I am operating windows xp home edition. I know I have spyware/malware as I am always directed to a site other than the one I have clicked on. Works like a bounce page…. Not only am I blocked from running hijack this but also from Malwarebytes' Anti-Malware. They both download and installed , yet when I click on the program icon, nothing happens. I am also unable to I defrag my hard drive. I tried the run command but to no avail. I have just completed 3 scans using ESET Nod32 and it detected a trojan on two of the scans. The last scan was clean. Could you please assist me in my next step?
Cheers…
Not a great deal of information there so lets see what you have, but the description lets me know where to look
To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.
The 64 bit only appears if you have a 64 bit system
Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-2802515966-2291512787-2924921057-1008\] > ->
YN -> HKEY_USERS\S-1-5-21-2802515966-2291512787-2924921057-1008\: "ProxyEnable" -> 1
< Run [HKEY_USERS\S-1-5-21-2802515966-2291512787-2924921057-1008\] > -> HKEY_USERS\S-1-5-21-2802515966-2291512787-2924921057-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "Win32 Firewall" -> C:\DOCUME~1\Shalane\LOCALS~1\Temp\001.exe [C:\DOCUME~1\Shalane\LOCALS~1\Temp\001.exe]
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\
YN -> NameServer -> 85.255.112.105,85.255.112.21
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\
YN -> {124565EC-AC53-439C-8274-6C81F6819FA3}\\NameServer -> 85.255.112.105,85.255.112.21 (Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC)
YN -> {1B83F50D-7691-483B-83D8-00E58D013D8A}\\NameServer -> 85.255.112.105,85.255.112.21 (Dynex G Desktop Card)
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
*TaskMan* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\TaskMan
YY -> C:\RECYCLER\S-1-5-21-7758632359-1830062104-423753160-9270\rundll32.exe -> C:\RECYCLER\S-1-5-21-7758632359-1830062104-423753160-9270\.exe
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e8de2cb-ab5d-11dd-b881-806d6172696f}\Shell\AutoRun\command ->
YN -> \{1e8de2cb-ab5d-11dd-b881-806d6172696f}\Shell\AutoRun\command\\"" -> D:\Autorun.exe [D:\Autorun.exe]
YN -> \{c0aaf2c4-dacd-11dd-b8d8-001e8caba2af} ->
[File - Lop Check]
NY -> {5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job -> C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
[Empty Temp Folders]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTS log.
I will review the information when it comes back in.
THEN
Run Malwarebytes and post the log
Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
I can not run Malwarebytes. I even uninstalled and reinstalled the program after this latest fix. When I click the desktop the icon nothing happens. Literally. I also just tried hijack this and I can't get that to work either.
Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again
Start AVZ.
Choose from the menu "File" => "Standard scripts " and mark the "Healing/Quarantine and Advanced System Analysis" check box.
Click on the “Execute selected scripts”.
Automatic scanning, healing and system check will be executed.
A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
All applications will work properly after the system restart.
When restarted
Start AVZ.
Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Analysis" check box.
Click on the "Execute selected scripts".
A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.
Attach both zip files to your next post
To attach a file, do the following:
Click Add Reply
Under the reply panel is the Attachments Panel
Browse for the attachment file you want to upload, then click the green Upload button
Once it has uploaded, click the Manage Current Attachments drop down box
Click on [external image: Posted Image] to insert the attachment into your post
I rebooted my pc… the first time after reboot I got an error stating could not locate c:/ …. I could access the c drive though..odd
the second time: it got as far as the windows xp screen, then rebooted itself back to bios stage and gave a page stating: we apologize for the inconvenience but windows did not start properly. This could be due to a recent software change, etc etc… then I was given a list of options to start windows, I choose start windows normally then the pc lagged while loading and seems to be running slower than it's normal state…
given this new information I just want to clarify that performing the above mentioned steps is safe at this point….shall I still forge ahead?
Note: When you run the script, your PC will be restarted
Click Run
Restart your PC if it doesn't do it automatically.
I will give Combofix instructions again
Download ComboFix from one of these locations:
Link 1 Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.