Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

comp.mind of it's own


  • This topic is locked This topic is locked

#1
punchclok

punchclok

    New Member

  • Member
  • Pip
  • 9 posts
hello:i did a reinstall of win98 and the darn thing won't shut down when i hit the close button.It also takes forever to do anything.i followed the steps for preparing to use "hijack this"so i hope i am doing this right.thank you.
Logfile of HijackThis v1.99.1
Scan saved at 10:31:08 PM, on 3/17/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMONSEARCH\VCATCH.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HJT.EXE
C:\HIJACK THIS.EXE
C:\PROGRAM FILES HIJACK THIS.EXE
C:\WINDOWS\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.primus.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Primus Canada
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Pop-Up Stopper] "A:\POP-UP STOPPER\DPPS2.EXE"
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [VCatch] C:\PROGRAM FILES\COMMONSEARCH\VCATCH.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.primus.ca
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Have you at anytime prior to this,Visted and or used any products from this Site:
DiamondCS

While Online,go to Add\Remove Programs and remove these:

VCATCH
Bullseye Network\Bargain Buddys

Open HijackThis and put a check by these but DO NOT hit the Fix Checked button yet!

O1 - Hosts: 64.91.255.87 www.dcsresearch.com

O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE

O4 - HKCU\..\Run: [VCatch] C:\PROGRAM FILES\COMMONSEARCH\VCATCH.EXE

Now Make sure ALL WINDOWS and BROWSERS are CLOSED and hit the Fix Checked Button!!

Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.syma...src=sec_doc_nam

After restarting in Safe Mode,Configure Windows to Show All Hidden Files and Folders,this must be done after restarting in Safe Mode!!
Here is a link to help with that:
http://www.bleepingc...showtutorial=62
Make sure to use the Instructions for Windows 98!!!

Locate and Delete this Folder in Bold Print:

C:\PROGRAM FILES\COMMONSEARCH

Look for a Folder on your system labeled:

Bullseye Network
or
Bargain Buddies

When finished, reboot your system again and bring it back up in normal mode. Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> type in MSCONFIG -> click OK.
Make Sure Normal Startup is Checked!!
Select the tab labeled Startup and put a Check by every box there!! Once everything is enabled, run "Hijack This!" and post a new log to this thread!!

Here is a link explaining:
Msconfig
  • 0

#3
punchclok

punchclok

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Logfile of HijackThis v1.99.1
Scan saved at 12:35:06 AM, on 3/19/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES HIJACK THIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.primus.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Primus Canada
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Pop-Up Stopper] "A:\POP-UP STOPPER\DPPS2.EXE"
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.primus.ca
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
  • 0

#4
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Thats a Clean log,Is the PC Running any better?
  • 0

#5
punchclok

punchclok

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts

Thats a Clean log,Is the PC Running any better?

View Post

i'm afraid it is no better.still runs very slow and will not shut off.Is there anything else you could suggest?I appreciate all you have done for me.thank you
  • 0

#6
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Download Microworlds Antivirus Toolkit Utility:
http://www.mwti.net/...e_utilities.asp

Once at the site select Download Link 1
Download,Extract all files and Install!

Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane.

All I need to see is what is displayed in the lower window,so have eScan produce a log and go through and Copy the Infected entried to a Notepad page and post those results here!
  • 0

#7
punchclok

punchclok

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
file c:\windows\command\ebd\ebd.cab tagged as not- a- virus:tool.dos.restart.no action taken.
file c:\program files\online services\at&t\attsetup.exe tagged as not- a- virus:tool.win32.reboot.no action taken
is this what you want?
punchclok
  • 0

#8
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Well,thats not exactly what I was hoping to hear!!

How often do you Defraf the System?

Now often do you Clear the Temp Files?

Also,Can you tell me the System Specs?

How do you connect to the Internet?

When was the last time you Updated Windows?

Windows 98 has several Issues with Shut Down,I will have to Search the Microsoft Knowledgebase to see if I can find something that Applies!

Try to answer these,the best you can!!!

Seeing no signs of Infections left on the PC!

Post back and let me know!!
  • 0

#9
punchclok

punchclok

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
hello again:i defragged after reinstalling win98.

I emptied the temp files at the same time

I connect thru the phone line

I updated all critical windows updates before coming here
operating system
windows 98 se

:processor 233 megahertz intel pentium w/mmx
drives:20.48 gigabytes usable hard drive capacity
20.06 gigabytes hard drive free space

main circuit board

bios:award software 4.51 pg
memory modules:190megabytes installed memory
hope these are the system specs you were referring to. punchclok
  • 0

#10
Dreoid

Dreoid

    New Member

  • Banned
  • Pip
  • 9 posts
Now, I'm not one of the resident experts here, but I would say that the problems you're having with the speed and stability of your computer stem from the fact that you are using Win98 SE on a Pentium 233.

Spend $100 on a new computer that will be 5 times the speed of what you've got.

In fact, all you really need is a new motherboard and processor. Seriously, get a 700mhz P3 and a new motherboard for $25 at a discount computer shop.

Problem solved.

-Dreoid
  • 0

Advertisements


#11
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
I am by no means a Windows 98 Expert and I dont notice a sizeable load on the PC!

The Fact that no scans detect Viruses or any other Infection,I am leaning Towards System Age!!

How old is the PC?

When you look in Msconfig,look under the StartUp Tab,do you see a number of Boxes without Checks in them?

I will see what I can Find out,but the Specs on the Machine are a bit weak!

See If I can round up a Windows 98 Guru!!
  • 0

#12
Guest_usetobe_*

Guest_usetobe_*
  • Guest
i'm of the same opinion, it more than likely relates to the low spec of the machine.

try ebay to pick up a bargain with better spec. :tazz:
  • 0

#13
punchclok

punchclok

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts

i'm of the same opinion, it more than likely relates to the low spec of the machine.

try ebay to pick up a bargain with better spec. :tazz:

View Post


  • 0

#14
punchclok

punchclok

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts

I am by no means a Windows 98 Expert and I dont notice a sizeable load on the PC!

The Fact that no scans detect Viruses or any other Infection,I am leaning Towards System Age!!

How old is the PC?

When you look in Msconfig,look under the StartUp Tab,do you see a number of Boxes without Checks in them?

I will see what I can Find out,but the Specs on the Machine are a bit weak!

See If I can round up a Windows 98 Guru!!

View Post


  • 0

#15
punchclok

punchclok

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
hello again:this is an old computer,how old i don't know.It was given to me for free,so i can live with the slowness,if necessary.windows xp was installed on the comp. when i received it,but crashed shortly after and i was unable to get back into windows(no cd)this is why i installed win 98 and reinstalled it again when it ran so slow and wouldn't shut off.(no better results) I thank you for the wonderful assistance and prompt replys.


in msconfig.all the boxes have check marks

punchclok
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP