Xp Freezing

  • Thread starter Thread starter Maineearle
  • Start date Start date
M

Maineearle

After being hit with Viruses and 3 Hacks had to reinstall Os.
Ran Killdisk and reformated also ran Windiag (no errors found). If I run
Windows Cleanmem my computer runs great for about 5 minutes.
The memory gets as low as 29bytes. I'm including some errors logs and
hijackthis log.
There were alot more errors and warnings but they were the same.

Application warnings:

Warning 2/8/2008 4:03:09 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 3:55:15 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 2:12:51 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 2:02:19 PM Windows Product
Activation None 1005 N/A RONALD-B2730983
Warning 2/8/2008 1:49:22 PM WinMgmt None 63 SYSTEM RONALD-B2730983



Security errors/warnings:

Failure Audit 2/11/2008 8:41:01 AM Security Policy Change 615 NETWORK
SERVICE RONALD-B2730983

System errors/warnings:


Error 2/11/2008 8:40:56 AM Dhcp None 1000 N/A RONALD-B2730983
Warning 2/11/2008 8:40:56 AM Dhcp None 1003 N/A RONALD-B2730983
Warning 2/11/2008 8:40:56 AM PlugPlayManager None 256 N/A RONALD-B2730983
Warning 2/10/2008 4:24:57 AM Dhcp None 1003 N/A RONALD-B2730983

Error 2/10/2008 4:24:37 AM PSched None 14103 N/A RONALD-B2730983

Warning 2/9/2008 12:46:25 PM PlugPlayManager None 256 N/A RONALD-B2730983
Error 2/9/2008 9:33:30 AM Dhcp None 1002 N/A RONALD-B2730983

Error 2/8/2008 6:07:24 PM Windows Update Agent Installation
20 N/A RONALD-B2730983


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:29 AM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\NICServ.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\WPC300N.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\OdHost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program
Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} -
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Linksys Wireless-N Notebook Adapter] C:\Program
Files\Linksys\Wireless-N Network Monitor\WPC300N.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\RunOnce: [FWCfg_Launch] C:\Program Files\Common Files\Symantec
Shared\Firewall\FWCfg.exe /i /s "C:\Program Files\Common Files\Symantec
Shared\Firewall\AppendRules.xml"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICSer_WPC300N - Unknown owner - C:\Program
Files\Linksys\Wireless-N Network Monitor\NICServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
Probably a ton of errors/warnings,why not toss the 3rd party junk out(memory
cleaner),and let xp run in its default mode...

Maineearle said:
After being hit with Viruses and 3 Hacks had to reinstall Os.
Ran Killdisk and reformated also ran Windiag (no errors found). If I run
Windows Cleanmem my computer runs great for about 5 minutes.
The memory gets as low as 29bytes. I'm including some errors logs and
hijackthis log.
There were alot more errors and warnings but they were the same.

Application warnings:

Warning 2/8/2008 4:03:09 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 3:55:15 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 2:12:51 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 2:02:19 PM Windows Product
Activation None 1005 N/A RONALD-B2730983
Warning 2/8/2008 1:49:22 PM WinMgmt None 63 SYSTEM RONALD-B2730983



Security errors/warnings:

Failure Audit 2/11/2008 8:41:01 AM Security Policy Change 615 NETWORK
SERVICE RONALD-B2730983

System errors/warnings:


Error 2/11/2008 8:40:56 AM Dhcp None 1000 N/A RONALD-B2730983
Warning 2/11/2008 8:40:56 AM Dhcp None 1003 N/A RONALD-B2730983
Warning 2/11/2008 8:40:56 AM PlugPlayManager None 256 N/A RONALD-B2730983
Warning 2/10/2008 4:24:57 AM Dhcp None 1003 N/A RONALD-B2730983

Error 2/10/2008 4:24:37 AM PSched None 14103 N/A RONALD-B2730983

Warning 2/9/2008 12:46:25 PM PlugPlayManager None 256 N/A RONALD-B2730983
Error 2/9/2008 9:33:30 AM Dhcp None 1002 N/A RONALD-B2730983

Error 2/8/2008 6:07:24 PM Windows Update Agent Installation
20 N/A RONALD-B2730983


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:29 AM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\NICServ.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\WPC300N.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\OdHost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program
Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} -
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Linksys Wireless-N Notebook Adapter] C:\Program
Files\Linksys\Wireless-N Network Monitor\WPC300N.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\RunOnce: [FWCfg_Launch] C:\Program Files\Common Files\Symantec
Shared\Firewall\FWCfg.exe /i /s "C:\Program Files\Common Files\Symantec
Shared\Firewall\AppendRules.xml"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICSer_WPC300N - Unknown owner - C:\Program
Files\Linksys\Wireless-N Network Monitor\NICServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
Andrew I thought I was using Window Cleanmem, not a 3rd party. I don't
understand what you mean by using xp default mode.

Andrew E. said:
Probably a ton of errors/warnings,why not toss the 3rd party junk out(memory
cleaner),and let xp run in its default mode...

Maineearle said:
After being hit with Viruses and 3 Hacks had to reinstall Os.
Ran Killdisk and reformated also ran Windiag (no errors found). If I run
Windows Cleanmem my computer runs great for about 5 minutes.
The memory gets as low as 29bytes. I'm including some errors logs and
hijackthis log.
There were alot more errors and warnings but they were the same.

Application warnings:

Warning 2/8/2008 4:03:09 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 3:55:15 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 2:12:51 PM Userenv None 1517 SYSTEM RONALD-B2730983
Warning 2/8/2008 2:02:19 PM Windows Product
Activation None 1005 N/A RONALD-B2730983
Warning 2/8/2008 1:49:22 PM WinMgmt None 63 SYSTEM RONALD-B2730983



Security errors/warnings:

Failure Audit 2/11/2008 8:41:01 AM Security Policy Change 615 NETWORK
SERVICE RONALD-B2730983

System errors/warnings:


Error 2/11/2008 8:40:56 AM Dhcp None 1000 N/A RONALD-B2730983
Warning 2/11/2008 8:40:56 AM Dhcp None 1003 N/A RONALD-B2730983
Warning 2/11/2008 8:40:56 AM PlugPlayManager None 256 N/A RONALD-B2730983
Warning 2/10/2008 4:24:57 AM Dhcp None 1003 N/A RONALD-B2730983

Error 2/10/2008 4:24:37 AM PSched None 14103 N/A RONALD-B2730983

Warning 2/9/2008 12:46:25 PM PlugPlayManager None 256 N/A RONALD-B2730983
Error 2/9/2008 9:33:30 AM Dhcp None 1002 N/A RONALD-B2730983

Error 2/8/2008 6:07:24 PM Windows Update Agent Installation
20 N/A RONALD-B2730983


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:29 AM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\NICServ.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\WPC300N.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Linksys\Wireless-N Network Monitor\OdHost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program
Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} -
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Linksys Wireless-N Notebook Adapter] C:\Program
Files\Linksys\Wireless-N Network Monitor\WPC300N.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\RunOnce: [FWCfg_Launch] C:\Program Files\Common Files\Symantec
Shared\Firewall\FWCfg.exe /i /s "C:\Program Files\Common Files\Symantec
Shared\Firewall\AppendRules.xml"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICSer_WPC300N - Unknown owner - C:\Program
Files\Linksys\Wireless-N Network Monitor\NICServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
Back
Top