Old 1st February 2005, 02:49   #1
firestorm64
Junior Member
 
Join Date: Feb 2005
Posts: 5
instant error when installing send report to microsoft

when i try to install winamp it works fine until i get to the section where i want to change the install path, then i get promted to send an error report, with this as the heading so to speak.
AppName: winamp508c_full_silvertide_emusic-7plus.exe AppVer: 0.0.0.0 ModName: unknown
ModVer: 0.0.0.0 Offset: 0013f325

then... if i dont change the install path it installs into my program files, but when i open it.. i get this heading:
AppName: winamp.exe AppVer: 5.0.0.8 ModName: unknown
ModVer: 0.0.0.0 Offset: 0013a8b2

my winamp version 5.07 were working fine, until a few days ago, when ever id tab out of a game it would come up, no big deal.. id just restart and keep listening to music, but now i cant listen to music and i want to.. lol

sys specs if u need to know..
xp sp1 pro
1 gig of ram
athlon XP 2 ghz
i dunno what else u want to know, minimal process 19 .. its just run of the mill stuff, stuff thats suppose to be running. i dunno its starting to piss me off. plz help, thanks.
firestorm64 is offline   Reply With Quote
Old 1st February 2005, 08:18   #2
The009
Junior Member
 
Join Date: Jan 2005
Posts: 9
Send a message via AIM to The009
this error is caused by windows and how much it sucks. but yeah it happens. i have heard a lot of my friends with this problem and the way that they have over come it was by unistalling the old winamp and downlong a fresh copy of the full free version of winamp. if you have purchased the pro version then download the free version full 7 megs and then install that and re insert the program key that you got whith the purchase of pro. that should work
The009 is offline   Reply With Quote
Old 1st February 2005, 17:29   #3
firestorm64
Junior Member
 
Join Date: Feb 2005
Posts: 5
well, it WAS working fine, but then it just starting fucking up, i dunno im using windows media player, i just want to listen to music lol, winamp is great, but i dunno what went wrong, ill just leave it, WMP will work until i reformat then ill try it all over again lol, thanks thow.
firestorm64 is offline   Reply With Quote
Old 1st February 2005, 17:38   #4
DrO
 
Join Date: Sep 2003
Posts: 27,873
have you tried re-downloading the installer (latest version 5.08d is here and see how that goes since it could just be a slightly corrupt installer (or Windows being ghey )

-daz
DrO is offline   Reply With Quote
Old 1st February 2005, 18:05   #5
JonnyMac
Moderator
 
JonnyMac's Avatar
 
Join Date: Dec 2000
Posts: 14,385
If you have a download manager/accelerator, disable it prior to downloading Winamp. Also, make sure any previous version of Winamp is not running at the time of install.

Using WinXP,are you on a limited/multi user account? Installing to a limited/multi user account is not suggested.

Please do not PM me for tech support. Any request for tech support through PM will be ignored.
Read the Stickies
---> | | | | <--- Knowledge is power
JonnyMac is offline   Reply With Quote
Old 2nd February 2005, 00:55   #6
firestorm64
Junior Member
 
Join Date: Feb 2005
Posts: 5
first post, i have the newest installer just downloaded, i did a clean uninstall of the program, im the administrator on my comp, so no conflict there, uhh, no download managers for me, anything else u want to know?
firestorm64 is offline   Reply With Quote
Old 2nd February 2005, 01:32   #7
JonnyMac
Moderator
 
JonnyMac's Avatar
 
Join Date: Dec 2000
Posts: 14,385
Please post a HijackThis log.
Download HjT from the link. After downloading unzip it and HjT should be ready to run. Run HjT and press the 'Scan' button. After scanning the button will change to a 'Save log' button. Save the report as a text file by giving it a txt extension instead of log. Example: HijackThis.txt. Please do not use the 'fix' button. Then attach the HjT log with your next reply.
It may be a little while before I or someone else has a chance to evaluate the HjT log and make the proper recommendations.
JonnyMac is offline   Reply With Quote
Old 2nd February 2005, 02:31   #8
firestorm64
Junior Member
 
Join Date: Feb 2005
Posts: 5
Logfile of HijackThis v1.99.0
Scan saved at 6:31:33 PM, on 2/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Appz\CloneDVD\AnyDVD\AnyDVD.exe
C:\WINDOWS\System32\tibs3.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Appz\Steam\Steam.exe
C:\Appz\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\System32\telcmd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\hicom.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Appz\Browsers\Avant Browser\avant.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\appz\WinRAR\WinRAR.exe
C:\DOCUME~1\Alex\LOCALS~1\Temp\Rar$EX00.922\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://soft-trend.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_p...unt_id=1002626
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_p...unt_id=1002626
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://soft-trend.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://soft-trend.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_p...unt_id=1002626
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://soft-trend.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://soft-trend.net
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL (file missing)
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\PROGRA~1\YOURSI~1\ysb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AnyDVD] C:\Appz\CloneDVD\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] C:\Appz\Steam\Steam.exe -silent
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Appz\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Add to AD Black List - C:\Appz\Browsers\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Block All Images from the Same Server - C:\Appz\Browsers\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Highlight - C:\Appz\Browsers\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Appz\Browsers\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Appz\Browsers\Avant Browser\Search.htm
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1103182581609
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8725B543-C656-43E2-8CD7-CFC0EAA091FB}: NameServer = 192.168.0.1,4.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{F588C465-F229-4F8B-B469-ACD6D9DA5589}: NameServer = 192.168.0.1,4.2.2.2
O23 - Service: Manageer Network Connections - Unknown - C:\WINDOWS\System32\telcmd.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Working Network Connections - Unknown - C:\WINDOWS\System32\hicom.exe
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe

here you are
firestorm64 is offline   Reply With Quote
Old 2nd February 2005, 04:03   #9
DJ Egg
Techorator
Winamp & Shoutcast Team
 
Join Date: Jun 2000
Posts: 36,137
You've got some nasty malware there (spyware, browser hijackers, dialers, trojans).

tibs3.exe / nem220.dll = Premium rate adult content diallers
http://www.liutilities.com/products/...library/tibs3/
http://computercops******clsid-1072.html
http://www3.ca.com/securityadvisor/p...x?id=453076438

SideFind sfbho.dll / istsvc.exe = ISTBar browser hijacker & trojan downloader
http://computercops******clsid-1105.html
http://www.sophos.com/virusinfo/anal...ojistbarm.html
http://www.pestpatrol.com/pestinfo/t..._istbar_eo.asp

WebRebates0.exe = TopRebates foistware
http://www3.ca.com/securityadvisor/p...x?id=453081191
http://www.greatis.com/appdata/d/w/webrebates0.exe.htm

bargains.exe / msbe.dll = Bullseye / Exact Advertising spyware (BargainBuddy)
http://www.liutilities.com/products/...rary/bargains/
http://sarc.com/avcenter/venc/data/a...gainbuddy.html
http://computercops******clsid-1338.html

Winstat.exe / AdStatServ.exe = Password stealer trojan
http://www.greatis.com/appdata/d/w/winstat.exe.htm
http://computercops******startuplist-6984.html

______________________________________________________________


Download and install the following spyware removal tools:

CWShredder (free standalone version)
SpybotSD
AdawareSE


Print out these instructions!

Close all browser/email/explorer windows - note, this is important!


Use "Task Manager > Processes" to End Process for the following:
C:\WINDOWS\System32\tibs3.exe
C:\Program Files\BullsEye Network\bin\bargains.exe


Run CWShredder first - click the "Fix" button


Run SpybotSD next
Make sure you get the latest detection updates before running the scan
Checkmark ALL results it finds and click "Fix selected problems"


Now run Adaware scan
Again, make sure you've got the latest detections first.
Click "Start"
Uncheck "search for negligible risk items" and checkmark "Perform full system scan".
Click "Next" to begin the scan
Checkmark all results it finds.
Click "Next" for checked items to be fixed/removed.

______________________________________________________________


IMPORTANT:

Unzip HijackThis.zip and save HijackThis.exe to its own folder, eg.
C:\Program Files\HijackThis


Run HJT scan again.
If ANY of the following entries still exist after running the above tools, checkmark them ONLY and click "Fix Checked":


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=1002626

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=1002626

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=1002626

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll

O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL (file missing)

O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL

O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll

O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\PROGRA~1\YOURSI~1\ysb.dll (file missing)

O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe

O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe

O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe

O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe

O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll

O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe

______________________________________________________________


I'm also not sure about the 2 other O23 - Service entries (telcmd.exe and hicom.exe).
Do you know what they are?
Both of them are also listed in your current running processes.
Hmm, I'm thinking that they could be some new malware variant, because there's hardly any results for either of them at google.

If you don't know what they are...
also End Process for hicom.exe and telcmd.exe, and also fix those 2 entries in HJT:

O23 - Service: Manageer Network Connections - Unknown - C:\WINDOWS\System32\telcmd.exe

O23 - Service: Working Network Connections - Unknown - C:\WINDOWS\System32\hicom.exe

______________________________________________________________


Locate and delete the following folders/files:

Make sure you can view hidden/system folders and that file extensions for known filetypes are not hidden (c/o Control Panel > Folder Options > View tab)

C:\WINDOWS\System32\tibs3.exe
C:\Program Files\BullsEye Network (delete folder)
C:\WINDOWS\nem220.dll
C:\Program Files\SideFind (delete folder)
C:\WINDOWS\System32\msbe.dll
C:\Program Files\Windows AdStatus (delete folder)
C:\Program Files\AdStatus Service (delete folder)
C:\Program Files\ISTsvc (delete folder)
C:\Program Files\Web_Rebates (delete folder)
C:\WINDOWS\zeta.exe

hicom.exe & telcmd.exe = pending...


Reboot

______________________________________________________________


Good luck.
DJ Egg is offline   Reply With Quote
Old 2nd February 2005, 16:10   #10
firestorm64
Junior Member
 
Join Date: Feb 2005
Posts: 5
wow, thanks alot, it my comp works alot better now, i still cant install winamp, but everything works alot better lol, i hated having to task manager close everything.

i can try other things if you want, but thanks so much for helping me get all that other shit off my comp.

see what bothers me, is that is was working and then it just stoped, nothing changed i just tabbed out of my game a few times and now nothing.

well, thanks again for the help if u think of anything ill keep checking the fourms , if not thats ok.

thanks, peace.
firestorm64 is offline   Reply With Quote
Reply
Go Back   Winamp & Shoutcast Forums > Winamp > Winamp Technical Support

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump