Plz Help me an error is occuring regularly

Status
Not open for further replies.

bhalchandra

Broken In
BCCode : 1000008e BCP1 : C0000005 BCP2 : 8057B722 BCP3 : B2274B64
BCP4 : 00000000 OSVer : 5_1_2600 SP : 1_0 Product : 256_1

Anybody know this error belongs to

my comp cofig is as follows

cpu amd athlon xp 3200+
mb asus A7N8X-E-Del
My OS is win XP 2003 version

It is happening regularly
please help me out of that
Any suggestion then please tell me
I am frustraited........
 
OP
B

bhalchandra

Broken In
Its happening for last whole week and also i had formatted may HDD and reinstalled windows for minimum 10 times
I thought that there is corruption in my OS cd so i changed that also but still it is same error
The computer suddenly get restarted and when it loads windows then it gave me above message
plz help me
 

Kl@w-24

Slideshow Bob
It doesn't seem to be a software related problem. When EXACTLY does this error message appear ?
 

lywyre

Cyborg Agent
Check that ur earthing is good enough. Some time bad power circuits also cause such problems.
 

medpal

Medic on Call!!
does it happen with bsod.

does it show any mesage after the system reboots i think your some of the hardware drivers are corrupted or some conflicts are there.

try and find hijackthis.exe (google it) and post the report file here.
 

wORm

Journeyman
If the computer just restarts by itself, it may also be a RAM problem. If you have two RAM modules installed, take one out and test your computer's stability. Have you been hearing beeps?
 
OP
B

bhalchandra

Broken In
sorry for delay
kl@w-24 : the error messege occuring generally when i try to play any game. But sometimes it happens when i try to access internet

So i did one thing yesterday i deassembled my system and thoroughly cleaned it.

medpal : yes that message i already displayed in my first topic

lywyre : No i already had a good 400 W vip power supply which is running fine

wORm: I dont think there is problem of RAM because when this problem occurs i tested both the RAMs in the service station located at Lamington Rd and they had undergone a testing of nearly two days and they told that they r working fine no probs at all

So is there any other possibility?
Do u know any site where i can ask my queries
please tell me
 
OP
B

bhalchandra

Broken In
As medpal said i downloaded hijackthis.exe and results are attached followed

Logfile of HijackThis v1.97.7
Scan saved at 1:30:47 PM, on 8/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svohost.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\System32\uiijhs.exe
C:\program files\180solutions\msbb.exe
C:\WINDOWS\gpypgr.exe
C:\WINDOWS\svchost.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Documents and Settings\Bhalchandra\My Documents\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = *searchcentral.cc/search.php?v=4&aff=2263
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = *searchcentral.cc/index.php?v=4&aff=2263
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = *searchcentral.cc/index.php?v=4&aff=2263
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F0 - system.ini: Shell=explorer.exe C:\WINDOWS\System32\svohost.exe
F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\System32\svohost.exe
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 81.211.105.69 lender-search.com
O1 - Hosts: 81.211.105.68 hot-searches.com
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem301.dll
O2 - BHO: (no name) - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [zmyrqztjh] C:\WINDOWS\System32\uiijhs.exe
O4 - HKLM\..\Run: [msbb] c:\program files\180solutions\msbb.exe
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
O4 - HKLM\..\Run: [gpypgr] C:\WINDOWS\gpypgr.exe
O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\swchost.exe
O4 - HKLM\..\Run: [NvClipRsv] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O4 - HKCU\..\Run: [iolo System Mechanic Utility Bar] C:\Program Files\iolo\System Mechanic 4\SMUtilityBar.exe
O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update13.js
O4 - Startup: svchost.exe
O4 - Global Startup: 24Online Client.lnk = C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: SATARaid.lnk = ?
O9 - Extra button: SideFind (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - *www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
O16 - DPF: {3E339D3C-4B12-4E8C-A529-9CC4BEEAFD4F} (VacPro.russia_ver3) - *www.advnt01.com/dialer/russia.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - *download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BAA8BCE2-021F-41A4-BB1B-00964B3F154B}: NameServer = 172.16.0.1,202.9.145.6,202.9.136.6

hope so it is useful
 

Kl@w-24

Slideshow Bob
Disable all startup items from msconfig (Click Start, Run and type msconfig). ur system is infected with spyware (xxx toolbar and a dialer). Get Spybot S&D and run a check. It will find and remove all spyware elements from ur system.
 

it_waaznt_me

Coming back to life ..
bhalchandra said:
C:\WINDOWS\System32\svohost.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\System32\uiijhs.exe
C:\program files\180solutions\msbb.exe
C:\WINDOWS\gpypgr.exe

Your system is messed with Spywares and Virus ..
How can you run a system without an Antivirus ??? I cant imagine it ..

First remove this junk from your computer. Scan your system with updated virus definitions:
Panda ActiveScan
Stinger
Symantec System Check

To proceed with your HijackThis log, Run HijackThis again and put a CheckMark next to these entries and Click on Fix Checked.
Please make sure that all Internet Explorer and Windows Explorer windows are closed.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = *searchcentral.cc/search.php?v=4&aff=2263
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = *searchcentral.cc/index.php?v=4&aff=2263
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = *searchcentral.cc/index.php?v=4&aff=2263
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F0 - system.ini: Shell=explorer.exe C:\WINDOWS\System32\svohost.exe
F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\System32\svohost.exe
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 81.211.105.69 lender-search.com
O1 - Hosts: 81.211.105.68 hot-searches.com
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem301.dll
O2 - BHO: (no name) - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe <-- Spyware .. Uninstall It
O4 - HKLM\..\Run: [zmyrqztjh] C:\WINDOWS\System32\uiijhs.exe
O4 - HKLM\..\Run: [msbb] c:\program files\180solutions\msbb.exe <-- Spyware .. Uninstall It
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe <-- Delete this file after Reboot
O4 - HKLM\..\Run: [gpypgr] C:\WINDOWS\gpypgr.exe <-- Delete this file after Reboot
O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\swchost.exe <-- Delete this file after Reboot
O4 - HKLM\..\Run: [NvClipRsv] C:\WINDOWS\svchost.exe
O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update13.js <-- Delete this file after Reboot
O4 - Startup: svchost.exe
O4 - Global Startup: 24Online Client.lnk = C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe <-- Spyware .. Uninstall It
O4 - Global Startup: SATARaid.lnk = ?
O9 - Extra button: SideFind (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - *www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
O16 - DPF: {3E339D3C-4B12-4E8C-A529-9CC4BEEAFD4F} (VacPro.russia_ver3) - *www.advnt01.com/dialer/russia.CAB

And then Please get yourself a decent Antivirus and an antispyware ..
 

it_waaznt_me

Coming back to life ..
I recommend using Spybot Search N Destroy and Spyware Blaster for keeping system free from spywares. Both should be updated regularily as new malwares are discovered frequently.

For Antivirus .. I myself use Kaspersky .. Though I got Norton licenced version but its a memory hog ..Still if you got good config then go for Norton ..or Try AVG ...
 

medpal

Medic on Call!!
bhalchandra you got your answer i think.

mcafee 8 prof is a good antivirus. but keep the definitions updated and also as to it
adaware se personal adition (www.lavasoft.de)
you can try avg (free antivirus and less memory consumption)

the message i was talking about was the system displays it after the restart or at the same time it displays your message. it usually contains the file name which is causing the probs.

i had the same prob and i got help of batty and got it solved it pointed to my onboard sound driver so loease look for that too it it happens again after the cleaning of system from spyware and virus.
 
Status
Not open for further replies.
Top Bottom