Still having problems after running all online scans and virus removal programs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by guitardaddy, Aug 15, 2005.

  1. guitardaddy

    guitardaddy Private E-2

    i ran all of the steps in the "Read me first..............." i am having problems trying to delete files, it says the program is in use or access denied, etc, i have looked in the task manager and se nothing out of place, i do see more svchost.exe there than i used to, also computer is running extremely slow and sometimes have to restart 3 or 4 times to get it to work halfway decent, please help! thanks
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    [​IMG] Download HijackThis 1.99.1

    [​IMG] Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    [​IMG] Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    [​IMG]Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    [​IMG]Run HijackThis and save your log file.

    [​IMG] Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    [​IMG]Need help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ,

    Guitardaddy has 6 threads started in the Spyware Forum. All of which we have been answered and none of which has there been a reply to. I think we need to inform Guitardaddy to stop posting new threads and remain in one. And to also answere the reponses that have been given from now on.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  5. guitardaddy

    guitardaddy Private E-2

    i thought that what this place was for
     
  6. guitardaddy

    guitardaddy Private E-2

    i dont know how to keep using the same thread for each problem
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remain in one thread for you problem and you never seem to respond to any of the procedures given to you. Look at each of your other posts.
     
  8. guitardaddy

    guitardaddy Private E-2

    here is my hijack this log, also if I am making some kind of bad mistakes let me know what they are, so i can do better, i will reply to all messages i usually just fix the problem and go on withough making more stuff for you guys to read
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just like you are right now.

    If each problem is different, it would be okay to work in new threads. But you should only work one problem thru to completion before starting others.
     
  10. guitardaddy

    guitardaddy Private E-2

    so do i just click, quick reply, or posty reply or just keep editing the same thread over and over
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just click reply in the thread to add a new message. You cannot edit messages after 5 minutes has elapsed since posting them.
     
  12. guitardaddy

    guitardaddy Private E-2

    just like this?, did you get my hijack this log?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! There are only a few minor things to fix. I'll give that below. But explain what your problems is. You said you are trying to delete "files". What files?


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Microsoft AntiSpyware helper - {F1E3D6A6-4101-4707-8307-159C698A30B3} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F1E3D6A6-4101-4707-8307-159C698A30B3} - (no file) (HKCU)

    I would also fix the below unless you recognize it to be valid.
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  14. guitardaddy

    guitardaddy Private E-2

    do i need to do this in safe mode or not? i already have system restore turned off, can i turn it back on and make a restore point as soon as i boot back to normal mode?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! We will normally tell you when you need to boot into different modes, so only do exactly what we write. If you have questions or are not sure (just like this one), just asked before continuing.
     
  16. guitardaddy

    guitardaddy Private E-2

    ok i will reply as soon as i am done
     
  17. guitardaddy

    guitardaddy Private E-2

    ok i did all that you said, is there anyway to get rid of that ipod thing in the log, i dont use it and have uninstalled it, but its still in the add/remove list with no option to remove it, should i attach my new hijack this log into this thread? also that file i cant remove is a xdat.avi file
     
  18. guitardaddy

    guitardaddy Private E-2

    here is my new hijack this log
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where is the xdat.avi file located? And did you try booting in safe mode and deleting it?

    For the iPod service, try the below.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to iPod Service (or iPodService). Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    iPod Service

    If that does not work, use the short name without a space in it: iPodService

    You may be told to reboot at this point so go ahead and reboot and look at your log after reboot to see if the service is gone.
     
  20. guitardaddy

    guitardaddy Private E-2

    I think I got rid of all the major problems I was having, still have a few things to rectify. Thanks for your help
     
  21. guitardaddy

    guitardaddy Private E-2

    Setting ActiveX on Netscape 8.0.0.3

    I am taking a class online and I need ActiveX enabled, I see the box for ActiveX in Tools/Options/Site Controls, but its grayed out where I can't check it, it's unchecked now, I know I can use IE but I have Netscape as my default browser, and I want to see if I can make it work with my class, any help would be appreciated.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Setting ActiveX on Netscape 8.0.0.3

    I don't use or have Netscape! This is not a malware topic either. You would be better off requesting help on this question in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds