1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: PC freezes sporatically

Discussion in 'Windows Vista' started by airforceone, Apr 9, 2010.

Thread Status:
Not open for further replies.
Advertisement
  1. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    I am running Vista Ultimate, SP2 on my 2.68 GHz/32 bit OS. It runs ok, but every 30-45 seconds or so, the hour glass goes through its freezing animation and the systems freezes for a couple of seconds. I have tried the Ctrl-Alt-Del to bring up the Task Manager but I cannot locate the culprit. I was wondering if someone out there may know if a short-cut to uncover the utility or utilities that are responsible for this.

    Thanks ahead for any and all suggestions.

    v/r
     
  2. joeten

    joeten

    Joined:
    Jan 15, 2009
    Messages:
    3,850
  3. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    Thanks joeten. Going through the process of elimination now.

    Appreciate the help!
     
  4. joeten

    joeten

    Joined:
    Jan 15, 2009
    Messages:
    3,850
    Hi your welcome hope it helps
     
  5. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    It took me a few days but that didn't solve the problem. I've come to find out that the problem lies in the winplayer.exe file. I ended up unchecking all the services ->msconfig->services->hide all microsoft services->unchecked all. Then I rebooted and left the computer on all night. Then I still noticed the computer periodically freezing. So I hit Ctrl-Alt-Del->start task mgr->Processes and noticed that the file dealing with winplayer would show up every minute or so. It made a sound like I was unplugging a "plug and play" item from the usb port.
     
  6. joeten

    joeten

    Joined:
    Jan 15, 2009
    Messages:
    3,850
    Hi can you set it to manual or disable it
     
  7. Phantom010

    Phantom010 Trusted Advisor

    Joined:
    Mar 9, 2009
    Messages:
    34,796
    Please click here to download and install version 2.0.2 of the HijackThis Installer.

    Run it (as Administrator) and select Do a system scan and save a logfile.

    The log will be saved in Notepad. Copy and paste the log in your next post.

    Do not fix anything
     
  8. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    Thanks
    On second notice I see the file is called wmplayer.exe (I think). It only stays visible for about 1/2 sec. Anyway - I see that it's a trojan or virus.

    Thanks for the link to hijackthis
    Here's the logfile:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:47:31 PM, on 4/16/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18904)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Gamevance Text - {BEAC7DC8-E106-4C6A-931E-5A42E7362883} - C:\Program Files\Gamevance\gvtl.dll
    O2 - BHO: Big Fish Games Toolbar - {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files\BfgBar\bfg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: Big Fish Games Toolbar - {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files\BfgBar\bfg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL2 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL2 (User 'Default user')
    O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
    O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)

    --
    End of file - 6166 bytes
     
  9. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    I forgot to mention that the problem has gotten worse over the past two days.
     
  10. Phantom010

    Phantom010 Trusted Advisor

    Joined:
    Mar 9, 2009
    Messages:
    34,796
    Could Windows DreamScene be the culprit?

    Try disabling it. Here's how.
     
  11. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    that didn't help. it appears to be some sort of virus.
     
  12. Phantom010

    Phantom010 Trusted Advisor

    Joined:
    Mar 9, 2009
    Messages:
    34,796
    What makes you think it's a virus?

    Is your computer freezing in Safe Mode?
     
  13. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    i googled it and some some on the replies came up that it was between possible and probable that - that is what the problem is. i'm running a norton scan on it now - so far it came up with one infection, but it's still running.

    i haven't tried safe mode yet. it freezes about every 15 seconds - momentarily.
     
  14. Phantom010

    Phantom010 Trusted Advisor

    Joined:
    Mar 9, 2009
    Messages:
    34,796
  15. airforceone

    airforceone Thread Starter

    Joined:
    Nov 21, 2003
    Messages:
    223
    Thanks Phantom01 -

    Trying Malwarebytes now
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/915906

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice