Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Help! Possible Virus!

Reply  
Thread Tools
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
29-Nov-2007, 08:02 PM #1
Help! Possible Virus!
My computer is running exceptionally slow and takes forever to load anything. Its a 1.8 GHZ processor with 512 MB Ram. I know its not the fastest, but it should still work better than super slow, right?

Here is a hijackthis log, I thought it would be a good starting point!

Any help is appreciated.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:00:08 PM, on 11/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Owner.adreanna\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mssu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916214_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916157_mcinfo.exe /insfin
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47...familyfeud.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bej...loader_v10.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 5875 bytes
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
29-Nov-2007, 10:39 PM #2
Looks fine

Has it been defragged recently
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
30-Nov-2007, 03:59 AM #3
Yes, defragged, and disk cleanup, and avg and everything. But it still lags when I type and everytime I open the task manager, it says at least 80% of my CPU is being used, but I can not find where or why. Even now, when nothing, and I mean NOTHING is running except IE, when I type it takes a few seconds for everything to show up. I don't understand.
Nesjemannen's Avatar
Computer Specs
Member with 230 posts.
 
Join Date: Nov 2007
Location: Norway!
Experience: Advanced
30-Nov-2007, 10:48 AM #4
Have you installed a Firewall or Virusscanner on your computer?





( And by the way - update you Hijackthis!)
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
30-Nov-2007, 05:16 PM #5
Yeah, I have AVG on my computer, and firewall as well. WHen I run my computer in Safe mode, it does not have any of the same issues that it has now. It runs smoothly and does not lag. It confuses me a lot. And I thought I had the newest edition of HIjack This
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
30-Nov-2007, 11:30 PM #6
Your version is fine
Have you recently added any new software or hardware
Xkarinx's Avatar
Computer Specs
Account Disabled with 227 posts.
 
Join Date: Nov 2007
Location: Minnesota
Experience: Beginner
30-Nov-2007, 11:33 PM #7
system restore is your only option im afriad.
~Candy~'s Avatar
Former Administrator with 104,742 posts.
 
Join Date: Jan 2001
Experience: Advanced
01-Dec-2007, 11:27 AM #8
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916214_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\OWNER~1.ADR\LOCALS~1\Temp\2007112916157_mcinfo.exe /insfin


I'd take the first two out of startup via start, run, msconfig startup tab.

Question for Cheeseball, what about those files running from temp locations?
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
01-Dec-2007, 10:17 PM #9
They are McAfee remnants
~Candy~'s Avatar
Former Administrator with 104,742 posts.
 
Join Date: Jan 2001
Experience: Advanced
02-Dec-2007, 11:11 AM #10
So, can they be zapped too?
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
02-Dec-2007, 01:03 PM #11
Looks like it may still be running: c:\progra~1\mcafee.com\vso\mcvsescn.exe
However the user said they use AVG now. Maybe it wasn't fully uninstalled?
ReDJeLLo1803's Avatar
Member with 52 posts.
 
Join Date: Aug 2004
03-Dec-2007, 02:49 AM #12
I went through and did the uninstall from the McAfee installer, if anything is left it should not be there. I have also noticed something curious in the fact that there are two Owner profiles for this laptop. And an administrator password that was never set by the Owner. One of the profiles is called "Owner.adreanna" and we do not even know someone of that name. It wasn't a display computer so I have no idea where that came from. How would I go about doing a better uninstall for the McAfee?
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
03-Dec-2007, 08:08 PM #13
What version is it?
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:58 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.