Go Back   Cyber Tech Help Support Forums > Software > Malware Removal

Notices

Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs

Reply
 
Topic Tools
  #1  
Old July 30th, 2017, 04:44 PM
rnsbg rnsbg is offline
Senior Member
 
Join Date: Jun 2004
Posts: 114
what's in this file slowing me down now please?(Moved by Murf)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:42:43 AM, on 7/30/2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18698)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
E:\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://mail.google.com/mail/u/0/?ta...render?tab=mch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Norton Identity Safety - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine32\22.10.0.85\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine32\22.10.0.85\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TUSBSleepChargeSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
O4 - HKLM\..\Run: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [StatusAlerts] "C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: intu-help-qb5 - {867FCB77-9823-4CD6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Gadget Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\windows\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP DS Service - Hewlett-Packard Company - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\22.10.0.85\NIS.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS. exe
O23 - Service: QBIDPService (QBVSS) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - Unknown owner - C:\windows\system32\ThpSrv.exe (file missing)
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12085 bytes
Reply With Quote
  #2  
Old July 31st, 2017, 03:16 AM
rnsbg rnsbg is offline
Senior Member
 
Join Date: Jun 2004
Posts: 114
Nobody sees anything odd within the file?
Reply With Quote
  #3  
Old August 1st, 2017, 01:51 AM
rnsbg rnsbg is offline
Senior Member
 
Join Date: Jun 2004
Posts: 114
Is there anybody out there? Why have a contact us link if you only direct us back here? I'm just looking for help.
Reply With Quote
  #4  
Old August 5th, 2017, 03:00 AM
jenae jenae is offline
Member
 
Join Date: Aug 2004
Location: Sydney
Posts: 61
Hi, well HijackThis is deprecated, it is no longer supported by the developer and was not suitable for 64 bit machines, (and currently also 32 bit), it requires expert analysis to read properly. As it has not been used professionally for years, it is basically useless today. Now simple problems can be fixed , though we do not know what problem you are having other then a general slowdown.

You can have Hijackthis fix these entries:-

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL (file missing)

O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)

O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)

In addition tell us what problems you are having, if they are malware related you will need to use the specialized forum. Norton may well be your problem. Are you updated fully with windows updates?

Go to search and type:- cmd right click on the returned cmd.exe and select "run as administrator" copy and paste all the below text into the prompt window:-

echo > 0 & systeminfo | find /V /I "hotfix" | find /V "KB" >> 0 & WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /format:list >> 0 & wmic PATH Win32_VideoController GET Description,PNPDeviceID /format:list >> 0 & tasklist /v >> 0 & net start >> 0 & echo >> 0 & notepad 0

Press enter, this will give us info on your machine, please attach the notepad output into your response.
Reply With Quote
  #5  
Old August 6th, 2017, 04:11 PM
lufbra lufbra is offline
CTH Subscriber
 
Join Date: Sep 2000
O/S: Windows 10 Home
Posts: 12,532
Quote:
Originally Posted by rnsbg View Post
Is there anybody out there? Why have a contact us link if you only direct us back here? I'm just looking for help.
You're posting this in the wrong Forum, you need to post this kind of thing here....

http://www.cybertechhelp.com/forums/...splay.php?f=25
Reply With Quote
  #6  
Old August 9th, 2017, 06:12 PM
rnsbg rnsbg is offline
Senior Member
 
Join Date: Jun 2004
Posts: 114
log

ECHO is on.
Host Name: PC
OS Name: Microsoft Windows 7 Home Premium
OS Version: 6.1.7601 Service Pack 1 Build 7601
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Workstation
OS Build Type: Multiprocessor Free
Registered Owner: PC
Registered Organization: Toshiba
Product ID: 00359-OEM-8992687-00057
Original Install Date: 6/16/2014, 8:49:37 PM
System Boot Time: 8/9/2017, 11:10:17 AM
System Manufacturer: TOSHIBA
System Model: Satellite A505
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
[01]: Intel64 Family 6 Model 23 Stepping 10 GenuineIntel ~2200 Mhz
BIOS Version: INSYDE 1.70, 9/15/2009
Windows Directory: C:\windows
System Directory: C:\windows\system32
Boot Device: \Device\HarddiskVolume1
System Locale: en-us;English (United States)
Input Locale: en-us;English (United States)
Time Zone: (UTC-06:00) Central Time (US & Canada)
Total Physical Memory: 3,964 MB
Available Physical Memory: 1,976 MB
Virtual Memory: Max Size: 7,926 MB
Virtual Memory: Available: 5,084 MB
Virtual Memory: In Use: 2,842 MB
Page File Location(s): C:\pagefile.sys
Domain: WORKGROUP
Logon Server: \\PC
Network Card(s): 2 NIC(s) Installed.
[01]: Realtek PCIe FE Family Controller
Connection Name: Local Area Connection
Status: Media disconnected
[02]: Realtek RTL8191SE Wireless LAN 802.11n PCI-E NIC
Connection Name: Wireless Network Connection
DHCP Enabled: Yes
DHCP Server: 10.0.0.1
IP address(es)
[01]: 10.0.0.126
[02]: fe80::88ba:2809:1ef9:e989
[03]: 2601:246:c500:19d4:7852:2c:8785:a51b
[04]: 2601:246:c500:19d4:88ba:2809:1ef9:e989
[05]: 2601:246:c500:19d4::ed72



D e s c r i p t i o n = M o b i l e I n t e l ( R ) 4 S e r i e s E x p r e s s C h i p s e t F a m i l y

P N P D e v i c e I D = P C I \ V E N _ 8 0 8 6 & a m p ; D E V _ 2 A 4 2 & a m p ; S U B S Y S _ F F 1 0 1 1 7 9 & a m p ; R E V _ 0 7 \ 3 & a m p ; 2 1 4 3 6 4 2 5 & a m p ; 0 & a m p ; 1 0





D e s c r i p t i o n = M o b i l e I n t e l ( R ) 4 S e r i e s E x p r e s s C h i p s e t F a m i l y

P N P D e v i c e I D = P C I \ V E N _ 8 0 8 6 & a m p ; D E V _ 2 A 4 3 & a m p ; S U B S Y S _ F F 1 0 1 1 7 9 & a m p ; R E V _ 0 7 \ 3 & a m p ; 2 1 4 3 6 4 2 5 & a m p ; 0 & a m p ; 1 1






Image Name PID Session Name Session# Mem Usage Status User Name CPU Time Window Title
========================= ======== ================ =========== ============ =============== ================================================== ============ ================================================== ======================
System Idle Process 0 Services 0 24 K Unknown NT AUTHORITY\SYSTEM 1:19:59 N/A
System 4 Services 0 1,192 K Unknown N/A 0:01:22 N/A
smss.exe 336 Services 0 936 K Unknown N/A 0:00:00 N/A
csrss.exe 524 Services 0 6,084 K Unknown N/A 0:00:00 N/A
wininit.exe 592 Services 0 3,524 K Unknown N/A 0:00:00 N/A
csrss.exe 616 Console 1 32,332 K Running N/A 0:00:06 N/A
services.exe 652 Services 0 9,080 K Unknown N/A 0:00:03 N/A
lsass.exe 664 Services 0 11,636 K Unknown N/A 0:00:06 N/A
lsm.exe 688 Services 0 3,720 K Unknown N/A 0:00:00 N/A
svchost.exe 800 Services 0 8,468 K Unknown N/A 0:01:23 N/A
winlogon.exe 836 Console 1 5,588 K Unknown N/A 0:00:00 N/A
svchost.exe 936 Services 0 8,560 K Unknown N/A 0:00:01 N/A
svchost.exe 352 Services 0 16,568 K Unknown N/A 0:00:01 N/A
svchost.exe 428 Services 0 143,408 K Unknown N/A 0:00:34 N/A
svchost.exe 620 Services 0 21,116 K Unknown N/A 0:00:01 N/A
svchost.exe 1016 Services 0 35,912 K Unknown N/A 0:00:23 N/A
audiodg.exe 1100 Services 0 23,796 K Unknown N/A 0:00:00 N/A
svchost.exe 1296 Services 0 14,472 K Unknown N/A 0:00:03 N/A
spoolsv.exe 1472 Services 0 10,660 K Unknown N/A 0:00:08 N/A
svchost.exe 1504 Services 0 12,032 K Unknown N/A 0:00:01 N/A
armsvc.exe 1604 Services 0 3,528 K Unknown N/A 0:00:00 N/A
DbxSvc.exe 1680 Services 0 3,240 K Unknown N/A 0:00:00 N/A
svchost.exe 1812 Services 0 5,912 K Unknown N/A 0:00:00 N/A
HPBDSService.exe 1924 Services 0 9,988 K Unknown N/A 0:00:00 N/A
HPLaserJetService.exe 2032 Services 0 7,096 K Unknown N/A 0:02:29 N/A
svchost.exe 1188 Services 0 3,192 K Unknown N/A 0:00:00 N/A
nis.exe 1324 Services 0 21,896 K Unknown N/A 0:05:09 N/A
svchost.exe 1736 Services 0 3,008 K Unknown N/A 0:00:00 N/A
QBCFMonitorService.exe 1740 Services 0 11,424 K Unknown N/A 0:00:01 N/A
QBIDPService.exe 2128 Services 0 9,524 K Unknown N/A 0:00:00 N/A
taskhost.exe 2612 Console 1 17,512 K Running PC 0:00:02 MCI command handling window
taskeng.exe 2648 Services 0 4,992 K Unknown N/A 0:00:00 N/A
dwm.exe 2660 Console 1 37,064 K Running PC 0:00:22 DWM Notification Window
explorer.exe 2692 Console 1 50,904 K Running PC 0:00:09 N/A
igfxtray.exe 2148 Console 1 5,076 K Running PC 0:00:00 igfxtrayWindow
hkcmd.exe 2388 Console 1 5,124 K Running PC 0:00:00 N/A
igfxpers.exe 2400 Console 1 5,476 K Running PC 0:00:00 PersistWndName
RAVCpl64.exe 2232 Console 1 7,444 K Running PC 0:00:00 Realtek HD Audio CPL for Vista
igfxsrvc.exe 2532 Console 1 5,180 K Running PC 0:00:00 OleMainThreadWndName
SynTPEnh.exe 2924 Console 1 10,752 K Running PC 0:00:00 N/A
ThpSrv.exe 2844 Console 1 4,664 K Running PC 0:00:00 TOSHIBA HDD Protection System
TPwrMain.exe 3020 Console 1 5,704 K Running PC 0:00:00 TPS8_PWRMAIN_Wnd
nis.exe 376 Console 1 10,244 K Running PC 0:00:01 DIEmWin
SDUpdSvc.exe 2932 Services 0 7,524 K Unknown N/A 0:00:00 N/A
SmoothView.exe 3088 Console 1 2,484 K Running PC 0:00:00 SmoothView
TCrdMain.exe 3192 Console 1 10,568 K Running PC 0:00:00 TCrdMain
Teco.exe 3240 Console 1 5,092 K Running PC 0:00:00 TECO_TRAY_WND_NAME
GoogleCrashHandler.exe 3424 Services 0 528 K Unknown N/A 0:00:00 N/A
GoogleCrashHandler64.exe 3588 Services 0 528 K Unknown N/A 0:00:00 N/A
taskeng.exe 3616 Console 1 5,324 K Running PC 0:00:00 TaskEng - Task Scheduler Engine Process
svchost.exe 3824 Services 0 6,172 K Unknown N/A 0:00:00 N/A
igfxext.exe 3892 Console 1 4,664 K Running PC 0:00:00 IgfxExt_Wnd_Name
NDSTray.exe 3996 Console 1 804 K Running PC 0:00:00 ConfigFree
TUSBSleepChargeSrv.exe 4004 Console 1 4,880 K Running PC 0:00:00 TUSBSleepChargeSrv
ThpSrv.exe 4068 Services 0 2,756 K Unknown N/A 0:00:00 N/A
TODDSrv.exe 3176 Services 0 4,108 K Unknown N/A 0:00:00 N/A
HPStatusAlerts.exe 3260 Console 1 8,428 K Running PC 0:00:00 N/A
TosCoSrv.exe 3316 Services 0 3,344 K Unknown N/A 0:00:00 N/A
hpwuschd2.exe 3096 Console 1 3,328 K Running PC 0:00:00 HPWU
TecoService.exe 3236 Services 0 3,760 K Unknown N/A 0:00:00 N/A
SDTray.exe 3968 Console 1 17,988 K Running PC 0:00:01 N/A
SearchIndexer.exe 3992 Services 0 26,428 K Unknown N/A 0:00:03 N/A
SDWSCSvc.exe 4108 Services 0 7,752 K Unknown N/A 0:00:00 N/A
iexplore.exe 4488 Console 1 40,756 K Running PC 0:00:11 what's in this file slowing me down now please? - Cyber Tech Help Suppor
SDFSSvc.exe 4956 Services 0 39,596 K Unknown N/A 0:00:01 N/A
svchost.exe 3028 Services 0 6,060 K Unknown N/A 0:00:00 N/A
iexplore.exe 1264 Console 1 563,796 K Running PC 0:04:59 N/A
TPCHSrv.exe 5152 Services 0 8,392 K Unknown N/A 0:00:00 N/A
svchost.exe 5336 Services 0 5,620 K Unknown N/A 0:00:00 N/A
TosSmartSrv.exe 5500 Services 0 7,552 K Unknown N/A 0:00:00 N/A
TPCHWMsg.exe 5580 Console 1 5,648 K Running PC 0:00:00 TPCHWarnMsg
TosSENotify.exe 5708 Console 1 9,148 K Running PC 0:00:00 TosSENotify
wmpnetwk.exe 5764 Services 0 3,912 K Unknown N/A 0:00:00 N/A
SynTPHelper.exe 5816 Console 1 3,420 K Running PC 0:00:00 N/A
GoogleToolbarUser_32.exe 3560 Console 1 13,980 K Running PC 0:00:00 N/A
CFSwMgr.exe 2016 Console 1 528 K Running PC 0:00:00 CFSwManager
CFIWmxSvcs64.exe 5628 Services 0 3,596 K Unknown N/A 0:00:00 N/A
MsSpellCheckingFacility.e 4504 Console 1 8,600 K Unknown PC 0:00:00 N/A
CFProcSRVC.exe 4892 Services 0 7,456 K Unknown N/A 0:00:00 N/A
CFSvcs.exe 4944 Services 0 1,132 K Unknown N/A 0:00:00 N/A
wuauclt.exe 4812 Console 1 6,920 K Running PC 0:00:00 Windows Update Taskbar Notification
FlashUtil64_26_0_0_151_Ac 6004 Console 1 10,144 K Running PC 0:00:01 OleMainThreadWndName
iexplore.exe 6080 Console 1 145,900 K Running PC 0:00:29 N/A
taskhost.exe 4968 Console 1 5,408 K Running PC 0:00:00 Task Host Window
splwow64.exe 4680 Console 1 10,416 K Unknown PC 0:00:00 N/A
cmd.exe 1756 Console 1 3,148 K Running PC 0:00:00 tasklist /v
conhost.exe 1088 Console 1 6,596 K Running PC 0:00:00 CicMarshalWnd
WINWORD.EXE 2760 Console 1 47,768 K Running PC 0:00:02 Document1 - Microsoft Word non-commercial use
TrustedInstaller.exe 2716 Services 0 15,692 K Unknown N/A 0:00:35 N/A
SearchProtocolHost.exe 5772 Services 0 5,368 K Unknown N/A 0:00:00 N/A
SearchFilterHost.exe 3208 Services 0 5,208 K Unknown N/A 0:00:00 N/A
WmiPrvSE.exe 4344 Services 0 12,692 K Unknown N/A 0:00:00 N/A
WmiPrvSE.exe 5292 Services 0 6,224 K Unknown N/A 0:00:00 N/A
tasklist.exe 5424 Console 1 6,820 K Unknown PC 0:00:00 N/A
These Windows services are started:
Adobe Acrobat Update Service
Application Experience
Application Information
Background Intelligent Transfer Service
Base Filtering Engine
CNG Key Isolation
COM+ Event System
ConfigFree Gadget Service
ConfigFree Service
ConfigFree WiMAX Service
Cryptographic Services
DbxSvc
DCOM Server Process Launcher
Desktop Window Manager Session Manager
DHCP Client
Diagnostic Policy Service
Diagnostic Service Host
Diagnostic System Host
Diagnostics Tracking Service
Distributed Link Tracking Client
DNS Client
Extensible Authentication Protocol
Group Policy Client
HP DS Service
HP LaserJet Service
IKE and AuthIP IPsec Keying Modules
IP Helper
IPsec Policy Agent
Multimedia Class Scheduler
Net Driver HPZ12
Network Connections
Network List Service
Network Location Awareness
Network Store Interface Service
Norton Internet Security
Plug and Play
Pml Driver HPZ12
Power
Print Spooler
Program Compatibility Assistant Service
Protected Storage
QBCFMonitorService
QBIDPService
Remote Procedure Call (RPC)
RPC Endpoint Mapper
Security Accounts Manager
Security Center
Server
Shell Hardware Detection
Spybot-S&D 2 Scanner Service
Spybot-S&D 2 Security Center Service
Spybot-S&D 2 Updating Service
SSDP Discovery
Superfetch
System Event Notification Service
Task Scheduler
TCP/IP NetBIOS Helper
Themes
TOSHIBA eco Utility Service
TOSHIBA HDD Protection
TOSHIBA HDD SSD Alert Service
TOSHIBA Optical Disc Drive Service
TOSHIBA Power Saver
TPCH Service
User Profile Service
Windows Audio
Windows Audio Endpoint Builder
Windows Driver Foundation - User-mode Driver Framework
Windows Event Log
Windows Firewall
Windows Font Cache Service
Windows Image Acquisition (WIA)
Windows Management Instrumentation
Windows Media Player Network Sharing Service
Windows Modules Installer
Windows Search
Windows Update
WLAN AutoConfig
Workstation
The command completed successfully.
ECHO is on.
Reply With Quote
  #7  
Old August 9th, 2017, 06:13 PM
rnsbg rnsbg is offline
Senior Member
 
Join Date: Jun 2004
Posts: 114
Wrong forum

I'll ensure I post to the correct forum next time.
Reply With Quote
  #8  
Old August 9th, 2017, 11:35 PM
jenae jenae is offline
Member
 
Join Date: Aug 2004
Location: Sydney
Posts: 61
Hi, I need you to work with me, I asked what sort of problems you were having, I am not in front of your computer and you have to tell me why you think you are having problems , what are these problems?

From what you posted (and I said attach, not paste the data, as in this form it is difficult to read). You have windows firewall and Norton internet security, which should also have a firewall, if both are active it will play havoc with your internet speeds and connections. You also have google toolbar, another problem util.

My advice is to be rid of Norton, use only windows defender (MSE in 7) and windows firewall, you have 4 gb of Ram performance can be improved by adding more ram, have you considered upgrading to 10?

To be rid of Norton you need to run their uninstall util (you can google for it).
Reply With Quote
  #9  
Old August 10th, 2017, 09:07 PM
olgun52's Avatar
olgun52 olgun52 is offline
Malware Removal Team
 
Join Date: Feb 2014
O/S: Windows 10 Pro
Location: Europa
Posts: 2,066
Hello rnsbg and Welcome to the CyberTechHelp Forums. .
I will be helping you fixing your problems.

Please take note of some guidelines for this fix:

1- My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Keep your sentences short. Thanks for your understanding.
2- Perform everything in the correct order. Sometimes one step requires the previous one.
3- Please open as administrator the computer. How is open as administrator the computer?
4- Disable your AntiVirus and AntiSpyware applications, as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to get help here
How to disable your security applications.
5- To make sure you have an accurate view of files there, make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"
6- Back up all your private data / important files on another (external) drive before using our tools (if possible).
7- Please subscribe to this thread if you have not done so already, and please don't do any other scans on your own and don't install or remove software.
8- Lastly, keep in mind that we are volunteers, so you do not have to pay for malware removal.

Thanks

************************************************** *******************************************
Let's check. Please do these.

Let's make things a bit easier for ourselves......

Please disable Spybot S&D’s TeaTimer protection, because it is known to interfere with our fixes.
  • Open Spybot and click on 'Mode' then click 'Advanced Mode'.
  • Click on 'Tools' in bottom left hand corner.
  • Click on the 'System Startup' icon.
    Uncheck 'Teatimer' box and/or uncheck 'Resident'.
  • Then, check next to the computer clock to see if the icon for Spybot is still there.
    If it is, right click it and choose 'exit Spybot-S&D Resident'.
Reboot the computer.

Or better still, once you have stopped Tea Timer from running... Uninstall Spybot.
We don't recommend it any more due to bad test results.

And I recommend you delete the Bing toolbar also .
---------------------------------------------------

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Have a nice day.

Reply With Quote
  #10  
Old August 10th, 2017, 09:10 PM
olgun52's Avatar
olgun52 olgun52 is offline
Malware Removal Team
 
Join Date: Feb 2014
O/S: Windows 10 Pro
Location: Europa
Posts: 2,066
Hello rnsbg and Welcome to the CyberTechHelp Forums. .
I will be helping you fixing your problems.

Please take note of some guidelines for this fix:

1- My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Keep your sentences short. Thanks for your understanding.
2- Perform everything in the correct order. Sometimes one step requires the previous one.
3- Please open as administrator the computer. How is open as administrator the computer?
4- Disable your AntiVirus and AntiSpyware applications, as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to get help here
How to disable your security applications.
5- To make sure you have an accurate view of files there, make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"
6- Back up all your private data / important files on another (external) drive before using our tools (if possible).
7- Please subscribe to this thread if you have not done so already, and please don't do any other scans on your own and don't install or remove software.
8- Lastly, keep in mind that we are volunteers, so you do not have to pay for malware removal.

Thanks

************************************************** *******************************************
Let's check. Please do these.

Let's make things a bit easier for ourselves......

Please disable Spybot S&D’s TeaTimer protection, because it is known to interfere with our fixes.
  • Open Spybot and click on 'Mode' then click 'Advanced Mode'.
  • Click on 'Tools' in bottom left hand corner.
  • Click on the 'System Startup' icon.
    Uncheck 'Teatimer' box and/or uncheck 'Resident'.
  • Then, check next to the computer clock to see if the icon for Spybot is still there.
    If it is, right click it and choose 'exit Spybot-S&D Resident'.
Reboot the computer.

Or better still, once you have stopped Tea Timer from running... Uninstall Spybot.
We don't recommend it any more due to bad test results.

And I recommend you delete the Bing toolbar and Java software also .
---------------------------------------------------

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Have a nice day.

Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Topics
Topic Topic Starter Forum Replies Last Post
File using up massive amounts of memory- Moved by MURF kuzzz Malware Removal 71 December 11th, 2018 10:32 PM
Run Dll - Moved by Murf MAllen5 Malware Removal 3 February 24th, 2014 01:15 AM
Can someone view this hijack this file.-Moved by Murf dr_ledger Malware Removal 22 June 19th, 2013 06:24 AM
HijackThis Log File (Moved from Hardware-Murf) Siamese Dog Malware Removal 1 November 11th, 2006 06:31 AM
Serious Lag - Help (Moved by Murf) EddieP27 Malware Removal 3 May 27th, 2006 03:57 AM


All times are GMT +1. The time now is 04:03 AM.