1
   

Please help me, please someone, anyone?

 
 
Reply Wed 16 Aug, 2006 12:10 pm
since my earlier post of my hijack log, more problems haved popped up Evil or Very Mad This all seemed to start after I downloaded the latest Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2 around 8/11/06. The printer problems started first, then the task bar and start menu stopped loading. As of yesterday, problems are snowballing.

1. While trying to uninstall/reinstall my HP OfficeJet 6120 all-in-one I get a message saying "cannot install hardware, RPC Server is unavailable"
2. I got the HP people to send me instructions on how to fix this; however, SPOOLSV.EXE is not in the processes list. (yes I have Administrator rights)
3. I checked the task bar/start menu setup; it is as it should be. Restarting my computer does nothing to bring it back.
4. I thought there might be a problem with a program I installed back in July so I began the uninstall program. Got a message that the windows installed could not be accessed (no I was not runnin in safe mode)
5. I thought I might do a system restore back past July, but I cannot access system restore. (yes it is turned on)
6. My firewall, System Mechanic, Ad-Aware, Spybot all are not working properly. None of them will get updates. This worries me very much.

I certainly could use some brains to help me with this.
Or should I just take it to the dumpster?
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,150 • Replies: 7
No top replies

 
timberlandko
 
  1  
Reply Wed 16 Aug, 2006 01:58 pm
Hate to tell you this, but your best option in this case might just be to back up all your personal data to external storage, then format and reinstall Windows. Of course, if you do so, you'll have to reapply al Windows updates (which you should do before doing anything else), reinstall your peripherals and any other 3rd-party software, starting with an antivirus and a firewall, and you likely also will need to update some drivers.
0 Replies
 
Sunmaiden
 
  1  
Reply Wed 16 Aug, 2006 03:50 pm
timberlandko wrote:
Hate to tell you this, but your best option in this case might just be to back up all your personal data to external storage, then format and reinstall Windows. Of course, if you do so, you'll have to reapply al Windows updates (which you should do before doing anything else), reinstall your peripherals and any other 3rd-party software, starting with an antivirus and a firewall, and you likely also will need to update some drivers.

OMG! Shocked
Do you know what has caused this?
Are you telling me to format my C: drive? OMG, why?
0 Replies
 
Sunmaiden
 
  1  
Reply Fri 18 Aug, 2006 02:33 pm
Here's the HiJack File
WHERE'S DON WHEN I NEED HIM????? Sad Embarrassed Question

Logfile of HijackThis v1.99.1
Scan saved at 8:28:27 PM, on 8/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\UTHSC_VPN Client\cvpnd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.8.1.2\PlaxoHelper.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\RRIM\aim.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AIM Helper - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.8.1.2\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\RRIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe /S
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: UTHSCSA VPN Client.lnk = C:\Program Files\UTHSC_VPN Client\vpngui.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.avgcc.exe
O15 - Trusted Zone: *.avginet.exe
O15 - Trusted Zone: http://*.sacu.com
O15 - Trusted IP range: http://140.107.131.37
O15 - Trusted IP range: http://140.107.131.36
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?1&6&04.00.07.02&unknown&unknown&http://aolexpressions.aol.com/testdrive.adp?clientId=2&&langCode=&search=ant&expTypeId=1&tm=171&expId=6384
O16 - DPF: {140F03AE-0588-11D4-BD45-0050048A82BF} (eShare Web Collaboration Class) - http://chat.1800flowers.com/netagent/objects/emagic.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://ava.whiops.org/postauthI/epi.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136650874531
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.broderbund.com/plugin/Download.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) -
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://prints.picturecenter.kodak.com/activex/LightSurfUploadControl.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) - https://www.plaxo.com/activex/plx_upldr-2k-xp.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\UTHSC_VPN Client\cvpnd.exe
O23 - Service: IomegaAccess - Iomega Corporation - C:\WINDOWS\system32\IomegaAccess.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Aventail VPN Client (NgVpnMgr) - Aventail Corporation - C:\WINDOWS\system32\ngvpnmgr.exe
O23 - Service: Symantec Client Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
O23 - Service: Symantec Client Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Client Firewall Proxy Service (SymPxSvc) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINDOWS\system32\ZipToA.exe
0 Replies
 
timberlandko
 
  1  
Reply Fri 18 Aug, 2006 03:19 pm
There is no yuckware evidenced in that log (giving AOL the benefit of the doubt of course, and futher assuming there's a valid reason an IP block registered to a Seattle cancer research facility would be in your IE Trusted Zone) , nor is there any indication of anything to which the symptoms you report might be attributed.

What is indicated is a malfunctioning operating system. Short of a full reinstall, you might try try the System File Check utility. With no other apps running, particularly any real-time monitoring/protecting apps, such as antivirus or antispyware, go to Start>Run, type (without the quotes) "sfc /scannnow" (note the space between "sfc and "/scannow", and note also the forward slash (/) and the 2 "n"s in "/scannow"), click "OK". A progress box should appear. During the process, you most likely will be asked to insert your WinXP installation disk, so have one handy (a vendor's "Restore" disk won't work without some fiddling, but alternately, any WinXP install disk - provided it is the same version - Home or Pro ... gotta be the same as what you have; Pro won't work on a Home version and vice-versa - and Service Pack as your installed Windows ... in your case SP2 ... will - and actually, all that's needed is the I386 file from the install disk, which can be copied from any WinXP install disk of the proper version and incorporating the appropriate Service Pack, even a "Restore" disk, placed in a folder on your machine, and targeted manually when you are prompted for your install disk). When the process has completed, reboot and see if your problems remain. Honestly, I suspect they'll still be there, but maybe not. One other note; after doing this, you'll hafta reinstall all Windows updates and patches released subsequent to the publication of Service Pack 2; they'll be gone.

Another option short of format-and-re-install would be to attempt to repair Windows through "Upgrade in place", a process essentially which will overlay a new installation of Windows over the existing one, hopefully remedying problems while leaving your your personal files, settings, and installed applications intact. That doesn't always work either, and frequently turns out not at all well. I do not recommend you try it.
0 Replies
 
stuh505
 
  1  
Reply Fri 18 Aug, 2006 08:07 pm
Sunmaiden,

Unfortunately, timberlandko is right. The chances of you actually fixing this type of issue are slim to none. Really the only reason to keep fiddling with it is if you want to gain experience for dealing with computer problems, but I can almost guarantee you that you're going to have to end up reformatting anyway.

I noticed that in your post you mentioned you installed SP1 and SP2. It is not necessary to install SP1 before installing SP2. It is also not recommended that you even go online without having SP2 because of internet vulnerabilities. You should, therefore, burn a copy of SP2 onto a CD before reformatting.

I know it sounds like a massive procedure to you, but unfortunately, it is really just a fact of life that these things happen to us all! Reinstalling should only take a couple hours. Usually what takes the real time is just reinstalling all your individual applications, but again, there are steps you can take to hasten this process, like being careful to keep all your installer files backed up so you don't have to run around online looking for them.

What can you do to protect yourself from problems in the future? First of all forget about ad ware blockers. They don't really work. Virus scanners ARE very good. If you don't have one, I highly recommend AVG Free Edition, which is a very high quality virus scanner with regular updates. Your best defenses, in my opinion, are to use high security settings on your internet browser (this can be an inconvenience, but it protects you very wel) and most importantly don't install programs from the internet unless you know you can trust them.

Also a tip, when you reformat, if you choose quick format instead of the deep format it will only take a few seconds instead of an hour, with the only disadvantage being that it is possible that some of the data from your previous install would be detectable by police detectives who might be analyzing your computer in connection with a crime...
0 Replies
 
Sunmaiden
 
  1  
Reply Fri 18 Aug, 2006 08:20 pm
Thank you!
I ran the sfc /scannow as you suggested and my system seems to be working as before. It performed lots of updates; afterwhich I was able to run System Mechanic and Ad-Aware and get the updates there as well. I started AVG free but it says it is corrupt; I uninstalled it and plan on reinstalling tomorrow. My printer is working correctly and my task/start bar is too.

Tomorrow I plan on buying an external hard drive and keeping all my personal files there instead of my C:\

Thanks everyone.
Sunmaiden
0 Replies
 
timberlandko
 
  1  
Reply Fri 18 Aug, 2006 09:09 pm
An external hard drive and a diligent backup routine will save you much headache if ever you encounter a catastrophic system crash - and if you have and use a 'puter for any length of time, odds are you'll encounter a catastrophic system crash. Another great idea is to keep on removable media installation copies of all your downloaded apps - or at the very least the ones for which you've paid - along with a text file (a Notepad save is usually perfect) of any key, activation code, and/or password required by that app, and to make a copy of any vendors' install disks you have, being sure to include any required codes keys, and/or passwords. If you never need them (an unlikely circumstance), you're out the few pennies a blank CD-R costs, however, if you do need them, nothing else will do.

Another good practice is to keep a copy of all the latest drivers you need; my method is to set aside a CD-RW for each of my machines, with a folder for every app or peripheral's (printers, modems, video, audio, and network cards, that sorta stuff) drivers, daughter folders inside that folder with drivers by date as they are updated - that serves a couple usful purposes; naturally, you have the latest drivers should you need them, but not only that, you have older drivers should a newer one for whatever reason prove unsatisfactory (and that happens from time to time).

Ain't much can go wrong with a 'puter that I haven't lived through - including the really entertaining "sparks and smoke" error message. Disasters happen whether you plan for them or not. Recovering from a disaster is much less stress, strain, and hassle if you've planned for it.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Please help me, please someone, anyone?
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 05/28/2024 at 11:43:37