Author Topic: [Complete]issues do to potential malware infection or failing graphics card  (Read 1575 times)

0 Members and 1 Guest are viewing this topic.

Offline PCBruiser

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 7354
Hi,

Get the drivers right from nVidia.  Here's the link for grabbing the correct drivers depending on which OS you are using:  http://www.nvidia.com/Download/index.aspx?lang=en-us  Use Option 2 and it should find the correct drivers for both your video and chipset.  If Option 2 does not find the correct chipset drivers, then use the one from Gateway.  It should find the video drivers easily.
« Last Edit: December 11, 2011, 10:54:50 AM by PCBruiser »
Don't Read?  Can't learn!

Offline ASydReign

  • Bronze Member
  • Posts: 89
Yeah, I had tried the option 2 scan already and it would just give me a driver for my gpu. Perhaps if I had the chipset drivers uninstalled and then ran the scan it would appear in the scan? I'll use the other one for now and we'll see how it works. Thanks for all the help, Bruiser.

Offline PCBruiser

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 7354
Grab the latest chipset driver set from Gateway - that should be OK.  The reason I want that installed fresh is that you might have corrupted chipset drivers, which could also be causing this type of issue, so I wanted that also done fresh.  The chipset drivers include slot management which includes the video slot.
Don't Read?  Can't learn!

Offline ASydReign

  • Bronze Member
  • Posts: 89
So I did all the steps and still the same ol'. I have replaced the battery, I have tried another cord with the monitor and I have removed, cleaned thoroughly and replaced the gpu and still, we have the same issue. I ran the computer without the gpu and the red lines were nowhere to be found. It allowed me to change resolution and everything. I'm starting to feel that it's my card :-(

I hope I did the steps correctly. I'm not sure if I was successful in removing the chipset drivers and replacing them clean. I guess now, unless the chipset drivers ARE in fact corrupted, we have to determine if the pci-e slot in the motherboard is functioning properly. What do you think, Bruiser?

Thanks for all the help!

Offline PCBruiser

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 7354
Hi,

I think it might well be the vidcard.  Or, the motherboard (much less likely).  First, do you have access to another vidcard you can slip in your system and see if the problem persists?  If it does, then it is probably the motherboard.  If not, then it is the vidcard.  Maybe you can borrow a friend's or family member's card for a short time?  Or maybe you have an older one hanging around?  If not, then I'd really like to see some screen shots.  One from boot in the bios, a second from Safe Mode and a third in normal Windows.  The reason I want the bios and Safe Mode is they use native drivers.  If the problem shows up in those shots, then it is hardware - vidcard most likely.  You will need to use a camera to take a bios shot - if you don't have a camera, then skip that one.  For Safe Mode and normal Windows, you can grab a free screenshot program from here:  http://www.snapfiles.com/freeware/gmm/fwscreen.html  There are a number of excellent and completely free screen shot utilities.

Edit - there is one other possibility:  Your PSU!  If that is having issues, it might not be supplying enough power to the vidcard to run it.  What you need to test it is one of these:  http://www.newegg.com/Product/Product.aspx?Item=N82E16899261023&cm_sp=DailyDeal-_-99-261-023-_-Product or the equivalent.  Even Radio Shack carries them, although theirs are more expensive.
« Last Edit: December 16, 2011, 08:29:21 AM by PCBruiser »
Don't Read?  Can't learn!

Offline ASydReign

  • Bronze Member
  • Posts: 89
You know, I was just at Fry's thinking about picking up a newer/cheaper vidcard to do just that but now that you say the PSU I think that that could very well be the issue also. The fan on the graphics cards doesn't sound like it's running (but then again, it was only ever truly audible when it was running a game and it hasn't done that in quite awhile). I already placed my order for the tester so we'll see how that goes. If it doesn't come with any decent instruction I may have to ask you how to correctly test it, but I'm pretty sure it's simply hooking up the wire connected to my gpu to the tester to see if it's supplying power.

I may just pick up a newer GPU from Fry's (surprisingly they have some good deals on EVGA Nvidia's scattered about so we'll see). I'll keep you posted! Don't close the topic just yet! :-P

Thanks Bruiser!

Offline PCBruiser

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 7354
Those testers are easy to use and handy as well.  I always test new PSUs and periodically test the ones in my systems.  You disconnect the large main power supply cable from the motherboard (IMPORTANT - remember to disconnect the wall power first!!!), then connect the lead you want to test to the meter.  Reconnect the wall power and turn the PSU on.  The display will then give you an accurate voltage reading.  Test each lead individually, and you can determine whether the PSU is within specs or not.

If you decide to get a new vidcard, remember to check NewEgg as well.  At least that will give you a good starting point for pricing.
« Last Edit: December 17, 2011, 09:29:09 AM by PCBruiser »
Don't Read?  Can't learn!

Offline ASydReign

  • Bronze Member
  • Posts: 89
Hey, Bruiser! Well, allow me to update you on the situation.

I went to Fry's after checking some prices on GPU's on Newegg and picked up a EVGA gtx 550ti. Newegg had it listed at $114.99 after a $20 mail in rebate but I guess if you follow through with the rebate procedure it voids your warranty (or so a comment said). Fry's had the same card for $139.99 so I just picked it up there. Got home and installed it and, wouldn't you know, EVERYTHING works fine again and my preformance is even better than before with my old 9800 gtx. No red lines, no funky resolution problems, nothing but crystal clear colors and some badass gaming. So I guess it was the GPU, which is a pity because I would have liked to use it in another computer that I would have solely hooked up to the TV in my living room to go on the internet and such.

I still have the tester coming in from Newegg so I still plan on testing all of that out to make sure I don't need to replace my power supply. I guess all I really need to do now is clean up my computer a bit (remove unused programs/games and defrag). Do you feel there is anything I should do before I breath a sigh of relief other than test the PSU? Any scan you would like me to run to see how the GPU is holding up? Any tips you can give me to improve overall performance?

Thanks for all the help, Bruiser! Learn something new each time you guys troubleshoot with me ;-) 

Offline PCBruiser

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 7354
Hi,

Well, that's not surprising with the symptoms your system was exhibiting.  That GTX 550TI is a good GPU, and it should blow the 9800GTX away in terms of performance.  I would definitely test the PSU when the tester arrives, but at this point, if all is working you should be OK.  Do install new video drivers, that is a newer GPU and your old drivers may not totally support the new card's capabilities.  Then make sure your Windows is completely up to date.  If you are using W7, then redo the system performance tests, W7 relies on the results of those tests to optimize performance of your hardware.

We can do a few things to check that you have your setup "lean and mean".  Run dxdiag from the command line like we did earlier and make sure everything is working.   Next, to in order to offer appropriate suggestions (and to give the system a quick check for malware, which I don't expect at this point), I need to see some additional information about what is happening in your machine. 
Please perform the following scan:
  • Download any one of the following DDS files by sUBs from one of the following links.  Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.   
  • When done, DDS will open two (2) logs

         1. DDS.txt
         2. Attach.txt
  • Save both reports to your desktop.
  • The instructions here ask you to attach the Attach.txt.

 
  • Instead of attaching, please copy/paste both logs into your next reply.

  • Close the program window, and delete the program from your desktop.
Please note:  You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet. 
Information on A/V control HERE
Don't Read?  Can't learn!

Offline ASydReign

  • Bronze Member
  • Posts: 89
Okay, finished the scans. Let's start with the dds logs. Oh, and I had already used driversweeper before installing the new GPU and updated the drivers so that should be good. I ran an Avira full system while sleeping and that went without a hitch as well. I remember reading somewhere on the internet that the is a program that you can download that will uninstall all unnecessary stock programs (wildtangent games, trial software, ect.) all in one sweep. Have you heard anything about that? I think something like that would free up a lot of memory. Also, although I plan on buying a new computer, I want to get the computer prepared for a life of servitude to my t.v. so I'll probably be upgrading the ram since it's on the cheap at the moment. Think can this rig handle/utilize 6gb's of ram? Thanks for all your help, Bruiser!

Attach log:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 11/17/2007 3:27:38 PM
System Uptime: 12/20/2011 2:17:05 AM (0 hours ago)
.
Motherboard: ELITEGROUP |  | MCP61PM-AM
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 6000+ | Socket AM2  | 3000/201mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 455 GiB total, 188.745 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 4.522 GiB free.
E: is CDROM (CDFS)
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
 Update for Microsoft Office 2007 (KB2508958)
AAC Decoder
AbiWord 2.6.8
Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe Audition 1.5
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.1)
Age of Conan - Hyborian Adventures
Alien Swarm
Apple Application Support
Apple Software Update
AutoUpdate
Avira Free Antivirus
Borderlands
Browser Address Error Redirector
CCleaner
City of Villains/City of Heroes (remove only)
Civilization III
Compatibility Pack for the 2007 Office system
CPUID CPU-Z 1.59
Creative MediaSource 5
Curse Client
D3DX10
Diablo II
Digital Media Reader
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
Driver Sweeper 1.5.5
EA Download Manager
EVEREST Home Edition v2.20
Fallout 3
ffdshow (remove only)
FINAL FANTASY XI
Game Console - WildGames
Gateway Connect
Gateway Games
Gateway Recovery Center Installer
H.264 Decoder
Heroes of Might and Magic V
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Java Auto Updater
Java(TM) 6 Update 29
LabelPrint
League of Legends
Malwarebytes' Anti-Malware version 1.51.2.1300
Marvell Miniport Driver
Mass Effect
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Money Essentials
Microsoft Money Shared Libraries
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft Works
Microsoft WSE 2.0 SP3 Runtime
MKV Splitter
Morrowind
Mozilla Firefox 8.0 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Neverwinter Nights 2
NVIDIA 3D Vision Controller Driver 285.62
NVIDIA 3D Vision Driver 285.62
NVIDIA Control Panel 285.62
NVIDIA Graphics Driver 285.62
NVIDIA HD Audio Driver 1.2.24.0
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.11.0621
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.5.20
NVIDIA Update Components
OGA Notifier 2.0.0048.0
Pando Media Booster
Pepsky Free Mp3 CD Maker  4.3.6.916
PlayNC Launcher
PlayOnline Viewer & Tetra Master
Power2Go 5.0
PS2 Multimedia Keyboard Driver
PunkBuster Services
QuickTime
Razer Imperator
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
RIFT
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Segoe UI
Sins of a Solar Empire
Skype™ 5.5
Soft Data Fax Modem with SmartCP
SPORE™
Spybot - Search & Destroy
StarCraft
Steam
System Requirements Lab
Team Fortress 2
TES Construction Set
Titan Quest
UE3Redist
Unreal Tournament 3
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.762
Ventrilo Client
VLC media player 1.1.11
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin
World of Warcraft
Yahoo! Messenger
.
==== Event Viewer Messages From Past Week ========
.
12/20/2011 2:19:07 AM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  i8042prt
12/17/2011 8:24:10 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
12/17/2011 8:24:10 PM, Error: Service Control Manager [7000]  - The Windows Search service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
12/17/2011 8:17:42 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
12/17/2011 7:44:41 PM, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:37 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
12/17/2011 7:44:35 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
12/17/2011 7:44:32 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD avipbb avkmgr DfsC i8042prt NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr ssmdrv tdx Wanarpv6
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error:  A device attached to the system is not functioning.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error:  A device attached to the system is not functioning.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.
12/17/2011 7:44:32 PM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Server service which failed to start because of the following error:  The dependency service or group failed to start.
12/17/2011 7:43:58 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
12/17/2011 7:43:58 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
12/17/2011 7:43:58 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
12/17/2011 7:43:48 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/17/2011 7:43:30 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
.
==== End Of File ===========================


DDS Log:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_29
Run by ASydReign at 2:46:14 on 2011-12-20
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3070.1933 [GMT -8:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Razer\Imperator\RazerImperatorTray.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\real\realplayer\Update\realsched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\windows\system32\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [1925664506] c:\users\asydre~1\appdata\local\temp\\jucheck.exe
uRun: [KeyboardBackupBackup] rundll32.exe
mRun: [Razer Imperator Driver] c:\program files\razer\imperator\RazerImperatorTray.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{7AC926DA-5804-4E34-BC8F-8447497809E9} : DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
STS: Deskscapes Class: {ec654325-1273-c2a9-2b7c-45d29bce68fb} - c:\program files\stardock\object desktop\deskscapes3\deskscapes.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\asydreign\appdata\roaming\mozilla\firefox\profiles\3e96shrn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 62242
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-11-10 36000]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-11-10 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-11-10 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-11-10 74640]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-12-13 21992]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2010-5-30 21504]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-12-17 2253120]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-10-15 381248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-12-17 139880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-5-30 22216]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-5-30 366152]
.
=============== Created Last 30 ================
.
2011-12-18 04:16:04   3602816   ----a-w-   c:\windows\system32\ntkrnlpa.exe
2011-12-18 04:16:04   2043904   ----a-w-   c:\windows\system32\win32k.sys
2011-12-18 04:16:03   3550080   ----a-w-   c:\windows\system32\ntoskrnl.exe
2011-12-18 04:16:03   2409784   ----a-w-   c:\program files\windows mail\OESpamFilter.dat
2011-12-18 04:16:02   49152   ----a-w-   c:\windows\system32\csrsrv.dll
2011-12-18 04:16:01   429056   ----a-w-   c:\windows\system32\EncDec.dll
2011-12-18 04:15:59   2048   ----a-w-   c:\windows\system32\tzres.dll
2011-12-18 03:54:06   6350144   ----a-w-   c:\windows\system32\nvcpl.dll
2011-12-18 03:54:06   3840320   ----a-w-   c:\windows\system32\nvsvc.dll
2011-12-18 03:54:06   203072   ----a-w-   c:\windows\system32\nvmctray.dll
2011-12-18 03:54:06   123712   ----a-w-   c:\windows\system32\nvshext.dll
2011-12-18 03:54:06   1136448   ----a-w-   c:\windows\system32\nvvsvc.exe
2011-12-18 03:54:05   602432   ----a-w-   c:\windows\system32\easyupdatusapiu.dll
2011-12-18 03:53:42   --------   d-----w-   c:\programdata\NVIDIA Corporation
2011-12-13 12:02:14   --------   d-----w-   C:\cabs
2011-12-13 11:33:43   21992   ----a-w-   c:\windows\system32\drivers\cpuz135_x32.sys
2011-12-13 11:33:43   --------   d-----w-   c:\program files\CPUID
2011-12-06 15:41:52   11776   ----a-w-   c:\program files\mozilla firefox\plugins\nprjplug.dll
2011-12-06 15:41:43   --------   d-----w-   c:\program files\common files\xing shared
2011-12-06 15:41:38   150696   ----a-w-   c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-12-06 15:41:34   108544   ----a-w-   c:\program files\mozilla firefox\plugins\nprpjplug.dll
.
==================== Find3M  ====================
.
2011-12-06 15:41:30   348160   ----a-w-   c:\windows\system32\msvcr71.dll
2011-11-13 10:56:38   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-03 22:47:42   1798144   ----a-w-   c:\windows\system32\jscript9.dll
2011-11-03 22:40:21   1427456   ----a-w-   c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47   1127424   ----a-w-   c:\windows\system32\wininet.dll
2011-11-03 22:31:57   2382848   ----a-w-   c:\windows\system32\mshtml.tlb
2011-10-20 00:56:50   74640   ----a-w-   c:\windows\system32\drivers\avgntflt.sys
2011-10-20 00:56:50   36000   ----a-w-   c:\windows\system32\drivers\avkmgr.sys
2011-10-15 08:54:52   321856   ----a-w-   c:\windows\system32\nvStreaming.exe
2011-10-15 08:53:00   919872   ----a-w-   c:\windows\system32\nvdispco32.dll
2011-10-15 08:53:00   877376   ----a-w-   c:\windows\system32\nvgenco32.dll
2011-10-15 08:53:00   7041856   ----a-w-   c:\windows\system32\nvwgf2um.dll
2011-10-15 08:53:00   61248   ----a-w-   c:\windows\system32\OpenCL.dll
2011-10-15 08:53:00   5578560   ----a-w-   c:\windows\system32\nvcuda.dll
2011-10-15 08:53:00   2458432   ----a-w-   c:\windows\system32\nvapi.dll
2011-10-15 08:53:00   2401088   ----a-w-   c:\windows\system32\nvcuvid.dll
2011-10-15 08:53:00   2099520   ----a-w-   c:\windows\system32\nvcuvenc.dll
2011-10-15 08:53:00   18871616   ----a-w-   c:\windows\system32\nvoglv32.dll
2011-10-15 08:53:00   17248576   ----a-w-   c:\windows\system32\nvcompiler.dll
2011-10-15 08:53:00   13205312   ----a-w-   c:\windows\system32\nvd3dum.dll
2011-10-15 08:53:00   10327360   ----a-w-   c:\windows\system32\drivers\nvlddmkm.sys
2011-10-03 12:06:03   472808   ----a-w-   c:\windows\system32\deployJava1.dll
.
============= FINISH:  2:46:45.59 ===============

Now the Dxdiag log I will have to attack because the site says that it forbids me to post due to a "possible trojan attack or infection". It's happened before but I don't know why.


Offline ASydReign

  • Bronze Member
  • Posts: 89
Oh, and about the RAM, what would you suggest I get? I can usually find a list of compatible sticks somewhere online but am having no luck with this old motherboard. Have an idea of where I could start to find some new compatible sticks? Thanks!

Offline PCBruiser

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 7354
Hi,

How much RAM do you currently have?  Try using Crucial's memory finder to see what the specs for add on memory would be.  http://www.crucial.com/  Your MB is Ecs MCP61PM-AM, and the specs are here:  http://www.ascendtech.us/ecs-mcp61pm-am-dual-core-am2-motherboard_i_mb64ecsmcp61pma.aspx  This would take 2 or 4 RAM sticks, and they should all be the same size.  So, it would take 2, 4 or 8 GB of RAM, not 6 GB.  Grab CPU-Z (you have an old version, v1.35, maybe 1.59 the log suggests both, and current is 1.52.2) and PCWizard from here:  http://www.cpuid.com/  and that will tell you what is in your system right now, including RAM (sizes and timings).  If you are unsure, just post a screen shot of CPU-Z (the Memory tab), and the Mainboard tab from PCWizard.  Click on Physical Memory before getting the screenshot as that has the RAM specs.  I'll find comparable for you if you want.  RAM is very inexpensive these days, so it is a good time to stock up, and NewEgg always has specials for RAM going.  I got 16GB of GSkill DDR3 (PC1600) for less than $70 recently.  Note that Vista is a RAM hog, but 4 GB should be enough, and for W7 it is ample (see my W7 comment below), that might be a better way than upgrading RAM.  8 GB might be marginally better, but you won't notice all that much improvement, it will be very marginal over 4GB.

Depending on your needs, you might consider upgrading to W7.  That is much more efficient than Vista - faster boot times, more stable, more responsive.  And, 64 bit also, I'm pretty sure that board and CPU handle that as well.  $100 at NewEgg but shop around, you can occasionally find it on sale.  Windows Home http://www.newegg.com/Product/Product.aspx?Item=N82E16832116986 is what you would need.

Quote

I remember reading somewhere on the internet that the is a program that you can download that will uninstall all unnecessary stock programs (wildtangent games, trial software, ect.) all in one sweep. Have you heard anything about that? I think something like that would free up a lot of memory.


I think this is what you were thinking of:  http://www.snapfiles.com/get/pcdecrap.html for getting rid of junk.  I've never used it myself, but it seems to be well reviewed.  You might also check this out:  http://www.snapfiles.com/get/soluto.html it works pretty well.  You can also grab WinPatrol, it has startup service and software controls.

The following startups are completely unnecessary, and you can kill them with either WinPatrol or Soluto:

uRun: [1925664506] c:\users\asydre~1\appdata\local\temp\\jucheck.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-12-13 21992]  (outdated)

and you can also disable (don't delete!!!) the Windows Search service - I think it is a useless waste of CPU cycles, as well as the companion Indexer.  Plus the AdobeARM service, that is also useless.  This too is cute, but unnecessary:  c:\program files\stardock\object desktop\deskscapes3\deskscapes.dll

I would uninstall:

Game Console - WildGames
Gateway Connect
Gateway Games
HiJackThis (outdated)
HijackThis 2.0.2  (outdated)
Pando Media Booster
Pepsky Free Mp3 CD Maker  4.3.6.916  (depending on where it was downloaded from - trusted sources only)

Quote

Now the Dxdiag log I will have to attack because the site says that it forbids me to post due to a "possible trojan attack or infection". It's happened before but I don't know why.


That's a bug in our anti-spammer filters which we are attempting to hunt down.  Unless there were errors in the log, I don't need to see it.  If there were errors and I need to review the log, zip the log and attach that.  That will bypass that filter.

I did not see any evidence of potential malware on the system in the DDS log.

I think that pretty well covers what I saw in the DDS logs and your questions.
Don't Read?  Can't learn!