1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Highjack This Log

Discussion in 'Malware and Virus Removal Archive' started by antiquer61, 2007/08/31.

  1. 2007/08/31
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    I've had problems and Arie got me to this point, thanks Arie!! I hope someone can help further with this log information. I have run Auslogics, Regcure, Housecall, Spy Bot, Registry Smart, Error Killer, Ad Ware, Bit Defender. Nothing has helped up to this point-- I have faith that experts on the forum can figure this out.

    All this started with an error message about symantec Antivirus! I have file folders that are light colored and say Hidden Attributes--msocache,uninstall information, windows update, net hood, application data, local settings, print hood, send to, templates, etc. Can't restore, go into user accounts-can only use admin, add/remove, use help & support center, defragment, etc.

    Lots of information--may be useful--may be useless?? The thread I read said to not just give a copy of the log???

    Thanks in advvance!! Antiquer:D

    Logfile of HijackThis v1.99.1
    Scan saved at 3:31:33 PM, on 8/31/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\PeoplePC\SECURI~1\ADSSER~1.EXE
    C:\WINDOWS\system32\atievxx.exe
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Documents and Settings\All Users\Application Data\PeoplePC\SecurityPack\ppc_isp.exe
    C:\Program Files\PeoplePC\ISP6500\Browser\Bartshel.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Exif Launcher\QuickDCF.exe
    C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
    C:\PROGRA~1\PeoplePC\ISP6500\Browser\PPShared.exe
    C:\Program Files\RegistrySmart\RegistrySmart.exe
    C:\WINDOWS\system32\AuthFw.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.peoplepc.com/websearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://home.peoplepc.com/search
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe "
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Bart Station] C:\Program Files\PeoplePC\ISP6500\BIN\PPCOLink.exe -STATION
    O4 - HKLM\..\Run: [PeoplePC Internet Security Pack] C:\Documents and Settings\All Users\Application Data\PeoplePC\SecurityPack\ppc_isp.exe /minimize
    O4 - HKLM\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
    O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1187813765290
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1187813597408
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{455EE659-88A7-42D5-9F53-FEDE16196E94}: NameServer = 209.244.0.3 209.244.0.4
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: ADSService - Copyright© Aluria Software, LLC - C:\DOCUME~1\ALLUSE~1\APPLIC~1\PeoplePC\SECURI~1\ADSSER~1.EXE
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
    O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: EarthLink Firewall Process Path Service (ElnkFWPPService) - Aluria Software, LLC. - C:\DOCUME~1\ALLUSE~1\APPLIC~1\PeoplePC\SECURI~1\EFWPPS~1.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (file missing)
    O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)
     
  2. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi antiquer61 :)

    Those hidden folders are normal system folders. You're seeing them because something, whether it was you or not I don't know, has enabled the view setting for them.

    Your HijackThis log appears normal. Any chance you know what the Symantec message was, even a part of it? Was it a Symantec message or a Windows message?

    Have you tried creating a new user profile?

    I see a lot of Symantec services, but none of the normal startup entries, nor 1 running process for Symantec. Have you disabled it?
     

  3. to hide this advert.

  4. 2007/09/01
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Thanks for your post, noandfear! I don't know how I hid the system files. Can you guide me to correct the view??

    It's good to know that the log is normal. The message read, C: Program~1\Common~1\Symant~1\Virusd~1\20061103.019 Corrupt and unreadbale. Run Chkdks utility, can't run the utility--this would pop-up all the time at the bottom right of my screen by the security icon--I don't know if this is a Windows or Symantec message--hope you know?? How do I get rid of all the unnecesary files for Symantec or get the file I need to run it??

    I have tried to create a new user profile. It says "Windows cannot open User Accounts control panel. I have tried to uninstall Symantec and can't. I put the foldrs in the Recycle Bin hopong that would help. I can't do much on my computer-get lots of error messages.

    When I attempt to back up I get this:
    Warning: Portions of "\Boot Files\C;\Windows\System 32\
    quartz.dll can't be read
    wmp.dll " " "
    wuaucl tl.exe " " "
    wuaueng/.dll " " "
    drivers\dmboot.sys " " "

    Can't get to the Windows help and support, add/remove, defragment, uninstall, symantec error 1317, scanregw.exe/ backup can't find, qttask.exe corrupt, etc.

    All this happened after Symantec seemed to crash. I don't have any idea what to do?? Any help is appreciated, if you aren't so condused you can't see straight!!

    Thanks, Antiquer:D
     
  5. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Sounds as though you might have deleted some system files. Go to the recycle bin and restore whatever folders/files you just recently deleted (since the problem began).

    Reboot. Let me know if there's any change.
     
  6. 2007/09/01
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Hi, Dave!

    I restored files and rebooted--no change?? I tried to install from the disk. It said it was interrupted before it could be completed. Gave the same message when I tried to patch and uninstall?? Very confusing.:confused: I feel like if I could just get rid of Symantec antivirus maybe things would be fine??
    Thanks, Antiquer:(
     
  7. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You tried to install what from the disk?
     
  8. 2007/09/01
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Install

    Hi!

    Sorry! I tried to remove Symantec, and repair Symantec from a window that opened. Restored files made no change.

    Antiquer:rolleyes:
     
  9. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Click Start>Run and type appwiz.cpl then hit enter. If Add/Remove opens, attempt to uninstall Symantec. You generally have to uninstall the various Symantec products in the correct order, else you will get a message that it can't be removed. If that happens, just try a different Symantec entry. Reboot when complete.

    Download the Norton Removal Tool and run it to clean up any leftovers.

    In the event that Add/Remove does not open, just run the removal tool.

    Reboot when complete and let me know if there's any improvement.
     
  10. 2007/09/01
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Dave,
    Tried appwiz.cpl. Message Windows cannot find appwiz.cpl. I'll go on to Norton and try that.
    Thanks, Antiquer:eek:
     
  11. 2007/09/01
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Dave,

    Norton Removal tool said the following programs were found on your computer, Symantec Antivirus 9 or later. Use Add/Remove before Norton Removal Tool can proceed.

    Thanks, Antiquer:p
     
  12. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Note: You must be logged onto an account with administrator privileges to complete the following.

    Download Deckard's System Scanner (dss.exe) to your desktop.
    Close all applications and windows.
    Double-click on dss.exe to run it and follow the prompts.
    When the scan is complete, two text files will open; main.txt, which will be maximized and extra.txt, which will be minimized.

    Post the contents of main.txt only for now.
     
  13. 2007/09/02
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    deckards scanner

    Hi! Here is the main.txt. Greek to me!!:eek:



    Deckard's System Scanner v20070826.66
    Run by admin on 2007-09-02 05:13:14
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    7: 2007-09-02 12:13:41 UTC - RP7 - Deckard's System Scanner Restore Point
    6: 2007-09-02 01:32:58 UTC - RP6 - Removed Symantec AntiVirus
    5: 2007-09-01 02:46:02 UTC - RP5 - System Checkpoint
    4: 2007-08-31 01:15:56 UTC - RP4 - Removed Symantec AntiVirus
    3: 2007-08-30 03:29:54 UTC - RP3 - Removed Symantec AntiVirus


    -- First Restore Point --
    1: 2007-08-28 23:53:55 UTC - RP1 - System Checkpoint


    Backed up registry hives.
    Performed disk cleanup.

    Total Physical Memory: 320 MiB (512 MiB recommended).


    -- HijackThis (run as admin.exe) -----------------------------------------------

    Unable to find log (file not found); running clone.
    -- HijackThis Clone ------------------------------------------------------------

    Emulating logfile of HijackThis v1.99.1
    Scan saved at 2007-09-02 05:33:59
    Platform: Windows XP Service Pack 2 (5.01.2600)
    MSIE: Internet Explorer (7.00.6000.16473)

    Running processes:
    C:\WINDOWS\system32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Documents and Settings\All Users\Application Data\PeoplePC\SecurityPack\adsservice.exe
    C:\WINDOWS\system32\atievxx.exe
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Documents and Settings\All Users\Application Data\PeoplePC\SecurityPack\ppc_isp.exe
    C:\Program Files\PeoplePC\ISP6500\Browser\BartShel.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Exif Launcher\QuickDCF.exe
    C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
    C:\Program Files\PeoplePC\ISP6500\Browser\PPShared.exe
    C:\Program Files\RegistrySmart\RegistrySmart.exe
    C:\WINDOWS\system32\AuthFw.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\admin\Desktop\Deckards Scanner.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.peoplepc.com/websearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://home.peoplepc.com/search
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll
    O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
    O4 - HKEY_LOCAL_MACHINE\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe "
    O4 - HKEY_LOCAL_MACHINE\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe "
    O4 - HKEY_LOCAL_MACHINE\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKEY_LOCAL_MACHINE\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKEY_LOCAL_MACHINE\..\Run: [Bart Station] C:\Program Files\PeoplePC\ISP6500\BIN\PPCOLink.exe -STATION
    O4 - HKEY_LOCAL_MACHINE\..\Run: [PeoplePC Internet Security Pack] C:\Documents and Settings\All Users\Application Data\PeoplePC\SecurityPack\ppc_isp.exe /minimize
    O4 - HKEY_LOCAL_MACHINE\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
    O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
    O9 - Extra 'Tools' menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: https://www.softpedia.com (HKCU)
    O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1187813765290
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1187813597408
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
    O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{455EE659-88A7-42D5-9F53-FEDE16196E94}: NameServer = 209.244.0.3 209.244.0.4
    O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
    O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
    O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
    O20 - Winlogon Notify: sclgntfy - C:\WINDOWS\system32\sclgntfy.dll (file missing)
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe "
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe "
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe "
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - "C:\Program Files\Symantec AntiVirus\DefWatch.exe "
    O23 - Service: dvpapi - Command Software Systems, Inc. - "C:\Program Files\Common Files\Command Software\dvpapi.exe "
    O23 - Service: EarthLink Firewall Process Path Service (ElnkFWPPService) - Aluria Software, LLC. - C:\Documents and Settings\All Users\Application Data\PeoplePC\SecurityPack\EFWPPService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - "C:\Program Files\Common Files\LightScribe\LSSrvc.exe "
    O23 - Service: SavRoam - Unknown owner - "C:\Program Files\Symantec AntiVirus\SavRoam.exe "
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe "
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Unknown owner - "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe "
    O23 - Service: Symantec AntiVirus - Unknown owner - "C:\Program Files\Symantec AntiVirus\Rtvscan.exe "



    -- File Associations -----------------------------------------------------------

    .reg - regfile - DefaultIcon - unable to read value
    .reg - regfile - shell\open\command - unable to read value


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R0 GRFILTER (CS NDIS Driver) - c:\windows\system32\drivers\grfilter.sys <Not Verified; Authentium, Inc.; NDIS packet redirector driver>
    R2 GRTdiMon (GR TDI Mon) - c:\windows\system32\drivers\grtdimon.sys <Not Verified; Authentium, Inc.; GRTdiMon>
    R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>

    S1 SAVRT - c:\??\c:\program files\symantec antivirus\savrt.sys (file missing)
    S1 SAVRTPEL - c:\??\c:\program files\symantec antivirus\savrtpel.sys (file missing)
    S3 SymEvent - c:\program files\symantec\symevent.sys (file missing)
    S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
    S3 W8335XP (IEEE 802.11g Wireless Cardbus/PCI Adapter HW51) - c:\windows\system32\drivers\mrv8000c.sys <Not Verified; Marvell Semiconductor, Inc; Device driver for Marvell 802.11 NIC>


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 CCALib8 (Canon Camera Access Library 8) - c:\program files\canon\cal\calmain.exe <Not Verified; Canon Inc.; >
    R2 dvpapi - "c:\program files\common files\command software\dvpapi.exe" <Not Verified; Command Software Systems, Inc.; Command AntiVirus for Windows>
    R2 LightScribeService (LightScribeService Direct Disc Labeling Service) - "c:\program files\common files\lightscribe\lssrvc.exe" <Not Verified; Hewlett-Packard Company; LightScribe>

    S2 ccEvtMgr (Symantec Event Manager) - "c:\program files\common files\symantec shared\ccevtmgr.exe" (file missing)
    S2 ccSetMgr (Symantec Settings Manager) - "c:\program files\common files\symantec shared\ccsetmgr.exe" (file missing)
    S2 DefWatch (Symantec AntiVirus Definition Watcher) - "c:\program files\symantec antivirus\defwatch.exe" (file missing)
    S2 Symantec AntiVirus - "c:\program files\symantec antivirus\rtvscan.exe" (file missing)
    S3 ccPwdSvc (Symantec Password Validation) - "c:\program files\common files\symantec shared\ccpwdsvc.exe" (file missing)
    S3 ElnkFWPPService (EarthLink Firewall Process Path Service) - c:\docume~1\alluse~1\applic~1\peoplepc\securi~1\efwpps~1.exe <Not Verified; Aluria Software, LLC.; EFWPPService Service Application>
    S3 SavRoam - "c:\program files\symantec antivirus\savroam.exe" (file missing)
    S3 SNDSrvc (Symantec Network Drivers Service) - "c:\program files\common files\symantec shared\sndsrvc.exe" (file missing)
    S3 SPBBCSvc (Symantec SPBBCSvc) - "c:\program files\common files\symantec shared\spbbc\spbbcsvc.exe" (file missing)


    -- Device Manager: Disabled ----------------------------------------------------

    Class GUID: {6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
    Description: SMC IrCC - Fast Infrared Port
    Device ID: ACPI\SMCF010\5&2920B891&0
    Manufacturer: SMC
    Name: SMC IrCC - Fast Infrared Port
    PNP Device ID: ACPI\SMCF010\5&2920B891&0
    Service: SMCIRDA


    -- Scheduled Tasks -------------------------------------------------------------

    2007-09-01 20:13:32 426 --a------ C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job
    2007-09-01 20:13:00 438 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
    2007-08-31 08:42:14 410 --a------ C:\WINDOWS\Tasks\ErrorKiller Scheduled Scan.job
    2007-08-31 08:42:14 496 --a------ C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
    2007-08-30 08:29:30 372 --a------ C:\WINDOWS\Tasks\RegCure.job


    -- Files created between 2007-08-02 and 2007-09-02 -----------------------------

    2007-08-31 11:26:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-08-31 09:18:31 0 d-------- C:\WINDOWS\BDOSCAN8
    2007-08-30 17:59:44 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
    2007-08-30 08:29:12 0 d-------- C:\Program Files\RegCure
    2007-08-29 20:44:16 0 d-------- C:\Program Files\Symantec
    2007-08-29 18:51:51 0 d-------- C:\Program Files\Symantec AntiVirus
    2007-08-29 17:33:49 0 d-------- C:\Program Files\HP
    2007-08-28 16:53:25 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
    2007-08-28 16:53:20 0 d-------- C:\Documents and Settings\LocalService\Application Data
    2007-08-28 16:53:20 0 d-------- C:\Documents and Settings\LocalService\Application Data\Microsoft
    2007-08-28 16:53:19 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
    2007-08-28 16:48:51 0 d--hs---- C:\found.000
    2007-08-28 14:57:44 0 d-------- C:\Program Files\AusLogics Disk Defrag
    2007-08-28 06:19:08 0 d-------- C:\Program Files\MSXML 4.0
    2007-08-23 07:02:24 0 d-------- C:\Program Files\RegistrySmart
    2007-08-22 18:44:11 49152 --a------ C:\AluriaCacheFile.dat
    2007-08-22 18:40:50 0 d-------- C:\Program Files\Common Files\EarthLink
    2007-08-22 18:40:18 65536 --a------ C:\WINDOWS\system32\ASE.dll <Not Verified; Aluria Software; ASE>
    2007-08-22 18:40:18 65536 --a------ C:\WINDOWS\system32\AluriaReg.dll <Not Verified; Aluria Software; Aluria_Registry_DLL>
    2007-08-22 18:40:17 10752 --a------ C:\WINDOWS\system32\aamd532.dll <Not Verified; Almeida & Andrade Ltda; MD5 Maker DLL>
    2007-08-22 18:40:16 82432 --a------ C:\WINDOWS\system32\msxml4r.dll <Not Verified; Microsoft Corporation; Microsoft(R) MSXML 4.0 SP1>
    2007-08-22 18:40:16 44544 --a------ C:\WINDOWS\system32\msxml4a.dll <Not Verified; Microsoft Corporation; Microsoft(R) MSXML 4.0 SP1>
    2007-08-22 18:40:03 0 d-------- C:\Program Files\Common Files\Command Software
    2007-08-22 18:39:55 368912 --a------ C:\WINDOWS\system32\vbar332.dll <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
    2007-08-22 18:39:55 0 d-------- C:\Documents and Settings\All Users\Application Data\PeoplePC
    2007-08-22 07:35:46 0 d-------- C:\WINDOWS\system32\NtmsData
    2007-08-21 10:31:25 0 d-------- C:\Program Files\PeoplePC Accelerated
    2007-08-21 10:25:58 0 d-------- C:\Documents and Settings\admin\Application Data\ScamBlocker
    2007-08-21 09:54:10 0 d-------- C:\Program Files\Common Files\PeoplePC
    2007-08-21 09:54:09 67584 -----n--- C:\WINDOWS\system32\unPPC.exe <Not Verified; PeoplePC; PeoplePC unPPC>
    2007-08-21 09:54:09 28672 -----n--- C:\WINDOWS\system32\RegHero.exe <Not Verified; ; RegHero Module>
    2007-08-21 09:54:09 18432 -----n--- C:\WINDOWS\system32\PPCInfo.exe <Not Verified; PeoplePC, Inc.; PPCInfo Module>
    2007-08-21 09:54:09 0 d-------- C:\Program Files\PeoplePC


    -- Find3M Report ---------------------------------------------------------------

    2007-09-01 18:58:26 0 d-------- C:\Program Files\microsoft frontpage
    2007-09-01 18:30:28 0 d-------- C:\Program Files\Common Files\Symantec Shared <SYMANT~2>
    2007-08-31 14:13:26 0 d-------- C:\Program Files\AdwareAlert
    2007-08-29 19:47:22 0 d-------- C:\Documents and Settings\admin\Application Data\ErrorKiller
    2007-08-27 20:51:45 0 d-------- C:\Program Files\Common Files
    2007-07-15 19:40:53 0 d-------- C:\Documents and Settings\admin\Application Data\ZoomBrowser EX
    2007-07-09 18:27:42 0 d-------- C:\Program Files\QuickTime


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
    04/10/2007 08:37 AM 232960 --a------ C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{A8FB8EB3-183B-4598-924D-86F0E5E37085} "= C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll [04/10/2007 08:37 AM 232960]

    [-HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
    [HKEY_CLASSES_ROOT\PeoplePal Toolbar]
    [HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
    [HKEY_CLASSES_ROOT\PeoplePal Toolbar]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RemoteControl "= "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [12/08/2003 05:35 PM]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [12/15/2006 03:23 AM]
    "Adobe Reader Speed Launcher "= "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM]
    "QuickTime Task "= "C:\Program Files\QuickTime\qttask.exe" [07/09/2007 06:26 PM]
    "Bart Station "= "C:\Program Files\PeoplePC\ISP6500\BIN\PPCOLink.exe" [03/12/2007 03:11 PM]
    "PeoplePC Internet Security Pack "= "C:\Documents and Settings\All Users\Application Data\PeoplePC\SecurityPack\ppc_isp.exe" [01/26/2006 03:06 PM]
    "RegistrySmart "= "C:\Program Files\RegistrySmart\RegistrySmart.exe" [08/07/2007 12:59 PM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 09:56 PM]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Exif Launcher.lnk - C:\Program Files\Exif Launcher\QuickDCF.exe [10/23/2006 11:04:08 AM]
    Wireless Configuration Utility HW.51.lnk - C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe [12/15/2004 10:41:28 AM]




    -- End of Deckard's System Scanner: finished at 2007-09-02 05:35:57 ------------
     
  14. 2007/09/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Open C:\Windows\system32 and see if you have the file appwiz.cpl
    If so, double click and see if Add/Remove programs opens.

    See if you have the file rstrui.exe located in C:\WINDOWS\system32\Restore
     
  15. 2007/09/02
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Open File

    Good morning!
    I am a true beginner! I can't open C:\Windows\system 32. Please help. I did a search and windows can't find that file???

    Antiquer:eek:
     
  16. 2007/09/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Click Start then Run and type cmd
    Hit enter. Does a command window open?
     
  17. 2007/09/02
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Cmd window

    Yes, a black window opens.
     
  18. 2007/09/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Highlight and copy the following bolded command.

    attrib -h C:\Windows\system32

    Now paste it in the command window, then hit enter.

    See if you now have the C:\Windows\system32 folder.
     
  19. 2007/09/02
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Cmd window

    I copied a pasted (Ctrl V) into the run window. Nothing happened. Typed it into the balck window and nothing happened. Couldn't copy it there, V is all that would come up. I'll have to check on your post later, I have to leave home. Sorry!!

    Thanks, Antiquer
     
  20. 2007/09/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You won't see anything happen, just check if you can navigate to C:\Windows\system32
    (you have to right click>paste .... Ctrl+V won't work)

    See you later! :)
     
  21. 2007/09/02
    antiquer61

    antiquer61 Inactive Thread Starter

    Joined:
    2007/08/28
    Messages:
    16
    Likes Received:
    0
    Cmd window

    Thanks! :D Waiting for husband to "get ready" 1 last post!

    Rt. click > paste worked!! I hit enter and another line C:\windows\Doc and Settings\admin came up under what I pasted. Guess I can't navigate to C:\wind\sys32
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.