System HiJacked...blank screen...scan logs attached - Help Plz

Discussion in 'Malware Help (A Specialist Will Reply)' started by toclark2, Aug 26, 2005.

  1. toclark2

    toclark2 Private E-2

    I've run the requisite initial scans in safe mode and then when they were not successful I ran the HiJackthis to take a snapshot of whats on my system.

    Symptoms: No explorer/start menu, no wallpaper, all applications going thru taskmgr manually.

    Anything you can do is greatly appreciated.

    Edit by chaslang: Unrequested inline log removed. Please do not post any HJT logs unless they are requested. Also do not post both inline and attached forms or the log.
     

    Attached Files:

    Last edited by a moderator: Aug 26, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have multiple antivirus applications installed (Kav and AVG). You must pick the one you prefer and uninstall the other. Do this before continuing.

    Also please install HijackThis properly per our sticky thread instructions. You have it on your desktop:
    C:\Documents and Settings\ToddJune\Desktop\SpyKiller\HijackThis.exe

    Also go to Add/Remove programs and uninstall:
    P2P Networking or P2P Networking
    P2P Networking3
    ViewMgr or Viewpoint or Viewpoint Manager <--- I'm assuming you do not use or need this junk from AOL. Most people do not.

    Do you know what this process is: C:\WINDOWS\System32\CNDNDlg.exe

    There are 2 registry keys that sometimes cause this problem with explorer.exe not loading. We are going to look for and delete these keys (if found).

    Press CTRL-ALT-DEL to bring up Task Manager. And click File, New Task (Run..) and enter regedit and click OK. This will run the registry editor. Now look for the below registry keys (navigate thru the registry). Make sure you only look for and delete the exact keys listed below.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplorer.exe

    After deleting this keys the desktop and explorer.exe may reappear if this is your particular problem. There are many forms of problems with explorer.exe not loading at startup. You may need to reboot after doing this. Let me know the results.

    Have HJT fix the below lines and then post a new HJT log:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
     
    Last edited: Aug 29, 2005
  3. toclark2

    toclark2 Private E-2

    Here is the new HJT log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please provide answers to all my questions and feedback on the results and where things stand as requested.

    I also still see:
    O4 - HKLM\..\Run: [P2P Networking2] C:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART
     
  5. toclark2

    toclark2 Private E-2

    AVG Selected

    HJT uninstalled...resinstalled at C:/Program Files/HJT/HijackThis.exe

    Removed all P2P and ViewMgr references in HJT.

    Yes - it is a Canon digital photography software utility file.

    Also removed MS-PhotoDraw lines with HJT.

    Neither .exe files or anything similar were present in the specified registry location.

    HJT fixed the specified lines in the primary response for help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok! So it still looks like explorer.exe is not loading at startup.

    Does c:\windows\explorer.exe exist?

    If you run it from Task Manager's, File, New Task(Run...) option, does it run and bring back your Desktop.

    Do you have a c:\windows\i386 or a c:\i386 folder?
     
  7. toclark2

    toclark2 Private E-2

    Yes, I have a explorer.exe

    When I have taskmgr run it - it disappears, I see the cpu take a hit in % used, but then nothing happens.

    No, I have neither folder.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your original Windows XP cd? If so look on it. There should be an i386 folder on it. In this folder there should be an explorer.ex_ (yes it ends with an underscore. It is a compressed file.)

    See if you can find this file.

    Also see if you can open a command prompt from Task Manager but enterind cmd into New Task (Run...)

    Let me know.
     
  9. toclark2

    toclark2 Private E-2

    Found it...folder i386

    Yes I can get the DOS prompt using cmd thru taskmgr
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where did you find i386? On the CD I assume?

    What is the drive letter of your CD drive? I assumed drive D in the steps below.

    In the command prompt Window enter the below commands each followed by the enter key:
    cd c:\Windows
    copy explorer.exe explorer.old
    expand D:\i386\explorer.ex_ explorer.exe

    If you get a message about overwriting an existing file just say OK.

    explorer <---- hopefully this causes your Desktop and icons to come back.


    Let me know.
     
  11. toclark2

    toclark2 Private E-2

    Correct

    No message

    I expanded the file it seemed to be happy no error messages. I rebooted and there is nothing changed...I went back to C:\windows to see if the \i386 was there and its not.

    I might have mis-understood this line. Is this a cmd to execute the explorer while I was at c:\windows location?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There was not suppose to be an i386 folder in c:\windows
    All we did was get a new copy of explorer.exe from your CD into the c:\windows folder.

    Yes that last line was a command to startup explorer. All you need to enter is explorer the .exe extension is not necessary.

    But if you still have a problem after rebooting, running the explorer command would not have helped. anyway (at least I doubt it).

    Does the same problem exist in safe mode?

    Do you have other user accounts on this PC? If so, does it happen on those accounts too?

    Check this link out: Taskbar Is Missing When You Log On to Windows
     
  13. toclark2

    toclark2 Private E-2

    I am working my way thru the MS-Clean boot process.

    I have determined that it functioned properly after booting in safe-mode and wiping the msconfig general tabs out...proc sys.ini.

    However, after rechecking the proc win.ini its stuck on winxp prof loading screen going on 10mins...I'm try to make sure it has all the time it needs.

    So whatever the problem its in there...not through reading carefully to see whether MS will take me to the next steps...
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean, after you used Selective Startup and unselected the options for the below:
    Process System.ini File
    Process WIn.ini File
    Load Startup Items

    that it booted up OK? What did you do with System Services at this point where it booted okay? And by saying " functioned properly" did you mean your Desktop and icons showed up and thus explorer.exe was running?

    And then you went back and rebooted but this time allowed Win.ini to load and now it will not boot????

    Post as attachments, copies of your win.ini and system.ini files (they are in your c:\windows folder).

    I'm starting to wonder if any of your problems are due to the way this PC got WinXP on it. It looks like you upgrade the PC to WinXP from an older OS. Is that true? This is not always a very graceful thing to do.
     
  15. toclark2

    toclark2 Private E-2

    Yes, I completed the MS-Clean Boot process. The desktop returned after the 1st clean boot and remained thru the re-enabling of services one at a time. Until I got to start-up and then the desktop disappeared again.

    So went to start-up and I found four files that looked bogus and so I disabled them and rebooted. No luck, still no desktop.
    - Point manager.exe -s
    - msmsgs.exe (MS IM annoying)
    - P2P Networking.exe /autostart
    - P2P Networking2.exe /autostart

    I sent the last note prior to the WIN_XP loading. After each service was enabled the WIN_XP load took 30 mins to complete. I believed WIN_XP to be hung in my last memo, but that was not the case. It loaded after an extremely long time and the desktop was visible. Until I got to the start-up service.

    If I remember I did upgrade to WIN_XP from WIN_2K...

    The upload feature won't let me add a .ini file do you still needed them?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you just let Win.ini, System.Ini and all services run (no Startups), does your Desktop work properly?

    Point Manager could be this: http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.topsearch.html

    You should look for an uninstall in Add/Remove programs and also see what the above link says about removing this.

    If you look back at earlier messages you will see I had you uninstall P2P Networking stuff and fix lines with HJT. I'm not sure why they would still be showing in Startup since we already removed the,.

    You did note post your win.ini and system.ini files as requested.

    Also do the below:

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     
  17. toclark2

    toclark2 Private E-2

    I just rebooted after disabling the start-ups service...still no desktop...I have not gone back and repeated the disable everything and then work forward again as that will (by example last night) take several hours...
    I'm not sure how to evade the geeks site file extension filter. When I attempt to upload the ini's it gets rejected as invalid extension.
    There is no reference in add/remove program to point manager.exe

    I did previously remove the P2P using the HJT app by clicking on the boxes and 'fix'...this is the first I've seen of the P2P since.

    Just to confirm the (to answer the obvious question: am I runnging a P2P apps: no)only apps I'm running are MS-Office, geek specified tools/utils & Iexplorer...so even though I had a p2p solution installed I've removed it in preliminary stages of the fix process.

    Startlist log attached.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can make copies of the files in another folder and rename them to have a .txt file extension or you could put both of them into a ZIP file and upload the zip file.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just disable leave all Startups disabled and all Services disable. Do you get a Desktop now?

    If not, add to that by disabling System.ini. Do you get a Desktop now?
     
  20. toclark2

    toclark2 Private E-2

    Disabled All - Desktop = Yes (no net)
    Sys.ini - Desktop = Yes (no net)
    Sys + Win.ini - Desktop = Yes (no net)
    Sys + Win.ini + Sys.srv - Desktop = No (connected)
    All enabled - Desktop = No (connected)

    How do I connect manually to the net?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With you system set to load all runt the below tools and post their logs:


    Download RunKeys and unzip it to your desktop. Then doubleclick to run it. It will generate a text file. Attach the text file to your next message.

    Now download SilentRunners and save it to your desktop. Doubleclick it to run it. You may have to disable script blocking if your antivirus interferes. It will create a text file on your desktop. Also attach this text file into your next message.

    Download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad file as an attachment too. Call it service.txt.
     
  22. toclark2

    toclark2 Private E-2

    RunSilent log
    GetServices log
     

    Attached Files:

  23. toclark2

    toclark2 Private E-2

    Startup Program log attached
     

    Attached Files:

  24. toclark2

    toclark2 Private E-2

    MISTAKE...I reread your note and I did not follow the part about resetting all to enabled...sorry
     
  25. toclark2

    toclark2 Private E-2

    K...here are the logs with all services enabled.
     

    Attached Files:

  26. toclark2

    toclark2 Private E-2

    Part II
     
  27. toclark2

    toclark2 Private E-2

    Part IIa (picky uploader)
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still looks to me like msconfig is limiting something! Is see the below in the logs:


    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

    This means msconfig is still running and restricting something.

    Let's try this!

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixSU.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixSU.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
    I'm also seeing the below which was not here before.
    "nod32kui" = "C:\Program Files\Eset\nod32kui.exe /WAITSERVICE" [file not found]

    Did you for some reason install NOD Antivirus?? Why? You aready had an AV installed and you must use only one. If you installed this, uninstall it.

    I also still see these:
    "P2P Networking2" = "C:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART" [file not found]
    "P2P Networking" = "C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART" [file not found]
    "AltnetPointsManager" = "c:\program files\altnet\points manager\points manager.exe -s" [file not found]

    Let's fix these too:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixAuto.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixAuto.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
    Now look for the below with Windows Explorer and delete them if found:
    C:\WINDOWS\System32\P2P Networking <-- the whole folder
    c:\program files\altnet\points manager <-- the whole folder


    Now reboot. And then rerun the three tools.
     
    Last edited: Aug 31, 2005
  29. toclark2

    toclark2 Private E-2

    Both reg edits successfully entered

    No, I didn't 'just' install it, it was a trial virus scanner I ran along time ago...didn't occur to me when I uninstalled the duplicate virus scanner. I just uninstalled it.

    These are clearly part of the issue...I know I've killed these before...

    There are no such folders...however there are a couple of files which are fishy in system32.
    -p2p.dll
    -p2pgasvc.dll
    -p2pGraph.dll
    -p2pnetsh.dll
    -p2psvc.dll

    Funny I located find.exe in the system32 folder and it just flashed on screen and terminated...? Not sure how else to search for the p2p folders if they're not in a top level windows sub-directory...

    Rebooting will post when done in a few...
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay if there is no uninstall for NOD we need to do another registry patch:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixNOD.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixNOD.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes


    And look for the below folder and delete it if found:
    C:\Program Files\Eset
     
  31. toclark2

    toclark2 Private E-2

    Latest logs...it appears our friends p2p are back...there must be a folder somewhere on my system...
     

    Attached Files:

  32. toclark2

    toclark2 Private E-2

    There's an odd occurence happening when I try to upload the getservice file...

    When I attempt to upload it the Geek app tells me its already been uploaded and rejects upload attempt. So whats funny is that I have renamed, resaved three times and each time it says its already been uploaded to the site.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably because the contents are exactly the same and it is checking the file by a CRC or similar method.

    Is your System Restore disabled? Double check!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see any P2P stuff. What are you referring too?

    It's strange that the below show up! Normally the minus sign cause the keys to be deleted.

    "MSConfig"="-"
    "nod32kui"="-"

    Try the below again. Make sure you copy this one because I changed some spacing in the text
     
  35. toclark2

    toclark2 Private E-2

    The procedure entry point RemoteAssistancePrepareSystemRestore could not be located in the dynamic link library WINSTA.dll
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    For the System Restore message, see: http://support.microsoft.com/?kbid=832323

    Did you do what I requested in my last message?

    Please answer my question about the P2P stuff?
     
  37. toclark2

    toclark2 Private E-2

    Okay, thanks for the sys restore fix link.
    Yes, I edited the registry copying and pasting exactly how you posted it. The registry editor indicated that the registry was successfully updated.

    p2p reference was related to my noticing p2p instances on an iteration of one of the log sequences (I dont remember which) that we've been running after editing the registry. I remember clearly thinking "they're still here"<insert:poltergeist scene/quote> ...and so incorrectly assumed they would still be there after running that last registry edit.

    Specifically, in between the 1:44 and 2:07 log uploads. I ran the process based on your 00:27 post and I saw the alledged p2p instances. Then I noticed your 1:47 update regarding eliminating the NOD32 lines. So rather than upload the logs I had just run, I reran the apps and generated fresh logs and posted them at 2:07.

    I'm not sure what happened to the p2p instances. I don't see them anymore either. It's possible that I had an earlier log still up on my screen (hard to believe with constant reboots) and saw something we had already fixed...
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! We have eliminated some items from loading at startup. But for some reason the below two items:
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSConfig" = "-"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "nod32kui" = "-"

    Just will not go away completely (like the P2P stuff did when we used the same patch). This is not a major concern right now since as the keys appear, they are doing nothing.

    So the question now remains what mode are you in right now? I assume the mode is that no msconfig is being used and that ALL items are being loaded. But what is the Desktop status. If there is no Desktop, we need to try to identify what Service is causing the Desktop issue because the Desktop problem appeard only when you allowed all services.
     
  39. toclark2

    toclark2 Private E-2

    I retried editing the registry copying and pasting the { = "-"} only from the other lines that worked. My thinking was maybe a dash/minus keys were different somehow...no luck they're still in the start-up.

    Confirmed msconfig=normal mode all items are being loaded and no desktop.

    I just rebooted after disabling system restore (apologies...I thought it was off)

    Latest logs attached
     

    Attached Files:

  40. toclark2

    toclark2 Private E-2

    Part 2 will not upload getservice file...? sys restore is off and rebooted since...
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's not what you would want to do with regedit. What you would want to do is delete the
    MSConfig andnod32kui entries .

    Try using msconfig and just go to the Services tab and select Hide all Microsoft Services. Then select Disable All . This will disable all non MS services. Let's see what affect this has.
     
  42. toclark2

    toclark2 Private E-2

    Last night reran some tools
    - CWShredder - removed CWS.msconfig
    - HSRemove - 8 items removed no log(?)..
    - Kill2Me - removed Look2Me infection
    - McAffee Stinger - all clean
    - AdAware - removed 15 garden variety MRUs

    1) Hid MS-Services, disabled all remaining.
    2) Rebooted Desktop returned.
    3) Uninstalled all non-MS services that were disabled.
    * StopZilla (pop-up blocker)
    * Ewido - Security Guard
    * AVG - Alert Mgr
    * AVG - Update Service
    * Sandra - Data Services
    * Sandra - Service
    4) Set msconfig to normal, rebooted Desktop returned.
    5) Logs run and attached.
     

    Attached Files:

  43. toclark2

    toclark2 Private E-2

    Start-Up Log.

    I only see one now, is the "-" gonna cause problems ??
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you notice all the bad stuff that is back?

    Post a new HJT log?

    What was that Sandra Service for? I wonder if it was a cause for explorer.exe not loading.

    On the other hand, I also wonder if the problem is that your explorer.exe file is actually infected and AVG may have been stopping it from loading. And now that AVG is gone, explorer will run but because it does run, the infections come back.

    You should connect to the below site and use the browse button to locate your explorer.exe file and have this site use a whole bunch of scanners to test your explorer.exe file. Let me know the results.

    http://www.virustotal.com/flash/virustotal_en.html
     
  45. toclark2

    toclark2 Private E-2

    <frown> No, but now I see them...P2P is back..$%^&*(!@#

    attached
    It was a app that I was experimenting with to help with tweaking performance out this pc..256mb ram...its not missed.
    Will do.

    Also just installed ZoneAlarm Firewall, I was told once upon a time if you had a wireless hub that you didn't need a firewall...

    I also re-installed AVG I didn't want to be exposed if I could help it. rebooted with both AVG and ZoneA with desktop coming up.
     
  46. toclark2

    toclark2 Private E-2

    forgot attachment
     

    Attached Files:

  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Is System Restore still disabled? And have you run that scan yet. Also do the below:

    Click Search and the Select "All files and folders"
    Enter explorer in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    Let me know the fullpath to all matches that are found.


    By the way, a software firewall should always be used even if you have a router with a firewall.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: Do not run hsremove anymore (or about:buster if you are) you do not need them.

    Comments/questions (make sure you answer all questions):
    C:\Documents and Settings\Marisa\My Documents\My Webs\_private\aim.exe <--- Why do you have aim here? This is not a normal installation.
    C:\Program Files\Mozilla Firefox\firefox.exe <--- should not be running when using HJT
    C:\WINDOWS\system32\taskmgr.exe <--- should not be running when using HJT. At least not now since your Desktop is ok.


    I thought you said you uninstalled Stopzilla???

    Do you have other user accounts on this PC?
    Have you been using them?

    Goto Add/Remove programs and uninstall if found:
    P2P Networking
    P2P Networking2
    P2P Networking3
    zangoclient or Zango or 180Solutions or N-Case
    SearchUpgrader


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [nod32kui] -
    O4 - HKLM\..\Run: [DXDllRegExe] C:\WINDOWS\System32\dxdllreg.exe
    O4 - HKLM\..\Run: [mdU2KW6e] C:\WINDOWS\wmyps.exe
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [P2P Networking2] C:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART
    O4 - HKLM\..\Run: [P2P Networking3] C:\WINDOWS\System32\P2P Networking\P2P Networking3.exe /AUTOSTART
    O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
    O4 - HKLM\..\Run: [zanu] c:\program files\zangoclient\zanu.exe

    Is the below line valid?
    O4 - HKCU\..\Run: [Spanish] C:\Documents and Settings\Marisa\Learn To Speak Japanese Demo V2.9\Study Conversation.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\wmyps.exe
    C:\WINDOWS\System32\P2P Networking <--- the whole folder
    C:\Program Files\Common files\SearchUpgrader <--- the whole folder
    c:\program files\zangoclient <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings ( Make sure you use www.majorgeeks.com for now while we are working your problems):
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  49. toclark2

    toclark2 Private E-2

    Confirmed Disabled

    I have 4 accounts on this system. Cameron, Marisa, ToddJune and Quantum. The search turned up around 40-50 lines. I tried to screen capture the search window to paste to a doc and upload, but its 200kb and your site rejected it for being greater than 97kb.

    explorer.exe total virus scan results attached.
     

    Attached Files:

  50. toclark2

    toclark2 Private E-2

    I screwed this up...

    I apologize for not making this any easier on you. I really do appreciate your time on this.

    I was in a hurry-head state (too much going on) and used HJT to pick off the obivious P2P, Zango...stuff. Only then did I get down to your express instructions to do this after killing any browsers.... So I rebooted from there.

    I'm starting again from the top of the page...just in case...I have taken a HJT snapshot of where I am now as a reference point.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds