Problems with an Old WINME computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by martinacan, Mar 14, 2007.

  1. martinacan

    martinacan Private E-2

    Hi I am having some problems with my old computer.
    The operating system is WIN ME
    The problem occurs when I close Internet explorer (Version 6.0.2800.1106). The program will hang for about 45 seconds, then the computer will start working again.

    I followed the instructions to remove malware.
    When using the "Super AntiSpyware", no spy ware was found

    I do see that some Trojans were found
    Can someone please advise on a cure?
    Thanks
    Martin
     

    Attached Files:

    Last edited: Mar 14, 2007
  2. martinacan

    martinacan Private E-2

    The last file that I have to upload
     

    Attached Files:

  3. martinacan

    martinacan Private E-2

    I forgot the Bitdefender report
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note that you problems may not be completely due to malware. Windows ME is just a poor excuse for an operating system and it gets worse over a period of time. Often the best fix is a reinstall but you will still have a flaky OS.
    However let's fix what I do see and then you can tell me if it helped at all.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\PROGRAM FILES\SVA PLAYER\SVAPLAYER.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SVAPlayer] C:\Program Files\SVA Player\SVAPLAYER.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Application Data\tvmknwrd.dll
    C:\Program Files\SVA Player <--- the whole folder


    Now run Ccleaner

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  5. martinacan

    martinacan Private E-2

    I followed the instructions - no problems were experienced
    Internet explorer is working normal now. I can close the program down & the computer does not lock up anymore
    Boy you are good at solving malware problems!!!

    The requested files are attached:
    Thank you once again
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Those logs look okay but I requested logs from ShowNew and HJT. I still need to see the HJT log.
     
  7. martinacan

    martinacan Private E-2

    Sorry
    I sent the wrong file by mistake
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds