masefield Posted April 16, 2005 Report Share Posted April 16, 2005 I have a bit of a query when I close my laptop - when I get an error message which stays on for a period of time but closes itself before I can obtain full details. It appears to be an error message which states that ashserve.exe can't write to the memory with a few other details but I can't tell you what they are. Has anybody got any help as to what to do. Thanks. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 16, 2005 Report Share Posted April 16, 2005 Is it, ashServ.exe? This is the Avast Anti-Virus service.You can try reinstalling Avast. A HijackThis log could also help solving this problem. Quote Link to comment Share on other sites More sharing options...
masefield Posted April 16, 2005 Author Report Share Posted April 16, 2005 Yes it is as I am running avast anti virus I will do a hijack this log scan and post the results on the forum. Thanks. Quote Link to comment Share on other sites More sharing options...
masefield Posted April 16, 2005 Author Report Share Posted April 16, 2005 Please find below hijackthis log. Any comments thanks.Logfile of HijackThis v1.99.0Scan saved at 20:39:36, on 16/04/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\ATK0100\Hcontrol.exeC:\WINDOWS\System32\sistray.EXEC:\WINDOWS\System32\khooker.exeC:\WINDOWS\system32\pctspk.exeC:\Program Files\Microsoft AntiSpyware\gcasServ.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\Java\j2re1.4.2_06\bin\jusched.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exeC:\WINDOWS\ATK0100\ATKOSD.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Picasa2\PicasaMediaDetector.exeC:\Program Files\MSN Messenger\MsnMsgr.ExeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exeC:\Program Files\BBC News alerts\skinkers.exeC:\Program Files\Microsoft AntiSpyware\gcasDtServ.exeC:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Sky Alerts\skinkers.exeC:\Program Files\HijackThis.exeC:\WINDOWS\system32\ch_utility.exeC:\Program Files\BBC Ticker\BBCTicker.exeC:\Program Files\Alwil Software\Avast4\setup\avast.setup Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 17, 2005 Report Share Posted April 17, 2005 Are you sure it's an error? It could be doing an auto-update, and not finding anything to update, so it goes away.Your HijackThis log looks OK, but there is some missing?Also, use the latest version. 1.99.1 http://www.merijn.org/files/hijackthis.zip Quote Link to comment Share on other sites More sharing options...
masefield Posted April 17, 2005 Author Report Share Posted April 17, 2005 Thanks for response please find attached latest Hijackthis logLogfile of HijackThis v1.99.1Scan saved at 07:50:42, on 17/04/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\ATK0100\Hcontrol.exeC:\WINDOWS\System32\sistray.EXEC:\WINDOWS\System32\khooker.exeC:\WINDOWS\system32\pctspk.exeC:\Program Files\Microsoft AntiSpyware\gcasServ.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\Java\j2re1.4.2_06\bin\jusched.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Picasa2\PicasaMediaDetector.exeC:\Program Files\MSN Messenger\MsnMsgr.ExeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\BBC News alerts\skinkers.exeC:\Program Files\Sky Alerts\skinkers.exeC:\WINDOWS\ATK0100\ATKOSD.exeC:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exeC:\WINDOWS\system32\ch_utility.exeC:\Program Files\Microsoft AntiSpyware\gcasDtServ.exeC:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\Program Files\BBC Ticker\BBCTicker.exeC:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXEC:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXEC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\WinRAR\WinRAR.exeC:\DOCUME~1\ROBERTS\LOCALS~1\Temp\Rar$EX04.659\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.blueyonder.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lbcom.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by LB Computers Ltd - 08702 241873O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exeO4 - HKLM\..\Run: [siS Tray] C:\WINDOWS\System32\sistray.EXEO4 - HKLM\..\Run: [siS KHooker] C:\WINDOWS\System32\khooker.exeO4 - HKLM\..\Run: [PCTVOICE] pctspk.exeO4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exeO4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exeO4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exeO4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exeO4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exeO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [bBC News alerts] C:\Program Files\BBC News alerts\skinkers.exeO4 - HKCU\..\Run: [sky Alerts] C:\Program Files\Sky Alerts\skinkers.exeO4 - Startup: BBCTicker.lnk = C:\Program Files\BBC Ticker\BBCTicker.exeO4 - Global Startup: Chrontel TV.lnk = C:\WINDOWS\system32\ch_utility.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.htmlO8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://www.lbcom.comO15 - Trusted Zone: *.musicmatch.comO15 - Trusted Zone: *.musicmatch.com (HKLM)O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocxO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cabO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 18, 2005 Report Share Posted April 18, 2005 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)Looks like Avast has been damaged some how. You should uninstall, reboot, and reinstall it. You can download it here Quote Link to comment Share on other sites More sharing options...
masefield Posted April 18, 2005 Author Report Share Posted April 18, 2005 Hi there thanks Scarecrow - have done as you have suggested - problem looks to be fixed. Many thanks for you help. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 18, 2005 Report Share Posted April 18, 2005 Your welcome. I am not sure what caused this, but I'm glad it was resolved. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 18, 2005 Report Share Posted April 18, 2005 This topic has now been resolved and subsequently closed.If you wish to add a reply, please contact an administrator or moderator to reopen the topic. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 18, 2005 Report Share Posted April 18, 2005 This topic has been reopened as it has not been resolved. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 18, 2005 Report Share Posted April 18, 2005 Sorry to say I did what you suggested earlier on - have just rebooted pc just now because I have stopped MSN automatically signing on - and I have received the error message that I raised earlier. Any clues etc.Are you attached to Avast? Because if not, you could try AVG. It is a free anti-virus as well. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.