Taskbar freezing after connecting to internet

  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2852

Post 3+ Months Ago

JrzyCrim wrote:
I found this about Updater.exe. It would be my guess that updater1.exe is related.
http://ask-leo.com/updaterexe_.html

This is the only thing I could find about loader.dll. It's another hijack this log. The person helping out wasn't sure about it either.
http://www.mytechsupport.ca/support/top ... IC_ID=3716


It sound strange and suspicious, there's no information out there about it and the name says nothing, I agree with you it has to be the problem or part of it.

//EDIT: tazmayneo, try to rename the two files, C:\WINDOWS\loader.dll and C:\WINDOWS\updater1.exe and restart windows to see how it work
  • Anonymous
  • Bot
  • No Avatar
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post 3+ Months Ago

  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Both are not in the Windows folder.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Try this:

Go to folder options > veiw and uncheck 'hide protected operating system files'. Click OK and then see if you can find those files.
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Still no files.

I just found a file called lbbho, configuration settings or something. I should delete that right?
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Yes, run hijack this and fix these entries:


O2 - BHO: C:\WINDOWS\lbbho.dll - {D048ACF8-5F23-4CDB-AB09-519510234B29} - C:\WINDOWS\lbbho.dll
O4 - HKCU\..\Run: [updater.dll] C:\WINDOWS\updater1.exe
O4 - HKCU\..\Run: [loader.dll] C:\WINDOWS\loader.dll

Also, did you follow the instructions in the sight ATNO provided for removing the browser helper object lbbho.dll?
http://www.pestpatrol.com/pestinfo/r/relatedlinks.asp
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Yep, I did. But I could not find this HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{efd84954-6b46-42f4-81f3-94ce9a77052d}. It stopped at microsoft. The sub-folders for microsoft are MasterAggregatorForIPP, MediaPlayer, Multimedia, and Windows Media Tool.

I'll try running HiJackThis and getting rid of those.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

I suspect some other spyware removal tools you may have used left remnants of these things. After running hijack this, reboot, rescan and post a new log,
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Alright, I deleted those files. Although the first one didn't show up. The computer started up fine and connecting to the internet was fine. But the taskbar is still frozen. Here's the new log.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\DiskeeperLite\DKService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\System32\sistray.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Documents and Settings\Maybelline Cabrera\My Documents\HiJackThis\HijackThis.exe

O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\en-us\msntb.dll
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [3Degrees] C:\Program Files\threedegrees\threedegrees.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/c ... /tt2_x.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.0.8.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://mirror.worldwinner.com/games/v47 ... ckwerx.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003 ... scan53.cab
O16 - DPF: {785EA525-5066-495F-ADF6-3B8316515DEF} (Collapse Control) - http://mirror.worldwinner.com/games/v46 ... llapse.cab
O16 - DPF: {78A730D4-0DF3-4B65-8DD2-BFCD433CEE30} - http://www.surfsecret.com/inst/CDRBInstaller.exe
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://mirror.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldwinner.com/games/v45 ... rdmojo.cab
O16 - DPF: {9DD6A49C-CF35-4544-BF13-34DF413BCF7A} ({9DD6A49C-CF35-4544-BF13-34DF413BCF7A}) - http://195.39.204.19/codebase/Stealthnet.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 2902546296
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/contr ... assCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/sh ... wflash.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://www.paltalk.com/prod/RegDload.CAB
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D287FC85-B8BB-4446-B3FF-C7D2E3657C16}: NameServer = 202.88.64.61 202.88.64.62
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Launch task manager and end this process: sistray.EXE

run hijack this again and fix this item:
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE

Reboot and see if the problem still exists.

Found this: http://www.lafn.org/webconnect/mentor/startup/EZB.HTM

It's also a legitimate program:

Quote:
System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. The utility itself is not of much use in our opinion.


It's not really necessary if it is the latter so either way it should be safe to remove this.

More info related to sistray.exe which suggests it could be related to the Prova Virus: http://www.windowsstartup.com/wso/brows ... 00&end=225
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Deleted. Started fine, connected fine, taskbar frozen. I'm about to pull my hair out.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

What type of graphics card do you have? I'm curious about what sistray.exe was actually doing on your system.
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

This is where you're going to have to tell me where to go to find that information 'cause I have no clue.
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2852

Post 3+ Months Ago

tazmayneo wrote:
Deleted. Started fine, connected fine, taskbar frozen. I'm about to pull my hair out.


*patience little grasshopper, sooner or later we'll find what's causing you this trouble* :wink:

- Right click on your desktop and select properties
- Select Settings tab and click on advanced button
- In the next window select Adapter tab
- There you'll find Adapter Type in the upper left of that window
- Post Adpter Information here too

//EDIT: lol, me too, I was too busy looking at my spelling :lol:
Well, now he has two differents ways to get that information :wink:
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

tazmayneo wrote:
This is where you're going to have to tell me where to go to find that information 'cause I have no clue.


Goto start > run, enter this:

msinfo32.exe

When System info pops up, go to components > Display. On the right side see what's listed beside Name at the top.

*lol I missed your post labrego :)
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

AG315E-32 is what it says.
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2852

Post 3+ Months Ago

tazmayneo, can you check your event log (Control Panel - Administrative Tools - Event Viewer - System Log) to see if there's is a recent error logged there? Look for something new or a repetitive error
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

that is a SIS vga card. So that wasn't the problem. No harm done there...

Before I recommend anything drastic I do have another idea. Close your instant messenger programs one at a time and see if the problem remains. Aim, then check, close MSN and check again etc.

In fact, reboot and before going on line close one and then check and see if the problem goes away.
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Most of the errors are coming from DCOM. One from atapi, one from serial, two from Service Control Manager.

And when I reboot, none of my Instant Messengers start up. I stopped doing it because of the problem.

Also, Yahoo and AIM seem to work fine when the taskbar is frozen, but MSN freezes.
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2852

Post 3+ Months Ago

Can you post the error messages here?
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

DCOM
Access denied attempting to launch a DCOM Server. The server is:
{00020906-0000-0000-C000-000000000046}
The user is Unavailable/Unavailable, SID=Unavailable.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.



DCOM got error "The service did not respond to the start or control request in a timely fashion. " attempting to start the service ccPwdSvc with arguments "" in order to run the server:
{DBA28A20-5CE1-4E8D-AD35-418B62269E54}

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


The server {520CCA63-51A5-11D3-9144-00104BA11C5E} did not register with DCOM within the required timeout.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Service Control Manager
Timeout (30000 milliseconds) waiting for the Symantec Password Validation Service service to connect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


The Diskeeper service terminated unexpectedly. It has done this 1 time(s).

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Access denied attempting to launch a DCOM Server. The server is:
{00020906-0000-0000-C000-000000000046}
The user is Unavailable/Unavailable, SID=Unavailable.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


atapi

The device, \Device\Ide\IdePort1, did not respond within the timeout period.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

serial

While validating that \Device\Serial2 was really a serial port, the contents of the divisor latch register was identical to the interrupt enable and the receive registers. The device is assumed not to be a serial port and will be deleted.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Try ending this process and see if that helps:

MsgPlus.exe

Also, in the event viewer, look under application for anything that might relate.

If the event log doesn't turn up anything useful, then I would close all programs and enter this from start >Run:

sfc /scannow

Have your XP CD ready.
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Alright for Applications, I've got Application Hang, Application Error, and Ci. There's a crapload, so if you want me to post the descriptions, it's going to take a while.

Edit- There's also VSS, EventSystem and MsiInstaller.

Quote:
Try ending this process and see if that helps:

MsgPlus.exe


Do you want me to end that before I connect to the internet? 'Cause right now, the taskbar let loose. It's been letting loose at different times.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

If most of them are related to the same applications, then just post a few.

did killing MsgPlus.exe help at all? You might try closing IE or whatever browser you are using and then kill that process and see if the problem persists,
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2852

Post 3+ Months Ago

Seems that we can get something from there, I think we'll wait for the posting.
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

I'll reboot, end MsgPlus.exe, connect to the internet, and see if it freezes. Then I'll paste some of the descriptions.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Sounds like a plan. I'm determined to get this resolved one way or the other.
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2852

Post 3+ Months Ago

ditto, same here
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Alright. I rebooted, ended MsgPlus.exe, connected to the internet. I tried to open SlimBrowser, but it seemed like it froze. And then several seconds later, it let up but SBrowser didn't open. So I opened Task Manager and ended sbrowser.exe, and it froze again. So I opened Opera and came here. As I was typing up the second sentence, the taskbar unfroze(pretty fast compared to before lol). So, I don't know if it's MsgPlus.exe or what.
  • tazmayneo
  • Novice
  • Novice
  • tazmayneo
  • Posts: 31
  • Loc: Saipan

Post 3+ Months Ago

Application Error

1000

Faulting application prizesurfer.exe, version 1.0.5.0, faulting module unknown, version 0.0.0.0, fault address 0x000c0100.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Application Hang

1002

Hanging application sbrowser.exe, version 3.8.3.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Ci

4124

Content index on c:\system volume information\catalog.wci is corrupt. Please shutdown and restart the Indexing Service (cisvc).

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

4126

Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci. Index will be automatically restored by refiltering all documents.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

EventSystem

4609

The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\nt\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

VSS

8193

Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

MsiInstaller

11706

Product: Paint Shop Pro 7 ESD -- Error 1706.No valid source could be found for product Paint Shop Pro 7 ESD. The Windows Installer cannot continue.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2852

Post 3+ Months Ago

I think this is related,
Content index on c:\system volume information\catalog.wci is corrupt. Please shutdown and restart the Indexing Service
let me post you some instructions
  • Anonymous
  • Bot
  • No Avatar
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post 3+ Months Ago

Post Information

  • Total Posts in this topic: 89 posts
  • Users browsing this forum: No registered users and 32 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 1998-2014. Ozzu® is a registered trademark of Unmelted, LLC.