Nothing is written to the event viewer. The user thinks the problem started
after her computer was updated about a month ago. Only windows updates and
Adobe were updated. Adobe was updated to 9.1. I did a system restore back
to the 1st of Feb but she still gets the error. I've looked at msconfig to
see what is running at startup. I've looked in the "run" key in the registry
to see if anything seems out of place. Everything appears normal. I
uninstalled and reinstalled her anti-virus software. I ran a registry cleaner
on her computer. So far, nothing has changed.
When I first started looking into this, I ended up having to just push the
power button to shut down. I restarted three times, and could never recreate
the problem. I thought it must be something that builds up during the day,
however I have monitored her computer for a full day, checking every 30
minutes for any rundll's in the task list. Nothing. This only happens at
shutdown after running for a full day or so. She does shut down every night.
Sometimes she will have only three rundll32's in task manager when she shuts
down. I've seen as many as seven.
Last week I made her an admin on the machine so that I could get to a
command prompt from her profile to run this command - c:\WMIC
/OUTPUT:C:\ProcessList.txt PROCESS get Caption,Commandline,Processid. Here
are the results, keeping in mind that I could NOT get to a command promt
until I CLEARED the first rundll32.exe error, so I don't know what process
was the one actually hanging the machine. When I tried to open command
prompt or Task Manager, I would get a message stating that the machine was
shutting down. However, I was able to cancel that first message, then go to
c:\. Here is the result:
Caption CommandLine
ProcessId
System Idle Process
0
System
4
smss.exe \SystemRoot\System32\smss.exe
472
csrss.exe C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On
SubSystemType=Windows ServerDll=basesrv,1
ServerDll=winsrv:UserServerDllInitialization,3
ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off
MaxRequestThreads=16
520
winlogon.exe winlogon.exe
544
services.exe C:\WINDOWS\system32\services.exe
588
lsass.exe C:\WINDOWS\system32\lsass.exe
600
svchost.exe C:\WINDOWS\system32\svchost -k DcomLaunch
772
svchost.exe C:\WINDOWS\system32\svchost -k rpcss
840
MsMpEng.exe "C:\Program Files\Windows Defender\MsMpEng.exe"
908
svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs
948
SavService.exe "C:\Program Files\Sophos\Sophos
Anti-Virus\SavService.exe"
1008
svchost.exe C:\WINDOWS\system32\svchost.exe -k NetworkService
1288
svchost.exe C:\WINDOWS\system32\svchost.exe -k LocalService
1332
spoolsv.exe C:\WINDOWS\system32\spoolsv.exe
1468
mainserv.exe "C:\Program Files\APC\APC PowerChute Personal
Edition\mainserv.exe"
1616
Iap.exe "C:\Program Files\Dell\OpenManage\Client\Iap.exe"
1748
mdm.exe "C:\Program Files\Common Files\Microsoft
Shared\VS7DEBUG\MDM.EXE"
1764
locator.exe C:\WINDOWS\system32\locator.exe
1876
SAVAdminService.exe "C:\Program Files\Sophos\Sophos
Anti-Virus\SAVAdminService.exe"
1912
ManagementAgentNT.exe "C:\Program Files\Sophos\Remote Management
System\ManagementAgentNT.exe" -service -name Agent
1944
ALsvc.exe "C:\Program Files\Sophos\AutoUpdate\ALsvc.exe"
136
RouterNT.exe "C:\Program Files\Sophos\Remote Management
System\RouterNT.exe" -service -name Router -ORBListenEndpoints
iiop://:8193/ssl_port=8194
160
searchindexer.exe C:\WINDOWS\system32\SearchIndexer.exe /Embedding
248
alg.exe C:\WINDOWS\System32\alg.exe
1648
explorer.exe C:\WINDOWS\Explorer.EXE
2336
ctfmon.exe "C:\WINDOWS\system32\ctfmon.exe"
2988
wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
1624
rundll32.exe rundll32.exe
C:\WINDOWS\system32\inetcpl.cpl,ClearMyTracksByProcess 1 26 211
880
rundll32.exe rundll32.exe
C:\WINDOWS\system32\inetcpl.cpl,ClearMyTracksByProcess 8 26 211
1600
searchprotocolhost.exe "C:\WINDOWS\system32\SearchProtocolHost.exe"
Global\UsGthrFltPipeMssGthrPipe94_ Global\UsGthrCtrlFltPipeMssGthrPipe94 1
-2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible;
MSIE 6.0; Windows NT; MS Search 4.0 Robot) " "C:\Documents and Settings\All
Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc"
"DownLevelDaemon" 2348
searchfilterhost.exe "C:\WINDOWS\system32\SearchFilterHost.exe" 0 588 592
600 65536 596
3860
cmd.exe "C:\WINDOWS\system32\cmd.exe"
2360
notepad.exe "C:\WINDOWS\system32\NOTEPAD.EXE"
\\sms\cdimages\Darla\see what processes are running and their command-line
parameters.txt
868
wmic.exe WMIC /OUTPUT:C:\ProcessList.txt PROCESS get
Caption,Commandline,Processid
2812
wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
2492
I looked up the "clearmytracksbyprocess" and see that is to erase cookies,
history, etc., so that seems ok. I did go in and set her "clear history" in
IE7 to 0. I can click OK or end process on these errors, though, and get
past them. It is that first one that completely hangs the computer. Is
there any kind of script or batch file I could put on the machine to log what
is happening at shutdown? Otherwise I'm at a loss as to how to find this.
We do use spam assassin, windows defender, and sophos antivirus. I have not
run a spyware program on there, but I can do that if you think it might help.