This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Programs shutting down [Solved]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For the last week my system has been very slow and programs are freezing or randomly shut down. I doesn't happen all the time but it is enough to make me think I have an infection of some sort. MalwareBytes found one trojan and removed it but I am still having issues. I downloaded HJT and pasted the log below. Thanks in advance for your assistance :)

__________________________________

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:46:38 PM, on 10/17/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
J:\WINDOWS\System32\smss.exe
J:\PROGRA~1\AVG\AVG2012\avgrsx.exe
J:\Program Files\AVG\AVG2012\avgcsrvx.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\Ant.com\IE add-on\AntUpdaterService.exe
J:\WINDOWS\Explorer.EXE
J:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
J:\Program Files\Dell Photo AIO Printer 966\memcard.exe
J:\WINDOWS\system32\rundll32.exe
J:\WINDOWS\System32\DLA\DLACTRLW.EXE
J:\Program Files\AVG\AVG2012\avgtray.exe
J:\WINDOWS\system32\CTHELPER.EXE
J:\WINDOWS\system32\CTXFIHLP.EXE
J:\Program Files\Common Files\Java\Java Update\jusched.exe
J:\Program Files\LogMeIn\x86\LogMeInSystray.exe
J:\WINDOWS\system32\ctfmon.exe
J:\Program Files\Messenger\msmsgs.exe
J:\WINDOWS\SYSTEM32\CTXFISPI.EXE
J:\Program Files\CyberScrub Privacy Suite\CSRiskMon.exe
J:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
J:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
J:\Program Files\AVG\AVG2012\avgwdsvc.exe
J:\WINDOWS\system32\dlcqcoms.exe
J:\Program Files\Flip Video\FlipShare\FlipShareService.exe
J:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe
J:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
J:\Program Files\AVG\AVG2012\avgnsx.exe
J:\Program Files\AVG\AVG2012\avgemcx.exe
J:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
J:\Program Files\Java\jre7\bin\jqs.exe
J:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
J:\Program Files\LogMeIn\x86\RaMaint.exe
J:\Program Files\LogMeIn\x86\LogMeIn.exe
J:\WINDOWS\system32\nvsvc32.exe
J:\WINDOWS\system32\svchost.exe
J:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
J:\Program Files\AVG\AVG2012\avgcsrvx.exe
J:\Documents and Settings\Mucko\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s%s
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - J:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DWABrowserHlprObj Class - {2709D830-B643-4e72-9A1E-701CFFFCF30C} - J:\WINDOWS\system32\dwabho.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - J:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Ant.com browser helper (video detector) - {346FDE31-DFF9-418A-90C8-BA31DC9FF2EF} - J:\Program Files\Ant.com\IE add-on\download.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - J:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - J:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - J:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - J:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Ant.com Video Downloader toolbar - {2E924F4F-67F0-4BD8-9560-49F468E843D2} - J:\Program Files\Ant.com\IE add-on\anttoolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AudioDrvEmulator] "J:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "J:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [FaxCenterServer] "J:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcqmon.exe] "J:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "J:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] J:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "J:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MediaFace Integration] J:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "J:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "J:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "J:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking9\Ereg.ini
O4 - HKLM\..\Run: [DLCQCATS] rundll32 J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "J:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DLA] J:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [AVG_TRAY] "J:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "J:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IDTSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "J:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "J:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] J:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "J:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Privacy Suite RiskMonitor] "J:\Program Files\CyberScrub Privacy Suite\Launch.exe" "J:\Program Files\CyberScrub Privacy Suite\CSRiskMon.exe"
O4 - HKCU\..\RunOnce: [Privacy Suite] "J:\Program Files\CyberScrub Privacy Suite\CSPSeraser.exe" "/R:J:\Documents and Settings\Mucko\Application Data\CyberScrub\Privacy Suite"
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://J:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - J:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: Download videos by Ant.com - {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - J:\Program Files\Ant.com\IE add-on\download.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - J:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - J:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} (IBM Lotus iNotes 8.5 Control) - https://nhxmail1.nu.com/dwa85W.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1303693490078
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - J:\Program Files\AVG\AVG2012\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - J:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - J:\WINDOWS\system32\browseui.dll
O23 - Service: Ant Toolbar updater service (AntUpdaterService) - Ant.com - J:\Program Files\Ant.com\IE add-on\AntUpdaterService.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - J:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - J:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - J:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: dlcq_device - - J:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: FlipShare Service - Unknown owner - J:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: FlipShare Server (FlipShareServer) - Unknown owner - J:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - J:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - J:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Intuit Update Service v4 (IntuitUpdateServiceV4) - Intuit Inc. - J:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - J:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - J:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - J:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - J:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - J:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - J:\WINDOWS\system32\STacSV.exe

–
End of file - 9995 bytes
Hi Sturgn68622,

I can take a look at your computer for you to see if you have any infections present. I'll need you to run the following scans for me so I can get a better idea of what's going on with your system.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS.scr will not run to completion. I tried the software from both of the links that were sent to me and neither would work. I tried several times and the last time with each I let them run for about 20 minutes and nothing. I have stopped the process and will wait for your reply before continuing. Thanks :)
Hi Sturgn68622,

Let's give this a shot.

Download DDS from here
  • Double click it to run it.
  • At the options screen, click the + sign next to "Options for dds.txt" then remove the check from the box which says "check MBR"
  • Ensure there is also a check next to "attach.txt"
  • Next, click Start. It should run and produce 2 logs for you, DDS.txt and Attach.txt
  • Save those logs and attach them in reply.
I followed your instructions to the letter. DDS will still not run to completion and does not generate any log files. It's hanging up just like my other programs are doing. What next??? :-(
I decided that insead of mucking around with this thing I'm just going to cave in and buy a new computer. This one is about a 2005 vintage machine and it is due for replacement. Thank you for your help. You can close this post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI