1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

multiple task mgr processes open

Discussion in 'Malware and Virus Removal Archive' started by gghartman, 2006/10/24.

  1. 2006/10/24
    gghartman

    gghartman Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,130
    Likes Received:
    0
    client of mine when system comes up is getting up to 20 instances of task manager being open, also multiple instances of outlook processes opening. am running out to pick up machine and bring back to office but thought i would ask you all before i left. this machine is protected with spybot, adware, spywareblaster, bitdefender antivirus.

    had client do a restore to a week ago but problem still happening. any ideas???
     
  2. 2006/10/24
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    That's an odd one. No way to sy if it's malware related or not. Were those the only symptoms?

    Off hand I'd go for an online scan or two, then maybe DL and install AVG\Ewido Anti-Spyware as well. see what they find.

    Then go to this page, Panda ActiveScan
    • Click the 'Scan your PC' button. ( You may have to disable any pop up blockers)
    • Then press the green 'Check Now' button.
    • Enter your country and state along with a valid email address.
    • Allow the ActiveX install, it may be a few minutes for all components. (For XP SP 2 watch for the yellow bar at the top of IE)
    • Once installation is complete you will need to select a device to scan. Please select 'My Computer' and the scan will begin.
    • Once the scan is done, click the 'See report' button, then the 'save report' button. Be sure to save the log file created in a place easy for you to find.
    (Please edit out any cookie, Recyler and System Volume Information Folder references from the results)

    Then go Trend Micro to run the Trend Microâ„¢ HouseCall Scan.
    • Click Scan now. It's free!
    • Read and put a Check next to Yes I accept the terms of use.
    • Click the Launching HouseCall>> button.
    • If confirmed that HouseCall can run on your system, under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
    • You may receive a Security Warning about the TrendMicro Java applet, click YES.
    • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
    • Please be patient while it installs, updates, and scans your system.
    • Once the scan is complete, it will take you to the summary page.
    • Under Cleanup options, choose clean all detected infections automatically.
    • Click the Clean now>> button.
    • If anything was found you may be prompted to run the scan again, you can just close the browser window.


    Download AVG Anti-Spyware 7.5 formerly Ewido Anti-Spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    • Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    • Once the setup is complete you will need run ewido and update the definition files.
    • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine ".
    • Under "Reports "
    • Select "Automatically generate report after every scan "
    • Un-Select "Only if threats were found "
    Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.

    Reboot, into safe mode, this way:
    • Turn on the computer
    • Immediately begin tapping the <F8> key.
    • Use the arrow keys to highlight Safe Mode and press the <Enter> key.
    IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process.

    Launch ewido-anti-spyware by double-clicking the icon on your desktop.
    • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan ".
    • ewido will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions "
    • Next select the "Reports" icon at the top.
    • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    • Close ewido and reboot your system back into Normal Mode and post the results of the ewido report scan.(Please edit out any cookie, Recyler and System Volume Information Folder references from the results)


    If anything substantial is found then also give us a HJT log as well.


    HiJackThis v:1.99.1zip.
    DL the zip file to your desktop, then create a new folder on your C drive, called 'HJT' or 'HijackThis'. Then unzip the files to the new folder. When you run HijackThis.exe from C:\HJT folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary which is easily accessible.

    Run the program, and press Scan. You will notice the Scan button will turn into a "Save Log" button. Save the log and Post that log onto this topic. DO NOT DELETE or modify anything yet, as some of it is needed to keep your system in proper working order.
     

  3. to hide this advert.

  4. 2006/10/24
    gghartman

    gghartman Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,130
    Likes Received:
    0
    TeMerc

    weird is very accurate. so far have run spyware doctor found 4 ran spysweeper found none. 4 spywares aint enough to cause this problem. running dell diags on machine and so far nothing wrong. i usually use trendmicro online scan so will give that a try next.

    when i first got to clients site task mgr had opened up 20 instances of itself and outlook 4. even closing the process they still opened themselves back up. this is a nice dual core xp pro 1g memory and only 3 months old so it shouldnt have these types of problems not yet anyway.

    thanks for info. not a fan of panda but will also give them a try....greg
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.