This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System Slow Unknown Process

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run Adaware, Skybot, and Norton 2004. The Hijackthis log is listed below. I would appreciate any assistance in cleaning out the running processes. Note: Is is normal for the "rundll32" application to be running continuously in the task manager. Also "wscript.exe" process is continuously running and using significant CPU resources. Thanks in Advance.


Logfile of HijackThis v1.98.2
Scan saved at 9:44:44 PM, on 11/28/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Ahead\InCD\InCDsrv.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\system32\LEXBCES.EXE
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\system32\LEXPPS.EXE
G:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\NewMixer.exe
G:\Program Files\Visioneer OneTouch\OneTouchMon.exe
G:\Program Files\Ahead\InCD\InCD.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
G:\WINDOWS\System32\WScript.exe
G:\WINDOWS\System32\lmagjg.exe
G:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
G:\QUICKENW\QWDLLS.EXE
G:\WINDOWS\system32\regsrv.exe
G:\WINDOWS\system32\sendi.exe
G:\Program Files\Internet Explorer\IEXPLORE.EXE
G:\Documents and Settings\cyrfamily\Local Settings\Temp\Temporary Directory 1 for hijackthisnew.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F0 - system.ini: Shell=Explorer.exe G:\WINDOWS\system32\winmgd.win
F1 - win.ini: run=G:\WINDOWS\system32\mouse_configurator.win
O2 - BHO: MultiMPPObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - G:\WINDOWS\multimpp.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - G:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - G:\WINDOWS\System32\dsktrf.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - G:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [C-Media Speaker Configuration] \Setup.exe /SPEAKER
O4 - HKLM\..\Run: [C-Media Mixer] G:\WINDOWS\NewMixer.exe /startup
O4 - HKLM\..\Run: [PrinTray] G:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [OneTouch Monitor] G:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [InCD] G:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] G:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] G:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Kernel32] G:\WINDOWS\system32\Kernel32.win
O4 - HKLM\..\Run: [ufgbsclj] G:\WINDOWS\System32\lmagjg.exe
O4 - HKLM\..\Run: [Israfel] G:\WINDOWS\system32\Israfel.vbs
O4 - HKLM\..\Run: [satmat] G:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [Win Server Updt] G:\WINDOWS\wupdt.exe
O4 - HKCU\..\Run: [PPWebCap] G:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] G:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - Startup: Event Reminder.lnk = G:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = G:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Quicken Startup.lnk = G:\QUICKENW\QWDLLS.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
Welcome Back.

First we need to get Hijackthis this in a permanent folder, Here's how:
Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. This way, it will create a backup file of modifications to use if restore is necessary.
Once you have this in the correct folder, delete it from the temp folder.

Next Please do an online scan at two of these places:
http://housecall.trendmicro.com/housecall/start_corp.asp

http://www.pandasoftware.com/activescan/co…n_principal.htm

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Fix what it finds and note any problems it could not fix if any.

Reboot and post a fresh HJT file.

Thanks,
Sky
Due to inactivity this topic will be closed.

To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?



If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI