Tech Support Guy banner
Status
Not open for further replies.
1 - 10 of 10 Posts

· Registered
Joined
·
16 Posts
Discussion Starter · #1 ·
HI. Having so many problems. Am running XP with SP2, Sygate and Avast. Have SpywareBlaster, SpywareGuard, SpySweeper, Ad-Adware SE, Win Patrol, GIANT Anti-Spy, Hi-JackThis, HiJackThis Analyzer, Spybot, and CWShredder. Only spyware programs I keep running all the time are SpywareBlaster, SpywareGuard and Win Patrol. Two days ago I dl Microsoft's Anti-Spy and kept it running but I disabled it late last night. I use all others every day but arn't running in background. Have no viruses or spyware that anything could find. I always keep my system defragged with Diskeeper 8 and run WinXP's 'error checker' periodically. Now, for about 10 or more time per day for about a week or more, I've gotten that stupid drwatson showing up in my task manager and everything will freeze up. I know what the program is but don't know why it is constanty showing up. I disabled it (or thought I did) but it is still showing up and causes me to freeze. Then, out of blue yesterday, on left side of desktop appears the long wide bar from top to bottom of screen that shows 'Folder Tasks' at the top, right under that 'Other Places', and under that 'Details' and all three give the arrows to expand for more options. That should only appear in folders, etc., not right on top of desktop. And, it was completely locked...could not get rid of it no matter what I did to try and fix it. Why/how would that happen? And, everything on my desktop was locked...I could open folders but not drap and drop or move folders around on desktop, and the setting would not work to allow me to fix it nor could I change wallpaper which I tried to do just to see if I could. Well, I tried everything and finally decided to use the Registry Optimizer which is part of my program 'Advanced System Optimizer'. It fixed the desktop problem. But, this morning I noticed in my Start Menu, my control panel was missing and in it's place was 'Set Program Access and Defaults', so I had to hunt the Control Panel up in my system and put a shortcut on my desktop which I dragged into my Start Menu. I was fine until tried to open Outlook Express and I froze up which led me to do Control/Alt/Del and was able to open Task Manager and lo and behold what was there? Dr.Watson of course. Yesterday I ran HiJackThis and followed with HiJackThis Analyzer. Below is copy of HiJack Analyzer which was done yesterday, but nothing has changed except I did remove the entry R3 (Default URL SearchHook is missing).
I re-installed Windows XP about a month and a half ago and surely do not wnat to have to re-do it. I hope I can somehow get to the bottom of this. I disabled 'System Restore' when I went into Safe Mode yesterday to run HiJack and HiJack Analyzer. I re-engaged it after and of course lost all restore points. Computers are CRAZY (or maybe perhaps some of us who use them......like me). Can anyone help me? Or has anyone ever had similar problem? Thank you for your help. Below is HiJackThis Analyzer as of yesterday.

Log was analyzed using KRC HijackThis Analyzer - Updated on 1/12/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.98.2
Scan saved at 1:17:20 PM, on 1/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\A.MyStuff\Diskeeper8Pro\DkService.exe
C:\Program Files\A.MyStuff\SpyApps\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\A.MyStuff\SpyApps\MicrosoftAnti-Spy\gcasServ.exe
C:\Program Files\A.MyStuff\SpyApps\MicrosoftAnti-Spy\gcasDtServ.exe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\A.MyStuff\AdobeReader\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\A.MyStuff\SpyApps\BillP Studios\WinPatrol\WinPatrol.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\A.MyStuff\SpyApps\MicrosoftAnti-Spy\gcasServ.exe"
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1102870761626

End of KRC HijackThis Analyzer Log.
 

· Registered
Joined
·
2,189 Posts
Dr.Watson at times grinds instead of its purpose of smoothing things along. Often here, it's recommended to disable it;

Disabling Dr. Watson via the GUI Interface:

Start/Run Type: drwtsn32.exe

Clear all check marks from Options boxes.

This will disable Dr. Watson from running.

restart and see what happens....Also await rereading of you hjt log.
 

· Registered
Joined
·
16 Posts
Discussion Starter · #3 ·
Yes, that is way I disabled it yesterday but it still was active today. But, I will give it another try and see what happens and also post my HJT log. I will change settings to 'show all files and folders' and 'show hidden files and folders' and go into safe mode and do a HiJack, then will post that. I'm guessing that is way you want me to post it.
 

· Registered
Joined
·
16 Posts
Discussion Starter · #5 ·
Never mind safe mode. The stupid Num Lock stayed on and I froze in safe mode. Tried it twice. Turned off computer, unplugged cord to computer and wall outlet and held on/off button on front of computer in for couple of minutes, plugged computer back up, restarted and tried it again. No go. Usually that will reset everything if that happens.....didn't this time. So, the HiJack log is done in regular mode.

Logfile of HijackThis v1.98.2
Scan saved at 11:48:12 AM, on 1/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\A.MyStuff\SpyApps\BillP Studios\WinPatrol\WinPatrol.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ePrompter\ePrompter.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\A.MyStuff\Diskeeper8Pro\DkService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\A.MyStuff\AdobeReader\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\A.MyStuff\SpyApps\BillP Studios\WinPatrol\WinPatrol.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1102870761626
 

· Registered
Joined
·
16 Posts
Discussion Starter · #7 ·
bobol said:
another way to disable dr.watson;
Start/Run/ type regedit
after you do a backup of registry.......
Find:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug
and change the value of "Auto" to 0 to disable
Ok, I did the above. That will send ole Doc.Watson off duty. :D
 

· Registered
Joined
·
16 Posts
Discussion Starter · #9 ·
Don't really know yet. Tried to go into safe mode and NumLock stayed on and couldn't check anything or run HiJack. Had to shut down. I disabled my Doc. Watson for good using the Registry. But, what would cause my Control Panel to just disappear I wonder?
 

· Registered
Joined
·
16 Posts
Discussion Starter · #10 ·
Don't know for sure if my problems are solved yet. I re-engaged Dr.Watson so I could see what programs were/are causing any conflicts. So far, no freeze ups or 'funny' stuff has happened. Strange how my control panel just disappeared though. Had to search for it and put shortcut to it in start menu.
 
1 - 10 of 10 Posts
Status
Not open for further replies.
Top