Arggggghhh computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BrokenComp19, Jan 23, 2007.

  1. BrokenComp19

    BrokenComp19 Private E-2

    Ok, first of all I have already gone through the steps listed in the READ AND RUN ME FIRST guide. Initially, I used system restore b/c of a svchost error. This fixed the svc problem, but now my computer and internet connection are lagging. Also, my homepage was changed. Here are all the logs I have
    PS I was unable to start my computer in safemode and counterspy would not let me save the results, it didn't find anything anyways.
    -Thanks for any help need my computer fixed asap for school!
     

    Attached Files:

  2. BrokenComp19

    BrokenComp19 Private E-2

    Here is the shownew file, if you guys need anything else just ask. I am tired of fighting this thing :major !
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run this:
    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    You may wish to uninstall Napster.

    Please copy the text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new:
    GetRunKeys
    NewFiles
    HJT
     
  4. BrokenComp19

    BrokenComp19 Private E-2

    Ok I did what you told me to, but did not uninstall napster. If i need to just let me know, here are the new files.
     

    Attached Files:

  5. BrokenComp19

    BrokenComp19 Private E-2

    My computer is running better, but still runs slow and the internet only works sometimes. Also, something tried to change my homepage to msn.com but counterspy stopped it. XoftSpySE found W32.Xabot.Worm on my computer, could this be causing the problem?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Who is the owner of this PC? Does it belong to a company? Or is it for personal use?

    The reasons I ask are the below registry settings. If you set them or a company did, then they may be valid. If not, then these are things the Xabot could do.

    You should also uninstall CounterSpy since you cannot fix anything with it anyway (probably expired the trial period) and since you already have Windows Defender installed. This will help speed things up too.

    Everything else is due to all the crap Lenovo/IBM runs at startup. Much of this may not be needed but since it is not malware, that is not a dicussion for this forum.
     
  7. BrokenComp19

    BrokenComp19 Private E-2

    It is a personal computer, but they are given to us by our college. I would assume those entries were installed by the college, b/c they did preinstall certain features. However, I don't know for sure. Also, I have been having difficulty shutting my computer down, it freezes when it is running logoff scripts or whatever.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since it is a college PC setup for their network, you really should take it to their IT department then. If we start changing things that could be malware or it could be things they did, we could mess up your PC for access into your college network. Or if it does not break anything as far as access, they may just get P.O'ed at you for messing with their security settings when they find out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds