954,157 Members — Technology Publication meets Social Media
Username:
Password:
Lost login information?
Have something to say? Contribute New Article Reply to this Article

Generic Host Process for Win32 Services has encountered a problem

I have run BITDEFENDER 2009 AD-AWARE 2008APYBOT AVG ANTI-VIRUS AND ANTI-SPYWARE MALWAREBYTES' ANTI-MALWARE and tried anything I can think of.
Any help?
I get this message when I boot up but everything works.

Malwarebytes' Anti-Malware 1.30
Database version: 1386
Windows 5.1.2600 Service Pack 3

11/22/2008 11:42:27 PM
mbam-log-2008-11-22 (23-42-27).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 300014
Time elapsed: 2 hour(s), 52 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:44:30 PM, on 11/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroTray.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.myidentitydefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.avg.com/ww.special-toolbar-first-run-tlbrf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1221429925828
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1221799765640
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP1\RpcSandraSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 12065 bytes

Let me know if there is anything, beyond reformatting WindowsXP.
Thanks in advance,
Jim

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 

You're back DaniWeb4Jim and obviously not following any advice when given. Back in September in this thread Lost All Programs List from Start Menu I gave you some information;
The ABSOLUTE RULE is ONE antivirus program.....on a computer. You are doing a "bit" better just two months later, now you only have 2 anti-virus programs running and back then you had 4 running. The rule is the very same today as it ALWAYS has been...ONE but now you are running AVG8 and BitDefender 2009
I also told you to FIX this entry with HiJackThis;
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.myidentitydefender.com/smallsearch.html
but instead you posted your log, with that still showing and left me this message before I could respond;
Here is my last log. I say it is fixed. No more problems related to that one....Judy:
MARK SOLVED I found the link.
Thanks again, Jim
I told you to fix that entry because it was associated with CyberDefender which was... at one time was listed as a Rogue anti-virus/anti-spy process because of it's false positives and the fact when something was found you would be prompted to download another pay for application for removal of these items. In checking recent reviews it still doesn't get good reviews

I truly hesitate to offer advice since it has not been followed before. This error you note should contain more information if you If you clickClick Here at the bottom of the message box, you will get some more information on possibly what file is causing the error.
The scan with MBA-M was done with an out of date program. It should always be updated before each and every scan. This program updates on a regular basis, sometimes daily or even more often. The Database version yours is showing is 1386 but the current version is now 1417.



Let me know if there is anything, beyond reformatting WindowsXP.
Thanks in advance,


Maybe follow advice given would be the place to begin.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

I am having trouble uninstalling Bitdefender because it said that I had a file missing call their support. BUT I did and do follow your advice, not a fair statement.
You sent or DANIWEB sent me a message and when I opened DANIWEB it did not show your message and I looked on your posts yesterday and did not find that one you mention?
Now this gives me a gray rectangular message that (Can I email it to you?=?=email?) That is annoying as heck.
Sorry you are right I did not update it but I ran and updated b4 and nothing shows I will try again. Thanks and really I enjoy getting your help and did follow you info but tried another antivirus without turning of the other.

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 
You sent or DANIWEB sent me a message and when I opened DANIWEB it did not show your message and I looked on your posts yesterday and did not find that one you mention?


Not certain which one you are talking about here, I noted several. Here is the post number from your previous thread for each one that I noted;
Post # 8: The ABSOLUTE RULE is ONE antivirus program.....on a computer.
I also told you to FIX this entry with HiJackThis;Post #16:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.myidentitydefender.com/smallsearch.html
I told you to fix that entry because it was associated with CyberDefender which was...Post #8
...at one time was listed as a Rogue anti-virus/anti-spy process because of it's false positives and the fact when something was found you would be prompted to download another pay for application for removal of these items. In checking recent reviews it still doesn't get good reviews

Now if BitDefender 2009 cannot be uninstalled because it is missing a file. Try using the BitDefender Uninstall Tool
Now this gives me a gray rectangular message that (Can I email it to you?=?=email?) That is annoying as heck.
What is giving you a gray rectangular message? Are you saying you want to email it to me or is the message saying that?

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

JHolland1964 can we chat and is there an email that I can add a pdf?
I will send you a screen print of the message. I have already tried Bill Gates fix which is Microsoft's Hot fix that is more than 3 years old and said to only happen with SP2. I am running SP3 so they loose. I ran all of the ANTI-MAL-SPYWARE-VIRUS anyone suggested. Puzzle is on another site a guy said he reformated and reinstalled Win XP and the message came back after he installed SP3 and Microsoft updates.
Jim

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 
I have already tried Bill Gates fix which is Microsoft's Hot fix that is more than 3 years old


Yes I have seen that also.
Look at my attachments so that you see what you need to click on and what we must see. What we have to know is the actual process that is causing the error. That is what I have clumsily outlined in the second attachement.

We need to know this because the 1st error notification box is just telling you that Generic Host Process for Win32 Services is having a problem. The Generic Host Process for Win32 is
Svchost.exe. If you look at the Windows XP process list in Task Manager , you will notice at several Svchost.exe processes: some running under the SYSTEM account (sometimes referred to as LocalSystem) and some running under two new service accounts: NETWORK SERVICE and LOCAL SERVICE. You may very well have more showing, that is ok. Svchost.exe. does exactly what the name implies, it HOSTS the services on the computer. So just this generic error won't tell us anything, we need to know the particulars of the specific error, that is why you have to look in the info and see what specific process or processes are causing the errors.

Attachments error_info_1.jpg 34.25KB error_info_2.jpg 50.09KB
jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

Yes I have seen that also.
Look at my attachments so that you see what you need to click on and what we must see. What we have to know is the actual process that is causing the error. That is what I have clumsily outlined in the second attachement.

We need to know this because the 1st error notification box is just telling you that Generic Host Process for Win32 Services is having a problem. The Generic Host Process for Win32 is
Svchost.exe. If you look at the Windows XP process list in Task Manager , you will notice at several Svchost.exe processes: some running under the SYSTEM account (sometimes referred to as LocalSystem) and some running under two new service accounts: NETWORK SERVICE and LOCAL SERVICE. You may very well have more showing, that is ok. Svchost.exe. does exactly what the name implies, it HOSTS the services on the computer. So just this generic error won't tell us anything, we need to know the particulars of the specific error, that is why you have to look in the info and see what specific process or processes are causing the errors.



See attachment

Attachments Generic_Host_Process_for_Win32_Services_has_encountered_a_problem.3msgs_.pdf (47.06KB)
DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 

Thanks for the uninstall link Bitdefender uninstalled

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 
Thanks for the uninstall link Bitdefender uninstalled


Good! Lots of times the anti-virus programs can be very stubborn on removal.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

Out curiosity Jim, how big is the hard drive and how much RAM is installed on this error producing computer?
Judy

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

I have a Clone I build it is a :
INTEL PENTIUM 4 - 2.66 Ghz
2.0 Gig of RAM
1 - WD 80 Gig HD
1 - WD250 Gig HD

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 

Ok. Thanks. Will get back with you ASAP.
Judy

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 
Ok. Thanks. Will get back with you ASAP.
Judy


You mentioned things I should not run I thought I turned off a lot can you send me my log and put your suggestions to stop running in RED.
Thanks
Jim

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 
You mentioned things I should not run I thought I turned off a lot can you send me my log and put your suggestions to stop running in RED.
Thanks
Jim


A question first before I give the list. I notice this entry on your HJT log;O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present Did you place these?
I only ask because, according to HJT guidelines;
This section corresponds to an Administrative lock down for changing the options or homepage in Internet explorer by changing certain settings in the registry.
These options should only appear if your administrator set them on purpose or if you used Spybots Home Page and Option Lock down features in the Mode -> Advanced Mode -> Tools -> IE Tweaks section.


Now here are the items I see in your HJT log which are either running as a Start up program or running at Start up via services and are not really required to run at start up;Google Desktop Search>>> supposedly, this is "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks". This program is not required to start automatically as you can run it when you need to. It is advised that you disable this program so that it does not take up necessary resources.

Windows Defender>>>this is users choice. I use only SpywareBlaster, which DOES NOT run in the background and find it's protection superior to those programs which must actually RUN.

NvCplDaemon
>>>Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card. User's choice

AppleSyncNotifier>>>Added by Apple's MobileMe synchronization software. This service helps to synchronize contact, email, and calendar information between your ITouch, iPhone, Mac, and PC.

QuickTime Task>>>System Tray access to Apple's "Quick Time" viewer from version 5 onwards. Not required
iTunesHelper>>>Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory. If disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times but it CAN be disabled if you want.

MSMSGS>>>Windows Messenger utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. This is NOT an IM program.

Microsoft Office Shortcut Bar>>> Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly

ctfmon.exe>>>CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features.

The noted below can be turned off by going to Start, Control Panel, Administrative Tools, Services. In Services they are listed in alphabetical order. Scroll through the list and double click on entries you wish to turn off. When the property box of the service opens if it is running Stop the service by clicking the Stop button. Once the service is stopped then go up to Start up type and click the little arrow next to the start type listing. You can either disable entirely or set it to manual. I will list recommended setting.

Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe>>>Disabled.

Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe Used by iTunes to communicate with the Apple iPhone when it is connected to your computer. If you use all these then set to Manual. If you know you don't use this service then Disable it.

Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe The Bonjour Service is typically installed with the iTunes software. Apple's site describes: "Bonjour, also known as zero-configuration networking. It is NOT needed to run automatically and can be set to Manual.

Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe I noted this above. Not needed.

Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe This service is used by Itunes for using your Ipod. If you do not use Itunes you can disable this service

Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe Java Quick Starter (JQS) improves the initial startup time of Java applets and applications. But I found that it made very little difference and when I turned this off my Firefox especially loaded pages faster, why? I don't know but it did and have not noticed ANY problems with java at all.

Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe. These types of programs generally are not needed. Myself and many others just don't see the benefit of running these. Your choice

Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe AdAware. It is recommended that you remove this program. Considered foistware as it comes bundled with other items such as AOL Instant Messenger, etc. This should be Uninstalled via Add/Remove.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

Judy:
I am going to research and turn off some of these things and I will be back at you. You have a lot of good points When did you start doing this and where did you get all the knowledge about the programs. Is there a book that has some of the errors and could you recommend one?
Thanks again.
Jim

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 

A question first before I give the list. I notice this entry on your HJT log;
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present Did you place these?
I only ask because, according to HJT guidelines;

Now here are the items I see in your HJT log which are either running as a Start up program or running at Start up via services and are not really required to run at start up;

Google Desktop Search>>> supposedly, this is "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks". This program is not required to start automatically as you can run it when you need to. It is advised that you disable this program so that it does not take up necessary resources.

Windows Defender>>>this is users choice. I use only SpywareBlaster, which DOES NOT run in the background and find it's protection superior to those programs which must actually RUN.

NvCplDaemon
>>>Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card. User's choice

AppleSyncNotifier>>>Added by Apple's MobileMe synchronization software. This service helps to synchronize contact, email, and calendar information between your ITouch, iPhone, Mac, and PC.

QuickTime Task>>>System Tray access to Apple's "Quick Time" viewer from version 5 onwards. Not required
iTunesHelper>>>Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory. If disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times but it CAN be disabled if you want.

MSMSGS>>>Windows Messenger utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. This is NOT an IM program.

Microsoft Office Shortcut Bar>>> Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly

ctfmon.exe>>>CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features.

The noted below can be turned off by going to Start, Control Panel, Administrative Tools, Services. In Services they are listed in alphabetical order. Scroll through the list and double click on entries you wish to turn off. When the property box of the service opens if it is running Stop the service by clicking the Stop button. Once the service is stopped then go up to Start up type and click the little arrow next to the start type listing. You can either disable entirely or set it to manual. I will list recommended setting.

Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe>>>Disabled.

Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe Used by iTunes to communicate with the Apple iPhone when it is connected to your computer. If you use all these then set to Manual. If you know you don't use this service then Disable it.

Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe The Bonjour Service is typically installed with the iTunes software. Apple's site describes: "Bonjour, also known as zero-configuration networking. It is NOT needed to run automatically and can be set to Manual.

Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe I noted this above. Not needed.

Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe This service is used by Itunes for using your Ipod. If you do not use Itunes you can disable this service

Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe Java Quick Starter (JQS) improves the initial startup time of Java applets and applications. But I found that it made very little difference and when I turned this off my Firefox especially loaded pages faster, why? I don't know but it did and have not noticed ANY problems with java at all.

Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe. These types of programs generally are not needed. Myself and many others just don't see the benefit of running these. Your choice

Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe AdAware. It is recommended that you remove this program. Considered foistware as it comes bundled with other items such as AOL Instant Messenger, etc. This should be Uninstalled via Add/Remove.



Thanks for all of this but I have one problem. Lately all of my links to uninstall my programs were gone. I did not remove them. I installed and then uninstalled a program and some worked. You gave me the BitDefender uninstall help but the one you said I did not do was CyberDefender so I did follow most of your suggestions.
I am going to try to do most of the red are true but some as you said are my choice I have to check what happens to everything I use when I turn of something.
Thanks for that. I still want to know where you learned all of this. It as if you are on a HELP DESK.
What does work instead of AD-Aware? My techie friend is a PC engineer and he only used AVG FREE 8.0 ANTI-VIRUS, AD-AWARE2008 and SPY BOT 1.6. And he makes a lot of money doing it. What do you suggest? as alternative programs
Jim

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 
What does work instead of AD-Aware? My techie friend is a PC engineer and he only used AVG FREE 8.0 ANTI-VIRUS, AD-AWARE2008 and SPY BOT 1.6. And he makes a lot of money doing it. What do you suggest? as alternative programs
Jim

I still use SpyBot 1.6, NOT the TeaTimer portion however.
I quit using AdAware when it went to this new version AdAware 2008 was that this AdAware Service was put in there and runs in the background but as I understand it with the FREE version this actually does nothing. You have to have the paid version for it to do what it is supposed to do. Here is what I found when reading various reviews of this newer version;One of the installation options that appears to be available even for Free users -- maintaining a constant scanner in the system tray, like a real anti-virus program -- forces the Free edition to respond later with a warning that the option isn't actually available.
Yes, this service can be turned off, but why have it anyway? Plus, I want to KNOW what I am going to install and what comes with it and does it work? When I found it was doing nothing I first disabled that service and kept the program, but then finally decided this newer version didn't work as well as the older one.
Plus I have found, like many others, that the free version ofMalwarebytes' Anti-Malware has updates more often, sometimes more than once a day, and finds, fixes and removes more. Yes, it must be manually updated because I use the Free version but it only takes a few seconds. So I uninstalled AdAware 2008 and now use MBA-M for scanning and removal, though it is extremely rare anything is found (I believe I have found only one or two items with it in all the months I have had it) because of the next program I write about. For protection from spyware, adware, browser hijackers, dialers, preventing the installing of ActiveX based spyware, blocking tracking cookies and an excellent restricted sites protection I use SpywareBlaster , which I have used for several years now and honestly wouldn't run a computer without it installed. The key thing about this program is that it DOES NOT run in the background and consume needed resources. I can honestly say that since I began using this program several years ago I have not had more than one or two tracking cookies on the computer, I have had very little spyware, if any at all on the computer, and I do have grandkids who occasionally visit and use the computer. Plus, when researching entries in people's various logs I have "traveled to parts unknown" to check out a website showing in the log and very often my browser will go "nowhere". I will check in the SpywareBlaster Restricted sites list and sure enough there it will be. So I know it works.
Judy

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

I got rid of the problem with a neat tool SDFix.exe I am zipping and sending it to you via your private email later. . But maybe it was the TREND HOUSECALL AND the intense TREND MICRO SECURITY SYSTEM CLEANER. I ran both and it cleaned out many of my KeyGens but I will look for them again. A key generator that is used by the company if you call and loose your code. I have a few programs that I did buy and lost the code so I do use them. I am rebooting to prove that it is gone but it must have been one of them that had a backdoor Trojan virus.
Thanks for all of your help. I will review my opinion of AD-Aware but I do use Spy-Bot without TEA-Timer also What ANTIVIRUS DO YOU USE. I use AVG Free 8.0 and it works well.

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 

SDFix is a tool used here quite often. We are very familiar with it. I use Antivir for my anti-virus program. I also use Spybot without TeaTimer and also MBA-M is now in my regular arsenal. Of course SpywareBlaster is a key program also.
Judy

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

Problem NOT solved, yet.
I rebooted and it is back, grrrrrrrrrrrrrrr
I am about to reinstall the whole thing, but, someone said it came back with the updates.
Sending you the messages via email

DaniWeb4Jim
Junior Poster
150 posts since Sep 2008
Reputation Points: 15
Solved Threads: 0
 

This article has been dead for over three months

Post: Markdown Syntax: Formatting Help
You