If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. |
|
|
Thread Tools | Display Modes |
#16
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
From: "Tex Hemke"
| I found the same thing that if I change the selected download site all the | downloads work fine in Spybot. I agree with you David..... | I just can't figure why you lockup or stall in Normal Mode. I'm no expert but I didn't see anything in your HJT Log. I assume based upon your reply you read the article on “How to perform a clean boot in Windows XP” and you still experienced the same. Dump the contents of the IE Temporary Internet Folder cache (TIF) start -- settings -- control panel -- internet options -- delete files Open a Command Prompt. In the Command Prompt type the following... CHKDSK C: /F If it replies.. "Chkdsk cannot run because the volume is in use by another process. Would you like to schedule this volume to be checked the next time the system restarts? (Y/N)" Choose - Y type; EXIT Reboot the PC. A full Check Disk will want to be performed, allow it. When it reboots, perform a defragmentation of the hard disk. You can get to the Defragmenting program easily by executing; dfrg.msc Start -- run - type; dfrg.msc -- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm |
Ads |
#17
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Thanks Mike Pawlak for the reply. I have posted the HiJackThis Log File and
found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "MAP" wrote: Post your log here while your waiting for Spywareinfo (It may take a complete day for them to get back to you). http://www.hijackthis.de/index.php?langselect=english -- Mike Pawlak |
#18
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Thanks Warren for the reply. I have posted the HiJackThis Log File and
found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .wma: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...nknown&unknown O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestation.com/common/c...b?ver=1,1,0,32 O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.co...veX/winrep.cab O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129397091163 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.shockwave.com/content/tumblebugs/axhost.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} - https://rtc3.webresponse.one.microso.../TLIEFlash.CAB O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - https://webresponse.one.microsoft.co...X/FileXfer.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab30149.cab O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole...rcadeRdxIE.cab O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) - O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.dll O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/tech...ActiveData.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents...r/imloader.cab O16 - DPF: {F0230524-9D39-4E84-8452-41C592961EA7} - http://www.4wav.com/Config.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe "Duane534" wrote: Perhaps the spyware is still running, even in Safe Mode. Check out the program "Hijack This!" "Tex Hemke" wrote: Running Windows XP Home Edition, 1693 MHz Processor, 47% Free Space on Hard Drive. Have done Disk Cleanup and full Defragmentation. Please assist as I am unable to complete a Spybot - Search & Destroy because when Running bot-check it gets to approximately (varies slightly) 23282/31725: Gain.Gator as then just freezes the computer. I have to hold the power button until it shuts down and the restart the computer by powering up. I have run the Ad-Aware SE Personal with the latest definitions, run MS AntiSpyware and the free Scan (both virus and spyware from http://housecall.trendmicro.com/. I can run a complete Spybot - Search & Destroy in "Safe Mode", but always freezes when running it under both User Logons in "Normal" mode. Each User has "Administrator" rights. Also WildTangent continues to show up. Other programs like Sims can also cause the computer to freeze. Please help. Any suggestions would be greatly appreciated. Thanks in advance. |
#19
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Thanks David H. Lipman for the reply. I have already done the steps you
suggested. Very good suggestions though. Thanks again.... "David H. Lipman" wrote: From: "Tex Hemke" | I found the same thing that if I change the selected download site all the | downloads work fine in Spybot. I agree with you David..... | I just can't figure why you lockup or stall in Normal Mode. I'm no expert but I didn't see anything in your HJT Log. I assume based upon your reply you read the article on “How to perform a clean boot in Windows XP” and you still experienced the same. Dump the contents of the IE Temporary Internet Folder cache (TIF) start -- settings -- control panel -- internet options -- delete files Open a Command Prompt. In the Command Prompt type the following... CHKDSK C: /F If it replies.. "Chkdsk cannot run because the volume is in use by another process. Would you like to schedule this volume to be checked the next time the system restarts? (Y/N)" Choose - Y type; EXIT Reboot the PC. A full Check Disk will want to be performed, allow it. When it reboots, perform a defragmentation of the hard disk. You can get to the Defragmenting program easily by executing; dfrg.msc Start -- run - type; dfrg.msc -- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm |
#20
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
From: "Tex Hemke"
| Thanks David H. Lipman for the reply. I have already done the steps you | suggested. Very good suggestions though. Thanks again.... | One last idea. Maybe it's choking on the User Registry since we precluded the file system. Create a NEW user account. Lets say; TEST Give TEST admin. rights so it can scan everything. Login as TEST and then run a complete scan in Normal Mode. How does that scan do ? -- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm |
#21
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Tex
I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .wma: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...nknown&unknown O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestation.com/common/c...b?ver=1,1,0,32 O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.co...veX/winrep.cab O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129397091163 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.shockwave.com/content/tumblebugs/axhost.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} - https://rtc3.webresponse.one.microso.../TLIEFlash.CAB O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - https://webresponse.one.microsoft.co...X/FileXfer.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab30149.cab O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole...rcadeRdxIE.cab O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) - O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.dll O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/tech...ActiveData.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents...r/imloader.cab O16 - DPF: {F0230524-9D39-4E84-8452-41C592961EA7} - http://www.4wav.com/Config.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe "Duane534" wrote: Perhaps the spyware is still running, even in Safe Mode. Check out the program "Hijack This!" "Tex Hemke" wrote: Running Windows XP Home Edition, 1693 MHz Processor, 47% Free Space on Hard Drive. Have done Disk Cleanup and full Defragmentation. Please assist as I am unable to complete a Spybot - Search & Destroy because when Running bot-check it gets to approximately (varies slightly) 23282/31725: Gain.Gator as then just freezes the computer. I have to hold the power button until it shuts down and the restart the computer by powering up. I have run the Ad-Aware SE Personal with the latest definitions, run MS AntiSpyware and the free Scan (both virus and spyware from http://housecall.trendmicro.com/. I can run a complete Spybot - Search & Destroy in "Safe Mode", but always freezes when running it under both User Logons in "Normal" mode. Each User has "Administrator" rights. Also WildTangent continues to show up. Other programs like Sims can also cause the computer to freeze. Please help. Any suggestions would be greatly appreciated. Thanks in advance. |
#22
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Hi David; Good advice, but still freezes when running Spybotin the newly
created account. This is not the answer. Any other thoughts? "David H. Lipman" wrote: From: "Tex Hemke" | Thanks David H. Lipman for the reply. I have already done the steps you | suggested. Very good suggestions though. Thanks again.... | One last idea. Maybe it's choking on the User Registry since we precluded the file system. Create a NEW user account. Lets say; TEST Give TEST admin. rights so it can scan everything. Login as TEST and then run a complete scan in Normal Mode. How does that scan do ? -- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm |
#23
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate
Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .wma: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...nknown&unknown O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestation.com/common/c...b?ver=1,1,0,32 O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.co...veX/winrep.cab O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129397091163 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.shockwave.com/content/tumblebugs/axhost.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} - https://rtc3.webresponse.one.microso.../TLIEFlash.CAB O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - https://webresponse.one.microsoft.co...X/FileXfer.cab |
#24
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Tex
Start. Administrative Tools, Services and check IPSEC Services -Is the Start Up type Automatic and the Status Started? RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the Status Started? Has the Windows XP SP2 update been installed? -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .wma: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdspl ay.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...nknown&unknown O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab30149.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestation.com/common/c...b?ver=1,1,0,32 O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.co...veX/winrep.cab O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129397091163 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.shockwave.com/content/tumblebugs/axhost.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} - https://rtc3.webresponse.one.microso.../TLIEFlash.CAB O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - https://webresponse.one.microsoft.co...X/FileXfer.cab |
#25
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Hi Gerry; The IPSEC Services is not running. The Startup Type is set to
"Automatic". I tried to start the service and got this error meesge: Could not start the IPSEC Service on Local Computer. Error 126: The specified module could not be found. Is there a fix for this? "Gerry Cornell" wrote: Tex Start. Administrative Tools, Services and check IPSEC Services -Is the Start Up type Automatic and the Status Started? RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the Status Started? Has the Windows XP SP2 update been installed? -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program |
#26
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Yes the Windows XP Home Edition Service Pack has been installed and all
Microsoft Updates..... "Gerry Cornell" wrote: Tex Start. Administrative Tools, Services and check IPSEC Services -Is the Start Up type Automatic and the Status Started? RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the Status Started? Has the Windows XP SP2 update been installed? -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program |
#27
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Yes the RPC (Remote Procedure Call ) is set as Start Up type Automatic and is
started. "Gerry Cornell" wrote: Tex Start. Administrative Tools, Services and check IPSEC Services -Is the Start Up type Automatic and the Status Started? RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the Status Started? Has the Windows XP SP2 update been installed? -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program |
#28
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Tex
Try the instructions in this link: http://snipurl.com/kcay -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; The IPSEC Services is not running. The Startup Type is set to "Automatic". I tried to start the service and got this error meesge: Could not start the IPSEC Service on Local Computer. Error 126: The specified module could not be found. Is there a fix for this? "Gerry Cornell" wrote: Tex Start. Administrative Tools, Services and check IPSEC Services -Is the Start Up type Automatic and the Status Started? RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the Status Started? Has the Windows XP SP2 update been installed? -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program |
#29
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Hi Gerry; I don't follow you. I have a valid IP Address so I don't know how
this would help with IPSEC Services not "Started". I can surf the web and receive e-mails so the IP is working even though IPSEC Services is not working. Confused.... "Gerry Cornell" wrote: Tex Try the instructions in this link: http://snipurl.com/kcay -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; The IPSEC Services is not running. The Startup Type is set to "Automatic". I tried to start the service and got this error meesge: Could not start the IPSEC Service on Local Computer. Error 126: The specified module could not be found. Is there a fix for this? "Gerry Cornell" wrote: Tex Start. Administrative Tools, Services and check IPSEC Services -Is the Start Up type Automatic and the Status Started? RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the Status Started? Has the Windows XP SP2 update been installed? -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll |
#30
|
|||
|
|||
Spybot Search & Destroy freezes computer about 3/4 through
Tex
I will take a second opinion and come back. -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I don't follow you. I have a valid IP Address so I don't know how this would help with IPSEC Services not "Started". I can surf the web and receive e-mails so the IP is working even though IPSEC Services is not working. Confused.... "Gerry Cornell" wrote: Tex Try the instructions in this link: http://snipurl.com/kcay -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; The IPSEC Services is not running. The Startup Type is set to "Automatic". I tried to start the service and got this error meesge: Could not start the IPSEC Service on Local Computer. Error 126: The specified module could not be found. Is there a fix for this? "Gerry Cornell" wrote: Tex Start. Administrative Tools, Services and check IPSEC Services -Is the Start Up type Automatic and the Status Started? RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the Status Started? Has the Windows XP SP2 update been installed? -- Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate Treats found". So the PC is clean, I assume. It only freezes when you run Spybot in "Normal Mode". "The Sims" is from a CD and is the Family Building Game from EA Games. The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and installed the latest Drivers Version 81.95 Released: Nov. 22, 2005. Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge 222M/1108M The RAM is 768 MB Event Viewer: There are no errors when the Spybot was running or when it frooze the PC. The only one is under System after I did a reboot (Hard Boot) and this is what it says: Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: 11/29/2005 Time: 10:33:03 AM User: N/A Computer: EISLER Description: The IPSEC Services service terminated with the following error: The specified module could not be found. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. "Gerry Cornell" wrote: Tex I would forget about running Spybot in normal mode. You will get problems if it tries to remove a file whilst it is in use. Run Spybot in Safe Mode. However, I think it is time to look at other potential causes of the Sims problem. What Sims programme is causing the problems? Is it a Games or other programme? What video card do you have? This freeware programme is excellent for getting information about your computer: Everest Home Edition (freeware) http://www.lavalys.hu/index.php Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to bring Task Manager and select the Performance Tab. What is the Total, the Commit Charge and the Peak? What RAM memory do you have? Another approach. Look in Event Viewer at the System and Application logs for Error and Warning reports about the time the freeze occurs and post copies here. You can access Event Viewer by selecting Start, Administrative Tools, Event Viewer. When researching the meaning of the error, information regarding Event ID, Source and Description are important. HOW TO: View and Manage Event Logs in Event Viewer in Windows XP http://support.microsoft.com/default...&Product=winxp A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. In the window, which appears is a button resembling two pages. Double click the button and close Event Viewer. Now start your message(email) and do a paste into the body of the message. This will paste the info from the Event Viewer Error Report complete with links into the message. Make sure this is the first paste after exiting from Event Viewer. Hope this helps. Gerry ~~~~~~~~~~~~~~~~~~~~~~~~ FCA Using invalid email address Stourport, Worcs, England Enquire, plan and execute. ~~~~~~~~~~~~~~~~~~~~~~~~ Please tell the newsgroup how any suggested solution worked for you. http://dts-l.org/goodpost.htm ~~~~~~~~~~~~~~~~~~~~~~~~ "Tex Hemke" wrote in message ... Thanks Warren for the reply. I have posted the HiJackThis Log File and found only one that they recommended fixing. Still didn't solve the freezing prolem. Nice site though. I will definetly use this site in the future. Thanks.... "Warren" wrote: Tex - go to: http://www.hijackthis.de/ and paste your HiJackThis log into the window and run the analyzer. This will get you started until the forum folks get to your log. hth, Warren Tex Hemke wrote: Hi Duane534; Thanks for the reply. I have run the HiJackThis and here is a log of it: Logfile of HijackThis v1.99.1 Scan saved at 11:11:17 AM, on 11/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Logitech\iTouch\iTouch.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 5.exe C:\WINDOWS\System32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/home_page.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;dynhost.inetcam.com;register.inetcam.co m;;localhost;local N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.alberta.com/"); (C:\Program Files\Netscape\Users\beisler1\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll |
Thread Tools | |
Display Modes | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Please Help with FREEZING Computer | Paul Black | Windows XP Help and Support | 35 | November 21st 05 12:48 AM |
Log access or prevent access to private/confidential information. | Robin Tucker | Windows XP Help and Support | 20 | September 1st 05 11:50 AM |
DOESN'T WORK | Robb Reis | General XP issues or comments | 22 | August 4th 05 10:49 PM |
SPybot - Search and Destroy | MIke | General XP issues or comments | 6 | February 6th 05 07:23 AM |
Computer Freezes randomly since installing XP SP2 | Fred | Windows Service Pack 2 | 3 | October 20th 04 03:46 AM |