Unsolved

This post is more than 5 years old

65 Posts

4897

January 31st, 2007 14:00

stupid computer

my computer turns on and off my virus protection and spyware programs and log me in and out on messenger . It seems the processor runs full speed ahead and games that are under the requirements for my computer are freezing and running weird or erroe on loading .HELP
 
 
Logfile of HijackThis v1.99.1
Scan saved at 11:23:11 AM, on 1/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPV5Updater.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 205.238.40.52 www.winmx.com err.winmx.com
O1 - Hosts: 205.238.40.1 cache0.winmx.com test3201.winmx.com test3205.winmx.com
O1 - Hosts: 205.238.40.2 cache1.winmx.com test3202.winmx.com test3206.winmx.com
O1 - Hosts: 82.43.224.20 cache2.winmx.com test3203.winmx.com test3207.winmx.com
O1 - Hosts: 82.204.21.111 cache3.winmx.com test3204.winmx.com test3208.winmx.com
O1 - Hosts: 205.238.40.1 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com
O1 - Hosts: 82.43.224.20 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com
O1 - Hosts: 82.43.224.20 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com
O1 - Hosts: 82.204.21.111 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com
O1 - Hosts: 82.204.21.111 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com
O1 - Hosts: 82.43.224.20 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com
O1 - Hosts: 82.43.224.20 c3527.z1301.winmx.com c3527.z1302.winmx.com c3527.z1303.winmx.com c3527.z1304.winmx.com c3527.z1305.winmx.com c3527.z1306.winmx.com
O1 - Hosts: 82.204.21.111 c3528.z1301.winmx.com c3528.z1302.winmx.com c3528.z1303.winmx.com c3528.z1304.winmx.com c3528.z1305.winmx.com c3528.z1306.winmx.com
O1 - Hosts: 82.204.21.111 c3529.z1301.winmx.com c3529.z1302.winmx.com c3529.z1303.winmx.com c3529.z1304.winmx.com c3529.z1305.winmx.com c3529.z1306.winmx.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster 16\pmremind.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - http://help.rr.com/Foundrysdccommon/download/tgctlar.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 

65 Posts

January 31st, 2007 16:00

i have just reformatted my computer for th third time since christmas thinking it was something i did on the install but i stopped thinking that when it hasn't stopped . i bought zoo tycoon 2 for my daughter and it freezes along with any other game with alot of graphics.

2 Intern

 • 

5.9K Posts

January 31st, 2007 16:00

ZA is Zone Alarm.  You should see it down in the systray (near the clock).  If you open it up then look down the left side there are different choices.  I think one of them is for Alarms.  (Don't have it here at work so going by memory).  When you get to the alarms there are two tabs at the top.  One just gives you the choice to turn the alert on or off the other is a list of activities.  Each time it lets a packet stream pass or blocks them it usually tells you.  Look and see if you are getting a lot of them in a short period of time.  (more than 1 or 2 a minute).
 
Your blacklight log shows nothing.  Let's check the event log and the device manager.
 
Check the Event logs for errors:
Start, Run, eventvwr.msc, OK then select System.  Look for red marked files that have a time stamp about the time of the slowdown.  Open the event then click on the bottom of the three buttons to copy the text.  Move to a reply and Edit, Paste.  Repeat for any other different errors that happened during the last slowdown period or last reboot.  Please don't go back to the beginning of time and no events from a Safe Mode boot.  Repeat for Application.  If your PC speaks something other than English don't translate it unless it doesn't use the Latin alphabet and then please include the timestamps.
 
 
Check the Device Manager for problems:
(Start) then rightclick on My Computer and select Manage.  Then Device Manager.  click on each of the + marks to open each item.  Look for yellow marked items and uninstall them or delete them and reboot.  Do they come back with yellow marks?  What has yellow marks?
 
After reloading your computer did you go to Windows update and get all the patches before doing any surfing?  This is very important as the reload is from a time period several months or even years ago and there have been a lot of security holes found and patched in that time.
 
 
Ron

 

65 Posts

January 31st, 2007 16:00

what is the ZA ....sorry i'm computer program stupid

2 Intern

 • 

5.9K Posts

January 31st, 2007 16:00

Hate to tell you this but the log you posted is not the one from Blacklight.  Looks like an installer log for something.
 
This is what a clean Blacklight log looks like:
 
01/06/07 13:09:23 [Info]: BlackLight Engine 1.0.55 initialized
01/06/07 13:09:23 [Info]: OS: 5.1 build 2600 (Service Pack 2)
01/06/07 13:09:24 [Note]: 7019 4
01/06/07 13:09:24 [Note]: 7005 0
01/06/07 13:09:41 [Note]: 7006 0
01/06/07 13:09:41 [Note]: 7011 1940
01/06/07 13:09:41 [Note]: 7026 0
01/06/07 13:09:41 [Note]: 7026 0
01/06/07 13:09:56 [Note]: FSRAW library version 1.7.1021
01/06/07 13:20:25 [Note]: 7007 0

It looks like vsmon.exe is taking up a lot of CPU time.  Don't know why.  Look in the ZA under Alerts and see if you are being attacked by a lot of outside sites or if a blocked internal program is trying to get out.
 
Post a new HJT log too.
 
Ron

65 Posts

January 31st, 2007 16:00

01/31/07 12:57:46 [Info]: BlackLight Engine 1.0.55 initialized
01/31/07 12:57:46 [Info]: OS: 5.1 build 2600 (Service Pack 2)
01/31/07 12:57:46 [Note]: 7019 4
01/31/07 12:57:46 [Note]: 7005 0
01/31/07 12:57:46 [Note]: 7006 0
01/31/07 12:57:47 [Note]: 7011 1180
01/31/07 12:57:47 [Note]: 7026 0
01/31/07 12:57:47 [Note]: 7026 0
01/31/07 12:57:50 [Note]: FSRAW library version 1.7.1021
01/31/07 13:00:08 [Note]: 7007 0
 
i think this is what i shoud have posted oops sorry .I don't even know what the other was???

65 Posts

January 31st, 2007 17:00

Event Type: Warning
Event Source: PlugPlayManager
Event Category: None
Event ID: 256
Date:  1/26/2007
Time:  3:51:51 PM
User:  N/A
Computer: COMPUTER
Description:
Timed out sending notification of device interface change to window of "ModemDeviceChange"
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: PlugPlayManager
Event Category: None
Event ID: 12
Date:  1/26/2007
Time:  10:22:07 AM
User:  N/A
Computer: MACHINENAME
Description:
The device 'Secondary IDE Channel' (PCIIDE\IDEChannel\4&136d273d&0&1) disappeared from the system without first being prepared for removal.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00              ....   
Event Type: Warning
Event Source: PlugPlayManager
Event Category: None
Event ID: 256
Date:  1/26/2007
Time:  3:51:51 PM
User:  N/A
Computer: COMPUTER
Description:
Timed out sending notification of device interface change to window of "ModemDeviceChange"
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
Event Type: Warning
Event Source: PlugPlayManager
Event Category: None
Event ID: 256
Date:  1/26/2007
Time:  3:51:51 PM
User:  N/A
Computer: COMPUTER
Description:
Timed out sending notification of device interface change to window of "ModemDeviceChange"
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 20
Date:  1/26/2007
Time:  8:38:18 PM
User:  NT AUTHORITY\SYSTEM
Computer: COMPUTER
Description:
Printer Driver PaperPort Color Printer Driver for Windows NT x86 Version-2 was added or updated. Files:- ppbint.dll, ppbiuif.dll, ppbint.ini.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 20
Date:  1/26/2007
Time:  8:38:22 PM
User:  NT AUTHORITY\SYSTEM
Computer: COMPUTER
Description:
Printer Driver PaperPort Mono Printer Driver for Windows NT x86 Version-2 was added or updated. Files:- ppbint.dll, ppbiuif.dll, ppbint2.ini.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 20
Date:  1/26/2007
Time:  8:41:49 PM
User:  NT AUTHORITY\SYSTEM
Computer: COMPUTER
Description:
Printer Driver Brother PC-FAX for Windows NT x86 Version-3 was added or updated. Files:- brofx04a.dll, brufx04a.dll, brofx04a.ppd.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 20
Date:  1/26/2007
Time:  8:42:35 PM
User:  NT AUTHORITY\SYSTEM
Computer: COMPUTER
Description:
Printer Driver Brother MFC-420CN USB Printer for Windows NT x86 Version-3 was added or updated. Files:- brio04a.dll, briu04a.dll, BRMF420C.PPD, brio04a.hlp, brmf420c.ini, bril04a.dll, brio04a.dat, briwm04a.ini, brqikmon.exe, brqikmon.hlp, brio04aa.bcm, brio04ab.bcm, brio04ac.bcm, brio04ad.bcm, brio04af.bcm, brio04ag.bcm, brio04ah.bcm, brio04ai.bcm, brio04ak.bcm, brio04al.bcm, brio04am.bcm, brio04an.bcm.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 20
Date:  1/26/2007
Time:  8:50:45 PM
User:  NT AUTHORITY\SYSTEM
Computer: COMPUTER
Description:
Printer Driver Amyuni Document Converter 2.10 for Windows NT x86 Version-2 was added or updated. Files:- acpdf210.dll, acpdfui210.dll, acfpdf.txt.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date:  1/27/2007
Time:  8:48:41 AM
User:  N/A
Computer: COMPUTER
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 01 00 54 00   ......T.
0008: 00 00 00 00 82 10 00 80   .... ..
0010: 01 00 00 00 00 00 00 00   ........
0018: 00 00 00 00 00 00 00 00   ........
0020: 00 00 00 00 00 00 00 00   ........
 
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date:  1/27/2007
Time:  8:37:19 PM
User:  N/A
Computer: COMPUTER
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 01 00 54 00   ......T.
0008: 00 00 00 00 82 10 00 80   .... ..
0010: 01 00 00 00 00 00 00 00   ........
0018: 00 00 00 00 00 00 00 00   ........
0020: 00 00 00 00 00 00 00 00   ........
 
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date:  1/27/2007
Time:  10:40:54 PM
User:  N/A
Computer: COMPUTER
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 01 00 54 00   ......T.
0008: 00 00 00 00 82 10 00 80   .... ..
0010: 01 00 00 00 00 00 00 00   ........
0018: 00 00 00 00 00 00 00 00   ........
0020: 00 00 00 00 00 00 00 00   ........
 
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date:  1/27/2007
Time:  11:11:35 PM
User:  N/A
Computer: COMPUTER
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 01 00 54 00   ......T.
0008: 00 00 00 00 82 10 00 80   .... ..
0010: 01 00 00 00 00 00 00 00   ........
0018: 00 00 00 00 00 00 00 00   ........
0020: 00 00 00 00 00 00 00 00   ........
Event Type: Warning
Event Source: W32Time
Event Category: None
Event ID: 36
Date:  1/28/2007
Time:  1:24:29 AM
User:  N/A
Computer: COMPUTER
Description:
The time service has not been able to synchronize the system time for 49152 seconds because none of the time providers has been able to provide a usable time stamp. The system clock is unsynchronized.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
I turned off my za because it went off so much ..I couldn't get anything done for it popping up again.. How do I turn it back on?
I haveno problems in device manager ..and I did the xp updates as soon as i reloaded my anti-virus protection.
 
 

2 Intern

 • 

5.9K Posts

January 31st, 2007 17:00

The TCP/IP outgoing limit alarm is a sign of  a possible worm but there can be other causes.  Let's see if we can figure out what is trying to connect.  Close all programs and wait about 5 minutes then:
 
Start, Run, cmd, OK to open a new black cmd window.  Type (with an Enter after each bold line)
 
netstat -o > junk.txt
 
tasklist /m >> junk.txt
 
notepad junk.txt
 
(This should bring up notepad with a bunch of text from the two commands.  Highlight all of it and copy it then paste it into a reply.  It may be too big for one post but you now have had a lot of practice breaking it up into smaller posts so it should be OK.)
 
I'll look at the other alarms in a little bit.  How do you connect to the internet?  Cable modem, DSL, dialup, company LAN? 
 
Ron
 
 

2 Intern

 • 

5.9K Posts

January 31st, 2007 18:00

try
 
tasklist.exe /m
 
(TASKLIST.EXE SPACE /M SPACE >> SPACE JUNK>TXT)
 
IF that doesn't work then see if you can right click on the clock and bring up the task manager.  If that works then select Processes then View Select Columns, check the box in front of PID if it's not checked and OK.  Now find the numbers that you see at the right side of the netstat -o display (996, 936, & 1420 were in your last one but they may change) and tell me what name is associated with each process. 
 
Ron

65 Posts

January 31st, 2007 18:00

iSafe.exe  system
VetMsg.exe    system
CAVTray.exe  what ( what is my user name on computer and there is only one user
 

2 Intern

 • 

5.9K Posts

January 31st, 2007 18:00

This alarm looks bad:
 
Event Type: Error
Event Source: PlugPlayManager
Event Category: None
Event ID: 12
Date:  1/26/2007
Time:  10:22:07 AM
User:  N/A
Computer: MACHINENAME
Description:
The device 'Secondary IDE Channel' (PCIIDE\IDEChannel\4&136d273d&0&1) disappeared from the system without first being prepared for removal.
 
 
Perhaps you have a loose IDE or power connector in your PC or a bad CD ROM but it could be a sign of hardware failure on the motherboard.  Seems unlikely that you would unplug a drive and I'm not really sure that would do it.  You might check and see if the PC maker offers a BIOS update for your PC.
 
If you have a dialup modem (or had one) it might be wise to uninstall it.  I think it's what causes a lot of the warnings you are seeing.
 
Ron
 
PS. Look at your netstat -o output as before with nothing running then open one instance of Internet Explorer.  Then run netstat -o again and see if you can see more than one new process.
 
 
 
 
 
 

65 Posts

January 31st, 2007 18:00

I am on road runner . the first command  and the third command work and i got this but the second command doesn't i even copied and pasted to see if it would help but to no avail.
 
 
Active Connections
  Proto  Local Address          Foreign Address        State           PID
  TCP    computer:1025          localhost:1032         ESTABLISHED     996
  TCP    computer:1025          localhost:2888         ESTABLISHED     996
  TCP    computer:1026          localhost:1033         ESTABLISHED     996
  TCP    computer:1026          localhost:2889         ESTABLISHED     996
  TCP    computer:1032          localhost:1025         ESTABLISHED     936
  TCP    computer:1033          localhost:1026         ESTABLISHED     936
  TCP    computer:2888          localhost:1025         ESTABLISHED     1420
  TCP    computer:2889          localhost:1026         ESTABLISHED     1420

65 Posts

January 31st, 2007 19:00

 Proto  Local Address          Foreign Address        State           PID
  TCP    computer:2029          by1msg4276310.phx.gbl:1863  ESTABLISHED     1548
  TCP    computer:1025          localhost:1032         ESTABLISHED     996
  TCP    computer:1025          localhost:2888         ESTABLISHED     996
  TCP    computer:1026          localhost:1033         ESTABLISHED     996
  TCP    computer:1026          localhost:2889         ESTABLISHED     996
  TCP    computer:1032          localhost:1025         ESTABLISHED     936
  TCP    computer:1033          localhost:1026         ESTABLISHED     936
  TCP    computer:2025          localhost:2026         CLOSE_WAIT      996
  TCP    computer:2888          localhost:1025         ESTABLISHED     1420
  TCP    computer:2889          localhost:1026         ESTABLISHED     1420
 
msmsgs.exe  what ( what is my computers name)
that was the only new one on there
 

65 Posts

January 31st, 2007 19:00

I think i can upgrade the bios but i'm no expert user and god forbid i ruin my computer ..isn't it hard to do that ? I do have a dial - up modem installed and i can uninstall it to see if that help ..since we have started my msn msg has logged on three time and i keep exiting the program but it just comes back .. my e-mail said i had the wrong pop server but worked again 30 mins later ...and sometimes you use the scroll on my mouse and it will close the ie page you are on or change it to something else . I am to the point I hate my computer and want to set it on fire but that would only cost me to get a new one . ..oh and i have also had to restart etrust pestpatrol earlier because it changed to stop active protection. 

2 Intern

 • 

5.9K Posts

January 31st, 2007 20:00

If you run HJT, scan only, you can check this one and Fix Checked and it may stop messenger for a while.  If you start Outlook Express it may fire it back up.
 
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 
I'm about to go home for the day so I may not be able to get back to you until tomorrow.
 
Run one of the online free scanners like:
 
See if it finds anything.  Also:
 
A Disk Check:
Run a disk error check and see if your harddrive has problems.  Start, My Computer then right click on Local Drive C and select Properties (verify that it shows you have at least 15% free) then Tools, Error-Checking => Check Now.  Check the 2 boxes then Start.  It will tell you it can't do it now but will be glad to schedule it for your next boot.  Tell it OK. When you reboot it will check your drive which usually takes 30-60 minutes.  Sometimes it will even fix your problems while it is at it.
 
Memory Check:
Verify that you still have the same amount of memory as you did originally.  (Start) then Open My Computer and select Help then About Windows.  Is the physical memory about what you bought?  Sometimes a single chip will fail and drop your memory in half.
 
 
BIOS updates are not hard.  Main thing is not to lose power to the PC while you are doing them or you will mess it up royally.  What PC do you have and what version of BIOS do you have?  You may need to go into the CMOS setup at boot in order to find out the BIOS version or it may tell you somewhere.  Haven't done one in a while.
 
Ron
 
 

65 Posts

January 31st, 2007 21:00

i have a del ldimension  4700 with a 2.82 ghz processor 512mb memory cd/dvd rom cd/dvd burner floppy drive  ati graphics card can't remeber witch one and a 160 gb hd
i wll try what you said an repost results ..gotta take daughter to church so if you don't get it today i will check tommorow. thanks
No Events found!

Top