Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Computer crashing/freezing constantly

[Fixed] Hijackthis! Logs - [Resolved] Computer crashing/freezing constantly posted in the Security & Safety forums; So I've had my computer for a little bit over a year now. I built it myself, here are the specs: Power Supply: 420 Watt PSU CPU : AMD FX-55 ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-29-2006
Bronze Member
My PC
 
Join Date: Nov 2006
Posts: 29
apointofnothing - See this Members User comments on their Profile page
Default [Resolved] Computer crashing/freezing constantly

So I've had my computer for a little bit over a year now. I built it myself, here are the specs:

Power Supply: 420 Watt PSU
CPU: AMD FX-55 2.6ghz
Motherboard: eVGA 133-K8-NF41 nForce-4 SLI Chipset
Memory: 2gigs Corsair DDR RAM
GPU: ATI RADEON X850XT
Hard Drives: 80gig Maxtor 7200rpm Ultra ATA-100, 250gig Western Digital 7200rpm ATA-100
Sound Card: Sound Blaster Live! 24-Bit
OS: Windows XP Professional

And here's my problem(s). My computer does 2 different things(which I believe are secretly the same thing) it will just lock up litterally freezing the screen and repeating the the last millisecond of a sound clip over and over again, and the of course, the blue screen of death, filled with text that I will probably never ever understand, so I've taken some pictures with my digi cam last few times it's happened(haven't got a chance to upload yet, need to find the usb cable). So anyway. The freezing thing, this can happen anytime. Mostly gaming, but also alot when I'm at work or out, leaving my computer idle. The blue screen, this pretty much can happen during any application. Gaming, movie/audio editing/recording, etc. Now I've been using PC's for quite some time and I've always been a DIY kind of guy so I figured I could fix it, I was wrong. First, I figured it was the video card. Maybe I got a faulty one. I sent for a replacement. Worked for about 2 days without freezes(probably luck) and then it was back to it's old ways. Sometimes I would go weeks without freezes, obviously playing less games, but still. Gernally, when I play games, I'd say after 30 minutes or so, there's a 50% chance that it could happen at any time. I then figured, ok maybe it's a heating issue. I took a box fan, set it next to my open case and proceeded to game. It still happened. Maybe a little less, but still happened enough to upset me.

I have just recently defragmented my hard drives, checked for errors, removed all spyware off my PC(I never get popups) all my drivers are up to date, and still basically I'm not sure what it is. I want to say, powersupply? But then again, I'm not sure. So instead of throwing away $200 on something that could be some stupid software problem, I figured I'd ask it here. The most recently installed hardware on my PC are my new harddrive, last week. Since then it hasn't happened any more frequently, I've just been playing more, so it's making me more aware. And also another gig of RAM about 2 months ago. Both appear to work fine and haven't caused any problems as far as I know.

Oh and as far as overheating goes. My harddrives sit at 38 and 40 degrees and my video card goes from 38 to 44 depending on if I'm gaming or not.

Any advice or help would be greatly appriciated. Thanks.





  #2  
Old 11-29-2006
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,580
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

Welcome to PCHF!

Can you please follow the PCHF Prework link in my sig and post back an AVG report and a Hijackthis log.

Moved to HJT Logs forum.


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #3  
Old 11-29-2006
GaRHaR's Avatar
Elite Member
My PC
 
Join Date: Jul 2006
Location: Western Australia
Posts: 6,042
PC Experience: Elite PC Guru
GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page
Send a message via ICQ to GaRHaR Send a message via MSN to GaRHaR Send a message via Yahoo to GaRHaR
Default

Welcome to the PCHF apointofnothing.

I doubt it will be related to malware, but can you please follow the prework (as upgrader has asked).

And instead of uploading the pictures of the BSOD, can you please tell us what the stop code error is and the file it's relating to?
Stop code error will say 0x0000000 (with different numbers and letters).

Thanks


__________________


"Study without desire spoils the memory, and it retains nothing that it takes in."
- Leonardo da Vinci

"I believe in Christianity as I believe that the sun has risen: not only because I see it, but because by it I see everything else."
- C. S. Lewis
  #4  
Old 11-29-2006
Bronze Member
My PC
 
Join Date: Nov 2006
Posts: 29
apointofnothing - See this Members User comments on their Profile page
Default

I don't have the pics yet, but I'll be able to get them later today or tomorrow, so then I can tell you the error name. For now, here are the logs:

Hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 4:55:32 AM, on 11/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\System32\CTSvcCDA.EXE
I:\Program Files\PalickSoft\HDD Temperature\HDDTSvc.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\System32\MsPMSPSv.exe
I:\WINDOWS\SOUNDMAN.EXE
I:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
I:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
I:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
I:\Program Files\HP\hpcoretech\hpcmpmgr.exe
I:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
I:\WINDOWS\system32\Rundll32.exe
I:\Program Files\QuickTime\qttask.exe
I:\Program Files\iTunes\iTunesHelper.exe
I:\Program Files\Winamp\winampa.exe
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
I:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
I:\Documents and Settings\Ryan\Desktop\Fraps\FRAPS.EXE
I:\Program Files\AIM\aim.exe
C:\Games\Valve\Steam.exe
I:\Program Files\iPod\bin\iPodService.exe
I:\Program Files\ATI Technologies\ATI.ACE\cli.exe
I:\Program Files\ATI Technologies\ATI.ACE\cli.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CTSysVol] I:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] I:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] I:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] I:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb1 0.exe
O4 - HKLM\..\Run: [HP Component Manager] "I:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "I:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SpywareQuake.com] I:\Program Files\SpywareQuake.com\Spyware-Quake.exe /h
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] I:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ATICCC] "I:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKCU\..\Run: [Fraps] I:\Documents and Settings\Ryan\Desktop\Fraps\FRAPS.EXE
O4 - HKCU\..\Run: [AIM] I:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] C:\Games\Valve\\Steam.exe -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = I:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - I:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: WgaLogon - I:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - I:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - I:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: HDD Temperature (HDDTService) - PalickSoft - I:\Program Files\PalickSoft\HDD Temperature\HDDTSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - I:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - I:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe





The AVG log is too big to post or to upload (137kb), I didn't want to delete any of it, even though most of the report looks like it's repeating itself, what should I do?




Apperently I had more malware than I had though :\



EDIT: BSOD happened like 10 minutes after I posted this.

PAGE_FAULT_IN_NONPAGED_AREA

With the error: 0x00000050 (0xE0001CF4, 0x00000001, 0x80602A18, 0X00000000)



Last edited by apointofnothing; 11-29-2006 at 10:50 PM.
  #5  
Old 12-01-2006
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm


  #6  
Old 12-01-2006
Bronze Member
My PC
 
Join Date: Nov 2006
Posts: 29
apointofnothing - See this Members User comments on their Profile page
Default

SmitFraudFix v2.126

Scan done at 1:58:07.73, Fri 12/01/2006
Run from I:\Documents and Settings\Ryan\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» I:\


»»»»»»»»»»»»»»»»»»»»»»»» I:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» I:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» I:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» I:\WINDOWS\system32

I:\WINDOWS\system32\hp???.tmp FOUND !
I:\WINDOWS\system32\hp????.tmp FOUND !
I:\WINDOWS\system32\ot.ico FOUND !
I:\WINDOWS\system32\stdole3.tlb FOUND !
I:\WINDOWS\system32\ts.ico FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» I:\Documents and Settings\Ryan


»»»»»»»»»»»»»»»»»»»»»»»» I:\Documents and Settings\Ryan\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

I:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url FOUND !
I:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» I:\DOCUME~1\Ryan\FAVORI~1

I:\DOCUME~1\Ryan\FAVORI~1\Antivirus Test Online.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» I:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="about:Home"
"SubscribedURL"="about:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"{a0c51615-738a-4542-801a-5af61614e182}"="bedimples"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"{62eb0924-19d2-4226-b4b9-8ad1f70904c1}"="bronchovascular"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"{55059d4f-a1ac-4837-ae07-4859101f598d}"="chromatodysopia"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"{6af69c4d-420a-4c95-b34f-e4635f84f53b}"="forevouched"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


  #7  
Old 12-01-2006
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".


The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning to others : running option #2 on a non infected computer will remove your Desktop background.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes
Linear Mode Linear Mode