Help Required

Hi, I had the winlogonpc.exe problem and I believe I got rid of it... except my computer still acts weird. It has been running slow, locking up right after startup, and not letting me delete certain things because they're being used by another program, except they aren't being used by another program.

Here's my HJT Log, can anybody help?

Logfile of HijackThis v1.99.0
Scan saved at 4:17:48 PM, on 2/16/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
C:\Program Files\AIM\aim.exe
C:\MWAV\MWAVSCAN.COM
C:\MWAV\kavss.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "hawkins"
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "hawkins"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1106435077118
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: iPod Service - Unknown - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
O23 - Service: Sandra Data Service - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exe
O23 - Service: Sandra Service - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exe

Comments

  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited February 2005
    I'm not seeing anything bad in your hijackthis log. Let's take a closer look just to be sure.
    • Download DLLCompare.
    • Double-click on DllCompare.exe to run the program.
    • Click "Run Locate.com" and it will scan your system for files.
    • Once the scan has finished click "Compare" to compare your files to valid Windows files.
    • Once it has finished comparing click "Make a Log of what was found".
    • Click "Yes" at the View Log file? prompt to view the log.
    • Copy and paste the entire log into this topic.
    • If you accidentally close out of the log it is also saved as log.txt to where you saved DllCompare.exe.
    • Click "Exit" to exit DLLCompare.
  • edited February 2005
    * DLLCompare Log version(1.0.0.127)
    Files Found that Windows does not See or cannot Access
    *Not everything listed here means you are infected!
    ________________________________________________

    O^E says: "There were no files found :)"
    ________________________________________________

    1,136 items found: 1,136 files, 0 directories.
    Total of file sizes: 205,045,059 bytes 195.54 M

    Administrator Account = True

    End log
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited February 2005
    Nothing there either. Some suggestions:

    1. You are badly behind on Windows updates. You should download and install all critical updates that are found for your computer.
    http://windowsupdate.microsoft.com/


    2. Download Adaware and Spybot and run them. Even if you are clean now, keep them and run them often, at least weekly.
    http://www.short-media.com/forum/showpost.php?p=146151&postcount=1


    3. Run an online virus scan or two, just to be extra safe.
    http://housecall.trendmicro.com/
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm



    These are general suggestions that may or may not help your problem. But they may help you rule out malware as your problem.
  • edited February 2005
    Thanks, I guess I've figured out malware isn't the problem. Well, alright, I'll figure it out. Thanks again.
This discussion has been closed.