This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer Freezing Up

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has started freezing up (I think) - at least my mouse quits working and I have to reboot.

Here is a copy of my HijackThis log.

Thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:30:39 PM, on 4/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: IE to Lightning Helper - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://forums.budget101.com
O15 - Trusted Zone: http://www.budget101.com
O15 - Trusted Zone: http://print.coupon.com
O15 - Trusted Zone: http://bricks.coupons.com
O15 - Trusted Zone: http://www.townplannerstl.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238528926738
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{91D2EC90-5FB7-478F-96C5-1A8C5263C28E}: NameServer = 146.163.252.6 146.163.252.7
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Virtual PDF Printer (Service1) - Unknown owner - C:\Program Files\Virtual PDF Printer\VirtualPrinting.exe

–
End of file - 7254 bytes

Hello free_spirit_etc,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HijackThis log now, I will post back shortly with instructions.

Thank you. I tried some cleaning on it today. I ran a new hijack this log after that. Should I post it? I will have to get back on my computer to get it. I unhooked mine and hooked my husband's up so I could try to work on the computer some without my computer freezing. But I imagine this computer needs all the antivirus programs updated before I do much on it. This is the first time I have used his computer to get online since he died (two years ago) - so I know everything is out of date on this one. But I can hook the other one back up and post a new hijackthis log if you need me to. Thanks so much!

Hello free_spirit_etc,

Before we start we need to disable one of your security programs so it won't interfere with out fix.

  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the Resident TeaTimer (Protection of overall system settings) active box.
  • Click on the System Startup icon in the List
  • Uncheck the TeaTimer box and OK any prompts.
  • If Teatimer gives you a warning that changes were made, click the Allow Change box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.)
- - - - - Next - - - - -

It appears that you don't have a Firewall installed. If you are currently using Windows Firewall you can skip this step.
This must be taken care of first. Please go to one of the links below and download and install a Firewall.

Firewall:
- - - - - Next - - - - -

Run HijackThis and select Do a System Scan Only

Before proceeding, make sure all programs and browser windows are closed, EXCEPT HijackThis
Place check marks next to the following items:
Now with all browsers closed, click on Fix Checked, then EXIT the program

- - - - - Next - - - - -

Please download ATF Cleaner by Atribune.
Download - http://www.nutnworks.com/downloads/ATF_Cleaner.exe
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

- - - - - Next - - - - -

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • New HijackThis log
  • Malwarebytes log
  • Tell me how your computer is running

Thanks!

I ran all the things you suggested. I didn't do the firewall yet - but my computer says the Windows one is turned on.

Everything worked fine - but then when I tried to post - the computer froze up twice.

So still having the same issue.

It doesn't matter if I am online or offline. Sometimes it freezes up right away - other times I have no problem for awhile.

It actually froze up several times a couple of weeks ago - but only when I opened a specific word document. So I quit opening it - and had no other problem until this weekend.

I have also been having a photo gallery thing wanting me to install a disk - to install something - when I turn the computer on. But I click cancel to that - because I have tried putting in my printer disk - and it apparently doesn't have what this photo gallery wants.

Yesterday, that QUIT coming up when I started my computer - for awhile – but after a few times, it started again.

Today - there was also a Message - Error 1704 An installation for opening office.org is currently suspended. You must undo change made by that installation to continue. Do you want to undo those changes? Yes No

But that error message comes up with the Photo gallery message.

I THOUGHT I UNinstalled Open Office yesterday. It doesn't have an unistall program - so I used the Add / Delete programs in the control panel. I actually only used it one time. I downloaded it to get a tax form. (the tax form didn't work either.)

Here are my logs:

Malwarebytes' Anti-Malware 1.36
Database version: 2047
Windows 5.1.2600 Service Pack 3

4/27/2009 12:03:41 PM
mbam-log-2009-04-27 (12-03-41).txt

Scan type: Quick Scan
Objects scanned: 69905
Time elapsed: 3 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:28 PM, on 4/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: IE to Lightning Helper - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238528926738
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6208 bytes

Thanks!

Free

Hello free_spirit_etc,

Thank you for the Malwarebytes log. No need to change your firewall if Windows firewall in enabled.

Your Java is outdated.
Please follow these steps to remove older version Java components.

  • Close any programs you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check Java™ 6 Update 7
  • Click the Remove or Change/Remove button.
  • Reboot your computer once all Java components are removed.
- - - - - Next - - - - -
  • Download the latest version of Java , which is Version 6 Update 13, and click Free Java Download
  • Follow the onscreen instructions to install Java
  • Reboot if requested to do so.
- - - - - Next - - - - -

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
  • Post ESET log.txt

Thanks. I have a couple questions: 1. Should I remove the Java 6 Update 3 also? 2. I clicked remove on the Java 6 Update 7, but then got the error message again: Error 1704 An installation for opening office.org is currently suspended. You must undo change made by that installation to continue. Do you want to undo those changes? Yes No I clicked No - but then the Java wasn't removed. Should I click Yes on the error message? Thanks! Free

Hi free_spirit_etc,

Please read the entire post prior to proceeding.

Should I remove the Java 6 Update 3 also?

Yes, you will need to remove all older versions of Java.

I clicked remove on the Java 6 Update 7, but then got the error message again:
Error 1704 An installation for opening office.org is currently suspended. You must undo change made by that installation to continue. Do you want to undo those changes? Yes No
I clicked No - but then the Java wasn't removed. Should I click Yes on the error message?

We will be addressing this first but here is a brief explanation as to what might be the cause of the Error 1704 message:

Sometimes, when you try to (un)install a program packaged with Windows Installer, the routine fails. It leaves behind registry entries that give an Error 1704 - preventing further (un)installs of Windows Installer packaged programs.

Please the following instructions below in order given.
  • Please go to http://www.softpedia.com/get/System/System…p-Utility.shtml and download Error 1704 Cleanup Utility 2
  • Save the file to it's own folder, (i.e create a folder here - C:/Program Files/Error 1704 Cleanup Utility)
  • Double click E1704.zip to unzip the file, save it in the Error 1704 Cleanup Utility folder (created previously)
    (There will be 2 files after unzipping. E1704C.exe and E1704C.txt)
  • Double click E1704C.exe to run program
  • Click Clear Error 1704 button
  • Reboot
- - - - - Next - - - - -

Note: If after rebooting you still encounter the Error 1704, please skip the Java removal and update step and continue with the ESET online scan and the DDS.

Your Java is outdated.
Please follow these steps to remove older versions of Java components.
  • Close any programs you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Remove All older versions of Java
    (you might have to repeat some of these steps more than once to remove all old versions of Java)
  • Click the Remove or Change/Remove button.
  • Reboot your computer once all Java components are removed.
- - - - - Next - - - - -
  • Download the latest version of Java , which is Version 6 Update 13, and click Free Java Download
  • Follow the onscreen instructions to install Java
  • Reboot if requested to do so.
- - - - - Next - - - - -

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs) < < < Important
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
  • Post ESET log.txt
  • Please also describe how your computer is running.

Thanks! I am working on it! My computer is working lots better already. It did freeze up a few times - but not near as often. Word is working much better. I can actually copy and paste something without it taking forever. Where I am stuck now is on Spybot: (Doing - · Disable any script blocking protection (How to Disable your Security Programs) < < < Important ) to run the DDS I was able to do: On the left hand side, click on Tools, then click on the Resident Icon in the list. Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box. (I actually did that yesterday in the other instuctions) But I was not able to: Click on the "System Startup" icon in the List Uncheck the "TeaTimer" box and "OK" any prompts. I am not finding Tea Timer in the System Startup list. I am not sure how I missed that yesterday - when I first disabled it on the other screen. I do have the newer version of JAVA now. And I ran the Eset Online Scanner Here is the log from that: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=4041 (20090428) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=a4d3616820c3a347a253594daccb211c # end=finished # remove_checked=false # unwanted_checked=true # utc_time=2009-04-29 06:18:42 # local_time=2009-04-29 01:18:42 (-0600, Central Daylight Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=241069 # found=1 # scan_time=2735 C:\Documents and Settings\Semproni\My Documents\LimeWire\Incomplete\CORRUPT-0-Adema - Co-Dependent.mp3 But I am not sure what to do about not having the Tea Timer in the Spybot Startup to uncheck. Thanks

Hi free_spirit_etc,

You have Limewire, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

If you wish to keep it, please do not use it until your computer is cleaned.

I would recommend that you uninstall Limewire, however that choice is up to you.

  • LimeWire
This is how you uninstall it/them:
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following LimeWire (if still present):
NOTE: Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

- - - - - Next - - - - -

Please locate the folder in red and delete it and it's entire contents.
Be sure to delete the entire folder that is designated.
  • C:\Documents and Settings\Semproni\My Documents\LimeWire
Right click the file or folder, select Delete.

- - - - - Next - - - - -

At this point re-try and disable Spybot Tea Timer from the previous post. If you have the same issue as previously, just close Spybot and continue with the remainder of the instructions.

- - - - - Next - - - - -

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs) < < < Important
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
  • Please also describe how your computer is running.

My computer is doing better than when I started. It did freeze up twice today. Once after I had used it for awhile and the second time right after I rebooted. And that box wanting me to install photo gallery still pops up every time I turn on the compter. I deleted the limewire folder and emptied the recycle bin - and uninstalled Limewire. I never used it anyway. My son's friend put it on my computer. I didn't find the Tea Timer in the Spybot system startup, but disabled it in the resident protection. Here is a copy of the DDS log: (and I hope I attached the other one right) DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 0:25:05.92 on Thu 04/30/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.226 [GMT -5:00] AV: avast! antivirus 4.8.1335 [VPS 090429-0] *On-access scanning disabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\Program Files\Microsoft Office\Office\WINWORD.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Semproni\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.yahoo.com/ uWindow Title = Microsoft Internet Explorer uSearch Bar = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: IE to Lightning Helper: {f1ff080d-12a3-439a-a2ef-4ba95a3148e8} - c:\program files\lightning download\LD_Catch.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe" mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe" mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\semproni\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238528926738 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\semproni\applic~1\mozilla\firefox\profiles\on0wtzl9.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-20 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-20 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-2-21 138680] R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);c:\windows\system32\drivers\es1370mp.sys [2008-2-26 37504] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-2-21 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-2-21 352920] =============== Created Last 30 ================ 2009-04-28 18:13 410,984 a——- c:\windows\system32\deploytk.dll 2009-04-28 18:13 73,728 a——- c:\windows\system32\javacpl.cpl 2009-04-28 16:06 –d—– c:\program files\EsetOnlineScanner 2009-04-28 12:18 –d—– c:\program files\E1704C 2009-04-28 12:17 131,829 a——- c:\program files\E1704C.zip 2009-04-26 18:27 –d—– c:\windows\system32\NtmsData 2009-04-25 19:30 –d—– c:\program files\Trend Micro 2009-04-25 12:05 10,240 a——- c:\windows\system32\virport.dll 2009-04-17 13:23 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll 2009-04-17 13:23 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll 2009-04-17 13:23 284,160 -c—— c:\windows\system32\dllcache\pdh.dll 2009-04-17 13:23 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe 2009-04-17 13:23 110,592 -c—— c:\windows\system32\dllcache\services.exe 2009-04-17 13:23 729,088 -c—— c:\windows\system32\dllcache\lsasrv.dll 2009-04-17 13:23 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll 2009-04-17 13:23 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-17 13:23 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll 2009-04-16 21:17 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-04-16 21:17 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb 2009-04-16 21:17 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe 2009-04-15 03:18 0 a——- C:\~GLHTTP1.TMP 2009-04-01 10:15 27,496 a——- c:\windows\system32\mucltui.dll.mui 2009-04-01 10:15 268,648 a——- c:\windows\system32\mucltui.dll 2009-03-31 15:06 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2 ==================== Find3M ==================== 2009-04-25 19:03 162,314 a——- c:\windows\pchealth\helpctr\config\cache\Personal_32_1033.dat 2009-04-06 15:32 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-06 15:32 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-03-14 17:35 149,353,184 a——- c:\program files\OOo_3.0.1_Win32Intel_install_wJRE_en-US.exe 2009-03-06 09:22 284,160 a——- c:\windows\system32\pdh.dll 2009-03-02 19:18 826,368 a——- c:\windows\system32\wininet.dll 2009-02-20 13:09 78,336 a——- c:\windows\system32\ieencode.dll 2009-02-09 07:10 729,088 a——- c:\windows\system32\lsasrv.dll 2009-02-09 07:10 714,752 a——- c:\windows\system32\ntdll.dll 2009-02-09 07:10 617,472 a——- c:\windows\system32\advapi32.dll 2009-02-09 07:10 401,408 a——- c:\windows\system32\rpcss.dll 2009-02-09 06:13 1,846,784 a——- c:\windows\system32\win32k.sys 2009-02-07 19:02 2,066,048 a——- c:\windows\system32\ntkrnlpa.exe 2009-02-06 06:11 110,592 a——- c:\windows\system32\services.exe 2009-02-06 06:08 2,189,056 a——- c:\windows\system32\ntoskrnl.exe 2009-02-06 05:39 35,328 a——- c:\windows\system32\sc.exe 2009-02-03 14:59 56,832 a——- c:\windows\system32\secur32.dll 2009-02-02 12:42 104,197 ——– c:\windows\hpoins04.dat 2008-12-17 11:51 7,518,240 a——- c:\program files\Firefox Setup 3.0.5.exe 2008-11-12 00:50 449,043 a——- c:\program files\RegSeeker.zip 2003-09-16 01:19 99,544 a——- c:\windows\inf\virprn.exe 2003-09-16 01:19 18,950 a——- c:\windows\inf\virpntd.dll 2003-09-16 01:19 10,240 a——- c:\windows\inf\virport.dll 2003-09-16 01:19 90,624 a——- c:\windows\inf\prtproc.dll 2001-11-23 13:08 712,704 a——- c:\windows\inf\other\AUDIO3D.DLL 2008-09-22 18:48 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092220080923\index.dat ============= FINISH: 0:25:44.75 ===============

Attachments:

Hi free_spirit_etc,

I would like to know if you use the program Photo Gallery? You stated that it requests the install disk on boot-up.
If you use this program do you have the install disks to re-install the program? If so, please locate them and have them handy.

If you don't use the program and would like to remove it from your computer please do the following:

Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:

  • Photo Gallery
Select each one of the programs, then select remove.
(if the program is not listed don't be alarmed, just continue)

Exit the Control Panel when finished.

- - - - - Next - - - - -

Please locate the folder in red and delete it and it's entire contents.
Be sure to delete the entire folder that is designated.
  • C:\Program Files\Photo Gallery (if found)
Right click the file or folder, select Delete.

Empty your Recycle Bin, then Reboot.

- - - - - Next - - - - -

If you would like to re-install Photo Gallery, please insert the CD into your CD drive and follow the onscreen instructions.

If not, just skip this step.

- - - - - Next - - - - -

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe

    :Services

    :Reg

    :Files
    C:\~GLHTTP1.TMP

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • New HijackThis log
  • OTMoveIt3 log
  • Tell me how your computer is running

Thanks!

My computer hasn't done the freeze at all today. :)

I couldn't find the photo gallery in the add / remove programs or the folder in the program files to delete. So that is still coming up when I start the computer.

Here are my logs:


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\~GLHTTP1.TMP moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Semproni\LOCALS~1\Temp\Google Toolbar\gtb1A.tmp.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Semproni\LOCALS~1\Temp\~DF20D2.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Semproni\LOCALS~1\Temp\~DFDA65.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Semproni\LOCALS~1\Temp\~DFE0A2.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\XGLTB8EH\bxdat4[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\XGLTB8EH\bxdat4[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\XGLTB8EH\de[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\XGLTB8EH\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\XGLTB8EH\navbar[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\BKPYZX7I\bxdat4[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\BKPYZX7I\bxdat4[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\BKPYZX7I\bxdat4[3].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\BKPYZX7I\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\BKPYZX7I\moneysavingmethods_blogspot_com[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\AAOFHQ5J\bxdat4[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\AAOFHQ5J\bxdat4[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\1GSKR9Q7\bxdat4[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\1GSKR9Q7\bxdat4[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\1GSKR9Q7\Computer_Freezing_Up_t102467[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\1GSKR9Q7\dg_specificclick_net[1] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\1GSKR9Q7\MSMHeader[1].gif scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Semproni\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Google Toolbar\gtm1B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\GoogleToolbarInstaller2.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5ac.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_710.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05012009_134939


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:10:59 PM, on 5/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: IE to Lightning Helper - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238528926738
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{91D2EC90-5FB7-478F-96C5-1A8C5263C28E}: NameServer = 146.163.252.6 146.163.252.7
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6496 bytes

free_spirit_etc,

Can you provide any additional information about the program Photo Gallery that is trying to load at start up?

Could it possibly be Windows Photo Gallery?

Please look here to see if this folder exists >> C:\Program Files\Windows Photo Gallery

- - - - - Next - - - - -

Reboot, on your next post please provide the following:

  • Any new information about Photo Gallery

I didn't find the file under Windows. And when I do a search - the only photogallery I find is on the DDS attachment.

I always thought it had something to do with the HP printer. But I tried putting the disk in - when they error asks for the disk - and it still didn't work.

It is listed at this website. I am not sure if that is the same error I am getting.

http://h10025.www1.hp.com/ewfrf/wc/documen…product=3351220

Common msi files and their associated software applications that come with HP and Compaq products:
aiosoftware.msi - HP Photosmart Digital Imaging software
documentviewer.msi - HP Photosmart Digital Imaging software
ezarc.msi - Sonic MyDVD
HpSdpAppCoreApp.msi - HP Easy Internet Signup
hpproductassistant.msi - HP Photosmart Digital Imaging software
mydvd.msi - Sonic MyDVD
Photogallery.msi - HP Photosmart Digital Imaging software
TrayApp.msi - HP Photosmart Digital Imaging software

I did notice when I was looking for the Tea Timer on the Spybot startup - that there was something disabled on start up.

The box is unchecked and it says startup disabled.
HPDigitalImagi C:\PROGRA~1|HP|DIGTA~1\bin\hpqtra08.exe

My computer is running much smoother. It did freeze up twice. Again, once after I rebooted from the previous freeze up.

And I had an error where the interenet wanted to shut down after I printed some coupons.

Not sure if those are connected.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI