Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop dns driver drivers error ethernet excel freeze gaming graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard network printer problem ram registry repair router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Solved: Computer Won't Shut Down Properly

Reply  
Thread Tools
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
17-Nov-2009, 12:09 PM #1
Computer Won't Shut Down Properly
I read through a bunch of similarly titled posts after searching this site. All of the information I got and tried on my own problem doesn't seem to do the trick. I am using Windows XP Home SP3.

All was working normally until about 1-2 weeks ago. My mouse was giving problems (single click would register as double-click and things like that) so I replaced it with a new, similar USB optical mouse. Just a plain, no-frills unit. All worked fine ... for a week or so.

During this time I also ran a defragment of my pagefile and this was around the time the trouble started. Co-incidence? I don't know how defragging but not removing anything would hurt but I thought I'd mention it (like this post isn't long enough)!

Then the computer started taking a very long time just to get to the box with the 3 choices of 'log out', 'turn off', and 'restart.' When I'd hit turn off it would hang for the longest time (15 minutes or so) and then give me the "Windows is shutting down" and the "saving your settings" screen where it would proceed to hang again. A bit shorter like 5-7 minutes.

So I checked around and came up with one tip that actually worked partially. Instead of hitting Start > Turn off Computer, the tip said type "shutdown -f -s -t 0" in the "Run" box and sure enough the computer would go to the "Windows is shutting down" screen -- and hang again. One freeze instead of two seemed better but not 100% right.

So I came here and started searching. I found these tips and tried:

- SFC /SCANNOW using my Windows XP recovery disk. Don't know if it did anything.

- ran the UPHClean hive cleaner application but still no improvement

- system restore is turned off but I use ERNDT to go back and replace just the registry to an earlier time which generally works but didn't in this case.

- disabled all start programs from "MSCONFIG" which got me to the "windows is shutting down" screen without a freeze but still froze 5-7 minutes there (like originally).

- tried some or all of the above in SAFE mode to no avail.

When I do something that gets me the box to "restart computer or exit without restart" (like installing something) I get to the Windows is shutting down / saving your settings screen without freezing but then that screen freezes for the 5-7 minutes like the rest.

So if this makes sense and anyone has some info or a clue as to what else I can try, please fire away, it's making me nuts. And thanks in advance for the help and time.

Robert
Crypton's Avatar
Computer Specs
Member with 82 posts.
 
Join Date: Nov 2009
Location: Crypt Next to APES
17-Nov-2009, 01:58 PM #2
Thats Not a Big Problem,
Follow this tutorial
and your problem been Solved

http://blogs.howtogeek.com/mysticgee...t-down-faster/
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
17-Nov-2009, 05:42 PM #3
Wow! That worked like a charm and was a whole lot less painful than I expected.

Thanks so much for that one. I appreciate the help.

Robert
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
18-Nov-2009, 05:03 PM #4
Oops, I spoke too soon! I changed all the settings as instructed in the above help article and my computer shut down as it used to. I marked this thread "solved" and moved on.

Next day after I used my computer and went to shut down, it started sticking / freezing again.

I checked my settings and registry (as per the article) and all was as it should be but my original problem has returned.

So, if anyone has any more suggestions as to what I can do to fix this freezing problem, I'd appreciate it. The first post in this thread will pretty much tell the story and just add the registry changes / fixes as per the article "Crypton" offered and we're up to speed.

Thanks to any and all who can give further tips or help (besides all the things I've done already) that may help to get my computer shutting down as it is supposed to.

Robert
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
18-Nov-2009, 05:10 PM #5
Try this fix: Auto End Tasks to Enable a Proper Shutdown

Save the reg file to your desktop. Double-click on it to merge it to your registry.

Reboot.
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
19-Nov-2009, 11:38 AM #6
Thanks, Phantom for that tip. I went in and made the changes (one was already at the suggested value from the previous registry changes suggested in the help article posted above earlier) and the shutdown went quickly. OK, good so far...

So I restarted and tried shutting down again a few times and it worked each time. Computer shuts down (and in fact those registry changes make the screens blaze on by!) normally and even a bit quicker than it did when working properly before the problem started.

Today I re-checked to see if the shutdown was still working like it had been and, oops, all had slowed down again. This is baffling.

When I hit "start> turn off computer" it takes a very long time to get to the box with the 3 choices of "turn off, restart and standby." When I hit either turn off or restart the computer it gets to the "windows is shutting down and saving your settings" screens and then freezes for a long time but not as long as the first freeze upon first hitting the "turn off" button.

This is exactly the same thing that happened after I modified the registry using the tips provided first (above). Right after making the value changes the computer shut down quickly. No problem. But upon restarting and trying to shut down at a later time the freezing goes back to where it was.

Now, one thing, if I type "shutdown -f -s -t 0" in the 'run' box [that's a zero and not an o] the computer blazes to the box with the 3 choices (standby, turn off, restart) and then hangs for a long time before shutting off. (I found that tip somewhere else.)

So, just to be a bit longer , all the changes I've made with the two tips offered above work great the first times I shutdown after making the changes. But after going off and coming back, turning on the computer and then trying to shut down I am back where I started. When I type that line in the 'run' box I get blazing fast speed getting to the choice box but then the long wait time starts until the unit actually does shut down or restart.

Thanks for the tips, so far, but any other ideas? I seem to be back (again) at square one.

Robert
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
19-Nov-2009, 12:08 PM #7
Read this Shutdown Troubleshooter and see if something applies to you.

Also, make sure you don't have a task scheduled to run at shutdown. Click on Start > Settings > Control Panel > Scheduled Tasks.

And,

Please click here to download and install the HijackThis installer.

Run it and select Do a system scan and save a logfile.

The log will be saved in Notepad. Copy and paste the log in your next post.

Do not fix anything
__________________

• Our help is free 'cause we like what we do, so at least, please reply in a timely manner... Thank you.
• If we've solved your problem, please click on Mark Solved in the upper left corner of your thread.
How to Mark Your Own Thread as "Solved".

Last edited by Phantom010; 19-Nov-2009 at 12:29 PM..
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
19-Nov-2009, 03:54 PM #8
Quote:
Originally Posted by Phantom010 View Post
Read this Shutdown Troubleshooter and see if something applies to you.

Also, make sure you don't have a task scheduled to run at shutdown. Click on Start > Settings > Control Panel > Scheduled Tasks.
I read the Shutdown Troubleshooter and about the only thing that caught my eye was the "Logitech Mouse" driver part. I had installed an application from the Logitech site, originally, but that didn't fix my problem.

I contacted Logitech help and they advised me to uninstall this app and that the Logitech mouse would work with the original (Dell) driver installed. There is no driver for the new Logitech USB mouse that I replaced the bad Dell mouse with. And the mouse works OK.

I have/had no tasks scheduled for shutdown (or anytime).

Here is the 'Hi-Jack This' log:

Logfile of HijackThis v1.97.7
Scan saved at 1:03:58 PM, on 11/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
F:\RegCure\RegCure.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
F:\UPHClean\uphclean.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\TaskPlus\taskplus0.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Clavier+\Clavier.exe
C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
C:\QUICKENW\QWDLLS.EXE
C:\Documents and Settings\Robert Hickey\Start Menu\Programs\Karen's Power Tools\PTReplicator.exe
C:\Program Files\YCIII\YankClip.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
G:\08 Programs\Cleaners\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\QUICKENW\inet\common\BLANK.HTM
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\QUICKENW\inet\common\BLANK.HTM
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dell4me.com/myway
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [TaskPlus] C:\Program Files\TaskPlus\taskplus0.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [Clavier+] C:\Program Files\Clavier+\Clavier.exe
O4 - HKCU\..\Run: [OpenDNS Updater] "C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe" /autostart
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Karen's Replicator.lnk = C:\Documents and Settings\Robert Hickey\Start Menu\Programs\Karen's Power Tools\PTReplicator.exe
O4 - Startup: Yankee Clipper III.lnk = C:\Program Files\YCIII\YankClip.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: Fill Forms (HKLM)
O9 - Extra button: Save (HKLM)
O9 - Extra 'Tools' menuitem: Save Forms (HKLM)
O9 - Extra button: RoboForm (HKLM)
O9 - Extra 'Tools' menuitem: RoboForm Toolbar (HKLM)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1188091841437
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com/get.../ultrashim.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B94F129-1B7E-4020-BD9D-35B1F28F445E}: NameServer = 208.67.222.222,208.67.220.220

Thanks, again, for your time and help.

Robert
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
19-Nov-2009, 04:46 PM #9
Please use the HijackThis version in my link. Yours is really outdated.
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
19-Nov-2009, 08:21 PM #10
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:20:03 PM, on 11/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
F:\UPHClean\uphclean.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\TaskPlus\taskplus0.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Clavier+\Clavier.exe
C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
C:\QUICKENW\QWDLLS.EXE
C:\Documents and Settings\Robert Hickey\Start Menu\Programs\Karen's Power Tools\PTReplicator.exe
C:\Program Files\YCIII\YankClip.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
F:\Mozilla Firefox\firefox.exe
F:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\QUICKENW\inet\common\BLANK.HTM
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\QUICKENW\inet\common\BLANK.HTM
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [TaskPlus] C:\Program Files\TaskPlus\taskplus0.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [Clavier+] C:\Program Files\Clavier+\Clavier.exe
O4 - HKCU\..\Run: [OpenDNS Updater] "C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe" /autostart
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Karen's Replicator.lnk = C:\Documents and Settings\Robert Hickey\Start Menu\Programs\Karen's Power Tools\PTReplicator.exe
O4 - Startup: Yankee Clipper III.lnk = C:\Program Files\YCIII\YankClip.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1188091841437
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B94F129-1B7E-4020-BD9D-35B1F28F445E}: NameServer = 208.67.222.222,208.67.220.220
O20 - Winlogon Notify: yaywwwWM - C:\WINDOWS\
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: OpenDNS Updater (OpenDNS Updater.exe) - Dell Computer Corporation - (no file)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 9643 bytes
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
19-Nov-2009, 09:14 PM #11
I think your computer might be infected but I'm not quite sure because I can't find any information on the following entry. Please click on the Report button and kindly ask for a malware removal expert's assistance.

O20 - Winlogon Notify: yaywwwWM - C:\WINDOWS\

Last edited by Phantom010; 19-Nov-2009 at 09:53 PM..
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
20-Nov-2009, 11:30 AM #12
I'd almost guarantee that what you found is a leftover component from an infection I had first part of the year. I had recurring boxes that kept popping up repeatedly and Combofix was used to clear the infection.

That line you have above looks an awful lot like one of those recurring box's content. But I looked at the "report" area you suggest and it says not to be used to get technical information.

Did I go to the right place?

And thanks for going through all of this mess. I appreciate the quick help!

Robert
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
20-Nov-2009, 11:37 AM #13
Yes, you can click on the Report button when asking for Malware Removal advice. Only members with a Gold Shield are allowed to give you malware removal advice or help you remove malware on this forum. You will probably be moved to the Malware Removal & HijackThis Logs forum.
robhic's Avatar
Member with 115 posts.
 
Join Date: Jul 2005
Experience: Intermediate
20-Nov-2009, 11:57 AM #14
Thanks a million!

Robert
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
20-Nov-2009, 12:02 PM #15
You're welcome!
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 09:11 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.