+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Junior Member
    Join Date
    Jan 2009
    Posts
    26

    Question Blue screen of death

    My son purchased a brand new pc about a month ago and in the second week it started blue screening. Its been back to the shop where we bought it but they reckon, after having it on the bench for a week, that thy couldn't get it to act up. We have reinstalled XP 3 times but to no avail. We think it might be the graphics card an ASUS Geforce GTX 285 - nVIDIA GeFOrce GTX285 but we can't be sure. Could someone analyse the attached Hijack This log as tell us whether it reveals anything, or are there any thoughts on this graphics card? THANKS.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:05:46, on 14/08/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
    C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\GIGABYTE\ET6\GUI.exe
    C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
    C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Mozilla Firefox\firefox.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [GEST] m‘|\ü
    O4 - HKLM\..\Run: [EasyTuneVI] C:\Program Files\GIGABYTE\ET6\ETcall.exe
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 5376 bytes

  2. #2
    Senior Member
    Join Date
    Aug 2006
    Posts
    408

    Default HJT Log auto parser

    When I run your log in the auto parser,

    HiJackThis! Log auto analyzer V2

    2 items stand out

    BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)File Missing


    HKLM\..\Run: [Alcmtr] ALCMTR.EXE

    researching alcmtr.exe in processlibrary.com, I see it is a Realtek monitoring function, which may be turned off if suspect. You could try disabling that and see if the BSOD comes back.

    Regarding the BHO - any Browser Helper Object with no identification us always suspect. I would go into IE and disable all the add-ons. Then bring them back one by one and see if you can get the BSOD to come back as a result of reinstating one of them.

    It really helps to get the complete error code when the BSOD shows up-you can disect it and it will provide clues as to what the cause is.

  3. #3
    Junior Member
    Join Date
    Jan 2009
    Posts
    26

    Default

    Thanks simrick. Touch wood it seems to be okay now after having a bios upgrade. I did investigate the stop error code which was suggestive of a driver problem. Have already removed suspect items thanks. He's back to University this week so fingers crossed. p.s he's doing a computing degree but I'm the one who has to sort out his PC when it goes tits up .. still haven't worked that one out.

    Cheers

  4. #4
    Senior Member
    Join Date
    Aug 2006
    Posts
    408

    Default

    Quote Originally Posted by Cinn View Post
    p.s he's doing a computing degree but I'm the one who has to sort out his PC when it goes tits up .. still haven't worked that one out.

    Cheers
    Oh!! ROFL!!!! I love it!

  5. #5

  6. #6
    Junior Member
    Join Date
    Jan 2009
    Posts
    26

    Default

    Thanks ailsa. As far as I know everything still cool after bios upgrade - perhaps the shop should have updated it in the first place. On the strength of all the aggro thought I'd build my own recently (had a couple of my own BSOD's - but hey, it happens) and installed windows 7. If you can get it cheap (I did as my son gets a student discount) I'd recommend it.

  7. #7
    Junior Member
    Join Date
    May 2010
    Posts
    9

    Default

    good info here thanks for posting

  8. #8
    but
    but is offline
    Junior Member
    Join Date
    Oct 2010
    Posts
    6

    Default

    hm... interesting...

Similar Threads

  1. blue screen of death
    By trualydixon in forum Windows XP Help
    Replies: 1
    Last Post: 07-08-2008, 11:17 PM
  2. M. DAY - Blue Screen
    By M. Day in forum Windows XP Help
    Replies: 1
    Last Post: 05-12-2007, 08:02 AM
  3. Blue screen
    By Elias.Banda@sccfo.org.zm in forum Windows XP Help
    Replies: 1
    Last Post: 15-02-2006, 11:25 AM
  4. Blue screen in XP
    By amy7234 in forum Windows XP Help
    Replies: 5
    Last Post: 13-11-2005, 06:17 PM
  5. Blue screen in XP
    By amy7234 in forum Chit Chat
    Replies: 0
    Last Post: 03-11-2005, 05:31 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts