TheTechGuide Forum

General Category => Tech Clinic => Topic started by: waterburn on February 04, 2008, 09:20:04 PM

Title: Command Prompt Error!
Post by: waterburn on February 04, 2008, 09:20:04 PM
Everytime I run or open anything command prompt related a error message pops up. I mean running ntvdm.exe, cmd.exe, command.com. I can't read it since it is in Chinese (get to that another time) but there is a red X with a circle around it with (0xc0000142) I am pretty sure it has to do with me messing with the registry. I followed some kind of guide and change the language settings to English for non-unicode programs. Now I can't remember the old numbers for the keys to set it back to Chinese for non-unicode programs. I am already begginning to have problems. The non-unicode programs are english but they window seems to be bigger and the letters spread apart. Sometimes there are lots of ????? in windows. Any help will be accepted. Thanks in advance!
Title: Command Prompt Error!
Post by: guestolo on February 05, 2008, 06:13:38 AM
Did you check this setting?

# Click Start -> Control Panel -> Regional and Language Options
# At the Regional and Language Options dialog, click on Advanced tab
# At the Language for non-Unicode programs box, select Chinese  and then click OK
Title: Command Prompt Error!
Post by: waterburn on February 05, 2008, 04:04:59 PM
[quote name=\'guestolo\' post=\'420899\' date=\'Feb 5 2008, 05:13 AM\']Did you check this setting?

# Click Start -> Control Panel -> Regional and Language Options
# At the Regional and Language Options dialog, click on Advanced tab
# At the Language for non-Unicode programs box, select Chinese and then click OK[/quote]

Here's my HjackThis log. I will fix ANYTHING you suggest, recommend or tell me to fix. But my problem is the opening of Command Prompt and the change in registry of non-unicode programs.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:06:22 PM, on 05/02/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Prime95\Prime95.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ (http://\"http://www.google.ca/\")
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 128.143.137.250:3124
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINNT\system32\Macromed\Flash\FlashUtil9d.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java ??? - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINNT\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINNT\bdoscandel.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: TruePass EPF 7,0,100,739 - https://blrscr3.egs-seg.gc.ca/applets/entru...sapplet-epf.cab (http://\"https://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab\")
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - http://www.worldwinner.com/games/v46/scrab...rabblecubes.cab (http://\"http://www.worldwinner.com/games/v46/scrabblecubes/scrabblecubes.cab\")
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab (http://\"http://downloads.ewido.net/ewidoOnlineScan.cab\")
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - http://www.worldwinner.com/games/v47/share...GamesLoader.cab (http://\"http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab\")
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab (http://\"http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab\")
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} - http://www.worldwinner.com/games/v50/pool/pool.cab (http://\"http://www.worldwinner.com/games/v50/pool/pool.cab\")
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (http://\"http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab\")
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} - http://www.ca.com/ca/en/securityadvisor/pe...an/pestscan.cab (http://\"http://www.ca.com/ca/en/securityadvisor/pestscan/pestscan.cab\")
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} - http://www.worldwinner.com/games/v57/bjattack/bja.cab (http://\"http://www.worldwinner.com/games/v57/bjattack/bja.cab\")
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab (http://\"http://download.bitdefender.com/resources/scan8/oscan8.cab\")
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} - http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab (http://\"http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab\")
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab (http://\"http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab\")
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} - http://www.worldwinner.com/games/v41/freecell/freecell.cab (http://\"http://www.worldwinner.com/games/v41/freecell/freecell.cab\")
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - http://www.worldwinner.com/games/shared/wwlaunch.cab (http://\"http://www.worldwinner.com/games/shared/wwlaunch.cab\")
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - http://camera.clemson.edu/long/AxisCamControl.ocx (http://\"http://camera.clemson.edu/long/AxisCamControl.ocx\")
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (http://\"http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab\")
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} - http://pcpitstop.com/mhLbl.cab (http://\"http://pcpitstop.com/mhLbl.cab\")
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} - http://www.worldwinner.com/games/v46/sol/sol.cab (http://\"http://www.worldwinner.com/games/v46/sol/sol.cab\")
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} - http://www.worldwinner.com/games/v41/hangman/hangman.cab (http://\"http://www.worldwinner.com/games/v41/hangman/hangman.cab\")
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe (http://\"http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe\")
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} - http://www.worldwinner.com/games/v47/wwspades/wwspades.cab (http://\"http://www.worldwinner.com/games/v47/wwspades/wwspades.cab\")
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab (http://\"http://driveragent.com/files/driveragent.cab\")
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Prime95 Service - Unknown owner - C:\Program Files\Prime95\Prime95.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1.GU-/LOCALS~1/Temp/msoclip1/02/clip_image002.jpg (http://\"http://file:///C:/DOCUME~1/ADMINI~1.GU-/LOCALS~1/Temp/msoclip1/02/clip_image002.jpg\")
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\My Documents\My Pictures\let it snow.bmp

--
End of file - 6795 bytes

Thanks in advance for any help.
Title: Command Prompt Error!
Post by: waterburn on February 05, 2008, 04:39:24 PM
[quote name=\'guestolo\' post=\'420899\' date=\'Feb 5 2008, 05:13 AM\']Did you check this setting?

# Click Start -> Control Panel -> Regional and Language Options
# At the Regional and Language Options dialog, click on Advanced tab
# At the Language for non-Unicode programs box, select Chinese and then click OK[/quote]

Sorry since I have windows 2000 I don't have those settings.
Title: Command Prompt Error!
Post by: waterburn on February 05, 2008, 07:06:36 PM
Here are some screenshots of the error message I am getting. The one in Chinese is the original while the one in English I got from Google Images. I believe it is the translation of my error message except instead of game.exe I have cmd.exe, ntvdm.exe or command.com... etc.
Title: Command Prompt Error!
Post by: guestolo on February 07, 2008, 09:42:37 PM
Quote
I am pretty sure it has to do with me messing with the registry. I followed some kind of guide and change the language settings to English for non-unicode programs. Now I can't remember the old numbers for the keys to set it back to Chinese for non-unicode programs.

What guide did you follow?
Link please
Title: Command Prompt Error!
Post by: waterburn on February 08, 2008, 04:01:09 PM
[quote name=\'guestolo\' post=\'421116\' date=\'Feb 7 2008, 08:42 PM\']What guide did you follow?
Link please[/quote]

The site is: http://www.hostingforum.ca/211890-how-chan...s-registry.html (http://\"http://www.hostingforum.ca/211890-how-change-language-non-unicode-programs-registry.html\") second post. Thanks for replying!
Title: Command Prompt Error!
Post by: guestolo on February 08, 2008, 06:19:45 PM
Have you seen this link
http://www.jollans.com/faq/nonunicode.htm (http://\"http://www.jollans.com/faq/nonunicode.htm\")

Scroll near the bottom

May also help to see the export of that key

==Open Notepad (START>>>RUN>>>type in notepad)
Hit OK
Copy the contents of the CODE box, not including the word "code"
Paste it to the empty Notepad file
In Notepad click FILE>>SAVE AS
Change the Save as Type to All Files.
Name the file as Export.bat

Save this file on the desktop

 
Code: [Select]
regedit /e export.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls"
export.txt


Double click on Export.bat>>A log will open, also
A file by the name export.txt will produce on your desktop
Can you UPLOAD that file in your response
Title: Command Prompt Error!
Post by: waterburn on February 09, 2008, 03:26:28 PM
[quote name=\'guestolo\' post=\'421172\' date=\'Feb 8 2008, 05:19 PM\']Have you seen this link
http://www.jollans.com/faq/nonunicode.htm (http://\"http://www.jollans.com/faq/nonunicode.htm\")

Scroll near the bottom

May also help to see the export of that key

==Open Notepad (START>>>RUN>>>type in notepad)
Hit OK
Copy the contents of the CODE box, not including the word "code"
Paste it to the empty Notepad file
In Notepad click FILE>>SAVE AS
Change the Save as Type to All Files.
Name the file as Export.bat

Save this file on the desktop

Code: [Select]
regedit /e export.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls"
export.txt


Double click on Export.bat>>A log will open, also
A file by the name export.txt will produce on your desktop
Can you UPLOAD that file in your response[/quote]

1) When I change the regional settings as it says on the site, it says I need the windows 2000 disk. I do not have the windows 2000 disk.

2) When I open Export.bat the same error message for cmd.exe and ntvdm.exe appears.

Thanks for the instructions!
Title: Command Prompt Error!
Post by: guestolo on February 09, 2008, 10:52:37 PM
Quote
I do not have the windows 2000 disk.
That sure doesn't help?

Can you run the following and see if it will run
Download [color=\"#008000\"]Deckard's System Scanner (dss.exe)[/color] (http://\"http://deckard.geekstogo.com/dss.exe\") to your desktop.
Close all applications and windows.
Double-click on dss.exe to run it and follow the prompts.
When the scan is complete, two text files will open; main.txt, which will be maximized and extra.txt, which will be minimized.

Post back just the Whole contents of Main.txt and Extra.txt
Title: Command Prompt Error!
Post by: waterburn on February 10, 2008, 09:30:30 AM
[quote name=\'guestolo\' post=\'421225\' date=\'Feb 9 2008, 09:52 PM\']That sure doesn't help?

Can you run the following and see if it will run
Download [color=\"#008000\"]Deckard's System Scanner (dss.exe)[/color] (http://\"http://deckard.geekstogo.com/dss.exe\") to your desktop.
Close all applications and windows.
Double-click on dss.exe to run it and follow the prompts.
When the scan is complete, two text files will open; main.txt, which will be maximized and extra.txt, which will be minimized.

Post back just the Whole contents of Main.txt and Extra.txt[/quote]

Note: During the scan another message with swreg.exe popped up. It is the same as the other messages except it had swreg.exe. I just pressed "OK" several times and the scan continued.

Here are the contents of Main.txt:
--------------------------------------------------------------------------------
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-02-11 09:11:44
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Backed up registry hives.
Performed disk cleanup.

[color=\"red\"]Total Physical Memory: 184 MiB (256 MiB recommended).[/color]
[color=\"red\"]System Drive C: has 0 GiB (less than 15%) free.[/color]


-- HijackThis (run as Administrator.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:13:38 AM, on 11/02/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Prime95\Prime95.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\??\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ (http://\"http://www.google.ca/\")
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 128.143.137.250:3124
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINNT\system32\Macromed\Flash\FlashUtil9d.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java ??? - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINNT\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINNT\bdoscandel.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: TruePass EPF 7,0,100,739 - https://blrscr3.egs-seg.gc.ca/applets/entru...sapplet-epf.cab (http://\"https://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab\")
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - http://www.worldwinner.com/games/v46/scrab...rabblecubes.cab (http://\"http://www.worldwinner.com/games/v46/scrabblecubes/scrabblecubes.cab\")
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab (http://\"http://downloads.ewido.net/ewidoOnlineScan.cab\")
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - http://www.worldwinner.com/games/v47/share...GamesLoader.cab (http://\"http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab\")
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab (http://\"http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab\")
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} - http://www.worldwinner.com/games/v50/pool/pool.cab (http://\"http://www.worldwinner.com/games/v50/pool/pool.cab\")
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (http://\"http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab\")
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} - http://www.ca.com/ca/en/securityadvisor/pe...an/pestscan.cab (http://\"http://www.ca.com/ca/en/securityadvisor/pestscan/pestscan.cab\")
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} - http://www.worldwinner.com/games/v57/bjattack/bja.cab (http://\"http://www.worldwinner.com/games/v57/bjattack/bja.cab\")
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab (http://\"http://download.bitdefender.com/resources/scan8/oscan8.cab\")
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} - http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab (http://\"http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab\")
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab (http://\"http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab\")
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} - http://www.worldwinner.com/games/v41/freecell/freecell.cab (http://\"http://www.worldwinner.com/games/v41/freecell/freecell.cab\")
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - http://www.worldwinner.com/games/shared/wwlaunch.cab (http://\"http://www.worldwinner.com/games/shared/wwlaunch.cab\")
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - http://camera.clemson.edu/long/AxisCamControl.ocx (http://\"http://camera.clemson.edu/long/AxisCamControl.ocx\")
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (http://\"http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab\")
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} - http://pcpitstop.com/mhLbl.cab (http://\"http://pcpitstop.com/mhLbl.cab\")
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} - http://www.worldwinner.com/games/v46/sol/sol.cab (http://\"http://www.worldwinner.com/games/v46/sol/sol.cab\")
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} - http://www.worldwinner.com/games/v41/hangman/hangman.cab (http://\"http://www.worldwinner.com/games/v41/hangman/hangman.cab\")
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe (http://\"http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe\")
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} - http://www.worldwinner.com/games/v47/wwspades/wwspades.cab (http://\"http://www.worldwinner.com/games/v47/wwspades/wwspades.cab\")
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab (http://\"http://driveragent.com/files/driveragent.cab\")
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Prime95 Service - Unknown owner - C:\Program Files\Prime95\Prime95.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1.GU-/LOCALS~1/Temp/msoclip1/02/clip_image002.jpg (http://\"http://file:///C:/DOCUME~1/ADMINI~1.GU-/LOCALS~1/Temp/msoclip1/02/clip_image002.jpg\")
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\My Documents\My Pictures\let it snow.bmp

--
End of file - 6817 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 OCDE (ZTekWare Original CD Emulator Service) - c:\winnt\system32\drivers\ocde.sys <Not Verified; ZTekWare.; ZTekWare Original CD Emulator>
R1 FsVga - c:\winnt\system32\drivers\fsvga.sys <Not Verified; Microsoft Corporation; Microsoft® Windows ® 2000 Operating System>
R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R3 ROOTMODEM (Microsoft Legacy Modem Driver) - c:\winnt\system32\drivers\rootmdm.sys <Not Verified; Microsoft Corporation; Microsoft® Windows ® 2000 Operating System>
R3 solo (ESS Solo Audio Driver (WDM)) - c:\winnt\system32\drivers\solo.sys <Not Verified; Microsoft Corporation; Microsoft® Windows ® 2000 Operating System>
R3 StillCam (Still Serial Digital Camera Driver) - c:\winnt\system32\drivers\serscan.sys <Not Verified; Microsoft Corporation; Microsoft® Windows ® 2000 Operating System>

S0 ntcdrdrv - c:\winnt\system32\drivers\ntcdrdrv.sys <Not Verified; NoteBurn Software; NoteBurn>
S3 NPF (Netgroup Packet Filter) - c:\winnt\system32\drivers\npf.sys <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
S3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 scrcap - c:\winnt\system32\drivers\scrcap.sys (file missing)
S3 SiSV6306 - c:\winnt\system32\drivers\sis6306p.sys <Not Verified; Silicon Integrated Systems Corporation; SiS ® 530/620 Miniport Driver for Windows 2000>
S3 TVICHW32 - c:\winnt\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 NetCM (Network Connection Manager) - c:\program files\common files\microsoft shared\speech\svchost.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
R2 Prime95 Service - c:\program files\prime95\prime95.exe <Not Verified; ; PRIME95 Application>

S2 Automatic LiveUpdate Scheduler - "c:\program files\symantec\liveupdate\aluschedulersvc.exe" (file missing)
S3 LiveUpdate - "c:\progra~1\symantec\liveup~1\lucoms~1.exe" (file missing)


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI ???????
Device ID: PCI\VEN_14F1&DEV_1033&SUBSYS_1500144F&REV_08\3&61AAA01&0&50
Manufacturer:
Name: PCI ???????
PNP Device ID: PCI\VEN_14F1&DEV_1033&SUBSYS_1500144F&REV_08\3&61AAA01&0&50
Service:

Class GUID: {4D36E97B-E325-11CE-BFC1-08002BE10318}
Description: NoteBurn Virtual CD-RW SCSI Controller
Device ID: ROOT\SCSIADAPTER\0001
Manufacturer: NTBURNER
Name: NoteBurn Virtual CD-RW SCSI Controller
PNP Device ID: ROOT\SCSIADAPTER\0001
Service: ntcdrdrv


-- Scheduled Tasks -------------------------------------------------------------

2008-01-27 17:25:02       286 --a------ C:\WINNT\Tasks\Uniblue SpeedUpMyPC Nag.job
2007-09-28 12:31:56       408 --a------ C:\WINNT\Tasks\Uniblue SpeedUpMyPC.job


-- Files created between 2008-01-11 and 2008-02-11 -----------------------------

2008-02-10 09:18:49    922862 ---h----- C:\WINNT\ShellIconCache
2008-02-09 22:37:11         0 d-------- C:\Documents and Settings\All Users.WINNT\Application Data\SUPERAntiSpyware.com
2008-02-05 16:04:46         0 d-------- C:\Program Files\Trend Micro
2008-02-04 21:07:37     53760 --a------ C:\WINNT\system32\ZD51145.DLL <Not Verified; InstallShield Corp.; InstallShield>
2008-02-04 20:46:49         0 d-------- C:\Conflict Desert Storm
2008-02-03 12:04:05         0 d-------- C:\Program Files\Fortinet
2008-02-03 11:52:48         0 d-------- C:\Program Files\Pocket Tanks
2008-02-03 11:51:04         0 d-------- C:\Program Files\Pocket Tanks Deluxe
2008-02-03 10:34:49         0 d-------- C:\Program Files\Common Files\InstallShield
2008-02-03 10:12:04     16384 --a------ C:\WINNT\system32\Perflib_Perfdata_54c.dat
2008-02-03 09:38:21         0 d-------- C:\WINNT\sysbckup
2008-02-03 09:18:53         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\WinRAR
2008-02-02 23:50:04         0 d-------- C:\Program Files\ImmenseTech
2008-02-02 10:40:01         0 d-------- C:\Program Files\IObit
2008-02-02 09:27:51         0 d-------- C:\WINNT\WinRescue
2008-02-02 09:25:41      4608 --a------ C:\WINNT\system32\W95Inf32.DLL <Not Verified; Microsoft Corporation; Microsoft® Plus! for Windows® 95>
2008-01-29 18:37:30         0 d-------- C:\Program Files\Prime95
2008-01-28 16:37:42     13440 --a------ C:\WINNT\system32\drivers\ntcdrdrv.sys <Not Verified; NoteBurn Software; NoteBurn>
2008-01-28 16:37:38         0 d-------- C:\Program Files\NoteBurner
2008-01-28 16:31:22         0 d-------- C:\Program Files\ZTekWare
2008-01-28 16:20:04         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\ImgBurn
2008-01-28 16:18:07         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\ImgBurn
2008-01-28 16:18:05         0 d-------- C:\Program Files\ImgBurn
2008-01-26 22:56:24         0 d-------- C:\Program Files\NCH Software
2008-01-26 22:49:44         0 d-------- C:\Documents and Settings\All Users.WINNT\Application Data\ashampoo
2008-01-26 22:08:34   1044173 --a------ C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\testmh240.exe <Not Verified; www.testmyhardware.com (http://\"http://www.testmyhardware.com\"); >
2008-01-26 22:08:34    942891 --a------ C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\error-repair.exe <Not Verified; www.error-repair-pro.com (http://\"http://www.error-repair-pro.com\"); >
2008-01-26 22:06:35    274432 --a------ C:\WINNT\system32\NCTAudioPlayer.dll <Not Verified; NCT Company; NCTAudioPlayer ActiveX DLL>
2008-01-26 22:06:32    892928 --a------ C:\WINNT\system32\NCTAudioInformation.dll <Not Verified; NCT Company; NCTAudioInformation ActiveX DLL>
2008-01-26 22:06:30   1703936 --a------ C:\WINNT\system32\NCTAudioFile.dll <Not Verified; NCT Company; NCTAudioFile ActiveX DLL>
2008-01-26 22:06:22    589824 --a------ C:\WINNT\system32\DVDRProX.dll <Not Verified; NuMedia Soft, Inc.; DVDRProX Module>
2008-01-26 22:06:06         0 d-------- C:\Program Files\Ace CD Burner
2008-01-24 19:22:40     16384 --a------ C:\WINNT\system32\Perflib_Perfdata_3d8.dat
2008-01-24 18:31:06         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\SUPERAntiSpyware.com
2008-01-24 16:06:31     16384 --a------ C:\WINNT\system32\Perflib_Perfdata_31c.dat
2008-01-23 20:58:58         0 d-------- C:\Program Files\PerformanceTest
2008-01-20 20:02:13         0 d-------- C:\Program Files\SmartUndelete
2008-01-20 19:16:49         0 d-------- C:\Program Files\FreeUndelete
2008-01-20 10:03:41         0 d-------- C:\Program Files\Lavasoft
2008-01-20 10:03:38         0 d-------- C:\Documents and Settings\All Users.WINNT\Application Data\Lavasoft
2008-01-20 10:02:40         0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-20 09:55:39         0 d-------- C:\Program Files\RogueRemover FREE
2008-01-20 09:41:48      2855 --a------ C:\WINNT\system32\kdgcl.PIF
2008-01-20 09:12:39         0 d-------- C:\Program Files\ACR
2008-01-19 17:24:51     25992 --a------ C:\WINNT\system32\pgdfgsvc.exe <Not Verified; Sysinternals - www.sysinternals.com (http://\"http://www.sysinternals.com\"); Page File Defragmenter>
2008-01-18 23:27:31         0 d-------- C:\Program Files\CCleaner
2008-01-17 17:48:57         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\GlarySoft
2008-01-17 17:44:10         0 d-------- C:\Program Files\Glary Utilities
2008-01-17 17:23:18         0 d-------- C:\Program Files\p
2008-01-16 16:25:30     52736 --a------ C:\WINNT\ipuninst.exe <Not Verified; Interplay Productions; Interplay Uninstaller for Windows 95>
2008-01-15 16:36:35         0 d-------- C:\Program Files\Alcohol Soft
2008-01-15 16:30:54    715248 --a------ C:\WINNT\system32\drivers\sptd.sys
2008-01-13 12:19:14         0 d-------- C:\NovaLogic


-- Find3M Report ---------------------------------------------------------------

2008-02-03 17:27:36      1524 --a------ C:\WINNT\system32\d3d8caps.dat
2008-01-26 22:51:42      1636 --a------ C:\WINNT\system32\d3d9caps.dat
2008-01-08 20:42:56     13234 --a------ C:\Program Files\backfont.zip
2008-01-08 20:42:28     28418 --a------ C:\Program Files\lcdfont.zip
2008-01-07 16:26:30         0 d-------- C:\Program Files\High-Logic
2008-01-07 16:26:30         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\FontCreator
2008-01-03 10:30:00         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\AVG7
2008-01-02 09:59:36         0 --a------ C:\WINNT\nsreg.dat
2008-01-02 09:59:22         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\Mozilla
2007-12-29 13:18:30     16384 --a------ C:\WINNT\system32\Perflib_Perfdata_510.dat
2007-12-28 15:43:42     55596 --a------ C:\WINNT\War3Unin.dat
2007-12-28 15:43:38      2829 --a------ C:\WINNT\War3Unin.pif
2007-12-28 15:43:38    139264 --a------ C:\WINNT\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2007-12-26 10:31:48         0 d-------- C:\Program Files\Software by Design
2007-12-25 12:46:10         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\BitTorrent
2007-12-25 12:45:48         0 d-------- C:\Program Files\DNA
2007-12-25 12:45:48         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\DNA
2007-12-25 12:45:46         0 d-------- C:\Program Files\BitTorrent
2007-12-24 10:31:44         0 d-------- C:\Program Files\MagicISO
2007-12-18 19:59:32         0 d-------- C:\Program Files\BTTF wallpapers
2007-12-16 17:18:32         0 d-------- C:\Program Files\Finding Martin
2007-12-16 17:18:14     57344 --a------ C:\WINNT\TADSUINS.EXE
2007-12-14 16:19:56         0 d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\CCleanup


-- Registry Dump ---------------------------------------------------------------

 

-- Hosts -----------------------------------------------------------------------

127.0.0.1 babe.the-killer.bz
127.0.0.1 www.babe.the-killer.bz (http://\"http://www.babe.the-killer.bz\")
127.0.0.1 babe.k-lined.com
127.0.0.1 www.babe.k-lined.com (http://\"http://www.babe.k-lined.com\")
127.0.0.1 did.i-used.cc
127.0.0.1 www.did.i-used.cc (http://\"http://www.did.i-used.cc\")
127.0.0.1 coolwwwsearch.com
127.0.0.1 www.coolwwwsearch.com (http://\"http://www.coolwwwsearch.com\")
127.0.0.1 coolwebsearch.com
127.0.0.1 www.coolwebsearch.com (http://\"http://www.coolwebsearch.com\")

6362 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-02-11 09:15:07 ------------

--------------------------------------------------------------------------------

Here are the contents of Extra.txt:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows 2000 Professional (build 2195) SP 4.0
Architecture: X86; Language: English

CPU 0: AMD-K6-2 ???
Percentage of Memory in Use: 70%
Physical Memory (total/avail): 183.48 MiB / 54.47 MiB
Pagefile Memory (total/avail): 555.88 MiB / 287.46 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1928.59 MiB

A: is Removable (No Media)
C: is Fixed (FAT32) - 4.76 GiB total, 0.01 GiB free.
D: is Fixed (FAT32) - 5.36 GiB total, 0.03 GiB free.
E: is Fixed (FAT) - 3.94 GiB total, 1.51 GiB free.
F: is CDROM (No Media)
G: is CDROM (No Media)
H: is CDROM (No Media)

\\.\PHYSICALDRIVE1 (http://\"http://file://\.PHYSICALDRIVE1\") - QUANTUM BIGFOOT TS10.0A - 9.32 GiB - 2 partitions
  \PARTITION0 (bootable) - Unknown - 5.37 GiB - D:
  \PARTITION1 - Extended w/Extended Int 13 - 3.94 GiB - E:

\\.\PHYSICALDRIVE0 (http://\"http://file://\.PHYSICALDRIVE0\") - QUANTUM FIREBALLlct10 05 - 4.76 GiB - 1 partition
  \PARTITION0 (bootable) - Unknown - 4.76 GiB - C:

 

-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.


-- Environment Variables -------------------------------------------------------

 

-- User Profiles ---------------------------------------------------------------

zhenzhen (admin)
Administrator.GU-3R3LEUQBGPNO (admin)


-- Add/Remove Programs ---------------------------------------------------------

 

-- Application Event Log -------------------------------------------------------

Event Record #/Type1720 / Error
Event Submitted/Written: 02/11/2008 09:02:42 AM
Event ID/Source: 100 / AVG7
Event Description:
2008-02-11 16:02:42,902 GU-3R3LEUQBGPNO [000620:000644] ERROR 000 AVG7.AM service module run failed: Error 0x80040154

Event Record #/Type1718 / Error
Event Submitted/Written: 02/10/2008 10:22:00 AM
Event ID/Source: 100 / AVG7
Event Description:
2008-02-10 17:22:00,015 GU-3R3LEUQBGPNO [000648:000668] ERROR 000 AVG7.AM service module run failed: Error 0x80040154

Event Record #/Type1716 / Warning
Event Submitted/Written: 02/10/2008 09:50:07 AM
Event ID/Source: 61 / WinMgmt
Event Description:
ÓÉÓÚ open º¯ÊýÖÐÓÐʱ¼ä³åÍ»£¬WMI ADAP ÎÞ·¨´¦Àí PerfDisk ÐÔÄÜ¿â

Event Record #/Type1715 / Error
Event Submitted/Written: 02/10/2008 09:47:23 AM
Event ID/Source: 100 / AVG7
Event Description:
2008-02-10 16:47:23,574 GU-3R3LEUQBGPNO [000612:000640] ERROR 000 AVG7.AM service module run failed: Error 0x80040154

Event Record #/Type1711 / Error
Event Submitted/Written: 02/10/2008 09:22:34 AM
Event ID/Source: 100 / AVG7
Event Description:
2008-02-10 16:22:34,279 GU-3R3LEUQBGPNO [000612:000632] ERROR 000 AVG7.AM service module run failed: Error 0x80040154

 

-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type7517 / Warning
Event Submitted/Written: 02/11/2008 09:08:05 AM
Event ID/Source: 2013 / Srv
Event Description:
D: ??????????????????????

Event Record #/Type7516 / Warning
Event Submitted/Written: 02/11/2008 09:08:05 AM
Event ID/Source: 2013 / Srv
Event Description:
C: ??????????????????????

Event Record #/Type7515 / Error
Event Submitted/Written: 02/11/2008 09:05:00 AM
Event ID/Source: 7031 / Service Control Manager
Event Description:
Ad-Aware 2007 Service ???????,????????? 1 ??????????? 5000 ?????: ???????

Event Record #/Type7514 / Error
Event Submitted/Written: 02/11/2008 09:05:00 AM
Event ID/Source: 7031 / Service Control Manager
Event Description:
AVG7 Update Service ???????,????????? 1 ??????????? 0 ?????: ?????

Event Record #/Type7513 / Error
Event Submitted/Written: 02/11/2008 09:04:58 AM
Event ID/Source: 7026 / Service Control Manager
Event Description:
?????????????????:
ntcdrdrv

 

-- End of Deckard's System Scanner: finished at 2008-02-11 09:15:07 ------------

-------------------------------------------------------------------------------------

Thanks again for your help!
Title: Command Prompt Error!
Post by: guestolo on February 10, 2008, 11:32:12 AM
I assume registry corruption,
Are you able to manually navigate to this key in the registry?

"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls"
Highlight Nls
Export it from the top menu bar (File>>Export registry file), give it a name and save it
Navigate to the exported key, it will have a name such as waterburn.reg
Right click on it and rename to waterburn.txt
Then upload the file

I can compare the export to an english Windows 2000 SP4 machine I have


what happens when you make a new profile
Here's the instructions
http://www.avid.com/onlineSupport/supportc...;contentID=8214 (http://\"http://www.avid.com/onlineSupport/supportcontent.asp?browse=&productID=43&contentID=8214\")

After Step 1. if you do not experience the same problems then it would be profile corruption
Title: Command Prompt Error!
Post by: waterburn on February 10, 2008, 02:57:30 PM
[quote name=\'guestolo\' post=\'421260\' date=\'Feb 10 2008, 10:32 AM\']I assume registry corruption,
Are you able to manually navigate to this key in the registry?

"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls"
Highlight Nls
Export it from the top menu bar (File>>Export registry file), give it a name and save it
Navigate to the exported key, it will have a name such as waterburn.reg
Right click on it and rename to waterburn.txt
Then upload the file

I can compare the export to an english Windows 2000 SP4 machine I have


what happens when you make a new profile
Here's the instructions
http://www.avid.com/onlineSupport/supportc...;contentID=8214 (http://\"http://www.avid.com/onlineSupport/supportcontent.asp?browse=&productID=43&contentID=8214\")

After Step 1. if you do not experience the same problems then it would be profile corruption[/quote]

I am not yet able to follow the instructions on the link, but when I do I will let you know about it. I have attached the file.

Thanks so much! I can't believe we are getting this far!
Title: Command Prompt Error!
Post by: guestolo on February 10, 2008, 03:06:32 PM
Do you have an english version of Windows 2000 installed on your system?
You may have to rebuild that key
It has unknown characters and definitely doesn't look right

Edit: Sorry, I had to save to disk to read it properly
Title: Command Prompt Error!
Post by: waterburn on February 10, 2008, 03:40:31 PM
[quote name=\'guestolo\' post=\'421278\' date=\'Feb 10 2008, 02:06 PM\']Do you have an english version of Windows 2000 installed on your system?
You may have to rebuild that key
It has unknown characters and definitely doesn't look right

Edit: Sorry, I had to save to disk to read it properly[/quote]

Sorry I don't. What should I do now?!!?
Title: Command Prompt Error!
Post by: guestolo on February 10, 2008, 03:45:06 PM
[quote name=\'waterburn\' post=\'421281\' date=\'Feb 10 2008, 01:40 PM\']Sorry I don't. What should I do now?!!?[/quote]

You don't have English 2000?
If you open test.txt, do you recognize any of the numbers you may have changed
What language version 2000 do you have?
Title: Command Prompt Error!
Post by: waterburn on February 10, 2008, 06:17:08 PM
[quote name=\'guestolo\' post=\'421282\' date=\'Feb 10 2008, 02:45 PM\']You don't have English 2000?
If you open test.txt, do you recognize any of the numbers you may have changed
What language version 2000 do you have?[/quote]

I know which keys I changed and what I changed them to. But I don't know what they used to be, that's the problem. As for the language version, I don't know what you mean, so all I can tell you is that it is in Chinese.

"We're getting colder and colder"
Title: Command Prompt Error!
Post by: guestolo on February 10, 2008, 10:01:40 PM
Quote
I know which keys I changed and what I changed them to. But I don't know what they used to be, that's the problem.
"We're getting colder and colder"
No, that's not true, your getting colder
No 2000 CD and you won't tell us what you changed, you just let us know you changed something

Are you running the English version of 2000?
Title: Command Prompt Error!
Post by: waterburn on February 11, 2008, 03:49:55 PM
[quote name=\'guestolo\' post=\'421303\' date=\'Feb 10 2008, 09:01 PM\']No, that's not true, your getting colder
No 2000 CD and you won't tell us what you changed, you just let us know you changed something

Are you running the English version of 2000?[/quote]

No, I am not running the English version of 2000, I am running the Chinese version.
Title: Command Prompt Error!
Post by: waterburn on February 11, 2008, 03:55:02 PM
[quote name=\'waterburn\' post=\'421362\' date=\'Feb 11 2008, 02:49 PM\']No, I am not running the English version of 2000, I am running the Chinese version.[/quote]

I changed HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Nls\CodePage
ACP 1252 for English ( United States )
MACCP 10000 for English ( United States )
OEMCP 437 for English ( United States )
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Nls\Language
Default 0409 for English ( United States )
Title: Command Prompt Error!
Post by: guestolo on February 11, 2008, 10:52:33 PM
Great, thanks for the info, so now we got a bit of work to track down the correct no's for Chinese version
By any chance do you know anyone with Windows 2000 Chinese version or even XP installed that can extract that same key from the registry for the correct info?
That would help alot
Title: Command Prompt Error!
Post by: waterburn on February 15, 2008, 10:26:45 AM
[quote name=\'guestolo\' post=\'421400\' date=\'Feb 11 2008, 09:52 PM\']Great, thanks for the info, so now we got a bit of work to track down the correct no's for Chinese version
By any chance do you know anyone with Windows 2000 Chinese version or even XP installed that can extract that same key from the registry for the correct info?
That would help alot[/quote]

I didn't look on the second page thats why I couldn't find your reply. Now... I don't know anyone with Windows 2000 Chinese version at the moment but that's why I am going to put up posts to find a person that does.

Thanks for the reply!

I am really relying on you for this one!
Title: Command Prompt Error!
Post by: waterburn on February 18, 2008, 01:04:05 PM
[quote name=\'waterburn\' post=\'421700\' date=\'Feb 15 2008, 09:26 AM\']I didn't look on the second page thats why I couldn't find your reply. Now... I don't know anyone with Windows 2000 Chinese version at the moment but that's why I am going to put up posts to find a person that does.

Thanks for the reply!

I am really relying on you for this one![/quote]

*PROBLEM FIXED, HELPED NOT NEEDED ANYMORE GOT WINDOWS 2000 DISK. *~PERMISSION TO DELETE POST~ THANKS TO ALL WHO HELPED!

WATERBURN
Title: Command Prompt Error!
Post by: guestolo on February 18, 2008, 08:50:19 PM
I would rather not delete the post and you tell us Exactly how you resolved your problems
Waterburn, this could help others in the future, it would be greatly appreciated