Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

servic pack 2


  • Please log in to reply

#1
lynn8706

lynn8706

    New Member

  • Member
  • Pip
  • 7 posts
every time i try to download windows xp Service Pack 2 it never downloads all the way or properly i was told that it was not needed but when i do things it says to do them i need it

can any one help me out pleaseAttached File  log.txt   10.65KB   140 downloads

Edited by lynn8706, 16 July 2005 - 10:06 AM.

  • 0

Advertisements


#2
Dark_Side

Dark_Side

    Member

  • Member
  • PipPipPip
  • 303 posts
Hello, :tazz:

What connection speed are you at? Dialup, Cable, T1?
  • 0

#3
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Hello lynn8706
Hold off on XP2 for right now your computer is infested with a load of garbage !!!

You will want to get it cleaned up prior !!!!!.
Give me a few minutes and I will post back and move this topic to the maleware forum,
  • 0

#4
lynn8706

lynn8706

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
well we have dial up i know we should get DSL or something but i dont pay for it so i cant really change that and i'm pretty much the only one who uses the computer so they dont know how much it can suck


also i'm not great at fixing things at the computer so you may have to be patient with me...but i'm learning ...i think
  • 0

#5
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
This will take a few rounds to get rid of, I need you to do quite a few things please,

Please Download LSPFix and Run the Program.
Disconnect from the Internet and close all Internet Explorer Windows.
Check the "I know what I'm doing" Button and remove all traces of osmim.dll ( Nothing else)
Then Reboot

Go to add/ remove programs and remove the following please

Media Access
Internet Optimizer
AutoUpdate
Web_Rebates
VBouncer
Shopnsave
mywebsearch


Restart your computer after you remove all the above programs,


Next
Go Here

Download install and update Ad-aware , Ewido and download and install Cleanup!
Don't run any of the programs yet just make sure they are updated,

Next Reboot into SAFE MODE

1 - Run cleanup!, Click the cleanup button and let it run, It will ask you to reboot choose NO,

Next Open Ad-aware run a scan and have it fix all it finds, Close out Ad-aware

Next open Ewido, Run a scan with it and save the log from it please,

Restart your computer, Restart HJT and post back a fresh log please,
  • 0

#6
lynn8706

lynn8706

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
ok did what you saidAttached File  Scan_report_20050716.txt.txt   116.66KB   33 downloadsAttached File  log_2.txt   7.85KB   112 downloads
  • 0

#7
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
OK Lynn

Probably a good idea to print out these instructions or save them to not pad,

In the killbox instructions below please copy to note pad the files listed with in the code box, You will need them later on

*Click Here to download Killbox by Option^Explicit.
*Extract the program to your desktop



Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it hjt.
Move HJT into this new folder prior to anything further,
  • Please set your system to show
    all files; please see here if you're unsure how to do this.






  • Close all programs leaving only HijackThis running. Place a check against each of the following:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
    R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
    O4 - HKLM\..\Run: [Windows] run.exe
    O4 - HKLM\..\Run: [Anti-Virus Update Scheduler V1.39.12R] C:\windows\mspaint.exe
    O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe
    O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
    O4 - HKLM\..\Run: [REGRUN] C:\Documents and Settings\Owner\reg.exe
    O4 - HKLM\..\Run: [Norton Antivirus 7.0a] C:\Documents and Settings\Owner\winfw.exe
    O4 - HKLM\..\Run: [PS1] C:\WINDOWS\System32\ps1.exe
    O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
    O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
    O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Imybqo.exe
    O4 - HKLM\..\Run: [bbisvc] C:\WINDOWS\System32\bbisvc.exe
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteine32.exe
    O4 - HKLM\..\Run: [WinLogon] C:\WINDOWS\logon.exe
    O4 - HKLM\..\Run: [Visual Element FX5] C:\DOCUME~1\Owner\LOCALS~1\Temp\See04152005.exe
    O4 - HKLM\..\Run: [tsoV3tP] chacui.exe
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\jaqnqb.exe reg_run
    O4 - HKLM\..\RunServices: [cvmonitor.exe] cvmonitor.exe
    O4 - HKLM\..\RunServices: [Audoi Device Loader] smssv.exe
    O4 - HKLM\..\RunServices: [Windows System Configuration] wincfg.exe
    O4 - HKLM\..\RunServices: [AOL Messenger] aolmsngr.exe
    O4 - HKLM\..\RunServices: [Windows] run.exe
    O4 - HKCU\..\Run: [cB79Rjj2V] fsefx13n.exe
    O8 - Extra context menu item: &Search - http://bar.mywebsear...html?p=ZNxdm414
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
    O15 - Trusted Zone: *.media-motor.net
    O15 - Trusted Zone: *.popuppers.com
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
    O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia...ll/pcs_0002.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1CCCC5A7-720C-48E1-9381-B0494F1F5095}: NameServer = 207.69.188.185 207.69.188.186
    O21 - SSODL: mtklefap - {9227635C-BB42-4B18-669A-83858E92F436} - C:\WINDOWS\System32\boyi32.dll (file missing)
    O21 - SSODL: mtklefa - {EC828A57-C6AB-4DFE-9EB7-AA346D583B23} - C:\WINDOWS\System32\khvmsl32.dll (file missing)
    O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Gofjiaih.dll (file missing)


    Click on Fix Checked when finished and exit Hijackthis


    Double-click on the Killbox folder, then double-click on Killbox.exe to start the program.
    *In the killbox program, select the Delete on Reboot option.
    *Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

    run.exe
    C:\windows\mspaint.exe
    C:\WINDOWS\seeve.exe
    C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    C:\WINDOWS\System32\picsvr\picsvr.exe
    C:\Documents and Settings\Owner\reg.exe
    C:\Documents and Settings\Owner\winfw.exe
    C:\WINDOWS\System32\ps1.exe
    C:\WINDOWS\System32\exp.exe
    C:\WINDOWS\System32\wintask.exe
    C:\WINDOWS\System32\Imybqo.exe
    C:\WINDOWS\System32\bbisvc.exe
    C:\windows\system32\eliteine32.exe
    C:\WINDOWS\logon.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\See04152005.exe
    chacui.exe
    C:\WINDOWS\System32\jaqnqb.exe reg_run
    cvmonitor.exe
    smssv.exe
    wincfg.exe
    aolmsngr.exe
    fsefx13n.exe

    *Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
    *Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.


    Your computer should restart, If it doesn't please restart your computer manually
Post back a fresh HijackThis log and we will take another look.
  • 0

#8
lynn8706

lynn8706

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
here you you go...Attached File  log3.txt   5.25KB   132 downloads
  • 0

#9
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Hi Lynn sorry for the late reply
  • Please set your system to show
    all files; please see here if you're unsure how to do this.





  • Close all programs leaving only HijackThis running. Place a check against each of the following:

    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\fservice.exe
    O4 - HKLM\..\Run: [Aeeifx] C:\Program Files\Shki\Aembnx.exe
    O4 - HKLM\..\Run: [cfgmgr51] RunDLL32.EXE C:\WINDOWS\cfgmgr51.dll,DllRun
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab


    Click on Fix Checked when finished and exit HijackThis.




    Open killbox again and kill the following same way you did earlier please

    C:\WINDOWS\system32\fservice.exe
    C:\Program Files\Shki\Aembnx.exe
    C:\WINDOWS\cfgmgr51.dll,DllRun


    Again your computer should reboot if it doesn't please restart manually
Post back a fresh HijackThis log and we will take another look.
  • 0

#10
lynn8706

lynn8706

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
o im just grateful that you're helping me out

here it is again Attached File  log4.txt   4.99KB   121 downloads
  • 0

#11
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Hi Lynn
  • Close all programs leaving only HijackThis running. Place a check against each of the following:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webfile.com/
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    Click on Fix Checked when finished and exit HijackThis.
Go ahead and see if you can update windows now


Post back a fresh HijackThis log and we will take another look.
  • 0

#12
lynn8706

lynn8706

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
ok here you go Attached File  lex5.txt   4.78KB   104 downloads

when you said see if it'll update windows did you mean service pack 2 cus i didnt do it tongiht cus it's late but thats the only updates it shows
  • 0

#13
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Yes your log is clean now see if you can update to SP2
  • 0

#14
lynn8706

lynn8706

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
it wouldnt let me install it

it didnt say why though
  • 0

#15
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Are you trying to download the updates through Internet Explorer ?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP