Computer Stops itself, Need to unplug then able to Start

Status
Not open for further replies.
Like I said get your hands on a multimeter, then test your PSU on it (there are plenty of guides that tell you how on Google and Bing)
 
I have changed CMOS battery, that led to default BIOS+ I have added another hard drive, COM1 USB port with audio cable.
It's performing well and not yet shut down.

Power Management shows:
ACPI Suspend Type :S3(STR)-Set suspend type to suspend to RAM under ACPI OS.

Note: I will wait and see the performance prior to changing PSU.

Please check HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:57:06 PM, on 31/12/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

--
End of file - 3567 bytes
 
Well lets us know, log looks excellent
It seems, at least changing CMOS battery CR2032 overcomes shutdown issues , but firefox windows crashed overnite , good point is that now I have event viewer to look as computer was working (ON).

I think it was rebooted probably but I can't say as I was sleeping after 2am.

I am focusing especially :

Event Type: Error
Event Source: crypt32
I have clicked to clear the Update Root Certificates check box in add/remove windows components.






Event Type: Information
Event Source: LoadPerf
Event Category: None
Event ID: 1000
Date: 01/07/2009
Time: 3:25:08 AM
User: N/A
Computer: ALEXANDRE
Description:
Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data contains the new index values assigned to this service.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.
Data:
0000: 0c 14 00 00 ....

------------------

Event Type: Information
Event Source: McLogEvent
Event Category: None
Event ID: 5000
Date: 01/07/2009
Time: 3:23:50 AM
User: NT AUTHORITY\SYSTEM
Computer: ALEXANDRE
Description:
McShield service started.
Engine version : 5301.4018
DAT version : 5656.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None


--------------------

Event Type: Information
Event Source: crypt32
Event Category: None
Event ID: 7
Date: 01/07/2009
Time: 3:23:34 AM
User: N/A
Computer: ALEXANDRE
Description:
Successful auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.


--------------

Event Type: Information
Event Source: SecurityCenter
Event Category: None
Event ID: 1800
Date: 01/07/2009
Time: 3:23:24 AM
User: N/A
Computer: ALEXANDRE
Description:
The Windows Security Center Service has started.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

---------------

-------------------
Event Type: Error
Event Source: crypt32

Event Category: None
Event ID: 11
Date: 01/01/2003
Time: 1:50:10 AM
User: N/A
Computer: ALEXANDRE
Description:
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.


For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

-------------
Event Type: Information
Event Source: crypt32
Event Category: None
Event ID: 2
Date: 01/01/2003
Time: 1:50:09 AM
User: N/A
Computer: ALEXANDRE
Description:
Successful auto update retrieval of third-party root list cab from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.


------------------
 
I left an online TV, since afternoon until this early morning so far, it didn't crushed/shut-down,.

But sometime it is still shutdowning earlier while my kids were playing some games via DVD, not seen how they/it itself shutdown, event logs showing several ( yellow ! )CDROM errors. Not sure shutdown caused due to this or earlier self shutdown problems when even we didn't use CDROM. I think these errors caused when they open CDROM without proper quit/exit commands.

Event Type: Warning
Event Source: Cdrom
Event Category: None
Event ID: 51
Date: 01/07/2009
Time: 7:32:55 PM
User: N/A
Computer: ALEXANDRE
Description:
An error was detected on device \Device\CdRom0 during a paging operation.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.
Data:
0000: 03 00 68 00 01 00 b8 00 ..h...¸.
0008: 00 00 00 00 33 00 04 80 ....3..€
0010: 2d 01 00 00 10 00 00 c0 -......À
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 90 5a 18 00 00 00 00 .￾Z.....
0028: 1b b6 58 00 00 00 00 00 .¶X.....
0030: ff ff ff ff 01 00 00 00 ÿÿÿÿ....
0038: 40 00 00 c4 02 00 00 00 @..Ä....
0040: 00 20 0a 12 48 02 00 40 . ..H..@
0048: 00 00 00 00 0a 00 00 00 ........
0050: 00 00 00 00 a0 c0 60 fa ....*À`ú
0058: 00 00 00 00 60 a4 a4 81 ....`¤¤￾
0060: 00 00 00 00 52 0b 03 00 ....R...
0068: 28 00 00 03 0b 52 00 00 (....R..
0070: 0e 00 00 00 00 00 00 00 ........
0078: 70 00 05 00 00 00 00 0a p.......
0080: 00 00 00 00 64 00 00 00 ....d...
0088: 00 00 00 00 00 00 00 00 ........
 
You have hardware issues somewhere ;)

As far as seen , all components are secured. We must concentrate problem was almost gone with longer time intervals until tonite its dropping with shorter intervals. I am going to put an online TV, tonite again and see if its working all night or not?
Otherwise I may do effort of replacing PSU.


This time I have run HJT in safe mode:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:30 PM, on 03/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

--
End of file - 3280 bytes

Earlier in the morning, a red marked event:

Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 03/07/2009
Time: 9:39:05 AM
User: ALEXANDRE\Jose Sanhueza
Computer: ALEXANDRE
Description:
DCOM got error "The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. " attempting to start the service McMSCSvc with arguments "" in order to run the server:
{398E2E68-BFDA-4834-B971-3CB8EC3C7219}

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
You have hardware issues somewhere ;)
Once again it worked amazingly all night after I left an online TV running. Last time, when I opened inside I have reset DDR to record its specs in my diary, though it was already intact. Everything looks secured.
I am ex SMT Quality Inspector.
 
Status
Not open for further replies.
Back
Top Bottom