Computers |
|
| | #1 (permalink) |
| Newb Techie | When I check my processes, explorer is running at 170,000 K + most of the time. That is abnormally high. Here is my HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:18:55 AM, on 6/30/2008 Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3264) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\PeerGuardian2\pg2.exe C:\Program Files\Sizer\sizer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe C:\Program Files\twhirl\twhirl.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\Grisoft\AVG7\avgw.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - Global Startup: Sizer (2).lnk = C:\Program Files\Sizer\sizer.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Yahoo! Pool 2 - http://origin.games.yahoo.net/games/...s/y/poti_x.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1196117104849 O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O24 - Desktop Component 1: (no name) - Netvibes -- End of file - 4401 bytes ---------------- Now playing: Death Cab for Cutie - Styrofoam Plates via FoxyTunes Last edited by Mak213; 06-30-2008 at 08:29 PM. |
| |
| | #2 (permalink) |
| Commander Super Mod Joker Join Date: Sep 2004 Location: In Trotter's crawl space
Posts: 15,589
| Hello Do you know what twhirl.exe is? From my research it shows that it can be a legit app but it also is shown as a virus. So did you install this yourself? If not then we have some work to do. Cheers, Mak |
| |
| | #3 (permalink) | |
| Newb Techie | Quote:
295,000 K now! Last edited by Mak213; 07-01-2008 at 08:07 AM. | |
| |
| | #4 (permalink) |
| Commander Super Mod Joker Join Date: Sep 2004 Location: In Trotter's crawl space
Posts: 15,589
| Hello, Okay do this then. Download ComboFix from Here or Here to your Desktop. Read first: "How to download and use ComboFix" If you downloaded ComboFix previously, delete that version and download it again as the tool is frequently updated!
Extra-Note: Please, DO NOT use ComboFix on your own. It is a very powerful tool designed to deal with sophisticated infections and if something goes wrong or you use it incorrectly, you could possibly lose the use of your computer. It is ONLY meant to be used under the direct supervision of a malware removal specialist. Please read Combofix's Disclaimer Logs needed in next post: ComboFix Cheers, Mak |
| |
| | #5 (permalink) | |
| Newb Techie | Quote:
| |
| |
| | #6 (permalink) |
| Commander Super Mod Joker Join Date: Sep 2004 Location: In Trotter's crawl space
Posts: 15,589
| Hello, You can go to some experts over at GTG. They have a special training course and fully trained experts to work with you if you trust that more. I suggest you take your log to the malware doctors found in this forum. Please make sure that you read this before posting anything in the malware forum. If you're still having problems after the malware doctors declare your log clean feel free to post back here and we'll help you to the best of our knowledge! ![]() Cheers, Mak |
| |
| | #7 (permalink) | |
| Newb Techie | Quote:
I was wondering. Could it be Windows SP3 that is causing it? If so, how can I downgrade to SP1 or SP2? | |
| |
| | #8 (permalink) |
| Commander Super Mod Joker Join Date: Sep 2004 Location: In Trotter's crawl space
Posts: 15,589
| Hello, I have been using XP SP3 since it was Beta and i have never experienced anything like this. I have seen reports of it but i can not say for sure if it is or isnt as i could never reproduce the issues they were having. Your Welcome for the reference. If you are going to continue with them i will move this to the finished area. ![]() Cheers, Mak |
| |
| | #9 (permalink) | |
| Newb Techie | Quote:
What ya think? | |
| |
| | #10 (permalink) |
| Commander Super Mod Joker Join Date: Sep 2004 Location: In Trotter's crawl space
Posts: 15,589
| Hello, I would go with SP2. That makes Windows the 2nd most secure it can be. MacBooks are good. I know a few people that do what you are talking about and i think it is a great idea. Moved. Cheers, Mak |
| |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Explorer.exe CRASHES INSTANTLY =( [F] | wootwoot | HijackThis Logs (finished) | 28 | 07-15-2008 01:47 PM |
| explorer.exe running a max fever of 170,000 K | DMcLaughlin | Windows Operating Systems and Software | 6 | 07-01-2008 04:17 AM |
| New Q6600 running VERY hot | immy3 | Overclocking, Case Mod, Tweaking PC Performance | 31 | 06-02-2008 07:37 PM |
| Desktop icons and processes not running.. | Manhuntkotor | Hardware Troubleshooting | 1 | 09-16-2007 10:46 PM |
| Am I running to hot? | AuThoRitY | Hardware Troubleshooting | 5 | 07-30-2007 02:59 AM |