also @ TechSpot: Weekend Open Forum: Have you upgraded to Windows 7 yet?
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Completed step 8 logs attached

Closed Thread
Page 2 of 2 1 2
Bookmark Thread Tools
  #21  
Old 12-02-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
I don't know about Google desktop. I don't use those things as they are already available on the net. It very well could be normal.

The 1% Cpu usage shows it is not hogging the cpu.

Perhaps someone that uses Google Desktop.

OK here is the cleanup you wanted.

If you Downloaded the Attachment Fixit then just delete it.

Thread closing-------------------------------------------------------------------------------------------------------------
Please download OTCleanIt http://download.bleepingcomputer.com.../OTCleanIt.exe

Save to desktop.

This will remove all the tools we used to clean your computer.
These tools update so often they require downloading again later if needed.

Double-click OTCleanIt.exe. Click CleanUp. Yes to the "Begin cleanup Process?"

Approve all if prompted by Firewall, Widows Defender or other guards or security programs about OTCleanIt attempting access to the Internet, allow all.

If prompted to Reboot click Yes.
OTCleanit will delete itself when finished, if not delete it by yourself.

-------------------------------------------------------------------------------------
Run CCleaner again twice or more on Cleanup temps, then on left click Registry then Scan for issues also repeat till clean.

D/L install and run ATF-Cleaner clear all except passwords in all browsers you have. Run repeatedly until no more found.

http://www.majorgeeks.com/ATF_Cleaner_d4949.html
-------------------------------------------------------------------------------------
The issues found is in System Restore so do the below

Start-Programs-Accessories-System Tools-Disk- System Restore and create a new Restore point. Name it "After cleanup at TechSpot".

Then Start-Programs-Accessories-System Tools-Disk Cleanup
Click OK to accept C:
Select all Boxes
Then click More Options
Here click System Restore and OK to "Are you sure" and the OK to Run.

As this runs it clears all but the most recent Restore Point but it does one other thing that can contain infested files and a huge amount of disk space.

It clears what is known as Shadow copies which are used by specialized back up programs.

This is if you have the Volume Shadow Copy running which is the default.
-------------------------------------------------------------------------------------

Every 2 weeks or so run mbam and sas until clean They take a while so leave scanning while you are sleeping working or watching TV. If not done under the gun they can be schedules not to interfere with computer time.

If they find something they can not clean then get back to us.

Additionally run CCleaner.

I have been using ThreatFire for more than a year, it just went from ver 3 to ver 4.

It was designed to co-exist with other Virus scanners.

Additionally it uses totally different process to protect. While conventional Virus scanners work from definitions ThreatFire works on recognizing Virus/Malware activity. It's like looking at it with 2 sets of eyes and from a different angle.

http://www.threatfire.com/Download/
-------------------------------------------------------------------------------------
Look at http://www.javacoolsoftware.com/spywareblaster.html

Run SpyBot ocassionally and use the Immunize function.
http://www.safer-networking.org/en/download/

Install Hostman and allow it to disable DNS Client and select all 4 Host files and the Update
Hostman http://www.abelhadigital.com/2008/07...-released.html

A Disk scan and Defrag are in order.

Mike
  #22  
Old 12-02-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,778 posts
Paul, I'll check the Task Manager. But in the meantime:

Remove the cleaning tools:

Download OTCleanIt (http://download.bleepingcomputer.com.../OTCleanIt.exe)
Quote:
Click the CleanUp! button.
It will go through the list and remove all of the tools it finds and then delete itself (requiring a reboot).
I'll come back with an EDIT for the Task Manager Processes.
Clear system restore points
Clear your existing system restore points and establish a new clean restore point:
Quote:
1. Go to Start > All Programs > Accessories > System Tools > System Restore
2. Select Create a restore point> OK.
3. Next, go to Start > Run and type in cleanmgr
4. Select the More options tab
5. Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created.
To remove this ad, sign in. To register for a new account, click here.
  
  #23  
Old 12-02-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,778 posts
New post for Processes in Task Manager:
Paul, this is more than you asked for. I have omitted some processes that need to run as part of the OS. Others, I have identified- some of which you can stop: those are marked 'non-essential'
Others say NO, meaning you should remove them from Startup or change Service Start up to wither Manual or Disabled/
The program or process can then be started manually of needed:
Use what you want, ignore the rest:

Windows Task Manager
1. aawservice.exe > AdAware 2008- from Service in 023

You have two Fax Services running. Do not need to either startup or run unless you are actively using them
Quote:
2. capFax.exe> capfax.exe is related to software for phone and fax. Manufacturer: BVPR Software.
3. fxssvc.exe> Microsoft's Fax Service: How to prevent fxssvc.exe from running at Windows startup?
Turn off automatic reception.
Set the Startup type of the Fax Service to Manual
.

None of the following need to startup and can be started manually when needed:Non-Essential means not necessary to start on boot"
Quote:
4. carpserv.exe> Associated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example: non-essential
5. gearsec.exe> Gear CD/DVD Burning Software: non
6. GhostTray.exe> Norton Ghost tray icon - the application can be launched manually:
From Google Groups:
Quote:
No need to worry, this is perfectly normal! Depending on what Google Desktop features you're using, such as the sidebar or content , indexing, you might see up to three GoogleDesktop.exe processes in the Tadk Mansger. it is not unusual to have 2 and possibly 3 Google Desktops running. This began after upgrading to the Google Desktop 5.7.0712.18632
7. GoogleDesktop.exe
8. GoogleDesktop.exe
Quote:
9. GoogleUpdaterService.exe(gusvc)> Used to update Google programs such as Google Toolbar. Stop
10 Hkcmd.exe> Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel: non-essential
11.hpcmpmgr.exe> HP Component Manager. installed on most computers to support HP products, such as the HP Photosmart, Deskjet, and All-In-One printers. May be use for some multimedia procucts.
12. hpztsb10.exe> Hewlett Packard Taskbar Utility for HP Deskjet printers to do maintenance tasks and diagnostics: non- essential
13. jqs.exe> Java Quick Stsrt Service> disable
14. jusched.exe> Java update: Stop
Control Panel> Java> Update tab> UNCHECK ‘check for updates automatically’> answer Yes when asked if you’re sure.
McAfee Processes:
Quote:
15. mcagent.exe> McAfee Security Center Agent. Yes
16. mcmscsvc.exe> McAfee Integrated Security Program User Manager (MISP User Manager) Very high CPu user. Can cause crashes. Put Service on Manual
17. McNASvc.exe> McAfee Network Agent.
18. McAfee Integrated Security Platform: non- essential
19. McProxy.exe> McAfee Proxy Service> Controls communication between various components of Mcafee Security Products.yes
20. Mcshield.exe> McAfee On-Access Scanner. virus scans files in the background as and when you access them.Yes.
21. mcsysmon.exe> McAfee SystemGuards is a component of Mcafee VirusScan Yes
22. MpfSrv.exe> Main executable for Mcafee Personal Firewall.: Yes
Scanners: No
Quote:
23. OneTouchMon.exe> For Visioneer OneTouch scanners. System tray access to the control panel for the scanner: non- essential\
24. PPWEBCAP.EXE> "PaperPort" software associated with scanners: non=essential
Quote:
25. SMAgent.exe> Sound subsystem driver on many ASUS motherboards. yes
26. SMax4PNP.exe > SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments y/n
The following are normal processes. I have 9 usually showing
Quote:
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
NOTE: Some of these processes are controlled on the stasartup menu:L Stasrt> Run> msconfig> enter> Selecive Strtup> Startup tab> UNCHECK any you don't want to startup> Apply> OK

Others are controlled according to the Startup type set for Serrvices
Quote:
Start> Run> services.msc> right click on Service to change> Properties> Change Start up type to your choice and need> CHECK the Dependency tab for other needed Servies. This is most ealist done in Safe Mod.
When through reboot te computer. You will get a nag message thst your can ignore after you check 'don't show this message again.' Stay in Selective Startup.
  #24  
Old 12-03-2008
Newcomer, in training
 
Member since: Nov 2008, 10 posts
Mike,

Followed your directions. Got to the last one about Hostman, but when I clicked your link it went to a page that says "The blog you were looking for was not found."
Everything else worked fine.

Bobbye,
Thanks for all of the information on the task manager. From all of your details, it doesn't look like I have anything suspicious left. I will get rid of the non-essential stuff.

Thanks again to both of you for you help, I really appreciate it.
Paul
  #25  
Old 12-03-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Here: http://www.abelhadigital.com/2008/07...-released.html

Mike
  #26  
Old 12-03-2008
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,778 posts
You're welcome Paul.
Closed Thread
Page 2 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Completed Step 8, Help with Logs Virus & Malware removal 10 11-21-2008 01:52 AM
Completed 8 steps - Logs posted Virus & Malware removal 10 11-17-2008 12:55 AM
I just completed the 8 step process Virus & Malware removal 2 11-13-2008 09:45 AM
I am uploading my logs for the 8 step removal process Virus & Malware removal 16 11-13-2008 05:07 AM
HJT and AVG-AS logs attached Virus & Malware removal 10 06-10-2007 07:49 AM


All times are GMT -4. The time now is 12:30 AM.