| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
06-Oct-2009, 02:18 PM
#1 |
| Infected? Avira wouldn't update and other protection shutting down. Hey there! I would like some help, please. I'm having an issue with my PC. I have an Acer Aspire M1640 running Vista Home Basic with a 32 bit OS w/ 2GB of RAM Last week, Avira AntiVir Personal found a trojan and it was quarantined and deleted. Sorry but I don't have info about what it was. The Comp was working just fine before and after that but maybe something else was left behind? This past weekend my housemate went on some poker sites and I don't know where else. The next day, the PC was slow and became slower and slower. I wasn't able to update Avira, and A2 Free and Gmer were shutting down a few minutes into scanning. When trying to run these applications, they would stall and my screen would flicker on and off. I wasn't able to shutdown my computer either. I had to unplug it. Bah! I restarted in safe mode and ran Avira, A-squared free, Malwarebytes anti-malware, SUPERAnti-spyware, and IObit 360. Nothing showed up. My PC is supposedly clean! Avira would still not update so I uninstalled and re-installed and now it will update but finds no virus. I'm thinking that re-installation might have been a mistake but it seemed logical to my frazzled mind at 3am in the morning. Now, I'm not even an Intermediate user but I'm not a complete newbie either. When I can't update my protection and my Comp is running slow but I have lots of memory left, I assume there is something dirty running and I look for it. I've gone as far as I can with my limmited knowledge and I'd appreciate any help I can get. I don't know what else to do. Could it be that my protection programs are interfering with eachother? Please help! This is my IObit 360 HijackThis log from yesterday: Logfile of IObit HijackScan v1.0.0.0 Scan saved at 13:3:1, on 2009-10-5 Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Program Files\a-squared Free\a2service.exe C:\Acer\Empowering Technology\ePerformance\MemCheck.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe C:\Windows\system32\svchost.exe C:\Program Files\IObit\IObit Security 360\IS360srv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Cyberlink\Shared files\RichVideo.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\SearchIndexer.exe C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Acer\Empowering Technology\SysMonitor.exe C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe C:\Windows\System32\nvraidservice.exe C:\Windows\System32\rundll32.exe C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Windows\System32\wpcumi.exe C:\Program Files\IObit\IObit Security 360\is360tray.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\System32\rundll32.exe C:\Windows\system32\wuauclt.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\sdclt.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Windows\system32\rundll32.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\IObit\IObit Security 360\is360.exe C:\Program Files\Avira\AntiVir Desktop\avcenter.exe C:\Program Files\IObit\IObit Security 360\a_hijackscan.exe O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: KeyScramblerBHO Class - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [SmartRAM] "C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [PCMService] "C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe" O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [NVRaidService] C:\Windows\system32\nvraidservice.exe O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [WPCUMI] C:\Windows\system32\WpcUmi.exe O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}Java Plug-in 1.6.0_11 - http://java.sun.com/update/1.6.0/jin...ndows-i586.cab O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: Apple Mobile Device (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: DCOM Server Process Launcher (DcomLaunch) - Unknown - O23 - Service: Diagnostic Policy Service (DPS) - Unknown - O23 - Service: eDataSecurity Service (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: Group Policy Client (gpsvc) - Unknown - O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Windows CardSpace (idsvc) - Unknown - %systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe O23 - Service: iPod Service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IS360service (IS360service) - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Net.Tcp Port Sharing Service (NetTcpPortSharing) - Unknown - %systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe O23 - Service: Quality Windows Audio Video Experience (QWAVE) - Unknown - %windir%\system32\svchost.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown - C:\Program Files\Cyberlink\Shared files\RichVideo.exe O23 - Service: Roxio UPnP Renderer 9 (Roxio UPnP Renderer 9) - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 (Roxio Upnp Server 9) - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe O23 - Service: RoxMediaDB9 (RoxMediaDB9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown - O23 - Service: Security Accounts Manager (SamSs) - Unknown - O23 - Service: Secondary Logon (seclogon) - Unknown - %windir%\system32\svchost.exe O23 - Service: Distributed Link Tracking Client (TrkWks) - Unknown - O23 - Service: Windows Modules Installer (TrustedInstaller) - Unknown - O23 - Service: Diagnostic Service Host (WdiServiceHost) - Unknown - O23 - Service: Diagnostic System Host (WdiSystemHost) - Unknown - O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown - %ProgramFiles%\Windows Media Player\wmpnetwk.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe Thanks Argh! update! 82% of my CPU is now in use!!!! Glllltht! Arckkk! Iccck! Last edited by whirlinggirl; 07-Oct-2009 at 05:11 AM.. Reason: 82% CPU being used!!!! |
| Tags |
| infected, malware, spyware |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 05:23 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

