This is a read-only archive. No new posts or registrations. Privacy Page
Software

Computer Problems

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I open my browser Mozilla Firefox, and while the website is loading, I am unable to open my MS Word program sometimes. I usually get an Application Hang problem which is recorded in the Event Viewer log below. Also, when I clip and paste anything from a webpage, or from any MSWord document, the pastes come out double or triple sometimes, even though I click the mouse only once to paste. I use XoftSpy, AVG and Kerio Firewall. I would greatly appreciate it if you could help me with these issues. Thank you. Event Type: Error Event Source: Application Hang Event Category: (101) Event ID: 1002 Date: 2/11/2007 Time: 4:06:44 PM User: N/A Computer: Description: Hanging application WINWORD.EXE, version 11.0.8106.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. 0000: 41 70 70 6c 69 63 61 74 Applicat 0008: 69 6f 6e 20 48 61 6e 67 ion Hang 0010: 20 20 57 49 4e 57 4f 52 WINWOR 0018: 44 2e 45 58 45 20 31 31 D.EXE 11 0020: 2e 30 2e 38 31 30 36 2e .0.8106. 0028: 30 20 69 6e 20 68 75 6e 0 in hun 0030: 67 61 70 70 20 30 2e 30 gapp 0.0 0038: 2e 30 2e 30 20 61 74 20 .0.0 at 0040: 6f 66 66 73 65 74 20 30 offset 0 0048: 30 30 30 30 30 30 30 0000000 Logfile of HijackThis v1.99.1 Scan saved at 11:17:06 PM, on 2/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Also ran Ad-Aware SE on two separate occasions and got these messages -: ArchiveData(WindowsRegData Vulnerability.bckp) Referencefile : SE1R150 09.02.2007 ====================================================== WINDOWS »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» obj[0]=RegData : regfile\shell\open\command "" ArchiveData(1criticalobject2407.bckp) Referencefile : SE1R146 22.01.2007 ====================================================== WINDOWS »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» obj[0]=RegData : regfile\shell\open\command "" TRACKING COOKIE »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» obj[1]=IECache Entry : Cookie:[removed]/ ====================================================== These items have all been quarantined.
Hello spiceball,

Welcome to Tom Coyote Forums!

I have a few questions I'd like you to answer for me:
Does this happen when you open Internet Explorer as well?
How long has this been occurring?
Have you made any recent changes?

Thanks,

Ax

Hello spiceball,

Welcome to Tom Coyote Forums!

I have a few questions I'd like you to answer for me:
Does this happen when you open Internet Explorer as well?
How long has this been occurring?
Have you made any recent changes?

Thanks,

Ax

Hello Ax, Thank you for getting back to me so promptly. I hardly use IE at all - mostly Mozilla Firefox with Thunderbird as my email client. I open all my emails on www.mail2web.com to avoid the unwanted ones being downloaded onto my hard drive. I had shut down my Active X controls in IE for the past year and stopped using Outlook Express. This significantly curtailed any hacker problems I was experiencing. The application hang problem has been occurring for the past year. But the clip & paste issue has only been happening in the past two weeks. I usually get rid of the cookies I sometimes enable for certain websites, after surfing the web. I also run AVG, Ad-Aware SE & XoftSpy almost weekly, and delete the Prefetch files in Windows & the *.tmp files, also weekly. Other than that, I haven't made any recent changes, although I am doing a lot of web-surfing lately.
Spiceball, I was asking the question about whether it happens with IE as well, not whether you use IE or not. I need you to check to see if it happens with IE as well, even if you no longer use it. This will help us to determine whether it is related to specific programs or the system as a whole. A year is quite a while to be having this problem, we'll see if we can get it worked out in less time than that ;). Web surfing isn't without consequences sometimes. One more thing, do yourself a favor and stop deleting the prefetch files. They help speed up your system and old ones are recycled automatically anyways. Ax
Hi Ax: Mea culpa for deleting the prefetch files! I got that from another techie's website, obviously not as good as yours! Also, just checked three times using IE and did not have the hang problem. I even tried opening IE, & also Mozilla Firefox after that and had no problem. When using Mozilla alone, no problem again. I can't understand why this happens only on days when I have crazy deadlines!!! It is pretty late at night so I will try using IE again tomorrow to see what happens, or is this enough? Bless you for looking into these problems.
spiceball,

Don't worry about having previously deleted the prefetch files, it is a common mistake (just don't do it anymore unless someone suggests it) :). You've also given me sufficient evidence to believe that Microsoft Word is not affected by opening Internet Explorer.

At this point, the issue you have could involve any number of things. What I'd like you to do, in order to see what things may be affecting your system, is to run the PC PitStop Full Tests and post a TechExpress Link here.

Thanks,

Ax
Hello Ax: Ever since I got your last post, I have been in the pcpitstop site, trying to do the tests. Since I have Mozilla, I have had difficulty getting the Neptune plug-in to work after downloading it. I can't even log in using IE to create an account, despite following all the instructions in Troubleshooting, activating scripts, enabling cookies, disabling pop-ups and Kerio firewall, etc. My concern is that since I have exhausted all my options except to go to pitstop's forums to post the problem, my computer is now very vulnerable to hackers, viruses, spyware, etc., until I get a response from their end. I even noticed on my Kerio Firewall log that the incidents of bad incoming traffic has increased and there are more listening episodes than before. Should I just default to my original controls until I post to pitstop's forums or is there an easier way to get around the restrictions of pitstop?
OK, just so that I understand you correctly, you are unable to get the Neptune plugin loaded into Firefox and you can't get into it with Internet Explorer either. I would say restore your settings back to where you had them, but there is definitely something going on with your system. We'll hold off on the Pit Test for now.

Try running Spybot - Search & Destroy (link in my sig), instructions here. Then, read this and post a HijackThis log here. If you are still having issues when your log is declared clean by an expert, post back here and we'll continue with our investigation.

Regards,

Ax

Then,
Hello Ax:

Just to clarify, I was able to get the Neptune plugin loaded into Firefox but had to do it manually (as per the instructions from pipitstop for Firefox users) but was not able to run it with Internet Explorer. It would open and nothing would happen after that.

Spybot, Ad-Aware SE, AVG AntiSpyware were clean. No problem with AFT Cleaner. After rebooting, ran HiJack This and have posted the log here. Hope this helps.

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 11:04:21 AM 2/16/2007
+ Scan result:
Nothing found.
::Report end

Logfile of HijackThis v1.99.1
Scan saved at 1:13:44 PM, on 2/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.netscape.not
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mycopper.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.netscape.not
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mycopper.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [ScriptSentry] C:\Documents and Settings\FionaFig\My Documents\ScriptSentry\ScriptSentry.exe /check
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: ELSBLaunch.lnk = C:\Program Files\EarthLink\spamBlocker\ELSBLaunch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.lavasoft.com
O15 - Trusted Zone: *.nytimes.com
O15 - Trusted Zone: *.windowsupdate.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/pcpitstop.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

Then, read this and post a HijackThis log here. If you are still having issues when your log is declared clean by an expert, post back here and we'll continue with our investigation.


OK, by "here" in the last quote I meant the HijackThis Log forum (it was more of a reference to the link to the forum). Please post your HijackThis log in a new thread in the HijackThis Log Forum. Sorry for the confusion.

Regards,

Ax
Sorry Ax, it was my fault really. I did go to the link you provided initially, but completely forgot to post there. I have now posted to the HJT forum. Thank you for checking in and have a nice evening.
Hello Ax :wavey: : I'm back after my latest HJT log was declared clean by Ken. :) He was patient and supportive in walking me through the various steps. From where we last left off, I would like to remove the IE6 on my system, and do a new download of IE6. When I click the search button after opening IE, nothing happens. I need to get IE6 working again so I can do the Pit test. Do you agree?
Welcome back spiceball,

I'm glad to see that your log has been all sorted out. The search button isn't integral to the functioning of Internet Explorer. All this does is pull up a search box from your default search provider. I'm not sure that reinstalling IE6 will be in line with what you are attempting. Is there a reason that you can't use the Address Bar to navigate to PC PitStop's website? Please let me know of the exact problems that are occurring now that your log is clean.

Regards,

Ax

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI