lesser-equity

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Security


Register


Reply
 
Thread Tools
  #41  
Old 28th May 2009, 04:24
Malware Group
 
Hi Bubba

I want you to run a different type of scan using HijackThis...

Please click Here to download HijackThis to your desktop.

Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.
It will be installed by default here: -> C:\Program Files\Trend Micro\HijackThis

A shortcut to the application will also be placed on your Desktop. The program will open automatically after installation.

Click on the option Open the Misc Tools section
Now select Open ADS Spy
Uncheck and take the tick out of Quick Scan
Click on Scan

This may take some while to complete, once done select Save Log

Post this back in your next reply
__________________
Proud member of ASAP & UNITE
__________________

My System: Steves Rig

Processor(s):
AMD Athlon 64x2 6000+
Motherboard:
ASUS M3N78 Pro
RAM Memory:
Corsair 4GB Dual Channel
Graphics Card(s):
NVIDIA GeForce 8400 GS
Sound Card:
Onboard
Hard Drive(s):
640GB Western Digital HD
Optical Drive(s):
LG Lightscribe
Case / PSU:
Cooling:
Stock HSF
Network / Internet:
20Mb Virgin Media Broadband
Monitor(s):
Hanns-G 19" Widescreen
Operating System(s):
Vista Premium 64x
  #42  
Old 28th May 2009, 12:21
Donor Group
 
That didn't take long at all, did I do something wrong lol? There is no header or anything on this log.

C:\ProgramData\TEMP : D1B5B4F1 (116 bytes)
C:\ProgramData\TEMP : DFC5A2B2 (110 bytes)
C:\ProgramData\TEMP : D1B5B4F1 (116 bytes)
C:\ProgramData\TEMP : DFC5A2B2 (110 bytes)
C:\Users\All Users\TEMP : D1B5B4F1 (116 bytes)
C:\Users\All Users\TEMP : DFC5A2B2 (110 bytes)
C:\Users\All Users\TEMP : D1B5B4F1 (116 bytes)
C:\Users\All Users\TEMP : DFC5A2B2 (110 bytes)
C:\Users\Shirley\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\1CA95AC3-00000001.eml : OECustomProperty (916 bytes)
C:\Users\Shirley\Documents\Message.eml : OECustomProperty (522 bytes)
C:\Users\Shirley\Favorites\Links\Suggested Sites.url : favicon (25214 bytes)
C:\Users\Shirley\Favorites\solved HELP! Unable to update Windows Code 80072EFD - Tech Support Guy Forums.url : favicon (1742 bytes)
  #43  
Old 28th May 2009, 15:50
Malware Group
 
Howdy there

Quote:
That didn't take long at all, did I do something wrong lol? There is no header or anything on this log.
You did great, the log is as it should be and the running times vary from computer to computer depending on the situation

Open HijackThis
Click on the option Open the Misc Tools section
Now select Open ADS Spy
Uncheck and take the tick out of Quick Scan
Click on Scan

Once the log is complete place a tick in the following check boxes at the left of the entries below and then press the Remove Selected button

C:\ProgramData\TEMP : D1B5B4F1 (116 bytes)
C:\ProgramData\TEMP : DFC5A2B2 (110 bytes)
C:\ProgramData\TEMP : D1B5B4F1 (116 bytes)
C:\ProgramData\TEMP : DFC5A2B2 (110 bytes)
C:\Users\All Users\TEMP : D1B5B4F1 (116 bytes)
C:\Users\All Users\TEMP : DFC5A2B2 (110 bytes)
C:\Users\All Users\TEMP : D1B5B4F1 (116 bytes)
C:\Users\All Users\TEMP : DFC5A2B2 (110 bytes)


Reboot your computer and let me know how things are now
__________________
Proud member of ASAP & UNITE
  #44  
Old 28th May 2009, 18:54
Donor Group
 
Same.
  #45  
Old 29th May 2009, 00:17
Malware Group
 
Hi Bubba

I think we have thrown everything at this one without success. I do not feel it is a malware problem although it is possible malware which you have removed prior to posting may have comtributed towards its initial cause.

Lets try a system file check.

You may need your original windows disc so have it next to you in case.

Click on the Vista orb, select All Programs - Accessories, right click on the command prompt and select Run as administrator and ok any UAC prompts
In the Command window type in the following

sfc /scannow

Notice the space between the sfc and /

Let it run its course, reboot yoor system and retry updates
__________________
Proud member of ASAP & UNITE
  #46  
Old 29th May 2009, 10:42
Donor Group
 
Same.
I got the message fromscan: Windows Resource Protection found corrupt files but was unable to fix some of them. It directed me to a log (actually there were 2). i would post them, but they are HUGE.

This system is an ACER running Vista Home Premium. I actually have an OEM copy of Home Premium. i was going to put it on my daughters computer when I built her one, but decided A: she has enough of a computer for a 6 year old (well she's 7 now) and B: when I did build her one I would put Win7 on it. ANyways, is there any reason I can't open the package, put the install disk in and use it for "Repair" and see what happens?

Also, we disabled Windows firewall (in the last post on page three, the way I view the site), can we get it working again? I guess, after we get Firewall working, I get the DVD player working again, and I try to repair, (assuming you say it's OK to do so, if you have nothing else to try, I'll install SP2, tell him i can't help him lol and give it back.
  #47  
Old 29th May 2009, 15:46
Malware Group
 
Hi bubba

Quote:
is there any reason I can't open the package, put the install disk in and use it for "Repair" and see what happens?
To be honest I myself cannot say if it would work or not, as this is no longer malware related it is beyond my boundries, therefore I feel I cannot give you a direct yes or no answer. Although I must say I feel it would be worth a try. Failing that I would look at a fresh start - format the system and start afresh.

Regarding the firewall, the fix in that particular post was not to turn off the firewall, but to reset the security settings to default. You should be able to turn it back on via the security centre again.
__________________
Proud member of ASAP & UNITE
  #48  
Old 29th May 2009, 17:33
Donor Group
 
Sorry about getting back to you so late, you are probably in bed now lol. I was researching the firewall thing.

Windows Firewall was working until we applied the following fix:
Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess]
"DependOnGroup"=hex(7):00,00
"DependOnService"=hex(7):4e,00,65,00,74,00,6d,00,6 1,00,6e,00,00,00,57,00,69,00,\
6e,00,4d,00,67,00,6d,00,74,00,00,00,00,00
"Description"="Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network."
"DisplayName"="Windows Firewall/Internet Connection Sharing (ICS)"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,6 5,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d ,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00 ,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73 ,00,00,00
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Epoch]
"Epoch"=dword:00002cd0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00, 65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00 ,6d,00,33,00,32,00,5c,00,\
69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e ,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile\AuthorizedApplications]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\AuthorizedApplications]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Setup]
"ServiceUpgrade"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Setup\InterfacesUnfirewalledAtUpda te]
"All"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Enum]
"0"="Root\\LEGACY_SHAREDACCESS\\0000"
"Count"=dword:00000001

"NextInstance"=dword:00000001

After that, she was deader than a hammer. The service won't even start.

Anyway, thanks for all your help. I think we can be reasonably sure that computer is malware free. I messed up on the Vista Home Premium thing though, I have an OEM copy of Ultimate. I continue perusing the world wide web on an endless quest for answers to the 80072 efd................
  #49  
Old 29th May 2009, 20:33
Donor Group
 
Hah, I fixed the firewall. Found the info here: http://support.microsoft.com/kb/943996

However, and I mentioned this earlier in the thread I think lol, in the security center, it is showing up as I have no Virus protection installed. Do you know how to fix that?

EDIT: Still haven't figured out about the update failure lol.
  #50  
Old 30th May 2009, 00:07
Malware Group
 
Hi Bubba

Glad you got the firewall sorted. You can disable the AV alerts by setting the security centre as follows: How to Disable Antivirus Alerts When Security Center Does Not Detect Installed Antivirus Application
__________________
Proud member of ASAP & UNITE
Reply

Register
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright ©2006 - 2009 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.