Teresa_B
asked on
services and controller app has encountered a problem and needs to close...
services and controller app has encountered a problem and needs to close... I seen that error message pop up once today.
PC shutting down everytime I try to install IE7. It installs for about 5 minutes. After a couple of minutes into running Microsoft Malicious Software Removal Tool (which is a part of instal of IE7), PC shuts down. And yes I have tried installing IE7 without doing updates and running above mentioned tool. PC shuts down quicker then.
Windows firewall not working either but I have replaced it with Comodo Personal firewall.
Spyware Dr and Quick Heal antivirus have both picked up threats which have been removed and I've used Regseeker and CCleaner and problem still occurs.
After PC starts up some times a error message saying about device driver - need to upgrade graphics card drivers or turn off acceleration and turn off write enable. I've done that and problem still occurs.
When I first got PC yesterday and through last night - the shutting down was happening about 5 minuts into Windows starting up - in particular when Spyware Dr was starting. Now it just seems to happen when I attempt to install IE7.
Temperatures are ok. I've checked that. I've scanned HDD and that's ok.
How do you do a repair when Win XP disk didn't come with PC?
PC shutting down everytime I try to install IE7. It installs for about 5 minutes. After a couple of minutes into running Microsoft Malicious Software Removal Tool (which is a part of instal of IE7), PC shuts down. And yes I have tried installing IE7 without doing updates and running above mentioned tool. PC shuts down quicker then.
Windows firewall not working either but I have replaced it with Comodo Personal firewall.
Spyware Dr and Quick Heal antivirus have both picked up threats which have been removed and I've used Regseeker and CCleaner and problem still occurs.
After PC starts up some times a error message saying about device driver - need to upgrade graphics card drivers or turn off acceleration and turn off write enable. I've done that and problem still occurs.
When I first got PC yesterday and through last night - the shutting down was happening about 5 minuts into Windows starting up - in particular when Spyware Dr was starting. Now it just seems to happen when I attempt to install IE7.
Temperatures are ok. I've checked that. I've scanned HDD and that's ok.
How do you do a repair when Win XP disk didn't come with PC?
ASKER
Results of Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 9:59:37 PM, on 21/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\csrss. exe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\LEXBCE S.EXE
C:\WINDOWS\system32\spools v.exe
C:\Apps\ActivBoard\nhksrv. exe
C:\Program Files\Comodo\Firewall\cmda gent.exe
C:\WINDOWS\system32\CTSvcC DA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\QUICKH~1\ONLNS VC.EXE
C:\WINDOWS\system32\nvsvc3 2.exe
C:\PROGRA~1\QUICKH~1\scanw scs.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\slserv .exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\wdfmgr .exe
C:\WINDOWS\system32\MsPMSP Sv.exe
C:\WINDOWS\system32\wuaucl t.exe
C:\PROGRA~1\QUICKH~1\UPSCH D.EXE
C:\PROGRA~1\QUICKH~1\SCANM SG.EXE
C:\Program Files\Java\jre1.5.0_09\bin \jusched.e xe
C:\PROGRA~1\QUICKH~1\Onlin eNT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LXSUPM ON.EXE
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Documents and Settings\Jamie\My Documents\My Music\iTunesHelper.exe
C:\PROGRA~1\MOUSEW~1\SYSTE M\EM_EXEC. EXE
C:\PROGRA~1\QUICKH~1\emlpr oxy.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\iPod\bin\iPodService .exe
C:\Apps\ActivBoard\MMKeybd .exe
C:\Apps\ActivBoard\TrayMon .exe
C:\Program Files\Comodo\Firewall\CPF. exe
C:\Apps\ActivBoard\OSD.exe
C:\WINDOWS\system32\RUNDLL 32.EXE
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintS creen.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Owner\LOCALS~1 \Temp\Rar$ EX01.188\H ijackThis. exe
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d ll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D 426709BBFE B} - C:\PROGRA~1\SPYWAR~1\tools \iesdsg.dl l
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D 4DAF1D92D4 3} - C:\Program Files\Java\jre1.5.0_09\bin \ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5 164760863C 6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1 7DF180C71A C} - C:\PROGRA~1\SPYWAR~1\tools \iesdpb.dl l
O4 - HKLM\..\Run: [On-Line Protection] C:\PROGRA~1\QUICKH~1\CATEY E.EXE
O4 - HKLM\..\Run: [Update Scheduler] C:\PROGRA~1\QUICKH~1\UPSCH D.EXE /CHECK
O4 - HKLM\..\Run: [Messenger] C:\PROGRA~1\QUICKH~1\SCANM SG.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin \jusched.e xe"
O4 - HKLM\..\Run: [Startup Scan] C:\PROGRA~1\QUICKH~1\Senso r.EXE /LOADRUN
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPM ON.EXE RUN
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Documents and Settings\Jamie\My Documents\My Music\iTunesHelper.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTE M\EM_EXEC. EXE
O4 - HKLM\..\Run: [Email Protection] C:\PROGRA~1\QUICKH~1\emlpr oxy.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd .exe
O4 - HKLM\..\Run: [Comodo Firewall] "C:\Program Files\Comodo\Firewall\CPF. exe" /background
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump rep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl. dll,NvStar tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr ay.dll,NvT askbarInit
O4 - HKLM\..\RunOnce: [Startup Scan] C:\PROGRA~1\QUICKH~1\Senso r.EXE /check
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon .exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.5] C:\Program Files\Gadwin Systems\PrintScreen\PrintS creen.exe /nosplash
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2 \Office10\ EXCEL.EXE/ 3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.5.0_09\bin \ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.5.0_09\bin \ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4 C56B4E14E8 4} - C:\PROGRA~1\SPYWAR~1\tools \iesdpb.dl l
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox. dll
O16 - DPF: {00B71CFB-6864-4346-A978-C 0A14556272 C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-9 7215F77A6B C} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C 7C580BBF70 0} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-4 94B6333150 B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2 D05CB95953 7} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-D C1FA91D2FC 3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161705569906
O16 - DPF: {8E0D4DE5-3180-4024-A327-4 DFAD1796A8 D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-5 95F0A5519F F} (MsnMessengerSetupDownload Control Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-2 2031317559 2} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-5 65BD30C9AE 9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-3 7301EF7BF9 8} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-B A914D7BE94 1} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8 E305202313 F} - C:\PROGRA~1\MSNMES~1\MSGRA P~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8 E305202313 F} - C:\PROGRA~1\MSNMES~1\MSGRA P~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog on.dll
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmda gent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcC DA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver \11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCE S.EXE
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv. exe
O23 - Service: NT Online Protection - Unknown owner - C:\PROGRA~1\QUICKH~1\ONLNS VC.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3 2.exe
O23 - Service: Quick Heal Helper Service WSC (ScanWscS) - Unknown owner - C:\PROGRA~1\QUICKH~1\scanw scs.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv .exe
Logfile of HijackThis v1.99.1
Scan saved at 9:59:37 PM, on 21/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\LEXBCE
C:\WINDOWS\system32\spools
C:\Apps\ActivBoard\nhksrv.
C:\Program Files\Comodo\Firewall\cmda
C:\WINDOWS\system32\CTSvcC
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\QUICKH~1\ONLNS
C:\WINDOWS\system32\nvsvc3
C:\PROGRA~1\QUICKH~1\scanw
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\slserv
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\wdfmgr
C:\WINDOWS\system32\MsPMSP
C:\WINDOWS\system32\wuaucl
C:\PROGRA~1\QUICKH~1\UPSCH
C:\PROGRA~1\QUICKH~1\SCANM
C:\Program Files\Java\jre1.5.0_09\bin
C:\PROGRA~1\QUICKH~1\Onlin
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LXSUPM
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Documents and Settings\Jamie\My Documents\My Music\iTunesHelper.exe
C:\PROGRA~1\MOUSEW~1\SYSTE
C:\PROGRA~1\QUICKH~1\emlpr
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\iPod\bin\iPodService
C:\Apps\ActivBoard\MMKeybd
C:\Apps\ActivBoard\TrayMon
C:\Program Files\Comodo\Firewall\CPF.
C:\Apps\ActivBoard\OSD.exe
C:\WINDOWS\system32\RUNDLL
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\ctfmon
C:\Program Files\Gadwin Systems\PrintScreen\PrintS
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Owner\LOCALS~1
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1
O4 - HKLM\..\Run: [On-Line Protection] C:\PROGRA~1\QUICKH~1\CATEY
O4 - HKLM\..\Run: [Update Scheduler] C:\PROGRA~1\QUICKH~1\UPSCH
O4 - HKLM\..\Run: [Messenger] C:\PROGRA~1\QUICKH~1\SCANM
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin
O4 - HKLM\..\Run: [Startup Scan] C:\PROGRA~1\QUICKH~1\Senso
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPM
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Documents and Settings\Jamie\My Documents\My Music\iTunesHelper.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTE
O4 - HKLM\..\Run: [Email Protection] C:\PROGRA~1\QUICKH~1\emlpr
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd
O4 - HKLM\..\Run: [Comodo Firewall] "C:\Program Files\Comodo\Firewall\CPF.
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
O4 - HKLM\..\RunOnce: [Startup Scan] C:\PROGRA~1\QUICKH~1\Senso
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.5] C:\Program Files\Gadwin Systems\PrintScreen\PrintS
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: {00B71CFB-6864-4346-A978-C
O16 - DPF: {14B87622-7E19-4EA8-93B3-9
O16 - DPF: {17492023-C23A-453E-A040-C
O16 - DPF: {2917297F-F02B-4B9D-81DF-4
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O16 - DPF: {8E0D4DE5-3180-4024-A327-4
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-5
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-2
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-5
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-3
O16 - DPF: {E8F628B5-259A-4734-97EE-B
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmda
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcC
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCE
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.
O23 - Service: NT Online Protection - Unknown owner - C:\PROGRA~1\QUICKH~1\ONLNS
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
O23 - Service: Quick Heal Helper Service WSC (ScanWscS) - Unknown owner - C:\PROGRA~1\QUICKH~1\scanw
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv
If you had a OEM Version your only options is this:
Get a copy from the place your bought your PC.
Borrow a OEM CD to do the repair.
MS will not help you becasue the whole thing with OEM is that the responibility is at where you bought your machine. IBM and Dell only ships with Images so its more or less impossible to get a cd from them. Other vendors might give you a nicer time.
When hearing about your problem I defently would recommend following these steps:
Boot from a Win XP CD(Have to be same as installed now because otherwise your product key wont work, needs to be replaced).
Choose install
Choose repair
when booting normal again, download all updates including IE7
Cheers,
Stefan
Get a copy from the place your bought your PC.
Borrow a OEM CD to do the repair.
MS will not help you becasue the whole thing with OEM is that the responibility is at where you bought your machine. IBM and Dell only ships with Images so its more or less impossible to get a cd from them. Other vendors might give you a nicer time.
When hearing about your problem I defently would recommend following these steps:
Boot from a Win XP CD(Have to be same as installed now because otherwise your product key wont work, needs to be replaced).
Choose install
Choose repair
when booting normal again, download all updates including IE7
Cheers,
Stefan
My immediate impression of the problem, or certainly something that is likely to be contributing to the problem in a big way, is the fact that you have quite a lot of Statup Programs launching as the system boots, and already running when you try to install IE7.
Take a look at the "04" (ie. Startup Programs) in your HiJack This Log for a start:
-------------------------- ---------- ---------- ---------- ----------
Running from the registry key:
HKEY_LOCAL_MACHINE\Softwar e\Microsof t\Windows\ CurrentVer sion\Run
On-Line Protection - C:\PROGRA~1\QUICKH~1\CATEY E.EXE
Update Scheduler - C:\PROGRA~1\QUICKH~1\UPSCH D.EXE /CHECK
Messenger - C:\PROGRA~1\QUICKH~1\SCANM SG.EXE
SunJavaUpdateSched- "C:\Program Files\Java\jre1.5.0_09\bin \jusched.e xe"
Startup Scan - C:\PROGRA~1\QUICKH~1\Senso r.EXE /LOADRUN
SiSUSBRG - C:\WINDOWS\sisUSBrg.exe
QuickTime Task -"C:\Program Files\QuickTime\qttask.exe " -atboottime
LXSUPMON - C:\WINDOWS\system32\LXSUPM ON.EXE RUN
Lexmark X6100 Series - "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
iTunesHelper - "C:\Documents and Settings\<username>\My Documents\My Music\iTunesHelper.exe"
EM_EXEC - C:\PROGRA~1\MOUSEW~1\SYSTE M\EM_EXEC. EXE
Email Protection - C:\PROGRA~1\QUICKH~1\emlpr oxy.exe
DSLAGENTEXE - dslagent.exe
Cmaudio - RunDll32 cmicnfg.cpl,CMICtrlWnd
ACTIVBOARD - C:\Apps\ActivBoard\MMKeybd .exe
Comodo Firewall- "C:\Program Files\Comodo\Firewall\CPF. exe" /background
KernelFaultCheck - %systemroot%\system32\dump rep 0 -k
NvCplDaemon - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl. dll,NvStar tup
nwiz - nwiz.exe /install
NvMediaCenter - RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr ay.dll,NvT askbarInit
Spyware Doctor - "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
ctfmon.exe - C:\WINDOWS\system32\ctfmon .exe
Gadwin PrintScreen 3.5 - C:\Program Files\Gadwin Systems\PrintScreen\PrintS creen.exe /nosplash
-------------------------- ---------- ---------- ---------- ----------
Running from the Registry Key:
HKEY_LOCAL_MACHINE\Softwar e\Microsof t\Windows\ CurrentVer sion\RunOn ce
This should NOT be listed as a Startup Process UNLESS the system is at the stage where something has just been modified and needs to be finalised at the very next boot, and once only.
Startup Scan - C:\PROGRA~1\QUICKH~1\Senso r.EXE /check
-------------------------- ---------- ---------- ---------- ----------
Running from Shortcuts in the C:\Windows\Start Menu\Programs\Startup folder:
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
Do you really need the MS Office Shortcut bar to open every time your system boots up?
-------------------------- ---------- ---------- ---------- ----------
I suggest that you:
1. Close all running applications and disconnect from the Internet
2. Start Menu > "Run" option > and type MSCONFIG > click OK.
3. Go to the "Startup" tab and UNTICK the following entries:
(I've left out the ones that are probably required.)
On-Line Protection
Update Scheduler
Messenger
SunJavaUpdateSched
Startup Scan (should be two entries)
QuickTime Task
LXSUPMON <---- Printer Monitor (printer may not work until re-enabled)
Lexmark X6100 Series <---- Printer Monitor (as above)
iTunesHelper
Email Protection
DSLAGENTEXE <----------- Broadband Modem Connection MAY require this!!
Comodo Firewall ***
NvMediaCenter
Spyware Doctor ***
Gadwin PrintScreen 3.5
Adobe Reader Speed Launch
Microsoft Office
4. Click on the "APPLY" button
5. Click the OK button, and restart the computer when prompted.
6. Now temporarily disable the following "Services" and restart the computer (shown as 023 entries in your HiJack This log):
Comodo Application Agent (CmdAgent) ***
iPodService
LexBce Server (LexBceS) <---- Printer Monitor (as previous section)
NT Online Protection
Quick Heal Helper Service WSC (ScanWscS)
PC Tools Spyware Doctor (SDhelper) ***
IMPORTANT:
Even though you will see a "Services" tab in MSCONFIG, DO NOT use this to disable Windows Sevices or modify their settings. The proper way to do that is to run SERVICES.MSC from the Start Menu's "Run" field.
If you are unsure how to temporarily disable a service, then just ask before doing so.
7. Now try and install IE7.
There are quite a few startups and Services that could well be interfering with the installation, especially Firewalls and background Anti-Spyware programs.
Here's the Analysis of your HiJack This file if you are interested:
http://www.hijackthis.de/logfiles/d044b14ca7b95fddb609a28c03282ef7.html
There's nothing nasty in there, but a few unnecessary things that can be disabled (NOT "FIXED" by HiJack This).
Bill
Take a look at the "04" (ie. Startup Programs) in your HiJack This Log for a start:
--------------------------
Running from the registry key:
HKEY_LOCAL_MACHINE\Softwar
On-Line Protection - C:\PROGRA~1\QUICKH~1\CATEY
Update Scheduler - C:\PROGRA~1\QUICKH~1\UPSCH
Messenger - C:\PROGRA~1\QUICKH~1\SCANM
SunJavaUpdateSched- "C:\Program Files\Java\jre1.5.0_09\bin
Startup Scan - C:\PROGRA~1\QUICKH~1\Senso
SiSUSBRG - C:\WINDOWS\sisUSBrg.exe
QuickTime Task -"C:\Program Files\QuickTime\qttask.exe
LXSUPMON - C:\WINDOWS\system32\LXSUPM
Lexmark X6100 Series - "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
iTunesHelper - "C:\Documents and Settings\<username>\My Documents\My Music\iTunesHelper.exe"
EM_EXEC - C:\PROGRA~1\MOUSEW~1\SYSTE
Email Protection - C:\PROGRA~1\QUICKH~1\emlpr
DSLAGENTEXE - dslagent.exe
Cmaudio - RunDll32 cmicnfg.cpl,CMICtrlWnd
ACTIVBOARD - C:\Apps\ActivBoard\MMKeybd
Comodo Firewall- "C:\Program Files\Comodo\Firewall\CPF.
KernelFaultCheck - %systemroot%\system32\dump
NvCplDaemon - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
nwiz - nwiz.exe /install
NvMediaCenter - RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
Spyware Doctor - "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
ctfmon.exe - C:\WINDOWS\system32\ctfmon
Gadwin PrintScreen 3.5 - C:\Program Files\Gadwin Systems\PrintScreen\PrintS
--------------------------
Running from the Registry Key:
HKEY_LOCAL_MACHINE\Softwar
This should NOT be listed as a Startup Process UNLESS the system is at the stage where something has just been modified and needs to be finalised at the very next boot, and once only.
Startup Scan - C:\PROGRA~1\QUICKH~1\Senso
--------------------------
Running from Shortcuts in the C:\Windows\Start Menu\Programs\Startup folder:
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
Do you really need the MS Office Shortcut bar to open every time your system boots up?
--------------------------
I suggest that you:
1. Close all running applications and disconnect from the Internet
2. Start Menu > "Run" option > and type MSCONFIG > click OK.
3. Go to the "Startup" tab and UNTICK the following entries:
(I've left out the ones that are probably required.)
On-Line Protection
Update Scheduler
Messenger
SunJavaUpdateSched
Startup Scan (should be two entries)
QuickTime Task
LXSUPMON <---- Printer Monitor (printer may not work until re-enabled)
Lexmark X6100 Series <---- Printer Monitor (as above)
iTunesHelper
Email Protection
DSLAGENTEXE <----------- Broadband Modem Connection MAY require this!!
Comodo Firewall ***
NvMediaCenter
Spyware Doctor ***
Gadwin PrintScreen 3.5
Adobe Reader Speed Launch
Microsoft Office
4. Click on the "APPLY" button
5. Click the OK button, and restart the computer when prompted.
6. Now temporarily disable the following "Services" and restart the computer (shown as 023 entries in your HiJack This log):
Comodo Application Agent (CmdAgent) ***
iPodService
LexBce Server (LexBceS) <---- Printer Monitor (as previous section)
NT Online Protection
Quick Heal Helper Service WSC (ScanWscS)
PC Tools Spyware Doctor (SDhelper) ***
IMPORTANT:
Even though you will see a "Services" tab in MSCONFIG, DO NOT use this to disable Windows Sevices or modify their settings. The proper way to do that is to run SERVICES.MSC from the Start Menu's "Run" field.
If you are unsure how to temporarily disable a service, then just ask before doing so.
7. Now try and install IE7.
There are quite a few startups and Services that could well be interfering with the installation, especially Firewalls and background Anti-Spyware programs.
Here's the Analysis of your HiJack This file if you are interested:
http://www.hijackthis.de/logfiles/d044b14ca7b95fddb609a28c03282ef7.html
There's nothing nasty in there, but a few unnecessary things that can be disabled (NOT "FIXED" by HiJack This).
Bill
Another thing.
The Machine Debug Manager (mdm.exe) is running in the background. It's a normal process, but can waste resources and isn't required.
How to turn off Machine Debug Manager in Office XP/2000:
http://support.microsoft.com/kb/321410
http://www.freddyreyes.com/index.php?option=com_content&task=view&id=54&Itemid=
Files with names that begins with "fff" appear in your Windows folder after you install Office xxxx:
http://support.microsoft.com/kb/221438/
http://www.microsoft.com/technet/archive/community/columns/inside/techan21.mspx#E2E
Bill
The Machine Debug Manager (mdm.exe) is running in the background. It's a normal process, but can waste resources and isn't required.
How to turn off Machine Debug Manager in Office XP/2000:
http://support.microsoft.com/kb/321410
http://www.freddyreyes.com/index.php?option=com_content&task=view&id=54&Itemid=
Files with names that begins with "fff" appear in your Windows folder after you install Office xxxx:
http://support.microsoft.com/kb/221438/
http://www.microsoft.com/technet/archive/community/columns/inside/techan21.mspx#E2E
Bill
ASKER
I've now got a second PC that's shutting down. Windows firewall not functioning either. Error message pops up. Everything is so slow. Has anyone heard of any new virus or malware that's causing shutdowns and Windows firewall to stop working?
Evertime I try to clean registry with Regseeker - PC shuts down. Seems to happen when scanning HKEY_current user.
Evertime I try to clean registry with Regseeker - PC shuts down. Seems to happen when scanning HKEY_current user.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Thank you Teresa
ASKER
Solution available? : No (see Next steps)
What does this error mean? : Windows has encountered an error from which it cannot recover and needs to restart
Cause : Unknown device driver
Computer symptoms : A message appears on a blue screen with error code information (for example: e.g. 0x0000001E, KMODE_EXCEPTION_NOT_HANDLE
Additional steps for you to take : Important: Please continue to send error reports so analysts at Microsoft can study and try to correct the problem as quickly as possible
Information about this error
You received this message because a device driver installed on your computer caused the Windows operating system to stop unexpectedly. This type of error is referred to as a "stop error." A stop error requires you to restart your computer.
Next steps
We have analyzed your error report and at this time are unable to determine the exact cause of the error. However, Microsoft will continue to analyze this error report to try to determine the specific cause of the error. If we are able to find the cause and correct it, and you encounter the same problem, you will receive an updated response that includes instructions for resolving the problem.