Help - Search - Members
Full Version: Need Help . . . please!
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
Tom AZ
I wasn't sure where to post this because I'm not sure what I'm up against. For the last couple of weeks or so, my computer has been acting somewhat pecuilarly. I use my computer a lot and it runs 24/7. Until a couple of weeks ago, I rarely HAD to reboot, but would re-boot a couple of times a week or so anyway. Now it seems like I am FORCED to reboot every 24 hours (or less.)

Everything starts to slow down, programs won't open, I start to have problems navigating -- and things in general just don't function properly. It gets to a point where the normal reboot/restart process won't even work and I literally have to unplug my computer. Once I restart, everything seems to be back to normal -- at least for a while -- about 24 hours -- then it all starts over again.

It just seems like everything gets sort of "clogged" up -- like there's an accumulation of something somewhere, but I don't know what it is. A reboot seems to unclog things -- at least for a while.

I'm using Windows XP Home w/ SP2, have a firewall, anti-virus and anti-spyware with active protection and do regular scans with both. I run CCleaner regularly and also defrag -- and even optimize my registry once in a while.

I have no idea what to do. It sounds a little like a malware issue, but that doesn't really seem to be the case. Any thoughts or suggestions would be greatly appreciated.
rridgely
Post a hijackthis log.
Its very possible that if your "optimizing your registry" that you could have screwed something up. I assume you mean you were using registry cleaners.

Other possibilities is that you have some junky software running thats causing problems( should show up in hjt log) or maybe some hardware is failing.
Tom AZ
QUOTE(rridgely @ Sep 4 2007, 04:31 AM) *
Post a hijackthis log.
Its very possible that if your "optimizing your registry" that you could have screwed something up. I assume you mean you were using registry cleaners.

Other possibilities is that you have some junky software running thats causing problems( should show up in hjt log) or maybe some hardware is failing.

Here's the HijackThis log -- thanks for taking a look:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:54:24 PM, on 09/03/07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSchedulerSvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\DeltTray.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\RAMpage\RAMpage.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Broderbund\Screen Shot Standard 8\SSstd8.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Miscellaneous Programs\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.networksolutions.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.quicken.com/investments/portfolio/"); (C:\Program Files\Netscape\Users\User00\prefs.js)
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Contribute 4\contributeieplugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Contribute 4\contributeieplugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon] C:\WINDOWS\System32\DeltTray.exe
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [RAMpage] "C:\Program Files\RAMpage\RAMpage.exe" R=300 T=200 A LW D=Y P="C:\Program Files\RAMpage\RAMpageConfig.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: HyperSnap-DX 5.lnk = C:\Program Files\Broderbund\Screen Shot Standard 8\SSstd8.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1183659554687
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: License Management Service ESD - element5 - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 1: SuperStats Desktop Display for vsign_1699474 - http://www.superstats.com/desktop/statsdes...236339f7aeb4776

--
End of file - 8217 bytes

rridgely
The log looks virus free to me. But I there are a couple of programs that I think could possibly be causing the issues.

RAMpage- If this is a memory optimizer program than get rid of it. These kinds of programs do not work and it could possibly be slowing things down.

SnoopFreeUI.exe- I've never heard of this program and its site looks pretty spamy.(badly written and lots of "5 stars from random site" awards. I would get rid of it and see if things seem better. It could very well be conflicting with something on this computer.

Your running asquared and superantispyware real time? I would only use one of those at a time to avoid conflicts.

Make sure you dont have any strange settings in outpost firewall either. If anything you may want to even try uninstalling it for a day or so and see if that could be the problem. It could possibly be a bug in there thats causing some issue.

Other than that you have pretty standard stuff running that shouldn't be causing any problems. Oh I would disable this from running if you dont use it:
C:\WINDOWS\System32\DeltTray.exe

Its some sort of audio control tray thing. I would find it pretty useless but maybe you use it. smile.gif
JDPower
QUOTE(rridgely @ Sep 6 2007, 01:52 AM) *
The log looks virus free to me. But I there are a couple of programs that I think could possibly be causing the issues.

I know I'm no expert in these things (so I'm probably wrong rolleyes.gif ) but is that Norton and AVG anti-virus running???
rridgely
QUOTE(JDPower @ Sep 5 2007, 10:29 PM) *
I know I'm no expert in these things but is that Norton and AVG anti-virus running???


Unless I missed something its not norton AV or firewall. Its the system works or utilities or whatever else symantec call their package now a days.
I dont think those would conflict with avg.
JDPower
QUOTE(rridgely @ Sep 6 2007, 03:31 AM) *
Unless I missed something its not norton AV or firewall. Its the system works or utilities or whatever else symantec call their package now a days.
I dont think those would conflict with avg.

Well I said I was probably wrong biggrin.gif
Tom AZ
QUOTE(rridgely @ Sep 6 2007, 12:52 AM) *
The log looks virus free to me. But I there are a couple of programs that I think could possibly be causing the issues.

RAMpage- If this is a memory optimizer program than get rid of it. These kinds of programs do not work and it could possibly be slowing things down.

SnoopFreeUI.exe- I've never heard of this program and its site looks pretty spamy.(badly written and lots of "5 stars from random site" awards. I would get rid of it and see if things seem better. It could very well be conflicting with something on this computer.

Your running asquared and superantispyware real time? I would only use one of those at a time to avoid conflicts.

Make sure you dont have any strange settings in outpost firewall either. If anything you may want to even try uninstalling it for a day or so and see if that could be the problem. It could possibly be a bug in there thats causing some issue.

Other than that you have pretty standard stuff running that shouldn't be causing any problems. Oh I would disable this from running if you dont use it:
C:\WINDOWS\System32\DeltTray.exe

Its some sort of audio control tray thing. I would find it pretty useless but maybe you use it. smile.gif

Thanks so much for your comments. What's puzzling about all of this is that except for a-Squared, I've been using all of these for the last 6 months+ with no problems at all.

RAMPage is indeed a very simple light-weight memory manager. I can certainly disable it and see what happens.

SnoopFree is pretty much what you might expect, but again, it hasn't been a problem, but I could try disabling that as well.

I am running SUPERAntiSpyware real time, but not a-Squared (only scan with it on demand).

Outpost I'm not sure about -- I suppose you could be right. Hasn't been a problem in the past, but not too long ago, there was a minor program update -- might have been something in that update. Do you think it would be worth my while to contact Agnitum?

Lastly "DeltTray" is related to my Delta soundcard -- which I use all the time (I do CD mastering for a living).

I don't know if my comments affect anything, but I really appreciate your help.

rridgely
Memory optimizers do not work. Ram is meant to be used and when windows needs more it will free up the ram on its own. Using those types of programs will if anything just make your computer slower.

Those software suggestions are just things I would try. Just disable/uninstall all of those things and if things seem better you know its one of them. If its not one of those then it could be other things.

To be honest this sounds more like a hardware issue. I think it would be a good idea to maybe test your ram and run a hard drive test program too.
http://www.memtest.org/

Since it goes by as time goes on heat could possibly be an issue too. The computer hasn't been moved into a poorly ventilated area or anything like that? Thats obviously not the only reason for over heating though.

Sorry I cant give you a definite "this is your problem and how to fix it" kind of answer but sometimes it goes that way. dry.gif
Tom AZ
QUOTE(rridgely @ Sep 6 2007, 03:17 AM) *
Memory optimizers do not work. Ram is meant to be used and when windows needs more it will free up the ram on its own. Using those types of programs will if anything just make your computer slower.

Those software suggestions are just things I would try. Just disable/uninstall all of those things and if things seem better you know its one of them. If its not one of those then it could be other things.

To be honest this sounds more like a hardware issue. I think it would be a good idea to maybe test your ram and run a hard drive test program too.
http://www.memtest.org/

Since it goes by as time goes on heat could possibly be an issue too. The computer hasn't been moved into a poorly ventilated area or anything like that? Thats obviously not the only reason for over heating though.

Sorry I cant give you a definite "this is your problem and how to fix it" kind of answer but sometimes it goes that way. dry.gif

Thanks again, I appreciate all your input.
Tom AZ
QUOTE(Tom AZ @ Sep 3 2007, 11:54 PM) *
It just seems like everything gets sort of "clogged" up -- like there's an accumulation of something somewhere, but I don't know what it is. A reboot seems to unclog things -- at least for a while.

Is there any way a third party software firewall could cause this kind of behavior?

Andavari
QUOTE(Tom AZ @ Sep 12 2007, 06:45 PM) *
Is there any way a third party software firewall could cause this kind of behavior?

Most third party firewalls cause an increased bootup time. As for slowing down other things some will go as far as effecting your installed antivirus making it take longer to finish a scan (namely the newest ZoneAlarm Free with the disabled Kaspersky Antivirus in it).

Depending upon when this started it may not even be your firewall at fault, it could be a Windows Update, an update to another resident/always running program, etc.
Tom AZ
QUOTE(Andavari @ Sep 13 2007, 04:12 PM) *
Depending upon when this started it may not even be your firewall at fault, it could be a Windows Update, an update to another resident/always running program, etc.

It's been happening for about a month now -- and real bugger to isolate -- just trial and error. But so far I haven't come up with anything. When it happens, it's always so quickly. Everything seems to be very normal -- then almost instantaneously, it just goes south. So, I have to reboot, and everything seems fine again -- for a while. That's why I've been trying to get the opinions of others -- hoping that someone might be able to put their finger on it because of a similar experience. I've even wondered if it could be a "clogged up" registry (whatever that is ohmy.gif ) -- or a video card (malware has been ruled out.) I suppose it could be just about anything -- it's just a matter of trying to find out what it is. Oh well, the beat goes on.

Daddypale
QUOTE(Tom AZ @ Sep 13 2007, 11:11 AM) *
It's been happening for about a month now -- and real bugger to isolate -- just trial and error. But so far I haven't come up with anything. When it happens, it's always so quickly. Everything seems to be very normal -- then almost instantaneously, it just goes south. So, I have to reboot, and everything seems fine again -- for a while. That's why I've been trying to get the opinions of others -- hoping that someone might be able to put their finger on it because of a similar experience. I've even wondered if it could be a "clogged up" registry (whatever that is ohmy.gif ) -- or a video card (malware has been ruled out.) I suppose it could be just about anything -- it's just a matter of trying to find out what it is. Oh well, the beat goes on.


Hi all,

Tom AZ... I`ve also had similar & just as perplexing slowdowns as you describe. Though mine tend to occur during browsing only & when changing pages only. It all seemed to start after I did a ""Optimize Reg" on CCleaner v.1.41. My HJT log looks clean but I still get slows a minute or two after first getting online with or without browser. I`m going to try some other fixes & see what happens including the removal of CC & Browser completely which includes Directory folders. Off I go...wish me luck. I`ll get back to this topic after the repair attempt.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.