1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Computer Locks Up and Error Messages

Discussion in 'Malware and Virus Removal Archive' started by larsonjean, 2007/11/17.

  1. 2007/11/17
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Hi,
    I have an old Windows 98 desktop that I still use now and then for my backup computer and I would like to figure out why it is locking up after doing numerous things with different programs.

    I am running Windows 98 on a Gateway computer and I have tried to delete programs but nothing helps. I have run Super AntiSpyware and they said they found no malacious programs.

    After cleaning up several programs, I get these two error messages when I need to reboot my computer now.

    1st Error Message - speedy.bat - Cannot find this file 'speedy.bat' (or one of its components). Make sure the path and filename are correct and that all required libraries are available.

    2nd Error Message - :Desktop - Could not load or run 'speedy.bat' specified in the WIN.INI file. Make sure the file exists on your computer or remove the reference to it in the WIN.INI file.

    I don't know what this speedy.bat does and also I don't know how to remove it from the WIN.INI file and if I really should.

    It seems as though this computer has more than one problem so I would appreciate any help that would start me off on my troubleshooting.

    Jean

    Thank you.
     
  2. 2007/11/17
    mattman

    mattman Inactive Alumni

    Joined:
    2002/06/10
    Messages:
    8,198
    Likes Received:
    63
    Hi Jean,
    Most information I see points to a worm W32.Opaserv:
    http://www.techspot.com/startup/7887/
    http://www.pcreview.co.uk/startup/Speedy.bat.php

    The worm may have been removed, but Windows is still trying to load speedy.bat even though it has been removed.

    If you go to Start -> Run and enter msconfig, you should be able to uncheck items under the Startup and Win.ini tabs, otherwise follow the procedures here:
    http://www.sophos.com/security/analyses/w32opaservp.html (Recovery tab)
    http://www.symantec.com/security_response/writeup.jsp?docid=2003-100318-3337-99&tabid=3

    If you would like, ask for this thread to be transferred to the security forum.

    Matt
     
    Last edited: 2007/11/17

  3. to hide this advert.

  4. 2007/11/18
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Hi,
    Thanks for your help. I'll try to follow some of the links and see if I can figure out what to do.

    How do I get this moved to the security section as you suggested?

    Thanks again for your help. I'll keep you posted.

    Jean
     
  5. 2007/11/19
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Jean
    If you are still having problems, Then please do the following.

    Download a copy of HijackThis installer from here and save it to your Desktop.

    1. Save HJTInstall.exe to your desktop.
    2. Double-click on the HJTintall.exe icon on your desktop.
      (Let it install to the default location C:\Program Files\Hijackthis)
    3. Continue to click Next in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
    4. Put a check by Create a desktop icon and then click Next again.
    5. Continue to follow the rest of the prompts from there.
    6. At the final dialogue box click Finish and it will launch HijackThis.
    7. Click on the Do a system scan and save a log file button.
      (It will scan and the log should open in Notepad.)
    8. Click on "Edit" > "Select All" to higlight the entire Notepad contents.
    9. Then click on "Edit" > "Copy ".
    10. Come back here to this thread and Paste the log in your next reply.
      (Right-click in the message body field and select "Paste ".)
    CAUTION: DO NOT have HijackThis "fix" anything without carefully following expert guidance. Otherwise, you might render your computer unstable or even unbootable. Most of what HijackThis finds will be harmless or even required.

    Thanks
    Geri
     
    Geri,
    #4
  6. 2007/11/19
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Hi,
    Thank you for sending the suggestions to help me fix my friend's computer. I will have to wait until I can get over to her house to try the fixes. I'll get back to you when I do and let you know how I make out.

    Have a Happy Thanksgiving and I'll be in touch.

    Jeanne
     
  7. 2007/11/19
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    I am using my old Windows 98 computer right now and I'm sure I am still having a problem with it. I have tried to follow some of the instructions that Mattman provided but they are complicated and I'm not that computer savy. I also tried to run the program suggested, Registry Booster, but it wouldn't work because I am on a Network.

    (Sorry about my previous posting when I said [Thank you for sending the suggestions to help me fix my friend's computer. I will have to wait until I can get over to her house to try the fixes. I'll get back to you when I do and let you know how I make out.] I have another posting on the XP Help Line and I got the two questions mixed up.)

    I did take Geri's suggestion and went to HiJack This and the following is what the log said:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:19:04 PM, on 11/19/07
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    C:\WINDOWS\SYSTEM\TELEPATH.101\tpexe.exe
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\STARTER.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\RUNDLL32.EXE
    C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
    C:\WINDOWS\SYSTEM\M1RMMON.EXE
    C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
    C:\WINDOWS\RUNDLL32.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_14\bin\ssv.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [rmmon] C:\WINDOWS\SYSTEM\m1rmmon.exe
    O4 - HKLM\..\Run: [ICSDCLT] C:\WINDOWS\rundll32.exe C:\WINDOWS\SYSTEM\icsdclt.dll,ICSClient
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O4 - HKLM\..\Run: [MMHID] rundll32 mmhid.dll,StartMmHid
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    O4 - HKLM\..\RunServices: [telepath] TELEPATH.101\tpexe.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_14\BIN\SSV.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_14\BIN\SSV.DLL
    O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB
    O16 - DPF: Win32 Classes - file://C:\WINDOWS\Java\classes\win32ie4.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - https://support.gateway.com/support/profiler//PCPitStop.CAB

    --
    End of file - 3385 bytes


    By the way I do want you to know that I went into msconfig and noticed that I have a: run= c:windows speedy.bat
    but there is not a checkmark in front of it.

    Any additional help will be appreciated.

    Thank you. Jean
     
  8. 2007/11/20
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Jean
    Please do this.

    Enable the 'Show Hidden Folders' option, like this:
    Click Start.
    Open My Computer.
    Select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.
    Click OK.


    Now Navigate to C:\Windows\system

    Find the win.ini file, Right click it and choose Open with, select NotePad.

    Copy and paste the contents of that file here.

    Thanks
    Geri
     
    Geri,
    #7
  9. 2007/11/21
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Hi Geri,
    I navigated and found the win.ini file in the C:Windows folder. I hope the following is what you wanted. Please let me know. Thank you.

    Jean

    [windows]
    NullPort=None
    UninstallPath=C:\
    Programs=EXE COM BAT PIF SCR
    ;Rem TShoot: norun=hpfsched
    norun=hpfsched c:\windows\speedy.bat
    load=

    [Desktop]
    Wallpaper=(None)
    TileWallpaper=0
    WallpaperStyle=2

    [intl]
    iCountry=1
    ICurrDigits=2
    iCurrency=0
    iDate=0
    iDigits=2
    iLZero=1
    iMeasure=1
    iNegCurr=0
    iTime=0
    iTLZero=0
    s1159=AM
    s2359=PM
    sCountry=United States
    sCurrency=$
    sDate=/
    sDecimal=.
    sLanguage=enu
    sList=,
    sLongDate=dddd, MMMM dd, yyyy
    sShortDate=M/d/yy
    sThousand=,
    sTime=:

    [Fonts]

    [Compatibility]
    _3DPC=0x00400000
    _BNOTES=0x224000
    _LNOTES=0x00100000
    ACAD=0x8000
    ACT!=0x400004
    ACROBAT=0x04000000
    AD=0x10000000
    ADW30=0x10000000
    ALARMMGR=0x0040000
    ALDSETUP=0x00400000
    AMIPRINT=0x04000000
    AMIPRO=0x04000010
    APORIA=0x0100
    APPROACH=0x0004
    BALER=0x08000000
    BMAPP=0x0004
    CASMONEY=0x00200000
    CAVOIDE=0x00200000
    CCMAIL=0x00200000
    CCMCWFY=0x80
    CHARISMA=0x2000
    CONFIG=0x00400000
    CORELDRW=0x48000
    CORELPNT=0x08000000
    COSTAR=0x0004
    CP=0x0040
    CROSSTIE=0x00000400
    DARCH=0x80
    DESIGNER=0x00002000
    DIRECTOR=0x00800000
    DPLANNER=0x00200000
    DRAW=0x2000
    DS40=0x8000
    DTWIN20=0x00000400
    EAP=0x0004
    ED=0x00010000
    EXCEL=0x1000
    EXPASTRO=0x04000000
    EXTYPWND=0x00200000
    FAXVIEW=0x04000000
    FAXWORKS=0x00000400
    FH4=0x00E08000
    FLW2=0x8000
    FMPRO=0x00200000
    FREEHAND=0x8000
    FULLTEXT=0x20000000
    GIFTMAKE=0x20000000
    GUIDE=0x1000
    HDW=0x04800000
    HGW=0x8000
    HGW2EXE=0x8000
    HGW3EXE=0x8000
    HJDRAW=0x00400000
    IDAPICFG=0x00400000
    IDRAW=0x04008000
    ILLUSTRATOR=0x8000
    IMPROV2=0x00000000
    INFOCENT=0x04000000
    INSIGHT=0x00000400
    INSTAL1=0x00400000
    INSTALL=0x00400000
    INTERMIS=0x10000000
    IS20INST=0x00000000
    IVIHEALT=0x00400000
    JEOPARDY=0x00200000
    JW=0x00000000
    KALOAD2=0x00400000
    KEYCAD=0x8000
    LE_ADMIN=0x00400000
    LUI=0x20000000
    MAILSPL=0x10000000
    MAKER=0x00200000
    MAPS1=0x04008022
    MATH=0x00000001
    MAVIS=0x00200000
    MCOURIER=0x0800
    MFWIN20=0x02000000
    MILESV3=0x1000
    MILESV40=0x4
    MOZART=0x40000000
    MSARTIST=0x00100000
    MSBHUMAN=0x4
    MSREMIND=0x10000000
    MVIEWER2=0x40200000
    MYINV=0x00200000
    MYST=0x08000000
    NAFTA1=0x4008022
    NBAMW4V4=0x04000000
    NETSET2=0x0100
    NOTES=0x200000
    NOTSHELL=0x0001
    OPERATOR=0x02000000
    OUTPOST=0x00000000
    OWLAPP=0x00400000
    PACKRAT=0x0800
    PAINTER=0x00000000
    PAWC8DC3=0x00400000
    PAWIN=0x4
    PEACHW=0x04800004
    PIXIE=0x0040
    PLANIT=0x0004
    PLANNER=0x2000
    PLUS=0x1000
    PM4=0xA000
    PM5APP=0x8000
    PP4=0x00000000
    PR2=0x2000
    PRINTHLP=0x0004
    QAPLUSW=0x0004
    QLIIFAX=0x00400000
    QUAKE=0x80
    QW=0x08000000
    RELAY=0x20000000
    REM=0x8022
    RR2CD=0x00200000
    RX=0x00000400
    RXL=0x00000400
    SETUP=0x00000000
    SIDEKICK=0x0004
    SLEEPER=0x10000000
    SPCB=0x04008000
    SPORTJEP=0x00200000
    SPWIN20=0x00400000
    ST2=0x4008022
    STRAUSS=0x40000000
    STRAV=0x40000000
    SCHUBERT=0x40000000
    SSBWIN=0x00200000
    SWCWIN=0x00800004
    TCVWIN=0x00200000
    TCW=0x00400000
    TCWIN=0x0004
    TERRAIN=0x00400000
    TISETUP=0x00200000
    TL6=0x08000000
    TME=0x0100
    TMSWIN=0x20000000
    TMTWIN=0x00200000
    TMTWINCD=0x00200000
    TOUCHUP=0x00400000
    TURBOTAX=0x00080000
    VB=0x0200
    VEWINFIL=0x00400000
    VISIO=0x00000004
    VISIOHM=0x00000004
    VISION=0x0040
    W4GL=0x4000
    W4GLR=0x4000
    WGW=0x00440000
    WIN2WRS=0x1210
    WINCIM=0x4
    WINLINK=0x20000000
    WINPHONE=0x0004
    WINSIM=0x2000
    WINTACH=0x00200000
    WORDSCAN=0x02200000
    WPWINFIL=0x00000006
    WPWIN60=0x00000400
    WPWIN61=0x02000400
    WSETUP=0x00200000
    XPRESS=0x00000008
    ZETA01=0x00400000
    ZIFFBOOK=0x00200000
    NOTIFIER=0x400000

    [Compatibility32]
    CLWORKS=0x00A00000
    MCAD=0x00600000
    PHOTOSHP=0x00208000
    PODW=0x00200000
    SPSSWIN=0x00200000
    TYPSTRY2=0x00200000
    V32VM20=0x02000000
    VISIO=0x00000000
    VISIOHM=0x00000000
    WINPHONE=0x00000004
    WRDART32=0x00400000
    SHELL=0x80000000
    USTATION=0x80000000

    [Compatibility95]
    CHAOS OV=0x80000000
    CONF=0x00000002
    MSDEV=0x00000002
    IMAGE32=0x80000000
    INST32=0x80000000

    [ModuleCompatibility]
    ACEROOBE=0x0004
    AIRNFM=0x0002
    ALDNCD=0x0002
    AMRES=0x0002
    ATM=0x0002
    ARCHANGEL=0x0002
    CSNOV=0x0002
    DEFDEMO=0x0002
    DIBWND=0x0002
    DIB=0x0002
    DS=0x0001
    EMLIB=0x0002
    EMSAVE=0x0002
    FH4=0x0002
    GEDIT=0x0002
    GEORGE=0x0002
    GVBSETUP=0x0002
    HRWCD=0x0002
    ISLFAXPR=0x0002
    KIDDESK=0x0002
    KIDSTYPE=0x0000
    KNPS=0x0002
    LIONKING=0x0002
    MAUI_DRV=0x0002
    MGXWMF=0x0002
    MEMMAP=0x0002
    MSARTIST=0x0002
    MSCRWRTR=0x0002
    MSCUISTF=0x0001
    MVIEWER2=0x0002
    MWAVSCAN=0x0002
    MYINV=0x0002
    OLESVR=0x0002
    PDOXWIN=0x0002
    PLANIT=0x0002
    PP3=0x0002
    PP4=0x0002
    PPPP=0x0002
    PXDSRV2=0x0002
    REVIEWRT=0x0002
    ROULETTE=0x0002
    RRIRJ=0x0002
    RR1=0x0002
    RR2CD=0x0002
    STL_DLG=0x0002
    TECO=0x0001
    TER=0x0002
    TLW0LOC=0x0002
    TMSWIN=0x0002
    USA=0x0002
    VOICE=0x0002
    WFXVIEW=0x0004
    WINFORM=0x0002
    WPWIN61=0x0002

    [TrueType]
    FontSmoothing=0

    [mci extensions]
    mid=Sequencer
    rmi=Sequencer
    wav=waveaudio
    avi=AVIVideo
    cda=CDAudio
    aif=MPEGVideo
    aiff=MPEGVideo
    aifc=MPEGVideo
    au=MPEGVideo
    m1v=MpegVideo
    mov=MPEGVideo
    mp2=MpegVideo
    mpa=MPEGVideo
    mpe=MpegVideo
    mpeg=MpegVideo
    mpg=MpegVideo
    qt=MPEGVideo
    snd=MPEGVideo
    dat=MpegVideo
    vbs=MpegVideo
    ac3=MpegVideo
    vob=MpegVideo
    sd8=MpegVideo
    midi=Sequencer
    asf=MPEGVideo2
    asx=MPEGVideo2
    ivf=MPEGVideo2
    wax=MPEGVideo2
    wvx=MPEGVideo2
    wm=MPEGVideo2
    wma=MPEGVideo2
    wmv=MPEGVideo2
    wmx=MPEGVideo2
    wmp=MPEGVideo2

    [MCICompatibility]
    QTWVideo=0x0001
    MCIXSND=0x0001
    GDAnim=0x0001

    [mciavi]

    [Desktop_Shell]
    Current=Win

    [Pscript.Drv]
    ATMWorkaround=1

    [Ports]
    LPT1:=
    LPT2:=
    LPT3:=
    COM1:=9600,n,8,1,x
    COM2:=9600,n,8,1,x
    COM3:=9600,n,8,1,x
    COM4:=9600,n,8,1,x
    FILE:=

    [embedding]
    Package=Package,Package,packager.exe,picture
    midfile=MIDI Sequence,MIDI Sequence,C:\WINDOWS\mplayer.exe /mid,picture
    SoundRec=Wave Sound,Wave Sound,C:\WINDOWS\sndrec32.exe,picture
    PBrush=Paintbrush Picture,Paintbrush Picture,C:\Progra~1\Access~1\MSPAINT.EXE,picture
    Paint.Picture=Bitmap Image,Bitmap Image,C:\Progra~1\Access~1\MSPAINT.EXE,picture
    mplayer=Media Clip,Media Clip,C:\WINDOWS\mplayer.exe,picture
    Wordpad.Document.1=WordPad Document,WordPad Document,C:\Progra~1\Access~1\WORDPAD.EXE,picture
    Imaging.Document=Image Document,Image Document,C:\WINDOWS\KodakImg.Exe,picture
    WangImage.Document=Image Document,Image Document,C:\WINDOWS\KodakImg.Exe,picture
    avifile=Video Clip,Video Clip,C:\WINDOWS\mplayer.exe /avi,picture
    AudioView=Sound(VOY),Sound(VOY),C:\PROGRA~1\VOYETRA\AUDIOS~1\AUDIOVIW.EXE,picture

    [Extensions]

    [Devices]

    [PrinterPorts]

    [FontSubstitutes]
    Helv=MS Sans Serif
    Tms Rmn=MS Serif
    Times=Times New Roman
    MS Shell Dlg 2=MS Sans Serif
    Monotype.com=Andale Mono
    Helvetica=Arial
    MS Shell Dlg=MS Sans Serif

    [colors]
    Scrollbar=192 192 192
    Background=109 167 231
    ActiveTitle=0 0 128
    InactiveTitle=128 128 128
    Menu=192 192 192
    Window=255 255 255
    WindowFrame=0 0 0
    MenuText=0 0 0
    WindowText=0 0 0
    TitleText=255 255 255
    ActiveBorder=192 192 192
    InactiveBorder=192 192 192
    AppWorkspace=128 128 128
    Hilight=0 0 128
    HilightText=255 255 255
    ButtonFace=192 192 192
    ButtonShadow=128 128 128
    GrayText=128 128 128
    ButtonText=0 0 0
    InactiveTitleText=192 192 192
    ButtonHilight=255 255 255
    ButtonDkShadow=0 0 0
    ButtonLight=224 224 224
    InfoText=0 0 0
    InfoWindow=255 255 225
    ButtonAlternateFace=184 184 184
    HotTrackingColor=0 0 255
    GradientActiveTitle=0 0 128
    GradientInactiveTitle=128 128 128


    [Mail]
    MAPI=1
    CMC=1
    CMCDLLNAME32=mapi32.dll
    CMCDLLNAME=mapi.dll
    MAPIX=1
    MAPIXVER=1.0.0.1
    OLEMessaging=1

    [MCI Extensions.BAK]
    asf=MPEGVideo2
    asx=MPEGVideo2
    ivf=MPEGVideo2
    wax=MPEGVideo2
    wvx=MPEGVideo2
    wm=MPEGVideo2
    wma=MPEGVideo2
    wmv=MPEGVideo2
    wmx=MPEGVideo2
    wmp=MPEGVideo2

    [spooler]
    QP.LPT1=WPSSSQP.DLL

    [Twain]
    Default Source=C:\WINDOWS\Twain_32\EPFB5\ESTW5.ds

    [Sounds]
    SystemDefault=,

    [Software by Design]
    Disk CleanUp for Windows 95/NT=v4.6

    [HPFECP08,LPT1]
    DefaultInputMode=4
    DefaultOutputMode=8
    RelaxState32Timeout=1

    [HPFECP11,LPT1]
    DefaultInputMode=4
    DefaultOutputMode=6
    RelaxState32Timeout=1
    DigitalFilterEnable=0

    [HPFECP11,HP DeskJet 810C Series Printer,LPT1]
    DefaultInputMode=4
    DefaultOutputMode=6
    RelaxState32Timeout=1
    DigitalFilterEnable=0

    [DrawDib]
    pnpdrvr.drv 800x600x16(555 0)=37,5,5,5
    pnpdrvr.drv 800x600x16(0)=37,5,5,5

    [HPO1284,LPT1]
    DefaultInputMode=0
    DefaultOutputMode=0
    RelaxState32Timeout=1



    [ActiveScan]
    ID={3C838E61-9463-11DC-93FA-00104BD15EE9}
     
  10. 2007/11/22
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Jean
    Do the following,

    Click Start > Run and type Sysedit. Bring C:\Windows\Win.ini to the front by clicking on it. Search for This line,

    norun=hpfsched c:\windows\speedy.bat

    and delete This, c:\windows\speedy.bat. By highlighting it, right click and choose delete. Delete only that reference, not any of the other text.

    OK change if asked and close the System Configuration Editor

    Now reboot.

    Let me know if you are still having the problem.

    Thanks
    Geri
     
    Geri,
    #9
  11. 2007/11/22
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Geri,
    I followed your instructions and deleted, c:\windows\speedy.bat from the win.ini file.

    After I rebooted the machine, it hung up and I tried again. It did start up but then hung up several more times.

    I'm sorry to say it didn't help at all, in fact, I think the machine is hanging up worse than before.

    Do you think I should try to just reformat the disk and load the original software. Of course, I didn't want to do this as I won't be able to get all the Windows 98 updates from Microsoft.

    What do you think. Thank you for trying to help me.

    Right now the computer is up and running but I'm afraid that after it is on for a length of time it will hang up again. Then I will have to power it down and restart it and let it go through the windows scan.

    Jean

    Happy Turkey Day!
     
  12. 2007/11/22
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Jean
    Let hold off on that for now.

    How long has it been sense you did a scandisk and defrag?

    Lets do this, It may take a while, and I'll ask noadhfear to check this and see what he thinks.
    Do these in the order given.

    Disk Cleanup
    Double-click My Computer, right-click the hard disk on which you want to free space, click Properties, and then click Disk Cleanup on the General tab.
    On the Disk Cleanup tab, click to select the check boxes below.
    • Deleting temporary Internet files.
    • Deleting downloaded program files.
    • Emptying the Recycle Bin.
    • Deleting files from your temporary folder.

    ScanDisk
    Click Start, point to Programs, point to Accessories, point to System Tools, and then click ScanDisk. Check Thorough. and be sure "Automatically Fix Errors" is checked. and then click Start.

    Defrag.
    Reboot into safe mode.
    Then Click Start, point to Programs, point to Accessories, point to System Tools, and then click Disk Defragmenter.
    Click the drive you want to defragment ( C ), click OK, and then click Yes.

    Geri
     
  13. 2007/11/23
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Hi Geri,

    I did try last week to scandisk and defrag but I don't remember if I was successful so I did everything again you told me to do.
    I did do a Disk Cleanup.
    I did do a ScanDisk, Thorough.
    I had trouble with Defrag but kept trying until I got it done.
    Here are some of the problems.
    I got into Safe Mode to defrag. Explorer performed an illegal operation and I had to power down. I then tried to defrag in Windows Mode (after shutting programs down). It ran to 88% and computer hung up.
    Powered down and restarted again in safe mode. It finally finished but I received an error message after closing defrag window saying: Defrag performed an illegal operation. I say OK and also another windows said, "Exporer" performed an illegal operation.

    I then powered down. Windows came up but I couldn't do anything. It was hung up so I powered down again and now Windows is up and running but I don't know how long this will last until it hangs up again.

    What do you think?

    Thank you for your time and patience.

    Jean
     
  14. 2007/11/23
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    I just went to check the computer again. I opened Internet Computer and when I tried to call up one of my favorites, nothing happened. I can't click on anything. It is hung up again. I'll power it down for tonight and wait for your reply.

    Jean
     
  15. 2007/11/23
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Jean
    Here is one reply I received,

    "Needs to open that PC up and blow it out. May be a case of cpu overheating. Make sure all power is off to the tower. Use a can of compressed air to blow it out. Don't blow on the fans so they spin.
    Reseat RAM at that time.
    Remove the stick(s) of RAM and reinsurt them.

    Check device manager for errors ......... update drivers. "

    I have also PM'ed a Team Member that deals with 98 machines and asked him to take a look, I'm sure he'll pipe in as soon as he gets the message.

    You might post the problem in the Windows 95/98/ME section with a link back here, Someone there may have a better idea.

    Geri
     
  16. 2007/11/24
    Rockster2U

    Rockster2U Geek Member

    Joined:
    2002/04/01
    Messages:
    3,181
    Likes Received:
    9
    Geri, Jean:

    I'm guessing thats markp62 and would certainly follow his advice. There is also an old but very good procedure posted quite some time ago by Mike Flynn. I would certainly recommend the following:

    These are for 95 98 only!

    Boot to DOS (not shutdown to DOS). While booting hit F8 to startup menu. Chose "command prompt only ".

    Type these commands exactly hit enter at the end (do not type the notes that are in parenthesis like this).

    del c:\*.swp (may get file not found, is ok)

    del c:\windows\*.swp

    deltree /y c:\windows\shelli*.*

    deltree /y c:\windows\temp\*.*

    deltree /y c:\windows\tempor~1\*.*

    deltree /y c:\windows\history\*.*

    deltree /y c:\windows\spool\printers\*.*

    deltree /y c:\windows\taskmon.exe

    deltree /y c:\windows\applog

    NOTE: deleting of taskmon and applog above are optional and may be skipped but they are well known to be useless and actually slow a defrag and waste disk space and also rob CPU resources since it runs in memory all the time. I would clear them!
    ____________________________________________
    Then boot to safe mode and do the following

    Configure CleanMgr to max settings
    Go to Start-Run and type

    cleanmgr /sageset:1
    the above need only be ran once (these settings will be remembered as the default until another sageset is ran).

    It will present a menu select all, then

    Go to Start-Run and type

    cleanmgr /sagerun:1
    As long as /sageset above has been ran on this computer from now on the /sagerun:1 is the only thing that needs to run.

    NOW do the scan and defrag WHILE IN SAFE MODE!

    These cleanups will not only possibly fix the problem but should help overall performance and stability.

    ;)
     
  17. 2007/11/24
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Thanks Rockster2U
    Actually that was from Dave, I was waiting for Markp62 to show up.

    Jean
    I would follow Rockster2U's instructions.

    Geri
     
  18. 2007/11/25
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    This computer apparently is still infected with Home Search Assistant?

    4 - HKLM\..\Run: [rmmon] C:\WINDOWS\SYSTEM\m1rmmon.exe

    Maybe a scan with Spybot Search & Destroy?

    The above cleanup as posted by Rockster2U will definitely help.

    I do also recommend disabling these two items with Msconfig.
    Taskmon
    SSDPSRV (This is Universal PlugnPlay for 98)
     
  19. 2007/11/25
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Markp62
    Thanks for stopping in.
    rmmon, comes back as this.
    Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card.

    Geri
     
  20. 2007/11/26
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Hi everyone,

    I'm trying most of the things that were suggested and I'm not sure how the computer is running right now.

    I'm a little confused due to the fact that I have this posting here and in the Windows 98 Group. I'll try to relate what I have done so far.

    I did follow Rockster's instructions. I did follow the procedure he sent (booting into Command Prompt - and deleting files he said). Also configured CleanMgr as he suggested. I also did the scan disk and defrag while in safe mode.

    Geri - We did open the PC and blew it out with compressed air. We checked the RAM and that seems to be very tight.

    The device manager shows no errors. I just went to the Gateway site and checked with them for updated drivers. They found a few and I updated them.

    I did post the problem in the Windows 98 section with a link back here.

    I honestly don't understand what they are trying to tell me or what I am supposed to do. They said:

    This computer apparently is still infected with Home Search Assistant?

    4 - HKLM\..\Run: [rmmon] C:\WINDOWS\SYSTEM\m1rmmon.exe

    Maybe a scan with Spybot Search & Destroy?
    The above cleanup as posted by Rockster2U will definitely help.

    I do also recommend disabling these two items with Msconfig.
    Taskmon
    SSDPSRV (This is Universal PlugnPlay for 98) "

    I have scanned with Super AntiSpy Ware but will try Spybot Search and Destroy.

    I'll write to them in the other section and see what I get there.

    I will let you know if the computer still hangs up after it being on for a certain time.

    Thanks for your help.

    Jean
     
  21. 2007/11/26
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Jean
    Ok, To put everyones mind at ease and to be sure lets find out.
    Searching for it brings up two possibilities

    First do this.

    Jotti File Submission:
    • Please go to Jotti's malware scan
    • Copy and paste the following file path into the "File to upload & scan "box on the top of the page:
      • C:\WINDOWS\SYSTEM\m1rmmon.exe
    • Click on the submit button

    If any of the venders show the file is infected, then do this.


    Re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.

    4 - HKLM\..\Run: [rmmon] C:\WINDOWS\SYSTEM\m1rmmon.exe

    Now close all windows other than HiJackThis, then click Fix Checked.

    Close HJT.

    Using Windows Explorer (to get there right-click your Start button and go to "Explore "), please delete these files (if present):

    C:\WINDOWS\SYSTEM\m1rmmon.exe

    After that, Reboot.

    Geri
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.