The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.

windows shuddown busted - just hangs nothing but desktop image on screen

Discussion in 'Dell Latitude, Vostro, and Precision' started by anthonology, Dec 27, 2008.

Thread Status:
Not open for further replies.
  1. anthonology

    anthonology Newbie

    Reputations:
    0
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    5
    Good day or night,

    Earlier today I got a nasty trojan off my computer. And now XP won't shutdown. The shutdown process begins, icons and taskbar disappear, and then it stops, nothing on the screen but my desktop image. The thing even goes into sleep mode this way. But no shutdown.

    I have tried some standard troubleshooting. Updated to SP3, updated Dell BIOS (have Vostro 1400). No luck.

    Could this have been damage caused by the trojan? Several trojans were removed during safe mode by Malewarebytes [only log with removal info below]. The log means little to me. Not sure if I had a zlob.g, zlob.d or a win32.zafi.b. A fake "windows security alert" was coming up warning about a "win32.zafi.b" and then mozilla stopped working and IE took me to a "safe soft review" website and then shut down.

    Anyone have any suggestions? Anything appreciated... :confused:

    Anthonology

    =============================================

    Malwarebytes' Anti-Malware 1.30
    Database version: 1321
    Windows 5.1.2600 Service Pack 2

    26/12/2008 2:07:22 AM
    mbam-log-2008-12-26 (02-07-22).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 112020
    Time elapsed: 51 minute(s), 35 second(s)

    Memory Processes Infected: 1
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 2
    Registry Data Items Infected: 1
    Folders Infected: 2
    Files Infected: 5

    Memory Processes Infected:
    C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Unloaded process successfully.

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msupdate (Rootkit.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msupdate (Rootkit.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\msupdate (Rootkit.Agent) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Documents and Settings\NetworkService\Application Data\wsnpoem (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\LocalService\Application Data\wsnpoem (Trojan.Agent) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\drivers\svchost.exe (Trojan.FakeAlert.H) -> Delete on reboot.
    C:\Documents and Settings\NetworkService\Application Data\wsnpoem\audio.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\LocalService\Application Data\wsnpoem\audio.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\~.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\msvcrtd.exe (Rootkit.Agent) -> Delete on reboot.
     
  2. man00

    man00 Notebook Geek

    Reputations:
    195
    Messages:
    99
    Likes Received:
    0
    Trophy Points:
    15
    maybe try a repair install, sometimes after a virus/trojan is just best to reinstall.
     
  3. anthonology

    anthonology Newbie

    Reputations:
    0
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    5
    maybe try a repair install, sometimes after a virus/trojan is just best to reinstall.

    this might seem like a lame question, but is this something that can be done without deleting all my files and programs? i am traveling so have to wait to obtain the dell/windows disks that came with notebook.
     
  4. man00

    man00 Notebook Geek

    Reputations:
    195
    Messages:
    99
    Likes Received:
    0
    Trophy Points:
    15
  5. vinumsv

    vinumsv MobileFreak™

    Reputations:
    502
    Messages:
    1,238
    Likes Received:
    0
    Trophy Points:
    55
    you can do the in-place installation AKA Repair install :D but remeber to install all the service packs and patch which came after the version which is in the CD/DVD
     
  6. anthonology

    anthonology Newbie

    Reputations:
    0
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    5
    actually came the michaelstevenstech restore site earlier in week. was out of town, back now, so i have access to my XP disks. will let you know how things go. thanks.
     
  7. anthonology

    anthonology Newbie

    Reputations:
    0
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    5
    reinstall worked! all is good now. thanks for help. sorry to get back to thread so late.
     
Loading...
Thread Status:
Not open for further replies.

Share This Page