333Mhz Compaq Laptop, XP (unsupported (?) no SP2)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Privategeek7305, Apr 15, 2006.

  1. Privategeek7305

    Privategeek7305 Private E-2

    Hi;
    I purchased this laptop for my son used off eBay. It came with XP installed but Microsoft won't support it anymore so I'm assuming the software might not be legit...(?) It had some hotfixes installed at first when I went to Microsoft update... so I thought it was fine initially, but SP2 wouldn't install... i don't know really...
    These are the logs after the initial add/remove prog's, running CCleaner, Ad-AwareSE - new build (w/updates), Spybot S&D w/updated signatures, and Microsoft malicious software removal tool. I couldn't get the safe mode with networking to work for the scanners, so they were done in normal, but the initial programs were run in "Safe mode with networking support" but without any network connection made.
    I understand there's a limitation to what can be accomplished here without the service packs updated... i hope there's something we can do... are the restore cabs infected?
    I see as I'm looking for the bdscan file that somethings I thought were deleted in the initial add/remove programs phase (such as MediaGateway, some AOL stuff, and some unfamiliar programs I hadn't even seen when I was deleting things still have folders in the program files folder)... I'm getting flustered. I'm going to go back to the add/remove programs and see if stuff has reappeared, or if the folders are just left over in the Program files folder and I'll just search and delete for any affiliated files/folders...
    Thanks for any and all assistance and advice,
    wayne
     
  2. Privategeek7305

    Privategeek7305 Private E-2

    i guess these fell off while doing editing and previews... anywhichway... here they are...
    w
     
  3. Privategeek7305

    Privategeek7305 Private E-2

    third times the charm...
     

    Attached Files:

  4. Privategeek7305

    Privategeek7305 Private E-2

    hi again...
    can i change that to a 366Mhz CPU? heh... whadiyaknow...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in step 7 of the READ ME exactly. You have HJT installed incorrectly and you obtained the log from safe mode not normal boot mode as required. Also you got your log before running the other steps of the READ & RUN ME sticky which is the wrong order.

    After fixing this, attach a new log.

    Note: Your OS is way out of date and is a major security risk.
     
  6. Privategeek7305

    Privategeek7305 Private E-2

    Happy Holidays Chaslang,
    I hope i've done it properly... this basic training is killing me sumpthin' fierce!
    Here we go...
    Thanks as always,
    wayne
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat! You must follow the directions in step 7 of the READ ME to get HijackThis install correctly. You are still running it directly from the ZIP file like the below:
    D:\Documents and Settings\Admin\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

    If you do this, you will not get any backups for anything we fix. And if you make a mistake during the fixing, you will be in trouble.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After you have made sure that hijackthis.exe is running from C:\Program Files\HJT\hijackthis.exe (you can easily verify this by just looking at your log) then you can continue with the below.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O4 - HKLM\..\Run: [CHIPSStart] CHPSTART.EXE
    O16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\ied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\wx.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\wx.cab
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\eied_s7.cab
    c:\wx.cab
    D:\WINDOWS\switchagreement.txt
    Additional step to delete files in the Downloaded Program Files folder :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s ied.inf
    del ied.inf
    attrib -r -h -s start.INF
    del start.INF
    attrib -r -h -s start7.inf
    del start7.inf
    exit
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. Privategeek7305

    Privategeek7305 Private E-2

    Re: 366Mhz Compaq Laptop, XP (unsupported (?) no SP2)

    Okay...
    Here's how it's going so far...
    I moved Hijackthis into it's own folder in the Program Files folder and extracted the .exe into that folder. I then ran HJT from there and fixed checked as per the instructions.
    Next, I exitted as instructed and using windows explorer, deleted the first and third files mentioned. I could not find the wx.cab file.
    Then i went to the command prompt and began running the commands... At first it was confusing because it was a D prompt and not a C prompt... but later it was saying WINDOWS\Downloaded Program Files\> and I just ran the commands after that. None were found, none were deleted. I switched the D prompt to a C prompt (and as soon as i typed the first line, it was back to WINDOWS\Downloaded Program Files\ ... I manually looked in both drives for the files mentioned and ran searches also with hidden files disabled (so I could see everything) and saw none of the files listed.
    When I got to the part about the prefetch, there wasn't a prefetch folder in the Windows Folder on the C drive, but there is a Prefetch folder in the D drive... and it's got about 100 files in it...
    I had thought that the fellow who sold me the laptop had installed windows NT on the D drive and XP on the C drive, but the other day when I tried to boot to the D drive (for the first time since I'd purchased the laptop), it came up as Windows98... and since I was trying in safe mode, almost nothing would load properly... long story short... i don't have a frikken clue... what to do...

    help...?
     
  10. Privategeek7305

    Privategeek7305 Private E-2

    Re: 366Mhz Compaq Laptop, XP (unsupported (?) no SP2)

    hi again;
    I read through the instructions and I'm guessing that not being able to find or delete those files was something that wasn't unexpected... just unexpected by me...
    so... i followed the rest of the instructions, and here's the HJT log...
    did i screw up?
    thanks, wayne
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: 366Mhz Compaq Laptop, XP (unsupported (?) no SP2)

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link. DO THIS ASAP!!!! You must get all of your Windows updates and a firewall installed without delay.

    How to Protect yourself from malware!
     
  12. Privategeek7305

    Privategeek7305 Private E-2

    Re: 366Mhz Compaq Laptop, XP (unsupported (?) no SP2)

    Hi;
    Thanks for the review AS Man... I ran the Nortons and was clean, I ran the bdscan and was clean, but when i ran the panda scan, it came up with some stuff in one of the quarantine folders (which I'll just delete) and a dialer (which might be that switch agreement.txt thing... idunno...
    here's the pandascan .txt log... I'm going to try and clean out that dialer before I crash and reset restore points...
    Thanks for all the help...
    wayne
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: 366Mhz Compaq Laptop, XP (unsupported (?) no SP2)

    Some of those are just the backups that HijackThis created. They are not problems but you can delete them if desired to avoid seeing them in a scan.

    Another is a cookie which is not a problem.

    The last is in your Recycle Bin which you should have emptied a dozen time over already during the running of the READ & RUN ME and using Ccleaner. Howerer it was on drive D so maybe you did not empty the Recycle Bin on drive D.
     
  14. Privategeek7305

    Privategeek7305 Private E-2

    No, I never boot to the D drive and I wasn't even aware there was a trash there... I ran the CCleaner and reset the restore point last night. All is clear and I'm going to begin the procedures for keeping malware off later this evening. Thanks a million for all your help!
    wayne - privategeek7305
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not need to boot to the drive. You just needed to empty the Recycle Bin on the second drive. It seems you are managing the two drives with a separate Recycle Bing.

    You're Welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds