Computer freezes during operation

  1. #1
    g.powers is offline Newbie

    Computer freezes during operation

    Hi

    I've had this problem for about 12 days now and I can't work out what is causing it. Any help would be appreciated.

    My virus scanner (AVG) started to freeze my computer overnight while it was running a scheduled scan. I have since tried 3 other Anti-virus programs (Avira Anti Vir, Avast and PC Tools Free version) and all have done the same.

    My PC has also frozen while using a TV station's media player to playback a missed TV programme (the BBC iplayer). A Backgammon game that I have had for about 4 years with no problem has also frozen the PC. Finally, playing music CD's on my PC will randomly freeze it. Some after 1 or 2tracks, others after 8 or 9 tracks.

    I am at a complete loss. I don't think it is a virus/malware problem but need help to sort out the problem as I am using the Internet without a Virus scanner at the moment.

    I have a Fujitsu Siemens PC with an Intel 4 CPU, 3.00 GHz and 1.00 GB of RAM running Windows XP SP2

    Thanks in anticiaption

  2. #2
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    A freeze that requires a manual power off is usually: Heat; bad Driver; bad Hardware.

    Do you monitor your temperatures? Do you monitor your CPU usage?

    Event Viewer
    --------------------------------------------------
    Check your Event Viewer via Administrative Tools.

    Open the System as well as Application tabs and look for red X errors that coincide with your problem. Details here:

    How to view and manage event logs in Event Viewer in Windows XP

    Basic information on Event Viewer errors can be found here: EventID.Net

  3. #3
    g.powers is offline Newbie
    Here are the list of errors found in the Event Viewer. I'm afraid that to reduce file size I have had to create screen dumps as JPG files. If you find them unmanageable then please let me know how to get them to you without typing out all the details.

    Also, If you need the description of any of these errors then again, please let me know.

    Many thanks for your anticiapted help

  4. #4
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    The system errors are the result of certain services not starting.It is not uncommon to have such errors on any machine. Usually they coincide with startup and usually they are benign. However the quantity that you have is unusual. You can right click each line and choose properties to get a specific description of each entry. Pick through a few and see if you find a common description.

    Application repeats this over and over:

    Event ID: 2004
    Source: PerfNet
    Type: Error
    Description: Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.

    There is some history of this error being associated with anti virus software.
    Again please get the description of these lines. I would venture they are all the same.

    Then on to the application hangs and application errors. Again please the description.

    Also try a virus scan in Safe Mode.

    Safe Mode
    --------------------------------------------------
    Can you get into Safe Mode?

    Also install and run Spybot S&D if you haven't already:

    http://www.safer-networking.org/index2.html

  5. #5
    g.powers is offline Newbie
    Here are the error description lists: -

    Event ID 7000
    Date Occurred 27 times since 16th Feb 2009 (log starts on 16th Feb)
    Source Error Service Control Manager
    Type System
    Description The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: The system cannot find the file specified

    Event ID 7034
    Date Occurred 22/02/09 and 19/02/09
    Source Error Service Control Manager
    Type System
    Description The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s).

    Event ID 7022
    Date Occurred 16/02/09
    Source Error Service Control Manager
    Type System
    Description The KService service hung on starting.

    Event ID 10010
    Date Occurred 10 times between 16 and 19/02/09
    Source Error DCOM
    Type System
    Description The server {000C101C-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.

    Event ID 2004
    Date Occurred 120 times since 25/05/08 (Log starts on this date)
    Source Error PerfNet
    Type Application
    Description Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.

    Event ID 2005
    Date Occurred 18/02/09
    Source Error PerfNet
    Type Application
    Description Unable to read performance data from the Server service. No Server performance data will be returned in this sample. Error code returned is in data DWORD 0, IOSB.Status is DWORD 1 and the IOSB.Information is DWORD 2.

    Event ID 2006
    Date Occurred 18/02/09
    Source Error PerfNet
    Type Application
    Description Unable to read Server Queue performance data from the Server service. No Server Queue performance data will be returned in this sample. Error code returned is in data DWORD 0, IOSB.Status is DWORD 1 and the IOSB.Information is DWORD 2.

    Event ID 3001
    Date Occurred 2 times on 07/02/09
    Source Error LoadPerf
    Type Application
    Description The performance counter name string value in the registry is incorrectly formatted. The bogus string is 5208, the bogus index value is the first DWORD in Data section while the last valid index values are the second and third DWORD in Data section.

    Event ID 3011
    Date Occurred 07/02/09
    Source Error LoadPerf
    Type Application
    Description Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The Error code is the first DWORD in Data section.

    Event ID 4609
    Date Occurred 25/01/09
    Source Error EventSystem
    Type Application
    Description The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8001010D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsyste mobj.cpp. Please contact Microsoft Product Support Services to report this error.

    Event ID 11904
    Date Occurred 18/12/08
    Source Error MsInstaller
    Type Application
    Description Product: 4oD -- Error 1904.Module C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx failed to register. HRESULT -2147220473. Contact your support personnel.

    Event ID 1002**
    Date Occurred 54 times between 28/08/08 and 19/02/09
    Source Error Application Hang
    Type Application
    Description Hanging application iexplore.exe, version 7.0.6000.16791, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

    Event ID 1000**
    Date Occurred 14 times between 25/08/08 and 15/02/09
    Source Error Application Error
    Type Application
    Description Faulting application ati2evxx.exe, version 6.14.10.4121, faulting module ati2evxx.exe, version 6.14.10.4121, fault address 0x0002816b.


    ** These have different application descriptions. (I can provide these, if needed. Omitted them to save time in getting this list together)

    Running virus scan and Spybot in safe mode - will post results

  6. #6
    g.powers is offline Newbie
    I have spent a few hours trying to get my PC to boot in safe mode. After a number of freezes I have managed to get it started in safe mode a few times. Spybot Search and Destroy froze while it was loading. AVG stated that it could only run a "Command line Scanner" in safe mode. I did this but it also froze

  7. #7
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    Do you run any P2P software?

    See if you can run HijackThis and post back the log if you can.

    http://www.trendsecure.com/portal/en...ols/hijackthis

  8. #8
    g.powers is offline Newbie
    I don't use P2P software any more (over 2 years ago was last time). Here's the HijackThis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 08:00:57, on 23/02/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Kontiki\KService.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\G Powers\Desktop\hijackgpthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstan ce.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st_current.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    --
    End of file - 6713 bytes

  9. #9
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    Cool. As you might have noticed we are in different time zones and probably different time sets as well.

    It is 3:30 AM to me but I usually stay up till 4 or so.

    Anyway I will take a look at that log tomorrow and get back to you.

    Some of your Service failures were related to services often stopped by P2P software hence the question there.

    C:\Program Files\Kontiki\KService.exe to be precise.

    Anyway will look further and get back to you.

  10. #10
    jephree is offline ¨*·.¸ «.·°·..·°·.» ¸.·*¨
    I would suggest the following:

    1) go to Control Panel > Add/Remove Programs > uninstall Yahoo Toolbar.

    2) go to start Run... msconfig > Startup

    Here click the box that says: Disable All & Apply & pass all the warnings etc. then reboot into Safe Mode.

    On reboot you will be told you are in a diagnostic mode etc. Just click thru these warnings as well.

    Try Spybot here and also your virus scan.

+ Reply to Thread
Page 1 of 2 1 2 LastLast