Everything freezes when accessing MyPictures folder
Hve been recommended to use this thread by Jephree.
When clicking on MY Pictures icon the folder appears and whithin seconds the windows explorer notice pops up to say that it has encountered a problem and has to shut down. I clicked on sending an error report and the reply was i probably had a virus TrojanDownloader:Win32/Purstiu.A,
I have run ADaware , spybot,.spyware doctor ,AVG and Kaspersky scan aswell as stinger and not found anything . I have also now noticed that I cannot play DVD's but can play cd's please find my hijack log. and boot up is getting slower
Many thanks for your help
Logfile of HijackThis v1.99.1
Scan saved at 23:17:34, on 26/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
to fix it just run HijackThis put a check mark in the
box next to it then click fix checked
then close out of HijackThis
now do this for me please
Download/Save this zipped file a reporting tool http://skads.org/special/rkfiles.zip
Unzip the files inside to a folder of its own.
It has to be ran in safe mode for it to work correctly.
Open the folder and run the RKFILES.BAT, sit back and wait untill its finished, when
it is finaly finished a text will open. close it.
Make a log with hijackthis while still in safe mode.
Restart back to a normal windows session:
Post the text located here C:\Log.txt please and that hijackthis log made in safe mode.
Thanks for your help, I have fixed R3 as suggested and followed the instruction to download RKfiles from Skads. Unfortunateley even thogh I have unzipped to my hard drive when operating in safe mode and try to run it windows cannot locate the file. I searched and found the file i originally tried to run double clicked and notification popped up again to say that windows cannot locate.
Thanks for the file tried again with the same response. This was using the file as suggested and Tried to see what would happen in non safe mode aswell but still the same as before.
** I have attached the screen dump (in normal mode) this is the same notification that I get in Safe Mode****
Odd lit's try this one see if same problem lit us know
Download FindIt's.zip to your desktop.
Unzip/extract the files inside preferable to C:\ < a new folder.
Disconnect from the internet, if you use an always on internet connection unplug it.
Let your PC be idle for 15 minutes !!
Open the folder and run the FindIt's.bat and wait for a text to open, it will take awhile be patient, post the results please. http://forums.net-integration.net/in...post&id=142443
If you get an error similar to:
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application...etc etc'
Go here and use the approprient fix for your system http://www.tech-forums.net/computer/topic/29806.html
Thanks for the response, I disconnected let the PC be idle for over 15 mins and then tried to run (as you can see from the attachment) then got the same response as per the previous log file. I can (edit)open the file in notepad but cannot run. I didn't run the second task as I thought it was innapropriate
Be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the file location so you can delete it yourself.
now i may have done this with you if so lit me know
Please follow the instructions provided, you may want to print out these instructions and use them as a reference.
First:
Please download ewido security suite it is a trial version of the program.
Install ewido security suite
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
Launch ewido, there should be an icon on your desktop double-click it.
The program will prompt you to update click the OK button
The program will now go to the main screen
You will need to update ewido to the latest definition files.
On the left hand side of the main screen click update
Click on Start
The update will start and a progress bar will show the updates being installed.
Once the updates are installed do the following:
Click on scanner
Make sure the following boxes are checked before scanning:
Binder
Crypter
Archives
Click on Start Scan
Let the program scan the machine
While the scan is in progress you will be prompted to clean files, click OK
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Have ran housecall and panda software, panda picked up a couple of low threat adware files which I have cleaned up.
Have ran Ewido found backdoor and alexa spyware have quarenteened them (screen dump attached)
Log attached only shows one infection as Internet connection crashed half way through
Thanks again for your help
Harfin
Last edited by Harfin; 17-07-2005 at 08:55 PM.
Reason: Previous post by mistake