Announcement Banner
UNSOLVED

dodge swinger

updated

18 years ago

0

4383

March 13th, 2009 16:00

Frequent "Internet Explorer not responding"

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:25:43 PM, on 3/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxdpcoms.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\File Scanner Library (Spybot - Search & Destroy)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\FILESC~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\File Scanner Library (Spybot - Search & Destroy)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\FILESC~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\FILESC~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1169160665000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225423992656
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://aerialsexpress.com/ae/ecwplugins/ncs1.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: lxdpCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdpserv.exe
O23 - Service: lxdp_device -   - C:\WINDOWS\system32\lxdpcoms.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 7096 bytes

Oh wow, it actually worked!  My first successful copy & paste!

Down to business--For the last month or so after using comp. 30 to 45min it begins locking up on Web sites or pages "internet explorer not responding"  can stay locked for few min. or much longer.  Frequently I finally had to shut down to get out.  Was sent here by Joe53 in virus and spyware dis., tried various virus removal programs to no success.  Joe53 thinks analyze this may find something to indicate problem.  Followed all instruct. on Bugbatter's post (I hope)  Would gladly supply info as to installed virus prog., security etc. but I think it's listed above.   Thank You.

 

  • Bugbatter

    4 Apprentice

    •

    20487 Posts

    545

    0

    Posted March 13th, 2009 18:00

    Hi, there,

    We could have continued in your other thread, but we'll continue here if you'd like.

    Spybot's TeaTimer is going to interfere with our tools, so we'll need to disable that until we are finished cleaning.

    Go to Start>Run. Type Msconfig

    Then click on OK.

    In the next window that opens > Startup tab UNcheck the entry for TeaTimer until this is over...
    1. Open Spybot
    2. Click Mode > Advanced Mode
    3. Click Yes
    4. Click Tools (located in the bottom left corner) > Resident
    5. Uncheck 'Resident "TeaTimer" (Protection of over-all system settings) active'
    6. Then close Spybot.
    Reboot.
    Verify that TeaTimer is not running.
    After ALL cleaning of your system has been completed and we have confirmed that your computer is clean, reverse these steps and re-enable the protection applets for TeaTimer.

    Run Disk Cleanup in each user's profile: Click "Start > Programs > Accessories > System Tools > Disk Cleanup" Please make sure only the following are checked:

    -- Downloaded Program Files

    -- Temporary Internet Files

    -- Recycle Bin

    -- Temporary Files

    Click "OK" and Disk Cleanup will delete those files for you.

    Following that  please download Malwarebytes Anti-Malware     and save it to your desktop.
    alternate download link 1 
    alternate download link 2

    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.

    MBAM will automatically start and you will be asked to update the program before performing a scan.

    • If an update is found, the program will automatically update itself.
    • Press the OK button to close that box and continue.
    • If you encounter any problems while downloading the updates,
    • manually download them from here
      and just double-click on mbam-rules.exe to install.
      Alternatively, you can update through MBAM's interface from a clean computer,
      copy the definitions (rules.ref) located in
      C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
      Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.

    On the Scanner tab:

    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top.
    • It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully.
    • Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.

    Back at the main Scanner screen:

    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report  into your next reply below and exit MBAM.

    Note:-- If MBAM encounters a file that is difficult to remove,
    you may be asked to reboot your computer so it can proceed with the disinfection process.
    Regardless if prompted to restart the computer or not, please do so immediately.
    Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

    -- MBAM may make changes to your registry as part of its disinfection routine.
    If you're using other security programs that detect registry changes (like Spybot's Teatimer),
    they may interfere with the fix or alert you after scanning with MBAM.
    Please disable such programs until disinfection is complete or permit them to allow the changes.

    **If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from HERE

    Feel free to post any questions if you need me to clarify any instructions.

  • tomron

    2 Intern

    •

    966 Posts

    545

    0

    Posted March 13th, 2009 20:00

    Could also be a heat issue......check for dust  inside of computer and check to make sure fan is working.

     

    NOTE: Only go inside of puter with power disconnected

     

    Check task manager>processes tab to see if any program is running with high CPU %

  • Bugbatter

    4 Apprentice

    •

    20487 Posts

    545

    0

    Posted March 13th, 2009 20:00

    Tom, we ask the posters on this forum not to do any procedures that we do not advise them to do and that they work with one trained helper per thread. If you would like to finish troubleshooting this issue, I'll let you continue so I can move on to helping others.. After cleaning any malware, Java needs to be removed/updated. Carry on. :emotion-1:

  • 545

    0

    Posted March 14th, 2009 17:00

    I don't know what that was with Tomron, I heard no more so I guess i'm in your hands.  I recognize your 'name' as having been involved early in the privious forum I posted, before Joe53 took over.  You want me to download and run Malwarebytes??  I went thru that about a week ago or so, that and SuperSpy; the full procedure, they found nothing my current programs missed.  Concerned I may have too many programs I uninstalled those two and went back to the AVG-AdAware and SpyBot I always had.  I did, however; save the install programs to a 'flash drive', if you want me to re-install Malware... maybe I can just pull it off there.  I apperciate any help I can get, and if you want me to go through the Malware.... procedure again I certainly will.  I just wanted to be sure you  knew I had already gone thru that.  Forgive me if my schedule of replying is erratic, current economic cond. have me grabbing any temp./odd job I can get, which makes any kind of schedule non-existant.

  • Bugbatter

    4 Apprentice

    •

    20487 Posts

    545

    0

    Posted March 14th, 2009 18:00

    No problem with your schedule. We'll get to this when we can. I thought Tom might continue here, but as long as I'm here this evening, we'll go for it. You really would be better off removing Ad-aware and Spybot and keeping MBAM and SuperAnti-Spyware instead. In my opinion, both are superior to the others. Yes, please install both again. UPDATE them and run them. Follow that by posting their logs. Thanks.

     

    ** If you are keeping Spybot, please make sure TeaTimer is disabled per instructions above.

  • 545

    0

    Posted March 16th, 2009 20:00

    Malwarebytes' Anti-Malware 1.34
    Database version: 1856
    Windows 5.1.2600 Service Pack 3

    3/16/2009 10:40:31 PM
    mbam-log-2009-03-16 (22-40-31).txt

    Scan type: Quick Scan
    Objects scanned: 70848
    Time elapsed: 9 minute(s), 23 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Here is the log from Malwarebytes you requested.  Sorry for the couple days, this thing was acting really bad Sat. and Sun. Locking up on any site I tried, even on itself when I wasn't on the Web..  When it starts locking up all I can do is shut it down and walk away!  I still have Tea Timer disabled, I think that is what you wish; or should I turn it back on now?

  • H2darizzo

    62 Posts

    545

    0

    Posted March 16th, 2009 20:00

    Can u please give me ur service tag so i can check the system specs???

  • Bugbatter

    4 Apprentice

    •

    20487 Posts

    545

    0

    Posted March 16th, 2009 21:00

    Dodge Swinger DO NOT post your service tag #  Click on Edit and remove it.

    The person who is asking for it should not be doing so.

    Dodge Swinger I will work on my next reply for you and reply tomorrow. Thank you for waiting patiently.

  • H2darizzo

    62 Posts

    269

    0

    Posted March 16th, 2009 21:00

    Have u tried with any other browser like FireFox? If not then give it  a try.Can u let me know if u have added any new s/w?

  • 545

    0

    Posted March 16th, 2009 21:00

    Ah gee, I already posted service tag before I saw your message.  Tried to edit or remove, I don't think I was successful (don't know how)