|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (6 bit)
|
50 processes !!
Hey guys. I was going through my process list when I realized I don't know more than half of the names and that I was running so many processes. I had Trillian, MSN, Firefox, Printkey (always running in background - handy printscreen tool) and I think an FTP program running.
Other system info...Norton Internet Security, Omega Drivers + Multires and ati-taskbar, ad-aware + ad-watch, use itunes (I think that's where the ipod helper is from). I'll post the image of my processes. And any freedback would be appreciated. Maybe even things I dont want running or can get not to run. http://pseudo.dynamized.com/processes.jpeg Cheers. Last edited by Statica; 11-13-2005 at 08:39 PM. Reason: Changed inline image to link |
|
|
|
|
|
#3 |
|
~ Ryan ~
|
Go over to the security forum area and read the sticky on Hijack This, then proceed with dowloading it and running it FOLLOWING the guidelines pointed out in the sticky. Then post up your thread here and I will take a shot at cleaning it up. I have a feeling you have some unecessary start up programs and potential malware.
__________________
RiotCats.com, an internet domain specifically fabricated and visually erected for the appreciation of the feline kingdom! |
|
|
|
|
|
#4 | |
|
Member (6 bit)
|
Okay Ryan, I did an ad-aware scan and virus check. Also closed all programs before running Hijackthis. Here are the log results. I hope I did everything right :S
Quote:
|
|
|
|
|
|
|
#5 |
|
~ Ryan ~
|
You will want to boot in safe mode, then search and delete these file below and then run HJT and have it fix it. It is a spyware which is gathering information.
C:\WINDOWS\ALCXMNTR.EXE (find and delete this one) O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE (have HJT fix this one) This might help a little bit. For the R1s, if the URL your homepage it's OK. If it is not, check it and have HijackThis fix the entry. You can see now that you only have 33 processes running - much better than before. Alot of your processes before were directly related to Norton A/V - I am not a fan of it as it does use quite a bit of system resources, but it does a nice good at procting a computer. I hope that helps a bit - might not free up as many processes but I found a spyware entry. Last edited by rspassey; 11-13-2005 at 07:24 PM. |
|
|
|
|
|
#6 |
|
Member (6 bit)
|
Okay thanks, I will be booting in safe mode to do those in a second. I forgot to mention that I found this on ad-aware. Hopefully it is the one you detected.
![]() Also, what virus scan/firewall do you recommend. I use Avast on my other computer and zone alarm. I have used AVG Free previous to this. Thanks. And I'll let you know how the fix goes
|
|
|
|
|
|
#7 |
|
~ Ryan ~
|
I use a medly of AV and Firewalls on my computer. For AV right now it is Avast, and software Firewall is Zone Alarm. Both I would recomend very much. I also think some sort of router is needed - if you have one then your good, if not I would seriously consider thinking about it. I also recomend using Spyware Blaster it is great tool and I would definately say add it to your arsenal.
Also, do you mind if I copy your HJT log onto my site, SecurePc and leave it there for further examination? I had been known to spend over two hours on logs before, so I might be able to pick out something else. Good luck. |
|
|
|
|
|
#8 |
|
Member (6 bit)
|
Ya sure, you can archive the log. I don't believe there is anything on it that can track it to me.
|
|
|
|
|
|
#9 |
|
~ Ryan ~
|
No there is not.
|
|
|
|
|
|
#10 |
|
Member (6 bit)
|
I started in safe mode and did what you instructed. However...aclxmonitor comes up again when I do another test. In windows aclxmonitor is still deleted though. Same with R1.
|
|
|
|
|
|
#11 |
|
~ Ryan ~
|
Try this.
- Enter msconfig (run > msconfig > startup) - search the entries for ACLXMONITOR - uncheck the box - save settings and reboot - rerun HJT and see if it is there Does it now show up with (file missing at the end)? |
|
|
|
|
|
#12 |
|
Member (12 bit)
Join Date: Nov 2001
Location: Woodland Hills, CA (suburb of Los Angeles)
Posts: 4,014
|
Most of your processes look pretty legitimate, though the RealTek Monitor is annoying = it's not the worst. It's apparently loading from the HKEY_Local_Machine/Software/Microsoft/Windows/CurrentVersion/Run or RunService key. You can use regedit to remove it from there if you'd like (visit a tutorial about Registry editing, though, if you haven't before).
If your cpu is a good one, it can handle a lot of work. What will slow things down is if you end up needing to use your swap file much. You can check that in Task Manager - from time to time see how much memory is free. If you've used up most or all of what's available, a little extra from a new module might help. [Of course, make sure it matches, and doesn't exceed the maximum size module for your motherboard]. I'm sure ryan will find anything that's not kosher with the startups. The Coulomb Dialer is sometimes a false positive for a "Groove" player often used to play certain online games (the Nick jr. site requires these, for example). I'll assume you've removed the entry already: which is the safe thing to do. I believe the latest AdAware definitions don't falsely identify the game software anymore. [If you really had the dialer, and you have a modem in your PC, you'd have a bunch of area code 900 calls on your phone bill! - it's a porn dialer]. Best of luck . . . Gary [Another good malware doublecheck tool that I like to recommend is TrendMicro's HouseCall - http://housecall.trendmicro.com - it does require that you allow it's ActiveX control to run - but it's specific to the scan]. LATE EDIT - just saw your latest posts: 1) be sure you spell that process correctly when searching, it's "Alcxmntr.exe" and not "ACLx..." Last edited by GaryRouth; 11-13-2005 at 09:03 PM. |
|
|
|
|
|
#13 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,791
|
alcxmntr.exe is installed alongside hardware drivers for the Realtek AC97 audio device. This program is a non-essential system process, but should not be terminated unless suspected to be causing problems.
|
|
|
|
|
|
#14 | |
|
~ Ryan ~
|
glc, where did you find that? Everything I found stated that it is a monitoring program, and should be removed especially if you have had instances with other spyware.
Quote:
Last edited by rspassey; 11-13-2005 at 09:35 PM. |
|
|
|
|
|
|
#15 |
|
Member (6 bit)
|
The rededit method finally got rid of it. Thanks alot for the help guys.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|