What's new

Computer help needed, possible virus, trojan or other malware... (1 Viewer)

Rommel_L

Second Unit
Joined
Apr 25, 2000
Messages
355
Nathan F,

You're computer looks clean. Let me guess, would that process be svchost.exe that's using the cpu up to 50%? Does this happen especially if you're connected to the internet while gaming (like MMORPGs)?

Here's some tips that can probably help:
- Download Java Runtime Environment (JRE) 5.0 Update 9, the latest version from Java. Remember to uninstall the old version first before installing the new one.
- Disable the real-time protection of your active antispyware programs (MS Defender / Spybot) when you're gaming.

- Reboot in safe mode.
- Run HiJackThis, put a check beside the following processes and hit Fix checked:
O4 - HKLM..Run: [SchedulingAgent] mstinit.exe /firstlogon
O4 - HKLM..Run: [SmcService] C:PROGRA~1SygateSPFsmc.exe -startgui
O4 - HKLM..Run: [ABIT uGuru] C:Program FilesABITABIT uGuruuGuru.exe
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_08binjusched.exe"
O4 - HKLM..Run: [CTSysVol] C:Program FilesCreativeSBAudigy2ZSSurround MixerCTSysVol.exe /r
O4 - HKLM..Run: [CTDVDDET] C:Program FilesCreativeSBAudigy2ZSDVDAudioCTDVDDet.EXE
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKCU..Run: [Yahoo! Pager] 1

Programs that doesn't really need to run during startup and take up unnecessary RAM space.

O16 - DPF: {18CD2FD8-81CE-44C3-99E1-0822E1C7116C} (EARTPatch8X Class) - http://files.ea.com/downloads/rtpatch/v4/EARTP8X.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!commonyinsthelper.dll
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} (Seagate SeaTools English Online) - http://www.seagate.com/support/disc/...npseatools.cab

They are small scripts and/or snippets of programs that are needed to view a particular web page at that time. You can delete any or all that you want and the next time you visit that page a fresh copy will be downloaded again if needed.

- Reboot to normal mode.
- Run Disk Defragmenter.

I'll be waiting for your feedback...
 

Nathan_F

Second Unit
Joined
Feb 6, 2001
Messages
274
Location
Fishers, IN
Real Name
Nathan
Thanks Rommel.. no, actually not svchost, but rather "System" was the process jumping up. As I mentioned above, removing, then reinstalling AVG seemed to correct the problem. New build maybe? And no MMORPGs for me.. RTS and Sports titles are more my speed.

Few questions:
(what does this do?) O4 - HKLM..Run: [SchedulingAgent] mstinit.exe /firstlogon
(this is my firewall) O4 - HKLM..Run: [SmcService] C:PROGRA~1SygateSPFsmc.exe -startgui
(I use this to keep tab of temps) O4 - HKLM..Run: [ABIT uGuru] C:Program FilesABITABIT uGuruuGuru.exe
(what does this do?) O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
(what does this do?) O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_08binjusched.exe"
(no longer running after latest Audigy drivrers) O4 - HKLM..Run: [CTSysVol] C:Program FilesCreativeSBAudigy2ZSSurround MixerCTSysVol.exe /r
(no longer running after latest Audigy drivrers) O4 - HKLM..Run: [CTDVDDET] C:Program FilesCreativeSBAudigy2ZSDVDAudioCTDVDDet.EXE
(what does this do?) O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
(I will check this one in HiJack) O4 - HKCU..Run: [Yahoo! Pager] 1
Programs that doesn't really need to run during startup and take up unnecessary RAM space.
 

Nathan_F

Second Unit
Joined
Feb 6, 2001
Messages
274
Location
Fishers, IN
Real Name
Nathan
Items cleaned up on hijack this. I've been running smoothly ever since the AVG removal and reinstall, so these things have just helped reduce processes and pagefile. 26 processes and ~150m page file at bootup. Not too shabby.
 

Nathan_F

Second Unit
Joined
Feb 6, 2001
Messages
274
Location
Fishers, IN
Real Name
Nathan
Yeah, the problem went away when I uninstalled AVG. I had to do that to run some of the other spyware, antivirus programs I had downloaded. For some reason, I decided to check on the problem after uninstalling it. Problem "solved". Still doesn't make sense to me. Anyway, I reinstalled AVG from a new download and the problem has not recurred.
 

Rommel_L

Second Unit
Joined
Apr 25, 2000
Messages
355
Sounds like the old copy was corrupted. It happens from time to time, on any any kind of executable file... Glad everything's kosher now...
 

Users who are viewing this thread

Sign up for our newsletter

and receive essential news, curated deals, and much more







You will only receive emails from us. We will never sell or distribute your email address to third party companies at any time.

Forum statistics

Threads
357,063
Messages
5,129,883
Members
144,281
Latest member
papill6n
Recent bookmarks
0
Top