Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.
101 - 120 of 137 Posts
We now need to run Combofix again using the instructions below.

First I would like you to check in Add/Remove Programs and uninstall any of these that may still be there.
Ignore any that are not visible but please tell of any that you DO find that will not uninstall.

ALOT Appbar
Coupon Printer for Windows
Norton PC Checkup
PC TuneUp Maestro
SpeedMaxPc
SpeedyPC Pro
Supreme Savings
WeatherBlink Toolbar

We are now going to run ComboFix a different way.

Open Notepad by clicking
> Run... and in the open box type: Notepad.exe
Press Ok, then copy and paste everything in the code box below into it.
-- Note: Make sure Word Wrap is unchecked in Notepad by clicking on Format in the top menu.

Code:
KillAll::

File::
c:\windows\system32\drivers\avgtpx86.sys
c:\windows\system32\DRIVERS\avglogx.sys
c:\windows\Tasks\SpeedyPC Registration3.job
c:\windows\Tasks\SpeedyPC Update Version3 Startup Task.job
c:\windows\Tasks\SpeedyPC Update Version3.job

Driver::
avgtp
vToolbarUpdater12.2.6
vToolbarUpdater14.2.0
Avglogx
Norton PC Checkup Application Launcher
PCCUJobMgr
TuneUp.UtilitiesSvc
TuneUpUtilitiesDrv

DDS::



Folder::
c:\program files\Common Files\AVG Secure Search
c:\program files\Norton PC Checkup 3.0
c:\program files\Norton PC Checkup
c:\program files\AVG
c:\program files\Common Files\SpeedyPC Software

ClearJavaCache::

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PCCUJobMgr]

Reboot::
  • Save the file as CFScript.txt by choosing Save As... in the File Menu, and save it to your Desktop where the ComboFix icon is also located.
  • Close your browser and disconnect from the Internet.
  • Now use your mouse to drag, then drop the CFScript.txt file on top of ComboFix.exe as seen in the image below.

  • This will start ComboFix again and launch the script.
  • ComboFix may reboot your system when it finishes. This is normal.
  • A log will be created just as before and saved to C:\ComboFix.txt. Please copy and paste the contents of ComboFix.txt in your next reply.
  • Be sure to re-enable your anti-virus and other security programs after the scan is complete.
  • NOTE: if you see a message like this when you attempt to open anything after the reboot "Illegal Operation attempted on a registry key that has been marked for deletion" please reboot the system again and the warning should not return.
======================================================================

After this has been done we will be moving on to deal with any of the items that would not uninstall, replacing the missing services and fixing the file associations.
 
Discussion starter · #102 ·
Ok, I went through Add/Remove programs and found Coupon Printer for Windows and uninstalled it. Nothing else on your list was there... Incidentally Boujour and something called Search Donkey is in there. Also, that APagent thing still shows up after re-booting. One more thing: lately when I search for something on the internet I get this annoying Hotstartsearch.com that goes in front of yahoo, everytime. I just thought I might mention this....

I did all the other things you asked me to do, and here is the log. You mentioned turning off and on my virus and Other security Programs. The only one I have is MSE.?

ComboFix 13-04-06.01 - Andrew 04/07/2013 8:55.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.231 [GMT -7:00]
Running from: c:\documents and settings\Andrew\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Andrew\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\windows\system32\DRIVERS\avglogx.sys"
"c:\windows\system32\drivers\avgtpx86.sys"
"c:\windows\Tasks\SpeedyPC Registration3.job"
"c:\windows\Tasks\SpeedyPC Update Version3 Startup Task.job"
"c:\windows\Tasks\SpeedyPC Update Version3.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\AVG Secure Search
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
c:\program files\Common Files\SpeedyPC Software
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\ad_generic.jpg
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\close.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\close_md.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\close_mo.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\close_pu.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\close_pu_md.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\close_pu_mo.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\Logo.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\min.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\min_md.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\min_mo.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\progress_glow.png
c:\program files\Common Files\SpeedyPC Software\UUS3\Images\topbar_gradient.png
c:\program files\Common Files\SpeedyPC Software\UUS3\LiteUnzip.dll
c:\program files\Common Files\SpeedyPC Software\UUS3\settings.xml
c:\program files\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe
c:\program files\Common Files\SpeedyPC Software\UUS3\UUS3.dll
c:\windows\jestertb.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_AVGLOGX
-------\Legacy_AVGTP
-------\Legacy_NORTON_PC_CHECKUP_APPLICATION_LAUNCHER
-------\Legacy_PCCUJOBMGR
-------\Legacy_TUNEUP.UTILITIESSVC
-------\Legacy_TUNEUPUTILITIESDRV
-------\Legacy_VTOOLBARUPDATER12.2.6
-------\Legacy_VTOOLBARUPDATER14.2.0
-------\Service_Avglogx
-------\Service_avgtp
-------\Service_Norton PC Checkup Application Launcher
-------\Service_PCCUJobMgr
-------\Service_TuneUp.UtilitiesSvc
-------\Service_TuneUpUtilitiesDrv
-------\Service_vToolbarUpdater12.2.6
-------\Service_vToolbarUpdater14.2.0
.
.
((((((((((((((((((((((((( Files Created from 2013-03-07 to 2013-04-07 )))))))))))))))))))))))))))))))
.
.
2013-04-07 14:30 . 2013-03-15 07:21 7108640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE899AA6-3416-44DF-BF5A-6F53705E5C9C}\mpengine.dll
2013-04-06 16:25 . 2013-03-15 07:21 7108640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-05 16:59 . 2013-04-05 16:59 177496 ----a-w- c:\windows\system32\drivers\51236355.sys
2013-04-05 16:59 . 2013-04-05 16:59 -------- d-----w- C:\TDSSKiller_Quarantine
2013-04-04 17:25 . 2013-04-04 18:24 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-04-04 17:22 . 2013-04-04 17:22 -------- d-----w- c:\program files\Tweaking.com
2013-04-03 23:16 . 2013-04-02 10:33 237088 ------w- c:\windows\system32\MpSigStub.exe
2013-04-03 23:06 . 2013-04-03 23:07 -------- d-----w- c:\program files\Microsoft Security Client
2013-03-29 22:19 . 2013-03-29 22:19 -------- d-----w- c:\windows\Sun
2013-03-26 04:23 . 2013-03-26 04:33 -------- d-----w- C:\d608f2bb5b323a930a256af12f5c77
2013-03-25 20:05 . 2013-03-25 20:05 -------- d-----w- c:\program files\Tuguu SL
2013-03-25 17:18 . 2013-03-25 17:18 -------- d-----w- c:\program files\SearchDonkey
2013-03-25 17:17 . 2013-03-25 17:17 -------- d-----w- c:\windows\system32\config\systemprofile\AppData
2013-03-25 17:17 . 2013-03-25 17:17 -------- d-----w- c:\documents and settings\NetworkService\AppData
2013-03-25 17:17 . 2013-03-25 17:17 -------- d-----w- c:\documents and settings\LocalService\AppData
2013-03-25 17:17 . 2013-03-25 17:17 -------- d-----w- c:\documents and settings\LAND & STREAM CO\AppData
2013-03-25 17:17 . 2013-03-25 17:17 -------- d-----w- c:\documents and settings\Andrew\AppData
2013-03-12 17:56 . 2013-03-12 18:28 -------- d-----w- c:\program files\Free Download Manager
2013-03-09 23:29 . 2013-03-09 23:29 -------- d-----w- c:\documents and settings\Andrew\Local Settings\Application Data\Yahoo
2013-03-09 23:12 . 2013-03-13 15:30 -------- d-----w- c:\windows\msdownld.tmp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-05 17:00 . 2004-08-03 23:07 187776 ----a-w- c:\windows\system32\drivers\acpi.sys
2013-02-21 19:32 . 2012-10-06 04:42 33112 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-02-12 00:32 . 2008-04-13 18:56 12928 ----a-w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-11-21 00:04 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-08 18:21 . 2013-02-08 18:22 5259504 ----a-w- c:\windows\uninst.exe
2013-02-05 20:05 . 2004-11-21 00:04 916480 ----a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05 . 2004-11-21 00:04 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05 . 2004-11-21 00:04 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53 . 2004-11-21 00:04 385024 ----a-w- c:\windows\system32\html.iec
2013-01-26 03:55 . 2004-11-21 00:04 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-20 22:59 . 2013-01-20 22:59 195296 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn3\yt.dll" [2012-06-11 1524056]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{DDA5D4B3-468F-4D62-9092-75142C6169B1}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-06 5406720]
"AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2009-11-11 771360]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
.
c:\documents and settings\Andrew\Start Menu\Programs\Startup\
Monitor Ink Alerts - HP Deskjet 3050 J610 series.lnk - c:\windows\system32\RunDll32.exe [2004-11-20 33280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2004-10-27 23:40 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\AirPort\\APAgent.exe"=
"c:\\Program Files\\AirPort\\APUtil.exe"=
"c:\\Program Files\\Online Services\\AOL Instant Messenger Setup\\aimsetup.exe"=
"c:\\Program Files\\Sony\\vaio media 3.1\\VmpClient.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"= 5353:UDP:Bonjour
.
R2 FastFreeConverterUpdt;FastFreeConverterUpdt;c:\program files\Fast Free Converter\FastFreeConverterUpdt.exe [11/26/2012 6:30 AM 687104]
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-06 c:\windows\Tasks\At1.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-07 c:\windows\Tasks\At10.job
- c:\program files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-06-09 02:06]
.
2013-04-05 c:\windows\Tasks\At11.job
- c:\program files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-06-09 02:06]
.
2013-04-06 c:\windows\Tasks\At12.job
- c:\program files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-06-09 02:06]
.
2013-04-07 c:\windows\Tasks\At2.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-06 c:\windows\Tasks\At3.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-06 c:\windows\Tasks\At4.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-06 c:\windows\Tasks\At5.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-07 c:\windows\Tasks\At6.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-07 c:\windows\Tasks\At7.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-06 c:\windows\Tasks\At8.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-15 00:07]
.
2013-04-06 c:\windows\Tasks\At9.job
- c:\program files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-06-09 02:06]
.
2013-04-07 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 18:11]
.
2008-12-17 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-11-21 00:12]
.
2008-12-17 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-11-21 00:12]
.
2008-12-17 c:\windows\Tasks\Registration reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-11-21 00:12]
.
2013-04-07 c:\windows\Tasks\User_Feed_Synchronization-{338A9EA3-733C-4378-9B99-3D24E7CBD95A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
2013-04-07 c:\windows\Tasks\User_Feed_Synchronization-{6658E6C8-7180-43A7-851B-F41F858CBE3B}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?ilc=79
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-07 09:15
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(832)
c:\windows\system32\VESWinlogon.dll
.
- - - - - - - > 'explorer.exe'(1488)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\System32\snmp.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2013-04-07 09:19:12 - machine was rebooted
ComboFix-quarantined-files.txt 2013-04-07 16:19
ComboFix2.txt 2013-04-06 16:06
.
Pre-Run: 55,925,854,208 bytes free
Post-Run: 56,052,011,008 bytes free
.
- - End Of File - - B3D2DBCB9CF08705D6E6E5E3087CE0B7
 
Ok, the Combofix log is looking good and all the deletions appear to have worked ok.

In answer to your queries, Bonjour is related to iTunes and is legitimate software.

Search Donkey is a legitimate Search Engine, if you don't use it uninstall it.

APagent is related to a flight simulator program which I believe you have installed.

Hotstartsearch we will have to search for and remove as I believe it is Adware. Please also run ADWCleaner again with the Delete button and post the log.

Please download SystemLook from the following link below and save it to your Desktop.


  • Double-click SystemLook.exe to run it.
  • Vista/Windows 7 users right-click and select Run As Administrator.
  • Copy and paste everything in the codebox below into the main textfield:
    Code:
    :filefind
    *Hotstartsearch*
    :folderfind
    *Hotstartsearch*
    :reg
    Hotstartsearch
  • Click the Look button to start the scan.
  • When finished, a Notepad window will open SystemLook.txt with the results of the search and save a copy on your Desktop.
  • Please copy and paste the contents of that log in your next reply.
 
Discussion starter · #104 ·
Another thing you might want to know: Before the really major meltdown, Google quit altogether. No access, couldn't download it or anything. I tried uninstalling it and re-trying it - nothing worked. So I gave up. I use gmail and yahoo mail for my three email addressed. In gmail, It tells me that I am using an outdated version of Internet Explorer and I should get a more modern browser. I have been clicking "dismiss" and I goes away. I don't know what this is all about. Here are the two logs you asked for:

# AdwCleaner v2.200 - Logfile created 04/07/2013 at 13:18:38
# Updated 02/04/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Andrew - E457FDF720CE414
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Andrew\Desktop\adwcleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

***** [Registry] *****

***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Registry is clean.
-\\ Google Chrome v25.0.1364.97
File : C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
File : C:\Documents and Settings\LAND & STREAM CO\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[S1].txt - [33103 octets] - [04/04/2013 12:44:11]
AdwCleaner[S2].txt - [1126 octets] - [05/04/2013 08:34:08]
AdwCleaner[S3].txt - [1187 octets] - [05/04/2013 14:25:07]
AdwCleaner[S4].txt - [1049 octets] - [07/04/2013 13:18:38]
########## EOF - C:\AdwCleaner[S4].txt - [1109 octets] ##########

SystemLook 30.07.11 by jpshortstuff
Log created at 13:33 on 07/04/2013 by Andrew
Administrator - Elevation successful
========== filefind ==========
Searching for "*Hotstartsearch*"
No files found.
========== folderfind ==========
Searching for "*Hotstartsearch*"
No folders found.
========== reg ==========
[Hotstartsearch]
Hive unrecognized.
-= EOF =-
 
Discussion starter · #105 ·
Something new -
I have two user accounts on this computer, one I use regularly and the other once in a while. When I went into the other account it said that IE had been upgraded - everything is new and fresh. It has a Google toolbar and access to Google, and it works. When I right-click on the IE icon in on the left side of the task bar, then Properties, I get "Launch IE Browser Properties", then I click "general"
and it say that it was created, modified, and accessed today, all at the same time. Also the Task Manager appears to work fine.
When I switch back to the other account(the one we've been dealing with) and go to "Launch IE Properties", General, I see Created 2008, Modified March 2013, and Accessed today. Also, the Task Manager does not work, and I have to log off that account for things to work.
 
Ok, I think at this point we should repair the missing services as it may help things run a bit smoother, please run RKill again and post the new log.
 
Discussion starter · #107 ·
Rkill 2.4.7 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 04/08/2013 07:46:05 AM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* Alerter [Missing Service]
* lanmanworkstation [Missing Service]
* NtLmSsp [Missing Service]
* RpcLocator [Missing Service]
* NetBIOS [Missing Service]
* RpcSs => %SystemRoot%\system32\svchost.exe -k rpcss [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 04/08/2013 07:47:03 AM
Execution time: 0 hours(s), 0 minute(s), and 57 seconds(s)
 
I have attached a zip file with all the service fixes. Download it to your desktop and the extract the contents, there are six .reg files. Double left click on each one in turn and allow them to merge with the registry.

When done reboot the system and run Rkill again and post the log to make sure all is well. See if there is any improvement in the way the system is running.
 

Attachments

Discussion starter · #109 ·
Here is the log. I will reboot again and look around for things. Everthing is running much faster. When I rebooted after running Rkill, that APAgent.exe is still there, and lots of ads keep coming up.

Rkill 2.4.7 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 04/08/2013 12:14:55 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 04/08/2013 12:15:28 PM
Execution time: 0 hours(s), 0 minute(s), and 32 seconds(s)
 
Which browser is showing the pop ups?

We need to do a search for APAgent.exe to find what it is related to.

Run SystemLook again and then copy the text in the code box into it and run it, post back the results.

Code:
:filefind
*APAgent*
:folderfind
*APAgent*
:reg
APAgent
 
Discussion starter · #112 ·
I don't think I know how to say this right: My internet service is running off of a router with Airport Extreme(fifth generation) with an Airport Express booster. When this booster was added(some time ago), it was a hassle to get my computer to run. After consulting with the Apple people(special Apple people over the phone), I downloaded and installed some software and have been able to run - it is slow and often I get kicked off. Much of the time I can't tell if problems are inside my computer or a result of the internet connection via all this Apple Airport stuff. It has to do with that. ?
About the pop ups: I am not sure I understand your question. I have been using IE the whole time, if I understand what you mean. Right now I am looking at one stretched across the bottom of my screen; it is one of the same ones that keeps popping up over and over.

SystemLook 30.07.11 by jpshortstuff
Log created at 16:25 on 08/04/2013 by Andrew
Administrator - Elevation successful
========== filefind ==========
Searching for "*APAgent*"
C:\Program Files\AirPort\APAgent.exe --a---- 771360 bytes [23:17 11/11/2009] [23:17 11/11/2009] 1C86D0C84FF3870A3E13808B853C040A
C:\WINDOWS\Prefetch\APAGENT.EXE-1586BE5C.pf --a---- 2978 bytes [03:32 07/04/2013] [22:00 08/04/2013] 17D7552A026250421AC2BA169DF17F67
========== folderfind ==========
Searching for "*APAgent*"
No folders found.
========== reg ==========
[APAgent]
Hive unrecognized.
-= EOF =-
 
I have no knowledge of the Airport software, may be Throoper can give some advice on that.

As for the continuing pop ups on IE, try running it with no Add-ons and see if that stops them.

Follow the instructions in this guide for IE: How to run Firefox and Internet Explorer with no add-ons
 
Discussion starter · #114 ·
I clicked on the "How to run IE with no add-ons" file and followed the instructions exactly: Start>Run>type: iexplore -extoff, ok, and get "Windows can not find iexplore. I then searched for iexplore and found lots of iexplore files. ?
I don't know whether this matters: I went into yahoo Mail and chose opt-out in ads settings, but I'm still getting lots of pop ups. Should I do the same thing in Gmail? I don't know. I'm at a loss here. I just don't want any ads.
 
Ok, please try this alternative method to disable Add-ons in IE and let me know if the pop ups stop in IE only.

Close all browsers.
Click on Start > All Programs > Accessories > System Tools > Look down the list and you should find Internet Explorer (No Add-ons) click on it and IE should open, run it for a while and see if any pop ups occur.
 
Discussion starter · #116 ·
I followed the instructions and got this: "Internet Explorer is currently running without add-ons. All IE add-ons such as ActiveX controls or toolbars are turned off. Some webpages might not display correctly. To continue using your homepage....
 
Simplest solution to the problem with APAgent would be to get a different router so you aren't using Apple software, but since you shelled out around $200 for it, I'm guessing you'd rather have another option. :D
Assuming you haven't uninstalled Bonjour, go into the Control Panel>Add/Remove and select bonjour.
Click Change/Remove and select Repair. You may have to insert your Airport install disc.
If the repair doesn't work, uninstall Bonjour and reinstall from the Apple store (be sure to download the latest Bonjour for Windows).

I can't be too much help on this as I've never tried repairing Bonjour. I've only eradicated it as an unwanted nuisance.
 
As for running IE without Add-ons the message you got is normal, did it run without any pop ups showing?
 
Discussion starter · #119 ·
Mark1956 - No the add-ons are still there. "Opt-out" in ad settings doesn't seem to be doing much. I think I got one ad to stop by clicking on a little T at the bottom. It sent me to a screen the let me uninstall it. It was called "Fast Free Converter". There are other ads with "ad choices" in the corner. When I click on that it sends me into a place where it tells all about ads, but not how to remove it. I don't know what this opt-out is doing: I'm getting ads from Western Union, dating, etc. It is better, but far from gone. Last time I checked my email in Yahoo, about a third of the screen was blanketed with pictures of available women over 50, and I don't subscribe to anything or visit sites like that.

Throoper - I tried to repair bonjour and it says "The feature you are trying to use is on a network resource that is unavailable." Also, I tried to remove it, but it won't. I don't have a disk for Airport Utility. I downloaded it from the web, and I don't remember the procedure, but I do recall that it was quite simple. I have Airport Utility in "All Programs", but when I try to run it I get "This application has failed to start because dnssd.dll was not found - Reinstalling the program may fix this problem." I just looked for Airport Utility for windows, and there are a bunch to choose from. ?
 
101 - 120 of 137 Posts
Status
Not open for further replies.
You have insufficient privileges to reply here.
Top