1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

DurhamDreamer's Log

Discussion in 'Security and Privacy' started by DurhamDreamer, 2004/07/13.

Thread Status:
Not open for further replies.
  1. 2004/07/13
    DurhamDreamer

    DurhamDreamer Inactive Thread Starter

    Joined:
    2004/07/13
    Messages:
    3
    Likes Received:
    0
    Virus problem/hijack this .txt

    Hello I have just joined BBS after reading some previous posts. I also downloaded Hijack this from ur link as directed in a reply to some1 else prob. I have win32:bispy on my pc and cant find a page on deleting it. Maybe there are registry changes involved (as I found when deleting backdoor.prorat which i had and eventually removed! ; ) - so here is a copy of the hijackthis .txt file - please help me - maybe noahdfear can help you seem to know a lot.....

    Logfile of HijackThis v1.98.0
    Scan saved at 19:03:09, on 13/07/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\logonui.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINDOWS\System32\yvsiihtt.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    C:\WINDOWS\System32\windll32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\AOL 9.0\waol.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\AOL 9.0\shellmon.exe
    C:\Program Files\Common Files\AOL\aoltpspd.exe
    C:\WINDOWS\system32\notpad.exe
    C:\Documents and Settings\michelle\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchcentral.cc/search.php?v=4&aff=3045
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchcentral.cc/index.php?v=4&aff=3045
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchcentral.cc/index.php?v=4&aff=3045
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.co.uk
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pocketsms.com/cool.html
    O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
    O1 - Hosts: 81.211.105.69 lender-search.com
    O1 - Hosts: 81.211.105.68 hot-searches.com
    O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SDWin32 Class - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - C:\WINDOWS\System32\SWin32.dll
    O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\en-us\msntb.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\System32\LVCOMS.EXE
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe "
    O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe
    O4 - HKLM\..\Run: [iixvurf] C:\WINDOWS\System32\yvsiihtt.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update13.js
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [windll32.exe] C:\WINDOWS\System32\windll32.exe
    O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.co.uk
    O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivillage.co.uk/save/makeover.cab
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
    O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.paltalk.com/download/0.x/regdload.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3B0DD5BD-6F77-46CA-A0F8-365CF711071F}: NameServer = 195.93.35.134
    O18 - Filter: text/html - {4F7681E5-6CAF-478D-9CB8-4CA593BEE7FB} - C:\WINDOWS\System32\xplugin.dll
     
  2. 2004/07/13
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Welcome to the boards!
    You might want to try this to remove bispy.

    *edit*
    Have you already downloaded and ran adaware and spybot? If not:

    Download and run Adaware
    Click the button to update it. Then run it. Put a check mark beside everything it finds.

    Then download and run Spybot
     
    Last edited: 2004/07/13

  3. to hide this advert.

  4. 2004/07/13
    DurhamDreamer

    DurhamDreamer Inactive Thread Starter

    Joined:
    2004/07/13
    Messages:
    3
    Likes Received:
    0
    Thanks daizy - i already have spybot but i didnt have adaware - I downloaded it and ran them both - then clicked on the v-cleaner link - it detected 6 viruses - win32:bispy, win32:mitglieder-H, win32:trojan-gen(VC), NcaseSpy, DyfucDldr-1 and Trojano-214 : did you see any irregularities in the HijackThis print out? Please any further help on sorting any of these probems will be much appreciated - this is a wkd site! Ok for now I am downloading AVG free edition and will run it/restart pc. Cheers RSVP
     
  5. 2004/07/13
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Yes, I did see problems with your log. Which is why I suggested you first clean out your computer with Spybot and Adaware. (Make sure you update them both)

    Also do an online scan at Housecall
     
  6. 2004/07/13
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    And after all the cleaning Daizy recommends, run Hijackthis again to generate a new log and post it here. Lots of the trash from the original one should be gone and it will be easier to target the baddies you still have.

    DurhamDreamer - would that indicate you are from the city founded because of St. Cuthbert (the need to move inland and safeguard his bones and relics from Vikings)? The history of Durham City fascinates me - maybe because it's so dang old when compared to places in the US and has such an interesting beginning.
     
    Newt,
    #5
  7. 2004/07/14
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    In addition to the other things suggested, you need to visit Windows Update and install all the criticals offered. :)
     
  8. 2004/07/14
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    It's recommended to uninstall NewDotNet.While off line,, Go to Control Panel add/remove programs and remove it. If you can't find it there go here and follow procedure number 4:
    http://www.newdotnet.com/#remove
    always restart the pc inf prompted.

    Make a new folder and unzip hijackthis to that folder
    C:\Documents and Settings\michelle\AntiSpyware for example

    and post a new log

    has notepad been working correctly,, ive never seen a notpad.exe without an e in it ?
     
  9. 2004/07/20
    DurhamDreamer

    DurhamDreamer Inactive Thread Starter

    Joined:
    2004/07/13
    Messages:
    3
    Likes Received:
    0
    Latest from durhamdreamer

    Hia folks - ok I think I've done everything you guys said == uninstalled newdotnet + removed reg items, auto-updated xp, ran adaware/spybot fixed probs, ran Avast and deleted probs. Below is a new printout from HijackThis could you tell me if any probs remain. I know something is up because although my pc has a 1.33 G processor and 256 M ram it still runs extremely slow (after I click on progs the windows are very slow to open - first a box appears then maybe 20 secs later it is populated with the prog screen....) any ideas? But first cheers people for your help it means a lot that people are doing this sort of thing - putting as much effort into helping people as those virus makers do in disrupting them!! And to Newt - yes I am from the very same place lol - St Cuthbert was the patron saint of Lindesfarne (farne islands - home of the puffin) not far up the coast from ere he is now burried in Durham Cathedral - you know your history m8 ; ) and yeah it is a very old city - it was here back when America was still populated by Native Americans and white Americans were still unborn tadpoles back with their English daddies ; ) just kiddin - if u wanna talk more you can post me again anytime == anyway now here is the hijackthis printout -- see you soon :

    Logfile of HijackThis v1.98.0
    Scan saved at 17:52:14, on 20/07/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\System32\windll32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and

    Settings\michelle\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    http://hot-searches.com/search.php?v=6&aff=0
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    http://hot-searches.com/index.php?v=6&aff=0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://hot-searches.com/index.php?v=6&aff=0
    R1 - HKLM\Software\Microsoft\Internet
    Explorer\Main,Default_Page_URL = http://www.freeserve.co.uk
    R1 - HKCU\Software\Microsoft\Internet Connection
    Wizard,ShellNext = http://www.pocketsms.com/cool.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
    Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
    O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
    O1 - Hosts: 81.211.105.69 lender-search.com
    O1 - Hosts: 81.211.105.68 hot-searches.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
    C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file)
    O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-16FAC1639198}
    - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\en-us\msntb.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
    C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [LVCOMS]
    C:\WINDOWS\System32\LVCOMS.EXE
    O4 - HKLM\..\Run: [AOL Spyware Protection]
    "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe "
    O4 - HKLM\..\Run: [iixvurf] C:\WINDOWS\System32\yvsiihtt.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [windll32.exe] C:\WINDOWS\System32\windll32.exe
    O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.co.uk
    O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) -
    http://makeover.ivillage.co.uk/save/makeover.cab
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
    http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
    O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746}
    (CRegistryDownload Class) - http://download.paltalk.com/download/0.x/regdload.cab
     
  10. 2004/07/20
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Try another virus scan.
    Windll32.exe description:
    File Windll32.exe is related to worm W32.HLLW.Respan.
    See Here.

    Free, online virus scan

    *edit*
    I see it can be a couple of other virii as well, so again, a scan is in order.
     
    Last edited: 2004/07/20
  11. 2004/07/20
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    In addition to Daizy's suggestion, download CWShredder from my signature. Save it to your desktop.

    Right click the desktop and choose new>folder. Name it HJT. Cut and paste HijackThis.exe to that folder. That will keep backup files from scattering all over the desktop. When you do a new HJT scan, after the log opens from being saved, press Ctrl+A to select all, then Ctrl+C to copy, and open a reply window here and paste.

    It may be helpful if you fix the following with HJT now (after moving it to new folder), by scanning and placing a check next to each entry, closing ALL other windows and click 'fix checked'. Then reboot and remove the necessary files.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://hot-searches.com/search.php?v=6&aff=0
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://hot-searches.com/index.php?v=6&aff=0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hot-searches.com/index.php?v=6&aff=0
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pocketsms.com/cool.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =*hot-searches.com*;*lender-search.com*
    O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
    O1 - Hosts: 81.211.105.69 lender-search.com
    O1 - Hosts: 81.211.105.68 hot-searches.com
    O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file)
    O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.dll (file missing)
    O4 - HKLM\..\Run: [iixvurf] C:\WINDOWS\System32\yvsiihtt.exe <<< Delete this file after reboot.
    O4 - HKCU\..\Run: [windll32.exe] C:\WINDOWS\System32\windll32.exe
    O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe <<<< Information about this virus here.


    Right click My Computer and choose properties. On system restore tab, check the box to turn off. OK out.

    Open CWShredder, close ALL other windows and click fix.

    Go to start>run and type msconfig, hit enter. On the boot.ini tab, check the box next to /safeboot and OK. Yes to restart. This will restart your computer in safe mode.

    Now in safe mode, you will need to show hidden files and folders.

    Delete the files/folders already pointed out by Daizy, myself and TrendMicro link.
    Open C:\Windows\Temp, select all and delete.
    Open C:\Documents and settings\username\Local Settings\temp, select all and delete. Do this for all usernames.
    Open C:\Windows\Prefetch, select all and delete.
    Open My Computer, right click Local disk C: and choose properties, then disk cleanup. Check all boxes except compress old files and OK.
    Uncheck the /safeboot box in msconfig and ok to reboot.

    Back in Windows, you can re-enable system restore. You still need to visit Windows Update. Click start>all programs and select Windows Update from the upper left-hand column. Scan and accept all critical updates.
    Reboot and go back to Windows Update until there are no more criticals offered. Then scan again and post a new log.
     
  12. 2004/08/14
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Did you ever get this resolved DurhamDreamer ?
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.