ROBOSRUS Posted August 14, 2007 Share Posted August 14, 2007 DrWatson's Post Mortem DeBugger is constinly crashing on my computer. It has that usual error window you get after a program is not responding and you try to close it. After DrWatson's goes out, my taskbar, etc remain frozen. I can't open any new windows. I have to use task manager to turn off my computer. That's getting pretty annoying, so any help? It generally goes out when I get a huge lag [bleep]e. Below is a HJTL you may need. Any questions, please ask. Thanks for your help (I wanted to use my recovery CD I received with my computer, but I'll only use it if no other solutions are feasible.) Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 10:59:05 PM, on 8/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss[Caution: Executable File] C:\WINDOWS\system32\winlogon[Caution: Executable File] C:\WINDOWS\system32\services[Caution: Executable File] C:\WINDOWS\system32\lsass[Caution: Executable File] C:\WINDOWS\system32\Ati2evxx[Caution: Executable File] C:\WINDOWS\system32\svchost[Caution: Executable File] C:\Program Files\Windows Defender\MsMpEng[Caution: Executable File] C:\WINDOWS\System32\svchost[Caution: Executable File] C:\Program Files\Alwil Software\Avast4\aswUpdSv[Caution: Executable File] C:\Program Files\Alwil Software\Avast4\ashServ[Caution: Executable File] C:\WINDOWS\system32\Ati2evxx[Caution: Executable File] C:\WINDOWS\Explorer[Caution: Executable File] C:\WINDOWS\system32\spoolsv[Caution: Executable File] C:\PROGRA~1\Grisoft\AVG7\avgamsvr[Caution: Executable File] C:\PROGRA~1\Grisoft\AVG7\avgupsvc[Caution: Executable File] C:\PROGRA~1\Grisoft\AVG7\avgemc[Caution: Executable File] C:\Program Files\Digital Media Reader\shwiconem[Caution: Executable File] C:\Program Files\CyberLink\PowerDVD\PDVDServ[Caution: Executable File] C:\WINDOWS\SOUNDMAN[Caution: Executable File] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB[Caution: Executable File] C:\Program Files\Java\jre1.6.0_02\bin\jusched[Caution: Executable File] C:\Program Files\Lexmark 8300 Series\lxcjmon[Caution: Executable File] C:\Program Files\Lexmark 8300 Series\ezprint[Caution: Executable File] C:\Program Files\Common Files\Real\Update_OB\realsched[Caution: Executable File] C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter[Caution: Executable File] C:\Program Files\Google\Google Talk\googletalk[Caution: Executable File] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp[Caution: Executable File] C:\Program Files\Windows Defender\MSASCui[Caution: Executable File] C:\WINDOWS\system32\svchost[Caution: Executable File] C:\WINDOWS\system32\ctfmon[Caution: Executable File] C:\WINDOWS\system32\Tablet[Caution: Executable File] C:\Program Files\BigFix\BigFix[Caution: Executable File] C:\Program Files\Logitech\SetPoint\SetPoint[Caution: Executable File] C:\WINDOWS\system32\Wtablet\TabUserW[Caution: Executable File] C:\Program Files\Alwil Software\Avast4\ashMaiSv[Caution: Executable File] C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR[Caution: Executable File] C:\Program Files\Alwil Software\Avast4\ashWebSv[Caution: Executable File] C:\WINDOWS\system32\lxcjcoms[Caution: Executable File] C:\WINDOWS\System32\svchost[Caution: Executable File] C:\Program Files\Mozilla Firefox\firefox[Caution: Executable File] C:\Documents and Settings\Owner\Desktop\HiJack This[Caution: Executable File] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=6.1&bm=ho_home R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: TBSB08645 - {C30521FB-47CD-43D0-B3DB-14AFB2227F32} - C:\Program Files\SBR Toolbar\sbr.basic.dll (file missing) O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: SBR Toolbar - {BFB5F154-9212-46F3-B547-AC6106030A54} - C:\Program Files\SBR Toolbar\sbr.basic.dll (file missing) O4 - HKLM\..\Run: [sunKistEM] C:\Program Files\Digital Media Reader\shwiconem[Caution: Executable File] O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck[Caution: Executable File] O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx[Caution: Executable File] O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ[Caution: Executable File]" O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD[Caution: Executable File] O4 - HKLM\..\Run: [soundMan] SOUNDMAN[Caution: Executable File] O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB[Caution: Executable File] O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched[Caution: Executable File]" O4 - HKLM\..\Run: [LXCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [lxcjmon[Caution: Executable File]] "C:\Program Files\Lexmark 8300 Series\lxcjmon[Caution: Executable File]" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 8300 Series\ezprint[Caution: Executable File]" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched[Caution: Executable File]" -osboot O4 - HKLM\..\Run: [rcpd] C:\WINDOWS\system32\rcpd[Caution: Executable File] O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR[Caution: Executable File] O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk[Caution: Executable File] /autostart O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp[Caution: Executable File] O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui[Caution: Executable File]" -hide O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher[Caution: Executable File]" O4 - HKCU\..\Run: [ctfmon[Caution: Executable File]] C:\WINDOWS\system32\ctfmon[Caution: Executable File] O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk[Caution: Executable File]" /autostart O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw[Caution: Executable File] /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw[Caution: Executable File] /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw[Caution: Executable File] /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw[Caution: Executable File] /RUNONCE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader[Caution: Executable File] O4 - Global Startup: Adobe Gamma Loader.lnk = ? O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix[Caution: Executable File] O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint[Caution: Executable File] O4 - Global Startup: TabUserW[Caution: Executable File].lnk = C:\WINDOWS\system32\Wtablet\TabUserW[Caution: Executable File] O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL[Caution: Executable File]/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag[Caution: Executable File] (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag[Caution: Executable File] (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs[Caution: Executable File] O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs[Caution: Executable File] O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175701064984 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab O20 - Winlogon Notify: rcpd - rcpd.dll (file missing) O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc[Caution: Executable File] O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv[Caution: Executable File] O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx[Caution: Executable File] O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ[Caution: Executable File] O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv[Caution: Executable File] O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv[Caution: Executable File] O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr[Caution: Executable File] O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc[Caution: Executable File] O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc[Caution: Executable File] O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService[Caution: Executable File] O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT[Caution: Executable File] O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService[Caution: Executable File] O23 - Service: lxcj_device - - C:\WINDOWS\system32\lxcjcoms[Caution: Executable File] O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet[Caution: Executable File] -- End of file - 10880 bytes Thanks again Link to comment Share on other sites More sharing options...
Chris Posted August 14, 2007 Share Posted August 14, 2007 Yeah, that program has a bad habit of locking up itself. What happens is, it detects a crash, tries to debug. It then crashes itself and opens another instance of the program to debug that crash. Thus locking up the system in a loop so to speak. Whenever this happens to me in XP, I just go into the task manager and into processes find the process and cancel it. It usually returns the PC to working condition without a restart. As for the actual problem, sorry but I can't be arsed with HJT logs. PS. I think the name of the process is drwatson32. Google it if you're not sure though. :) Notoriously Trollish. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now