| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 60385 | 2005-07-30 23:34:00 | Startup Issues | pepper2 (8629) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 376887 | 2005-07-30 23:34:00 | I seem to have a change in my computer's starup procedures and so far I have been unable to isolate the problem. First the computer specs: CPU AMD Athlon XP 3000+ RAM size 512MB RAM type DDR333 HDD ST380011A Optical Drive CD-RW 52x24x52 Optical Drive ATAPI DVD-ROM 16xMax VIDEO NVIDIA GeForce 5200 (128MB) Microsoft XP Home SP2 The make is The PC Company and is two years old. The computer has been very reliable and stable - never had the box open. The change happened a few days ago and it is possible that I had an unscheduled shutdown, I pressed the start button inadvertently. On startup the screen shows a logo for Lenten System Recovery which it never showed before. Next the screen shows the box containing details of the drives starting with the Diskette drive, PRI Master, PRI slave, SEC Master, SEC Slave, etc. together with their details. Under that it gives a PCI Device Listing with about 10 lines. finally it has a line reading Verifying DMI Pool Data ... It then starts windows as normal. The second issue was with my Eudors Email. It would not start and gave an error message of "Out of date Table of contents" . I fixed this problem by deleting my INBOX and OUTBOX files and let the software regenerate these boxes itself. Now works perfectly as before. The tird issue is that I had occaision to try using my DVD drive for the first time and I could not ge it to work at all - the software did not recognise that there was a disk in the drive. also the drive door would not open until I shut the computer down and restarted it and then opened the drawer during the startup process. This problem may be copletely unrelated to the above. Other software recognises te drive but I was not prepared to play around with someone elses precious DVD. Otherwise the computer is going fine. I would appreciate some comments on the startup issue at least. Thank you |
pepper2 (8629) | ||
| 376888 | 2005-07-30 23:46:00 | Get hijackthis . merijn . org/files/hijackthis . zip" target="_blank">www . merijn . org From here . spywareinfo . com/~merijn/" target="_blank">www . spywareinfo . com Make a folder called HJUT . Unzip this file into it, run and scan . Post a log here . |
Speedy Gonzales (78) | ||
| 376889 | 2005-07-31 00:25:00 | I forgot to say that my antivirus software AVG is always up to date and I have zone alarm installed and up to date. XP is on automatic updates. LOG File Logfile of HijackThis v1.99.1 Scan saved at 11:11:55 a.m., on 31/07/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe C:\Program Files\ScanSoft\OmniPageSE\opware32.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 7.exe C:\WINDOWS\System32\fast.exe C:\WINDOWS\System32\taskswitch.exe C:\WINDOWS\system32\carpserv.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\Fast.exe C:\WINDOWS\system32\wscntfy.exe C:\DOCUME~1\MOFFAT~1.HOM\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 7.exe O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\System32\fast.exe O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - housecall60.trendmicro.com O16 - DPF: {058025FC-4416-436B-ACFD-03E6224C901C} (FileInfo Class) - diagnostics.support.hp.com O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Thanks |
pepper2 (8629) | ||
| 376890 | 2005-07-31 00:26:00 | sound's like the sytsem bios has somehow perhaps defaulted to show the detailed POST screen instead of what it may have been showing before which would be the 'quick boot' screen or similar....... | drcspy (146) | ||
| 376891 | 2005-07-31 00:45:00 | Tick these entries. And click on fix checked. Close the browser/s first. Then reboot. O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) I would also update Java. BUT yup, I would go in to the BIOS and reconfigure it as well. |
Speedy Gonzales (78) | ||
| 376892 | 2005-07-31 01:15:00 | As drcspy has already pointed out, it definitely sounds like the BIOS has been changed to show post details instead of the quickboot option This can happen 4 ways: 1. Someone has manually changed the BIOS settings. 2. Your motherboards battery is flat 3. A virus has attempted to write to the BIOS (unlikely if AVG is up to date) 4. The BIOS is failing On most of the PC Company machines I've worked on they have suppled a reasonably good manual with them. Have a look through it and see if there is a BIOS section in it, it will explain what each section of the BIOS does and how to configure it. If not, they will have supplied a manual for your motherboard and it will have the BIOS instructions in it. Unless you are experienced altering BIOS rules make one change at a time (and remember what it was you changed) then reboot Continue doing this until the machine is booting up the way you like it. If you get in trouble just rest the BIOS to defaults and start again Take care though as a wrong BIOS setting can make your system unstable or unbootable and sometimes makes it necessary to open the machine up and move jumpers etc to boot the default bios settings again. If you can find the BIOS info that came with the machine read it before you start changing settings |
bartsdadhomer (80) | ||
| 376893 | 2005-07-31 01:48:00 | Thank you folks for your good advice. Yes I know about one change at a time. The BIOS showed Quick startup (or whatever was the name) as enabled so I did not change it. The drive for first choice for boot info was shown as Floppy and I changed that to the hard drive with Floppy as the second choice. It now starts without all the extra writing to the screen. I have also removed the two lines as recommended and as far as I can tell there has been no adverse effects. I will run with this setup for a few days to see if there are any other problems showing up. Incidentially I have noted the reference to MS Money which I have never used. I did have Google Toolbar installed for awhile but it has been removed. so you can see i was surprised to note those entries on the Hijackthis Log. Thank you |
pepper2 (8629) | ||
| 1 | |||||