Author Topic: Can anyone see a problem here?  (Read 7297 times)

0 Members and 1 Guest are viewing this topic.

Adrienne81

  • Guest
Can anyone see a problem here?
« on: February 08, 2008, 07:50:27 AM »
See a few months ago I have had some major problems with my PC. It all started with a window's update..then the computer wouldn't boot. Then I had to reformat and reinstall window's over and over again. The problem got worse when i would shut the computer down, it just wouldn't boot back up. It's like it seems to dump files when I shut it down. I thought maybe it might be a virus or a trojan that I am not aware of?? I have the system info here from HJT, but I am not really too keen on finding these virus. I thought maybe you guys could help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:58 AM, on 2/8/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe
C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O13 - Gopher Prefix:
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe

--
End of file - 4722 bytes



philly12

  • Guest
Re: Can anyone see a problem here?
« Reply #1 on: February 08, 2008, 02:54:25 PM »
the good news is your HJT report looks clean, the bad news is that I don't know what could be causing u problems.  I would advise you to look for rootkits by downloading icesword 1.20 for vista from here: http://antirootkit.com/software/IceSword.htm .  Once you have it installed, click on all the left tabs one by one going down and report any of the ones that show up in red (do not try to delete or dissable them because there are some security programs that run with rootkit-type behavior such as vsdatant by zone alarm firewall's truevector).

That's about the only other thing i could think of malware wise because ur report looks clean.

Adrienne81

  • Guest
Re: Can anyone see a problem here?
« Reply #2 on: February 08, 2008, 04:09:00 PM »
Thank you so much. It's good to hear that the report is clean. Now I'm really puzzled as to what is causing this crap. But I did a report in Icesword, and to no avail..everything came up clean. Nothing was in red. Someone mentioned that they thought it might just be a corrupted hard drive. I just find it wierd that if that was the cause..then why all the sudden? especially when it's a new machine. I don't know..something just sound's weird about the whole thing.

philly12

  • Guest
Re: Can anyone see a problem here?
« Reply #3 on: February 08, 2008, 07:01:52 PM »
I'm just trying to think what may be the culprit here.  I'm just wondering, right before you started having problems did you change anything using System Mechanic Professional 7 such as fixing the registry, defragging the hard drive, or especially scan and fix the hard drive?  I am not familiar with System Mechanic Professional 7, but i'm sure it most likely has an option that checks and fixes a hard drive.  It may have actually caused harm to it by accident, but this is only an assumption.  If you didn't change anything using SMP 7 right before u started having problems then you probably have a different problem.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Can anyone see a problem here?
« Reply #4 on: February 08, 2008, 07:11:05 PM »
HI philly12 and Adrienne81

System mechanic is an anti virus program. So the problem may be a conflict between the two avs.

Spiritsongs

  • Guest
2 antivirus programs
« Reply #5 on: February 09, 2008, 08:17:36 AM »
 :)  Hi Adrienne :

      As "oldman" mentioned, ONE of your 3 "System Mechanic Professional"
     programs is an antiVIRUS program, which is "conflicting" with Avast,
     causing problems . Should definitely COMPLETELY REMOVE One of them .
     Guess which One we recommend !?

Adrienne81

  • Guest
Re: Can anyone see a problem here?
« Reply #6 on: February 10, 2008, 02:59:47 AM »
Yep as you can see, I have System Mechanic Pro isntalled..but I had a DAX error, after installing it. I Installed it after the fact that I started having these problems in a desperate attempt to solve the problem with the boot log. It doesn't work now. It's running but It doesn't seem to be working. I did use it to partition and wipe the drive with it's drive scrubber abilities. And after I installed it after this last wipe, it worked for about two boots and then started having the error. Now I am using avast, it seems to work much better with  the dreaded Vista, than anything else. And I've used it in the past. But the problems that I was having, started before I installed Mech Pro.  :D

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Can anyone see a problem here?
« Reply #7 on: February 10, 2008, 03:11:58 AM »
How long have you had this one, it would vring the total to 3

Authentium\AntiVirus