Low resources???
Results 1 to 6 of 6

Thread: Low resources???

  1. #1
    Join Date
    Sep 2003
    Location
    Arlington, Texas
    Posts
    4

    Angry Low resources???

    I have a 3 yr old HP Pavilion with 128 mb of RAM running on Windows 2000, 10 gig hard drive with 38% free. Haven't had many problems, but lately nearly everything has gone wrong. I can click on files in Windows Explorer, the hourglass appears for a second then nothing happens, won't let me move or copy files, programs won't open, some open and give error messages and shut down, among other things. There is a memory checker installed on my computer which shows less than 45% free memory, which will start to drop very quickly. Any help will be greatly appreciated.

  2. #2
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391
    Some things to check out first.
    Do you have a up to date antivirus program. Run it.
    If not then I suggest
    HOUSECALL
    , a free online antivirus program.
    I always start with my antivirus checks.

  3. #3
    Join Date
    Sep 2003
    Location
    Arlington, Texas
    Posts
    4
    Thanks for the reply Train. I did run 'Spybot' on my computer last night and most of the problems were fixed. But now I can't get on the internet, as before I had all these other problems but could get on the internet (I am posting this message from my work computer). I have DSL and whenever I click on connect, I get an error message (Failed to creatre File...).

  4. #4
    Join Date
    Feb 2000
    Location
    Idaho Falls, Idaho, USA
    Posts
    18,428
    Sounds like you still have some remnants of viruses or spyware on your PC. You could download Hijack This and post the log file here. Check for viruses using Train's link also.

    http://www.tomcoyote.org/hjt/

  5. #5
    Join Date
    Sep 2003
    Location
    Arlington, Texas
    Posts
    4
    Logfile of HijackThis v1.96.4
    Scan saved at 9:28:21 PM, on 9/9/2003
    Platform: Windows 2000 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 (5.00.2920.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\msdtc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe
    C:\WINDOWS\system32\regsvc.exe
    C:\WINDOWS\System32\wins\DLLHOST.EXE
    C:\WINDOWS\system32\MSTask.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\WBEM\WinMgmt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\WINDOWS\System32\mqsvc.exe
    C:\WINDOWS\Explorer.exe
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    C:\Program Files\yhpager\yhpager.exe
    C:\WINDOWS\System32\wininetd.exe
    C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe
    C:\Program Files\MemoryMeter\MemoryMeter.exe
    C:\WINDOWS\TVTMD.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe
    C:\PROGRA~1\AIM95\aim.exe
    C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    C:\PROGRA~1\EFFICI~1\ENTERN~1\app\EnterNet.exe
    C:\PROGRA~1\Yahoo!\browser\YBrowser.exe
    C:\WINDOWS\System32\rsvp.exe
    C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPClient.exe
    C:\WINDOWS\System32\MDM.EXE
    C:\Documents and Settings\Sadaf Khalil\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcy/d...search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/sbcy/d.../www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/sbcy/d...o.sbc.com/dial
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/sbcy/d...o.sbc.com/dial
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcy/d...search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/sbcy/d...o.sbc.com/dial
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/sbcy/d.../www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.sbcglobal.prodigy.net
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;http://www.prodigy.ne;enroll.prodigy...l-isp.prodigy;<local>
    O1 - Hosts: 217.116.231.7 aimtoday.aol.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_1_5_0.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {213d24f0-f4b3-459d-9be7-f7e1e408edd9} - C:\DOCUME~1\SADAFK~1\APPLIC~1\xchnoutrpg.dll
    O2 - BHO: (no name) - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
    O2 - BHO: (no name) - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
    O3 - Toolbar: (no name) - {8A05273A-2EA5-42DE-AA75-59EA7D9D50D7} - (no file)
    O3 - Toolbar: maioucreeea - {3fb56ce3-b19d-4e36-86fa-ab6d270255f0} - C:\DOCUME~1\SADAFK~1\APPLIC~1\xchnoutrpg.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_1_5_0.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [iWon Messenger Pipe] C:\Program Files\iWon\Messenger\bin\i1IMPipe.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [yhpager lptt01] "C:\Program Files\yhpager\yhpager.exe"
    O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Yahoo! Monitor.lnk = C:\Program Files\Encompass\EncMontr.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: PTP Manager.lnk = C:\Program Files\PIXELA\PTP Manager\PixePtpManager.exe
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O8 - Extra context menu item: Power Search - res://C:\PROGRA~1\COMMON~1\MSIETS\msiets.dll//iemenu
    O9 - Extra button: Yahoo! Login (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O12 - Plugin for .ASP: C:\Program Files\SBIS\Communicator\Program\PLUGINS\nppdf32.dll
    O12 - Plugin for .ipp: C:\PROGRA~1\INTERN~1\Plugins\npimth32.dll
    O12 - Plugin for .ipt: C:\PROGRA~1\INTERN~1\Plugins\npimth32.dll
    O12 - Plugin for .pcm: C:\PROGRA~1\INTERN~1\PLUGINS\NpCurMem.dll
    O12 - Plugin for .ppt: C:\Program Files\SBIS\Communicator\Program\PLUGINS\npsurge.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .swf: C:\Program Files\SBIS\Communicator\Program\PLUGINS\NPSWF32.dll
    O16 - DPF: Dialpad Java Applet - http://www.dialpad.com/applet/src/vscp.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab
    O16 - DPF: {1B77F337-2C1E-4D52-88F7-AAEE5BFB6F5B} - http://www.netbroadcaster.com/player/MovieNetworks1.exe
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
    O16 - DPF: {9C813B33-52A2-466D-8C51-EB4189C1FF98} - http://image.imgfarm.com/images/noca...LV1.1.0.17.cab
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/installs/ymail/ymmapi.dll
    O16 - DPF: {AFDBB6D0-6B96-419C-8BC6-FF0B99368C0B} - http://www.memorymeter.com/MemoryMeter.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yaho...yiebio4024.cab
    O16 - DPF: {F17EDBC0-3EB2-11D3-AB74-00A0C5A512B9} - http://www.powertoolbar.com/install.exe
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = u5257.ecpm.com
    O17 - HKLM\System\CCS\Services\Tcpip\..\{AE4BF39C-600F-4847-8047-7C7F54FD678A}: Domain = u5257.ecpm.com
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E24A265B-771F-48DB-9741-911D6BEC52CD}: Domain = u5257.ecpm.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = u5257.ecpm.com
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = u5257.ecpm.com

  6. #6
    Join Date
    Jul 2002
    Posts
    38
    Continue to follow Train's advice re: antivirus, as it looks like you may have at least one Trojan running - C:\WINDOWS\System32\wininetd.exe. See here for some info on what it is and how to remove it. http://securityresponse.symantec.com...oor.winet.html

    Also, do you recall installing Personal Web Server on your computer? If not, C:\WINDOWS\System32\inetsrv\inetinfo.exe should be prevented from running.

    The easiest way to clean up some of this stuff is to grab a copy of Msconfig for WinXP and put it in the c:\winnt\system32 folder and then run it. (after doing the virus/trojan bit first )
    Last edited by joblo; September 10th, 2003 at 12:40 AM.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •