Solved XP freezing constantly

Discussion in 'Windows XP' started by CaliGirlnGA, Jul 7, 2012.


Thread Status:
Not open for further replies.
  1. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    Okay thank you again Malnutrition for your help and patients with me. I'm doing these steps now as well as downloading Avira.

  2. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,736
    Likes Received:
    718
    My System
    Loading...
    If you have already run the AVG removal tool then just hold up on downloading Avira and go ahead and run the Eset scan then install Avira/.
  3. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    Will do. :) I ran the tweaking software, rebooted and it's complete now.I'll start the Eset scan and then download Avira. Thank you again as always.
  4. Google Advertisement

  5. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,736
    Likes Received:
    718
    My System
    Loading...
    A couple more things to do when you have finished the eset scan and the download of Avira.

    Download the program below unzip it to your desktop and set it to run on the next boot.
    http://technet.microsoft.com/en-us/sysinternals/bb897426.aspx


    Then clear all of your restore points and create a new one you can do this by turning off system restore and rebooting and turning it back on and rebooting again.
    http://support.microsoft.com/kb/310405

    Then download Erunt and create a backup of your registry and then download ntregopt and run it and then reboot.
    http://www.larshederer.homepage.t-online.de/erunt/

    Now defrag your machine with auslogics select defrag and optimize just uncheck the boxes in the shot below when installing auslogics disk defrag.
    http://www.auslogics.com/en/downloads/disk-defrag/disk-defrag-setup.exe

    defrag warning.JPG

    Now give your machine a good cleaning and re-seat the hardware.
    Unplug the tower open up the side.Get can of compressed air and blow out the machine and reseat the ram modules video card etc,see video Plug it back in and see how it goes.WHILE YOU HAVE THE RAM AND VIDEO CARD OUT BLOW OUT THE SLOTS THAT THEY PLUG INTO.ALSO BLOW OUT THE HEAT SINK.SEE VIDEO






    Edit: Do not use a Vaccum or an Air Compressor !!!!!!!! Only Canned Air
    CaliGirlnGA likes this.
  6. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    Awesome will do all that as well. With all this great information something has to give huh. lol ;) I am running the ESET scan now it's just at 31% so may take a while but no biggie. I'll get right on to your last post as soon as it's complete. Thank you so very much!
    Malnutrition likes this.
  7. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    Hi Malnutrition.I used the defrag tool and it found 86 junk files but when I tried to delete them it open another window this one http://www.auslogics.com/en/cpages/softwareadvice/?source=disk-defrag&reason=junkfiles and I downloaded it but at the end it said you have to pay in order to get all of them removed. Also 41 registry errors were found and this site opened http://www.auslogics.com/en/cpages/softwareadvice/?source=disk-defrag&reason=registry and I was told to download this as well, which I have not yet. Do I just let that go and not clean the junk files and registry errors up? Thank you again. :)
  8. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,736
    Likes Received:
    718
    My System
    Loading...

    Only run the defrag from auslogics leave the other nonsense alone.Also Download Autoruns and Autorunsc unzip Autoruns to your desktop run it.See any entries that read file not found when you see them right click and select delete (or just simply uncheck if you do not feel comfy deleting)do this only for the entries that read file not found also uncheck any scheduled task that are set to run on your machine,close the program.

    Also let me see another hijack this log please.
  9. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    Okay I am about to start this up now. Umm...what is "hijack this log please? LOL Sorry to sound clueless, will it be from this new downloaded here or something else? :confused:
  10. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,736
    Likes Received:
    718
    My System
    Loading...

    1- Please click HERE to download HijackThis.

    2- Run the program.

    3- Click on the Main Menu button if not already there.

    4- Select Do a system scan and save a logfile.

    5- Copy and paste the scan log from Notepad into your next reply.
  11. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    OH from the Autoruns and Autorunsc is that where I find the hijack? Because I see here "Image Hijacks" is that what you need to see?
  12. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    Gotcha on to that too, thank you. :)
  13. CaliGirlnGA Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    1
    My System
    Loading...
    Here is the hijackthis log and I found numerous file not found and unchecked them. Many thank you's. :) Also an added bonus is I got to uncheck the annoying pop up from a program I deleted way back.


    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 7:05:11 PM, on 7/10/2012
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\DellSupport\brkrsvc.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Webroot\Washer\WasherSvc.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe
    C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    C:\Documents and Settings\Jody Carter\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jody Carter\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jody Carter\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Documents and Settings\Jody Carter\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jody Carter\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jody Carter\Local Settings\Application Data\Google\Update\1.3.21.111\GoogleCrashHandler.exe
    C:\Documents and Settings\Jody Carter\My Documents\Downloads\HijackThis (1).exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
    O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe" -agent
    O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe" -RESTART
    O4 - S-1-5-18 Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe (User 'Default user')
    O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://www.ehow.com
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bellsouth.net/sdccommon/download/tgctlsr.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
    O16 - DPF: {4BF2E7B7-69F4-4178-B669-257C7C8A4072} (WebCamX Control) - http://208.41.190.242:8001/WebCamX.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
    O16 - DPF: {65FDEDF3-8ED9-4F5B-825E-18C2D44191A7} (OneCCCtl Class) - https://as00.estara.com/UI/proxyhtt...155.171.21_41625&=&req=1174502081796OneCC.cab
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154137676196
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {81240A82-9679-40A5-B49A-272BD966802D} (AdamsKeegan.AdamsKeeganAX) - https://www.adamskeegan.com/timeclock.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://www.taxsimple.com/tsweb/msrdp.cab
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
    O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
    O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} (CUpdateCtl Object) - http://update.hpphoto.com/download/HPSWUpdate.ocx
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
    O24 - Desktop Component AutorunsDisabled: (no name) - (no file)

    --
    End of file - 10803 bytes
  14. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,736
    Likes Received:
    718
    My System
    Loading...
    You need to Open Ccleaner and disable the entries listed below.From your startup

    O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe" -agent
    O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe" -RESTART
    O4 - S-1-5-18 Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe (User 'Default user')
    O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe


    Hit start button at lower left hand corner of the screen.Then in the run box type services.msc. Find the service listed below,one at a time. left click it once you should have the option to either stop the service or restart it , stop the service then right click selected service select properties then change the startup type to manual then left click apply and move on to the next service.If the service is stopped and the startup type is manual then do nothing.

    O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

    O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive
    \McciCMService.exe

    O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    After you have finished the above then please post a fresh hijack this log.
  15. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,736
    Likes Received:
    718
    My System
    Loading...
    Also uninstall Window Washer From your add remove programs this is un-needed.
  16. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,736
    Likes Received:
    718
    My System
    Loading...
    After you finish post #73 then you will need to reboot and then post a fresh hijack this log.

XP freezing constantly

Thread Status:
Not open for further replies.