Computer Issues / Hijackthis log attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by msedlak, May 24, 2006.

  1. msedlak

    msedlak Private E-2

    Hello,

    Recently I have been having some issues with my computer that I will describe momentarily. I ran my virus scanner (Panda) but it didn't find anything. Then I ran Spybot and it found a couple of things and fixed them. For good measure I decided to run Trend Micro's online scanner and when I do it finds a trojan right at the beginning but it never finishes the scan. My browser always suddenly closes halfway through the process. Anyway, I tried all of the steps suggested before and everything comes out clean. I tried some of the alternative scans but they don't find anything so maybe Trend Micro is wrong but I want to make sure. Anyway, these are some of the problems that I have been having, although many might be due to some other issue rather than a virus:

    1- When I used to download files from the internet a box would come up when it was completed asking me what I wanted to do. This box doesn't show up anymore and I am pretty sure I never checked anything telling it not to.

    2- Whenever I am on a webpage that has windows media player in it (such as when watching music videos on Yahoo) I always get a error message and the webpage closes. I tried all the suggestions that Microsoft gives after sending an error report but none of them worked.

    3- Whenever I am using microsoft word some strange things happen. From time to time when I close everything down it starts saying something like "normal has been changed. save changes?" Also, whenever I insert a table or something from Excel and try to move it, while it used to work fine now it will take it and place it somewhere like a half-page higher and wrapped into the text.

    4- When I first turn on my computer, while everything boots up pretty fast, everything runs slow for a little while. I will try to open internet explorer and it will take at least a minute for it to show up. This is after all my stuff has loaded and it happens even when things arent being downloaded, like updates to windows or my antivirus program.

    5- When I try to open up certain folders in My Computer, a box will come up saying "Connect to msnusers.com" and asking for a username and password. If I close it it just keeps popping back up. So far this has only happened when I am in My Computer.

    Thank you very much for your time.
     

    Attached Files:

  2. msedlak

    msedlak Private E-2

    Sorry, had hijackthis in the wrong place. Here is a new log with it in the right place.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please attach the two requested logs from step 6 of the READ & RUN ME.

    Since your Panda security suite also contains an antispyware application, you should uninstall Windows Defender to avoid the excess use of system resource (I'm sure Panda is already using a bunch) and to avoid conflicts.

    You do not have you Home page set to anything. Is this on purpose?

    And do you mean the popup you are getting is like below:
     

    Attached Files:

    Last edited: May 24, 2006
  4. msedlak

    msedlak Private E-2

    I have attached the two logs. I don't know what you mean about not having a homepage; when I open up internet explorer it opens google. And yes, that is the pop-up that I get.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to HijackThis. It says:
    Or are you using a browser other than Internet Explorer?


    You may be getting that popup due to certain files being in your folders that need access to MSN. When exactly does the popup occur? What folders are you accessing?
     
  6. msedlak

    msedlak Private E-2

    Nope, I use internet explorer. Thats strange. I mean, when I click on the house icon it always brings me back to google as well. It happened just now when I was trying to access my Documents and Setting folder.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which folder exactly in C:\Documents and Settings or do you mean the base of C:\Documents and Settings ?

    If the base, what files are in this folder? Give the full filenames. Make sure you have enabled viewing of hidden files, system files and extensions for known file types per the READ & RUN ME.

    Normally there are no files in the base of the folder. There should only be user account named folders like Administrator, All Users, LocalService, DefaultUser, and other user account names you have.


    Shutdown any protection software (like Panda and Windows Defender) and do the below.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings (use www.majorgeeks.com for now! You can switch to google later!):
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.
     
    Last edited: May 25, 2006
  8. msedlak

    msedlak Private E-2

    I have attached a new hjt log. The pop-up occured when I opened up the Administrator.MATT folder. I have also attached a screenshot of the contents of the folder.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see nothing strange in that folder (meaning not reason why a connect to MSN should occur).


    Your home page now shows correct as:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.majorgeeks.com/

    Now change it to www.google.com (or whatever you wanted) and that R0 line should change to whatever you use.


    Let's get a Startup List with HijaakThis.

    Generating Startup Lists with HijackThis
    • Run HijackThis, click Open the Misc Tools section
    • Put a check in the List also minor sections (full) check box.
    • Now click the Generate StartupList Log button.
    • This will create a file named startuplist.txt in the same folder that HijackThis is installed into.
    • Also a notepad file will open with this startuplist in it.
    • Attach the startuplist.txt file to your next message.
    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note something I just noticed is that you have both Panda and Symantec antivirus software installed. You must uninstall one. It looks like you maybe tried to uninstall Symantec and it did not work properly. You should neve install a new antivirus application if the previous one is still installed.
     
  11. msedlak

    msedlak Private E-2

    How do I go about uninstalling it. There is no folder for it so I cant find an uninstall icon and its not in my add/remove programs. The requested logs are attached. By the way, after getting that msnusers connect thing last time I noticed that I kept getting popup-s saying Wifi intruder detected and even if I deny them I still keep getting the pop-up periodically. This has happened in the past though so I don't know if its related to anything but I figured I should let you know. (By the way I have a wireless network in my apartment and its a pretty big apartment complex so that might be the reason.)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try something. Locat the below file using Windows Explorer:

    C:\Program Files\Common Files\Microsoft Shared\Web Folders\Msonsext.dll

    Right click on it and select Rename. Change the name to Msonsext.dll.old

    Then reboot your PC and let me know if you are still having problems and also makes sure everything else seems to work properly.

    Did you enable encryption in your wireless network to block others from gaining access to it?

    Goto Add/Remove programs and uninstall the below old version of Sun Java:
    J2SE Runtime Environment 5.0 Update 5
     
  13. msedlak

    msedlak Private E-2

    I renamed the file and removed what the old version of Sun Jave. When I went into the Admininistrator.Matt folder the msnusers connect thing didn't pop up but a wifi intruder thing did. I just remembered that I do have my network encrypted with a WEP key i think its called. I am also still having the problem with internet explorer closing down when there is a windows media player thing inside it.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware problem. It is more of an adminstration problem with your hardware and your network. You may want to check out the below programs:

    myWIFIzone

    and also maybe:

    Retina WiFi Scanner - Windows Version
     
  15. msedlak

    msedlak Private E-2

    I tried installing the program you reccommended but it didn't help. However, the wifi intruder is the only pop-up that I get when I open the folder and it only occurs once as opposed to many times. I was able to get trend micro to finish its scan and it found and removed whatever trojan it was saying it found before. Thank you for your help.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still does not sound like malware.

    Are you saying you only get this Wi-Fi intruder message when you open the
    C:\Douments and Settings\ Admininistrator.Matt folder? Does it happen when opening any other folders? If you shut down your Wi-Fi connection, do you still get the popup. Are you sure your encryption key is set? How many PCs are you connecting to your wi-fi network?
     
  17. msedlak

    msedlak Private E-2

    So far it has only happened when I open that specific folder. I am sure about the encryption key and at the moment there are two computers hooked up to the wireless, my laptop that we were working on and my girlfriends computer that I just posted something about. I disabled my computer from the network and opened the folder and the pop up did not appear.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like it has something to do with your network then. You may want to try posting a message in the Networking Forum to see if anyone knows anything about this. Is this a home network or are you at a school?
     
  19. msedlak

    msedlak Private E-2

    This is at home. When I was on the school's network I never had this problem. I will try over in the networking forum, thanks for the suggestion.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds