Tech Support Guy banner
Status
Not open for further replies.
1 - 20 of 22 Posts

· Registered
Joined
·
45 Posts
Discussion Starter · #1 ·
Help the tyro please! My system will stop responding from time to time. seems like when printing or opening a new window. Nothing works, not even the three finger ballet(ctrl-alt-del). could somebody please look at my Hijack log and see if anything looks suspicious? I am running Norton 2003 pro with all updates. All updates for windows w/ latest service packs and latest patches. I have also run ad-aware and had the cwshredder go thru once.

My system is a P111/ 450m
8g hdd no partition

Logfile of HijackThis v1.97.7
Scan saved at 9:12:08 PM, on 4/6/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
C:\Documents and Settings\Apryl n' John\Desktop\Virus Busters\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C82 Series" /O5 "LPT1:" /M "Stylus C82"
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "C:\WINDOWS\system32\E_S7.tmp"
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38066.2332986111
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Thanx
 

· Registered
Joined
·
45 Posts
Discussion Starter · #7 ·
O.K. I ran the memtest for 8.5 hrs and it showed no errors. Since then i have also experienced multiple Blue screens. DRIVER_IRQL_LESS_THAN_OR_NOT_EQUAL and BAD_POOL_CALLER
What else can I check or do ? I can leave the computer on idle for days on end and it doesn't freeze. Seems to occur more when opening pages or spooling for the printer. Any suggestions? :confused:

P.S. I am on a ranch so I am in and out all the time.

thanx
 

· Registered
Joined
·
16,832 Posts
Is there any info that you can provide from the error screen to add ?
Also you may try going and right click on "my computer" / manage/ event viewer/ application and see if the generated report gives up any clues..
 

· Registered
Joined
·
45 Posts
Discussion Starter · #9 ·
2nd attempt at posting this. Last time computer rebooted in the middle of my paragraph. VERY FRUSTRATING!!!
I looked at the event veiwer where each error was marked and it generally went like this; Cleaning up corrupt content index metadata on C:\system volume information\catalouge wci. index will be automatically restored by refiltering all documents.

It seems that all the errors have something to do with the indexing system.

The only blue screen notes that I took were ****STOP: 0k000000c2 (0x00000099, 0xe2d218c8, BAD_POOL_CALLER. beginning physical memory dump.

does this help?
 

· Registered
Joined
·
45 Posts
Discussion Starter · #10 ·
Just figured out how to do this,
Event Type: Error
Event Source: Ci
Event Category: CI Service
Event ID: 4126
Date: 4/9/2004
Time: 12:10:11 PM
User: N/A
Computer: DESKTOP
Description:
Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci. Index will be automatically restored by refiltering all documents.
 

· Registered
Joined
·
45 Posts
Discussion Starter · #12 ·
Hi again, chkdsk has offered up nothing new. All files and folders o.k. System ran fine on Sunday afternoon, then froze while I was trying to compose this reply.
I defragged and the system was o.k.on Sunday aft as mentioned. After the evening freeze I checked the defragger again and it seems that the files need to be defragged again. Could this indicate anything amiss?
Also , in the report, some of the files that couldn't be fixed were the .wci files that showed up in the event veiwer report. I don't know if there's a connection or not.
Thanks for the continued help and patience all, esp mobo!
 

· Registered
Joined
·
45 Posts
Discussion Starter · #16 ·
Device already set to auto. I did change the recovery to restart the service on the first , second and third failure.
Anything else I could try?
By the way , the defragging thing was a bust. I had the system defrag overnight and when I opened the internet this am the fist site I went to froze!


Pan, Pan, Pan...I wish to report an inflight fire.....
 

· Registered
Joined
·
45 Posts
Discussion Starter · #18 ·
Hi, once again , I apologize for the delays in answering. Most of the time it happens while online. The only other time was when I was spooling multiple pages for my printer. (45)
 

· Registered
Joined
·
16,832 Posts
You need to update the service pack for that system is the resolve I have come up with. Service pack one is quite outdated so update it to service pack 4.
 

· Registered
Joined
·
45 Posts
Discussion Starter · #20 ·
Hi Mobo, I have all the latest updates installed along with all the latest norton anti-virus updates. I have run ad-aware and the cw shredder. I had this before i began the posts so I don't think the problem lies there. After I reboot, Windows does a diskchk and a lot of times I get stuff like C:\ documents\settings\temp\spool\ 005000. ci entry size not valid, entry will be truncated ( Not verbatim!! ) but somthing along those lines. If you think this could help I will post next time it happens exactley what it said.
is there anything else I could possibly give you for Info?? I am including the latest Hijack log. Thanx

Logfile of HijackThis v1.97.7
Scan saved at 12:02:30 PM, on 4/17/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Apryl n' John\Desktop\Virus Busters\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C82 Series" /O5 "LPT1:" /M "Stylus C82"
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "C:\WINDOWS\system32\E_S7.tmp"
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38066.2332986111
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{557DC980-BD9B-4EBB-B0E7-8914EC5366CD}: NameServer = 206.47.244.79 206.47.244.12
 
1 - 20 of 22 Posts
Status
Not open for further replies.
Top