Unsolved

This post is more than 5 years old

1663

December 6th, 2009 10:00

Slowing of Computer - Windows open/close during startup

Hello, I am pretty sure I have a virus in my computer.  Whenever I log in, I now see like 2-3 windows that just open and close in a second, and you can't really read what it says.  The speed of everything has been going a lot slower also, and just yesterday, I could go to google.com, but when I clicked searched, the webpage wouldn't change.  I restarted the computer and it worked, but that has never happened before.  I just downloaded BitDefender, and will probably run it soon and re-post I guess.

I don't know which files and locations or anything are infected, because this virus isn't really showing much of itself.  I have a Windows XP computer.  I have like 3-4 files on this computer, so would I need to run HJT on each and every file?  The file I am posting this log from is the OWNER account, I have 2 others the family uses.

Thank you for your help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:28 PM, on 9/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos Windows\windhcp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msgrmsn] C:\Arquivos Windows\windhcp.exe
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250294482617
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe

--
End of file - 4039 bytes

December 6th, 2009 13:00

Here is my HiJackThis Log after running BitDefender: Didn't want to delete the one before this in case you wanted to compare or anything.  Computer hasn't opened up the windows yet, but the start-up screen still takes forever to fully log in.  When you basically log in on Windows XP, the blue-screen with the display name takes a while to go away and then finally I see the desktop.

The overall speed is still slow... I don't know if this is because I downloaded BitDefender or anything, but that may be it because I think BitDefender does make things slow since it's a scanner.  But the computer speed has not returned to normal.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:37 PM, on 9/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250294482617
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe

--
End of file - 3945 bytes

December 6th, 2009 13:00

And here is the BitDefender Log:



 
BitDefender Log File      
Product: BitDefender Antivirus 2010
Version: BitDefender Antivirus Scanner
Scanning task: Deep System Scan
Log date: 9/23/2009 4:22:35 PM
Log path: C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\deep_scan\1253737355_1_01.xml
      
Scan paths:      
Path 0000: C:\
      
Scan Level:      
Scan for viruses: Yes
Scan for adware: Yes
Scan for spyware: Yes
Scan for applications: Yes
Scan for dialers: Yes
Scan for rootkits: Yes
Scan for keyloggers: Yes
      
Virus Scanning Options:      
Scan registry keys: Yes
Scan cookies: Yes
Scan boot sectors: Yes
Scan memory processes: Yes
Scan archives: Yes
Scan runtime packers: Yes
Scan e-mails: Yes
Scan all files: Yes
Heuristic Scan: Yes
Scanned extensions: not configured
Excluded extensions: not configured
      
Target Processing:      
Default first action for infected objects: Disinfect
Default second action for infected objects: None
Default first action for suspect objects : None
Default second action for suspicious objects: None
Default action for hidden objects: None
Default first action for encrypted infected objects: Disinfect
Default second action for encrypted infected objects: None
Default first action for encrypted suspicious objects: None
Default second action for encrypted suspicious objects: None
Default action for password-protected objects: Log only
      
Scan Engines Summary      
Virus signatures: 4699423
Archive plugins: 44
E-mail plugins: 6
Scan plugins: 13
System plugins: 5
Unpack plugins: 8
      
Basic      
Scanned items: 202702
Infected items: 9
Suspect items: 0 (no suspected items have been detected)
Hidden items: 29
Resolved items: 38
Unresolved items: 0 (no issues remained unresolved)
      
Advanced      
Scan time: 01:45:51
Files per second: 31
Skipped items: 20058
Password-protected items: 0
Over-compressed items: 0
Individual viruses found: 4
Scanned folders: 5390
Scanned boot sectors: 2
Scanned archives: 6770
Input-output errors: 34
Scanned processes: 49
Infected processes: 2
Scanned registry keys: 924
Infected registry keys: 1
Scanned cookies: 388
Infected cookies: 0
      
      
      
Resolved issues:               
Object Path    Threat Name    Final Status      
C:\Documents and Settings\Owner\Desktop\Stuff1\Thumbs.db    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\shoppingcart.gif    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\none.gif    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\monocss.htm    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\logo_oc.gif    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\logo_cards.gif    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\img_cvvs.jpg    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\img_checkoutflow_4.gif    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\gima0102.gif    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\a1.gif    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\usc_dorm.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\top5.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\another.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\DesktopStuff1\stanford.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\olym.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\sh6.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\rirl.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\perfect_storm.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\OC_Sway.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\obl.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\nbc2001.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\nal.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\DesktopStuff1\In.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\Fly.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\cornell_scream.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\Carolina Almonte    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\ar.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\ar2.flv    Rootkit-Hidden items:    Renamed      
C:\Documents and Settings\Owner\Desktop\Stuff1\X12-30107.exe    Rootkit-Hidden items:    Renamed      
=>HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\msgrmsn=>C:\ARQUIVOS WINDOWS\WINDHCP.EXE    Trojan.Generic.2822462    Deleted      
=>C:\Arquivos Windows\windhcp.exe [2812] (memory dump)    Trojan.Generic.2822462    Deleted      
=>C:\Arquivos Windows\windhcp.exe [2812] (disk)    Trojan.Generic.2822462    Deleted      
C:\System Volume Information\_restore{61F482F6-61DF-465D-ACD0-0B6E3BD0EEC4}\RP494\A0023763.exe    Trojan.Generic.2822462    Deleted      
C:\Documents and Settings\OWNER-HWTNV7FHFH\My Documents\Downloads\Fotos_DSC_OLY325685.JPG(2).COM    Gen:Trojan.Heur.bmKfrvxno6jG    Deleted      
C:\Documents and Settings\OWNER-HWTNV7FHFH\My Documents\Downloads\Fotos_DSC_OLY325685.JPG(3).COM    Gen:Trojan.Heur.bmKfrvxno6jG    Deleted      
C:\Documents and Settings\OWNER-HWTNV7FHFH\My Documents\Downloads\Fotos_DSC_OLY325685.JPG.COM    Gen:Trojan.Heur.bmKfrvxno6jG    Deleted      
C:\System Volume Information\_restore{61F482F6-61DF-465D-ACD0-0B6E3BD0EEC4}\RP483\A0021632.exe    Generic.Banker.Delf.5AD38A4F    Deleted      
C:\winup.exe    Trojan.Downloader.VB.WJV    Deleted      
     







December 9th, 2009 21:00

Bumping the topic, hopefully someone sees this

December 14th, 2009 19:00

Bump again, did this topic get skipped or maybe not seen by mistake?

No Events found!

Top