logs attached.. can someone please look at them. thanks!

Discussion in 'Malware Help (A Specialist Will Reply)' started by srmjdm, Jun 4, 2010.

  1. srmjdm

    srmjdm Private E-2

    Hi! I am working on gateway computer for my cousin. She got the computer several years ago thru PeoplePC. She no longer has service thru PeoplePC. She is wanting to get hooked up to internet thru a local ISP but before doing this she wanted to make sure that the computer is in good working order and clean. She hasn't been using the computer because it runs too slow to do much on and she has recently been encountering a problem with a box popping up that said "Microsoft has encountered a problem..." She did not give me the rest of the error message and I have not had the popup come up while working with her computer. She did say it happened a lot if she was online but not always. I do not have dialup service here at home to hook her computer up to the internet so can not replicate that issue. But I did take her computer thru the read and run me steps just to make sure there were no nasties hiding in her computer.

    Since computer is not connected to internet, I downloaded programs to usb drive and then uploaded them to problem computer.

    1. I deleted Nortons 2003 and anything I could find associated with PeoplePC (as it seemed to take over everything!)

    2. Started by using msconfig to boot in normal mode but doing this made computer boot into safe mode???? Not sure how to correct that and hope it will not make a difference in the logs.

    3. RootRepeal would not run on problem computer. Box came up that said "initializing.... " but would not ever go past this. I had to hard boot the problem computer and went on to the next step.

    Thank you in advance for your help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is primarily because it does not have enough memory to properly run Windows XP. The logs show
    Code:
    Total Physical Memory 256.00 MB 
    Available Physical Memory 156.51 MB 
    This is only 1/4 of the MINIMUM recommended amount for Windows XP especially with an old microprocessor like in this PC. It real need 8 times the amount in it which is 2 GB.

    And this PC is in desparate need of getting Windows properly updated. Is is running Win XP SP1 which is a security risk. It needs a lot of very large updates and doing this via an archaic dialup connection will be extremely difficult. Some one needs to get BroadBand.;)

    In addition it has no protection software installed at this time and when you do install some, it will also add to the slow down especially with inadequate memory available.

    To fix the safe boot mode issue, you need to edit the C:\boot.ini file ( a hidden system file) and you will see the below in this file:
    You need to edit the last line to remove the /safeboot:minimal


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: PeoplePC FixedBandBHO - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\Program Files\ISP40\bin\BandObject.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
    O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP40\hta\station.sbrt
    O4 - HKLM\..\Run: [074FC84A] C:\WINNT\System32\cwobuccbuqyg.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O16 - DPF: {511073AD-BE56-4D43-AE68-93390514385E} (TechToolsActivex.TechTools) - hcp://system/TechTools.CAB
    O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
    O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. srmjdm

    srmjdm Private E-2

    Not enough memory explains the slow performance this computer has had since she got it. I am assuming the memory is upgradable, but thinking she might be better off just purchasing a new one.

    Lacking the connection is it possible to copy the service pack updates to usb drive and then load them onto the problem computer?

    But to finish what I started... the logs are attached.

    Thanks chaslang for all your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but that is a topic for the Software Forum and this will be an ongoing issue with getting updates on a dial-up connection.

    Also note, do not update unless you add more memory first since it will only get slower after updating. And this PC also has no protection software installed which is also a major issue and another reason more memory is needed.


    There are a couple of system files missing. Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  5. srmjdm

    srmjdm Private E-2

    Thanks chaslang.

    I knew I could depend on MajorGeeks!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds