Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Is my HJT log OK?  (Read 10361 times)

0 Members and 1 Guest are viewing this topic.

ImnoGuru

    Topic Starter


    Adviser
  • The wonders of modern technology.
  • Thanked: 8
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 10
    Is my HJT log OK?
    « on: June 05, 2010, 05:56:38 AM »
    Hello and thank you for looking at my thread.

    My computer showed a few little anomalies recently.

    When I try to open a window internal of the browser window, say in Ebay, when you want to get a close up of the product, instead of opening straight away like it usually does, the window takes over 1 minute before it opens.
    Also another simple one, when I want to find out what is on TV and click on the program in the program guide, it also takes an extremely long time to open.

    So I did a scan with MS Essentials and ran HJT.

    Can someone have a look at my HJT log and tell me if there are any problems that I don't know of, please?


    OK, now the hard part... I have the log ..., How do I copy and paste it here??  ???
    I have tried several different ways to C&P but the HJT log doesn't want to play the game?

    So far I have tried right mouse click.... nothing..., tried control C ..same End result no copy and no paste.!!
    So how exactly do I get to show you what my HJT log is?

    Thank you. ImnoGuru.
    It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Is my HJT log OK?
    « Reply #1 on: June 05, 2010, 08:40:45 AM »
    You can't be running the scan correctly. When you open HJT click "do a system scan and save a log file". After the scan is completed, the log will open in Notepad as a .txt file. Just copy and paste that log here.
    Windows 8 and Windows 10 dual boot with two SSD's

    ImnoGuru

      Topic Starter


      Adviser
    • The wonders of modern technology.
    • Thanked: 8
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 10
      Re: Is my HJT log OK?
      « Reply #2 on: June 05, 2010, 10:09:35 PM »
      Thanks SuperDave, I figured I must have been the problem rather than the solution.
      I'll give that a try and see where I end up then.
      It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

      ImnoGuru

        Topic Starter


        Adviser
      • The wonders of modern technology.
      • Thanked: 8
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 10
        Re: Is my HJT log OK?
        « Reply #3 on: June 05, 2010, 10:37:50 PM »
        Ok lets try again then..

        Additional options, browse, select file .jpg and post yeah?

        [recovering disk space - old attachment deleted by admin]
        It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Is my HJT log OK?
        « Reply #4 on: June 06, 2010, 10:38:46 AM »
        Sorry, that's not correct. Please do this: Double-click Hijackthis to open it. Select "do a system scan and save a log file". After the scan is completed, the log will open in Notepad as a .txt file. Just copy and paste that log here.
        Windows 8 and Windows 10 dual boot with two SSD's

        BC_Programmer


          Mastermind
        • Typing is no substitute for thinking.
        • Thanked: 1140
          • Yes
          • Yes
          • BC-Programming.com
        • Certifications: List
        • Computer: Specs
        • Experience: Beginner
        • OS: Windows 11
        Re: Is my HJT log OK?
        « Reply #5 on: June 07, 2010, 03:47:04 PM »
        Ok lets try again then..

        Additional options, browse, select file .jpg and post yeah?

        what?

        you opened it in word, saved it as an docx file, and then gave it a jpg extension? That's sort of... crazy.

        here are the contents:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 2:15:13 PM, on 6/06/2010
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Tall Emu\Online Armor\OAcat.exe
        C:\Program Files\Tall Emu\Online Armor\oasrv.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\NCH Software\Eyeline\eyeline.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Analog Devices\Core\smax4pnp.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
        C:\program files\microsoft office\Office12\GrooveMonitor.exe
        C:\Program Files\Microsoft Security Essentials\msseces.exe
        C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
        C:\Program Files\NCH Swift Sound\Talk\talk.exe
        C:\Program Files\Common Files\Java\Java Update\jusched.exe
        C:\Program Files\Tall Emu\Online Armor\oaui.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Ares\Ares.exe
        C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFBP.EXE
        C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
        C:\program files\microsoft office\Office12\WINWORD.EXE
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onlinecashgateway.com/MemberLogin.aspx
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R3 - URLSearchHook: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll
        R3 - URLSearchHook: Yahoo!7 Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll
        O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\program files\microsoft office\Office12\GrooveShellExtensions.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
        O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
        O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
        O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
        O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
        O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll
        O3 - Toolbar: Yahoo!7 Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
        O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
        O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
        O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
        O4 - HKLM\..\Run: [GrooveMonitor] "C:\program files\microsoft office\Office12\GrooveMonitor.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
        O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
        O4 - HKLM\..\Run: [Talk] "C:\Program Files\NCH Swift Sound\Talk\talk.exe" -logon
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
        O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
        O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe" -stealth
        O4 - HKCU\..\Run: [EPSON TX110 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFBP.EXE /FU "C:\WINDOWS\TEMP\E_S2F1.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [Wisdom-soft ScreenHunter 5.1 Pro] 0
        O4 - HKCU\..\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] 0
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
        O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
        O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
        O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
        O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
        O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\program files\microsoft office\Office12\GrooveSystemServices.dll
        O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
        O23 - Service: Eyeline Video System (EyelineService) - NCH Software - C:\Program Files\NCH Software\Eyeline\eyeline.exe
        O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Google Update Service (gupdate1c989bcb1b1848b) (gupdate1c989bcb1b1848b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\OAcat.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe

        --
        End of file - 11978 bytes
        I was trying to dereference Null Pointers before it was cool.

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Is my HJT log OK?
        « Reply #6 on: June 07, 2010, 05:09:50 PM »
        P2P - I see you have P2P software installed on your machine. (Ares) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

        Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

        I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

        ===============================

        Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

        Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

        Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

        Exit out of MessengerDisable then delete the two files that were put on the desktop.

        =================================

        Open HijackThis and select Do a system scan only

        Place a check mark next to the following entries: (if there)

        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

        O2 - BHO: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll
        O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll

        (The above two lines concerning XfireXO Toolbar modifies the default IE URL search hook. Conduit toolbars are reputed to have a certain trackware functionality. The option is up to you if you want to keep it. If not, you should uninstall XfireXO from you computer. See instructions above for uninstalling programs)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

        Important: Close all open windows except for HijackThis and then click Fix checked.

        Once completed, exit HijackThis.

        =================================

        SUPERAntiSpyware

        If you already have SUPERAntiSpyware be sure to check for updates before scanning!


        Download SuperAntispyware Free Edition (SAS)
        * Double-click the icon on your desktop to run the installer.
        * When asked to Update the program definitions, click Yes
        * If you encounter any problems while downloading the updates, manually download and unzip them from here
        * Next click the Preferences button.

        •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
        * Click the Scanning Control tab.
        * Under Scanner Options make sure only the following are checked:

        •Close browsers before scanning
        •Scan for tracking cookies
        •Terminate memory threats before quarantining
        Please leave the others unchecked

        •Click the Close button to leave the control center screen.

        * On the main screen click Scan your computer
        * On the left check the box for the drive you are scanning.
        * On the right choose Perform Complete Scan
        * Click Next to start the scan. Please be patient while it scans your computer.
        * After the scan is complete a summary box will appear. Click OK
        * Make sure everything in the white box has a check next to it, then click Next
        * It will quarantine what it found and if it asks if you want to reboot, click Yes

        •To retrieve the removal information please do the following:
        •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
        •Click Preferences. Click the Statistics/Logs tab.

        •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

        •It will open in your default text editor (preferably Notepad).
        •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

        * Save the log somewhere you can easily find it. (normally the desktop)
        * Click close and close again to exit the program.
        *Copy and Paste the log in your post.

        ================================

        Please download Malwarebytes Anti-Malware from here.

        Double Click mbam-setup.exe to install the application.
        • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
        • If an update is found, it will download and install the latest version.
        • Once the program has loaded, select "Perform Full Scan", then click Scan.
        • The scan may take some time to finish,so please be patient.
        • When the scan is complete, click OK, then Show Results to view the results.
        • Make sure that everything is checked, and click Remove Selected.
        • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
        • Please save the log to a location you will remember.
        • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
        • Copy and paste the entire report in your next reply.
        Extra Note:

        If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

        =================================

        Download ComboFix by sUBs from one of the below links. 

        Important! You MUST save ComboFix to your desktop

        link # 1
        Link # 2

        Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

        Double click on ComboFix.exe & follow the prompts.

        Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

        Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

        When the scan completes it will open a text window.
         
        Post the contents of that log in your next reply.

        Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.
        Windows 8 and Windows 10 dual boot with two SSD's

        ImnoGuru

          Topic Starter


          Adviser
        • The wonders of modern technology.
        • Thanked: 8
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 10
          Re: Is my HJT log OK?
          « Reply #7 on: June 07, 2010, 08:21:36 PM »
          Thanks  for your reply BC_Programmer, I tried to add it as a docx but it didn't upload.

          Having read the instructions, (you'd think I would have read them before now  :-X ), CH required the upload to be in a set of parameters, being .jpg as one of them.

          I'm just a simple mortal. ;D
          Maybe there was an easier way..... I don't know?

          what?

          you opened it in word, saved it as an docx file, and then gave it a jpg extension? That's sort of... crazy.

          Ok it's crazy, BC_Programmer, but it worked didn't it?

          SuperDave, thank you too for your input. I see you ask me to remove windows messenger.
          Just curious as to why you think that needs to go? I don't have a problem getting it gone. In fact I don't know how the devil it even appeared on my computer. I don't use either of the programs, in fact the same applies to Ares actually.

          Are there more than one P2P (pier to pier) programs on this computer?
          Something in your reply makes me think you see more than one?

          Now, Xfire is a program my brother asked me to put on here as we can talk over the internet via headphones and there is no cost, just data flow ( from what he tells me).
          I didn't have any problems after installing or using it , the slow window opening came ages after that.
          I suspect from some download that occurred without authority. It was never opened because I was suspect of it and I deleted it instantly. From memory I was trying to find out the cost of an RV to purchase for my trip to America.  (|

          Is there something better about that we can use to talk to each other via the net, that is safe/free of cost?

          And so to all the rest.... I have a lot to do ... SAS run that, so on so on.
          Better get into it then. If I don't do it it will never happen.

          Thanks again InmoGuru.  ;D
          It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Is my HJT log OK?
          « Reply #8 on: June 08, 2010, 08:44:35 AM »
          Quote
          Just curious as to why you think that needs to go?
          Window Messenger is a frequent cause of pop-ups and is not needed. Not to be confused with MSN Messenger.

          Quote
          Are there more than one P2P (pier to pier) programs on this computer?
          Not that I can see. We may see more when the ComboFix comes back.

          Quote
          Is there something better about that we can use to talk to each other via the net, that is safe/free of cost?
          A lot of people use Skype.
          Windows 8 and Windows 10 dual boot with two SSD's

          ImnoGuru

            Topic Starter


            Adviser
          • The wonders of modern technology.
          • Thanked: 8
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 10
            Re: Is my HJT log OK?
            « Reply #9 on: June 11, 2010, 04:15:14 AM »
            I have been looking at my Task manager and it has 41 processes running.
            One of them is stealing all my resources and the CPU is at 100%.
            The name of it is mscorsvw.exe ? I found this but it doesnt make much sense to me.

            It really doesnt tell me what the program is that it controls, what it does or enlighten me as to whether it is even necessary.
            I have a feeling that this is part of my computer running slow.

            Does any one have any thoughts on that please?
            It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Is my HJT log OK?
            « Reply #10 on: June 11, 2010, 01:29:25 PM »
            If you don't run the scans that I've suggested, there is no way I can help you.
            Windows 8 and Windows 10 dual boot with two SSD's

            ImnoGuru

              Topic Starter


              Adviser
            • The wonders of modern technology.
            • Thanked: 8
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 10
              Re: Is my HJT log OK?
              « Reply #11 on: June 12, 2010, 02:19:11 AM »
              Yes. sorry I got sidetracked on that doing them now.
              Thanks SuperDave. I needed a little bit of focus. Im on it.
              It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

              ImnoGuru

                Topic Starter


                Adviser
              • The wonders of modern technology.
              • Thanked: 8
                • Computer: Specs
                • Experience: Experienced
                • OS: Windows 10
                Re: Is my HJT log OK?
                « Reply #12 on: June 12, 2010, 04:20:25 AM »
                Ok. Now I have the SAS log and proceeding to MBAM.
                More to follow.  ;D

                [recovering disk space - old attachment deleted by admin]
                It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

                ImnoGuru

                  Topic Starter


                  Adviser
                • The wonders of modern technology.
                • Thanked: 8
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 10
                  Re: Is my HJT log OK?
                  « Reply #13 on: June 12, 2010, 06:48:23 AM »
                  Well that didnt take as long as I thought it would.
                  I now have the MBam log.

                  [recovering disk space - old attachment deleted by admin]
                  It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.

                  ImnoGuru

                    Topic Starter


                    Adviser
                  • The wonders of modern technology.
                  • Thanked: 8
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 10
                    Re: Is my HJT log OK?
                    « Reply #14 on: June 12, 2010, 08:23:43 AM »
                    And now I have the last one. The Combofix log.

                    (I hope I have done all this right)

                    Thank you ImnoGuru.

                    [recovering disk space - old attachment deleted by admin]
                    It takes 15 years to become an overnight success & Windows 10 will add another 10 years to it.