Unsolved
This post is more than 5 years old
145 Posts
0
1663
December 6th, 2009 10:00
Slowing of Computer - Windows open/close during startup
Hello, I am pretty sure I have a virus in my computer. Whenever I log in, I now see like 2-3 windows that just open and close in a second, and you can't really read what it says. The speed of everything has been going a lot slower also, and just yesterday, I could go to google.com, but when I clicked searched, the webpage wouldn't change. I restarted the computer and it worked, but that has never happened before. I just downloaded BitDefender, and will probably run it soon and re-post I guess.
I don't know which files and locations or anything are infected, because this virus isn't really showing much of itself. I have a Windows XP computer. I have like 3-4 files on this computer, so would I need to run HJT on each and every file? The file I am posting this log from is the OWNER account, I have 2 others the family uses.
Thank you for your help!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:28 PM, on 9/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos Windows\windhcp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msgrmsn] C:\Arquivos Windows\windhcp.exe
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250294482617
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
--
End of file - 4039 bytes


Undertaker_282
145 Posts
0
December 6th, 2009 13:00
Here is my HiJackThis Log after running BitDefender: Didn't want to delete the one before this in case you wanted to compare or anything. Computer hasn't opened up the windows yet, but the start-up screen still takes forever to fully log in. When you basically log in on Windows XP, the blue-screen with the display name takes a while to go away and then finally I see the desktop.
The overall speed is still slow... I don't know if this is because I downloaded BitDefender or anything, but that may be it because I think BitDefender does make things slow since it's a scanner. But the computer speed has not returned to normal.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:37 PM, on 9/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250294482617
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
--
End of file - 3945 bytes
Undertaker_282
145 Posts
0
December 6th, 2009 13:00
And here is the BitDefender Log:
BitDefender Log File
Product: BitDefender Antivirus 2010
Version: BitDefender Antivirus Scanner
Scanning task: Deep System Scan
Log date: 9/23/2009 4:22:35 PM
Log path: C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\deep_scan\1253737355_1_01.xml
Scan paths:
Path 0000: C:\
Scan Level:
Scan for viruses: Yes
Scan for adware: Yes
Scan for spyware: Yes
Scan for applications: Yes
Scan for dialers: Yes
Scan for rootkits: Yes
Scan for keyloggers: Yes
Virus Scanning Options:
Scan registry keys: Yes
Scan cookies: Yes
Scan boot sectors: Yes
Scan memory processes: Yes
Scan archives: Yes
Scan runtime packers: Yes
Scan e-mails: Yes
Scan all files: Yes
Heuristic Scan: Yes
Scanned extensions: not configured
Excluded extensions: not configured
Target Processing:
Default first action for infected objects: Disinfect
Default second action for infected objects: None
Default first action for suspect objects : None
Default second action for suspicious objects: None
Default action for hidden objects: None
Default first action for encrypted infected objects: Disinfect
Default second action for encrypted infected objects: None
Default first action for encrypted suspicious objects: None
Default second action for encrypted suspicious objects: None
Default action for password-protected objects: Log only
Scan Engines Summary
Virus signatures: 4699423
Archive plugins: 44
E-mail plugins: 6
Scan plugins: 13
System plugins: 5
Unpack plugins: 8
Basic
Scanned items: 202702
Infected items: 9
Suspect items: 0 (no suspected items have been detected)
Hidden items: 29
Resolved items: 38
Unresolved items: 0 (no issues remained unresolved)
Advanced
Scan time: 01:45:51
Files per second: 31
Skipped items: 20058
Password-protected items: 0
Over-compressed items: 0
Individual viruses found: 4
Scanned folders: 5390
Scanned boot sectors: 2
Scanned archives: 6770
Input-output errors: 34
Scanned processes: 49
Infected processes: 2
Scanned registry keys: 924
Infected registry keys: 1
Scanned cookies: 388
Infected cookies: 0
Resolved issues:
Object Path Threat Name Final Status
C:\Documents and Settings\Owner\Desktop\Stuff1\Thumbs.db Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\shoppingcart.gif Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\none.gif Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\monocss.htm Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\logo_oc.gif Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\logo_cards.gif Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\img_cvvs.jpg Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\img_checkoutflow_4.gif Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\gima0102.gif Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\a1.gif Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\usc_dorm.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\top5.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\another.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\DesktopStuff1\stanford.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\olym.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\sh6.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\rirl.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\perfect_storm.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\OC_Sway.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\obl.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\nbc2001.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\nal.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\DesktopStuff1\In.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\Fly.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\cornell_scream.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\Carolina Almonte Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\ar.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\ar2.flv Rootkit-Hidden items: Renamed
C:\Documents and Settings\Owner\Desktop\Stuff1\X12-30107.exe Rootkit-Hidden items: Renamed
=>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\msgrmsn=>C:\ARQUIVOS WINDOWS\WINDHCP.EXE Trojan.Generic.2822462 Deleted
=>C:\Arquivos Windows\windhcp.exe [2812] (memory dump) Trojan.Generic.2822462 Deleted
=>C:\Arquivos Windows\windhcp.exe [2812] (disk) Trojan.Generic.2822462 Deleted
C:\System Volume Information\_restore{61F482F6-61DF-465D-ACD0-0B6E3BD0EEC4}\RP494\A0023763.exe Trojan.Generic.2822462 Deleted
C:\Documents and Settings\OWNER-HWTNV7FHFH\My Documents\Downloads\Fotos_DSC_OLY325685.JPG(2).COM Gen:Trojan.Heur.bmKfrvxno6jG Deleted
C:\Documents and Settings\OWNER-HWTNV7FHFH\My Documents\Downloads\Fotos_DSC_OLY325685.JPG(3).COM Gen:Trojan.Heur.bmKfrvxno6jG Deleted
C:\Documents and Settings\OWNER-HWTNV7FHFH\My Documents\Downloads\Fotos_DSC_OLY325685.JPG.COM Gen:Trojan.Heur.bmKfrvxno6jG Deleted
C:\System Volume Information\_restore{61F482F6-61DF-465D-ACD0-0B6E3BD0EEC4}\RP483\A0021632.exe Generic.Banker.Delf.5AD38A4F Deleted
C:\winup.exe Trojan.Downloader.VB.WJV Deleted
Undertaker_282
145 Posts
0
December 9th, 2009 21:00
Bumping the topic, hopefully someone sees this
Undertaker_282
145 Posts
0
December 14th, 2009 19:00
Bump again, did this topic get skipped or maybe not seen by mistake?