Getting Runtime Errors & Found Spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chuckycr, Jan 21, 2007.

  1. Chuckycr

    Chuckycr Private E-2

    I was having some trouble recently on IE with runtime errors on several of internet sites ("A Runtime Error Has Occurred. Do you with to debug..."). I am running Windows 2000 Pro and IE6. I also have Office 2003. I thought initially it might be the Office script debugger, but I tried to uninstall and reinstall Office without the web debugger. I also went into Internet Tools to disable script debugging and uncheck the notify for every error box, but they are still coming up on many sites.

    I went through the entire READ & RUN FIRST procedures, and discovered two spyware/malware items in the counterspy scan (Trojan.Win32.Agent.rx, and SpySheriff).

    I'm not sure if this was my problem or if it's unrelated, but if there is any help I could get it would be greatly appreciated (on both subjects).

    (On a side note, I did to the Panda ActiveScan. It found no problems, but when the scan was finished I could not find any button to See or Save Report. I don't know if I just missed it or not, but I wanted to let you know that I did run it).\

    Thanks!
     

    Attached Files:

  2. Chuckycr

    Chuckycr Private E-2

    The other files...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no signs of malware in your logs other than what CounterSpy already fixed. I suggest running the below rootkit scan. If it does not find anything, I then suggest you post in the Software Forum because you would not be having malware problems.

    Using Sophos Anti-Rootkit


    It does appear that you never ran CCleaner (doubt that it matters) since the below folder has files as old as Nov 9, 2006:
    C:\Documents and Settings\Charles Rodriguez\Local Settings\Temp\
     
  4. Chuckycr

    Chuckycr Private E-2

    Thanks for your help. I ran Sophos and it found nothing, so I guess I'm clean now.

    It's interesting that you found those old files in that temp folder. I did run ccleaner in both the normal and safe modes during the process. (Oh well!)

    I was wondering if you could help me as to which anti-spyware program would be good for me. I was using the Windows Defender Beta version until it expired, and the new one appears to only work on Windows XP, not Win 2K.

    I'm now using Spywareblaster, Spybot, and Ad-Adware SE, but none of them were obviously able to pick up this latest problem.

    Should I be using something like CounterSpy or SpySweeper in addition to the other ones? Or would they replace any of these? What would you recommend?

    Thanks!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is it set to clean those Temp folders?

    I have about 4 PCs running Win2K SP4 and Windows Defender runs fine on them. As far as I know, as long as you have Win2K SP4 it should work.

    What problem are you referring too?

    Yes you need a real time blocking tool like one of those. You were using Windows Defender which is a blocker as well as a scanner. Windows Defender is far from our tool of preference but it is better than nothing and it is free. If you don't mid paying, Spy Sweeper is one of the best but some people are starting to see it slowing there PC down a lot.

    While I did not see any malware, there are a few things I would like you to do. I don't think they will fix your runtime errors but let's see what happens.

    First uninstall the CounterSpy trial since we are finished with it and it will expire anyway.

    Question: Are you having any problems shutting your PC down or restarting/rebooting?

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Core LC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Automatic LiveUpdate Scheduler
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste Symantec Core LC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • Automatic LiveUpdate Scheduler
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Common Files\Symantec Shared <--- the whole folder
    C:\Program Files\Symantec <--- the whole folder

    Now run Ccleaner

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Charles Rodriguez\Local Settings\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Chuckycr

    Chuckycr Private E-2

    Yes. Ccleaner is set to clear out temp folders (at least I think it is…I have it set on the default settings, and never changed them…)

    Where are you getting Windows Defender from that runs on Win 2K? I have Windows 2000 with SP4, and when the beta version expired on 12/31/06 I received a link to download the new version. After download, it failed on install because I did not have Windows XP. I tried to search all over Microsoft’s website, but I could never find a version that supported Windows 2000.

    Sorry I wasn’t more specific…the problem I was referring to was the spyware and malware that was found on my system. None of those programs I mentioned above that I am currently using were able to block/detect them. But as you mention below, I'm not using a realtime blocking tool right now.

    I wouldn’t mind paying for a spyware program if it’s good and doesn’t use up too much system resources. Of course, if there is a free way of doing it that’s just as good, like the AVG and ZoneAlarm programs, that would be fine too. I’ve seen spy sweeper mentioned prominently by some of the others around here, but how much is “a lot” when you refer to PC’s slowing down? I used to use Symantec’s NIS in the past, and one of the reasons I dumped it was because it was becoming too much of a resource hog. The computer I'm using is fairly old - it has a 1200 MHz Processor and 1GB of RAM. Would you see Spy Sweeper clogging that one up pretty good? Or is there another one out there you would think might be better?

    But back to your instructions...

    Done.

    No. It takes a while to boot, but I think that's because there's a lot of background processes being loaded (like AOL stuff, etc.). I look into the Task Manager and see a bunch all the time. I'm trying to tool around with MS Config to see which ones I can turn off to free up some resources, but while I'm not completely illiterate I'm also not an expert at all of these things and weary of doing something that will cause a huge crash of some sort. I would like to figure out a way to disable some of the "unneeded" startup items that take up system resources without harming the computer's overall operation.

    You mentioned "the below two Services" (on the 5th dot) but there was only one (Automatic LiveUpdate Scheduler) below that. Should there be another?

    But Scheduler was done.



    • I did get an error message "The service you entered is system-critical! It can't be deleted." But I just ignored it like you said and moved on...

    Did the other with no error. But only one other was mentioned like before instead of two.

    Thanks so much for helping me get rid of these! They were driving me nuts every time my computer booted up (especially the RealPlay).

    Is it safe to do this procedure for the AOL Spyware Protection? I accidently loaded once and I hated it, but like Symantic I can't seem to get it completely wiped from my computer. Was just wondering...

    This one I found and deleted.

    This one I didn't find, but I did find 3 other "Symantec" Folders:
    C:\Documents and Settings\All Users\Application Data
    C:\Documents and Settings\Default User\Application Data
    C:\Documents and Settings\System\Application Data

    I haven't deleted these yet...I wanted to get your OK first.

    done with all default settings.

    I don't have a C:\WINDOWS\Temp folder, but I assume you meant the C:\WINNT\Temp folder, so I went and deleted the files in there. I also did the same for the second folder as well.

    You should find the logs attached (I assume you wanted me to reboot and run them back in the normal mode and get out of the safe mode, so that's what I did). Let me know how things look.

    Thank you very much for all of your help!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I got it from Majorgeeks but you are correct that the latest version will no longer support Windows 2K. More bad public relations on Microsofts part. I have not tried my Windows 2K PCs where I have this installed recently (since the new year). It does not matter too much anyway since Windows Defender was a pretty poor program anyway. Better than nothing and it was free, but it went downhill since Microsoft acquired GiantAntispyware and renamed it Microsoft Antispyware. When it became Windows Defender, it took a huge jump in the negative direction. If you are looking for a free program that will block malware, try this: Spyware Terminator

    There really wasn't very much found, but if you don't have a realtime blocking tool you are susceptible to more problems.

    Try the free program mentioned above for awhile and see how you like it.

    Your PC may be too slow to handle Spy Sweeper which is very good but lately has been suffering from Norton/Symantec's disease. ;) However note, to be fair, all good blocking tools (whether they are antivirus, antispyware, or firewalls) will have an effect on performance. The ptoblem is that some of them are worse then the malware they are supposed to protect you from.


    You can use MSconfig to experiment, but don't use it as a permanent solution. Either uninstall unnecessary software or permanently remove them from starting up.


    No just one. Just a typo from not completely editing one of my procedures to fit your situation

    Yes do the below:
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to AOL Spyware Protection Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteAOLService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    Yes remove all Symantec stuff but first check Add/Remove programs because I see something still installed: Symantec KB-DocID:2003093015493306 If you see anything from Norton or Symantec, uninstall it. If not, make sure you tell me.


    Also delete the below folders leftover from CounterSpy and McAfee:
    C:\Documents and Settings\Charles Rodriguez\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\McAfee
    C:\Program Files\mcafee.com

    Also see if you can locate the folder for AOL Antispyware to delete. It should be somewhere like the below:
    C:\Program Files\Common Files\AOL\AOL AntiSpyware


    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Are you having any other malware problems?
     
  8. Chuckycr

    Chuckycr Private E-2

    What else is new? ;)

    That you for pointing me to Spy Terminator. I installed it and I'll give it a try.

    And thanks for helping me get rid of AOL Spyware too.

    I did first check the Add/Remove programs, but I did not find that Symantec program in there. In fact, I couldn't find it at all on my hard drive. I deleted all of the other folders anyway. What else, if anything, should I do?

    I deleted all of the other folders you mentioned as well (Sunbelt, McAfee, AOL), and I also uninstalled and reinstalled the new Sun Java Runtime Environment. (Thanks for letting me know there's a new one)!

    As far as I know, I'm clean now as far as malware goes.

    Thank you for all of your help. :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. Chuckycr

    Chuckycr Private E-2

    Here's the log...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new log from ShowNew.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. Chuckycr

    Chuckycr Private E-2

    Ok. I did the steps, and here's the log.

    How does it look?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good! Symantec is gone! ;)
     
  14. Chuckycr

    Chuckycr Private E-2

    Thank you for all of your help, Mr. Anti-Spyware-Man! :)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  16. Chuckycr

    Chuckycr Private E-2

    Chaslang,

    I don't know if you're still around or able to pick up this thread anymore, but for the past few days I've started to get stop errors and the "blue screen of death."

    I've received the following two errors:

    Stop: 0x0000001E (0xC0000006, 0x7CC40F31, 0x00000000, 0x7CC40F31)
    K_MODE_EXCEPTION_NOT_HANDLED
    Beginning dump of physical memory
    Dumping physical memory to disk: (then number count...)

    Stop: 0x000000D1 (0x022E3005, 0x00000002, 0x00000001, 0x77RCD492)
    DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Beginning dump of physical memory
    Dumping physical memory to disk: (then number count...)

    After the number count the machine reboots automatically.

    The first error I got twice, and the second once (this morning).

    All times the errors occured after running the virus and spyware program scans overnight, and in the morning when I tried to access Internet Explorer that's when the error occurred.

    I haven't messed with the registry at all since we did those procedures above, and I haven't installed any new programs either. Could these errors be related to anything we did?

    Thanks.

    EDIT: You know what I just realized? My virus and spyware scans may overlap a little (one might still be finishing up when the other starts). Although the error hasn't happened every night/morning since I installed Spyware Terminator, could that be a potential cause?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should not run overlapping scans.


    This statement is confusing. If it has not occurred since installing Spyware Terminator, what's the problem. Or do you mean it started occurring since installing Spyware Terminator? Were the overlapping scans your AV and Spyware Terminator? Don't overlap and tell me what happens. Don't run a Spyware Terminator scan.....what happens.


    Your second error message is described here: http://support.microsoft.com/kb/293077
     
  18. Chuckycr

    Chuckycr Private E-2

    Sorry for the confusion. It did start happening after installing Terminator. I will spread out the scans more to make sure they don't overlap, and I will also experiment with not running a Spyware Terminator scan, etc., and I'll let you know what happens.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Describe what happens when you finishing testing.
     
  20. Chuckycr

    Chuckycr Private E-2

    chaslang,

    Thanks for all of your help. I've been running some tests, and have still been experiencing some intermittent crashes (both with and without Spyware Terminator running - or even installed).

    Since my system is now clean of malware I began thinking it might be a hardware issue, so I ran some diagnostic utilities that came with my computer. I got the following message regarding my hard drive:

    IDE Disk 0 - Confidence Test
    Status: Fail Status Code: DOS DDG-D Disk 192 068
    Device: IDE_Disk_0 Test: Confidence_Test_Read_Test
    Release: 1070 Module(s): Disk
    Msg: Block 29294577: Uncorrectable data error or media is write protected

    The drive failed to perform the confidence test properly. This may indicate that the drive needs to be replaced.


    I'm thinking that now my problem is that my hard drive is starting to fail and it may be time to get a new one.

    Is that what you would think?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are in the wrong forum for that message! Try the Hardware Forum this is not a topic for this forum since it is not malware.

    You may just need to run chkdsk /f /r
     
  22. Chuckycr

    Chuckycr Private E-2

    I figured as such and already posted over there last night.

    Thanks anyway. :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds