Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Operating Systems » Windows XP/2000 » Something is eating my programs

Windows XP/2000 - Something is eating my programs posted in the Operating Systems forums; Hello to everybody and please help , it looks serious ... Since a week or two I am not able to see on the screen pictures, graphics, live bids action ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-18-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 12
ewakrakow - See this Members User comments on their Profile page
Default Something is eating my programs

Hello to everybody and please help , it looks serious ...

Since a week or two I am not able to see on the screen pictures, graphics, live bids action etc. I see small colored squares instead, dead ones.
It affected my life badly, when not able to print security card, I was locked out of my very important account . Administrator advised to get flashmedia (??) . Obviously I had it before, for problem is recent.
I went to download page for media player, click download and saw the cute square and nothing else. Tried to use system restore, click..and empty screen !! I used it with no problem a few times before. Wanted to use WinFixer2005 ( paid $30 bucks or so, a month ago) and nothing, broken link from the shortcut, it is not there !!!
Today I downloaded CCleaner and applied. The list was very long, now I am afraid I deleted something what I not suppose to... , please help. I use XP and have relatively new, 2 years , powerful desktop PC .
regards eva


  #2  
Old 11-18-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile page
Default

Hi there Eva , welcome to PCHF.

Originally Posted by ewakrakow
I see small colored squares instead, dead ones.
Could you describe those some more?

Originally Posted by ewakrakow
Wanted to use WinFixer2005 ( paid $30 bucks or so, a month ago) and nothing, broken link from the shortcut, it is not there !!!
Ouch! , Sorry to hear that , but i have bad news im afraid... That app is malware itself.. They made you paid money to get infected instead of getting a cleaning app.


Let's see what we can do about that , if you follow the instructions in the "Prework" link below in my sig , and then post the 2 resulting log files we'll have a look at that for you.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 11-18-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 12
ewakrakow - See this Members User comments on their Profile page
Default Thanks a lot Joe5

I am not quit sure what am I doing , but hope this is it, thanks one more time
eva
Attached Files
File Type: txt hijackatt.txt (13.3 KB, 3 views)


  #4  
Old 11-18-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile page
Default

Before using HijackThis Please Do the Following:



Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.

Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Please download CCleaner

Download the Hoster from here.

Then go to add and remove programs and uninstall these if present:

wintools
Media Gateway
pib Toolbar
WebSearch toolbar

During the uninstall process, you will be presented with several prompts to guide you through uninstalling the product. Read these carefully to make sure you are actually choosing to uninstall rather than keep the software.

** Note: I find it particularly funny that after the install, the company actually pops up a screen telling you its not spyware and guiding you to buy spyware removal software with what appears to be affiliate links that the company would profit from.


Click Start>Run and type in: services.msc
Click OK
In the Services window find:

WebSeach Toolbar support NT service
WinTools for IE service

Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > “delete an NT service”
Copy and past:

TBPSSvc
WinToolsSvc

Click OK.

Then boot in safemode (hit f8 when booting up)

Remove the Startup Entries in the Registry

Click on Start, Run, Type REGEDIT and Click OK

Click the pluses(+) next to the following items

HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersion
Run

Right-Click on the file WinTools and click DELETE

Click the pluses(+) next to the following items

HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersion
RunServices

Right-Click on the file WinTools and click DELETE

Close REGEDIT

Then fix these with hjt:
(if still present)


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = -
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: &WebSearch Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [pm5ifsp9] C:\WINDOWS\system32\pm5ifsp9.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/18...ridge-c445.cab
O18 - Protocol: relatedlinks - {CD8D1CAA-FE4A-45DF-A06C-028AAF1821DE} - (no file)
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - WebSearch - C:\PROGRA~1\Toolbar\TBPSSvc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe
Then delete the files in bold and run Ccleaner.

Now start Hoster and Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original Hosts file.


And last after rebooting , run an Ewido scan:

Download Ewido Security Suite
  • Install Ewido Security Suite.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu
  • Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen
  • You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
  • The update will start and a progress bar will show the updates being installed.*
  • After the updates are installed, exit ewido.
Once the updates are installed do the following:
  • If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Reboot into Safe Mode, restart your computer, tap the F8* key. Use your up arrow key to highlight Safe Mode, then hit enter.
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
  • Click on Scanner , Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK, Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*

DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

Click Save report. Save the report to your desktop, exit ewido


Note:

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.
After that please post the Ewido log and a new Hijackthis log.


Also i see you have no firewall , to be protected from things like this it is recommended to have one , have a look in our download section for some free ones.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 11-18-2005 at 06:02 PM.
  #5  
Old 11-23-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 12
ewakrakow - See this Members User comments on their Profile page
Default It is not working

hijackthisattforJ.txt Hi Joe; by any chance if you glance over here.
I had done everything to the letter what you suggested to me and the same problems. I also downloaded flash, but did not help.
To make disaster more dramatic my new scanner does not work .
I had long chat with HP technician , followed all his instructions and nothing help. Evido report is clean at the moment, I deleted many files showed infected. Report hichjack is attached. I also attached the copy of the chat about scanner . What should I do ? Trash the computer entirerly ? Format the disk and buy new operating system ? Take computer to repair shop ? I am afraid the most of the last possibility, for a few times I paid a lot of money for nothing in the past.hijackthisattforJ.txt

I appreciate help if any left, thanks eva
Attached Files
File Type: txt hpforJ.txt (7.9 KB, 2 views)


  #6  
Old 11-23-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile pagejoe5 - See this Members User comments on their Profile page
Default

I don't see any more problems in log log , so it loks like youre clean.

But about the scanner , did you manage to follow the HP techs suggestions? Or did you have any problems with one of the steps?



Also try installing/updating Java here:

http://java.com/en/download/index.jsp


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 11-23-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 12
ewakrakow - See this Members User comments on their Profile page
Default

Hi: yes I followed everything what he told me to do, no problem with it , but did not help. The same I did downloaded Java already.
Sorry for being negative, and thanks a lot for your responce.
eva



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
How Do I Remove Kazaa and its installed programs? the_machine Security Tutorials 9 11-22-2006 07:01 PM
[Fixed] help please add/remove programs ianbrum Windows XP/2000 7 11-12-2005 02:04 PM
Using msconfig to disable startup programs MadGamer Windows Tutorials 2 07-27-2005 07:45 PM
[Fixed] - HELP.......Programs Opening & Closing Slowly ?? Snake420 Windows 95, 98 & ME 17 03-27-2005 02:34 PM

All times are GMT +1. The time now is 06:50 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top