problem after emule

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by languy99, Dec 14, 2006.

  1. languy99

    languy99 Corporal

    my brother decied to install emule on my computer. of course i took it off as fast as possible but it was too late. ever since i can't get into hotmail, the only way to do it is in safe mode, and when i try to get into windows update is says that the site is intemperance problems. i did everything in the run and read me first, the logs are attached. Also i am having problems getting into newegg and i can't even attach the logs on this site, i have to do this from safe mode. i also get a message from my firewall when i start up that says " NDIS i/o driver (ndisuio.sys) has received a Broadcast packet from a remote machine" i never used to get this before. thanks for the help.
     

    Attached Files:

  2. languy99

    languy99 Corporal

    the other logs...
     

    Attached Files:

  3. languy99

    languy99 Corporal

    disregard that HJT log because i accidentally did it in safe mode. here is one done in normal mode sorry.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs for the following and uninstall them if found:

    Kazaa Lite (Up to you but recommended)

    Spyware Terminator

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defaults/sb/*http://www.yahoo.com/search/i e.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:4001;http=localhost:4001
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Again, make sure ALL browser windows are closed when you click FIX.

    C:\Program Files\Spyware Terminator Delete this whole folder if it exist!

    C:\WINDOWS\system32\closeapp.exe

    Next, run CCleaner to clean up cookies and temp files.

    After you complete the above, REBOOT and proceed with the rest of this fix...

    Next Reset Web Settings & Default Security Settings

    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.

    Note for IE 7 users:
    Select Internet Options, then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.

    Once you complete this post reboot and let me know how things are running and if the problem remains.
     
  5. languy99

    languy99 Corporal

    ok i did what you said and i still can't get into hotmail or even do attachments on this board, i'm doing this from safe mode. also i could not find some of the things you were talking about but went on anyway and finished everything. attached is a new htj log and some other logs form other scans i did. thanks
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs look good.

    What happens when you try to access the internet in normal mode? How do you connect?
     
  7. languy99

    languy99 Corporal

    i connect though my dsl modem (has a build in firewall but have not messed with it in ages). i have sygate firewall running and anti virus running. most sites work, the only problem is that i can't log on into hotmail, it hangs after i enter the password and it just keeps loading. when i try to add attachments to my posts here i get the window popup and everything and when i hit upload it just sits there saying waiting for forums.majorgeeks.com, also i can't get into windows update anymore, after i click express it takes forever to load and when it does it says "The website has encountered a problem and cannot display the page you are trying to view....." but in safe mode i can upload attachments and check my hotmail, but i still can't get into windows update.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This isn't malware related, it's software related so I would post this in the Software Forum.

    I would try disabling the firewall and antivirus and see if that has any effect.
     
  9. languy99

    languy99 Corporal

    i got it to work all now, it was sygate firewall that was blocking it. i had not changed anything it just started blocking stuff by itself, i switched back to zonealarm and i can now get into windows update, hotmail and can even attach messages on my posts. weird, but thanks for the help much appreciated.
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!

    I was thinking it may be Sygate, anyway glad to hear it's working now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds