There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
acer black screen blue screen boot bsod computer connection crash css dell display driver drivers email error excel explorer firefox firefox 3 game hard drive internet internet explorer itunes laptop linux malware network networking outlook outlook 2003 outlook express partition password printer problem ram router security slow software sound trojan usb video virus vista windows windows xp wireless
General Security
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > General Security >
Help! Possible Virus!


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
29-Nov-2007, 07:02 PM #1
Help! Possible Virus!
My computer is running exceptionally slow and takes forever to load anything. Its a 1.8 GHZ processor with 512 MB Ram. I know its not the fastest, but it should still work better than super slow, right?

Here is a hijackthis log, I thought it would be a good starting point!

Any help is appreciated.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:00:08 PM, on 11/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Owner.adreanna\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mssu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916214_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916157_mcinfo.exe /insfin
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47...familyfeud.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bej...loader_v10.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 5875 bytes
Cheeseball81's Avatar
Moderator with 71,680 posts.
 
Join Date: Mar 2004
Location: New York
Experience: Mighty Nerdy
29-Nov-2007, 09:39 PM #2
Looks fine

Has it been defragged recently
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
30-Nov-2007, 02:59 AM #3
Yes, defragged, and disk cleanup, and avg and everything. But it still lags when I type and everytime I open the task manager, it says at least 80% of my CPU is being used, but I can not find where or why. Even now, when nothing, and I mean NOTHING is running except IE, when I type it takes a few seconds for everything to show up. I don't understand.
Nesjemannen's Avatar
Computer Specs
Senior Member with 200 posts.
 
Join Date: Nov 2007
Location: Norway!
Experience: AdvancedComputerKnowledge
30-Nov-2007, 09:48 AM #4
Have you installed a Firewall or Virusscanner on your computer?





( And by the way - update you Hijackthis!)
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
30-Nov-2007, 04:16 PM #5
Yeah, I have AVG on my computer, and firewall as well. WHen I run my computer in Safe mode, it does not have any of the same issues that it has now. It runs smoothly and does not lag. It confuses me a lot. And I thought I had the newest edition of HIjack This
Cheeseball81's Avatar
Moderator with 71,680 posts.
 
Join Date: Mar 2004
Location: New York
Experience: Mighty Nerdy
30-Nov-2007, 10:30 PM #6
Your version is fine
Have you recently added any new software or hardware
Xkarinx's Avatar
Computer Specs
Account Disabled with 227 posts.
 
Join Date: Nov 2007
Location: Minnesota
Experience: Beginner
30-Nov-2007, 10:33 PM #7
system restore is your only option im afriad.
AcaCandy's Avatar
Computer Specs
Administrator with 100,200 posts.
 
Join Date: Jan 2001
Location: Las Vegas, NV & Acapulco, Mexico
Experience: Advanced
01-Dec-2007, 10:27 AM #8
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916214_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916157_mcinfo.exe /insfin


I'd take the first two out of startup via start, run, msconfig startup tab.

Question for Cheeseball, what about those files running from temp locations?
__________________
Microsoft MVP - Windows Desktop
My Website: http://www.casalasvegas.us/
My Worksite:http://www.supportspace.com/home/exp...ofile/AcaCandy
Limited Time $15 coupon. Email me and I'll send it to you.
http://www.supportspace.com/?aiu=Gen...FQE4GgodlFj1tQ
Cheeseball81's Avatar
Moderator with 71,680 posts.
 
Join Date: Mar 2004
Location: New York
Experience: Mighty Nerdy
01-Dec-2007, 09:17 PM #9
They are McAfee remnants
AcaCandy's Avatar
Computer Specs
Administrator with 100,200 posts.
 
Join Date: Jan 2001
Location: Las Vegas, NV & Acapulco, Mexico
Experience: Advanced
02-Dec-2007, 10:11 AM #10
So, can they be zapped too?
Cheeseball81's Avatar
Moderator with 71,680 posts.
 
Join Date: Mar 2004
Location: New York
Experience: Mighty Nerdy
02-Dec-2007, 12:03 PM #11
Looks like it may still be running: c:\progra~1\mcafee.com\vso\mcvsescn.exe
However the user said they use AVG now. Maybe it wasn't fully uninstalled?
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
03-Dec-2007, 01:49 AM #12
I went through and did the uninstall from the McAfee installer, if anything is left it should not be there. I have also noticed something curious in the fact that there are two Owner profiles for this laptop. And an administrator password that was never set by the Owner. One of the profiles is called "Owner.adreanna" and we do not even know someone of that name. It wasn't a display computer so I have no idea where that came from. How would I go about doing a better uninstall for the McAfee?
Cheeseball81's Avatar
Moderator with 71,680 posts.
 
Join Date: Mar 2004
Location: New York
Experience: Mighty Nerdy
03-Dec-2007, 07:08 PM #13
What version is it?
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:35 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.