Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Blue screens and Visicom_antiphising.exe - corrupt file yellow triangle in system tray


  • Please log in to reply
3 replies to this topic

#1 FSNDesignGal

FSNDesignGal

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:41 AM

Posted 06 June 2012 - 06:56 PM

Good evening )
I am having a new error which has started in the last few days or so. A yellow triangle with an exclamation point is in the system tray. It appears every few minutes or so then disappears.

My system specs are:

Intel Centrino
HP 30D5
Intel i945GM/GME
Intel Core Duo T2300E @ 1666MHz
2048MB (2 x 1024 DDR2-SDRAM )
Mobile Intel® 945 Express Chipset Family
Western Digital WD800BEVT-22ZCT0 ATA Device (80GB)
Optiarc DVD RW AD-7530B
LGPhilipsLCD LP154WX4-TLC1 - 15 inches
Intel 82562ET/EZ/GT/GZ PRO/100 VE (LOM) Ethernet Controller Mobile
Intel PRO/Wireless 3945ABG [Golan] Network Connection
Windows Vista ™ Home Basic Home Edition 6.00.6001 Service Pack 1 (32-bit)
DirectX : Version 10.0
Windows Performance Index : 3.0 on 5.9


The error reads
Visicom_antiphishing.exe - Corrupt File

''The file or directory C:\Users\AppData\Local\Microsoft\Windows\TemporaryInternetFiles\Content.IE5\P6T9NGX3\Stamp[1].txt is corrupt and unreadable''

I am also experiencing blue screen crashes, 2 in the last week with writing which is too small to read!
I stupidly deleted that file in the hope it would regenerate itself but this didn't work, obviously.

Any help would be much appreciated

Nadine

Edited by hamluis, 06 June 2012 - 09:28 PM.
Moved from Vista to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


#2 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,826 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:41 AM

Posted 06 June 2012 - 09:25 PM

Download BLUESCREENVIEW and install and run it to read the dump files created by windows.
Double click on BlueScreenView.exe file to run the program.
When scanning is done, go Edit>Select All.
Go File>Save Selected Items, and save the report as BSOD.txt.
Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.


Please Download and run TFC.exe
http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/

The error you are getting in reguards to Visicom_antiphishing.exe - Corrupt File Relates to the software in the link below it is safe to remove this from your add remove programs.
http://software.visicommedia.com/en/products/antiphishing/

Please download MINITOOLBOX and run it.

Checkmark following boxes:


Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List Devices (problems only)



Click Go and post the result.

Hit the start button in lower left hand corner. Then in the run box type msconfig, then hit the services tab then put a check mark in hide microsoft services what is listed there,after hiding microsoft services?Please post back to us in a vertical list.


Open Msconfig and disable everything Except your Antivirus and if you connect wirelessly do not disable that.



Download Autoruns and Autorunsc unzip Autoruns to your desktop run it.See any entries that read file not found when you see them right click and select delete do this only for the entries that read file not found also uncheck any scheduled task that are set to run on your machine,close the program.

Then please do the following.Open Elevated Command Prompt Click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.Then copy the contents of the code box and paste it into the command prompt and hit enter.




sfc /scannow







Then please do the following.Open Elevated Command Prompt Click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator. Then type or copy and paste the following. CHKDSK /R Reply Y when asked if you want this to happen on the next boot.Now Type Exit and Reboot your machine.

Edited by InadequateInfirmity, 06 June 2012 - 09:46 PM.

What happens when you press Alt + F4 at the same time?

#3 FSNDesignGal

FSNDesignGal
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:41 AM

Posted 07 June 2012 - 10:16 AM

Hello InadequateInfirmity and thanks for your help.

I ran the bluescreenview exe and got the following:

Dump File : Mini060612-01.dmp
Crash Time : 06/06/2012 01:29:58
Bug Check String :

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x826ba001
Parameter 3 : 0x88d5f8b4
Parameter 4 : 0x88d5f5b0
Caused By Driver : ataport.SYS
Caused By Address : ataport.SYS+14001
File Description : ATAPI Driver Extension
Product Name : Microsoft® Windows® Operating

System
Company : Microsoft Corporation
File Version : 6.0.6001.18000

(longhorn_rtm.080118-1840)
Processor : 32-bit
Crash Address : ataport.SYS+14001
Stack Address 1 : sptd.sys+1316b
Stack Address 2 :
Stack Address 3 : ntkrnlpa.exe+164603
Computer Name :
Full Path : C:\Windows\Minidump\Mini060612-

01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 6001
Dump File Size : 138,520
==================================================

==================================================
Dump File : Mini060212-01.dmp
Crash Time : 02/06/2012 00:34:20
Bug Check String : KERNEL_STACK_INPAGE_ERROR
Bug Check Code : 0x00000077
Parameter 1 : 0xc000000e
Parameter 2 : 0xc000000e
Parameter 3 : 0x00000000
Parameter 4 : 0x347a2000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+cd1cb
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating

System
Company : Microsoft Corporation
File Version : 6.0.6001.18538

(vistasp1_gdr.101014-0432)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+cd1cb
Stack Address 1 : ntkrnlpa.exe+a1ca0
Stack Address 2 : ntkrnlpa.exe+839be
Stack Address 3 : ntkrnlpa.exe+51537
Computer Name :
Full Path : C:\Windows\Minidump\Mini060212-

01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 6001
Dump File Size : 144,696
==================================================


I had a bit of an issue trying to run TFC..

Firstly, Avast flagged it up by putting it in the Sandbox, which kept cutting TFC off after a minute or two, so I selected to open TFC normally in

Avast, which must have been a mistake because then everything from my desktop went blank except for the background image and the sidebar...

And I kept getting a dialogue box title TFC - Corrupt file with exactly the same imformation as the original error, this appeared over and over every

second or so, closing each box down did nothing and it continued like this until I had to CTRL - ALT - DElETE and log off!


http://software.visicommedia.com/en/products/antiphishing/ - does not appear to be on my computer so I left that step.



MiniToolBox by Farbar Version: 04-06-2012
Ran by NadineBack4Good (administrator) on 07-06-2012

at 15:40:58
Microsoft® Windows Vista™ Home Basic Service Pack 1

(X86)
Boot Mode: Normal
*****************************************************

**********************

========================= IE Proxy Settings:

==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings:

==============================

========================= Hosts content:

=================================



::1 localhost
127.0.0.1 localhost
127.0.0.1 activate.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com

========================= IP Configuration:

================================

Intel® PRO/Wireless 3945ABG Network Connection =

Wireless Network Connection (Connected)
Intel® PRO/100 VE Network Connection = Local Area

Connection (Media disconnected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global defaultcurhoplimit=64

icmpredirects=enabled
set subinterface interface= subinterface=wireless_0

mtu=1500
add address name="ethernet_13" address=10.64.64.2


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : NadineBack4G-

PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . :

cable.virginmedia.net

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel®

PRO/100 VE Network Connection
Physical Address. . . . . . . . . : 00-1B-38-7E-

F6-23
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . :

cable.virginmedia.net
Description . . . . . . . . . . . : Intel®

PRO/Wireless 3945ABG Network Connection
Physical Address. . . . . . . . . : 00-1B-77-69-

B9-2A
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . :

fe80::98fa:6b79:d4ae:c648%8(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.0.101

(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : 06 June 2012

01:30:03
Lease Expires . . . . . . . . . . : 13 June 2012

08:46:55
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DNS Servers . . . . . . . . . . . : 192.168.0.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter Local Area Connection* 7:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{FBAAE95C-43BC-4E2A-8A1B-BB9BB32E4781}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 9:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo

Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-

4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . :

fe80::3c06:223f:3f57:ff9a%11(Preferred)
Default Gateway . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter Local Area Connection* 18:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . :

isatap.hshld.com
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 16:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{FBAAE95C-43BC-4E2A-8A1B-BB9BB32E4781}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 22:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{EE56ACA5-EDFA-4DCB-86CE-5D8E2214B74C}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 24:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{3793DF30-4999-4DA3-B444-DD908F36879B}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 27:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{3793DF30-4999-4DA3-B444-DD908F36879B}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 28:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{3793DF30-4999-4DA3-B444-DD908F36879B}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 29:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{3793DF30-4999-4DA3-B444-DD908F36879B}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 31:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.

{2F7D24AD-2DE6-445C-B9E1-E9D0343B9DD9}
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 11:

Media State . . . . . . . . . . . : Media

disconnected
Connection-specific DNS Suffix . :

cable.virginmedia.net
Description . . . . . . . . . . . :

isatap.cable.virginmedia.net
Physical Address. . . . . . . . . : 00-00-00-00-

00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: dir-615
Address: 192.168.0.1

Name: google.com.cable.virginmedia.net
Address: 81.200.64.50



Pinging google.com [173.194.34.132] with 32 bytes of

data:

Reply from 173.194.34.132: bytes=32 time=15ms TTL=55

Reply from 173.194.34.132: bytes=32 time=16ms TTL=55



Ping statistics for 173.194.34.132:

Packets: Sent = 2, Received = 2, Lost = 0 (0%

loss),

Approximate round trip times in milli-seconds:

Minimum = 15ms, Maximum = 16ms, Average = 15ms

Server: dir-615
Address: 192.168.0.1

Name: yahoo.com.cable.virginmedia.net
Address: 81.200.64.50



Pinging yahoo.com [98.139.183.24] with 32 bytes of

data:

Reply from 98.139.183.24: bytes=32 time=430ms TTL=50

Reply from 98.139.183.24: bytes=32 time=388ms TTL=49



Ping statistics for 98.139.183.24:

Packets: Sent = 2, Received = 2, Lost = 0 (0%

loss),

Approximate round trip times in milli-seconds:

Minimum = 388ms, Maximum = 430ms, Average = 409ms

Server: dir-615
Address: 192.168.0.1

Name: bleepingcomputer.com
Address: 208.43.87.2



Pinging bleepingcomputer.com [208.43.87.2] with 32

bytes of data:

Reply from 208.43.87.2: Destination host unreachable.

Reply from 208.43.87.2: Destination host unreachable.



Ping statistics for 208.43.87.2:

Packets: Sent = 2, Received = 2, Lost = 0 (0%

loss),



Pinging 127.0.0.1 with 32 bytes of data:

Reply from 127.0.0.1: bytes=32 time<1ms TTL=64

Reply from 127.0.0.1: bytes=32 time<1ms TTL=64



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0%

loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

=====================================================

======================
Interface List
12 ...00 1b 38 7e f6 23 ...... Intel® PRO/100 VE

Network Connection
8 ...00 1b 77 69 b9 2a ...... Intel® PRO/Wireless

3945ABG Network Connection
1 ........................... Software Loopback

Interface 1
14 ...00 00 00 00 00 00 00 e0 isatap.{FBAAE95C-

43BC-4E2A-8A1B-BB9BB32E4781}
11 ...02 00 54 55 4e 01 ...... Teredo Tunneling

Pseudo-Interface
19 ...00 00 00 00 00 00 00 e0 isatap.hshld.com
15 ...00 00 00 00 00 00 00 e0 isatap.{FBAAE95C-

43BC-4E2A-8A1B-BB9BB32E4781}
16 ...00 00 00 00 00 00 00 e0 isatap.{EE56ACA5-

EDFA-4DCB-86CE-5D8E2214B74C}
18 ...00 00 00 00 00 00 00 e0 isatap.{3793DF30-

4999-4DA3-B444-DD908F36879B}
21 ...00 00 00 00 00 00 00 e0 isatap.{3793DF30-

4999-4DA3-B444-DD908F36879B}
22 ...00 00 00 00 00 00 00 e0 isatap.{3793DF30-

4999-4DA3-B444-DD908F36879B}
23 ...00 00 00 00 00 00 00 e0 isatap.{3793DF30-

4999-4DA3-B444-DD908F36879B}
25 ...00 00 00 00 00 00 00 e0 isatap.{2F7D24AD-

2DE6-445C-B9E1-E9D0343B9DD9}
26 ...00 00 00 00 00 00 00 e0

isatap.cable.virginmedia.net
=====================================================

======================

IPv4 Route Table
=====================================================

======================
Active Routes:
Network Destination Netmask Gateway

Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1

192.168.0.101 25
127.0.0.0 255.0.0.0 On-link

127.0.0.1 306
127.0.0.1 255.255.255.255 On-link

127.0.0.1 306
127.255.255.255 255.255.255.255 On-link

127.0.0.1 306
192.168.0.0 255.255.255.0 On-link

192.168.0.101 281
192.168.0.101 255.255.255.255 On-link

192.168.0.101 281
192.168.0.255 255.255.255.255 On-link

192.168.0.101 281
224.0.0.0 240.0.0.0 On-link

127.0.0.1 306
224.0.0.0 240.0.0.0 On-link

192.168.0.101 281
255.255.255.255 255.255.255.255 On-link

127.0.0.1 306
255.255.255.255 255.255.255.255 On-link

192.168.0.101 281
=====================================================

======================
Persistent Routes:
None

IPv6 Route Table
=====================================================

======================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
8 281 fe80::/64 On-link
11 266 fe80::/64 On-link
11 266 fe80::3c06:223f:3f57:ff9a/128
On-link
8 281 fe80::98fa:6b79:d4ae:c648/128
On-link
1 306 ff00::/8 On-link
11 266 ff00::/8 On-link
8 281 ff00::/8 On-link
=====================================================

======================
Persistent Routes:
None
========================= Winsock entries

=====================================

Catalog5 01 C:\Windows\system32\NLAapi.dll [48128]

(Microsoft Corporation)
Catalog5 02 C:\Windows\system32\napinsp.dll [50176]

(Microsoft Corporation)
Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464]

(Microsoft Corporation)
Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464]

(Microsoft Corporation)
Catalog5 05 C:\Windows\System32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog5 06 C:\Windows\System32\winrnr.dll [19968]

(Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 20 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 21 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 22 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 23 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)
Catalog9 24 C:\Windows\system32\mswsock.dll [223232]

(Microsoft Corporation)

========================= Event log errors:

===============================

Application errors:
==================
Error: (06/07/2012 03:28:55 PM) (Source: Application

Hang) (User: )
Description: The program TFC.exe version 3.1.7.0

stopped interacting with Windows and was closed. To

see if more information about the problem is

available, check the problem history in the Problem

Reports and Solutions control panel.
Process ID: 12f4
Start Time: 01cd44b99cca3af0
Termination Time: 16

Error: (06/07/2012 03:18:22 PM) (Source: VSS) (User:

)
Description: Volume Shadow Copy Service error:

Unexpected error querying for the IVssWriterCallback

interface. hr = 0x80070005.
This is often caused by incorrect security settings

in either the writer or requestor process.


Operation:
Gathering Writer Data

Context:
Writer Class Id: {e8132975-6f93-4464-a53e-

1050253ae220}
Writer Name: System Writer
Writer Instance ID: {51afe501-a047-4af0-853e-

398ec7dd77b0}

Error: (06/04/2012 05:22:02 AM) (Source: Application

Hang) (User: )
Description: The program firefox.exe version

12.0.0.4493 stopped interacting with Windows and was

closed. To see if more information about the problem

is available, check the problem history in the

Problem Reports and Solutions control panel.
Process ID: 11a0
Start Time: 01cd41aaa6b15e20
Termination Time: 13

Error: (06/03/2012 04:19:32 AM) (Source: Windows

Search Service) (User: )
Description: The entry

<C:\USERS\NADINEBACK4GOOD\APPDATA\ROAMING\MACROMEDIA\

FLASH

PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#EDGE.B

UZZDOCK.COM> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not

functioning. (0x8007001f)

Error: (06/03/2012 04:19:32 AM) (Source: Windows

Search Service) (User: )
Description: The entry

<C:\USERS\NADINEBACK4GOOD\APPDATA\ROAMING\MACROMEDIA\

FLASH

PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#EDGE.B

UZZDOCK.COM> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not

functioning. (0x8007001f)

Error: (06/03/2012 04:19:23 AM) (Source: Windows

Search Service) (User: )
Description: The entry

<C:\USERS\NADINEBACK4GOOD\APPDATA\ROAMING\MACROMEDIA\

FLASH

PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#EDGE.B

UZZDOCK.COM> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not

functioning. (0x8007001f)

Error: (06/03/2012 04:19:23 AM) (Source: Windows

Search Service) (User: )
Description: The entry

<C:\USERS\NADINEBACK4GOOD\APPDATA\ROAMING\MACROMEDIA\

FLASH

PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#EDGE.B

UZZDOCK.COM> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not

functioning. (0x8007001f)

Error: (06/02/2012 10:04:25 PM) (Source: Windows

Search Service) (User: )
Description: The entry

<C:\USERS\NADINEBACK4GOOD\APPDATA\ROAMING\MACROMEDIA\

FLASH

PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#EDGE.B

UZZDOCK.COM> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not

functioning. (0x8007001f)

Error: (06/02/2012 10:04:25 PM) (Source: Windows

Search Service) (User: )
Description: The entry

<C:\USERS\NADINEBACK4GOOD\APPDATA\ROAMING\MACROMEDIA\

FLASH

PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#EDGE.B

UZZDOCK.COM> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not

functioning. (0x8007001f)

Error: (06/02/2012 10:04:16 PM) (Source: Windows

Search Service) (User: )
Description: The entry

<C:\USERS\NADINEBACK4GOOD\APPDATA\ROAMING\MACROMEDIA\

FLASH

PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#EDGE.B

UZZDOCK.COM> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not

functioning. (0x8007001f)


System errors:
=============
Error: (01/18/2012 08:57:21 PM) (Source: EventLog)

(User: )
Description: The previous system shutdown at 19:56:00

on 18/01/2012 was unexpected.

Error: (01/17/2012 11:12:52 PM) (Source: bowser)

(User: )
Description: The master browser has received a server

announcement from the computer MAC001FF3D183D6
that believes that it is the master browser for the

domain on transport NetBT_Tcpip_{FBAAE95C-43BC-4E2A-

8A1B-BB.
The master browser is stopping or an election is

being forced.

Error: (01/17/2012 10:52:35 PM) (Source: bowser)

(User: )
Description: The master browser has received a server

announcement from the computer MAC001FF3D183D6
that believes that it is the master browser for the

domain on transport NetBT_Tcpip_{FBAAE95C-43BC-4E2A-

8A1B-BB.
The master browser is stopping or an election is

being forced.

Error: (01/17/2012 10:22:31 PM) (Source: bowser)

(User: )
Description: The master browser has received a server

announcement from the computer KELLY-PC
that believes that it is the master browser for the

domain on transport NetBT_Tcpip_{FBAAE95C-43BC-4E2A-

8A1B-BB9BB32E4.
The master browser is stopping or an election is

being forced.

Error: (01/17/2012 10:21:42 PM) (Source: netbt)

(User: )
Description: A duplicate name has been detected on

the TCP network. The IP address of
the computer that sent the message is in the data.

Use nbtstat -n in a
command window to see which name is in the Conflict

state.

Error: (01/17/2012 10:21:42 PM) (Source: netbt)

(User: )
Description: A duplicate name has been detected on

the TCP network. The IP address of
the computer that sent the message is in the data.

Use nbtstat -n in a
command window to see which name is in the Conflict

state.

Error: (01/17/2012 10:18:39 PM) (Source:

WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070006

Error: (01/17/2012 10:18:18 PM) (Source: Dhcp) (User:

)
Description: The IP address lease 192.168.0.100 for

the Network Card with network address 001B7769B92A

has been denied by the DHCP server 192.168.0.1 (The

DHCP Server sent a DHCPNACK message).

Error: (01/17/2012 10:18:12 PM) (Source: HTTP) (User:

)
Description: \Device\Http\ReqQueueKerberos

Error: (01/17/2012 10:18:10 PM) (Source: EventLog)

(User: )
Description: The previous system shutdown at 10:43:25

on 17/01/2012 was unexpected.


Microsoft Office Sessions:
=========================
Error: (05/13/2012 01:45:58 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft

Office Word, Application Version: 12.0.6612.1000,

Microsoft Office Version: 12.0.6612.1000. This

session lasted 55607 seconds with 9720 seconds of

active time. This session ended with a crash.

Error: (12/16/2010 04:18:40 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 50 seconds with 0

seconds of active time. This session ended with a

crash.

Error: (12/15/2010 05:49:50 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 21341 seconds

with 120 seconds of active time. This session ended

with a crash.

Error: (12/10/2010 11:23:18 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 2077 seconds with

300 seconds of active time. This session ended with

a crash.

Error: (11/30/2010 08:00:03 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 108345 seconds

with 540 seconds of active time. This session ended

with a crash.

Error: (11/22/2010 07:57:23 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 19427 seconds

with 0 seconds of active time. This session ended

with a crash.

Error: (11/07/2010 06:18:14 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 3865 seconds with

300 seconds of active time. This session ended with

a crash.

Error: (11/07/2010 05:13:32 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 42538 seconds

with 720 seconds of active time. This session ended

with a crash.

Error: (10/19/2010 07:55:16 PM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 11399 seconds

with 60 seconds of active time. This session ended

with a crash.

Error: (10/19/2010 03:10:37 AM) (Source: Microsoft

Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft

Office PowerPoint, Application Version:

12.0.4518.1014, Microsoft Office Version:

12.0.4518.1014. This session lasted 27495 seconds

with 900 seconds of active time. This session ended

with a crash.


=========================== Installed Programs

============================

Update for Microsoft Office 2007 (KB2508958)
32 Bit HP CIO Components Installer (Version: 1.0.0)
Adobe Flash Player 11 Plugin (Version: 11.2.202.235)
Adobe Illustrator CS5 (Version: 15.0)
Adobe Media Player (Version: 1.8)
Adobe Photoshop CS5 (Version: 12.0)
Adobe Reader 9.5.1 (Version: 9.5.1)
Adobe Shockwave Player 11.5 (Version: 11.5.7.609)
Akamai NetSession Interface Service
Anti-phishing Domain Advisor (Version: 1.0.0.0)
Apple Application Support (Version: 2.1.7)
Apple Mobile Device Support (Version: 5.1.1.4)
Apple Software Update (Version: 2.1.3.127)
avast! Free Antivirus (Version: 7.0.1426.0)
BitComet 1.28 (Version: 1.28)
Canon Easy-PhotoPrint EX
Canon Easy-PhotoPrint Pro - Pro9000 series Extention

Data
Canon Easy-PhotoPrint Pro - Pro9500 series Extention

Data
Canon MG6100 series MP Drivers
Canon MG6100 series User Registration
Canon MP Navigator EX 4.0
Canon My Printer
Canon Solution Menu EX
CD-LabelPrint
Conexant HD Audio (Version: 4.36.7.61)
Dropbox (Version: 1.2.52)
Eusing Free Registry Cleaner
Free WMA to MP3 Converter 1.16
HP OCR Software 8.0 (Version: 8.0)
HP Product Detection (Version: 10.7.9.0)
HP Update (Version: 4.000.005.006)
Intel® Graphics Media Accelerator Driver
InterActual Player
iTunes (Version: 10.6.1.7)
Java Auto Updater (Version: 2.0.7.1)
Java™ 6 Update 31 (Version: 6.0.310)
Malwarebytes Anti-Malware version 1.60.1.1000

(Version: 1.60.1.1000)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version:

4.0.30319)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007 (Version:

12.0.6612.1000)
Microsoft Office Access Setup Metadata MUI (English)

2007 (Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (Version:

12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (Version:

12.0.6612.1000)
Microsoft Office Groove MUI (English) 2007 (Version:

12.0.6612.1000)
Microsoft Office Groove Setup Metadata MUI (English)

2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (English) 2007

(Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version:

12.0.6612.1000)
Microsoft Office Outlook MUI (English) 2007 (Version:

12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007

(Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version:

12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version:

12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version:

12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version:

12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3

(SP3)
Microsoft Office Publisher MUI (English) 2007

(Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version:

12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English)

2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version:

12.0.6612.1000)
Microsoft Visual C++ 2008 Redistributable - KB2467174

- x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86

9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86

9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86

9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053)
Microsoft_VC90_ATL_x86 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (Version: 1.0.0)
Microsoft_VC90_CRT_x86 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (Version: 1.00.0000)
Mozilla Firefox 13.0 (x86 en-GB) (Version: 13.0)
Mozilla Maintenance Service (Version: 13.0)
MpcStar 5.1 (Version: 5.1)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyDefrag v4.3.1 (Version: 4.0.0.0)
NirSoft BlueScreenView
PC Wizard 2012.2.0
PeerBlock 1.1 (r518) (Version: 1.1.0.518)
Revo Uninstaller 1.90 (Version: 1.90)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1

(KB963707) (Version: 1)
Update for Microsoft Office 2007 Help for Common

Features (KB963673)
Update for Microsoft Office Access 2007 Help

(KB963663)
Update for Microsoft Office Excel 2007 Help

(KB963678)
Update for Microsoft Office Infopath 2007 Help

(KB963662)
Update for Microsoft Office OneNote 2007 Help

(KB963670)
Update for Microsoft Office Outlook 2007 Help

(KB963677)
Update for Microsoft Office Outlook 2007 Junk Email

Filter (KB2598290) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help

(KB963669)
Update for Microsoft Office Publisher 2007 Help

(KB963667)
Update for Microsoft Office Script Editor Help

(KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0)
VLC media player 1.1.11 (Version: 1.1.11)
WAV to MP3 Encoder (Version: 1.0.0)
WinRAR 4.00 (32-bit) (Version: 4.00.0)

========================= Devices:

================================


========================= Memory info:

===================================

Percentage of memory in use: 55%
Total physical RAM: 2038.66 MB
Available physical RAM: 903.66 MB
Total Pagefile: 4312.6 MB
Available Pagefile: 3062.92 MB
Total Virtual: 2047.88 MB
Available Virtual: 1945.3 MB

========================= Partitions:

=====================================

1 Drive c: () (Fixed) (Total:74.53 GB) (Free:2.27 GB)

NTFS
3 Drive e: (SIX_FEET_UNDER_SEASON2) (CDROM)

(Total:7.52 GB) (Free:0 GB) UDF

========================= Users:

========================================

User accounts for \\NADINEBACK4G-PC

Administrator Guest

NadineBack4Good
scanfix


**** End of log ****



List of services after disabling all Microsoft

services in Msconfig:

Adobe Flash Player Update service - Stopped
Apple Mobile Device - Running
Avast!Antivirus - Running
Bitcomet Disk Boost Service - Running
Ipod Service - Running
Mozilla Maintenance Service - Stopped
Switchboard (Adobe systems incorporated) - Stopped


When you say

''Open Msconfig and disable everything Except your Antivirus and if you connect wirelessly do not disable that.''
.........Am I supposed to be checking the hide microsoft services again? If so, there isn't anything else to select and my wireless is not listed there.

#4 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,826 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:41 AM

Posted 07 June 2012 - 07:01 PM

You will need to temperarily disable Avast when you run TFC.exe :)

When you say

''Open Msconfig and disable everything Except your Antivirus and if you connect wirelessly do not disable that.''
.........Am I supposed to be checking the hide microsoft services again? If so, there isn't anything else to select and my wireless is not listed there.


Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe Run as Administrator click Select. Then
click Remove Older Versions.


Here is a link explaining how to use Msconfig to disable start-up items.

http://www.netsquirrel.com/msconfig/msconfig_vista.html



Your Service Pack is out of date,you will need to install Service pack 2 save the file in the link below to your desktop and run it from there in safemode.

http://www.microsoft.com/en-us/download/details.aspx?id=16468


You have low space on your C: drive Which will cause windows to struggle to work correctly.
1 Drive c: () (Fixed) (Total:74.53 GB) (Free:2.27 GB)
You will need to free up at least 8 gigs of space here is a program that will assist you in doing this.
http://w3.win.tue.nl/nl/onderzoek/onderzoek_informatica/visualization/sequoiaview/
This may be the main reason you are having issues but these other steps when taken will surely not hurt.


Hit start button at lower left hand corner of the screen.Then in the run box type services.msc. Find the service listed below,one at a time, left click it once you should have the option to either stop the service or restart it , stop the service then right click selected service select properties then change the startup type to manual then left click apply and move on to the next service.If the service is stopped and the startup type is manual then do nothing.


Adobe Flash Player Update service
Apple Mobile Device
Ipod Service
Mozilla Maintenance
Switchboard





Lets change your dns setting to a faster more secure connection.
http://www.computerhope.com/issues/ch001161.htm
Change your dns to the below.

Preferred DNs 208.67.222.222

Alternate dns 208.67.220.220



Please Disable/uncheck Ipv6

Hit start
Control Panel
NetWork & Sharing Center
Manage Network Connections
Right Click Your Connection
Select Properties
Un-Check Ipv6
Select ok
Continue Below



Disable the IP Helper service:

1. Hold the Windows key and type R, enter "services.msc" (without the quotes) and press Enter

2. Scroll down to the IP Helper service, right click on it and select Properties
3. In the dropdown box that says "Automatic" or "Manual", set it to Disabled and then click on "Apply"
4. Then click on "Stop" to stop the service from running in the current session.
5. Click OK to exit the dialog

Then please do the following.Open Elevated Command Prompt Click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.

At Command Prompt, type in the following hitting enter after each command:

netsh int ip reset reset.log

netsh winsock reset catalog

ipconfig /release

ipconfig /renew

ipconfig /flushdns


Restart computer.


Go here and run the Microsoft fix it to set your hosts files back to default.
http://support.microsoft.com/kb/972034


Please also confirm that you have ran the checkdisk as well as ran the sfc /scannow command. Please do not skip any step here these steps are needed!!To get your machine running properly.

Edited by InadequateInfirmity, 07 June 2012 - 07:05 PM.

What happens when you press Alt + F4 at the same time?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users