Computer freezing-HJT log

Technical User
Mar 29, 2001
Hi, I'm running in safe mode because my xp pro won't boot up. It gets the the XP splash screen with the status bar then after about 15 seconds goes to a graying blank screen with only a mouse pointer. Sometimes the pointer moves and sometimes it freezes after movng it for a few seconds.

I was thinking I might have bad memory or a failing HD, but I've been running in safe mode for 2 days straight with no issues until a few minutes ago when I wrote this whole post out everything froze and I had to do another hard shut down. When it freezes I get a continuous noise out of the tower: a continuous beep that sounds like it is coming through the little speaker that gives you bios error codes.
If I can get to the end of writing this and post it, here is my HJT log for an expert to look at and advise if there are issues. At first I thought it might be a failing h ard drivfe or bad memory, but maybe it's the remains of 2 trojan viruses that I removed about 4 days ago in 2 seperate incidents. Used AVG to remove them. Here's my log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:44:50 AM, on 3/7/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {3C7195F6-D788-4D50-BA72-2EE212EDAC78} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {2C0A5F28-48D8-408B-9172-9C6121025BCE} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SPC1300] C:\WINDOWS\vspc1300.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - Trusted Zone: O15 - Trusted Zone: bar1.nxcore.net
O15 - Trusted Zone: bar2.nxcore.net
O15 - Trusted Zone: ameritrade01.streamer.com
O15 - Trusted Zone: ameritrade02.streamer.com
O15 - Trusted Zone: ameritrade03.streamer.com
O15 - Trusted Zone: ameritrade04.streamer.com
O15 - Trusted Zone: *.streamer.com
O15 - Trusted Zone: apis.tdameritrade.com
O15 - Trusted Zone: O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O15 - Trusted IP range:
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - O16 - DPF: {03A0F84E-3E69-4B3E-B4D3-019CB73B57B3} - O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (MSN Games – Matchmaking) - O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (MSN Games – Game Chat) - O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - O16 - DPF: {D6526FE0-E651-11CF-99CB-00C04FD64497} (Microsoft MSChat Control Object) - O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxdxCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe
O23 - Service: lxdx_device - - C:\WINDOWS\system32\lxdxcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe

End of file - 9533 bytes
This could have all been solved if you had a Mac. Not that many spyware infections as a PC has.

With the memory and hard drive test, your dell system has a diagnostic software that can be downloaded from Dell's support site or should be loaded on the drivers CD under diagnostic software.

The fastest way to clean an really infected the system or an embedded virus in your operating system is to backup your data and then reload the operating system with updates. Drivers can be downloaded from Dell's support site or on the CD given. Just be careful that the files that you are backing up are not infected. The way to check is to make sure that you have a clean system with an up to date antivirus and antimalware program. Connect your backup files to the clean system and it should find the malware or viruses that may still be with your backup files.

After you get the beep does anything get recorded in the Event Viewer in the System or Application folder?

Outlook Express can also be set to maintain a log file for troubleshooting purposes in Tools/ Options/ Maintenance/ Troubleshooting. Whether it includes internal problems I'm not too sure?

You could also try disabling any Anti Virus from checking E-mails and just rely on the realtime scanning to protect you as and when you open E-mails.

You could also look at downloading Windows Live Mail which is pretty much the same as OE6 or Windows Mail.

Hi Linney, there are no enties in event viewer that correspond to the beep in OE. There are some warnings in there: WinMgmt, event-5603, user-SYSTEM: Userenv, event-1517; WinMgmt event-63 but not sure what they mean. I just opened OE again and as soon as a new email downloaded into my inbox, there was that one short beep. No accompanying event log was recorded for this action.

I finished loading SP3 earlier and my browser windows seem much more stable without a 2 second delay with doing things, especially like I was getting on ebay pages. But Google is really fast with coming up and searching.

On another note, I'm a bit perplexed why I still have IE6 even though I updated to SP3..... I thought it would have updated my browser version to 7 or 8. (?)

I haven't installed antivirus yet but that's next, probably free AVG or up to suggestions.

I appeciate yours and everyone's responses
Are you sure it is a motherboard based beep and not OE - OE does beep when mail is received or deleted.


To Paraphrase:"The Help you get is proportional to the Help you give.."
It's coming through the mb speaker because I still haven't configured my sound card and I have no audio yet. I know the chime notification sound that you are referring to and it's not that. thanks.
I wonder whether "Turkbear" might be on to something with his last idea? Some programs will use the the motherboard speaker if no sound card is fitted or configured.

You could at least disable sound notifications in Outlook Express and see if that fixes the problem or install drivers for your sound card and set it up.
