houston we got a problem!

Discussion in 'Malware Help (A Specialist Will Reply)' started by twinkles, May 11, 2007.

  1. twinkles

    twinkles Private E-2

    everyone will have to bear with me. this is my first post. i have a problem with a search engine that i cannot get rid of. i tried with all i could find on my computer to uninstall it but it keeps coming back every time i restart my computer. it is wizardsearch.org (your most trusted search engine) and it pops up as a webpage in ie upon startup. it did have a web page that opened up behind it every time but i seem to have gotten that deleted somehow. either by blocking it through ie or deleting the file i dont know which because i did so many things before i found this website.

    Anyway i have followed all the directions before asking for your help:
    deleted all unused programs and files
    deleted all norton logs
    opened up all hidden files
    downloaded=Ccleaner
    downloaded=spybot
    downloaded=counter spy
    downloaded=getrunkey
    downloaded=shownew
    downloaded=HighJackThis

    i still have to run all these as per your directions , but i have already ran into a problem. one of the programs is running upon boot and it will not let the system run in safe mode. i dont know what to do. maybe i am being impatient and i just need to let it scan the files in safe mode, but i wasnt sure. so i stopped and restarted in normal mode.

    so my question is do i need to turn the comp off and back on in safe and let it scan the files in safe mode before booting?

    I also need to ask about the ccleaner program it found a lot of files to delete in the advanced area but i was not sure what to do with them. they were uninstall files for secirity updates from microsoft. there were lots of them. do i need to erase those before sending you log files? Thanks to anyone that can help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What program are you referring too? I don't know what you mean it will not let the system run in safe mode. Are you referring to a malware program? None of the items downloaded in the READ ME will block booting in safe mode and the only one that runs at startup is CounterSpy and it will not block booting in safe mode either.
     
  3. twinkles

    twinkles Private E-2

    i turned my computer off and tried to restart in safe mode and when it got to start booting in safe it just seemed to hang , but i was saying maybe it just was slow because the counter spy was scanning the files and i thought it should boot right up . i will try again and wait for awhile. Thanks for responding
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let me know if you still have problems!
     
  5. twinkles

    twinkles Private E-2

    ok Chaslang,
    i think i am ready to get help, not sure i have done everything right, i think i have=just let me know if i need to do it some other way. i really appreciate the help here= i may get mixed up so bear with me.
    i have done all the steps on the READ AND RUN ME FIRST post so here we go:
     

    Attached Files:

  6. twinkles

    twinkles Private E-2

    ok here are the rest of my log files=
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why were you running this PC without any of the below installed:
    • Antivirus
    • Antispyware
    • Firewall
    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03
    Search <-- this may or may not appear and is probably the cause of your problems!

    Make sure you reboot after uninstalling the above!

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: Search - {BFB5F154-9212-46F3-B547-AC6106030A54} - C:\WINDOWS\system32\Search\wizard.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\Search <--- the whole folder:
    C:\WINDOWS\system32\Favorites\deskbar.dll

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  8. twinkles

    twinkles Private E-2

    THANK YOU! THANK YOU! THANK YOU! chaslang you are the greatest!

    that pesky pop up website search engine is gone.

    You ask why i am not running anti virus, antispyware, or firewall.
    i am running all three i think anyway!= i have Norton anti virus which i understand has a spyware and phishing detector in it(running)= i have Windows Defender for spyware(running) = i have XoftSpy for spyware(i do not keep it running i just use it from time to time).
    i do not know why they dont show up on these files for you maybe because i was in safe mode or maybe somethings wrong. i hope not!tell me if you think so.

    one other thing the Search program you told me to delete in Add/Remove program would not delete from there, should i try to delete it some other way.

    any way thank you again for all your time and help. here are the log files you requested.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why didn't they show in your HJT log?? Are you filtering items? If so you should never do that when posting in help forums, otherwise questions like mine will occur. Look at your current HJT log and you will see the processes and services do not show in the registry key area where they would be loaded. However some processes do show running. Do you have a firewall in Norton?

    I thought this was only a scanner and it is not very good as far as we are concerned. Too many ridiculous false positives.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Getting Uninstall Programs List From The Registry and attach the requested log. From this, we should be able to figure out how to remove it.

    Based on your log Windows Defender is not running! You should uninstall it, reboot, and reinstall it.
     
  11. twinkles

    twinkles Private E-2

    Oh chaslang! your really gonna be ticked= i have to apologize to you= hope this does not cause a big problems = i was really trying hard to do everything right, but i messed up bigtime.
    = what happened is i initially came upon the hijack this website so i downloaded it and ran it to try and solve the problem on my own, at that time i put all of the files i sort of knew were ok on the ignore list in hijackthis program. after that, i found out about the majorgeeks website. i was so happy that someone was going to help me, that i forgot all about putting those files in the ignore list, so i did not delete them from the ignore list before running the scan and sending the log file to you. again, i am so sorry, i didnt even think to look at them carefully, if i had i would have known there were a lot of missing files. i was too busy making sure i was doing everything right by the READ AND RUN ME FIRST instructions. really stupid on my part, i hope this doesnt make everything we did so far moot.
    =here is the hijackthis log that has everything, if that helps anything at this point. sorry again!
    =and also, Here is the GetUnKey file you requested.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so stop filtering everything right now and attach a new log.

    You forgot to attach the GetUnKey.txt log.
     
  13. twinkles

    twinkles Private E-2

    ok i thought i sent those logs last time, i am changing my middle name to sorry= here they are=
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks better and now things make sense! ;)


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Viewpoint Manager Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteViewpoint Manager Service into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  15. twinkles

    twinkles Private E-2

    ok first when i tried to delete viewpoint service with the hijackthis program it came back with an error message that says:

    "C:/program Files\Viewpoint\Common\ViewpointService.exe"
    was not found in the register.

    so it would not let me delete the program with hijackthis.

    the registery thing worked fine.

    and here are the new log files you requested=

    do i still need to uninstall Defender and reinstall it.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My instructions did say
    The error you got is why the message is there! ;) The fix worked!

    No! It did not show properly before but that was due to the filtering you were doing.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds