This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC is loading very slowly

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

errrm antivir guard keep detecting a virus or unwanted program found
C:\Program Files\…\BackWeb-1940576.exe is the TR/Agent.16384.CX trojan.

this is my HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:08:52 AM, on 2/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qsg10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9415/tudouva.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall getPlus® for Adobe] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

–
End of file - 6184 bytes
Hi chankfj,

Are you using an HP/Compaq computer?

This is a legitamate program that comes bundled on Compaq machines. It checks for updates from Compaq. Antivir may be detecting it because of it's behavior. Just to be certain, we'll check the file. :)

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file paths, one at a time into the "Suspicious files to scan" box on the top of the page:
  • wait for the results before submitting the next file

    C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Thanks
this is the log:


VirSCAN.org Scanned Report :
Scanned time : 2009/02/17 11:57:13 (SGT)
Scanner results: 11% Scanner(4/37) found malware!
File Name : BackWeb-1940576.exe
File Size : 16384 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 708fc5318f6ab059104ffd415f146781
SHA1 : 278038c76e058c4ad45fb53776b41c24fe7b45f5
Online report : http://virscan.org/report/8c0e85040a00a4f0…f8429bbe2f.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090216231831 2009-02-16 2.22 -
AhnLab V3 2009.02.17.00 2009.02.17 2009-02-17 2.87 -
AntiVir 7.9.0.79 7.1.2.33 2009-02-16 1.77 TR/Agent.16384.CX
Antiy 2.0.18 20090216.2186924 2009-02-16 0.12 AdWare/BackWeb.a[:not_virus]
Authentium 5.1.1 200902161542 2009-02-16 1.08 -
AVAST! 3.0.1 090216-1 2009-02-16 0.00 -
AVG 7.5.52.442 270.10.25/1956 2009-02-16 1.97 -
BitDefender 7.81008.2671604 7.23713 2009-02-17 2.49 -
CA (VET) 9.0.0.143 31.6.6360 2009-02-16 3.91 -
ClamAV 0.94.2 8995 2009-02-16 0.01 -
Comodo 3.0 980 2009-02-16 0.93 -
CP Secure 1.1.0.715 2009.02.17 2009-02-17 6.92 -
Dr.Web 4.44.0.9170 2009.02.16 2009-02-16 4.03 -
F-Prot 4.4.4.56 20090216 2009-02-16 1.08 -
F-Secure 5.51.6100 2009.02.16.11 2009-02-16 0.06 -
Fortinet 2.81-3.117 10.48 2009-02-16 0.14 PossibleThreat
GData 19.3139/19.227 20090217 2009-02-17 3.19 -
ViRobot 20090216 2009.02.16 2009-02-16 0.43 -
Ikarus T3.1.01.45 2009.02.17.72310 2009-02-17 3.68 -
JiangMin 11.0.706 2009.02.16 2009-02-16 1.45 -
Kaspersky 5.5.10 2009.02.17 2009-02-17 0.04 -
KingSoft 2008.9.8.18 2009.2.16.20 2009-02-16 0.61 -
McAfee 5.3.00 5528 2009-02-16 3.21 Generic.dx
Microsoft 1.4306 2009.02.17 2009-02-17 4.71 -
mks_vir 2.01 2009.02.16 2009-02-16 2.72 -
Norman 6.00.06 6.00.00 2009-02-16 8.01 -
Panda 9.05.01 2009.02.16 2009-02-16 1.59 -
Trend Micro 8.700-1004 5.848.03 2009-02-15 0.03 -
Quick Heal 10.00 2009.02.17 2009-02-17 0.90 -
Rising 20.0 21.17.02.00 2009-02-16 0.79 -
Sophos 2.83.3 4.38 2009-02-17 2.40 -
Sunbelt 4819 4819 2009-02-16 0.51 -
Symantec 1.3.0.24 20090216.005 2009-02-16 0.05 -
nProtect 20090216.02 3155787 2009-02-16 3.75 -
The Hacker [removed] v00258 2009-02-16 0.53 -
VBA32 3.12.8.12 20090215.1437 2009-02-15 1.67 -
VirusBuster 4.5.11.10 10.101.15/904334 2009-02-16 1.13 -
Hi Chankfj,

Looking at the results, I would say it's Antivir's detection of a clean legitimate file based on what it does. This file can connect to the internet and download updates.

The others that detect it are also detecting it by Heuristic evaluation

read more here, #4 in particular
http://www.claymania.com/virus-specific.html

This method is good, but can create false positives. I suggest you visit the Antivir forum on how to exclude this file from future scans.
http://forum.avira.com/wbb/index.php?langid=1

If you check their forum, you will see similar problems with other manufacturers tha use Backweb for updates. Logitech being another one.

Any other problems?
Hi Chankfj, You're very welcome. glad I could help. Keep your new antivirus program updated as well as your other security programs. Good luck and keep safe. :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI