Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Win 95 registry probs 1

Status
Not open for further replies.

Ngolem

Programmer
Aug 23, 2001
2,724
CA
I am getting a more than usual number of registry problems in the last few weeks while running Internet Explorer.

I can find no problems running Ad-aware, SpyBot and the following is the HiJackthis log


Logfile of HijackThis v1.97.7
Scan saved at 5:31:44 PM, on 7/22/04
Platform: Windows 95 B (Win9x 4.00.1111)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\LOADWC.EXE
C:\PROGRAM FILES\ANALOGX\COOKIEWALL\COOKIE.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\ZIPS_INSTALLS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BrowserWebCheck] loadwc.exe
O4 - HKLM\..\Run: [CookieWall] C:\PROGRAM FILES\ANALOGX\COOKIEWALL\COOKIE.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE"
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\SVCHOST.EXE
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

Please advise if you see anything wrong here....or how I can troubleshoot/fix these registry problems.

this group has helped me a lot...I appreciate it very much


Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
Define registry problems...

Matt J.

Please always take the time to backup any and all data before performing any actions suggested for ANY problem, regardless of how minor a change it might seem. Also test the backup to make sure it is intact.
 
Have hijack FIX ;

O4 - HKLM\..\Run: [CookieWall] C:\PROGRAM FILES\ANALOGX\COOKIEWALL\COOKIE.EXE

follow these removal instructs;

funny also....you have no SCANREGW.EXE /autorun for daily registry backup int he RUN key
Once clean you May need to add the entry manually
Start > Run REGEDIT
go to
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
right click blank area in right pane
select NEW
select String Value
type in ScanRegistry
right click on Scan Registry
choose Modify
type this in--> C:\WINDOWS\scanregw.exe /autorun
OK
Close out and Reboot


TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
First..it's good you don't have a scanregw running UNTIL you're clean
I suspect you've disabled some things using MSCONFIG
While using HijackThis -- this is a no no
(see Kernel32 fix below)

Also that SVCHOST isn't looking good...that's not a 95-98 file ..it's an XP file /service actually
and I dont like Loadwc or Loadqm either Loadqm especially;
see;
to disable it

ALso;
According to what I'm reading you NEED to REPLACE your Kernel32.dll file
Use SFC (not sure if 95B contains SFC)
If not use Extract

Start > Run SFC (System File Checker)
use the "Extract one file from installation disk"
Enter the file name (KERNEL32.DLL say)
Click START
the rest is intuitive
(for "Restore from" - navigate to the .cab files whether on CDROM or on HDD)
(for "Save file in" - navigate to the folder where the file belongs - KERNEL32.DLL belongs in \WINDOWS\SYSTEM)

If not
(grumblegrumble '95 pain in the A$$) - I just don't know th 95 CAB directory structure..I could give you the exact command to type, but I need to know the First cabinet in the chain's anme atleast.in 98 it's BASE4.CAB
See the very Bottom of this page;
"Extract Files by Using Startup Disk".
and this

WINKEY + F -
In "Named" type *.cab -
In "Look in" make sure only C:\ is showing
If the files are on your HDD use command similer to below.....if not present ANYWHERE on the HDD, you need to use the CDROM or the DMF disks.
extract /a /d /y c:\windows\options\cabs\win95_02.cab kernel32.dll /l c:\windows\system

See this FAQ760-3862
for FREE online scanners


TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
First of all to, define my registry problems.

I get 2 types of problems. One is where I get a screen pop-up that informs me that there is a registry problem (it is white and blue as I recall) and asks me if I wish to inform Microsoft of the problem before rebooting my explorer.

The second is a grey pop-up screen which advises me that there is a problem with my registry and tells me to shut down everything before I click the button and it kicks me out of Explorer..

I only have problems while in Window IE and only since I upgraded to IE 5.5, though that isn't really fair since I did this when I rebuilt my machine.

The problems are random....I may go a couple of days with no problem or it may happen twice in a session.

*****
Have hijack FIX ;

O4 - HKLM\..\Run: [CookieWall] C:\PROGRAM FILES\ANALOGX\COOKIEWALL\COOKIE.EXE

follow these removal instructs
******

I don't think Cookiewall is my problem. I have had this program for years with no difficulty at all

Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
hi jim;
firstly I may be wrong about that cookie blocking porgram - (I realize that by using IE5.5 you do NOT have the cookie advanced features settings found in IE6.).

you may be getting Registry errors because you have XP services (or just files) running and/or installed (if Details are available in the error messages - view, copy and paste

Svchost.exe is an NT file system file (maybe you installed an NT version of an app which caused this)
Scvhost.exe would be a virus though.notice the flopping of "c" and "v"

try renaming that file to Scvhost.old and restart (to see if it's even necessary for one of your apps to work)...use the pc.....see what happens

if no more Reg errors..good
95B doesn't have the 5 reg backups like 98's scanregw.exe creates to choose from.
-- you may want to try SCANREG /FIX (if available from a Command Prompt in Real DOS mode
-- uninstall and re-install IE maybe

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
hmmm....this is interesting.

Is Svchost.exe required at all in Win95??

As well I have been reading about

loadwc.exe and loadqm.exe Are these files necessary too?

Can I use Hijackthis to get rid of this stuff.

I have been reading this Link
And I don't like what I am reading there....I have this qmgr.cab file in my Windows/temp folder...

There is a lot of other crap in this folder that I wonder about.

Why would there be a Windows\temp\Temporary Internet Files\Content.IE5 folder there with a snapshot of my real Content.IE5 files???

Also there seems to be a Cookie folder in my Windows\temp directory....with cookies in it...they are MSN cookies from the look of them...I am toasting those guys!!

Here are a couple of other EXE's that I can find no google info on that are in this folder

DelC040.exe
Del2235.exe
Del11D1.exe

Don't like the sound of those.

I also found a .DMP file with this in its text

*********************************************************

[junk missing]

> ƒˆjdß_e~;MÔD¹F4ó@ô¼ŸK‚̧Ð-"×±ð.Í!R¼>±†RM?û¢®Æ=ªM|Ò(Îr±&?ºø¦K¹¤\ChÓF j×ÑiQG%@ “ þpàœÿp  B 8 C : \ W I N D O W S \ S Y S T E M \ U R L M O N . D L L : C : \ W I N D O W S \ S Y S T E M \ V E R S I O N . D L L < C : \ W I N D O W S \ S Y S T E M \ L I N K I N F O . D L L 2 C : \ W I N D O W S \ S Y S T E M \ M P R . D L L < C : \ W I N D O W S \ S Y S T E M \ S H F O L D E R . D L L : C : \ W I N D O W S \ S Y S T E M \ W I N I N E T . D L L 8 C : \ W I N D O W S \ S Y S T E M \ T A P I 3 2 . D L L < C : \ W I N D O W S \ S Y S T E M \ B R O W S E L C . D L L < C : \ W I N D O W S \ S Y S T E M \ B R O W S E U I . D L L 6 C : \ W I N D O W S \ S Y S T E M \ O L E 3 2 . D L L l C : \ P R O G R A M F I L E S \ P A N I C W A R E \ P O P - U P S T O P P E R \ D P H O O K 3 2 . D L L , C : \ W I N D O W S \ P A N I C 3 2 . D L L 6 C : \ W I N D O W S \ S Y S T E M \ W I N M M . D L L : C : \ W I N D O W S \ S Y S T E M \ S H D O C L C . D L L : C : \ W I N D O W S \ S Y S T E M \ S H D O C V W . D L L : C : \ W I N D O W S \ S Y S T E M \ S H E L L 3 2 . D L L < C : \ W I N D O W S \ S Y S T E M \ C O M C T L 3 2 . D L L 8 C : \ W I N D O W S \ S Y S T E M \ M S V C R T . D L L ^ C : \ P R O G R A M F I L E S \ I N T E R N E T E X P L O R E R \ I E X P L O R E . E X E : C : \ W I N D O W S \ S Y S T E M \ S H L W A P I . D L L 8 C : \ W I N D O W S \ S Y S T E M \ U S E R 3 2 . D L L 6 C : \ W I N D O W S \ S Y S T E M \ G D I 3 2 . D L L < C : \ W I N D O W S \ S Y S T E M \ A D V A P I 3 2 . D L L < C : \ W I N D O W S \ S Y S T E M \ K E R N E L 3 2 . D L L   ðÿÿ  ÿÿ ÿÿÿÿÿÿhóxO¨VxWÿÿ ?ÿÿ
! W W IšX Œ–X  V¨\–X ý p–X °½pO “ `–X W

[some garbage missing]

   URLMON.dbg lmon.dll
  dll\shfolder.dbg .dll
   WININET.dbg \sdk\lib\i386\wininet.dll
   BROWSEUI.dbg seui.dll
  !3 ole32.dbg public\sdk\lib\chicago\i386\ole32.dll
   SHDOCVW.dbg ocvw.dll
   COMCTL32.dbg tl32.dll
NB10 'Âò7 e:\8637\vc61\boot\bin\x86\msvcrt.pdb
  exe\iexplore.dbg .exe   SHLWAPI.dbg wapi.dll


*****************************


What is this about??? Evidence of past present problems??

Anyway this is an interesting exercise for me.

Oh Yeah....not always but twice in the last 2 weeks, on booting my computer...a task scheduler pops up....with no tasks in it????

curiouser and curiouser....

Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
Boot to a command prompt in Real DOS and go;
CD WINDOWS
deltree/y temp
ctrl +alt +del
Boot into command prompt again
CD WINDOWS
MD TEMP
ctrl+alt+del
Reboot fully into Windows, and Open an MS DOS Prompt box and type SET
-- copy and paste whatever you have
------------------
C:\WINDOWS>set
TMP=C:\WINDOWS\TEMP
TEMP=C:\WINDOWS\TEMP
PROMPT=$p$g
winbootdir=C:\WINDOWS
PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
COMSPEC=C:\WINDOWS\COMMAND.COM
windir=C:\WINDOWS
SNDSCAPE=C:\WINDOWS

----------------------
Q Can I use Hijackthis to get rid of this stuff.?
A. YES....but other things may be necessary too

Q Is Svchost.exe required at all in Win95??
A. NO - it's Not in 98....and it's in XP...

Q What is this about??? Evidence of past present problems??
A YES

guessing that the malware is using svchost.exe to execute a scheduled task.. also ICQ attracts viruses and so do messengers in general bacause of the open ports vulnerability, (135,137,138,139.445) and the dcom problem.
need a firewall after you fix what's broke

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
as far as my last command set i just posted
this --> CD %windir%
can be used instead of CD WINDOWS
this is "default" - but if you named windows folder something else, then use %windir% wherever you'd type WINDOWS (or the actual DOS name of the directory).

ALSO note; (as to my scanregw posts)
I don't think scanregw.exe exists in 95 (only reg backup is system.dat and user.dat - hidden system files found in the windows directory).

ALSO ALSO
Wouldn't hurt to get all the "Critical Updates" available for security if you need to stay with 95....you are finding it's flaws (when used as a main internet box without all the "fixes" applicable to only newer OSs.)

Actually - If I were you and NEED to stay with 95b or c - I'd ditch IE completely and go with Moz/Firefox (No ActiveX or Java Applets [smile]).
Unfortunately this'll usually mean a complete Clean install of OS - thanks Bi$$ for the integration of IE into the OS [sad]
Once installed fresh...you run one or two IE neutering tools to keep it down

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
just a few questions before I do this

********
Reboot fully into Windows, and Open an MS DOS Prompt box and type SET
-- copy and paste whatever you have
------------------
C:\WINDOWS>set
TMP=C:\WINDOWS\TEMP
TEMP=C:\WINDOWS\TEMP
PROMPT=$p$g
winbootdir=C:\WINDOWS
PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
COMSPEC=C:\WINDOWS\COMMAND.COM
windir=C:\WINDOWS
SNDSCAPE=C:\WINDOWS
**********************

Is this an example of what I should see? and you want posted?....not clear from your instructions

I am going to uninstall ICQ...no one uses it much anymore anyways.

Shud I use Hijack this to "fix" svchost.exe , Loadqm.exe and loadwc.exe after this proceedure of yours is over?


Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
Q Is this an example of what I should see? and you want posted?....
A YES

Q Shud I use Hijack this to "fix" svchost.exe , Loadqm.exe and loadwc.exe after this proceedure of yours is over
A YES -



TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
well I did as you said and the result is pretty close to your posting

C:\WINDOWS>set
TMP=C:\WINDOWS\TEMP
TEMP=C:\WINDOWS\TEMP
PROMPT=$p$g
winbootdir=C:\WINDOWS
PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
COMSPEC=C:\WINDOWS\COMMAND.COM
windir=C:\WINDOWS
Blaster = A220 I5 D1 H5 P330 T6


Only the last line is different and I have sound Blaster as my audio card so I assume that is the reference.

I "fixed" svchost.exe , Loadqm.exe and loadwc.exe using HiJackthis and they no longer appear in the scan.

I will let you know if something weird happens. My home page seemed noticably faster.

Anything else to do??

Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
The Blaster entry is fine as it configures the SoundCard and tells DOS the settings, unless a DOS Game/App shortcut with diff settings overrides/sets these. mine happens to be onboard sound.
Just check your "default" Tempoarary Internet Files Location which can be moved via TweakUI (as well as most System Folders). Usually though if you go Control Panel > Internet Options/Settings > General Tab and click "Settings" in the TIF sections and click "move folder", you'll see the location you've told the system where to Keep the TIF files...(which can be changed here as well).
Set the Disk Space to 8-10MB usually is fine
"View Files" will show you location as well, in the address bar.
"View Objects" stores the Active X crud....only IE4 needs 4 distinct files here...otherwise Nothing is necessary...but form your Hijack Log, you should find the - 016 DPF From Macromedia here.


TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
WELL!!!! I have discouvered the first MAJOR positive result of your advice.

I now have no problems with Graphic images on any site.

In the past 6 months I have had a degradation of my graphic images. In fact I believe I posted this problem of mine several months ago. I was told at the time that my video card was either not set properly on the mother board or the card had inadequate memory.

Well this was not the problem at all. For some reason it was due to those files that I had gotten rid of.

No longer do certain sites (including MSN at times) render my graphics as though they were negative images. Now they are crystal clear.

Amazing....Thanks TT4U....an unexpected benefit!!!



Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
btw;
you probably d/l some nasty to your TEMP folder previously and infected from there. I keep my Temp and TIF clean always.

any more registry errors?
if so..what?

Goodies;
--------------------------------
win98 criticals, pick and choose;
General Information About Windows 98 and Windows 98 Second Edition Hotfixes

everything I could find for WIN95 only

here's for msconfig for 95

tweakui;

Backup Batch file for Win95-98

How to Back Up the Registry in Microsoft Windows 95

hth

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
No longer do certain sites (including MSN at times) render my graphics as though they were negative images. Now they are crystal clear.
[/b]

only too Glad to help
[rockband]

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
No problems with the registry so far...but then they were happening only once in a while anyway so too early to tell yet.

One thing about having Win95 as my operating system, most virus scripts don't run since they are missing dll's :)

Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
understood;
I wont let VB6 on my boxes for nothing....[smile]


TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
OK...nothing is wrong but you have me looking in my Windows directory.

I have several ".ZIP" files in the following directory

C:\Windows\Java\Packages

1nnxftb7.zip
243t7v93.zip
Alvnvdrx.zip
Dzxrrzff.zip
F9vbrj7z.zip
Fftb9f73.zip
I6rzl753.zip

I don't like the crytic nature of these filenames


Here is the archive list in a small one: 243t7v93.zip

************************

AclEntryImpl.class CLASS File 1/12/01 4:30 PM 1,988
AclEnumerator.class CLASS File 1/12/01 4:30 PM 1,057
AclImpl.class CLASS File 1/12/01 4:30 PM 3,777
AlgIdDSA.class CLASS File 1/12/01 4:30 PM 2,622
AlgorithmId.class CLASS File 1/12/01 4:30 PM 6,107
AllPermissionsImpl.c.CLASS File 1/12/01 4:30 PM 333
AVA.class CLASS File 1/12/01 4:30 PM 3,904
BigInt.class CLASS File 1/12/01 4:30 PM 1,752
CertAndKeyGen.class CLASS File 1/12/01 4:30 PM 3,354
CertException.class CLASS File 1/12/01 4:30 PM 1,812
CertParseError.class CLASS File 1/12/01 4:30 PM 280
ContentInfo.class CLASS File 1/12/01 4:30 PM 2,908
CRC32OutputStream.class CLASS File 1/12/01 4:30 PM 608
DerInputBuffer.class CLASS File 1/12/01 4:30 PM 1,658
DerInputStream.class CLASS File 1/12/01 4:30 PM 4,463
DerOutputStream.class CLASS File 1/12/01 4:30 PM 2,578
DerValue.class CLASS File 1/12/01 4:30 PM 5,577
DSA.class CLASS File 1/12/01 4:30 PM 8,872
DSAKeyPairGenerator.... CLASS File 1/12/01 4:30 PM 6,972
DSAPrivateKey.class CLASS File 1/12/01 4:30 PM 2,212
DSAPublicKey.class CLASS File 1/12/01 4:30 PM 2,187
EncodingException.class CLASS File 1/12/01 4:30 PM 294
GroupImpl.class CLASS File 1/12/01 4:30 PM 1,613
IdentityDatabase.class CLASS File 1/12/01 4:30 PM 6,184
JarEntryVerifier.class CLASS File 1/12/01 4:30 PM 2,496
JarException.class CLASS File 1/12/01 4:30 PM 280
JarImageSource.class CLASS File 1/12/01 4:30 PM 728
JarVerifierStream.class CLASS File 1/12/01 4:30 PM 6,904
Main.class CLASS File 1/12/01 4:30 PM 24,645
Main.class CLASS File 1/12/01 4:30 PM 9,077
Manifest.class CLASS File 1/12/01 4:30 PM 4,615
MD5.class CLASS File 1/12/01 4:30 PM 4,464
ObjectIdentifier.class CLASS File 1/12/01 4:30 PM 2,924
OwnerImpl.class CLASS File 1/12/01 4:30 PM 1,113
ParsingException.class CLASS File 1/12/01 4:30 PM 292
PermissionImpl.class CLASS File 1/12/01 4:30 PM 529
PKCS10.class CLASS File 1/12/01 4:30 PM 3,811
PKCS7.class CLASS File 1/12/01 4:30 PM 5,675
PKCS8Key.class CLASS File 1/12/01 4:30 PM 4,958
PrincipalImpl.class CLASS File 1/12/01 4:30 PM 616
RDN.class CLASS File 1/12/01 4:30 PM 1,767
SHA.class CLASS File 1/12/01 4:30 PM 2,646
SignatureFile.class CLASS File 1/12/01 4:30 PM 5,033
SignerInfo.class CLASS File 1/12/01 4:30 PM 4,509
Sun.class CLASS File 1/12/01 4:30 PM 1,559
SystemIdentity.class CLASS File 1/12/01 4:30 PM 1,476
SystemSigner.class CLASS File 1/12/01 4:30 PM 1,491
WorldGroupImpl.class CLASS File 1/12/01 4:30 PM 317
X500Name.class CLASS File 1/12/01 4:30 PM 4,900
X500Signer.class CLASS File 1/12/01 4:30 PM 1,400
X509Cert.class CLASS File 1/12/01 4:30 PM 8,226
X509Key.class CLASS File 1/12/01 4:30 PM 4,535
version.txt ext Document 1/12/01 4:13 PM 58
53 file(s) 184,156

************************

Am I being paranoid... or educated??? :)

Should I get rid of this folder? If so how? How do I prevent these "packages" if they are malicious.

Learning a lot, I am...



Jim Broadbent

The quality of the answer is directly proportional to the quality of the problem statement!
 
Encrypted?
They're meant to be, just like MS CONTENT.IE5 subfolders
They're fine [smile]

for ex.
go here; and click on any one....it's just java code.

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top