Unsolved

This post is more than 5 years old

14 Posts

1300

January 29th, 2007 03:00

Viruses on computer (popups, computer running slow, programs not working)

I am extremely new to all this and have no clue what some of this stuff is. For example, I do not know what malware is. I am having issues with my computer. It started out as a minor annoyance about a month ago with a pop up or two here and there or my computer running slightly slower. Over time it has begun to cripple my computer and now I get tons of pop ups a day, some programs don't work, and sometimes I can only check emails but not go to websites. Please help! I am completely ignorant when it comes to fixing a problem like this on my computer. Thank you!
 
 
Logfile of HijackThis v1.99.1
Scan saved at 11:09:10 PM, on 1/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\{74D83C19-0AE9-1033-1108-040416200001}\Update.exe
C:\DOCUME~1\User\MYDOCU~1\SMANTE~1\javaw.exe
C:\Program Files\?icrosoft.NET\s?ool32.exe
C:\WINDOWS\csrss.exe
C:\Program Files\AOL 9.0\aoltray.exe
c:\program files\common files\aol\1142033861\ee\services\antiSpywareApp\ver2_0_27_1\AOLSP Scheduler.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\AOL\1142033861\ee\aolsoftware.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\common files\aol\1142033861\ee\aolsoftware.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\DOCUME~1\User\LOCALS~1\Temp\services.exe
C:\America Online 6.0\waol.exe
C:\Program Files\Hijackthis\HijackThis.exe
R3 - URLSearchHook: (no name) - {552CC461-2F80-7E0C-A1E9-05D58D21B29A} - C:\WINDOWS\system32\gxh.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {552CC461-2F80-7E0C-A1E9-05D58D21B29A} - C:\WINDOWS\system32\gxh.dll
O2 - BHO: (no name) - {B1AF6EE2-8D05-F28A-7603-F81A06CE0890} - C:\WINDOWS\system32\aiflqges.dll (file missing)
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1142033861\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [DLBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Russ] "C:\DOCUME~1\User\MYDOCU~1\SMANTE~1\javaw.exe" -vt ndrv
O4 - HKCU\..\Run: [Dqgvly] C:\Program Files\?icrosoft.NET\s?ool32.exe
O4 - HKCU\..\Run: [zrwm] C:\PROGRA~1\COMMON~1\zrwm\zrwmm.exe
O4 - HKCU\..\Run: [Kernel Fault Safe] C:\WINDOWS\smss.exe
O4 - HKCU\..\Run: [Shell explorer driver] C:\WINDOWS\csrss.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C6248388-3CC1-4967-A3CD-3E14C2C4603A}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: dlbx_device - Dell - C:\WINDOWS\system32\dlbxcoms.exe
O23 - Service:   (Network Monitor) - Unknown owner - C:\WINDOWS\.exe (file missing)
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 

14 Posts

February 7th, 2007 02:00

I followed your instructions and when notepad opened up, the following is what was on it. There was nothing else. I really hope this helps you get what you need.
 
 Volume in drive C has no label.
 Volume Serial Number is 74D8-3C19

2 Intern

 • 

5.9K Posts

February 7th, 2007 08:00

Sorry, I reversed two letters in the file name.  Please try again.
 
Ron
 
 
 
 
cd \
 
(Prompt should change to C: \ > )  Sorry I reversed two letters in the file name.  Please try again.
 
dir /a /s csrss.exe > junk.txt
 
(will take a few minutes to finish and give you back your prompt)
 
notepad junk.txt
 
exit
 
 
 

14 Posts

February 8th, 2007 01:00

Ah, this sort of response makes more sense to me now than the one I got before. Hopefully this will tell you what you need to know...... 
 
 
Volume in drive C has no label.
 Volume Serial Number is 74D8-3C19
 Directory of C:\WINDOWS\system32
08/04/2004  06:00 AM             6,144 csrss.exe
               1 File(s)          6,144 bytes
 Directory of C:\WINDOWS\system32\dllcache
08/04/2004  06:00 AM             6,144 csrss.exe
               1 File(s)          6,144 bytes
     Total Files Listed:
               2 File(s)         12,288 bytes
               0 Dir(s)  71,190,265,856 bytes free

2 Intern

 • 

5.9K Posts

February 8th, 2007 08:00

Much better.
 
Odd that we do not see the one in C:\windows that showed up in HJT.  Try going back to the command window and:
 
cd \windows
attrib -r -h -s -a csrss.exe
dir /a csrss.exe > junk.txt
notepad junk.txt
 
 
Also let's look at the test.bat file that combofix found.  Close notepad (after copying the text to a reply) and go back to the cmd window.
 
notepad \WINDOWS\test.bat
 
Copy this text to the reply too.
 
 
The ones we do see are the same exact size as the ones I have on my PC so are probably the correct ones.
 
Run the combofix one more time.  Do you see the file we just deleted? 
 
Also make a new HJT log and post it in your reply.
 
Ron


Message Edited by RKinner on 02-08-2007 04:55 AM

14 Posts

February 9th, 2007 01:00

 
This is what I got when I did the cmd window for the test.bat file:
:Repeat
del C:\21205388.exe
if exist C:\21205388.exe goto Repeat
C:\DOCUME~1\User\LOCALS~1\Temp\metasploit.exe goto Repeat
 
 
When I went to the cmd window and ran
cd \windows 
attrib -r -h -s -a csrss.exe 
it told me the file could not be found. ????? So now I am really confused. I didn't run another HJT log b/c I couldn't  get that first step done.

2 Intern

 • 

5.9K Posts

February 9th, 2007 08:00

Run Killbox.
 
In the box under "Full path of File to Delete," type the following:
 
C:\DOCUME~1\User\LOCALS~1\Temp\metasploit.exe

Then press the red button to delete the file.
Does it say it was able to delete the file?
 
Repeat for
 
C:\WINDOWS\test.bat
Then run smitfraudfix as they do here:
 
 
Don't worry that you don't have the same symptoms.  I just want you to download and run smitfraudfix like they do.
 
Post a new HJT log when done.
 
Ron

14 Posts

February 10th, 2007 03:00

Here's my latest HJT log. As for the instructions you gave me, I was able to delete the test.bat file on killbox. However, when I tried to do the other one, it didn't indicate that it was deleted. In fact, it told me the file could not be found.
 
Then when I did the smitfraudfix I followed all the steps. Once it asked me if I wanted it to clean the registry, I typed a "y" then pressed enter. Instead of it counting down to reboot the computer then it rebooting, it just automatically opened the notepad window with the log on it. I don't know if this made a difference in the outcome or not but I thought you should know about it just in case.
 
 
Logfile of HijackThis v1.99.1
Scan saved at 10:50:55 PM, on 2/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\AOL\1142033861\ee\AOLSoftware.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\AOL 9.0\aoltray.exe
c:\program files\common files\aol\1142033861\ee\services\antiSpywareApp\ver2_0_27_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1142033861\ee\aolsoftware.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\America Online 6.0\waol.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1142033861\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [DLBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Shell explorer driver] C:\WINDOWS\csrss.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{C6248388-3CC1-4967-A3CD-3E14C2C4603A}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: dlbx_device - Dell - C:\WINDOWS\system32\dlbxcoms.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 

2 Intern

 • 

5.9K Posts

February 10th, 2007 08:00

I think smitfraudfix didn't find anything worth rebooting for.
 
Go back to the cmd window and type:
 
cd \windows
 
mkdir csrss.exe
 
If the file is really not there then the mkdir (make directory) command should succeed.  You can't have a directory with the same folder as a file of the same name.
 
Then run Killbox and have it Delete on Reboot the
 
 
C:\WINDOWS\v2odt77re.dll
 
file then run a new HJT log and post it as a reply.
 
Then run combofix again and email the log to me as an attachment.
 
rkinner
AT
gmail
DOT
com
 
Subject: DELL twinzz
 
Also get Tasklist.exe from:
 
 
We want to save it to \windows\system32
 
so Press the SAVE button then where it says File Name: tasklist.exe, change it to read:
 
\windows\system32\tasklist.exe
 
 
 
Now open a CMD window as before and type:
 
tasklist /m > \junk.txt
 
 
Send that file (C:\junk.txt) to me as an attachment too.
 
Ron
 
 
 
 
 
 
 
 

14 Posts

February 15th, 2007 01:00

Hey, Ron, I just wanted to apologize for not replying to you sooner. I have had a lot going on and have not had the chance to take your last reply's instructions and carry them out. It will probably be another 2-3 days before I get the chance to sit down and do it. I just wanted to log on and let you know what was up. I am so sorry. Thanks again for all that you've done so far and for being so patient with me!
 
Andrea

2 Intern

 • 

5.9K Posts

February 15th, 2007 09:00

Don't worry about delays.  I have so many threads going at one time that I never notice.
 
Ron
No Events found!

Top