1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

im having problems with my computer

Discussion in 'Windows - Virus and spyware problems' started by static88, Jun 27, 2006.

  1. static88

    static88 Member

    Joined:
    Jun 27, 2006
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    i just have popupscomming on it all the time and it will freeze and stop working out of nowhere. also a msg comes up that says im running low on resorces alot.

    Logfile of HijackThis v1.99.1
    Scan saved at 10:37:32 PM, on 6/27/2006
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v5.50 (5.50.4134.0100)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
    C:\PROGRAM FILES\LINKSYS WIRELESS-G USB WIRELESS NETWORK MONITOR\WUSB54GV4.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
    C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
    C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSOL.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\NAVISEARCH\BIN\NLS.EXE
    C:\WINDOWS\SYSTEM\SYSMON.EXE
    C:\WINDOWS\APPLICATION DATA\TOFARERACI\SYSTVMRS.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\1150674352\EE\AOLSOFTWARE.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\PDEE2C.EXE
    C:\PROGRAM FILES\COOKIE WASHER\AOLWASHER.EXE
    C:\WINDOWS\SYSTEM\PDEE2C.EXE
    C:\PROGRAM FILES\COMMON FILES\BHAT\NTVDM.EXE
    C:\WINDOWS\APPLICATION DATA\RAAR\OBQWYQSV.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\AOL COMPANION\COMPANION.EXE
    C:\HJT\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.1987324.com?301
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.exactsearch.net/sidesearch
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {5DF85C53-C2BC-914B-CFCA-93FC2EF7E5C3} - C:\WINDOWS\SYSTEM\HWM.DLL
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: Mirar - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\SYSTEM\WINNB63.DLL
    O2 - BHO: (no name) - {F484C398-C71D-4482-8700-A9CCE5D2A0BE} - C:\WINDOWS\SYSTEM\win32hp.dll
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
    O2 - BHO: IEFW Object - {B5141620-C2B2-4D95-9F0F-134D99C87AB0} - C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\IEFWBHO.DLL (file missing)
    O2 - BHO: CIEIntegrator Object - {2178F3FB-2560-458F-BDEE-631E2FE0DFE4} - C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\WINPGI.DLL (file missing)
    O2 - BHO: (no name) - {5DF85C53-C2BC-914B-CFCA-93FC2EF7E5C3} - C:\WINDOWS\SYSTEM\HWM.DLL
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: (no name) - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
    O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSEcomR.EXE
    O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
    O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
    O4 - HKLM\..\Run: [WINIPE32] rundll32 WINIPE32.DLL,run
    O4 - HKLM\..\Run: [e3ad4e32.exe] C:\WINDOWS\SYSTEM\e3ad4e32.exe
    O4 - HKLM\..\Run: [Systems] C:\WINDOWS\SYSTEM\sysmon.exe
    O4 - HKLM\..\Run: [4a247efd.exe] C:\WINDOWS\SYSTEM\4a247efd.exe
    O4 - HKLM\..\Run: [oeuai] C:\WINDOWS\Application Data\tofareraci\systvmrs.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1150674352\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
    O4 - HKLM\..\RunServices: [WUSB54Gv4] C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
    O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE"
    O4 - HKCU\..\Run: [ccWasher] C:\Program Files\Cookie Washer\aolwasher.exe /0
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [PDEE2C] C:\WINDOWS\SYSTEM\PDEE2C.exe
    O4 - HKCU\..\Run: [e3ad4e32.exe] C:\WINDOWS\Application Data\e3ad4e32.exe
    O4 - HKCU\..\Run: [Reoe] "C:\Program Files\Common Files\bhat\ntvdm.exe" -vt yax
    O4 - HKCU\..\Run: [Miostlfx] C:\WINDOWS\Application Data\Raar\obqwyqsv.exe
    O4 - HKCU\..\Run: [4a247efd.exe] C:\WINDOWS\Application Data\4a247efd.exe
    O4 - HKCU\..\RunOnce: [PDEE2C] C:\WINDOWS\SYSTEM\PDEE2C.exe
    O4 - Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
    O4 - Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
    O10 - Hijacked Internet access by WebHancer
    O10 - Hijacked Internet access by WebHancer
    O10 - Hijacked Internet access by WebHancer
    O15 - Trusted Zone: *.p0rt2.com
    O15 - Trusted Zone: www.1987324.com
    O15 - Trusted Zone: www.softlab.name
    O15 - Trusted Zone: www.adslconnection.name
    O15 - Trusted Zone: www.sgrunt.biz
    O15 - Trusted Zone: www.xxx-content.name
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O15 - Trusted Zone: http://click.getmirar.com (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://www.mirarsearch.com (HKLM)
    O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-615111193427} - http://www.www2.p0rt2.com/files/epl95.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193429} - http://www.www2.p0rt2.com/files/_ipsec_.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193423} - http://www.www2.p0rt2.com/files/777.cab
    O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
    O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
    O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://www.softlab.name/closer/close.exe
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2405.exe
    O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\\foo.mht!http://85.255.118.42/data/on.chm::/on.exe
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
    O20 - AppInit_DLLs: INICFG32.DLL,inicfg32.dll
    O20 - Winlogon Notify: svchost5 - C:\WINDOWS\svchost5.dll
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\G4102080.DLL
     
  2. 21Q

    21Q Regular member

    Joined:
    Jun 23, 2006
    Messages:
    634
    Likes Received:
    1
    Trophy Points:
    28
    WOW, looks like a lot of infected files, there are two things you can do, (1) get mcafee (aol and comcast internet have free legal downloads).
    (2) Backup Only your most important files on a disk or floppy an do a system restore.
     
  3. static88

    static88 Member

    Joined:
    Jun 27, 2006
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    Alright how do i go about backing up my files and doing a system restore?
     
  4. 21Q

    21Q Regular member

    Joined:
    Jun 23, 2006
    Messages:
    634
    Likes Received:
    1
    Trophy Points:
    28
    If you you have a cd burner you can burn ONLY your MOST IMPORTANT files to a cd-r or cd-rw disk. If not you would have to put them a floppy disk.
    Now for system restore, When you bought your computer it should of came with reinstallation cds or a cd that simply says "system restore". Now as soon as you turn on the comp (doesn't mean let it load up all the way to desktop screen) put the cd in then turn the comp off. Turn back on and push the button that will let you choose which are to boot from (differs from comp company). The from there it should tell you what to do.

    Now if you dont have any of those cd's, I recommend trying to buy the restore cd. I wouldn't suggest getting a Windows OS installation cd from a friend because then if he used it you wouldn't be registered as having a genuine copy of windows (but thats up to you). To buy a Windows OS installation cd would cost you about 100-150 $ depending on which version of xp you buy.
     
  5. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi static88,

    Remove first via add/remove application

    Webhancer

    Please download ewido anti malware it is a free version of the program -> http://www.ewido.net/en/download/

    1. Install ewido security suite
    2. When installing, under "Additional Options" uncheck..
    * Install background guard
    * Install scan via context menu
    3. Launch ewido, there should be an icon on your desktop, double-click it.
    4. The program will now open to the main screen.
    5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
    6. You will need to update ewido to the latest definition files.
    * On the left hand side of the main screen click update.
    * Then click on Start Update.
    7. The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")

    If you are having problems with the updater, you can use this link to manually update ewido.
    ewido manual updates -> http://www.ewido.net/en/download/updates/

    Once the updates are installed do the following:


    Download Killbox to your desktop -> http://www.downloads.subratam.org/KillBox.zip
    Unzip it to your desktop.

    Run Killbox.exe
    -> Choose Delete on Reboot
    -> Click All Files option.

    Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)

    C:\WINDOWS\SYSTEM\WINIPE32.DLL
    C:\WINDOWS\SYSTEM\e3ad4e32.exe
    C:\WINDOWS\SYSTEM\sysmon.exe
    C:\WINDOWS\SYSTEM\4a247efd.exe
    C:\WINDOWS\Application Data\tofareraci\systvmrs.exe
    C:\WINDOWS\Application Data\e3ad4e32.exe
    C:\WINDOWS\Application Data\4a247efd.exe
    C:\WINDOWS\Application Data\Raar\obqwyqsv.exe
    C:\WINDOWS\SYSTEM\PDEE2C.exe
    C:\WINDOWS\svchost5.dll
    C:\WINDOWS\G4102080.DLL

    Then go back to Killbox
    -> go to File
    -> choose Paste from Clipboard
    -> Click the red-white Delete File option.
    -> Click Yes to Delete on Reboot question
    -> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
    -> Restart your computer if Killbox won't do it.

    (If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)


    Reboot your computer in SafeMode by doing the following:

    1. Restart your computer
    2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3. Instead of Windows loading as normal, a menu should appear
    4. Select the first option, to run Windows in Safe Mode.

    Launch ewido:

    * Click on scanner
    * Click on Complete System Scan and the scan will begin.
    * You will be prompted to clean the first infection.
    * Select "Perform action on all infections", then proceed.
    * Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    * Click Save report.
    * Save the report .txt file to your desktop or a location where you can find it easily.

    Close ewido security suite.

    Reboot back to normal mode

    Send a ewido report and a fresh hijack log
     
  6. static88

    static88 Member

    Joined:
    Jun 27, 2006
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    11
    i could not find that webhancer file in the add/remove programs section. And edwido only supports system with windows 2000 or higher and i have windows ME. Is there any other way you can help me?
     
  7. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi static88

    Sorry that Ewido,

    1. Download whCC_webhancer.exe to your computer.
    http://download.webhancer.com/files/whCC-webhancer.exe
    2. Double-click on whCC_webhancer.exe. By default, Customer Companion is installed to \Program Files\webHancer, usually on C:\.
    3. Read the license agreement.
    4. Click Yes.
    5. When the installation is complete, restart your computer.
    6. Once your computer has restarted, go to Start / Settings / Control Panel and double-click on the "Add/Remove Programs" icon.
    7. Select the program called "webHancer Customer Companion" and click the Add/Remove button.
    8. Once the program has been uninstalled, restart your computer.
    9. Connect with the Internet and confirm that your programs are now working properly.

    Delete webHancer folder.

    Download eScan to your desktop -> http://www.spywareinfo.dk/download/mwav.exe
    Run the file mwav.exe and unzip it to its default location, C:\Kaspersky

    1. Updating the scanner (close the eScan window if open)
    -> Go to My Computer
    -> C:\
    -> Kaspersky
    -> Run the file kavupd.exe, it starts downloading updates
    -> When downloading is finished, go to C:\Downloads
    -> Copy all the files in the Downloads folder by pressing CTRL+A and then CTRL+C
    -> Then go back to the C:\Kaspersky folder and paste the files by pressing CTRL+V
    -> Answer Yes to all when it asks about replacing files
    -> Now the scanner has been updated

    2. Scanner settings
    -> Go to folder C:\Kaspersky and run the file mwavscan.com (or mwavscan.exe)
    -> The scanner window opens
    -> Select the same settings than in this picture -> http://koti.mbnet.fi/pattaya1/eScan6.jpg
    -> When ready, press the Scan Clean button
    -> Scanning for infections begins

    3. Posting the results
    -> When the scan has finished (scan may take a quite long time), you'll need to post the findings
    -> Copy all the text in this field -> http://koti.mbnet.fi/pattaya1/eScan10.jpg
    -> Click the field, press CTRL+A, CTRL+C
    -> Then open Notepad and paste the findings into a new document by pressing CTRL+V
    -> Save the document to your desktop
    -> Post the contents of that textfile to here

    And a fresh hijack log

     

Share This Page