Malware Removal & HijackThis Logs |
| |

| | Thread Tools |
|
06-Jul-2008, 10:30 PM
#1 | |
| help!! message box before welcome screen hi.. i have a problem with my windows xp before i can get to the desktop, there is a message box with strange font that appeared. i have to click the OK button so i can continue to desktop here is the image: ![]() the font changes randomly.. here is my hijackthis log: Quote:
|
|
09-Jul-2008, 03:35 PM
#2 |
| Hello anjrot and welcome to TSG. Let's see what we can find. Please follow the steps below in order: Before running a new scan let's clean out the temporary folders. Download ATF Cleaner to your Desktop.
Click the Empty Selected button. Click Exit on the Main menu to close the program. Now download OTScanIt from here or here to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop. Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
Cheers. OT |
|
09-Jul-2008, 11:01 PM
#4 |
| Hi anjrot. I don't see anything in the log. What was showing in the original log is no longer there. Let's just do a little housekeeping and call it good: Start OTScanIt. Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the Run Fix button. Code: [Kill Explorer]
[Unregister Dlls]
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> LanzarL2007 -> %SystemDrive%\DOCUME~1\purba's\LOCALS~1\Temp\{0F9A7E18-02BA-4A79-8FBB-FC78C1F93DEE}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe ["C:\DOCUME~1\purba's\LOCALS~1\Temp\{0F9A7E18-02BA-4A79-8FBB-FC78C1F93DEE}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009"]
YN -> NVIDIA Display -> %SystemRoot%\DisplayMonitor.exe [C:\WINDOWS\DisplayMonitor.exe]
YN -> Win32 Console -> %SystemRoot%\cmd.exe [C:\WINDOWS\cmd.exe]
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YN -> LMIinit ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button]
YN -> {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [EpsonToolBandKicker Class]
[Registry - Additional Scans - Non-Microsoft Only]
< BotCheck > ->
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YServer.exe -> %ProgramFiles%\Yahoo!\Messenger\YServer.exe [C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\mIRC\mirc.exe -> %ProgramFiles%\mIRC\mirc.exe [C:\Program Files\mIRC\mirc.exe:*:Disabled:mIRC]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\c:\windows\system32\rk.exe -> %SystemRoot%\system32\rk.exe [c:\windows\system32\rk.exe:*:Enabled:rk.exe]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\purba's\Local Settings\Temp\~os2.tmp\ossproxy.exe -> %UserProfile%\Local Settings\Temp\~os2.tmp\ossproxy.exe [C:\Documents and Settings\purba's\Local Settings\Temp\~os2.tmp\ossproxy.exe:*:Enabled:ossproxy.exe]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\c:\windows\system32\rlvknlg.exe -> %SystemRoot%\system32\rlvknlg.exe [c:\windows\system32\rlvknlg.exe:*:Enabled:rlvknlg.exe]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Veoh Networks\Veoh\VeohClient.exe -> %ProgramFiles%\Veoh Networks\Veoh\VeohClient.exe [C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Disabled:Veoh Client]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\purba's\My Documents\wi3\torrent\utorrent.exe -> %UserProfile%\My Documents\wi3\torrent\utorrent.exe [C:\Documents and Settings\purba's\My Documents\wi3\torrent\utorrent.exe:*:Disabled:µTorrent]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\purba's\My Documents\lagu\wi3\utorrent.exe -> %UserProfile%\My Documents\lagu\wi3\utorrent.exe [C:\Documents and Settings\purba's\My Documents\lagu\wi3\utorrent.exe:*:Disabled:µTorrent]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BearShare Applications\BearShare\BearShare.exe -> %ProgramFiles%\BearShare Applications\BearShare\BearShare.exe [C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Disabled:BearShare]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\LimeWire\LimeWire.exe -> %ProgramFiles%\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe:*:Enabled:Kaspersky Anti-Virus]
[Files/Folders - Created Within 30 days]
NY -> 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
[Files Created - Additional Folder Scans - Non-Microsoft Only]
NY -> %temp& -> %ProgramFiles%\%temp&
[Files/Folders - Modified Within 30 days]
NY -> 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
NY -> qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
[Empty Temp Folders]
[Start Explorer] If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTScanIt will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that information back here. I will review the information when it comes back in. Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer. Cheers. OT |
|
09-Jul-2008, 11:36 PM
#5 |
| i did the scan and reboot (the message box still appeared) here is the log: 07102008_111708.log i do have another problem in my computer but i don't know if this is related to the topic when i open IE, it will open the homepage which is yahoo! but if i write other web address in the address bar then it will open in the website in firefox so, every website that i want to see in IE will automatically directed to firefox i scanned my computer with AVG 8 but there is no virus found. |
|
10-Jul-2008, 09:19 AM
#7 |
| Hi anjrot. I figured it would. We didn't really remove anything, just cleaned up some entries with no files for them and cleaned out the temp folders. There doesn't appear to be any malware on the system so the screen is most likely coming from one of the installed programs. Let's try disabling all of them and then re-enabling them one at a time and see if that is it. Click Start -> Run and then type msconfig into the edit box and then click the Ok button. Go to the Startup tab and click Disable All and then the Ok button. You should be asked to reboot. Choose Ok. When it reboots, none of the startup programs will be started. Does the box appear? If not, then go back to MsConfig and place a check in front of the first item to start it on bootup and reboot. Repeat the process with each ermaining item until the funky box appears. Whatever program does does it, that's where it's coming from. As for the browser issue, either IE7 is messed up or Firefox is messed up. Uninstall Firefox and see what happens. Cheers. OT |
![]() |

| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 05:53 PM. Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved. Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd. Search Engine Optimization by vBSEO 3.1.0 | |




