I'm pretty sure it's Malware....

Discussion in 'Malware Help (A Specialist Will Reply)' started by achoriim, Jun 4, 2008.

  1. achoriim

    achoriim Private E-2

    I really hope there is help for me. For the last 6 days I have been having a problem with my Internet Explorer. I have Windows XP Home and browse with IE 7.

    The Problem: My Browser constantly freezes and ends up in a "Not Responding" situation. I think it has been getting increasingly worse over the last 6 days. Nothing particular has to be done for it to get to this frozen state. It can be on any site at any time.

    In order to get out of the situation, I can try incessantly clicking the red x to close the problematic window which sometimes does and sometimes does not work. Or I can run Windows Task Manager and end the process from there (which by the way also states that the program is not responding).

    Usually, while that is happening on one window of explorer, I can open up an additional browser and search there ok until the problem strikes there as well.

    In addition, I have not been able to d/l through my torrent client all of the sudden today whereas, yesterday I had no problem and I have not made any settings changes.

    I hope that is enough info. I very much thank you for any help you can provide.
     

    Attached Files:

  2. achoriim

    achoriim Private E-2

    Here is the last of the 4 logs that need attaching.

    Thanks again for your help, I eagerly await your response.

    Achoriim
     

    Attached Files:

  3. achoriim

    achoriim Private E-2

    I forgot one important point

    I forgot to mention that an additional problem has been that I continuously end up on a page that states Internet Explorer cannot display this page and then I either need to recycly the page or go back and try again.

    Also, the one major change I made around the time this all started happening as that I switched from Norton to Mcaffe. I also did this on my laptop but have had no problems there.

    Thanks again

    Achoriim
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I forgot one important point

    Your problems did not sound like malware to me and after looking at your logs, my initial assumption still appears to be true. I'm going to give you a few non-malware things to do and we will go from there; however do note that you problems may be something that has to be worked in another forum.

    First disable Spybot's Teatimer as requested in the READ & RUN ME. See: How to disable Spybot's TeaTimer

    Now uninstall SUPERAntiSpyware since we are finished with it.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - blank (file missing)
    O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
    O2 - BHO: (no name) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - blank (file missing)
    O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/se...000001f.0000005b&c=00000082.00000021.0000004d
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - http://a248.e.akamai.net/f/248/5462...img/operations/symbizpr/xcontrol/SymDlBrg.cab
    O23 - Service: FireDaemon Service: winsecure (winsecure) - Unknown owner - C:\WINDOWS\security\FireDaemon.exe (file missing)

    Optionally fix the below which I assume you do no really need to always load at startup:
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

    After clicking Fix, exit HJT.


    Now delete the below file
    C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job


    Now click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot your PC.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! Actually I'm not expecting that the above will change the problems you described.
     
  5. achoriim

    achoriim Private E-2

    First of all......Thank you SOOOO much for your info and direction. Every time my computer gets a little kafluey I learn so much from the help you guys give here.....Thanks! Also, thanks for your honesty about the lack of optimism for what you suggested actually fixing my issue....that being said....

    I completed all the tasks you assigned me and they all ran beautifly. You told me to specificaly let you know if the regsitry additions were conpleted, and they were. I received a message of success.

    I just now finished these steps and need to surf a while in order to see if the problem persists. We will see....if nothing else....I definitely feel like I got a good "house cleaning" in the meanitime. I can only hope it solved the larger problem. I have attached the latest mgtools log. I look forward to hearing your future suggestions as they arise. I will update you from my end promptly.

    Thanks,
    Achoriim

    P.s. I am already skeptical as when I went to attach the mglogs....I clicked on upload and the initial response was "Internet Explorer cannot find the current page" I then closed the window, went back through the attachment process and it went through fine. This is what has been happening in my browsing. I get that very often.....then I either go back....and open the page again with success or I recycle the page.
    Any ideas?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try a couple other things, but I still don't think this is a malware problem.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to FireDaemon Service: winsecure
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastewinsecure into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when if tells you it needs to.

    Now run this Running GMER to detect rootkits and attach the requested log.

    Now download, install and do you surfing with this: Mozilla FireFox

    Do you still have the same issues when using FireFox?
     
  7. achoriim

    achoriim Private E-2

    Ok, I have performed the latest procedures.

    I will start surfing with firefox and see.

    You keep mentioning that you don't think it's Malware....if not, do you have any thoughts on what it could be?

    Thanks again for everything and I'll keep you updated.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need the log from GMER.

    Software issue with Windows or IE or another setting or problem on your PC. That is why I want the results of using FireFox.
     
  9. achoriim

    achoriim Private E-2

    Woops, here is the GMERlog

    Thanks again
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's clean too! What's the results from using FireFox.
     
  11. achoriim

    achoriim Private E-2

    Ok, after surfing now for a while, I must say that in general I like Firefox better. In regards to our issue, it has not frozen at all, it has however given me (albeit only once) a "server not found page" message. On firefox it then asks if you want to retry, which I did, then loaded the page immediately with no problem. This seems similar to to "internet Browser cannot find your page" message from IE7. It did it on a page that I know exists which worries me.

    I am facing an amorphis, unsolvable issue? You mentioned it might be a software issue or a larger computer issue. Are we on the right track?

    Thanks again for all of your help,

    Achoriim
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it seems more like an issue with either your software (like IE) or with intermittant issues with your hardware or ISP.

    You could try doing the following to see if it finds any missing or corrupted files within your Windows OS.

    Click Start, Run, and enter sfc /scannow now and click OK. There is a space after the sfc. This may ask for your Windows CD if it finds a problem and has no suitable replacement on your PC.


    I also suggest that you do the below:
    1. power cycle your cable or DSL modem (assuming you have one)
    2. Do this again like previously done. Click Start, Run, and enter ipconfig /flushdns and click OK.
    3. Power cycle your router.
    Now it is time to clean up from running the READ ME:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. Go to add/remove programs and uninstall HijackThis.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  13. achoriim

    achoriim Private E-2

    Well, I have performed the sfc scan and it has been running pretty smoothly so far. I don't understand how files can get removed that are necessary for correct running.

    Anyway, I am glad it doesn't seem like malware and I VERY MUCH appreciate your time and effort is assisting me through this problem. I have learned quite a but.

    Thanks,

    Hillel
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great news! Problems like this happen all the time. It can happen for a variety of reasons.

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds