PDA

View Full Version : hijack this log


jeezy1901
09-01-2008, 05:39 PM
Tuesday of last week I switched over to At&t for my internet provider. After days of arguing with them I finally receive my 2 wire modem and an installation disk. I went ahead and installed my 2 wire modem, then turned off my computer screen and went to bed. The next morning, I go to turn my computer screen back on, and I receive this error " http://i36.tinypic.com/2gugjvd.jpg " I google it and find the fixya website, and a nice person by the name of rjfvillarosa helps me to get my computer up and running again. He directed me to this site because I have malware problems with my computer.To make a long story short, when I open folders on my computer or install certain things like the adware software on here a windows installer box pops up and then tells me after it finishes that i do not have windows installer properly installed.

ive used ccleaner,trend micro housecall 6.5 which found a "TROJ_HORST.JX, CRYP_PESPIN, FREELOADER_SPYWARESTORMER,ADWARE_180SOLUTIONS
ive also used malware bytes anti malware and spybot search and destroy

and nothing has changed:(
the scan for micro housecall 6.5 stated that it could not delete the troj horst.jx and id have to manually delete it but i have no clue as to where it could be at
thank you for taking ur time to read this
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:37:51 PM, on 9/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dad\Desktop\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3522
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toggle.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /dropdisc
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: &Search - ?p=ZJfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex/DIGHardwareControl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8E82893F-7ED1-4811-A247-580DCC0E2629} (SFLauncherTDE Class) - http://www.sf.in.th/activex/StarterSFTDE.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {C70E8BB2-849B-478E-828E-9F71729C86B2} (ATXWSM Control) - http://download.wayi.com.tw/download/WSM/ATXWSM.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Windows Live OneCare Family Safety (fsssvc) - Unknown owner - C:\Program Files\Windows Live\Family Safety\fsssvc.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11149 bytes

rjfvillarosa
09-01-2008, 05:58 PM
Welcome to PCMech jeezy.

You can tell HJT to fix this 08 and 09 entry

O8 - Extra context menu item: &Search - ?p=ZJfox000
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

All of these 04's are opening when Windows starts and are optional, you don't really need them. If you want to see what effect they will have try disabling them (not delete) in Tools>StartUp of CCleaner.

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /dropdisc
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE


edit....
I am going to wait for Negeva to give your log a look over, I am concerned that the Windows installer application is having problems, something is telling me that somehow you have wound up with system file damage.

jeezy1901
09-01-2008, 06:29 PM
thank you i also forgot to mention that its also freezing up when i go to restart or shut down my computer it usually takes it 2-3 minutes to show the shut down option after i go to start>turnoff computer

rjfvillarosa
09-01-2008, 06:44 PM
You mentioned in your email that you don't have the recovery CD's.
Can you see on the side or rear of your machine the COA Microsoft sticker with your installation product code on it?
Do you have a CD or DVD burner in that machine?
Do you know anyone who may have an OEM copy of XP you can borrow?

jeezy1901
09-02-2008, 05:25 AM
nope do not see any product code just says that its capable of running windows vista on it
yes i have a cd burner and no i dont know anyone who uses xp anymore :(

Negeva
09-02-2008, 01:23 PM
Only malicious entry I see is this:

http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe

Not sure why a home user would have this:

C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


It's a legal programme but I've only really seen it in development situations. You can safely disable it via services.msc. You can also alter the Punkbuster service (PnkBstrA.exe) to manual too as Evenbalance are too damn lazy to code properly - you won't get kicked.



A tad confused over your security arrangements. Can see entries for Norton/Symantec, Windows Live One Care and NOD32 (Eset). Plus, all those toolbars! Do you really need that many or for that matter any of them?

jeezy1901
09-02-2008, 02:09 PM
Only malicious entry I see is this:

http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe

Not sure why a home user would have this:

C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


It's a legal programme but I've only really seen it in development situations. You can safely disable it via services.msc. You can also alter the Punkbuster service (PnkBstrA.exe) to manual too as Evenbalance are too damn lazy to code properly - you won't get kicked.



A tad confused over your security arrangements. Can see entries for Norton/Symantec, Windows Live One Care and NOD32 (Eset). Plus, all those toolbars! Do you really need that many or for that matter any of them?

had norton made my computer start up and shut down extra slow the antivirus i use is nod32 so do i take out the norton entries and windows live one care and wat toolbars are u talking about i never downloaded any toolbar

rjfvillarosa
09-02-2008, 02:41 PM
wat toolbars are u talking about i never downloaded any toolbar

These are all evidence of toolbars operating on your machine, don't use HJT to get rid of them, just decide which ones you don't want and use CCleaner to uninstall them.
With your Windows installer problem, did you have any problems installing CCleaner?

R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: &Search - ?p=ZJfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html

jeezy1901
09-03-2008, 07:19 AM
These are all evidence of toolbars operating on your machine, don't use HJT to get rid of them, just decide which ones you don't want and use CCleaner to uninstall them.
With your Windows installer problem, did you have any problems installing CCleaner?

nope none at all it ran perfect internet explorer crashes though when i try and open it and it gives me the windows installer

*edit* ran the google chrome browser and got this http://i38.tinypic.com/s3eatc.jpg
then i google that error code and came up with this fix think it might work?
http://support.microsoft.com/kb/321497

rjfvillarosa
09-03-2008, 07:40 AM
Jeezy.
Download a little application called magicaljellybean, this app will reveal your CD installation product code which will enable you to reinstall Windows as a last resort.
www.magicaljellybean.com

I hope you can install it considering your Windows installer service is not working.
I will check back as soon as I can, I live in the Caribbean and we are feeling the effects of tropical storm, soon to be, hurricane IKE. The power keeps going out and I am worried a lightning strike will take out my modem.
Don't believe what you hear about surge protectors, they are not that good in my opinion.

jeezy1901
09-03-2008, 10:05 AM
ok ty got the code now how do i go about reinstalling it?

also i went ahead and performed that fix i listed above and it fixed the problem with me installing stuff but when i open folders instead of windows installer box i get this
http://i36.tinypic.com/x4j0og.jpg

rjfvillarosa
09-03-2008, 12:04 PM
Now that you have the product code you can reinstall XP using an OEM install disk.
To be honest the point you are at now with what looks like system file damage we nearly always recommend a format and reinstall of Windows.

1st. Using a spare harddrive, pen drive or CD/DVD recordables save all your personal files.
2nd. Do a zero fill of your harddrive, a zero fill means to overwrite the entire harddrive with zeros, which destroy all data on the harddrive including malware and viruses including boot sector viruses. The zero fill utility can be accessed from harddrive manufacturers diagnostic tools or other sources like UBCD (the ultimate boot CD).
3rd. Reinstall Windows.

Ok. First you will need to find an OEM copy of XP, it must be an OEM copy to be able to use your product code. See if you can beg, steal or borrow a copy from someone.

jeezy1901
09-10-2008, 01:33 PM
ok well i managed to get a copy of the cd i need so how do i go about running the zero fill:confused:

rjfvillarosa
09-10-2008, 02:00 PM
First and foremost you need to make backups of your personal photos, music and whatever otherfiles you have.
Have a look in Control Panel>System>Hardware>Device Manager.
Click the little box next to "Disk Drives" and see if you can identify your harddrive manufacturer (ST = SeaGate WD = Westerndigital)
You can then go to the harddrive manufacturers website and download the diagnostic utility, you will need to make a bootable CD out of the downloaded file and there should be instructions on the manufacturers site, should the downloaded file need unpacking or anything.
The diagnostic tool is always worth running on your harddrive prior to a reinstall just to make sure the drive is ok and the zero fill utility should also be on the CD.

jeezy1901
09-10-2008, 03:05 PM
First and foremost you need to make backups of your personal photos, music and whatever otherfiles you have.
Have a look in Control Panel>System>Hardware>Device Manager.
Click the little box next to "Disk Drives" and see if you can identify your harddrive manufacturer (ST = SeaGate WD = Westerndigital)
You can then go to the harddrive manufacturers website and download the diagnostic utility, you will need to make a bootable CD out of the downloaded file and there should be instructions on the manufacturers site, should the downloaded file need unpacking or anything.
The diagnostic tool is always worth running on your harddrive prior to a reinstall just to make sure the drive is ok and the zero fill utility should also be on the CD.

off to do it right now hopefully all goes well :D

*edit* ok followed the steps on the cd but did not see a zero fill on it

rjfvillarosa
09-10-2008, 05:11 PM
Have you run the harddrive tests?
Everything OK?

Download and create the UBCD (ultimatebootcd), this CD contains many hardware testing tools. You can use the DBAN tool to do a secure erase of your harddrive.
You can download UBCD here:
http://www.ultimatebootcd.com/


It's a good thing CD's are cheap....;)

jeezy1901
09-10-2008, 08:09 PM
ok it was done clean install from scratch fixed the problem but now its telling me that there was an error when installing my ethernet controller:confused:

rjfvillarosa
09-10-2008, 08:23 PM
Thats no problem, just go to the site of your computers manufacturer and download the drivers for your LAN card to a pen drive or something.
Have you looked in Device Manager for any yellow triangles? if you have any you will need the drivers for those as well.

jeezy1901
09-10-2008, 08:36 PM
Thats no problem, just go to the site of your computers manufacturer and download the drivers for your LAN card to a pen drive or something.
Have you looked in Device Manager for any yellow triangles? if you have any you will need the drivers for those as well.

yea popped up for my ethernet controller printer video controller and a pci simple communications

there yellow question marks

rjfvillarosa
09-10-2008, 08:51 PM
The driver download page on the manufacturers site should have everything you want.
What make and model of machine is it?

jeezy1901
09-10-2008, 09:03 PM
The driver download page on the manufacturers site should have everything you want.
What make and model of machine is it?

t3522 emachine spoke to a tech support agent on live chat and she gave me this link

http://www.e4allupgraders.info/dir1/motherboards/socket775/D915GUX_downloads.shtml

but the warning on the top concerns me as whether to trust it

rjfvillarosa
09-10-2008, 09:11 PM
That warning is a good one, it is telling you that flashing the BIOS can be a risky business, fortunately you are not touching the BIOS.
Download all the drivers you need and leave the BIOS files well alone.

jeezy1901
09-11-2008, 02:30 AM
ok got everything thing set up but this driver VIDEO: Intel® Graphics Media Accelerator ive went through the list and tried them all but cant see to find the right one :(

rjfvillarosa
09-11-2008, 09:51 AM
That site you linked to is an unofficial upgrade site, I think I would try some of the drivers here:
http://www.emachines.com/support/product_support.html?cat=Desktops&subcat=T%20Series&model=T3522
There is an ATI video driver listed on that link, try that.


Edit..
A little bit of a conundrum there, although your system specifications say you have an Intel graphics chip, two sets of drivers are listed, Intel and ATI graphics.
There is a warning next to the Intel graphics drivers that they are not to be used with a third party graphics card (ATI). I honestly don't remember working on an EvilMachines computer that used onboard graphics.
The quickest way to tell what you have is by the layout of the graphics port, usually if it is vertical it is onboard, in this case Intel. If the port is horizontal it is a graphics card, maybe the ATI card they list the drivers for.
What way is your graphics port orientated? horizontal or vertical?

glc
09-11-2008, 11:13 AM
The Intel chipset driver must be installed first - then the Intel video driver should install.

Use the official driver site.

jeezy1901
09-11-2008, 11:39 AM
That site you linked to is an unofficial upgrade site, I think I would try some of the drivers here:
http://www.emachines.com/support/product_support.html?cat=Desktops&subcat=T%20Series&model=T3522
There is an ATI video driver listed on that link, try that.


Edit..
A little bit of a conundrum there, although your system specifications say you have an Intel graphics chip, two sets of drivers are listed, Intel and ATI graphics.
There is a warning next to the Intel graphics drivers that they are not to be used with a third party graphics card (ATI). I honestly don't remember working on an EvilMachines computer that used onboard graphics.
The quickest way to tell what you have is by the layout of the graphics port, usually if it is vertical it is onboard, in this case Intel. If the port is horizontal it is a graphics card, maybe the ATI card they list the drivers for.
What way is your graphics port orientated? horizontal or vertical?

ty ty ty finished installing all the drivers got my computer running back to normal in ur opinion nod32, avg, norton, or kaspersky which one is a better antivirus?
also for some reason its saying i cant activate windows xp because my copy is invalid:confused:
next trip i take to puerto rico to visit my family drinks will be on me ;)

rjfvillarosa
09-11-2008, 11:59 AM
Most of us old farts here like AVG, the new 8.0 version is quite a good package as it now includes AVG's spyware scanner as well and a root scanner.
If you are behind a router, then as far as I am concerned the router's built in firewall and Windows firewall are plenty of firewall protection (plus Windows firewall doesn't play nice with third party firewalls).
On all my machines (except my linux box) I am running:
AVG 8.0 free (set to manual scan)
Malwarebytes (set to manual scan)
Spybot Search and destroy (set to manual scan)

Thompson Speed Touch modem with NAT
Linksys router with firewall
Windows XP firewall
I use manual scanning because I am boring and never go to any naughty sites, I also use CCleaner regularly just to keep on top of all the rubbish that Windows drops about the place. To me Windows is like a scruffy teenager, when it finishes using something instead of putting back where it got it from it just drops it on the floor where it was last used...;)
You can get AVG 8.0 free from www.download.com, malwarebytes from www.malwarebytes.org and SpyBot from http://www.safer-networking.org/en/index.html



next trip i take to puerto rico to visit my family drinks will be on me ;)

Mira, Manuel ¿quieres un vaso de Pittorroh con piña....:cool:

rjfvillarosa
09-11-2008, 12:44 PM
ty also for some reason its saying i cant activate windows xp because my copy is invalid
Follow the instructions to validate your copy of Windows over the phone, it is a simple painless procedure that takes no more than ten minutes, plus the call is a toll free number.

glc
09-11-2008, 01:42 PM
A good alternative to AVG is Avast. It's also available in a free edition.