Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > PC Technology Zone > Windows Operating Systems and Software » Vista 32bit home has sprung a leak pls Hyjackthis log
Reply
Old 10-24-2009, 03:53 PM   #1 (permalink)
patonb's Avatar
 
Master Techie

Join Date: Jan 2005

Location: In Gov't Regulated Cubical

Posts: 2,773

patonb has a spectacular aura aboutpatonb has a spectacular aura about

Default Vista 32bit home has sprung a leak pls Hyjackthis log

This is a sorta build on my mommys webcam issue... I reformated/usefd the recovery partion to redo windows.
Got the cam back, but a problem has come up now of running out of ram.

Its a acer lappy with 3Gig of ram. When you boot it up, there will be 1400Meg free, and you can watch it slowly tick down till free becom 0Meg, and 2000 cache
Now the intresting thing is it says in task manager its using only 42% of physical ram. I memtested with 0 errors, only 1 pass though.

I've looked at all processes and it doesnt look like theres aqnything up gobs of memory, and only 85 processes.

Any help narrowing a leak down??

I'm adding a hyjack this too, just incase, but its only a week old on the vista reinstall.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:56:51 PM, on 24/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\liz\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EX E
C:\Program Files\Acer\Acer VCM\VC.exe
C:\Program Files\Acer\Acer VCM\acp2HID.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\liz\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo! Canada
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Yahoo! Canada
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Sympatico.ca – Where Canadians start their day
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo! Canada
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo! Canada
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Yahoo! Canada
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
O4 - HKLM\..\Run: [SetSpeaker] C:\Windows\SetSpkDefault.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'Default user')
O4 - Startup: Acer Product Registration.lnk = C:\Program Files\Acer Registration\ACE1.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8750 bytes
__________________
Intel Q6600 g0 @ 3.2Ghz Turniq 120 Heatsink BFG 260 OC MaxCore (core 216) + xfx GTX 260 (core 216)
2x2gb OCZ Platinums XFX 680i motherboard Silverstone DA700 Antec 900
16,412 3dmark06 score


Foldie = e2180 Asus pq5-n SLI 8800gt T-rad cooler (710/1836/1010) 1Gig RAM
TOTAL
patonb is offline   Reply With Quote
Old 10-24-2009, 04:32 PM   #2 (permalink)
Mak213's Avatar
 

Join Date: Sep 2004

Location: C:\Windows\System32

Posts: 25,723

Mak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to all

Default Re: Vista 32bit home has sprung a leak pls Hyjackthis log

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Sympatico.ca – Where Canadians start their day
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

The first one only remove if you dont know what it is. The others are unnecessary. Have you run Combofix and MBAM yet? Have you installed MSE? I would at least run CF and MBAM and post up those logs as well for analysis.
__________________
R.I.P. Danny L. Trotter
14 Nov 1945 - 4 Sept 2009
Images created by CarnageX | Decaptured...Listen! | Visit Baezware!! | You've been Mak'd! | 儿做好
I do not accept support questions via EMail, PM, IM or my Spaces page! .:|:. This is what happens when an unstoppable force meets an immovable object.
Thanks to all the guys on the staff for your support in my time of need. Hefe you are my personal Hero for your contribution.



<<<< If I help you, or you just like what I said, rep me
Mak213 is online now   Reply With Quote
Old 10-24-2009, 04:38 PM   #3 (permalink)
patonb's Avatar
 
Master Techie

Join Date: Jan 2005

Location: In Gov't Regulated Cubical

Posts: 2,773

patonb has a spectacular aura aboutpatonb has a spectacular aura about

Default Re: Vista 32bit home has sprung a leak pls Hyjackthis log

yha.. the canadian is as I'm way up ear in da froozen nord eh...... Its just msn.ca, but the cdn name.
Thought though the other 2 too.

Like I had said... I reinstalled vista, and later that day it started.. This happened 4 months ago too, but my mother said it fixed after reinsalling norton and mbam.

Think it's possible a virus made it through the reinstall?

I'll run the other 2 aswell..
__________________
Intel Q6600 g0 @ 3.2Ghz Turniq 120 Heatsink BFG 260 OC MaxCore (core 216) + xfx GTX 260 (core 216)
2x2gb OCZ Platinums XFX 680i motherboard Silverstone DA700 Antec 900
16,412 3dmark06 score


Foldie = e2180 Asus pq5-n SLI 8800gt T-rad cooler (710/1836/1010) 1Gig RAM
TOTAL
patonb is offline   Reply With Quote
Old 10-24-2009, 06:00 PM   #4 (permalink)
Mak213's Avatar
 

Join Date: Sep 2004

Location: C:\Windows\System32

Posts: 25,723

Mak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to all

Default Re: Vista 32bit home has sprung a leak pls Hyjackthis log

Well the first thing that should be done after a install, especially a Windows one, is to get a AV installed.

MSE, AVG, Avast, Avira are all free. MSE has found soem stuff that even MBAM has missed.

I would suggest a scan with the guide, then next time, make sure that you have it disconnected from the net for the install and use a Flash Drive to put on a AV right away. Then hook it up to the net for updates after. Best way to stay protected. It could have easily gotten infected that fast after a install. It is Windows after all.
__________________
R.I.P. Danny L. Trotter
14 Nov 1945 - 4 Sept 2009
Images created by CarnageX | Decaptured...Listen! | Visit Baezware!! | You've been Mak'd! | 儿做好
I do not accept support questions via EMail, PM, IM or my Spaces page! .:|:. This is what happens when an unstoppable force meets an immovable object.
Thanks to all the guys on the staff for your support in my time of need. Hefe you are my personal Hero for your contribution.



<<<< If I help you, or you just like what I said, rep me
Mak213 is online now   Reply With Quote
Old 10-24-2009, 06:14 PM   #5 (permalink)
 
Monster Techie

Join Date: Feb 2005

Posts: 1,611

mikee is on a distinguished road

Default Re: Vista 32bit home has sprung a leak pls Hyjackthis log

Maybe the recovery partition got infected so loading the recovery image would load the infection back up as well. I had this happen with a friends dell a while back. Make sure what ever AV you use is set to scan the recovery partition as well in its scan.
__________________
My Rig

Intel core 2 duo E4300
2GB ram
120 gb HDD, 1.5TB HDD
LG DVD burner
BFG 8600 GTS OC'd
mikee is offline   Reply With Quote
Old 10-24-2009, 06:18 PM   #6 (permalink)
patonb's Avatar
 
Master Techie

Join Date: Jan 2005

Location: In Gov't Regulated Cubical

Posts: 2,773

patonb has a spectacular aura aboutpatonb has a spectacular aura about

Default Re: Vista 32bit home has sprung a leak pls Hyjackthis log

Yha, saddly, norton was on last.. had to d/l the sp's before installing.. was smart as i d/l'd the sps and saved to the d drive.
MBAM was on right away though...

Ah well, will have to wait til they get home to get the scans.
__________________
Intel Q6600 g0 @ 3.2Ghz Turniq 120 Heatsink BFG 260 OC MaxCore (core 216) + xfx GTX 260 (core 216)
2x2gb OCZ Platinums XFX 680i motherboard Silverstone DA700 Antec 900
16,412 3dmark06 score


Foldie = e2180 Asus pq5-n SLI 8800gt T-rad cooler (710/1836/1010) 1Gig RAM
TOTAL
patonb is offline   Reply With Quote
Old 10-24-2009, 06:37 PM   #7 (permalink)
Mak213's Avatar
 

Join Date: Sep 2004

Location: C:\Windows\System32

Posts: 25,723

Mak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to all

Default Re: Vista 32bit home has sprung a leak pls Hyjackthis log

MBAM isnt protection. It is more for removal.
__________________
R.I.P. Danny L. Trotter
14 Nov 1945 - 4 Sept 2009
Images created by CarnageX | Decaptured...Listen! | Visit Baezware!! | You've been Mak'd! | 儿做好
I do not accept support questions via EMail, PM, IM or my Spaces page! .:|:. This is what happens when an unstoppable force meets an immovable object.
Thanks to all the guys on the staff for your support in my time of need. Hefe you are my personal Hero for your contribution.



<<<< If I help you, or you just like what I said, rep me
Mak213 is online now   Reply With Quote
Old 11-04-2009, 10:26 PM   #8 (permalink)
patonb's Avatar
 
Master Techie

Join Date: Jan 2005

Location: In Gov't Regulated Cubical

Posts: 2,773

patonb has a spectacular aura aboutpatonb has a spectacular aura about

Default Re: Vista 32bit home has sprung a leak pls Hyjackthis log

Just a follow/ ending to this.

After taking out updates, 1 at a time, its now fine... seems an update didn't agree with it.. Don't ask which, my mommy did the removing at her end.
__________________
Intel Q6600 g0 @ 3.2Ghz Turniq 120 Heatsink BFG 260 OC MaxCore (core 216) + xfx GTX 260 (core 216)
2x2gb OCZ Platinums XFX 680i motherboard Silverstone DA700 Antec 900
16,412 3dmark06 score


Foldie = e2180 Asus pq5-n SLI 8800gt T-rad cooler (710/1836/1010) 1Gig RAM
TOTAL
patonb is offline   Reply With Quote
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
The Tech Forums Official 3DMark06/03 Top List gurusan Overclocking, Case Mod, Tweaking PC Performance 4136 10-29-2009 04:40 PM
Currently on windows xp. Want to get dx10 and have vista 32bit key. Is it worth it? stainer711 Windows Operating Systems and Software 17 01-03-2009 09:22 AM
Windows Vista Service Pack 2 Beta Mak213 Windows Operating Systems and Software 0 10-26-2008 02:52 PM
10 Reasons You Don't Need Vista Today Cyber.Logan Building, Buying, or Upgrading High Performance PC Systems 47 08-15-2007 05:31 PM
Vista Home Premium 32bit or 64bit cub1971 Windows Operating Systems and Software 10 04-20-2007 08:18 PM