Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer is continuously uploading something


  • Please log in to reply
4 replies to this topic

#1 UserNancy

UserNancy

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 12 October 2009 - 04:33 AM

I have already run ad-aware and I have avast which runs constantly. I used to have AVG but it got so slow (taking over 24 hours to do a daily scan) that I got rid of it, this was when I downloaded avast by recommendation of a friend.

I am barely more than a basic computer user. I don't know where to turn next. I can usually solve my problems with a quick Google search, if I can figure out what's wrong to begin with.

At night, the LAN icon on my computer has both monitors lit up, it's sending and receiving data continuously. My computer runs TERRIBLY slow when it does this. I have no idea what is wrong or what to do next. I have been trying to clean up my computer for a while now and I'm not making any progress.

If anyone would please give me some suggestion of what to try next I would greatly appreciate it. I'm going to try to set this to e-mail me when replies are posted, if it's able to do that.

Thank You,

Nancy

BC AdBot (Login to Remove)

 


#2 bradumd

bradumd

  • Members
  • 201 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Maryland
  • Local time:09:32 PM

Posted 12 October 2009 - 09:40 AM

Try downloading malware bytes from this link and running it. It seems that you may have a virus, I had a simliar problem at one point.

http://download.cnet.com/Malwarebytes-Anti...4-10804572.html

Just download it, update, and run a quick scan.

#3 Aus Smithy

Aus Smithy

  • Members
  • 160 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Brisbane QLD Australia
  • Local time:11:32 AM

Posted 17 October 2009 - 01:14 AM

What is active in TASK MANAGER when all this activity is present? Don't forget to hit the box at the bottom of the Processes tab that says "Show processes from all users".

#4 UserNancy

UserNancy
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 03 February 2010 - 10:09 PM

no process shows up when it's happening that doesn't show up during other times too

nothing under "Mem usage" or "CPU" is very high, the CPU usage runs at about 3-20%


Sorted by User Name running processes are:

LOCAL SERVICE (username)
svchost.exe
svchost.exe
alg.exe
svchost.exe
svchost.exe
Nancy (username)
firefox.exe
explorer.exe
MSASCui.exe
ashDisp.exe
ctfmon.exe
taskmgr.exe
NETWORK SERVICE (username)
svchost.exe
svchost.exe
SYTEM (username)
System Idle Process
System
smss.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
ashMaiSv.exe
ashWebSv.exe
svchost.exe
MsMpEng.exe
svchost.exe
wmiprvse.exe
aswUpdSv.exe
ashServ.exe
spoolsv.exe
svchost.exe
ViewpointService.exe
unsecapp.exe


between the time that I started this thread and today the windows malicious software removal tool has removed something, i don't know if it was what was causing the problem or not as I haven't been on my computer as much lately. My computer is running better, but it still gets pretty slow sometimes. I'll try to remember to check the processes again if it seems to be stuck up/downloading things without running anything. I know I've checked them before and not found anything unusual, everything above is always there (except if I have firefox closed). Nothing is running right now besides firefox and task manager and anything that always runs in the background (including ad-aware and avast!) I have a tab open with hotmail open and a download processing for the malwarebytes which is completed pretty quickly.


WOW I just realized how long ago I posted this initially. o.o I've been terribly busy and I just was going through my e-mail and had an e-mail notifying me of a reply to my thread. I didn't realize it had been over 3 months. I honestly don't think anything's really changed except my level of tolerance.

Edited by UserNancy, 03 February 2010 - 10:11 PM.


#5 UserNancy

UserNancy
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:32 PM

Posted 03 February 2010 - 10:36 PM

UGH

i thought i got rid of mywebsearch and zango a couple years ago once this computer became solely under my control. EW there's still traces of it? BLEH

I'm glad to get rid of all this scum :huh: thanks for the recommendation of malwarebytes.

Malwarebytes' Anti-Malware 1.44
Database version: 3686
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/3/2010 8:35:47 PM
mbam-log-2010-02-03 (20-35-47).txt

Scan type: Quick Scan
Objects scanned: 134547
Time elapsed: 15 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 26
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{067c6a37-72ea-4437-863a-5be20c246f3c} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1a2af056-1fe1-47ca-993d-5d09d18e674e} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b247f5bf-bd9d-4ecd-8fc1-365f36a1fda1} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbbfb891-98ae-4678-86f3-bd5a2eed86c9} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bf1bf02c-5a86-4ecf-adac-472c54c4d21e} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{914a8f99-38e4-47ec-b875-2b0653516030} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0ac49246-419b-4ee0-8917-8818daad6a4e} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99410cde-6f16-42ce-9d49-3807f78f0287} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f31a5d11-bf0b-4a4e-90af-274f2090aaa6} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8109fd3d-d891-4f80-8339-50a4913ace6f} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Rogue.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Rogue.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Rogue.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Rogue.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\seekmosa (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Rogue.Ascentive) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Ruth\Application Data\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ruth\Application Data\FunWebProducts\Data (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ruth\Application Data\FunWebProducts\Data\Ruth (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\SysRestore.dll (Rogue.Ascentive) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nancy\Local Settings\Temp\nsl65.tmp\Resource.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ruth\Application Data\FunWebProducts\Data\Ruth\avatar.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users