Author Topic: NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!  (Read 3916 times)

0 Members and 1 Guest are viewing this topic.

resistance722

  • Guest
NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!
« on: December 31, 2012, 08:17:16 PM »
I am using an alternate computer to help fix my laptop, which does not currently have internet access due to problems.

Computer Stats:
Toshiba Laptop
Satellite L355
Windows Vista Home Basic Service Pack 2

Problems:
Froze while using Firefox on YouTube
Rebooted, froze on Media Player
Rebooted, froze on startup at desktop, did not load sidebar or widgets
Rebooted, could not access or click anything
Rebooted, theme is gone, Avast is shut down, cannot access network, cannot access sound hardware, Toshiba Service Station does not function, no restore points found, text-based apps unaccessable (word, word pad, note pad, etc).

Ran Malwarebytes (non-updated version already on laptop)
No infections found
Ran TDSSkiller
No infections found

Ran ComboFix
ComboFix deleted file c:\windows\wininit.ini
Restarted system, ComboFix failed on finishing after restart, Windows had to shut it down.
Got error report of something like:
"APPCRASH
PEV.exe   
Version.txt, AppCompat.txt, memory.hdmp, minidump.mdmp"
Restarted, text apps now accessable.

ComboFix Log is attached.

Any help will be greatly appreciated. I hope it's not a hardware failure.

Thank you,

Alex

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!
« Reply #1 on: December 31, 2012, 08:39:08 PM »
Hi could you run this for me please so that I can have a look see. Please attach both logs as the extras will show me any errors 

Download OTL  to your Desktop
Secondary link
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.


  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
winsock.*
/md5stop
CREATERESTOREPOINT


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Attach   both logs

resistance722

  • Guest
Re: NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!
« Reply #2 on: December 31, 2012, 09:13:22 PM »
Attached are the results from OTL

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!
« Reply #3 on: December 31, 2012, 11:14:53 PM »
On completion of this can you let me know what problems you are having

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:OTL
IE - HKLM\..\SearchScopes\{7D55826F-A58C-4F6B-9FE1-90C1BDD2B9E5}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1QzutDtD0F0FyB0CzztDtCtB0Bzyzy0E0F0FtN0D0Tzu0CtCzytAtN1L2XzutBtFtCtFtDtFtAtDtC&cr=1273771554
IE - HKU\S-1-5-21-147710734-4063299252-3070791712-1000\..\SearchScopes\{258EA180-AE26-33C1-5429-58DF5F052B20}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=109935&babsrc=SP_ss&mntrId=f63a9eff00000000000000ff7c8012b9
FF - prefs.js..extensions.netassistant.keyword.url: "http://click.w3i.com/?Programid=132&Elementname=Keyword&Applicationid={3100D86C-27D6-4660-A91D-C902B783440D}&Version=3.6.5&Vintage=20120622&Defaultbrowserid=16&Productid=1937&Vendorid=4152&Offerid=6894&searchterm="
FF - prefs.js..extensions.enabledItems: {a6bf16ab-42a1-4bc5-965d-5e407e449aaa}:1.0.0.0
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present


:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

resistance722

  • Guest
Re: NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!
« Reply #4 on: December 31, 2012, 11:50:35 PM »
In the meantime while waiting for a reply, I ran avast in Safe Mode and found a High risk trojan, which I deleted.

After running the OTL fix, the system is still the same, with the same problems :(

Attached is the log.

resistance722

  • Guest
Re: NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!
« Reply #5 on: January 01, 2013, 12:14:26 AM »
Update:
I ran msconfig and saw all the services that were stopped. I enabled all and restarted.
Now the computer froze on the desktop upon reboot but it looks like it tried to load everything.

Don't know if this helped.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: NEED HELP! COMPUTER ON THE FRITZ! Possible Winitit infection!
« Reply #6 on: January 01, 2013, 12:33:34 PM »
Next we will check for driver conflicts

Step 1: Start MSConfig

Click Start, type msconfig in the Start Search box, and then press ENTER.
If you are prompted for an administrator password or for a confirmation, type the password, or provide confirmation.

Step 2: Configure Selective Startup options

1.In the System Configuration Utility dialog box, click Selective Startup on the General tab.



2.Click to clear the Load Startup Items check box.
Note The Use Original Boot.ini check box is unavailable.

3.Click the Services tab.



4.Click to select the Hide All Microsoft Services check box.
5.Click Disable All, and then click OK.
6. When you are prompted, click Restart.

Once back in windows does the problem still occur ?