HJT log/problems/questions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JaneC, Jan 7, 2006.

  1. JaneC

    JaneC Private E-2

    Hi,

    This is my first time posting and I hope I've done everything right. I did everything in the read before posting thread. I have all the programs loaded, have run them all, did it in safemode, etc. I want to mention something that I'm not sure about. I have Zone Alarm and every time I turn my computer on it asks me about a run dll and win NT logon. I deny both of them because I don't know if they would cause a problem and suspect they would. I would assume if it was the regular logon and I was denying it, my computer wouldn't be running?? I've run HJT more than once and cleaned/fixed according to what you have written on the HJT log page describing what the programs are, etc., and what to get rid of. Even after cleaning, when I run it again it keeps showing the dll under 020 winlogon notify. I have no idea what that is.

    Anyway, I will attach my HJT log.

    Thank you in advance for any help you can give.

    Jane
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    That is not a complete HJT log there are some obvious things missing like all of the processes. You must follow the directions in step 7 exactly. Also you have not run ALL steps in procedure. Like step 6 and the associated logs required.

    You should not be fixing anything on your own using HJT. It is not a tool for inexperienced users.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
    You have a Look 2 Me infection.
     
  3. JaneC

    JaneC Private E-2

    Hi,

    I'm sorry, I thought I had done everything correctly. Somehow I totally skipped over the bitdefender and panda scan. Also, I didn't delete anything in hijack this except for start-up pages in IE, because it was obvious they were not what I had for my start-up page. I don't even use IE anymore, I use firefox.

    I redid the whole thing last night from scratch. Safemode, etc. I already had all of the programs installed {spybot, etc.}. The only problems I had running anything were with bitdefender and panda. Bitdefender scanned and found a trojan and deleted three files. At the end of the scan it totally froze up and stayed that way so I had to shut down. I signed on this morning and ran it again. It didn't find anything, but booted me as soon as it finished scanning. I went to run panda and it wouldn't run. I got to the page where I chose what to scan and it kept saying I had an error on the page. I DID use IE for these scans though and not firefox. I rebooted and tried again, I refreshed, etc., and still got an error on page, so I couldn't run it.

    When I was in safemode with networking I was getting a ton of firefox popups.

    Hopefully this HJT log is correct. I went to msconfig and selected normal start up and rebooted before running it.

    Thanks again, and I apologize for my first post.

    Jane
     

    Attached Files:

  4. JaneC

    JaneC Private E-2

    I forgot to mention, none of the spyware scans found anything. The only thing that came up was the MRU list in ad-aware. All of the other programs found nothing.

    Jane
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I notice that you have a firewall from AOL installed and also ZoneAlarm firewall installed. You must use only one firewall. Please uninstall one. Personally I would not use any of AOL's tools but that is your decision. Also make sure you do not have the firewall in WinXP SP2 enabled.

    I also notice you have Spybot's Teatimer running which we suggest not to use. It could make it difficult to remove some problems and it has been noted to be a resource hog. With MS Antispyware installed and running you should disable Teatimer.

    Look in Add/Remove programs for Media Access and uninstall if found.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} -
    O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} -
    O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} -
    O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Media Access <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode.

    You have a Look 2 Me infection we need to fix now. So run the steps in the below link and post the two logs.

    Look2Me VX2 Removal


    After running the above post a new HJT log. And tell us how things are working.


    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. JaneC

    JaneC Private E-2

    Thank you so much for your help!

    I did everything you wrote in your post. Before I read your post I had run my spyware again to see if it would find anything. Ad-aware found IEHijacker.zestyfind and Spybot found coolwwwsearch.feat2installer. I had them fix both of them so that may be why I didn't see everything you told me to fix in hijack this. The only things missing were the mediaaccess and the 016 DPF 31e one. The others I fixed.

    When I rebooted the first time I got another popup on firefox and a mcaffee found a suspect file.. run a scan now. When I rebooted the second time I got the mcafee warning again.

    As far as AOL's firewall, when I installed their security stuff I told it NOT to install the firewall. When I pull up the safety controls it says zonealarm is installed and I should install AOL's firewall. So it says it's not running. I do see it in programs in hijack this though, so I don't know why it's there. I still have my computer set for normal start-up as well. I had also turned off spybot's timer as well, but for some reason it came back on. It's not running now on my toolbar at start-up. I had disabled it after coming to this board and reading where you all said not to run it.

    Anyway, here are my logs. Thanks again!

    Jane
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said the following:
    Why would they say you should install AOL's firewall if ZoneAlarm was already found? They should say and do the exact opposite.


    Well the L2MeFix tool seems to have been blocked from fixing the infection. If Teatimer had been running that may be why. Also it is possible that MS Antispyware interferred with it (or something from AOL).

    So let's first do the following to make sure they do not get in our way:
    - uninstall MS Antispyware using Add/Remove programs (you can re-install later when we get finished with all fixes
    - double check to make sure Teatimer is disabled. To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer. Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked. Now quit Spybot!

    Then re-run the Look2Me VX2 Removal steps and post the logs again. But this time while running them make sure you physically disconnect from the internet (unplug the cable) and make sure no browsers are opened while running the tool.
     
  8. JaneC

    JaneC Private E-2

    AOL has a "safety and security center" thing. It shows that your virus software is running, spyware software, etc. They are the ones saying I should download their firewall because they claim that way the security center can monitor everything on your computer and they can't monitor zone alarm. I'd rather keep zone alarm. I trust it more than a firewall they'd have.

    Anyway, I did what you stated and I will attach the logs. I did another hijack this log as well because I wasn't sure if you wanted that one too. My virus software ran a scan earlier and came up with nothing. I know that doesn't mean anything, but just wanted to mention it.

    Thanks!

    Jane
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something is still preventing the tool from working properly. Let's try a different approach.

    Please run this Running Ewido Security Suite and attach the Ewido log.

    Then boot into safe mode to do the below. Print the below instructions or save them locally. You MUST BE physically disconnect from the internet (unplug you cable) and you MUST exit all borwsers and shut down all running applications. Right click on each item in your system tray and exit or close. Shut down everything you can. Do not plug the cable back in and do not open any browsers until I say to.

    Now while in safe mode we are going to run L2Mfix again but only option #2. If you cannot find it on your Desktop, then you may need to get back into normal mode and move the whole L2Mfix folder to a folder like c:\L2MFix which should be visible in safe mode.

    Next DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.

    Your computer will go crazy for a bit, but just let it run. It should eventually spit out a log in Notepad.

    Now plug your cable back in and open your browser to come back here and post this new log from L2MeFix.

    Also attach a new HJT log. Please tell me if you are getting any error messages of any kind while running steps.
     
  10. JaneC

    JaneC Private E-2

    Hi,

    I didn't get any error popups at any time. The only thing that ever came up was the Mcafee warning about a suspect file when I rebooted.

    The only things running in safemode while I ran the L2Mfix was
    explorer.exe, svchost.exe, lsass, services, winlogon, csrss, smss, system and system idle process. Those all need to run, right? Rundll32 was running but I stopped it. It came back and I stopped it again. It didn't come back again after that.

    My logs are attached.

    Also, I did not run the ewido in safemode because you didn't say to and I wasn't sure if I needed to or not. I rebooted in safe mode to run the L2Mfix, unplugged the cable like you told me to, etc.

    Thanks!

    Jane
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I quote from the directions in the link I gave to you for running Ewido
    For some reason the tool just keeps getting blocked on your system. I have never seen this before. Let's try another toool and we will see what happens.

    Run this tool and follow the directions on the download page:

    Look2Me Remover

    Afterwards reboot and then post a new HJT log.
     
  12. JaneC

    JaneC Private E-2

    This is driving me nuts! I don't think it fixed it this time either.

    I downloaded the L2me remover. I clicked scan and my computer crashed. Restarted, tried again and crashed again. So I rebooted in safemode, unplugged the cable and re-ran the CCleaner and ewido. I'll post the ewido log below. REbooted and ran the L2mefix. I'll attach that log as well. Then I figured I might as well try the L2meremover in safemode so rebooted and tried to run it. I got an error that a file wasn't found, but it brought up a registry key. I didn't see a way to save a log, but copied and pasted the results from the bottom of the scanner. It said..

    17:07:10 -> Start scanning procedures...
    17:07:10 -> Suspected Registry Key found. Key added to list.
    17:07:10 -> Start checking running tasks...
    17:07:10 -> End of the scan process.
    17:07:18 -> No ACTIVE virus/trojan found in Memory but the Registry contains suspected voices! The voices are listed in the Registry Key Found box. We suggest you to delete them using the Delete Keys button!
    17:07:32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MS-DOS Emulation deleted!
    17:07:34 -> Key(s) deleted! Please, reboot the machine now!

    I'll also attach the newest HJT log.

    Thanks again for your time and patience!

    **I just tried to upload the log from l2mefix and it says I've already uploaded this log. That's the newest log in the folder {the only one in the folder} but even when I try to change the name to log1 and upload it says the same thing??**

    Jane
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but do you see the big difference in the Ewido log this time vs last time from normal boot mode. Notice how it now found a load of Look 2 Me problems.

    Make sure during this whole procedure below that no browsers are running and no connection to the internet is available.

    Please run Ewido two more times (both from safe mode) and save the log each time to a new name. (Note if the first run shows no Look 2 Me infections at all, you do not need to do the second one).

    Then reboot into normal mode and run both steps in the original Look2Me VX2 Removal thread and when complete, reconnect to the internet and come back and attach those two new logs also. .
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If this does not work, you will have to uninstall all the AOL antivirus, antispyware, and firewall software and possibly the McAfee AV too. You are probably having conflicts from this software due to multiple AVs and firewalls as stated earlier. And once bad stuff like this is on a PC, the protection tools can make it difficult to impossible to remove the bad stuff. This happens because they are monitoring the steps we are performing and to them, what we are doing looks like malware and they block what we are doing.
     
  15. JaneC

    JaneC Private E-2

    Well, I did it and think it's still on my computer. I'll attach the logs.

    As far as the virus software, etc... I had Mcafee originally. I had a version that was free for AOL hosts back when I was a host. I kept that on my computer and kept it updated. When I saw that AOL had a security thing to download with the spyware, etc., I uninstalled McAfee and installed AOL's stuff. The McAfee I have now is still through AOL. That's all that should be on the computer as far as virus software unless there is something there that I don't know about. I don't know how to read the logs, so if I need to uninstall something, just let me know what to do and I'll do it. AOL still says I do not have their firewall installed and I just have zone alarm so I'm totally lost there.

    Here are the logs and thanks again!

    Jane
     

    Attached Files:

  16. JaneC

    JaneC Private E-2

    And here is the HJT log if you want that too.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well for some reason, L2MeFix can find the infected files in the first scan (option 1) but when it trys to repair them (option 2) it is not finding and removing the files. It happens everytime. We use this procedure dozens of time per week and it normally works. So unless you have a brand new vintage of the infection (I don't think so) this still leads me to all the stuff installed from AOL possibly getting in our way. It still looks to me like you have the olde McAfee running to as indicated by the below lines in your HJT log.

    C:\PROGRA~1\mcafee.com\ANTIVI~1\OasClnt.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
    O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
    O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe

    Let's try one more thing and hope that it works otherwise you will have to uninstall ALL the McAfee and AOL software.

    Download, install, update and run this slightly older version of Spy Sweeper: here
    Save the Spy Sweeper log and post it here as an attachment.
    Also post a new HJT log.
     
  18. JaneC

    JaneC Private E-2

    Wow, could it finally be gone?? I ran spy sweeper and it found icannews, look2me, screensavers, shopathomeselect and winad. It had me reboot when it was done, to finish removing everything. I rebooted and had to run out for a little bit so figured I'd just run it again while I was gone and see if it found anything. I came back and it said it found nothing! I will attach the HJT log and hope you don't see anything there!

    Thanks,

    Jane
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Yes it is gone. It would be helpful if you could find and upload the SpySweeper log as an attachment. I would like to see more info on what it found.

    Obviously it one item was the Look2Me infection we were trying to fix but I'm wondering what was blocking L2MeFix from fixing problems.
     
  20. JaneC

    JaneC Private E-2

    Hi,

    I didn't see the log the first time so didn't save it. I just saved it and will post it below. I did get another McAfee popup that said I have a suspect file on my system, but I have no idea why.

    Hopefully everything is fine now and it's gone and will stay gone. :eek:)

    Thank you so much for your help. I never could have figured this out on my own!

    Jane
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Well Spy Sweeper find the same files that L2MeFix was trying to repair. But Spy Sweeper was able to finish the fix which is great.

    Your last HJT log was clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds