Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unable To Install A/virus. Help.


  • This topic is locked This topic is locked
10 replies to this topic

#1 dutchmul

dutchmul

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:18 AM

Posted 11 March 2007 - 05:57 PM

Hi guys,

My pc started crashing today for no discernible reason and now crashes everytime i try and run kaspersky av & avg antispyware. Adaware wont start, nor will ccleaner, registry mechanic and privacy guardian. a message pops up saying the program encountered a problem and had to close.

I have uninstalled kaspersky and tried to install avg free and avast, both progs would not install as they said they encountered a problem during installation. an online scan using bitdefender failed as well.

Spybot sd states that the program has changed when Itry to run it and to scan for viruses and spyware immediatelt !!!!!

Please help me, my hijack log is posted below, I do not understand how I have become infected.

Thanks for your help.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.micromart.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TrustInstaller] E:\Setup.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} - https://remote.barnardos.org.uk/dana-cached...oterisSetup.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe





thanks again for all your help. James.

BC AdBot (Login to Remove)

 


#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:18 AM

Posted 22 March 2007 - 03:47 PM

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. :thumbsup:
I apologize for the delay getting to your log, the helpers here are very busy.

If you still need help, please post a fresh Hijackthis log, in this thread, so I can help you with your malware problems.
If you have resolved this issue please let us know.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 dutchmul

dutchmul
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:18 AM

Posted 22 March 2007 - 05:00 PM

Hi Buckeye,

I have posted a new hijack log below. still having same probs.

Thanks a lot for your help. Much appreciated

Logfile of HijackThis v1.99.1
Scan saved at 21:54:54, on 22/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.micromart.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TrustInstaller] E:\Setup.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} - https://remote.barnardos.org.uk/dana-cached...oterisSetup.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe


Thanks again for your help. I have now installed nod32 av scanner but it crashes my comp when i run a scan.

#4 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:18 AM

Posted 22 March 2007 - 06:42 PM

Just to make sure I understand all that is going on, you are unable to run a virus scan with Nod32, or any other program? And you are also unable to run AVG Antispyware to completion? I just want to make sure I have that correct. Assuming that it is, let's get rid of those programs that aren't working for now.

Uninstall Nod32 and AVG

Before the problem with Kaspersky began, did you have a different antivirus installed?

Now let's clean up a few more things.

Run Hijackthis again, click scan, and Put a checkmark next to each of the lines listed below. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [TrustInstaller] E:\Setup.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)



Reboot your computer.


Now without an antivirus or firewall installed while we sort this out your computer will be at risk. So be very cautious about your web surfing while we work through this.



Download and run Stinger. It should return a small log that you can post here in your next reply.



Click Start -> Run -> eventvwr.msc

Look in SYSTEM and APPLICATIONS for anything in the last day or so.
Double click on anything you see with a red X, press the Copy button, and then paste it here in your next reply.

Edited by Buckeye_Sam, 22 March 2007 - 06:44 PM.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#5 dutchmul

dutchmul
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:18 AM

Posted 24 March 2007 - 11:29 AM

Hi Buckeye,

Thanks for your help.

Yes, I have been unable to run full scans, windows usually crashes approx 75% through the scan.

I have been unable to install some av progs, others such as nod32 install but are unable to complete a scan.

Spybot through up a message stating "this prog has been altered since it was installed, please scan for viruses immediately".

I had no other av progs installed when kaspersky started having probs, I have been using it since oct 2006.

I have fixed the entries you suggested on hijack this.

nod32 & avg antispyware have now been uninstalled and I have no security software on my pc.

Here is the stinger log -

McAfee AVERT Stinger Version 2.6.0. built on Apr 5 2006

Copyright © 2005 Networks Associates Technology, Inc. All Rights Reserved.

Virus data file v1000 created on Feb 2 2006.

Ready to scan for 55 viruses, trojans and variants.



Scan initiated on Sat Mar 24 15:27:59 2007

Number of clean files: 104330

I hope this is the correct logfile, i could find no other one.

Here are the details from eventvwr -

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 14:51:07
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. McAfee AVERT Stinger Version 2.6.0. built on Apr 5 2006
Copyright © 2005 Networks Associates Technology, Inc. All Rights Reserved.
Virus data file v1000 created on Feb 2 2006.
Ready to scan for 55 viruses, trojans and variants.

Scan initiated on Sat Mar 24 15:27:59 2007
Number of clean files: 104330 Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 24/03/2007
Time: 13:29:18
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application iexplore.exe, version 6.0.2900.2180, faulting module browseui.dll, version 6.0.2900.3059, fault address 0x0001a279.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 36 2e 30 2e 32 39 e 6.0.29
0028: 30 30 2e 32 31 38 30 20 00.2180
0030: 69 6e 20 62 72 6f 77 73 in brows
0038: 65 75 69 2e 64 6c 6c 20 eui.dll
0040: 36 2e 30 2e 32 39 30 30 6.0.2900
0048: 2e 33 30 35 39 20 61 74 .3059 at
0050: 20 6f 66 66 73 65 74 20 offset
0058: 30 30 30 31 61 32 37 39 0001a279
0060: 0d 0a .. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 24/03/2007
Time: 13:29:11
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application iexplore.exe, version 6.0.2900.2180, faulting module browseui.dll, version 6.0.2900.3059, fault address 0x0001a279.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 36 2e 30 2e 32 39 e 6.0.29
0028: 30 30 2e 32 31 38 30 20 00.2180
0030: 69 6e 20 62 72 6f 77 73 in brows
0038: 65 75 69 2e 64 6c 6c 20 eui.dll
0040: 36 2e 30 2e 32 39 30 30 6.0.2900
0048: 2e 33 30 35 39 20 61 74 .3059 at
0050: 20 6f 66 66 73 65 74 20 offset
0058: 30 30 30 31 61 32 37 39 0001a279
0060: 0d 0a .. Event Type: Error
Event Source: PerfNet
Event Category: None
Event ID: 2004
Date: 22/03/2007
Time: 23:33:05
User: N/A
Computer: JAMES-E2654BE4D
Description:
Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 34 00 00 c0 4.. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 18/03/2007
Time: 13:59:47
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application oblivion.exe, version 1.1.0.511, faulting module binkw32.dll, version 1.7.3.0, fault address 0x00019a04.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 6f 62 6c ure obl
0018: 69 76 69 6f 6e 2e 65 78 ivion.ex
0020: 65 20 31 2e 31 2e 30 2e e 1.1.0.
0028: 35 31 31 20 69 6e 20 62 511 in b
0030: 69 6e 6b 77 33 32 2e 64 inkw32.d
0038: 6c 6c 20 31 2e 37 2e 33 ll 1.7.3
0040: 2e 30 20 61 74 20 6f 66 .0 at of
0048: 66 73 65 74 20 30 30 30 fset 000
0050: 31 39 61 30 34 0d 0a 19a04.. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 18/03/2007
Time: 13:55:48
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application oblivion.exe, version 1.1.0.511, faulting module binkw32.dll, version 1.7.3.0, fault address 0x00019a04.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 6f 62 6c ure obl
0018: 69 76 69 6f 6e 2e 65 78 ivion.ex
0020: 65 20 31 2e 31 2e 30 2e e 1.1.0.
0028: 35 31 31 20 69 6e 20 62 511 in b
0030: 69 6e 6b 77 33 32 2e 64 inkw32.d
0038: 6c 6c 20 31 2e 37 2e 33 ll 1.7.3
0040: 2e 30 20 61 74 20 6f 66 .0 at of
0048: 66 73 65 74 20 30 30 30 fset 000
0050: 31 39 61 30 34 0d 0a 19a04.. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 18/03/2007
Time: 13:55:01
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application oblivion.exe, version 1.1.0.511, faulting module binkw32.dll, version 1.7.3.0, fault address 0x000199f7.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 6f 62 6c ure obl
0018: 69 76 69 6f 6e 2e 65 78 ivion.ex
0020: 65 20 31 2e 31 2e 30 2e e 1.1.0.
0028: 35 31 31 20 69 6e 20 62 511 in b
0030: 69 6e 6b 77 33 32 2e 64 inkw32.d
0038: 6c 6c 20 31 2e 37 2e 33 ll 1.7.3
0040: 2e 30 20 61 74 20 6f 66 .0 at of
0048: 66 73 65 74 20 30 30 30 fset 000
0050: 31 39 39 66 37 0d 0a 199f7.. Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1004
Date: 18/03/2007
Time: 13:08:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application avp.exe, version 6.0.0.299, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00010c3f.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 61 76 70 ure avp
0018: 2e 65 78 65 20 36 2e 30 .exe 6.0
0020: 2e 30 2e 32 39 39 20 69 .0.299 i
0028: 6e 20 6e 74 64 6c 6c 2e n ntdll.
0030: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0038: 32 36 30 30 2e 32 31 38 2600.218
0040: 30 20 61 74 20 6f 66 66 0 at off
0048: 73 65 74 20 30 30 30 31 set 0001
0050: 30 63 33 66 0c3f Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 18/03/2007
Time: 11:58:58
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application avp.exe, version 6.0.0.299, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00010c3f.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 61 76 70 ure avp
0018: 2e 65 78 65 20 36 2e 30 .exe 6.0
0020: 2e 30 2e 32 39 39 20 69 .0.299 i
0028: 6e 20 6e 74 64 6c 6c 2e n ntdll.
0030: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0038: 32 36 30 30 2e 32 31 38 2600.218
0040: 30 20 61 74 20 6f 66 66 0 at off
0048: 73 65 74 20 30 30 30 31 set 0001
0050: 30 63 33 66 0c3f Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 18/03/2007
Time: 11:58:45
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application avp.exe, version 6.0.0.299, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00010c3f.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 61 76 70 ure avp
0018: 2e 65 78 65 20 36 2e 30 .exe 6.0
0020: 2e 30 2e 32 39 39 20 69 .0.299 i
0028: 6e 20 6e 74 64 6c 6c 2e n ntdll.
0030: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0038: 32 36 30 30 2e 32 31 38 2600.218
0040: 30 20 61 74 20 6f 66 66 0 at off
0048: 73 65 74 20 30 30 30 31 set 0001
0050: 30 63 33 66 0c3f Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:27:31
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 15:27:31
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:27:31
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:22:26
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 15:22:26
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:22:26
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:19:40
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 15:19:40
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:19:40
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 14:54:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 14:54:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 14:54:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 14:51:07
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 24/03/2007
Time: 13:29:18
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application iexplore.exe, version 6.0.2900.2180, faulting module browseui.dll, version 6.0.2900.3059, fault address 0x0001a279.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 36 2e 30 2e 32 39 e 6.0.29
0028: 30 30 2e 32 31 38 30 20 00.2180
0030: 69 6e 20 62 72 6f 77 73 in brows
0038: 65 75 69 2e 64 6c 6c 20 eui.dll
0040: 36 2e 30 2e 32 39 30 30 6.0.2900
0048: 2e 33 30 35 39 20 61 74 .3059 at
0050: 20 6f 66 66 73 65 74 20 offset
0058: 30 30 30 31 61 32 37 39 0001a279
0060: 0d 0a .. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 24/03/2007
Time: 13:29:11
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application iexplore.exe, version 6.0.2900.2180, faulting module browseui.dll, version 6.0.2900.3059, fault address 0x0001a279.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 36 2e 30 2e 32 39 e 6.0.29
0028: 30 30 2e 32 31 38 30 20 00.2180
0030: 69 6e 20 62 72 6f 77 73 in brows
0038: 65 75 69 2e 64 6c 6c 20 eui.dll
0040: 36 2e 30 2e 32 39 30 30 6.0.2900
0048: 2e 33 30 35 39 20 61 74 .3059 at
0050: 20 6f 66 66 73 65 74 20 offset
0058: 30 30 30 31 61 32 37 39 0001a279
0060: 0d 0a .. Event Type: Error
Event Source: PerfNet
Event Category: None
Event ID: 2004
Date: 22/03/2007
Time: 23:33:05
User: N/A
Computer: JAMES-E2654BE4D
Description:
Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 34 00 00 c0 4.. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 18/03/2007
Time: 13:59:47
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application oblivion.exe, version 1.1.0.511, faulting module binkw32.dll, version 1.7.3.0, fault address 0x00019a04.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 6f 62 6c ure obl
0018: 69 76 69 6f 6e 2e 65 78 ivion.ex
0020: 65 20 31 2e 31 2e 30 2e e 1.1.0.
0028: 35 31 31 20 69 6e 20 62 511 in b
0030: 69 6e 6b 77 33 32 2e 64 inkw32.d
0038: 6c 6c 20 31 2e 37 2e 33 ll 1.7.3
0040: 2e 30 20 61 74 20 6f 66 .0 at of
0048: 66 73 65 74 20 30 30 30 fset 000
0050: 31 39 61 30 34 0d 0a 19a04.. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 18/03/2007
Time: 13:55:48
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application oblivion.exe, version 1.1.0.511, faulting module binkw32.dll, version 1.7.3.0, fault address 0x00019a04.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 6f 62 6c ure obl
0018: 69 76 69 6f 6e 2e 65 78 ivion.ex
0020: 65 20 31 2e 31 2e 30 2e e 1.1.0.
0028: 35 31 31 20 69 6e 20 62 511 in b
0030: 69 6e 6b 77 33 32 2e 64 inkw32.d
0038: 6c 6c 20 31 2e 37 2e 33 ll 1.7.3
0040: 2e 30 20 61 74 20 6f 66 .0 at of
0048: 66 73 65 74 20 30 30 30 fset 000
0050: 31 39 61 30 34 0d 0a 19a04.. Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 18/03/2007
Time: 13:55:01
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application oblivion.exe, version 1.1.0.511, faulting module binkw32.dll, version 1.7.3.0, fault address 0x000199f7.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 6f 62 6c ure obl
0018: 69 76 69 6f 6e 2e 65 78 ivion.ex
0020: 65 20 31 2e 31 2e 30 2e e 1.1.0.
0028: 35 31 31 20 69 6e 20 62 511 in b
0030: 69 6e 6b 77 33 32 2e 64 inkw32.d
0038: 6c 6c 20 31 2e 37 2e 33 ll 1.7.3
0040: 2e 30 20 61 74 20 6f 66 .0 at of
0048: 66 73 65 74 20 30 30 30 fset 000
0050: 31 39 39 66 37 0d 0a 199f7.. Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1004
Date: 18/03/2007
Time: 13:08:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application avp.exe, version 6.0.0.299, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00010c3f.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 61 76 70 ure avp
0018: 2e 65 78 65 20 36 2e 30 .exe 6.0
0020: 2e 30 2e 32 39 39 20 69 .0.299 i
0028: 6e 20 6e 74 64 6c 6c 2e n ntdll.
0030: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0038: 32 36 30 30 2e 32 31 38 2600.218
0040: 30 20 61 74 20 6f 66 66 0 at off
0048: 73 65 74 20 30 30 30 31 set 0001
0050: 30 63 33 66 0c3f Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 18/03/2007
Time: 11:58:58
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application avp.exe, version 6.0.0.299, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00010c3f.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 61 76 70 ure avp
0018: 2e 65 78 65 20 36 2e 30 .exe 6.0
0020: 2e 30 2e 32 39 39 20 69 .0.299 i
0028: 6e 20 6e 74 64 6c 6c 2e n ntdll.
0030: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0038: 32 36 30 30 2e 32 31 38 2600.218
0040: 30 20 61 74 20 6f 66 66 0 at off
0048: 73 65 74 20 30 30 30 31 set 0001
0050: 30 63 33 66 0c3f Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 18/03/2007
Time: 11:58:45
User: N/A
Computer: JAMES-E2654BE4D
Description:
Faulting application avp.exe, version 6.0.0.299, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00010c3f.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 61 76 70 ure avp
0018: 2e 65 78 65 20 36 2e 30 .exe 6.0
0020: 2e 30 2e 32 39 39 20 69 .0.299 i
0028: 6e 20 6e 74 64 6c 6c 2e n ntdll.
0030: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0038: 32 36 30 30 2e 32 31 38 2600.218
0040: 30 20 61 74 20 6f 66 66 0 at off
0048: 73 65 74 20 30 30 30 31 set 0001
0050: 30 63 33 66 0c3f Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:27:31
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 15:27:31
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:27:31
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:22:26
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 15:22:26
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:22:26
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:19:40
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 15:19:40
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 15:19:40
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 14:54:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 14:54:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 14:54:13
User: N/A
Computer: JAMES-E2654BE4D
Description:
The Acronis Scheduler2 Service service failed to start due to the following error:
The system cannot find the path specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 24/03/2007
Time: 14:51:07
User: N/A
Computer: JAMES-E2654BE4D
Description:
The ProtexisLicensing service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 24/03/2007
Time: 14:51:07
User: N/A
Computer: JAMES-E2654BE4D
Description:
Timeout (30000 milliseconds) waiting for the ProtexisLicensing service to connect.

Hope i have included all info you require. If I have included too much info I apologise.

Thanks very much for your help.

:thumbsup: :flowers:

#6 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:18 AM

Posted 24 March 2007 - 08:05 PM

Not a lot of help there, but that is exactly the info I needed to see. :thumbsup:

Let's get a closer look at what's on your computer and see what we can turn up.

Please download ComboFix and save it to your desktop.
Double click combofix.exe and follow the prompts.
When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#7 dutchmul

dutchmul
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:18 AM

Posted 25 March 2007 - 05:49 AM

Hi Buckeye,

Sorry that the last lot of info wasn't much help.

Here is the log file for combo fix, I don't know if this is any help to you but when I double clicked on combofix.exe a message popped up saying "freeware implementation of REG.EXE has encountered a problem & needs to close" i did not send an error report to microsoft and combofix ran fine when i closed the message box.

When i tried to open internet explorer to come back and post the combofix log, a message popped up saying that internet explorer was not my default browser, this was strange as it is the only browser I have.

here is the logfile.

-03-25 11:26:27 Service Pack 2
ComboFix 07-03-23 - Running from: "C:\Documents and Settings\James \Desktop"

((((((((((((((((((((((((((((((( Files Created from 2007-02-25 to 2007-03-25 ))))))))))))))))))))))))))))))))))


2007-03-18 12:55 <DIR> d--hs---- C:\found.000
2007-03-17 22:21 <DIR> d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\Apple Computer
2007-03-11 23:03 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-03-11 19:17 <DIR> d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\Ahead
2007-03-11 19:14 2,277,376 --------- C:\WINDOWS\UNNMIX.exe
2007-03-11 19:12 2,293,760 --------- C:\WINDOWS\UNNeroVision.exe
2007-03-11 19:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-03-11 19:11 2,277,376 --------- C:\WINDOWS\UNNMP.exe
2007-03-11 19:05 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-03-11 19:05 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-03-11 19:05 <DIR> d-------- C:\Program Files\Ahead
2007-03-06 18:14 <DIR> d-------- C:\Program Files\Microsoft Encarta
2007-03-05 21:43 <DIR> d-------- C:\Program Files\DivX
2007-03-04 19:57 87,608 --a------ C:\DOCUME~1\JAMESM~1\APPLIC~1\ezpinst.exe
2007-03-04 19:57 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-03-04 19:57 47,360 --a------ C:\DOCUME~1\JAMESM~1\APPLIC~1\pcouffin.sys
2007-03-04 19:57 <DIR> d-------- C:\Program Files\vso
2007-03-04 19:57 <DIR> d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\Vso
2007-03-04 10:25 <DIR> d-------- C:\DOCUME~1\LORNAM~1\APPLIC~1\Apple Computer
2007-03-03 21:38 784 --a------ C:\DOCUME~1\JAMESM~1\APPLIC~1\mpauth.dat
2007-03-01 16:18 <DIR> d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\Nero
2007-02-27 15:11 313 --a------ C:\WINDOWS\option.dat


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-18 12:40 -------- d-------- C:\Program Files\privacy guardian
2007-03-18 12:38 -------- d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\lavasoft
2007-03-17 22:18 2552 --a------ C:\DOCUME~1\JAMESM~1\APPLIC~1\wklnhst.dat
2007-03-11 19:50 -------- d--h----- C:\Program Files\installshield installation information
2007-03-11 19:43 33 --a------ C:\DOCUME~1\JAMESM~1\APPLIC~1\pcouffin.log
2007-03-11 19:43 1144 --a------ C:\DOCUME~1\JAMESM~1\APPLIC~1\pcouffin.inf
2007-03-11 19:43 1074 --a------ C:\DOCUME~1\JAMESM~1\APPLIC~1\pcouffin.cat
2007-03-06 21:13 395744 --a------ C:\WINDOWS\system32\drivers\timntr.sys
2007-03-06 21:13 39264 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-03-06 21:12 114048 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2007-03-06 17:56 -------- d-------- C:\Program Files\microsoft autoroute
2007-03-05 21:43 4184 --ahs---- C:\WINDOWS\system32\kgygaavl.sys
2007-02-19 16:29 -------- d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\officeupdate12
2007-02-13 19:05 -------- d-------- C:\Program Files\ubisoft
2007-02-03 19:35 88 -r-hs---- C:\WINDOWS\system32\15559ac3b4.sys
2007-02-03 19:35 -------- d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\corel
2007-02-02 20:47 98880 --a------ C:\WINDOWS\system32\drivers\psh_drv.sys
2007-01-26 00:44 -------- d-------- C:\DOCUME~1\JAMESM~1\APPLIC~1\ati
2007-01-26 00:25 -------- d-------- C:\Program Files\Common Files\wise installation wizard
2007-01-12 01:26 16384 --a------ C:\WINDOWS\cthelper.exe
2007-01-12 01:22 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"CTHelper"="CTHELPER.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb06.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ScanPanel.lnk]
"backup"="C:\\WINDOWS\\pss\\ScanPanel.lnkCommon Startup"
"location"="Common Startup"
"item"="ScanPanel"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{83db1084-772b-11db-b0fc-001485e2560b}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://adfarm.mediaplex.com/ad/ck/7022-425...6666-0?rfr=2799


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-03-25 11:27:31

Once again Buckeye, many thanks for your help, much appreciated.

I was wondering if my problems could be caused by faulty hardware? My computer is less than a year old but I googled one of the error messages ( stop: ox0000007e) and this indicated it could be caused by software or faulty ram. I am going to test my 2 sticks of ram individually today to see if they are faulty using memtest 86. I will post back the results here.

#8 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:18 AM

Posted 25 March 2007 - 10:01 AM

I certainly wouldn't rule out a hardware issue at this point. But your combofix log does show a few things that we should check out.

Are you getting any popups or being redirected to poker or gaming sites?

Let's clean your registry out a bit:
  • Please dowload: RegSeeker.
  • Click on "Clean The Registry" in the left panel.
  • Check all boxes (make sure the backup box in the lower left corner is selected!).
  • After it runs, click "Select All" on the bottom, then right-click on any selected item in the window and select "Delete Selected Items".
  • Click "Quit RegSeeker".
Now, open any of your installed programs, and make sure that everything opens ok. If so, reboot, then go back and run the RegSeeker again, do the same thing again if anything is found. When RegSeeker finds nothing else, then it's clean!


Let me know how it goes.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#9 dutchmul

dutchmul
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:06:18 AM

Posted 25 March 2007 - 03:49 PM

Hi Buckeye,

No pop ups or redirects to gaming/poker sites have occured.

I have checked both my sticks of ram and one of them is faulty. I have now removed this from my pc and am running with 1 stick(512mb) in single channel mode and comp now seems stable.

I have used regseeker many times and now have no entries showing in it except applications/radiotracker.exe and applications/googlearth.exe. both these progs were installed but have now been uninstalled. I seem unable to remove these 2 entries completely. Though it looks like they are just harmless remnants of these progs and are nothing to worry about.

I have reinstalled nod32. I have now run a full scan to completion with nod32 and it reports no threats found.

Thanks for all your help buckeye, it is very much appreciated. I will donate to the site to say thanks for all your help.As the problems I was having seem to have been caused by my faulty ram i have probably wasted your time, for which I am very sorry.

Anyway, if you think I may still be infected post back and I will take any advice or actions you wish to give me.

Once again, many thanks. :thumbsup: :flowers:

#10 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:18 AM

Posted 25 March 2007 - 04:12 PM

I'm glad I could help and it's good to hear that you isolated the problem. RAM is relatively cheap these days so that shouldn't set you back too much.

I did notice one line in your last Combofix log that I'd like to clean up. It's probably just a remnant from an old adware infection, but we can fix it easily.

Open Notepad, and copy everything in the code box below and paste it into a new notepad file. Change the "Save As Type" to "All Files". Save it as fixme.reg on your Desktop. Make sure there is NO blank line above "REGEDIT4"!

REGEDIT4

[-HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{83db1084-772b-11db-b0fc-001485e2560b}]
Locate fixme.reg on your Desktop and double-click on it. When it asks if you want to merge with the registry, click YES.


Reboot and you should be all set. :flowers:



Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

:thumbsup: :huh:
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#11 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:12:18 AM

Posted 09 April 2007 - 07:46 AM

Now that your problem appears to be resolved, this thread will be closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users