Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Lots of problems with Laptop, Windowx XP  (Read 22800 times)

0 Members and 1 Guest are viewing this topic.

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Lots of problems with Laptop, Windowx XP
« Reply #30 on: December 21, 2008, 10:17:30 PM »
OK that worked.

Please go through with the Malwarebytes and HijackThis instructions.

slafa23

    Topic Starter


    Beginner

    Re: Lots of problems with Laptop, Windowx XP
    « Reply #31 on: December 21, 2008, 10:24:14 PM »
    I'm sorry, but where is that?

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Lots of problems with Laptop, Windowx XP
    « Reply #32 on: December 21, 2008, 10:26:33 PM »
    Here ya go.

    Download Malwarebytes' Anti-Malware (MBAM)

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
      • Then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select Perform quick scan, then click Scan.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Be sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy and Paste the entire report in your next reply.
      Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

      ----------

      Download TrendMicro HijackThis.exe (HJT) to the Desktop.

      • Double-click on HJTInstall.
      • Click on the Install button.
      • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
      • Upon install, HijackThis should open for you.
      • Click on the Do a system scan and save a log file button
      • HijackThis will scan and then a log will open in notepad.
      • Copy and then paste the entire contents of the log in your post.
      • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

      slafa23

        Topic Starter


        Beginner

        Re: Lots of problems with Laptop, Windowx XP
        « Reply #33 on: December 21, 2008, 10:33:32 PM »
        Thank you so much for all of your help by the way. The  Malwarebytes scan is running now...

        slafa23

          Topic Starter


          Beginner

          Re: Lots of problems with Laptop, Windowx XP
          « Reply #34 on: December 21, 2008, 10:35:46 PM »
          Malwarebytes' Anti-Malware 1.31
          Database version: 1528
          Windows 5.1.2600 Service Pack 3

          12/22/2008 12:34:54 AM
          mbam-log-2008-12-22 (00-34-54).txt

          Scan type: Quick Scan
          Objects scanned: 49059
          Time elapsed: 6 minute(s), 32 second(s)

          Memory Processes Infected: 0
          Memory Modules Infected: 0
          Registry Keys Infected: 5
          Registry Values Infected: 1
          Registry Data Items Infected: 0
          Folders Infected: 0
          Files Infected: 2

          Memory Processes Infected:
          (No malicious items detected)

          Memory Modules Infected:
          (No malicious items detected)

          Registry Keys Infected:
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weather Services (Adware.Hotbar) -> Quarantined and deleted successfully.

          Registry Values Infected:
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.

          Registry Data Items Infected:
          (No malicious items detected)

          Folders Infected:
          (No malicious items detected)

          Files Infected:

          slafa23

            Topic Starter


            Beginner

            Re: Lots of problems with Laptop, Windowx XP
            « Reply #35 on: December 21, 2008, 10:36:37 PM »
            Edit:
            cont.-

            Files Infected:
            C:\WINDOWS\system32\litikusi.dll_old (Trojan.Vundo) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\wulubuvo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

            slafa23

              Topic Starter


              Beginner

              Re: Lots of problems with Laptop, Windowx XP
              « Reply #36 on: December 21, 2008, 10:38:38 PM »
              Hijack this log--

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:38:05 AM, on 12/22/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16762)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
              C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
              C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\notepad.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Network Associates\Common Framework\udaterui.exe
              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
              C:\Program Files\Network Associates\Common Framework\McTray.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
              C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.unh.edu/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
              O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\udaterui.exe" /StartedFromRunKey
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
              O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O15 - Trusted Zone: *.amaena.com
              O15 - Trusted Zone: *.avsystemcare.com
              O15 - Trusted Zone: *.onerateld.com
              O15 - Trusted Zone: *.safetydownload.com
              O15 - Trusted Zone: *.trustedantivirus.com
              O15 - Trusted Zone: *.virusremover2008.com
              O15 - Trusted Zone: *.virusschlacht.com
              O15 - Trusted Zone: *.amaena.com (HKLM)
              O15 - Trusted Zone: *.avsystemcare.com (HKLM)
              O15 - Trusted Zone: *.onerateld.com (HKLM)
              O15 - Trusted Zone: *.safetydownload.com (HKLM)
              O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
              O15 - Trusted Zone: *.virusremover2008.com (HKLM)
              O15 - Trusted Zone: *.virusschlacht.com (HKLM)
              O16 - DPF: {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_04) -
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
              O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
              O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe

              --
              End of file - 7649 bytes

              slafa23

                Topic Starter


                Beginner

                Re: Lots of problems with Laptop, Windowx XP
                « Reply #37 on: December 21, 2008, 10:52:15 PM »
                Should I do anything else with the Hijack? Or just reboot?
                Am I done?

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Lots of problems with Laptop, Windowx XP
                « Reply #38 on: December 21, 2008, 10:53:31 PM »
                Quote from: slafa23
                Am I done?

                Not yet. Still a few more steps.

                Thank you so much for all of your help by the way. The  Malwarebytes scan is running now...

                Your welcome.

                The real-time protection of two antivirus programs may conflict with each other and cause the following:

                1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
                2) Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
                3) Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.

                Please uninstall one antivirus, either McAfee or Avast. Two actually leaves you less protected.

                ----------

                Open HijackThis and select Do a system scan only.

                Place a check mark next to the following entries: (if there)

                • O15 - Trusted Zone: *.amaena.com
                • O15 - Trusted Zone: *.avsystemcare.com
                • O15 - Trusted Zone: *.onerateld.com
                • O15 - Trusted Zone: *.safetydownload.com
                • O15 - Trusted Zone: *.trustedantivirus.com
                • O15 - Trusted Zone: *.virusremover2008.com
                • O15 - Trusted Zone: *.virusschlacht.com
                • O15 - Trusted Zone: *.amaena.com (HKLM)
                • O15 - Trusted Zone: *.avsystemcare.com (HKLM)
                • O15 - Trusted Zone: *.onerateld.com (HKLM)
                • O15 - Trusted Zone: *.safetydownload.com (HKLM)
                • O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
                • O15 - Trusted Zone: *.virusremover2008.com (HKLM)
                • O15 - Trusted Zone: *.virusschlacht.com (HKLM)
                .
                Important: Close all windows except for HijackThis and then click Fix checked.

                Exit HijackThis.

                ----------

                Your Java is out of date.

                Older versions have vulnerabilities that malicious sites can use to infect your system.

                First install the new Sun Java Runtime Environment

                Be sure to close all browser windows before beginning the install.

                Remove the old version(s)

                Download JavaRa
                • Unzip the file and open the JavaRa.exe
                • Click Remove Older Versions
                • JavaRa will search for and remove any outdated version of Java and remove any that are found.
                • Click Additional Tasks
                • Place a check next to Remove Useless JRE Files and click Go
                • Exit JavaRa
                • Delete the JavaRa files from the Desktop
                .
                ----------

                How is the computer running now?

                slafa23

                  Topic Starter


                  Beginner

                  Re: Lots of problems with Laptop, Windowx XP
                  « Reply #39 on: December 22, 2008, 11:22:31 AM »
                  Ok, to remove Avast, should I just Add or Remove program?

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Lots of problems with Laptop, Windowx XP
                  « Reply #40 on: December 22, 2008, 11:27:28 AM »
                  Yes. There should be just one entry to uninstall. Be sure to restart the computer after uninstalling it.

                  slafa23

                    Topic Starter


                    Beginner

                    Re: Lots of problems with Laptop, Windowx XP
                    « Reply #41 on: December 22, 2008, 11:30:32 AM »
                    Ok, I did the uninstall and reboot. I did the Hijackthis and fixed all of the O15s.
                    Now I am about to do the Java.

                    evilfantasy

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Calm like a bomb
                    • Thanked: 493
                    • Experience: Experienced
                    • OS: Windows 11
                    Re: Lots of problems with Laptop, Windowx XP
                    « Reply #42 on: December 22, 2008, 11:36:39 AM »
                      OK, some cleanup and then a (hopefully) final scan.

                      • Click START then RUN
                      • Now type Combofix /u in the runbox
                      • Make sure there's a space between Combofix and /u
                      • Then hit Enter.
                      .
                      • The above procedure will:
                      • Delete the following:
                      • ComboFix and its associated files and folders.
                      • Reset the clock settings.
                      • Hide file extensions, if required.
                      • Hide System/Hidden files, if required.
                      • Set a new, clean Restore Point.
                      .
                      ----------

                      Download
                    OTCleanIt.exe and save it to your Desktop.
                    • Double-click OTCleanIt.exe.
                    • Click the CleanUp! button.
                    • Select Yes when the "Begin cleanup Process?" prompt appears.
                    • If you are prompted to Reboot during the cleanup, select Yes.
                    • The tool will delete itself once it finishes, if not delete it yourself.
                    .
                    Run CCleaner.

                    Important: Restart the computer before continuing.

                    ----------

                    Run the Kaspersky Online Scanner

                    In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

                    • Click on SCAN NOW
                    • Click Accept.
                    • The program will then begin downloading the latest definition files.
                    • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
                    • The scan will take a while, so be patient and let it finish.
                    When the scan is done, in the Scan is complete window, any infection is displayed.
                    There is no option to clean/disinfect, however, we need to analyze the information on the report.

                    To obtain the report:
                    Click on: Save Report As
                    • Next, in the Save as prompt, Save in area, select: Desktop.
                    • In the File name area use KScan, or something similar.
                    • In Save as type: click the drop arrow and select: Text file [*.txt]
                    • Then, click: Save


                    Copy and paste the Kaspersky Online Scanner Report in your next reply.

                    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

                    slafa23

                      Topic Starter


                      Beginner

                      Re: Lots of problems with Laptop, Windowx XP
                      « Reply #43 on: December 22, 2008, 11:39:07 AM »
                      Before that, both times I tried running JavaRa, it had to close because it encountered an error. The first time it deleted a lot of stuff before showing the message, the second time it was right after I opened it. What should I do?

                      slafa23

                        Topic Starter


                        Beginner

                        Re: Lots of problems with Laptop, Windowx XP
                        « Reply #44 on: December 22, 2008, 11:40:38 AM »
                        It worked the next time I tried. Would you like to see the log?