having problems....scan results

Discussion in 'Malware Help (A Specialist Will Reply)' started by frenchpea2002, Mar 6, 2006.

  1. frenchpea2002

    frenchpea2002 Private E-2

    I read and ran the "read and run me first" page, and the results from the two online scans are attached. Spybot, Ad Aware, and Mcafee virus scan and stinger showed nothing.

    Here's a brief explination of my problem: My computer "crashed" a few weeks ago and would not go past the "Microsoft Windows XP" screen when booting up, but it wasn't frozen persay, since the blue bar would still scroll. Dell ended up sending me a Windows CD and I ran a repair reinstall, but no programs would work after that. My dad took it to one of his friends who did something and most everything works, only it is still very slow, and a fre program still do not work. I have McAfee Security Center that is kept up to date, but recently (until last night when I did all of the scans) the antivirus would be disabled almost all the time. I haven't run a hijackthis scan yet, since the post says to post the others first.

    Thanks in advance for your help!
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Attach your HijackThis log. The BitDefender Report shows an infected System Restore point; we'll deal with that after we deal with any issues shown by HijackThis.
     
  3. frenchpea2002

    frenchpea2002 Private E-2

    here's the hijack this log. So, what's next? :confused:
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You are running HijackThis directly from the ZIP file. UnZip HijackThis to C:\Program Files\HJT.

    After you have placed HijackThis in its own directory. Scan and fix the following:
    Follow the directions for Running WinPfind by OldTimer.

    Post WinPFind.txt and a fresh HijackThis log,
     
  5. frenchpea2002

    frenchpea2002 Private E-2

    While running WinPFind I got this error:

    "Cannot open file C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare"

    I clicked okay and it essentially froze up, giving me an hourglass. attached is what it scanned so far
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download Blacklight Beta from here:
    http://www.f-secure.com/blacklight/try.shtml
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of log.
     
  7. frenchpea2002

    frenchpea2002 Private E-2

    I ran the scan, but "no hidden items found"

    attached is the log
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Log didn't attach.

    Try running WinPFind again. Do you get the same error?
     
  9. frenchpea2002

    frenchpea2002 Private E-2

    sorry about the attachment, it should be there now. I tried to run the WinP again and I still got the same error
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    Press 'OK'

    The search will run for a while then alert you when it is finished.

    Press 'OK' and copy the contents of the WordPad window and post in this thread
     
  11. frenchpea2002

    frenchpea2002 Private E-2

    it came up with no results, so there's no wordpad to post. The program is still not working and it still takes a really long time to boot up. Should I run another hijackthis scan?
     
  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I don't know what this folder is for;
    "Cannot open file C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare", and can't find any information about it.

    Download ISeeYouXP and place it on your Desktop. {EDIT} Link to ISeeYouXP corrected.

    Reboot to Safe Mode.

    -- Locate ISeeYouXP and DoubleClick it and allow it to run.
    A DOS Window will appear and you may get “file not found” message(s). That’s OK – Just let it run. It may take 10 -15 seconds to finish.

    -- A log should pop up in Notepad. Please save it and attach it to your next post.

    Reboot to Normal Mode.

    Post a frresh HijackThis log and the log from ISeeYouXP.
     
    Last edited: Mar 9, 2006
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SPD,

    Links to ISeeYouXp are never available. For some reason they always delete them after people use them in a particular thread. Bad thing to do but that is what they do!
     
  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Fixed the link, this one works.

    That is very annoying.
     
  15. frenchpea2002

    frenchpea2002 Private E-2

    When I click on the link I get this message:
    Invalid Attachment specified. If you followed a valid link, please notify the administrator
     
  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Sorry, the server that the file is stored on is down right now.

    Follow the steps in the below link and attach the runkeys.txt log to your next message:

    Using GetRunKey
     
    Last edited by a moderator: Mar 12, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds