Click to See Complete Forum and Search --> : Low resources???
foundforce
September 8th, 2003, 05:51 PM
I have a 3 yr old HP Pavilion with 128 mb of RAM running on Windows 2000, 10 gig hard drive with 38% free. Haven't had many problems, but lately nearly everything has gone wrong. I can click on files in Windows Explorer, the hourglass appears for a second then nothing happens, won't let me move or copy files, programs won't open, some open and give error messages and shut down, among other things. There is a memory checker installed on my computer which shows less than 45% free memory, which will start to drop very quickly. Any help will be greatly appreciated.
Train
September 8th, 2003, 07:15 PM
Some things to check out first.
Do you have a up to date antivirus program. Run it.
If not then I suggest
HOUSECALL (http://housecall.antivirus.com/housecall/start_corp.asp), a free online antivirus program.
I always start with my antivirus checks.
foundforce
September 9th, 2003, 09:07 AM
Thanks for the reply Train. I did run 'Spybot' on my computer last night and most of the problems were fixed. But now I can't get on the internet, as before I had all these other problems but could get on the internet (I am posting this message from my work computer). I have DSL and whenever I click on connect, I get an error message (Failed to creatre File...).
jdc2000
September 9th, 2003, 01:47 PM
Sounds like you still have some remnants of viruses or spyware on your PC. You could download Hijack This and post the log file here. Check for viruses using Train's link also.
http://www.tomcoyote.org/hjt/
foundforce
September 9th, 2003, 10:27 PM
Logfile of HijackThis v1.96.4
Scan saved at 9:28:21 PM, on 9/9/2003
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\System32\wins\DLLHOST.EXE
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\yhpager\yhpager.exe
C:\WINDOWS\System32\wininetd.exe
C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe
C:\Program Files\MemoryMeter\MemoryMeter.exe
C:\WINDOWS\TVTMD.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe
C:\PROGRA~1\AIM95\aim.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\PROGRA~1\EFFICI~1\ENTERN~1\app\EnterNet.exe
C:\PROGRA~1\Yahoo!\browser\YBrowser.exe
C:\WINDOWS\System32\rsvp.exe
C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPClient.exe
C:\WINDOWS\System32\MDM.EXE
C:\Documents and Settings\Sadaf Khalil\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcy/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/sbcy/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/sbcy/defaults/*http://yahoo.sbc.com/dial
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/sbcy/defaults/*http://yahoo.sbc.com/dial
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcy/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/sbcy/defaults/*http://yahoo.sbc.com/dial
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/sbcy/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.sbcglobal.prodigy.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;www.prodigy.ne;enroll.prodigy.n;enroll-isp.prodigy;<local>
O1 - Hosts: 217.116.231.7 aimtoday.aol.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_1_5_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {213d24f0-f4b3-459d-9be7-f7e1e408edd9} - C:\DOCUME~1\SADAFK~1\APPLIC~1\xchnoutrpg.dll
O2 - BHO: (no name) - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: (no name) - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O3 - Toolbar: (no name) - {8A05273A-2EA5-42DE-AA75-59EA7D9D50D7} - (no file)
O3 - Toolbar: maioucreeea - {3fb56ce3-b19d-4e36-86fa-ab6d270255f0} - C:\DOCUME~1\SADAFK~1\APPLIC~1\xchnoutrpg.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_1_5_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [iWon Messenger Pipe] C:\Program Files\iWon\Messenger\bin\i1IMPipe.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [yhpager lptt01] "C:\Program Files\yhpager\yhpager.exe"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Yahoo! Monitor.lnk = C:\Program Files\Encompass\EncMontr.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PTP Manager.lnk = C:\Program Files\PIXELA\PTP Manager\PixePtpManager.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: Power Search - res://C:\PROGRA~1\COMMON~1\MSIETS\msiets.dll//iemenu
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .ASP: C:\Program Files\SBIS\Communicator\Program\PLUGINS\nppdf32.dll
O12 - Plugin for .ipp: C:\PROGRA~1\INTERN~1\Plugins\npimth32.dll
O12 - Plugin for .ipt: C:\PROGRA~1\INTERN~1\Plugins\npimth32.dll
O12 - Plugin for .pcm: C:\PROGRA~1\INTERN~1\PLUGINS\NpCurMem.dll
O12 - Plugin for .ppt: C:\Program Files\SBIS\Communicator\Program\PLUGINS\npsurge.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .swf: C:\Program Files\SBIS\Communicator\Program\PLUGINS\NPSWF32.dll
O16 - DPF: Dialpad Java Applet - http://www.dialpad.com/applet/src/vscp.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {1B77F337-2C1E-4D52-88F7-AAEE5BFB6F5B} - http://www.netbroadcaster.com/player/MovieNetworks1.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {9C813B33-52A2-466D-8C51-EB4189C1FF98} - http://image.imgfarm.com/images/nocache/aornumIWRLV1.1.0.17.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/installs/ymail/ymmapi.dll
O16 - DPF: {AFDBB6D0-6B96-419C-8BC6-FF0B99368C0B} - http://www.memorymeter.com/MemoryMeter.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio4024.cab
O16 - DPF: {F17EDBC0-3EB2-11D3-AB74-00A0C5A512B9} - http://www.powertoolbar.com/install.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = u5257.ecpm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE4BF39C-600F-4847-8047-7C7F54FD678A}: Domain = u5257.ecpm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E24A265B-771F-48DB-9741-911D6BEC52CD}: Domain = u5257.ecpm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = u5257.ecpm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = u5257.ecpm.com
joblo
September 10th, 2003, 12:33 AM
Continue to follow Train's advice re: antivirus, as it looks like you may have at least one Trojan running - C:\WINDOWS\System32\wininetd.exe. See here for some info on what it is and how to remove it. http://securityresponse.symantec.com/avcenter/venc/data/backdoor.winet.html
Also, do you recall installing Personal Web Server on your computer? If not, C:\WINDOWS\System32\inetsrv\inetinfo.exe should be prevented from running.
The easiest way to clean up some of this stuff is to grab a copy of Msconfig for WinXP and put it in the c:\winnt\system32 folder and then run it. (after doing the virus/trojan bit first ;) )