Hi guys, am running xp pro and having problems with pc going into sleep mode when i open microsoft office outlook, sometimes it will open but as soon as i try and open a folder it shuts down and the only thing i see is a small window saying attention pc going into sleep mode and then it reboots itself.
Any ideas on where i should look or what to try would be great.

thanks ... ...

Dani AI

Generated

Following 's report and the helpful tips from and , this short expert note pulls together a compact diagnostic path and prevention checklist for a desktop that unexpectedly enters sleep or reboots when an email client is opened. The thread rightly focused on removing infections, but the problem can also come from power-management, drivers, firmware, or failing hardware — so include those checks before or after a reinstall.

First, capture hard evidence. Reproduce the event if possible and note exact times, then inspect the Windows Event Viewer System and Application logs for entries at those times (they will usually say whether the OS triggered a sleep or the machine lost power). Try a clean-boot or Safe Mode to see if the fault persists with minimal drivers and startup items; disable email-client add-ins while testing. Also check scheduled tasks and any autorun utilities that might trigger power state changes.

If logs point to hardware or give no clear software cause, move to firmware and components. Confirm BIOS/UEFI power/ACPI settings and update firmware if available. Check cooling and PSU health (noisy fans, bulging capacitors, unstable voltages), run an extended memory test, and test stability with minimal RAM/drives installed. A failing power supply or overheating CPU can look like an OS-initiated sleep or crash, so swapping in a known-good PSU or booting from rescue media for a stability test can be decisive.

After a clean install, prioritize installing vendor chipset and power-management drivers, apply OS updates, and restore only known-good data and programs. Keep a tested recovery image and avoid reintroducing untrusted installers. If the issue returns, export the exact Event Viewer entries and hardware-test logs before posting them — that data makes remote diagnosis far more effective.

Recommended Answers

All 16 Replies

Is it a pc or a laptop. If it is a pc then turn off sleep mode in Control Panel - Power Options.

It may be caused by some type of infection. What protective software do you have and what does it say when you do a full scan?

hi and thanks for the reply. it is a desk top - scan came back with 0 problems, turned off sleep mode and tried to open outlook and it still shut down. Am running symantic

Right, Symantec / Norton software is absolutely rubbish at protecting a pc.
Download, update, and do a full scan with Mbam - http://www.malwarebytes.org/mbam.php then post it's results in this thread and we will see how infected your pc is.

Your pc will probably need further work, running Mbam is just the first stage.

hi Rik, how right you are... still doing scan but straight away found 9infections, will post final outcome when done.
Hopefully this will lead to fixing the problem.
Thanks for your help.

No problem. But please pleas please wait until you are given the all clear by myself or someone else before thinking your pc is %100 clean. Many people see an improvement after just an Mbam scan and think their system is clean when in fact further work is needed.

Hi, finished scan and had 64 infections which were removed. they were all adwear from something called Zango and the other was My web search. rebooted and opened email and it still came up with the window which has red across the top and ATTENTIION entering sleep mode then reboots itself. I had already backed up entire pc onto an external hard drive so i can format if i need to. PC belongs to a friend and it has 3 partitions one of them contains a program called Acronis which seems to be a system recovery but when i accessed it through F11 none of the functions worked and said no hard disk drivers found. It also has an error coming up saying windows installer not installed correctly.
am thinking formatting is the best road, what do you recommend.

I need to see the log that Mbam produced.

Malwarebytes' Anti-Malware 1.38
Database version: 2297
Windows 5.1.2600 Service Pack 3

10/07/2009 8:08:11 AM
mbam-log-2009-07-10 (08-08-11).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 180679
Time elapsed: 1 hour(s), 5 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 31
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 23
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\coresrv.lfgax (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.lfgax.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\ (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zango (Adware.Zango) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
c:\documents and settings\All Users\Application Data\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.
c:\documents and settings\User\Application Data\Zango (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\IESkins (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0 (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOI (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOI\static (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOL (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOL\dynamic (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\HostOL\static (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango\dynamic (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango\static (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\Zango\v3.0\Zango\static\1 (Adware.Zango) -> Quarantined and deleted successfully.

Files Infected:
c:\program files\internet explorer\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
d:\my documents\Blakes\LimewireSetup.exe (Adware.Zango) -> Quarantined and deleted successfully.
d:\my documents\Blakes\LimewireSetup2.exe (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\ZangoSA\ZangoSA.dat (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\ZangoSA\ZangoSAAbout.mht (Adware.Zango) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\ZangoSA\ZangoSAEULA.mht (Adware.Zango) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.

hey matilda21
i don’t know much about Mbam but we use Norton at work after all other antivirus has failed to produce. I am now a Norton fan, however if you treat it well it works fine.
If you are up to reformatting your pc and have the ALL the cd’s that you might need that is definitely the way to go. No machine that hosted a hacker is EVER 100% save again. You go on and format and re-install ( one should do that in any way every 1 – 2 years for maximum reliability)
After the re-install you can use a fire-wall program like online armor, (remember to disconnect windows firewall) a program called spyware Blaster and also a program called spyware terminator and if you use it in combination with spybot search and destroy and a antivirus like Norton you should be fine fine fine!
I never have any problems and use above programs (they are all free except for Norton)
Hope it helps
barry

I have seen the logs from hundreds of infected pc's and I can tell you that Norton is complete rubbish.
The worst infected were those with no protection. A very close second goes to those with Norton on it.

I wouldn't recommend Norton to my worst enemy.

matilda21, it does indeed look like Mbam has been very successful but as a precaution, I would like you to download HJT from here - http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html and post a log from it for me to check over.

Thanks Rick and Barry for your help, am not sure what happened but pc suddenly crashed and i couldn't even get into safe mode. I formatted and did clean install of windows and its working great. I am however not sure what is the best protection to use as some think norton or symantec are great and others think they are no good.I read reviews and alot think Bit defender is ok, there are so many out there do any of them really do all they claim to do.

Norton is absolute rubbish, don't waste your money on it.
There is plenty of free software out there that will do a far far better job of protecting your pc with absolutely zero cost.

Phishing filter - http://www.mywot.com/ It's free and very good.
Antivirus - http://www.avast.com/eng/download-avast-home.html Avast is very good and is free.
Aintispyware - http://www.malwarebytes.org/mbam.php Probably the best antimalware software there is at the moment and free.
Firewall - There is plenty of information about free firewalls here.


The only reason that people say Norton is good is because they will believe all the hype of the adverts rather than evidence of it's uselessness.

Thanks for that information Rick will go ahead and download those programs.
thanks again for all you help.

No problem at all. At least someone on here appreciates my advice.

Dear Matilda and Rik
Rik it is not that I did not appreciate you advice, I am one of those people who look at any and all advice and make up my own mind, for years I didn’t like Norton ONLY because it made my machine slow , lately I find that it is not the case! I have never seen any Norton add in my life , I did not even know that they make adds. At work I have used AVG on all our workstations and bit defender on our servers, we got an 2 old viruses one called voiterai and the other one I cant remember its name , because AVG could not pick up the virus it infected about 50 of our pc’s unfortunately bit defender from day one gave us trouble with the installation and registration on our servers (it could be me that might have been to stupid to install it) eventually our main server got infected and bit defender (it is licensed, paid for) did not help me, i then proceeded to buy Norton as well because one of my colleagues at work had a old copy of Norton on his machine and it could detect and clean the 2 viruses(witch by this time infected 10000's of files) a 3 x license for Norton was about R450 ($60) so we bought 10 boxes ( 30 licenses) for a start , just to see.
Norton removed all the viruses, and could also scan other computers for viruses and removed them as well (it just took a little more man hours)
I do however feel that one should give each person a chance to discover for themselves what works and what they like, if not everyone would have been driving a Ford, and that is luckily not the case. I am quoting again from my previous mail as to what I have found to be of great help software wise on my home pc, to help prevent viruses (I have never had one in 25 years) maybe I am just lucky

After the re-install you can use a fire-wall program like online armor, (remember to disconnect windows firewall) a program called spyware Blaster and also a program called spyware terminator and if you use it in combination with spybot search and destroy and a antivirus like Norton you should be fine fine fine!

Hope it helps
Humbly replied
barry

Hi Barry and Rik, am not sure I should be having any more input here but I do feel the need to say that all advise given on this site is appreciated. Most people who are looking for help are probably like me and have very limited knowledge to the workings of computers and turn to Daniweb in the hope their problems can be fixed, the more unput from different people the better as it helps learners like me understand just that little bit more with each post.

Thanks guys ... PC is working beautifully now and well protected.
Matilda21... ...

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.