BigOrangeArmy
Don't tase me, bro!
+12|6258|Dallas
So I'm sitting here with my friend (ThunderDown21) trying to diagnose his computer. His computer:

---Will not connect to the internet beyond the Dell Homepage
---Has around 70-80 processes, and half are hidden
---Has some adware on it, and probably some malware. Problem is, without internet access, I can't download Spybot, Ad-Aware, or AVG and there'll be no updates. I looked through his visible processes and besides an adware process, can't find anything incriminating. Until I can get a hijack-this report, this is what he has for processes:


DLG.exe
DSAgnt.exe
SearchProtection.exe
SetPoint.exe
VolPanlu.exe
SetPoint.exe
ezprint.exe
ehtray.exe
ieuser.exe
GoogleDesktop.exe
GoogleToolbarNotifier.exe
issch.exe
KHALMNPR.exe
LogitechDesktopMessenger.exe
lxcymon.exe
MSASCui.exe
RtHDVCpl.exe
taskeng.exe
taskmgr.exe
WolPanlu.exe
wmdc.exe
wuaudt.exe

Oh, and I left out some of the basic processes that everyone has, like iexplorer.exe and ones I know to trust. Oh, and its Vista, so i wanna castrate it right now . Any help would be great help
liquidat0r
wtf.
+2,223|6889|UK
Type the process names in to Google/etc and websites will tell you what they belong to, and stuff.
CC-Marley
Member
+407|7091
Windows defender
Lucien
Fantasma Parastasie
+1,451|6915
Has he disabled any services? (start > run > services.msc)
Try disabling all unnecessary startup programs (start > run > msconfig > startup)
https://i.imgur.com/HTmoH.jpg
Winston_Churchill
Bazinga!
+521|7001|Toronto | Canada

Download it in safemode + networking?
BigOrangeArmy
Don't tase me, bro!
+12|6258|Dallas

Winston_Churchill wrote:

Download it in safemode + networking?
Booted into safe mode, and now It doesnt even connect to the internet now .

Er, no anti-virus + Vista = fail

Also, Im very confused. As a windows XP user, I find a lot of processes for Vista that are really confusing. Looking at PCPitstop and Neuber.com, they show a lot of processes that are unfamiliar. Is there any way to get spybot or AVG onto his computer--with the recent updates? That would help a lot.
ceslayer23
IN YOUR MIRROR
+142|6623|CLOSER THAN I APPEAR
make sure you booted into "safemode + networking" and not just "safemode"
Noobpatty
ʎʇʇɐdqoou
+194|6616|West NY

BigOrangeArmy wrote:

iexplorer.exe
iexplorer.exe = probably virus
iexplore.exe = internet explorer
Winston_Churchill
Bazinga!
+521|7001|Toronto | Canada

Did you do it in

Winston_Churchill wrote:

Download it in safemode + networking?
BigOrangeArmy
Don't tase me, bro!
+12|6258|Dallas

Winston_Churchill wrote:

Did you do it in

Winston_Churchill wrote:

Download it in safemode + networking?
At the risk of exposing my non-technical prowess , I'm assuming that the safemode + networking will enable internet? And why does regular safe mode not automatically allow internet?
liquidat0r
wtf.
+2,223|6889|UK
Safemode, by itself just doesn't start any network services. Simple as that.
BigOrangeArmy
Don't tase me, bro!
+12|6258|Dallas
Alright, I'm gonna try to boot into safe-mode + networking. Will be back in a few
BigOrangeArmy
Don't tase me, bro!
+12|6258|Dallas
Alright, this might be worse than I feared.

Problems now:

---Internet magically works on one account, and not another admin account. On the first account, I can get onto the AVG site, but then it fails when I want to download. And whenever I try to go to Spybot (Safer-Networking.com), it skips to a site called StopSign: Free Spyware and Virus Remover (Ten bucks says that its malware ). Then it will go to another random page if I try it again!

On the plus side:

--Caught a trojan and a piece of spyware -- pcpc.exe and ld08.exe that run on startup.

My question: Can I get the update AVG or Spybot by downloading the update onto a USB? Then I can put it onto my friends computer.
Drykill
I Like Waffles.
+47|6954|England
Wouldn't it be less of a ball ache to just back up his data and reinstall windows??
Noobpatty
ʎʇʇɐdqoou
+194|6616|West NY
How's the situation regarding what I posted...is his PC really running "Iexplorer.exe" or Iexplore.exe ?
Finray
Hup! Dos, Tres, Cuatro
+2,629|6050|Catherine Black

BigOrangeArmy wrote:

Er, no anti-virus + Vista = fail
I've been running Vista x64 with no anti virus since Christmas and my computer is completely clean.

It's all down to the user.
https://i.imgur.com/qwWEP9F.png
The_Sniper_NM
Official EVGA Fanboy
+94|6376|SC | USA |
When this happens, your homepage usually is set to the maker of the malware, probably just a fail coder.

Download this on to a flash drive, then run it on his computer. The malware probably wont let it update, just run it anyways.

http://download.cnet.com/Malwarebytes-A … tag=button

Run a quick scan, reboot, then run a full scan.

And get some motherfucking anti virus on his comp.
Hakei
Banned
+295|6257
D:\WINDOWS\system32\drivers\etc\hosts

Make sure this area is clear of any info after:

#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host
BigOrangeArmy
Don't tase me, bro!
+12|6258|Dallas
Hehe I finally did it . Put AVG on a flash drive from a clean comp and installed it on his comp. Then, after manually deleting the PCcleaner trojan, managed to get an update from Grisoft.

Found like 3 trojans, a worm, and a couple of registry keys that were mucked up. Thanks all for the help

Edit: Oh, and it turned out to be a false alarm with the iexplorer thing. It was only iexplore.

Last edited by BigOrangeArmy (2009-06-29 08:58:39)

Shadow893
lel
+75|6954|England

Finray wrote:

BigOrangeArmy wrote:

Er, no anti-virus + Vista = fail
I've been running Vista x64 with no anti virus since Christmas and my computer is completely clean.

It's all down to the user.
YES FINALLY - someone else

everyones like zomg you fail with no anti-virus.. no you fail for visiting dodgy pr0n sites. /rant

Board footer

Privacy Policy - © 2025 Jeff Minard