cancel
Showing results for 
Search instead for 
Did you mean: 

Shud Oi be bovvered?

Luzern
Seasoned Pro
Posts: 2,883
Thanks: 233
Fixes: 2
Registered: 31-07-2007

Shud Oi be bovvered?

I may be an idiot but recently odd things have worried me computer-wise.
It has seemed much slower to start up. I have had more instances of having to use Control Alt Delete to exit screens, and have even had to use the switch at the back of the box as opposed to clicking on Start and exiting that way. Early this morning I was on an other forum and had clicked on a link t open in a new window, when I had read it and tried to close the link, everything was completely locked and I was forced to use the switch mentioned above.
So be bovvered or not, and yes, what to do next, please?
No one has to agree with my opinion, but in the time I have left a miracle would be nice.
19 REPLIES
Luzern
Seasoned Pro
Posts: 2,883
Thanks: 233
Fixes: 2
Registered: 31-07-2007

Re: Shud Oi be bovvered?

@PJ Actually have started copying over quite a bit of what's on to DVD RAM disks, photos first
Have the AVG progs so will update and run a scan,even though I did scans quite recently, when nothing was found. Will look into others and follow recs.
Am on XP SP2 and Firefox. Modem at moment until S-i-L locates leads to the router he is giving me.
TBH I was wondering if my HDD was becoming temperamental. I take it you are not thinking that.
No one has to agree with my opinion, but in the time I have left a miracle would be nice.
oddjob
Dabbler
Posts: 22
Registered: 15-08-2007

Re: Shud Oi be bovvered?

Quote from: lucerne
I was wondering if my HDD was becoming temperamental. I take it you are not thinking that.
You might be right but, as PJ says, this is more likely to be malware.
if you're not having much success fixing the problem I suggest you scan your system with HijackThis* and post the resulting log file report to this thread.
I - or someone else else with the appropriate knowledge - will guide you on what action to take next.

*This is the HJT procedure ...
Download  Trend Micro HijackThis 2.0.2 here ……
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" and Paste the entire contents of the log  (no attachments) into your next post.

DO NOT use the ”AnalyseThis” button. Its findings are dangerous if misinterpreted.
DO NOT have Hijackthis fix anything yet.
Most of what HJT lists will be harmless or even required by your Operating System.

OJ
Luzern
Seasoned Pro
Posts: 2,883
Thanks: 233
Fixes: 2
Registered: 31-07-2007

Re: Shud Oi be bovvered?

Quote from: PJ

Might also be worth running a error check next time you boot although this is extremely limited
Not sure how to do that.
I have run the AVGs, and the Antispyware found one medium tracker, whilst Windows Defender found something called
" SoftwareBundler:Win32/MessengerPlus.a!installer" with the following note
"This potentially unwanted software is detected by the Microsoft antispyware engine. Technical details are not currently available.". Pro tem this is quarantined. Disk Cleanup is dome and all that remains now is the overnight Defrag. then I will look at the other options posted. Thanks all for help so far Smiley
No one has to agree with my opinion, but in the time I have left a miracle would be nice.
Denzil
Grafter
Posts: 1,733
Registered: 31-07-2007

Re: Shud Oi be bovvered?

It is also worth running the TweakNow registry cleaner. http://www.tweaknow.com/RegCleaner.html It will get rid of the obsolete links that build up over time in the registry. 
MikeWhitehead
Grafter
Posts: 748
Registered: 19-08-2007

Re: Shud Oi be bovvered?

I agree with OJ. Post a HJT log and a few of us will help you identify any rogue entries and remove them.
Luzern
Seasoned Pro
Posts: 2,883
Thanks: 233
Fixes: 2
Registered: 31-07-2007

Re: Shud Oi be bovvered?

HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:32:22, on 04/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.faithspace.org.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126202523546
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {82F2D6B2-6C58-4404-A930-9DB0FD90D4B1} (Driver_Detective_v43_Non_Member.DD_v43) - http://www.drivershq.com/cab/prod/Driver_Detective_v43_Non_Member.CAB
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://www.contentwatch.com/audit/includes/ContentAuditControl.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.groups.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4667/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\GordonHC\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - (no file)
--
End of file - 8612 bytes
No one has to agree with my opinion, but in the time I have left a miracle would be nice.
MikeWhitehead
Grafter
Posts: 748
Registered: 19-08-2007

Re: Shud Oi be bovvered?

Nope, your log seems fine, although
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')

looks a bit odd to me, don't know why it needs an entry 4 times for each type of user it is. Otherwise things look ok.
I've noticed you have a few toolbars, iTunes, etc and quite a few things (not really over the top) loading at startup. If you don't need these applications to start when you turn the system on then that would probably cut down the freezing you are experiencing.
How much RAM do you have in your machine? iTunes is a huge resource hog so if you often have that running then that may be the culprit.
Hope this helps.
oddjob
Dabbler
Posts: 22
Registered: 15-08-2007

Re: Shud Oi be bovvered?

Only one thing  to ad to that.
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 to your desktop from here ……
    http://javadl.sun.com/webapps/download/AutoDL?BundleId=12798
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then install the newest version by double-clicking the update file you just downloaded to your desktop.


OJ
MikeWhitehead
Grafter
Posts: 748
Registered: 19-08-2007

Re: Shud Oi be bovvered?

Good catch OJ, I noticed that when I was going through the list but totally forgot to mention it afterwards Cheesy
Luzern
Seasoned Pro
Posts: 2,883
Thanks: 233
Fixes: 2
Registered: 31-07-2007

Re: Shud Oi be bovvered?

@MikeWhitehead Safe to get rid of duplicate AVG entries and which one to retain, if it matters?
Itunes I'll look at but somehow I think it is somehow bound up with the Camedia prog that goes along with my Olympus camera, being the only prog that gives me full exposure data.
RAM ----512 DDR
HDD---- 80 GN 23.3 used
Will install new Java tomorrow. NOw to the defrag whilst
 
No one has to agree with my opinion, but in the time I have left a miracle would be nice.
VileReynard
Seasoned Pro
Posts: 10,645
Thanks: 204
Fixes: 9
Registered: 01-09-2007

Re: Shud Oi be bovvered?

Installing trial software, especially free magazine stuff and then uninstalling it has a tendency to leave clutter behind, which will eventually cause sluggish startups and possible instability.

Community Veteran
Posts: 1,571
Thanks: 3
Registered: 13-04-2007

Re: Shud Oi be bovvered?

Its a wonder the poor pc ever gets going with that lot get startup cpl from http://www.mlin.net/StartupCPL.shtml
and get rid of half of the startup programs as there cant be much memory left.
If you run startpcpl you can untick most of the startup and add them back as required.
You dont need realplayer update
hp update
java
incd unless you are packet writing
quicktime
it tunes helper
carpserv.exe this is for modems
You dont need all the anti spyware choose one only
Get rid of that lot and you will have some ram free
Luzern
Seasoned Pro
Posts: 2,883
Thanks: 233
Fixes: 2
Registered: 31-07-2007

Re: Shud Oi be bovvered?

@ oddjob: Very strange but I could not find Java or Sun in the Add/Remove progs list Huh, so deleted the Java Prof File manually. Is there anywhere else I must look, either in Windows or the Registry and act?
I have found several entries in Search ( see attachment). Can you please look and confirm they all need be removed, please?
No one has to agree with my opinion, but in the time I have left a miracle would be nice.
oddjob
Dabbler
Posts: 22
Registered: 15-08-2007

Re: Shud Oi be bovvered?

Quote from: axisofevil
Installing trial software, especially free magazine stuff and then uninstalling it has a tendency to leave clutter behind, which will eventually cause sluggish startups and possible instability.

This is a good point. Always use Ccleaner and/or CleanUp! to help reduce clutter and free up disk space. The first time you run it/them you may be pleasantly surprised at the amount of disk space you free up but remember .... if you use the programs on their default options they may well clear out things you want to keep such as site passwords etc. That's no real problem; it just means you'll have to re-enter the information next time you visit the site.
Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …
http://www.ccleaner.com/
CleanUp! is here ....
http://www.stevengould.org/index.php?option=com_content&task=view&id=15&Itemid=69

As to the java I think it's best left alone if it's not in your Add/Remove Programs (which I find odd). Just make sure you update to version 6, update 3 which was released a few days ago.
OJ