Hello
My w98 machine has progressively slowed down untill lately it barely works. I cannot now access the internet with any reliability posting via a laptop. Spybot reports Virtumonde and although temporarily removing the registry entry it comes back on the next bootup. Have tried VunoFix.exe (nothing found) but suspect it has been worse since then. I also suspect other problems and have had a history of Oprsrv which I've learned to deal with but it comes back after a month or so?
Have updated spybot to 1.6 per you "Before you post" page.
Any help would be much appreciated.
Thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:58 AM, on 26-07-08
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\TINYSPELL\TINYSPELL.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\WINDOWS\TMPSTART MENU\PROGRAMS\STARTUP\ISPTIMER.EXE
C:\PROGRAM FILES\ROBOMAGIC\SOCKETWATCH\SWATCH.EXE
C:\PROGRAM FILES\DESKPINS\DESKPINS.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/myhome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM\..\Run: [O'Reilly Utilities] "C:\Program Files\Annoyances\oraboot.exe" /init
O4 - HKLM\..\Run: [WINDVW32] rundll32 WINDVW32.DLL,irCRun
O4 - HKLM\..\RunServices: [Hidserv] Hidserv.exe run
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU\..\Run: [tinySpell] C:\PROGRAM FILES\TINYSPELL\TINYSPELL.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [tinySpell] C:\PROGRAM FILES\TINYSPELL\TINYSPELL.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [EasyDVDMon] (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Default user')
O4 - .DEFAULT Startup: isptimer.exe (User 'Default user')
O4 - .DEFAULT Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe (User 'Default user')
O4 - .DEFAULT Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe (User 'Default user')
O4 - .DEFAULT Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe (User 'Default user')
O4 - .DEFAULT User Startup: isptimer.exe (User 'Default user')
O4 - .DEFAULT User Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe (User 'Default user')
O4 - .DEFAULT User Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe (User 'Default user')
O4 - .DEFAULT User Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe (User 'Default user')
O4 - Startup: isptimer.exe
O4 - Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe
O4 - Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe
O4 - Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe
O4 - User Startup: isptimer.exe
O4 - User Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe
O4 - User Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe
O4 - User Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: + &Download Express: download this file - E:\Download Express\Add_Url.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O12 - Plugin for .dwg: c:\program files\opera8\PLUGINS\npdwg32.dll
O12 - Plugin for .dxf: c:\program files\opera8\PLUGINS\npdwg32.dll
O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - file://H:\controls\sdkinst.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
--
End of file - 5322 bytes
My w98 machine has progressively slowed down untill lately it barely works. I cannot now access the internet with any reliability posting via a laptop. Spybot reports Virtumonde and although temporarily removing the registry entry it comes back on the next bootup. Have tried VunoFix.exe (nothing found) but suspect it has been worse since then. I also suspect other problems and have had a history of Oprsrv which I've learned to deal with but it comes back after a month or so?
Have updated spybot to 1.6 per you "Before you post" page.
Any help would be much appreciated.
Thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:58 AM, on 26-07-08
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\TINYSPELL\TINYSPELL.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\WINDOWS\TMPSTART MENU\PROGRAMS\STARTUP\ISPTIMER.EXE
C:\PROGRAM FILES\ROBOMAGIC\SOCKETWATCH\SWATCH.EXE
C:\PROGRAM FILES\DESKPINS\DESKPINS.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/myhome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM\..\Run: [O'Reilly Utilities] "C:\Program Files\Annoyances\oraboot.exe" /init
O4 - HKLM\..\Run: [WINDVW32] rundll32 WINDVW32.DLL,irCRun
O4 - HKLM\..\RunServices: [Hidserv] Hidserv.exe run
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU\..\Run: [tinySpell] C:\PROGRAM FILES\TINYSPELL\TINYSPELL.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [tinySpell] C:\PROGRAM FILES\TINYSPELL\TINYSPELL.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [EasyDVDMon] (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Default user')
O4 - .DEFAULT Startup: isptimer.exe (User 'Default user')
O4 - .DEFAULT Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe (User 'Default user')
O4 - .DEFAULT Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe (User 'Default user')
O4 - .DEFAULT Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe (User 'Default user')
O4 - .DEFAULT User Startup: isptimer.exe (User 'Default user')
O4 - .DEFAULT User Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe (User 'Default user')
O4 - .DEFAULT User Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe (User 'Default user')
O4 - .DEFAULT User Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe (User 'Default user')
O4 - Startup: isptimer.exe
O4 - Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe
O4 - Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe
O4 - Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe
O4 - User Startup: isptimer.exe
O4 - User Startup: SocketWatch.lnk = C:\Program Files\Robomagic\SocketWatch\swatch.exe
O4 - User Startup: opera.exe.lnk = C:\Program Files\Opera8\Opera.exe
O4 - User Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: + &Download Express: download this file - E:\Download Express\Add_Url.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O12 - Plugin for .dwg: c:\program files\opera8\PLUGINS\npdwg32.dll
O12 - Plugin for .dxf: c:\program files\opera8\PLUGINS\npdwg32.dll
O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - file://H:\controls\sdkinst.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
--
End of file - 5322 bytes
Last edited by a moderator: