There's my sign! But I need help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by azsteve, Sep 7, 2005.

  1. azsteve

    azsteve Private E-2

    My Fellow Geeks, I need your help. I've been trying to rectify this computer problem but I've been unsuccessful thus far.

    I've been to the following and have what was instructed but I still came up empty handed. http://forums.majorgeeks.com/showthread.php?t=35407

    The results from my online virus scan at:
    Bitdefender was - 7
    RAV - 0

    Some of the files from bitdefender unremovable.

    So what do I need help with you ask? When I try to access my registry by going to start - run - regedit, the window pops up and disappears so I have to manually go in by going to start - windows, etc. A couple days ago I also noticed that ctrl+alt+delete wasn't working either. But that is no longer an issue because it's works now.

    Also while browsing my connection freezes up on me and is running slower than usual. When I click on my network connection icon in my system tray and click the support tab, then click repair, it gives me the following error message "The following steps of the repair operation failed: renewing the IP address. Please contact your network administrator or ISP."

    So I'm a mess and I'd be grateful for any help.

    Steve
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below exactly:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. azsteve

    azsteve Private E-2

    Here's my HJT log. Thanks for your help.

    Steve
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log does not indicate that RAVantivirus was run. Are you sure it ran?

    Post the BitDefender log so I can see what was found and not removed.

    You HJT log shows no real major problems. Just the below minor items can be fixed.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - Default URLSearchHook is missing
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0947a60179396111f720/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.

    Can you explain in more detail the exact problems you are having? When do they occur? Is it all the time or only sometimes? Do they also occur if you boot in safe mode?
     
  5. azsteve

    azsteve Private E-2

    Chaslang,

    Here are my other logs. The first time through I did run the RAV, it took over an hour to scan my machine. Yesterday I spent a good part of the day going back over http://forums.majorgeeks.com/showthread.php?t=35407. I have posted all logs in this message.

    As for my problems:

    My computer is running a lot slower than normal. Some pages are taking 30 seconds or more to load, pages that shouldn't take this long. I had to reboot several times yesterday as I was going through the list of cleaning software. Even in safe mode my computer was acting up. Had to restart after Avert Stinger and the second set of virus scans. Restart again after Bitdefender. Restart again before CCleaner. My internet connection was lost, that's why I had to restart.

    I also can't access regedit by going to: start-run-regedit.

    I noticed all these problems around the same time. My Norton trial was expired and I thought 50 for their softwar was kinda high so I looked around for a cheaper version. Deleted Norton and installed PC Cillin. I also added a new Epson printer and software around the same day.

    The computer is slow pretty much all the time. I really haven't noticed if there is certain times of the day that are worse. Right now it's slow. Last night it was slow. I thought I ran a pretty tight ship but something has gotten a hold of my system.

    Spybot had two problems with wildtangent but they were fixed.
    HSR-removed 8 items
    CWS-nothing found

    Thanks for all your help,
    Steve
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a note: you have no reason to be running HSremove (or about:buster if you have been). You do not have any HSA hijacker issues. HSremove has a bug and always reports 8 items found.

    RAV should leave a foot print in your HJT log and I did not see one.

    Are you sure your regedit.exe file exists? Use Windows Explorer to look for c:\windows\regedit.exe

    There are not problems in your log but you can fix the below (left over from running HSremove):

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    Open a command prompt by clicking Start, Run and enter cmd and click OK. Then enter the below command and tell me what happens.

    sfc /scannow

    This will scan your PC for missing/corrupted system files and attempt to replace them. You may need your Windows XP CD.
     
  7. azsteve

    azsteve Private E-2

    I can click Start, Run and enter cmd but that is all I can do. A black window pops up and disappears, so I am unable to type sfc/scannow
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it this way:

    Start, Run and enter sfc /scannow and click OK.

    Now what happens!
     
  9. azsteve

    azsteve Private E-2

    Okay, opened up a window saying it was checking all windows files. It ran and closed without doing anything else.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what it may do if it find no problems or if it finds then and can immediately fix them without needing a CD. Is there any change to your problems?

    You did not answer my question from message # 6 about regedit.exe.
     
  11. azsteve

    azsteve Private E-2

    c:\windows\regedit.exe <----does exsist, sorry I didn't answer that question.

    IE is still running slow.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that's why you cannot run regedit from the Star, Run box. You need to replace this. Either search your harddisk for another copy or get it from your CD. Itmay be named regedit.ex_ because it is a compressed file. When you find a copy we can put it back in c:\windows. If it is the compressed form, we will have to expand it to regedit.exe.


    Let's see if we can find and cleanup any other hidden baddies
    .

    Let's see if we can cleanup some more hidden baddies.

    - First run CCleaner before doing the below.

    - Download this trial version of Ewido Security Suite
    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:

    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report

    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report. And tell me if you are still having any problems. This log could get quite large and you may need to compress it into a ZIP file to upload it.


    Post this Ewido log.
     
    Last edited: Sep 11, 2005
  13. azsteve

    azsteve Private E-2

    Since I'm a little confused by your last email, I've attached a screenshot of my search results - Start, Search, regedit
     

    Attached Files:

  14. azsteve

    azsteve Private E-2

    I didn't even see the bottom half of that last post...so diregard my last post. I'm going to do as instructed.

    Thanks,
    Steve
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow step 3 of the READ ME FIRST. Please go back and follow it exactly.

    You do have regedit.exe exactly where it is supposed to be.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this registry patch to fix your regedit problem.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file enableRE.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the enableRE.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

     
  17. azsteve

    azsteve Private E-2

    I see where I went wrong in step 3 of the READ ME FIRST. I also added the contents of the last post to my registry. Where do I go from here? Should I go back to READ ME FIRST and redo it ALL over again? I feel like such an idiot. I could have saved you a lot of time had I unchecked the second of the two boxes. Please accept my apology.

    Steve
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does regedit work now?

    Did you run the Ewido scan? Post the log!
     
  19. azsteve

    azsteve Private E-2

    Regedit still doesn't work. Opens and then closes. I can access it by going to c:\windows\regedit

    I installed and ran ewido. The log is posted.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have Administrator priviledges?

    At this point I would say your problem is not related to malware and you may have to work this in the Sotware Forum.

    But try it this way:

    Start, Run and enter msconfig and click OK.

    Does msconfig come up and stay up!

    How about this one:

    Start, Run and enter services.msc and click OK.

    Does the Services windows open and stay open.
     
  21. azsteve

    azsteve Private E-2

    Both open and stay open.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But neither regedit or cmd will open and stay open? Correct?

    Are there any others like that?

    Also you said you can run regedit.exe from Windows Explorer....right?

    What about c:\windows\system32\cmd.exe
     
  23. azsteve

    azsteve Private E-2

    This is correct.

    I'm not that advanced to know if there are others that don't work.

    Correct, I can run regedit.exe from explorer.

    This file does exsist. I also have cmd.com - is that nornmal?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not normally. It may exist if a person like me had suggested that you make a copy of cmd.exe and call it cmd.com (or even if you renamed the original to cmd.com and that put a new copy of cmd.exe in place. sfc may have even done this.)

    Are they both the same size and do they have the same file dates?

    Rename cmd.com to cmd.old

    Does cmd.exe execute from Explorer?

    Will it now run from the Start, Run box?
     
  25. azsteve

    azsteve Private E-2

    cmd.exe was created on 1-14-05 (367kb)

    cmd.com was created on 9-1-05 (2bites)

    I changed cmd.com to cmd.old and it asked if I was sure I wanted to rename the system file and I said yes. But now I can access cmd from explorer and run.

    I'm not sure what's going on with this machine.

    I appreciate ALL your help and don't know what I'd do without it.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try running cmd from the Start, Run box now? It probably works now.

    I have a feeling that you have the same problem with regedit.exe. You probably have a regedit.com file. If so, rename it to regedit.old.

    Let me know what you find and what happens with the above.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't forget according to your snapshot taken awhile back, you also had a regedit in c:\windows\system32. You did not have extensions showing but it could be a .com file and it does not belong there.
     
  28. azsteve

    azsteve Private E-2

    cmd works from Start, Run. It also works from explorer.

    regedit.com was an existing file but it was under c:\windows\system32 I changed it to regedit.old and now it works when I go to Start, Run.

    What do you recommend from here? Should I go back and redo the READ ME first page? I want to delete PC Cillin and get AVG or Avast. Any other recommendations to rid my system of unwanted pests?
     
  29. azsteve

    azsteve Private E-2

    should I delete any regedit files from c:\windows\system32
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See my message posted just before you posted yours.

    Are you having anymore problems? Are you unhappy with PC Cillin or was it just a trial.

    See: How to Protect yourself from malware!
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only the one that you just renamed that was in c:\windows\system32 not any others. And do not touch REGEDT32.EXE either.
     
  32. azsteve

    azsteve Private E-2

    The only problem I'm still having is that my computer still seems slow. Other than that, I've not noticed anything.

    PC Cillin was a trial version. I checked out what people were saying about Avast and AVG and they sound pretty good and the bonus is that they are free.

    Steve
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall all of PC Cillin yet? This could be part of the reason your PC is slow. You had two firewalls running. The one from PC Cillin and Zonealarm. Only one software firewall should be used.
     
  34. azsteve

    azsteve Private E-2

    No, I did NOT uninstall PC Cillin yet. I plan to later today. As for the dual firewall. I disabled PC Cillin's firewall protection and I'm just using their AV.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your HJT log:

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    The firewall service is still actuall running!
     
  36. azsteve

    azsteve Private E-2

    pc cillin - GONE! I deleted it and installed avast. I've attached my HJT log for review.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good! Is it running any better now?

    Did you leave the below on your system on purpose?
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
  38. azsteve

    azsteve Private E-2

    I've been trying to eliminate any and all remaining symantec files but they're turning out to be pretty pesky.

    My computer seems to be running better as far as speed, but as of 10 minutes ago, it's been randomly turning off. My girlfriends sister came over and was on here using myspace, so I'm not sure if its myspace specific or not. I'll do some browsing and see if it randomly restarts.

    I don't know what I'd do without without you or this site.
     
  39. azsteve

    azsteve Private E-2

    When I installed avast it said that there was some sort of conflict with avast and ZA...I saved the screenshot but I can't locate the file. So I don't exactly remember what it said.

    It's probably because when the computer restarted I lost any new files?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what the conflict is! I have never heard of it. Unless you installed the version of Avast with a firewall??

    You should not lose any new files just because the computer restarted. If it restarted before the files were saved, then you could lose them.

    We can remove the Symantec Service is you want! Just say the word!
     
  41. azsteve

    azsteve Private E-2

    lets get rid of the unwanted symantec files.

    I'll look again on my hard drive to see what the conflict was. It said something along the lines that some websites might not work and they gave yahoo mail as their example.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to SymWMI Service (or if not found look for SymWSC) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, go back to HJT and select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SymWMI Service

    If that does not work try entering the short name: SymWSC

    Now exit HJT but and reboot. Post a new HJT log.
     
  43. azsteve

    azsteve Private E-2

    I did all of the above but HJT wouldn't let me delete the file when I went to "delete an NT service." I encountered the following error message.

    "the service you entered is system-critical! It can't be deleted."

    At the same time an Avast warning popped up:

    Avast information. An error has occured while attempting to update! Click here for more information."

    "cannot connect to donload11.avast.com (unknown 80)"

    In my new HJT log, 7th entry, 04 [kernelfaultcheck]...
    What is this?
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It worked anyway. The Symantec program is gone.

    Is the problem with updating Avast still occurring?

    Lines like:

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    occur when you have had some kind of Windows system error. They create memory dumps used for debugging purposes. You can disable these by:
    - right clicking on My Computer, selecting Properties and then the Advanced tab.
    - Click on the Settings button in 'Startup and Recovery'.
    - In the bottom pane under 'Write debugging information', click on the down arrow and then select 'None'
    - OK your way out of these screens.
     
  45. azsteve

    azsteve Private E-2

    I am still having troubles with avast. There is some sort of conflict happening. I can't update. It can't find the server. Could this be because of that symantec file?
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What Symantec file? It's gone!

    Check to make sure it has permission thru your firewall (you can even disable the firewall - only temporary....do not leave it disabled after checking for updates to Avast).
     
  47. azsteve

    azsteve Private E-2

    The symantec file was still on this machine after I downloaded avast. Although it's gone now, I thought it might have created some sort of conflict.

    I just went to avast.com http://www.avast.com/eng/faq_firewall.html#idt_1366 and searched for what the problem might be and I came accross this.


    5) Optimization for permanent connections
    If your computer has a permanent connection to the Internet, you can let avast! know this fact so that it can bypass the connection checks. To do so, follow these steps:

    In Notepad, open the file AVAST4.INI
    (C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\DATA)
    Find the section [InetWD]. If this section doesn´t exist, create it.
    Into this section insert this row:
    AssumeAlwaysConnected=1
    NOTE: Your avast! build must be 4.0.172 or higher!

    Should I follow their directions?
     
  48. azsteve

    azsteve Private E-2

    I just went to ZA and allowed ALL access to avast. Then I went to update and updated. Should I allow access all the time?
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That way it will always automatically update. Autoupdates for your AV are a good idea.
     
  50. azsteve

    azsteve Private E-2

    Chaslang

    I'm still having troubles with my computer randomly rebooting. It only happens when browsing online. It also seems to only happen with certain sites. My girlfriends sister comes over and uses myspace.com or lyrics.com - without fail the computer reboots.

    It doesn't to happen to me when I'm online. If I went to those sites it would, but while I'm on here it doesn't reboot.

    I went to the software support forum to ask for help. I also tried firefox to see if that would help and it didn't.

    Could I still have some pesky virus, spyware, worm, etc. on here even after I did all the READ ME FIRST files?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds