Forum Home
Press F1
 
Thread ID: 66351 2006-02-19 20:53:00 pc crashes, broadband goes slow, then dumps physical memory.... fent (9751) Press F1
Post ID Timestamp Content User
432285 2006-02-19 20:53:00 Hi,

Occasionally when just Im on the net, although mostly when im playing Battlefiel2 2 (on-line), my pc ****s down and goes to a blue screen where it begins dumping physical memory...This is realy annoying me and I havent a clue what to do to remedy it!

on the blue screen, the message reads: IRQL_NOT_LESS_OR_EQUAL


what does this mean and can i fix my pc? :yuck:
fent (9751)
432286 2006-02-19 20:56:00 Does the blue screen show the name of a driver at all??

What else does the BSOD say besides IRQL_NOT_LESS_OR_EQUAL ?
Speedy Gonzales (78)
432287 2006-02-19 21:31:00 i dont think it says anything about any drivers.

It only says if this has not happened before then restart, othrwise run a diagnostic application, espacially a memory test.

Ive got memtest, but im not too sure what to look for when i run it. And if i do have an error what happens? Is that a waste of the £40 it cost to buy a 512 stick?
fent (9751)
432288 2006-02-19 21:45:00 I think with memtest its meant to run overnight. Just as long as it doesnt bring up any errors, the ram is fine.

If the ram is faulty, and under warranty take it back.

Whats the videocard? Nvidia or ATI based? And what version of the drivers are installed for it?

I would open the case, and make sure the cards you have are in properly as well. (With the system off).

What u could also do, is get hijackthis (www.merijn.org) from here (www.spywareinfo.com)

Unzip this file first, and run it then click on scan and save a log.

Copy and paste the log here. There maybe other reasons why the broadband speed is slow / the PC crashes - ie: Viruses/worms/trojans.
Speedy Gonzales (78)
432289 2006-02-20 03:07:00 Hey,

Ive got the latest versions of the drivers for my NVidia 6600GT OC

Heres a copy of the stuff it came up with

ogfile of HijackThis v1.99.1
Scan saved at 03:05:09, on 20/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\BROADB~1\SMARTB~1\BTHelpNotifier.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\htpatch.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program Files\Broadband Desktop Help\bin\mpbtn.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\PROGRA~1\Yahoo!\BROWSER\YCOMMON.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\WINDOWS\system32\msiexec.exe
fent (9751)
432290 2006-02-20 06:38:00 Are you running a hyperthreading CPU, since this entry

C:\WINDOWS\htpatch . exe

Is for SIS mobos running HT CPU's .

Also, SIS-based mobos do lag a bit .

The other PC here is SIS-based and can be slow as hell . Even with 1 GB . Just opening programs, there's a bit of a delay in opening programs, on the hdd .

Is that all of the log? You've got nothing running when u boot up the system??
Speedy Gonzales (78)
432291 2006-02-23 15:16:00 Are you running a hyperthreading CPU, since this entry

C:\WINDOWS\htpatch . exe

Is for SIS mobos running HT CPU's .

Also, SIS-based mobos do lag a bit .

The other PC here is SIS-based and can be slow as hell . Even with 1 GB . Just opening programs, there's a bit of a delay in opening programs, on the hdd .

Is that all of the log? You've got nothing running when u boot up the system??


Hey, sorry it took so long for me to get back to you .

I havent got a clue what a hyperthreading pc is, so cant answer the question!

I ran hijackthis straight from startup, and have pasted the entire log below . Ive also started to pkay pro evo 5, which runs fine . But when i play black and white 2, it encounters a random crash at a random point in the game and closes down . I have all the updates etc, and am way way over the reccomended requirements . It just says windows has encountered a prob and will need to shut the programme down . I only mention it as I think this may be linked to the other crashes my pc has been having .

You got any ideas, going from the stuff below, what i should do? Ive updated my drivers etc and i cant think of anything else to do!

Thanks!



Logfile of HijackThis v1 . 99 . 1
Scan saved at 15:10:24, on 23/02/2006
Platform: Windows XP SP2 (WinNT 5 . 01 . 2600)
MSIE: Internet Explorer v6 . 00 SP2 (6 . 00 . 2900 . 2180)

Running processes:
C:\WINDOWS\System32\smss . exe
C:\WINDOWS\system32\winlogon . exe
C:\WINDOWS\system32\services . exe
C:\WINDOWS\system32\lsass . exe
C:\WINDOWS\system32\svchost . exe
C:\WINDOWS\System32\svchost . exe
C:\WINDOWS\system32\spoolsv . exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1 . EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st . exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys . exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32 . EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32 . EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32 . exe
C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst . exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32 . EXE
C:\WINDOWS\system32\nvsvc32 . exe
C:\Program Files\F-Secure Internet Security\Common\FCH32 . EXE
C:\Program Files\F-Secure Internet Security\Common\FAMEH32 . EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh . exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw . exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd . exe
C:\WINDOWS\Explorer . EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag . exe
C:\PROGRA~1\BROADB~1\SMARTB~1\BTHelpNotifier . exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 . exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32 . exe
C:\Program Files\F-Secure Internet Security\Common\FSM32 . EXE
C:\Program Files\Common Files\Real\Update_OB\realsched . exe
C:\WINDOWS\system32\RunDll32 . exe
C:\WINDOWS\htpatch . exe
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw . exe
C:\Program Files\Java\jre1 . 5 . 0_03\bin\jusched . exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll . exe
C:\WINDOWS\system32\RUNDLL32 . EXE
C:\Program Files\Messenger\msmsgs . exe
C:\Program Files\MSN Messenger\MsnMsgr . Exe
C:\Program Files\Adobe\Acrobat 7 . 0\Reader\reader_sl . exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex . exe
C:\Program Files\Broadband Desktop Help\bin\mpbtn . exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08 . exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08 . exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog . exe
C:\WINDOWS\system32\wuauclt . exe
C:\PROGRA~1\ Yahoo! \BROWSER\YCOMMON . EXE
C:\Program Files\ Yahoo! \browser\ybrwicon . exe
C:\Program Files\Internet Explorer\IEXPLORE . EXE
C:\Program Files\WinRAR\WinRAR . exe
C:\DOCUME~1\GREIG~1 . JOH\LOCALS~1\Temp\Rar$EX00 . 094 \HijackThis . exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = . red . clientapps . yahoo . com/customize/btyahoo/defaults/sp/*http://uk . search . yahoo . com/" target="_blank">uk . red . clientapps . yahoo . com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bt . yahoo . com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = . red . clientapps . yahoo . com/customize/btyahoo/defaults/sb/*http://uk . docs . yahoo . com/info/bt_side . html" target="_blank">uk . red . clientapps . yahoo . com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = . red . clientapps . yahoo . com/customize/btyahoo/defaults/su/*http://uk . search . yahoo . com/" target="_blank">uk . red . clientapps . yahoo . com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Yahoo! Broadband
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\ Yahoo! \Companion\Installs\cpn0\ycomp5_3_17_0 . dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7 . 0\ActiveX\AcroIEHelper . dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper . dll
O3 - Toolbar: BT Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\ Yahoo! \Companion\Installs\cpn0\ycomp5_3_17_0 . dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm . ocx
O4 - HKLM\ . . \Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag . exe" /icon
O4 - HKLM\ . . \Run: [Motive SmartBridge] C:\PROGRA~1\BROADB~1\SMARTB~1\BTHelpNotifier . exe
O4 - HKLM\ . . \Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2 . exe
O4 - HKLM\ . . \Run: [NvCplDaemon] RUNDLL32 . EXE C:\WINDOWS\system32\NvCpl . dll,NvStartup
O4 - HKLM\ . . \Run: [nwiz] nwiz . exe /install
O4 - HKLM\ . . \Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32 . EXE" /splash
O4 - HKLM\ . . \Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil . exe" /CHECKALL /WAITFORSW
O4 - HKLM\ . . \Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW . EXE" /reboot
O4 - HKLM\ . . \Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched . exe" -osboot
O4 - HKLM\ . . \Run: [Cmaudio] RunDll32 cmicnfg . cpl,CMICtrlWnd
O4 - HKLM\ . . \Run: [HTpatch] C:\WINDOWS\htpatch . exe
O4 - HKLM\ . . \Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg . exe
O4 - HKLM\ . . \Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1 . 5 . 0_03\bin\jusched . exe
O4 - HKLM\ . . \Run: [NvMediaCenter] RUNDLL32 . EXE C:\WINDOWS\system32\NvMcTray . dll,NvTaskbarInit
O4 - HKCU\ . . \Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs . exe" /background
O4 - HKCU\ . . \Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr . Exe" /background
O4 - HKCU\ . . \Run: [ Yahoo! Pager] "C:\Program Files\ Yahoo! \Messenger\ypager . exe" -quiet
O4 - Global Startup: Adobe Reader Speed Launch . lnk = C:\Program Files\Adobe\Acrobat 7 . 0\Reader\reader_sl . exe
O4 - Global Startup: Broadband Desktop Help . lnk = C:\Program Files\Broadband Desktop Help\bin\matcli . exe
O4 - Global Startup: F-Secure Anti-Virus 2006 . lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex . exe
O4 - Global Startup: HP Digital Imaging Monitor . lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08 . exe
O4 - Global Startup: Microsoft Office . lnk = E:\Microsoft Office\Office10\OSA . EXE
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups . htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office10\EXCEL . EXE/3000
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield . dll
O9 - Extra 'Tools' menuitem: IE Shield . . . - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield . dll
O9 - Extra button: BT Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\ Yahoo! \BROWSER\ysidebarIE . dll
O9 - Extra 'Tools' menuitem: BT & Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\ Yahoo! \BROWSER\ysidebarIE . dll
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker . exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\ Yahoo! \MESSEN~1\ypager . exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\ Yahoo! \MESSEN~1\ypager . exe
O9 - Extra button: Homepage - {0282D75A-6F56-412C-826B-2AE0AED76EB0} - http://bt . yahoo . com (file missing) (HKCU)
O9 - Extra button: BT - {CFD9707C-F18A-4B3F-A879-69D6A8DE4E30} - http://www . bt . com (file missing) (HKCU)
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\ Yahoo! \common\yucconfig . dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\ Yahoo! \common\yinsthelper . dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - . microsoft . com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site . cab?1138913581046" target="_blank">update . microsoft . com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - . microsoft . com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site . cab?1138895558998" target="_blank">update . microsoft . com
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - . msn . com/download/MsnMessengerSetupDownloader . cab" target="_blank">messenger . msn . com
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - . ladbrokes . com/instant-play-en/FlashAX . cab" target="_blank">flashcasino . ladbrokes . com
O17 - HKLM\System\CCS\Services\Tcpip\ . . \{12DED5F4-152C-4B74-B2E5-FDDD4AB35B66}: NameServer = 194 . 72 . 0 . 98 194 . 72 . 9 . 38
O17 - HKLM\System\CS1\Services\Tcpip\ . . \{12DED5F4-152C-4B74-B2E5-FDDD4AB35B66}: NameServer = 194 . 72 . 0 . 98 194 . 72 . 9 . 38
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp . dll" (file missing)
O23 - Service: F-Secure Anti-Virus 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1 . EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st . exe
O23 - Service: fsbwsys - F-Secure Corp . - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys . exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd . exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32 . EXE
O23 - Service: M-Audio CMIDI Installer (MA_CMIDI_InstallerService) - Unknown owner - C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst . exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32 . exe
O23 - Service: YPCService - Yahoo! Inc . - C:\WINDOWS\system32\YPCSER~1 . EXE
fent (9751)
432292 2006-02-23 20:14:00 AS far as the IRQL_NOT_LESS_OR_EQUAL message, without the rest of the error its a bit hit and miss as far as the meaning.
You could however look through this page (aumha.org) and see if any resemble what you are getting
NOTE: use the 'find on this page' (Control F in Firefox) function in your browser and enter the error
Myth (110)
432293 2006-02-23 22:06:00 Hmm you can run hijackthis again, and tick these entries and tick fix checked .

These entries arent nasty, but theyre not needed, to run on startup .

O4 - HKLM\ . . \Run: [nwiz] nwiz . exe /install

O4 - HKLM\ . . \Run: [HTpatch] C:\WINDOWS\htpatch . exe - This can slow things down, if you've got a 533 mhz system, and running a 3 . 0 GHZ CPU .


O4 - HKCU\ . . \Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs . exe" /background

O4 - HKLM\ . . \Run: [Cmaudio] RunDll32 cmicnfg . cpl,CMICtrlWnd

O4 - HKCU\ . . \Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr . Exe" /background

O4 - HKCU\ . . \Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager . exe" -quiet

O9 - Extra button: Homepage - {0282D75A-6F56-412C-826B-2AE0AED76EB0} - http://bt . yahoo . com (file missing) (HKCU)

O9 - Extra button: BT - {CFD9707C-F18A-4B3F-A879-69D6A8DE4E30} - http://www . bt . com (file missing) (HKCU)

The entries below, look like they can cause probs .

O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker . exe

O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - . ladbrokes . com/i . . . -en/FlashAX . cab" target="_blank">flashcasino . ladbrokes . com
Speedy Gonzales (78)
432294 2006-02-23 22:38:00 I would also (if u can) post a screenshot of whats in your add/remove programs here (www.imagef1.net.nz)

Thats if you've got some kind of graphics program installed, so you can take a snapshot (Press prt screen on the keyboard after you go to add/remove programs), and paste it into the graphics program, and upload it to the above site.

There maybe some adware thats installed, which will have to be uninstalled.

Which maybe causing probs.
Speedy Gonzales (78)
1