A few problems on this end

Discussion in 'Malware Help (A Specialist Will Reply)' started by aggiedude, May 3, 2005.

  1. aggiedude

    aggiedude Private E-2

    Hey folks, apparently I opened a bad email and now boxes keep popping up that say this basically. Error in Winsock Module; Connection is unknown;Possible Reason; Your firewall and/or Antivirus application block the system-File; services.exe. Also box that says the same for cmss.exe and smss.exe I've ran adaware, spybot, and also attempted to do an avast scan, and the avast scan came back saying it couldn't read these certain files, which I'll also post here......I AM a computer idiot so please speak in laymen's terms for me..Oh yea, and it "stole" my Norton AntiVirus from me and now if/when I try to add it back, it says the Integrator can't be found......I'm here so any and all help is GREATLY appreciated, Marty...So 1st is the hijackthis scan and then the avast scan ok;
    ------------------------------------------------------------------------

    Edit by chaslang: Unrequested inline log removed

    [B]And here's the avast scan....................[/B]
    avast! Virus Cleaner Tool - version 1.0.207 Unicode

    Creating log file: C:\avast.log

    5/3/2005, 2:34:31 PM
    Memory scanning started...
    No virus body found in memory.
    Memory scanning finished (33.4s).
    ----------
    Files scanning started...
    C:\WINDOWS\Connection Wizard\Status\csrss.exe... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\packed1.sbr... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\packed2.sbr... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\packed3.sbr... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\sacri1.ggg... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\sacri2.ggg... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\sacri3.ggg... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\services.exe... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\smss.exe... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\voner1.von... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\voner2.von... file could not be scanned!
    C:\WINDOWS\Connection Wizard\Status\voner3.von... file could not be scanned!
    No virus body found.
    Files scanning finished (42098 files, 0 infected, 700.2s).
    Drives scanned: C:
    ----------
     
    Last edited by a moderator: May 4, 2005
  2. aggiedude

    aggiedude Private E-2

    I tried to edit the hijack this scan after seeing I was NOT supposed to send it unless requested. I don't see where/how to edit it and apologize big time.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the below steps but first tell me if you know anything about the lines mentioning Connection Wizard in your logs.

    You should also use Add/Remove programs to uninstall Weather Bug.

    Make sure you properly install HijackThis as stated. You were running it improperly and you also did not exit your browsers before running it.

    One list of things you can fix immediately with HijackThis is all the lines that look like the below line:
    O18 - Protocol: bw+0 - {0F4E1883-1E14-4299-BCE0-5CB84FD1DCCB} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. aggiedude

    aggiedude Private E-2

    chaslang, will do that buddy but also just found out something here at work...Got an email about a new worm called Worm_Sober.S and it looks like that's what I think I have ..I DID open an email from a company I was expecting an email from, but it surprised me when the email said my password had been changed. Well, I clicked on it and it downloaded a .zip file and I think that's where I am now.....Any "fixes" besides taking it to a shop ? Still do what you are saying, etc...????? I work until 6am CST but would appreciate, and do appreciate, your help. Like I said, I'm pretty much a computer idiot but will try anything..Thanx again, Marty
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just follow all the steps I gave you Marty. And if you know anything about those Connection Wizard lines tell me. I believe they are not valid. A normal Connection Wizard entry for Internet Explorer would appear in c:\Program File\Internet Explorer\Connection Wizard.
     
  6. aggiedude

    aggiedude Private E-2

    chas, I got no clue what they are, or mean, buddy....Sorry about that. Just not too swift with this stuff.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's OK! Just work on the procedures and will figure it out later.
     
  8. aggiedude

    aggiedude Private E-2

    Will do it when I get home in the morning..And I again apologize for the HJT list; I didn't read to NOT do it until after it was too late. And as far as the avast log goes, a buddy who knows a lot about computers ((but getting married tomorrow and then a 2 week honeymoon, so not much more help there for a while)) told me to run that.....Thanks a million and will let ya know what happens tomorrow...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Just get back to me when finished. You will also notice the Avast tool mentioned down in the Alternative Scans section of the READ ME FIRST.
     
  10. aggiedude

    aggiedude Private E-2

    Ya know something ?? After reading the Sticky of Do not post until you read this; this sounds like it might take a while, but if it works, will be worth it. I've never had to do anything like this and just hope I can follow some of these "foreign" (to me) instructions...It'll definitely be a major challenge but I'll do my best.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running the steps of the sticky thread will not always fix all the problems that users have but it does in some cases. However, we relie on it to help clean any of the many of the easier problems up for us making the remaining job that much easier. It also gets the system into a somewhat known condition for us to work from. I would not count on it fixing your main problems but it may help fix other issues that may be hiding.
     
  12. aggiedude

    aggiedude Private E-2

    I definitely understand...Won't be as much "junk" in there and after gettin' rid of tons of that, make the main problem easier to identify and deal with..Talk to ya manana !!!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Take notes duing the process and let me know what the steps do find and fix (and also not fix)!
     
    Last edited: May 4, 2005
  14. aggiedude

    aggiedude Private E-2

    Great googily moogily chas...I think I'm done buddy and now have to go to work.....After over 8 hours of scanning, rescanning, spywaring, adawaring, etc......Symantec Security Check came back the 2nd time saying there were no viruses or anything in my files or memory.....I honestly must get to work now but what should I do next besides bowing and bowing to you folks ?????
    Do you need to see an HJT paste in the morning or anything ???? And any ideas how I can get my Norton Antivirus back or did the virus take it ????
    Oh yea, the main things I had are these;
    C:\WINDOWS\system32\bdlgs.dll was infected with Adware.Better.Internet
    C:\WINDOWS\system32\winhlp32.dll.exe was infected with Security Risk.Downldr
    C:\ProgramFiles\Symantec\LiveUpdate\LUALL.EXE was infected with W32.Sober.O@mm (might have been a 0) and
    C:\Documents and Settings\marty\\winhlp32.exe was infected with Adware Toolband

    Let em know what to do next ok..I got tons of spyware in my system now so think that'll help, and will do whatever you gurus tell me to do tomorrow ok....
    Thanks VERY much !!!! Marty :D
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just finish the procedure I gave you by posting the follow up HijackThis log.
     
  16. aggiedude

    aggiedude Private E-2

    I don't know how to do the attatchment part, so I copied it, and will paste it....Hope that's ok......Here goes...............................And I don't understand why HJT is showing as a document...I thought I put it in a program area...


    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: May 5, 2005
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To attach files, you must be in Advance Mode (Click Go Advanced at the bottom of the message window). Then scroll down and click the Manage Attachments button. Then browse for your file, upload it, and close the Manage Attachments window. Submit your message.

    You are not running the correct HijackThis.exe then. I'm not sure how you are starting it up but you are running a version that is installed here" C:\Documents and Settings\marty\Desktop\HijackThis.exe

    Delete that one (which is on your desktop) and run the one (if installed where requested) in c:\Program Files\HJT\HijackThis.exe

    You do not appear to have an antivirus program installed. At least not properly installed as I do not see it running. This is not a good idea.

    Is this log from normal boot mode or safe mode? Logs must be from normal boot mode unless otherwise requested.

    I do not see any of that Connection Wizard stuff. What happened to it?
     
    Last edited: May 5, 2005
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [system check] C:\WINDOWS\Downloaded Program Files\updater.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program Files\Agnitum\Outpost Firewall\TRASH.EXE (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program Files\Agnitum\Outpost Firewall\TRASH.EXE (file missing) (HKCU)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/31da4b28980ee4...tzip/RdxIE2.cab
    After clicking Fix, exit HJT.

    Now boot into safe mode.

    Special step to delete updater.exe:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s updater.exe
    del updater.exe
    exit


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  19. aggiedude

    aggiedude Private E-2

    chas, I'm "ass u ming" that one of the many scans deleted the conection wizard buddy, but honestly don't know...And I had the Norton before the virus/worm/something deleted it so will have to use my ISP's as of tomorrow I guess. ((and which would you recommend over all others)). Would consider deleting all of Norton Systemworks if I found something newer and better; mine's a 2002 edition....Will also try and find the correct HJT because I know it's in there...This boot was from a normal mode with all accessories, internet, email, etc..closed.....
    I did notice one thing though. After all these scans, now theres a Logitech Keyboard icon that wants to download at the bottom of my screen. Maybe I pushed the F8 too many times or something, I don't know.....
    So will try all of this when I get home ok. Wish I understood how u folks could comprehend all this greek stuff, but I just thank GOd y'all are out there....Thanks and will try to "finish her up" manana !!! Marty
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  21. aggiedude

    aggiedude Private E-2

    chas, I think I did it right this time, but God only knows....Also, my ISP has set me up with free Anti Virus, Pop up and Spyware Killer, Personal Firewall, and parental control (don't need that), so wondering what I could/should delete of the other programs..Thanks a million..Marty
    Also, it's called B-secure if you see it in here...
     

    Attached Files:

  22. aggiedude

    aggiedude Private E-2

    Oh yea, and should I keep the Norton System Works on my computer or uninstall it all now ??? Just got this other stuff and wondering if it'll "mess with" that stuff....Thanks so very much for ur help so far; it's GREATLY appreciated !!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not think you have all of those tools and I do not not to much about B-Secure. All I do know about it is that it is only a popup blocker and nothing else.

    You do have InetCntrl which appears to be: Bsafe Online - internet filter
    But this tool appears to be broken due to a missing file and it could be messing up you internet connection. See the below line from your HJT log that indicates this problem:
    O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

    Again I have no idea what this Bsafe Online includes. I'm not sure how good any of these tools really are. They are not standard prorgams that most people would use. You may be better off with the tools I gave to you in my How to Protect thread.

    Also are you sure these tools are not just a free 10 or 15 day trial? I did see that they are only trial versions in some cases and you have to buy the.
     
  24. aggiedude

    aggiedude Private E-2

    chas, I ain't sure what to say on that....My ISP rep offered this Bsecure to me free for as long as I'm with them, and advised me that normally it's like $60 a year, and that it includes Pop up and Spyware Killer, Anti Virus, and Personal Firewall.....Here's the website and if you need my login info, PM me or email me and I'll give it to you ok.....This is now my 2nd favorite site in the world pal; can't give up www.surplusrifle.com as my 1st.. :cool:

    http://portal.grandecom.net/x.php?e...%2F%2Fportal.grandecom.net%2F&srce=my_premium

    Thanks, as always, for everything, and let me know what to keep, what to delete, what to do, ok......Marty
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you get the application fixed?
    O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

    This is part of the stuff you installed from your ISP and a file seems to be missing.
     
  26. aggiedude

    aggiedude Private E-2

    Just waiting on a reply from my ISP guy...hopefully one of the techs there can fix/repair/walk me through it, or something....Let's hope.
    And chas, does it hurt to run CC Cleaner everytime I'm on the computer ? Seems to make things run faster even though I need to re-enter passwords sometimes....Thanks buddy.
     
  27. aggiedude

    aggiedude Private E-2

    Here's their reply so far chas....

    I'm not sure what he's referring to, hijackthis scans his computer. Any errors it generates would be on his computer, and unless his cable modem is going through USB, we don't install any software on the computers. I checked the modem out and I show it's going through a network card. So this error is not something on our end. According to what I have found on this hijackthis should be able to fix this error message. This of course is something we don't support here in Technical Support, but I did some searching and found people fixing it with hijackthis.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Numb nuts that do not now what they are talking about!

    Of course we can fix the
    O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

    line using HijackThis or another tool but this message indicates that yoyr LSP (Layered Service Provider) chain is broken. The inetctrl.dll file is part of the tools they had you install. If the file is missing your tools will not be able to do their job properly. This will happen because a component they require that allows the software to intercept your communication on you network card connection to help protect you is missing.

    As I stated earlier I don't know to much about these tools they are giving you but I'm sure we can do better with software available on MGs and they are also free and probably much more reliable.

    If you are not having any problems and feel comfortable that you are protected properly that's your call. Stick with what you have. However if you run into anymore malware issues in the near future come back and tell me and we will relive this discussion.
     
  29. aggiedude

    aggiedude Private E-2

    They said because they didn't instal any software for me to connect it isn't their deal...Hell, I dunno pal. I just want my computer to be safe ya know...Here's his reply to ur 1st post, not this one....


    Yeah, if we had to install software in order for him to connect, then this would be correct information, but we didn't install anything on his pc.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Who are they refering to when they say "his" and "him"? Who are they having this conversation with?

    And aren't they the ones that suggested that you use the B secure package. It has nothing to do with connecting, it has to do with protecting and they are the ones who told you to use it. Software packages that attempt to protect you can also break your connection. It's obvious that the people you are dealing with have no idea how a PC works. They probably do not even know what the LSP chain is. If they do not use software themselves and do not understand how it works, they should not be recommending that anyone use it. That it pretty negligent on their part.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds