Huge number of problems, requesting help

  1. #1
    kaput is offline Newbie

    Unhappy Huge number of problems, requesting help

    Sorry if that was a bad title.

    Anyhow, my computer, running XP, is experiencing a huge number of problems as of late. It is 2.8 ghz, and yet it moves at the speed of light (That was sarcism). When I start it up, it takes 6-8 minutes to useable, and when I open anything to begin with, more often than not it will freeze up, and take 5-10 minutes to do anything. If I switch user (running home edition), then when you try to log on as someone else, it will crash with a blue screen. IE crashes the first time it is used, if it opens at all. Also, I am having trouble removing the Elitebar and Searchmiracle spyware, which just refuses to go. I have run several virus scans, Norton and a few online scanners. I've used Ad-aware and Spybot, and still nothing. Here is the hijackthis log:

    Logfile of HijackThis v1.99.0
    Scan saved at 8:11:47 PM, on 09/01/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Softex\OmniPass\Omniserv.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Softex\OmniPass\OPXPApp.exe
    C:\Program Files\Handspring\HOTSYNC.EXE
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Quinn\My Documents\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    O1 - Hosts: comments (such as these) may be inserted on individual
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - (no file)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
    O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvutd32.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Startup: Free WebSite Tools.lnk = ?
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: ChatSpace Full Java Client 3.1.0.235 - http://chatway.hostxpro.net:8000/Java/cfs31235.cab
    O16 - DPF: HushEncryptionEngine - https://mailserver1.hushmail.com/sha...tionEngine.cab
    O16 - DPF: morfit3dWorld - http://www.3dstate.com/download/plug...fit3dWorld.CAB
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab27571.cab
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {356E71A0-B0F1-4AF7-877C-A4E9B4D6BED5} (RWViewer Control) - http://www.radishworks.com/Viewer/RWViewer.cab
    O16 - DPF: {502D6B74-E970-47B7-A4CB-A09CC799EFE6} (Fly3D Control) - http://www.fly3d.com.br/ocx/flyActiveX.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/295bbbf9...p/RdxIE601.cab
    O16 - DPF: {57712586-627E-11D2-B30B-C498B1CB6A7A} (SummitOCX) - http://www.summit3d.com/summitocx.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1093407920781
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {854CE4DE-C85D-483C-9337-C1692E66ADCE} (pPan3d Control) - http://www.paralelo.com.br/pan3d/pPan3d.cab
    O16 - DPF: {8C548F0C-0193-11D5-8929-0080AD303E97} (Miner3D Viewer) - http://miner3d.com/m3Dsite/miner3D.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab27571.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/sof...iveXPlugin.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab32846.cab
    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
    O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/...ler/dwnldr.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Instal...sinstaller.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F2F31625-8AD4-44C1-B33F-F3DE0E4F3EF7}: NameServer = 142.161.130.155 142.161.2.155
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Softex OmniPass Service - Unknown - C:\Program Files\Softex\OmniPass\Omniserv.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    Finally, if I get IE working, then occasionally it will crash for 2-5 seconds while I'm writing something. This happened while I was writing this post.
    Any help is greatly appreciated!

  2. #2
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    You should post your HiJack This log in the Spyware/ Viruses Section for reading.

    In this thread you can relate any error messages you get.
    From the blue screen Stop Errors?
    or from the Event Viewer
    Start > Run > eventvwr.msc
    Look for Red X errors after opening the tabs, click on error line for details.

    Post back errors that seem to relate to a crash or just seem to be repetitive.

  3. #3
    kaput is offline Newbie
    OK, sorry.

    In the System tab, I'm getting a lot of errors for "Service Control Manager" and "DCOM." Same with "W32time." There are also plenty of warnings for "Dhcp."

  4. #4
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    with the source as well as the event ID you can search here

    http://www.eventid.net/search.asp

    or post back & we'll have a look.

    if you see a bunch that relate to a specific Time that you recognise as a crash that would pinpoint it further.

  5. #5
    kaput is offline Newbie
    Er, that was a bit hard to understand, but I think this is what you want, tell me if it isn't:

    Service Control Manager, 7000
    DCOM is unrecognized, but ID of 6005. Some times... 11:24, 11:23, 11:22
    Dhcp, 1007
    Userenv, 1517

    That help?

  6. #6
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    Did these problems just start happening?
    Any new hardware or software?
    Have you tried a Restore Point?

    Those were just general errors not leading to much.

    The next time you get a blue screen error be sure to copy all the details, #'s etc.

    Owen will comment on your log tomorrow. Perhaps that will shed some light.

    Those errors only show like this:

    Potentially any service may cause this to be recorded so there could be 1000s of variants. Missing or corrupted files, insufficient rights, missing registry entries, antivirus software, faulty hardware, software bugs and probably many other reasons may cause a service to fail in the starting process. The Service Control Manager that handles the startup of services simply records the failure.

    Message generated when a computer is configured to obtain its IP address automatically (from a DHCP server) but no DCHP server answered the request. A random IP address (within the 169.254.0.0 range) is assigned to the computer. Check the availability of a DHCP server for that segment.

    Windows saved user <user name> registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

  7. #7
    kaput is offline Newbie
    OK, I'll bring up the blue screen now. That's how bad it is, I can do it on command.

  8. #8
    chou is offline Dedicated Member
    like jephree said have these problems just started happening?

    to me it just sounds like a total spyware clog up and if i were you i would back up my files then format, if you dont feel comfortable with formatting then a thorough going over with spyware programs like ad-aware and spybot

  9. #9
    kaput is offline Newbie
    I've done that, nothing found.

  10. #10
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    Any Blue Screen errors yet?

    Is your XP a full install or OEM?

    Perhaps a Repair Install is in order?

+ Reply to Thread
Page 1 of 2 1 2 LastLast