Welcome! Register for a free account (or login) > How does it work?
|
|


Oct 17 2008, 10:15 PM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 2 Joined: 17-October 08 Member No.: 82,003 Operating System: Windows XP Professional Version 2002 Service Pack 3 |
Hi. I've been following several member's threads and studied how to do all this removal processes and getting guidance from those who knows better and so here's my 1st-timer shot and I do hope I can get someone if not many people, to help me to somewhat remove whatever that's causing all these problems.
Description in detail what problems my notebook is currently facing: 1. I've been downloading a few one too many MP3 songs from Ares as well as music video clips and etc.; altho technically I've had people telling me that the chances of us getting all this trojans and viruses and what not from each download is very high - but then again, I heard that, THAT only occurs when you download naughty things and stuffs - well my downloads was somewhat purely need not to be 18yo ++ to download. Anyways, I've been downloading for quite sometimes and had no problems so far whatsoever - not until last night/ yesterday 2. My notebook starts to slow down - my Firefox keeps on crashing automatically - as far as am concerned, I haven't installed anything that might have caused my notebook to get all slow and all. 3. I always do daily notebook clean-ups with TuneUp Utilities from A to Z as well as using the CCleaner service and normally it clears out everything and everything will be back to normal. But this time around, it's not working. Cleaning the registry can't seem to clear off all those issues found, and always, just always, these would be the main issue, over and over again: To view print-screen image of the problem, click this link -> http://img525.imageshack.us/my.php?image=errorgx2.jpg 4. So cutting things short - after countless of times trying to remove 'it' (mind you lots, am not an expert in these sort of thing so you can say am like an amateur kindda person when it comes to all these technical issues so forgive me if I sounded slow or bluntly put, stupid... LOL! Sorry... I'm trying my level best to keep up here... LOL!); where was I? Ah yes; I've done all the possible things a dummy like me could do - Google-ed and Yahoo-ed for answers and all, and it all drew me to forums and all and after considering 2 to 3 forums, I found out that this forum can certainly help a newbie like me and so here I am, doing the things I've read as guide and up till now I guess I pretty much have a path to lead here. Just stop me along the way if I make any mistakes. 5. Now I noticed that I can't browse my own domain at www.lealaurielle.com, I can't view www.bleepingcomputer.com and such - is it because of this problem I'm facing with the registry? Anyways... Actions taken so far: 1. Ok now, right - after carefully reading a few threads from other members experiencing somewhat like what I'm facing now, up to this point, I've downloaded: i) FixWareOut ii) ATF Cleaner Both downloaded to my desktop 2. Prior to typing this new thread, I've done the following; am not so sure of the sequence as what I read from some states that they run the FixWareOut program first, then only they used the ATF Cleaner - and I've got some who does the other way round. And so what I did? I did the FixWareOut first, then I decided if problem still continues, I'll run the ATF Cleaner, then... 3. So I guess here's my HijackThis log and I really hope someone could identify what's causing this problem to my notebook... QUOTE Username "XXXX XXXXXX" - 10/18/2008 0:01:50 [Fixwareout edited 9/01/2007] ~~~~~ Prerun check HKLM\SOFTWARE\~\Winlogon\ "System"="kdebt.exe" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{2016244A-BA98-4267-8F66-CFC54F5470C1} "nameserver"="85.255.112.179;85.255.112.78" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{BD247085-0934-441D-9303-65502A4A08AB} "nameserver"="85.255.112.179;85.255.112.78" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D4687C3C-F61E-4BD5-9734-E09529E78F92} "nameserver"="85.255.112.179;85.255.112.78" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{BD247085-0934-441D-9303-65502A4A08AB} "DhcpNameServer"="85.255.112.179;85.255.112.78" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D4687C3C-F61E-4BD5-9734-E09529E78F92} "DhcpNameServer"="85.255.112.179;85.255.112.78" <Value cleared. Successfully flushed the DNS Resolver Cache. System was rebooted successfully. ~~~~~ Postrun check HKLM\SOFTWARE\~\Winlogon\ "system"="" .... .... ~~~~~ Misc files. .... ~~~~~ Checking for older varients. .... ~~~~~ Other C:\WINDOWS\Temp\kdebt.ren 70656 04/13/2008 ~~~~~ Current runs (hklm hkcu "run" Keys Only) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe" "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe" "hpWirelessAssistant"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,48,\ 65,77,6c,65,74,74,2d,50,61,63,6b,61,72,64,5c,48,50,20,57,69,72,65,6c,65,73,\ 73,20,41,73,73,69,73,74,61,6e,74,5c,48,50,57,41,4d,61,69,6e,2e,65,78,65,00 "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" "GrooveMonitor"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\"" "SynTPStart"="C:\\Program Files\\Synaptics\\SynTP\\SynTPStart.exe" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\"" "Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe" "avgnt"="\"C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "C:\\WINDOWS\\system32\\kdebt.exe"="C:\\WINDOWS\\system32\\kdebt.exe" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater] .... Hosts file was reset, If you use a custom hosts file please replace it... ~~~~~ End report ~~~~~ What should I do now? I guess, just wait for someone who knows exactly what to do to reply this msg, right? And so I'll wait... Regards Lea - Malaysia |
|
|
|
Nurlea Laurielle [Closed] Uncertainty of the infection/ damage level to my noteboo Oct 17 2008, 10:15 PM
Nurlea Laurielle anybody??? Oct 18 2008, 01:45 AM
ken545 Hello Lea
Welcome to the Whatthetech Malware Remo... Oct 19 2008, 07:57 PM
ken545 Still with us Lea ?? Oct 30 2008, 05:14 AM
ken545 Due to inactivity this topic will be closed.
If yo... Nov 12 2008, 10:10 AM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | Mordimier | 75 | Today, 09:54 PM Last post by: CatByte |
|||
![]() |
29 | Stormicats | 1,205 | Today, 03:58 PM Last post by: extremeboy |
|||
![]() |
3 | harliequin | 113 | Today, 03:30 AM Last post by: oldman960 |
|||
![]() |
2 | ArtemusGordon | 71 | Yesterday, 09:41 AM Last post by: LDTate |
|||
|
Time is now: 17th March 2010 - 11:20 PM |