Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads

something clever and nasty on my laptop

This is a discussion on something clever and nasty on my laptop within the Resolved HJT Threads forums, part of the Tech Support Forum category. hello info below: Microsoft Windows [Version 6.0.6001] Copyright (c) 2006 Microsoft Corporation. All rights reserved. C:\Users\HAYLEY>sc qc sharedaccess [SC] QueryServiceConfig


 
 
Thread Tools Search this Thread
Old 10-14-2009, 02:38 PM   #41
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



hello

info below:
Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Users\HAYLEY>sc qc sharedaccess
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: sharedaccess
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Windows\System32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Internet Connection Sharing (ICS)
DEPENDENCIES : Netman
: WinMgmt
: RasMan
: BFE
SERVICE_START_NAME : LocalSystem

C:\Users\HAYLEY>

__________________
hmk_32 is offline  
Old 10-15-2009, 10:14 AM   #42
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Hello again, Hayley.

Go Start and then type services.msc into the Start Search box and click OK.

Scroll down to 'Base Filtering Engine Service' or 'BFE' and double-click it.

Set Startup type to 'Automatic', then set the Service status to Started by clicking 'Start', then 'Apply'.

If you were successful, see if you can do the same with 'Windows Firewall/Internet Connection Sharing (ICS)'.

Let me know.

------------------------------------------------------

__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-15-2009, 02:29 PM   #43
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi Chemist

No luck with BFE - error message received below

-Windows could not start the base filtering engine service on local computer
Error 2 : The system can not find the file specified

Hayley
__________________
hmk_32 is offline  
Old 10-15-2009, 08:33 PM   #44
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Hello again, Hayley.

Go Start Search and copy/paste the following single-line command into the Start Search box and click OK:

cmd /c peV -ltf "%systemdrive%\bfe.dll" >log.txt&log.txt&del log.txt

A Notepad file will open. Post the contents of log.txt in your next reply.

------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-16-2009, 01:05 AM   #45
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi Chemist,

I have a new problem now

when l start up the laptop it goes to a black screen and then l get the following messages:

FOR REALTECK RTL8101E/8102E PCI-E Ethernet controller v1.07(080320)
PXE-E61: media test failure, check cable
PXE-M0F: EXITING PXE ROM.

NO BOOTABLE DEVICE-- insert boot disk and press any key

it just repeates it over and over - l am unable to log in under safe mode even ????

Regards
Hayley
__________________
hmk_32 is offline  
Old 10-16-2009, 06:23 AM   #46
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Hello again, Hayley. What was done to your machine since the last time it booted up correctly? Do you have the setup CD for your system? Can you access your BIOS? What is the order of devices listed?

http://en.kioskea.net/faq/sujet-283-...ur-bios-set-up
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-16-2009, 03:04 PM   #47
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi

I havent been using the laptop at all, l have only turned it on to follow your instructions then l switch it off again.....and l dont have the set up CD (l will have another search for them as l find it really stupid of me to thow it out)

I think below is what you where wanting:

1. HDD
2.FDD
3.CD/DVD
4.LAN
5USB MEMORY

Thanks
Hayley
__________________
hmk_32 is offline  
Old 10-16-2009, 03:28 PM   #48
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi Chemist

It loaded up this time ?

When l complted the below step
cmd /c peV -ltf "%systemdrive%\bfe.dll" >log.txt&log.txt&del log.txt

The CMD window comes up saying : Access is denied

nothing else happens

Hayley
__________________
hmk_32 is offline  
Old 10-16-2009, 04:53 PM   #49
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Hello again, Hayley.

Let's check your system for corrupted files.

Go Start > Programs > Accessories > right-click 'Command Prompt' > Run as Administrator

Type sfc /scannow and press 'Enter'(there is a space between c and /).

Let it scan your system. Let me know the results.

------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-16-2009, 07:14 PM   #50
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi

Results below

Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Windows\system32>sfc /scannow

Beginning system scan. This process will take some time.

Beginning verification phase of system scan.
Verification 100% complete.

Windows Resource Protection found corrupt files and successfully repaired
them. Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For
example C:\Windows\Logs\CBS\CBS.log

C:\Windows\system32>
__________________
hmk_32 is offline  
Old 10-16-2009, 07:29 PM   #51
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Hello again, Hayley. Please navigate to this file:

C:\Windows\Logs\CBS\CBS.log

Right-click > Rename to CBS.txt

Please attach the file to your next reply.

------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-16-2009, 10:13 PM   #52
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi Again,

unable to open the log - error saying acceaa was denied

Hayley
__________________
hmk_32 is offline  
Old 10-16-2009, 10:14 PM   #53
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



sorry typo - access was denied
__________________
hmk_32 is offline  
Old 10-16-2009, 10:32 PM   #54
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Drag the file onto Inherit.exe and then rename it.
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-17-2009, 12:36 AM   #55
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi

The file is attached to big to post on here screen kept freezing

Hayley
Attached Files
File Type: zip look.zip (444.9 KB, 3 views)
__________________
hmk_32 is offline  
Old 10-17-2009, 05:42 AM   #56
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Hello again, Hayley. Are you still unable to start 'Base Filtering Engine' and 'Windows Firewall/Internet Connection Sharing'?

------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-19-2009, 12:10 AM   #57
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi Chemist

Still unable to start either.

Regards
Hayley
__________________
hmk_32 is offline  
Old 10-19-2009, 02:49 AM   #58
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Did you find the CD, or can you borrow one with same service pack?
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
Old 10-20-2009, 04:24 AM   #59
Registered Member
 
Join Date: Oct 2009
Location: Australia
Posts: 31
OS: vista



Hi Chemist

I found the CD and re loaded vista again so lm back at the start again.... lm able to access the net and everything seems to be working fine

Regards
Hayley
__________________
hmk_32 is offline  
Old 10-20-2009, 06:08 AM   #60
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 26,411
OS: XP SP3; Win7 32/64-bit



Hello again, Hayley.

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.

SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles: To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware, or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an add-on available for both Firefox and IE.
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites in Internet Explorer. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
Keep your antivirus program and antispyware programs updated and scan with them on a regular basis.

Please respond to this thread one more time so we can mark this thread as resolved.

__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

chemist is offline  
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2


All times are GMT -7. The time now is 11:11 AM.


Copyright 2001 - 2014, Tech Support Forum

Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts