Unsolved
This post is more than 5 years old
17 Posts
0
5525
March 25th, 2011 15:00
Memory usage gradually builds while laptop is powered up even if no applications are being run
Hi My name is Shaun. I have an Alienware M17x. When I power it up the Memory usage while doing nothing would already be at 1.12 Gb or so. Gradually the memory rises until it is up to 3.9 Gb, I only have 4 Gb(remember this is even if no applications are being run). At this point and before it the laptop begins to freeze for everything. I was wondering if the usage of Memory effects the processor, as I have a quad core and when the memory usage is high the cpu can be 40% or more even when I don't ask the computer to do anything.
Thanks and here is my log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:18:21, on 25/03/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\OSD\Launch_CC.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayAlert.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110226160312.dll
O2 - BHO: FAIESSO Helper Object - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - C:\Program Files\Alienware\Command Center\AlienSense\FAIESSO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
O4 - HKLM\..\Run: [OSD] c:\Program Files\OSD\Launch.exe
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Philips SA19xx Device Manager.lnk = C:\Program Files (x86)\Philips\GoGear SA19xx Device Manager\main.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Shaun Naughton\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O20 - Winlogon Notify: FastAccess - C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Alienware Fusion Service (AlienFusionService) - Alienware - C:\Program Files\Alienware\Command Center\AlienFusionService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Vista Session Launcher Service (CustomSvc) - Unknown owner - C:\Program Files\OSD\Service1.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FAService - Sensible Vision - C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Vodafone Mobile Broadband Service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Windows Presentation Foundation Font Cache 4.0.0.0 (WPFFontCache_v0400) - Unknown owner - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe (file missing)
--
End of file - 12789 bytes


kevin27_b3d29f
2 Intern
•
1.5K Posts
0
March 27th, 2011 11:00
Hi TheTripJunkie1,
Is this the same system that you posted about a month ago? An analyst replied to the thread within 24 hours.
Please let me know you are still with this thread and are going to be until the end before we continue.
Thanks.
TheTripJunkie1
17 Posts
0
March 27th, 2011 18:00
Thanks for replying. No this is a different system. Sorry about not replying to the last thread, a lot happened between the time I posted and the three days I had to reply, by the time I got sorted it was too late to reply. Yes I will follow this thread through.
Thanks again
Shaun
kevin27_b3d29f
2 Intern
•
1.5K Posts
0
March 28th, 2011 04:00
Hi,
Thank you for letting me know. If you need longer than three days, just let me know.
Download and scan with CCleaner
1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
In the Applications Tab:
4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.
Then Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
MBAM will automatically start and you will be asked to update the program before performing a scan.
On the Scanner tab:
Back at the main Scanner screen:
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.
I then need to see some additional information about what is happening in your machine.
Please perform the following scan:
1. DDS.txt
2. Attach.txt
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
Please copy/paste back the MBAM log and BOTH DDS logs for review.
Thanks.
TheTripJunkie1
17 Posts
0
March 28th, 2011 06:00
Thanks again heres the MalwareBytes log
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6191
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
28/03/2011 12:49:23
mbam-log-2011-03-28 (12-49-23).txt
Scan type: Quick scan
Objects scanned: 161849
Time elapsed: 3 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\program files (x86)\Vodafone\vodafone mobile broadband\Bin\vodafone.view.taskbar.dll (Trojan.Dropper) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files (x86)\Vodafone\vodafone mobile broadband\Bin\vodafone.view.taskbar.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
kevin27_b3d29f
2 Intern
•
1.5K Posts
0
March 28th, 2011 17:00
Hi,
Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)
Go here to run an online scannner from ESET.
TheTripJunkie1
17 Posts
0
March 29th, 2011 19:00
Hi, I turned off all Anti-Vius, Spyware & firewall. The scan found no threats but after 2.5 hours running my memory is at 3.5Gb of 4. My cpu is also at 40% when only running Internet Explorer. What do you think the next step should be??
Thanks again for all your help its really appreciated:)
Shaun
kevin27_b3d29f
2 Intern
•
1.5K Posts
0
March 30th, 2011 14:00
Hi,
Run the system for a little while so the memory usage is high and then run the following tool:
You will now be presented with a screen showing all the running processes on your machine.
Thanks.
TheTripJunkie1
17 Posts
0
March 30th, 2011 19:00
HI
Here's a lthe log after almost 2 hours of running the computer
Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 63.99 0 K 24 K
System 4 0.84 112 K 928 K
Interrupts n/a 7.74 0 K 0 K Hardware Interrupts and DPCs
smss.exe 304 520 K 108 K
csrss.exe 512 < 0.01 2,352 K 1,944 K
conhost.exe 1552 1,064 K 192 K
wininit.exe 596 1,912 K 528 K
services.exe 652 8,056 K 7,120 K
svchost.exe 784 6.74 5,112 K 4,084 K Host Process for Windows Services Microsoft Corporation
WmiPrvSE.exe 2460 1.59 6,280 K 5,248 K
BTStackServer.exe 5132 < 0.01 11,800 K 3,136 K Bluetooth Stack COM Server Broadcom Corporation.
BluetoothHeadsetProxy.exe 5292 1,332 K 728 K Bluetooth Headset Skype Proxy Broadcom Corporation.
nvvsvc.exe 848 1,512 K 524 K NVIDIA Driver Helper Service, Version 179.85 NVIDIA Corporation
rundll32.exe 1268 < 0.01 3,248 K 936 K
svchost.exe 884 < 0.01 6,196 K 5,204 K Host Process for Windows Services Microsoft Corporation
svchost.exe 948 0.06 19,148 K 11,988 K Host Process for Windows Services Microsoft Corporation
audiodg.exe 3928 14,516 K 15,500 K
svchost.exe 988 < 0.01 115,692 K 108,652 K Host Process for Windows Services Microsoft Corporation
wlanext.exe 1544 2,180 K 1,056 K
dwm.exe 3080 0.31 47,628 K 32,640 K Desktop Window Manager Microsoft Corporation
svchost.exe 1016 0.08 28,788 K 21,584 K Host Process for Windows Services Microsoft Corporation
stacsv64.exe 336 0.01 7,952 K 2,228 K IDT PC Audio IDT, Inc.
svchost.exe 1164 7,368 K 5,576 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1352 0.71 13,340 K 8,624 K Host Process for Windows Services Microsoft Corporation
spoolsv.exe 1536 8,180 K 2,768 K Spooler SubSystem App Microsoft Corporation
FAService.exe 1588 0.01 15,636 K 4,488 K FastAccess Sensible Vision
svchost.exe 1648 13,500 K 7,944 K Host Process for Windows Services Microsoft Corporation
AESTSr64.exe 1756 1,316 K 176 K Andrea filters APO access service (64-bit) Andrea Electronics Corporation
AlienFusionService.exe 1792 16.52 3,006,296 K 2,823,532 K AlienFusionService Alienware
AppleMobileDeviceService.exe 1836 1,884 K 660 K Apple Mobile Device Service Apple Inc.
mDNSResponder.exe 1856 2,108 K 1,456 K Bonjour Service Apple Inc.
btwdins.exe 1884 2,484 K 528 K Bluetooth Support Server Broadcom Corporation.
Service1.exe 1932 1,708 K 596 K
OSD_Main.exe 3936 2,380 K 2,652 K
svchost.exe 1964 0.02 5,936 K 4,780 K Host Process for Windows Services Microsoft Corporation
mfevtps.exe 2004 6,216 K 1,732 K McAfee Process Validation Service McAfee, Inc.
NBService.exe 328 3,056 K 1,472 K Nero BackItUp Nero AG
svchost.exe 1380 1,972 K 1,196 K Host Process for Windows Services Microsoft Corporation
nSvcAppFlt.exe 1480 2,408 K 1,420 K app_filter Module
mcshield.exe 1452 0.01 169,552 K 40,068 K McAfee On-Access Scanner service McAfee, Inc.
mfefire.exe 2168 4,636 K 3,576 K McAfee Core Firewall Service McAfee, Inc.
nSvcIp.exe 2212 3,344 K 1,084 K NVIDIA Corporation
VmbService.exe 2288 < 0.01 19,000 K 4,300 K VmbService Vodafone
McSvHost.exe 2484 < 0.01 31,708 K 22,724 K McAfee Service Host McAfee, Inc.
taskhost.exe 3040 8,548 K 3,812 K Host Process for Windows Tasks Microsoft Corporation
SearchIndexer.exe 5068 < 0.01 49,260 K 30,676 K Microsoft Windows Search Indexer Microsoft Corporation
SearchProtocolHost.exe 5272 < 0.01 3,716 K 8,736 K
SearchFilterHost.exe 5844 3,260 K 7,236 K
svchost.exe 2196 3,332 K 3,080 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1564 1,956 K 1,220 K Host Process for Windows Services Microsoft Corporation
lsass.exe 672 < 0.01 5,556 K 4,888 K Local Security Authority Process Microsoft Corporation
lsm.exe 680 2,892 K 1,480 K
csrss.exe 616 0.04 7,764 K 4,460 K
conhost.exe 3420 1,708 K 564 K Console Window Host Microsoft Corporation
conhost.exe 4112 1,712 K 548 K Console Window Host Microsoft Corporation
winlogon.exe 472 3,360 K 1,384 K
explorer.exe 3160 0.09 34,640 K 46,416 K Windows Explorer Microsoft Corporation
sttray64.exe 3408 7,876 K 2,008 K IDT PC Audio IDT, Inc.
rundll32.exe 3440 2,556 K 644 K Windows host process (Rundll32) Microsoft Corporation
AlienwareAlienFXController.exe 3452 < 0.01 30,912 K 3,016 K Alienware AlienFX Controller Alienware Corporation
AlienFXHook32Mngr.exe 3544 < 0.01 9,328 K 880 K AlienFXHook32 Manager Alienware
AlienFXHook64Mngr.exe 3736 32,928 K 1,016 K AlienFXHook64 Manager Alienware
Launch_CC.exe 3460 1,860 K 952 K Alienware Corporation
SynTPEnh.exe 3472 0.09 4,500 K 2,876 K Synaptics TouchPad Enhancements Synaptics Incorporated
SynTPHelper.exe 2244 1,572 K 432 K
M-AudioTaskBarIcon.exe 3480 3,952 K 876 K M-Audio Task Bar Icon Applet Avid Technology, Inc.
sidebar.exe 3488 33,976 K 9,616 K Windows Desktop Gadgets Microsoft Corporation
BTTray.exe 3708 0.02 6,132 K 4,608 K Bluetooth Tray Application Broadcom Corporation.
ONENOTEM.EXE 4080 1,136 K 792 K Microsoft Office OneNote Quick Launcher Microsoft Corporation
procexp.exe 2352 1,856 K 5,960 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
procexp64.exe 5148 1.07 20,632 K 40,120 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
brs.exe 4036 1,096 K 616 K brs cyberlink
FATrayMon.exe 4052 1,596 K 1,120 K FATrayMon Sensible Vision
FATrayAlert.exe 3304 0.03 4,800 K 3,124 K FATrayAlert Application Sensible Vision
PDVD8Serv.exe 728 1,460 K 1,356 K PowerDVD RC Service CyberLink Corp.
jusched.exe 1420 2,296 K 4,504 K Java(TM) Platform SE binary Sun Microsystems, Inc.
realsched.exe 3720 2,412 K 388 K RealNetworks Scheduler RealNetworks, Inc.
mcagent.exe 3268 53,012 K 3,896 K McAfee Security Center McAfee, Inc.
MobileBroadband.exe 1044 0.01 86,988 K 14,612 K MobileBroadband Vodafone
bmctl.exe 4332 2,132 K 2,068 K Control Process Bytemobile, Inc.
Thanks again:)
kevin27_b3d29f
2 Intern
•
1.5K Posts
0
April 1st, 2011 12:00
Hi,
Let disable some of them unneeded programs from running at start and see if that makes a difference. Although nothing is physically running, there is an awfal lot running in the background.
Lets run a tool to disable some unneeded programs from starting when the system starts and see if it makes a difference to your speed problems,
Please download Startups@Ease by AbuIbrahim12
NOTE: If after running startup@Ease you feel as if you have made a mistake, please open the tool and click the "Restore Backups" button, this will re-enable all of the programs you disabled at startup on the next reboot.
Please post the Startups@Ease log back to me for review
Thanks,
TheTripJunkie1
17 Posts
0
April 3rd, 2011 10:00
Hi
I think the S@E system has changed since you used it last there is no longer a begin button. Now you choose to startup, services or windows services. I ran them all & stopped some startups & some services. There is no longer a log file button. My computer is still using way too much ram & cpu. If I reinstall my OS do you think it might make a difference??
Thanks again,
kevin27_b3d29f
2 Intern
•
1.5K Posts
0
April 4th, 2011 01:00
Hi,
With these kinds of problems it could be numerous things causing the RAM/CPU spike, it could be a faulty piece of hardware, an infection or a program that is over resourceful. The trouble is, its a process of elimation, it could take weeks or even months trying to trouble shoot via a forum, A reinstall would certainly be quicker but then you would have to make all the relevant backups before you reinstalled and then reinstall all your programs again. You would at least be able to reinstall each program one at a time and see if one was causing the issue.
Lets run one more tool and see what that unearths and then we will go from there.
Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)
Please download ComboFix.exe. Please visit THIS webpage for download links, and instructions for running the tool:
ComboFix MUST be saved to your desktop before running the tool
* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
When prompted to install the recovery console please make sure to do so as this is a VERY IMPORTANT backup of ComboFix (XP only, Vista/Windows 7 will NOT be propmted to install the recovery console)
You will need to be conected to the net to install the recovery console, if you can not install it DO NOT run ComboFix,
Post back and we will install it manually.
DO NOT mouse click when ComboFix is running as this will cause ComboFix to Stall and it will not work as it should
EXTRA NOTES:
Please include the C:\ComboFix.txt in your next reply for further review.
Thanks,
K27.
TheTripJunkie1
17 Posts
0
April 4th, 2011 04:00
Here's the ComboFix logfile
ComboFix 11-04-03.03 - Shaun Naughton 04/04/2011 11:23:47.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.353.1033.18.3838.1147 [GMT 1:00]
Running from: c:\users\Shaun Naughton\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-03-04 to 2011-04-04 )))))))))))))))))))))))))))))))
.
.
2011-04-04 10:30 . 2011-04-04 10:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-03 16:02 . 2011-04-03 16:05 -------- d-----w- C:\S@E_backups
2011-03-30 01:27 . 2010-06-18 18:50 205376 ------w- c:\windows\system32\US-122_MKII_US-144_MKII.CPL
2011-03-30 01:27 . 2011-03-30 01:27 -------- d-----w- c:\windows\usb-audio.deTascam
2011-03-30 01:24 . 2010-06-18 18:50 31296 ----a-w- c:\windows\system32\drivers\tscusb2m.sys
2011-03-30 01:24 . 2010-06-18 18:50 50240 ----a-w- c:\windows\system32\drivers\tscusb2a.sys
2011-03-30 01:24 . 2010-06-18 18:50 409664 ----a-w- c:\windows\system32\drivers\tascusb2.sys
2011-03-29 23:47 . 2011-03-29 23:47 -------- d-----w- c:\program files (x86)\ESET
2011-03-28 11:42 . 2011-03-28 11:42 -------- d-----w- c:\users\Shaun Naughton\AppData\Roaming\Malwarebytes
2011-03-28 11:42 . 2011-03-28 11:42 -------- d-----w- c:\programdata\Malwarebytes
2011-03-28 11:42 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-28 11:42 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-28 11:42 . 2011-03-28 11:42 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-03-28 11:08 . 2011-03-28 11:08 -------- d-----w- c:\program files\CCleaner
2011-03-28 01:24 . 2011-03-28 01:24 -------- d-----w- c:\program files\M-Audio
2011-03-28 01:24 . 2011-03-28 01:24 -------- d-----w- c:\program files (x86)\Common Files\Digidesign
2011-03-24 03:24 . 2011-03-24 03:24 388096 ----a-r- c:\users\Shaun Naughton\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-24 03:24 . 2011-03-24 03:24 -------- d-----w- c:\program files (x86)\Trend Micro
2011-03-24 00:12 . 2010-03-09 16:33 1849856 ----a-w- c:\windows\system32\drivers\athurx.sys
2011-03-08 19:38 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll
2011-03-08 19:38 . 2010-12-23 06:07 723968 ----a-w- c:\windows\system32\EncDec.dll
2011-03-08 19:38 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2011-03-08 19:38 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll
2011-03-08 19:38 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-08 19:38 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll
2011-03-08 19:38 . 2010-12-23 05:28 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-03-08 19:38 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
2011-03-08 19:38 . 2010-12-18 06:12 3138048 ----a-w- c:\windows\system32\mstscax.dll
2011-03-08 19:38 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\SysWow64\mstscax.dll
2011-03-08 19:38 . 2010-12-18 06:08 1097216 ----a-w- c:\windows\system32\mstsc.exe
2011-03-08 19:38 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\SysWow64\mstsc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-26 14:33 . 2011-02-26 14:33 39552 ----a-w- c:\windows\system32\drivers\tcpipBM.sys
2011-02-26 14:33 . 2011-02-26 14:33 16512 ----a-w- c:\windows\system32\drivers\BMLoad.sys
2011-01-07 08:06 . 2011-02-25 14:01 46080 ----a-w- c:\windows\system32\atmlib.dll
2011-01-07 07:27 . 2011-02-25 14:01 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2011-01-07 05:49 . 2011-02-25 14:01 366080 ----a-w- c:\windows\system32\atmfd.dll
2011-01-07 05:33 . 2011-02-25 14:01 294400 ----a-w- c:\windows\SysWow64\atmfd.dll
2011-01-05 06:20 . 2011-02-25 14:04 612352 ----a-w- c:\windows\system32\vbscript.dll
2011-01-05 05:37 . 2011-02-25 14:04 428032 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-01-05 04:00 . 2011-02-25 14:07 3127808 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-10-04 133104]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2009-05-01 75048]
"FATrayAlert"="c:\program files\Alienware\Command Center\AlienSense\FATrayMon.exe" [2009-05-09 95496]
"OSD"="c:\program files\OSD\Launch.exe" [2009-05-12 36864]
"RemoteControl8"="c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-10-17 91432]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-01-17 1484856]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-12-31 398848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-6 1025576]
Philips SA19xx Device Manager.lnk - c:\program files (x86)\Philips\GoGear SA19xx Device Manager\main.exe [2009-12-11 119296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]
2009-05-09 17:48 140552 ----a-w- c:\program files\Alienware\Command Center\AlienSense\FALogNot.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
2;2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys
R3 MAUSBMICRO;Service for M-Audio Micro;c:\windows\system32\DRIVERS\MAudioMicro.sys
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys
R3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;c:\windows\system32\Drivers\tascusb2.sys
R3 TASCAM_US144_MIDI;TASCAM US-144 WDM MIDI Device;c:\windows\system32\drivers\tscusb2m.sys
R3 TASCAM_US144_WDM;TASCAM US-144 WDM;c:\windows\system32\drivers\tscusb2a.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
R4 ahcix64;ahcix64;c:\windows\system32\drivers\ahcix64.sys
R4 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2009/09/16 11:33];c:\program files (x86)\CyberLink\PowerDVD8\000.fcl [2009-03-05 08:47 146928]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\AESTSr64.exe [2009-03-02 89600]
S2 CustomSvc;Vista Session Launcher Service;c:\program files\OSD\Service1.exe [2009-02-20 13312]
S2 FAService;FAService;c:\program files\Alienware\Command Center\AlienSense\FAService.exe [2009-05-09 2360584]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-13 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-10-13 149032]
S2 VmbService;Vodafone Mobile Broadband Service;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
S3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys
S3 OA007Vid;Creative Camera OA007 Function Driver;c:\windows\system32\DRIVERS\OA007Vid.sys
S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys
S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\OSD\WinRing0x64.sys [2008-07-25 14544]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WINRING0_1_2_0
*Deregistered* - mfeavfk01
*Deregistered* - mfesmfk
*Deregistered* - MPFP
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2566811811-2272734622-3803116043-1003Core.job
- c:\users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-04 21:15]
.
2011-04-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2566811811-2272734622-3803116043-1003UA.job
- c:\users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-04 21:15]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF14345.cfxxe"
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-23 15961632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-23 82464]
"AlienFX Controller"="c:\program files\Alienware\Command Center\AlienwareAlienFXController.exe" [2009-05-22 52480]
"M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2010-03-26 798728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\users\Shaun Naughton\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-RegistryBooster - c:\program files (x86)\Uniblue\RegistryBooster\launcher.exe
Wow6432Node-HKLM-Run-FAStartup - (no file)
HKLM-Run-OSD CC - %ProgramFiles%\OSD\Launch_CC.exe
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\OSD\Launch_CC.exe
c:\program files\OSD\OSD_Main.exe
c:\program files\Alienware\Command Center\AlienSense\FATrayAlert.exe
c:\program files\Alienware\Command Center\AlienFXHook32Mngr.exe
c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\bmctl.exe
.
**************************************************************************
.
Completion time: 2011-04-04 11:38:43 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-04 10:38
.
Pre-Run: 84,202,987,520 bytes free
Post-Run: 83,895,074,816 bytes free
.
- - End Of File - - 8F9B05387FFA04D9FC0C2806E0225F79
kevin27_b3d29f
2 Intern
•
1.5K Posts
0
April 5th, 2011 13:00
Hi,
The log is clean, lets try this.
Please uninstall McAfee via "Remove Programs" in Control Panel and then please run the McAfee Removal Tool
Once McAfee is removed, please post a fresh HJT log.
Thanks.
TheTripJunkie1
17 Posts
0
April 6th, 2011 15:00
Hi before I uninstall I was wondering how I reinstall on the same license as my McAfee came pre-installed on my machine?? I still have a year and a half left on my license.
Thanks again:):)
kevin27_b3d29f
2 Intern
•
1.5K Posts
0
April 7th, 2011 00:00
Hi,
If McAfee was preinstalled then you should have a disk with McAfee on and that will have the product key on it. If not, look around the tower case and see if there is a sticker on the side/top/bottom with a McAfee product key sticker.
Thanks.