--:{prob with windows update}:--

Status
Not open for further replies.

silverTwins

Broken In
i hav windows xp with SP1

recently while trying the windows update page it displayed that i hav recently installed a program which requires a restart.but even after restarting it shows the same problem!!!!!!! :cry:

i hav scanned for viruses and spyware but to no avail!!!!!!!!!!!!!

again i checked Msconfig and runonce in the registry but didnt find any paths!!!!!!!!!

so spammers and geeks plz help :cry:
 

technoteen

Journeyman
the best thing i say is you try and reinstall windows update coz it may have become corrupt

to do so go to C:\WINDOWS\Downloaded Program Files and delete the files for windows update then visit the windows update site, this ma solve your problem
 
OP
S

silverTwins

Broken In
dear svk uninstalling is not an easy job for me coz i stand to lose a lot of time and a lot of stuff!!!!!!!!!!!

as for the mod here is the logfile:

StartupList report, 11/10/2004, 9:09:35 PM
StartupList version: 1.52.2
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\WINDOWS\System32\ZoneLabs\isafe.exe
D:\Program Files\Executive Software\Diskeeper\DkService.exe
D:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
D:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\hkcmd.exe
D:\PROGRA~1\POPUPCOP\PCCloser.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\FlashGet\flashget.exe
D:\Program Files\BitComet\BitComet.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\DOCUME~1\***\LOCALS~1\Temp\Rar$EX00.875\HijackThis.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = D:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

IgfxTray = D:\WINDOWS\System32\igfxtray.exe
HotKeysCmds = D:\WINDOWS\System32\hkcmd.exe
PopUpCopCloser = D:\PROGRA~1\POPUPCOP\PCCloser.exe
AVG7_CC = D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
AVG7_EMC = D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
AVG7_RegCleaner = D:\PROGRA~1\Grisoft\AVG7\avgregcl.exe /BOOT
Zone Labs Client = "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
DiskeeperSystray = "D:\Program Files\Executive Software\Diskeeper\DkIcon.exe"

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MSMSGS = "D:\Program Files\Messenger\msmsgs.exe" /background

--------------------------------------------------

Shell & screensaver key from D:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=D:\WINDOWS\System32\ssmypics.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - (no file) - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - D:\PROGRA~1\FLASHGET\jccatch.dll - {A5366673-E8CA-11D3-9CD9-0090271D075B}
(no name) - d:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
ToolHelper - D:\PROGRA~1\LOKITO~1\LOKITO~1.DLL - {AAAE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}
(no name) - D:\PROGRA~1\FlashFXP\IEFlash.dll - {E5A1691B-D188-4419-AD02-90002030B8EE}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Norton SystemWorks One Button2005 Checkup.job
Symantec NetDetect.job
Symantec Drmc.job

--------------------------------------------------

Enumerating Download Program Files:

[ChkDVDCtl Class]
InProcServer32 = D:\WINDOWS\DOWNLO~1\ChkDVD.dll
CODEBASE = *www.gocyberlink.com/winxp/CheckDVD.cab

[Shockwave Flash Object]
InProcServer32 = D:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = *download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

Protocol #1: imslsp.dll (file MISSING)
Protocol #2: imslsp.dll (file MISSING)
Protocol #3: imslsp.dll (file MISSING)
Protocol #4: D:\WINDOWS\System32\ZoneLabs\vetredir.dll
Protocol #20: D:\WINDOWS\System32\ZoneLabs\vetredir.dll
Protocol #21: imslsp.dll (file MISSING)

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: D:\WINDOWS\system32\SHELL32.dll
CDBurn: D:\WINDOWS\system32\SHELL32.dll
WebCheck: D:\WINDOWS\System32\webcheck.dll
SysTray: D:\WINDOWS\System32\stobject.dll

--------------------------------------------------
End of report, 5,653 bytes
Report generated in 0.187 seconds
 

it_waaznt_me

Coming back to life ..
Well ... I asked HijackThis log .. Anyways ..Now run HijackThis and put a checkmark next to these entries and click on Fix Checked .. Close all Windows explorer and Internet Explorer windows before proceeding ....


D:\DOCUME~1\***\LOCALS~1\Temp\Rar$EX00.875\HijackThis.exe
And please move HijackThis to its own dedicated folder Like C:\Programs\HijackThis so you could find backups of what you fix handy incase anything goes wrong ( It shouldnt btw :p) ...

(no name) - (no file) - {53707962-6F74-2D53-2644-206D7942484F}
ToolHelper - D:\PROGRA~1\LOKITO~1\LOKITO~1.DLL - {AAAE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}
Protocol #1: imslsp.dll (file MISSING)
Protocol #2: imslsp.dll (file MISSING)
Protocol #3: imslsp.dll (file MISSING)
Protocol #21: imslsp.dll (file MISSING)

And then post a new HijackThis log ..
 
OP
S

silverTwins

Broken In
dudes i used norton systemworks 2005 one button scan and removed the invalid entries in the reg.and even hijack this removed the entries still it is showing the same error in the ms site!!!!!!!

here is the hijackthis log file

Logfile of HijackThis v1.98.2
Scan saved at 7:10:05 PM, on 11/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\WINDOWS\System32\ZoneLabs\isafe.exe
D:\Program Files\Executive Software\Diskeeper\DkService.exe
D:\WINDOWS\System32\hkcmd.exe
D:\PROGRA~1\POPUPCOP\PCCloser.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
D:\Program Files\Browser Sentinel\BrowserSentinel.exe
D:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\Program Files\FlashGet\flashget.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\BitComet\BitComet.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\System32\wuauclt.exe
D:\Program Files\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - D:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - D:\PROGRA~1\POPUPCOP\PopUpCop.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PopUpCopCloser] D:\PROGRA~1\POPUPCOP\PCCloser.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] D:\PROGRA~1\Grisoft\AVG7\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "D:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [Browser Sentinel] "D:\Program Files\Browser Sentinel\BrowserSentinel.exe" -autorun
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O12 - Plugin for .avi: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - *www.gocyberlink.com/winxp/CheckDVD.cab

any help!!!!!!!!!!
 

it_waaznt_me

Coming back to life ..
It looks clean now ...

Hmm.. Try removing that CheckDVD DPF ... it seems the problem is somewhere else .. Hmm
 
Status
Not open for further replies.
Top Bottom