Freezing Browser !

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by geneman, Jan 27, 2005.

  1. geneman

    geneman Private First Class

    Hi guys

    few days back i got bunch of adrwares which i cleaned using adaware, spybot and symentec. i had also installed spyware blaster at that time and it prompted me to put some active x related settings in the internet explorer( now i cannt say wat were those and i have unistalled it now). now pop ups r cleaned, but i have a prob with the internet explorer. when i open it, it opens very late and when behaves as if it has got hanged (though in tusk list after putting ctrl alt del, internet explorer doesnt show that it is "not responding"). then when i try to close the browser the message of "this program not responding, end tusk" comes. i have recently installed mozilla also, it opens well, though lil slow. rest all programs r opening and working at normal speed.

    could any one plis tell wat may b the prob? if mozilla causing problem?

    plis help !

    best regards,
    gene
     
  2. TheOldThug

    TheOldThug First Sergeant

    Have you gone through the whole tutorial?

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    If you have then PP or Chaslang will ask you to do the following:

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT
     
  3. geneman

    geneman Private First Class

    Hi Oldthug

    thanx for replying! yes i have followed everything mentioned in the sticky thread, and after that only the broser freezing problem arised ( though i was able to clean the pop ups).
    i have attached herewith the HJT log, plis check it out..
    regards
    gene
     

    Attached Files:

  4. TheOldThug

    TheOldThug First Sergeant

    Chaslang and PP are the PROS on the HJT logs. They will get to it as soon as they can.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First go to Control Panel, Add/Remove programs and look for anything with Wild Tangent and uninstall it if found.
    Do the same for WhenU, if found.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\cmjgrfte.exe
    C:\WINDOWS\System32\msupd5.exe

    After killing all the above processes, click "Back". Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {0124A648-E06F-FC8C-4E3B-1B14764D71E9} - C:\WINDOWS\System32\epourwne.dll
    O2 - BHO: (no name) - {9FE13CF7-8771-9253-28A5-B4B05238AA13} - C:\WINDOWS\System32\iksatggk.dll
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [cmjgrfte] C:\WINDOWS\System32\cmjgrfte.exe
    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.nabausha.com/fonts/tdserver.cab
    O23 - Service: Miscrosoft Updates Service 5 - Unknown - C:\WINDOWS\System32\msupd5.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\WildTangent <-- the whole folder
    C:\Program Files\VVSN <-- the whole folder
    C:\WINDOWS\System32\cmjgrfte.exe
    C:\WINDOWS\System32\msupd5.exe
    C:\WINDOWS\System32\epourwne.dll
    C:\WINDOWS\System32\iksatggk.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Question:
    I'm curious about the next line. Do you know what it is used for? Is it really something for NetMeeting? Do you use NetMeeting?
    O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\System32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
     
  6. geneman

    geneman Private First Class

    Dear Chaslang

    After i did as u said, its working fine now! thanks man once again u have helped me, last week u helped me with another computer.. u r simply greeaat !

    but i cudnt kill this :
    O23 - Service: Miscrosoft Updates Service 5 - Unknown - C:\WINDOWS\System32\msupd5.exe

    it says:
    the following process cudnt b killed.it may have already closed or it may b protected by windows.this process may b a service wich u can stop from the services applet in the admin tools
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post the HJT log I asked for! Let's check this out a little more. That msupd5.exe file has got to be a trojan. Notice they don't even spell Microsoft correctly.

    They say "Miscrosoft Updates Service 5"
     
  8. geneman

    geneman Private First Class

    Dear Chaslang
    Sorry i am late in replying, was out of campus. i will post the HJT log in an hour, working on some sites now. anyway , i have seen some new prob with the recycle bin.
    when i delete something and go to the recycle bin, i dont see the deleted items in there (my delete immediately without sending to trash bin option is off). moreover each and every time i right click on recycle bin , and click on empty recycle bin, i see "there r 90 items in the recycle bin, do u want to delete them". even if i delete those 90 items, and repeat the above process, again i see " u have 90 items in the recycle bin". how its happening? plis help me....

    best regards
    gene
     
  9. PhilliePhan

    PhilliePhan Guest

    Hi Gene,

    Please download this tool: Generic Detection Tool - NT/2000/XP

    NOW:
    Unzip the Generic Detection Tool to a safe folder of your choice and run "find.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Please attach that Log along with a fresh HJT and Chas will probably get back to you when free time rools around.

    PP :)
     
  10. geneman

    geneman Private First Class

    Dear Chaslang and Philie,

    Here i have attached the newest HJT and Generic log. Plis help me solving the Recycle Bin problem..

    Thousand Thanks !
    Gene
     

    Attached Files:

  11. PhilliePhan

    PhilliePhan Guest

    Hi Gene,

    I think you might have additional issues, but do not have time right now to investigate further . . . . . Sorry! Busy weekend! Chas may drop in, though.

    Try this for the problem at hand:

    Please download the following tool: Pocket KillBox

    NOW:
    Please run Pocket KillBox and Copy & Paste the Following into the box: C:\RECYCLER\Desktop.ini - Click Red X to delete it using Standard File Kill.

    Do the same for these 2:
    C:\WINDOWS\system32\thinInstOIT61MegaV2s.dll
    C:\WINDOWS\system32\innathlp.dll


    NEXT:
    Copy and paste the information below to notepad. Save it to your Desktop as type "all files" and name it fixrclr.reg


    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{FCDB0592-D244-425B-8707-D113725DDCA9}"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer]



    Now:
    DoubleClick on the fixrclr.reg file you made and allow it to merge the registry entries into the registry.

    See if that helps.

    PP :)
     
  12. geneman

    geneman Private First Class

    Dear Philie

    I did as u told, and i can see items, and delete them from recycle bin now. :)
    by theway i cudnot kill the following using pocket kill box, says that file may not exist:
    C:\WINDOWS\system32\innathlp.dll

    Do u think my issue is solved, u mentioned there may b some other issues, cud u or Dr C tell me if i need to do something more..

    moreover can i delete the fixrclr.reg file from desktop now?

    best regards
    gene
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why were the below items running when you were running HJT? You must remember to exit unnecessary programs. These could have been assumed to have been malware.
    C:\Documents and Settings\Owner\Desktop\vcdcut.exe
    C:\Documents and Settings\Owner\Desktop\vcdcut.exe



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {0124A648-E06F-FC8C-4E3B-1B14764D71E9} - (no file)
    O2 - BHO: (no name) - {9FE13CF7-8771-9253-28A5-B4B05238AA13} - (no file)
    O23 - Service: Miscrosoft Updates Service 5 - Unknown - C:\WINDOWS\System32\msupd5.exe (file missing)

    After clicking Fix, exit HJT.
    Let me know if you still get an error on the msupd5.exe line.

    How is everything running now?
     
  14. geneman

    geneman Private First Class

    Hi Chaslang,
    I was using the VCDCUT just b4 using HJT and the program window of VCDCUT just disappeared of its own and i didnt see it on the tuskbar. so i had no way to close. it happened twice like that, thats why there r 2 entries of it in the log.

    anyway, i did as u told and cud fix msupd this time.
    Thanks a lot for your kind help!

    Do u think i need to do some more work? plis inform. also plis inform can i delete that fixrclr.reg file that Dr C told me to make to solve the recycle bin problem?

    Thanks a lot for the time and effort u put to help me !!!
    Best regards
    Gene
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Gene.

    Dr C is me! I think you meant the file Phillie had you put on your Desktop. Yes, you can delete that file now.

    You should now follow the steps in the below thread to help avoid future problems:

    How to Protect yourself from malware!
     
  16. geneman

    geneman Private First Class

    Dear Chaslang

    Today again suddenly the internet speed became very slow, then i put AVG antivirus, spybot and adaware. AVG and spybot cud get around 4-5 malwares and trojans. i think some traces are still left. i have attached herewith a new HJT log. i will be grateful if u or Philie have a look on it and let me know if some work is needed...
    Best regards
    Gene
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you not follow my instructions last time when I said do the steps here: How to Protect yourself from malware!

    You already had an anitvirus application installed. Why did you install AVG? That will add to your slowness. But if you want my opinion....uninstall all of the Symantec/Norton stuff and only use what is in the link I gave you. That should help speed things up. Did you install a firewall yet.

    If you are so concerned about speed and slow downs you should get rid of some of the unnecessary stuff you are running. Unless you can tell me you really need them I would say review the below:

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe <---
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe <--- do you use or need these two. Read below.
    Background tasks installed by the HP Share-to-Web software. HP’s Share-to-Web software enables the end-user to transfer pictures and images directly from their HP scanner, all-in-one multifunctional printer, or digital camera, to HP-recommended secure online photo sharing providers. These providers provide services such as secure online photo sharing, photo reprints, creation and sending of electronic or printed greetings, online document and file sharing, online backup of important files.

    C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe <--- non-essentional. See: http://www.liutilities.com/products/wintaskspro/processlibrary/hpqcmon/

    C:\Program Files\Winamp\Winampa.exe <--- I don't think you need this at startup
    C:\Program Files\iTunes\iTunesHelper.exe <--- non-essential but causes problems if you stop it.
    C:\Program Files\QuickTime\qttask.exe <--- definitely not needed
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe <--- definitely not needed

    C:\Program Files\hp center\137903\Program\BackWeb-137903.exe <--- non-essential. See http://www.liutilities.com/products/wintaskspro/processlibrary/backweb-137903/
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe <--- non-essential. See http://www.liutilities.com/products/wintaskspro/processlibrary/ymsgr_tray/
    C:\Program Files\WinZip\WZQKPICK.EXE <--- non-essential. See http://www.liutilities.com/products/wintaskspro/processlibrary/wzqkpick/
     
  18. geneman

    geneman Private First Class

    Hi Chaslang

    Actually i installed AVG yesterday only just after when i got some spywares in spybot. usually i install and uninstall it after one or two scan.

    tonight i m gonna follow the instructions of "How to Protect yourself from malware!"

    regarding all those processes u mentioned, no i dont need any of them. plis let me know how i can remove all those stuffs?

    thanking you
    gene
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about that? Someone installed WinAMP you need this at startup
    and iTunesHelper.exe .

    Let's just start with the below and we will continuing discussing what's next.
    Have HJT fix these two lines:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
     
  20. geneman

    geneman Private First Class

    Dear Chaslang
    actually the guy who was having the PC with him earlier, may b he had installed winamp and itunes. can u tell me wat r their works? so that i can decide shud i remove it or not, as far as i know i dont remember using those two.
    gene
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't quite understand what you are saying in the above.

    Is this your PC?
    Does anyone else use it? If so, do they use any of those programs?

    Did you fix the items I already gave you to fix with HijackThis? I'll repeat them:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
     
  22. geneman

    geneman Private First Class

    chaslang,

    the pc was with one of my frend , but its with me now, he doesnt use it anymore. i think the 2 u told me to remove r related with real player and quicktime player. isnt it? i sometimes use these two players, so if i kill them will the players stop working ? lemme know plis..

    thanx

    gene
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Removing those two items from startup by having HJT fix them will not prevent the applications from working when you need them.

    What about the Winamp and iTunes?
    Do you use them?

    Do you uses Yahoo Messenger?
    Do you have the HP Printer and do you need those capabilities I mentioned?
     
  24. geneman

    geneman Private First Class

    Dear Chaslang

    winamp i use sometimes for music, itunes i dont use.

    moreover i dont use any printer.

    regards
    gene
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You use WinAmp sometimes. Leave the program installed but fix the line I gave you related to it with HJT. It does not need to be loaded. I use WinAmp and that is what I do. When I want it to run, I run it from the Desktop or from the Start, All Programs menu.

    Look in Add/Remove programs for things relating to:
    iTunes
    Hewlett-Packard or HP Share-to-Web etc

    Tell me what you find. (if you find iTunes you should just uninstall it since you don't need it).

    What about Yahoo Messenger?
     
  26. geneman

    geneman Private First Class

    hi chaslang

    i have uninstalled itunes and have killed those two things that u told, using HJT.
    yahoo messenger i use.
    regarding things related with hp, i cudnt get which r related.. i will post a screenshot of the add/remove program list for u to look.

    by the way i m getting prob opening some sites in IE, all the things in the page doesnt get visible,
    like this page:
    http://www.timesofmoney.com/remittance/jsp/home.jsp#null

    the page doesnt load properly.. why it is? wats its remedy?

    plis inform.

    gene
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The HP items should be rather obvious. They more than likely say HP or Hewlett-Packard.

    For the other problem, you may need to check either your Active X settings.

    Check this link for how I recommend configuring Active X settings in Step 7.
    How to Protect yourself from malware!
     
  28. geneman

    geneman Private First Class

    Dear chaslang
    active x control is set exactly as per the instructions. but i cannt open certain pages, they still dont load fully..

    mozilla also cannt open those sites. may b they r not optimized for mozilla,

    wat can i do?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you done the last section of the READ ME FIRST: Keeping your computer safe and secure:


    In particular the Sun Java install. Use the MSJVM Removal Tool 1.0a automatic removal tool first.
     
  30. geneman

    geneman Private First Class

    Hi Chaslang

    while going thru my "add and remove program" section, i have noticed something called "arcsoft software suite" which is of a 573 MB size ! what is this?? i think i dont use it for any purpose. shud i remove this ?? plis advice.

    regards
    Gene
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure? See this: http://www.arcsoft.com/en/products/photosoftware.asp

    Please answer my previous message!
     
  32. geneman

    geneman Private First Class

    hi Chaslang

    Thousand thanx for the lightening speed in replying. i really appreciate it !
    I am goin thru the arcsoft software site u gave. m goin thru it, it seems its related with photo editing. but i dont see any icon of "arcsoft" on my desktop to see wat kinda work the arcsoft i my computer can do. so not being able to know if it may help me in some way or not.

    regarding your earlier question, i think u r telling about removal of microsoft java and install of sun java. actually few days back when i wanted to get Netscape i got the option of installing Sun Java2. i opt to do that.. but the installing was going on for ever.. uptill about 1.5 hour it was saying "configuring sun java2". i got confused and stopped the install. now in "add and remove program" list i see "java 2 runtime environment", but thinking that i stopped java 2 install in between , i tried to remove that "runtime environment" but it doesnt get removed, the name is still there in "add remove program" list.

    so i donno wat i m doin.. hehehe...plis help..

    Regards
    Gene
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was the Arcsoft program installed in another user account?
    Also not all programs have Desktop icons. Look in Start, All Programs for it too.

    I'm not sure what to tell you about your Sun Java problem (actually both of these issues really are candiates for the Software Forum).

    Try looking at this link: http://www.java.com/en/download/help/5000010400.xml

    You have to realize that this can be a large installation. If you are on dial-up, it can take a very long time.

    You may need to just download an install again.
     
  34. geneman

    geneman Private First Class

    i didnt get properly wat u meant by "was the acrsoft installed in another user account". it was installed by my friend who no more uses the computer. i saw the program , it has some photo editing options, didnt seem to be very helpful to me, so shud i uninstall it? or there may b some prob in proper functioning of the computer if i remove it?

    geneman
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't need, just uninstall it!
     
  36. geneman

    geneman Private First Class

    Dear Chaslang

    Ok i will uninstall the arcsoft.

    Moreover i saw a strange thing today while shutting on the compu. at first it didnt get booted, though the green light in the tower was on but there was nothing in the screen. then i put off the power, and again tried to start the compu. this time it booted but a message came at first, it was very long, but the first few lines that i cud read b4 it disappeared were like "we are sorry, your windows didnt start properly, a recent hardware or software change may have caused it. u can choose to start with last best windows configuration ...(or something like that)...
    then the message disappeared and the compu booted..
    now i was thinking wat change i made last night, i tried to uninstall that java 2 runtime environ. once again.. thats wat i did... though it is still there in the "add or remove program " list....
    i know this question is better to b put in the software forum, but i thought it will b better to inform u also...
    Regards
    Gene
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It would be better in the Software Forum! Do you have that problem all the time or only that one time?
     
  38. geneman

    geneman Private First Class

    it happened only that one time.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So is eveything else okay now?
     
  40. geneman

    geneman Private First Class

    ya everything ok now chaslang.

    thanks a lot for your help !

    gene
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  42. geneman

    geneman Private First Class

    Dear Chasland,

    How u doing man?

    Was absent for long. back from a long tour throughout asia. i am getting some prob with my pc. when i open any program like a video editing program, the pc gets very slow. why it is? could u plis put some light in this matter/

    Best Regards
    Gene
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hi Gene! You probably should have started another thread for this and it may really belong in the Software Forum. Video editing can require a lot of horsepower. Is your PC fast enough and do you have sufficient memory? Which video editing program?

    Unless you have a malware problem this is better discussed (as stated) in the Software Forum. If you have malware issues. It would be best to start a new thread here after first running thru the standard cleanup procedure: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  44. geneman

    geneman Private First Class

    Dear Chaslang

    Sorry i posted it in the wrong place but as u were dealing with some other isues of this computer thats why i posted it here. anyway, my computer is 512mb ram, athlon processor , 80gb (i m using about 70gb now).

    Regards
    Gene
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Processor Speed?

    Still sounds like a software forum issue?
     
  46. geneman

    geneman Private First Class

    Dear Chaslang,

    Thousand thanks for giving me some time in your very busy schedule in here. I think lately i got some spywares. day b4 yesterday i downloaded a torrent client and got these trojans packed with it..
    I have ran adaware, spybot and AVG and they cleaned few trojans. But after few hours again if i run them i get some more, that means all traces havent got removed. i have followed all the primary guidelines given in this forum.

    I have attached a Hijackthis Log for you to have a look.

    Best Regards,
    Gene
     

    Attached Files:

  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We always tell users to stay away from P2P file sharing programs and sites but many users just do not listen to the warnings.

    You still have not fixed what we discussed in message number 17 on 2/8/05. You are running multiple AV packages. You must uninstall either Symantec or AVG. And you also never installed the firewall as I requested in message #27 (How to Protect...). You must to this now before we continue.

    If you installed Spyware Doctor and this is the demo/trial version you should uninstall it. It is not of any use to you since it will not fix anything.
    If you bought Spyware Doctor you should uninstall it, reboot and reinstall it because it is broken.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing what I requested in the message before this one, continue with the below.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\nvstwh16.exe
    C:\WINDOWS\System32\nv4stmib.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {0124A648-E06F-FC8C-4E3B-1B14764D71E9} - (no file)
    O2 - BHO: (no name) - {9FE13CF7-8771-9253-28A5-B4B05238AA13} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [2f3W0eEb] C:\WINDOWS\bfhgrlvf.exe
    O4 - HKLM\..\Run: [sFsV35P] nvstwh16.exe
    O4 - HKCU\..\Run: [do39RRjpj] nv4stmib.exe

    Do you know what these two below items are for? If not, fix them too.
    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.nabausha.com/fonts/tdserver.cab
    O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://livenj03.rightnowtech.com/6030-b462h/rnl/java/RntX.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\bfhgrlvf.exe
    C:\WINDOWS\System32\nvstwh16.exe
    C:\WINDOWS\System32\nv4stmib.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  49. geneman

    geneman Private First Class

    Dear Chaslang,

    I did as u told, but cudnt find some of them to fix, like:

    C:\WINDOWS\System32\nvstwh16.exe
    C:\WINDOWS\System32\nv4stmib.exe
    C:\WINDOWS\bfhgrlvf.exe

    this one is of a site i visit: O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.nabausha.com/fonts/tdserver.cab

    After i did everything, i cud see pop ups.. though very few..

    i have attached the new log.

    Regards,
    Gene
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do what I asked in message #47 and then post a new HJT log. You MUST do this before we continue with the cleanup.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds