ChiefsPlanet

ChiefsPlanet (https://chiefsplanet.com/BB/index.php)
-   Media Center (https://chiefsplanet.com/BB/forumdisplay.php?f=2)
-   -   Computers The Official Malware/Antivirus Thread - Need help or general advice? Read this first! (https://chiefsplanet.com/BB/showthread.php?t=232173)

Hays 05-29-2012 09:40 AM

typically when i get this i go into
control panel
internet options
advanced
and click the reset button. It usually lets it start working.

thecoffeeguy 05-29-2012 10:11 AM

Quote:

Originally Posted by Buck (Post 8639100)
I'm having a hell of a time with something redirecting me on clicked links from google searches. I can't find it with anything.

Post a hijack this log so we can take a look...

Lzen 06-21-2012 09:21 PM

HELP
 
C:\Program Files\HitmanPro\hmpsched.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Zune\ZuneBusEnum.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\WSED\WSED.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\Chad\LOCALS~1\Temp\Temporary Directory 1 for rogueremoval.zip\HiJack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - http://support.dell.com/systemprofil...SystemLite.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: Mobile Broadband Core Service (WMCoreService) - Unknown owner - C:\Program Files\Dell\Dell WWAN\WMCore\WMCore.exe

--
End of file - 6152 bytes

Bearcat 06-22-2012 09:11 AM

Lzen, I don't see anything out of the ordinary.

What are the symptoms? Did you run HiJack this and malwarebytes in Safe Mode? Have any of the scans picked up anything?

Lzen 06-22-2012 04:48 PM

This is my kids' laptop. Something shut off Avast. I think they had to select allow for that to happen because Avast doesn't let crap like that in.Also, several keys on the keyboard aren't working.

Fish 06-22-2012 06:38 PM

Hmmm. Can you turn Avast back on and does it stay on?

I can't see how any virus or malware would disable any keys. I don't see how that's possible.

Lzen 06-22-2012 08:41 PM

Can't turn avast on and can't uninstall it.

Fish 06-22-2012 08:53 PM

What happens when you try? Error messages? Did you try in Safe Mode?

chasedude 06-23-2012 12:17 AM

You might want to run an error check on her hard drive, just to help rule out it causing your problems

Open Up "My Computer" and right click on the hard drive... choose properties. (it's usually the last choice)

You should see a new window popup with multiple tabs to click on, click on the Tools Tab.

Now you should see a button that says "Error Checking", click on it.

A new smaller window will popup, choose both options... auto check system errors and recover bad sectors. Now click start.

Depending on the size of her HD and the resources available, it might take a while. Start it before you go to bed and hopefully it'll be done by the time you wake.

The guys above have gave good advice, I thought this would help at least to see if the HD was causing problems.

Lzen 06-25-2012 07:47 AM

Ok, I have narrowed down that the keyboard issue is a bad keyboard. A USB keyboard works fine. I ordered a new one and it shouldn't be too difficult to replace.

But the whole thing with Avast is weird. It had some kind of malicious software that shut down Avast. Even after I ran everything according to this thread and got rid of the crap, Avast would not work. It won't work in safe mode, either. And I can't uninstall it and reinstall it. I'm using AVG now, but I prefer Avast.

BTW, I think the keyboard issue timing was just a coincidence.

Fish 06-25-2012 07:55 AM

Quote:

Originally Posted by Lzen (Post 8700012)
Ok, I have narrowed down that the keyboard issue is a bad keyboard. A USB keyboard works fine. I ordered a new one and it shouldn't be too difficult to replace.

But the whole thing with Avast is weird. It had some kind of malicious software that shut down Avast. Even after I ran everything according to this thread and got rid of the crap, Avast would not work. It won't work in safe mode, either. And I can't uninstall it and reinstall it. I'm using AVG now, but I prefer Avast.

BTW, I think the keyboard issue timing was just a coincidence.

From the sounds of it, Avast imploded. I've seen it happen before, and it had nothing to do with any malicious software.

Try the Avast uninstall utility: http://www.avast.com/uninstall-utility

That will let you remove it and reinstall it from scratch...

Lzen 06-25-2012 08:38 AM

Quote:

Originally Posted by KC Fish (Post 8700016)
From the sounds of it, Avast imploded. I've seen it happen before, and it had nothing to do with any malicious software.

Try the Avast uninstall utility: http://www.avast.com/uninstall-utility

That will let you remove it and reinstall it from scratch...

Ok, thanks. I'll try that.

Lzen 06-25-2012 10:08 AM

That worked. Thanks Fish.

Mr. Plow 06-25-2012 07:08 PM

Quote:

Originally Posted by Lzen (Post 8700174)
That worked. Thanks Fish.


We just can't let you have anything to play with, can we?


:evil:

Lzen 06-26-2012 10:00 AM

Quote:

Originally Posted by Mr. Plow (Post 8701175)
We just can't let you have anything to play with, can we?


:evil:

Hey, it wasn't me. It's my kids' laptop that always has crap happening to it. My laptop is fine. :thumb:


All times are GMT -6. The time now is 09:24 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.