?
Solved

16 bit MS-DOS error, now screenshots come out black and white.

Posted on 2005-04-01
12
Medium Priority
?
955 Views
Last Modified: 2008-01-09
I tried to install an old Copy of Hex Workshop on Windows XP Pro machine.  I got an error saying, "This is a 16-bit MS-Dos app....cancel or ignore".  I cancelled out of it and it immediately changed my video color depth to 16-bit.  I changed it back to 32-bit and now when I try to take a screen shot and paste into a graphics program, the image comes out with a black background and white text.  No other color.  What files got corrupt?  What do I need to do to get my machine back to working correctly?


Thanks.
0
Comment
Question by:harboramerican
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 4
12 Comments
 
LVL 88

Expert Comment

by:rindi
ID: 13681089
You may have picked up some malware. Do the following to try to remove it:

Turn off System Restore (Control Panel, System).
 
start msconfig (Start, Run, msconfig), select the startup tab and remove the ticks from any programs you aren't sure of what they might be.
 
Let your PC be restarted
 
Download and install Spy-bot S & D (http://www.safer-networking.org/en/index.html)
Let the installer activate the tea-timer and update Spy-bot.
Click on "make registry backup", wait until done and click on next.
Let the scan finish, then select all the found items and select clean.
If the system wasn't able to clean out everything it found, let it reboot. Spy-bot should startup before you log-on, do another scan.
Again select all found items and clean. When finished select "immunize", then close spy-bot.
 
Download and install Adaware (http://lavasoft.com).
Let the installer do an update, then scan the system.
Select all found items and let them be removed.
A reboot may also be necessary here.
 
If either Spy-bot or adaware or both still weren't able to remove all malware, reboot your system to safe-mode and let the tool which couldn't remove a malware do another scan. If it is adaware, change the scan settings to scan within archives, then start a scan.
Again select all found malware and let them be removed.
 
Use the following link to scan your system for virii on-line (The advantage here is if your AV program has been compromised by a virus, it won't be able to detect at least that virus anymore, so an external scan can help)
http://housecall.trendmicro.com 
 
if you still have malware on your system after that, download the latest version of HijackThis:
 
http://www.hijackthis.de/downloads 
run it and save the log. Paste the log to the following website:
 
http://www.hijackthis.de/en 
 
Click the "analyze" button and you will have an analysis of your log.
Now paste the analyzed log here, so we can help further (provided you don't get enough info from the log and can do it yourself).
 
next make sure your AV Software is up-to-date and running. Let the system do a thorough AV scan.
0
 

Author Comment

by:harboramerican
ID: 13681185

I already have HJT, Spybot, Symantec 8.1 Corporate, and Adaware installed and up-to-date.  This program doesn't have malware on it.  It was designed for Windows 98.  I have used it on 98 machines in the past, but never on Windows XP...and now I know why.  Below is the analyzed log attached.

------------------------------------------------------------------------------------------------------


Logfile of HijackThis v1.99.1  
Safe.   Shows the version of HijackThis an. The newest version is: v1.99.1!   This should be the newest version. (v1.99.1)
  Platform: Windows XP SP1 (WinNT 5.01.2600)          
  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)  
Safe.   Shows the version of your Internet Explorer. Newest Version is: 6.00.2800.1106!   This should be the newest version. (6.00.2800.1106)
  C:\WINDOWS\System32\smss.exe  
Safe.   running process. (smss.exe)
Systemprozess - Anwendung, die benutzt wird um Sitzungen zu starten, verwalten und löschen.  
 
  C:\WINDOWS\system32\winlogon.exe  
Safe.   running process. (winlogon.exe)
Systemprozess - Windows Login Routine  
 
  C:\WINDOWS\system32\services.exe  
Safe.   running process. (services.exe)
Systemprozess - Verwaltet die Systemdienste.  
 
  C:\WINDOWS\system32\lsass.exe  
Safe.   running process. (lsass.exe)
Systemprozess  
 
  C:\WINDOWS\system32\svchost.exe  
Safe.   running process. (svchost.exe)
Systemprozess - Allgemeiner Hostprozessname für Dienste.  
 
  C:\WINDOWS\System32\svchost.exe  
Safe.   running process. (svchost.exe)
Systemprozess - Allgemeiner Hostprozessname für Dienste.  
 
  C:\WINDOWS\system32\spoolsv.exe  
Safe.   running process. (spoolsv.exe)
Systemprozess  
 
  C:\WINDOWS\system32\crypserv.exe  
Safe.   running process. (crypserv.exe)
   
 
  C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe  
Safe.   running process. (cvpnd.exe)
   
 
  C:\Program Files\Symantec\DeepSight Extractor\ExtractorService.exe  
Unknown   running process. (ExtractorService.exe)
   This is a unknown process.
 
  C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe  
Safe.   running process. (DefWatch.exe)
   
Possibly nasty! According to our database this process runs normally in c:\programme\symantec antivirus\! Check if you know this process and arrange a viruscheck where required.
  C:\WINDOWS\System32\inetsrv\inetinfo.exe  
Safe.   running process. (inetinfo.exe)
Used by MS Internet Information Server (IIS).  
 
  C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe  
Safe.   running process. (Rtvscan.exe)
Symantec Corporate Edition  
Possibly nasty! According to our database this process runs normally in c:\programme\symantec antivirus\! Check if you know this process and arrange a viruscheck where required.
  C:\Program Files\Dell\OpenManage\Network Manager\oware3rd\versant\6_0_0\NT\bin\versantd.exe  
Unknown   running process. (versantd.exe)
   This is a unknown process.
 
  C:\Program Files\RealVNC\WinVNC\WinVNC.exe  
Safe.   running process. (WinVNC.exe)
Win VNC  
Possibly nasty! According to our database this process runs normally in c:\programme\tightvnc\! Check if you know this process and arrange a viruscheck where required.
  c:\progra~1\dell\openma~1\networ~1\oware\bin\owprocman.exe  
Unknown   running process. (owprocman.exe)
   This is a unknown process.
 
  C:\WINDOWS\system32\NiWSD.exe  
Unknown   running process. (NiWSD.exe)
   This is a unknown process.
 
  C:\WINDOWS\Explorer.EXE  
Safe.   running process. (Explorer.EXE)
Systemprozess für Desktop und Taskleiste.  
 
  C:\WINDOWS\System32\hkcmd.exe  
Safe.   running process. (hkcmd.exe)
   
 
  C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe  
Safe.   running process. (mm_tray.exe)
   Not dangerous, but unnecessary.
 
  C:\Program Files\Ahead\InCD\InCD.exe  
Safe.   running process. (InCD.exe)
   
 
  C:\Program Files\RightFax\FaxCtrl.exe  
Unknown   running process. (FaxCtrl.exe)
   This is a unknown process.
 
  C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe  
Safe.   running process. (vptray.exe)
   
Possibly nasty! According to our database this process runs normally in c:\programme\navnt\! Check if you know this process and arrange a viruscheck where required.
  C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe  
Safe.   running process. (mmtask.exe)
   
 
  C:\Program Files\Winamp\Winampa.exe  
Safe.   running process. (Winampa.exe)
   
 
  C:\Program Files\Nortel Networks\Symposium Call Center Server\client\en\bin\nicrlstn.exe  
Unknown   running process. (nicrlstn.exe)
   This is a unknown process.
 
  C:\WINDOWS\System32\taskswitch.exe  
Safe.   running process. (taskswitch.exe)
Windows XP Power Tools Taskswitch  
 
  C:\Program Files\QuickTime\qttask.exe  
Safe.   running process. (qttask.exe)
Part of QuickTime  
 
  C:\Program Files\PestPatrol\PPControl.exe  
Safe.   running process. (PPControl.exe)
   
 
  C:\Program Files\Invisible Keylogger\nvsr32.exe  
Unknown   running process. (nvsr32.exe)
   This is a unknown process.
 
  C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE  
Safe.   running process. (WCESCOMM.EXE)
   
 
  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe  
Safe.   running process. (TeaTimer.exe)
   Not dangerous, but unnecessary.
 
  C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe  
Safe.   running process. (acrotray.exe)
   
 
  C:\Program Files\Nortel Networks\Symposium Call Center Server\client\en\bin\nbnmsrvc.exe  
Unknown   running process. (nbnmsrvc.exe)
   This is a unknown process.
 
  C:\Program Files\G6 FTP Server\G6FTPSrv.exe  
Safe.   running process. (G6FTPSrv.exe)
BulletProof FTP Server  
Possibly nasty! According to our database this process runs normally in c:\programme\bpftp server\! Check if you know this process and arrange a viruscheck where required.
  C:\Program Files\Salive\serversalive.exe  
Safe.   running process. (serversalive.exe)
Serverüberwachung  
 
  c:\progra~1\dell\openma~1\networ~1\oware3rd\versant\6_0_0\nt\bin\cleanbe.EXE  
Unknown   running process. (cleanbe.EXE)
   This is a unknown process.
 
  c:\progra~1\dell\openma~1\networ~1\oware3rd\versant\6_0_0\nt\bin\obe.EXE  
Unknown   running process. (obe.EXE)
   This is a unknown process.
 
  c:\progra~1\dell\openma~1\networ~1\oware3rd\versant\6_0_0\nt\bin\cleanbe.EXE  
Unknown   running process. (cleanbe.EXE)
   This is a unknown process.
 
  c:\progra~1\dell\openma~1\networ~1\oware3rd\versant\6_0_0\nt\bin\obe.EXE  
Unknown   running process. (obe.EXE)
   This is a unknown process.
 
  c:\progra~1\dell\openma~1\networ~1\oware3rd\versant\6_0_0\nt\bin\cleanbe.EXE  
Unknown   running process. (cleanbe.EXE)
   This is a unknown process.
 
  c:\progra~1\dell\openma~1\networ~1\oware3rd\versant\6_0_0\nt\bin\obe.EXE  
Unknown   running process. (obe.EXE)
   This is a unknown process.
 
  C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE  
Safe.   running process. (OUTLOOK.EXE)
E-Mail Client für Windows.  
Possibly nasty! According to our database this process runs normally in c:\programme\microsoft office\office11\! Check if you know this process and arrange a viruscheck where required.
  C:\WINDOWS\System32\svchost.exe  
Safe.   running process. (svchost.exe)
Systemprozess - Allgemeiner Hostprozessname für Dienste.  
 
  C:\WINDOWS\System32\dllhost.exe  
Safe.   running process. (dllhost.exe)
   
 
  C:\WINDOWS\System32\msdtc.exe  
Safe.   running process. (msdtc.exe)
   
 
  C:\WINDOWS\System32\inetsrv\DavCData.exe  
Safe.   running process. (DavCData.exe)
   
 
  C:\Program Files\Messenger\msmsgs.exe  
Safe.   running process. (msmsgs.exe)
MSN Messenger  
 
  C:\Program Files\Microsoft Office\Office10\EXCEL.EXE  
Safe.   running process. (EXCEL.EXE)
Microsoft Excel  
 
  C:\Program Files\Microsoft Office\Office10\WINWORD.EXE  
Safe.   running process. (WINWORD.EXE)
Microsoft Word  
 
  C:\Program Files\Internet Explorer\IEXPLORE.EXE  
Safe.   running process. (IEXPLORE.EXE)
Internet Explorer - Wir empfehlen einen sichereren alternativen Browser zu verwenden. (z.B. Firefox)  
 
  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe  
Safe.   running process. (GoogleDesktop.exe)
Google Desktop Search  
 
  C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe  
Safe.   running process. (GoogleDesktopIndex.exe)
Goodle Dekstop Search  
 
  C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe  
Safe.   running process. (GoogleDesktopCrawl.exe)
Goodle Dekstop Search Crawler  
 
  C:\WINDOWS\System32\nwwentr.exe  
Unknown   running process. (nwwentr.exe)
   This is a unknown process.
 
  C:\Program Files\AutoUpdate\AutoUpdate.exe  
Unknown   running process. (AutoUpdate.exe)
Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates    This is a unknown process.
 
  C:\Program Files\AutoCAD 2002\acad.exe  
Unknown   running process. (acad.exe)
   This is a unknown process.
 
  C:\Program Files\AutoCAD 2002\assist.exe  
Unknown   running process. (assist.exe)
   This is a unknown process.
 
  C:\Program Files\Internet Explorer\IEXPLORE.EXE  
Safe.   running process. (IEXPLORE.EXE)
Internet Explorer - Wir empfehlen einen sichereren alternativen Browser zu verwenden. (z.B. Firefox)  
 
  C:\Documents and Settings\armstrong_a\Desktop\hijackthis_199\HijackThis.exe  
Safe.   running process. (HijackThis.exe)
Tool, mit dem sie dieses Logfile erzeugt haben.   Remember that Hijackthis must be run in an own folder. Only if Hijackthis run in an own folder it will create backups!
  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/   
Safe.   This page has been identified as safe.    
  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://adam.harboramerican.com/users/   
Safe.   This page has been identified as safe.    
  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/   
Safe.   This page has been identified as safe.    
  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/   
Safe.   This page has been identified as safe.    
  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://adam.harboramerican.com/users/   
Safe.   This page has been identified as safe.    
  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Harbor Insurance Group  
Safe.   This page has been identified as safe.    
  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0  
Possibly nasty   This page could possibly be nasty.   If you do not know the entry ':0', delete it.
  O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C:\Program Files\Invisible Keylogger\web.dll  
Nasty   Entries found in this registry zone are potentially nasty. This application ([1E1B2879-88FF-11D3-8D96-D7ACAC95951A] - Result: 1E1B2879-88FF-11D3-8D96-D7ACAC95951A) has been checked. Hit rate: 99 %   Must be fixed!
  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll  
Safe.   Entries found in this registry zone are potentially nasty. This application ([53707962-6F74-2D53-2644-206D7942484F] - Result: 53707962-6F74-2D53-2644-206D7942484F) has been checked. Hit rate: 99 %    
  O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll  
Safe.   Entries found in this registry zone are potentially nasty. This application ([7c1ce531-09e9-4fc5-9803-1c2956615786] - Result: 7c1ce531-09e9-4fc5-9803-1c2956615786) has been checked. Hit rate: 99 %    
  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll  
Safe.   Entries found in this registry zone are potentially nasty. This application ([AA58ED58-01DD-4d91-8333-CF10577473F7] - Result: AA58ED58-01DD-4d91-8333-CF10577473F7) has been checked. Hit rate: 99 %    
  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx  
Safe.   Entries found in this registry zone are potentially nasty. This application ([8E718888-423F-11D2-876E-00A0C9082467] - Result: 8E718888-423F-11D2-876E-00A0C9082467) has been checked. If the name is made up of random letters, found in the folder 'Application Data' and the kind is 'Unknown' , it should be fixed. Hit rate: 99 %    
  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll  
Safe.   Entries found in this registry zone are potentially nasty. This application ([2318C2B1-4965-11d4-9B18-009027A5CD4F] - Result: 2318C2B1-4965-11D4-9B18-009027A5CD4F) has been checked. If the name is made up of random letters, found in the folder 'Application Data' and the kind is 'Unknown' , it should be fixed. Hit rate: 96 %    
  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe  
Safe.   Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
Hit rate: 86 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe  
Safe.   Application that implements the Intel Hotkey command.
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe  
Safe.   MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator
Hit rate: 99 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER  
Safe.   System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
Hit rate: 99 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe  
Safe.   Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
Hit rate: 91 % (result)    
  O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe  
Safe.  
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\\FaxCtrl.exe  
Unknown  
Hit rate: 5 % (result)   Unknown application.
  O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe  
Safe.   System Tray icon for Norton Anti-Virus Corporate Edition. Gives access to the options available and may not be required. Some users may have problems - refer here
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper  
Safe.   WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon  
Safe.   Find more information about its use here
Hit rate: 99 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe  
Safe.   Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"  
Safe.   Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don t take over as default player for various media types. Available via Start -> Programs
Hit rate: 76 % (result)    
  O4 - HKLM\..\Run: [ReportListener] "C:\Program Files\Nortel Networks\Symposium Call Center Server\client\en\bin\nicrlstn.exe"  
Unknown  
Hit rate: 15 % (result)   Unknown application.
  O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe  
Safe.   ALT TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"  
Safe.   Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
Hit rate: 82 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"  
Safe.   Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
Hit rate: 99 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN  
Safe.   Part of IBMs iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. Its a waste of resources
Hit rate: 99 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"  
Unknown   Welcome wizard launcher - Part of IBMs iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?
Hit rate: 99 % (result)   Unknown application.
  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime  
Safe.   QuickTime
Hit rate: 99 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe  
Safe.   PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe  
Safe.  
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe  
Safe.  
Hit rate: 99 % (result)    
  O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe  
Safe.  
Hit rate: 99 % (result)   Not dangerous, but unnecessary.
  O4 - HKLM\..\Run: [InternetK] C:\Program Files\Invisible Keylogger\nvsr32.exe  
Unknown  
Hit rate: 14 % (result)   Unknown application.
  O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"  
Nasty   PeopleonPage foistware
Hit rate: 99 % (result)   Must be fixed!
  O4 - HKLM\..\RunOnce: [SCRRUN.DLL] regsvr32.exe /s C:\WINDOWS\System32\SCRRUN.DLL  
Possibly nasty  
Hit rate: 6 % (result)   It seems that the name of this program is the same as the name of the file. In the most cases this is the result of trojans. To be sure, you should check this file.
  O4 - HKLM\..\RunOnce: [MSVBVM60.dll] regsvr32.exe /s C:\WINDOWS\System32\MSVBVM60.dll  
Possibly nasty  
Hit rate: -1 % (result)   It seems that the name of this program is the same as the name of the file. In the most cases this is the result of trojans. To be sure, you should check this file.
  O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"  
Safe.   Active sync for use with Windows CE based palm PC
Hit rate: 99 % (result)    
  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background  
Safe.   Microsoft s MSN Messenger 6
Hit rate: 99 % (result)    
  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe  
Safe.   Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla. TeaTimer.exe monitors certain changes to the registry and notifies when browser plugins and activeX controls get installed, allowing you to block/reverse this.
Hit rate: 99 % (result)    
  O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup  
Safe.   Google Desktop Search
Hit rate: 99 % (result)    
  O4 - Startup: BPFTP Server.lnk = C:\Program Files\G6 FTP Server\G6FTPSrv.exe  
Unknown  
Hit rate: 9 % (result)   Unknown application.
  O4 - Startup: NetPerSec.lnk = C:\Program Files\NetPerSec\NetPerSec.exe  
Safe.   NetPerSec - measures the real-time speed of your Internet connection
Hit rate: 89 % (result)   Not dangerous, but unnecessary.
  O4 - Startup: Servers Alive.lnk = C:\Program Files\Salive\serversalive.exe  
Unknown  
Hit rate: 13 % (result)   Unknown application.
  O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe  
Safe.   Used to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation
Hit rate: 47 % (result)    
  O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe  
Safe.   Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine
Hit rate: 89 % (result)    
  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe  
Safe.   Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine
Hit rate: 94 % (result)    
  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE  
Safe.  
Hit rate: 93 % (result)    
  O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html  
Safe.   The entry &Google Search has been identified as safe.   If the entry '&Google Search ' is not needed anymore, it should be fixed.
  O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html  
Safe.   The entry Backward Links has been identified as safe.   If the entry 'Backward Links ' is not needed anymore, it should be fixed.
  O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html  
Safe.   The entry Cached Snapshot of Page has been identified as safe.   If the entry 'Cached Snapshot of Page ' is not needed anymore, it should be fixed.
  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000  
Safe.   The entry E&xport to Microsoft Excel has been identified as safe.   If the entry 'E&xport to Microsoft Excel ' is not needed anymore, it should be fixed.
  O8 - Extra context menu item: Get Flash by &Arty Flash Ripper - C:\Program Files\Softdigger\FlashRipper\IEMenu.htm  
Possibly nasty   Entries shown in the menu that pops up when right-clicking into the Internet Explorer. Unknown entries should be fixed.   To be fixed if the entry 'Get Flash by &Arty Flash Ripper ' is unknown.
  O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html  
Safe.   The entry Similar Pages has been identified as safe.   If the entry 'Similar Pages ' is not needed anymore, it should be fixed.
  O8 - Extra context menu item: Sothink SWF Decompiler - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm  
Possibly nasty   Entries shown in the menu that pops up when right-clicking into the Internet Explorer. Unknown entries should be fixed.   To be fixed if the entry 'Sothink SWF Decompiler ' is unknown.
  O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html  
Safe.   The entry Translate into English has been identified as safe.   If the entry 'Translate into English ' is not needed anymore, it should be fixed.
  O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll  
Safe.   The entry Create Mobile Favorite has been identified as safe.   If the entry 'Create Mobile Favorite ' is not needed anymore, it should be fixed.
  O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll  
Safe.   The entry has been identified as safe.   If the entry '' is not needed anymore, it should be fixed.
  O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll  
Safe.   The entry Create Mobile Favorite... has been identified as safe.   If the entry 'Create Mobile Favorite... ' is not needed anymore, it should be fixed.
  O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll  
Safe.   The entry Run WinHTTrack has been identified as safe.   If the entry 'Run WinHTTrack ' is not needed anymore, it should be fixed.
  O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll  
Safe.   The entry Launch WinHTTrack has been identified as safe.   If the entry 'Launch WinHTTrack ' is not needed anymore, it should be fixed.
  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll  
Safe.   The entry Real.com has been identified as safe.   If the entry 'Real.com ' is not needed anymore, it should be fixed.
  O9 - Extra button: SWFDecompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm  
Possibly nasty   Unknown buttons or entries in the 'Extras'-menu should be fixed.   To be fixed if the entry 'SWFDecompiler ' is unknown.
  O9 - Extra 'Tools' menuitem: Sothink SWF Decompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm  
Possibly nasty   Unknown buttons or entries in the 'Extras'-menu should be fixed.   To be fixed if the entry 'Sothink SWF Decompiler ' is unknown.
  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE  
Safe.   The entry Messenger has been identified as safe.   If the entry 'Messenger ' is not needed anymore, it should be fixed.
  O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE  
Safe.   The entry Messenger has been identified as safe.   If the entry 'Messenger ' is not needed anymore, it should be fixed.
  O16 - DPF: SEAGULL J Walk Java Client 3_3C10 -  
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} -  
Nasty   This entry is possibly nasty.   Should be fixed.
  O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -  
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} -  
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {55A548B3-AFA8-41E3-8057-FD24931C6388} (FXExec Control) - http://216.87.37.188/app/FXCtrl.cab   
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx  
Safe.   This entry has been identified as safe.    
  O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://rick.harboramerican.com/tsweb/msrdp.cab   
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab   
Safe.   This entry has been identified as safe.    
  O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx  
Safe.   This entry has been identified as safe.    
  O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab   
Safe.   This entry has been identified as safe.    
  O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx  
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {D4BC3B10-F024-4EF7-A62C-A298A11B51B5} - http://www.directxtras.com/speaksforitself/download/mstts_mike.cab   
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {E4DFABBD-F5F6-11D3-8421-0080C6F79C42} (SpeechControl Class) - http://www.directxtras.com/speaksforitself/download/speechplugin.cab   
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} -  
Possibly nasty   Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!   Check if you know this site and fix it if you do not.
  O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx  
Safe.   This entry has been identified as safe.    
  O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = harboramerican.com  
Possibly nasty   If this Domain does not belong to your ISP, or your firms network, these entries should be fixed. 'SearchList' entries should be fixed too.   Do you know the IP or Domain 'harboramerican.com'? If not, fix this entry.
  O17 - HKLM\Software\..\Telephony: DomainName = harboramerican.com  
Possibly nasty   If this Domain does not belong to your ISP, or your firms network, these entries should be fixed. 'SearchList' entries should be fixed too.   Do you know the IP or Domain 'harboramerican.com'? If not, fix this entry.
  O17 - HKLM\System\CCS\Services\Tcpip\..\{DAA712E5-9DC3-4BE9-9CDB-501037CBBF79}: NameServer = 10.1.15.2  
Possibly nasty   If this Domain does not belong to your ISP, or your firms network, these entries should be fixed. 'SearchList' entries should be fixed too.   Do you know the IP or Domain '10.1.15.2'? If not, fix this entry.
  O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = harboramerican.com  
Possibly nasty   If this Domain does not belong to your ISP, or your firms network, these entries should be fixed. 'SearchList' entries should be fixed too.   Do you know the IP or Domain 'harboramerican.com'? If not, fix this entry.
  O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = harboramerican.com  
Possibly nasty   If this Domain does not belong to your ISP, or your firms network, these entries should be fixed. 'SearchList' entries should be fixed too.   Do you know the IP or Domain 'harboramerican.com'? If not, fix this entry.
  O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = harboramerican.com  
Possibly nasty   If this Domain does not belong to your ISP, or your firms network, these entries should be fixed. 'SearchList' entries should be fixed too.   Do you know the IP or Domain 'harboramerican.com'? If not, fix this entry.
  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll  
Unknown      
  O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll  
Unknown      
  O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll  
Unknown      
  O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (awhost32.exe) was identified as a good one.
  O23 - Service: DeepSight Extractor CC Service (ccExtractorService) - Unknown owner - C:\Program Files\Symantec\DeepSight Extractor\ccExtractorService.exe  
Unknown   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   Unknown service. (ccExtractorService.exe)
  O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (crypserv.exe) was identified as a good one.
  O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (cvpnd.exe) was identified as a good one.
  O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (CWBRXD.EXE) was identified as a good one.
  O23 - Service: Deepsight Extractor (DeepsightExtractor) - Unknown owner - C:\Program Files\Symantec\DeepSight Extractor\ExtractorService.exe  
Unknown   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   Unknown service. (ExtractorService.exe)
  O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (DefWatch.exe) was identified as a good one.
  O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (iPodService.exe) was identified as a good one.
  O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (Macromedia Licensing.exe) was identified as a good one.
  O23 - Service: Network Instruments Web Server (NiWebSrv) - Unknown owner - C:\WINDOWS\SYSTEM32\NiWsdSrv.srv  
Unknown   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   Unknown service. (NiWsdSrv.srv)
  O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (Rtvscan.exe) was identified as a good one.
  O23 - Service: Dell OpenManage Network Manager (OWProcMan) - Unknown owner - c:\progra~1\dell\openma~1\networ~1\oware\bin\owprocman.exe  
Unknown   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   Unknown service. (owprocman.exe)
  O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)  
Unnecessarily   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service () was identified as a good one.
Unnecessary (deactivated) entry that can be fixed.
  O23 - Service: Servers Alive (salive) - Woodstone bvba - C:\PROGRA~1\Salive\serversalive.exe  
Safe.   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   This service (serversalive.exe) was identified as a good one.
  O23 - Service: VERSANTD - Unknown owner - C:\Program Files\Dell\OpenManage\Network Manager\oware3rd\versant\6_0_0\NT\bin\versantd.exe  
Unknown   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   Unknown service. (versantd.exe)
  O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -service (file missing)  
Unnecessarily   These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.   Unknown service. (WinVNC.exe" -service (file missing))
Unnecessary (deactivated) entry that can be fixed.


This log has been checked automatically.
Check your log file automatically at www.hijackthis.de.
0
 
LVL 12

Expert Comment

by:rossfingal
ID: 13681654
Hi!

This should fix that 16 bit DOS error.
http://www.visualtour.com/downloads/xp_fix.exe

It probably means autoexec.nt and/or config.nt are missing or corrupt.

Post a LINK to your log from the analysis site back here.
www.hijackthis.de/en
(this is the English language link)

RF
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:harboramerican
ID: 13682007
still didn't work.  

When this originally happened...I went to a MS article and extracted the autoexec.nt, config.nt, and command.com like they said, and it didn't work either.
0
 
LVL 12

Accepted Solution

by:
rossfingal earned 375 total points
ID: 13682188
Try going into "Safe" mode
Look in the dllcache, Prefetch, and Repair folders
for copies of these files (probably, only in the Repair folder).
Rename the copies you find - autoexec.nt to autoexec.old - for instance
Then try the fix.

Good luck!
(Post a LINK to your log back here)
RF
0
 

Author Comment

by:harboramerican
ID: 13706778
That worked.

I went into safe mode, in c:\windows\repair I renamed the autoexec.nt to autoexec.nt.old, ran patch, rebooted and all is good.

Thanks.
0
 

Author Comment

by:harboramerican
ID: 13730427
Still having problems....and in some Windows Apps as well as Internet Explorer I get what might be called "Piano Keys".  Where you click on a drop down, and the list is not displayed until you scroll up and down and sometimes even then it wont show the list.

Please Help!
0
 
LVL 12

Expert Comment

by:rossfingal
ID: 13730589
Have you tried System File Checker to replace damaged/changed files?
sfc /scannow
Have your XP CD handy.

RF
0
 

Author Comment

by:harboramerican
ID: 13730706
I typed this in Start>Run and in DOS and a quick screen flashed up and then nothing else.  Does it run in the background or am I missing something?

0
 

Author Comment

by:harboramerican
ID: 13730723
O.K...here is what I get when I run it from DOS

C:\Documents and Settings\armstrong_a>sfc /scannow
Windows File Protection could not initiate a scan of protected system files.

The specific error code is 0x000004dd [The operation being requested was not per
formed because the user has not logged on to the network.
The specified service does not exist.
0
 
LVL 12

Expert Comment

by:rossfingal
ID: 13733820
Run it from "CMD" - from the "Run" box type cmd.exe
You have to be logged on with Administrative Privileges to run this.

RF
0
 

Author Comment

by:harboramerican
ID: 13735207
I did it from cdm.exe and I have Domain Administrator rights and admin rights on the local machine.
0

Featured Post

New benefit for Premium Members - Upgrade now!

Ready to get started with anonymous questions today? It's easy! Learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Step by step guide to Clean and Sort your windows registry! Introduction: Always remember: A Clean registry = Better performance = Save your invaluable time In this article we're going to clear our registry manually! Yes, manually! The e…
If you have done a reformat of your hard drive and proceeded to do a successful Windows XP installation, you may notice that a choice between two operating systems when you start up the machine. Here is how to get rid of this: Click Start Clic…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question