PDA

View Full Version : Too many processess running in the background


Twisted Logic
11-12-2004, 02:18 PM
I am running a laptop with Windows 2000 and I am having some problems with my RAM usage. I have optimized the OS already so I don't believe this to be the problem When I open the task manager I notice (after watching for a while) that multiples of processess start up one after the other, for example 5 or 6 net.exe's and cmd's will start up one after the other draining my ram. Is there anything that I can do to change this from happening by turning something off?

Thanks for your help

KoolDrew
11-12-2004, 02:28 PM
If you have already optimized the OS then it could likely be spyware and/or virus releated.

Twisted Logic
11-12-2004, 03:37 PM
I have scanned with varous anti virus software as well as spy ware removal software and nothing is detected, any other ideas? Would really appreciate the help.

Ciao

KoolDrew
11-12-2004, 03:42 PM
It may not be detected by the programs you are scanning with so run hijackthis and post the log.

This thread should help too:
http://www.hardforum.com/showthread.php?t=768776

Twisted Logic
11-12-2004, 04:05 PM
Log as follows:
Logfile of HijackThis v1.98.2
Scan saved at 3:03:37 PM, on 11/12/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\wltrysvc.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
c:\winnt\system32\winstat\apc.exe
C:\Program Files\I8kfanGUI\I8kfanGUI.exe
c:\winnt\system32\winstat\wshield.exe
C:\Program Files\Gaim\gaim.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ALEXAN~1\LOCALS~1\Temp\Rar$EX02.189\HijackThis.e xe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://luft.netfirms.com/luft/lan
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: C:\WINNT\lbbho.dll - {9E02D80E-4BC4-4550-BD90-84ADCC7378F5} - C:\WINNT\lbbho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SP2 data] c:\winnt\system32\winstat\repcale.exe c:\winnt\system32\winstat\apc.exe
O4 - HKLM\..\Run: [MSConfig] C:\Documents and Settings\Alexander Roth\My Documents\msconfig.exe /auto
O4 - HKLM\..\RunServices: [Start Upping] windupdts.exe
O4 - HKLM\..\RunServices: [dfe CTRLx Shift] et3rd.exe
O4 - HKLM\..\RunServices: [Control System] c:\winnt\system32\ghtbt\repcale.exe c:\winnt\system32\ghtbt\beird.exe
O4 - HKLM\..\RunServices: [Go And Start] f0v4r.exe
O4 - HKLM\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKLM\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe
O4 - HKCU\..\Run: [HomeAlarm] C:\Program Files\Chameleon Clock\ChamClock.exe
O4 - HKCU\..\Run: [i8kfangui] C:\Program Files\I8kfanGUI\I8kfanGUI.exe /startup
O4 - HKCU\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKCU\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab

Thanks

KoolDrew
11-12-2004, 05:08 PM
Remove the follwong


c:\winnt\system32\winstat\apc.exe
C:\WINNT\system32\Ati2evxx.exe (can be removed if you do not use the hotkey feutures.)
C:\WINNT\System32\bcmwltry.exe (if you do not use its feutures.
)
O2 - BHO: C:\WINNT\lbbho.dll - {9E02D80E-4BC4-4550-BD90-84ADCC7378F5} - C:\WINNT\lbbho.dll
O4 - HKLM\..\Run: [SP2 data] c:\winnt\system32\winstat\repcale.exe c:\winnt\system32\winstat\apc.exe
O4 - HKLM\..\RunServices: [Start Upping] windupdts.exe (I have no idea what this is but if you run into problems hijackthis makes backups)
O4 - HKLM\..\RunServices: [dfe CTRLx Shift] et3rd.exe
O4 - HKLM\..\RunServices: [Control System] c:\winnt\system32\ghtbt\repcale.exe c:\winnt\system32\ghtbt\beird.exe
O4 - HKLM\..\RunServices: [Go And Start] f0v4r.exe (don't know about this either but doesn't look good)
O4 - HKLM\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKLM\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe
O4 - HKCU\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKCU\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe

It looks like you need to change your browsing habits as there are soemt hings on there tha are most likely causing the problem.

Twisted Logic
11-12-2004, 06:54 PM
Thanks for the help. Muchlty appreciated.