System Info Tool Problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by boneyeye, May 8, 2004.

  1. boneyeye

    boneyeye Corporal

    Hi,
    Was just checking above, on opening Componants I have the following:
    Display:Driver: oemrom.bin; driver not installed.
    Input :Driver:idvkd. sys : driver not installed
    Modem: Driver: pctwave.inf :driver not installed.
    PC Probs: Browsing has become a bit slow, answers to help trouble shooting is not working.
    Do I need to replace these,and if so where do I get them and where do Iinstall them to.
    Hope someone can helpas this js my first question.


    Specs:Amd K6 3Dnow MMX 500
    RAM 192-reads184
    AVG VirusScan, ZoneAlarm firewall.


    Thanks so much Boneyeye.
     
    Last edited by a moderator: May 11, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I not sure about you driver not installed issues. Maybe someone else can help you there. But exactly which system info tool did you mean? Was it SystemInfo1.01.

    But the Browsing being slow problem could be an a virus or spyware issue. Is you AVG up to date and have you run a full scan recently? Also ou may want to try installing, updating and running both Ad-aware and SpyBot S&D. See this link:

    http://www.majorgeeks.com/vb/showthread.php?t=26149

    Clean up what they find. If still having a problem, post a HiJaak This log.
     
  3. boneyeye

    boneyeye Corporal

    Chaslang,
    TY for answering.The program I used was Msoft Sy.Info Tool (Supplied with Win 98). Full maintainance schedule weekly, plus spybot s/d IE5.5 repair Adware6, SFC. Spybot,Adware,VirusScan, ZoneAlarm ,Wins.,updated weekly.So I do not know what else I can do. Reinstall of Wins.SE. occasionally. What I would like to kow is: Is this important to the running of computer. I would like to see some more replies as this site was recommended to me as being the very best there is.TY again.
    Boneyeye.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there any reason you have not upgraded to IE 6? It is probably a good idea to do this.
    As far as what to do next, if you have run all those items listed in your weekly maintenance schedule, I recommend post a HiJaak This log. We can have a look and see if anything looks bad in there.
     
  5. boneyeye

    boneyeye Corporal

    Hi Chaslang, TY again. I did not upgrade to IE6.O as I felt from what I have read there was more probs. than IE5.50. The only prob. I have with 5.50 is a registry key key prob which Adware deals with each time. Will do as you say re Hijackthis log but you will need to guide me on this plz. Boneyeye.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. boneyeye

    boneyeye Corporal

    Logfile of HijackThis v1.97.7
    Scan saved at 19:55:50 P.M,, on 11/5/2004
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\INETSRV\INETINFO.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\Ptsnoop.exe
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\ALOGSERV.EXE
    C:\WINDOWS\DRWATSON.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.ie
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.majorgeeks.com/vb/index.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
    O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [Load] Ptsnoop
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\RunServices: [inetinfo.exe] C:\WINDOWS\SYSTEM\inetsrv\inetinfo.exe -e w3svc
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O9 - Extra button: Yahoo! Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {DC765522-D5BE-49C9-AF5F-8C715A44BA28} - http://fdl.msn.com/public/investor/v9/ticker.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www1.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {6FB9FE59-7D3B-483D-9909-C870BE5AFA1F} (DiskHealth Class) - http://www.pcpitstop.com/pcpitstop/diskhealth.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw14fd.law14.hotmail.msn.com/activex/HMAtchmt.ocx
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37894.7292361111
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www1.pcpitstop.com/internet/pcpConnCheck.cab
    O16 - DPF: {F8F88D0D-E455-11D6-B547-00400555C7FB} (DiskHealth2 Class) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/052f427afd5bdc69f106/netzip/RdxIE601.cab
    O16 - DPF: {13991839-0420-11D5-BDA3-00A0C982BA51} (PDAnalyzeCtrl Class) - http://www.pnltools.com/PDWeb.cab
    O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/ssoap/pptproactauthakamai/systemsoappro.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} (MSN Chat Control 4.2) - http://fdl.msn.com/public/chat/msnchat42.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 127.0.0.1
    Hi Chaslang,Hope this arrives ok. It looks as if i've been hijacked. Hope not. TY again Bonayeye
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boneyeye,

    Run HiJaak This again and check the below items off and delete them:

    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
    O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/052f427...ip/RdxIE601.cab
    O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/s...stemsoappro.cab


    Also if www.eircom.net is not your ISP and you did not choose the below for your Home Page, check and delete the next two lines with HiJaak This:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net


    Boot into Safe Mode and delete this folder if it exists:

    C:\PROGRA~1\COMMON~1\Real
     
  9. boneyeye

    boneyeye Corporal

    Hi, before I startdeletingplease give me directions on;
    R1
    014
    as www.eircom.net is my ISP but Majorgeeks is my home page as you have been recommended to me as the very best. TYagain. Boneyeye.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From Internet Explorer window, click Tools, Internet Options. Does your home page show as http://www.majorgeeks.com

    If not set it to that and click Apply.

    Now cleanup the stuff I gave you below, which I'll repeat:

    Run HiJaak This again and check the below items off and delete them:

    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
    O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/052f427...ip/RdxIE601.cab
    O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/s...stemsoappro.cab

    Then reboot your PC. And give us another HiJaak This log and let us know of any problems.
     
  11. boneyeye

    boneyeye Corporal

    Did as you advised and browsing has increased a lot TY Now other probs.on pc are same as 1st post.1) On Helptroubleshooting answers are not working,just blank page on (r) side
    I guessed this was because of prob with DISPLAY Driver mentioned in 1st post .When I opened History I got the blue screen of fatal exceptionOE has occurred in 016 F: BFFAADOB . does that give you any info? Temp also increases from 37C-73C in 15mins browsing(is that to fast) and lastly there is no 46cab in Win/Options and could not find same on 98SE Disk .Maybe there is no cab46 you tell me. See Log below I hope. TY again Boneyeye
    You would not believe it but I have failed miserably to paste the screenshot to you (something I have always found hard to master-no mater how often I read the directions)
    Ican assure you all that you asked is gone.Maybe I should leave this for a while as am getting very tired .TY again. Sorry for this.
    Boneyeye
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still not sure what's up with your Help Troubleshooting issue. I wonder if it could be related to a missing or corrupted file? Is your video display working okay otherwise? Do you have any devices shown with yellow exclaimation points on them in Device Manager?

    Not sure what you are referring to with 46cab in Win/Options. What brought this up? Do you mean you are missing the Win98_46.cab file but the rest are there? If so just copy it from you original Win98 CD back into the Windows/Options/Cabs directory.

    Cutting and pasting should be simple for you. Just bring up the log in notepad, left click at the beginning and while holding down the left mouse button drag the mouse to the end of the file. Now everything should be highlighted. Just hit CTRL-C to copy. Now in your Majorgeeks message click the mouse in the Message window and then hit CTRL-V to paste in the copied information.

    An alternative method to dragging the mouse is to left click at the beginning of the information to copy, let go of the button, now hold down the shift key and at the end of the data to copy, left click again. Now everything is highlighted again. Follow the directions above from CTRL-C onward.
     
  13. boneyeye

    boneyeye Corporal

    Logfile of HijackThis v1.97.7
    Scan saved at 19:04:18 P.M,, on 13/5/2004
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\INETSRV\INETINFO.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\Ptsnoop.exe
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\START MENU\MY INSTALLED UTILLITIES\HIJACKTHIS.EXE
    C:\WINDOWS\NOTEPAD.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.majorgeeks.com/vb/index.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eircom.net
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\WINDOWS\Start Menu\My Installed Utillities\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [Load] Ptsnoop
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\RunServices: [inetinfo.exe] C:\WINDOWS\SYSTEM\inetsrv\inetinfo.exe -e w3svc
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.eircom.net
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {DC765522-D5BE-49C9-AF5F-8C715A44BA28} - http://fdl.msn.com/public/investor/v9/ticker.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www1.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {6FB9FE59-7D3B-483D-9909-C870BE5AFA1F} (DiskHealth Class) - http://www.pcpitstop.com/pcpitstop/diskhealth.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw14fd.law14.hotmail.msn.com/activex/HMAtchmt.ocx
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37894.7292361111
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www1.pcpitstop.com/internet/pcpConnCheck.cab
    O16 - DPF: {F8F88D0D-E455-11D6-B547-00400555C7FB} (DiskHealth2 Class) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {13991839-0420-11D5-BDA3-00A0C982BA51} (PDAnalyzeCtrl Class) - http://www.pnltools.com/PDWeb.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} (MSN Chat Control 4.2) - http://fdl.msn.com/public/chat/msnchat42.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 127.0.0.1

    At last. Boy have I agonised because of this. I was saving itin paint and I think it is more complicated Thanks again. Boneyeye
     
  14. boneyeye

    boneyeye Corporal

    Chaslang hi,
    I think that we may be misinterpreting each other. In 1ist post I was just letting you know what I found after checking System info tool. Further problems were posted with an intention to help you come to a conclusion of what is wrong with comput. They are all present ther all the time except for fatel exception-which has not recurred. I have run sfc and nothing came up there except the files we Hijacked, at the same time Iam convinced myself that I deleted the file, that applies to troubleshooting answers, in error.If you could give me the name and where to find it I could check I hope.I posted problem re Cab46 as I thought the help file may hav been in it.I did post you also that cab46 could not be found on Win98 SE disk in post 11. Yet you have told me to coy it in post 12. In Device Manager:
    Sound, vidoe and game controller
    CMI 18738/C 3DX Pci Audio Controller
    Gameport
    Wave device for Voice Modem
    Hope this helps and that I have furnished all information requested. TY again, Boneyeye.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what this ptsnoop.exe program is? It appears in your
    HiJaak This log in two places:

    C:\WINDOWS\Ptsnoop.exe
    O4 - HKLM\..\Run: [Load] Ptsnoop



    I see some negative comments about this
    program and also a reference to one with the same name that may be used
    for a modem. Are you using the modem they mentioned. See these links:

    http://www.computing.net/windows95/wwwboard/forum/13515.html
    http://www.sophos.com/virusinfo/analyses/trojptsnoop.html
    http://www.computing.net/security/wwwboard/forum/1754.html
    http://www.infopackets.com/computer+questions/internat.exe+and+ptsnoop.exe+in+my+msconfig+startup+part+2.htm
    http://www.p-r-f.com/sites/ptsnoop_exe.htm


    Otherwise log looks good.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boneyeye, can we be a little careful on choice of words. What does this mean:
    " I have run sfc and nothing came up there except the files we Hijacked"

    What is sfc? What do you mean the files we Hijacked? We did not hijaak anything? Do you mean the files we deleted from your system that were in a HiJaak This log?

    There is no such file as Cab46. The original Windows 98 SE CD has a directory called \win98. In this directory you will find lots of cab files. Do you mean (as I said before) you do not have WIN98_46.CAB on your PC. This are normally copied to your Windows\options\cabs directory. Is your Win98 Se installation disk a CD or do you have floppies? Is it a full install version or an upgrade version? I don't believe that should matter the files should always be there. Unless...maybe you do not have a real Win98 Se installation disk. Are you referring to an OEM System Restore/Recovery type disk?
     
  17. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    TY for last post. Ptsnoop, I feel may be necessary for my modem, because when I deleted it from "run" in System Registry, or disabled it in "start up" I cannot hear " int.connection" eventhough "volome" is turned on. I ,personally , like to hear "Int. Connection. Please excuse my choice of words , as you know I am not a compt./techie "buff" so I would not be aware if certain terminology caused different interpitration.Sfc= System file checker, which you may know shows missing and corrupted files which you remarked on in post12. Now I have managed previous missing/corrupted files, but I am not sure it was done correctly . Which/whether it may not now be mentioned, but it could still remain a problem. And the only files mentioned here were the ones we used HijackThis on. Re Win98 disk, which was supplied with purchase of computer I feel myself it's an upgrade. Win98 was install4ed on computer when purchased. then 2yrs ago I used this disk and I had WinSE on computer. This is what is on disk: Msoft.Windows98 for PCs without Windows.On (R) side is:" For distribution with new PCs only.SECOND EDITION. 1981-1999 Msoft.Corp. products are licenced to OEM by Msoft Licencing Inc.subsidery of Msoft.Corporation. You tell me. Have I an OEM System Restore/Recoveryor Upgrade type disk. Hope all information is furnished TY again. Boneyeye.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boneyeye,

    You should use msconfig to disable startup programs from running. This is a much safer method to use instead of deleting items in the registry. That what it is much easier to just renable them again if you find out that you need it.

    Sounds like you have a full install version of Windows 98. You should be able to see a win98 directory on the CD and you should be able to find the missing cab file. The cab file you mentioned does not contain any help files though. I think the file you are missing is the Tshoot98.chm file which is normally in the \windows\help folder. This is the Windows Troubleshooter file. It is in the WIN98_60.CAB file.
     
  19. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    TYfor your reply. I checked Win98_60CAB.and found a big yellow Question mark on Tshoot98.chn file,and also on 3/4 more. Similiar on Win98 SE disk.I checked al Win98 Cab Files and found:

    Win98_22CAB File 4/5 Yellow Question Marks
    " 23 " " " ALl " " "
    " 24 " " " " " " "
    " 25 " " " 8/9 " " "
    " 26 " " " BLANK TOTALLY
    " 60 " " " As above
    And it is similiar on Mt Msoft.Win98 SE disk supplied with compt. Now I know where I can get another disk as 2 computers were purchased together, but it will take some time. If I get disk would you be willing to guide me through it, but if not where would I get the advice. The company where computer was purchased is closed since last year due to tragic death of owner. Maybe the above is the cause of all my problems.TY again. Boneyeye.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yellow question marks icons are what is used for marking these .chm (Compile HTML Help) files. That is normal behavior. Where did you find Win98_60.CAB? In your Windows\help directory or are you talking about on the Windows 98 Se CD Rom?


    What are you trying to tell me? Yes many of these CAB file will have .CHM files in them?
    What's your point? By the way Win98_26.CAB is not BLANK. It has 206 files in it. It just does not have any .CHM files.

    Why do you need another disk? If you just want to fix corrupted or missing files found with SFC then just use the "Extract one file from installation disk" option of SFC to restore the files.

    By the way, to fix your troubling shooting problem you may need to repair Tshoot98.chm as well as Tshoot.ocx (Tshoot.ocx is in Win98_69.CAB)
     
  21. boneyeye

    boneyeye Corporal

    Hi,
    TY for last post and for sticking with a lot of this " gobbledegook" I just thought that when those large yellow question marks were shown over those files that there was something wrong or that they may be missing. Shows how much I have to learn and again my apologies, Now you will have to take me step by step on the repair you advised. Now WIn98_26Cab is totally complete so no prob there. But wait for it WIN98_46CAB is missing from C:\OPTIONS\WIN98 and I have it on the Win98SE disk how do I put this right. I think that those are the only 2probs I am left with. Again thanking you for your patience.
    Boneyeye.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean C:\windows\options\cabs don't you? If the WIN98_46.CAB file is missing, you can just copy it from the CD to the C:\windows\options\cabs folder. But you do not really need to have all these CAB files on your hard disk. It is just convient sometimes and avoids the necessity of finding your Win98 CD when something asks for it.
     
  23. boneyeye

    boneyeye Corporal

    Hi,
    Thanks, but how do I repair Tshoot98.chm and Tshoot.ocx(both in Win98_69.CAB ).

    Boneyeye
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I mentioned that in my message on 5/16/04:

    "Why do you need another disk? If you just want to fix corrupted or missing files found with SFC then just use the "Extract one file from installation disk" option of SFC to restore the files."

    You could also just extract the files you need using WinZip (or another tool that handles CAB files).
     
  25. boneyeye

    boneyeye Corporal

    Hi,
    TY for last post. I have now extracted both files to C:\windows\options\cabs folder with no different effect .By the way Tshoot.chm is in Win_60CAB on my computer It said that whan I attempted to extract it to to Win_69CAB . Tshoot.ocx extracted to Win _69CAB.
    But I still have same problem. Now I saw somewhere that a font file missing caused the (L) page in " help" to nonfunction and I checked at that time and that font was present, in my font files. I wonder could it be a different font file for the "answers" in "help" and that font may be missing. Just a thought. My 2cents. TY again.

    Boneyeye.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Using SFC you are not suppose to extract to a CAB file. You merely extract the files that you need to there appropriate directories. For example: from WIN98_60.CAB you would extract Tshoot98.chm to C:\windows\help. And from WIN98_69.CAB you would extract Tshoot.ocx to c:\windows\help.

    Use the "Extract one file from installation disk" option of SFC to restore the files."
     
  27. boneyeye

    boneyeye Corporal

    Hi,
    TY again. Now I have both files in C:\windows\ help folder with no change whatsoever. Answers to help Tshooting remain blank. Have you checked on the font issue I mentioned in my previous post. TY.

    Boneyeye
     
  28. Maxwell

    Maxwell Folgers

    If you are unable to view your windows troubleshooter you can always use the on-line version at: http://support.microsoft.com/default.aspx?scid=fh;EN-US;w98tshoot&product=w98
    and further information at: http://www.microsoft.com/technet/archive/win98/support/trblshoot/trouble.mspx

    I do recall that there have been some issues with chm files in the past: http://support.microsoft.com/default.aspx?scid=kb;en-us;297026 and http://support.microsoft.com/default.aspx?scid=kb;en-us;323255

    However, it was mentioned earlier to upgrade to IE6 - I have this on my Windows 98 machine without problems but I suppose "if it ain't broke don't fix it".
     
  29. boneyeye

    boneyeye Corporal

    Hi Maxwell,
    TY for answering. Actually you will see in post 4 why I did not change to IE6.
    Now are you saying that if I did do so, the prob. with help answers, would be solved. I visited all your links TY very much, but I have always found Msoft. too high tech for me that is why I am visiting Majorgeeks. Maybe we will have to leave this one unsolved which is a first for Majorgeeks.TY again.

    Boneyeye
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boneyeye,

    In one of the links Maxwell gave: http://support.microsoft.com/defaul...kb;en-us;297026
    it does imply that upgrading to a more recent version of IE5.5 has fixed problems like you are seeing. This could be true of upgrading to IE6 too. May be worth a try. IE6 is more secure that IE5.5 so it is probably a good idea to upgrade anyway.
     
  31. boneyeye

    boneyeye Corporal

    Hi,

    Have upgraded to IE6 but no change.
    Boneyeye
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must have some corrupted files! What are the exact steps you are doing to bring up the troubleshooter you are having a problem with?
     
  33. boneyeye

    boneyeye Corporal

    Hi Maxwell,
    Attempted remapping again and" Hey Presto" problem re ""/@ is solved. Thanks a bunch. Hope to get same result from Chaslang soon. Bye for now.

    Boneyeye
     
  34. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    I click "start",then "help" Windows Help dialog box opens.I click on "Troubleshooting" and Windows98 Troubleshooters dialog box opens. No matter what troubleshooter I select the end result is the same. I radio click on any of the probs.on (R) hand side, then click on "next" and then I get my famouse blank page . Now as I told you previously I get the same result if I go to "troubleshooters" via DirectX Diag. Tool at the commencement of this thread. TYagain.

    Boneyeye
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't remember seeing any mention of DirectX Diag anywhere?

    But if you run Dxdiag, what does it say about your Display adapter? Are there any problems?

    Was your display adapter built-in to the mother board? Perhaps a reinstall of the drivers for your adapter would help resolve this.
     
  36. boneyeye

    boneyeye Corporal

    Hi Chaslang,
    DxDiag is one of Mcsoft's Systems Info Tools in Wins98. Ihave explained all this to you in ist post. please check it over again. Iwas wondering is there any possibility that the missing Display Driver:eek:emrom.bin has something to do with displaying the answers to "Help Troubleshooters"

    Boneyeye
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know what dxdiag is! What I was questioning is that you never mentioned it as far as I can see in any post before.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way Microsoft's System Info tool is msinfo32.exe. Dxdiag is a diagnostic tool to help in finding problems with display and sound problems related to DirectX drivers incompatibilities.

    By the way what version of DirectX do you have installed?
     
  39. boneyeye

    boneyeye Corporal

    DxDiag. Ver.4.09.0000.0902 Copyright 1999-2003 Boneyeye
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! What does it give you under the display tab for:

    Device Name, Manufacturer, memory
    and for Drivers, what is the main driver, its version, and date.

    Are there any directx errors or complaints about your card?
    Can you run the DirectDraw and Direct3D tests okay?
     
  41. boneyeye

    boneyeye Corporal

    Hi,
    Device Name:SIS 530
    Manufact. :SIS
    Memory :7.5MB
    (display adapter says 8MB)
    Chip Type : 530
    DAC Type Internal
    Current Display Mode:1024x768(16bit) default refresh rate
    Main Drive :SIS 530V.drv
    Version :4.11.0001.1060(English)
    Date :3/8/1999
    WHQL Logo'd :yes
    Mini VDD SIS 530v.vxd
    Vdd. *vdd
    DDI Version : 6
    Notes:Hardware Accellerated Direct 3D 9+ is not available,because display driver does not support it.You may be able to get new one from manufacturer..All Direct Draw and other 3D Tests i.e. 7&8 were successful. Cheers. Boneyeye.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hi Boneyeye,

    That sounds okay. Maybe it is something related to a driver for you video chips or perhaps as you suggested earlier maybe it is related to a font problem. Seems strange though that you only have a problem displaying trouble shooting information. I'll keep checking but I have not found anything on this yet. Maybe you could try reinstalling the drivers for you video card. I forget, was it a built-in?
     
  43. boneyeye

    boneyeye Corporal

    OK Chaslang one last bash at this prob. plz. Can you find out for me what font the troubleshooter answers are displayed in and I may be able to solve it from there. Now I am quite sure that the left side and right side of troubleshooters are in different fonts, so its quite possible that the answers are in a 3rd different font. By the way do not have video driver as I have no DVD drive -just Display Adapter: SIS 530. Thanks a bunch again for sticking so long with me on this one. It is certainly true about the recommendation I was given by a friend you all here at "majorgeeks" are the best .


    Boneyeye
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boneyeye,

    I just sent a message to another person here at MG's that may be able to shed more light on this problem. Hopefully he'll be jumping in soon. Look for Adrynalyne's reply.

    Chas
     
  45. Adrynalyne

    Adrynalyne Guest

    Does anyone know if the Windows 98 troubleshooter uses javascript? Windows ME, XP, and maybe 2k does.

    Try this while I do more research.

    Start, run, jscript.dll.

    Click ok.

    It should succeeed.

    Reboot and retry it.
     
  46. Adrynalyne

    Adrynalyne Guest

    Start, run, and type the following:

    regedit /e tshoot.txt HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{4B106874-DD36-11D0-8B44-00A024DD9EFF}

    Click OK.

    Open the tshoot.txt file on your desktop.

    Paste the contents of it in a post here.
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks Adryn! I knew you would have some ideas! ;)
     
  48. boneyeye

    boneyeye Corporal

    Hi Adrynalyne,
    TY for replying, and I hope you will be able to help solving this prob.Well I tried "jscript.dll" in run. Did not work Because of no Program association with "dll" files. So you wouldhave to take me step by step for this. Any way I found file in registry but one no is different. It is {4B106875} at the beginning as opposed to yours, and with the results I got perhaps you cou check yours. Now nothing happened in run with new one either but will quote it to you. When I clicked on the number I got:
    ab Default Name : Data "Microsoft Local Troubleshooter Property Pa..........

    And on the No's Tree Extension When I clicked I got:
    "C\WINDOWS\HELP\TSHOOT.OCX"
    So I feel we are on to something here.

    Iwould rather spend ihr printing out data than 2dys trying to do this paste thing. Just a brain block with it Even with "MG" in the past Hope this gives you some inspiration TYagain
    Boneyeye.
     
  49. Adrynalyne

    Adrynalyne Guest

    Crap, I am an idiot. I meant to type, go to start, run and type:

    regsvr32.exe jscript.dll and click OK.
     
  50. Adrynalyne

    Adrynalyne Guest

    Ok, I think our solution is here.

    Where you say yours reads {4B106875} .

    It should actually read, {4B106874}.

    More specifically, it should read {4B106874-DD36-11D0-8B44-00A024DD9EFF}

    Change that one number value from 5 to 4 and I suspect it will work again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds