Dell problem...

EWC88

Member
Ok this desktop is probably 3yrs old? But since day one we got it the thing had so many problems! And dell did absouttely nothing about it ( hint why i HATE dell ) but my sister needs a comp and we were thinking lets clean it up and send it out to her (technically it is hers anyways)

I have no idea what to do with it but I'll just lists whats wrong with it.

Runs slow (don't get why its basicaully new cause she never used it since it was messed up all the time)

Always get large amounts of pop ups

I don't know what some unnessicary things are that could be taking of..please list if any..
 
Run a program called CCleaner

Run a Hijackthis log - do a system scan only

Do a defrag of the hard drive

and what OS are you running?? XP i guess being 3 years old???
 
what you mean by post a hijack this log?

And yea its Windows XP thats one the computer...

I have defrag the computer several times, but I'll do it again
 
Well for some reason its not letting me connect on the interent something is up with the IP address...I gotta figure out how I can get her computer to get online now so I can do this...
 
If all else fails, reformat the drive and install a fresh copy of XP. That always helps! :)
 
Ok I got the interent up and running (actaully on her comp rright now) when I click on that link were do I go to d.l it? or run a scan?
 
I don't know if I dont see it but there is nothing on that link you sent that says download, all it says is share and Anti Spy-ware tools and that when you click shows a bunch of stuff and Hijack this is under that, is that what i do?
 
Post a Hijackthis Log

  • Download Hijackthis from here
  • Open Hijackthis
  • Click on "Do a system Scan and Save a Logfile"
  • A notepad window will open
  • Hit (Ctrl + A)
  • Copy (Ctrl + C)
  • Paste (Ctrl + V) in a forum reply

Then we can go from there.
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:56:50 PM, on 07/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1153398350\ee\AOLSoftware.exe
C:\Program Files\BySoft FreeRAM\FreeRAM.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1153398350\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [BySoft FreeRAM] C:\Program Files\BySoft FreeRAM\FreeRAM.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\GetFlash.exe
O4 - HKLM\..\Policies\Explorer\Run: [rdgxzo] C:\WINDOWS\System32\rdgxzo.exe
O4 - HKUS\S-1-5-18\..\Run: [Osfqofg] C:\WINDOWS\System32\t?skmgr.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Osfqofg] C:\WINDOWS\System32\t?skmgr.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 4681 bytes
 
Please be patient.
I will look over the logfile.
If anything needs to be fixed i will give instructions in my next reply. :)
 
Ok I'll be patient take your time!

Just let me know whenever what the heck to do to fix this junk

Hello:
Your HiJackThis log had no indication of any infections or traces or malware.
However i do have a few instructions for you.
First of all since HiJackThis didn't show anything ComboFix just mite.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

After you have finished running ComboFix.exe please do the following:

Found a suspicious file...

Please go to Virus Total or Jotti and upload
C:\Program Files\BySoft FreeRAM\FreeRAM.exe
and
C:\WINDOWS\System32\rdgxzo.exe
for scanning.

Please make sure to only upload one file to one site at one time.

For Virus Total

  1. Please copy and paste
    C:\Program Files\BySoft FreeRAM\FreeRAM.exe
    and
    C:\WINDOWS\System32\rdgxzo.exe
    in the text box next to the Browse button.
  2. Click on Send File.

For Jotti

  1. Please copy and paste
    C:\Program Files\BySoft FreeRAM\FreeRAM.exe
    and
    C:\WINDOWS\System32\rdgxzo.exe
    in the text box next to the Browse button.
  2. Click on Submit.

Once those files have finished scanning please post the results here for a professional to look over them.
 
When I did the combo fix thing, something popped up saying that something could happen to my computer and that 1/100 comp made it with out getting screwed up...so I stopped it, but was that right?
 
When I did the combo fix thing, something popped up saying that something could happen to my computer and that 1/100 comp made it with out getting screwed up...so I stopped it, but was that right?

Actually it should have said: "1/100 computers fail to complete this process click ok to continue" You should click okay or yes whatever it is to continue. I've never had a computer fail to complete the scan, the only time something happens is if you use a script. I'm just telling you to run it and go to virus total and jotti. Please complete my instructions as provided.
 
Back
Top