Outline ·
[ Standard ] ·
Linear+
Acer TimelineX 3820TG & 4820TG, Owners and visitors discussion
|
sarf2k4
|
Feb 16 2011, 11:17 PM
|
|
QUOTE(lee_what2004 @ Feb 16 2011, 11:09 PM) Try upload that server.exe to http://www.virustotal.com/Just to check the hdd, can you download this and run the benchmark? http://crystalmark.info/software/CrystalDi...rk/index-e.htmlhere it is... i dunno much about this site and i guess this is one of the trojan as well? server.exe
|
|
|
|
|
|
sarf2k4
|
Feb 16 2011, 11:21 PM
|
|
QUOTE(lee_what2004 @ Feb 16 2011, 11:19 PM) Most likely trojan or something, the path is quite abnormal... so i delete them? ive been wondering about some trojans called dwh###.tmp that always resides in the temp area... what could this be mean? my av keep quarantining the file but it keeps coming like a horde in the LOTR. right now, its probably around 9k liao
|
|
|
|
|
|
sarf2k4
|
Feb 16 2011, 11:25 PM
|
|
QUOTE(lee_what2004 @ Feb 16 2011, 11:24 PM) I think you better do some virus scanning... didnt detect anything though since my av is symantec endpoint protection cos i hate those crybaby avs... asking what to do with the virus it found the hdd test
This post has been edited by sarf2k4: Feb 16 2011, 11:29 PM
|
|
|
|
|
|
sarf2k4
|
Feb 16 2011, 11:35 PM
|
|
QUOTE(lee_what2004 @ Feb 16 2011, 11:33 PM) The HDD looks fine, then most likely software problem that delay the startup... What about if you delete the files in the temp area? It still coming out ? Try use this to scan, http://www.malwarebytes.org/Install the free version is enough, it won't startup or anything, just use it to scan (after done the update first).. it wont... i dunno what does it do actually... wonder if its from the game booster itself?
|
|
|
|
|
|
sarf2k4
|
Feb 16 2011, 11:46 PM
|
|
QUOTE(lee_what2004 @ Feb 16 2011, 11:39 PM) Well, if one AV keep telling it successful to quarantine and it keep saying it, I straight uninstall it and use other AV to scan and done... At least that with happen with BitDefender and I change it to Avast... if ure referring to dwh###.tmp trojans, i dunno what kind of av to use that have the same features, auto update without prompt, remove upon browsing the explorer without any notifications it nvr tells me that this server.exe is trojan or something
|
|
|
|
|
|
sarf2k4
|
Feb 16 2011, 11:50 PM
|
|
QUOTE(elm0001 @ Feb 16 2011, 11:47 PM) i told my friend i'm considering this lappy, but then they wouldn't recommend me to buy because of the brand (acer) lolol. my friend said that as well, becos of their trauma with acer warranties so their families is 'anti-acer'... this thing is great for an all-rounder laptop with a great battery life... only that it comes with 2gb ddr3, which is a must add another 2gb ram, crapware also came with it but i just bought a chip mag today, they recommended 'Crapware Cleaner' to clean those crap softwares
|
|
|
|
|
|
sarf2k4
|
Feb 16 2011, 11:54 PM
|
|
QUOTE(cowithgun @ Feb 16 2011, 11:49 PM) 32bit processes are stored in HKLM\Software\Wow64Node\Microsoft\Windows\CurrentVersion\Run... if even msconfig cant detect, try use Autoruns (Microsoft)... autoruns? how? this shows me how noob i am in the registry keys, the server.exe not in the list Added on February 16, 2011, 11:55 pmQUOTE(lee_what2004 @ Feb 16 2011, 11:53 PM) I thought those just need to set the settings ? e.g. NOD32 » Click to show Spoiler - click again to hide... « other avs like avg, kaspersky, avira This post has been edited by sarf2k4: Feb 16 2011, 11:55 PM
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 12:40 AM
|
|
QUOTE(cowithgun @ Feb 17 2011, 12:01 AM) Autoruns will list ALL automated started program in your notebook; services, registry, browser helper object, drivers, etc, etc. 1 nice feature is that you can enable "Verification of Signer". this will tell you if the binary is being signed by who it claimed to be. usually, if it is "Verified", it's safe. u can also quickly hide all Microsft entry so u can focus on third party proggie... try play with it. but dun simply uncheck (to prevent it from autorun), might end up cannot boot! owh... this one... p/s the registry required to run this server.exe is HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run This post has been edited by sarf2k4: Feb 17 2011, 12:41 AM
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 01:30 AM
|
|
the mbam scan completed and it shows that server.exe is one of the malware as well
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 01:51 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 01:48 AM) Still running with 100 task ? now its 93 tasks... shoud i delete this server.exe for good?
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 02:00 AM
|
|
ok... deleted it... i wonder if it already infect my system and made it slower?
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 02:08 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 02:03 AM) Maybe... Noticed any suspicious from the task manager ? How's the boot time now ? or easier way to find the problem, see the list on the performance analyzer, which processes that delay too much.. or use this, http://www.soluto.com/It will display all the processes in the boot with their delay... im mote sure about the unsecapp.exe process, there r 2 of them each time i start windows... currently downloading something from hotfile.com so i cant restart my machine yet
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 02:22 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 02:12 AM) unsecapp.exe is fine, mine sometime have it also.. sometimes its very scary to see some of the processes have 2 instances in the task manager at the same time further more, its the same name. i personally think that its the boot processes and from what i remembers, upon entering the logon through the complete start of the processes for windows it would be normal for me i wonder y my laptop right now is quite hot... didnt run anything from what i remember that would make this machine goes hot
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 02:26 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 02:24 AM) See the temp ? Which one is >50C ? CPU or GPU? HDD ? its the cpu, constant 60'c
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 02:32 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 02:27 AM) Check the task manager ? The CPU usage? Still virus scanning ? no virus scanning cpu usage is around 5-40%... the gap r wide. avg is right around 20%
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 02:36 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 02:33 AM) See which processes take that up the CPU usage ? if u were saying under the cpu column, it would be firefox but i dont think firefox r able to make this machine under such a stress. the figures r around 4-10 or sometimes 20 but quite rare... im going to reboot after soluto finish up
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 03:01 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 02:38 AM) I do mean the CPU column... But at least, the firefox do contribute to the cpu usage.. owh... one of the factor also due to the area of my machine, which is no fan in where i sit with my laptop right now but still, i feel like its an unusual thing for my laptop to go hot without anything opened to stress this thing...
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 03:07 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 03:05 AM) There's nothing blocking the vent on the bottom side, right ? no... solid flat wood desk... used soluto and going to restart my pc for some changes if its true... spotted this norton ghost took a huge amount of time 170sec and tweaked some of the application and services into delay and pause, able to get about 2m 47s from soluto's boot estimation
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 03:22 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 03:13 AM) 2m 47s is still long though... Is this still include the norton ghost ? actual thing is 3:45mins recorded by soluto, the ghost already turned off. should i run the wpt again? i was considering of using the last resort for this, revert back to either factory default, using the recovery dvd+crapware cleaner+soluto+wpt, or clean format or use the ghost checkpoint
|
|
|
|
|
|
sarf2k4
|
Feb 17 2011, 03:32 AM
|
|
QUOTE(lee_what2004 @ Feb 17 2011, 03:29 AM) WPT should be run after everything has been done, no more program installation/uninstallation and such... Its the final part... Well, best result would be clean install + launch manager, that is enough, no need other acer apps... Nothing more can be disabled from soluto ? nothing more... other 154sec lies on the grey side of soluto which most of them r services... do u have any programs that can back up applications registry settings?
|
|
|
|
|