Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

WhatsApp Voicemail Virus Removal


  • This topic is locked This topic is locked
27 replies to this topic

#1 MsInformation

MsInformation

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 04 December 2013 - 01:19 PM

  :killcomp:

 

 

Hello to the awesome geeks that will hopefully be able to rescue this Damsel in distress.! You are needed!!   :horse: 

 

 

Im a seasoned end user and can usually fix my own problems but this is a first for me, so be patient please, this may take awhile.

 

I have tried everything I can think of to fix this but I need some real help now to see this to virus removal or total wipe.

I just ran a DSS (see below) as the rules state to do, my network was turned off during it so please tell me if we need one with network on. You are the only place I will seek guidance as per the rules. If I break any rules please know its unintentional and an oversight so just let me know.  :nono: <mods    :blush: <me > :oopsign:   :graduate: 

 

my pc is a Frankenstein put together by someone I use to know so I am unsure some of the specs or tweaks.

I DO HAVE An uninfected  NETBOOK as well so I could be talked through repairs and reboots without leaving a conversation if its easier to chat me through any of this stuff on yahoo messenger. (if you tell me your ID on yahoo) But however you can,  Please help me

 

Thank You - MsInformation  :wub: 

 

 

Why I know I have this WhatsApp Voicemail Trojan/virus:  I broke my Smartphone and after a week of using the backup flip phone and getting no voicemails I missed a call and didnt see a VM again. but at that moment an email came in from WhatsApp telling me I had voicemails. When i set up my Smartphone there was an issue with SMS and a non native program took them over for me, so I thought well maybe WhatsApp was running my voicemails. So i moved it from my junk (sigh) and opened it on Dec 1 2013. googled the local number displayed because i didnt recognize it. i get a lot of unrecognized calls so this didnt stick out to me. But the file failed to play. and a few minutes later my REAL voice mail program notified me of a real voicemail so i didnt give it much thought til the MSE notice happened. After days of no luck with total removal and googling file names the AV progs game me nothing would tell me what caused it. but finally it came to me how odd that email was and i googled whatsapp virus and sure enough, there is one and i fit every description of it. i was able to delete the WhatsApp file from my downloads folder yesterday (3rd).

 

 

 

notice of a problem:

 

everythings taking a long time all of a sudden (on the 2nd early morning), no website will load. thought my downloads were too much for the system so i turned of Utorrent and then Microsoft Security Essentials warns me of a problem with a couple exe files. MSE kept finding things on every full system scan i did. I cleaned it as recommended, but I started seeing twenty or so odd exe files in task manager and my tower sounded like the fan/revolutions of something was about to blow the system up, it ran like that for hours even though I would manually turn them off. Also saying its accessing IP addresses I don’t try to go to, and on shut down a message about referenceing memory problem with 00X000 and 0X0008< not exact) so i got Malwarebytes, ran it, and again found lots of things, removed all found. Then saw online that kaspersky was good for hard to remove stuff. Got that, and uninstalled MSE on recommendation from them, but kept malware bytes. Kaspersky found a lot of items. Next morning I though maybe it was over (the 3rd) after I located and removed the WhatsAP file from my downloads folder. but malwarebytes found more. I thought maybe the 2 were imessing each other up so I uninstalled malware bytes and ran kaspersky time and again finding things each time all day. Ran the program Trojan Remover, found more bad exe files. Kaspersky ran ithout finding anything so I thought maybe it was over.  Removed that TR program and tried Vipre. Found 1 more bad exe and a good one it was confused about so I deleted both. Ran again with a clean bill of health.    But we know its not gone, or else id not find it when I use other scans.  The system still wont start in safe mode, still wont stop sounding like spinning hardwares going to explode any moment when the network is turned on.

 

 

 

INFO:

80% of the bad files have been located in Application Data or System Volume Information areas  and have been called variants of Trojan.Win32.Generic.pak!cobra (Vipres name) Trojan.Win32.Zbot.quaz (Kasperskys name) Trojan.Win32.Zbot.gen.ap (cant recall where that one popped up)

 

What ive tried:

Kaspersky, Trojan remover, Microsoft windows essentials, Vipre, Malwarebytes,

Tried to create a kaspersky boot USB but my tower wont boot to it and kaspersky generic answer page says some systems are too old to boot from USB. I got imgburn to try to make an iso of the disc but all I have on hand is an old CD-RW that’s been used and that failed to write too. 

cant open in safe mode, cant do a system recovery on any date shown, my backup from my new #TB Toshiba external drive purchased the day before virus appeared came with NTI backup EZ but that failed the DAY before this virus due to user error and I didn’t notice until after virus took hold because I had a false “systems safe” message from NTI but that didn’t mean it was backup up properly (sigh).

 

I picked Vipre because a google results mentions them warning people of it by the WhatsApp name so I thought it would be the final fix.

 

 

At this point I am lost what to do next. I am not wanting to but am willing to wipe the system to be sure its all gone if need be but I don’t even think that’s possible since I lost my Microsoft XP discs. I need someone to help me through this, and if it cant be removed to help me refresh the system, or really bad worst case scenario decide between a new win 7 or 8 system with 32 or 64 bit.

-----------------------------------------------------------------------------------------------------------------------------------------

 

Ps: anything that says “MsInformation” as the user name on reports was  replaced from my actual windows user name … for security purposes for this openly visible forum.  hope this is okay.

-----------------------------------------------------------------------------------------------------------------------------------------

DDS (Ver_2012-11-20.01) - NTFS_x86 
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.45.2
Run by MsInformation at 11:05:08 on 2013-12-04
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2047.913 [GMT -5:00]
.
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: ThreatTrack Security VIPRE *Disabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C}
FW: Kaspersky Internet Security *Disabled* 
.
============== Running Processes ================
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
C:\Program Files\PDF Architect\HelperService.exe
C:\Program Files\PDF Architect\ConversionService.exe
C:\Program Files\VIPRE\SBPIMSvc.exe
C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\SWAS.exe
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\MsInformation\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k bthsvcs
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.pogo.com/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - <orphaned>
BHO: PDF Architect Helper: {3A2D5EBA-F86D-4BD3-A177-019765996711} - c:\program files\pdf architect\PDFIEHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: VIPRE Search Guard Helper: {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} - c:\program files\vipre\VSG.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\onlinebanking\online_banking_bho.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\urladvisor\klwtbbho.dll
BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: PDF Architect Toolbar: {25A3A431-30BB-47C8-AD6A-E1063801134F} - c:\program files\pdf architect\PDFIEPlugin.dll
TB: VIPRE Search Guard Toolbar: {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - c:\program files\vipre\VSG.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [LTMSG] LTMSG.exe 7
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [CTHelper] CTHELPER.EXE
mRun: [BackupNowEZtray] "c:\program files\nti\nti backup now ez\BackupNowEZtray.exe" -k
mRun: [SBAMTray] "c:\program files\vipre\SBAMTray.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\MsInformation\startm~1\programs\startup\displa~1.lnk - c:\program files\12noon display changer\dc.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 14.0.0\ieext\urladvisor\klwtbbho.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{2DEEB1C1-6F46-47B0-A701-0D0CB3FC5F00} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{7C98AFE4-BCEA-439B-B28D-B3EC15FF2438} : DHCPNameServer = 192.168.188.1
Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - c:\program files\vipre\VSG.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - c:\windows\system32\klogon.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\MsInformation\application data\mozilla\firefox\profiles\y2cb40st.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.amazon.com
FF - component: c:\documents and settings\MsInformation\application data\mozilla\firefox\profiles\y2cb40st.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\XPATLCOM.dll
FF - plugin: c:\documents and settings\MsInformation\application data\mozilla\firefox\profiles\y2cb40st.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\documents and settings\MsInformation\application data\mozilla\firefox\profiles\y2cb40st.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
FF - plugin: c:\documents and settings\MsInformation\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\MsInformation\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\MsInformation\application data\mozilla\plugins\npo1d.dll
FF - plugin: c:\documents and settings\MsInformation\local settings\application data\google\update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1166636.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: !HIDDEN! 2011-01-11 23:37; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: general.useragent.extra.brc - BRI/1
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.ytff.general.dontshowhpoffer, true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============
.
R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2013-10-8 135776]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2013-12-2 575072]
R1 klpd;klpd;c:\windows\system32\drivers\klpd.sys [2013-4-12 14432]
R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2013-5-14 45024]
R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2013-6-6 145120]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2013-12-4 24032]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2013-12-4 224336]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2011-1-7 54760]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2011-11-6 12184]
R2 NTI BackupNowEZSvr;NTI BackupNowEZSvr;c:\program files\nti\nti backup now ez\BackupNowEZSvr.exe [2013-2-5 46072]
R2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\pdf architect\HelperService.exe [2012-11-22 1522312]
R2 PDF Architect Service;PDF Architect Service;c:\program files\pdf architect\ConversionService.exe [2012-11-22 905864]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2013-12-4 70888]
R2 SBPIMSvc;SB Recovery Service;c:\program files\vipre\SBPIMSvc.exe [2013-9-5 176016]
R2 SWAS_Core;SyncThru Web Admin Service;c:\program files\samsung network printer utilities\syncthru web admin service\SWAS.exe [2012-10-21 1449984]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\system32\drivers\thdudf.sys [2013-7-6 66944]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2013\TuneUpUtilitiesService32.exe [2013-10-11 1729336]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2013-4-19 36448]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2013-10-8 24160]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2013-10-8 24672]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [2011-9-2 42648]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [2011-9-2 12184]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2013\TuneUpUtilitiesDriver32.sys [2012-11-16 10088]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-7-20 756392]
S2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 14.0.0\avp.exe [2013-10-8 214512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SBAMSvc;VIPRE Antivirus;c:\program files\vipre\SBAMSvc.exe [2013-9-5 3937472]
S3 CyUsb;Flatmii USB Driver;c:\windows\system32\drivers\CyUsb.sys [2011-1-15 34304]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [2011-10-15 45288]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys [2013-12-4 43368]
S3 gfiutil;gfiutil;c:\windows\system32\drivers\gfiutil.sys [2013-12-4 24040]
S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [2011-1-12 131888]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [2008-1-25 25088]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
.
=============== File Associations ===============
.
ShellExec: PDF Architect.exe: open="c:\program files\pdf architect\\PDF Architect.exe""%1"
.
=============== Created Last 30 ================
.
2013-12-04 05:19:32 43368 ----a-w- c:\windows\system32\drivers\gfiark.sys
2013-12-04 05:19:32 24040 ----a-w- c:\windows\system32\drivers\gfiutil.sys
2013-12-04 05:12:55 -------- d-----w- c:\documents and settings\MsInformation\application data\deb27c1a-00e6-4263-94b2-8b78ea4d32ae
2013-12-04 05:12:46 70888 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2013-12-04 05:12:45 24032 ----a-w- c:\windows\system32\drivers\sbaphd.sys
2013-12-04 05:11:27 224336 ----a-w- c:\windows\system32\drivers\sbtis.sys
2013-12-04 05:11:20 -------- d-----w- c:\windows\system32\drivers\VDD
2013-12-04 05:11:05 -------- d-----w- c:\documents and settings\all users\application data\VIPRE
2013-12-04 05:09:58 -------- d-----w- c:\documents and settings\all users\application data\Downloaded Installations
2013-12-04 05:08:26 -------- d-----w- c:\program files\VIPRE
2013-12-04 05:08:11 -------- d-----w- c:\documents and settings\MsInformation\local settings\application data\VIPRE
2013-12-04 05:08:11 -------- d-----w- c:\documents and settings\MsInformation\application data\VIPRE
2013-12-03 16:22:01 -------- d-----w- c:\documents and settings\MsInformation\_uninstall
2013-12-03 00:31:37 -------- d-----w- c:\program files\Kaspersky Lab
2013-12-03 00:31:37 -------- d-----w- c:\documents and settings\all users\application data\Kaspersky Lab
2013-12-03 00:30:21 93280 ----a-w- c:\windows\system32\drivers\klflt.sys
2013-12-02 21:47:04 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-12-02 21:26:59 -------- d-----w- c:\documents and settings\MsInformation\application data\Yzruisr
2013-12-02 14:53:24 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2013-12-02 14:53:24 77072 ----a-w- c:\windows\system32\ztvcabinet.dll
2013-12-02 14:53:24 75264 ----a-w- c:\windows\system32\unacev2.dll
2013-12-02 14:53:24 605968 ----a-w- c:\windows\system32\ztv7z.dll
2013-12-02 14:53:24 185616 ----a-w- c:\windows\system32\ztvunrar39.dll
2013-12-02 14:53:24 169744 ----a-w- c:\windows\system32\ztvunrar36.dll
2013-12-02 14:53:23 153088 ----a-w- c:\windows\system32\unrar3.dll
2013-12-02 06:29:16 -------- d-----w- c:\documents and settings\MsInformation\application data\Malwarebytes
2013-12-02 06:28:40 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-11-29 18:18:36 -------- d-----w- c:\windows\system32\NtmsData
2013-11-29 18:13:32 -------- d-----w- c:\documents and settings\all users\application data\NTIReg
2013-11-29 18:02:24 14464 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys
2013-11-29 18:02:22 13440 ----a-w- c:\windows\system32\drivers\UBHelper.sys
2013-11-29 18:02:10 -------- d-----w- c:\windows\system32\drivers\nti\Xp_x86
2013-11-29 18:02:09 -------- d-----w- c:\windows\system32\drivers\nti\w2k_x86
2013-11-29 18:02:09 -------- d-----w- c:\windows\system32\drivers\nti\Vista_x86
2013-11-29 18:02:09 -------- d-----w- c:\windows\system32\drivers\nti\Vista_ia64
2013-11-29 18:02:08 -------- d-----w- c:\windows\system32\drivers\nti\Vista_amd64
2013-11-29 18:02:08 -------- d-----w- c:\windows\system32\drivers\nti\2003_x86
2013-11-29 18:02:08 -------- d-----w- c:\windows\system32\drivers\nti\2003_ia64
2013-11-29 18:02:07 -------- d-----w- c:\windows\system32\drivers\nti\2003_amd64
2013-11-29 18:01:33 -------- d-----w- c:\windows\system32\drivers\nti
2013-11-29 18:01:33 -------- d-----w- c:\program files\NTI
.
==================== Find3M  ====================
.
2013-12-03 00:55:05 135776 ----a-w- c:\windows\system32\drivers\kl1.sys
2013-12-02 05:06:10 87608 ----a-w- c:\documents and settings\MsInformation\application data\inst.exe
2013-12-02 05:06:09 47360 ----a-w- c:\documents and settings\MsInformation\application data\pcouffin.sys
2013-11-19 10:21:30 230048 ------w- c:\windows\system32\MpSigStub.exe
2013-10-16 12:56:19 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-10-16 12:56:14 145408 ----a-w- c:\windows\system32\javacpl.cpl
2013-10-13 07:25:38 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:25:08 43520 ------w- c:\windows\system32\licmgr10.dll
2013-10-13 07:25:02 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:24:17 18944 ----a-w- c:\windows\system32\corpol.dll
2013-10-13 06:57:59 385024 ------w- c:\windows\system32\html.iec
2013-10-12 15:56:19 278528 ----a-w- c:\windows\system32\oakley.dll
2013-10-11 13:24:48 32568 ----a-w- c:\windows\system32\TURegOpt.exe
2013-10-11 13:24:40 30520 ----a-w- c:\windows\system32\uxtuneup.dll
2013-10-09 13:12:48 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-08 22:55:53 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-08 22:55:52 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-08 18:49:18 24672 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2013-10-08 18:49:18 24160 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2013-10-07 10:59:21 603136 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:14:01 7168 ----a-w- c:\windows\system32\xpsp4res.dll
2013-09-12 18:00:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2013-09-06 02:33:22 13712 ----a-w- c:\windows\system32\drivers\vdd\apvdd.dll
2013-09-06 02:33:20 44944 ----a-w- c:\windows\system32\sbbd.exe
.
============= FINISH: 11:08:34.15 ===============

 

Attached File  attach.txt   66.97KB   1 downloads
 
Update 12/04/13 3:35pm:
Kaspersky found 6 more of the same files as before but a new name was given to these trojan files:
HEUR:Trojan.Win32.Generic
Trojan.Win32.Fraud.adf
Trojan-Spy.Win32.Zbot.quav
the c: location was system information and it states _restore and a string of numbers.exe

Edited by MsInformation, 04 December 2013 - 03:43 PM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,602 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:21 AM

Posted 09 December 2013 - 01:20 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/516346 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:21 AM

Posted 11 December 2013 - 06:00 PM

Hello MsInformation,
  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Follow This Topic.I suggest you click it and select Immediate E-Mail notification and click on Follow This Topic. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.
  • Finally, please reply using the Post  button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.
1.
Download AdwCleaner
  • Double click on AdwCleaner.exe to run the tool.
    ***Note: Windows Vista and Windows 7 users:
    Right click in the adwCleaner.exe and select
    "Run as administrator"
  • Click the Scan button.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your next reply.
  • Or you can find the logfile at C:\AdwCleaner[R1].txt.
2.
  • Download RogueKiller on the desktop
  • Close all the running processes
  • Under Vista/Seven, right click -> Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • When prompted, Click Scan
  • A report should open, give its content to your helper. (RKreport could also be found next to the executable)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename in winlogon.exe (or winlogon.com) and try again

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#4 MsInformation

MsInformation
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 12 December 2013 - 09:53 AM

hello fireman!

i have had kaspersky and tune up utilities running and cleaning still.
someone in the welcome section said it was okay.

since all this was posted my modem appears to be suffering from loss of signal which is intermitent and new. not sure if related

so please let me know what to about the kaspersky and tunup and vipre. turn off from startup?
also would u like a fresh scan? if yes should internet connection be on during scan to catch anything?



thank you. (so so much im happy to start getting my pc back.

Ms

#5 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:21 AM

Posted 12 December 2013 - 10:44 PM

Please follow my directions in my previous post and post those logs.


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#6 MsInformation

MsInformation
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 14 December 2013 - 09:17 PM

when i start the pc it automatically starts kaspersky and vipre and other things. i did right click and exit on those so they will not scan. i am not sure if that is right but i dont know how else to stop them from scanning.

 

I did step 1

download and run adwcleaner scan

results:

once i clicked scan it scanned and got to the end and the status states:

"pending please uncheck elements you dont want to remove"

and no logfile automatically appeared. so i am attaching with the path you provided.

Attached File  AdwCleanerR1.txt   2.63KB   4 downloads

 

 

i did step 2

download rogue killer

stopped other running processes

ran scan for roguekiller

"status: scan finishes please look at the different tabs and delete items with the buttons"

Attached File  RKreport0_S_12142013_212144.txt   1.58KB   2 downloads

 

my kaspersky key arrived that i ordered for my internet security 2014. so you know its ready to add but i will wait til directed.

 

 


Edited by MsInformation, 14 December 2013 - 09:28 PM.


#7 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:21 AM

Posted 15 December 2013 - 12:34 AM

1.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Clean.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

 

2.

I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png  button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.png
       icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#8 MsInformation

MsInformation
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 15 December 2013 - 11:38 AM

pc is really struggling with restarts and closing things and all this.

 

 

 step one. 

attempt 1 did not automatically say clean, i needed to scan and the tab that was in the front was folders. it appears only folders was cleaned,

attempt 1 logfile only included "folders"

that log file is here

Attached File  AdwCleanerS0.txt   2.79KB   1 downloads

 

attempt 2

felt more automated, ran a scan on its own  when i started it

*i did not see anything check marked during this scan except n the firefox tab but it seemed more automated than the previous time.

Attached File  AdwCleanerS1.txt   1.36KB   1 downloads

 

 

 

Step two

Attached File  ESETScan.txt   242bytes   2 downloads


Edited by MsInformation, 15 December 2013 - 08:55 PM.


#9 MsInformation

MsInformation
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 15 December 2013 - 08:59 PM

:thumbup2:



#10 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:21 AM

Posted 15 December 2013 - 11:14 PM

1.

We need to download Temp File Cleaner (TFC) by OldTimer:

  • Please download TFC.exe by Oldtimer at one of the two links: Link 1 Link 2
  • Save and close all running applications
  • Double-click on TFC.exe to run the program
  • Click on Start to begin the cleaning process
    note: this program may close running applications, make your screen disappear temporarily, or require a reboot of your PC - this is normal and part of the cleanup
  • When the scan is complete, if you were not asked to reboot the computer, please do so now


More Information can be found about the tool here: http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/

 

2.

Download Windows Repair (all in one) from this site

Install the program then run it.

Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:

p22001645.gif



Once that is done then go to Step 3 and allow it to run System File Check by clicking on Do It button:

p22001646.gif


Go to Step 4 and under "System Restore" click on Create button:

p22001644.gif


Go to Start Repairs tab and click Start button.

p22001166.gif


Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):

p22001647.gif

Click on box next to the Restart System when Finished. Then click on Start.

 

3.

  • Please download and save HardwareInfo to you desktop.
  • Double click HardwareInfo it will produce a log named HardwareInfo.txt.
  • Copy and paste that log in your next reply.

 

 

How is your machine running after running these tools?


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#11 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:21 AM

Posted 19 December 2013 - 04:57 PM

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 3-5 days the topic will need to be closed.

Thanks for understanding :)

With Regards,
fireman4it


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#12 MsInformation

MsInformation
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 19 December 2013 - 05:00 PM

im sorry. dealing with a loss of power with the storms etc. i will make this a priority tomorrow morning. thank you for your patience.

#13 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:04:21 AM

Posted 19 December 2013 - 05:21 PM

Take your time. Just wanted to know you were still needing help.


Edited by fireman4it, 19 December 2013 - 05:22 PM.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#14 MsInformation

MsInformation
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 20 December 2013 - 02:42 PM

Working on this now. 

 

I am having major connection issues when i turn this pc tower on. it knocks out my entire networks wireless connection meaning my netbook loses connection too when the tower is turned on.

 

i can trigger the connection problem when i use the utorrent program on either my tower or netbook with or without the tower connected.

 

i called my internet provider to see if it was them having signal issue when it first started (day 3 of this virus) and was told its not them, my signal is solid and that my modems warranty had expired 5 days previous, she had me plug in ethernet to the netbook to see if signal was lost but it was hard to tell because being wired i wasnt watching  it ever second but i didnt see a connection issue once ethernet was used.

 

 

okay onto fixing the things u recommended,,just know connection may be an issue and slow me down and i do need help with it too.,



#15 MsInformation

MsInformation
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England, USA
  • Local time:04:21 AM

Posted 20 December 2013 - 03:23 PM

i did 1, no problems. TFC

 

onto  2 for Windows Repair

under  step 3 it says to have my windows disc if i have XP. i have XP pro and do not have my windows disc. do i still do step 3 System File Check and continue?

 

awaiting your reply 


Edited by MsInformation, 20 December 2013 - 03:27 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users