Help - Search - Members - Calendar
Full Version: extremely low system resources
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
dochappy
I used to be able to run photoshop winmedia player and surf the web at the same time without runnign low on resources but for some reason lately I can barely surf the web and use photoshop at the same time.

any help will greatly be appreciated.

QUOTE
Logfile of HijackThis v1.97.7
Scan saved at 2:46:50 PM, on 4/13/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\TWAIN_32\A6U16K\WATCH.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\CALLWAVE\IAM.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\DESKTOP\DOWNLOADS\SYSTEM TOOLS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://security.kolla.de/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://security.kolla.de/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [Digital Dashboard] C:\Program Files\Compaq\Digital Dashboard\DevGulp.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [CPQInet] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\SYSTEM\Restore\StateMgr.exe
O4 - Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\A6U16K\WATCH.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Translate (HKLM)
O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
O9 - Extra 'Tools' menuitem: AV Live (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...8073.2676736111
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab
dochappy
it's really getting bad now . I can't even have three web pages open at the same time without a low resource message appear.

I've scanned for viruses , nothing , spybot , spywareblaster , and spywareblocker show nothing.. this is driving me nuts crying.gif
CalamityJane
I don't see any malware running in your log. I assume you have rebooted? Photoediting programs can certainly use up a great deal of resources and don't always give it all back when you close them.

Also have you followed all the regular routine maintenance for your WinME operating system - clear out the cache (temporary internet files), empty the TEMP folder, clean out the history files, defrag, etc.?

I'll ask some of our operating systems experts to take a look here and see what they might suggest since I need to continue on with the infected victims in this forum. :)
toadbee
Dochappy -

:) Give us little help - in order to help you ;)
What's new on your computer? Have you installed anything lately? Is AVG new to you?

The only thing that is questionable is "PCTVOICE.exe" see the quoted below:
Background task installed with the drivers for the PCTEL 2304WT V.92 MDC Modems. Seen mainly in laptops.

Recommendation :
We do not yet know what this task really does, but we do know that PCTVOICE.EXE and the related PCTSPK.EXE occasionally run away with CPU consumption, up to 95%-100%, causing the inevitable extreme PC slow-down or freeze. In all cases that we have seen, disabling this process with The Ultimate Troubleshooter has not given the user any problem in his use of the modem. (http://www.answersthatwork.com/Tasklist_pages/tasklist_p.htm)

Perhaps you've recently installed a new modem - and PCTvoice is a leftover from an old modem?
if this is the case, let us know - you may have another entry or two that can be removed.

The link I mentioned above says generally it can be disabled, I would NOT recommend that. you may try end-task on it to see how your system responds -
ctrl-alt-delete and end task on "PCTVOICE.exe". Then see how your computer behaves.

Let us know - Again, if you know you've made system changes lately (new software or hardware) - let us know about that as well.
Hunter
Consider using this tool..clean all the files..then reboot and defrag your hard drive.

Then watch the defrag and make sure it is really defraging the entire drive.



System Security Suite

Powered by Borland Delphi


http://www.igorshpak.net/

Requirements: Windows 95/98/ME/2000/XP, Internet Explorer 4.0 or higher

System Security Suite (3S) is the program to remove internet tracks and junk files from your computer. It allows you to delete Cookies, clear Internet Explorer Cache, delete index.dat Files, clear Typed URLs, Windows Temp Folder and much more. You can also specify custom folder locations with file masks, which will be cleaned in addition to the selected items. In addition, the program allows you to view and optionally remove programs that launch automatically at Windows startup as well as Browser Helper Objects.
05.01.04 System Security Suite v1.04 has been released (268 Kb)
dochappy
thanks for all the responses. the only new thing I've added was I installed all the windows updates that I needed . now i get mprexe.exe as a running process along with 3 other files that weren't there before. When i try to delte them or kill them i get a blue screen of death.

When i defrag it has several little icons that correspond to data that cannot be moved other than that the rest seems to defrag (I think .. i'm a complete newb to this lol)

I killed the pctvoice process without hassle. its a feature of my modem but I never use it . is there a way i can stop it from running without deleting it from the system.?


thanks Hunter I will run this program and see if it helps. could a damaged registry cause these problems ? my friend said he thinks my registry is damaged.. if so is there a way to repair the registry ?


thanks for all the help. I hate bugging people but I feel so helpless when it comes to this stuff :unsure:
jfgnet
Process Viewer may help you determin what is using all your CPU power and can be found at http://www.teamcti.com/pview/prcview.htm

Another thing to look at is Win95/98 and ME use system resources when you store a lot on your desktop, try reorganizing an moving off of desktop
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.