Hi Guys, I am in need of an expert here I think.
My system went way slow after an attack of several virusses and spyware.
I ran Mcafee, Ad Aware, and Microsoft defender.
Symptoms: harddisk seems to take 5/6 seconds before starting a new program, IE waits for like 3 seconds until it does its next 'thing'.
Here's the Hijackthis log.. thanks in advance!!! :) :)
Logfile of HijackThis v1.99.1
Scan saved at 7:22:12, on 21-3-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You have uninstalled NOD32 antivirus? It is not uninstalled completely and this may cause some slowdowns.
Do this to remove the remains of NOD32:
->Open Notepad
->Copy the following lines to it.
sc stop NOD32krn sc delete NOD32krn
Save the document to your desktop as NODRemoval.bat and FILE TYPE: All Files Then go to your desktop and run the file NODRemoval.bat and answer yes to any questions.
Hi JapK, amazing. thanks.
here's the requested log: sorry for the language, schoongemaakt means cleaned. STill getting Spywarestrike notifications through mcafee.
---------------------------------------------------------
ewido anti-malware - Scan rapport
---------------------------------------------------------
+ Gemaakt op: 10:13:15, 21-3-2006
+ Rapport samenvatting: A9CDB618
+ Scan resultaten:
C:\Documents and Settings\Comes\Cookies\comes@ivwbox[2].txt -> TrackingCookie.Ivwbox : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@com[1].txt -> TrackingCookie.Com : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@e-2dj6wjl4wiajsbo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Schoongemaakt met een backup
C:\Documents and Settings\Comes\Cookies\comes@e-2dj6wfmiamdzgdq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Schoongemaakt met een backup
C:\Program Files\SpyFalcon -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\msvcr71.dll -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\msvcp71.dll -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\blacklist.txt -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\syg.db -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\Lang -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\Lang\English.ini -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\Logs -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\Quarantine -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\uninst.exe -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\sf.ini -> Adware.SpyFalcon : Schoongemaakt met een backup
C:\Program Files\SpyFalcon\ignored.lst -> Adware.SpyFalcon : Schoongemaakt met een backup
If you deleted the smitrem folder, download it again.
Restart your computer to the safe mode.
Go to the Control Panel -> Add or remove program -> Delete SpyFalcon (if found) (if it asks you to restart the computer, DO NOT do it)
Make your hidden files visible:
->On the Tools menu in Windows Explorer, click Folder Options.
->Click the View tab.
->Under Hidden files and folders, click Show hidden files and folders.
Delete these files if found:
C:\Windows\System32\-->dxmpp.dll C:\WINDOWS\system32\-->ginuerep.dll
Delete this folder if found:
C:\Program Files\-->SpyFalcon
Go to smitrem folder and run the file RunThis.bat (follow the instructions)
Post again the C:\smitfiles.txt to here and post a new HijackThis log too.
And if Mcafee still keeps finding that SpyWareStrike.dll, post the location of the file to here.
Running from
C:\Documents and Settings\Comes\Bureaublad\smitRem
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pre-run SharedTask Export
(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com
Registry Pseudo-Format Mode (Not a valid reg file):
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"
"{C9FA1DC9-1FB3-C2A8-2F1A-DC1A33E7AF9D}"="Prestige Software"
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 820 'explorer.exe'
Starting registry repairs
Registry repairs complete
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SharedTask Export after registry fix
(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com
Registry Pseudo-Format Mode (Not a valid reg file):
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"
"{C9FA1DC9-1FB3-C2A8-2F1A-DC1A33E7AF9D}"="Prestige Software"
Running from
C:\Documents and Settings\Comes\Bureaublad\smitRem
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pre-run SharedTask Export
(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com
Registry Pseudo-Format Mode (Not a valid reg file):
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"
spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 808 'explorer.exe'
Starting registry repairs
Registry repairs complete
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SharedTask Export after registry fix
(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com
Registry Pseudo-Format Mode (Not a valid reg file):
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"
Logfile of HijackThis v1.99.1
Scan saved at 13:56:13, on 21-3-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)