My comp is messing up

ChaoZ

Diamond Member
Apr 5, 2000
8,906
1
0
I have no idea what's going on, but my comp is really slow/weird right now. I have to click multiple times on icons for it to work.

I see a bunch of weird processes running too. Here are a few:
drclearmain
IMJPMIG
shdong

I've restarted my computer and it didn't help. I'm running anti-virus at the moment. I can post a hijackthis if anyone can read it.
 

niji1875

Senior member
Aug 31, 2006
579
0
0
virus mustbe.

kill them all, or format system

but I suggest u to use a kill virus boost pen drive, kill them in dos or mini linux condition.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
IMJPMIG is okay = imjpmig.exe belongs to the Microsoft Input Method Editor.

Those other two files definitely look suspicious.
 

MagnusTheBrewer

IN MEMORIAM
Jun 19, 2004
24,122
1,594
126
imjpmig.exe belongs to the Microsoft Input Method Editor. It is used to simplify the input of Asian characters in the Microsoft Office suite. It's not a critical component.

shdong turned up on a Korean help site but unfortunately the English translation was no help at all. Sorry, please post the hiJackThis log.

Have you run any anti-spyware/malware programs?
 

ChaoZ

Diamond Member
Apr 5, 2000
8,906
1
0
I've ran spybot and adware; got rid of a bunch of stuff. Nothing showed up when I ran AVG. Anyways here's my log and thanks for the help.




Logfile of HijackThis v1.99.1
Scan saved at 1:57:43 PM, on 10/26/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Stardock\Object Desktop\2\wbload.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\AIM\aim.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\System32\msupsrv.exe
C:\Documents and Settings\Chaoz\Local Settings\Temp\shdong.exe
C:\Documents and Settings\Chaoz\Local Settings\Temp\wtdmm.exe
C:\Documents and Settings\Chaoz\Local Settings\Temp\lmosxh.exe
C:\WINDOWS\System32\SUPERKEY.EXE
C:\WINDOWS\Temp\wocmx.exe
C:\WINDOWS\Temp\touhan.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Chaoz\LOCALS~1\Temp\Rar$EX00.344\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 59.165.163.18:8080
O2 - BHO: adBalloon.Coupon - {04523F7A-6A8B-4A9C-BE0D-89B4C7C9CBBA} - C:\WINDOWS\System32\adBalloon.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Sponsor.Box - {2EEB588F-9336-44FE-BE26-65C5B72B8E50} - C:\WINDOWS\System32\Sponsor.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Wow Toolbar (&W) - {843B3544-28B7-4FC0-8BAC-DA833AE628C9} - C:\Program Files\mkizn\WowToolbar.dll
O2 - BHO: wOcashAX Class - {982B25FC-32CD-4956-91DD-D96ABB97CC09} - C:\Program Files\wOcash\wOcash.dll
O2 - BHO: SHxObj Class - {C8D97067-F899-482E-BD1F-4059A93E1D09} - C:\Program Files\Windows Search Helper\shsharp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Windows Wow Toolbar (&W) - {843B3544-28B7-4FC0-8BAC-DA833AE628C9} - C:\Program Files\mkizn\WowToolbar.dll
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [mstcenter] C:\WINDOWS\mstcenter.exe
O4 - HKLM\..\Run: [Windows Search Helper] C:\Program Files\Windows Search Helper\shmanager.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Windows IE Opencash] C:\Program Files\wOcash\wocm.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [firefox] C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ¿ÀÇÂij½¬ - {32DAEBBD-97D7-49f4-8217-30754ACBB16D} - C:\Program Files\wOcash\wOcash.dll
O9 - Extra 'Tools' menuitem: ¿ÀÇÂij½¬ - {32DAEBBD-97D7-49f4-8217-30754ACBB16D} - C:\Program Files\wOcash\wOcash.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup...86/client/wuweb_site.cab?1141182433062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup...86/client/muweb_site.cab?1141182428421
O17 - HKLM\System\CCS\Services\Tcpip\..\{D94B99CF-4B0B-4DFA-91DC-4EA1BCEB2857}: NameServer = 4.2.2.1,4.2.2.2
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\2\fastload.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Internet Explorer Preference Service (IEPreferenceService) - IEPreferanceService - C:\WINDOWS\system32\gizxcpb.exe
O23 - Service: MS Ineterner Explorer Update Services (msieupservice) - JK - C:\WINDOWS\System32\msupsrv.exe
O23 - Service: Browsers Control Service Pack (SBServiceControl) - JK - C:\WINDOWS\system32\xzbgezz.exe

 

MagnusTheBrewer

IN MEMORIAM
Jun 19, 2004
24,122
1,594
126
Nothing jumps out at me other than a dislike for bitcomet. Have you posted your log over at tomcoyote?
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Well, a lot of stuff jumps out at me. Your system is definitely infected.
 

Pulsar

Diamond Member
Mar 3, 2003
5,224
306
126
Is there any reason for your system to be running a bunch of asian langauge programs? Because these files are only showing up on asian-langauge websites.

I would tril killing:

msupsrv.exe
shdong.exe
wtdmm.exe
lmosxh.exe
superkey.exe
wocmx.exe
touhan.exe

Uninstall bitcomet.

I would go into safemode and then use hijack this to remove the above processes.

Also all it to fix the issues you have listed, then rerun it and repost.