I have been getting crc errors when trying to install games and extract zip folders. My pc has also been doing some strange things, like taskbar changing from blue to grey and the sound not working.
Here is a hijack this log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:11 PM, on 6/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE
c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\ApvxdWin.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Sarah\My Documents\New Folder\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Internet Security 2008\Inicio.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{02D5B361-A00C-4340-8DC9-830C1FE6B8E8}: NameServer =
O17 - HKLM\System\CS2\Services\Tcpip\..\{02D5B361-A00C-4340-8DC9-830C1FE6B8E8}: NameServer =
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe

--
End of file - 6670 bytes

Dani AI

Generated

The symptoms described by — CRC errors extracting/installing, the taskbar falling back to a plain grey theme, and intermittent sound loss while Panda seems to get disabled — point more toward hardware/driver instability than a classic persistent browser hijack. 's suggestions (memory, disk checks and Themes service) are on target; the log itself contains mostly legitimate entries and no obvious persistent BHO/rootkit indicators.

Key suspects to prioritize

  • Intermittent RAM errors that slip past a single overnight run; even one bad stick or slot can corrupt files and cause odd service crashes.
  • Storage-controller or cabling problems (third-party RAID/IDE drivers can cause CRCs and file corruption).
  • Driver conflicts or explorer/service crashes that temporarily disable AV and reset the visual style.
  • Power/thermal issues or a failing PSU producing random corruption.

Practical, ordered troubleshooting (do these before a full reinstall)

  1. Rerun a thorough memory test: run MemTest for multiple full passes and test each DIMM in each slot individually.
  2. Verify file integrity: re-download the same archive on a second, known-good machine or test the same archive with an alternate archiver to confirm it is not a bad download.
  3. Run disk and system checks: chkdsk c: /r (reboot required) and sfc /scannow.
  4. Swap the SATA/IDE cable and move the drive to a different controller port; temporarily remove any third-party RAID/JMicron drivers and use the motherboard's native controller driver.
  5. Perform a clean boot (msconfig - hide Microsoft services, disable the rest) and see if the problem reproduces without non-Microsoft services/startups.
  6. Inspect Event Viewer (eventvwr.msc) for Application/System errors and explorer.exe or service crash/restart timestamps that match the failures.

If all hardware and driver checks pass but problems persist, test with a fresh Windows install (do not restore a potentially infected or corrupted image) and add third-party software one piece at a time. For deeper analysis, collect memtest logs, the relevant Event Viewer entries (timestamps), motherboard/chipset and storage-controller driver versions before escalating.

Recommended Answers

All 4 Replies

Looks normal, though I'm not a `trained expert` in HJT logs.
Why do you assume infection? Have you run a ChkDsk, an HD diagnostic from your HD manufacturer, a memory test ? Admittedly memory problems usually result in blue screens but worth doing anyway. Ensure all your devices are using the latest drivers. Do a System File Check too.

Run ChkDsk; http://support.microsoft.com/kb/315265
Run SFC;

Manufacturers HD diagnostics;
http://home.comcast.net/~SupportCD/DiagnoseXP.html#Harddrive
http://www.pcstats.com/articleview.cfm?articleid=1583&page=6

Info about your PC if needed for the above: www.gtopala.com
Memory test; http://www.memtest.org

Taskbar colour change - go into Control Panel/Desktop and ensure Windows XP theme is selected;

If it is selected and you still have the plain-looking Classic appearance - ensure the Themes service is started and set to Automatic. Go to Start menu/run, type Services.msc, press return, scroll down the list to Themes and check the aforementioned settings.

I have run memtest 86 overnight. I have tried dropping my O/C back to standard. Whatever this is it disables my anti virus when it changes the taskbar colour. I have replaced my hdd with a new one still get the problem. I am doing a complete virus scan on panda active online atm.

Does it stop any other services when this happens? System Restore no good? Any enlightening entries in the Event log?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.