Slow running computer/ msconfig will not allow changes
I posted on another board about this problem and was recommended that i go here. It was suspected that i have a virus. I have been trying to isolate the problem through msconfig but it prompts me to log in as the adminastrator to make changes, but i am the only one on this computer and my account is set up as adminstrator. I have run hijackthis here is the log.Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:01:58 PM, on 4/8/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal
1. Rerun Hijackthis (scan only) and place checks beside the following entries
R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: ALOT eMusic Toolbar - {8260C2B8-E0D1-448a-B062-33D12D468BF0} - C:\Program Files\alot\bin\alot.dll (file missing) O4 - HKLM\..\RunServices: [Windows System] \winsys32.exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis
2. Using Windows Explorer
(Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and Delete the following file
C:\Windows\System32\winsys32.exe
Close windows explorer ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
Bamajim thank you for your help. I have tried finding the winsys32.exe file but no luck finding it. even search in hidden files and folders. Here is a new log.Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:50:08 PM, on 4/9/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
1. Rerun Hijackthis (scan only) and place checks beside the following entries
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O3 - Toolbar: (no name) - {8260C2B8-E0D1-448a-B062-33D12D468BF0} - (no file) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
Bamajim here is the latest hijackthis log. also i have been trying to run spybot S&D, everything runs fine but it freezes when i try to fix the problems. I don't know if this is related or not. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:26:39 PM, on 4/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
It may or may not be related. What is it trying to fix when it freezes?
Run an online virus scan called Kaspersky from HERE.
1. Click on " Kaspersky Online Scanner" 2. A new smaller window will pop up. Press on " Accept". After reading the contents. 3. Now Kaspersky will update the anti-virus database. Let it run. 4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK. 5. Then click on " My Computer". And the scan will start. 6. When the scan is complete Select "Save error report as" Then in the file name just type in kaspersky Under "save as type" select text .txt Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan
bamajim spybot found 289 Items but when i tried to fix the program froze. also tried to fix one at a time and it still froze. I don't know if this makes any difference or not. I am having some diffuculty posting the entire results here is what i can get you.Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true
Scan Target - My Computer: C:\ D:\ E:\ F:\
Scan Statistics: Total number of scanned objects: 107553 Number of viruses found: 0 Number of infected objects: 0 Number of suspicious objects: 0 Duration of the scan process: 01:47:20
Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\003c890d1b110f9f6268912a7e3ad113_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0062104e10e8f129f40369d7014993bd_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0074a50ef24429f165612514d6365e6a_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\00baf74c74dd32a9568a46912c0fa76d_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\015e14f1cb6623c41cf3a258fa658a23_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\025af052e3eee3024d7e48df11fd1834_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\033be9c425dcd91be95c624589945c88_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03f0a28f24f0bbf2a3e573c662807f3c_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\046537070e42b8416d38e9086afb540d_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\057840c29eafec80f77096fc9bbea957_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06a9d9fdae9e73075dabf062a88b5099_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\074d33304123071330592ac7410dbf07_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\07647a74a8f034c2b8d4db1adf9cfe2b_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\07892f50ddf10c1f966b6738b6e9b689_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\087d459e8d43d385d5bd9247848b0ff2_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\08b4ac3ff3e2b1112cbbc254e1fe72d8_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\095a7c3824b32d5d075379d91a845674_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\098c651ceeb0fc87f870d89c8b47b7c4_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\09d5d95104520cbd7e9899cd22b9603c_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0a0a7572cf9c0d3a8afd947b1794c0c7_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ada9f24db6c2a6d71ef3ff9fd802849_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0aff6d62a3b84fa18e73cd7696ecc8e8_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0cb47bd38779d64108911180380639ee_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0cd50cb0dd4041c7cc4376265caa5456_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d5568676f8b705939c3ea65d446ef76_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ff8cee247c04a26161d1e584dda3f8d_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\104be295c0c7059b8b8bc1dfd51c431d_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1062313f3d1ce0de918fe3bb96891362_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10ea70fffc909aee492a547cb9d99a15_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\110b60371ef6ccc3496ccce6d5db07eb_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\115ea5963fc9223dae69cb442d88ae61_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11a7bba992a80253799a1732849bef47_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12d91eae8d7a39419198b2e26dad0d77_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
Bamajim here is the bottom half of the hijackthis log.C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\dirapi.dll Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\iml32.dll Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Plugin.dll Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\PluginPing.dll Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwMenu.dll Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\CBrowser.x32 Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Flash Asset.x32 Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\INetURL.x32 Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\NetFile.x32 Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\NetLingo.x32 Object is locked skipped C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Speech.x32 Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_5b0.dat Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped
We may have to uninstall SpyBot S&D abd reinstall it when we are done. But let's try one more thing to give me another look.
disable SpyBotS&D Tea timer
1) Run Spybot-S&D 2) Go to the Mode menu, and make sure "Advanced Mode" is selected 3) On the left hand side, choose Tools -> Resident 4) Uncheck "Resident TeaTimer" and OK any prompts 5) Restart your computer.
Save it to your Desktop Rt Click ->> Extract all ->> And extract it to your Desktop Additional help on extracting zip files can be found HERE Open the File Lister Folder. Rt Click FileLister.vbe ->>Select Open Then Open to confirm. As the program runs, it will appear that nothing is happening. When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.
bamajim
10376 Posts
415
0
Posted April 9th, 2008 14:00
1. Rerun Hijackthis (scan only) and place checks beside the following entries
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ALOT eMusic Toolbar - {8260C2B8-E0D1-448a-B062-33D12D468BF0} - C:\Program Files\alot\bin\alot.dll (file missing)
O4 - HKLM\..\RunServices: [Windows System] \winsys32.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis
2. Using Windows Explorer
Locate and Delete the following file
Close windows explorer ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
"The world is what you make of it"