Need help with computer, possible virus and slowness

johnb35

Administrator
Staff member
The hidden administrator account will appear in safe mode, so you are fine. When you created the new account did you give yourself adminstrator privileges?
 

johnb35

Administrator
Staff member
What happens when you try to install hijackthis, what is the exact error message you get? Can you browse the internet? If so please go here and download it from their computer.

http://free.antivirus.com/hijackthis/

Click the blue "installer" link under version 2.04 and try installing it and tell me what happens.
 

TryingToProve

New Member
I tried to click "here" in your post that you posted for the Hijackthis and when I do a blank screen pops up and nothing happens. So I went to download.com & downloaded it from there & an error pops up that says the systems administrator has set policies to prevent this installation...and does not let me do it.

I am at MY house now next door. I cannot go back to my parents house until tomorrow (my daughter is asleep and my husband is working).

Do you think since I tried to download it from download.com and it did NOT work that it would work on the link you just provided me? Also, yes I can browse then internet ONLY in safemode. If I am not in safemode there is just no way. It is way too slow.

I unplugged my parents computer before I left just in case. So what do you recommend I do tomorrow?? Thank you so much again John. You are just so nice.
 
Last edited:

johnb35

Administrator
Staff member
I understand now. On the "here" link you need to right click on it and click on "open in new window" Then it should work correctly.
 

TryingToProve

New Member
Okay what if it does not work then what do I do? Because It did pop up when I went to download.com and downloaded it, but when it finished that the systems administrator has set policies to prevent this installation message popped up.
 

johnb35

Administrator
Staff member
If for some reason Malwarebytes will not install or run please download and run Rkill.scr, Rkill.exe, or Rkill.com but DO NOT reboot the system and then try installing or running Malwarebytes. If Rkill (which is a black box) appears and then disappears right away or you get a message saying rkill is infected, keep trying to run rkill until it over powers the infection and temporarily kills it. Once a log appears on the screen, you can try running malwarebytes or downloading other programs.
That procedure also pertains to hijackthis, its possible you are still infected and the malware is stopping hijackthis from installing/running, so follow the procedure and let me know what happens. There will be a log that pops up on the screen after rkill runs. If you could please save the log and post in a reply so i can see it.
 

johnb35

Administrator
Staff member
Try doing hijackthis without running rkill first. But I think you should be able to run it ok without it.
 

TryingToProve

New Member
Okay thank you so much. Have you heard of this virus before? A hello4 box kept popping up when I started XP normally. Then I did cntrl alt delete and went to processes and OMG there was so much there, it was crazy!
 

johnb35

Administrator
Staff member
I can't say I have personally, but there are anywhere from 5 to 10 new malware created daily. This may take some time to get cleaned up so please bare with me and be patient.
 

TryingToProve

New Member
I tried to open it in a new window and it did open, but again it wouldnt run, it said the administrator set policies to not allow it.

OKay I went and click that free virus link you showed me last night. I did the executable one and here is that log file.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:00:04 AM, on 5/6/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WREI8WLX\HijackThis[1].exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {047B5C1F-D6B8-4C71-8546-58D11EEF1A96} - C:\WINDOWS\system32\authz32.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110102062528.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: ShopAtHomeIEHelper - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: ShopAtHome Toolbar - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe
O4 - HKLM\..\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [psoluuekbq] rundll32 "C:\WINDOWS\system32\cliconfg8.dll",Tommb
O4 - HKUS\S-1-5-18\..\Run: [R8388QA8U8] C:\WINDOWS\TEMP\Chh.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [R8388QA8U8] C:\WINDOWS\TEMP\Chh.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe

--
End of file - 8157 bytes
 

johnb35

Administrator
Staff member
This machine is still severely infected. You must run a deeper scan using combofix. However, Mcafee is installed and would need to be disabled before running it. It may be simpler to uninstall Mcafee and then we can install a better virus program after we are done.

You will need to download the following program and since you are having problems clicking on file download links I will post links to the website and then you can click on the download link.

http://www.bleepingcomputer.com/download/anti-virus/combofix

You will see a page like this.



click on the bleepingcomputer mirror link then download the file to the desktop and then run it. Again, Mcafee would need to be totally disabled or uninstalled before running because it interferes with the running of combofix.

The scan may take a 20 minutes or more if the machine is badly infected. If it says there is rootkit activity and needs to restart the system, please let it do so. There will be a log that will pop up when its done running. I need to see that log. Afterwards, please run a fresh hijackthis log and post it as well.
 

Attachments

  • combofix.jpg
    combofix.jpg
    96.5 KB · Views: 45

TryingToProve

New Member
It says I cannot rename combofix to combofix 1 and wont run. My computer does that loud beep like it is going to, then I get that box saying what I just said in teh first sentence.
 

johnb35

Administrator
Staff member
When you download the file save it as kittyfix and then run it. Also if you have the file combofx already on the desktop, please delete it.
 

TryingToProve

New Member
I saved it as combofix7 haha. Anyways it had to restart because of a rootkit so I restarted it in safemode and its running now. I had to leave to my put my daughter to sleep, But it is still running at their house on their computer in safemode.
 

johnb35

Administrator
Staff member
ok. If it restarted the pc then it detected rootkit activity. Can you tell me the specs of the system like what processor is installed and how much system memory is installed? If you right click on "my computer" and click on properties, the system properties page will come up. Look on the general tab about halfway down under where it says computer, it will list cpu and how much system memory it has. This will let me know if its possible they have a slower system.

Just a note here though. Even if we can get this system cleaned up, the damage may still be there and the only way to get the system back up to speed is to reinstall the operating system.
 

TryingToProve

New Member
I understand. I can tell you they have windows XP. That is all I know right now since I am not there, but as soon as my daughter wakes up, I am heading over there. I am waking her about in 1-2 hours & I will post as soon as I get over there and tell you all of this. I know its a compaq.
 

johnb35

Administrator
Staff member
I may or may not be home when you reply again, i have some errands to run, but I will be back on later. Try to get me the model number of the pc if you can, should be listed on a sticker somewhere on the pc either on the front or side of the case.
 
Top