• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Too many processess running in the background

Twisted Logic

Weaksauce
Joined
Sep 9, 2004
Messages
65
I am running a laptop with Windows 2000 and I am having some problems with my RAM usage. I have optimized the OS already so I don't believe this to be the problem When I open the task manager I notice (after watching for a while) that multiples of processess start up one after the other, for example 5 or 6 net.exe's and cmd's will start up one after the other draining my ram. Is there anything that I can do to change this from happening by turning something off?

Thanks for your help
 
If you have already optimized the OS then it could likely be spyware and/or virus releated.
 
I have scanned with varous anti virus software as well as spy ware removal software and nothing is detected, any other ideas? Would really appreciate the help.

Ciao
 
Log as follows:
Logfile of HijackThis v1.98.2
Scan saved at 3:03:37 PM, on 11/12/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\wltrysvc.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
c:\winnt\system32\winstat\apc.exe
C:\Program Files\I8kfanGUI\I8kfanGUI.exe
c:\winnt\system32\winstat\wshield.exe
C:\Program Files\Gaim\gaim.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ALEXAN~1\LOCALS~1\Temp\Rar$EX02.189\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://luft.netfirms.com/luft/lan
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: C:\WINNT\lbbho.dll - {9E02D80E-4BC4-4550-BD90-84ADCC7378F5} - C:\WINNT\lbbho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SP2 data] c:\winnt\system32\winstat\repcale.exe c:\winnt\system32\winstat\apc.exe
O4 - HKLM\..\Run: [MSConfig] C:\Documents and Settings\Alexander Roth\My Documents\msconfig.exe /auto
O4 - HKLM\..\RunServices: [Start Upping] windupdts.exe
O4 - HKLM\..\RunServices: [dfe CTRLx Shift] et3rd.exe
O4 - HKLM\..\RunServices: [Control System] c:\winnt\system32\ghtbt\repcale.exe c:\winnt\system32\ghtbt\beird.exe
O4 - HKLM\..\RunServices: [Go And Start] f0v4r.exe
O4 - HKLM\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKLM\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe
O4 - HKCU\..\Run: [HomeAlarm] C:\Program Files\Chameleon Clock\ChamClock.exe
O4 - HKCU\..\Run: [i8kfangui] C:\Program Files\I8kfanGUI\I8kfanGUI.exe /startup
O4 - HKCU\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKCU\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab

Thanks
 
Remove the follwong

c:\winnt\system32\winstat\apc.exe
C:\WINNT\system32\Ati2evxx.exe (can be removed if you do not use the hotkey feutures.)
C:\WINNT\System32\bcmwltry.exe (if you do not use its feutures.
)
O2 - BHO: C:\WINNT\lbbho.dll - {9E02D80E-4BC4-4550-BD90-84ADCC7378F5} - C:\WINNT\lbbho.dll
O4 - HKLM\..\Run: [SP2 data] c:\winnt\system32\winstat\repcale.exe c:\winnt\system32\winstat\apc.exe
O4 - HKLM\..\RunServices: [Start Upping] windupdts.exe (I have no idea what this is but if you run into problems hijackthis makes backups)
O4 - HKLM\..\RunServices: [dfe CTRLx Shift] et3rd.exe
O4 - HKLM\..\RunServices: [Control System] c:\winnt\system32\ghtbt\repcale.exe c:\winnt\system32\ghtbt\beird.exe
O4 - HKLM\..\RunServices: [Go And Start] f0v4r.exe (don't know about this either but doesn't look good)
O4 - HKLM\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKLM\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe
O4 - HKCU\..\RunServices: [System Restore Data] c:\winnt\system32\frbyjed\repcale.exe c:\winnt\system32\frbyjed\beird.exe
O4 - HKCU\..\RunServices: [NBT System alias] c:\winnt\system32\bntrth\repcale.exe c:\winnt\system32\bntrth\beird.exe

It looks like you need to change your browsing habits as there are soemt hings on there tha are most likely causing the problem.
 
Back
Top