1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Msinfo.exe

Discussion in 'Earlier Versions of Windows' started by tweetyejb, Sep 22, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. tweetyejb

    tweetyejb Thread Starter

    Joined:
    Jul 30, 2003
    Messages:
    62
    Could someone help me help my brother. As soon as he starts up he get a grey box error saying that the MSINFO.EXE is missing a file. If you click Ok on this a new error shows up and this one says WIN.INI file is missing a file. Click on this one and your good to go.
    I told him about SPYBOT to run that he did and he said that it stopped in the middle of the run. He did Norton system work cleaned all cookies , scan disk , disk defragmenter. It's doesn't look like he has a virus. Need help Thanks Tweety
     
  2. Top Banana

    Top Banana

    Joined:
    Nov 10, 2002
    Messages:
    1,344
  3. BlueSpruce

    BlueSpruce

    Joined:
    Jul 24, 2003
    Messages:
    420
    Hi tweetyejb ,

    After you have run CWShredder to remove the CoolWebSearch garbage Please do the following ,

    Close all browser windows , Open Spybot search & destroy , Click Excludes , scroll down to and place a check in the two C2.Lop entries , Click Spybot-S&D , Click check for problems , put a check in every entry Spybot search & destroy finds and Click Fix Selected Problems.

    Next , Download SpywareBlaster v2.6.1 and SpywareGuard v2.2 for the prevention of both Spyware Active X installation and running , and Browser Hijacking protection in real-time http://www.wilderssecurity.net/index.html

    Finally , Download Hijack This version 1.97 www.tomcoyote.org/hjt/ Press the scan button , the scan button becomes save log button , (Do not fix anything yet) save the log in the same folder Hijack This resides in , copy and paste the log to the forum.

    Good luck
     
  4. tweetyejb

    tweetyejb Thread Starter

    Joined:
    Jul 30, 2003
    Messages:
    62
    Hi did all you ask, CWSHREDDER, Spybot, spywareblaster, spywaregaud, And spybot still sropped at 2951 out of 5900. Same problem comes up when starting machine grey box . I 'm seding startup list and Hijacklog OK. Thank for your help.
    StartupList report, 10/4/03, 5:11:42 PM
    StartupList version: 1.52
    Started from : C:\WINDOWS\TEMP\STARTUPLIST.EXE
    Detected: Windows 98 SE (Win9x 4.10.2222A)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTSTARTSERVICE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
    C:\WINDOWS\SYSTEM\PRINTRAY.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
    C:\PROGRAM FILES\MSN\MSNCOREFILES\MSN6.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTSTARTTRAYAPP.EXE
    C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBINST.EXE
    C:\PROGRAM FILES\MICROSOFT HARDWARE\GAME CONTROLLERS\SWTRAY.EXE
    C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE
    C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
    C:\Program Files\Norton SystemWorks\Norton CleanSweep\Monwow.exe
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBSRV.EXE
    C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
    C:\WINDOWS\TEMP\STARTUPLIST.EXE

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\WINDOWS\Start Menu\Programs\StartUp]
    SwTray.lnk = C:\Program Files\Microsoft Hardware\Game Controllers\SWTRAY.EXE
    Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    PowerReg Scheduler.exe
    Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
    Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
    PowerReg Scheduler V3.exe
    Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    ScanRegistry = c:\windows\scanregw.exe /autorun
    TaskMonitor = c:\windows\taskmon.exe
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    SystemTray = SysTray.Exe
    CPQEASYACC = C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
    EACLEAN = C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
    CompaqPrinTray = PrinTray.exe
    DXM6Patch_981116 = C:\WINDOWS\p_981116.exe /Q:A
    LoadQM = loadqm.exe
    StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
    DSS = C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
    ccApp = "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    ccRegVfy = "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    GhostStartTrayApp = c:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
    NPROTECT = c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    Hotbar = C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBINST.EXE /Upgrade

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    SchedulingAgent = mstask.exe
    ccEvtMgr = "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
    ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    CSINJECT.EXE = c:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
    NPROTECT = c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    SymTray - Norton SystemWorks = c:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
    GhostStartService = C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTSTARTSERVICE.EXE

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    explore = c:\windows\explore.exe

    --------------------------------------------------

    C:\WINDOWS\WININIT.BAK listing:
    (Created 13/9/2003, 15:21:54)

    [Rename]
    C:\WINDOWS\system.bak=C:\WINDOWS\system.dat
    C:\WINDOWS\user.bak=C:\WINDOWS\user.dat
    C:\WINDOWS\system.dat=C:\WINDOWS\system.pak
    C:\WINDOWS\user.dat=C:\WINDOWS\user.pak

    --------------------------------------------------

    C:\AUTOEXEC.BAT listing:

    C:\essolo.com
    if exist c:\pipost.bat call c:\pipost.bat
    if exist c:\pipost.bat del c:\pipost.bat
    SET PATH=C:\WINDOWS\SYSTEM\WBEM;%PATH%;"c:\Program Files\Norton SystemWorks\Norton Ghost\"
    SET CLASSPATH=C:\PROGRA~1\CANONC~1\PHOTOD~1\ADOBEC~1

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    CSBHO - C:\PROGRAM FILES\COMET\BIN\CSBHO.DLL - {D14D6793-9B65-11D3-80B6-00500487BDBA}
    (no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    Hotbar - C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBHOSTIE.DLL - {B195B3B3-8A05-11D3-97A4-0004ACA6948E}
    NAV Helper - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
    (no name) - C:\WINDOWS\TEMP\MSPHEP.DLL - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Tune-up Application Start.job
    Symantec NetDetect.job
    Speed Disk.job
    Maintenance-Defragment programs.job
    Maintenance-ScanDisk.job
    Maintenance-Disk cleanup.job
    Norton SystemWorks One Button Checkup.job
    Norton AntiVirus - Scan my computer.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL

    --------------------------------------------------
    End of report, 7,424 bytes
    Report generated in 0.631 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only

    next is the hijacklist
    Logfile of HijackThis v1.97.2

    Scan saved at 5:48:22 PM, on 10/4/03

    Platform: Windows 98 SE (Win9x 4.10.2222A)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)



    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL

    C:\WINDOWS\SYSTEM\MSGSRV32.EXE

    C:\WINDOWS\SYSTEM\MPREXE.EXE

    C:\WINDOWS\SYSTEM\MSTASK.EXE

    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE

    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE

    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE

    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE

    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTSTARTSERVICE.EXE

    C:\WINDOWS\SYSTEM\mmtask.tsk

    C:\WINDOWS\EXPLORER.EXE

    C:\WINDOWS\TASKMON.EXE

    C:\WINDOWS\SYSTEM\SYSTRAY.EXE

    C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE

    C:\WINDOWS\SYSTEM\PRINTRAY.EXE

    C:\WINDOWS\LOADQM.EXE

    C:\WINDOWS\SYSTEM\STIMON.EXE

    C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE

    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE

    C:\WINDOWS\SYSTEM\SPOOL32.EXE

    C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE

    C:\PROGRAM FILES\MSN\MSNCOREFILES\MSN6.EXE

    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTSTARTTRAYAPP.EXE

    C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBINST.EXE

    C:\PROGRAM FILES\MICROSOFT HARDWARE\GAME CONTROLLERS\SWTRAY.EXE

    C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE

    C:\WINDOWS\SYSTEM\WMIEXE.EXE

    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE

    C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE

    C:\Program Files\Norton SystemWorks\Norton CleanSweep\Monwow.exe

    C:\WINDOWS\SYSTEM\PSTORES.EXE

    C:\WINDOWS\SYSTEM\DDHELP.EXE

    C:\WINDOWS\SYSTEM\RNAAPP.EXE

    C:\WINDOWS\SYSTEM\TAPISRV.EXE

    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE

    C:\WINDOWS\NOTEPAD.EXE

    C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBSRV.EXE

    C:\PROGRAM FILES\WINZIP\WINZIP32.EXE

    C:\WINDOWS\TEMP\HIJACKTHIS.EXE



    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msnmember.msn.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://files.cc.cometsystems.com/assist/cc/1.0/assist_ct.html

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by MSN

    O2 - BHO: CSBHO - {D14D6793-9B65-11D3-80B6-00500487BDBA} - C:\PROGRAM FILES\COMET\BIN\CSBHO.DLL

    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX

    O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBHOSTIE.DLL

    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll

    O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\WINDOWS\TEMP\MSPHEP.DLL

    O3 - Toolbar: Comet Toolbar - {FE6BC4EF-5676-484B-88AE-883323913256} - C:\PROGRAM FILES\COMET\BIN\CSIETB.DLL

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX

    O3 - Toolbar: &Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBHOSTIE.DLL

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll

    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun

    O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe

    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe

    O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe

    O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe

    O4 - HKLM\..\Run: [CompaqPrinTray] PrinTray.exe

    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A

    O4 - HKLM\..\Run: [LoadQM] loadqm.exe

    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE

    O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE

    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"

    O4 - HKLM\..\Run: [GhostStartTrayApp] c:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe

    O4 - HKLM\..\Run: [NPROTECT] c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE

    O4 - HKLM\..\Run: [Hotbar] C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBINST.EXE /Upgrade

    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe

    O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"

    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg

    O4 - HKLM\..\RunServices: [CSINJECT.EXE] c:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE

    O4 - HKLM\..\RunServices: [NPROTECT] c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE

    O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] c:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"

    O4 - HKLM\..\RunServices: [GhostStartService] C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTSTARTSERVICE.EXE

    O4 - HKCU\..\Run: [explore] c:\windows\explore.exe

    O4 - Startup: SwTray.lnk = C:\Program Files\Microsoft Hardware\Game Controllers\SWTRAY.EXE

    O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

    O4 - Startup: PowerReg Scheduler.exe

    O4 - Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe

    O4 - Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe

    O4 - Startup: PowerReg Scheduler V3.exe

    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe

    O8 - Extra context menu item: AltaVista Home - http://jump.altavista.com/avie5/home

    O8 - Extra context menu item: AV Search This Term - http://jump.altavista.com/avie5/search

    O8 - Extra context menu item: AV Translate this Web Page - http://jump.altavista.com/avie5/babelfish

    O8 - Extra context menu item: AV Translate Selection - http://jump.altavista.com/avie5/babelfish

    O9 - Extra button: Related (HKLM)

    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

    O9 - Extra 'Tools' menuitem: &AltaVista Home (HKLM)

    O9 - Extra button: Translate (HKLM)

    O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)

    O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)

    O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)

    O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll

    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll

    O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll

    O12 - Plugin for .mpg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll

    O14 - IERESET.INF: START_PAGE_URL=http://msnmember.msn.com

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    Thank you again for all your help I awaite your answer
     
  5. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    You are showing all the entries that Spybot should have removed if run properly. Did you reboot afterwards? Was this Scan taken before or after?

    Run Spybot again if necessary, have it "check for problems" and then "fix" all checked items and reboot afterwards. Then post another HijackThis Scanlog.

    Also, as Spybot may not catch this:

    O4 - HKCU\..\Run: [explore] c:\windows\explore.exe

    Please check and "fix" that with HijackThis and delete the explore.exe NOT explorer.exe in c:\windows.

    Also, oddly there is no evidence of msinfo.exe or a win.ini file referenced in the startup list.

    Go to Start, Run and enter win.ini and it will open in Notepad. Look for

    run=
    load=

    and remove any text you see after the "=" and close the file and accept the changes.
     
  6. starwaves77

    starwaves77

    Joined:
    Feb 16, 2002
    Messages:
    540
    Hi,
    The MSINFO error is related to Global Find spyware,
    Look for a file called msinfo.exe - delete it, I know the errror message says it's missing, but you really want to make sure this file is gone. You could do a search in "find" start / find / files or folders / "msinfo.exe" <type, use quotations it will zero in on this file, when you find it DELETE IT.....

    Don't delete msinfo32.exe - you need that one.

    Then go to Start\Run and type Win.ini The Win.ini will open in Notepad. Delete the line that refers to to msinfo.exe,

    It should look like this or very similar>
    F1
    run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSINFO\msinfo.exe

    DELETE THE WHOLE LINE, CLOSE NOTEPAD, AND "SAVE CHANGES"......

    But it looks like msinfo has been removed by your other spware removers, still, pieces might be haning around,
    __________-

    Next search for a file called bootconf.exe and delete that.

    GO Back to Start\Run and type msconfig Click on the startup tab and uncheck the line that refers to bootconf.exe.

    On your desktop explorer icon, right click and choose properties, reset your homepage to one you like,


    RUN HIJACK AGAIN:
    check and "fix" all the following

    C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE

    C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBINST.EXE

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://files.cc.cometsystems.com/as.../assist_ct.html

    O2 - BHO: CSBHO - {D14D6793-9B65-11D3-80B6-00500487BDBA} - C:\PROGRAM FILES\COMET\BIN\CSBHO.DLL

    O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBHOSTIE.DLL

    O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\WINDOWS\TEMP\MSPHEP.DLL

    O3 - Toolbar: Comet Toolbar - {FE6BC4EF-5676-484B-88AE-883323913256} - C:\PROGRAM FILES\COMET\BIN\CSIETB.DLL


    O3 - Toolbar: &Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\PROGRAM FILES\HOTBAR\BIN\4.3.1.0\HBHOSTIE.DLL


    O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE

    O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)


    ____________-

    Here's an UNINSTALLER for HOTBAR,
    which is in your system
    Uninstaller HotBar

    Also check your ADD/REMOVE Programs for
    Global Find
    Hotbar
     
  7. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/166742

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice