Go Back   Cyber Tech Help Support Forums > Operating Systems > Windows NT, 2000, 2003

Notices

Reply
 
Topic Tools
  #1  
Old February 24th, 2004, 03:28 PM
dekonstruct dekonstruct is offline
New Member
 
Join Date: Feb 2004
Posts: 8
format

hi there,

my computer's been playing up lately, i've been told formatting it is the best solution. i've saved all my music/files/images on cds. i need to make a bootdisk, cause i got the comp. from a friend and didn't have any disks with it. i have downloaded the w2000 zips from bootdisk.com. i also saw W2k server to download there, is it part of the stuff i need to make a bootdisk?

after i make the bootdisk, how do i format the computer? is that all i need to do it, the bootdisks? silly question, but if i format it, will devices get deleted?

please help.

thank you in advance,
lola
Reply With Quote
  #2  
Old February 24th, 2004, 07:23 PM
dekonstruct dekonstruct is offline
New Member
 
Join Date: Feb 2004
Posts: 8
Unhappy awww

23 views and no one can help?

please...

i'm sure it's all basic knowledge of computers, but it's knowledge i haven't got :-/
Reply With Quote
  #3  
Old February 24th, 2004, 09:14 PM
degsy's Avatar
degsy degsy is offline
Cyber Tech Help Moderator
 
Join Date: Jul 2001
Location: North-East, UK
Posts: 22,042
Blog Entries: 1
Quote:
i got the comp. from a friend and didn't have any disks with it
If you're installing W2K then why not boot from the CD?
__________________
Cheers,
Degs

Please post back with your results
CTH Terms of Use

CTH Subscriptions :: Adaware Guide :: HijackThis
Reply With Quote
  #4  
Old February 24th, 2004, 10:31 PM
renegade600's Avatar
renegade600 renegade600 is offline
Certifiable Bum
 
Join Date: Sep 2003
O/S: Linux
Location: Jonesboro, Ar
Posts: 22,003
Sorry you cannot get help fast enough but...you will and normally within 24 hours so please be patient.

Reformatting is the last resort. What problems are you having with your computer? Give exact error messages.
__________________
Dan
Registered Linux User #382181 - Don't be irreplaceable; if you can't be replaced, you can't be promoted.

posting tips - cth tos - how to post hijackthis log





Reply With Quote
  #5  
Old February 24th, 2004, 11:05 PM
dekonstruct dekonstruct is offline
New Member
 
Join Date: Feb 2004
Posts: 8
degsy: i haven't got any cds. i just got the computer with windows 2000 pro on it.

renegade: sorry :-/ i rushed...
it's doing lots of things: i have to restart it very often, cause it's the only way to do anything. for example, menus in ie {i haven't really used any other programs lately} don't work, they can't be clicked on. copy & paste doesn't work. add & remove programs doesn't work {unless i open it right after restarting}, "close" on menus is "Cl&ose". and it's got some user folders? i can't delete. ha! now it's doing this thing, where i go back on a word to change a letter and... it's hard to explain. if i press space it eats a letter?

i had a virus lovesan,but AVG says it's clear now.

it's just a nuisance, and it was ok for a while when i got it, but then someone put their hard drives on it, and after that, when they removed them, they deleted some stuff, and since it's been messed up.

there's just stuff on it that i'm not sure belongs to me, cause so many people have used it in the past.

so that's why i sort of wanna format it, so it's my own from the beggining. if you know what i mean.

thank you for replying,
lola
Reply With Quote
  #6  
Old February 24th, 2004, 11:16 PM
renegade600's Avatar
renegade600 renegade600 is offline
Certifiable Bum
 
Join Date: Sep 2003
O/S: Linux
Location: Jonesboro, Ar
Posts: 22,003
Lets work with your computer before you format. With the problems you are describing, maybe it can be fixed.

download, run and post the log from hijackthis and someone will look at it.

However if you insist on reformatting, then use the Win2k cd to boot your computer. Just stick it in the drive and turn on the computer and follow the onscreen instructions. It should start the process.
__________________
Dan
Registered Linux User #382181 - Don't be irreplaceable; if you can't be replaced, you can't be promoted.

posting tips - cth tos - how to post hijackthis log





Reply With Quote
  #7  
Old February 25th, 2004, 02:10 AM
Murf's Avatar
Murf Murf is offline
Moderator
 
Join Date: Oct 2001
O/S: Windows Vista 32-bit
Location: Hampton VA
Posts: 10,078
i haven't got any cds. i just got the computer with windows 2000 pro on it.

If you format you WIPE THE DRIVE CLEAN and obviously, lose W2K pro, so how would you reinstall if you don't have the W2K CD>>>
__________________
Help at Murf's Garage
Microsoft MVP - 2004-2008

"Moderator - Windows 98, XP, Vista, Hardware"
Posting results - helps others


Please consider supporting CTH with a Subscription.
Reply With Quote
  #8  
Old February 25th, 2004, 10:48 AM
dekonstruct dekonstruct is offline
New Member
 
Join Date: Feb 2004
Posts: 8
murf, you are right! i'm such a such and such! i don't know why i was under the impression that... i'm too embarassed to say it. that everything i needed would be on the boot disks... so i guess i can't format it until i get w2k on a cd. cause i still want to get rid of all these undeleteble folders with system files, there's too many sets of them.

following renegade's advice i managed to download hijackthis after restarting the comp numerous times. when i tried to post the log tough, my comp had enough, so i saved it and i'm posting it from work. here it goes:

Logfile of HijackThis v1.97.7
Scan saved at 23:41:31, on 24/02/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINNT\AGRSMMSG.exe
C:\PROGRA~1\OpiStat\OpiStat\OpiStat.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\WINNT\System32\rundll32.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\WINNT\System\webcheck.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\imesh\iMeshClient.exe
C:\WINNT\system32\topsys.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\GetRight\GETRIGHT.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\+\floppy\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.greenapple.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Green Apple, Inc.
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_64.dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [OpiStat] C:\PROGRA~1\OpiStat\OpiStat\OpiStat.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKCU\..\Run: [System Update] C:\WINNT\System\webcheck.exe
O4 - HKCU\..\RunOnce: [eZstub] C:\WINNT\system32\topsys.exe /Wait
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: iMesh.lnk = C:\Program Files\imesh\iMeshClient.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Global Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Broken Internet access because of LSP provider 'nmtracer.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.greenapple.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613} (OPInstall Control) - http://a14.g.akamai.net/f/14/7141/14...n_4.1.10.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A36BAF7-F540-4DBB-BC92-8FFD0411D72C}: NameServer = 212.67.96.129 212.67.120.148

what do you think?
thank you in advance for replies.

lola
Reply With Quote
  #9  
Old February 26th, 2004, 06:37 PM
dammit's Avatar
dammit dammit is offline
Rampant Rabbit
 
Join Date: Dec 2002
Location: New York/Paris/Milan/pie country
Age: 6
Posts: 11,536
Blog Entries: 2
Hi lola...OK a few things to do....you have been hijacked :no:

First download this to your desktop and use it if you have trouble connecting to the net after the next step.
http://www.cexx.org/lspfix.htm

Then go here and run this
http://www.new.net/support/uninstall3_88.exe

After that...download and run cwshredder from
www.zerosrealm.com/downloads/CWShredder.zip

check for updates
hit the "fix" button and let it run.

Post back a new hijack log
__________________
Founder Member of the CTH Brat Pack. The Divine Leader.
......\\ \ll/ //......
......( @ @ )......
oOOo==(~)==oOOo
You're only young once - but you can be immature for ever. FREEDOM for Smokers.
Reply With Quote
  #10  
Old February 27th, 2004, 06:55 PM
dullman300 dullman300 is offline
New Member
 
Join Date: Feb 2004
Posts: 3
It looks like you have a lot of extra stuff running. You probably have some spywhere or something running. That will degrade your performance a lot. A telltale sign of this happening is new search bars or new icons showing up. Lavasoft makes a great product for searching and removing this stuff. It's called Adware. Current version is 6.0. Best part is that it is high quality and free. Run it, delete what it finds, reboot, and scan it again. After you do that a couple of times, you'd be suprised how much better you're pc will run.

www.lavasoftusa.com
Reply With Quote
  #11  
Old February 29th, 2004, 12:37 AM
dekonstruct dekonstruct is offline
New Member
 
Join Date: Feb 2004
Posts: 8
hello...

dammit: i tried the first link, and downloaded it and ran it, it removed lots of stuff, but couldn't remove some because it's always running in the background. the second link downloaded a webpage, and i didn't find anything there to unistall that newnet thing. the third link tries to download something, but then i get a message saying "insert the windows 2000 cd", and as i said before, i got the computer from a friend with everything installed, but no cd's or disks.

dullman: i didn't download that adware stuff, cause it said on the site recommended by dammit that adware and the other program would have a conflict or something. i think i'll try it now?

thank you both for your help, and here is another hijackthis log. altough the computer is still being strange.


Logfile of HijackThis v1.97.7
Scan saved at 23:36:32, on 28/02/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINNT\AGRSMMSG.exe
C:\PROGRA~1\OpiStat\OpiStat\OpiStat.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\WINNT\System32\rundll32.exe
C:\WINNT\System\webcheck.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\imesh\iMeshClient.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\GetRight\GETRIGHT.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\+\floppy\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.greenapple.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Green Apple, Inc.
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: DashBar Toolbar - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - C:\Program Files\DashBar\DashBar15.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [OpiStat] C:\PROGRA~1\OpiStat\OpiStat\OpiStat.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
O4 - HKCU\..\Run: [System Update] C:\WINNT\System\webcheck.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: iMesh.lnk = C:\Program Files\imesh\iMeshClient.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Global Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O10 - Broken Internet access because of LSP provider 'nmtracer.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.greenapple.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613} (OPInstall Control) - http://a14.g.akamai.net/f/14/7141/14...n_4.1.10.0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A36BAF7-F540-4DBB-BC92-8FFD0411D72C}: NameServer = 212.67.96.129 212.67.120.148

thank you... buh bye.
lola

Last edited by dekonstruct; February 29th, 2004 at 01:00 AM.
Reply With Quote
  #12  
Old February 29th, 2004, 12:51 AM
dammit's Avatar
dammit dammit is offline
Rampant Rabbit
 
Join Date: Dec 2002
Location: New York/Paris/Milan/pie country
Age: 6
Posts: 11,536
Blog Entries: 2
Hi again...close IE and all open windows and have hijack fix

O3 - Toolbar: DashBar Toolbar - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - C:\Program Files\DashBar\DashBar15.dll

Reboot....
__________________
Founder Member of the CTH Brat Pack. The Divine Leader.
......\\ \ll/ //......
......( @ @ )......
oOOo==(~)==oOOo
You're only young once - but you can be immature for ever. FREEDOM for Smokers.
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 09:46 PM.

[ RSS ]