A Virus??

--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its calling me to the darkside!
 
Sorry to be slow in responding. I'll try to watch more often over the weekend.
It CPU % is drwtsn32.exe at about 78%. I googled that file and it
is the Dr Watson error checking utility. But it doesn't stop, it
just keeps going.
Dr Watson is more of an error reporting utility. I've never seen it even appear on the task list unless something else has failed. There's a description of Dr Watson at http://support.microsoft.com/kb/308538/ .

Look in your c:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson directory for a file named Drwtsn32.log. Using notepad, or any text file viewer, look for lines like starting with "Application exception occurred:" You should find something like this (a failure of Acrobat Reader shown in my log file, as recorded by drwatson.

Application exception occurred:
App: C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe (pid=3180)
When: 10/15/2004 @ 13:13:31.484
Exception number: c0000005 (access violation)

Also, open the System Event Viewer (Control Panel-> Administrative Tools-> Event Viewer) and look in the Application and System panels. Look for red X's to mark failures. You can double click on any line to get more information about the failure. I expect you will see multiple failures of some time. Let us know what is failing. (Some failures are harmless; others are not.)

I wouldn't worry about AVG I/O counts at this time. Any AV program will have very high counts if it has performed a scan of your hard drives.

Guy
 
I checked out the site and it says that :WinSock XP Fix offers a last resort if your Internet connectivity has been corrupted due to invalid or removed registry entries. I can connect to the internet it's just running my programs that is very slow. Do you think thatthis may help?

Thanks,
Bruce
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its
calling me to the darkside!
--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/

My Daughter's Art/Photo Site, Please have a look http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
 
Hi digitalshooter,
Restore is a Win item that lets you go back in time to a date when
your PC operated fine. If any of those have spy or virus, most
programs will not clean within a restore point.
Are you saying to empty the Restore folder? I guess that will erase any restore points that have been set. Last week I restored it to about a month ago. That didn't help so I reversed the restore. But I ran adaware, spy sweeper and my AVG anti virus. For some reason that helped. About 2 days later when I booted up, spy sweeper came up with a file trying to access the internet, it looked lik an HP file. I have a hP printer so I thought it was the HP software so I clicked OK. I think that is how my problems started again.
Prefetch is files theat Win XP looks for to help the startup
process. Viruses and spys hide everywhere.
OK, so you are saying to delete everything in the prefetch folder?
As a tech, I have learned that if initial runs of anti virus,
spyware and a restore point dont help, in safe mode, then I remove
the drive and put in a machine as a backup and try to check it as a
"d" drive.

My tactics are sometimes more of a challenge because as stated
earlier, sometimes it is better to repartition/reformat/reload.

I love a good challenge though. If you reload make sure you
REPARTITIOn also then reformat and reload.
My C; Drive is a 40gb IDE drive and is not partitioned. I have two other drives, 2 - 250gb SATA drives that are partitioned and striped so the system reads them as one drive that I use for my programs and storage. If I do reformat the C: drive I don't think that I will be partitioning it as I will be using it for Windows, e-mail and my spyware/virus programs. What do you mean by "Reload" re-installing windows?
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its
calling me to the darkside!
Thanks again,
Bruce
--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/

My Daughter's Art/Photo Site, Please have a look http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
 
About 2 days later when I booted up, spy
sweeper came up with a file trying to access the internet, it
looked lik an HP file. I have a hP printer so I thought it was the
HP software so I clicked OK. I think that is how my problems
started again.
It might be helpful if you had the exact name of the file. Does your spy sweeper maintain a log somewhere that you could look it up?

Guy
 
Restore is a Win item that lets you go back in time to a date when
your PC operated fine. If any of those have spy or virus, most
programs will not clean within a restore point.
Are you saying to empty the Restore folder? I guess that will erase
any restore points that have been set. Last week I restored it to
about a month ago. That didn't help so I reversed the restore.
But I ran adaware, spy sweeper and my AVG anti virus. For some
reason that helped. About 2 days later when I booted up, spy
sweeper came up with a file trying to access the internet, it
looked lik an HP file. I have a hP printer so I thought it was the
HP software so I clicked OK. I think that is how my problems
started again.
Yes it will, I say this so that none of the checkers find things it cannot repair within the restore points.
Prefetch is files theat Win XP looks for to help the startup
process. Viruses and spys hide everywhere.
OK, so you are saying to delete everything in the prefetch folder?
es it will not hurt anything.
As a tech, I have learned that if initial runs of anti virus,
spyware and a restore point dont help, in safe mode, then I remove
the drive and put in a machine as a backup and try to check it as a
"d" drive.

My tactics are sometimes more of a challenge because as stated
earlier, sometimes it is better to repartition/reformat/reload.

I love a good challenge though. If you reload make sure you
REPARTITIOn also then reformat and reload.
My C; Drive is a 40gb IDE drive and is not partitioned.
You need to delete the c: partition to completely erease it. It could have a boot sector issue.

I have two
other drives, 2 - 250gb SATA drives that are partitioned and
striped so the system reads them as one drive that I use for my
programs and storage. If I do reformat the C: drive I don't think
that I will be partitioning it as I will be using it for Windows,
e-mail and my spyware/virus programs. What do you mean by "Reload"
re-installing windows?
Placing the CD in the CD deive and complete reinstall of the OS. Not a repair/
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its
calling me to the darkside!
Thanks again,
Bruce
--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/
My Daughter's Art/Photo Site, Please have a look
http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its calling me to the darkside!
 
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its calling me to the darkside!
 
If your machine is hijacked, it will restore your connection back. You can be hijacked and still get to the Internet.

--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its calling me to the darkside!
 
If your machine is hijacked, it will restore your connection back.
You can be hijacked and still get to the Internet.
I See. Ok I'll give it a try. Also When I just booted up I got an error message that jmy AVG Firewall was not running. I opened it and it is running but I checked on the applications that it had in the log and the Dr Watson was being blocked. I changed it to allow it to run and now my cpu isn't running at such a high rate, now in the 40-50% range total. The process now using up more cpu power is changing between avgw.exe and System Idle Process. It keeps changing back and forth.
What does this seem to mean to you?
Thanks,
Bruce
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its
calling me to the darkside!
--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/

My Daughter's Art/Photo Site, Please have a look http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
 
About 2 days later when I booted up, spy
sweeper came up with a file trying to access the internet, it
looked lik an HP file. I have a hP printer so I thought it was the
HP software so I clicked OK. I think that is how my problems
started again.
It might be helpful if you had the exact name of the file. Does
your spy sweeper maintain a log somewhere that you could look it up?

Guy
Hi Guy,
I am checking my Spy Sweeper log now. I keep finding this message:

The Spy Communication shield has blocked access to: WWW.TOPMOXIE.COM Also when I boot up it gives me an alert about the same site. I am going through the whole log now and will see if I can find the message that it gave me and I allowed. If it is not there doesn't windows keep a log somewhere also?
Thanks
Bruce
I am continuing to look t
--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/

My Daughter's Art/Photo Site, Please have a look http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
 
About 2 days later when I booted up, spy
sweeper came up with a file trying to access the internet, it
looked lik an HP file. I have a hP printer so I thought it was the
HP software so I clicked OK. I think that is how my problems
started again.
It might be helpful if you had the exact name of the file. Does
your spy sweeper maintain a log somewhere that you could look it up?

Guy
Guy, I think this may be the file, here is a line from my spysweeper logg from last Monday at 7:15PM. I think thatis about the time I allowed it.:

7:15 PM: Access to Hosts file allowed for D:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTRA08.EXE

What do you think?

--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/

My Daughter's Art/Photo Site, Please have a look http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
 
safe/ mode?
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its calling me to the darkside!
 
If your machine is hijacked, it will restore your connection back.
You can be hijacked and still get to the Internet.

--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its
calling me to the darkside!
I ran it and there were some error messages while trying to back up my registry. Anyway after the reboot I now get an error message that my AVG Firewall is disabled. When I try to re-activate it I get this error message "An error occured while starting AVG Firewall. This operation returned because the timeout period expired. (1460)"

I think that this program didn't help and that I should try to restore my original registry file.

--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/

My Daughter's Art/Photo Site, Please have a look http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
 
Not yet but I will.

Please respond to my other messages from a little while ago so I know if there is anything els that I need to do.
safe/ mode?
--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its
calling me to the darkside!
--
http://CusinBrucie.smugmug.com/gallery/1285864/1/60412211

http://borkofsky.ilovesuccess.net/

My Daughter's Art/Photo Site, Please have a look http://lipping.myexpose.com/gallery/
Nikon D200, 18-200mm VR lens
 
and in safe mode. You can always reinstall zone alarm. Your problem is topmoxie.com.

--
Thanks,

Digitalshooter!

Member of the 7D and Beercan Cult!

The light at the end of the tunnel is becoming clearer and its calling me to the darkside!
 

Keyboard shortcuts

Back
Top