Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Out of Resources - Need to Reboot

Status
Not open for further replies.

Kjonnnn

IS-IT--Management
Jul 14, 2000
1,145
US
My boss' boss has a laptop with XP Pro loaded. Every 4 to 5 hours it seems to run out of resources and need to be rebooted. When this happens, he cannot save anything that he is working on (so of course he's frequently saving now).

I've checked the event viewer, checked for spyware using Adaware6, virus definitions are up to date, has all the current patches and SPs for XP. There are no "odd" programs running in his startup (that's not to say he doesnt have quite a few things starting up, you know how Execs are).

Can anyone point me to a possible cause of this issue?

 
What virus checker are you running?

Look in Task Manager - Processes tab - which process is making most demands?
 
Thanks. Running Symantec 8.1 Enterprise.

Here's the Hijack.

Logfile of HijackThis v1.97.7

Scan saved at 8:30:56 AM, on 7/9/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\System32\drivers\CDAC11BA.EXE

C:\WINDOWS\System32\CTsvcCDA.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Roxio\GoBack\GBPoll.exe

C:\PROGRA~1\Iomega\System32\AppServices.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\Program Files\Creative\ShareDLL\CtNotify.exe

C:\Program Files\Sony\Jog Dial Navigator\JogServ2.exe

C:\Program Files\Iomega\DriveIcons\ImgIcon.exe

C:\Program Files\Microsoft Hardware\Keyboard\type32.exe

C:\Program Files\Sony\HotKey Utility\HKserv.exe

C:\Program Files\Creative\ShareDLL\Mediadet.exe

C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE

C:\WINDOWS\System32\atiptaxx.exe

C:\Program Files\Iomega\AutoDisk\ADUserMon.exe

C:\WINDOWS\System32\ezSP_Px.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\PowerPDF\pwrpdfsrv.exe

C:\WINDOWS\System32\dnzwkzyu.exe

C:\Program Files\QuickTime\qttask.exe

C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

C:\WINDOWS\System32\svchost.exe

C:\windows\msbb.exe

C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe

C:\Program Files\AIM\aim.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Roxio\GoBack\GBTray.exe

C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe

C:\WINDOWS\System32\WFXSVC.EXE

C:\Program Files\Symantec\WinFax\WFXMOD32.EXE

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\System32\ZipToA.exe

C:\Program Files\Iomega\AutoDisk\ADService.exe

C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe

C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe

C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE

C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE

C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE

C:\Program Files\Internet Explorer\iexplore.exe

\Bdc\D\HiJackThis\HijackThis.exe



R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)

O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\2.bin\MYBAR.DLL

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar2.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll (file missing)

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar2.dll

O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\2.bin\MYBAR.DLL

O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [JOGSERV2.EXE] C:\Program Files\Sony\Jog Dial Navigator\JogServ2.exe

O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe

O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"

O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe

O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE

O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART

O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe

O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [pwrpdfprsrv.exe] C:\Program Files\PowerPDF\pwrpdfsrv.exe

O4 - HKLM\..\Run: [mlsulhag] C:\WINDOWS\System32\dnzwkzyu.exe

O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [wbgh] C:\WINDOWS\wbgh.exe

O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe

O4 - HKLM\..\Run: [msbb] c:\windows\msbb.exe

O4 - HKLM\..\Run: [enslcxmf] C:\WINDOWS\enslcxmf.exe

O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe

O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm

O8 - Extra context menu item: &Google Search - res://c:\windows\downloaded program files\GoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: Backward &Links - res://c:\windows\downloaded program files\GoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\downloaded program files\GoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Si&milar Pages - res://c:\windows\downloaded program files\GoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://c:\windows\downloaded program files\GoogleToolbar2.dll/cmtrans.html

O9 - Extra button: Yahoo! Login (HKLM)

O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)

O9 - Extra button: AOL Toolbar (HKLM)

O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)

O9 - Extra button: Research (HKLM)

O9 - Extra button: AIM (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople

O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} -
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
 
This entry is a bit worrying C:\WINDOWS\System32\dnzwkzyu.exe, this is not the first time I have seen files with seemingly random filenames. I can see no valid reason for having such a file name.

O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\2.bin\MYBAR.DLL
Relates to spyware and could be the cause of IE instances.

There are other such as those below that are a cause of concern.

O4 - HKLM\..\Run: [wbgh] C:\WINDOWS\wbgh.exe

O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe

Take a look at faq779-5240, You could do with BHOCop, Spybot and AdAware at least.

Running these should solve your problem

Greg Palmer
Free Software for Adminstrators
 
Few things bothering me.you did not mention wheather you have checked how much resource the system already taken.You also could increase the size on page file.I had almost similar problem with goback.I don't see any reason that you have to run goback since xp itself has system restore.You should check the startup files with msconfig.And disable all these non-system file.This step will release a lot of memory.Hope these and other advise solve your problem.
 
More info.

The above problem continues. But we're thinking maybe there's something wrong with the factory install of the software, or the harddrive. So, we purchase a new hard drive, REINSTALLED everything. The systems seem to "run" cleaner, but it still makes my boss shut down after 4 or 5 hours of use, like clockwork.

Now this system also had an issue with a pnpframework.exe error with shutting down.

After I reinstalled everything it run fine. But I did notice that pnpframework.exe error came back after I installed his Office 2003. Now this version of Office is the Full Version of Office with One Note he got through the mail. Microsoft just sent him a freebie ... (yea I know HUH?), go figure. Can the Office 2003 / pnpframework.exe error be connnected to the out of resources issue? Has any one heard of an issue with Office 2003 and Sony Vaios?
 
Why not advise your top boss to do their own restart every 2 or 3 hours? That way, no work gets lost and they can be doing some other task.

If restart doesn't do it, try shut-down and start after a couple of minutes.

Madawc Williams (East Anglia)
 
Yea but that really doesnt fix the problem ... with a new laptop.
 
Hi,
Not to ask the obvious, but is the battery getting charged properly?

[profile]
 
New Battery
But always used on cord power.
 
Kjonnnn, people like us might want to get to the bottom of the problem, but the typical boss just wants a tool that works for them.

Madawc Williams (East Anglia)
 
NO. He wants the problem fixed. We're doing the work-around of booting when necessary. But if there is a solution out there, I'd like to find it. I don't like "half way" doing my job.
 
Try the following:

Start > Control Panel > Admin Tools > Event Viewer > Right Click on Application and select Clear All Events > Repeat for System.

Now wait for the resource problem, check the Event Viewer logs for clues to the problem.

Pinning this sort of problem down can be hard, when you did the Hijack This log for me before it showed some problem applications. These must have been installed by your Boss, these are known problem applications. Often part of other software such as Icon/Pointer Sets, emoticons for AOL/Yahoo messenger, Weather software, Time and Date Managers etc..

If you get no joy with the Event Viewer try the Hijack This log again and we can show you what needs to go.

Greg Palmer
Free Software for Adminstrators
 
Thanks. I remember checking the event viewer, and it showed no indication of an error.

But you know VPs and "their" software. I want him to not use the Office 2003, because he didnt have a problem before he added it.

But thanks again, I'll try your popular solution.
 
kjonnnn said:
But you know VPs and "their" software

I know what you mean, they expect you to have a fully secure system with 100% uptime, but then flaut every security policy that you have in place.

Greg Palmer
Free Software for Adminstrators
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top