Hi, my sister's laptop constantly have problems. This time there are several nasty problems, any suggestions and help will be greatly appreciated!
Here are the problems:
- games.sms591.com & sms591.net ring tone pop up: this ring tone web page always opens up an IE window from time to time.
- BitComet auto shut off: it is fine to start up. I can load up Bit Comet fine, but as soon as I click anywhere in the BitComet window, it will close itself off. Close itself off as it didn't minimized, the whole program bitcomet.exe gets shut off from the Windows Process List.
- Unable to view hidden files: every time I select view hidden files, no hidden files will be shown up at all. And as soon as I go back to the options to select view hidden files, it is always the hide hidden files option being checked.
- iedw.exe error: I have no clue what iedw.exe is. I don't even think my sister has such a program at all as she only knows how to surf (mainly Chinese news, celebrity sites). The error message says:
iedw.exe - Application Error
The applicateion failed to initialize properly (0xc0000142). Click on OK to terminate the application.
Here is what I have done:
The games.sms591.com & sms591.net ring tone pop up, I have tried the methods that are mentioned in this site:
http://blog.cersp.com/userlog19/48446/archives/2007/254282.shtml (sorry it is a Chinese site) I haev used Sreng2 and done what it said in the site. With the exception that I can't seem to find similar numeric .EXE or .DLL files that have been mentioned on the site (not sure if they are hidden or what)
For the Bit Comet, I have tried to uninstall and reinstall, but the same problem still exist. Bit Comet problem seems to happen after I installed AVG. Though, even after I removed AVG, the same problem still exits. (reinstalled to do scan)
I used Ad-aware and removed infected files that it has found (over 140).
I have also used AVG scan. Did find a lot of infected thing, I have deleted all. But it can't seem to find sms591.
Also, used Security Task Manager. I have removed a lot of weird programs, but still these seems to coming back:
Ghook.dll C:\SysAd3\Ghook.dll
Ghook.dll C:\SysAd2\Ghook.dll
svchost.exe C:\SysAd2\svchost.exe
svchost.exe C:\SysAd3\svchost.exe
Here is the screenshot that I have took. One shows up 100 rating, and the other shows 57 rating.
http://img69.imageshack.us/img69/4555/securitytaskmanagerky4.jpgI have tried to locate those files, but I can't find them. So they are probably hidden files I assume. But as I have mentioned, I can't view hidden files.
Also done a HijackThis log, this is the log:
Logfile of HijackThis v1.99.1
Scan saved at 11:05:30 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\DEC\System32\sm
ss.exe
C:\WINDOWS\DEC\system32\cs
rss.exe
C:\WINDOWS\DEC\system32\wi
nlogon.exe
C:\WINDOWS\DEC\system32\se
rvices.exe
C:\WINDOWS\DEC\system32\ls
ass.exe
C:\WINDOWS\DEC\system32\At
i2evxx.exe
C:\WINDOWS\DEC\system32\sv
chost.exe
C:\WINDOWS\DEC\system32\sv
chost.exe
C:\WINDOWS\DEC\System32\sv
chost.exe
C:\WINDOWS\DEC\system32\sv
chost.exe
C:\WINDOWS\DEC\system32\sv
chost.exe
C:\WINDOWS\DEC\system32\sp
oolsv.exe
C:\WINDOWS\DEC\system32\sv
chost.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\DEC\system32\At
i2evxx.exe
C:\WINDOWS\DEC\Explorer.EX
E
C:\WINDOWS\DEC\system32\ct
fmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\SysAd2\svchost.exe
C:\SysAd3\svchost.exe
C:\WINDOWS\DEC\system32\ws
cntfy.exe
C:\WINDOWS\DEC\System32\al
g.exe
C:\Program Files\Security Task Manager\TaskMan.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Screenshot Pilot\ScrPlt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Joey\My Documents\Min Folder\hijackthis\HijackTh
is.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5
B79BFDFEA6
0} - C:\Program Files\BitComet\tools\BitCo
metBHO_1.1
.2.7.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
164760863C
6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\DEC\system32\IM
E\TINTLGNT
\TINTSETP.
EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\DEC\system32\IM
E\TINTLGNT
\TINTSETP.
EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\DEC\IME\imjp8_
1\IMJPMIG.
EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1 ] C:\WINDOWS\DEC\ime\imkr6_1
\IMEKRMIG.
EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\DEC\system32\IM
E\PINTLGNT
\ImScInst.
exe /SYNC
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [eabconfg.cpl] ; C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [HP Software Update] ; C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] ; C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [iTunesHelper] ; "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [LogitechGalleryRepair] ; C:\Program Files\Logitech\ImageStudio
\ISStart.e
xe
O4 - HKLM\..\Run: [LogitechImageStudioTray] ; C:\Program Files\Logitech\ImageStudio
\LogiTray.
exe
O4 - HKLM\..\Run: [LogitechVideoRepair] ; C:\Program Files\Logitech\Video\ISSta
rt.exe
O4 - HKLM\..\Run: [LogitechVideoTray] ; C:\Program Files\Logitech\Video\LogiT
ray.exe
O4 - HKLM\..\Run: [LVCOMS] ; C:\Program Files\Common Files\Logitech\QCDriver3\L
VCOMS.EXE
O4 - HKLM\..\Run: [LVCOMSX] ; C:\WINDOWS\DEC\system32\LV
COMSX.EXE
O4 - HKLM\..\Run: [miniqqlive] ; "C:\Program Files\Tencent\QQLive\MiniQ
QLive.exe"
O4 - HKLM\..\Run: [nmapp] ; "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [QuickTime Task] ; "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\DEC\system32\ct
fmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.ex
e/AddLink.
htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.ex
e/AddVideo
.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.ex
e/AddAllLi
nk.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.h
tm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\m
sntabres.d
ll.mui/229
?69b62a7f5
235431bb6b
c9f218a10a
935
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\m
sntabres.d
ll.mui/230
?69b62a7f5
235431bb6b
c9f218a10a
935
O8 - Extra context menu item: 上传到QQ
网&#
32476;
828;௢
4; - C:\Program Files\Tencent\QQ\AddToNetD
isk.htm
O8 - Extra context menu item: 添加到QQ
自&#
23450;
041;༣
4;板
- C:\Program Files\Tencent\QQ\AddPanel.
htm
O8 - Extra context menu item: 添加到QQ
表&#
24773; - C:\Program Files\Tencent\QQ\AddEmotio
n.htm
O8 - Extra context menu item: 用QQ彩信
发&#
36865;#
813;ࢳ
0;片
- C:\Program Files\Tencent\QQ\SendMMS.h
tm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\MSNMES~1\MSGRA
P~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\MSNMES~1\MSGRA
P~1.DLL
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-4
8966E44ABA
8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\DEC\system32\At
i2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.ex
e
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraap
ache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
Also when I open Windows Process List, sometimes I will find a lot of random unknown programs running, like.. winlog0n.exe and other weird named exe programs.
Any help or suggestions on how to solve these problems will be greatly appreciated. If you need any more information or need more explanation or details, please feel free to tell me.
I apologize for the long post.
Thank you very much!
Added:
I removed and restarted computer. And rescan use Security Task Manager, these aren't on the list anymore.
Ghook.dll C:\SysAd3\Ghook.dll
Ghook.dll C:\SysAd2\Ghook.dll
svchost.exe C:\SysAd2\svchost.exe
svchost.exe C:\SysAd3\svchost.exe
Though, I am still having other problems. Please help. Thanks!