itcantam
asked on
Svchost.exe hosting the RPCss services take up to 90-100% of the CPU...
Let me know what I have to do to... The 1st log is from HiJack and the 2nd one is from process Explorer...
I did run each and every software of AV and SPYware without success...
Its always the same thread in svchost.exe that take all the CPU :
Kernell32.dll!RegisterWait ForInputId le+0x4a that just multiply itself, start with 3 thread using approx 33% of the CPU each, at the end (before I power off) it can goes up to 8 thread like this splitting up all the CPU...
The desktop are not affected like the laptop (have a Firewall (zone alarm) and a VPN client (Aventail connect)). The moment this event happensl, the desktop taskbar freezes completly(svchost looks to kill himself and restart), but all opened apps still working and alt-tab to switch, can't open any new apps... For the laptop, we can start anything, but the CPU is busy by svchost.exe.
-------------------------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- -
StartupList report, 7/20/2004, 1:27:06 PM
StartupList version: 1.52.2
Started from : J:\GENASDV2\Tam\tools\Spy finders\HijackThis\HijackT his.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
========================== ========== ========== ====
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon .exe
C:\WINNT\system32\services .exe
C:\WINNT\system32\lsass.ex e
C:\WINNT\System32\ibmpmsvc .exe
C:\WINNT\system32\svchost. exe
C:\WINNT\System32\svchost. exe
C:\Program Files\Aventail\Connect\as3 2svc.exe
C:\WINNT\system32\spoolsv. exe
C:\WINNT\System32\Ati2evxx .exe
C:\WINNT\system32\DcPSI.ex e
C:\PROGRA~1\SYMANT~1\SYMAN T~1\DefWat ch.exe
C:\Program Files\Executive Software\DiskeeperWorkstat ion\DKServ ice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Novell\ZENworks\naln tsrv.exe
C:\PROGRA~1\SYMANT~1\SYMAN T~1\Rtvsca n.exe
C:\Program Files\Novell\ZENworks\Remo teManageme nt\RMAgent \WolSerNT. exe
C:\Program Files\Novell\ZENworks\Remo teManageme nt\RMAgent \ZenRem32. exe
C:\Program Files\SafeBoot\SBMGRNT.EXE
C:\WINNT\system32\SLClient .exe
C:\WINNT\system32\ZoneLabs \vsmon.exe
C:\Program Files\Novell\ZENworks\wm.e xe
C:\Program Files\Novell\ZENworks\WMRU NDLL.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Dazel\Output Envoy\bin\DcDaemon.exe
C:\Program Files\OnDemand\OdPlayer\OD Player.exe
C:\Program Files\Symantec_Client_Secu rity\Syman tec AntiVirus\vptray.exe
C:\PROGRA~1\ThinkPad\PkgMg r\HOTKEY\T PHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTK EY\TPONSCR .exe
C:\Program Files\ThinkPad\PkgMgr\HOTK EY_1\TpScr ex.exe
C:\Program Files\Synaptics\SynTP\SynT PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT PEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\ctfmon.e xe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\RemotePoint Presenter\rpointpr.exe
C:\Program Files\Zone Labs\Integrity Client\iclient.exe
C:\Program Files\netscape\Program\net scape.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\wbem\wmi apsrv.exe
C:\Program Files\InterVideo\WinDVD\Wi nDVD.exe
J:\GENASDV2\Tam\tools\Spy finders\HijackThis\HijackT his.exe
-------------------------- ---------- ---------- ----
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\jfthibea.000\Star t Menu\Programs\Startup]
BHODemon 2.0.lnk = GENASDV2\Tam\tools\Spy finders\BHODeamon\BHODemon .exe
HotSync Manager.lnk = Program Files\Palm\HOTSYNC.EXE
pcLogic.lnk = C:\ScriptLogic\mrLogic.exe
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
HotSync Manager.lnk = ?
RemotePoint Presenter.lnk = C:\Program Files\RemotePoint Presenter\rpointpr.exe
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
-------------------------- ---------- ---------- ----
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W indows NT\CurrentVersion\Winlogon ]
UserInit = C:\WINNT\system32\userinit .exe,
[HKLM\Software\Microsoft\W indows\Cur rentVersio n\Winlogon ]
*Registry key not found*
[HKCU\Software\Microsoft\W indows NT\CurrentVersion\Winlogon ]
*Registry value not found*
[HKCU\Software\Microsoft\W indows\Cur rentVersio n\Winlogon ]
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Run
AGRSMMSG = AGRSMMSG.exe
ATIModeChange = Ati2mdxx.exe
Tempfile = C:\WINNT\BAT\TEMP.LNK
DAZEL Delivery Agent = "C:\Program Files\Dazel\Output Envoy\bin\DcDaemon.exe"
OnDemand = C:\ScriptLogic\wKiX32.exe "C:\Program Files\OnDemand\OdPlayer\On Demand.Kix "
SBMGRNT.EXE = C:\PROGRA~1\SafeBoot\SBMGR NT.EXE -WinLogon
vptray = C:\Program Files\Symantec_Client_Secu rity\Syman tec AntiVirus\vptray.exe
TPHOTKEY = C:\PROGRA~1\ThinkPad\PkgMg r\HOTKEY\T PHKMGR.exe
SynTPLpr = C:\Program Files\Synaptics\SynTP\SynT PLpr.exe
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynT PEnh.exe
ZENRC Tray Icon = C:\WINNT\System32\zentray. exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe " -atboottime
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunOnce
*No values found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunOnceEx
*No values found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunServic es
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunServic esOnce
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Run
ctfmon.exe = C:\WINNT\System32\ctfmon.e xe
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunOnce
*No values found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunOnceEx
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunServic es
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunServic esOnce
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi ndows NT\CurrentVersion\Run
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi ndows NT\CurrentVersion\Run
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Run
[OptionalComponents]
*No values found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunOnce
*No subkeys found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunOnceEx
*No subkeys found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunServic es
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \RunServic esOnce
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Run
*No subkeys found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunOnce
*No subkeys found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunOnceEx
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunServic es
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \RunServic esOnce
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi ndows NT\CurrentVersion\Run
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi ndows NT\CurrentVersion\Run
*Registry key not found*
-------------------------- ---------- ---------- ----
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\ shell\open \command
(Default) = "%1" %*
-------------------------- ---------- ---------- ----
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\ shell\open \command
(Default) = "%1" %*
-------------------------- ---------- ---------- ----
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\ shell\open \command
(Default) = "%1" %*
-------------------------- ---------- ---------- ----
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\ shell\open \command
(Default) = "%1" %*
-------------------------- ---------- ---------- ----
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\ shell\open \command
(Default) = "%1" /S
-------------------------- ---------- ---------- ----
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\ shell\open \command
(Default) = C:\WINNT\System32\mshta.ex e "%1" %*
-------------------------- ---------- ---------- ----
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\ shell\open \command
(Default) = %SystemRoot%\system32\NOTE PAD.EXE %1
-------------------------- ---------- ---------- ----
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Ac tive Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab -0080c74c7 e95}]
StubPath = C:\WINNT\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e -de4607462 76c}] *
StubPath = %systemroot%\system32\shmg rate.exe OCInstallUserConfigIE
[>{881dd1c5-3dcf-431b-b061 -f3f88e8be 88a}] *
StubPath = %systemroot%\system32\shmg rate.exe OCInstallUserConfigOE
[>{CCB781BC-EB81-436D-B7D1 -6AC8F8E60 36D}] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM
[{2C7339CF-2B09-4501-B3F3- F3508C9228 ED}] *
StubPath = %SystemRoot%\system32\regs vr32.exe /s /n /i:/UserInstall
%SystemRoot%\system32\them eui.dll
[{306D6C21-C1B6-4629-986C- E59E1875B8 AF}]
StubPath = "C:\WINNT\System32\rundll3 2.exe" "C:\Program
Files\Messenger\msgsc.dll" ,ShowIcons User
[{44BBA840-CC51-11CF-AAFA- 00AA00B601 5C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA- 00AA00B601 5B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSecti on
C:\WINNT\INF\msnetmtg.inf, NetMtg.Ins tall.PerUs er.NT
[{5945c046-1e7d-11d1-bc44- 00c04fd912 be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSecti on
C:\WINNT\INF\msmsgs.inf,BL C.Install. PerUser
[{6BF52A52-394A-11d3-B153- 00C04F79FA A6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSecti on C:\WINNT\INF\wmp.inf,PerUs erStub
[{7790769C-0471-11d2-AF11- 00C04FA35D 02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user
/install
[{89820200-ECBD-11cf-8B85- 00AA005B43 40}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85- 00AA005B43 83}] *
StubPath = %SystemRoot%\system32\ie4u init.exe
-------------------------- ---------- ---------- ----
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\IC Q\Agent\Ap ps
*Registry key not found*
-------------------------- ---------- ---------- ----
Load/Run keys from C:\WINNT\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon : load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon : run=*Registry value not found*
HKLM\..\Windows\CurrentVer sion\WinLo gon: load=*Registry key not found*
HKLM\..\Windows\CurrentVer sion\WinLo gon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon : load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon : run=*Registry value not found*
HKCU\..\Windows\CurrentVer sion\WinLo gon: load=*Registry key not found*
HKCU\..\Windows\CurrentVer sion\WinLo gon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=
-------------------------- ---------- ---------- ----
Shell & screensaver key from C:\WINNT\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=%SystemRoot%\ bat.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
-------------------------- ---------- ---------- ----
Checking for EXPLORER.EXE instances:
C:\WINNT\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINNT\Explorer\Explorer .exe: not present
C:\WINNT\System\Explorer.e xe: not present
C:\WINNT\System32\Explorer .exe: not present
C:\WINNT\Command\Explorer. exe: not present
C:\WINNT\Fonts\Explorer.ex e: not present
-------------------------- ---------- ---------- ----
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
-------------------------- ---------- ---------- ----
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINNT
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
-------------------------- ---------- ---------- ----
Enumerating Browser Helper Objects:
(no name) - C:\WINNT\System32\ATPART~1 .DLL - {00000EF1-0786-4633-87C6-1 AA7A44296D A}
(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH elper.ocx -
{06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3}
-------------------------- ---------- ---------- ----
Enumerating Task Scheduler jobs:
*No jobs found*
-------------------------- ---------- ---------- ----
Enumerating Download Program Files:
[DirectAnimation Java Classes]
CODEBASE = file://C:\WINNT\Java\class es\dajava. cab
OSD = C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd
[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINNT\Java\class es\xmldso. cab
OSD = C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd
[F1 Organizer Class]
InProcServer32 = C:\WINNT\System32\ATPART~1 .DLL
CODEBASE = http://www.addictivetechnologies.net/DM0/cab/wzzp4.cab
[PCPitstop Utility]
InProcServer32 = C:\WINNT\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
[Installer Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\ISTactivex.dll
CODEBASE = http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
[HouseCall Control]
InProcServer32 = C:\WINNT\DOWNLO~1\xscan53. ocx
CODEBASE =
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
[mhLabel Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\mhLbl.dll
CODEBASE = http://www.pcpitstop.com/mhLbl.cab
[ActiveScan Installer Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\asinst.dll
CODEBASE = http://www.pandasoftware.com/activescan/as5/asinst.cab
[SassCln Object]
InProcServer32 = C:\WINNT\Downloaded Program Files\SassCln.dll
CODEBASE = http://www.microsoft.com/security/controls/Sasser/20/SassCln.CAB
[CentraDownloaderCtl Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\CentraDownloader.dll
CODEBASE = http://batclass.icconsulting.com.au/SiteRoots/main/Install/CentraDownloader.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINNT\System32\macromed \flash\Fla sh.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
-------------------------- ---------- ---------- ----
Enumerating Winsock LSP files:
NameSpace #1: C:\Program Files\Aventail\Connect\asd ns.dll
NameSpace #2: C:\WINNT\System32\mswsock. dll
NameSpace #3: C:\WINNT\System32\winrnr.d ll
NameSpace #4: C:\WINNT\System32\mswsock. dll
Protocol #1: C:\WINNT\system32\mswsock. dll
Protocol #2: C:\WINNT\system32\mswsock. dll
Protocol #3: C:\WINNT\system32\mswsock. dll
Protocol #4: C:\WINNT\system32\mswsock. dll
Protocol #5: C:\WINNT\system32\rsvpsp.d ll
Protocol #6: C:\WINNT\system32\rsvpsp.d ll
Protocol #7: C:\WINNT\system32\mswsock. dll
Protocol #8: C:\WINNT\system32\mswsock. dll
Protocol #9: C:\WINNT\system32\mswsock. dll
Protocol #10: C:\WINNT\system32\mswsock. dll
Protocol #11: C:\WINNT\system32\mswsock. dll
Protocol #12: C:\WINNT\system32\mswsock. dll
Protocol #13: C:\WINNT\system32\mswsock. dll
Protocol #14: C:\WINNT\system32\mswsock. dll
-------------------------- ---------- ---------- ----
Enumerating Windows NT/2000/XP services
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Embedded Controller Driver: System32\DRIVERS\ACPIEC.sy s (system)
aeaudio: system32\drivers\aeaudio.s ys (manual start)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drive rs\afd.sys (autostart)
Agere Systems Soft Modem: System32\DRIVERS\AGRSM.sys (manual start)
Alerter: %SystemRoot%\System32\svch ost.exe -k LocalService (manual start)
Application Layer Gateway Service: %SystemRoot%\System32\alg. exe (manual start)
Application Management: %SystemRoot%\system32\svch ost.exe -k netsvcs (manual start)
Aventail Connect: C:\Program Files\Aventail\Connect\as3 2svc.exe (autostart)
Ascrypto: \??\C:\Program Files\Aventail\Connect\asc rypto.sys (manual start)
Askernel: \??\C:\Program Files\Aventail\Connect\asn tkrnl.sys (system)
Astdi: \??\C:\Program Files\Aventail\Connect\asn ttdi.sys (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac. sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
Ati HotKey Poller: %SystemRoot%\System32\Ati2 evxx.exe (autostart)
ati2mtag: System32\DRIVERS\ati2mtag. sys (manual start)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.s ys (manual start)
Windows Audio: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.s ys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\System32\svch ost.exe -k netsvcs
(manual start)
Computer Browser: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisv c.exe (manual start)
ClipBook: %SystemRoot%\system32\clip srv.exe (manual start)
Microsoft AC Adapter Driver: System32\DRIVERS\CmBatt.sy s (manual start)
Microsoft Composite Battery Driver: System32\DRIVERS\compbatt. sys (system)
COM+ System Application: C:\WINNT\System32\dllhost. exe
/Processid:{02D4B3F1-FD88- 11D1-960D- 00805FC792 35} (manual start)
Cryptographic Services: %SystemRoot%\system32\svch ost.exe -k netsvcs (autostart)
Darpan: System32\DRIVERS\Darpan.sy s (manual start)
DAZEL Delivery Agent: DcPSI.exe (autostart)
DefWatch: C:\PROGRA~1\SYMANT~1\SYMAN T~1\DefWat ch.exe (autostart)
DHCP Client: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Diskeeper: C:\Program Files\Executive Software\DiskeeperWorkstat ion\DKServ ice.exe
(autostart)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmad min.exe /com (manual
start)
dmboot: System32\drivers\dmboot.sy s (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sy s (disabled)
Logical Disk Manager: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sy s (manual start)
DNS Client: %SystemRoot%\System32\svch ost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.s ys (manual start)
Intel(R) PRO/1000 Adapter Driver: System32\DRIVERS\e1000325. sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\serv ices.exe (autostart)
COM+ Event System: C:\WINNT\System32\svchost. exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual
start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Volume Manager Driver: System32\DRIVERS\ftdisk.sy s (system)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual start)
Microsoft HID Class Driver: System32\DRIVERS\hidusb.sy s (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt. sys (system)
IBMPMDRV: System32\DRIVERS\ibmpmdrv. sys (manual start)
IBM PM Service: %SystemRoot%\System32\ibmp msvc.exe (autostart)
CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINNT\System32\imapi.ex e (manual start)
IntelIde: System32\DRIVERS\intelide. sys (system)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv. sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sy s (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IrDA Protocol: System32\DRIVERS\irda.sys (autostart)
IR Enumerator Service: System32\DRIVERS\irenum.sy s (manual start)
Infrared Monitor: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sy s (system)
LanHound Filter: System32\DRIVERS\isproto.s ys (autostart)
Keyboard Class Driver: System32\DRIVERS\kbdclass. sys (system)
Keyboard HID Driver: System32\DRIVERS\kbdhid.sy s (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sy s (manual start)
Server: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svch ost.exe -k LocalService (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
(autostart)
Messenger: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
NetMeeting Remote Desktop Sharing: C:\WINNT\System32\mnmsrvc. exe (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass. sys (system)
Mouse HID Driver: System32\DRIVERS\mouhid.sy s (manual start)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sy s (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sy s (system)
Distributed Transaction Coordinator: C:\WINNT\System32\msdtc.ex e (manual start)
Windows Installer: C:\WINNT\System32\msiexec. exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.s ys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK. sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Novell Application Launcher: C:\Program Files\Novell\ZENworks\naln tsrv.exe (autostart)
NAVAP: \??\C:\PROGRA~1\SYMANT~1\S YMANT~1\NA VAP.sys (manual start)
NAVAPEL: \??\C:\Program Files\Symantec_Client_Secu rity\Syman tec AntiVirus\NAVAPEL.SYS
(autostart)
NAVENG: \??\C:\PROGRA~1\COMMON~1\S YMANT~1\VI RUSD~1\200 40719.048\ NAVENG.sys (manual start)
NAVEX15: \??\C:\PROGRA~1\COMMON~1\S YMANT~1\VI RUSD~1\200 40719.048\ NAVEX15.sy s (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi. sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.s ys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.s ys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.s ys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netd de.exe (manual start)
Network DDE DSDM: %SystemRoot%\system32\netd de.exe (manual start)
Net Logon: %SystemRoot%\System32\lsas s.exe (autostart)
Network Connections: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual start)
NICM: System32\Drivers\Nicm.sys (system)
Network Location Awareness (NLA): %SystemRoot%\System32\svch ost.exe -k netsvcs (manual
start)
Network Monitor Driver: System32\DRIVERS\NMnt.sys (manual start)
Symantec AntiVirus Client: C:\PROGRA~1\SYMANT~1\SYMAN T~1\Rtvsca n.exe (autostart)
NSC Infrared Device Driver: System32\DRIVERS\nscirda.s ys (manual start)
Novell Local Security Context Manager: \SystemRoot\System32\drive rs\novell\ nscmnt.sys
(manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsas s.exe (manual start)
Removable Storage: %SystemRoot%\system32\svch ost.exe -k netsvcs (manual start)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt. sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd. sys (manual start)
OracleOraHome92ClientCache : C:\oracle\ora92\bin\ONRSD. EXE (manual start)
PalmUSBD: system32\drivers\PalmUSBD. sys (manual start)
Parallel port driver: System32\DRIVERS\parport.s ys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
Pcmcia: System32\DRIVERS\pcmcia.sy s (system)
Plug and Play: %SystemRoot%\system32\serv ices.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsas s.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.s ys (manual start)
Processor Driver: System32\DRIVERS\processr. sys (system)
Novell ZfD Wake on LAN Status Agent: C:\Program
Files\Novell\ZENworks\Remo teManageme nt\RMAgent \WolSerNT. exe (autostart)
Protected Storage: %SystemRoot%\system32\lsas s.exe (autostart)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.s ys (manual start)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sy s (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual
start)
WAN Miniport (IrDA): System32\DRIVERS\rasirda.s ys (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.s ys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual
start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe. sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sy s (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sy s (system)
Terminal Server Device Redirector Driver: System32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINNT\system32\sessmgr. exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.s ys (system)
Novell ZfD Remote Management: C:\Program
Files\Novell\ZENworks\Remo teManageme nt\RMAgent \ZenRem32. exe (autostart)
Routing and Remote Access: %SystemRoot%\System32\svch ost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svch ost.exe -k LocalService (autostart)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\loca tor.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svch ost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp .exe (manual start)
SafeBoot Configuration Manager: C:\Program Files\SafeBoot\SBMGRNT.EXE (autostart)
Security Accounts Manager: %SystemRoot%\system32\lsas s.exe (autostart)
SbcpHid: \??\C:\WINNT\System32\Driv ers\SbcpHi d.sys (system)
Smart Card Helper: %SystemRoot%\System32\SCar dSvr.exe (manual start)
Smart Card: %SystemRoot%\System32\SCar dSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Secdrv: System32\DRIVERS\secdrv.sy s (manual start)
Secondary Logon: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svch ost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.s ys (manual start)
Serial port driver: System32\DRIVERS\serial.sy s (system)
Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS):
%SystemRoot%\System32\svch ost.exe -k netsvcs (disabled)
Shell Hardware Detection: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
ScriptLogic service: SLClient.exe (autostart)
Intel(R) SMBus 2.0 Driver: System32\DRIVERS\smb.sys (manual start)
smwdm: system32\drivers\smwdm.sys (manual start)
Microsoft Kernel Audio Splitter: system32\drivers\splitter. sys (manual start)
Print Spooler: %SystemRoot%\system32\spoo lsv.exe (autostart)
System Restore Filter Driver: \SystemRoot\System32\DRIVE RS\sr.sys (disabled)
System Restore Service: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svch ost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svch ost.exe -k imgsvc (manual start)
Software Bus Driver: System32\DRIVERS\swenum.sy s (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sy s (manual start)
MS Software Shadow Copy Provider: C:\WINNT\System32\dllhost. exe
/Processid:{06BEA234-9FA7- 4D9B-B821- AF1C242995 ED} (manual start)
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SY S (manual start)
Synaptics TouchPad Driver: System32\DRIVERS\SynTP.sys (manual start)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio. sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlo gsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sy s (system)
Terminal Services: %SystemRoot%\System32\svch ost.exe -k netsvcs (disabled)
Themes: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Telnet: C:\WINNT\System32\tlntsvr. exe (disabled)
Distributed Link Tracking Client: %SystemRoot%\system32\svch ost.exe -k netsvcs (autostart)
Microcode Update Driver: System32\DRIVERS\update.sy s (manual start)
Upload Manager: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Universal Plug and Play Device Host: %SystemRoot%\System32\svch ost.exe -k LocalService
(disabled)
Uninterruptible Power Supply: %SystemRoot%\System32\ups. exe (manual start)
Microsoft USB Generic Parent Driver: System32\DRIVERS\usbccgp.s ys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.s ys
(manual start)
Microsoft USB Standard Hub Driver: System32\DRIVERS\usbhub.sy s (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.S YS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.s ys
(manual start)
VgaSave: \SystemRoot\System32\drive rs\vga.sys (system)
vsdatant: \??\C:\WINNT\System32\vsda tant.sys (autostart)
TrueVector Internet Monitor: C:\WINNT\system32\ZoneLabs \vsmon.exe -service (autostart)
Volume Shadow Copy: %SystemRoot%\System32\vssv c.exe (manual start)
Windows Time: %SystemRoot%\System32\svch ost.exe -k netsvcs (autostart)
Intel(R) PRO/Wireless 7100 Adapter Driver: System32\DRIVERS\w70n51.sy s (manual start)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sy s (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sy s (manual start)
WebClient: %SystemRoot%\System32\svch ost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svch ost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svch ost.exe -k netsvcs (manual
start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svch ost.exe -k
netsvcs (manual start)
WMI Performance Adapter: C:\WINNT\System32\wbem\wmi apsrv.exe (manual start)
Automatic Updates: %systemroot%\system32\svch ost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svch ost.exe -k netsvcs (disabled)
Novell XTier Authentication Service: \SystemRoot\System32\drive rs\novell\ xauthnt.sy s (manual
start)
Workstation Manager: C:\Program Files\Novell\ZENworks\wm.e xe (autostart)
-------------------------- ---------- ---------- ----
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperation s: *Registry value not found*
-------------------------- ---------- ---------- ----
Enumerating ShellServiceObjectDelayLoa d items:
PostBootReminder: C:\WINNT\system32\SHELL32. dll
CDBurn: C:\WINNT\system32\SHELL32. dll
WebCheck: C:\WINNT\System32\webcheck .dll
SysTray: C:\WINNT\System32\stobject .dll
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \policies\ Explorer\R un
*Registry key not found*
-------------------------- ---------- ---------- ----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi ndows\Curr entVersion \policies\ Explorer\R un
*Registry key not found*
-------------------------- ---------- ---------- ----
End of report, 35,064 bytes
Report generated in 0.100 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
-------------------------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- -
Process Explorer log when the prob happend...
Process PID CPU Description Company Name
System Idle Process 0
Interrupts n/a Hardware Interrupts
DPCs n/a Deferred Procedure Calls
System 4 1
smss.exe 580 Windows NT Session Manager Microsoft Corporation
csrss.exe 644 1 Client Server Runtime Process Microsoft Corporation
winlogon.exe 668 Windows NT Logon Application Microsoft Corporation
services.exe 712 2 Services and Controller app Microsoft Corporation
ibmpmsvc.exe 904
svchost.exe 940 94 Generic Host Process for Win32 Services Microsoft Corporation
hpgs2wnf.exe 3600 hpgs2wnf Module
svchost.exe 1168 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1180 Generic Host Process for Win32 Services Microsoft Corporation
spoolsv.exe 1392 Spooler SubSystem App Microsoft Corporation
cusrvc.exe 1664 Novell Client Update Service Novell, Inc.
DcPSI.exe 1680
DKService.exe 1696 DKSERVICE.EXE Executive Software International, Inc.
mdm.exe 1728 Machine Debug Manager Microsoft Corporation
NALNTSRV.EXE 1752 NT Service for Novell Application Launcher (ZENLITE) Novell, Inc.
Rtvscan.exe 1856 Symantec AntiVirus Symantec Corporation
PCAHelper.exe 1900 PCAHelper Module SYMON Communications, Inc.
WolSerNT.exe 1924 Novell ZFD Wake on Lan Status Agent Novell Inc.
ZenRem32.exe 1944 Novell ZEN Remote Management Agent Novell Inc.
locator.exe 2044 Rpc Locator Microsoft Corporation
sbmgrnt.exe 132 SafeBoot Configuration Manager for NT Control Break International
SLClient.exe 184 SLServer ScriptLogic Corporation
svchost.exe 244 Generic Host Process for Win32 Services Microsoft Corporation
vsmon.exe 280 TrueVector Service Zone Labs Inc.
winvnc.exe 416 VNC server for Win32 RealVNC Ltd.
WM.EXE 448 ZEN for Desktops Workstation Manager Novell, INC.
WMRUNDLL.EXE 1060 ZEN for Desktops Helper DLL Processor Novell, INC.
svchost.exe 1076 Generic Host Process for Win32 Services Microsoft Corporation
dllhost.exe 2844 COM Surrogate Microsoft Corporation
msiexec.exe 436 Windows® installer Microsoft Corporation
lsass.exe 724 LSA Shell (Export Version) Microsoft Corporation
explorer.exe 2336 Windows Explorer Microsoft Corporation
tp4mon.exe 2500 IBM PS/2 TrackPoint Application IBM Corporation
DcDaemon.exe 2528 DAZEL Delivery Agent Hewlett-Packard Company
wKiX32.exe 2360 KiXtart main executable Ruud van Velsen (Microsoft)
OdPlayer.exe 2156 OnDemand Player Global Knowledge, Inc.
VPTray.exe 2688 Symantec AntiVirus Symantec Corporation
TPHKMGR.exe 2780
TPONSCR.exe 2848
nwtray.exe 3112 Novell System Tray Icon Novell, Inc.
hpgs2wnd.exe 3192 hpgs2wnd Hewlett-Packard
ctfmon.exe 3200 CTF Loader Microsoft Corporation
NALDESK.EXE 3664 ZENworks Application Explorer Executable Novell, Inc
HOTSYNC.EXE 240 HotSync® Manager Application Palm, Inc.
procexp.exe 1976 2 Sysinternals Process Explorer Sysinternals
MPSRPT_SETUPPerf.EXE 3228 MPS Reporting Tool for Setup and Performance Support Microsoft Corporation
cmd.exe 2452 Windows Command Processor Microsoft Corporation
msinfo32.exe 784 System Information Microsoft Corporation
cmd.exe 2140 Windows Command Processor Microsoft Corporation
cscript.exe 2696 Microsoft (r) Console Based Script Host Microsoft Corporation
cmd.exe 3000 Windows Command Processor Microsoft Corporation
tlist.exe 2912 Microsoft® Process List Utility Microsoft Corporation
autokr.exe 4088 Auto Kernrate Tool
cmd.exe 232 Windows Command Processor Microsoft Corporation
CheckSym.exe 1296 Symbol Collection and Verification Process Microsoft Corporation
wuauclt.exe 2852 Windows Update AutoUpdate Client Microsoft Corporation
Process: svchost.exe Pid: 940
Type Name
Thread svchost.exe(940): 980
Thread svchost.exe(940): 980
Thread svchost.exe(940): 980
Thread svchost.exe(940): 976
Thread svchost.exe(940): 976
Thread svchost.exe(940): 948
Thread svchost.exe(940): 948
Thread svchost.exe(940): 944
Thread svchost.exe(940): 3616
Thread svchost.exe(940): 3492
Thread svchost.exe(940): 3476
Thread svchost.exe(940): 2896
Thread svchost.exe(940): 2804
Thread svchost.exe(940): 2748
Thread svchost.exe(940): 2644
Thread svchost.exe(940): 2404
Thread svchost.exe(940): 228
Thread svchost.exe(940): 2200
Thread svchost.exe(940): 1484
Thread svchost.exe(940): 1376
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\LOCAL SERVICE
Process hpgs2wnf.exe(3600)
Key HKU
Key HKU
Key HKU
Key HKU
Key HKLM\SYSTEM\ControlSet001\ Services\W inSock2\Pa rameters\P rotocol_Ca talog9
Key HKLM\SYSTEM\ControlSet001\ Services\W inSock2\Pa rameters\N ameSpace_C atalog5
Key HKLM\SYSTEM\ControlSet001\ Services\T cpip\Param eters
Key HKLM\SYSTEM\ControlSet001\ Services\T cpip\Linka ge
Key HKLM\SYSTEM\ControlSet001\ Services\N etBT\Param eters\Inte rfaces
Key HKLM\SYSTEM\ControlSet001\ Services\N etBT\Param eters
Key HKLM\SOFTWARE\Microsoft\Ol e
Key HKLM\SOFTWARE\Microsoft\CO M3
Key HKLM\SOFTWARE\Microsoft\CO M3
Key HKLM\SOFTWARE\Microsoft\CO M3
Key HKLM\SOFTWARE\Microsoft\CO M3
Key HKLM\SOFTWARE\Microsoft\CO M3
Key HKLM\SOFTWARE\Microsoft\CO M3
Key HKLM
Key HKCU\Software\Classes
Key HKCR\CLSID
Key HKCR\CLSID
Key HKCR\CLSID
Key HKCR\AppID
Key HKCR
Key HKCR
Key HKCR
Key HKCR
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
File C:\WINNT\system32
WindowStation \Windows\WindowStations\Se rvice-0x0- 3e7$
WindowStation \Windows\WindowStations\Se rvice-0x0- 3e7$
Directory \Windows
Port \RPC Control\epmapper
Directory \KnownDlls
KeyedEvent \KernelObjects\CritSecOutO fMemoryEve nt
File \Dfs
File \Device\Udp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NwlnkSpx\Stream
File \Device\NamedPipe\Winsock2 \CatalogCh angeListen er-3ac-0
File \Device\NamedPipe\svcctl
File \Device\NamedPipe\net\NtCo ntrolPipe3
File \Device\NamedPipe\epmapper
File \Device\NamedPipe\epmapper
File \Device\KsecDD
File \Device\Ip
File \Device\Ip
File \Device\Ip
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
Desktop \Default
Event \BaseNamedObjects\userenv: User Profile setup event
Section \BaseNamedObjects\ShimShar edMemory
Mutant \BaseNamedObjects\ShimCach eMutex
Event \BaseNamedObjects\ScmCreat edEvent
Section \BaseNamedObjects\RotHintT able
Mutant \BaseNamedObjects\{02D4B3F 1-FD88-11D 1-960D-008 05FC
Section \BaseNamedObjects\__R_0000 00000007_S Mem__
Directory \BaseNamedObjects
Thank you in advance... Any advice will be appreciated.
I did run each and every software of AV and SPYware without success...
Its always the same thread in svchost.exe that take all the CPU :
Kernell32.dll!RegisterWait
The desktop are not affected like the laptop (have a Firewall (zone alarm) and a VPN client (Aventail connect)). The moment this event happensl, the desktop taskbar freezes completly(svchost looks to kill himself and restart), but all opened apps still working and alt-tab to switch, can't open any new apps... For the laptop, we can start anything, but the CPU is busy by svchost.exe.
--------------------------
StartupList report, 7/20/2004, 1:27:06 PM
StartupList version: 1.52.2
Started from : J:\GENASDV2\Tam\tools\Spy finders\HijackThis\HijackT
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==========================
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
C:\WINNT\system32\services
C:\WINNT\system32\lsass.ex
C:\WINNT\System32\ibmpmsvc
C:\WINNT\system32\svchost.
C:\WINNT\System32\svchost.
C:\Program Files\Aventail\Connect\as3
C:\WINNT\system32\spoolsv.
C:\WINNT\System32\Ati2evxx
C:\WINNT\system32\DcPSI.ex
C:\PROGRA~1\SYMANT~1\SYMAN
C:\Program Files\Executive Software\DiskeeperWorkstat
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Novell\ZENworks\naln
C:\PROGRA~1\SYMANT~1\SYMAN
C:\Program Files\Novell\ZENworks\Remo
C:\Program Files\Novell\ZENworks\Remo
C:\Program Files\SafeBoot\SBMGRNT.EXE
C:\WINNT\system32\SLClient
C:\WINNT\system32\ZoneLabs
C:\Program Files\Novell\ZENworks\wm.e
C:\Program Files\Novell\ZENworks\WMRU
C:\WINNT\Explorer.EXE
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Dazel\Output Envoy\bin\DcDaemon.exe
C:\Program Files\OnDemand\OdPlayer\OD
C:\Program Files\Symantec_Client_Secu
C:\PROGRA~1\ThinkPad\PkgMg
C:\Program Files\ThinkPad\PkgMgr\HOTK
C:\Program Files\ThinkPad\PkgMgr\HOTK
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\ctfmon.e
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\RemotePoint Presenter\rpointpr.exe
C:\Program Files\Zone Labs\Integrity Client\iclient.exe
C:\Program Files\netscape\Program\net
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\wbem\wmi
C:\Program Files\InterVideo\WinDVD\Wi
J:\GENASDV2\Tam\tools\Spy finders\HijackThis\HijackT
--------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\jfthibea.000\Star
BHODemon 2.0.lnk = GENASDV2\Tam\tools\Spy finders\BHODeamon\BHODemon
HotSync Manager.lnk = Program Files\Palm\HOTSYNC.EXE
pcLogic.lnk = C:\ScriptLogic\mrLogic.exe
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
HotSync Manager.lnk = ?
RemotePoint Presenter.lnk = C:\Program Files\RemotePoint Presenter\rpointpr.exe
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W
UserInit = C:\WINNT\system32\userinit
[HKLM\Software\Microsoft\W
*Registry key not found*
[HKCU\Software\Microsoft\W
*Registry value not found*
[HKCU\Software\Microsoft\W
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
AGRSMMSG = AGRSMMSG.exe
ATIModeChange = Ati2mdxx.exe
Tempfile = C:\WINNT\BAT\TEMP.LNK
DAZEL Delivery Agent = "C:\Program Files\Dazel\Output Envoy\bin\DcDaemon.exe"
OnDemand = C:\ScriptLogic\wKiX32.exe "C:\Program Files\OnDemand\OdPlayer\On
SBMGRNT.EXE = C:\PROGRA~1\SafeBoot\SBMGR
vptray = C:\Program Files\Symantec_Client_Secu
TPHOTKEY = C:\PROGRA~1\ThinkPad\PkgMg
SynTPLpr = C:\Program Files\Synaptics\SynTP\SynT
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynT
ZENRC Tray Icon = C:\WINNT\System32\zentray.
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*No values found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*No values found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ctfmon.exe = C:\WINNT\System32\ctfmon.e
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*No values found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
[OptionalComponents]
*No values found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\
(Default) = "%1" %*
--------------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\
(Default) = "%1" %*
--------------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\
(Default) = "%1" %*
--------------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\
(Default) = "%1" %*
--------------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\
(Default) = "%1" /S
--------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\
(Default) = C:\WINNT\System32\mshta.ex
--------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\
(Default) = %SystemRoot%\system32\NOTE
--------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Ac
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab
StubPath = C:\WINNT\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e
StubPath = %systemroot%\system32\shmg
[>{881dd1c5-3dcf-431b-b061
StubPath = %systemroot%\system32\shmg
[>{CCB781BC-EB81-436D-B7D1
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM
[{2C7339CF-2B09-4501-B3F3-
StubPath = %SystemRoot%\system32\regs
%SystemRoot%\system32\them
[{306D6C21-C1B6-4629-986C-
StubPath = "C:\WINNT\System32\rundll3
Files\Messenger\msgsc.dll"
[{44BBA840-CC51-11CF-AAFA-
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
C:\WINNT\INF\msnetmtg.inf,
[{5945c046-1e7d-11d1-bc44-
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
C:\WINNT\INF\msmsgs.inf,BL
[{6BF52A52-394A-11d3-B153-
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
[{7790769C-0471-11d2-AF11-
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user
/install
[{89820200-ECBD-11cf-8B85-
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-
StubPath = %SystemRoot%\system32\ie4u
--------------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\IC
*Registry key not found*
--------------------------
Load/Run keys from C:\WINNT\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon
HKLM\..\Windows NT\CurrentVersion\WinLogon
HKLM\..\Windows\CurrentVer
HKLM\..\Windows\CurrentVer
HKCU\..\Windows NT\CurrentVersion\WinLogon
HKCU\..\Windows NT\CurrentVersion\WinLogon
HKCU\..\Windows\CurrentVer
HKCU\..\Windows\CurrentVer
HKCU\..\Windows NT\CurrentVersion\Windows:
HKCU\..\Windows NT\CurrentVersion\Windows:
HKLM\..\Windows NT\CurrentVersion\Windows:
HKLM\..\Windows NT\CurrentVersion\Windows:
HKLM\..\Windows NT\CurrentVersion\Windows:
--------------------------
Shell & screensaver key from C:\WINNT\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=%SystemRoot%\
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------
Checking for EXPLORER.EXE instances:
C:\WINNT\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINNT\Explorer\Explorer
C:\WINNT\System\Explorer.e
C:\WINNT\System32\Explorer
C:\WINNT\Command\Explorer.
C:\WINNT\Fonts\Explorer.ex
--------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINNT
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
--------------------------
Enumerating Browser Helper Objects:
(no name) - C:\WINNT\System32\ATPART~1
(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
{06849E9F-C8D7-4D59-B87D-7
--------------------------
Enumerating Task Scheduler jobs:
*No jobs found*
--------------------------
Enumerating Download Program Files:
[DirectAnimation Java Classes]
CODEBASE = file://C:\WINNT\Java\class
OSD = C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd
[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINNT\Java\class
OSD = C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd
[F1 Organizer Class]
InProcServer32 = C:\WINNT\System32\ATPART~1
CODEBASE = http://www.addictivetechnologies.net/DM0/cab/wzzp4.cab
[PCPitstop Utility]
InProcServer32 = C:\WINNT\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
[Installer Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\ISTactivex.dll
CODEBASE = http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
[HouseCall Control]
InProcServer32 = C:\WINNT\DOWNLO~1\xscan53.
CODEBASE =
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
[mhLabel Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\mhLbl.dll
CODEBASE = http://www.pcpitstop.com/mhLbl.cab
[ActiveScan Installer Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\asinst.dll
CODEBASE = http://www.pandasoftware.com/activescan/as5/asinst.cab
[SassCln Object]
InProcServer32 = C:\WINNT\Downloaded Program Files\SassCln.dll
CODEBASE = http://www.microsoft.com/security/controls/Sasser/20/SassCln.CAB
[CentraDownloaderCtl Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\CentraDownloader.dll
CODEBASE = http://batclass.icconsulting.com.au/SiteRoots/main/Install/CentraDownloader.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINNT\System32\macromed
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
--------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\Program Files\Aventail\Connect\asd
NameSpace #2: C:\WINNT\System32\mswsock.
NameSpace #3: C:\WINNT\System32\winrnr.d
NameSpace #4: C:\WINNT\System32\mswsock.
Protocol #1: C:\WINNT\system32\mswsock.
Protocol #2: C:\WINNT\system32\mswsock.
Protocol #3: C:\WINNT\system32\mswsock.
Protocol #4: C:\WINNT\system32\mswsock.
Protocol #5: C:\WINNT\system32\rsvpsp.d
Protocol #6: C:\WINNT\system32\rsvpsp.d
Protocol #7: C:\WINNT\system32\mswsock.
Protocol #8: C:\WINNT\system32\mswsock.
Protocol #9: C:\WINNT\system32\mswsock.
Protocol #10: C:\WINNT\system32\mswsock.
Protocol #11: C:\WINNT\system32\mswsock.
Protocol #12: C:\WINNT\system32\mswsock.
Protocol #13: C:\WINNT\system32\mswsock.
Protocol #14: C:\WINNT\system32\mswsock.
--------------------------
Enumerating Windows NT/2000/XP services
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Embedded Controller Driver: System32\DRIVERS\ACPIEC.sy
aeaudio: system32\drivers\aeaudio.s
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drive
Agere Systems Soft Modem: System32\DRIVERS\AGRSM.sys
Alerter: %SystemRoot%\System32\svch
Application Layer Gateway Service: %SystemRoot%\System32\alg.
Application Management: %SystemRoot%\system32\svch
Aventail Connect: C:\Program Files\Aventail\Connect\as3
Ascrypto: \??\C:\Program Files\Aventail\Connect\asc
Askernel: \??\C:\Program Files\Aventail\Connect\asn
Astdi: \??\C:\Program Files\Aventail\Connect\asn
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys
Ati HotKey Poller: %SystemRoot%\System32\Ati2
ati2mtag: System32\DRIVERS\ati2mtag.
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.s
Windows Audio: %SystemRoot%\System32\svch
Audio Stub Driver: System32\DRIVERS\audstub.s
Background Intelligent Transfer Service: %SystemRoot%\System32\svch
(manual start)
Computer Browser: %SystemRoot%\System32\svch
CD-ROM Driver: System32\DRIVERS\cdrom.sys
Indexing Service: %SystemRoot%\system32\cisv
ClipBook: %SystemRoot%\system32\clip
Microsoft AC Adapter Driver: System32\DRIVERS\CmBatt.sy
Microsoft Composite Battery Driver: System32\DRIVERS\compbatt.
COM+ System Application: C:\WINNT\System32\dllhost.
/Processid:{02D4B3F1-FD88-
Cryptographic Services: %SystemRoot%\system32\svch
Darpan: System32\DRIVERS\Darpan.sy
DAZEL Delivery Agent: DcPSI.exe (autostart)
DefWatch: C:\PROGRA~1\SYMANT~1\SYMAN
DHCP Client: %SystemRoot%\System32\svch
Disk Driver: System32\DRIVERS\disk.sys (system)
Diskeeper: C:\Program Files\Executive Software\DiskeeperWorkstat
(autostart)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmad
start)
dmboot: System32\drivers\dmboot.sy
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sy
Logical Disk Manager: %SystemRoot%\System32\svch
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sy
DNS Client: %SystemRoot%\System32\svch
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.s
Intel(R) PRO/1000 Adapter Driver: System32\DRIVERS\e1000325.
Error Reporting Service: %SystemRoot%\System32\svch
Event Log: %SystemRoot%\system32\serv
COM+ Event System: C:\WINNT\System32\svchost.
Fast User Switching Compatibility: %SystemRoot%\System32\svch
start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Volume Manager Driver: System32\DRIVERS\ftdisk.sy
Generic Packet Classifier: System32\DRIVERS\msgpc.sys
Help and Support: %SystemRoot%\System32\svch
Human Interface Device Access: %SystemRoot%\System32\svch
Microsoft HID Class Driver: System32\DRIVERS\hidusb.sy
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.
IBMPMDRV: System32\DRIVERS\ibmpmdrv.
IBM PM Service: %SystemRoot%\System32\ibmp
CD-Burning Filter Driver: System32\DRIVERS\imapi.sys
IMAPI CD-Burning COM Service: C:\WINNT\System32\imapi.ex
IntelIde: System32\DRIVERS\intelide.
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sy
IP Network Address Translator: System32\DRIVERS\ipnat.sys
IPSEC driver: System32\DRIVERS\ipsec.sys
IrDA Protocol: System32\DRIVERS\irda.sys (autostart)
IR Enumerator Service: System32\DRIVERS\irenum.sy
Infrared Monitor: %SystemRoot%\System32\svch
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sy
LanHound Filter: System32\DRIVERS\isproto.s
Keyboard Class Driver: System32\DRIVERS\kbdclass.
Keyboard HID Driver: System32\DRIVERS\kbdhid.sy
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sy
Server: %SystemRoot%\System32\svch
Workstation: %SystemRoot%\System32\svch
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svch
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
(autostart)
Messenger: %SystemRoot%\System32\svch
NetMeeting Remote Desktop Sharing: C:\WINNT\System32\mnmsrvc.
Mouse Class Driver: System32\DRIVERS\mouclass.
Mouse HID Driver: System32\DRIVERS\mouhid.sy
WebDav Client Redirector: System32\DRIVERS\mrxdav.sy
MRXSMB: System32\DRIVERS\mrxsmb.sy
Distributed Transaction Coordinator: C:\WINNT\System32\msdtc.ex
Windows Installer: C:\WINNT\System32\msiexec.
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.s
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys
Novell Application Launcher: C:\Program Files\Novell\ZENworks\naln
NAVAP: \??\C:\PROGRA~1\SYMANT~1\S
NAVAPEL: \??\C:\Program Files\Symantec_Client_Secu
(autostart)
NAVENG: \??\C:\PROGRA~1\COMMON~1\S
NAVEX15: \??\C:\PROGRA~1\COMMON~1\S
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.s
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.s
NetBIOS Interface: System32\DRIVERS\netbios.s
NetBios over Tcpip: System32\DRIVERS\netbt.sys
Network DDE: %SystemRoot%\system32\netd
Network DDE DSDM: %SystemRoot%\system32\netd
Net Logon: %SystemRoot%\System32\lsas
Network Connections: %SystemRoot%\System32\svch
NICM: System32\Drivers\Nicm.sys (system)
Network Location Awareness (NLA): %SystemRoot%\System32\svch
start)
Network Monitor Driver: System32\DRIVERS\NMnt.sys (manual start)
Symantec AntiVirus Client: C:\PROGRA~1\SYMANT~1\SYMAN
NSC Infrared Device Driver: System32\DRIVERS\nscirda.s
Novell Local Security Context Manager: \SystemRoot\System32\drive
(manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsas
Removable Storage: %SystemRoot%\system32\svch
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.
OracleOraHome92ClientCache
PalmUSBD: system32\drivers\PalmUSBD.
Parallel port driver: System32\DRIVERS\parport.s
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
Pcmcia: System32\DRIVERS\pcmcia.sy
Plug and Play: %SystemRoot%\system32\serv
IPSEC Services: %SystemRoot%\System32\lsas
WAN Miniport (PPTP): System32\DRIVERS\raspptp.s
Processor Driver: System32\DRIVERS\processr.
Novell ZfD Wake on LAN Status Agent: C:\Program
Files\Novell\ZENworks\Remo
Protected Storage: %SystemRoot%\system32\lsas
Direct Parallel Link Driver: System32\DRIVERS\ptilink.s
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sy
Remote Access Auto Connection Manager: %SystemRoot%\System32\svch
start)
WAN Miniport (IrDA): System32\DRIVERS\rasirda.s
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.s
Remote Access Connection Manager: %SystemRoot%\System32\svch
start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.
Direct Parallel: System32\DRIVERS\raspti.sy
Rdbss: System32\DRIVERS\rdbss.sys
RDPCDD: System32\DRIVERS\RDPCDD.sy
Terminal Server Device Redirector Driver: System32\DRIVERS\rdpdr.sys
Remote Desktop Help Session Manager: C:\WINNT\system32\sessmgr.
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.s
Novell ZfD Remote Management: C:\Program
Files\Novell\ZENworks\Remo
Routing and Remote Access: %SystemRoot%\System32\svch
Remote Registry: %SystemRoot%\system32\svch
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\loca
Remote Procedure Call (RPC): %SystemRoot%\system32\svch
QoS RSVP: %SystemRoot%\System32\rsvp
SafeBoot Configuration Manager: C:\Program Files\SafeBoot\SBMGRNT.EXE
Security Accounts Manager: %SystemRoot%\system32\lsas
SbcpHid: \??\C:\WINNT\System32\Driv
Smart Card Helper: %SystemRoot%\System32\SCar
Smart Card: %SystemRoot%\System32\SCar
Task Scheduler: %SystemRoot%\System32\svch
Secdrv: System32\DRIVERS\secdrv.sy
Secondary Logon: %SystemRoot%\System32\svch
System Event Notification: %SystemRoot%\system32\svch
Serenum Filter Driver: System32\DRIVERS\serenum.s
Serial port driver: System32\DRIVERS\serial.sy
Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS):
%SystemRoot%\System32\svch
Shell Hardware Detection: %SystemRoot%\System32\svch
ScriptLogic service: SLClient.exe (autostart)
Intel(R) SMBus 2.0 Driver: System32\DRIVERS\smb.sys (manual start)
smwdm: system32\drivers\smwdm.sys
Microsoft Kernel Audio Splitter: system32\drivers\splitter.
Print Spooler: %SystemRoot%\system32\spoo
System Restore Filter Driver: \SystemRoot\System32\DRIVE
System Restore Service: %SystemRoot%\System32\svch
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svch
Windows Image Acquisition (WIA): %SystemRoot%\System32\svch
Software Bus Driver: System32\DRIVERS\swenum.sy
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sy
MS Software Shadow Copy Provider: C:\WINNT\System32\dllhost.
/Processid:{06BEA234-9FA7-
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SY
Synaptics TouchPad Driver: System32\DRIVERS\SynTP.sys
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.
Performance Logs and Alerts: %SystemRoot%\system32\smlo
Telephony: %SystemRoot%\System32\svch
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys
Terminal Device Driver: System32\DRIVERS\termdd.sy
Terminal Services: %SystemRoot%\System32\svch
Themes: %SystemRoot%\System32\svch
Telnet: C:\WINNT\System32\tlntsvr.
Distributed Link Tracking Client: %SystemRoot%\system32\svch
Microcode Update Driver: System32\DRIVERS\update.sy
Upload Manager: %SystemRoot%\System32\svch
Universal Plug and Play Device Host: %SystemRoot%\System32\svch
(disabled)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.
Microsoft USB Generic Parent Driver: System32\DRIVERS\usbccgp.s
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.s
(manual start)
Microsoft USB Standard Hub Driver: System32\DRIVERS\usbhub.sy
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.S
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.s
(manual start)
VgaSave: \SystemRoot\System32\drive
vsdatant: \??\C:\WINNT\System32\vsda
TrueVector Internet Monitor: C:\WINNT\system32\ZoneLabs
Volume Shadow Copy: %SystemRoot%\System32\vssv
Windows Time: %SystemRoot%\System32\svch
Intel(R) PRO/Wireless 7100 Adapter Driver: System32\DRIVERS\w70n51.sy
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sy
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sy
WebClient: %SystemRoot%\System32\svch
Windows Management Instrumentation: %systemroot%\system32\svch
Portable Media Serial Number Service: %SystemRoot%\System32\svch
start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svch
netsvcs (manual start)
WMI Performance Adapter: C:\WINNT\System32\wbem\wmi
Automatic Updates: %systemroot%\system32\svch
Wireless Zero Configuration: %SystemRoot%\System32\svch
Novell XTier Authentication Service: \SystemRoot\System32\drive
start)
Workstation Manager: C:\Program Files\Novell\ZENworks\wm.e
--------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperation
--------------------------
Enumerating ShellServiceObjectDelayLoa
PostBootReminder: C:\WINNT\system32\SHELL32.
CDBurn: C:\WINNT\system32\SHELL32.
WebCheck: C:\WINNT\System32\webcheck
SysTray: C:\WINNT\System32\stobject
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
End of report, 35,064 bytes
Report generated in 0.100 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
--------------------------
Process Explorer log when the prob happend...
Process PID CPU Description Company Name
System Idle Process 0
Interrupts n/a Hardware Interrupts
DPCs n/a Deferred Procedure Calls
System 4 1
smss.exe 580 Windows NT Session Manager Microsoft Corporation
csrss.exe 644 1 Client Server Runtime Process Microsoft Corporation
winlogon.exe 668 Windows NT Logon Application Microsoft Corporation
services.exe 712 2 Services and Controller app Microsoft Corporation
ibmpmsvc.exe 904
svchost.exe 940 94 Generic Host Process for Win32 Services Microsoft Corporation
hpgs2wnf.exe 3600 hpgs2wnf Module
svchost.exe 1168 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1180 Generic Host Process for Win32 Services Microsoft Corporation
spoolsv.exe 1392 Spooler SubSystem App Microsoft Corporation
cusrvc.exe 1664 Novell Client Update Service Novell, Inc.
DcPSI.exe 1680
DKService.exe 1696 DKSERVICE.EXE Executive Software International, Inc.
mdm.exe 1728 Machine Debug Manager Microsoft Corporation
NALNTSRV.EXE 1752 NT Service for Novell Application Launcher (ZENLITE) Novell, Inc.
Rtvscan.exe 1856 Symantec AntiVirus Symantec Corporation
PCAHelper.exe 1900 PCAHelper Module SYMON Communications, Inc.
WolSerNT.exe 1924 Novell ZFD Wake on Lan Status Agent Novell Inc.
ZenRem32.exe 1944 Novell ZEN Remote Management Agent Novell Inc.
locator.exe 2044 Rpc Locator Microsoft Corporation
sbmgrnt.exe 132 SafeBoot Configuration Manager for NT Control Break International
SLClient.exe 184 SLServer ScriptLogic Corporation
svchost.exe 244 Generic Host Process for Win32 Services Microsoft Corporation
vsmon.exe 280 TrueVector Service Zone Labs Inc.
winvnc.exe 416 VNC server for Win32 RealVNC Ltd.
WM.EXE 448 ZEN for Desktops Workstation Manager Novell, INC.
WMRUNDLL.EXE 1060 ZEN for Desktops Helper DLL Processor Novell, INC.
svchost.exe 1076 Generic Host Process for Win32 Services Microsoft Corporation
dllhost.exe 2844 COM Surrogate Microsoft Corporation
msiexec.exe 436 Windows® installer Microsoft Corporation
lsass.exe 724 LSA Shell (Export Version) Microsoft Corporation
explorer.exe 2336 Windows Explorer Microsoft Corporation
tp4mon.exe 2500 IBM PS/2 TrackPoint Application IBM Corporation
DcDaemon.exe 2528 DAZEL Delivery Agent Hewlett-Packard Company
wKiX32.exe 2360 KiXtart main executable Ruud van Velsen (Microsoft)
OdPlayer.exe 2156 OnDemand Player Global Knowledge, Inc.
VPTray.exe 2688 Symantec AntiVirus Symantec Corporation
TPHKMGR.exe 2780
TPONSCR.exe 2848
nwtray.exe 3112 Novell System Tray Icon Novell, Inc.
hpgs2wnd.exe 3192 hpgs2wnd Hewlett-Packard
ctfmon.exe 3200 CTF Loader Microsoft Corporation
NALDESK.EXE 3664 ZENworks Application Explorer Executable Novell, Inc
HOTSYNC.EXE 240 HotSync® Manager Application Palm, Inc.
procexp.exe 1976 2 Sysinternals Process Explorer Sysinternals
MPSRPT_SETUPPerf.EXE 3228 MPS Reporting Tool for Setup and Performance Support Microsoft Corporation
cmd.exe 2452 Windows Command Processor Microsoft Corporation
msinfo32.exe 784 System Information Microsoft Corporation
cmd.exe 2140 Windows Command Processor Microsoft Corporation
cscript.exe 2696 Microsoft (r) Console Based Script Host Microsoft Corporation
cmd.exe 3000 Windows Command Processor Microsoft Corporation
tlist.exe 2912 Microsoft® Process List Utility Microsoft Corporation
autokr.exe 4088 Auto Kernrate Tool
cmd.exe 232 Windows Command Processor Microsoft Corporation
CheckSym.exe 1296 Symbol Collection and Verification Process Microsoft Corporation
wuauclt.exe 2852 Windows Update AutoUpdate Client Microsoft Corporation
Process: svchost.exe Pid: 940
Type Name
Thread svchost.exe(940): 980
Thread svchost.exe(940): 980
Thread svchost.exe(940): 980
Thread svchost.exe(940): 976
Thread svchost.exe(940): 976
Thread svchost.exe(940): 948
Thread svchost.exe(940): 948
Thread svchost.exe(940): 944
Thread svchost.exe(940): 3616
Thread svchost.exe(940): 3492
Thread svchost.exe(940): 3476
Thread svchost.exe(940): 2896
Thread svchost.exe(940): 2804
Thread svchost.exe(940): 2748
Thread svchost.exe(940): 2644
Thread svchost.exe(940): 2404
Thread svchost.exe(940): 228
Thread svchost.exe(940): 2200
Thread svchost.exe(940): 1484
Thread svchost.exe(940): 1376
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\SYSTEM
Token NT AUTHORITY\LOCAL SERVICE
Process hpgs2wnf.exe(3600)
Key HKU
Key HKU
Key HKU
Key HKU
Key HKLM\SYSTEM\ControlSet001\
Key HKLM\SYSTEM\ControlSet001\
Key HKLM\SYSTEM\ControlSet001\
Key HKLM\SYSTEM\ControlSet001\
Key HKLM\SYSTEM\ControlSet001\
Key HKLM\SYSTEM\ControlSet001\
Key HKLM\SOFTWARE\Microsoft\Ol
Key HKLM\SOFTWARE\Microsoft\CO
Key HKLM\SOFTWARE\Microsoft\CO
Key HKLM\SOFTWARE\Microsoft\CO
Key HKLM\SOFTWARE\Microsoft\CO
Key HKLM\SOFTWARE\Microsoft\CO
Key HKLM\SOFTWARE\Microsoft\CO
Key HKLM
Key HKCU\Software\Classes
Key HKCR\CLSID
Key HKCR\CLSID
Key HKCR\CLSID
Key HKCR\AppID
Key HKCR
Key HKCR
Key HKCR
Key HKCR
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
Token CA\cdagenai
File C:\WINNT\system32
WindowStation \Windows\WindowStations\Se
WindowStation \Windows\WindowStations\Se
Directory \Windows
Port \RPC Control\epmapper
Directory \KnownDlls
KeyedEvent \KernelObjects\CritSecOutO
File \Dfs
File \Device\Udp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\Tcp
File \Device\NwlnkSpx\Stream
File \Device\NamedPipe\Winsock2
File \Device\NamedPipe\svcctl
File \Device\NamedPipe\net\NtCo
File \Device\NamedPipe\epmapper
File \Device\NamedPipe\epmapper
File \Device\KsecDD
File \Device\Ip
File \Device\Ip
File \Device\Ip
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
File \Device\Afd\Endpoint
Desktop \Default
Event \BaseNamedObjects\userenv:
Section \BaseNamedObjects\ShimShar
Mutant \BaseNamedObjects\ShimCach
Event \BaseNamedObjects\ScmCreat
Section \BaseNamedObjects\RotHintT
Mutant \BaseNamedObjects\{02D4B3F
Section \BaseNamedObjects\__R_0000
Directory \BaseNamedObjects
Thank you in advance... Any advice will be appreciated.
"The moment this event happensl, the desktop taskbar freezes completly"
When does this happen, the second the computer is started up, or after it has run a while? Also, does the same thing happen in safe mode? How do you know that you can not start any more apps on the desktop computers?
kyledude
When does this happen, the second the computer is started up, or after it has run a while? Also, does the same thing happen in safe mode? How do you know that you can not start any more apps on the desktop computers?
kyledude
I'm not familiar with this one:
C:\WINNT\system32\DcPSI.ex e
is that part of DAZEL? what is DAZEL anyway?
C:\WINNT\system32\DcPSI.ex
is that part of DAZEL? what is DAZEL anyway?
You are totally focussed on service host -- and all that is is a major windows task director to execute tasks that other modules call on service host to do the work -- like kernel32, it is the central workhorse that runs processes.
If you forget ALL the logs, realize that service host is nothing more than a butler that serves up stuff for other people -- and if you rephrase your question about what is really going on when the system freezes, we may be able to help you. At present, I see no way of helping you, without a clearer explanation of exactly what is happening.
If you forget ALL the logs, realize that service host is nothing more than a butler that serves up stuff for other people -- and if you rephrase your question about what is really going on when the system freezes, we may be able to help you. At present, I see no way of helping you, without a clearer explanation of exactly what is happening.
ASKER
Thanks for the feedback guys... To anwser to some of your questions...
-It happen ramdomly on any PC... lap/desktop... while users are working, could be at any time... 5 min after login on the domain or 6 hours after... No apps could be pinpoint at this moment....
-Dazel is our IP printer services...
-Its RPCss that run under svchost.exe that looks to crash... regardless of the logs...
-Why delete winhelp.hlp btw... ??? just curious...
To give you more info...
This bug could appear 6 times on the same PC a day, and the same PC won't have any probs for the nest week, then could crash again...
If you have any clear/specific questions... feel free.
-It happen ramdomly on any PC... lap/desktop... while users are working, could be at any time... 5 min after login on the domain or 6 hours after... No apps could be pinpoint at this moment....
-Dazel is our IP printer services...
-Its RPCss that run under svchost.exe that looks to crash... regardless of the logs...
-Why delete winhelp.hlp btw... ??? just curious...
To give you more info...
This bug could appear 6 times on the same PC a day, and the same PC won't have any probs for the nest week, then could crash again...
If you have any clear/specific questions... feel free.
I encountred once in the same malfunction... The same symptoms. I reneamed winhelp.hlp to *.old and restarted the OS causing it to restore the file from system backup. I guess it is somthing to do a link made by SVCHOST process and the winhelp.hlp.
So, Just try to rename it in safe mode and restart your computer... If it wont help... it wont do any harm
Good luck
Cyber
So, Just try to rename it in safe mode and restart your computer... If it wont help... it wont do any harm
Good luck
Cyber
Hey look at this -- couple of these boards at super low prices. They may climb as the come to a close, but now --
http://search.ebay.com/ASUS-P4T-E_Desktop-PC-Components_W0QQbsZSearchQQcatrefZC6QQfromZR2QQsacategoryZ3667QQsatitle
ZASUSQ20P4TQ2dEQQsbrftogZ1 QQsocolumn layoutZ3QQ sofocusZbs QQsorecord sperpageZ5 0QQsosorto rderZ1QQso sortproper tyZ1
Piece that back into a single line, and it will give you a link to the same MBs, below $50.
http://search.ebay.com/ASUS-P4T-E_Desktop-PC-Components_W0QQbsZSearchQQcatrefZC6QQfromZR2QQsacategoryZ3667QQsatitle
ZASUSQ20P4TQ2dEQQsbrftogZ1
Piece that back into a single line, and it will give you a link to the same MBs, below $50.
Oops sorry posted to the wrong thread, this is a problem with the current questioner name baing unreadable.
Just ignore post above, please.
Just ignore post above, please.
Sorry for the above mess, itcantam, EE has been changing the headers on these questions, and it is very hard right now to keep track of things.
I have a suggestion you could try -- and it might take a day or two to test it out, but it might be the only way you will narrow this bug --
1. When this happens, do control-alt-delete and go to the processes tab of task manager. There will normally be 2 service host instances for the system, one for the network, and one for local service, about halfway down. There may be one or two higher up. If there are any right at the top, close windows by right clicking on each in the task bar -- see which processes go away that you can't identify by windows on the task bar. That will tell you which app is spawning the process.
2. You should also check the server this way too, without closing the processes.
3. Kill the Dazel print service on the printer (with queues) long enough to determine if that is/is not the problem.
4. Cyber's fix looks interesting -- he always comes up with original ideas -- try it !!
I have a suggestion you could try -- and it might take a day or two to test it out, but it might be the only way you will narrow this bug --
1. When this happens, do control-alt-delete and go to the processes tab of task manager. There will normally be 2 service host instances for the system, one for the network, and one for local service, about halfway down. There may be one or two higher up. If there are any right at the top, close windows by right clicking on each in the task bar -- see which processes go away that you can't identify by windows on the task bar. That will tell you which app is spawning the process.
2. You should also check the server this way too, without closing the processes.
3. Kill the Dazel print service on the printer (with queues) long enough to determine if that is/is not the problem.
4. Cyber's fix looks interesting -- he always comes up with original ideas -- try it !!
ASKER
I will try to delete the hlp asap to see if it could fix this prob...
The thing is once the "bug" happen... We can't do nothing but alt-tab... Not even open Task manager...
We do have now some desktop setup with (FileMon, RegMon, Task Managerk, Process Explorer and a command prompt) open, and ask the users to work with this open... and I just wish that it will ahppen again on those ;)
I already try to kill all task one by one... The only one that brings me back my taskbar was by kill the svchost.exe hosting rpcss, but I had to kill it 5 times before that happen... And I still wait for another PC to crash to do it again to see if I delete only this one if it will have the same effect...
I will came back with news by tomorrow once trying all this.
Thanks again.
The thing is once the "bug" happen... We can't do nothing but alt-tab... Not even open Task manager...
We do have now some desktop setup with (FileMon, RegMon, Task Managerk, Process Explorer and a command prompt) open, and ask the users to work with this open... and I just wish that it will ahppen again on those ;)
I already try to kill all task one by one... The only one that brings me back my taskbar was by kill the svchost.exe hosting rpcss, but I had to kill it 5 times before that happen... And I still wait for another PC to crash to do it again to see if I delete only this one if it will have the same effect...
I will came back with news by tomorrow once trying all this.
Thanks again.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
<< We can't do nothing but alt-tab... Not even open Task manager...>>
ALMOST CERTAINLY A VIRUS OR WORM !!
DO EXTENSIVE VIRUS SCANS -- www.trendmicro.com -- online scanner.
Once cleaned, if this persists, reinstall is needed.
ALMOST CERTAINLY A VIRUS OR WORM !!
DO EXTENSIVE VIRUS SCANS -- www.trendmicro.com -- online scanner.
Once cleaned, if this persists, reinstall is needed.
ASKER
We did try trendsmicro, stinger of McAfee... Nothing found as virus...
IF we kill one the the svchost.exe, everything came back to normal... But I know its not RPCss, neither the DNS one... Have to focus on the 2 others to see witch one after we kill it gave us back the control, I'll let you know.
IF we kill one the the svchost.exe, everything came back to normal... But I know its not RPCss, neither the DNS one... Have to focus on the 2 others to see witch one after we kill it gave us back the control, I'll let you know.
Hmmm....
Found something. i didnt try it my-self but it sounds promising...
http://www.stiller.com
Tell me if you wish to implement it on your computer and how it worked...
Cyber
Found something. i didnt try it my-self but it sounds promising...
http://www.stiller.com
Tell me if you wish to implement it on your computer and how it worked...
Cyber
Itcantam -- If it is the network process you have to kill, that might you are being probed. Have you gone to your firewall and made sure it is tight?
Go to www.grc.com -- wade through some pages looking for "probe my ports" -- Gibson's site is a great way to test your firewall -- as long as everything comes up stealth, you are safe -- and yes, you can test it from a WS, as all it probes is the WAN IP -- main firewall.
Go to www.grc.com -- wade through some pages looking for "probe my ports" -- Gibson's site is a great way to test your firewall -- as long as everything comes up stealth, you are safe -- and yes, you can test it from a WS, as all it probes is the WAN IP -- main firewall.
ASKER
Oki... I did try the renaming of the winhlp32.hlp...
I know now for sure...
That if I kill the svchost.exe that host (Audiosrv, dhcp, messenger, browser, help + support...), I gain back the control over the PC, Start menu work... only thing is that prcss is now takin 100% of CPU... ;)
We did run all anti-virus possible without succes... look like we did create our onw one :( hehe
All this happen when we began to pahse out our Novell environment (IPX) to go full IP.
Thanks
I know now for sure...
That if I kill the svchost.exe that host (Audiosrv, dhcp, messenger, browser, help + support...), I gain back the control over the PC, Start menu work... only thing is that prcss is now takin 100% of CPU... ;)
We did run all anti-virus possible without succes... look like we did create our onw one :( hehe
All this happen when we began to pahse out our Novell environment (IPX) to go full IP.
Thanks
<< All this happen when we began to pahse out our Novell environment (IPX) to go full IP >>
Wish you had said that a long while ago. Is the novell now gone, or still on line?
<< only thing is that prcss is now takin 100% of CPU >>
Which process?
Wish you had said that a long while ago. Is the novell now gone, or still on line?
<< only thing is that prcss is now takin 100% of CPU >>
Which process?
Are you using GroupWise?
Cyber
Cyber
Hi,
try the following: update all critical patches using windows update
i am almost sure its virus attacks,
virus is not infecting you, but doing smth like DDoS
thats why cpu is ~95-100%
Also check your local network for viruses
try the following: update all critical patches using windows update
i am almost sure its virus attacks,
virus is not infecting you, but doing smth like DDoS
thats why cpu is ~95-100%
Also check your local network for viruses
ASKER
Hey guys... guess what???
Still have to be tested, our virus came from this article... ;)
http://support.novell.com/cgi-bin/search/searchtid.cgi?/10092225.htm
Have a look, we did upgrade/remove some of our Zen Agent to see if the prob will appear again... But I really doubt.
Woup woup woup... Novell again!!! Just bad luck after bad luck with this F***** agent... We still wait for the "Midas" version of it...
Have a nice week-end and thx to all for the help on this issue... We will have to wait a week or so to see if the symptoms is really dead... I will keep you post.
Still have to be tested, our virus came from this article... ;)
http://support.novell.com/cgi-bin/search/searchtid.cgi?/10092225.htm
Have a look, we did upgrade/remove some of our Zen Agent to see if the prob will appear again... But I really doubt.
Woup woup woup... Novell again!!! Just bad luck after bad luck with this F***** agent... We still wait for the "Midas" version of it...
Have a nice week-end and thx to all for the help on this issue... We will have to wait a week or so to see if the symptoms is really dead... I will keep you post.
It's probably a courtesy to all the people who put in time to assign points now to the most accurate answer that led to finding the fix, or else SPLIT points among the answers you feel helped the most get you there. If the problem continues, you can always ask another Q later. They become old after 2-5 days :)))
We're all glad you found it!!
We're all glad you found it!!
Hi,
Try using the task command to view what service inside the svhost may be causing the crash. I managed to resolve this on a few machines by disabling ctfmon.exe, (there is a worm that kills the ctfmon and takes its identity) however I dont know if this is relevant or not in your case.
In command prompt type:
tasklist /svc
You will then be able to see inside so to speak and something may stand out.
Try using the task command to view what service inside the svhost may be causing the crash. I managed to resolve this on a few machines by disabling ctfmon.exe, (there is a worm that kills the ctfmon and takes its identity) however I dont know if this is relevant or not in your case.
In command prompt type:
tasklist /svc
You will then be able to see inside so to speak and something may stand out.
Uninstall the Indexing service and reinstall. It is in add/remove problems. If that doesn't work (it should) then follow the next step..If this is a sony laptop reply back to me because i will give you a link to the fix for it. It is a known issue with the sony laptop with cpu running at 100% because of svchost.exe. They put out a fix for it..
if you installed any applications recently, more than likely it will be the cause, even updates. i remember that after installing a service pack svchost was running like a killer...97% cpu time, etc. eventually i ended up unistalling the apps and the service pack. then my system was working like a charm. i realised that you're running a os like windows nt or windows 2000 due to %winnt% mentioned. i would suggest that you check to see if the apps are compatible with the os. and also check services to see if there are any unneccessary services starting up.
Cyber