too many process modules!!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ahjan, Oct 20, 2004.

  1. ahjan

    ahjan Private E-2

    i have a dell dimension 4600 intel pentium 4 processor @ 3.0GHz with HT technology, 512 DDR SDRAM @ 400MHzith an 80gig HD. It is running very slow. I run every other day an updated McAfee virus scan, a2, Adaware 6, CWShredder, Stinger, and Spybot. Search keeps showing 8 wild tangent entries, which every time i delete, then when i boot up, i get an error message saying it can't find wild tangent - so i go to the wild tangent web site and download it again. A2 tells me today it can't update because an error occurred during the download process. I did update it two days ago. But the most telling issue seems to be when i run adaware it says there are 61 running processes and get this - 2406 process modules. I ran all the scans in safe mode after upddateing them two days agoand did find two malawares in a2 which i deleted, but it has not helped speed things up. any ideas? thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ad-aware 6 is out of date. You must update to Ad-Aware SE . Latest version is 1.05.
    If you do not want WildTangent, it must be uninstalled from Add/Remove programs.

    You should follow all the steps in: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    I know you stated you ran some of the items there but you did not run all of them and in the order we have stated. Plus, if you had one incorrect version of an application, you could have more. Make sure you check the links we give and you have the version in those links.

    Then tell us where you stand.
     
  3. ahjan

    ahjan Private E-2

    ok, i faithfully followed all your instructions. i made sure i had updated windows, i booted my windows xp in safe safemode.
    ran trend micro (Clean)
    Symantec security check(you are protected against most common
    security threats)
    CC CLeaner and i checked delete index.dat
    adaware se personal build 1.05 with updates. adaware showed 14
    running processes and 533 process modules but that was probably
    because it was in safe mode. it had three negligilbe objects which i
    removed.
    Ran McAfee, updated, it was clean
    A2 found malaware C:\Program Files\WildTangent|System Config0100.dll,
    so i removed that.
    Spybot, updated and imunized. it found Avenue A -1entry
    Advertising.com - 2 entries
    Double click - 1 entry
    DSO Exploit - 5 entries
    Link Synergy - 1 entry
    Wild Tangent - 8
    I told spybot to fix the selected problems and i got the following error
    messages.
    this application has failied to start because msjava was not
    found. Reinstalling the application may fix this problem.(what
    application msjava or spybot?)

    this application WDEngine.dll was not found. Reinstalling this
    application may fix this problem. (Again reinstalling what -
    spybot or WDEngine.dll whatever that is.)

    The Application orDLLC:\WINDOWS\wt\wtupdates\Webd\
    4.1.1\files\legacy\webdriver.dll is not a valid windows image.
    please check this against your installation diskette. (What
    does that mean? I have the dell diskettes, but have no idea
    how to use them)

    The Application or DLL C:\WINDOWS\wt\wtupdates\Webd\
    4.1.1\files\legacy\webdriver\wt3d.dll is not a valid windows
    image. Please check this against your installatioin diskette.
    (What does that mean?)

    Then it said 18 problems were fixed.

    Stinger had 86900 clean files.
    About Buster - found no ADS on system.
    CWShredder - found nothing
    Kill2Me if was present it was removed.
    HS REmove v.2.39 - no items were removed. removal complete

    Now when I boot up I get an error message that says error loading C\Program
    Files\WildTangent\Apps\CDA\cda\Engine0400.dll. The specified module could not be found. I can install from the web site, but the it keeps showing up in my spybot scans and A2. Why is that? Are there good and bad versions of wild tangent and maybe i am getting some bad versions when i go on the internet? or can i tell spybot and a2 to ignore wild tangent? I tried to run adaware again when i booted up and it showed 42 running processes and 1560 process modules. is that manking my computer slow? Thanks!!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had said in my previous message to use Add/Remove Programs to uninstall WildTangent. Using the scanners does not typically do a complete job and that is why you had all these messages. Including the WDENGINE.DLL one.

    WDENGINE.DLL is not associated with or required for Spybot to run; it is associated with WildTangent software. If Spybot is mentioning that the dll is not found, just ignore it; as I said it's your choice whether to remove WildTangent or not.

    You can try going to Add/Remove programs now to uninstall all WildTangent stuff but it will probably fail due to the stuff deleted manually. Sometimes the only way to fix this is to reinstall WildTangent and then uninstall.

    Post a HijackThis log as an attachment.
     
  5. ahjan

    ahjan Private E-2

    i reinstalled wild tangent. then to be sure i went to documents & settings which for some reason had an entire wt folder. i deleted everything in there, then went to control panel, uninstall and uninstalled and for a time there seems to be no more wild tangent. WHAT are these process modules that keep showing up in adaware? I ran it again today and adaware still showed 55 running processes, which is probably normal, but it still showed 2053 process modules. I thionk that is excessive and i know i did not always have anywhere near that number.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The more programs you have running (especially browser windows and scanners etc) the more process modules. I typically run around 1230 with no programs open but I only have about 35 processes running. Opening one IE browser causes it to jump to 1335. Opening 3 IE browsers and I'm at 1481. Check what you have right after reboot without running anything. You have a lot more process loading (almost double what I have) at startup.
     
  7. ahjan

    ahjan Private E-2

    i rebooted and had 41 running processes and 1433 process modules. way too many. my husband & I are retired so even if we spend time on the internet it is not game sites or music stuff, but my children come home once a week usually and although they don't spend a lot of time on the computer, they could be going to sites that would give them weird stuff on my computer.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! In message #4 I said post a HijackThis log.

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or from a sub-folder of C:\Documents and Settings, or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  9. ahjan

    ahjan Private E-2

    i hope the log file is attached, if not i will try and resubmit
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you put HijackThis in the correct type of directory but you did not download HijackThis from the link we gave you. Thus you have the wrong version. Also you still had a browser running (C:\Program Files\Internet Explorer\iexplore.exe).

    So go back to the READ ME FIRST and click the link for HijackThis and get the correct version and put it in the directory your have already created (thus overwriting the old version). Then exit all of your browser sessions (this one too). And run a scan and save your log to a text file. Then re-open your browser and come back here and post the new log. The new HJT detects many more items and does a better job fixing too. We need this before continuing.
     
  11. ahjan

    ahjan Private E-2

    i've think this should do it, i hope.
     
  12. ahjan

    ahjan Private E-2

    well, i thought i had it, i'll try again.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use this Viewpoint Manager stuff that AOL put on your system:
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    If not, goto Add/Remove Programs and uninstall it and the Toolbar that came with it too.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/056f4317b970e9cb3d05/netzip/RdxIE601.cab


    And unless you know what the below line is and know you need it, fix it too.
    O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://www.makeoversolutions.com/save/makeover.cab


    And if you want to cut down on running processes the below items do not need to be run at startup either.
    4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

    Tell me what you have decided to do and if you want to do any additional cleanup. I'm sure we could find more items that are not required.
     
  14. ahjan

    ahjan Private E-2

    i don't use AOL so i removed viewpoint mgr. i also removed all the other lines including 016 - DPF:{17D7290-7A15-11D4-921E-0080C8DQ7A5E} (AimSp32 Class) -http://www.makeoversolutions.com/save/makeover.cab

    The last four on the bottom of your message, i didn't know if i should remove them by clikking fix on hijackthis or by going to the startup menu. i checked startup and there was nothing there like those, but after the warning when i deleted the other lines, i was unsure how to proceed with these.

    Also, when i run spybot and it shows in the bottom left what it is scanning of the 17,000 items are included the following:
    All-in-one-telcom
    Direct Dialer
    Money Tree
    XDiver
    Main Paen
    Teen Sex
    Web Dialer
    Ad Goblin
    CoolWWWSearch
    CoolWWWSearchHome Search
    CoolWWWSearchSmaart Search
    Free Scratch&Win
    KXplorer
    SearchCentrix
    StatBlasterMemory
    SCKeyLog
    CouponSaver
    Xabot
    GAIN.Gator
    G.Lap
    BonziBuddy
    Dropper
    HackATask
    GoldenPalaceCasino
    N'Case
    HangUpTeam.Technic.Rat

    That's all i could write as i saw it flashing by. some stuff i recognize, but what the heck is the rest of this stuff. Is it on my computer? How can I get rid of it, if i don't know where it is. Also after the hijack this corrections, I still have 412 processes running and 1432 process modules. help!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those last 4 items:
    4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

    I am suggesting you fix with HijackThis. That will remove the lines that cause those processes to run at startup. They are not necessary. If you do not use QuickTime or MusicMatch, you could also choose to uninstall them from Add/Remove programs. That's up to you. QuickTime is need for some types of media playback but you don't need to run the task at startup.

    Ignore those items you see in Spybot's window, they are only showing you what it is currently scanning for not what it is finding.

    I think you had a typo. You do not have 412 processes running, do you? If you did, you PC would probably be at a stand still.
     
  16. ahjan

    ahjan Private E-2

    you are correct, it is 41 running processes. what about these:
    04 - HKCU \..\ Run:[ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    016 - DPF {74D05D43-3236-11D4-BDCD-00C04F9A3B61}(House Call
    Control - http://a840.g.akamai.net/7/840/537/2004061001
    /housecall.trendmicro.com/housecall/xscan53.cab
    My computer is running a little faster, but not as much as it used to. any other ideas?
     
  17. ahjan

    ahjan Private E-2

    after removing those four 04 items i am at 38 running processes and 1376 process modules. my husband uses weather bug, could that be a culprit or is that harmless;he uses it when he travels? also under the "hot lights" one of my daughters admitted to playing "fishy" on addicting games.com and she looked at some comments on the "fishy forum" and then logged off.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WeatherBug should be uninstalled using Add/Remove programs. The free version adds other crap to your computer and causes ads to popup. You do not want it.

    Run Ad-Aware SE and when it finishes scanning, save the log to a text file and post it here as an attachment. Make sure you only have the same things running as when you said,
    "i am at 38 running processes and 1376 process modules."
     
  20. ahjan

    ahjan Private E-2

    hope this works!
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here are a couple more processes for you to decide if you really need them:

    #:22 [dsentry.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 516
    ThreadCreationTime : 10-27-2004 7:55:22 PM
    BasePriority : Normal
    FileVersion : 1, 0, 5, 0
    ProductVersion : 1, 0, 5, 0
    ProductName : Dell - DVDSentry
    CompanyName : Dell - Advanced Desktop Engineering
    FileDescription : DVDSentry
    InternalName : DVDSentry
    LegalCopyright : Copyright © 2002 Dell
    OriginalFilename : DSentry.exe
    Comments : DVDSentry launches your software DVD player when a DVD is inserted.
    dsentry - dsentry.exe - Process Information
    Process File: dsentry or dsentry.exe
    Process Name: Dell DVD Sentry

    Description:
    dsentry.exe is an application provided by Dell. It stops the autorun application from executing
    on disc insertion. This is a non-essential process. Disabling or enabling this is down to user
    preference


    #:31 [notifyalert.exe]
    FilePath : c:\Program Files\Dell\Support\Alert\bin\
    ProcessID : 1260
    ThreadCreationTime : 10-27-2004 7:55:23 PM
    BasePriority : Normal
    notifyalert - notifyalert.exe - Process Information
    Process File: notifyalert or notifyalert.exe
    Process Name: Dell Notifier

    Description:
    notifyalert.exe is a process belonging to Dell support which notifies you regarding critical
    updates from Dell whenever applicable. This is a non-essential process. Disabling or enabling
    this is down to user preference
     
  22. ahjan

    ahjan Private E-2

    how do i disable these?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For Dsentry, have HijackThis fix the below line:
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe


    For the the other item it may be necessary to remove the Dell Support stuff. You should really determine whether you need this first before removing it. The line in HJT shows up as:
    O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe

    It most likely also causes the running of the notifyalert program too. If you decide that this Dell Support stuff is not require by you, look in Add/Remove programs for an uninstall.
     
  24. ahjan

    ahjan Private E-2

    if that is the case, then i don't think i will get rid of either one of them. i hate to fool with any of the dell stuff anyway. it's like of you fool with the dell stuff, then you get the dell curse and nothing works. everything seems to be working better now, so i won't try and do anything else that may destroy that equilibrium. thank you very much.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Fair enough! I personally remove all those kinds of programs as I never need them. But for people who still use the PC manufacturer's support lines, it may be best to leave them in place.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds