|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (9 bit)
Join Date: Mar 2001
Location: Illinois
Posts: 352
|
"base2 PaneForm"...ever heard of this
My System:
P-4 2.4 Ghz 512 RDRAM Windows SP2 Multiple layers of security...all up to date. Here's the problem, when I shut down windows...shutdown begins normally, then a windows error popup apears saying "this program is not responding", and the countdown begins and the program (file ???) get's closed, and shutdown is then, normal. The program (file???) is "base2 PaneForm" This began after one of two installs of a new multi-function machines. The first was a Brother 620, which I tested for about a month. I un-installed the SW, and returned the machine (piece of junk...multiple problems). The second is a HP photoseries 2600. This machine is still hooked up & running fine. My delima is what this program (file???) is & why it is running in the background. If it's a leftover from the Brother SW package,,,then I want to remove it. It may also be part of the HP SW package (which is a SW bloat BTW), in which case I may need it to do certain task. I have a program to monitor startup programs, but I can't see anything that would resemble this program (file???). Same with "Task Manager"...nothing that resembles this program (file???) This is NOT an earth shattering problem, since it's only about a 15 second delay...but if it's running in the background, and it don't need to be than I want to stop it from running. |
|
|
|
|
|
#2 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
Can you go into "start up" in msconfig and give us a list of the prgrams that are checked or run a hjt log, make sure you run the hjt straight after booting up before you have opened any programs.
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta. |
|
|
|
|
|
#3 |
|
Member (9 bit)
Join Date: Mar 2001
Location: Illinois
Posts: 352
|
Log removed, not needed any more, was way too long
Last edited by glc; 05-27-2005 at 02:10 PM. Reason: remove extensive log |
|
|
|
|
|
#4 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
According to zonelabs you have the "petch" trojan/virus.
http://vic.zonelabs.com/tmpl/body/CA....jsp?VId=37468 According to symantec you have picked it up through IRC, http://securityresponse.symantec.com...w32.petch.html Considering the amount of damage this virus can do I would strongly suggest a format and reinstall. |
|
|
|
|
|
#5 | |
|
Member (9 bit)
Join Date: Mar 2001
Location: Illinois
Posts: 352
|
Quote:
I run nightly updates for AVG anti-virus, and then a complete anti-virus scan...this is every night. I also have Zone Alarm Pro, and three spyware programs...one, MS Anti-spyware which runs in residence continually. I just checked the AVG log and it has run every night as scheduled...no viruses. Secondly, Zone Labe & Symantic both say this virus\trojan enters via IRC. I have never used IRC chat or any other messenger service. |
|
|
|
|
|
|
#6 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
XEC.EXE
right at the bottom of your management tools list, google search xec.exe and that is what it comes back with and I have seen this infection on many an occasion, also why is your log so truncated it should be much shorter. Here is the Brother software that is still on your system: O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - Last edited by rjfvillarosa; 05-24-2005 at 05:21 PM. |
|
|
|
|
|
#7 | |
|
Member (9 bit)
Join Date: Mar 2001
Location: Illinois
Posts: 352
|
OK, I got rid of the Logitek Desktop messenger, and then tool this hjt log:
Quote:
|
|
|
|
|
|
|
#8 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
This is a link to the analysis of your latest log on the HJT site, according to them its clean.
http://www.hijackthis.de/logfiles/39...6b3c44f73.html I also noticed that XEC.EXE has disappeared but there is a .exe with a very similar name associated with your logitech, maybe just a bad coincidence of names. O4 - HKLM\..\Run: [EM_EXEC] H:\BOGIEP~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE Ok my mistake, the log is so truncated it looks like a separate entry and there is no XEC.EXE it is actually EM_EXEC.EXE Last edited by rjfvillarosa; 05-24-2005 at 05:32 PM. |
|
|
|
|
|
#9 |
|
Member (9 bit)
Join Date: Mar 2001
Location: Illinois
Posts: 352
|
It now seems as though removing Logitek Desktop Messenger has changed my hjt log considerably including the "XEC.EXE" entries which are now gone. What do you think of the latest log?
1. Are there other removal tools that I could do to make sure I do not have this trojan\virus. 2. If I do have this virus\trojan, would'nt up to date virus protection have detected it? |
|
|
|
|
|
#10 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
I don't think you do have it, your log was so truncated it made it look like a separate entry, follow the link I gave you and inspect your analysis on the HJT site it shows up pretty clean, I also singled out the Brother software that is still running on your machine.
Can you tell me how many things are checked in "MSCONFIG" so that they run when you start windows.? |
|
|
|
|
|
#11 |
|
Member (9 bit)
Join Date: Mar 2001
Location: Illinois
Posts: 352
|
rjfvillarosa...the other logitech entry is from an older device and I know it's OK. I looked at the rest of the review, and it seems all is well as far as the log goes...seems as though the new logitech keyboard I recently bought was also loading me up with their "Desktop Messenger", which seemed to contain the bad log entries.
Now I'll try a restart. |
|
|
|
|
|
#12 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
Do you have an Epson printer too? If not, you have the Epson status monitor installed.
Word to the wise - whenever installing ANY Logitech software, do a custom install and do NOT install the Desktop Messenger and all the other crap they want to shove in your face. All that does is clog up your bandwidth looking for updates and anything else Logitech wants to try to feed you. |
|
|
|
|
|
#13 |
|
Member (9 bit)
Join Date: Mar 2001
Location: Illinois
Posts: 352
|
Yes I do have an Epson printer on this computer. Thanks for the heads up on Logitech...I always do a custom install, and avoid anything with the word "Messenger" like the plague, but this one got by me. This was a good time to do some other house cleaning in my HJT log, however!
I still have the "base2PaneForm" Not Responding on shutdown, and I have found two other programs\files that also do the same on shutdown. They are "WindowFormsParkingWindow", and the last one I was not able to get totally but it started with "hp". I am now pretty sure these "Not Responding" errors are a part of the HP multi-function machine SW. I'll probably just let it be since this is only a 10-15 second delay...and there are no other evident problems with the system. Thanks All! |
|
|
|
|
|
#14 | |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
This is post #6 from
http://forum.pcmech.com/showthread.php?t=126271 Quote:
O4 - Global Startup: HP Image Zone Fast Start.lnk = H:\Bogie Programs\HP\Digital Imaging\bin\hpqthb08.exe |
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|