new update problem - freezes

Hi, Hope you can help. I just got the new update and when the scan gets to C.|…|s-1-5-21-2646752555-2703944788-1453689197-1055 it freezes everything up. I have looked everywhere for this file and am unable to find it. I have xp sp2 and sbcyahoo dsl.
Thanks for your time.

Cloud

I just saw this problem on another post and they downloaded beta 4.5.536 to fix it. Where do I find that download?

Thanks a bunch. Cloud

I hate to sound stupid but what is beta? ::slight_smile:

Hi cloud,
to install the version 4.5.36 pls read this thread:
http://forum.avast.com/index.php?board=2;action=display;threadid=9007

I’m not sure if 4.5.36 is officially released now, so pls check Your version before doing that.

A beta version is a software not oficially released yet, which is published for testing. Usually such a version may have some minor bugs, which are then corrected during the beta test phase till the software is officially released. Avast beta version are very stable - I have this version installed and had no problems with it.

Are You sure everything freezes - may be the file is a huge archive, which take some time to scan. I assume this file is in one of the temporary directories.

br
Peter

Peter,

Yeah, even my mouse stops working. I had to turn off my machine with the switch which I hate to do. Everything looks okay though. I’m running 4.5 version.

I checked the temp directory but will try again. If it is there I could just delete it, right?

Thanks for the info on the 4.5.536, will check it out.

Cloud

What operating system are you using?

I’m using xp sp2

I downloaded beta 4.5.536 and still having the same problem. I found this file in the registry but I will have to get a friend to help me find out what it is. lol

Any help is appreciated.

Thanks,

Cloud

There has been a very recent official release 4.5.542, just do a regular manual program update.

What file did you find in registry? You have lots of friends here, you just haven’t met them yet.

The registry doesn’t contain files but links to files.

the file is HKEY_USERS btw

cloud:
HKEY_USERS, one of the “real” keys in the Windows 95/98 and Windows NT registry. …

Bob,

hmmmm, I guess that means those are important to my system. I have XP. Would that make a difference?

Thanks very much for your help everyone. I do appreciate it. I will get this figured out and I’m learning a lot.

Cloud

Please post the key here and let us have a look.
(start > run > regedit > navigate to and click on the key > file > export > copy/paste the content of the created file here)

Not everything in the registry is legitimate :wink:

I was unable to copy and when I tried to attach it there was a dns error. The registry editor would let me print it. When I checked to see how much paper I needed it showed 3764 pages and 86.6 MB! I scanned the 1st 5 pages. I hope this helps. Thanks for your patience.

Cloud

Key Name:
Class Name:
Last Write Time: Value 0
Name: Type: Data:

Value 1 Name: Type: Data:

Key Name: \AppEvents Class Name:
Last Write Time:

HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
11/29/2004 - 9:51 PM

HTTPllSAVED REG DWORD OxO

HTTPllSAVED VAL REG DWORD OxO

HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005

12/11/2002 - 1:58 PM

Key-Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels ­
Class Name:
Last Write Time: 8/24/2004 - 8:35 PM

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\ Default
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

Value 1 Name: Type: Data:

REG SZ Default Beep

DispFileName REG SZ @mmsys.cpl,-5824

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\ActivatingDocument
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ Complete Navigation

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\AppGPFault
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

Value 1 Name: Type: Data:

REG SZ Program error

DispFileName REG SZ @mmSys.cpl,-5825

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\Banner
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0

Name: Type: Data:

REG SZ Directional Arrows

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\BlockedPopup
Class Name:
Last Write Time: 8/24/2004 - 8:35 PM
Value 0
Name: Type: Data:

REG SZ Blocked Pop-up Window

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\CCSelect
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ Select

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\Close
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name:
Type:
Data:

REG SZ Close program

Value 1 Name: Type: Data:

DispFileName REG SZ @rnrnsys.cpl,-5826

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\CriticalBatteryAlarm
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ Critical Battery Alarm

Value 1 Name: Type: Data:

DispFileName REG SZ @rnrnsys.cpl,-5827

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\DeviceConnect
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name:
Type:
Data:

REG SZ DevIce Connect

Value 1 Name: Type: Data:

DispFileName REG SZ @rnrnsys.cpl,-5828

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\DeviceDisconnect
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ DevIce Disconnect

Value 1 Name: Type: Data:

DispFileName REG SZ @mmsys.cpl,-5829

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\DeviceFail
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ DevIce Failed to Connect

Value 1 Name: Type: Data:

DispFileName REG SZ @mmsys.cpl,-5830

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\DragDrop
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ Drag-n-Drop

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\EmptyRecyc1eBin
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ Empty Recycle Bin

Value 1 Name: Type: Data:

DispFileName REG SZ @mmsys.cpl,-5831

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\FaxError
Class Name:
Last Write Time: 1/21/2003 - 11:41 AM
Value 0
Name: Type: Data:

REG SZ Fax error

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\FaxLineRings
Class Name:

Last Write Value 0
Name: Type: Data:

Time:

1/21/2003 - 11:41 AM

REG SZ Fax line rings

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\FaxNew
Class Name:
Last Write Time: 1/21/2003 - 11:41 AM
Value 0
Name: Type: Data:

REG SZ New fax

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\FaxSent
Class Name:
Last Write Time: 1/21/2003 - 11:41 AM
Value 0
Name: Type: Data:

REG SZ
Fax sent

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\ListSelect
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ Launcher List Select

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\LowBatteryAlarm
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ Low Battery Alarm

Value 1 Name: Type: Data:

DispFileName REG SZ @mmsys.cpl,-5832

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\MailBeep
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

REG SZ New-Mail Notification

Value 1 Name: Type: Data:

DispFileName REG SZ @mmsys.cpl,-5837

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\Maximize

Class Name:
Last Write Time: Value 0
Name: Type: Data:

Value 1 Name: Type: Data:

12/11/2002 - 1:58 PM

REG SZ MaxImize

DispFileName REG SZ @mmsys.cpl,-5833

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\MenuCommand
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

Value 1 Name: Type: Data:

REG SZ
Menu command

DispFileName REG SZ @mmsys.cpl,-5834

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\MenuPopup
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

Value 1 Name: Type: Data:

REG SZ Menu popup

DispFileName REG SZ @mmsys.cpl,-5835

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\Minimize
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

Value 1 Name: Type: Data:

REG SZ MinImize

DispFileName REG SZ @mmsys.cpl,-5836

Key Name: HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005
\AppEvents\EventLabels\MoveMenuItem
Class Name:
Last Write Time: 12/11/2002 - 1:58 PM
Value 0
Name: Type: Data:

Key Name:

REG SZ Move Menu Item

HKEY USERS\S-1-5-21-2646752555-2703944788-1453689397-1005

Please don’t give up on me. I have no idea what to do next. :cry: Registry is a very scary place and I don’t know if I have av protection.

Thanks for all your help so far.

Cloud

Try to update to the recent build (546).
If the problem still persists… well, it’s necessary to find the particular file/folder. You can e.g. turn on the creation of the report file (check all the items there, including “OK files”) and run the scan again. After the freeze, check the end of the report file - the real file is likely to be close to the end of the file.
Btw, does it matter if the scanning of archives is on/off?

Thank you soooo much! I will check it out and let you know what happens. Hopefully my next reply will be good news. :smiley:

Cloud

the last entry on the report is

C:\RECYCLER\S-1-5-21-2646752555-2703944788-1453689397-1005\Dc16.SBS\UnnamedStream_1 [+] is OK
I found the file in recycler(NPROTECT) and it is deleted files and folders from the recycle bin. I was unable to delete it…says it is in use by another person or program.
I also have a folder called NTDETECT.COM which shows to be a dos application but when clicked on it it says that it is not suitable for running dos or window applications. I sent it to the recycle bin despite the warning that it is a system file.

If I do not scan the archive the scan works just fine.

This is getting interesting. How to I get rid of these backed up, deleted files?

I’m such a dummy with these things but I am learning. Again, thank you very much.

Cloud

:o I did a search NTDETECT and when I found out what it was I restored it. All is well. Almost anyway. :stuck_out_tongue:

Cloud

One more stupid question please. I researched NPROTECT and found out how to remove it. Will I delete the recycle bin if I delete NPROTECT? (Feel free to laugh if you want) I just want to be sure.

Okay, I lied :-, one more stupid question. If I am right about this situation. How did I get NPROTECT anyway? I am sure I did not download it. Norton av had me in fits on my laptop, I sure wouldn’t download any of their stuff.

You folks have been the best. I can’t thank you enough for your time and effort.

Cloud

Cloud
Nprotect is part of Norton Utilities.