Here is my log. Can someone look at it and see if there is any problems?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:12:04 PM, on 3/4/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.
If you think you have similar problems, please post a log in the HJT forum and wait for help.
Hi firefighter123 and welcome to What the Tech
I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:
I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for this issue on this machine!.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
If you don't know, stop and ask! Don't keep going on.
Please reply to this thread. Do not start a new topic.
Refrain from running self fixes as this will hinder the malware removal process.
It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
Vista Advice:
This Operating System comes with a inbuilt utility called User Access Control(UAC) when prompted by this with anything I ask you to do carry out please select the option Allow.
Next:
As it stands I see no indication of Malware in the log you posted. Is there any particular symptoms currently being experienced ? There is a Service Pack available for Vista but we can address that later.
Next:
I would like to view a list of currently installed software applications on you're PC. How to provide as follows:
Right click on HiJackThis.exe and select Run as Administrator and click on Open the Misc Tools section:
Click Open Uninstall Manager…
Click Save list... and save it to your Desktop.
Copy and paste the file uninstall_list.txt into your next reply.
Next:
Please go here to run an online scanner from ESET.
You will need to use Internet explorer for this scan
Note for Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic
When completed the above, please post back the following in the order asked for:
How is you computer performing now, any symptoms at all?
Dakeyras,
Thank you for helping me. The problem that I am having is the computer is running at 100% with no programs running. I am not sure if there is some virus running in the background that is causing this.
I am not able to run the Eset scan you wanted. I followed all of the instructions that you gave. When it gets to the part were I accept the active-x i get an error that says "Windows has blocked this software because it can't verify the publisher".
Here are the other two logs you requested.
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Apple Mobile Device Support
Apple Software Update
Bonjour
Broadcom 802.11 Wireless LAN Adapter
Conexant HD Audio
Driver Genius Professional Edition 2007
eBay Toolbar Featuring Yahoo!
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HDAUDIO Soft Data Fax Modem with SmartCP
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
iTunes
Java™ 6 Update 4
Java™ 6 Update 5
LimeWire 4.18.3
LiveUpdate 3.2 (Symantec Corporation)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Mozilla Firefox (3.0.5)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
Nero 8
neroxml
NVIDIA Drivers
QuickTime
Symantec AntiVirus
Synaptics Pointing Device Driver
VCRedistSetup
Vista Manager
Windows Media Player Firefox Plugin
Yahoo! ¤u¨ã¦C
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:36:17 PM, on 3/5/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Symantec AntiVirus\SavUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\System32\notepad.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 1669 bytes
The problem that I am having is the computer is running at 100% with no programs running. I am not sure if there is some virus running in the background that is causing this.
Thank you for the clarification, I will see what I can advise to help with this problem. There are also some applications that require updating but we can address that later.
I am not able to run the Eset scan you wanted. I followed all of the instructions that you gave. When it gets to the part were I accept the active-x i get an error that says "Windows has blocked this software because it can't verify the publisher".
OK no problem we can address this later.
Nero Scout Check/Disable:
This part of your Nero 8 application is a know system resource intensive component. I advise you disable this as follows:
Click on Start >> All Programs >> Nero 8 >> Tools >> Nero Scout.
Uncheck the box next to Enable Nero Scout.
Click OK.
Now Reboot(restart your computer)
P2P Advice:
Presently you have the following installed:
LimeWire 4.18.3
My advice would be to remove this application via Start >> Control Panel >> Programs and Features.
However if you opt not too, please refrain from using this application during the malware removal process.
Peer to Peer software may be a great way to get lots of seemingly freeware, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well. My advice avoid these types of software applications.
Next:
The last HijackThis log you posted is vastly smaller than the original. To be on the safe side please rename the executable file for HijackThis as follows, as in some instances malware can hide from HijackThis.
Please navigate to the following:
My Computer >> Program Files >> Trend Micro >> HijackThis >> HijackThis.exe
Now right click on HijackThis.exe and select the option Rename
Rename it Firefighter.exe please.
Now please post a new HighjackThis log. Remember to right click Firefighter.exe and select Run as Administrator.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:27:55 AM, on 3/7/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Right-click on mbam-setup.exe and select Run as Administrator, follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please post that log in your next reply.
The log can also be found here:
Launch Malwarebytes' Anti-Malware
Click on the Logs radio tab.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to Restart the computer, please do so immediately.
When completed the above, please post back the following in the order asked for:
How is you computer performing now, any other symptoms and or problems encountered?
Answer to my Nero Scout query.
Malwarebytes' Anti-Malware Log.
A new HijackThis Log. <– Remember to right click Firefighter.exe and select Run as Administrator.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:22:45 AM, on 3/9/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode with network support
Yes i disabled Nero Scout.
The computer is still running at 100%.
OK thank you for informing myself.
Why have your recently installed Service pack 1 for Vista ? If I may draw your attention to part of my original post to your good self:
Refrain from running self fixes as this will hinder the malware removal process.
Now before we proceed any further the actual Anti-Virus application installed is the Norton Anti-Virus Corporate Edition. Is this Computer used for personal use only and or business related tasks/part of a office network ?
Dakeyras,
I did not know the SP1 was installed. maybe that is why the computer was running at a snails pace???
I am not to sure about its use. It is my boys girlfriends computer. If that is a problem I can see if it can be removed. I like AVG myself. I use to have Nortons but it let too many things through.
I did not know the SP1 was installed. maybe that is why the computer was running at a snails pace???
It has been installed recently during the course of this topic. If indeed this is a malware issue it will not have helped matters at all. Vista SP1 however should not impinge upon a systems overall performance, in theory anyway as anything is possible. We will leave this alone for the time being.
I am not to sure about its use. It is my boys girlfriends computer.
Ah this both explains a lot and may pose a problem, I really need to know exactly what your Sons girlfriend uses this particular computer for. As mentioned in my last post to your good self the type of Anti-Virus software in use is rarely used on a home computer at all. If I may draw you attention to the below:
The malware removal forum is set up to help those in need of assistance with their personal computers. If it's a Company owned computer / or Server, contact your IT person.
We realise on occasion an IT person might need a second opinion. In which case please state that up-front and note the steps already taken. Our volunteers appreciate that.
If you are a computer business claiming to remove spyware for your paying customers, our Volunteers are not here to support such. Personal computer clients may be directed to this forum to receive free advice in the first person.
Dakeyras,
After speaking with her I found out that she "borrowed" a copy of the anti virus from where she works. I told her that that was not acceptable and I would not be able to get her anymore help until she removed it. I am sorry for taking up your time in this matter.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI