1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

extremely slow computer

Discussion in 'Malware and Virus Removal Archive' started by roundhouse459, 2005/07/23.

Thread Status:
Not open for further replies.
  1. 2005/07/23
    roundhouse459

    roundhouse459 Inactive Thread Starter

    Joined:
    2005/07/23
    Messages:
    2
    Likes Received:
    0
    I have a dirt slow computer and need help really bad. My HJT log is attached . Someone please help me!!!!!!!!!
    hLogfile of HijackThis v1.99.1
    Scan saved at 3:25:38 PM, on 7/23/2005
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v5.50 (5.50.4134.0100)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\WINDOWS\IPDV.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
    C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE
    C:\WINDOWS\DESKTOP\HIJACK\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...aults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {B483C39A-AFEB-7AB8-EF0F-3D81EE87313A} - C:\WINDOWS\SYSTEM\MFCGI32.DLL
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YCOMP5_5_7_0.DLL
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [NPROTECT] C:\PROGRA~1\NORTON~1\ADVTOOLS\NPROTECT.EXE
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe "
    O4 - HKLM\..\RunServices: [IPDV.EXE] C:\WINDOWS\IPDV.EXE /s
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
    O16 - DPF: Pirate's Gold by pogo - http://swashbucks.pogo.com/applet-6.1.2.25/piratesgold/piratesgold-ob-assets.cab
    O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.3.0.46/pinochle/pinochle-ob-assets.cab
    O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.2.1.34/canasta/canasta-ob-assets.cab
    O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.1.3.21/aces/aces-ob-assets.cab
    O16 - DPF: Dominoes by pogo - http://game1.pogo.com/applet-6.3.0.46/domino/domino-ob-assets.cab
    O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.2.1.41/spades/spades-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.1.3.21/worldclass/worldclass-ob-assets.cab
    O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.2.5.28/hearts/hearts-ob-assets.cab
    O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/applet-6.2.5.28/waterwheel/waterwheel-ob-assets.cab
    O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.2.5.28/freecell/freecell-ob-assets.cab
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.2.5.42/lottso/lottso-ob-assets.cab
    O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.2.3.39/wordjong/wordjong-ob-assets.cab
    O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.3.0.46/pool2/pool-ob-assets.cab
    O16 - DPF: Ali Baba Slots TM by pogo - http://game1.pogo.com/applet-6.1.3.28/slots/alibaba-ob-assets.cab
    O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.1.3.28/checkers2/checkers-ob-assets.cab
    O16 - DPF: Poppit TM by pogo - http://game1.pogo.com/applet-6.1.3.28/poppit/poppit-ob-assets.cab
    O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.1.4.22/popfu/popfu-ob-assets.cab
    O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.2.3.36/jumbee/jumbee-ob-assets.cab
    O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.1.4.22/euchre/euchre-ob-assets.cab
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.46/blackjack/blackjack-ob-assets.cab
    O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.2.0.30/holdem/holdem-ob-assets.cab
    O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
    O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.1.4.29/mahjong/mahjong-ob-assets.cab
    O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.1.4.29/drawpoker/drawpoker-ob-assets.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.2.2.51/squelchies/squelchies-ob-assets.cab
    O16 - DPF: Chess by pogo - http://game1.pogo.com/applet-6.1.5.21/chess2/chess2-ob-assets.cab
    O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.3.0.46/peaks/peaks-ob-assets.cab
    O16 - DPF: Video Poker by pogo - http://game1.pogo.com/applet-6.1.5.21/videopoker2/videopoker-ob-assets.cab
    O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.2.1.34/poppit2/poppit2-ob-assets.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.5.28/jigsaw/jigsaw-ob-assets.cab
    O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.2.5.42/solitaire2/solitaire2-ob-assets.cab
    O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.3.0.46/gin/gin-ob-assets.cab
    O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.com/applet-6.2.0.37/slots/showbiz-ob-assets.cab
    O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.2.1.27/spider/spider-ob-assets.cab
    O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.2.1.34/paigow/paigow-ob-assets.cab
    O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.2.5.42/slots/showbiz2-ob-assets.cab
    O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.2.5.28/checkeredflag/checkeredflag-ob-assets.cab
    O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.2.2.51/mlslots/mlslots-ob-assets.cab
    O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.2.4.32/sweettooth/sweettooth-ob-assets.cab
    O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.2.5.28/harvest/harvest-ob-assets.cab
    O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.2.2.66/backgammon/backgammon-ob-assets.cab
    O16 - DPF: SciFi Slots by pogo - http://game1.pogo.com/applet-6.2.2.66/slots/scifi-ob-assets.cab
    O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.com/applet-6.2.3.36/turbo21/turbo21-ob-assets.cab
    O16 - DPF: Cribbage by pogo - http://game1.pogo.com/applet-6.2.3.36/cribbage/cribbage-ob-assets.cab
    O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.2.3.36/flinger/flinger-ob-assets.cab
    O16 - DPF: The Sims Pinball by pogo - http://game1.pogo.com/applet-6.2.3.39/simball/simball-ob-assets.cab
    O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.2.3.39/poppazoppa/poppazoppa-ob-assets.cab
    O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.2.4.32/omaha/omaha-ob-assets.cab
    O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.2.5.28/superbingo/superbingo-ob-assets.cab. :confused:
     
  2. 2005/07/23
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    Hello, welcome to the boards. I removed your other thread.

    You have a trojan on your system, actually you may have multiple copies of it. Download Ewido, install and update it. Then close for now.
    http://www.ewido.net/en/download/
    Disable System Restore, else bad files will reappear.
    Rescan with HJT, and remove these items.
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {B483C39A-AFEB-7AB8-EF0F-3D81EE87313A} - C:\WINDOWS\SYSTEM\MFCGI32.DLL
    O4 - HKLM\..\RunServices: [IPDV.EXE] C:\WINDOWS\IPDV.EXE /s

    Then restart into Safe Mode, and copy/paste these commands into Start\Run.
    deltree C:\WINDOWS\SYSTEM\MFCGI32.DLL
    deltree C:\WINDOWS\IPDV.EXE
    Type a Y that you want to delete when prompted in the dos window that will appear.

    Then do the ewido scan, it will work in Safe Mode, and will do a better job this way.
    When done, restart into normal mode, enable System Restore. Please post a new HJT log to see if you are clean.
     

  3. to hide this advert.

  4. 2005/07/24
    roundhouse459

    roundhouse459 Inactive Thread Starter

    Joined:
    2005/07/23
    Messages:
    2
    Likes Received:
    0
    ewido download

    I tried the ewido.net download but got a message that said it was for windows 2000 and above. Whats next. I have ME edition. Thanks
     
  5. 2005/07/24
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Try The Cleaner from www.moosoft.com
     
  6. 2005/07/24
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.