everything was going fine with my newly acquired dial-up connection, until this morning when i first turned the computer on. i got an error message and it asked if i wanted to send microsoft a report. i was not connected yet, so i was unable to send it. i clicked on the verizon icon to connect, and the screen went a dark blue. i waited a few minutes and decided that it may never change and hard killed by pushing the button in and holding it.

it is now working like nothing ever happened, but i thought it would be a good idea to have the hijackthis analyzed just in case. if it's clean i can store the log for future references. sorry i was unable to add it as an attachment, there was an error, i had to copy and paste it. i am wondering if all these errors couldn't be related to the slower dial-up connection.
i appreciate the analysis and the expert advice. Ed James

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:18:04 AM, on 10/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\program files\a-squared free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Owner\My Documents\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{858C72D5-7F64-4695-8FB7-6C649C80409A}: NameServer =
O20 - Winlogon Notify: SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 6070 bytes

Dani AI

Generated

A concise troubleshooting checklist to follow after an unexpected error + one-off blue screen. The HijackThis output posted looks clean (as noted) and others suggested a hardware angle (see ). That combination makes transient driver/hardware problems more likely than persistent infection, but a few focused checks will either confirm that or catch something less obvious.

Gather crash evidence first: check Event Viewer (System/Application) for entries at the crash time, enable small memory dumps and turn off automatic restart so a future BSOD can be inspected, and look for any minidumps in %SystemRoot%\Minidump. Useful quick commands:

eventvwr.msc
msinfo32
devmgmt.msc

sfc /scannow
chkdsk C: /r

Analyze any minidump with a crash viewer (BlueScreenView) or the Debugging Tools for Windows to extract the STOP code and driver name.

Hardware and driver triage next: run a boot-time memory test (Memtest86+), run the HDD vendor’s offline diagnostics or chkdsk /r, and check BIOS hardware-monitor temps/voltages. Verify modem/telephony drivers (dial-up stacks can hang the system) and update them if available. Booting into Safe Mode with Networking or using msconfig to disable non-Microsoft services helps determine whether a third-party driver or security product is implicated — disable AV/firewall only briefly and while offline if testing.

A single, unreproducible crash often needs only monitoring after these checks; repeated crashes with the same STOP code or a named driver point to a specific fix (driver rollback/update, replace bad RAM, repair/replace HDD, or adjust cooling/PSU). Keeping the HijackThis log and any captured minidump/STOP code makes further diagnosis faster for anyone assisting later.

Recommended Answers

All 4 Replies

Looks clean to me.

You might wish to go into system informationand look for IRQ conflicts or other conflicts. Otherwise it's probably one of those one off gliotches that we all get from time to time and don't bother with.

i checked system information IRQ, and most of everything else that was there, and found nothing. everything was ok. when i return home tonight i will check it better. the fan turned on last night unexpectedly, so it may be overheating. i will also remove the cover and clear out the dust.
thanks for the analysis and advice. if anything else comes to mind, please give a hollar. Ed James

Yep, dust clearing is always a good thing to do. Also if you suspect overheating, buy another fan to put in, just 1 will make all the difference. They are quite cheap to pick up from most computer stores, Maplins is a good place to start i believe. Or if you want to splash some cash, you could have a water-cooling system fitted, which will deffinatly put an end to any overheating issues.

everything was going fine with my newly acquired dial-up connection, until this morning when i first turned the computer on. i got an error message and it asked if i wanted to send microsoft a report. i was not connected yet, so i was unable to send it. i clicked on the verizon icon to connect, and the screen went a dark blue. i waited a few minutes and decided that it may never change and hard killed by pushing the button in and holding it.

it is now working like nothing ever happened, ....

Don't worry about it. You've probably never noticed the fan before.

Everyone's had something like that happening; you boot up and get an unexpected error; after that it's blue screen or something unpredictble. It's likely to be a one time glitch.

It won't hurt to be proactive and clear the dust out - but if it happens regularly then we have to look a bit deeper.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.