Nill
Topic Starter
Well, first of all, a couple of months back I noticed that some programs I had installed suddenly stopped functioning properly, telling me that the file (keepass.exe, ccleaner and a few others) couldn't be found, even though they were still in their program folders when I checked. When I tried to reinstall these programs, either it would hang at 50% cpu usage with the appropriate installer.exe running as a process but nothing happening, or it would install and then refuse to start again.
I ran a malwarebytes scan (I think the program was reccomended to me on a different forum, but I understand you reccomend it too?) which detected 3 possible infections, one of which was in the 'soundmix.exe' file in system 32, and it needed me to reboot in order to delete it.
I rebooted, except a message popped up asking me what program I wanted to use to run mbam.exe (or something like that, I'm pretty sure it was a malwarebytes file) as though .exe was an unknown file type. After I cancelled that, suddenly ALL .exe files and programs I had installed threw up the same error message
I tried to repair my XP using the installation disk, but while doing so it threw up dozens of the same errors about unknown filetypes, for rundll32.exe (or something like that) and a couple of others. I then formatted the partition with XP installed on it (but not my second data partition) and reinstalled XP.
My current issue is that, after a pause of a minute or so, windows will start up but without any toolbar or desktop icons, even though explorer.exe is running as a process. I'm forced to restart explorer.exe in order to get it to run.
In addition to this, some applications, especially IE and Microsoft Word crash seemingly at random.
Do I somehow have malware that backed itself up in my data partition? Or is my two and a bit year old computer suffering hardware problems of some kind? And if it is hardware, is there any way of telling which part I need to replace?
Sorry for the long message, I just wanted to make sure I'd covered everything, and thanks in advance for any help you can give me on this.
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:08 PM, on 24/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\soundmix.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\DOCUMENTS AND SETTINGS\BILL\DESKTOP\PROCEXP.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
O1 - Hosts: 61.129.115.198 www.xldd.com
O1 - Hosts: 61.129.115.198 www.ojiang.com
O1 - Hosts: 61.129.115.198 www.shuixian.net
O1 - Hosts: 61.129.115.198 www.xlarea.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [EPSON Stylus Photo R250 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHP.EXE /F "C:\WINDOWS\TEMP\E_S111.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [EPSON Stylus Photo R250 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHP.EXE /F "C:\WINDOWS\TEMP\E_S1A6.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [soundmix] C:\WINDOWS\system32\soundmix.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\RunOnce: [Uninstall getPlus® for Adobe] "C:\DOCUME~1\Bill\LOCALS~1\Temp\nos_uninstall_Adobe.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
–
End of file - 3410 bytes