Page 1 of 2

boot up problems!

PostPosted: Thu Sep 09, 2004 9:28 am
by poisonedchalice
Ooh, shiny new site!! You can tell I haven't been here for a while!!! lol
Luuuurve the new logo!!!

Anyhoo....get to the point Suzii!!!
For the past few days I've been having problems booting up. It gets so far, like loading all my desktop icons, (but not my wallpaper!!) but won't load any start up programs like Norton, Incredimail, Explorer etc!
When I try a ctrl+alt+del restart I either get the blue 'busy' screen or just a blank screen. :|
I shut down by holding the power button, restart, comp goes straight into a disk scan and everything boots up ok!
I've run spybot & Norton with no results (apart from a DSO Exploit, which I'm trying to find a patch for!)

Anyone got any ideas?!

Thanx
xxxxxxxx
Suzii

PostPosted: Thu Sep 09, 2004 10:40 am
by brad
Please run HiJackThis and Click on the "Config" Button. Now Click on the Misc. Tools Tab. Check the Box next to "List also minor sections (full)"
Click the "Generate StartupList log" Button. Now "Copy and Paste" that Log File into a post.

brad

PostPosted: Thu Sep 09, 2004 10:58 am
by poisonedchalice
Thanx Brad, you're a star! :)

xxxxxx


StartupList report, 09/09/2004, 10:54:31
StartupList version: 1.52
Started from : C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v5.50 (5.50.4134.0600)
* Using default options
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\NORTON INTERNET SECURITY\NISUM.EXE
C:\PROGRAM FILES\NORTON INTERNET SECURITY\CCPXYSVC.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SCM\LEDTRAY.EXE
C:\PROGRAM FILES\LOGITECH\VIDEO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\ADAPTEC SHARED\CREATECD\CREATECD50.EXE
C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SAFE-SHARE\SAFESHARE.EXE
C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\BACKWEB-8876480.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\INCREDIMAIL\BIN\IMAPP.EXE
C:\PROGRAM FILES\LOGITECH\VIDEO\LOWLIGHT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\HPZSTATX.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
LEDTRAY = C:\PROGRA~1\COMMON~1\SCM\LEDTRAY.EXE
LogitechVideoRepair = C:\Program Files\Logitech\Video\ISStart.exe
LogitechVideoTray = C:\Program Files\Logitech\Video\LogiTray.exe
LVComs = C:\WINDOWS\SYSTEM\LVComS.exe
QuickTime Task = "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMON.EXE
CreateCD50 = "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
AdaptecDirectCD = "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
LoadQM = loadqm.exe
Unshare = C:\Program Files\safe-share\SafeShare.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
SSDPSRV = C:\WINDOWS\SYSTEM\ssdpsrv.exe
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
ccEvtMgr = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
Nisum = C:\Program Files\Norton Internet Security\NISUM.EXE
ccPxySvc = C:\PROGRA~1\NORTON~2\CCPXYSVC.EXE
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MoneyAgent = "C:\Program Files\Microsoft Money\System\Money Express.exe"
LDM = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[{89820200-ECBD-11cf-8B85-00AA005B4395}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[>PerUser_MSN_Clean] *
StubPath = C:\WINDOWS\msnmgsr1.exe

[PerUser_LinkBar_URLs] *
StubPath = C:\WINDOWS\COMMAND\sulfnbk.exe /L

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = C:\WINDOWS\SYSTEM\ie4uinit.exe

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=
run=hpfsched

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 31/8/2004, 11:51:54)

[Rename]

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Enumerating Browser Helper Objects:

NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL - {53707962-6F74-2D53-2644-206D7942484F}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Tune-up Application Start.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[IMDownloader Class]
CODEBASE = http://www2.incredimail.com/contents/se ... loader.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNPUPLD.DLL
CODEBASE = http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab

[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/C ... 8168.30625

[RealArcadeRdxIE Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\REALARCADERDXIE.DLL
CODEBASE = http://games-dl.real.com/gameconsole/Bu ... eRdxIE.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shoc ... wflash.cab

[{62475759-9E84-458E-A1AB-5D2C442ADFDE}]
CODEBASE = http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://fpdownload.macromedia.com/get/sh ... tor/sw.cab

[CR64Loader Object]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\RETRO64_LOADER.DLL
CODEBASE = http://www.miniclip.com/bestfriends/retro64_loader.dll

[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CODEBASE = http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab

[Cameractl Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\CAMERA.OCX
CODEBASE = http://www.nwales-traffic.co.uk/files/a ... camera.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
UPnPMonitor: C:\WINDOWS\SYSTEM\UPNPUI.DLL
AUHook: C:\WINDOWS\SYSTEM\AUHOOK.DLL

--------------------------------------------------
End of report, 9,830 bytes
Report generated in 1.138 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

PostPosted: Thu Sep 09, 2004 11:13 am
by brad
One thing:
Get rid of Universal Plug and Play: To remove this program, open Add/Remove Programs / Select / Add/Remove Windows Components / Communications / Uncheck "Universal Plug and Play".
Now reboot. If it still messes up run HJT and post the HJT Log File.
Also, you need to update Windows.
brad

PostPosted: Thu Sep 09, 2004 11:26 am
by poisonedchalice
I know you know what you're talking about, but why do I need to remove Universal Plug & Play? (I didn't even know I had it, but that's me to a T!!! lol)
I'm not being picky or anything, I just like to know why I have to do something before I do it!!!! Tiz the best way to learn about stuff! :wink:

xxxxx
Suzii

PostPosted: Thu Sep 09, 2004 11:52 am
by poisonedchalice
hmm, I can't get into my add/remove program!!!! Get the following error message....

Rundll32 has caused an error in SETUPX.DLL.
Rundll32 will now close

Not my bloomin day is it eh?! lmao

xxxxx

PostPosted: Thu Sep 09, 2004 2:47 pm
by Restek

PostPosted: Thu Sep 09, 2004 3:52 pm
by Cactus
Here's on article at Microsoft of that exact problem Suzii...

http://support.microsoft.com/default.as ... bContent=1


Cactus Image

PostPosted: Fri Sep 10, 2004 9:09 am
by poisonedchalice
I did wonder what I'd being doing today.....now I know.....moving files!!!!! lmao

Thanx Cactus, I'll let you know if works!!!

xxxxxxx
Suzii

PostPosted: Fri Sep 10, 2004 10:27 am
by poisonedchalice
Nope!!! And the next step is to move em all back and reinstall windows....slight problem there tho....I haven't got a windows back up disk!!!! :roll: ......just a reformat disk....Aaaaaaaaaargh, not again!!!! lmao (3 times already this year!!!!) Dolly's not having a good 2004!!!! lol

I'll keep searching and see if I can find another way!

.......I'll be back!!!! lol

xxxxxxx
Suzii

PostPosted: Fri Sep 10, 2004 1:00 pm
by Geekgirl

PostPosted: Fri Sep 10, 2004 1:58 pm
by poisonedchalice
Thanx GeekGirl, I'll give it a try!

Back to my Add/Remove problem tho, and don't swing for me Cactus....lol....it did actually work, but after I rebooted! It didn't occur to me to do so....I've got a lot on my mind at the moment, and it wasn't the first thing that sprung to mind! lol
Thing is, now I've isolated the problem file, there's nothing I can do about it coz I haven't got a WinME back up disk!!! So unless I can actually download a single replacement file, I'm stuffed!!!!

It has meant I've been able to uncheck plug and play tho, even tho I'm still none the wiser why I had to....BRAD?!!!!! lol And Dolly seems to be rebooting ok now....can someone please explain the connection to me?! :|

:)

xxxxxxxx
Suzii

PostPosted: Fri Sep 10, 2004 2:07 pm
by lilpinkflower
You crack me up Suzii :lol: :lol: :lol:

....... soz I have no answers to your missing file... i just wanted you to know i appreciated your humour..... hehe

AND I'm also waiting on the Universal Plug n Play fing...... *taps fingers*... cos none of us know when we may have to remove our own

:D hehehehehehe

lilpink x

PostPosted: Fri Sep 10, 2004 2:37 pm
by poisonedchalice
Oh, you know me, anything to make folk laff!!!! :wink: :lol:

lol

As for the plug n play thingy, I guess Brad's just a busy fella, I'm sure he'll post something totally professional and unintelligible sooner or later! (jus kiddin Brad, you're a star really!!!! :) )

xxxxxxxx
Suzii

PostPosted: Fri Sep 10, 2004 2:52 pm
by Geekgirl
Here's a description of

...and also probably the reason brad has suggested you remove it








.....I could be wrong I often am :|