Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » Need Help understanding this

[Fixed] Hijackthis! Logs - Need Help understanding this posted in the Security & Safety forums; My CPU is still running at an amazing rate when I'm doing something small, I'll open something and it will spike to 40 - 50% I'll be looking at a ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 12-08-2007
Bronze Member
My PC
 
Join Date: Aug 2007
Posts: 99
Arch Enemy - See this Members User comments on their Profile page
Default Re: Need Help understanding this

My CPU is still running at an amazing rate when I'm doing something small, I'll open something and it will spike to 40 - 50%

I'll be looking at a webpage and it will be 30 - 40 and 20% when idle.


Any ideas?


  #9  
Old 12-08-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,555
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: Need Help understanding this

Lets see if this finds anything...


Go to Kaspersky Online Scanner
Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #10  
Old 12-08-2007
Bronze Member
My PC
 
Join Date: Aug 2007
Posts: 99
Arch Enemy - See this Members User comments on their Profile page
Default Re: Need Help understanding this

It's running an update, expect the scan results in 30 - 45 minutes


  #11  
Old 12-08-2007
Bronze Member
My PC
 
Join Date: Aug 2007
Posts: 99
Arch Enemy - See this Members User comments on their Profile page
Default Re: Need Help understanding this

23% of the scans done and my CPU usage is sticking around 45 - 50%

It's detected 4 viruses and 12 infected objects, I'm just scanning my HDD by the way


  #12  
Old 12-08-2007
Bronze Member
My PC
 
Join Date: Aug 2007
Posts: 99
Arch Enemy - See this Members User comments on their Profile page
Default Kaspersky Log

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, December 08, 2007 3:29:17 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/12/2007
Kaspersky Anti-Virus database records: 476970
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 108296
Number of viruses found: 5
Number of infected objects: 15
Number of suspicious objects: 0
Duration of the scan process: 01:28:29

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Satan\.housecall6.6\Quarantine\179848.exe .bac_a01244/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Satan\.housecall6.6\Quarantine\179848.exe .bac_a01244/WISE0017.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Documents and Settings\Satan\.housecall6.6\Quarantine\179848.exe .bac_a01244/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
C:\Documents and Settings\Satan\.housecall6.6\Quarantine\179848.exe .bac_a01244 WiseSFX: infected - 3 skipped
C:\Documents and Settings\Satan\.housecall6.6\Quarantine\179848.exe .bac_a01244 WiseSFXDropper: infected - 3 skipped
C:\Documents and Settings\Satan\.housecall6.6\Quarantine\179848.exe .bac_a01244 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Satan\.housecall6.6\Quarantine\NDNuninsta ll6_38.exe.bac_a00760 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\cer t8.db Object is locked skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\for mhistory.dat Object is locked skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\Goo gleToolbarData\googlesafebrowsing.db Object is locked skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\his tory.dat Object is locked skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\key 3.db Object is locked skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\par ent.lock Object is locked skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\sea rch.sqlite Object is locked skipped
C:\Documents and Settings\Satan\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\url classifier2.sqlite Object is locked skipped
C:\Documents and Settings\Satan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Microsoft\Windows Live Contacts\chris_meee_3@hotmail.co.uk\real\members.s tg Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Microsoft\Windows Live Contacts\chris_meee_3@hotmail.co.uk\shadow\members .stg Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\Cac he\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\Cac he\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\Cac he\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Application Data\Mozilla\Firefox\Profiles\15261s0u.default\Cac he\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Temp\~DFC020.tmp Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Temp\~DFC05E.tmp Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Temp\~DFDDBA.tmp Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Temp\~DFDDCC.tmp Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Satan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Satan\My Documents\mirc631.exe/stream/data0001/stream/data0014 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\Documents and Settings\Satan\My Documents\mirc631.exe/stream/data0001/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\Documents and Settings\Satan\My Documents\mirc631.exe/stream/data0001 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\Documents and Settings\Satan\My Documents\mirc631.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\Documents and Settings\Satan\My Documents\mirc631.exe NSIS: infected - 4 skipped
C:\Documents and Settings\Satan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Satan\ntuser.dat.LOG Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\Program Files\Philips\Philips SPC710NC Webcam\MioNet\install_MioNet_ver1_6_11.exe/cmdow.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
C:\Program Files\Philips\Philips SPC710NC Webcam\MioNet\install_MioNet_ver1_6_11.exe CreateInstall: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D642016C-10C7-4416-B7C1-E4D1BFEC68B0}\RP361\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


  #13  
Old 12-08-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,555
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: Need Help understanding this

All that has got is quarantined files.There is nothing else there...


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #14  
Old 12-08-2007
Bronze Member
My PC
 
Join Date: Aug 2007
Posts: 99
Arch Enemy - See this Members User comments on their Profile page
Default Re: Need Help understanding this

Please tell me you're joking


When I go to scan I get the following options - Critical Areas, Memory, My Computer, My Email, Folders and a single file, I chose My Computer for that scan and that log = what the scan gave me



Last edited by Arch Enemy; 12-08-2007 at 04:46 AM.

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 02:18 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top