Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Please Help  (Read 8591 times)

0 Members and 1 Guest are viewing this topic.

phibroke

    Topic Starter


    Rookie

    • Experience: Beginner
    • OS: Unknown
    Please Help
    « on: November 29, 2010, 05:11:46 PM »
    I'm going to post a log (in parts, top to bottom) from Hijack This, I have installed Trend Micro AND Windows Security Essentials as well as Malaware Bytes anti malaware and none of these detect a virus. Yet my download speed is EXTREMELY slow, almost impossible. Any help is hugely appreciated....

    phibroke

      Topic Starter


      Rookie

      • Experience: Beginner
      • OS: Unknown
      Log 1
      « Reply #1 on: November 29, 2010, 05:12:22 PM »
      Logfile of Trend Micro HijackThis v2.0.4
      Scan saved at 7:02:47 PM, on 11/29/2010
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\WLTRYSVC.EXE
      C:\WINDOWS\System32\bcmwltry.exe
      C:\WINDOWS\system32\spoolsv.exe

      phibroke

        Topic Starter


        Rookie

        • Experience: Beginner
        • OS: Unknown
        Log Part 2
        « Reply #2 on: November 29, 2010, 05:12:48 PM »
        C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
        C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
        C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Viewpoint\Common\ViewpointService.exe

        phibroke

          Topic Starter


          Rookie

          • Experience: Beginner
          • OS: Unknown
          Log Part 3
          « Reply #3 on: November 29, 2010, 05:13:21 PM »
          C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
          C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe
          C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          C:\WINDOWS\stsystra.exe
          C:\Program Files\Real\RealPlayer\RealPlay.exe
          C:\Program Files\Dell\MediaDirect\PCMService.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\igfxpers.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\WINDOWS\system32\igfxsrvc.exe
          C:\WINDOWS\system32\dla\tfswctrl.exe
          C:\Program Files\Dell\QuickSet\quickset.exe
          C:\WINDOWS\system32\WLTRAY.exe

          phibroke

            Topic Starter


            Rookie

            • Experience: Beginner
            • OS: Unknown
            Log Part 4
            « Reply #4 on: November 29, 2010, 05:13:45 PM »
            C:\Program Files\Microsoft Security Essentials\msseces.exe
            C:\Program Files\NetWaiting\netWaiting.exe
            C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
            C:\Program Files\Dell Support\DSAgnt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            C:\Program Files\Digital Line Detect\DLG.exe
            C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
            C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
            C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
            C:\Documents and Settings\NEW\Desktop\HijackThis.exe

            phibroke

              Topic Starter


              Rookie

              • Experience: Beginner
              • OS: Unknown
              Log Part 5
              « Reply #5 on: November 29, 2010, 05:14:11 PM »
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070123
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070123
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070123

              phibroke

                Topic Starter


                Rookie

                • Experience: Beginner
                • OS: Unknown
                Log Part 6
                « Reply #6 on: November 29, 2010, 05:14:43 PM »
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: Trend Micro NSC BHO - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll
                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
                O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                O2 - BHO: TmBpIeBHO - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
                O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                O4 - HKLM\..\Run: [Trend Micro Titanium] "C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" -set Silent "1" SplashURL ""
                O4 - HKLM\..\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"

                phibroke

                  Topic Starter


                  Rookie

                  • Experience: Beginner
                  • OS: Unknown
                  Log Part 7
                  « Reply #7 on: November 29, 2010, 05:15:15 PM »
                  O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [eqmjvnhm] C:\Documents and Settings\Jay Ricciardi\Local Settings\Application Data\ygtoscgsi\xmxvwuitssd.exe
                  O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                  O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
                  O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
                  O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
                  O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
                  O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                  O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\NEW\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                  O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

                  phibroke

                    Topic Starter


                    Rookie

                    • Experience: Beginner
                    • OS: Unknown
                    Log Part 8
                    « Reply #8 on: November 29, 2010, 05:15:41 PM »
                    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
                    O4 - Global Startup: Digital Line Detect.lnk = ?
                    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                    O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
                    O4 - Global Startup: WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                    O18 - Protocol: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
                    O18 - Protocol: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll

                    phibroke

                      Topic Starter


                      Rookie

                      • Experience: Beginner
                      • OS: Unknown
                      Log Part 9
                      « Reply #9 on: November 29, 2010, 05:16:13 PM »
                      O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                      O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                      O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
                      O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                      O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
                      O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
                      O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
                      O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

                      --
                      End of file - 10814 bytes

                      SuperDave

                      • Malware Removal Specialist


                      • Genius
                      • Thanked: 1020
                      • Certifications: List
                      • Experience: Expert
                      • OS: Windows 10
                      Re: Please Help
                      « Reply #10 on: November 30, 2010, 01:17:13 PM »
                      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

                      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
                      2. The fixes are specific to your problem and should only be used for this issue on this machine.
                      3. If you don't know or understand something, please don't hesitate to ask.
                      4. Please DO NOT run any other tools or scans while I am helping you.
                      5. It is important that you reply to this thread. Do not start a new topic.
                      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
                      7. Absence of symptoms does not mean that everything is clear.

                      Please don't break up the logs in small pieces. You can paste most logs in one reply.

                      Quote
                      Yet my download speed is EXTREMELY slow, almost impossible.
                      Is it just on the downloads that you find your computer slow or is it slow all the time? What kind of internet connection do you have? Dial-up, ADSL, Cable, etc.

                      You have Viewpoint installed.

                      Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

                      More information:

                      * ViewMgr.exe - Useless
                      * Viewpoint to Plunge Into Adware

                      It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

                      * Viewpoint
                      * Viewpoint Manager
                      * Viewpoint Media Player
                      * Viewpoint Toolbar
                      * Viewpoint Experience Technology

                      *************************************
                      Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

                      Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

                      Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

                      Exit out of MessengerDisable then delete the two files that were put on the desktop.

                      *************************************************

                      Your HJT is running from the incorrect place. Please delete it, download a new one here and let it install in the default location.

                      Please download: HiJackThis to your Desktop.
                      • Double Click the HijackThis icon, located on your Desktop.
                      • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
                      • Accept the license agreement.
                      • Click the Open the Misc Tools section button.
                      • Place a checkmark beside Calculate MD5 of files if possible. Then, click Back.
                      • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
                      • Please post the log in your next reply.
                      **************************************
                      Download Security Check by screen317 from one of the following links and save it to your desktop.

                      Link 1
                      Link 2

                      * Unzip SecurityCheck.zip and a folder named Security Check should appear.
                      * Open the Security Check folder and double-click Security Check.bat
                      * Follow the on-screen instructions inside of the black box.
                      * A Notepad document should open automatically called checkup.txt
                      * Post the contents of that document in your next reply.

                      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
                      Windows 8 and Windows 10 dual boot with two SSD's