Does Spyware burn itself onto a CD with data?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by o2bageek, Dec 20, 2004.

  1. o2bageek

    o2bageek Private E-2

    I too am getting a condition where my CPU is constantly running at 100%.

    Does anyone know whether spyware will copy itself to a disc when using the CD writer in windows XP(home edition). I am sure I have something infecting my laptop (suddenly slower than molasses, sudden onset of symptoms, addition of a new svchost in 'processes' that will not die). I have tried the usual processes as indicated in the document by Chaslang, but have been unable to access the online services. Nothing has changed the condition

    I am at the point where I want to burn all wanted data onto a CD, then bomb machine back to original state and re-load data as needed. However, I am worried about the spyware hiding itself on the CD and re-occuring later.

    Any info would be greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you were referring to: How to Protect yourself from malware!
    That is to help protect you from future problems. Follow the steps below if already having problems.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. o2bageek

    o2bageek Private E-2

    Thanks for a quick response. I was actually referring to your article "READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal". I have downloaded each of the programs, installed as necessary, and follwed the procedure. The problem I encountered is that I have dialup (Compuserve) which refuses to connect when I boot in safe mode with networking, and each time I have tried to access Trend or Symantec online scans while booted in normal mode it takes too long, and the scan will not run.

    Should I go ahead and post a Hijack this 1.99 log ?
     
  4. PhilliePhan

    PhilliePhan Guest

    Hi O2bageek,

    If you have attempted all of the other steps in the Cleanup Tutorial, please go ahead and send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’ve been pretty busy with work lately, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  5. o2bageek

    o2bageek Private E-2

    Here is my hijack this 1.99 log file.

    I apologise if there is anything running that you wanted me to shut down - I'm a little out of my depth here. The only thing I could see in the system tray was a Toshiba power control icon. I did have Norton 2005 running so I uninstalled it per suggestions here.

    Thanks for any help you can give.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you really uninstall Norton 2005? The HJT tutorial just requests that you end the processes before running HJT. Are you still experiencing the 100% CPU useage problems right now with Norton uninstalled?

    I would run HJT and have it fix the next line below, but I don't think it is the cause of your problem.
    O16 - DPF: {D9EA64B2-B966-E177-332C-78B69886526D} (MNPerformer Class) - http://download.newaol.com/bkpromo/download/PerformerSetup.cab


    Are the next two lines what is required by your ISP?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.15.0.91:3128
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6AA1C332-897B-4413-B14C-00AF6FF74DF6}: NameServer = 10.15.0.91

    Why are you running msconfig at startup? Are you using a selective startup?
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    If so, click Start, Run, then enter msconfig in the box and click OK.

    In the window that comes up, click the General tab and make sure normal startup is selected. We need to see everything that you system really wants to load.

    Now reboot and then post a new HJT log. If still having a problem, hit CTRL-ALT-DEL to bring up Task Manager and click the Processes tab. Tell me which process is using all the CPU time.
     
  7. o2bageek

    o2bageek Private E-2

    I cleaned up the entries you suggested. I removed the lines you thought might be from my ISP, but my online service ran perfectly so I guess they were not relevant for that.

    The system is still running really slowly - so I changed to normal startup, then stopped the programs running in my system tray.

    Then I ran Hijack This (file enclosed here).

    The process that seems to be getting the most CPU usage is the system idle process. It's getting about 81/82 on CPU usage, and is getting way more time in the CPU time column than anything else.

    Thanks for taking time to look at these
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't stop anything! For you particular problem I want to see everything that loads and runs (that is why I don't want msconfig to limit anything from loading).

    Idle CPU is not usage. It's just what it says. The CPU is idle. Normally this will hover in the high 97 to 99 % area as long as you have no scanning operations running and are not actively click and opening and closing processes. What process (or processes) are using the other 18%, and is it always totalling to about 18 %?

    This Findfast process is not required and has always been know to be a resource waster. Also it can be the cause of lots of unnecessary disk activity. I would have HJT fix the next line.
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE

    You have two of these OSA.EXE processes loading. Have HJT fix the second one.
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
     
    Last edited: Dec 23, 2004
  9. o2bageek

    o2bageek Private E-2

    Items fixed as suggested. I left everything running, and ran hijack this per your instructions.

    With all of this running, the system idle process is down to 67, with explorer taking about 9, taskmanager about 20.

    One of the svchost processes is using 2 - 3.

    Thanks for the help
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. You just have a lot of stuff running. I don't understand why they are using CPU time if the processes are currently doing nothing. For example, you said "explorer taking about 9, taskmanager about 20." If I'm just sitting here with many process loaded but I'm doing nothing but just looking at the Process list in Task Manager, explorer.exe is 0% CPU and about 25.1 Mb of mem. Task Manager is 0% CPU and about 2.18 Mb of mem.

    You may want to consider not allowing certain items to load that you don't use. Don't use msconfig for that. Use a startup manager or just completely remove them from startup if you don't need them.

    Note: You have a LexMark printer. Some of their process have been known to cause Windows Startup problems and also be resource hogs.
     
    Last edited: Dec 25, 2004
  11. o2bageek

    o2bageek Private E-2

    Thanks for taking the time to look at this - I really appreciate the help. I'll make some changes based on your recommendations.

    Thanks again
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check out this startup manager - Startup CPL
    This is a better thing to use than msconfig.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds