computer internally melting down...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aokmaster42, Jun 9, 2005.

  1. aokmaster42

    aokmaster42 Private E-2

    Yesterday my computer had something happen to it and now it's definetely got some issues that I need help with. It's pretty much "melting down" and I can't do anything. I minimize windows and they disappear. I can't move anything on my desktop (like to a zip drive or a memory key). I can't run add/remove programs because it says microsoft installer is corrupt or something along those lines. Norton's antivirus 2003 no longer works and can't be run. I can't use my burner to back things up. I can't access my computer's shared files on the other computer on my network. I've ran and used ad-aware, spybot s&d, registry mechanic, ewido, cwshredder, cleanup40, norton's utilities, and hijack this. I'd be happy to post my log if someone could analyze it for me. I have absolutely no idea what happened. My start menu doesn't appear half the time either. I can't do a system restore back to a previous point, it never works. I ran house call and it found something called troj keenval.e. It used to take 30 seconds to boot up my computer, it now takes 5+ minutes. I have 3+ years of stuff on this computer and I don't want to just wipe it all out. I want to try everything possible first. I've been working on things for over a day now, and I don't know what to do anymore. Can anyone help me???
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you can download, install, and run programs, follow the procedures below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. aokmaster42

    aokmaster42 Private E-2

    I really apologize, but I can't click on any links. I click on them and nothing happens, they won't take me anywhere. I have my hijack log file though. I'm sorry too but I can't attach the file, I'm lucky that I can even paste it in here. I know you're not supposed to paste it, but I couldn't attach it.

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jun 9, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but at least follow directions and install HJT properly. You have it:
    C:\Documents and Settings\John Hilgers\Desktop\HijackThis.exe

    Directions specifically request that it not be put there. Please fix that now.

    Also why were the below running:

    C:\Program Files\Internet Explorer\iexplore.exe <-- all browsers should be closed
    C:\WINDOWS\system32\taskmgr.exe <-- unnecessary and should not be running at this time
     
    Last edited: Jun 9, 2005
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After addressing my previous message, continue with these steps.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
    O2 - BHO: (no name) - {5FDDA881-274E-3479-A589-CDBC989EDCE5} - (no file)
    O2 - BHO: (no name) - {82315A18-6CFB-44a7-BDFD-90E36537C252} - (no file)
    O3 - Toolbar: (no name) - {722C4620-805D-48FE-8259-F449DF362212} - (no file)
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (file missing)
    O15 - Trusted Zone: http://Download.Windowsupdate.com
    O18 - Protocol: relatedlinks - {CD8D1CAA-FE4A-45DF-A06C-028AAF1821DE} - (no file)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot your PC (in normal mode) and post a new HJT log. And tell us how things are working.
     
  6. aokmaster42

    aokmaster42 Private E-2

    Well I was able to follow your directions as best I could. There was one problem...my computer would NOT let me disable system restore. it said there was a problem enabling/disabling it, please restart your machine and try again. I did that, but it still wouldn't let me. Thanks for all the help so far and I apologize for not following the correct directions. I still can't move items on my desktop and they still disappear when I minimize them. Both Norton's programs still are corrupt. It still takes just as long to start up. I'm not sure if there's any difference. I can't copy and paste things either. Windows installer service cannot be accessed. I can't make a data CD to try and back things up.

    Here's my new hijack log. Once again I apologize for not attaching it. Thanks again for the help. It's much appreciated.

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jun 9, 2005
  7. aokmaster42

    aokmaster42 Private E-2

    Also, I was still unable to click on the sticky thread the "READ ME FIRST BEFORE ASKING FOR SUPPORT" The little pointer acts like you can click it, but if you do, nothing happens.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your installation CD for Norton AV and Norton Utilities? If so, perhaps you should uninstall them, reboot, and then reinstall. Then try running a antivirus scan. It may be best to run it in safe mode.
     
    Last edited: Jun 10, 2005
  9. aokmaster42

    aokmaster42 Private E-2

    I uninstalled utilities, but it won't let me do norton's antivirus. It says "preparing to install" then it says "the windows installer service could not be accessed. This can occur if you are running in safe mode (which i'm not) or if the Windows installer is not correctly installed."

    Anything stand out on the new highjack log?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. aokmaster42

    aokmaster42 Private E-2

    If I right click on the READ THIS FIRST and save the target, i can then open it. I went down and ran services.msc when it came up, to the right of Services (Local) ... in the big box, nothing is showing, half of the screen is just pure red. Do you have any idea what could be wrong? I'm running a squared right now and housecall
     
  12. aokmaster42

    aokmaster42 Private E-2

    I really just want to be able to drag and move things so i can backup some of my files, then I'm just going to reinstall xp. Do you know what could cause my computer to not be able to move things on the desktop? or copy and paste it or drag and drop it?
     
  13. aokmaster42

    aokmaster42 Private E-2

    I doubt this helps, but here are some more errors/problems I'm experiencing.

    *I can't open media player because of "low memory"
    *I could open that website from symantec for the norton's uninstaller but it wouldn't open the file to download
    *In my task manager it doesn't display my name under the "user name" it's just blank
    *I can semi open norton's antivirus, however everything just says "refreshing" and i can't scan for viruses.

    A squared has currently found 4 malware files and is about 40% done.

    I really don't know what else to do or try.
     
  14. aokmaster42

    aokmaster42 Private E-2

    This is what house call found
    Troj Keenval.e in C:\System Volume information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1363\A0217447.exe

    This is what HiJack Free Found

    Name Command Description
    Norton Auto ccApp.exe Added by the Akher.d worm
    Protect

    Symantect ccApp.exe Added by the Akher.d worm
    Service

    ccApp [random Added by the Absorb trojan
    filename]

    ccApp WMADZ.Exe Added by the RBOT-LJ Worm

    AVG Grifsoft updater.exe Added by the AGOBOT-OT Worm
    Updater



    Then one more

    Port Protocol
    1492 TCP FTP99CMP,Back.Orifice.FTP


    Those are the things that are messing up my computer...Do you know how to get rid of them? Granted the system restore can't be shut down and norton's doesn't work?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you did not do step 1 of the READ ME FIRST. That is, system restore is supposed to be disabled.


    ccApp.exe is a valid Norton Antivirus process.

    If you have WMADZ.Exe , that is a problem and you should delete the file.

    The updater.exe file I would have to know where it was located.
    However from you HJT log. it was part of your iRiver Manager. See the below line.
    O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe

    Does ftp99cmp.exe actually exist on your PC? If so, delete it.
     
  16. aokmaster42

    aokmaster42 Private E-2

    My computer is running efficiently and seemingly perfectly smoothly, however when i ran hijack free with a squared and it still says the same trojans/worms were found. any idea how to get rid of them? Norton's virus definitions doesn't include these which is why i'm assuming it's not catching it. I have no idea how to clean those out of my computer.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please provide a detailed list of the exact file names and paths that are being found.

    Did you you disable system restore now?

    Did you delete WMADZ.Exe ?

    Please provide feedback on instructions given. It is difficult to help you without feedback.
     
  18. aokmaster42

    aokmaster42 Private E-2

    I couldn't find WMADZ.exe (or don't know how to find it correctly)

    I uninstalled norton's 2003 and ran the a squared hijack program and all 4 of the errors/bugs/worms in ccapp were gone (obviously since it was no longer on my computer) (system restore was disabled) then i reinstalled norton's and ran the a squared hijack free analysis and all 4 of those things were back. this is exactly what it says on the website analysis

    Name: ccApp
    Path: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Good - 1 Bad - 4

    X Norton Auto-Protect ccApp.exe Added by the AKHER.D WORM! Note - for the valid Norton AV entry the filename is "navapexe". This is also not the valid Norton AV file with the same filename

    X Symantec Service ccApp.exe Added by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filename

    Y ccApp ccApp.exe Part of Norton AntiVirus 2003. Auto-protect and E-mail check will not function without this

    X ccApp [random filename] Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus

    X ccApp WMADZ.EXE Added by the RBOT-LJ WORM!

    key:
    "Y" - Normally leave to run at start-up
    "N" - Not required - typically infrequently used tasks that can be started manually if necessary
    "U" - User's choice - depends whether a user deems it necessary
    "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
    "?" - Unknown

    Then...

    Port: 1025 TCP
    Path: C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Process ID: 120)

    1025 TCP/UDP NetSpy, Maverick's Matrix, RemoteStorm



    That's all that it finds for problems. Everything else i've ran found nothing (housecall, spybot, nortons, nortons utilities, registry mechanic and panda)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! Forgot. Too many threads going! But now he has it disabled.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would appear that you are getting false positives from A-Squared. The problem here is that they confuse people the way they word things. As long as the programs are running from the proper folders, they are okay.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds