I followed the steps on your page on both of the profiles on my comp. It is still very slow and background is locked in only one profile. (sandra) I am running XP Pro SP1
I also tried a SYSTEM RESTORE, it would not except it.
The other thing I noticed is there is a process using 85-99% CPU (tsc.exe) for long periods of time.
Thanks,
Tom
LOGFILES:
Logfile of HijackThis v1.99.1
Scan saved at 2:23:26 PM, on 6/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Sunbelt Software\iHatePopups\iHatePopups.exe
C:\Program Files\Sunbelt Software\iHateSpam\siService.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\FSI\F-Prot\F-Sched.exe
C:\Program Files\FSI\F-Prot\F-StopW.EXE
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\FSI\F-Prot\fpavupdm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\iHateSpam\siSpamFilterEngine.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\0000\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [iHatePopups.exe] "C:\Program Files\Sunbelt Software\iHatePopups\iHatePopups.exe"
O4 - HKLM\..\Run: [siService.exe] "C:\Program Files\Sunbelt Software\iHateSpam\siService.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\svchost.exe /s
O4 - HKLM\..\Run: [FRISK FP-Scheduler] C:\Program Files\FSI\F-Prot\F-Sched.exe STARTUP
O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [PopUpInspector] "C:\Program Files\Sunbelt Software\iHatePopups\iHatePopups.exe"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [Nlhi] C:\WINDOWS\System32\??sembly\services.exe
O4 - HKCU\..\Run: [Ncao] C:\Program Files\nrpn\osoa.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Allow popups from this web page - C:\Program Files\Sunbelt Software\iHatePopups\allowsite.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Stop popups from this web page - C:\Program Files\Sunbelt Software\iHatePopups\denysite.htm
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: iHatePopups - {D216B74A-9A2F-4025-9690-86780AA75F6E} - C:\Program Files\Sunbelt Software\iHatePopups\iHatePopups.exe (HKCU)
O9 - Extra 'Tools' menuitem: iHatePopups - {D216B74A-9A2F-4025-9690-86780AA75F6E} - C:\Program Files\Sunbelt Software\iHatePopups\iHatePopups.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted IP range: 67.19.178.84
O15 - Trusted IP range: 67.19.178.84 (HKLM)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1111037563703
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: F-Prot Antivirus Update Monitor - FRISK Software - C:\Program Files\FSI\F-Prot\fpavupdm.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
*******************
---------------------------------------------------------
ewido security suite - Scan report (ON TOMS PROFILE, LAST NIGHT)
---------------------------------------------------------
+ Created on: 9:42:01 PM, 6/17/2005
+ Report-Checksum: 6D70453A
+ Date of database: 6/18/2005
+ Version of scan engine: v3.0
+ Duration: 71 min
+ Scanned Files: 117816
+ Speed: 27.54 Files/Second
+ Infected files: 33
+ Removed files: 32
+ Files put in quarantine: 32
+ Files that could not be opened: 0
+ Files that could not be cleaned: 1
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
+ Scan result:
C:\Documents and Settings\Tom\Cookies\tom@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Error during cleaning
C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0CB22B47-D928-4A67-9FAA-9AEDBC\83381F95-F86A-4246-A8DC-1F1580 -> Spyware.MediaTickets -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\596E666D-5D26-4205-9F9A-984099\B6206AB5-B1BB-4F68-AF12-03692A -> Spyware.MediaTickets -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9F3D03DE-5536-4E67-92C2-080855\6A3E293D-BDA5-42B8-8B42-9B2453 -> Spyware.MediaTickets -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C78D9B07-1F8B-40FE-874B-57C142\5A427762-9A30-4128-BD3F-1215F2 -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\E301C698-7A9C-4A2B-846F-AA2DCA\DFD3128F-BA93-4671-A9DF-EDBD9C -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\Program Files\nrpn\__delete_on_reboot__osoa.exe -> Spyware.PurityScan -> Cleaned with backup
C:\WINDOWS\cdmdownld\ylslfycfjy.exe -> Spyware.SmartPops -> Cleaned with backup
C:\WINDOWS\SSK3_B5.exe -> TrojanDropper.Small.qn -> Cleaned with backup
C:\WINDOWS\system32\edrrg6io.dll -> Spyware.SAHA -> Cleaned with backup
C:\WINDOWS\system32\maxd.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\system32\vxgame4.exe -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\system32\аѕsembly\services.exe -> Spyware.PurityScan -> Cleaned with backup
D:\Documents and Settings\Carissa\Cookies\carissa@adknowledge[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Carissa\Cookies\carissa@myway[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Carissa\Cookies\carissa@S147752[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Carissa\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Tom Masters\Cookies\tom masters@35487201[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Tom Masters\Cookies\tom masters@70307935[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Tom Masters\Cookies\tom masters@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Tom Masters\Cookies\tom masters@com[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Tom Masters\Cookies\tom [email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Tom Masters\Cookies\tom masters@myway[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Documents and Settings\Tom Masters\Cookies\tom [email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug.a -> Cleaned with backup
D:\Program Files\CxtPls\CxtPls(2).dll -> Spyware.Apropos.e -> Cleaned with backup
D:\Program Files\CxtPls\CxtPls(3).dll -> Spyware.Apropos.e -> Cleaned with backup
D:\Program Files\CxtPls\CxtPls(4).dll -> Spyware.Apropos.e -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010447.dll -> Spyware.PeopleOnPage -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010448.dll -> Spyware.BiSpy.m -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010449.exe -> Spyware.BiSpy.q -> Cleaned with backup
D:\WINDOWS\SYSTEM32\msbb321.dll -> Spyware.180solutions -> Cleaned with backup
::Report End
*************
---------------------------------------------------------
ewido security suite - Scan report (ON SANDRAS PROFILE, TODAY)
---------------------------------------------------------
+ Created on: 11:19:04 AM, 6/18/2005
+ Report-Checksum: AA836DE2
+ Date of database: 6/18/2005
+ Version of scan engine: v3.0
+ Duration: 120 min
+ Scanned Files: 118863
+ Speed: 16.48 Files/Second
+ Infected files: 7
+ Removed files: 7
+ Files put in quarantine: 7
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
+ Scan result:
C:\Documents and Settings\Sandra\Cookies\sandra@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Sandra\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010463.dll -> Spyware.Wheaterbug.a -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010464.dll -> Spyware.Apropos.e -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010465.dll -> Spyware.Apropos.e -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010466.dll -> Spyware.Apropos.e -> Cleaned with backup
D:\System Volume Information\_restore{07979A59-4D52-4AAB-AEE2-6D9B4C8A45A8}\RP123\A0010467.dll -> Spyware.180solutions -> Cleaned with backup
::Report End
Edited by The Roamer, 18 June 2005 - 03:58 PM.