Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 10-22-2009, 09:52 PM   #21 (permalink)
Registered User
 
Join Date: Oct 2009
Location: chicago
Posts: 16
OS: xp


Re: Please help with Lenovo _cpnprt2 trojan

I will go to the link and uninstall IE8 and install IE7
Hope it works. This may take until tomorrow.
I will report back. Thanks for your continued effort on my behalf.
John Suchy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 10-22-2009, 10:11 PM   #22 (permalink)
Registered User
 
Join Date: Oct 2009
Location: chicago
Posts: 16
OS: xp


Re: Please help with Lenovo _cpnprt2 trojan

Currently operating with IE7
Still no information Bar @ windowsupdate
There is a update ready to install IE8 from Microsoft
Awaiting your reply to continue.
John Suchy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-22-2009, 10:32 PM   #23 (permalink)
Registered User
 
Join Date: Oct 2009
Location: chicago
Posts: 16
OS: xp


Re: Please help with Lenovo _cpnprt2 trojan

I went to adobe.com and installed adobe flash player, the information bar showed up and the player installed.
I returned to the windows update site the address in the browser resolved to
HTTP://update.microsoft.com/microsof...ult.aspx?ln=en
the following links were inaccessable
Microsoft update home
review your update history
restore hidden updates

am I in a cloned microsoft page?
John Suchy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-23-2009, 06:45 PM   #24 (permalink)
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
 
Join Date: Oct 2007
Location: Georgia
Posts: 10,649
OS: XP SP3


Re: Please help with Lenovo _cpnprt2 trojan

Sorry John Suchy. I failed to receive notification of your last two replies. It happens sometimes if you make multiple replies too close together.

When you say inaccessible, do you mean the links are grayed out? Can you post a screenshot? Do you receive any error messages?
__________________
Our help is free but please donate

Proud member of ASAP
Proud member of UNITE
chemist is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-23-2009, 07:07 PM   #25 (permalink)
Registered User
 
Join Date: Oct 2009
Location: chicago
Posts: 16
OS: xp


Re: Please help with Lenovo _cpnprt2 trojan

Good evening Chemist,

Sorry for the multiple post so close together.

I was excited about the removal of IE8 and the fallback to IE7.
I thought thatthis would surely work but alas....
I am afraid I cannot make a screenshot. The Website displays the page
with the three references grqayed out. The other links do take me to some content. I just noticed this last night. The computer Has the yellow shield
and when I click on it and go to Custom it is ready to update to IE8.
As I mentioned I does reference That it wants to install an activex control
which I have seen MANY times however the information bar does not display.
Given the anonimity of the internet I became suspicious and took notice of the greyed out links.
John Suchy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-23-2009, 07:54 PM   #26 (permalink)
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
 
Join Date: Oct 2007
Location: Georgia
Posts: 10,649
OS: XP SP3


Re: Please help with Lenovo _cpnprt2 trojan

Hello again, John Suchy. Go Tools > Add-ons > Enable or Disable Add-ons...

Look through all categories for MUWebControl Class

Is it enabled? If not, enable it, reboot. Any difference?

------------------------------------------------------

If still no joy...

Open Notepad and copy/paste the entire contents of the codebox below into Notepad:

Code:
net stop wuauserv
regsvr32 /s wuapi.dll
regsvr32 /s wuaueng1.dll
regsvr32 /s wuaueng.dll
regsvr32 /s wucltui.dll
regsvr32 /s wups2.dll
regsvr32 /s wups.dll
regsvr32 /s wuweb.dll
net start wuauserv
Save this Notepad file as register.bat and choose to Save as type: - All Files then close the Notepad file.
It should look like this:

Double-click on register.bat & allow it to run. You may delete the file afterwards.

Let me know if you are able to install the Windows Updates.

------------------------------------------------------
__________________
Our help is free but please donate

Proud member of ASAP
Proud member of UNITE
chemist is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-24-2009, 05:53 AM   #27 (permalink)
Registered User
 
Join Date: Oct 2009
Location: chicago
Posts: 16
OS: xp


Re: Please help with Lenovo _cpnprt2 trojan

Good morning Chemist !!!

I found that the Muwebcontrol class (muweb.dll) was indeed disabled.
Created register.bat and executed.
Went to the windows update site. The computer searched for updates.
IE8 was listed as critical.

I did not see the information bar, but perhaps if the contol was already installed the program did not need to set it.
Yesterday or the day before the infomation bar did appear on the adobe website for the flash player.
the review updates link was not greyed out.
microsoft update home was greyed
restore hidden updates was greyed.
Before this fix the computer did not search for required updates and now it did
Update to IE8?
Thank You again for all your efforts on my behalf
I can understand the terse warning to not make changes on my own
and found your method of analysis excellent.
John Suchy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-24-2009, 10:34 AM   #28 (permalink)
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
 
Join Date: Oct 2007
Location: Georgia
Posts: 10,649
OS: XP SP3


Re: Please help with Lenovo _cpnprt2 trojan

Hello again, John Suchy. Yes, update to IE8 if you want it back, let me know, and I will give you some final instructions.
__________________
Our help is free but please donate

Proud member of ASAP
Proud member of UNITE
chemist is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-24-2009, 01:05 PM   #29 (permalink)
Registered User
 
Join Date: Oct 2009
Location: chicago
Posts: 16
OS: xp


Re: Please help with Lenovo _cpnprt2 trojan

Good afternoon Chemist,
Installation to IE8 completed
Thank you
John Suchy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-24-2009, 01:11 PM   #30 (permalink)
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
 
Join Date: Oct 2007
Location: Georgia
Posts: 10,649
OS: XP SP3


Re: Please help with Lenovo _cpnprt2 trojan

Congratulations. Well done! Your logs appear clean. You should be good to go.

Please disable avast! before uninstalling ComboFix and then re-enable it after doing so.

Go to Start >> Run and Copy/Paste the following single-line command into the Run box and click OK:

combofix /uninstall

This will uninstall ComboFix and delete ComboFix's quarantine folder. It will also implement some cleanup procedures, remove old System Restore Points which contain previous infections, and create a fresh, clean System Restore Point.

Please re-enable your antivirus program and any other antispyware programs disabled earlier if you haven't already.

You can safely delete any tools downloaded or any logs, files, and any shortcuts on your desktop that were created during this fix.

------------------------------------------------------

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.

SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles: To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an add-on available for both Firefox and IE.
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
    • Download Host.zip and Save it to your Desktop.
    • Right-click hosts.zip and select 'Extract all files' or 'Extract files...'.
    • Follow the prompts and click 'Finish'.
    • This will open the newly created hosts folder on your Desktop.
    • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
    • Once updated you should see another prompt that the task was completed.
Keep your antivirus program and antispyware programs updated and scan with them on a regular basis.

Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Our help is free but please donate

Proud member of ASAP
Proud member of UNITE

Last edited by chemist; 10-24-2009 at 01:13 PM.
chemist is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-29-2009, 10:01 AM   #31 (permalink)
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
 
Join Date: Oct 2007
Location: Georgia
Posts: 10,649
OS: XP SP3


Re: Please help with Lenovo _cpnprt2 trojan

As this topic appears to be resolved, this thread will be archived. If you need continued support, please begin a new thread, and provide a link to this topic. This applies only to the original topic starter. Everyone else please begin a New Topic, after following the steps outlined here:

IMPORTANT - Read This Before Posting For Malware Removal Help

------------------------------------------------------
__________________
Our help is free but please donate

Proud member of ASAP
Proud member of UNITE
chemist is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 04:22 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85