Status
Not open for further replies.
1 - 10 of 10 Posts

· Registered
Joined
·
886 Posts
Discussion Starter · ·
OS 98

I have a computer who has a computer that was and still is a mess. The computer was infected by the Istbar Trojan. Supposedly now it is only in the system restore but I can't get it off because anytime I try to run AVG or Adaware the computer crashes. This also happens when I try to start AOL 8.0 for broadband. So, I brought her computer home and hooked it up to my cable so that I could download some additional programs and to consult with TSGF since I am stumped. I have run Spybot and cleaned everything off. I ran the registry scan from Norton and got a bunch of stuff off. She was having an error message with Quicktime, so I uninstalled and then still found more quicktime files in start up and in the registry which I had to delete one by one. Since that things are better, but still bad. I did run hijack this and got some bad programs off, but want to consult here berfore further deleting. Please note that I have a number of startup items checked to not load otherwise I cannot get into normal Windows, only save mode.

When the computer crashes when I try to run Avg or any other program, if I try to get directly into normal windows, I get a number of Kernel32.dll errors andthen it stalls. I then can open in Safe mode, and reboot without the kernel32.dll errors. The error messages include a number of start up things like task AVGcc.exe or NortonP.exe. All programs that usually load up. (Even though I had many of them checked up not to start via selective startup.)

Anyway here is the Hijack this. Could someone please look and advise. Also any other suggestions - a scan on the net, etc. will be appreciated!!!

Logfile of HijackThis v1.97.7
Scan saved at 4:44:22 PM, on 4/1/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38044.3046990741
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net

· Registered
Joined
·
886 Posts
Discussion Starter · ·
Oops the first line should say I have a client who has a computer!! Sorry for the confusion.

· Registered
Joined
·
886 Posts
Discussion Starter · ·
Oh, one more thing. I just tried to run housecall. It gets about 95% of the engine downloaded and then freezes.

· Registered
Joined
·
886 Posts
Discussion Starter · ·
I've solved a lot more since post, ie. Ican always get into normal windows now. However, I still cannot run avg or adaware or panda etc. And I guess I'm going goo goo eyes. I am running Windows ME. I've only seen the 50 times I rebooted today! Please help if you have any suggestions. I just can't figure out why it starts a scan and then shuts off.

Thanks

#### \$teve

· Registered
Joined
·
9,520 Posts
Hi
Theres nothing showing up in your log,but if you r using MSConfig that could be why.......your going to have to enable all and somehow post a log af the full running processes so`s we can see everything thats happening.

Also......do i see both AVG and NAV running......not a good idea.

I would disable both for now till your able to give us a full HijackThis log.

· Registered
Joined
·
886 Posts
Discussion Starter · ·
Oops posted this on wrong thread. Sorry if there is a duplication. Thanks, steve for replying. I've been on this stupid computer for more hours thanI want to admit!
I don't have NAV and avg running. Was clean sweep and utilities. However I uninstalled and it was still on. Tried to remove again and was unable because so files were missing. I did disable in start up so that I could at least get in to normal windows.

Heres the scan.
Logfile of HijackThis v1.97.7
Scan saved at 4:44:22 PM, on 4/1/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38044.3046990741
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net

#### \$teve

· Registered
Joined
·
9,520 Posts
Its a clean log:up

· Registered
Joined
·
886 Posts
Discussion Starter · ·
Thanks. I thought I cleaned it out. But do you have any other suggestions? It just shuts down anytime I try adaware panda etcc. There has got be something that is hanging it up and then stopping. I'm kind of at a loss of what to do. Thanks!

#### \$teve

· Registered
Joined
·
9,520 Posts
What shuts down......the program or the comp?