P
perrin
Hi all. This is a problem I acquired when I installed a new HDD as the
bootup device. The computer freezes randomly for anything up to a minute,
during which the HDD LED is completely lighted (not flickering as in
ordinary access of the drive).
I'm not sure if the problem is hardware or software related. When I first
installed a copy of Win XP Pro on the drive, I made the mistake of going
online to update it without installing any protection. The computer was
affected by a number of viruses, spyware and malware. I *think* I have
gotten rid of all of them - F-Prot, Lavasoft Adware and Spybot S&D don't
detect anything now. I am posting a HijackThis log just in case below.
I'm wondering if it can also be due to programmes running in the background.
How do I copy the list of processes and post them here?
I am also attaching a number of warnings and errors in the Event Viewer.
Specs:
Windows XP Pro SP 2
512 MB RAM
NVidia GeForce4 Ti4200
Maxtor 120 GB
IBM Deskstar 80GB
Sorry for the long post. TIA.
perrin
Event Type: Warning (repeated instances)
Event Source: Disk
Event Category: None
Event ID: 51
Date: 3/17/2005
Time: 5:31:56 PM
User: N/A
Computer: LKS-B5M4QRKWCB2
Description:
An error was detected on device \Device\Harddisk2\D during a paging
operation.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 03 04 68 00 01 00 b6 00 ..h...¶.
0008: 00 00 00 00 33 00 04 80 ....3..€
0010: 2d 01 00 00 85 01 00 c0 -...…..À
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: e0 19 00 00 00 00 00 00 à.......
0030: ff ff ff ff 01 00 00 00 ÿÿÿÿ....
0038: 40 00 00 4e 00 00 00 00 @..N....
0040: ff 20 0a 12 4c 02 20 40 ÿ ..L. @
0048: 00 10 00 00 0a 00 00 00 ........
0050: 00 00 00 00 38 bb 2b 82 ....8»+‚
0058: 00 00 00 00 08 e0 f3 81 .....àó
0060: 00 00 00 00 00 01 00 00 ........
0068: 28 00 00 00 01 00 00 00 (.......
0070: 08 00 00 00 00 00 00 00 ........
0078: 00 00 00 00 00 00 00 00 ........
0080: 00 00 00 00 00 00 00 00 ........
0088: 00 00 00 00 00 00 00 00 ........
Event Type: Error (repeated instances)
Event Source: HDDTService
Event Category: None
Event ID: 0
Date: 3/19/2005
Time: 12:25:53 AM
User: N/A
Computer: LKS-B5M4QRKWCB2
Description:
The description for Event ID ( 0 ) in Source ( HDDTService ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be
able to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: The
handle is invalid.
Logfile of HijackThis v1.99.1
Scan saved at 8:11:16 PM, on 3/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\FSI\F-Prot\fpavupdm.exe
F:\Program Files\Palick Soft\HDD Temperature Pro\HDDTsvc.exe
F:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
F:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
F:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
F:\WINDOWS\system32\GSICON.EXE
F:\WINDOWS\system32\dslagent.exe
F:\WINDOWS\system32\windowsp.exe
F:\Program Files\FSI\F-Prot\F-StopW.EXE
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\WINDOWS\system32\CAPRPCSK.EXE
F:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
F:\Program Files\eMule\emule.exe
F:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
F:\Program Files\Palick Soft\HDD Temperature Pro\HDDTemperaturePro.exe
F:\Program Files\Miranda IM\miranda32.exe
F:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\WINDOWS\system32\cmd.exe
F:\Documents and Settings\Kah Seng\My Documents\Downloads\start_ups.exe
F:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Outlook Express\msimn.exe
F:\Documents and Settings\Kah Seng\My
Documents\Downloads\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://soccernet.espn.go.com/index?cc=4716&POLL=28546966
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.singnet.com.sg
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyServer = proxy.singnet.com.sg:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
F:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EM_EXEC] F:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [CAPON]
F:\WINDOWS\System32\Spool\Drivers\w32x86\3\CAPONN.EXE
O4 - HKLM\..\Run: [Windows Network Controller] windowsp.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [F-StopW] F:\Program Files\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program
Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [RemoteControl] "F:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program
Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [Windows Network Controller] windowsp.exe
O4 - HKLM\..\RunOnce: [Windows Network Controller] windowsp.exe
O4 - HKCU\..\Run: [Windows Network Controller] windowsp.exe
O4 - HKCU\..\Run: [eMuleAutoStart] F:\Program
Files\eMule\emule.exe -AutoStart
O4 - HKCU\..\RunOnce: [Windows Network Controller] windowsp.exe
O4 - Startup: MailWasherPro.lnk = F:\Program Files\FireTrust\MailWasher
Pro\MailWasher.exe
O4 - Global Startup: HDD Temperature Pro.lnk = F:\Program Files\Palick
Soft\HDD Temperature Pro\HDDTemperaturePro.exe
O4 - Global Startup: Miranda IM.lnk = F:\Program Files\Miranda
IM\miranda32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program
Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: F:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B866353-E598-4403-8E4D-B871AB30DC55} (Speed Class) -
http://integratedi.singnet.com.sg/technical/helptools/media/SpeedCtrl.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{1C9A6F4A-9663-43F4-BA52-DD31F0E5FC19}:
NameServer = 165.21.100.88 165.21.83.88
O23 - Service: F-Prot Antivirus Update Monitor - FRISK Software - F:\Program
Files\FSI\F-Prot\fpavupdm.exe
O23 - Service: HDD Temperature (HDDTService) - PalickSoft - F:\Program
Files\Palick Soft\HDD Temperature Pro\HDDTsvc.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies -
F:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - F:\Program
Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
F:\WINDOWS\System32\nvsvc32.exe
bootup device. The computer freezes randomly for anything up to a minute,
during which the HDD LED is completely lighted (not flickering as in
ordinary access of the drive).
I'm not sure if the problem is hardware or software related. When I first
installed a copy of Win XP Pro on the drive, I made the mistake of going
online to update it without installing any protection. The computer was
affected by a number of viruses, spyware and malware. I *think* I have
gotten rid of all of them - F-Prot, Lavasoft Adware and Spybot S&D don't
detect anything now. I am posting a HijackThis log just in case below.
I'm wondering if it can also be due to programmes running in the background.
How do I copy the list of processes and post them here?
I am also attaching a number of warnings and errors in the Event Viewer.
Specs:
Windows XP Pro SP 2
512 MB RAM
NVidia GeForce4 Ti4200
Maxtor 120 GB
IBM Deskstar 80GB
Sorry for the long post. TIA.
perrin
Event Type: Warning (repeated instances)
Event Source: Disk
Event Category: None
Event ID: 51
Date: 3/17/2005
Time: 5:31:56 PM
User: N/A
Computer: LKS-B5M4QRKWCB2
Description:
An error was detected on device \Device\Harddisk2\D during a paging
operation.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 03 04 68 00 01 00 b6 00 ..h...¶.
0008: 00 00 00 00 33 00 04 80 ....3..€
0010: 2d 01 00 00 85 01 00 c0 -...…..À
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: e0 19 00 00 00 00 00 00 à.......
0030: ff ff ff ff 01 00 00 00 ÿÿÿÿ....
0038: 40 00 00 4e 00 00 00 00 @..N....
0040: ff 20 0a 12 4c 02 20 40 ÿ ..L. @
0048: 00 10 00 00 0a 00 00 00 ........
0050: 00 00 00 00 38 bb 2b 82 ....8»+‚
0058: 00 00 00 00 08 e0 f3 81 .....àó
0060: 00 00 00 00 00 01 00 00 ........
0068: 28 00 00 00 01 00 00 00 (.......
0070: 08 00 00 00 00 00 00 00 ........
0078: 00 00 00 00 00 00 00 00 ........
0080: 00 00 00 00 00 00 00 00 ........
0088: 00 00 00 00 00 00 00 00 ........
Event Type: Error (repeated instances)
Event Source: HDDTService
Event Category: None
Event ID: 0
Date: 3/19/2005
Time: 12:25:53 AM
User: N/A
Computer: LKS-B5M4QRKWCB2
Description:
The description for Event ID ( 0 ) in Source ( HDDTService ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be
able to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: The
handle is invalid.
Logfile of HijackThis v1.99.1
Scan saved at 8:11:16 PM, on 3/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\FSI\F-Prot\fpavupdm.exe
F:\Program Files\Palick Soft\HDD Temperature Pro\HDDTsvc.exe
F:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
F:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
F:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
F:\WINDOWS\system32\GSICON.EXE
F:\WINDOWS\system32\dslagent.exe
F:\WINDOWS\system32\windowsp.exe
F:\Program Files\FSI\F-Prot\F-StopW.EXE
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\WINDOWS\system32\CAPRPCSK.EXE
F:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
F:\Program Files\eMule\emule.exe
F:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
F:\Program Files\Palick Soft\HDD Temperature Pro\HDDTemperaturePro.exe
F:\Program Files\Miranda IM\miranda32.exe
F:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\WINDOWS\system32\cmd.exe
F:\Documents and Settings\Kah Seng\My Documents\Downloads\start_ups.exe
F:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Outlook Express\msimn.exe
F:\Documents and Settings\Kah Seng\My
Documents\Downloads\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://soccernet.espn.go.com/index?cc=4716&POLL=28546966
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.singnet.com.sg
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyServer = proxy.singnet.com.sg:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
F:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EM_EXEC] F:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [CAPON]
F:\WINDOWS\System32\Spool\Drivers\w32x86\3\CAPONN.EXE
O4 - HKLM\..\Run: [Windows Network Controller] windowsp.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [F-StopW] F:\Program Files\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program
Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [RemoteControl] "F:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program
Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [Windows Network Controller] windowsp.exe
O4 - HKLM\..\RunOnce: [Windows Network Controller] windowsp.exe
O4 - HKCU\..\Run: [Windows Network Controller] windowsp.exe
O4 - HKCU\..\Run: [eMuleAutoStart] F:\Program
Files\eMule\emule.exe -AutoStart
O4 - HKCU\..\RunOnce: [Windows Network Controller] windowsp.exe
O4 - Startup: MailWasherPro.lnk = F:\Program Files\FireTrust\MailWasher
Pro\MailWasher.exe
O4 - Global Startup: HDD Temperature Pro.lnk = F:\Program Files\Palick
Soft\HDD Temperature Pro\HDDTemperaturePro.exe
O4 - Global Startup: Miranda IM.lnk = F:\Program Files\Miranda
IM\miranda32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program
Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: F:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B866353-E598-4403-8E4D-B871AB30DC55} (Speed Class) -
http://integratedi.singnet.com.sg/technical/helptools/media/SpeedCtrl.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{1C9A6F4A-9663-43F4-BA52-DD31F0E5FC19}:
NameServer = 165.21.100.88 165.21.83.88
O23 - Service: F-Prot Antivirus Update Monitor - FRISK Software - F:\Program
Files\FSI\F-Prot\fpavupdm.exe
O23 - Service: HDD Temperature (HDDTService) - PalickSoft - F:\Program
Files\Palick Soft\HDD Temperature Pro\HDDTsvc.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies -
F:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - F:\Program
Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
F:\WINDOWS\System32\nvsvc32.exe