Recommended Driver Scanner

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Blue Screen :(

[Fixed] Hijackthis! Logs - [Resolved] Blue Screen :( posted in the Security & Safety forums; You have indeed a couple of problems in there , but we should have that fixed up soon enough. Look in your control panels add/remove programs for PuritySCAN By OIN, ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 07-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

You have indeed a couple of problems in there , but we should have that fixed up soon enough.



Look in your control panels add/remove programs for PuritySCAN By OIN, OuterInfo, OIN or similar , click on it and click remove.

Reboot and delete this folder if found:
C:\Program Files\PurityScan


If not listed, download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe

Tutorial for the uninstaller if needed:
http://www.outerinfo.com/howto.html

Reboot when done and delete this folder if found:
C:\Program Files\PurityScan



Then boot youre pc in safemode again, and run HijackThis , select to do a "system scan only" and then place a check beside each of the following:

O4 - HKLM\..\Run: [Explorer 2238] C:\DOCUME~1\Raffi\LOCALS~1\Temp\19515\explorer.exe
O4 - HKCU\..\Run: [Sen] "C:\PROGRA~1\COMMON~1\YMANTE~1\dexplore.exe" -vt ndrv
O4 - HKCU\..\Run: [Eqhsrwdz] C:\WINDOWS\SYSTEM32\?dobe\t?skmgr.exe
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/Yazzl...cab?refid=1123
O20 - Winlogon Notify: winxzq32 - winxzq32.dll (file missing)
O21 - SSODL: PmGoP - {B452AE8C-1EF8-0426-C338-46D8A3BF5A18} - C:\WINDOWS\system32\ahacv.dll (file missing)
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file)
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\2236_26.dll
O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\Raffi\LOCALS~1\Temp\19515\explorer.exe
Now first close all windows and browsers other than HiJackThis , then click fix checked and close HijackThis.

Manually search for, and delete these file/folders:

C:\DOCUME~1\Raffi\LOCALS~1\Temp\19515 << This folder
C:\WINDOWS\system32\2236_26.dll << This file
C:\WINDOWS\system32\ahacv.dll << This file
C:\WINDOWS\system32\winxzq32.dll << This file
C:\WINDOWS\SYSTEM32\?dobe << This folder
C:\PROGRA~1\COMMON~1\YMANTE~1 << This folder

Reboot youre pc.

Do a Panda AV scan here:
http://www.pandasoftware.com/activescan/

And save the log from it , when done , post the Panda log and a new HJT log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #9  
Old 07-16-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 10
Xombie - See this Members User comments on their Profile page
Default

I followed your instructions and deleted all the things listed that I could find. However, I didn't see anything called "PurityScan" or anything close to it, and there weren't any files called "ahacv.dll, winxzq32.dll, ?dobe, or ymante.

I am still getting a blue screen. I ran a windows memory diagnostic, and I am confident that the memory is not the problem.

The error message on the blue screen is now
STOP: 0x0000008E (0xc0000005, 0x860ECB6C, 0xF7798FA70, 0x00000000)


  #10  
Old 07-16-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 10
Xombie - See this Members User comments on their Profile page
Default

Here are the logs.
Attached Files
File Type: txt Activescan.txt (9.0 KB, 2 views)
File Type: txt hijackthisnew.txt (6.3 KB, 2 views)


  #11  
Old 07-16-2006
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,967
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default

Click Here to download KillBox
Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
In the killbox program, select the Delete on Reboot option.
Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\Program Files\MsConfigs\MsConfigs.exe
C:\WINDOWS\system32\p2pnetwork.exe
C:\WINDOWS\system32\CMD.COM
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\smdat32m.sys

Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
After the reboot run HijackThis again. Check the following items in HijackThis.
Close all windows except HijackThis and click Fix checked:

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART

Reboot once more and post the resulting HijackThis log.


__________________
  • An Australian Member of
  • and
My real name is Eddy

Last edited by Pancake; 07-16-2006 at 03:17 AM.
  #12  
Old 07-16-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 10
Xombie - See this Members User comments on their Profile page
Default

Still getting blue screen.
Attached Files
File Type: txt hijackthisnew.txt (6.2 KB, 1 views)


  #13  
Old 07-17-2006
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,967
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default

Ok.That looks fine.All clean.


If you wish to do so, here are a few things that you can do that will help keep your computer a bit more clean and secure..
If you have not already done so, you might want to run Disk Cleanup and run it in each user's profile:
Run Disk Cleanup
Click "Start > Programs > Accessories > System Tools > Disk Cleanup"
Please make sure the following are checked:
-- Downloaded Program Files
-- Temporary Internet Files
-- Recycle Bin
-- Temporary Files
Click "OK" and Disk Cleanup will delete those files for you.

Now that you are clean its now is a good time to flush out your restored files.
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.
Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.
How Do I Protect My Computer Against Future Malware Now I'm Clean.
NOTE:You may have already taken some of these steps.
Update your anti-virus software & Windows operating system on a daily or weekly basis. Microsoft also distributes updates to its operating systems. These updates fix security holes or other problems that make a computer susceptible to security breaches. How to update your Windows operating system
Know What You're Installing
Check the source.
To avoid malware, make sure your software comes from a reputable source. Be particularly suspicious of sponsored software (software that relies on advertising) or software that claims to speed up your Internet connection.
Use Custom Install.
If you feel comfortable with software installation, you can choose Custom Install (as opposed to Typical Install). Custom Install allows you to select only the software components you wish to install, and leave out others (such as potential spyware).
Modify Security Settings (Internet Explorer 6)
To reduce the risk of installing malware, you can set Internet Explorer to high security mode. To do so:
Open Internet Explorer. Go to Tools > Internet Options?.
On the Internet Options screen, select the Security tab, then select the Internet icon (if it is not already selected).
Under Security level for this zone, click Default Level. Set the slider to High.
Note: You may have to lower the security level to view certain Web sites.
Next, select the Trusted Sites icon. Under Security level for this zone, click Default Level. Set the slider to Medium.
Click Apply, then OK to save the changes.
Some Recommended Protection Programs
Each tool has its own strengths for identifying and removing specific types of malware. To thoroughly check your computer, its recommend that you use more than one malware removal program. Don't forget to back up your data files before starting a scan!
Some available programs are:
Ad-Aware
SpyBot Search & Destroy
Now that you are clean, to help protect your system I recommend that you get the following free programs:
SpywareBlaster to help prevent spyware from installing.
SpywareGuard to catch and block spyware .
IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.
WinPatrol to monitor any changes that programs make to the registry.
If you do not have a firewall, here is a free one for personal use:
ZoneAlarm
http://www.zonelabs.com/store/conten..._freedownloads
http://www.zonelabs.com/store/conten...g=en&lid=ho_za

Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List. It will save you a lot of grief, as well as money if you are thinking of purchasing. Here is the link:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
If you want to know just how effective your anti-spyware program is, or how well any of the "rogue" programs listed at the above link work, check this for an independent comparison of several anti-spyware programs:
http://www.spywarewarrior.com/asw-test-guide.htm

Here is a helpful article:
"So how did I get infected in the first place?"
http://computercops.biz/postlite7736-.html
http://www.pchelpforum.com/index.php?page=protect
Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #14  
Old 07-19-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by Xombie
Still getting blue screen.
Hya Zombie, how is it going with the blue screens? Have they stopped now, or do they still happen?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:21 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top