MSN B'defender problems may have virus...scan report incl.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by casual69, Aug 6, 2008.

  1. casual69

    casual69 Private E-2

    Hello,

    A few days Bitdefender suddenly stopped working, with a warning outling a number of issues that needed to be fixed. The Firewall had turned itself off, and when I opted for the fix, nothing happened. The AV was no longer working, basically all protection was off and it would not allow me to fix even though it was prompting me towards using fix.
    It was also not updating itself.

    Secondly at about the same time, my msn messenger began encountering problems. Once signed in, the msn icon locates in the taskbar as normal, except as soon as my mouse courser goes over the MSN icon in the taskbar, the icon disappears and msn vanishes. When i try an re-start msn the msn logo with the cross through it appears in my task bar and yea same again...mouse over icon...icon gone.

    Yesterday I ran Kaspersky's online check and this is the log that came up...

    Code:
    KASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, August 6, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Tuesday, August 05, 2008 21:21:35
    Records in database: 1057928
    --------------------------------------------------------------------------------
    
    Scan settings:
        Scan using the following database: extended
        Scan archives: yes
        Scan mail databases: yes
    
    Scan area - My Computer:
        C:\
        D:\
        E:\
    
    Scan statistics:
        Files scanned: 91754
        Threat name: 5
        Infected objects: 8
        Suspicious objects: 0
        Duration of the scan: 11:06:00
    
    
    File name / Threat name / Threats count
    C:\Documents and Settings\Desktop\USDownloader-Lite\captcha.exe    Infected: Backdoor.Win32.Rbot.rms    1
    C:\Documents and Settings\Desktop\USDownloader-Lite\USDownloader-Lite\captcha.exe    Infected: Backdoor.Win32.Rbot.rms    1
    C:\Documents and Settings\Desktop\USDownloader-Lite.rar    Infected: Backdoor.Win32.Rbot.rms    1
    C:\Documents and Settings\Desktop\Aone_Ultra_RM_Converter_v3.3.0916.rar    Infected: not-a-virus:FraudTool.Win32.SpyNoMore.g    1
    C:\Documents and Settings\Desktop\Internet.Download.Manager.5.12.Build.9.www.viciowarez.com.rar    Infected: Trojan-GameThief.Win32.OnLineGames.rzzo    1
    C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL    Infected: not-a-virus:AdTool.Win32.MyWebSearch.az    1
    C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL    Infected: not-a-virus:AdTool.Win32.MyWebSearch.az    1
    C:\Program Files\mIRC\mirc.exe    Infected: not-a-virus:Client-IRC.Win32.mIRC.631    1
    
    The selected area was scanned.
    Is that log any help at all?

    I really am out of my depth and lost on this one.





    .
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not sure if your problems are due to malware. Let's find out.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.




    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. casual69

    casual69 Private E-2

    Hello,

    I've completed all the stuff asked, now what logs do I need to attach?

    Thanks

    p.s. when i ran the Kaspersky online check, one of programmes it singled out was USdownloader as being Infected: Backdoor.Win32.Rbot.rms
    I deleted the files for this, however some still remain, namely USdownloader.exe.manifest, USdownloader.ini and usdownloader.lst. When I tried removing the first a warning came up saying it was a system file and if removed my computer or one of my programs may not work properly.
     
    Last edited: Aug 7, 2008
  4. casual69

    casual69 Private E-2

    BTW, Ive just checked msn and I'm till having the same problems with messenger.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you installed USDownloader-Lite, perhaps you should uninstall it and delete all files from it since it appears to be at least one of the sources of your problems.

    The ones the procedure requested. The below is quoted from the cleaning procedure.

     
  6. casual69

    casual69 Private E-2

    Thanks, will attach.

    You mentioned I should delete all the effected files, however the question I have is, am I ok deleting USdownloader.exe.manifest, USdownloader.ini and usdownloader.lst? When I tried removing the first a warning came up saying it was a system file and if removed my computer or one of my programs may not work properly.

    Also evertime I come onto the internet I get a warning about my certificate saying someone else may be using my domain.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated, uninstall the program if it is installed. If it is not installed, just delete the files. It is not a system file and is not required by Windows.

    I'm not sure what this is but let's see your logs first. Are you on a private domain (like a company domain/network)?
     
  8. casual69

    casual69 Private E-2

    all files deleted...attaching logs, as requested.

    Thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the other 2 requested logs.
     
  10. casual69

    casual69 Private E-2

    I've tried searching for the logs but cant find them anywhere.

    Now i know there were problems but I'm also sure the programs rectified them.

    I have literally searched through everything with no luck.

    Is what I have attached of any use at all?

    Also, I've noticed that when I open I.E and log into Hotmail, as I click on an email to open, internet explorer shuts itself off.
     
    Last edited: Aug 8, 2008
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions in the cleaning procedure explain how to get the logs.

    Yes but I need to see those logs to know what problems may have been found. That info tells me what else I may need to be looking for. It also may indicated possible failures to fix something.

    Does this happen all the time?
     
  12. casual69

    casual69 Private E-2

    I've looked though every file thats a log file and looked in the program files but the other 2 are just not there :(.

    On the I.E. issue, Ive tried on 3 occasions and yes it has happened on each occasion.

    Doesn't happen on Firefox though, there its fine.
     
    Last edited: Aug 8, 2008
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Stop looking and do what the instructions tell you to do to find the logs.

    Based on the only logs you have attached, you do not have malware problems. You only have a severely cluttered Desktop that you need to fix. You need to stop downloading things to your Desktop. You even have duplicates of many files saved there.
     
    Last edited: Aug 8, 2008
  14. casual69

    casual69 Private E-2

    I only started searching for them after I was unable to find them in the way outlined by the instructions.

    I agree my desktop is cluttered and I;ll work on clearing that up today.

    However what would you say accounts for I.E. turning itself off, the msn problems I'm encountering via my taskbar, and being asked on 7ral occasions to verify my certificate when I try to use the internet saying someone else may be using my connection.

    I'm also unable to download updates from microsoft.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These all sound like problems within your Windows Operating System
     
  16. casual69

    casual69 Private E-2

    Thank you for your help so far.

    Don't know where I would be with out this forum.

    If the problems I'm experiencing are within my operating system, how can I fix them?

    BTW All the problems I have began after bitdefender crashed and I was unable to fix the errors it was showing.
     
  17. casual69

    casual69 Private E-2

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the current version of MGtools.exe to C:\MGtools.exe and run it to produce a new MGlogs.zip file. Attach the new log.


    Try shutting down your download manager and then do your update. Are you referring to a Windows Update?
     
  19. casual69

    casual69 Private E-2

    I completely uninstalled IDM, and then tried again. Once again not downloading. M'soft updates tried to download service pack 3 to my laptop, and whilst it got past step one, it then froze on the main download showing 0% progress even after 3 hours.

    I'm now downloading MGtools.

    Thanks for your help so far.
     
  20. casual69

    casual69 Private E-2

    Hello,

    Log attached after fresh scan.

    Thanks once again :)
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Okay this answers one question. Your logs from SAS and MBAM are right where they are supposed to be.
    Code:
    "C:\Documents and Settings\Kamran Malik\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~1.log   7 Aug 2008         465  "SUPERAntiSpyware Scan Log - 08-07-2008 - 14-42-36.log"
                                                                                  
    "C:\Documents and Settings\Kamran Malik\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mb6548~1.txt   7 Aug 2008         813  "mbam-log-8-7-2008 (19-44-02).txt"
    mbam-l~1.txt   4 Aug 2008        1194  "mbam-log-8-4-2008 (18-28-32).txt"
    mbam-l~2.txt   6 Aug 2008         830  "mbam-log-8-6-2008 (20-51-14).txt"
    mbam-l~3.txt   7 Aug 2008         895  "mbam-log-8-7-2008 (17-58-00).txt"
    mbam-l~4.txt   7 Aug 2008         813  "mbam-log-8-7-2008 (18-54-33).txt"
    
    Based on the size of the only SAS log, it probably found nothing. The first MBAM log from 8/4/2008 may have something in it. The others probably have nothing of interest except maybe something in the one that is 895 bytes. Attach the MBAM log from 8/4.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One other thing occurred to me. In message #1 you stated that BitDefender stopped working. I suggest that you uninstall it now since it may be corrupted. After uninstalling, reboot and see if there is any noticeable change to any problems.

    You should also uninstall SpywareGuard because it is too old and out of date to be of any real use anymore.

    Also a program for Roxio may be broken according to the below service:
    O23 - Service: SessionLauncher - Unknown owner - C:\DOCUME~1\KAMRAN~1\LOCALS~1\Temp\DX9\SessionLauncher.exe (file missing)

    Is that file really mising?

    What is the below for?
    O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
     
  23. casual69

    casual69 Private E-2



    Hi,


    Log attached as requested...

    I've tried to delete Bitdefender but so far have failed.
    Firstly I tried the Windows-provided uninstall feature but Bitdefender is not listed on there, secondly I tried finding an uninstall feature within the program, but so far have failed, I then tried deleting the folder, but I'm getting a message saying cannot delete bdch.dll access denied.

    What would you suggest I do?

    Roxio works ok, so I dont knw. Whats the file for?

    Its a file that allows me to access my desktop from any PC that also has that program installed. It allows both to connect via a pin number.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you some steps below to manually remove it.


    Then ignore it. No I have no idea what it is for, but it is a totally stupid place for them to put a service in a temp folder which is always prone to deletion.


    If you have not already cleaned up your Desktop as suggested, you should do this immediately.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!



    As far as all of your problems go, they are not related to malware. And you probably need to reinstalled Windows Live Messenger since one the files for a service seems to be missing:
    Code:
    O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\Windows Live\Messenger\usnsvc.exe (file missing)
     
  25. casual69

    casual69 Private E-2

    Thanks for all your help, Ive completed all the stuff up to this point.
    On Ccleaner do I run on the cleaner option or on the registry option?

    If on the registry option then do I fix all problems to?

    THanks
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only the same as requested in the original READ & RUN ME instructions and that is just clean temp files and nothing else.
     
  27. casual69

    casual69 Private E-2

     

    Attached Files:

    Last edited: Aug 12, 2008
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well BitDefender appears to be gone now! Do you plan on using it again? If yes, you can try reinstalling it to see if it will work properly.

    All of these may not be related to malware. You need to check your Event Viewer logs ( a Software Forum topic) to see why the IE application is crashing. Windows Update and HP Update issues are also topics for the Software Forum. Windows Update has many many reasons for not working.


    Also not a malware issue. I will take a quick stab at something. Uninstall it and DO NOT reinstall yet until I suggest that you do. Just reboot your PC and then attach a new MGlogs.zip file after running the C:\MGtools\GetLogs.bat program again.
     
  29. casual69

    casual69 Private E-2

    Thanks so far for everything!


    What would you suggest?
    If i don't use Bitdefender when it comes to Antivirus & Antispyware, a Firewall, anti spyware etc, basically am I better off doing it individually or an all in one like Bitdefender? If individually what would you use for each?

    I've tried uninstalling it, but I can't. When I try and use add/remove I receive a message saying that it can't uninstall the product as "an installation source for this product is not available. Verify that the source exists and that you can access it".
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Well we don't like security suites since they are normally resource hogs. It is more a matter of choice and ease for you the end user. Do you mind paying and would you rather have one program that gets all your updates automatically? And does the performance hit bother you?

    What we recommend (based primarily on free software) is in the below link:

    How to Protect yourself from malware!


    Then just try reinstalling over what you already have. Other than that, I suggest you post in the Software Forum for this.
     
  31. casual69

    casual69 Private E-2

    Hi

    Unfortunately MSN won't install over the original either!

    However I may have found a reason for why its crashing along with I.E.

    I was checking my system and it has something called Software Distribution Service 3.0 on it.

    Having done a check on this software, Ive found people with this software are all complaining of having similar problems.


    Turning to the security software, what products would you recommend if I was happy to purchase products as opposed to relying upon free versions?

    Thanks
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't recommend any of the paid Internet Security Suites as they are all massive resource hogs and too expensive considering the fact that they do not work very well. And I'm not particularly fond of any of the paid AV programs (if you can find one that is only an AV) either. Although NOD32 and Kaspersky are pretty good.

    Use any one of the free AV programs in the link I gave you. For realtime spyware protection, purchase SUPERAntiSpyware. Use one of the free software firewalls and also use a router with a hardware firewall. Do this along with the other tips and you should be fine. The most important part of your protection is the person sitting in front of the computer.
     
  33. casual69

    casual69 Private E-2

    Thanks for all your help!

    BTW, is it worth using a registry fix/ cleaner such as cc cleaner on the registry option or Tune up utilities?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally I don't like them, but if I do use one I just use it to get a report for items that I may want to cleanup from an application that did not properly uninstall itself (most do not). And then I selectively remove only what I want to remove. You will get a variety of opinions on using registry cleaners.

    If you do decide to use any registry cleaner, it would be a very good idea for you to create a System Restore point first, and also do a full registry backup with a program like Erunt first.

    There have been many cases where aggressive registry cleaning can remove entries required for some programs to operate and it could cause a PC to become unbootable. This is a rare case. Many people use tools like CCleaner all the time without issue. I'm just warning you of possibilities. Some people will tell you that cleaning the registry improves performance others will tell you that the any performance change is insignificant. I tend to believe that overall they may help, but I prefer to go by the old rule "if it ain't broke, don't fix it".

    This is not really a malware topic and you would get more opinions/feedback in the Software Forum if you with to discuss it further.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds