Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: How can I get rid of it?  (Read 10247 times)

0 Members and 1 Guest are viewing this topic.

Steven2006

  • Guest
How can I get rid of it?
« on: August 14, 2006, 06:51:12 AM »
Hello to all fellow forum members,

I have encountered this pop-up message, "Generic host Process for Win 32 Service has encountered a problem and need to close down.....", whenever I am online. It usually appears after maybe 10/20 mins whenever i am online.

After I closed the pop-up window, everything except the Internet connection is fine-I was disconnected eventhough the connection icon is still indicating that the Internet connection is on. I tried to bring out the connecion window in order to reconnect, and it didn't work.

Anyone out there can give me some advices, and your help will be fully appreciated, thanks

Steven

GX1_Man

  • Guest
Re: How can I get rid of it?
« Reply #1 on: August 14, 2006, 06:59:33 AM »
Did this just start or it has been going on for a while?

What spyware/virus protection are you using?

What Windows? What service pack? All Microsoft updates loaded?

Here's a good read:

http://www.computerhope.com/cgi-bin/yabb/YaBB.cgi?num=1149948530

Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #2 on: August 14, 2006, 08:03:29 AM »
Hi GXi_Man,

Thanks for your reply.

This problem just started about 3 days ago.
I am using ad-aware 6 and spybot-search and destroy. Besides that I have downloaded a program(FixBlast) to fix the so-called W32.Blaster.Worm virus, which have been known for causing this problem, unfortunately it didn't work.

I am using the Window xp professional.

Service pack???

I believe i don't all the MS updated loaded.

Thanks and looking forward to your advice.

Steven

GX1_Man

  • Guest
Re: How can I get rid of it?
« Reply #3 on: August 14, 2006, 08:10:49 AM »
Quote
Service pack???
I believe i don't all the MS updated loaded.

You should have Service Pack 2 and all updates applied, at the least.

Look in Control Panel/System and see what it says right below your version of Windows.

Use Microsoft Update.

The key to this is using your prevention/removal tools in Safe Mode with System Restore turned off. Otherwise you can just reinfect yourself.


Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #4 on: August 14, 2006, 08:26:01 AM »
Hi GXi_Man,

Control Panel/System says -
Microsoft Windows XP
Professional
Version 2002
Service Pack 2

"Use Ms Update" means I have to download them from MS homepage?

"The key to this is using your prevention/removal tools in Safe Mode with System Restore turned off. Otherwise you can just reinfect yourself." - This part I am not quite sure that i am fully understood.

Could you pls list out the step(s) of doing it :) How do I get into the Safe Mode and how to turn off the System Restore..

Thanks again

Steven

P.S At the time of this writing, the mentioned message was pop-up again and i was disconnect from the Internet after I clicked on the "Don't Send" button.
« Last Edit: August 14, 2006, 08:28:30 AM by Steven2006 »

GX1_Man

  • Guest
Re: How can I get rid of it?
« Reply #5 on: August 14, 2006, 09:45:27 AM »
Under the Start Window should be Windows Update. Click on that and follow along.

Safe Mode can be entered by pressing F8 a few times when the machine starts BEFORE the Windows logo.

Here is some info on System Restore:

http://www.geocities.com/tmbzone_cfb/system_restore.htm

http://support.microsoft.com/kb/306084/

Is that a real Windows CD by the way?

Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #6 on: August 14, 2006, 10:12:13 AM »
Hi GXi_Man,

Thanks for your info.

What do you meant by "Is that a real Windows CD by the way?"? and does it mean something in solving this problem?

Thanks,
Steven

squirrel

  • Guest
Re: How can I get rid of it?
« Reply #7 on: August 14, 2006, 10:22:08 AM »
is the CD new and shiny, and does it say microsoft?

Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #8 on: August 14, 2006, 12:28:27 PM »
Hi all,

The problem is still there, any more suggestions?

thanks,
Steven

GX1_Man

  • Guest
Re: How can I get rid of it?
« Reply #9 on: August 14, 2006, 01:20:34 PM »
Quote
[highlight]is the CD new and shiny, and does it say microsoft[/highlight]?

What EXACTLY have you done so far?

Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #10 on: August 15, 2006, 09:26:37 AM »
Hi GXi_Man,

I have been encountered this problem almost 3 days from now. It seems like it appeared form nowhere. As far as I could recall, I didn't download anything suspicious from the Internet, and everything was fine before this error message started to pop up.

In addition, I have scanned my pc with antivirus and spyware programs i could get my hands on, like Norton, avg, ad-aware, spybot-search and destroy in safe mode. I also downloaded updates from Microsoft.

For your reference, this is the info i got from the error message pop-up

Error signature
EventType: BEX P1:svchost.exe P2:5.1.2600.2180 P3:41107ed6
P4:netapi32.dll P5:5.1.2600.2180 P6:411096ac P7:0000a3c0
P8:c0000409 P9:00000000

Technical info for this error
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\svchost.exe.mdmp
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\appcompat.txt

Logfile of HijackThis v1.99.1

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\MetaTrader Data Center\mtdcsrv.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\BeenLee\LOCALS~1\Temp\Rar$EX00.734\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155570321328
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://seevideo.co.kr/pub/seevideo2003/SVPorsche.cab
O16 - DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} (WebDigiNet Control) - http://ifocus.no-ip.info/WebDiginet.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E6A0D90-51EE-4479-BF60-E9ECB998B1EF}: NameServer = 202.188.0.133 202.188.1.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{D37993D3-C149-4F2C-86E1-D4FC9E2222F9}: NameServer = 202.188.0.133,202.188.1.5
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\

Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #11 on: August 15, 2006, 09:43:55 AM »
This is the log after the error message appeared,

Logfile of HijackThis v1.99.1
Scan saved at 11:35:12 PM, on 8/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\MetaTrader Data Center\mtdcsrv.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\BeenLee\LOCALS~1\Temp\Rar$EX12.594\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155570321328
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://seevideo.co.kr/pub/seevideo2003/SVPorsche.cab
O16 - DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} (WebDigiNet Control) - http://ifocus.no-ip.info/WebDiginet.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E6A0D90-51EE-4479-BF60-E9ECB998B1EF}: NameServer = 202.188.0.133 202.188.1.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{D37993D3-C149-4F2C-86E1-D4FC9E2222F9}: NameServer = 202.188.0.133,202.188.1.5
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON

Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #12 on: August 16, 2006, 08:37:04 AM »
Hi anyone out there has any new ideas how to fix this problem?


Thanks,
Steven

Zylstra

  • Moderator


  • Hacker

  • The Techinator!
  • Thanked: 45
    • Yes
    • Technology News and Information
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 7
Re: How can I get rid of it?
« Reply #13 on: August 16, 2006, 08:21:11 PM »
Steven2006
Did I help you in the CH Chat with this problem?

If so, I can provide the links I gave you earlier for the Microsoft help search?

Steven2006

  • Guest
Re: How can I get rid of it?
« Reply #14 on: August 17, 2006, 04:54:09 AM »
Hi all,



This problem "Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry for the inconvenience."

Error signature
EventType:BEX P1:svchost.exe P2:5.1.2600.2180 P3:41107ed6
P4: netapi32.dll P5: 5.1.2600.2180 P6:411096ac P7:0000a3c0
P8:c0000409 P9:00000000

Technical info for this error
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\svchost.exe.mdmp
C:.DOCUME~1\BeenLee\LOCALS~1\Temp\WERF345.dif00\appcompat.txt

Is happened whenever I am browsing the Internet. It doesn't matter whether I am using Firefox or IE. When this error messager window pop-up, my connection to the Internet will be closed soon, eventhough the connection icon is still indicating that the connection is on. I try to click on the computer icon (connection) in order to bring up the connection window, it just flash and disappear.

I scanned my pc with AVG, Norton, spybot, fixSasser, ewido, free sasser removal too and fixblaster program(s) and no virus is found. I also downloaded some windows updates.

Is this problem of my system or network connection-svchost.exe.mdmp, appcompat.txt?

Can anyone intrepret the log files i posted in the previous reply and spot some unusual activities?

I don't think we chat before, anyway can you give the link as you mentioned and I will try it to see if it works.

Any idea what's happened?

Thanks,

infoseeker

  • Guest
Re: How can I get rid of it?
« Reply #15 on: August 17, 2006, 05:25:46 AM »
Hi Steven,
i think some advice of GX1, you did not follow.
He ask you what Antispyware/virus, but you only mentioned the Anti Spyware
and did you read below of his post
Quote
Please post as much information about your computer, operating system, and problem as possible. Too much is OK, too little is pointless! Please don't just say "My computer doesn't work. What's wrong?"
and please post what happen/result of your Anti-Spyware and Anti Virus results

im not so expert in HJT, but i noticed you have 2 anti virus
*NORTON
*AVG
 please if possible uninstall one of those
if you decide to AVG then uninstall NORTON or vice versa

Because your pc is getting wierd when scannning

When uninstall one of your AV, restart your pc in SAFE MODE

Then Scan your pc with your AV and AntiSpyware (Still in SAFE MODE) immunized, clean, delete etc.. what ever you call for the result

Then follow this step for "turning OFF your System REstore"

Quote
For Windows XP:

1: Right click on the My Computer icon on your desktop and select properties.
2: Click on the system restore tab.
3: Check the box that says "Turn off system restore on all drives". Click OK.
4: Click Yes when you are prompted to restart the computer
5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.

why:

Quote from:
If you have been infected with any trojans, spyware, etc, they could have been saved in System Restore and are waiting to re-infect you. Since System Restore is a protected directory, your tools can not access it to delete files that may contain viruses inside them. Please follow instructions to disable system restore but only after you have already cleaned your system of the malware. Keeping even infected restore points around while we are fixing things may prove useful if something goes wrong during the process.

Disable And Enable System Restore

The reason for doing this after your system has been completely cleaned of problems, is so we can remove possible infected restore points. When you disable system restore, it removes restore points! Then you should reboot and then re-enable system restore.

then restart your pc in normal mode
then "turn ON you Sytem restore" by following the above procedure (but turn on)

>>infoseeker / jhempelayo<<
« Last Edit: August 17, 2006, 05:26:25 AM by infoseeker »

unlovedwarrior



    Guru

  • someday this name will be known
  • Thanked: 13
    Re: How can I get rid of it?
    « Reply #16 on: August 17, 2006, 11:22:49 AM »
    http://noahdfear.geekstogo.com/click%20counter/click.php?id=1  


    download this file extract the files(put them on your desktop so u can find them easier) restart in safe mode and run the "run this".bat file

    post back if that helps.


    « Last Edit: August 17, 2006, 11:23:15 AM by unlovedwarrior »

    Steven2006

    • Guest
    Re: How can I get rid of it?
    « Reply #17 on: August 17, 2006, 11:28:32 AM »
    Hi infoseeker,

    Thanks for your precios time and advice

    I am using Norton for antivirus, and Ad-aware/Spoybot for spyware. I had used them all in safe mode but found no virus or spyware.

    Yes I had post my system info in my previous replies within this thread which is,

    Microsoft Window XP professional
    version 2002
    Service Pack 2

    Intel(R)
    Pentium(R) 4 CPU 2.66GHz
    512 MB of RAM

    For the problem part I have listed out very clearly in the previous replies also, if you have time have a look at them.

    As you suggested, I also have uninstalled AVG antivirus leaving only Norton.

    Scanned using both AV and AntiSpyware in safe mode

    Turned off System Restore in safe mode

    "Disable and Enable System Restore", this part not quite sure what you're trying to say,..

    Then enabled SR again in normal mode (because you can't re-enabled SR in safe mode after disabled it in safe mode)

    Please let me know if I have done it correctly.

    Thanks,
    Steven

    Steven2006

    • Guest
    Re: How can I get rid of it?
    « Reply #18 on: August 18, 2006, 06:50:29 AM »
    Hi unlovedwarrior,

    Thanks for your help, but it doesn't work, and the problem is still there.

    Any other possible solution?

    Thanks,
    Steven

    unlovedwarrior



      Guru

    • someday this name will be known
    • Thanked: 13
      Re: How can I get rid of it?
      « Reply #19 on: August 18, 2006, 04:06:45 PM »
      it might just be easier to back up all of your data and reformat

      Steven2006

      • Guest
      Re: How can I get rid of it?
      « Reply #20 on: August 19, 2006, 08:58:25 AM »
      Hi unlovedwarrior,

      Since I'm not computer savy, could you be kind enough to show me the steps how to reformat my pc and back up my data.

      Your help will be fully appreciated.

      Thanks,
      Steven
      « Last Edit: August 19, 2006, 09:02:33 AM by Steven2006 »

      GX1_Man

      • Guest
      Re: How can I get rid of it?
      « Reply #21 on: August 19, 2006, 09:18:50 AM »
      Steven,

      How old are you and what are all the details about your computer, including what Windows CD or whatever you have and what are the main programs running. ALL of the hardware is important - CD burner, etc.

      Steven2006

      • Guest
      Re: How can I get rid of it?
      « Reply #22 on: August 20, 2006, 06:02:26 AM »
      Hi

      I am using windows xp professional as my os, and microsoft office.

      Dvd drive and e drive, no other hardware connected.

      thankds,
      Steven

      GX1_Man

      • Guest
      Re: How can I get rid of it?
      « Reply #23 on: August 20, 2006, 10:12:52 AM »
      With no CD burner, you will either have to back up data to a pen drive, or across a network to a computer htat does have a CDRW or use floppies, if that is an option.

      To reinstall, have a read here. There are lots of pictures:

      Have a read here and follow along AFTER you back up your data:

      http://www.theeldergeek.com/xp_home_install_-_graphic.htm

      Is this a real XP Pro CD from Microsoft you have to work with?
      « Last Edit: August 20, 2006, 10:13:35 AM by GX1_Man »

      patio

      • Moderator


      • Genius
      • Maud' Dib
      • Thanked: 1769
        • Yes
      • Experience: Beginner
      • OS: Windows 7
      Re: How can I get rid of it?
      « Reply #24 on: August 20, 2006, 12:35:31 PM »
      Quote
      Quote
      [highlight]is the CD new and shiny, and does it say microsoft[/highlight]?

      What EXACTLY have you done so far?


      This query went un replied to 4 times...

      patio.    8-)
      " Anyone who goes to a psychiatrist should have his head examined. "

      GX1_Man

      • Guest
      Re: How can I get rid of it?
      « Reply #25 on: August 20, 2006, 04:00:23 PM »
      Quote
      is the CD new and shiny, and does it say microsoft?

      Did we ever get this addressed? I don't think so.

      Steven2006

      • Guest
      Re: How can I get rid of it?
      « Reply #26 on: August 31, 2006, 10:15:36 AM »
      Hi all thanks for your helps,

      I believe that i've solved this problem without reformatting my pc.

      Thanks,
      Steven

      dl65

      • R.I.P.


      • Prodigy

        Thanked: 18
        Re: How can I get rid of it?
        « Reply #27 on: August 31, 2006, 11:08:33 AM »
        Steven2006... Perhaps you could tell us what you did to fix your issue .
        We would appreciate that .

        dl65  ::)
        If you don't know the answer, it isn't a dumb question.

        unlovedwarrior



          Guru

        • someday this name will be known
        • Thanked: 13
          Re: How can I get rid of it?
          « Reply #28 on: August 31, 2006, 11:16:53 AM »
          if you have not already read this it might be a good read


          http://www.updatexp.com/msblast-exe.html

          its kinda old but  
          « Last Edit: August 31, 2006, 11:17:39 AM by unlovedwarrior »

          Steven2006

          • Guest
          Re: How can I get rid of it?
          « Reply #29 on: August 31, 2006, 01:05:03 PM »
          Hi,

          I just downloaded and installed a specific patch from Microsoft.

          Thanks

          unlovedwarrior



            Guru

          • someday this name will be known
          • Thanked: 13
            Re: How can I get rid of it?
            « Reply #30 on: August 31, 2006, 01:06:45 PM »
            did it solve the problem??

            Steven2006

            • Guest
            Re: How can I get rid of it?
            « Reply #31 on: August 31, 2006, 01:13:09 PM »
            Yes, so far so good.

            The problem has not shown up anymore.

            I think this issue has been discussed all over the net, the trick is that you have to know which patch to install, since there are so many patches to choose from, I think.

            Hopely, the problem won't come up again.

            Steven

            unlovedwarrior



              Guru

            • someday this name will be known
            • Thanked: 13
              Re: How can I get rid of it?
              « Reply #32 on: August 31, 2006, 01:15:05 PM »
              IF it does then came back

              Steven2006

              • Guest
              Re: How can I get rid of it?
              « Reply #33 on: August 31, 2006, 01:17:49 PM »
              Thanks alot for the help.

              unlovedwarrior



                Guru

              • someday this name will be known
              • Thanked: 13
                Re: How can I get rid of it?
                « Reply #34 on: August 31, 2006, 01:18:31 PM »
                glad to help