Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer Slower


  • Please log in to reply
3 replies to this topic

#1 TheComputerNoob

TheComputerNoob

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:11:30 AM

Posted 20 August 2007 - 07:37 PM

Well, my computer seems like it's getting slower. I have an theory that "svshost.exe" is causing the problem. My firewall shows two processes of "svshost.exe" causing a high CPU usage.

But there may be others I have, I am not sure.

LOG :::

Logfile of HijackThis v1.99.1
Scan saved at 7:34:03 PM, on 8/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\svshost.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svshost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: g5iuo8nzhul fxxrybzh - Unknown owner - C:\WINDOWS\system32\svshost.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: opj8lnt0biiru - Unknown owner - C:\WINDOWS\system32\svshost.exe

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:30 PM

Posted 21 August 2007 - 03:21 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum TheComputerNoob :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Download KillBox,unzip/extract it to your desktop.
http://download.bleepingcomputer.com/spyware/KillBox.exe
Start up Killbox and place a check in 'Delete on Reboot'.
In the 'Full path of file to delete' box,copy and paste:
C:\WINDOWS\system32\svshost.exe
Then press the red button with the white cross.
It will then provide a window for you to confirm the delete.
Next it will ask if you now wish to reboot,select YES.
Allow it to reboot.
If it does'nt reboot automatically,reboot manually.

Copy and paste the following bold blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.bat to your desktop.
Then double click on the fix.bat file on your desktopPosted Image
You'll see a black screen flash,thats normal.

@echo off
sc stop g5iuo8nzhul fxxrybzh
sc stop opj8lnt0biiru
sc delete opj8lnt0biiru
sc delete g5iuo8nzhul fxxrybzh

Restart your pc.

Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 TheComputerNoob

TheComputerNoob
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:11:30 AM

Posted 22 August 2007 - 04:12 PM

I cannot run KillBox because it says " Component MSCOMCTL.OCX or one of its dependencies not correctly registered: a file is missing or invalid.

EDIT:: I got that fixed


ComboFix Log ::

ComboFix 07-08-23.2 - "Admin" 2007-08-22 16:30:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.18 [GMT -7:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup


((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 )))))))))))))))))))))))))))))))


2007-08-22 16:29 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-22 16:16 <DIR> d-------- C:\!KillBox
2007-08-20 20:14 504,320 --a------ C:\WINDOWS\system32\logonui.exe
2007-08-20 20:13 219,648 --a------ C:\WINDOWS\system32\logon.scr
2007-08-20 17:15 35,980 --a------ C:\dmgr.exe
2007-08-20 15:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-20 15:23 <DIR> d-------- C:\WINDOWS\CSC
2007-08-19 21:41 66,821 --a------ C:\WINDOWS\system32\eraseme_28484.exe
2007-08-19 01:23 <DIR> d-------- C:\DOCUME~1\Admin\APPLIC~1\Sandbox
2007-08-19 01:21 <DIR> d-------- C:\Program Files\Sandboxie
2007-08-17 22:18 0 --a------ C:\WINDOWS\system32\fsb.exe
2007-08-17 21:46 <DIR> d-------- C:\Program Files\DivX
2007-08-17 17:13 2,811 --a------ C:\WINDOWS\system32\rounders.dat
2007-08-17 12:36 98,304 --a------ C:\WINDOWS\system32\wmpshell.dll
2007-08-17 12:36 7,680 --a------ C:\WINDOWS\system32\asferror.dll
2007-08-17 12:36 225,280 --a------ C:\WINDOWS\system32\wmpdxm.dll
2007-08-17 12:36 208,896 --a------ C:\WINDOWS\system32\wmpns.dll
2007-08-17 12:36 2,940,928 --a------ C:\WINDOWS\system32\wmploc.dll
2007-08-17 12:36 167,936 --a------ C:\WINDOWS\system32\wmerror.dll
2007-08-17 12:36 106,496 --a------ C:\WINDOWS\system32\wmpasf.dll
2007-08-17 12:35 997,888 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2007-08-17 12:35 981,504 --a------ C:\WINDOWS\system32\wmnetmgr.dll
2007-08-17 12:35 892,416 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2007-08-17 12:35 816,264 --a------ C:\WINDOWS\system32\wmvdmod.dll
2007-08-17 12:35 81,408 --a------ C:\WINDOWS\system32\logagent.exe
2007-08-17 12:35 760,968 --a------ C:\WINDOWS\system32\wmsdmod.dll
2007-08-17 12:35 670,208 --a------ C:\WINDOWS\system32\wmadmoe.dll
2007-08-17 12:35 6,656 --a------ C:\WINDOWS\system32\laprxy.dll
2007-08-17 12:35 52,224 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2007-08-17 12:35 486,536 --a------ C:\WINDOWS\system32\wmspdmod.dll
2007-08-17 12:35 384,512 --a------ C:\WINDOWS\system32\mp4sdmod.dll
2007-08-17 12:35 358,912 --a------ C:\WINDOWS\system32\msscp.dll
2007-08-17 12:35 316,040 --a------ C:\WINDOWS\system32\mp43dmod.dll
2007-08-17 12:35 27,136 --a------ C:\WINDOWS\system32\wmdmlog.dll
2007-08-17 12:35 253,952 --a------ C:\WINDOWS\system32\msnetobj.dll
2007-08-17 12:35 245,760 --a------ C:\WINDOWS\system32\mswmdm.dll
2007-08-17 12:35 241,664 --a------ C:\WINDOWS\system32\qasf.dll
2007-08-17 12:35 241,664 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2007-08-17 12:35 232,960 --a------ C:\WINDOWS\system32\blackbox.dll
2007-08-17 12:35 23,552 --a------ C:\WINDOWS\system32\wmdmps.dll
2007-08-17 12:35 201,728 --a------ C:\WINDOWS\system32\mspmsp.dll
2007-08-17 12:35 20,480 --a------ C:\WINDOWS\system32\wmpui.dll
2007-08-17 12:35 20,480 --a------ C:\WINDOWS\system32\wmpcore.dll
2007-08-17 12:35 20,480 --a------ C:\WINDOWS\system32\wmpcd.dll
2007-08-17 12:35 159,232 --a------ C:\WINDOWS\system32\CEWMDM.dll
2007-08-17 12:35 143,360 --a------ C:\WINDOWS\system32\wmidx.dll
2007-08-17 12:35 1,111,040 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2007-08-17 12:34 82,432 --a------ C:\WINDOWS\system32\drmstor.dll
2007-08-17 12:34 678,912 --a------ C:\WINDOWS\system32\drmv2clt.dll
2007-08-17 12:34 301,712 --a------ C:\WINDOWS\system32\drmclien.dll
2007-08-14 17:49 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-08-14 17:49 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-08-14 17:49 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-08-14 17:49 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-08-14 17:49 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-08-14 17:49 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-08-14 17:49 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-08-14 17:49 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-08-14 17:49 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-08-14 17:49 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-08-14 17:49 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-08-14 17:49 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2007-08-14 17:49 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-08-14 17:49 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-08-14 17:49 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-08-14 17:49 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-08-14 17:49 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-08-14 17:49 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-08-14 17:48 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-08-14 17:47 <DIR> d-------- C:\WINDOWS\RegisteredPackages
2007-08-14 17:44 83,968 --a------ C:\WINDOWS\system32\drivers\nabtsfec.sys
2007-08-14 17:44 52,096 --a------ C:\WINDOWS\system32\drivers\msdv.sys
2007-08-14 17:44 47,104 --a------ C:\WINDOWS\system32\wstdecod.dll
2007-08-14 17:44 354,816 --a------ C:\WINDOWS\system32\psisdecd.dll
2007-08-14 17:44 18,688 --a------ C:\WINDOWS\system32\drivers\wstcodec.sys
2007-08-14 17:44 16,896 --a------ C:\WINDOWS\system32\msyuv.dll
2007-08-14 17:44 16,384 --a------ C:\WINDOWS\system32\drivers\ccdecode.sys
2007-08-14 17:44 15,104 --a------ C:\WINDOWS\system32\drivers\mpe.sys
2007-08-14 17:44 14,976 --a------ C:\WINDOWS\system32\drivers\streamip.sys
2007-08-14 17:44 11,392 --a------ C:\WINDOWS\system32\drivers\bdasup.sys
2007-08-14 17:44 10,880 --a------ C:\WINDOWS\system32\drivers\slip.sys
2007-08-14 17:44 10,112 --a------ C:\WINDOWS\system32\drivers\ndisip.sys
2007-08-14 17:44 1,230,336 --a------ C:\WINDOWS\system32\msvidctl.dll
2007-08-14 17:43 98,816 --a------ C:\WINDOWS\system32\dmstyle.dll
2007-08-14 17:43 974,848 --a------ C:\WINDOWS\system32\dxdiag.exe
2007-08-14 17:43 80,896 --a------ C:\WINDOWS\system32\dpvsetup.exe
2007-08-14 17:43 8,192 --a------ C:\WINDOWS\system32\d3d8thk.dll
2007-08-14 17:43 797,184 --a------ C:\WINDOWS\system32\d3dim700.dll
2007-08-14 17:43 79,360 --a------ C:\WINDOWS\system32\dpwsockx.dll
2007-08-14 17:43 77,824 --a------ C:\WINDOWS\system32\dpmodemx.dll
2007-08-14 17:43 76,800 --a------ C:\WINDOWS\system32\dmscript.dll
2007-08-14 17:43 733,184 --a------ C:\WINDOWS\system32\qedwipes.dll
2007-08-14 17:43 723,968 --a------ C:\WINDOWS\system32\dpnet.dll
2007-08-14 17:43 7,424 --a------ C:\WINDOWS\system32\drivers\mskssrv.sys
2007-08-14 17:43 68,096 --a------ C:\WINDOWS\system32\dpnhupnp.dll
2007-08-14 17:43 66,408 --a------ C:\WINDOWS\system32\dxdllreg.exe
2007-08-14 17:43 64,512 --a------ C:\WINDOWS\system32\amstream.dll
2007-08-14 17:43 602,624 --a------ C:\WINDOWS\system32\dx7vb.dll
2007-08-14 17:43 58,368 --a------ C:\WINDOWS\system32\dmcompos.dll
2007-08-14 17:43 5,504 --a------ C:\WINDOWS\system32\drivers\mstee.sys


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-02 19:06 2706 --a------ C:\WINDOWS\pchealth\HELPCTR\PackageStore\SkuStore.bin
2007-08-02 14:55 8738 --a------ C:\WINDOWS\pchealth\HELPCTR\Config\Cntstore.bin


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-08-02 15:15]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-08-02 15:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"System Files Updater"="C:\WINDOWS\FlyakiteOSX\System Files Updater.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-07-16 14:54]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
C:\Program Files\Sandboxie\Control.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows DLL Loader]
C:\WINDOWS\System32\mlxw.exe

S3 projectx1;projectx1;\??\C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX03.500\Project X\FelipeZe.sys

*Newly Created Service* - CATCHME

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-23 16:31:51
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

C:\WINDOWS\system32\cmd.exe [280] 0xFE2D8020


scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-23 16:32:40
C:\ComboFix-quarantined-files.txt ... 2007-08-23 16:32

--- E O F ---



HiJackThis LOG :::

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:35:11 PM, on 8/23/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Ares\Ares.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX00.329\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [System Files Updater] C:\WINDOWS\FlyakiteOSX\System Files Updater.exe /S
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

--
End of file - 2825 bytes

Edited by TheComputerNoob, 22 August 2007 - 04:37 PM.


#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:30 PM

Posted 23 August 2007 - 07:58 AM

Make sure all hidden files are showing:
* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.
* Uncheck the 'Hide file extensions for known types' option.
* Uncheck the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

Copy and paste the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktopPosted Imageand agree to merge the imformation into the registry,then restart your pc.

REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows DLL Loader]

Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.

You should copy/print the following because you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE" using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)


Find and delete:
C:\WINDOWS\system32\eraseme_28484.exe

Scan with DrWeb-CureIt as follows:
* Double-click on drweb-cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
* Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
* Once the short scan has finished, Click Options > Change settings
* Choose the "Scan tab" and UNcheck "Heuristic analysis"
* Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
* Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
* When done, a message will be displayed at the bottom advising if any viruses were found.
* Click "Yes to all" if it asks if you want to cure/move the file.
* When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
(This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
* Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
* Save the DrWeb.csv report to your desktop.
* Exit Dr.Web Cureit when done.
* Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
* After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Also post a new Hijackthis log.
Let me know how your pc is running now.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users