Spybot Search & Destroy freezes computer about 3/4 through

G

Gerry Cornell

Tex

I would forget about running Spybot in normal mode. You will get
problems if it tries to remove a file whilst it is in use. Run Spybot in
Safe Mode. However, I think it is time to look at other potential causes
of the Sims problem.

What Sims programme is causing the problems? Is it a Games or other
programme?

What video card do you have?

This freeware programme is excellent for getting information about your
computer:
Everest Home Edition (freeware)
http://www.lavalys.hu/index.php

Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to
bring Task Manager and select the Performance
Tab. What is the Total, the Commit Charge and the Peak? What RAM memory
do you have?

Another approach. Look in Event Viewer at the System and Application
logs for Error and Warning reports about the time the freeze occurs and
post copies here.

You can access Event Viewer by selecting Start, Administrative Tools,
Event Viewer. When researching the meaning of the error, information
regarding Event ID, Source and Description are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;enus;308427&Product=winxp

A tip for posting copies of Error Reports! Run Event Viewer and double
click on the error you want to copy. In the window, which appears is a
button resembling two pages. Double click the button and close Event
Viewer. Now start your message(email) and do a paste into the body of
the message. This will paste the info from the Event Viewer Error Report
complete with links into the message. Make sure this is the first paste
after exiting from Event Viewer.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~



Tex Hemke said:
Thanks Warren for the reply. I have posted the HiJackThis Log File and
found only one that they recommended fixing. Still didn't solve the
freezing
prolem. Nice site though. I will definetly use this site in the
future.
Thanks....

Warren said:
Tex - go to:
http://www.hijackthis.de/
and paste your HiJackThis log into the window and run the analyzer.
This will get you started until the forum folks get to your log.

hth,
Warren

Tex said:
Hi Duane534; Thanks for the reply. I have run the HiJackThis and
here is a
log of it:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:17 AM, on 11/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/home_page.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride =
127.0.0.1;;dynhost.inetcam.com;register.inetcam.com;;localhost;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.alberta.com/"); (C:\Program
Files\Netscape\Users\beisler1\prefs.js)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO -
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} -
C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO -
{56071E0D-C61B-11D3-B41C-00E02927A304} -
C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC]
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart
11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common
Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero
Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe
O9 - Extra button: Real.com -
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
- C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .wma: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .wmv: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers
Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl
Class) -
https://components.viewpoint.com/MT...known&unknown&unknown&unknown&unknown&unknown
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall
Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX
Control) -
http://www.ipix.com/download/ipixx.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC}
(MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
Advantage
Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper
Flags Class)
- http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec
AntiVirus
scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data
Collection
Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image
Editor
Control) -
http://www.imagestation.com/common/classes/BPImageEditor.cab?ver=1,1,0,32
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A}
(Microsoft.WinRep) -
https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl
Class) -
http://www.imagestation.com/common/classes/batchdwnl.cab?version=4,3,2,20802
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI
Utility
Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl
Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129397091163
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall
Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl
Class) -
http://www.shockwave.com/content/luxor/mjolauncher.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A}
(WildfireActiveXHost
Class) - http://www.shockwave.com/content/tumblebugs/axhost.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
(MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} -
https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} -
https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro
Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE
Class) -
http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI
Registry
Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload
Tool) -
http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime
Environment
1.4.0_01) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo
Class) -
https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune
Object) -
http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader
Object) -
http://anu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess
Object) -
http://messenger.zone.msn.com/binary/Chess.cab30149.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj
Class) -
https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader
Class) -
http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {F0230524-9D39-4E84-8452-41C592961EA7} -
http://www.4wav.com/Config.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control
4.5) -
http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire
Showdown Class)
- http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} -
C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: PCANotify -
C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec
Corporation -
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. -
C:\Program
Files\Common Files\Command Software\dvpapi.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program
Files\Common
Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA
Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program
Files\Common
Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPH11 - HP -
C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation -
C:\Program
Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony
Corporation -
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

:


Perhaps the spyware is still running, even in Safe Mode. Check out
the
program "Hijack This!"

:


Running Windows XP Home Edition, 1693 MHz Processor, 47% Free
Space on Hard
Drive. Have done Disk Cleanup and full Defragmentation. Please
assist as I am
unable to complete a Spybot - Search & Destroy because when
Running bot-check
it gets to approximately (varies slightly) 23282/31725: Gain.Gator
as then
just freezes the computer. I have to hold the power button until
it shuts
down and the restart the computer by powering up. I have run the
Ad-Aware SE
Personal with the latest definitions, run MS AntiSpyware and the
free Scan
(both virus and spyware from http://housecall.trendmicro.com/. I
can run a
complete Spybot - Search & Destroy in "Safe Mode", but always
freezes when
running it under both User Logons in "Normal" mode. Each User has
"Administrator" rights. Also WildTangent continues to show up.
Other programs
like Sims can also cause the computer to freeze. Please help. Any
suggestions
would be greatly appreciated. Thanks in advance.
 
G

Guest

Hi David; Good advice, but still freezes when running Spybotin the newly
created account. This is not the answer. Any other thoughts?
 
G

Guest

Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No immediate
Treats found". So the PC is clean, I assume. It only freezes when you run
Spybot in "Normal Mode".

"The Sims" is from a CD and is the Family Building Game from EA Games.

The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and
installed the latest Drivers Version 81.95 Released: Nov. 22, 2005.

Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit Charge
222M/1108M

The RAM is 768 MB

Event Viewer: There are no errors when the Spybot was running or when it
frooze the PC. The only one is under System after I did a reboot (Hard Boot)
and this is what it says:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 11/29/2005
Time: 10:33:03 AM
User: N/A
Computer: EISLER
Description:
The IPSEC Services service terminated with the following error:
The specified module could not be found.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



Gerry Cornell said:
Tex

I would forget about running Spybot in normal mode. You will get
problems if it tries to remove a file whilst it is in use. Run Spybot in
Safe Mode. However, I think it is time to look at other potential causes
of the Sims problem.

What Sims programme is causing the problems? Is it a Games or other
programme?

What video card do you have?

This freeware programme is excellent for getting information about your
computer:
Everest Home Edition (freeware)
http://www.lavalys.hu/index.php

Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to
bring Task Manager and select the Performance
Tab. What is the Total, the Commit Charge and the Peak? What RAM memory
do you have?

Another approach. Look in Event Viewer at the System and Application
logs for Error and Warning reports about the time the freeze occurs and
post copies here.

You can access Event Viewer by selecting Start, Administrative Tools,
Event Viewer. When researching the meaning of the error, information
regarding Event ID, Source and Description are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;enus;308427&Product=winxp

A tip for posting copies of Error Reports! Run Event Viewer and double
click on the error you want to copy. In the window, which appears is a
button resembling two pages. Double click the button and close Event
Viewer. Now start your message(email) and do a paste into the body of
the message. This will paste the info from the Event Viewer Error Report
complete with links into the message. Make sure this is the first paste
after exiting from Event Viewer.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~



Tex Hemke said:
Thanks Warren for the reply. I have posted the HiJackThis Log File and
found only one that they recommended fixing. Still didn't solve the
freezing
prolem. Nice site though. I will definetly use this site in the
future.
Thanks....

Warren said:
Tex - go to:
http://www.hijackthis.de/
and paste your HiJackThis log into the window and run the analyzer.
This will get you started until the forum folks get to your log.

hth,
Warren

Tex Hemke wrote:
Hi Duane534; Thanks for the reply. I have run the HiJackThis and
here is a
log of it:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:17 AM, on 11/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/home_page.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride =
127.0.0.1;;dynhost.inetcam.com;register.inetcam.com;;localhost;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.alberta.com/"); (C:\Program
Files\Netscape\Users\beisler1\prefs.js)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO -
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} -
C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO -
{56071E0D-C61B-11D3-B41C-00E02927A304} -
C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC]
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart
11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common
Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero
Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe
O9 - Extra button: Real.com -
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
- C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .wma: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .wmv: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers
Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl
Class) -
https://components.viewpoint.com/MT...known&unknown&unknown&unknown&unknown&unknown
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall
Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX
Control) -
http://www.ipix.com/download/ipixx.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC}
(MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
Advantage
Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper
Flags Class)
- http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec
AntiVirus
scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data
Collection
Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image
Editor
Control) -
http://www.imagestation.com/common/classes/BPImageEditor.cab?ver=1,1,0,32
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A}
(Microsoft.WinRep) -
https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl
Class) -
http://www.imagestation.com/common/classes/batchdwnl.cab?version=4,3,2,20802
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI
Utility
Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl
Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129397091163
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall
Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl
Class) -
http://www.shockwave.com/content/luxor/mjolauncher.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A}
(WildfireActiveXHost
Class) - http://www.shockwave.com/content/tumblebugs/axhost.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
(MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} -
https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} -
https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
 
G

Gerry Cornell

Tex

Start. Administrative Tools, Services and check

IPSEC Services -Is the Start Up type Automatic and the Status Started?

RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the
Status Started?

Has the Windows XP SP2 update been installed?

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~


Tex Hemke said:
Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No
immediate
Treats found". So the PC is clean, I assume. It only freezes when you
run
Spybot in "Normal Mode".

"The Sims" is from a CD and is the Family Building Game from EA Games.

The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and
installed the latest Drivers Version 81.95 Released: Nov. 22, 2005.

Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit
Charge
222M/1108M

The RAM is 768 MB

Event Viewer: There are no errors when the Spybot was running or when
it
frooze the PC. The only one is under System after I did a reboot (Hard
Boot)
and this is what it says:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 11/29/2005
Time: 10:33:03 AM
User: N/A
Computer: EISLER
Description:
The IPSEC Services service terminated with the following error:
The specified module could not be found.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



Gerry Cornell said:
Tex

I would forget about running Spybot in normal mode. You will get
problems if it tries to remove a file whilst it is in use. Run Spybot
in
Safe Mode. However, I think it is time to look at other potential
causes
of the Sims problem.

What Sims programme is causing the problems? Is it a Games or other
programme?

What video card do you have?

This freeware programme is excellent for getting information about
your
computer:
Everest Home Edition (freeware)
http://www.lavalys.hu/index.php

Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to
bring Task Manager and select the Performance
Tab. What is the Total, the Commit Charge and the Peak? What RAM
memory
do you have?

Another approach. Look in Event Viewer at the System and Application
logs for Error and Warning reports about the time the freeze occurs
and
post copies here.

You can access Event Viewer by selecting Start, Administrative Tools,
Event Viewer. When researching the meaning of the error, information
regarding Event ID, Source and Description are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;enus;308427&Product=winxp

A tip for posting copies of Error Reports! Run Event Viewer and
double
click on the error you want to copy. In the window, which appears is
a
button resembling two pages. Double click the button and close Event
Viewer. Now start your message(email) and do a paste into the body of
the message. This will paste the info from the Event Viewer Error
Report
complete with links into the message. Make sure this is the first
paste
after exiting from Event Viewer.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~



Tex Hemke said:
Thanks Warren for the reply. I have posted the HiJackThis Log File
and
found only one that they recommended fixing. Still didn't solve the
freezing
prolem. Nice site though. I will definetly use this site in the
future.
Thanks....

:

Tex - go to:
http://www.hijackthis.de/
and paste your HiJackThis log into the window and run the
analyzer.
This will get you started until the forum folks get to your log.

hth,
Warren

Tex Hemke wrote:
Hi Duane534; Thanks for the reply. I have run the HiJackThis and
here is a
log of it:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:17 AM, on 11/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Zero Knowledge\TELUS Security
service\Freedom.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/home_page.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride =
127.0.0.1;;dynhost.inetcam.com;register.inetcam.com;;localhost;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.alberta.com/"); (C:\Program
Files\Netscape\Users\beisler1\prefs.js)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO -
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} -
C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO -
{56071E0D-C61B-11D3-B41C-00E02927A304} -
C:\Program Files\Zero Knowledge\TELUS Security
service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC]
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart
11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common
Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero
Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM -
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe
O9 - Extra button: Real.com -
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
- C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .wma: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .wmv: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers
Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl
Class) -
https://components.viewpoint.com/MT...known&unknown&unknown&unknown&unknown&unknown
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall
Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX
Control) -
http://www.ipix.com/download/ipixx.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC}
(MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows
Genuine
Advantage
Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper
Flags Class)
- http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec
AntiVirus
scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft
Data
Collection
Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image
Editor
Control) -
http://www.imagestation.com/common/classes/BPImageEditor.cab?ver=1,1,0,32
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A}
(Microsoft.WinRep) -
https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33}
(ZingBatchAXDwnl
Class) -
http://www.imagestation.com/common/classes/batchdwnl.cab?version=4,3,2,20802
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec
RuFSI
Utility
Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl
Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129397091163
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall
Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A}
(MJLauncherCtrl
Class) -
http://www.shockwave.com/content/luxor/mjolauncher.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A}
(WildfireActiveXHost
Class) - http://www.shockwave.com/content/tumblebugs/axhost.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
(MessengerStatsClient
Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} -
https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} -
https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
 
G

Guest

Hi Gerry; The IPSEC Services is not running. The Startup Type is set to
"Automatic". I tried to start the service and got this error meesge:
Could not start the IPSEC Service on Local Computer.
Error 126: The specified module could not be found.
Is there a fix for this?

Gerry Cornell said:
Tex

Start. Administrative Tools, Services and check

IPSEC Services -Is the Start Up type Automatic and the Status Started?

RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the
Status Started?

Has the Windows XP SP2 update been installed?

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~


Tex Hemke said:
Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No
immediate
Treats found". So the PC is clean, I assume. It only freezes when you
run
Spybot in "Normal Mode".

"The Sims" is from a CD and is the Family Building Game from EA Games.

The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and
installed the latest Drivers Version 81.95 Released: Nov. 22, 2005.

Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit
Charge
222M/1108M

The RAM is 768 MB

Event Viewer: There are no errors when the Spybot was running or when
it
frooze the PC. The only one is under System after I did a reboot (Hard
Boot)
and this is what it says:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 11/29/2005
Time: 10:33:03 AM
User: N/A
Computer: EISLER
Description:
The IPSEC Services service terminated with the following error:
The specified module could not be found.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



Gerry Cornell said:
Tex

I would forget about running Spybot in normal mode. You will get
problems if it tries to remove a file whilst it is in use. Run Spybot
in
Safe Mode. However, I think it is time to look at other potential
causes
of the Sims problem.

What Sims programme is causing the problems? Is it a Games or other
programme?

What video card do you have?

This freeware programme is excellent for getting information about
your
computer:
Everest Home Edition (freeware)
http://www.lavalys.hu/index.php

Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to
bring Task Manager and select the Performance
Tab. What is the Total, the Commit Charge and the Peak? What RAM
memory
do you have?

Another approach. Look in Event Viewer at the System and Application
logs for Error and Warning reports about the time the freeze occurs
and
post copies here.

You can access Event Viewer by selecting Start, Administrative Tools,
Event Viewer. When researching the meaning of the error, information
regarding Event ID, Source and Description are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;enus;308427&Product=winxp

A tip for posting copies of Error Reports! Run Event Viewer and
double
click on the error you want to copy. In the window, which appears is
a
button resembling two pages. Double click the button and close Event
Viewer. Now start your message(email) and do a paste into the body of
the message. This will paste the info from the Event Viewer Error
Report
complete with links into the message. Make sure this is the first
paste
after exiting from Event Viewer.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~



Thanks Warren for the reply. I have posted the HiJackThis Log File
and
found only one that they recommended fixing. Still didn't solve the
freezing
prolem. Nice site though. I will definetly use this site in the
future.
Thanks....

:

Tex - go to:
http://www.hijackthis.de/
and paste your HiJackThis log into the window and run the
analyzer.
This will get you started until the forum folks get to your log.

hth,
Warren

Tex Hemke wrote:
Hi Duane534; Thanks for the reply. I have run the HiJackThis and
here is a
log of it:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:17 AM, on 11/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Zero Knowledge\TELUS Security
service\Freedom.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/home_page.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride =
127.0.0.1;;dynhost.inetcam.com;register.inetcam.com;;localhost;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.alberta.com/"); (C:\Program
Files\Netscape\Users\beisler1\prefs.js)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO -
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} -
C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO -
{56071E0D-C61B-11D3-B41C-00E02927A304} -
C:\Program Files\Zero Knowledge\TELUS Security
service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC]
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart
11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common
Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero
Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://C:\Program
 
G

Guest

Yes the Windows XP Home Edition Service Pack has been installed and all
Microsoft Updates.....

Gerry Cornell said:
Tex

Start. Administrative Tools, Services and check

IPSEC Services -Is the Start Up type Automatic and the Status Started?

RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the
Status Started?

Has the Windows XP SP2 update been installed?

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~


Tex Hemke said:
Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No
immediate
Treats found". So the PC is clean, I assume. It only freezes when you
run
Spybot in "Normal Mode".

"The Sims" is from a CD and is the Family Building Game from EA Games.

The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and
installed the latest Drivers Version 81.95 Released: Nov. 22, 2005.

Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit
Charge
222M/1108M

The RAM is 768 MB

Event Viewer: There are no errors when the Spybot was running or when
it
frooze the PC. The only one is under System after I did a reboot (Hard
Boot)
and this is what it says:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 11/29/2005
Time: 10:33:03 AM
User: N/A
Computer: EISLER
Description:
The IPSEC Services service terminated with the following error:
The specified module could not be found.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



Gerry Cornell said:
Tex

I would forget about running Spybot in normal mode. You will get
problems if it tries to remove a file whilst it is in use. Run Spybot
in
Safe Mode. However, I think it is time to look at other potential
causes
of the Sims problem.

What Sims programme is causing the problems? Is it a Games or other
programme?

What video card do you have?

This freeware programme is excellent for getting information about
your
computer:
Everest Home Edition (freeware)
http://www.lavalys.hu/index.php

Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to
bring Task Manager and select the Performance
Tab. What is the Total, the Commit Charge and the Peak? What RAM
memory
do you have?

Another approach. Look in Event Viewer at the System and Application
logs for Error and Warning reports about the time the freeze occurs
and
post copies here.

You can access Event Viewer by selecting Start, Administrative Tools,
Event Viewer. When researching the meaning of the error, information
regarding Event ID, Source and Description are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;enus;308427&Product=winxp

A tip for posting copies of Error Reports! Run Event Viewer and
double
click on the error you want to copy. In the window, which appears is
a
button resembling two pages. Double click the button and close Event
Viewer. Now start your message(email) and do a paste into the body of
the message. This will paste the info from the Event Viewer Error
Report
complete with links into the message. Make sure this is the first
paste
after exiting from Event Viewer.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~



Thanks Warren for the reply. I have posted the HiJackThis Log File
and
found only one that they recommended fixing. Still didn't solve the
freezing
prolem. Nice site though. I will definetly use this site in the
future.
Thanks....

:

Tex - go to:
http://www.hijackthis.de/
and paste your HiJackThis log into the window and run the
analyzer.
This will get you started until the forum folks get to your log.

hth,
Warren

Tex Hemke wrote:
Hi Duane534; Thanks for the reply. I have run the HiJackThis and
here is a
log of it:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:17 AM, on 11/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Zero Knowledge\TELUS Security
service\Freedom.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/home_page.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride =
127.0.0.1;;dynhost.inetcam.com;register.inetcam.com;;localhost;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.alberta.com/"); (C:\Program
Files\Netscape\Users\beisler1\prefs.js)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO -
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} -
C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO -
{56071E0D-C61B-11D3-B41C-00E02927A304} -
C:\Program Files\Zero Knowledge\TELUS Security
service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC]
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart
11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common
Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero
Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://C:\Program
 
G

Guest

Yes the RPC (Remote Procedure Call ) is set as Start Up type Automatic and is
started.

Gerry Cornell said:
Tex

Start. Administrative Tools, Services and check

IPSEC Services -Is the Start Up type Automatic and the Status Started?

RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the
Status Started?

Has the Windows XP SP2 update been installed?

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~


Tex Hemke said:
Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No
immediate
Treats found". So the PC is clean, I assume. It only freezes when you
run
Spybot in "Normal Mode".

"The Sims" is from a CD and is the Family Building Game from EA Games.

The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded and
installed the latest Drivers Version 81.95 Released: Nov. 22, 2005.

Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480 Commit
Charge
222M/1108M

The RAM is 768 MB

Event Viewer: There are no errors when the Spybot was running or when
it
frooze the PC. The only one is under System after I did a reboot (Hard
Boot)
and this is what it says:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 11/29/2005
Time: 10:33:03 AM
User: N/A
Computer: EISLER
Description:
The IPSEC Services service terminated with the following error:
The specified module could not be found.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



Gerry Cornell said:
Tex

I would forget about running Spybot in normal mode. You will get
problems if it tries to remove a file whilst it is in use. Run Spybot
in
Safe Mode. However, I think it is time to look at other potential
causes
of the Sims problem.

What Sims programme is causing the problems? Is it a Games or other
programme?

What video card do you have?

This freeware programme is excellent for getting information about
your
computer:
Everest Home Edition (freeware)
http://www.lavalys.hu/index.php

Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete to
bring Task Manager and select the Performance
Tab. What is the Total, the Commit Charge and the Peak? What RAM
memory
do you have?

Another approach. Look in Event Viewer at the System and Application
logs for Error and Warning reports about the time the freeze occurs
and
post copies here.

You can access Event Viewer by selecting Start, Administrative Tools,
Event Viewer. When researching the meaning of the error, information
regarding Event ID, Source and Description are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;enus;308427&Product=winxp

A tip for posting copies of Error Reports! Run Event Viewer and
double
click on the error you want to copy. In the window, which appears is
a
button resembling two pages. Double click the button and close Event
Viewer. Now start your message(email) and do a paste into the body of
the message. This will paste the info from the Event Viewer Error
Report
complete with links into the message. Make sure this is the first
paste
after exiting from Event Viewer.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~



Thanks Warren for the reply. I have posted the HiJackThis Log File
and
found only one that they recommended fixing. Still didn't solve the
freezing
prolem. Nice site though. I will definetly use this site in the
future.
Thanks....

:

Tex - go to:
http://www.hijackthis.de/
and paste your HiJackThis log into the window and run the
analyzer.
This will get you started until the forum folks get to your log.

hth,
Warren

Tex Hemke wrote:
Hi Duane534; Thanks for the reply. I have run the HiJackThis and
here is a
log of it:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:17 AM, on 11/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Zero Knowledge\TELUS Security
service\Freedom.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mytelus.com/home_page.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride =
127.0.0.1;;dynhost.inetcam.com;register.inetcam.com;;localhost;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.alberta.com/"); (C:\Program
Files\Netscape\Users\beisler1\prefs.js)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO -
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} -
C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO -
{56071E0D-C61B-11D3-B41C-00E02927A304} -
C:\Program Files\Zero Knowledge\TELUS Security
service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC]
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart
11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common
Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero
Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://C:\Program
 
G

Gerry Cornell

Tex

Try the instructions in this link:
http://snipurl.com/kcay

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~

Tex Hemke said:
Hi Gerry; The IPSEC Services is not running. The Startup Type is set
to
"Automatic". I tried to start the service and got this error meesge:
Could not start the IPSEC Service on Local Computer.
Error 126: The specified module could not be found.
Is there a fix for this?

Gerry Cornell said:
Tex

Start. Administrative Tools, Services and check

IPSEC Services -Is the Start Up type Automatic and the Status
Started?

RPC (Remote Procedure Call ) -Is the Start Up type Automatic and the
Status Started?

Has the Windows XP SP2 update been installed?

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~


Tex Hemke said:
Hi Gerry; I have run the Spybot in "Safe Mode" and it reports "No
immediate
Treats found". So the PC is clean, I assume. It only freezes when
you
run
Spybot in "Normal Mode".

"The Sims" is from a CD and is the Family Building Game from EA
Games.

The Video Card is a "NVIDIA GeForce3 Ti200 which I have downloaded
and
installed the latest Drivers Version 81.95 Released: Nov. 22, 2005.

Commit Charge (K) Total: 227728, Limit: 1134932, Peak: 320480
Commit
Charge
222M/1108M

The RAM is 768 MB

Event Viewer: There are no errors when the Spybot was running or
when
it
frooze the PC. The only one is under System after I did a reboot
(Hard
Boot)
and this is what it says:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 11/29/2005
Time: 10:33:03 AM
User: N/A
Computer: EISLER
Description:
The IPSEC Services service terminated with the following error:
The specified module could not be found.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



:

Tex

I would forget about running Spybot in normal mode. You will get
problems if it tries to remove a file whilst it is in use. Run
Spybot
in
Safe Mode. However, I think it is time to look at other potential
causes
of the Sims problem.

What Sims programme is causing the problems? Is it a Games or
other
programme?

What video card do you have?

This freeware programme is excellent for getting information about
your
computer:
Everest Home Edition (freeware)
http://www.lavalys.hu/index.php

Another thing to do. Try the "Sims" and then Try Ctrl+Alt+Delete
to
bring Task Manager and select the Performance
Tab. What is the Total, the Commit Charge and the Peak? What RAM
memory
do you have?

Another approach. Look in Event Viewer at the System and
Application
logs for Error and Warning reports about the time the freeze
occurs
and
post copies here.

You can access Event Viewer by selecting Start, Administrative
Tools,
Event Viewer. When researching the meaning of the error,
information
regarding Event ID, Source and Description are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;enus;308427&Product=winxp

A tip for posting copies of Error Reports! Run Event Viewer and
double
click on the error you want to copy. In the window, which appears
is
a
button resembling two pages. Double click the button and close
Event
Viewer. Now start your message(email) and do a paste into the body
of
the message. This will paste the info from the Event Viewer Error
Report
complete with links into the message. Make sure this is the first
paste
after exiting from Event Viewer.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~



Thanks Warren for the reply. I have posted the HiJackThis Log
File
and
found only one that they recommended fixing. Still didn't solve
the
freezing
prolem. Nice site though. I will definetly use this site in the
future.
Thanks....

:

Tex - go to:
http://www.hijackthis.de/
and paste your HiJackThis log into the window and run the
analyzer.
This will get you started until the forum folks get to your
log.

hth,
Warren

Tex Hemke wrote:
Hi Duane534; Thanks for the reply. I have run the HiJackThis
and
here is a
log of it:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:17 AM, on 11/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft
Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Zero Knowledge\TELUS Security
service\Freedom.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page =
http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page =
http://www.mytelus.com/home_page.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride =
127.0.0.1;;dynhost.inetcam.com;register.inetcam.com;;localhost;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.alberta.com/"); (C:\Program
Files\Netscape\Users\beisler1\prefs.js)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO -
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} -
C:\Program Files\Zero Knowledge\TELUS Security
service\pkR.dll
O2 - BHO: (no name) -
{53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO -
{56071E0D-C61B-11D3-B41C-00E02927A304} -
C:\Program Files\Zero Knowledge\TELUS Security
service\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google -
{2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC]
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart
11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CM-SmWizard]
C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common
Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TELUS Security service] C:\Program
Files\Zero
Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program
Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages -
res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://C:\Program
 
G

Guest

Hi Gerry; I don't follow you. I have a valid IP Address so I don't know how
this would help with IPSEC Services not "Started". I can surf the web and
receive e-mails so the IP is working even though IPSEC Services is not
working. Confused....
 
G

Gerry Cornell

Tex

I will take a second opinion and come back.

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~
 
G

Gerry Cornell

Tex

Is this a standalone or networked computer. Is it connected to the
internet through a Router or ?

--


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~
 
G

Gerry Cornell

Tex

Try Start, Administrative Tools, Services, double-click IPSEC services
and change the StartUp type to Manual. Watch for any complaints from the
system and check after 2/3 days whether error reports have ceased.

The conclusion is that your system set up does not require the IPSEC
service. The change will test out whether this presumption is correct.


Hope this helps.

Gerry
~~~~~~~~~~~~~~~~~~~~~~~~
FCA

Using invalid email address

Stourport, Worcs, England
Enquire, plan and execute.
~~~~~~~~~~~~~~~~~~~~~~~~
Please tell the newsgroup how any
suggested solution worked for you.



~~~~~~~~~~~~~~~~~~~~~~~~
 
G

Guest

Hi Gerry; Unfortunately I had to take the computer back to my friend's house.
I do appreciate the help you have suggested. It still freezes when running
Spybot, but works for e-mail and surfing the web. I will keep looking at this
tread for further answers and try them by using "pcAnywhere" to apply these
suggestions. Thanks again for all your help. Maybe this is one that just
can't be fixed. I don't know....
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top