REVscene Automotive Forum

REVscene Automotive Forum (https://www.revscene.net/forums/)
-   Gaming, Computer Tech & Electronics (https://www.revscene.net/forums/gaming-computer-tech-electronics_32/)
-   -   Computer getting all messed up! (https://www.revscene.net/forums/570622-computer-getting-all-messed-up.html)

LsquareD 04-02-2009 02:07 AM

Computer getting all messed up!
 
Started messing up on April 1st (weird huh?) Really hope its not that Conflicker shit :mad:

I'll keep it point form..

- Internet slower than usual.
- Whenever I try going on a anti-virus website (AVG/Norton/etc.) The link gets redirected to some random ass link. Because of this.. my Anti-Virus/Spyware programs can't update anymore.
- Google search results also gets redirected to random links sometimes.
- Can't turn on Windows Firewall sometimes.
- Warcraft 3 crashes everytime a game starts.
- Firefox crashes every few minutes.
- I get signed out of MSN every few minutes.

There are more problems but can't think right now.. I'll update the list later.

I ran 3 scans: Malwarebytes, AVG and NOD32. Still no luck.. Might give it another scan tomorrow.

Any help and information is appreciated. Thanks!

HiJackThis Log:
Spoiler!

asian_XL 04-02-2009 02:18 AM

how many antivirus programs do you have in your computer???

Psykopathik 04-02-2009 08:26 AM

"R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local"

this line jumps out at me but don't know what it means :(

did you try scanning in SAFE mode?

kwokerz 04-02-2009 11:40 AM

sounds terrible. back up important stuff and format the damn thing!

LsquareD 04-02-2009 12:42 PM

Quote:

Originally Posted by Turbo E (Post 6361028)
"R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local"

this line jumps out at me but don't know what it means :(

did you try scanning in SAFE mode?

Just finished scanning my computer with AVG and NOD32 in safe mode. Found a trojan horse but computer still acting the same. Malwarebytes stopped working for some reason.. Gotta reinstall it.

kurayami 04-02-2009 04:35 PM

sounds like the conflicker virus to me...

Symptoms
Account lockout policies being reset automatically.
Certain Microsoft Windows services such as Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender and Error Reporting Services disabled.
Domain controllers responding slowly to client requests.
Congestion on local area networks.
Web sites related to antivirus software or the Windows Update service becoming inaccessible.

Source:
http://en.wikipedia.org/wiki/Conficker

Psykopathik 04-02-2009 05:25 PM

yah at this point cut your losses and backup critical files and do a clean sweep. it is faster than hunting this little bitch down. not as satisfying, but effective.

LsquareD 04-02-2009 07:03 PM

FML.

winson604 04-02-2009 07:47 PM

Not sure if this helps but here's microsofts guide for conflicker

http://support.microsoft.com/kb/962007

danned 04-02-2009 10:06 PM

i have a problem about keyboard and mouse

sometimes the mouse and keybroad stop working at times
when mouse stuck, i have to press the Start key from keyboard
or the tab and alt in order for mouse to move

sometimes i press tab alt, and the square is moving slowly

something wrong? i unplugged the keyb and mouse
still had this fucking problem
i even format the computer too, nothing helps
any suggestion?

kwokerz 04-02-2009 11:01 PM

Quote:

Originally Posted by Turbo E (Post 6361882)
yah at this point cut your losses and backup critical files and do a clean sweep. it is faster than hunting this little bitch down. not as satisfying, but effective.

+1

LsquareD 04-05-2009 02:44 PM

one last bump before I reformat :(

InvisibleSoul 04-05-2009 05:01 PM

O23 - Service: PnkBstrA - Unknown owner - CWINDOWS\system32\PnkBstrA.exe

That one looks suspicious to me.

LsquareD 04-05-2009 05:10 PM

^ its for COD5 when you play online to prevent using hacks or something.

syee 04-05-2009 05:17 PM

Quote:

Originally Posted by Turbo E (Post 6361028)
"R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local"

this line jumps out at me but don't know what it means :(

did you try scanning in SAFE mode?

That line is probably for Bypass proxy when the resource is on the local netowrk. (It's in your Internet Options in IE/Connections/LAN Settings/Proxy Server.

It's not the issue here.

If anything, I think it's these two lines:
O4 - HKUS\S-1-5-19\..\Run: [pibusiweje] Rundll32.exe "CWINDOWS\system32\vokuharo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [pibusiweje] Rundll32.exe "CWINDOWS\system32\vokuharo.dll",s (User 'NETWORK SERVICE')

However, they look like they are tied to specific user logins (the HKUS which is the HKEY_USERS hive) so it may happen only to certain people.

Try renaming that file vokuharo.dll (may need to boot up to safe mode to do it if the file is in use), and then restart to see if that helps.

You have a lot of stuff in your Run key. Must take you forever to boot up that machine...

Inaii 04-05-2009 06:06 PM

+1 on Conficker. I'd say play it safe and reformat.

underscore 04-05-2009 09:34 PM

Quote:

Originally Posted by InvisibleSoul (Post 6366221)
O23 - Service: PnkBstrA - Unknown owner - CWINDOWS\system32\PnkBstrA.exe

That one looks suspicious to me.


Punkbuster - Call of Duty's anti-cheating software.

danned 04-05-2009 10:04 PM

sosad..what to do


All times are GMT -8. The time now is 01:03 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
SEO by vBSEO ©2011, Crawlability, Inc.
Revscene.net cannot be held accountable for the actions of its members nor does the opinions of the members represent that of Revscene.net