional on my computer and I´ve also formated hole disk C: , and I´m so grateful that you took time to write all this stuff anyway for me and if you have time and think it´s okay to do this, I would really appreciate if you could recommend some things and programs to make my computer very secure and fast. I´ve tried many programs and stuff so it´s not really neccesary but if you want you could just recommend some things so I stay out of trouble. Thank you...... Smile Smile
0 Replies
 
timberlandko
 
  1  
Reply Wed 16 Feb, 2005 08:13 am
Sure. Practice Safe Hex - with particular attention paid to keeping current with all operating system and application security/privacy updates.


Some useful stuff - provided time and effort are taken to understand, properly configure, and effectively employ them:

Spybot S&D (Includes real-time blocking, an interactive Registry monitor, a comprehensive Hosts list, and an effective, easy-to-use startup manager, among other handy things)

AdAware SE (The free Personal version is quite effective at detection and removal of yuckware, though no real-time blocking is provided. The various paid-subscription upgrades offer increased functionality)

SpywareBlaster

SpywareGuard

Microsoft AntiSpyware (Win 2K and later only)

IE SpyAd


Able2Know Toolbar (Very good pop-up blocker, extensive search capabilities)

A tremendous resource for those interested in computer security/privacy is Eric Howes' Website
0 Replies
 
parados
 
  1  
Reply Wed 16 Feb, 2005 08:43 am
A couple of issues for you to consider.

1. If you have a high speed or always on connection to internet then you MUST have a firewall. Either software or hardware. I recommend hardware since you can prevent anyone from even getting to your computer. (Windows has too many connection points that need protection from hackers.) A day doesn't go by that my log doesn't show some hacking attempt on my home computer and that is with just 3 ports open to my linux box. The majority of the attempts are attacks on Windows machines.

2. Download Firefox and stop using IE6. Firefox is great on W2000. Firefox allows you to turn off popups and selectively allow them for specific websites that require them for logging on or checking out, etc. Use the tabbed windows. Firefox doesn't clutter up your computer desktop with 10 different windows when you just create new tabbed connections. Also Firefox is presently immune to a lot of spyware that looks for running instances of IE to hijack.
0 Replies
 
parados
 
  1  
Reply Wed 16 Feb, 2005 08:44 am
A couple of issues for you to consider.

1. If you have a high speed or always on connection to internet then you MUST have a firewall. Either software or hardware. I recommend hardware since you can prevent anyone from even getting to your computer. (Windows has too many connection points that need protection from hackers.) A day doesn't go by that my log doesn't show some hacking attempt on my home computer and that is with just 3 ports open to my linux box. The majority of the attempts are attacks on Windows machines.

2. Download Firefox and stop using IE6. Firefox is great on W2000. Firefox allows you to turn off popups and selectively allow them for specific websites that require them for logging on or checking out, etc. Use the tabbed windows. Firefox doesn't clutter up your computer desktop with 10 different windows when you just create new tabbed connections. Also Firefox is presently immune to a lot of spyware that looks for running instances of IE to hijack.
0 Replies
 
daddymurphy
 
  1  
Reply Wed 16 Feb, 2005 09:27 am
Thanks A LOT.....
Thanks A LOT, both of you....

Your suggestions helped very much, thank you.... Smile
0 Replies
 
timberlandko
 
  1  
Reply Wed 16 Feb, 2005 09:56 am
Decent points, parados - all covered pretty well in the Safe Hex article linked earlier.

Opininin' here - no matter what operatin' system, browser, email client, or security/privacy software ya use, the most important tools for protectin' your machine are common sense and good practice. Carelessness, inattention, and just plain laziness will get ya into trouble just about regardless of whatever safeguards may be in place. "Foolproof" is a flawed concept; never underestimate the power of foolishness.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » HELP, my computer don´t start in normal mode the HJT is here
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 05/01/2024 at 05:45:51