Author Topic: Help please..think I have a virus  (Read 3222 times)

0 Members and 1 Guest are viewing this topic.

J-blaze

  • Guest
Help please..think I have a virus
« on: July 11, 2005, 01:28:31 AM »
Hey, I've been having problems with getting many of my programs to work and I think there might be a virus on my computer which is causing this. When I open games like the sims 2 or any other game that takes the whole screen to go into 3d mode, I get a message that says "This program has been damaged, possibly by a bad sector of the hard drive or a virus." or something similar to that. Even my yahoo messenger is messed up.. I tried reinstalling my windows and making a new partition, but still didn't fix these problems. Can anyone help me? Let me know whatever can help me please. Here's my highjackthis scan....

-------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 6:13:36 PM, on 7/10/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\LEXBCES.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\LEXPPS.EXE
E:\WINDOWS\System32\alg.exe
E:\WINDOWS\System32\drivers\crauto.exe
E:\WINDOWS\System32\drivers\IMountSRV.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
E:\Program Files\BearShare\BearShare.exe
E:\Program Files\QuickTime\qttask.exe
E:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe
E:\Program Files\Save\Save.exe
E:\Program Files\Spyware Doctor\swdoctor.exe
E:\Program Files\MSN Messenger\MsnMsgr.Exe
E:\Program Files\WinZip\WZQKPICK.EXE
E:\Program Files\Smart Link\IMTrans\IMTrans.exe
E:\WINDOWS\System32\mousehs.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
E:\WINDOWS\System32\wdfmgr.exe
E:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
E:\WINDOWS\System32\wuauclt.exe
E:\WINDOWS\system32\1.tmp
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\Documents and Settings\Justin\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - E:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - E:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - E:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - E:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [Encrypted Disk Auto Mount] rundll32.exe edshell.dll,MountAll
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler V1.39.12R] E:\WINDOWS\system32\1.tmp
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] E:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [BearShare] "E:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Services] E:\WINDOWS\system32\1.tmp
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler] E:\WINDOWS\system32\1.tmp
O4 - HKLM\..\Run: [msnappau] "E:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [WhenUSave] "E:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "E:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [AIM] E:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ATI Launchpad] "E:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - HKCU\..\Run: [NetZero_uoltray] E:\Program Files\NetZero\exec.exe regrun
O4 - Startup: IMTranslator.lnk = E:\Program Files\Smart Link\IMTrans\IMTrans.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinZip Quick Pick.lnk = E:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://E:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://E:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - E:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121036218397
O17 - HKLM\System\CCS\Services\Tcpip\..\{99C143DE-E8B5-4BD9-9BF4-9EC2488FA3D4}: NameServer = 205.152.144.235 205.152.132.235
O23 - Service: Adobe LM Service - Unknown owner - E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: crauto - Unknown owner - E:\WINDOWS\System32\drivers\crauto.exe
O23 - Service: IMountSRV - Unknown owner - E:\WINDOWS\System32\drivers\IMountSRV.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - E:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - E:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Mouse Hardware Sync (mousehs) - Unknown owner - E:\WINDOWS\System32\mousehs.exe
O23 - Service: PMounter - Unknown owner - E:\Paragon HDM\Ext2\PMounter.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - E:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

« Last Edit: July 11, 2005, 02:15:08 AM by J-blaze »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89294
  • No support PMs thanks
Re: Help please..think I have a virus
« Reply #1 on: July 11, 2005, 02:15:51 AM »
What do you expect, it doesn't appear that you have an anti-virus installed certainly not one that is recognised, you don't appear to have a firewall installed (unless you have a hardware router and firewall). You are playing Russian Roulette with an automatic.

1. Your OS and browser are way out of date, you need an urgent visit to the windows update site. There have been many vulnerabilities patched, not to mention many security enhancements for your OS, IE Browser and OE if you are also using that.

2. Check out this on-line analysis of your HJT log file - http://hijackthis.de/logfiles/525d7b0a29e6adf5fb69420e261ce249.html and fix the nasty entries and check the unknown (using google, etc.) and fix if required.

You need to urgently, a) install an anti-virus, b) install a firewall, c) visit windows update, d) use a different browser that is more secure and less vulnerable than IE, I suggest firefox.

If you haven't already got this software (freeware), download, install, update and run it.
1. Ad-Aware
2. Spybot Search and Destroy
3. Spywareblaster
4. Download HijackThis.zip - HiJackThis Tutorial
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

J-blaze

  • Guest
Re: Help please..think I have a virus
« Reply #2 on: July 11, 2005, 06:22:54 PM »
Thx alot I'll download those as soon as I can, already have firefox and those freeware programs for spyware I just need to install them again because i just reinstalled my windows.