Options

Greetings all, please help me out if you can.

Alrighty...i have a myriad of viruses on my computer...i think. Not totally sure on that one but i cant think of anything that would be causing it to be slow and crap. So umm...here are the ones i can think of at the moment.

MSN takes up almost 100% of CPU usage. This was earlier today though it seems fine at the moment.

When i open My Computer it takes forever to show A: (floppy drive), C: and D: (local drives), E: and F: (DVD drives) and then the various other folders. When opened it is blank for a while, then shows the flashlight for atleast 1-2minutes, ive done defrags and spy scans and all sorts of stuff.

uhh, there is others, but they are probably my biggest concerns at the moment, especially the my computer one, if i can fix that i might format one drive and reinstall windows, all the ways ive tried to fix this computer have left windows xp worse off than before :P

this is the hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 9:40:09 PM, on 10/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Mozilla Firefox\firefox.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Documents and Settings\Trent\My Documents\Downloads\hijackthis_199\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\qhqftusg.dll",forkonce
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://pharojebus.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165388952727
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/cnma/default/ct.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{56024F34-2A52-4D21-81E7-4CE8D54E62AC}: NameServer = 203.0.178.191
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\msvcrtd.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

Comments

  • edited July 2007
    Hi DakarRally I'm checking your log, so please be patient.
  • edited July 2007
    Hi DakarRally
    Welcome to Icrontic Malware Removal Forum.
    My name is peku006 and I will be assisting you.

    Looking over your log, it seems you don't have any evidence of an anti-virus software.
    Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

    1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
    2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
    3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.
    It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

    You aren't running Firewall Software. Please download and install one of them first!
    Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. If you use the Windows Firewall you might think that's sufficient but it only controls one way of the traffic (inbound/outbound not sure). Simply using a Firewall in its default configuration can lower your risk greatly. Here are some firewalls which are free for personal use and most used:
    Comodo
    Kerio
    ZoneAlarm
    As you did this, we can begin with the fix.


    Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible.
    Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

    Step 1: Rename HijackThis
    There is probably an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
    Please rename hijackthis.exe to scanner.exe
    Right-click on HijackThis.exe & select Rename to scanner.exe

    Step 2: Remove bad HijackThis entries
    • Run HijackThis
    • Click on the Scan button
    • Put a check beside all of the items listed below (if present):

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\qhqftusg.dll",forkonce
      O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\msvcrtd.exe
    • Close all open windows and browsers/email, etc...
    • Click on the "Fix Checked" button
    • When completed, close the application.
    Step 3:Download and Run SDFix
    Download SDFix and save it to your Desktop.
    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)
    Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard ready for posting back on the forum).
    • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
    Step 4: Download and Run: VundoFix
    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to run it.
    • Click the Scan for Vundo button.
    • Once it's done scanning, click the Remove Vundo button.
    • You will receive a prompt asking if you want to remove the files, click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will reboot your computer, click OK.
    • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
    Finally, please post a new HijackThislog , SDFix.Report.txt and VundoFix.txt
  • edited July 2007
    Hey, thanks for such a quick response. I have Ad-aware SE Personal, Easycleaner, a-squared free and Spybot SD, do you still recommend one of the aformentioned anti-virus programs?
    Also thanks for the tip about windows firewall, i have it running but didnt realise it was only a one way thing, ill download another firewall once i fix my computer.

    Ok so, this is being typed from another computer because i cant currently access the internet on my computer. It has been dodgy for a while, there is no connect to link thingy in the start menu, so you have to open a program such as msn or firefox and hope that it asks you to connect to the internet. I ran hijackthis and SDFix no problems, VundoFix however seems to have made my computer crap itself. I am constantly getting the little pop-up about C:\WINDOWS\system32 being corrupt and unreadable and that i should run the chkdsk utility but when i run that it wont complete step 2 (index checking) it says there is an unspecified error and then just stops and the computer continues to boot and then harrass me with more popups about system32. So yeah ive attached the report from SDFix and VundoFix and made a new report of hijackthis once i had run those two programs, hope you can help me out, i really want my computer back.
  • edited July 2007
    Hi DakarRally
    Good Work
    do you still recommend one of the aformentioned anti-virus programs
    YES
    Just like a Firewall is important for blocking malicious and unnecessary traffic, an Anti-Virus program is important for detecting and removing Viruses, Trojans and Worms.

    Please do the following...

    Step 1: Remove bad HijackThis entries
    • Run HijackThis
    • Click on the Scan button
    • Put a check beside all of the items listed below (if present):
      O2 - BHO: (no name) - {6D05CA72-3239-4AFE-ADA3-42BFDCABD7D3} - C:\WINDOWS\system32\jkkji.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {890CFBF0-10D5-43D3-ABFD-206F7C4A2699} - (no file)
      O20 - Winlogon Notify: jkkji - C:\WINDOWS\system32\jkkji.dll
    • Close all open windows and browsers/email, etc...
    • Click on the "Fix Checked" button
    • When completed, close the application.
    Step 2: Download and Run ComboFix
    1. Download combofix from one of these links:
    Link1
    Link2
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you. Post that log in your next reply
    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    Finally, please post a new HijackThislog and Combofix.txt
  • edited July 2007
    ahhh!!! it ran the ComboFix thing fine and then reset itself like i assume its meant to. But now its really crapped itself. I cant startup, it wants to run the chkdsk utility to fix the whole "C:\WINDOWS\system32 is corrupt" thingy. So i does that but again returns the unspecified error at the second step. So then it restarts and comes up with a screen telling me windows didnt start right and gives me the options to start it in safe mode and such, but safe mode doesnt start up, it shows all these files up until one that i think was called mug or something similar...but i have a usb issue that is stopping my keyboard working so i cant even select safe mode to check that file (the usb issue is unrelated to what we have done so far, it has been playing up for a while now.) The computer isnt even saying no keyboard present when it starts up, even though i unplugged it. I've been meaning to get some new usb's so ill probably do that, but im hoping you can figure out why it wont start up at all?
  • edited July 2007
    Hi DakarRally
    Have you tried to use the last known good configuration?
    Just before the Windows booting screen comes up, press F8.
    This should bring up a menu, where you can select to boot the last known good configuration.
  • edited July 2007
    Yeah i tried that once but nothing happened, and yeah, as i said, now i cant do anything at all cause the USB's wont pick up my keyboard...(i have atleast 6 and i have tried them all). So yeah...if you know anything that might be wrecking my USB's that would be nice, otherwise i might just go and grab some new ones and see if that solves it.
  • edited July 2007
    Hi DakarRally

    You may need to change the boot order in the system BIOS so the CD boots before the hard drive. Check your system documentation for steps to access the BIOS and change the boot order.

    1. Boot your computer using the Windows XP CD.
    2. When prompted press Enter to install Windows XP.
    3. After pressing F8 to accept the End-Use License Agreement, setup should detect your existing Windows installation.
    4. Press R to begin the recovery process.
    5. Setup will copy the necessary files to your hard drive and then reboot.
    6. Do not press any key to boot from the CD-ROM this time. Instead let setup continue.

    A Repair Install will replace the system files with the files on the XP CD used for the Repair Install. It will leave your applications and settings intact, but Windows updates will need to be reapplied.
    A Repair Install will replace files altered by adware and malware, but will not fix an adware, malware problem
  • edited July 2007
    Ok, so i managed to get windows going again, i disconnected c drive (the problematic drive) and installed windows on d drive, then changed to the boot order in BIOS so that d drive booted first, it seems to be working fine, have to download and install a lot of stuff again, but yeah, atleast it is working. A lot of the files in c drive seem to have gone missing, i was thinking of using the recovermyfiles application to see what i can get back, but was wondering if you had any suggestions?

    Thanks for all the help, i think it was too stuffed for anyone to fix.
    Trent
  • edited July 2007
    Hi DakarRally
    I am not sure.......try Recover My Files (which is free)
  • edited July 2007

    Glad I could be of assistance! The help you received here was free. Please read through some of these Prevention Tips that Short-Media offers.

    This topic is now closed. If you wish it reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

    Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.

    If you are not the user who started this thread, you must start a new Thread instead :)

    Would you also be interested to join Short-Media (Team #93) with the Folding@Home Project? More information available here
Sign In or Register to comment.