1
   

Sudden crashes - HJT log posted

 
 
Shamus
 
Reply Mon 16 May, 2005 04:54 pm
Several days ago my computer started crashing with alarming frequency. I have had crash problems when running games, but now it is crashing even when I am just surfing the web. I have tried to run several scans with programs such as Add-aware SE and Norton AV. However, everytime I do, my computer crashes before the scan finishes. I did run both Add-aware and Norton scans last week (Add-aware found little of concern, and Norton found nothing). I also make it a regular habit of cleaning out my various temp files. I am hoping that there might be something in HJT log that might explain the problem. There may also be a registry problem, as when after a crash today, a message came up saying that a missing registry (entry or key I believe) had been replaced.

Logfile of HijackThis v1.98.2
Scan saved at 7:03:20 PM, on 5/16/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Creative\TaskBar\CTLTray.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton AntiVirus\defwatch.exe
C:\Program Files\Norton AntiVirus\rtvscan.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.ca/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = webproxy.queensu.ca:8080
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.yahoo.ca"); (C:\Documents and Settings\customer\Application Data\Mozilla\Profiles\default\uc1tdiqo.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\customer\Application Data\Mozilla\Profiles\default\uc1tdiqo.slt\prefs.js)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NORTON~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\ScanSoft\NaturallySpeaking\Program\Ereg.exe" -r "C:\Program Files\ScanSoft\NaturallySpeaking\Program\ereg.ini"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\TaskBar\CTLTray.exe"
O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\TaskBar\CTLTask.exe"
O4 - HKCU\..\Run: [Lavasoft Adwatch] C:\Program Files\Lavasoft Ad-aware\Ad-watch.exe /min
O4 - HKCU\..\Run: [CommCtr] C:\PROGRA~1\NET2PH~1\CommCtr.exe -auto
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Go2CallClient - http://www.go2call.com/fwDialer/CallClient.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security1.norton.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020323/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/09586776da64c9eac401/netzip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security1.norton.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15009/CTPID.cab
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 806 • Replies: 6
No top replies

 
Shamus
 
  1  
Reply Wed 18 May, 2005 11:59 am
Can anyone help? My computer can barely perform any tasks right now without crashing.
0 Replies
 
Shamus
 
  1  
Reply Sat 4 Jun, 2005 10:01 am
Wow, what has happened to this forum? It used to be that if you posted with a question, someone would be able to help you within a day. I posted my quandry nearly 3 weeks ago, and have yet to get a reply. Just wondering what has happened.
0 Replies
 
timberlandko
 
  1  
Reply Sat 4 Jun, 2005 08:28 pm
Mostly what happened is there aren't a lotta folks around with the ability to help. I've been busy elsewhere, and haven't really been on the ball for yuckware removal help recently. It may take me a while, but I'll see what I can do for you. Be patient for another day or so, OK?

In the meanwhile, Fully Update Windows

Perform an online scan of your system using Trend Housecall and Symantec Security Check


Download the following - right now, just download them, don't run them yet.

Microsoft Malicious Software Removal Tool and Microsoft Antispyware (Beta)

The current version of McAffee AVERT's STINGER.

The current version of CWSHredder

The current version of HiJackThis

Steve Gould's Clean Up!

When you've updated Windows, run the online scans, and and gathered the downloads, disconnect from the internet. Boot your machine into safe mode, and, while in safe mode, do the following in the order listed (if prompted by any of these to reboot, do so, but boot back into safe mode, don't boot normally):

Install and run the Microsoft Malicious Software Removal tool.

Install and run Microsoft AntiSpyware (Beta)

Install and run STINGER

Install and run CWShredder

Install and run Cleanup!

Reboot your machine normally when prompted by Cleanup!.

Install the current version of HijackThis, run it, save the log, connect to the internet, and post it to this thread.
0 Replies
 
Shamus
 
  1  
Reply Mon 6 Jun, 2005 12:37 pm
Cheers for the reply. I wasn't meaning offense, I was just curious about what was going on.

I ran Windows update successfully, however upon restarting my computer (for the changes to take effect), my computer became locked in an endless cycle of re-starts. Every time it loads just past the window with the Windows name and moving bar below it, the computer restarts. I have tried loading it in safe mode, as well as loading with the last know good configuration, but both have the same results.

I haven't a clue what to do. I can't even get my computer started now (I'm writing from my wife's comp). Please Help! Sad
0 Replies
 
Derevon
 
  1  
Reply Tue 7 Jun, 2005 06:25 pm
If neither of those two modes work I can think of little else to do than to reinstall Windows I'm afraid.
0 Replies
 
timberlandko
 
  1  
Reply Tue 7 Jun, 2005 09:29 pm
Its unlikely a format-and-reinstall is nescessary (though sometimes its the best abd easiest solution). I bet you can get away without doing that, and save all your personal files and 3rd-party programs. There's always the XP Recovery Console, but thats pretty techy to play with, so I don't advise most folks try that.

I don't imagine you have an emergency boot floppy handy. No big deal, though, since you have another operating XP machine. Try this:

Place a blank, formatted floppy in the working machine's floppy drive.

Open Windows Explorer, select the C:\ drive folder, and open it. Select Tools>Folder Options>View. Click "Show hidden files and folders" and unclick "Hide protected operating system files (Recommended)". Click "Apply", then click "OK" to exit. Do not close Windows Explorer.

In Windows Explorer, in which should still be open your C:\ drive folder, find and copy from C:\ to the floppy the files ntldr, ntdetect.com, and boot.ini. Remove the floppy and lable it something like "XP Boot".

With the problem machine turned off, place the floppy into the problem machine's floppy drive, then power on the problem machine, while continually tapping the F8 key.

Windows should bypass the corrupted boot files in favor of those on the floppy, and present you with the boot menu. If so, select "Safe Mode", remove the floppy, and press "Enter"

Click Settings>Control Panel>Add/Remove Programs. Find SP2, and delete it. Confirm when prompted, and reboot when prompted.

If that doesn't work for you (it may not- but its quick and easy, so its a good place to start), Microsoft offers a toll-free number for SP2 install issues:
(888) SP2-HELP (772-4357). Weekday hours are 5:00 AM - 9:00 PM, Weekend hours are 6:00 AM - 3:00 PM US Pacific Time.
- its their baby, let them sort it out for you. In fact, if you're like most folks, uncertain of how and why Windows works, calling Microsoft night just be the best place for you to start.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Sudden crashes - HJT log posted
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 12/27/2025 at 04:41:01