1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

help pLease virus?

Discussion in 'Virus & Other Malware Removal' started by MASQUERADEMA, Oct 2, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    my mouse dosen't work. comp display is in 16 bit. i tried to reinstall windows..... didn't work please help





    Logfile of HijackThis v1.97.2
    Scan saved at 4:44:59 PM, on 10/2/2003
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Unable to get Internet Explorer version!

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\EZULA\MMOD.EXE
    C:\PROGRAM FILES\EBKRDR\MEDIAMAN.EXE
    C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srng.net/search/9885/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.shopnav.com/apps/epa/epa?cid=shnv9885&s=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?c=3c00&s=consumer&LC=0409
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c00&s=searchbar&LC=0409
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c00&s=searchbar&LC=0409
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.shopnav.com/apps/epa/epa?cid=shnv9885&s=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://srng.net/search/9885/search.html
    F0 - system.ini: Shell=
    O1 - Hosts: 216.177.73.139 auto.search.msn.com
    O1 - Hosts: 216.177.73.139 search.netscape.com
    O1 - Hosts: 216.177.73.139 ieautosearch
    O2 - BHO: (no name) - {0000001D-BA9B-11D2-BDF1-0090272A6D78} - C:\WINDOWS\SYSTEM\SMBAR.DLL
    O2 - BHO: (no name) - {00000EF1-34E3-4633-87C6-1AA7A44296DA} - (no file)
    O2 - BHO: (no name) - {A94EDD52-85B3-472F-8BC0-D651D760FBF8} - D:\PROGRAM FILES\POPUPZERO\POPUPZEROIEDLL.DLL
    O2 - BHO: (no name) - {08351226-6472-43BD-8A40-D9221FF1C4CE} - C:\WINDOWS\SBCIE0261.DLL
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {14b3d246-6274-40b5-8d50-6c2ade2ab29b} - C:\PROGRAM FILES\SRNG\SNHELPER.DLL
    O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRAM FILES\COMMONNAME\TOOLBAR\CNBABE.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
    O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
    O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
    O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
    O4 - HKCU\..\Run: [media_manager] C:\Program Files\ebkrdr\mediaman.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
    O4 - HKLM\..\RunOnce: [hhctrl.ocx] C:\WINDOWS\SYSTEM\regsvr32 /s C:\WINDOWS\SYSTEM\hhctrl.ocx
    O4 - HKLM\..\RunOnce: [CDGuide] C:\WINDOWS\SYSTEM\REGSVR32.EXE /s C:\PROGRA~1\ADAPTEC\SHARED\CDGUIDE\CDGUIDE.OCX
    O4 - HKLM\..\RunOnce: [REGJEWEL] C:\PROGRA~1\ADAPTEC\SHARED\JEWELC~1\CDJEWEL.EXE /REGSERVER
    O4 - HKLM\..\RunOnce: [MSMask32] C:\WINDOWS\SYSTEM\REGSVR32.EXE /s C:\WINDOWS\SYSTEM\MSMASK32.OCX
    O4 - HKLM\..\RunOnce: [Creator] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATR32.EXE /REGSERVER
    O4 - HKLM\..\RunOnce: [acmwrapperserver.dll] c:\windows\system\regsvr32.exe /s "C:\Program Files\Adaptec\Shared\ECDC Engine\acmwrapperserver.dll"
    O4 - HKLM\..\RunOnce: [drivers.dll] c:\windows\system\regsvr32.exe /s "C:\Program Files\Adaptec\Shared\ECDC Engine\drivers.dll"
    O4 - HKLM\..\RunOnce: [mediaplayer.dll] c:\windows\system\regsvr32.exe /s "C:\Program Files\Adaptec\Shared\ECDC Engine\mediaplayer.dll"
    O4 - HKLM\..\RunOnce: [engine.dll] c:\windows\system\regsvr32.exe /s "C:\Program Files\Adaptec\Shared\ECDC Engine\engine.dll"
    O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - User Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    O4 - User Startup: PowerReg Scheduler.exe
    O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
    O8 - Extra context menu item: Bookmark This Page - C:\Program Files\CommonName\Toolbar\createbookmark.htm
    O8 - Extra context menu item: Add A Page Note - C:\Program Files\CommonName\Toolbar\createnote.htm
    O8 - Extra context menu item: Email This Link - C:\Program Files\CommonName\Toolbar\emaillink.htm
    O8 - Extra context menu item: Search using CommonName - C:\Program Files\CommonName\Toolbar\navigate.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE10\EXCEL.EXE/3000
    O9 - Extra button: Translate (HKLM)
    O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
    O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
    O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
    O9 - Extra 'Tools' menuitem: AV Live (HKLM)
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O16 - DPF: {F7E3BB7B-9B9F-11D5-9F7A-0090F50400FE} (PlayIt7Student.PlayIt7d) - file://E:\content\PlayIt7d.CAB
    O16 - DPF: {BD70B8AE-CE34-11D5-9F7A-0090F50400FE} (PlayIt7Student.PlayIt7e) - file://E:\content\PlayIt7e.CAB
    O16 - DPF: {F4BDA33C-7C59-11D5-9F7A-0090F50400FE} (Project1.checkfiles) - file://E:\checkfiles.CAB
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
    O8 - Extra context menu item: Bookmark This Page - C:\Program Files\CommonName\Toolbar\createbookmark.htm
    O8 - Extra context menu item: Add A Page Note - C:\Program Files\CommonName\Toolbar\createnote.htm
    O8 - Extra context menu item: Email This Link - C:\Program Files\CommonName\Toolbar\emaillink.htm
    O8 - Extra context menu item: Search using CommonName - C:\Program Files\CommonName\Toolbar\navigate.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE10\EXCEL.EXE/3000
    O9 - Extra button: Translate (HKLM)
    O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
    O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
    O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
    O9 - Extra 'Tools' menuitem: AV Live (HKLM)
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O16 - DPF: {F7E3BB7B-9B9F-11D5-9F7A-0090F50400FE} (PlayIt7Student.PlayIt7d) - file://E:\content\PlayIt7d.CAB
    O16 - DPF: {BD70B8AE-CE34-11D5-9F7A-0090F50400FE} (PlayIt7Student.PlayIt7e) - file://E:\content\PlayIt7e.CAB
    O16 - DPF: {F4BDA33C-7C59-11D5-9F7A-0090F50400FE} (Project1.checkfiles) - file://E:\checkfiles.CAB
     
  2. Dingus

    Dingus

    Joined:
    Apr 21, 2002
    Messages:
    1,149
    Excuse me if I'm being obvious, but have you tried another mouse.
     
  3. dragoonsgl

    dragoonsgl

    Joined:
    Aug 25, 2003
    Messages:
    106
    It may be the mouse but a few things stuck out but you will need to get better help. Run Hijack This again and check these entries then hit "Fix Checked":

    O1 - Hosts: 216.177.73.139 auto.search.msn.com
    O1 - Hosts: 216.177.73.139 search.netscape.com
    O1 - Hosts: 216.177.73.139 ieautosearch

    ~Good luck with your problems
     
  4. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    the mouse works in safe mode. when i tried ti install windows again it said i was missing a .sys file. i ran norton anti virus it came up with nothing. i deleted those 3 things it put back up files on my desktop.
     
  5. IMM

    IMM Malware Specialist

    Joined:
    Feb 1, 2002
    Messages:
    3,257
    There's a bunch of junk including CommonName.
    I've no idea what that LSP is.
    What was the name of the missing sys file ?? - perhaps using Device manager and selecting a MS mouse or driver which actually fits your mouse would help - if you're stuck choose a simple two button mouse as a driver for most corded mice. What is the thing ? cordless? USB? Logitech?

    Download Spybot - Search and Destroy

    Use the beta updates - after installing, press Settings, and Settings again.
    Go to the Webupdate section, and check "Display also available beta versions".
    After installing, first press Online, and search for, put a check mark at, and install all updates.

    Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds.

    After SpybotSD - reboot - run Hiujack this again and post another log.
     
  6. IMM

    IMM Malware Specialist

    Joined:
    Feb 1, 2002
    Messages:
    3,257
    I think you should download LSPFix from http://www.cexx.org/lspfix.htm and use it to remove barlayer.dll from your protocol catalog - particularly if you have trouble getting online after spybotsd.
    (I think I'd do it anyway) :)
     
  7. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    pdti2o.sys is missing. the other comp won't go on the internet either. i'll dl and burn on this comp and istall on the other. brb
     
  8. IMM

    IMM Malware Specialist

    Joined:
    Feb 1, 2002
    Messages:
    3,257
    Never heard of pdti2o.sys ! (nor, apparently, has Google assuming the spelling is correct).

    I think I'd search the registry,win.ini and system.ini for references to it and remove them.
    I'd probably remove any driver sets or utilities for the mouse which are present in Add/Remove programs.
    I'd likely remove the mouse device(s) from Device Manager and let it rediscover the hardware on the reboot - use SAFE mode and remove all meeses. (tho' you still haven't said what the rodent is)

    If you can't get online then definitely put LSPFix in expert mode and move the barlayer.dll I mentioned to the right hand side - then fix it.
    BTW - LSPFix will fit on a floppy.
     
  9. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    oops dpti2o.sys

    logitech

    how would i check the registery and system for refrences?

    spyboy couldn't fix some things that have to do with the registery key. i'll run hijack again now.
     
  10. IMM

    IMM Malware Specialist

    Joined:
    Feb 1, 2002
    Messages:
    3,257
    Is this a Dell?
    That driver is a SCSIAdapter (NT I2O SCSI) - perhaps your burner software or it may be hard drive related if your machine is Raid?
    At any rate it isn't for the rodent - so I think you can ignore it for a little while - tho' it may give other problems.
     
  11. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    compaq 5000

    raid?
     
  12. IMM

    IMM Malware Specialist

    Joined:
    Feb 1, 2002
    Messages:
    3,257
    Redundant Array of Inexpensive Disks
    Some home machines have IDE controllers which support it (it usu. can be disabled in the bios)
    Or perhaps there is a SCSI controller on that motherboard?
    I'll do a little hunting on the 5000

    I'd definatily uninstall Logitech using Add/Remove programs.
    Perhaps someone else will pick up this post - I'm calling it a night.
     
  13. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    Logfile of HijackThis v1.97.2
    Scan saved at 3:47:14 AM, on 10/3/2003
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Unable to get Internet Explorer version!

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?c=3c00&s=consumer&LC=0409
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c00&s=searchbar&LC=0409
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c00&s=searchbar&LC=0409
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.shopnav.com/apps/epa/epa?cid=shnv9885&s=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://srng.net/search/9885/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = iexplore
    F0 - system.ini: Shell=
    O2 - BHO: (no name) - {0000001D-BA9B-11D2-BDF1-0090272A6D78} - C:\WINDOWS\SYSTEM\SMBAR.DLL
    O2 - BHO: (no name) - {A94EDD52-85B3-472F-8BC0-D651D760FBF8} - D:\PROGRAM FILES\POPUPZERO\POPUPZEROIEDLL.DLL
    O2 - BHO: (no name) - {08351226-6472-43BD-8A40-D9221FF1C4CE} - C:\WINDOWS\SBCIE0261.DLL
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {14b3d246-6274-40b5-8d50-6c2ade2ab29b} - C:\PROGRAM FILES\SRNG\SNHELPER.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
    O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
    O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
    O4 - HKLM\..\Run: [CPQInet] C:\cpqdrv\compaq\CPQInet\CPQInet.exe
    O4 - HKLM\..\Run: [Digital Dashboard] C:\Program Files\Compaq\Digital Dashboard\DevGulp.exe
    O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
    O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
    O4 - HKLM\..\Run: [LexStart] Lexstart.exe
    O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
    O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\SYSTEM\SahAgent.exe
    O4 - HKLM\..\Run: [RVP] "C:\Program Files\RVP\bpc.exe"
    O4 - HKLM\..\Run: [srng] \Program Files\Srng\Srng.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [DeadAIM] rundll32.exe C:\PROGRA~1\AIM95\DeadAIM.ocm,ExportedCheckODLs
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
    O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O4 - HKLM\..\RunOnce: [SpyBotSnD] "C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE" /autocheck
    O8 - Extra context menu item: LimeShop Preferences - file://c:\Program Files\topMoxie\TEMP\limeshop_script.htm
    O9 - Extra button: Translate (HKLM)
    O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
    O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
    O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
    O9 - Extra 'Tools' menuitem: AV Live (HKLM)
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O10 - Unknown file in Winsock LSP: c:\windows\barlayer.dll
    O16 - DPF: {F7E3BB7B-9B9F-11D5-9F7A-0090F50400FE} (PlayIt7Student.PlayIt7d) - file://E:\content\PlayIt7d.CAB
    O16 - DPF: {BD70B8AE-CE34-11D5-9F7A-0090F50400FE} (PlayIt7Student.PlayIt7e) - file://E:\content\PlayIt7e.CAB
    O16 - DPF: {F4BDA33C-7C59-11D5-9F7A-0090F50400FE} (Project1.checkfiles) - file://E:\checkfiles.CAB
     
  14. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    there no add/remove for the mouse

    but it works in safe mode
     
  15. MASQUERADEMA

    MASQUERADEMA Thread Starter

    Joined:
    Oct 2, 2003
    Messages:
    22
    the c:\windows\systems\comet\mcc\cursors\cd_electric.ani file which contains the normal select cursor is missing or corrupt
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/169097

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice