Spyware?Trojan?Periodic loss of control panel and administrative usage

Discussion in 'Malware Help (A Specialist Will Reply)' started by mongooseba, Sep 2, 2007.

  1. mongooseba

    mongooseba Corporal

    Dear All, :crybaby

    I'm totally lost and do not know how to solve my problem. These are the symptoms that I'm having.

    1. Periodic loss of "control panel" access and the "system restore" does not work
    2. It all started with a yellow triangular icon on the right task bar that states - " your computer is infected - windows detected spyware" and also a pop-up that states "windows security alert-warning! click to remove ..." Obviously my son clicked and closed this pop-up window

    I have followed all the instructions as described in your logs. Summary of findings.
    1. AVG antivirus (did not detect any problems)
    2. Spybot (removed two items)
    3, AVG antispyware - detected problems and quarantined
    4. BitDefender - detected problems and removed
    5. PandaActiveScan - detected and removed a trojan and I reran the cleaning of my "norton recycle bin" and cleaned the reminaing with CCleaner
    6. Ran GetRunKey and ShowNew
    7. Ran the Hijack log

    So far the yellow triangle icon is missing and the pop-ups have stopped. I suspect I still have some problems because of the periodic loss of administrative rights to certain programs and loss of control of certain microsoft features e.g. control panel, system restore.

    Kindly review and I look forward to your advice. I have learnt a lot from the malware removal guide.

    Sincerely,
    Mongooseba
     

    Attached Files:

  2. mongooseba

    mongooseba Corporal

    Dear All,

    Here are the remaining files needed to help me.

    Below is a summary of my Hijack log


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.



    Mongooseba
     

    Attached Files:

    Last edited by a moderator: Sep 2, 2007
  3. mongooseba

    mongooseba Corporal

    Deal All,

    Sorry that I forgot to upload the Hijack log and have posted it on the thread instead. Newbie problem.

    Sincerely,
    Mongooseba:eek:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    GetRunKey and ShowNew are not running properly for you. It could be due to your infection. It looks like the Windows Registry Editor is missing or is being blocked from running. Does your user account have administrator priviledges?

    Please run this: ChodeFix - How download and run

    Then attach a new log from GetRunKey. Tell me if you see any error messages in the command prompt window that opens.

    I see two antivirus programs running (Norton and AVG). Did you see step 3 of the READ ME or does you problem block uninstalling.
     
  5. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks for your prompt reply. I ran the "Chodefix" and something happened. I could not save the details. Enclosed is the new GetRunKey log. I have delected the previous Norton Antivirus. I kept the remaining speeddisk section. Also thanks for clearing my Hijack log.

    Sincerely,
    Mongooseba
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You appear to have skipped the part about not using MSConfig in step 0 of the READ ME. Or are you having a problem running MSconfig to set it for Normal Startup mode? Try is now and tell me what happens.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After setting your system for Normal Startup mode continue with the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MT...505&t=1706&d=626&djs=40&s=0&r=0&noreloadredir
    O20 - AppInit_DLLs: C:\WINDOWS\system32\hadjajr.ini


    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I could not enter the "msconfig" initially and I skipped this step. I will now try this again per your instructions. Thanks.

    Sincerely,
    Mongooseba
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let me know what happens. Either way continue on with the instructions in message # 7.
     
  10. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks again for following-up closely on my case. I have performed all the steps as instructed.

    1. MSConfig: I was able to start in normal mode (loaded everything)
    2. Ran "disable/remove window messenger" to uninstall the window messenger
    3. Removed items on Hijack log (could not find 07 - HKCU\Software\****). I presume this was removed somewhere along the way
    4. Merged your code with my registry in "fixme.reg"
    5. Processed "avenger". I saw the log that it could not find the various files to be deleted. I could not find the files in my computer either. I presume this worked
    6. Clicked on "Ccleaner"

    My system restore has been suspended. The pop-ups did not occur and I am able to access the control panel e.t.c.. Do you think my computer is clean??????


    Sincerely,
    Mongoosebarolleyes
     

    Attached Files:

  11. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    This is my remaining file for your perusal. Thanks again.

    Sincerely,
    Mongooseba
     

    Attached Files:

  12. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Should I delete all the Symantec products and substitute a new freeware defragmenter e.g. Fast Defrag Standard 2.31, Diskeeper Lite 7.0, or O&O software? Do you have a preference as to which I should choose?

    The Symantec product does not seem to do a good job - way too slow: took > 6 hours to defrag and stalls. Could I have a problem with the software? Please advise and instruct. Thanks again.

    Sincerely,
    Mongooseba
     
    Last edited: Sep 3, 2007
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The main issues you have with malware seem to be fixed however there are still issues that remain. First you still have two antivirus program installed. Norton is still installed according to your logs and so is AVG 7.5. Choose which you want and uninstall the other.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_05
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME


    You should see the below link which will give you other alternatives for defraggers and much much more. And also if you wish to discuss this further, the Software Forum is the appropriate place for that topic.


    http://www.majorgeeks.com/page.php?id=20



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  14. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks for the input regarding these programs: Java 2 Runtime Environment, SE v1.4.2_05, Viewpoint Manager, and Viewpoint Media Player. As instructed, these programs were removed. I also decided to remove all the Symantec products and Skype as well. However, I'm not sure what "avanquest update"? Should I remove this as well?


    I also disabled and enabled the "system restore" and the previous save points were erased. I uploaded the "comodo firewall" and "IOBit Smart Defrag" programs.

    I have AVG antivirus, spybot, and spywareblaster. However, what should I do with the two "after the fact scanning tools" namely AVG antispyware and Superantispyware? My C:\recycler\Nprotect directory has a ton of files. Aren't these supposed to be erased when you empty the recycle bin? I thought that my recycle bin becomes normal when you remove all your Symantec products. Did I not remove all the Symantec products? Thanks.

    Mongooseba
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that related to this?

    http://support.avanquest.co.uk/downloadsv85.php


    You can keep them or uninstall them. It's up to you. During the trial period, AVG AS actually provides realtime protection too.

    No! That is why this is mentioned specifically in step 1 of the READ ME.

    No! I only told you to uninstall the antivirus program. You still had a load of other software from Norton/Symantec which includes System Works and Utilities which is where Nprotect comes from. The below were seen in your logs:

    LiveReg (Symantec Corporation)
    LiveUpdate 3.0 (Symantec Corporation)
    Norton CleanSweep
    Norton Password Manager
    Norton SystemWorks 2004 (Symantec Corporation)
    Norton Utilities
    Norton WMI Update
    Symantec pcAnywhere
     
  16. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I have no idea what is "avanquest"? Should I remove this, and if I do make a mistake, can this step be reversed? I removed the Symantec's Norton antivirus program previously and removed the remaining products as well. I believe I did it correctly since I do not see them in the Hijack log. I do not like the Norton product any way. Too late and no regrets.

    Probably I didn't quite understand the section on "Read Me: 1" instructions. I could not quarantine my previous Norton Antivirus because the program was erased initially. The Norton protected bin was emptied. Am I still suppose to have files on the C:\Recycler\*.*? Can I delete this files manually? Should I also check the registry for remaining Norton products?

    My recycle bin behaves differently from my other computers. I do not have recycle bin properties when I right click the icon. What should I do?

    Sincerely,
    Mongooseba
    :eek:
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure it is not part of SoftV92 Data Fax Modem.
    No it cannot be reversed unless you know where to get the software to reinstall it, but if you knew that you would know where you got it from. It is not malware, so I would ignore it.

    Yes it is normal to see things in this folder even after you empty the recycle bin or run Ccleaner which also empties it.

    You can do that if you like using the Issues tab of Ccleaner or using another registry cleaning tool (these are topics for the Software Forum). However whatever you decide to do, make sure you backup the registry first.

    This is really not a malware issue either, but let me ask whether you disable it at anytime. A system policy normally controls this. See the below link:

    http://www.pctools.com/guides/registry/detail/1301/
     
  18. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I will leave the "avanquest" alone then. The CCleaner did not remove the components off the C:\Recycler\*.* folder. Is there something wrong here? I do not recall disabling the "recycle bin" at all. Do I need to restore this at the XP register? Please advise.

    Sincerely,
    Mongooseba
     
  19. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I've checked the registry and the following value was present.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace

    {645FF040-5081-101B-9F08-00AA002F954E}

    Should I delete and remake a new value? Thanks.

    Sincerely,
    Mongooseba:confused
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat what I said in my previos message
    I don't know what you are referring too.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you want to touch this? Are you seeing tabs left over from Norton Protection?
     
  22. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    My recycle bin originally had a Norton label to the icon. I renamed it to just "recycle bin." I assume that the "add and remove" program did not fully unistall the Norton bin. I am not able to right-click on my recycle bin and have the properties tab appear. However, when I delete a file, this appears in the recycle bin. What should I do?

    As regards to the registry, I wanted to show you that the keys are not messed up. I'm not an expert in the registry, but have changed some keys before. Your advice it appreciated.

    Sincerely,
    Mongooseba
    :yum
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but that is not a complete registry key so it is of no use to me in showing if the correct info is there or not.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  24. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I did as advised and merged the code into my registry. The recycle bin still does not have the proper tabs in the properties mode. Enclosed is a jpeg file for your perusal. I look forward to your reply.

    Sincerely,
    Mongooseba :cry
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the typical Desktop icon for the Recycle Bin. That is only a shortcut to the Recycle Bin and that is why you don't have the normal Properties info.


    Try the below!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  26. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    You are the best. My recycle bin works! Kudos to you. My computer so far has not be acting up. What should I do with the quarantined items? Should I delete them? Do you have instructions? Thanks again for your patience.

    Sincerely,
    Mongooseba

    :D
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    What items in quarantine are you referring too?
     
  28. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    I have quarantined items in "Superantispyware" and "AVG antivirus" softwares. Enclosed is the jpeg file for your view. Should I press and buttons that says "remove"? Thanks.

    Sincerely,
    Mongooseba

    :hyper
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can empty those quarantines now.
     
  30. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks again for your reply and I have removed all the items from the quarantine bin. My computer is running and I have also tweaked the start-ups with CCleaner. On the side, do you know of any freeware to only direct or allow internet sites suitable for kids and teenagers? What I'm eluding to is ... any help with this issue would be helpful. Look forward to your reply.

    Sincerely,
    Mongooseba
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't play with tools like that so you would be better served by asking this question in the Software Forum. There have been lots of tools like that. One I do remember is http://www.netnanny.com/
     
  32. mongooseba

    mongooseba Corporal

    Dear Chaslang,

    Thanks for all your help and write to me if I may help in any way. Meanwhile, I believe I was nearly tricked with another computer with a malware problem. I posted it on the Malware section. Youuuuuuuuu aaaaarrrreee greeeeaaaat!


    Regards,
    Moogooseba
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds