Tricksy messages [RESOLVED], Problems loading windows and opening files |
![]() ![]() |
Tricksy messages [RESOLVED], Problems loading windows and opening files |
Oct 6 2008, 09:51 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 10 OS: Windows XP |
I think I have contracted some sort of malware on my computer. When I log in to windows I keep getting a message saying that userinit.exe has failed to open and that the application needs to terminate. I then get left staring at my background for windows but with no desktop on it. I can get into Task Manager by pushing Ctrl+Alt+Del and run programs from there. Sometime when I try to run explorer.exe my desktop returns, but when I try to get into a number of files I find that userinit.exe (or sometimes rundll32.exe) has failed to open as expected and I can't gain access. If I am browsing folders on my computer I find that double clicking on folders causes a message to come up saying "ATEENTION! You have downloaded malicious software..." etc. And that downloading anti-virus protection is recommended. Whether or not I click yes or no takes me to a phoney internet site that tries to implant more viruses on my computer. I have included a hijackthis logfile below.. Can you help?!? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:36:27, on 7/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\UStorSrv.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [BM2f1c8d47] Rundll32.exe "C:\WINDOWS\system32\oekxdtek.dll",s O4 - HKLM\..\Run: [2c2fbedb] rundll32.exe "C:\WINDOWS\system32\okslvqbd.dll",b O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user') O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM') O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Risk\Images\stg_drm.ocx O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1142804080452 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142804620077 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Risk\Images\armhelper.ocx O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing) O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NT login service (ntlogin32) - Unknown owner - C:\WINDOWS\System32\libsys32.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe -- End of file - 9161 bytes |
|
|
Oct 7 2008, 11:57 AM
Post
#2
|
|
|
Global Moderator Posts: 9,544 From: Darkest Cornwall OS: Vista Ultimate |
Hi there lets see if we can get you back on your feet again
This will be in two parts. First a quick clean and then a deep search CLEAN Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. SEARCH To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link. Download OTScanit to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
Please attach the log in your next post. To attach a file, do the following:
|
|
|
Oct 9 2008, 06:32 AM
Post
#3
|
|
|
Member ![]() ![]() Posts: 10 OS: Windows XP |
OTScanIt.Txt ( 280.39K )
Number of downloads: 4
mbam_log_2008_10_09__22_55_32_.txt ( 8.41K )
Number of downloads: 4Thanks so much for taking on my case! Here are the two attachments you asked for, I hope they are helpful! cheers, Heardy |
|
|
Oct 9 2008, 01:49 PM
Post
#4
|
|
|
Global Moderator Posts: 9,544 From: Darkest Cornwall OS: Vista Ultimate |
OK now a few more to marmalise
Start OTScanit. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button. CODE [Unregister Dlls] [Registry - Non-Microsoft Only] < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks YN -> {8EA479BF-A910-4B14-8BB1-CD195871F947} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [] [Files/Folders - Created Within 30 days] NY -> aesuunyp.dll -> %SystemRoot%\System32\aesuunyp.dll NY -> atpfuuyg.dll -> %SystemRoot%\System32\atpfuuyg.dll NY -> bvghvnwi.dll -> %SystemRoot%\System32\bvghvnwi.dll NY -> hshmkvii.dll -> %SystemRoot%\System32\hshmkvii.dll NY -> ivonkrhn.ini -> %SystemRoot%\System32\ivonkrhn.ini NY -> jrvvkliv.dll -> %SystemRoot%\System32\jrvvkliv.dll NY -> jxlksmoj.dll -> %SystemRoot%\System32\jxlksmoj.dll NY -> ngvrvyuo.dll -> %SystemRoot%\System32\ngvrvyuo.dll NY -> njvhaadi.dll -> %SystemRoot%\System32\njvhaadi.dll NY -> pdproomo.dll -> %SystemRoot%\System32\pdproomo.dll NY -> rgf.dll -> %SystemRoot%\System32\rgf.dll NY -> rifxjfmk.dll -> %SystemRoot%\System32\rifxjfmk.dll NY -> sddevmgr.dll -> %SystemRoot%\System32\sddevmgr.dll NY -> wkmrhnrk.ini -> %SystemRoot%\System32\wkmrhnrk.ini [Files/Folders - Modified Within 90 days] NY -> aesuunyp.dll -> %SystemRoot%\System32\aesuunyp.dll NY -> AIRBKUtv.ini -> %SystemRoot%\System32\AIRBKUtv.ini NY -> atpfuuyg.dll -> %SystemRoot%\System32\atpfuuyg.dll NY -> bvghvnwi.dll -> %SystemRoot%\System32\bvghvnwi.dll NY -> hshmkvii.dll -> %SystemRoot%\System32\hshmkvii.dll NY -> ivonkrhn.ini -> %SystemRoot%\System32\ivonkrhn.ini NY -> jrvvkliv.dll -> %SystemRoot%\System32\jrvvkliv.dll NY -> jxlksmoj.dll -> %SystemRoot%\System32\jxlksmoj.dll NY -> ngvrvyuo.dll -> %SystemRoot%\System32\ngvrvyuo.dll NY -> njvhaadi.dll -> %SystemRoot%\System32\njvhaadi.dll NY -> nvapps.xml -> %SystemRoot%\System32\nvapps.xml NY -> pdproomo.dll -> %SystemRoot%\System32\pdproomo.dll NY -> pgagemvu.ini -> %SystemRoot%\System32\pgagemvu.ini NY -> rgf.dll -> %SystemRoot%\System32\rgf.dll NY -> rifxjfmk.dll -> %SystemRoot%\System32\rifxjfmk.dll NY -> sminvgyl.ini -> %SystemRoot%\System32\sminvgyl.ini NY -> ucsmftpq.ini -> %SystemRoot%\System32\ucsmftpq.ini [Empty Temp Folders] The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new Hijackthis log. I will review the information when it comes back in. Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer. Logs required : OTScanit report and a new Hijackthis log. Plus how is your computer now ? |
|
|
Oct 9 2008, 03:45 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 10 OS: Windows XP |
10102008_082325.txt ( 14.61K )
Number of downloads: 4
hijackthis.txt ( 10.99K )
Number of downloads: 4Here are the log files... After doing the fix and scan you suggested in your post, my computer is behaving itself much better! Beforehand it was a little erratic (sometimes windows would start properly but not always), however this time it restarted as if nothing had happened. Does this mean I might be cured?! |
|
|
Oct 9 2008, 03:52 PM
Post
#6
|
|
|
Global Moderator Posts: 9,544 From: Darkest Cornwall OS: Vista Ultimate |
In the words of the immoral Bard and subject to no further problems
Now the best part of the day ----- Your log now appears clean A good workman always cleans up after himself so...Download and run this small programme and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep We will now confirm that your hidden files are set to that, as some of the tools I use will change that
Please download JavaRa to your desktop and unzip it to its own folder
XP Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
You now have a clean restore point, to get rid of the bad ones:
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ? Keep safe |
|
|
Oct 11 2008, 11:06 AM
Post
#7
|
|
|
Global Moderator Posts: 9,544 From: Darkest Cornwall OS: Vista Ultimate |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
4 / 359 | 28th December 2007 - 10:04 AM 7seconds started - last by Excal |
|||||
![]() |
7 / 2,428 | 9th January 2008 - 10:00 AM Carle started - last by coachwife6 |
|||||
![]() |
11 / 422 | 10th April 2008 - 06:45 AM Obscure started - last by Stamper19 |
|||||
![]() |
18 / 509 | 30th September 2008 - 08:21 AM barbe4 started - last by RatHat |
|||||
|
Time is now: 2nd December 2008 - 06:59 AM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |