Ok. Brief summary of my problem. It first started when I noticed a PartyPoker icon on my desktop, and yazifind pop ups started to occur. I've been hijacked before and cleaned up fairly well (or did I?) so I knew some of the steps to take to get rid of this problem. Well, everything was fine for about a month or so, when my computer re-started up to a black screen. (fatal exception while working with the program TDT) After the WinXp Logo just black screen with mouse. No curser for command prompt. Safe mode was same. Tried all options, boot to last known good config....., etc. and finally just reinstalled WinXP. Got my screen back! And I think some adware too! At least I'm pretty sure, cause PartyPoker came back and Yazifind popped up again. I'm not sure what to delete, and Now it is a major pain just trying to do windows updates and the like, as internet is slow. All seems fine for a little bit (20 mins. or so) then it will just slow down. I've managed to download a few updates and now i can't tell what is legit and what is Spy-Ad ware. And quite a few of my files look suspicious to me. But with slow internet, research is difficult! Can someone please have a look at my HiJackThis log and tell me if you see anything that is known to cause trouble? A Few more notes. Have several svchost.exe running. at least four now at all times. even before internet connection. Used to only have two. Now at least four. I have two instances of lsass.exe running in task manager. Also, task manager fails to "show up" sometimes. When I click on it it appears in Sys tray but no window opens. Also get runtime error for a.exe which under properties labled as tinymfc.exe. And the error "a.exe is not a valid Win32 application" or something like that. slinstaller.exe was under my local computer(C:) along with other icon applications that i don't recognize. Like a.exe and b.exe, dd.exe and dse.exe, and updatees.exe (at least I assume they are .exe because they are applications.) get errors that windows can't find slinstaller.exe. I am quite leary of deleting anything because I have gotten myself into "trouble" by deleting before. I thought i knew a little bit more than i actually do. Probably still seems to be the case! Anyway. I said BRIEF! Sorry! Any advice is GREATLY APPRECIATED! & THANKS SO MUCH for all the help you provide to everyone!!!! Here is my HiJackThis Log:
StartupList report, 7/2/2005, 7:48:29 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HiJackThis!\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\mzhxlixm.exe
C:\WINDOWS\System32\wuitgurd.exe
C:\WINDOWS\System32\msfirewalls.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\WINDOWS\slrundll.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\a.exe
C:\Program Files\HiJackThis!\HijackThis.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
-------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ccApp = C:\Program Files\Common Files\Symantec Shared\ccApp.exe
ccRegVfy = C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
Microsoft Windows Update XP64 = mzhxlixm.exe
CPU Temp Control = wuitgurd.exe
USB Updates = msfirewalls.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Windows Update XP64 = mzhxlixm.exe
CPU Temp Control = wuitgurd.exe
USB Updates = msfirewalls.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Works Update Detection = C:\Program Files\Microsoft Works\WkDetect.exe
Microsoft Windows Update XP64 = mzhxlixm.exe
CPU Temp Control = wuitgurd.exe
USB Updates = msfirewalls.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Windows Update XP64 = mzhxlixm.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\sstext3d.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Symantec NetDetect.job
--------------------------------------------------
Enumerating Download Program Files:
[WUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119675518875
[Update Class]
InProcServer32 = C:\WINDOWS\System32\iuctl.dll
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38528.5111342593
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 5,004 bytes
Report generated in 0.016 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only