Computer keeps restarting

  1. #1
    RedHawk50 is offline Junior Member

    Angry Computer keeps restarting

    First, let me forewarn, a little patience may be required as my tech knowledge is limited.
    I'm running Windows XP Home.
    At random times I'm getting screen freeze ups and other times
    my computer just restarts. After each time, I get an error message from Microsoft that says
    a serious error has occured, please send a report to MS. After sending the report
    I'm taken to a MS website that says the error was caused by a DEVICE DRIVER, but
    they are unable to give anymore information.
    Troubleshooter suggest uninstalling
    every driver one by one, each time waiting to see if the restarts stop. This doesn't
    seem practical, because sometimes a whole day will pass without a restart, but other times
    it may restart 6 or 7 times in as many minutes! It's driving me crazy! Please help!
    After loosing a lot of important data, not mention a "buttload" of work, twice in the same day
    I was barely able to keep myself from putting my foot thru the monitor!

    Any help would be appreciated to the point of donating BODY PARTS!


    Hijackthis Log:

    Logfile of HijackThis v1.98.0
    Scan saved at 7:19:52 PM, on 8/3/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\Mixer.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Aladdin Systems\iClean\iClean.exe
    C:\Program Files\America Online 9.0\aoltray.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\America Online 9.0\waol.exe
    C:\Program Files\America Online 9.0\shellmon.exe
    C:\Program Files\America Online 9.0\aolwbspd.exe
    C:\Program Files\Windows NT\Accessories\wordpad.exe
    C:\Program Files\Aladdin Systems\StuffIt 7.5\stuffit.exe
    C:\Program Files\Aladdin Systems\StuffIt 7.5\stuffit.exe
    C:\Documents and Settings\All Users\Documents\AOL Downloads\hijackthis.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\All Users\Documents\AOL Downloads\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html#1526
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = c:\searchpage.html#1526
    R1 - HKLM\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html#1526
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\searchpage.html#1526
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html#1526
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = c:\searchpage.html#1526
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = c:\searchpage.html#1526
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\searchpage.html#1526
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html#1526
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = c:\searchpage.html#1526
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\searchpage.html#1526
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = c:\searchpage.html#1526
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = c:\searchpage.html#1526
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = c:\searchpage.html#1526
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = c:\searchpage.html#1526
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: iempg - {FFFFFFFF-FFFF-FFFF-FFFF-5F8507C5F4E9} - C:\WINDOWS\iempg2.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [iClean] "C:\Program Files\Aladdin Systems\iClean\iClean.exe" /I
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
    O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
    O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
    O13 - DefaultPrefix: c:\searchpage.html?page=
    O13 - WWW Prefix: c:\searchpage.html?page=
    O13 - Home Prefix: c:\searchpage.html?page=
    O13 - Mosaic Prefix: c:\searchpage.html?page=
    O16 - DPF: {10000000-1000-0000-1000-000000000000} -
    O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.3.1_03) -
    O16 - DPF: {CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} (Java Plug-in 1.3.1_03) -
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9B00F9AA-E2F9-479F-A856-2E3E04787EA0}: NameServer = 66.0.60.9,199.170.121.15
    O17 - HKLM\System\CCS\Services\Tcpip\..\{FE7FCF8D-E799-46EE-B11C-03B36335B760}: NameServer = 205.188.146.146
    Last edited by RedHawk50; 04-08-2004 at 01:23 AM. Reason: HijackThis Log Added


  2. #2
    Rainbow32 is offline Junior Member
    Have you added any new hardware like sound card, video card, printer, etc. and this problem started? Do you update any drivers for any hardware that you have and before this started? Alot of times restarting is a sign of overheating. Open the tower and make sure all your fans are operating properly and the inside is free of dust and debris. Leave the cover off for a couple of days and see if the problem goes away. Then you know it's an overheating problem.

  3. #3
    RedHawk50 is offline Junior Member
    Thanks for the quick reply Rainbow! Gosh, it's been going on for so long I don't really remember, but I THINK around the time it started I had just gone to a cable modem, and may have added a digital camera driver.
    I also thought of the CPU fan, and check the temp when it restarts, it's always around 118 degrees, but since my knowledge is so scarce, I don't know if that's abnormal or not.

  4. #4
    Rainbow32 is offline Junior Member
    I'm no expert on HiJackThis log but can give you a link to their tutorial page.
    http://hjt.wizardsofwebsites.com/
    These 2 entries could be a browser hijacking.

    O17 - HKLM\System\CCS\Services\Tcpip\..\{9B00F9AA-E2F9-479F-A856-2E3E04787EA0}: NameServer = 66.0.60.9,199.170.121.15
    O17 - HKLM\System\CCS\Services\Tcpip\..\{FE7FCF8D-E799-46EE-B11C-03B36335B760}: NameServer = 205.188.146.146


    You also have 2 programs I would stop using just to see if they maybe related to the problem.
    Iclean .exe
    Diskeeper Service.
    Check your event viewer when this problem happens and see if there's anymore info on what device driver maybe resoponsible for this. To access event viewer go to start>control panel>administrative tools>event viewer. Check both the application and system events for a time and date that coincides with the problem.
    As for your temp 118 is O.K. especially if your using an AMD processor.
    What vidoe card are you using?

+ Reply to Thread