please help...logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shanrene123, Jan 20, 2007.

  1. shanrene123

    shanrene123 Private First Class

    I'm working on my friend's pc, who said it "crashed" when trying to set up a new desktop/"user account". Running Win XP SP2 & PC is a Dell Dimension 2400. Haven't been able to get Norton's 2003 all the way off, even using Norton's Removal Tools, & in fact, Symantec interfered with running both the GetRunKey & ShowNew scans, but I just clicked "ignore" & think they worked. Anyway, decided this PC was infected when AdAware found tons of "Criticals" & Spybot kept finding things that couldn't be fixed, even with it running on boot up with a restart. Having trouble getting online as well, & networking has been troublesome. It will not "automatically detect settings" at all & have to go in & manually enter IP address, default gateway, etc... This is the only PC we've ever had to do that with when working with this Belkin router & cable modem. System tray network icon said I was connected, but IE 7 (yuck!) wouldn't find a web page, so I changed to Mozilla Firefox as my default browser & was finally able to get online. Pretty sure that all of the scans I've ran (per sticky thread) found infected items, incl. registry keys. I've attached all my log files, as instructed in sticky thread. Can anyone help?confused Thanks! Shannon
     

    Attached Files:

  2. shanrene123

    shanrene123 Private First Class

    Here's rest of logfiles. Thanks:) !
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run Counterspy and have it remove/quarantine all the items that it finds.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Attach new logs from:
    GetRunKeys
    NewFiles
    HJT

    Please tell us how things are running!
     
  4. shanrene123

    shanrene123 Private First Class

    Ok, Tim. I did as you instructed and new logfiles are attached -- the 3 you requested. When I boot into normal mode, with normal startup checked in "run/miscofig", I get "Windows Installer" searching for a CD to install something & cannot get this window to close, either by the X or "Cancel", & have to End Task with Control/Alt/Delete. It's rather aggravating. Any ideas about what this is about? I'm assuming I need to keep the "Windows Installer" program itself. Anyway, here are my new logfiles after running Counterspy & quarantining it's findings & after fixing items you listed in HJT. Thanks! :) Shannon
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Spybot - Search & Destroy 1.3 is more than two years out of date. You should update it ASAP.

    As to your installation pop-ups you may want to see if this Windows Installer CleanUp Utility finds any problems!

    Otherwise your logs are clean and you may uninstall any programs that we had you download for the analysis.

     
  6. shanrene123

    shanrene123 Private First Class

    Ok, thanks Tim;) ! Spybot has been updated to latest version. Windows Installer CleanUp Utility took care of other issues. I have set up the desktops/user acct's my friend wants. Glad log's were all clean now:cool ! All seems to be running well. Thanks so much for your time & your help!
    :major Shannon
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem ...safe surfing!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds