I keep getting "blue screen of death" when I make systematic changes on XP. need help

Discussion in 'Software' started by rickstermar555, Jan 10, 2011.

  1. rickstermar555

    rickstermar555 Private E-2

    I thought I fixed the problem when I removed a bad memory ram from this thread I made a couple of days ago.
    http://forums.majorgeeks.com/showthread.php?t=230659

    I ran MBAM, and SAS. No trojan founded in either scan. I have Avast and IObit Security 360 running at the same time along with ZoneAlarm which I installed about a month ago. I'm on Windows XP 32bit.

    I've tried making the systematic changes without ZoneAlarm running and the computer still gives me the BSOD.

    I get the BSOD when I do these things below:

    #1: I tried to disable a "process" called "IpodService.exe" "C:\Program Files\iPod\bin\iPodService.exe" in Control Panel--> Administrative Tools--> Services and I got the BSOD twice when I clicked "Apply".

    #2: Right click "My Computer" --> Properties --> Advanced --> Performance --> Settings --> Adjust for Best Performance ...I click "Apply" or "Ok" ...I get the BSOD. I tried this twice as well.

    Here's my HiJackThis log.
    ----------------------------------------------------------------------------------
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    I suggest you Right click "My Computer" --> Properties --> Advanced and go to the tab for start up and recovery and to reboot on errors and uncheck it. Then you will know what the error message is when you get a BSOD.

    There is nothing wrong with your HJT log.
     
  3. rickstermar555

    rickstermar555 Private E-2

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    I was able to change #1 and #2 in Safe Mode without getting the BSOD.

    Technial Info:

    0x0000008E (0xc0000005, 0xEB107d8C, 0xB58BAC18, 0x00000000)

    aswSP.sys - Address Eb107d8C base at Eb100000, datestamp 4d1e3650

    http://img210.imageshack.us/img210/4473/photo0369a.jpg

    Hopefully someone can describe to me what this means and how I can fix it...thanks
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    Do you have Avast installed?
     
  5. rickstermar555

    rickstermar555 Private E-2

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    yup installed and running.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    By chance do you have Comodo also installed?
     
  7. rickstermar555

    rickstermar555 Private E-2

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    Nope, I actually had Comodo installed and uninstalled when I installed ZoneAlarm.

    Could it be that some leftover files from Comodo are conflicting with Zonealarm?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    The error you are getting is for a driver file with Avast. My only suggestion is to uninstall Avast, run CCleaner and then download and install it again. Perhaps the driver somehow got corrupted.
     
  9. rickstermar555

    rickstermar555 Private E-2

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    Thanks...I'm gonna try that...I'll report back in a couple of hours.
     
  10. satrow

    satrow Major Geek Extraordinaire

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    If TimW's suggestion doesn't fix it, here's some more to read and try.

    The 0x8E BSOD with the first parameter of 0x05 indicates a memory access violation
    http://www.carrona.org/bsodindx.html#0x0000008E

    It looks like an Avast! driver - maybe the Hotspot Shield or the self-protection driver itself (aswSP.sys), is having problems, perhaps clashing with outdated drivers - the network card perhaps.

    Try to make sure your drivers are fully updated (not from Windows Update but the hardware makers themselves, if you can), if the drivers are all up to date, try disabling one Avast! module at a time.

    If you set your PC to save crash dumps as minidumps (right-click My Computer > Properties > Advanced > Startup and Recovery > Settings), you'll have a usable dump file to analyse any future BSOD's, with Bluescreenview you can then list all the loaded drivers in date order (and more), much easier to pick out the likely culprits.
     
  11. rickstermar555

    rickstermar555 Private E-2

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    Thanks TimW! Actually TimW's suggestion work great. I've uninstalled IOBit and Avast...ran CCleaner...now I'm able to make changes without getting the BSOD. I'm planning to run Avast with ZoneAlarm only now...hopefully it works well.

    I feel like I have a massive startup load...is there any processes that I can safely remove. In Task Manager I have 60 processes running, is this normal?

    Which processes can I safely remove?
     
  12. satrow

    satrow Major Geek Extraordinaire

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    60 processes is excessive, I prefer to see an XP machine running closer to 20 - 30 at boot up.

    Open CCleaner > Tools > Startup > Save list and upload the list so we can give you some ideas about which items don't need to be running constantly.
     
  13. rickstermar555

    rickstermar555 Private E-2

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    Wow 20-30 processes...that's a dramatic decrease...hopefully I can cut back on some these processes/programs.

    Here is the list. Thanks :)


    Yes HKCU:Run Google Update "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    Yes HKCU:Run Weather C:\Program Files\AWS\WeatherBug\Weather.exe 1
    Yes HKCU:Run Rainlendar2 C:\Program Files\Rainlendar2\Rainlendar2.exe
    No HKCU:Run wcescomm "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    No HKCU:Run TomTomHOMERunner "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
    Yes HKLM:Run ehTray C:\WINDOWS\ehome\ehtray.exe
    Yes HKLM:Run ftutil2 rundll32.exe ftutil2.dll,SetWriteCacheMode
    Yes HKLM:Run IAAnotif C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    Yes HKLM:Run DMAScheduler "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
    Yes HKLM:Run Recguard C:\WINDOWS\SMINST\RECGUARD.EXE
    Yes HKLM:Run PCDrProfiler
    Yes HKLM:Run HPBootOp "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    Yes HKLM:Run HP Software Update C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    Yes HKLM:Run LogitechCommunicationsManager "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    Yes HKLM:Run CanonMyPrinter C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    Yes HKLM:Run NPSStartup
    Yes HKLM:Run KBD C:\HP\KBD\KBD.EXE
    Yes HKLM:Run GrooveMonitor "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    Yes HKLM:Run IgfxTray C:\WINDOWS\system32\igfxtray.exe
    Yes HKLM:Run HotKeysCmds C:\WINDOWS\system32\hkcmd.exe
    Yes HKLM:Run Persistence C:\WINDOWS\system32\igfxpers.exe
    Yes HKLM:Run EPSON Stylus Photo RX620 Series C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB003" /M "Stylus Photo RX620"
    Yes HKLM:Run SunJavaUpdateSched "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    Yes HKLM:Run IMJPMIG8.1 "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    Yes HKLM:Run IMEKRMIG6.1 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    Yes HKLM:Run MSPY2002 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    Yes HKLM:Run PHIME2002ASync C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    Yes HKLM:Run PHIME2002A C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    Yes HKLM:Run DivXUpdate "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    Yes HKLM:Run TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    Yes HKLM:Run RTHDCPL RTHDCPL.EXE
    Yes HKLM:Run Alcmtr ALCMTR.EXE
    Yes HKLM:Run ZoneAlarm Client "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    Yes HKLM:Run Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    Yes HKLM:Run Adobe ARM "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    Yes HKLM:Run QuickTime Task "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    Yes HKLM:Run iTunesHelper "C:\Program Files\iTunes\iTunesHelper.exe"
    Yes HKLM:Run NvMediaCenter RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    Yes HKLM:Run NvCplDaemon RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    Yes HKLM:Run nwiz C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
    Yes HKLM:Run avast5 "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
    No HKLM:Run Quickcam "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    No HKLM:Run maxmenumgr "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
    Yes Startup Common Updates From HP.lnk C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    No Startup User OneNote 2007 Screen Clipper and Launcher.lnk C:\PROGRA~1\MICROS~4\Office12\ONENOTEM.EXE /tsr
     

    Attached Files:

  14. rickstermar555

    rickstermar555 Private E-2

  15. satrow

    satrow Major Geek Extraordinaire

    Re: I keep getting "blue screen of death" when I make systematic changes on XP. need

    Ok, so I'm a little more extreme than most Windows users about what runs at boot ;) it makes troubleshooting a lot easier though.

    I'm gonna suggest you investigate these Startups yourself, after all, you know your PC and how it works best for you.

    Use StartupCPL to actually enable/disable the processes, it has fewer potential knock-on effects than MSconfig, CCleaner, etc. Install it then start it from it's icon in Windows Control Panel.

    For the 'updaters' you disable, consider using SecuniaPSI weekly/fortnightly to ensure you have the most common programs + Windows securely patched.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds