Computer Hope

Other => Other => Topic started by: Steven2006 on August 14, 2006, 06:51:12 AM

Title: How can I get rid of it?
Post by: Steven2006 on August 14, 2006, 06:51:12 AM
Hello to all fellow forum members,

I have encountered this pop-up message, "Generic host Process for Win 32 Service has encountered a problem and need to close down.....", whenever I am online. It usually appears after maybe 10/20 mins whenever i am online.

After I closed the pop-up window, everything except the Internet connection is fine-I was disconnected eventhough the connection icon is still indicating that the Internet connection is on. I tried to bring out the connecion window in order to reconnect, and it didn't work.

Anyone out there can give me some advices, and your help will be fully appreciated, thanks

Steven
Title: Re: How can I get rid of it?
Post by: GX1_Man on August 14, 2006, 06:59:33 AM
Did this just start or it has been going on for a while?

What spyware/virus protection are you using?

What Windows? What service pack? All Microsoft updates loaded?

Here's a good read:

http://www.computerhope.com/cgi-bin/yabb/YaBB.cgi?num=1149948530
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 14, 2006, 08:03:29 AM
Hi GXi_Man,

Thanks for your reply.

This problem just started about 3 days ago.
I am using ad-aware 6 and spybot-search and destroy. Besides that I have downloaded a program(FixBlast) to fix the so-called W32.Blaster.Worm virus, which have been known for causing this problem, unfortunately it didn't work.

I am using the Window xp professional.

Service pack???

I believe i don't all the MS updated loaded.

Thanks and looking forward to your advice.

Steven
Title: Re: How can I get rid of it?
Post by: GX1_Man on August 14, 2006, 08:10:49 AM
Quote
Service pack???
I believe i don't all the MS updated loaded.

You should have Service Pack 2 and all updates applied, at the least.

Look in Control Panel/System and see what it says right below your version of Windows.

Use Microsoft Update.

The key to this is using your prevention/removal tools in Safe Mode with System Restore turned off. Otherwise you can just reinfect yourself.

Title: Re: How can I get rid of it?
Post by: Steven2006 on August 14, 2006, 08:26:01 AM
Hi GXi_Man,

Control Panel/System says -
Microsoft Windows XP
Professional
Version 2002
Service Pack 2

"Use Ms Update" means I have to download them from MS homepage?

"The key to this is using your prevention/removal tools in Safe Mode with System Restore turned off. Otherwise you can just reinfect yourself." - This part I am not quite sure that i am fully understood.

Could you pls list out the step(s) of doing it :) How do I get into the Safe Mode and how to turn off the System Restore..

Thanks again

Steven

P.S At the time of this writing, the mentioned message was pop-up again and i was disconnect from the Internet after I clicked on the "Don't Send" button.
Title: Re: How can I get rid of it?
Post by: GX1_Man on August 14, 2006, 09:45:27 AM
Under the Start Window should be Windows Update. Click on that and follow along.

Safe Mode can be entered by pressing F8 a few times when the machine starts BEFORE the Windows logo.

Here is some info on System Restore:

http://www.geocities.com/tmbzone_cfb/system_restore.htm

http://support.microsoft.com/kb/306084/

Is that a real Windows CD by the way?
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 14, 2006, 10:12:13 AM
Hi GXi_Man,

Thanks for your info.

What do you meant by "Is that a real Windows CD by the way?"? and does it mean something in solving this problem?

Thanks,
Steven
Title: Re: How can I get rid of it?
Post by: squirrel on August 14, 2006, 10:22:08 AM
is the CD new and shiny, and does it say microsoft?
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 14, 2006, 12:28:27 PM
Hi all,

The problem is still there, any more suggestions?

thanks,
Steven
Title: Re: How can I get rid of it?
Post by: GX1_Man on August 14, 2006, 01:20:34 PM
Quote
[highlight]is the CD new and shiny, and does it say microsoft[/highlight]?

What EXACTLY have you done so far?
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 15, 2006, 09:26:37 AM
Hi GXi_Man,

I have been encountered this problem almost 3 days from now. It seems like it appeared form nowhere. As far as I could recall, I didn't download anything suspicious from the Internet, and everything was fine before this error message started to pop up.

In addition, I have scanned my pc with antivirus and spyware programs i could get my hands on, like Norton, avg, ad-aware, spybot-search and destroy in safe mode. I also downloaded updates from Microsoft.

For your reference, this is the info i got from the error message pop-up

Error signature
EventType: BEX P1:svchost.exe P2:5.1.2600.2180 P3:41107ed6
P4:netapi32.dll P5:5.1.2600.2180 P6:411096ac P7:0000a3c0
P8:c0000409 P9:00000000

Technical info for this error
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\svchost.exe.mdmp
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\appcompat.txt

Logfile of HijackThis v1.99.1

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\MetaTrader Data Center\mtdcsrv.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\BeenLee\LOCALS~1\Temp\Rar$EX00.734\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155570321328
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://seevideo.co.kr/pub/seevideo2003/SVPorsche.cab
O16 - DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} (WebDigiNet Control) - http://ifocus.no-ip.info/WebDiginet.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E6A0D90-51EE-4479-BF60-E9ECB998B1EF}: NameServer = 202.188.0.133 202.188.1.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{D37993D3-C149-4F2C-86E1-D4FC9E2222F9}: NameServer = 202.188.0.133,202.188.1.5
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 15, 2006, 09:43:55 AM
This is the log after the error message appeared,

Logfile of HijackThis v1.99.1
Scan saved at 11:35:12 PM, on 8/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\MetaTrader Data Center\mtdcsrv.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\BeenLee\LOCALS~1\Temp\Rar$EX12.594\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155570321328
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://seevideo.co.kr/pub/seevideo2003/SVPorsche.cab
O16 - DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} (WebDigiNet Control) - http://ifocus.no-ip.info/WebDiginet.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E6A0D90-51EE-4479-BF60-E9ECB998B1EF}: NameServer = 202.188.0.133 202.188.1.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{D37993D3-C149-4F2C-86E1-D4FC9E2222F9}: NameServer = 202.188.0.133,202.188.1.5
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 16, 2006, 08:37:04 AM
Hi anyone out there has any new ideas how to fix this problem?


Thanks,
Steven
Title: Re: How can I get rid of it?
Post by: Zylstra on August 16, 2006, 08:21:11 PM
Steven2006
Did I help you in the CH Chat with this problem?

If so, I can provide the links I gave you earlier for the Microsoft help search?
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 17, 2006, 04:54:09 AM
Hi all,



This problem "Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry for the inconvenience."

Error signature
EventType:BEX P1:svchost.exe P2:5.1.2600.2180 P3:41107ed6
P4: netapi32.dll P5: 5.1.2600.2180 P6:411096ac P7:0000a3c0
P8:c0000409 P9:00000000

Technical info for this error
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\svchost.exe.mdmp
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\appcompat.txt

Is happened whenever I am browsing the Internet. It doesn't matter whether I am using Firefox or IE. When this error messager window pop-up, my connection to the Internet will be closed soon, eventhough the connection icon is still indicating that the connection is on. I try to click on the computer icon (connection) in order to bring up the connection window, it just flash and disappear.

I scanned my pc with AVG, Norton, spybot, fixSasser, ewido, free sasser removal too and fixblaster program(s) and no virus is found. I also downloaded some windows updates.

Is this problem of my system or network connection-svchost.exe.mdmp, appcompat.txt?

Can anyone intrepret the log files i posted in the previous reply and spot some unusual activities?

I don't think we chat before, anyway can you give the link as you mentioned and I will try it to see if it works.

Any idea what's happened?

Thanks,
Title: Re: How can I get rid of it?
Post by: infoseeker on August 17, 2006, 05:25:46 AM
Hi Steven,
i think some advice of GX1, you did not follow.
He ask you what Antispyware/virus, but you only mentioned the Anti Spyware
and did you read below of his post
Quote
Please post as much information about your computer, operating system, and problem as possible. Too much is OK, too little is pointless! Please don't just say "My computer doesn't work. What's wrong?"
and please post what happen/result of your Anti-Spyware and Anti Virus results

im not so expert in HJT, but i noticed you have 2 anti virus
*NORTON
*AVG
 please if possible uninstall one of those
if you decide to AVG then uninstall NORTON or vice versa

Because your pc is getting wierd when scannning

When uninstall one of your AV, restart your pc in SAFE MODE

Then Scan your pc with your AV and AntiSpyware (Still in SAFE MODE) immunized, clean, delete etc.. what ever you call for the result

Then follow this step for "turning OFF your System REstore"

Quote
For Windows XP:

1: Right click on the My Computer icon on your desktop and select properties.
2: Click on the system restore tab.
3: Check the box that says "Turn off system restore on all drives". Click OK.
4: Click Yes when you are prompted to restart the computer
5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.

why:

Quote from:
If you have been infected with any trojans, spyware, etc, they could have been saved in System Restore and are waiting to re-infect you. Since System Restore is a protected directory, your tools can not access it to delete files that may contain viruses inside them. Please follow instructions to disable system restore but only after you have already cleaned your system of the malware. Keeping even infected restore points around while we are fixing things may prove useful if something goes wrong during the process.

Disable And Enable System Restore

The reason for doing this after your system has been completely cleaned of problems, is so we can remove possible infected restore points. When you disable system restore, it removes restore points! Then you should reboot and then re-enable system restore.

then restart your pc in normal mode
then "turn ON you Sytem restore" by following the above procedure (but turn on)

>>infoseeker / jhempelayo<<
Title: Re: How can I get rid of it?
Post by: unlovedwarrior on August 17, 2006, 11:22:49 AM
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1  


download this file extract the files(put them on your desktop so u can find them easier) restart in safe mode and run the "run this".bat file

post back if that helps.


Title: Re: How can I get rid of it?
Post by: Steven2006 on August 17, 2006, 11:28:32 AM
Hi infoseeker,

Thanks for your precios time and advice

I am using Norton for antivirus, and Ad-aware/Spoybot for spyware. I had used them all in safe mode but found no virus or spyware.

Yes I had post my system info in my previous replies within this thread which is,

Microsoft Window XP professional
version 2002
Service Pack 2

Intel(R)
Pentium(R) 4 CPU 2.66GHz
512 MB of RAM

For the problem part I have listed out very clearly in the previous replies also, if you have time have a look at them.

As you suggested, I also have uninstalled AVG antivirus leaving only Norton.

Scanned using both AV and AntiSpyware in safe mode

Turned off System Restore in safe mode

"Disable and Enable System Restore", this part not quite sure what you're trying to say,..

Then enabled SR again in normal mode (because you can't re-enabled SR in safe mode after disabled it in safe mode)

Please let me know if I have done it correctly.

Thanks,
Steven
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 18, 2006, 06:50:29 AM
Hi unlovedwarrior,

Thanks for your help, but it doesn't work, and the problem is still there.

Any other possible solution?

Thanks,
Steven
Title: Re: How can I get rid of it?
Post by: unlovedwarrior on August 18, 2006, 04:06:45 PM
it might just be easier to back up all of your data and reformat
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 19, 2006, 08:58:25 AM
Hi unlovedwarrior,

Since I'm not computer savy, could you be kind enough to show me the steps how to reformat my pc and back up my data.

Your help will be fully appreciated.

Thanks,
Steven
Title: Re: How can I get rid of it?
Post by: GX1_Man on August 19, 2006, 09:18:50 AM
Steven,

How old are you and what are all the details about your computer, including what Windows CD or whatever you have and what are the main programs running. ALL of the hardware is important - CD burner, etc.
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 20, 2006, 06:02:26 AM
Hi

I am using windows xp professional as my os, and microsoft office.

Dvd drive and e drive, no other hardware connected.

thankds,
Steven
Title: Re: How can I get rid of it?
Post by: GX1_Man on August 20, 2006, 10:12:52 AM
With no CD burner, you will either have to back up data to a pen drive, or across a network to a computer htat does have a CDRW or use floppies, if that is an option.

To reinstall, have a read here. There are lots of pictures:

Have a read here and follow along AFTER you back up your data:

http://www.theeldergeek.com/xp_home_install_-_graphic.htm

Is this a real XP Pro CD from Microsoft you have to work with?
Title: Re: How can I get rid of it?
Post by: patio on August 20, 2006, 12:35:31 PM
Quote
Quote
[highlight]is the CD new and shiny, and does it say microsoft[/highlight]?

What EXACTLY have you done so far?


This query went un replied to 4 times...

patio.    8-)
Title: Re: How can I get rid of it?
Post by: GX1_Man on August 20, 2006, 04:00:23 PM
Quote
is the CD new and shiny, and does it say microsoft?

Did we ever get this addressed? I don't think so.
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 31, 2006, 10:15:36 AM
Hi all thanks for your helps,

I believe that i've solved this problem without reformatting my pc.

Thanks,
Steven
Title: Re: How can I get rid of it?
Post by: dl65 on August 31, 2006, 11:08:33 AM
Steven2006... Perhaps you could tell us what you did to fix your issue .
We would appreciate that .

dl65  ::)
Title: Re: How can I get rid of it?
Post by: unlovedwarrior on August 31, 2006, 11:16:53 AM
if you have not already read this it might be a good read


http://www.updatexp.com/msblast-exe.html

its kinda old but  
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 31, 2006, 01:05:03 PM
Hi,

I just downloaded and installed a specific patch from Microsoft.

Thanks
Title: Re: How can I get rid of it?
Post by: unlovedwarrior on August 31, 2006, 01:06:45 PM
did it solve the problem??
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 31, 2006, 01:13:09 PM
Yes, so far so good.

The problem has not shown up anymore.

I think this issue has been discussed all over the net, the trick is that you have to know which patch to install, since there are so many patches to choose from, I think.

Hopely, the problem won't come up again.

Steven
Title: Re: How can I get rid of it?
Post by: unlovedwarrior on August 31, 2006, 01:15:05 PM
IF it does then came back
Title: Re: How can I get rid of it?
Post by: Steven2006 on August 31, 2006, 01:17:49 PM
Thanks alot for the help.
Title: Re: How can I get rid of it?
Post by: unlovedwarrior on August 31, 2006, 01:18:31 PM
glad to help