Computing.Net > Forums > Security and Virus > I think I may have a virus.

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

I think I may have a virus.

Reply to Message Icon

Name: oldpaddy
Date: April 30, 2003 at 10:47:54 Pacific
OS: WinME
CPU/Ram: P4 1.7 (O/C to 2.10) Cor
Comment:

I recently installed kazaa since then I've lost at least one icon and my vid games are slower. I have closed all programs by using ctrl+alt+del (except systray and explorer) then starting my game and it still is slow. I've also tried disengaging the startup progams using msconfig. No luck. So I finally updated my norton and tried scanning my pc. Each time it hasn't finished, I've gotten the blue screen of death 3 times, and an win error once. I also tried mcafee online scan and got the blue screen twice, I tried panda and it keeps saying "error installing panda active scan". So what do I do? I'm getting a little frustrated. Any help would be extremely apreciated.



Sponsored Link
Ads by Google

Response Number 1
Name: Tom41
Date: April 30, 2003 at 11:25:15 Pacific
Reply:

Let's have a look, Go here and download and unzip StartupList:

StartupList

Then go back to msconfig/startup and re-check everything you unchecked and reboot.
After rebooting, run StartupList. It will create a log file, copy the log and paste it in a reply.


0

Response Number 2
Name: oldpaddy
Date: April 30, 2003 at 11:42:19 Pacific
Reply:

StartupList report, 4/30/2003, 2:41:54 PM
StartupList version: 1.52
Started from : C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\BW50PMES\STARTUPLIST1521[1]\STARTUPLIST.exe
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v5.50 (5.50.4134.0100)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\PROGRAM FILES\AMERICA ONLINE 7.0\WAOL.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\PROGRAM FILES\GO!ZILLA\GOZILLA.exe
C:\WINDOWS\RUNDLL32.exe
C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\BW50PMES\STARTUPLIST1521[1]\STARTUPLIST.exe

---------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

[Setup]
Registrando Panda ActiveScan = C:\WINDOWS\SYSTEM\regsvr32.exe /s C:\WINDOWS\SYSTEM\ActiveScan\as.dll
Registrando Panda Almacen = C:\WINDOWS\SYSTEM\regsvr32.exe /s C:\WINDOWS\SYSTEM\ActiveScan\pavpz.dll

---------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 29/4/2003, 18:46:50)

[Rename]
NUL=C:\PROGRA~1\NORTON~1\CUSTACT.exe

---------------------

C:\AUTOEXEC.BAT listing:

SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

---------------------

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

---------------------


Enumerating Browser Helper Objects:

(no name) - C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL - {CD4C3CF0-4B15-11D1-ABED-709549C10000}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

---------------------

Enumerating Task Scheduler jobs:

Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Symantec NetDetect.job

---------------------

Enumerating Download Program Files:

[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37702.5816087963

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[MaxisSimCity4PatcherX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\MAXISS~1.OCX
CODEBASE = http://simcity.ea.com/patch/MaxisSimCity4PatcherX.cab

[EARTPatchX Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\EARTPX.DLL
CODEBASE = http://simcity.ea.com/patch/EARTPX.cab

[Hotmail Attachments Control]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\HMATCHMT.OCX
CODEBASE = http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocx

[McFreeScan Class]
InProcServer32 = C:\WINDOWS\MCAFEE.COM\FREESCAN\MCFSCAN.DLL
CODEBASE = http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4259/mcfscan.cab

[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\ASINST.DLL
CODEBASE = http://www.pandasoftware.com/activescan/as/asinst.cab

---------------------

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
UPnPMonitor: C:\WINDOWS\SYSTEM\UPNPUI.DLL
AUHook: C:\WINDOWS\SYSTEM\AUHOOK.DLL

---------------------


0

Response Number 3
Name: Tom41
Date: April 30, 2003 at 11:57:51 Pacific
Reply:

Did you re-check the items in msconfig and reboot before running StartupList? If not, please do.


0

Response Number 4
Name: GoingCrazyGal
Date: April 30, 2003 at 12:11:48 Pacific
Reply:

Did you run a scan with Spybot?
Try doing that and see what happens. Also did you install Kazaa or KazaaLite? If you must have Kazaa, d/l KazaaLite


0

Response Number 5
Name: oldpaddy
Date: April 30, 2003 at 12:12:23 Pacific
Reply:

StartupList report, 4/30/2003, 3:12:48 PM
StartupList version: 1.52
Started from : C:\WINDOWS\TEMP\TD_0001.DIR\STARTUPLIST.exe
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v5.50 (5.50.4134.0100)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\TV VIEWER\TVWAKEUP.exe
C:\WINDOWS\SYSTEM\SSDPSRV.exe
C:\PROGRAM FILES\TV VIEWER\ANNCLIST.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\PCTVOICE.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\CPUIDLE\CPUIDLE.exe
C:\WINDOWS\RUNDLL32.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\PROGRAM FILES\WINBOND\HARDWARE DOCTOR\HWDOCTOR.exe
C:\WINDOWS\RUNDLL32.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\PROGRAM FILES\LOGITECH\WINGMAN SOFTWARE\LWEMON.exe
C:\PROGRAM FILES\AMERICA ONLINE 7.0\WAOL.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\WINDOWS\TEMP\TD_0001.DIR\STARTUPLIST.exe

---------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
Hardware Doctor.lnk = C:\Program Files\winbond\Hardware Doctor\Hwdoctor.exe
America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
NvCplDaemon = RUNDLL32.exe C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
PCTVOICE = pctvoice.exe
NAV Agent = C:\PROGRA~1\NORTON~1\NAVAPW32.exe
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
SystemTray = SysTray.exe
CountrySelection = pctptt.exe
CpuIdle = C:\PROGRAM FILES\CPUIDLE\CPUIDLE.exe

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
TVWakeup = C:\Progra~1\TVView~1\tvwakeup.exe
SSDPSRV = C:\WINDOWS\SYSTEM\ssdpsrv.exe
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
VidSvr =
Announcements = C:\Program Files\TV Viewer\annclist.exe
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
SchedulingAgent = mstask.exe

---------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

NVIEW = rundll32.exe nview.dll,nViewLoadHook
NvMediaCenter = RUNDLL32.exe C:\WINDOWS\SYSTEM\NVMCTRAY.DLL,NvTaskbarInit
Start WingMan Profiler = "C:\Program Files\Logitech\WingMan Software\lwtest.exe" /detect /quiet /launch "C:\Program Files\Logitech\WingMan Software\lwemon.exe /noui"

---------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 29/4/2003, 18:46:50)

[Rename]
NUL=C:\PROGRA~1\NORTON~1\CUSTACT.exe

---------------------

C:\AUTOEXEC.BAT listing:

SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

---------------------

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

---------------------


Enumerating Browser Helper Objects:

(no name) - C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL - {CD4C3CF0-4B15-11D1-ABED-709549C10000}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

---------------------

Enumerating Task Scheduler jobs:

Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Symantec NetDetect.job

---------------------

Enumerating Download Program Files:

[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37702.5816087963

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[MaxisSimCity4PatcherX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\MAXISS~1.OCX
CODEBASE = http://simcity.ea.com/patch/MaxisSimCity4PatcherX.cab

[EARTPatchX Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\EARTPX.DLL
CODEBASE = http://simcity.ea.com/patch/EARTPX.cab

[Hotmail Attachments Control]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\HMATCHMT.OCX
CODEBASE = http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocx

[McFreeScan Class]
InProcServer32 = C:\WINDOWS\MCAFEE.COM\FREESCAN\MCFSCAN.DLL
CODEBASE = http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4259/mcfscan.cab

[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\ASINST.DLL
CODEBASE = http://www.pandasoftware.com/activescan/as/asinst.cab

---------------------



0

Related Posts

See More



Response Number 6
Name: Tom41
Date: May 1, 2003 at 01:51:20 Pacific
Reply:

There is no sign of a virus.
Click Start > Run > type sysedit and click OK
What is listed on the Shell= line of the system.ini file?
What is listed on the load= and run= lines of the win.ini?


0

Response Number 7
Name: Mike007
Date: May 1, 2003 at 02:50:28 Pacific
Reply:

I hate those 'real' viruses that dont show up as a task and infect EXE files and do not need to have a startup entry as they infect exes and when you run the exe is ran it also runs the virus - so that list she posted does not mean theres no virus - it means theres no basic VB virus that some guy made in his basement, there could be exe infectors or anything


0

Response Number 8
Name: oldpaddy
Date: May 1, 2003 at 06:36:40 Pacific
Reply:

shell=Explorer.exe
load=
run=

I was finally able to run a full san with norton, it said I was clean. But I was unable to scan the mbr. Norton said that that had been changed, when I tried to scan it it would give me the win errors. Also what is rundll32? I seem to have at least two running at once now (ctrl+alt+del). When I tried to close them out out I get errors on everything listed in ctrl+alt+del. I finnaly have to manually turn off my machine. This is REALLY starting to bug me. All I wanted to do was play some baseball. :(
Anyways Thanks for all the help people.


0

Response Number 9
Name: Tom41
Date: May 1, 2003 at 06:51:59 Pacific
Reply:

Open msconfig/startup and uncheck both
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme entries.
Also Control Panel > Power Management.
Set to 'Always On' and the rest to never.

You can also uncheck the other startup entries that are not needed. Do not uncheck these though:

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
SystemTray = SysTray.exe
*StateMgr =
C:\WINDOWS\System\Restore\StateMgr.exe


0

Response Number 10
Name: Abnormal
Date: May 1, 2003 at 12:51:54 Pacific
Reply:

Uncheck this also;
SSDPSRV = C:\WINDOWS\SYSTEM\ssdpsrv.exe

Helpful tweaks from Trev.
http://www.burzurq.com/forum/trevtweak.html


0

Response Number 11
Name: oldpaddy
Date: May 1, 2003 at 16:25:19 Pacific
Reply:

OK I'm an idiot. I found out why my games were slowing down. I must have changed my vid card settings around the same time that I installed kazaa, I reset the settings. But I'm still having problems... I tried what you recommended tom41, thanks. Anyway now after I'm playing mvp baseball 2003 for a while it crashes with a ddhelp error. I didn't have these problems before (nevermind the performance problems, which I fixed [it's not overheating my temps are fine]). This system is about 3-4 months old. Like I said before these problems have happend since I installed kazaa (win errors, crashes, and lockups). Unfortunetly I can't uninstall kazaa since I deleted the addon progs that came with it. IS this a virus?! Norton says no, but I can't figure it out. I really don't want to wipe out my h/d, it's such a pain in the ass to reinstall everything. Once again thanks for all the help, I really apreciate it.


0

Response Number 12
Name: Abnormal
Date: May 1, 2003 at 17:01:33 Pacific
Reply:

Try Kazaabegone from Merijn, for your
Kazaa problem.
http://www.spywareinfo.com/~merijn/

Hijack this, at same link to remove this
C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL - {CD4C3CF0-4B15-11D1-ABED-709549C10000}

Good luck


0

Response Number 13
Name: oldpaddy
Date: May 1, 2003 at 18:37:29 Pacific
Reply:

Thanks. I was wondering if Abnormal or Tom41 could email me. I've got a question that maybe you guy's could help me with. My email is oldpaddy@hotmail.com


0

Response Number 14
Name: Abnormal
Date: May 2, 2003 at 12:27:12 Pacific
Reply:

Sorry, no e-mail to people I don't know.

I delete all mail, except for the three
friends in adress book.

Start another post with your question,
others here like to help too.

I don't trust anyone, better safe than sorry.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: I think I may have a virus.

I Must have a virus or do I/? www.computing.net/answers/security/i-must-have-a-virus-or-do-i/6089.html

I think I have a virus in my OS www.computing.net/answers/security/i-think-i-have-a-virus-in-my-os-/21992.html

do i have a virus? www.computing.net/answers/security/do-i-have-a-virus/692.html