We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

How do I find out what my computer is doing?

13»

Comments

  • erb
    erb Posts: 547 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    I have run another full scan and 5 objects were infected. This is the log MBS produced so if anyone knows how bad these infections are it would be appreciated.

    Malwarebytes' Anti-Malware 1.44
    Database version: 3886
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    20/03/2010 12:19:39
    mbam-log-2010-03-20 (12-19-14).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 424338
    Time elapsed: 1 hour(s), 45 minute(s), 9 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 4
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\TypeLib\{661e32fd-a5f0-49bc-96cc-d872fe10a7dc} (AdWare.WebHancer) -> No action taken.
    HKEY_CLASSES_ROOT\Interface\{3296405e-e08f-4442-801e-3dcd2c6aa82c} (AdWare.WebHancer) -> No action taken.
    HKEY_CLASSES_ROOT\CLSID\{bf0118d4-63ff-4138-9327-f3028fb1a578} (AdWare.WebHancer) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bf0118d4-63ff-4138-9327-f3028fb1a578} (AdWare.WebHancer) -> No action taken.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\Web\Wallpaper\welcome\AWhelper.dll (AdWare.WebHancer) -> No action taken.
    Regards
    erb :)
  • More issues? You do have a firewall, right?

    Off the top of my head, aside from malware, you need check:
    - task manager for I/O Bytes Written/ Read and seeing which processes use the most
    (View>Columns)
    - disable unnecessary services
    - check if AV system is downloading and installing excessive updates (you may find it better to disable 'auto-update')
    - telling us which processes are running
  • Taffybiker
    Taffybiker Posts: 927 Forumite
    It seems all 5 of your objects are WebHancer, note that MBAM took no action. I would uninstall it manually.
    Try saying "I have under-a-pound in my wallet" and listen to people react!
  • erb
    erb Posts: 547 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    edited 21 March 2010 at 7:55PM
    More issues? You do have a firewall, right?

    Off the top of my head, aside from malware, you need check:
    - task manager for I/O Bytes Written/ Read and seeing which processes use the most
    (View>Columns)
    - disable unnecessary services
    - check if AV system is downloading and installing excessive updates (you may find it better to disable 'auto-update')
    - telling us which processes are running

    Firewall with the router and also using Zonealarm

    The process using the most bytes are:
    MsMpeng.exe 489,755,986
    jqs.exe 176,517,993
    vsmon.exe 79,840,668
    firefox.exe 32,577,890
    searcchindexer.exe 13,722,691
    wuauclt.exe 8,604,170
    svchost.exe 8,497,007
    explorer.exe 8,108,104

    There are now 60 processes running but all others are under 4,000,000 Bytes.

    Don't know which services are unecessary.
    AV only updates once a day.
    Regards
    erb :)
  • erb
    erb Posts: 547 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    Taffybiker wrote: »
    It seems all 5 of your objects are WebHancer, note that MBAM took no action. I would uninstall it manually.

    I have now used MBAM to remove them so hope everything will now work ok.
    Regards
    erb :)
  • hansi
    hansi Posts: 3,001 Forumite
    Part of the Furniture 1,000 Posts
    andy2004 wrote: »
    60 processes running on xp pro, that is definately way over the top, under xp pro you shouldnt have more than 40, with some fine tuning possible to get that down to 27, mine is currently 35, and i have 13 non microsoft programs running.

    1. download, install, update and run a quick scan using malwarebytes > www.malwarebytes.org <freeware and possibly one of the best

    2. antivirus AVAST HOME http://www.avast.com/free-antivirus-download

    3. Hijackthis 2.0.3 http://free.antivirus.com/hijackthis/
    download, install, click scan and LOG, it will open notepad when finished, just copy and paste the contents here, so someone can take a look at it.


    I have 61 processes running on XP and I have no problems with that. When I open Task Manager, the majority of processes are using 00 on the CPU. As I write, my CPU usage is 1%, so Im not worried with that figure
  • closed
    closed Posts: 10,886 Forumite
    edited 21 March 2010 at 8:34PM
    http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx

    35 more processes than I've got, post a hijackthis log, and consider uninstalling zonealarm firewall, and disabling indexer service and java quick start, if you have too much running at startup, and little ram, the machine will be using the page file all the time.
    !!
    > . !!!! ----> .
  • erb
    erb Posts: 547 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    Just to say since I removed the Adware infections I have had no problems with the computer suddenly going off and doing something.

    Task Mangager is still showing about 60 processes but they don't all run all the time and CPU usage is currently between 3% and 6% so no problem there.
    Regards
    erb :)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245K Work, Benefits & Business
  • 600.6K Mortgages, Homes & Bills
  • 177.4K Life & Family
  • 258.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.