Question

Windows XP Professional with keyboard and mouse that stop responding after short period of use

Asked by: humbill

Please check Hijack this log. I may have fixed this PC but maybe not. Performed repair from installation disk and then repeated SFC /scannow until ran to completion.

Use AVG Security but PC compromised.  Appreciate recommendations regarding other protection.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:03:36 AM, on 9/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
D:\bin\httpd.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
D:\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe
C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSMonitor.exe
D:\bin\ApacheMonitor.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\vsnapvss.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe /EnsureFileVersions
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GoToMyPC] "C:\Program Files\Citrix\GoToMyPC\g2svc.exe" -logon
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKLM\..\Run: [AVGIDS] "C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~2\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe" -stealth
O4 - Global Startup: CardMinder Viewer.lnk = ?
O4 - Global Startup: Conversion to PDF with ScanSnap Organizer.lnk = ?
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: Monitor Apache Servers.lnk = D:\bin\ApacheMonitor.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O4 - Global Startup: ScanSnap Manager.lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: Apache2 - Apache Software Foundation - D:\bin\httpd.exe
O23 - Service: Apache2.2 - Apache Software Foundation - D:\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: AVGIDSAgent - AVG - C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe
O23 - Service: AVGIDSWatcher - AVG - C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToMyPC - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToMyPC\g2svc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: ShadowProtect Service (ShadowProtectSvc) - StorageCraft Technology Corporation - C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
O23 - Service: StorageCraft Shadow Copy Provider (VSNAPVSS) - StorageCraft Technology Corporation - C:\WINDOWS\system32\vsnapvss.exe

--
End of file - 15489 bytes

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-13 at 10:28:05ID24728021
Tags

windows xp

,

frozen keyboard

,

frozen mouse

,

stops responding

Topics

Windows XP Operating System

,

HijackThis Software

,

Internet Security

Participating Experts
4
Points
500
Comments
89

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. HijackThis log
    Can someone tell me if anything from this hijackthis log needs to be removed? Even with firewall and anti-virus running I still got hit with adware and a virus. I already removed kernels32.exe from a previous hijackthis log and ran ad-aware in safe mode. But I'm still having ...
  2. export from ipod to itunes
    Hi I have a 4th generation ipod. My PC corrupted so I lost the itunes folder - is there any way of exporting the songs on my ipod back into itunes? Many thanks
  3. iTunes not recognizing my iPod
    I'm using iTunes on Windows XP, and my iPod is the 5th gen 80 gig. when I plug my Ipod in and iTunes comes up I get a message saying "iTunes has detected an iPod in recovery mode. You must restore this iPod before it can be used with iTunes. Now my iPod is fine, and so ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: sarangk_14Posted on 2009-09-13 at 10:46:05ID: 25321139

Hi,

Let me understand this correctly.

You are saying that the Keyboard and the mouse used to stop responding after some time/ use, right?

If the KB and Mouse stop responding, are you sure that it's not the system that's hanging?

is Apache service a critical component?
Is httpd a critical component?
If the above two are not critical, I'll suggest you stop them if not uninstall.

Hope this helps.

Warm regards,
Sarang

 

by: humbillPosted on 2009-09-13 at 10:54:39ID: 25321158

Sarangk 14:

Forgive me, bad memory.  I also updated the NVIDIA display driver.

The repair replaced hundreds of files. SFC stopped part way through but completed on the second go.

Apache is still not operational. I like to have a localhost running for website work and hope to get it back up soon.

Other than Apache, you see nothing else that could generate further trouble, right?

 

by: sarangk_14Posted on 2009-09-13 at 11:11:22ID: 25321203

Well, httpd can possibly a malware.
But other than that, I don't see anything (other experts might be more helpful in this regard)

I'll anyway sugest the following:

- Monitor the CPU utilization and the memory utilization of processes
- Scan your system using an online malware scanner

Hope this helps.

Warm regards,
Sarang

 

by: humbillPosted on 2009-09-13 at 11:20:06ID: 25321217

AVG and Malware come up clean. I would have assumed it was a driver issue but for all of the files missing or changed.

I had to uninstall reinstall rhapsody. System event view showed: The MCSTRM service failed to start due to the following error: The system cannot find the file specified.

This has reoccurred so I will have to uninstall reinstall again I presume.

Does this indicate anything to you.

Thank you so much for your comments so far.

-- Bill

 

by: optomaPosted on 2009-09-13 at 12:55:52ID: 25321495

Download UBCD. You can run memory + hard drive diagnostics using this
http://www.ultimatebootcd.com/download.html

Also run dxdiag to test the graphics card
http://support.microsoft.com/kb/190900

If all passess try switching the keyboard with a known working keyboard and test to see if pc freezes

 

by: humbillPosted on 2009-09-13 at 13:54:52ID: 25321684

optoma:

UBCD downloading.
dxdiag finds no problems.

Thank you, optoma.

 

by: MbrincatPosted on 2009-09-14 at 03:20:37ID: 25324046

i just want to confirm that this is A desktop PC not a Laptop...?

If its a laptop its because of the windows Power managment system... when the battery gets to a certain level the OS cuts off the power to the keyboard and mouse... theres no way to stop it really unless you buy a new battery or keep it plugged into the mains...

if not then it could still be the Windows Power managment try disabling it...

 

by: humbillPosted on 2009-09-14 at 05:13:33ID: 25324603

Mbrincat:

Thank you.

It is a desktop.

That is a good idea. I will check it out.

After restarting after running UBCD it has happened one more time.

Thinking this is a driver problem and will begin to check drivers one at a time.

-- Bill

 

by: optomaPosted on 2009-09-14 at 05:21:26ID: 25324661

Did you try switching the keyboard?

 

by: humbillPosted on 2009-09-14 at 06:15:07ID: 25325024

Optoma:

Thank you.

I did try installing a different keyboard earlier when the problem was severe. The installation couldn't complete at the time but has since worked. I am back to the original keyboard now.

-- Bill

 

by: humbillPosted on 2009-09-14 at 06:21:17ID: 25325064

MozyHome Remote Backup has had problems running from the outset.  It still is failing. I would really like to get it going. I use ShadowProtect to another internal drive but want the offsite protection.

It tends to hang probalby because of whatever causes the keyboard and mouse to stop working.

Driver?

 

by: humbillPosted on 2009-09-14 at 06:23:03ID: 25325072

Another AVG scan is six hours into a run...

Only cookies found so far.

 

by: MbrincatPosted on 2009-09-14 at 08:27:34ID: 25326440

did you try disabling the Windows Power managment? if you have installed windows again it may be a power managment setting in your bios? what motherboard are you using? i know that some asus motherboards have power managment software which can disable USB etc. if you've got the option to use a PS2 keyboard and mouse give that a try you might find that they continue to work whereas the usb ones won't...

 

by: humbillPosted on 2009-09-14 at 10:44:51ID: 25327636

Mbrincat:

Thank you.

Control Panel power management is off.  BIOS? I will have to shutdown to take a look. Before that I have to let some processes continue to completion.

Attached is the system information:

 

by: humbillPosted on 2009-09-14 at 10:46:42ID: 25327652

Open the System Information with WordPad.

 

by: eXpeLLeD_4RM_heLLPosted on 2009-09-14 at 12:09:30ID: 25328330

has it frozen when you run UBCD4WIN??? That is boot from UBCD4win

 

by: optomaPosted on 2009-09-14 at 12:55:49ID: 25328706

It may be possible some remenants of malware/viruses are still present after hardware tests seem ok.

A few options if you like:
Malwarebytes http://www.malwarebytes.org/mbam-download.php
Superantispyware http://www.superantispyware.com/
Combofix http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Nod32 online scan http://www.eset.com/onlinescan/
Kaspersky live cd http://devbuilds.kaspersky-labs.com/devbuilds/RescueDisk/

 

by: humbillPosted on 2009-09-14 at 13:50:36ID: 25329218

eXpeLLeD_4RM_heLL:

No it hasn't.

 

by: humbillPosted on 2009-09-14 at 13:52:48ID: 25329238

optoma:

Installed NVIDIA Network Drivers. Still waiting to see if there is a freeze up.

Unable to network with other of my computers before or after, still trying to figure this out.

Good comment.  Will try some that I haven't tried before.

Thank you.

 

by: humbillPosted on 2009-09-14 at 14:54:20ID: 25329703

Started SuperAntiSpyware scan and walked away.
On return, keyboard and mouse did not respond, there was no report on the screen so it didn't finish I assume and the disk drive light was off.
Powered off and on.
This is the second time in a row that F8 would not interrupt windows startup so I could go into safe mode.
Observing task manager after startup when response stopped I saw that it too had stopped although the disk drive remained solidly lit. Then the PC started working again.
Restarting SuperAnti...

 

by: optomaPosted on 2009-09-14 at 15:04:54ID: 25329778

If it freezes again try Kaspersky live cd.

 

by: humbillPosted on 2009-09-14 at 16:05:49ID: 25330107

optoma:

It froze again.
DriverCure download stopped at 26:09; AntiSpyware stopped at 25:07.
Alt-Tab shows little action box but doesn't work. Keyboard otherwise inoperative. Mouse moved but nothing else. Disk drive inactive.
AVG Firewall was off.
Processes 79; CPU Usage 39%; Commit Charge 971M/5211M
Power UP F8 worked; chose Safe Mode with Networking; Log on as Administrator.
If possible, in this state, I will try Kaspersky live cd. Otherwise, will try under regular log on.

 

by: optomaPosted on 2009-09-14 at 16:16:20ID: 25330166

Only way is to boot to the live cd.
Will scan your system "outside" of itself

 

by: humbillPosted on 2009-09-14 at 21:20:51ID: 25331697

morincat:

Disabled power management in BIOS.

PC repeatedly booted never getting beyond BIOS.

Re-enabled power management.

That was a little frightening.  There was no keyboard response.  I had to connect the keyboard directly to the PC to gain keyboard control.

 

by: humbillPosted on 2009-09-14 at 21:22:28ID: 25331705

optoma:

Downloaded kaspersky and created CD.  It wouldn't work. I proabably need to use the right thing to create an ISO disk.  Still working on this problem.

 

by: humbillPosted on 2009-09-14 at 21:26:54ID: 25331724

Returned again to a frozen PC.

Keyboard: only responded to ALT-TAB. It just displayed the choices and froze.
Mouse: would only move the cursor.

Installed all out of date drivers using Pareto product.

Noted possible flakyness in Belkin USB hub that the keyboard and mouse were connected to. Plugged keyboard and mouse directly into computer.

Awaiting further freezes.

 

by: optomaPosted on 2009-09-14 at 21:41:59ID: 25331774

Always best to have keyboard and mouse connected directly to machine-not through usb gadgets. May be the cause of issue.

 

by: humbillPosted on 2009-09-14 at 21:53:47ID: 25331826

optoma:

I agree.  I should have had the hub port lights facing toward me so that I could notice that they weren't lit up all of the time.

The KB&M are connected direct for now.

Time will tell. I'll give it a day.

 

by: humbillPosted on 2009-09-15 at 05:13:02ID: 25333957

Just checked the PC and found the KB and Mouse useless and the hard drive light off.

Powered off and back on and here I am again.

There must be a troubleshooting methodology. I feel like a blind man throwing darts, in the dark!

I am going to see if I can get the ISO disk, Kaspersky live cd, to work. I must have to burn it a certain way.

 

by: humbillPosted on 2009-09-15 at 05:59:01ID: 25334349

Got Feinman's ISO recorder.

Dowloading Kaspersky live CD.

 

by: optomaPosted on 2009-09-15 at 08:20:50ID: 25335879

cdburnerxp burns isos also http://cdburnerxp.se/


With troubleshooting a possible hardware problem like this, just have you machine connected with the mininum parts needed:keyboard,mouse,monitor cable,psu lead.
Have keyboard+mouse directly connected to pc(no usb hubs)

See what happens:)

This link may help you in troubleshooting steps http://www.howtofixcomputers.com/forums/how-guides/troubleshooting-computer-freezes-lockups-2694.html

 

by: humbillPosted on 2009-09-15 at 16:59:26ID: 25340722

Thank you, optoma:

Checked out the troubleshooting link and bookmarked it. Good reference. I also provide free repair services to elderly and out-of-work people.

ISO creation successful. After 30 minutes Kaspersky live CD still read 1% complete scanning only the first drive so I will run it tonight.

All drivers are up to date now.

Most recent software installations were GoToMyPC and MozyHome Online Backup. I may remove one of them after the next freeze.

Networking still doesn't work. Hmmm.

KB & M are connected directly.

Just home, awaiting  next freeze if it is going to happen.

Next, need to check disks and memory I presume.

Meanwhile, catching up on photography and website work.

-- Bill

 

by: humbillPosted on 2009-09-15 at 18:25:47ID: 25341071

Just had another freeze.

Checked temperatures and voltages in BIOS. OK

 

by: humbillPosted on 2009-09-15 at 18:39:06ID: 25341120

System Events:

SSPORT, MCSTRM, DigVecp failed to start. Could not find file specified.
Files are disappearing once again.

Redbook: The drive has not been shown to support digital audio playback.
ff 00 04 00 01 00 5c 00
00 00 00 00 09 00 ff 4f
Which drive?

 

by: optomaPosted on 2009-09-16 at 00:38:52ID: 25342886

Did kaspersky finish sucessfully?
What state/enviroment was the machine in when it froze?In windows?

 

by: humbillPosted on 2009-09-16 at 09:27:31ID: 25347398

optoma:

Didn't run Kaspersky last night fater all.

Has frozen three more times. If I can get some predictability to the freezes I can start leaving some things not running with msconfig.. It doesn't seem to matter what is running on the desktop. I walk away for an hour or two and return to a frozen machine most of the time. Other times it happens right after start-up.

Ran SFC to restore missing files.

Event log uneventful so far today despite freezes.

Updated system information in my profile on EE.

I have actually been able to get some work done.

 

by: optomaPosted on 2009-09-16 at 11:57:27ID: 25348848

Sorry just getting a bit off track!

Question:
1-From previous post ID:25321495. Did you run the hard drive and memory diagnostics and did they pass?

2-Did kaspersky finish successfully? Aborted? Frooze?

 

by: humbillPosted on 2009-09-16 at 19:44:03ID: 25352456

Optoma:

Putting in new floors today. Network down during that time.

Ran chkdsk again this morning. Volume clean.

Looked for my memory test software, haven't run yet.

Kaspersky tonight.

Multiple freezes today. Made getting anything done pretty difficult. Also, PC runs very very slowly at times. Very frustrating.

The problems below have reoccurred today after having been repaired yesterday:

System Events:

SSPORT, MCSTRM, DigVecp failed to start. Could not find file specified.
Files are disappearing once again.

Redbook: The drive has not been shown to support digital audio playback.
ff 00 04 00 01 00 5c 00
00 00 00 00 09 00 ff 4f
Which drive?

Driver Update Program reports that the Audio Drive is again out of date or bad. That lines up with the Redbook event information. Tried to update the driver again and the process hung.

Starting to see a pattern here?

 

by: MbrincatPosted on 2009-09-17 at 00:59:27ID: 25353674

have you tired a different hard drive or RAM as you need to rule out that the idea that the hard drive could have bad physical sectors which once data gets written to that area of the drive the PC freezes also you might have some dodgy RAM in the machine...

if your getting errros when trying to run a Live CD like kaspersky that points towards a hardware issue.

what is your hardware setup? i.e make / models of hardrive, RAM, motherboard, processor.

do you have any temperature monitors...?

To work out if its freezing rather than if your input devices are not responding try playing an audio file constantly then check the machine and if its still playing but your KB/M are not working you'll know its the input devices.

 

by: humbillPosted on 2009-09-17 at 04:04:46ID: 25354665

Mbrincat:

Disk checked out with CHKDSK
Memory test ran several hours without error.
Kaspersky running, no errors, at 30%.

I put the hardware setup into my profile here but I can't seem to figure out how you could see it. I am working from a different computer right now so I can't pull that information up until later today.

I have checked the temperatures immediately after a freeze by looking at BIOS and they were OK as were voltages.

Playing an audio file should cause disk activity. When it freezes, there is no disk drive activity based on looking at the light that flashes when there is activity.

I hope this addresses the issues you have brought up.

I will see what I can do to make the system information more available.

-- Bill

 

by: humbillPosted on 2009-09-17 at 08:54:09ID: 25357573

Kaspersky has been working all night on boot sectors and drive 1.  It is at 38% now.

It has only picked up four viruses and four trojans all in e-mail archives from 2006.

Memory test had no exceptions.

Just wondering if I could work around this problem by making drive 2 of 3 primary and install the operating system on it.

It would probably be better to figure this out.

 

by: humbillPosted on 2009-09-17 at 08:55:45ID: 25357596

Kaspersky has been running for nine hours without a freeze up.

 

by: humbillPosted on 2009-09-17 at 11:02:49ID: 25359074

Kaspersky: 47%.

 

by: optomaPosted on 2009-09-17 at 11:28:25ID: 25359335

On the upside it hasnt frooze and is detecting viruses, although it is taking a long time to scan!
You mention "drive 2 of 3".

3 hard drives in pc?
All with data on them?

 

by: humbillPosted on 2009-09-17 at 11:32:31ID: 25359385

Drive 2 was the original primary drive before being hit by something awhile back.
Drive 3 is a back-up drive. I use ShadowProtect.

 

by: optomaPosted on 2009-09-17 at 11:41:20ID: 25359481

Kaspersky is having a lot of data to scan so!

 

by: humbillPosted on 2009-09-17 at 12:41:49ID: 25360129

Kaspersky is at 51% with 9 objects detected.  All are in very old Outlook mail archives.

 

by: humbillPosted on 2009-09-17 at 12:43:37ID: 25360148

There is a lot of data on this PC. I am a published Photographer, record concerts and produce CD's, and create and maintain a number of websites.

 

by: humbillPosted on 2009-09-17 at 14:40:41ID: 25361362

Kaspersky: 15 hours, 55%.

 

by: optomaPosted on 2009-09-17 at 14:59:07ID: 25361483

Well, over the half way mark! :)

 

by: humbillPosted on 2009-09-17 at 15:42:11ID: 25361777

Kaspersky: 16 hours, 57%. No new events.

 

by: optomaPosted on 2009-09-17 at 15:58:06ID: 25361872

So far that machine hasn't lock up or frooze in over 16 hours. So far its a good indication that its not hardware related!

 

by: humbillPosted on 2009-09-17 at 16:41:38ID: 25362137

Right you are.

17 hours; 60%; no new objects found.

 

by: humbillPosted on 2009-09-17 at 17:48:29ID: 25362344

18:05 62% No more objects found.

 

by: humbillPosted on 2009-09-17 at 21:09:29ID: 25362884

21:23 73% No more objects found.
7.83 more hours
Est'd finish time: 5 AM

 

by: humbillPosted on 2009-09-17 at 22:54:21ID: 25363178

23:11 78%

 

by: humbillPosted on 2009-09-18 at 03:19:17ID: 25364373

27:36 90%

 

by: humbillPosted on 2009-09-18 at 04:28:58ID: 25364741

28:45 92% About four more hours. Still no threats of concern found.

 

by: humbillPosted on 2009-09-18 at 08:22:37ID: 25366906

Kaspersky completed with no threats found other than those in e-mails in Outlook Archives from before 2005.

 

by: humbillPosted on 2009-09-18 at 10:34:39ID: 25368106

So what is next to try?

 

by: optomaPosted on 2009-09-18 at 10:56:05ID: 25368304

Could you run combofix. Read through the overview firstly and follow its instructions. Whens its completed attach its logfile here.
 http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: humbillPosted on 2009-09-18 at 12:25:02ID: 25369131

Will do.

 

by: humbillPosted on 2009-09-18 at 14:57:59ID: 25370334

Have had to do some website work. No freeze ups.
Updated audio drivers.
Installed SP3.
Think I have AVG out of the picture.
Think I have SuperSpyware offline.
Waiting on SP3 installation.

 

by: humbillPosted on 2009-09-18 at 16:40:32ID: 25370781

SP3 reported it could not complete and reversed itself finally saying the PC might not work correctly.

 

by: optomaPosted on 2009-09-18 at 17:16:44ID: 25370909

Ok.
Try running combofix.
I take it that the machine isn't freezing up anymore?

 

by: humbillPosted on 2009-09-18 at 19:46:23ID: 25371323

It hasn't so far.

 

by: humbillPosted on 2009-09-19 at 07:01:22ID: 25373079

Still hasn't frozen up.

Just wondering if the partial SP3 installation helped.

Just started ComboFix.

 

by: humbillPosted on 2009-09-19 at 07:37:51ID: 25373178

Unable to run ComboFix.

First try:

Screen goes blank; flashes. Windows Task Manager shows a number of n.pif processes left behind and others.

Second try:

Used msconfig to change start-up loading to none.

Got disclaimer screen, nothing further.

Maybe should wait to see if freezes continue to happen.

And, try to complete an SP3 installation.

 

by: optomaPosted on 2009-09-19 at 08:31:15ID: 25373351

Try downloading combofix on another pc and transfer it to the machine in question through a memory stick or cd.
When downloading combofix change its name as you are saving it, from combofix.exe to something like cm-fx.exe.
See if it progressess further then

 

by: humbillPosted on 2009-09-19 at 08:33:19ID: 25373361

OK

 

by: humbillPosted on 2009-09-19 at 09:44:43ID: 25373621

I will be away for the weekend.

Will have to wait until return.

 

by: optomaPosted on 2009-09-22 at 12:52:22ID: 25396822

Did combofix run?

 

by: humbillPosted on 2009-09-22 at 16:57:58ID: 25398829

Hi optoma:

Thank you for checking back in with me.

Upon returning I installed SP3. The PC continued to run, albeit slowly, without freeze-ups.

There is still a problem with non-working sound.

To address the speed issue I opened msconfig and turned off all start-up items.  I am adding back a few at a time after first seeking information about each on on the Internet and , on some, making sure the file on the PC is the right size and in the right place.

The sound doesnt' work and needs a driver. I am not sure which one. It is identified as Realtek High Definition Audio but this is probalby NVIDIA High Definition Audio. I did have a driver service running but it isn't now and I have to figure that out or reinstall it.

-- humbill

 

by: optomaPosted on 2009-09-22 at 22:37:25ID: 25400267

Your welcome.
Download SIW http://www.gtopala.com/siw-download.html
Run it and there is loads a sections  within it but go to motherboard section and it should tell you the exact name and model of the board.
Once you know this go to the motherboards website and you should get the correct audio drivers there.

In hijackthis remove:
O24 - Desktop Component 0: (no name) - (no file)

 

by: humbillPosted on 2009-09-23 at 16:29:05ID: 25408981

Hi optoma:

O24 does not delete.

Working.

 

by: optomaPosted on 2009-09-23 at 16:48:22ID: 25409074

 

by: humbillPosted on 2009-09-23 at 17:08:22ID: 25409187

Registry entry:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"=""
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00000000
"Position"=hex:2c,00,00,00,00,00,00,00,01,00,00,00,bc,01,00,00,6c,01,00,00,e8,\
  03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:00000001
"OriginalStateInfo"=hex:18,00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,\
  ff,ff,01,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
  00,00,01,00,00,00

Safe to delete it?

 

by: humbillPosted on 2009-09-23 at 17:08:40ID: 25409190

Registry entry:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"=""
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00000000
"Position"=hex:2c,00,00,00,00,00,00,00,01,00,00,00,bc,01,00,00,6c,01,00,00,e8,\
  03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:00000001
"OriginalStateInfo"=hex:18,00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,\
  ff,ff,01,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
  00,00,01,00,00,00

Safe to delete it?

 

by: humbillPosted on 2009-09-23 at 17:11:00ID: 25409205

Still want to run combofix?

 

by: optomaPosted on 2009-09-23 at 17:14:14ID: 25409232

Run combofix if you already havn't ran it. Follow its tutorial firstly
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: humbillPosted on 2009-09-23 at 23:36:16ID: 25410538

Not sure how to turn off AVG 8.5 Anitvirus, everything else is done so I am starting the combofix.

 

by: humbillPosted on 2009-09-24 at 00:27:57ID: 25410748

It ran.

AVG found malware after. I quaranteened it.

Looking for the report.

 

by: humbillPosted on 2009-09-24 at 00:29:43ID: 25410756

Log file was to display automatically.

AVG must have interrupted.

Need help killing it.

 

by: optomaPosted on 2009-09-24 at 00:38:47ID: 25410798

http://www.bleepingcomputer.com/forums/topic114351.html
It says how to stop AVG from running.
Combofix's log is usually located at :
C\Combofix.txt

 

by: humbillPosted on 2009-09-24 at 01:27:06ID: 25411054

It says:
AVG 8.5
Please open the AVG 8.5 Control Center, by right clicking on the AVG icon on task bar.

    * Click on Open AVG Interface.
    * Double click on Resident Shield
    * Deselect the option to "Enable Resident Shield."
    * Save changes, and exit the application.
    * To re-enable AVG 8.5, please select "Enable Resident Shield" again.

This is what I did but AVG Antivirus continued to run. Maybe msconfig is the way to kill it.

 

by: optomaPosted on 2009-09-24 at 01:30:38ID: 25411076

in msconfig uncheck any avg entries in startup ,and services sections

 

by: humbillPosted on 2009-09-24 at 02:20:46ID: 25411306

Run completed. Lot attached.

 

by: optomaPosted on 2009-09-24 at 03:15:23ID: 25411577

Ok,
Combofix found and deleted items.
Unfortunately, I dont have indept knowledge to check its log fully so hopefully someone else will review it shortly.
 Regards,
Optoma.

 

by: humbillPosted on 2009-09-24 at 15:51:09ID: 25418735

I have posted a separate question regarding the Combofix Log.

See:  http://www.experts-exchange.com/Virus_and_Spyware/Anti-Virus/Desktop_Anti-Virus/Q_24760248.html#a25418707

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...