Forum Home
Press F1
 
Thread ID: 105347 2009-11-28 09:41:00 Some help please rogsmith (15465) Press F1
Post ID Timestamp Content User
834392 2009-11-28 09:41:00 Hello to all,this looks a very handy forum.Anyway can someone look at this for me and tell me if all seems ok,what i need and dont need etc.I just feel my computer isnt running as well as it should.Its only a few weeks old so im trying to get it running as it should.
Many thanks.




Type Status Entry Describe
Process System No Record
Process smss.exe Session Manager Subsystem
Process csrss.exe Client/Server Runtime Server Subsystem
Process wininit.exe No Record
Process csrss.exe Client/Server Runtime Server Subsystem
Process services.exe Windows Service Controller
Process lsass.exe Local Security Service
Process lsm.exe No Record
Process svchost.exe Service Host Process
Process nvvsvc.exe No Record
Process svchost.exe Service Host Process
Process svchost.exe Service Host Process
Process svchost.exe Service Host Process
Process svchost.exe Service Host Process
Process svchost.exe Service Host Process
Process winlogon.exe Windows Logon Process
Process audiodg.exe No Record
Process svchost.exe Service Host Process
Process SLsvc.exe No Record
Process svchost.exe Service Host Process
Process nvvsvc.exe No Record
Process svchost.exe Service Host Process
Process aswUpdSv.exe No Record
Process ashServ.exe No Record
Process spoolsv.exe Printer Spooler Service
Process svchost.exe Service Host Process
Process CLHNService.exe No Record
Process CLMSMonitorService.exe No Record
Process CLMSServer.exe No Record
Process taskeng.exe No Record
Process MWLService.exe No Record
Process svchost.exe Service Host Process
Process svchost.exe Service Host Process
Process svchost.exe Service Host Process
Process SearchIndexer.exe No Record
Process taskeng.exe No Record
Process nSvcAppFlt.exe No Record
Process dwm.exe No Record
Process explorer.exe Windows Explorer
Process nSvcIp.exe No Record
Process taskeng.exe No Record
Process ashMaiSv.exe No Record
Process ashWebSv.exe No Record
Process MSASCui.exe No Record
Process EgisUpdate.exe No Record
Process mwlDaemon.exe No Record
Process RtHDVCpl.exe No Record
Process ArcadeDeluxeAgent.exe No Record
Process CLMLSvc.exe No Record
Process PMVService.exe No Record
Process PDVD8Serv.exe No Record
Process ashDisp.exe No Record
Process GoogleToolbarNotifier.exe No Record
Process msnmsgr.exe No Record
Process iexplore.exe Internet Explorer
Process iexplore.exe Internet Explorer
Process GoogleToolbarUser_32.exe No Record
Process WmiPrvSE.exe No Record
Process infocard.exe No Record
Process FlashUtil10a.exe No Record
Process AWC.exe Advanced WindowsCare
Services aswUpdSv.exe Related to Avast AntiVirus
Services ashServ.exe Related to Avast AntiVirus
Services ashMaiSv.exe Related to Avast AntiVirus
Services ashWebSv.exe Related to AWIL Software http://www.avast.com/
Services CLHNService.exe No Record
Services CLMSMonitorService.exe No Record
Services CLMSServer.exe No Record
Services nSvcAppFlt.exe Related to Nvidia Corp. Intelligent Application Manager.
Services GoogleUpdaterService.exe Related to Google_Updater_Service Note: Located in C:\Program Files\Google\Common\Google Updater\
Services MWLService.exe No Record
Services nSvcIp.exe Related to Nvidia Corp. Network Access Manager.
Services nvvsvc.exe No Record
Services wmpnetwk.exe Related to Windows_Media_Player Network Sharing Service. Note: Located in %ProgramFiles%\Windows Media Player\
Start UP GoogleToolbarNotifier.exe Companion to the Google Toolbar that lets you keep Google as your default search engine and prevents this setting from being changed without your consent. Shouldn't remain in memory after the feature is disabled as it's a bug - see here
Start UP background No Record
Start UP EgisUpdate.exe No Record
Start UP mwlDaemon.exe No Record
Start UP NvCpl.dll No Record
Start UP NvStartup No Record
Start UP RtHDVCpl.exe High definition audio codec driver from Realtek Semiconductor
Start UP ArcadeDeluxeAgent.exe No Record
Start UP CLMLSvc.exe No Record
Start UP PMVService.exe No Record
Start UP PDVD8Serv.exe No Record
Start UP Language.exe No Record
Start UP ashDisp.exe Part of Avast! anti-virus software
Start UP Skytel.exe Process associated with Realtek Voice Manager for some of their audio chipsets
Start UP Reader_sl.exe Speeds up the launch of Adobe (Acrobat) Reader 7
Start UP AdobeARM.exe No Record
BHO 18DF081C-E8AD-4283-A596-FA578C2EBDC3 No Record
BHO 5C255C8A-E604-49b4-9D64-90988571CECB No Record
BHO 9030D464-4C02-4ABF-8ECC-5164760863C6 WindowsLiveLogin.dll - Microsoft Windows_Live, http://ideas.live.com/
BHO AA58ED58-01DD-4d91-8333-CF10577473F7 googletoolbar.dll, googletoolbar*.dll, googlenav.dll, googletoolbar_en_*.**-big.dll, googletoolbar_en_*.*.**-deleon.dll - Google Toolbar, http://toolbar.google.com/
BHO AF69DE43-7D58-4638-B6FA-CE66B5AD205D swg.dll - Google Toolbar Notifier, googlesystem.blogspot.com
BHO C84D72FE-E17D-4195-BB24-76C02E2E7C4E No Record
Tool Bar 2318C2B1-4965-11d4-9B18-009027A5CD4F googletoolbar.dll, googletoolbar*.dll, googlenav.dll, googletoolbar_en_*.**-big.dll, googletoolbar_en_*.*.**-deleon.dll - Google Toolbar, //toolbar.google.com/
Menu E No Database
Button {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} No Database
Button {2670000A-7350-4f3c-8081-5663EE0C6C49} No Database
Button {92780B25-18CC-41C8-B9BE-3C9C571A8263} No Database
rogsmith (15465)
834393 2009-11-28 09:46:00 Download and run Highjackthis from free.antivirus.com and paste the scan results back on this forum.
:)
Trev (427)
834394 2009-11-28 09:47:00 Umm whats that from?? It doesnt tell us much. Get hijackthis below, install/run it. Click on scan the system, and save a log. Copy and paste the log here Speedy Gonzales (78)
834395 2009-11-28 09:50:00 Hey thanks for the quick replies.Im not the best with computers as you can probably tell.I will do that now and paste it. rogsmith (15465)
834396 2009-11-28 09:55:00 Hopefully thats what you need.Once again thanks.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:02:40, on 28/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = homepage.acer.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = homepage.acer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.koower.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\s wg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [ avast! ] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: CyberLink Media Server Monitor Service - Unknown owner - C:\Program Files\Acer Arcade Deluxe\Acer HomeMedia Connect\Kernel\DMS\CLMSMonitorService.exe
O23 - Service: CyberLink Media Server Service - CyberLink - C:\Program Files\Acer Arcade Deluxe\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt. exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MyWinLocker Service (MWLService) - EgisTec Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 7972 bytes
rogsmith (15465)
834397 2009-11-28 10:05:00 You got it, thats what we need.

Go to control panel / windows defender, then double click on it. Then go to tools / options. Scroll down to administrator options / untick Use windows defender. Then click on save, it'll disable it. Since Avast is installed.

You can tick these entries then tick fix checked. Close browsers

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"

O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"

Whats the specs of the system (ie: What kind of CPU, how much memory)??
Speedy Gonzales (78)
834398 2009-11-28 10:17:00 Great stuff thanks mate i will do that in a minute.My system is,
intel (r) atom (tm)cpu 230 @160ghz
2.00 gb
rogsmith (15465)
834399 2009-11-28 10:21:00 No probs. Cool ok. One more thing. Go to control panel / double click on program and features. Look for ForceWare Network Access Manager, and / or NVIDIA Network Access Manager. (if this exists as well) uninstall both of them. It can cause probs. Then reboot, then see if things are faster Speedy Gonzales (78)
834400 2009-11-28 10:31:00 You have been a great help,cheers mate.I have done everything and will try those now.Cheers mate. rogsmith (15465)
834401 2009-11-28 10:36:00 Sweet, no probs Speedy Gonzales (78)
1