Author Topic: problems with windows xp. PLEASE HELP  (Read 33056 times)

0 Members and 1 Guest are viewing this topic.

aguyfaescotland

  • Guest
problems with windows xp. PLEASE HELP
« on: May 26, 2007, 03:21:16 PM »
A few days ago things went haywire on my pc with regards to internet connection. At times I was able to get on but mostly I could not. After several scans I discovered and deleted a trojan virus, unsure of exact name unfortunately. Anyway since getting this virus and hopefully removing it my computer no longer seems to remember any settings.
For example when I startup and login none of my startup programs have started, and they are all set to come on at startup obviously. when i go online via internet explorer every time I open it I am asked to set automatic fishing, as if I starting the application for the first time each and evry time. Dopn't have any problems iwth mozilla though it seems to remember all previous settings. Having to reinstall windows would present huge problems for me and I really hope there is some alternative, any suggestions????????????????????????????????????????
« Last Edit: May 28, 2007, 03:20:18 AM by aguyfaescotland »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: problems with windows xp. PLEASE HELP
« Reply #1 on: May 26, 2007, 04:03:11 PM »
Lets have a look see


* Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Doubleclick on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

aguyfaescotland

  • Guest
Re: problems with windows xp. PLEASE HELP
« Reply #2 on: May 26, 2007, 04:12:55 PM »
Cheers very much, will try that. Sadly stuck at work at moment so will be a couple of hours before I get chance. but asap I will post it. Out of curiosity the fact that mozilla works but windows applications aren't properly do think it could just be a case of detecting whatever and prob resolved without having to reinstall windows?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: problems with windows xp. PLEASE HELP
« Reply #3 on: May 26, 2007, 04:46:17 PM »
I allways live in hope and treat a re-install as a failure  8)

aguyfaescotland

  • Guest
Re: problems with windows xp. PLEASE HELP
« Reply #4 on: May 26, 2007, 09:09:04 PM »
Here it comes, cheers.


Logfile of HijackThis v1.99.1
Scan saved at 20:07:07, on 26/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
C:\Program Files\Comodo\Firewall\cpf.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\CallingID\Toolbar\CallingIDGlobal.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program

aguyfaescotland

  • Guest
Re: problems with windows xp. PLEASE HELP
« Reply #5 on: May 26, 2007, 09:09:32 PM »
and some more

Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: CallingID for IE - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CallingID\Toolbar\CallingIDIE.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: CallingID - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CallingID\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKLM\..\Run: [BOC-423] C:\PROGRA~1\Comodo\CBOClean\BOC423.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ErrorFixer] C:\Program Files\Error Fixer\ErrorFixer.exe -AutoStart
O4 - HKLM\..\RunOnce: [*Restore] C:\WINDOWS\system32\restore\rstrui.exe -c
O4 - Global Startup: AVG Anti-Spyware.lnk = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
O4 - Global Startup: AVG Control Center.lnk = C:\Program Files\Grisoft\AVG7\avgcc.exe
O4 - Global Startup: Comodo BOClean.lnk = C:\Program Files\Comodo\CBOClean\BOC423.EXE
O4 - Global Startup: COMODO Firewall Pro.lnk = C:\Program Files\Comodo\Firewall\cpf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,0,0/McUpdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150904764953
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37960.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4965/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D9B2F1C-41CA-4A6D-95FD-252F78F9664C}: NameServer = 192.168.0.1,195.40.1.36
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Control Pro (RCPServer) - Alchemy Lab - C:\Program Files\Remote Control Pro\rcpserver.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89129
  • No support PMs thanks
Re: problems with windows xp. PLEASE HELP
« Reply #6 on: May 27, 2007, 12:32:30 AM »
Interesting that you haven't even got avast installed and this is a support forum for avast anti-virus, I assume support is decidedly lacking with AVG free [/sarcasm] ?

Other than these I see nothing obvious.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Do you know what this is it something you installed:
O4 - HKLM\..\Run: [ErrorFixer] C:\Program Files\Error Fixer\ErrorFixer.exe -AutoStart
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: problems with windows xp. PLEASE HELP
« Reply #7 on: May 27, 2007, 12:40:24 AM »
Nothing apparent lets go for a deeper scan

Download WinPFind3u.exe  to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
      <list of options>
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts.

aguyfaescotland

  • Guest
Re: problems with windows xp. PLEASE HELP
« Reply #8 on: May 27, 2007, 11:03:33 AM »
I did indeed have avast installed on my computer upto a couple of days ago when this all started. While avast initally appeared to discover and delete the virus, I was still having problems after and indeed upto and beyond now. So in my desperation to get my computer fixed without loosing everyting that I had failed to backup, I tried various other spyware, adware and anti-virus programs, but sadly with no success. I have every intention of reinstalling avast once prob is resolved but for moment my uninstalling and installing effort are concentrating on resolving the issue at hand.

Will try suggested alternative at some point later, unfortunately I am stuck in hell, or as some may call work and unlikely to get early release as I've already used my good behaviour days. will get back to you. cheers again for help, it's very much appreciated the wife isnae too please that I've buggered the computer and potentially lost all our family pictures and most importantly her sims2 collection.

The errorfixer is a program I downloaded recently to try and resolve my problem, it's a registry fixer I believe.
« Last Edit: May 27, 2007, 11:23:31 AM by aguyfaescotland »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: problems with windows xp. PLEASE HELP
« Reply #9 on: May 27, 2007, 02:49:03 PM »
Try the winpfind that should  show where the problems are and I may be able to fix it, 

Quote
wife isnae too please that I've buggered the computer and potentially lost all our family pictures and most importantly her sims2 collection.

Not yet time for hari kiri

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: problems with windows xp. PLEASE HELP
« Reply #10 on: May 27, 2007, 03:13:50 PM »
Hi aguyfaescotland,

Errorfixer, which David asked you about, seems to be scamware: asking for money for doing nothing.

Get rid of it. If you want to check for registry errors, TuneUp Utilitiies has a free working trial:

http://www.tune-up.com/

It would help us to know what the original virus was and what the symptoms were and are. What are the problems you say you are still having?

If they still seem to be virus-related, it would be work running some rootkit (hidden malware) scans:

http://www.pandasoftware.com/products/antirootkit/

http://www.f-secure.com/blacklight/

http://free.grisoft.com/doc/avg-anti-rootkit-free/lng/us/tpl/v5
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

aguyfaescotland

  • Guest
Re: problems with windows xp. PLEASE HELP
« Reply #11 on: May 27, 2007, 03:51:41 PM »
hello. went home at lunch and downloaded program. in your post you mentioned something about checking some boxes, but the boxes seemed to be missing from your post. when i ran the program without checking any boxes in seemed to crash, I checked all boxes and it crashed. I then checked just a few and it started scanning, sadly I had to return to work before it completed so will have to post results later. just incase I need to do it again what boxes should I have checked.


errorfixer didnae work for me though I don't recall it asking for any money.

My problems started a few days ago. I couldn't access the internet and at that time I had Avast but it didn't display any error messages. After a few days of internet problems I ran a boot scan with avast and it appeared to detect and delete a trojan, although I failed to memorise name (sorry). After this and booting my computer back up none of my startup programs were running, things like comodo and ani-virus and one or two other things failed to launch. When I attempt to access internet I can get online but internet explorer seems to forget my setting and presents me with the option of setting automatic fishing every time. I can't update windows, when i try, I get the blocking banner at top of screen and when I click and allow install of the microsft components it just resets back and again asks to enable active x controls for site. Mozilla firefox works without any probs what so ever and still remember settings from before all this started. Very, very frustrating and I could go on.

« Last Edit: May 27, 2007, 05:15:37 PM by aguyfaescotland »

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: problems with windows xp. PLEASE HELP
« Reply #12 on: May 27, 2007, 05:52:58 PM »
If you had kept avast!, you could have looked at the log to see what had been deleted, and that might have given us a clue to the problem.

Also, it's always best to quarantine any malware found just in case it is a false-positive detection of a legitimate system file. The removal of such a file can cause problems like those you describe, and having the file in quarantine, you could have re-scanned it to confirm it was malware, and replaced it if it turned out to be a false positive.

Not being able to access the internet is not necessarily the symptom of a virus, so I wonder if the Tojan detected by avast! was responsible for that problem in the first place.

I think I would be tempted to try a System Restore to a time before you started experiencing problems- assuming you can find a working restore point. As you have removed/installed several anti-malware programs since then, you may find you need to remove and reinstall programs before they work properly after a system restore.

If you do do a sytem restore, run a scan with whatever AV you decide to install, plus AVG Anti-Spyware because the system restore may reactivate malware. Be sure to make a note of any detections and to chose the quarantine option (put in chest in avast!).

Errorfixer is definitely a con-trick, so bin it.

http://www.pcreview.co.uk/forums/thread-443706.php
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

aguyfaescotland

  • Guest
Re: problems with windows xp. PLEASE HELP
« Reply #13 on: May 27, 2007, 06:24:43 PM »
I've tried system restore, and you would know this if I bothered to inform you to begin with, sorry. I tried system restore but system just crashes during restore. Also I have a system exlporer program which replaced task manager and it is now not working and I am unable to uninstall and I'm unable to check it. I have advanced windows care which is also crashing since this problem but I can access the startup menu using it and I noticed yesterday that file called something like rstrui.exe was checked to start with windows, I've never noticed this before and thought it could be cause of problem but when I checked the file name on internet (which I can access, internet explorer just doesn't remember my settings) it says it's to do with system restore so thought I should just leave. But I've definately never saw it in startup before is it normal for it to be there if you've used (or as in my case unsuccessfully tried) the restore function?

aguyfaescotland

  • Guest
Re: problems with windows xp. PLEASE HELP
« Reply #14 on: May 27, 2007, 07:20:48 PM »
Here it comes and what a size of a document, sorry.

WinPFind3 logfile created on: 27/05/2007 13:48:59
WinPFind3U by OldTimer - Version 1.0.38   Folder = D:\Documents and Settings\Jamie\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 7.0.5730.11)
 
2.00 Gb Total Physical Memory | 1.36 Gb Available Physical Memory | 67.80% Memory free
3.85 Gb Paging File | 3.40 Gb Available in Paging File | 88.43% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.99 Gb Total Space | 11.47 Gb Free Space | 38.25% Space Free
Drive D: | 241.65 Gb Total Space | 110.38 Gb Free Space | 45.68% Space Free
E: Drive not present or media not loaded
F: Drive not present or media not loaded

Computer Name: XAVIER
Current User Name: Jamie
Logged in as Administrator.
Current Boot Mode: Normal


[Processes - Non-Microsoft Only]
aolacsd.exe -> %CommonProgramFiles%\AOL\ACS\AOLacsd.exe -> America Online, Inc. [Ver = 2.0.20.1.UK.223       | Size = 1135728 bytes | Modified Date = 08/04/2004 08:38:26 | Attr =    ]
avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 23/05/2007 23:02:22 | Attr =    ]
avgcc.exe -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 416256 bytes | Modified Date = 23/05/2007 23:02:22 | Attr =    ]
avgemc.exe -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 351744 bytes | Modified Date = 23/05/2007 23:02:22 | Attr =    ]
avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 23/05/2007 23:02:24 | Attr =    ]
bocore.exe -> %ProgramFiles%\Comodo\CBOClean\BOCore.exe -> COMODO [Ver = 4.23.001 | Size = 76528 bytes | Modified Date = 17/04/2007 15:21:08 | Attr =    ]
cmdagent.exe -> %ProgramFiles%\Comodo\Firewall\cmdagent.exe -> COMODO [Ver = 2.4.0.20 | Size = 361040 bytes | Modified Date = 26/02/2007 15:20:08 | Attr =    ]
cpf.exe -> %ProgramFiles%\Comodo\Firewall\cpf.exe -> COMODO [Ver = 2.4.0.58 | Size = 1115728 bytes | Modified Date = 26/02/2007 15:20:08 | Attr =    ]
elservice.exe -> %ProgramFiles%\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -> Intel Corporation [Ver = 1.0.0.1093 | Size = 180224 bytes | Modified Date = 08/11/2005 15:51:54 | Attr =    ]
googleupdaterservice.exe -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.767.25472.beta | Size = 136952 bytes | Modified Date = 30/03/2007 20:54:42 | Attr =    ]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 28/09/2006 15:13:20 | Attr =    ]
iaantmon.exe -> %ProgramFiles%\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> Intel Corporation [Ver = 5.5.0.1035 | Size = 86140 bytes | Modified Date = 12/10/2005 12:30:24 | Attr =    ]
lexbces.exe -> %System32%\LEXBCES.EXE -> Lexmark International, Inc. [Ver = 9.37 | Size = 307200 bytes | Modified Date = 26/02/2004 08:55:20 | Attr =    ]
lexpps.exe -> %System32%\LEXPPS.EXE -> Lexmark International, Inc. [Ver = 9.37 | Size = 174592 bytes | Modified Date = 26/02/2004 08:55:50 | Attr =    ]
nvsvc32.exe -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.9147 | Size = 155715 bytes | Modified Date = 11/08/2006 21:42:50 | Attr =    ]
saservice.exe -> %ProgramFiles%\SiteAdvisor\6066\SAService.exe -> McAfee, Inc. [Ver = 2.4.0 | Size = 321064 bytes | Modified Date = 14/04/2007 00:04:26 | Attr =    ]
tablet.exe -> %System32%\Tablet.exe -> Wacom Technology, Corp. [Ver = 4.84-6 | Size = 729088 bytes | Modified Date = 10/01/2005 12:10:38 | Attr =    ]
ulcdrsvr.exe -> %CommonProgramFiles%\Ulead Systems\DVD\ULCDRSvr.exe -> Ulead Systems, Inc. [Ver = 1, 0, 0, 3 | Size = 49152 bytes | Modified Date = 26/02/2004 09:52:00 | Attr =    ]
winpfind3u.exe -> D:\Documents and Settings\Jamie\Desktop\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.38.0 | Size = 318976 bytes | Modified Date = 22/05/2007 18:27:40 | Attr =    ]
x10nets.exe -> %CommonProgramFiles%\X10\Common\X10nets.exe -> X10 [Ver = 1, 0, 0, 1 | Size = 20480 bytes | Modified Date = 12/11/2001 13:31:48 | Attr =    ]