1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

can not update XP

Discussion in 'Windows XP' started by richocki, Feb 16, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. richocki

    richocki Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    167
    I have automatic update turned on but I have not been alerted to any updates from MS. I went to the update site and I had 13 updates that needed to be installed. I clicked on 'express' to update but all updates failed. I can manually download the updates and install them ok. Any idea why I am not being alerted of updates and why I can not update from the site?

    Logfile of HijackThis v1.99.1
    Scan saved at 2:53:26 PM, on 2/16/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\_Tools\MS Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.exe
    C:\_Tools\WIN Patrol\winpatrol.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\_Internet\SpyWall\SpyWall.exe
    C:\_Tools\SmartDefrag\IObit SmartDefrag.exe
    D:\Tools\a_squared\a-squared Anti-Dialer\a2adguard.exe
    C:\_Tools\MS Defender\MSASCui.exe
    C:\_Internet\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    C:\_Tools\StartUp Guru\startupguru.exe
    C:\_Internet\AVG Anti Virus\avgcc.exe
    D:\_Applications\EverNote\EverNote.exe
    D:\_Applications\YCIII\YankClip.exe
    C:\_Internet\AVG Anti-Spyware 7.5\guard.exe
    C:\_INTER~1\AVG Anti Virus\avgamsvr.exe
    C:\_INTER~1\AVG Anti Virus\avgupsvc.exe
    C:\_INTER~1\AVG Anti Virus\avgemc.exe
    C:\Program Files\Common Files\Novatix\Cyberhawk\CHService.exe
    C:\_Tools\System Mechanic 6 Pro\IoloSGCtrl.exe
    C:\WINDOWS\System32\snmp.exe
    C:\_Internet\Spyware Terminator\sp_rsser.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\System32\svchost.exe
    C:\_Applications\WordWeb\wweb32.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\_Internet\FireFox\firefox.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://e.my.yahoo.com/config/my_init?.intl=us&.partner=my&.from=i
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://e.my.yahoo.com/config/my_init?.intl=us&.partner=my&.from=i
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: Shell=C:\WINDOWS\Explorer.exe
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: (no name) - {D03B6018-E880-4A89-99A2-7354FE52DDAE} - (no file)
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup"
    O4 - HKLM\..\Run: [WinPatrol] "C:\_Tools\WIN Patrol\winpatrol.exe"
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SpywareFirewall] C:\_Internet\SpyWall\SpyWall.exe
    O4 - HKLM\..\Run: [SmartDefrag] "C:\_Tools\SmartDefrag\IObit SmartDefrag.exe" /startup
    O4 - HKLM\..\Run: [a-squared Anti-Dialer] "D:\Tools\a_squared\a-squared Anti-Dialer\a2adguard.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\_Tools\MS Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\_Internet\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\_Internet\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKCU\..\Run: [Startup Guru] "C:\_Tools\StartUp Guru\startupguru.exe" /B
    O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\_Tools\SpeedUpMyPC\SpeedUpMyPC.exe -s
    O4 - Startup: 1st QuickRes.lnk = C:\_Applications\QuickResolution\1stqres.exe
    O4 - Startup: avgcc.lnk = C:\_Internet\AVG Anti Virus\avgcc.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\_Tools\Registry_backUp\AUTOBACK.EXE
    O4 - Startup: EverNote.lnk = D:\_Applications\EverNote\EverNote.exe
    O4 - Startup: YankClip.lnk = D:\_Applications\YCIII\YankClip.exe
    O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
    O8 - Extra context menu item: Add to EverNote - res://D:\_Applications\EverNote\enbar.dll/2000
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O8 - Extra context menu item: Search - C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Search.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - D:\_Applications\EverNote\enbar.dll
    O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - D:\_Applications\EverNote\enbar.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4866/mcfscan.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{82614FED-0B4A-4993-9AB4-88E0933D67FD}: NameServer = 85.255.115.5 85.255.112.24
    O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
    O20 - Winlogon Notify: SASWinLogon - C:\_Internet\SuperAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\_Internet\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\_INTER~1\AVG Anti Virus\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\_INTER~1\AVG Anti Virus\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\_INTER~1\AVG Anti Virus\avgemc.exe
    O23 - Service: Cyberhawk - Unknown owner - C:\Program Files\Common Files\Novatix\Cyberhawk\CHService.exe" service (file missing)
    O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\_Tools\System Mechanic 6 Pro\IoloSGCtrl.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe
    O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\_Internet\Spyware Terminator\sp_rsser.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
  2. Tabvla

    Tabvla

    Joined:
    Apr 10, 2006
    Messages:
    2,554
    Your Firewall might be blocking the site. You need to add the MS update URL to your list of trusted sites.
     
  3. richocki

    richocki Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    167
    That's not the problem. I can even turn off Zone Alarm and the update fails.

    On one of the failed updates I get --
    Installation Failure

    Error Code: 0x80246008
    Try to install the update again, or request help from one of the following resources.

    For self-help options:

    Frequently Asked Questions
    Find Solutions
    Windows Update Newsgroup

    I have tried the self-help options with no joy.
    I can not even up date the Defender from within the application.
    The BIT service is set to manual. Should it be automatic?
    I have also reinstalled the Microsoft Windows Installer 3.1.
    ***** I changed the Background Intelligent Transfer Service (BITS) to automatic and the update worked!
    For anyone else having this problem the BITS setting is in Control Panel -> Adminstration Tools -> Services
     
  4. Augie65

    Augie65

    Joined:
    Mar 23, 2005
    Messages:
    6,052
    Check and see if Background Intelligent Transfer Service is started. Go to Microsoft Support and click on:
    Verify that BITS is correctly configured
     
  5. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, richocki :)

    Welcome to TSG.

    Please print these instructions for reference, as you will have to restart your computer during the fix.

    Please download FixWareout from Here or Here.

    Note: You will need to run this tool while having an Internet Connection. The tool will download other files while running.
    1. Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
    2. The fix will begin; follow the prompts.
    3. If your firewall gives an alert, (because this tool will download an additional files from the internet), please don't let your firewall block it, but allow it instead.
    4. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
    5. Once the desktop loads a text file will open (report.txt), you can close it - the file has already been saved.
    Run HijackThis. Click "Do a System Scan Only", and place a check next to the following items (if found):

    O17 - HKLM\System\CCS\Services\Tcpip\..\{82614FED-0B4A-4993-9AB4-88E0933D67FD}: NameServer = 85.255.115.5 85.255.112.24


    Click FIX CHECKED. Close HijackThis.
    1. Enter your Control Panel and double-click on Network Connections
    2. Then right click on your Default Connection
      • Usually Local Area Connection for Cable and DSL, or AOL Connection.
    3. Left click on Properties
    4. Double-Click on the Internet Protocol (TCP/IP) item
    5. Select the radio dial that says Obtain DNS Servers Automatically
    6. Press OK twice to get out of the properties screen
    7. Restart the computer
    Go to Start->Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:

    ipconfig /flushdns (The space between g and / is needed)
    Exit

    Restart the computer.

    Finally, please post the contents of the text file that opened earlier (you can find it at C:\fixwareout\report.txt ), along with a new HijackThis log into this topic.
     
  6. richocki

    richocki Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    167
    I ran FixWareout as directed. There was no 017 entry in the HiJackThis.
    When I open Network Connections I get a blank page. There is NO connections listed. That surprised me because I use to have two - default and a back up of the default. Because I could not complete the network connections step I did not complete the ipconfig /flushdns step. Should I have anyway?

    Fixwareout Last edited 2/11/2007
    Post this report in the forums please
    ...
    »»»»»Prerun check

    »»»»» System restarted

    »»»»» Postrun check
    HKLM\SOFTWARE\~\Winlogon\ "system"=""
    ....
    ....
    »»»»» Misc files.
    ....
    »»»»» Checking for older varients.
    ....

    Search five digit cs, dm, kd, jb, other, files.
    The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



    Click browse, find the file then click submit.
    http://www.virustotal.com/flash/index_en.html
    Or http://virusscan.jotti.org/

    »»»»» Other



    »»»»» Current runs
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="\"RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup\" "
    "WinPatrol"="\"C:\\_Tools\\WIN Patrol\\winpatrol.exe\""
    "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
    "SpywareFirewall"="C:\\_Internet\\SpyWall\\SpyWall.exe"
    "SmartDefrag"="\"C:\\_Tools\\SmartDefrag\\IObit SmartDefrag.exe\" /startup"
    "a-squared Anti-Dialer"="\"D:\\Tools\\a_squared\\a-squared Anti-Dialer\\a2adguard.exe\""
    "Windows Defender"="\"C:\\_Tools\\MS Defender\\MSASCui.exe\" -hide"
    "!AVG Anti-Spyware"="\"C:\\_Internet\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
    "SpywareTerminator"="\"C:\\_Internet\\Spyware Terminator\\SpywareTerminatorShield.exe\""
    "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Startup Guru"="\"C:\\_Tools\\StartUp Guru\\startupguru.exe\" /B"
    "Uniblue SpeedUpMyPC"="C:\\_Tools\\SpeedUpMyPC\\SpeedUpMyPC.exe -s"
    ....
    Hosts file was reset, If you use a custom hosts file please replace it
    »»»»» End report »»»»»

    Logfile of HijackThis v1.99.1
    Scan saved at 11:46:44 PM, on 2/16/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\_Tools\MS Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.exe
    C:\_Internet\AVG Anti-Spyware 7.5\guard.exe
    C:\_INTER~1\AVG Anti Virus\avgamsvr.exe
    C:\_INTER~1\AVG Anti Virus\avgupsvc.exe
    C:\_INTER~1\AVG Anti Virus\avgemc.exe
    C:\Program Files\Common Files\Novatix\Cyberhawk\CHService.exe
    C:\_Tools\System Mechanic 6 Pro\IoloSGCtrl.exe
    C:\WINDOWS\System32\snmp.exe
    C:\_Internet\Spyware Terminator\sp_rsser.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\_Tools\WIN Patrol\winpatrol.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\_Internet\SpyWall\SpyWall.exe
    C:\_Tools\SmartDefrag\IObit SmartDefrag.exe
    D:\Tools\a_squared\a-squared Anti-Dialer\a2adguard.exe
    C:\_Tools\MS Defender\MSASCui.exe
    C:\_Internet\AVG Anti-Spyware 7.5\avgas.exe
    C:\_Internet\Spyware Terminator\SpywareTerminatorShield.exe
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    C:\_Tools\StartUp Guru\startupguru.exe
    C:\_Tools\SpeedUpMyPC\SpeedUpMyPC.exe
    C:\WINDOWS\System32\svchost.exe
    C:\_Applications\QuickResolution\1stqres.exe
    C:\_Internet\AVG Anti Virus\avgcc.exe
    D:\_Applications\EverNote\EverNote.exe
    D:\_Applications\YCIII\YankClip.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://e.my.yahoo.com/config/my_init?.intl=us&.partner=my&.from=i
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://e.my.yahoo.com/config/my_init?.intl=us&.partner=my&.from=i
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: Shell=C:\WINDOWS\Explorer.exe
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: (no name) - {D03B6018-E880-4A89-99A2-7354FE52DDAE} - (no file)
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup"
    O4 - HKLM\..\Run: [WinPatrol] "C:\_Tools\WIN Patrol\winpatrol.exe"
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SpywareFirewall] C:\_Internet\SpyWall\SpyWall.exe
    O4 - HKLM\..\Run: [SmartDefrag] "C:\_Tools\SmartDefrag\IObit SmartDefrag.exe" /startup
    O4 - HKLM\..\Run: [a-squared Anti-Dialer] "D:\Tools\a_squared\a-squared Anti-Dialer\a2adguard.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\_Tools\MS Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\_Internet\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\_Internet\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKCU\..\Run: [Startup Guru] "C:\_Tools\StartUp Guru\startupguru.exe" /B
    O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\_Tools\SpeedUpMyPC\SpeedUpMyPC.exe -s
    O4 - Startup: 1st QuickRes.lnk = C:\_Applications\QuickResolution\1stqres.exe
    O4 - Startup: avgcc.lnk = C:\_Internet\AVG Anti Virus\avgcc.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\_Tools\Registry_backUp\AUTOBACK.EXE
    O4 - Startup: EverNote.lnk = D:\_Applications\EverNote\EverNote.exe
    O4 - Startup: YankClip.lnk = D:\_Applications\YCIII\YankClip.exe
    O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
    O8 - Extra context menu item: Add to EverNote - res://D:\_Applications\EverNote\enbar.dll/2000
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O8 - Extra context menu item: Search - C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Search.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - D:\_Applications\EverNote\enbar.dll
    O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - D:\_Applications\EverNote\enbar.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4866/mcfscan.cab
    O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
    O20 - Winlogon Notify: SASWinLogon - C:\_Internet\SuperAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\_Internet\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\_INTER~1\AVG Anti Virus\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\_INTER~1\AVG Anti Virus\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\_INTER~1\AVG Anti Virus\avgemc.exe
    O23 - Service: Cyberhawk - Unknown owner - C:\Program Files\Common Files\Novatix\Cyberhawk\CHService.exe" service (file missing)
    O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\_Tools\System Mechanic 6 Pro\IoloSGCtrl.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe
    O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\_Internet\Spyware Terminator\sp_rsser.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
  7. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, richocki :)

    Veryfy if the Plug and Play Service is enabled and running. To do so, follow these steps:

    1. Click Start, click Run, type services.msc, and then click OK.
    2. Scroll down to Plug and Play.
    3. Right click on Plug and Play and select Properties
    4. Make sure the service is running.
    5. In the Startup Type list, click Automatic, and then click OK.
    6. Close Services.
     
  8. richocki

    richocki Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    167
    Plug and Play is working.

    I have successfully used the update site and all updates are installed.
    Everything seems to be working with the exception of the missing network connections in Network Connections. That problem I will post later after looking things over.
    Thanks for the help.
     
  9. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, richocki :)

    I am glad to learn you were able to resolve the Windows Updates issue.

    Concerning the other issue, are you able to see the Device Manager? Is there any conflict therein?
     
  10. richocki

    richocki Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    167
    The Device Manager shows everything working - no yellow marks. I use the same short cut that I have had in the Quick Launch Menu. When I check its properties it shows that is is calling rasphone.exe that is in the system32 folder. I connect ok to the internet but with out the icons in the system tray (I use to have 2 icons - 1 showing the modem was active(?) and another one when I went on line) I can not disconnect if I want to. Actually I can by stooping all internet activity using Zone Alarm. I have not installed anything out of the ordinary.

    I have DSL.

    Should I start another post with this problem?
     
  11. JSntgRvr

    JSntgRvr Moderator Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, richocki :)

    No need to open a new thread. I will request an MPV in Networking to take a look at this thread.

    Standby!
     
  12. JohnWill

    JohnWill Retired Moderator

    Joined:
    Oct 19, 2002
    Messages:
    106,418
    It sounds like you're connected, just don't see anything in Network Connections? Let's start by seeing what you get for this:

    Start, Run, CMD to open a command prompt:

    Type the following command:

    IPCONFIG /ALL

    Right click in the command window and choose Select All, then hit Enter.
    Paste the results in a message here.
     
  13. richocki

    richocki Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    167
    Hi JohnWill
    Thanks for the help... I do connect through that rasphone.exe I mentioned. Not sure if rasphone.exe was used before or not, my guess it was because what would change it to that. I was tempted to use the DSL install disk but I think SBC/Yahoo has moved on to a different installation. I had a connection problem about 4 months ago and SBC/Yahoo sent me a different CD but I corrected the problem before I received it and never used it. Maybe I should but I am afraid I will lose my connection altogether -- any way here is the results of your request.

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\Rick.RCC>IPCONFIG /ALL

    Windows IP Configuration

    Host Name . . . . . . . . . . . . : Rick
    Primary Dns Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Unknown
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : Yes

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : NVIDIA nForce MCP Networking Adapter

    Physical Address. . . . . . . . . : 00-00-60-00-F7-A4
    Dhcp Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    Autoconfiguration IP Address. . . : 169.254.189.58
    Subnet Mask . . . . . . . . . . . : 255.255.0.0
    Default Gateway . . . . . . . . . :

    PPP adapter DSL Connection:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
    Physical Address. . . . . . . . . : 00-53-45-00-00-00
    Dhcp Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : 69.37.210.192
    Subnet Mask . . . . . . . . . . . : 255.255.255.255
    Default Gateway . . . . . . . . . : 69.37.210.192
    DNS Servers . . . . . . . . . . . : 85.255.115.5
    85.255.112.24

    C:\Documents and Settings\Rick.RCC>
     
  14. JohnWill

    JohnWill Retired Moderator

    Joined:
    Oct 19, 2002
    Messages:
    106,418
    Well, obviously you have network capability, I see a standard wired NIC which is apparently not connected, and a PPP connection, no doubt your ISP's connection.

    Just to be sure, you're talking about Control Panel, Network Connections, and it's totally blank? Here's what I see FWIW.
     

    Attached Files:

    • nw.jpg
      nw.jpg
      File size:
      34.7 KB
      Views:
      69
  15. richocki

    richocki Thread Starter

    Joined:
    Apr 17, 2004
    Messages:
    167
    JohnWill,

    I thought the NIC card would be 'active' because when I installed DSL I installed what I believe they called a NIC card. Prior to DSL I had dialup which used a U.S. Robotics V92 FAX modem which is still listed in the device manager. Under Network Adapters in Device Manager I have a 1394 Net Adapter and NVIDIA NForce MCP Networking Adapter listed. I really don't know what either is but thought one was for the DSL.

    I don't know how to post a screen shot here but my Network Connections page from the Control Panel IS BLANK. Before I had lost my icons in the System Tray I had 2 connections listed on that page - 1 was the default and then I had a back up of the default. Not sure if I needed the backup but I made it anyway - but of course they are both gone now.

    Would a DSL modem use rasphone.exe to connect to the internet? That doesn't seem right... but what do I know :)
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/544629

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice