about:blank and Trojan.Downloader

Discussion in 'Malware Help (A Specialist Will Reply)' started by flipflop, Aug 27, 2005.

  1. flipflop

    flipflop Private E-2

    Greetings Geeks and Geekettes;

    Well...after 12 hours of spyware downloads and 3 hours of scanning...IE still defaults to about:blank.

    There were a couple of issues I ran into while following the Four Commandments post. All the prelim. stuff was done (disable system restore, stop/disable services[Network Security Service], enable views, etc.) All the spyware was downloaded. BUT I couldn't boot in safe mode AND establish an internet connection. Tried the IC wizard (while in safe mode), but was only offered the option of configuring a cable internet connection; the dialup and the LAN options were greyed out. Huh!

    So the only option was to boot normal and run bitdefender; which found and fixed a slew of stuff, but was unable to disinfect and/or delete 3 trojans in C\Window\System32\mfcyr.exe (Trojan.Downlaoder.Agent.BQ and BI; Genpak.Trojan.Agent.BI; ); and Downloader.Winshow.AK in C:\Windows\System32\xobcy.dll. Unable to install RAV Antivirus, as IE error'd out during the definition download.

    Then went back to the plan in the post, booting in safe mode and running all the downloaded spyware programs. Very productive. AdAware found 26 Alexa and CWS objects and fixed them; Spybot found Trek Blue Error Nuker (and NOT all the CWS's it found in previous runs) and fixed it; Kill2Me found Look2me and killed it; and HSR found 26 objects and fixed them. Things were looking up!

    Did a normal restart and made an internet connection. HSR's page came up telling me that I was (they hoped) free of hijackers. Be still my heart! Went to my favorite website to set as default homepage, hit apply, OK, closed IE, opened IE again and....about:blank was my homepage. Crap!

    Let me know if you want HJT log files; as I downloaded that program too, just in case I needed it. I hate being right that way. Oh, and maybe you could point me to a thread that discusses why the H-E-double toothpicks Norton didn't pick up the Downloader.Trojan (it's on their list!) in the first place. Also, maybe you tell me where the MS Malware Protection Tool downloaded during a pre-scan Windows update went. MS Help is, of course, an oxymoron on this issue.

    Thanks in advance for any consideration

    flip
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Question did you find any of the bad services (step 2 of the READ ME) running? Are they still running? Quite often they will respawn and even change to one of the other service names. This may happen after each reboot.

    Please follow the steps below exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    IMPORTANT: DO NOT REBOOT OR POWER DOWN AFTER POSTING THE ABOVE LOG! WAIT FOR INSTRUCTIONS TO BE POSTED. You can disconnect your cable to the internet for security or lock the internet with a firewall if desired.
     
  3. flipflop

    flipflop Private E-2

    Yes, Network Security Service was found and stopped/disabled initially. Now I see that it was running again, so it is stopped/disabled again. The other two were not found before or now.

    HJT log from 5 minutes ago attached (after re-stopping bad service).

    Will await your re-post. thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The service does not look stopped and disabled in your log. I would bet one of the other process is restarting it. Probably D:\WINDOWS\system32\mfcyr.exe is causing it to restart. Let's try the below.

    You need to disable SpybotSD TeaTimer because it will get in our way.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    Please download the following tool: Pocket KillBox

    Extract Pocket Killbox to its own folder but do not run it yet. We will need it later.

    You're OS and IE versions are way out of date and represent a major security risk. After we fix your current problems, you must get updated. We will cover this later.

    Let's try a simple approach to fixing you HSA infection. This may or may not work. Depends on whether there are other hidden processes that we are not seeing right now.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    D:\WINDOWS\system32\mfcyr.exe
    D:\WINDOWS\system32\javazk32.exe

    After killing all the above processes, click the "Back" that is right under the Process window. And just leave HijackThis running for now.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Network Security Service (or if not found loook for 11Fßä#·ºÄÖ`I) ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, go back to HJT and select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Network Security Service

    If that does not work try entering the short name: 11Fßä#·ºÄÖ`I
    NOTE: There is a space in front of the 11F so make sure you start with a space.
    You will need to cut and paste the short name since the characters are not easily typed.

    Now click the back button on the lower right side of the HJT window.

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\srbpy.dll/sp.html#12047
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\srbpy.dll/sp.html#12047
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://D:\WINDOWS\system32\srbpy.dll/sp.html#12047
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\srbpy.dll/sp.html#12047
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\srbpy.dll/sp.html#12047
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\srbpy.dll/sp.html#12047
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\srbpy.dll/sp.html#12047
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {2FD6FA5C-0926-8DFD-5D77-4533A2EF1BD2} - D:\WINDOWS\apirz32.dll
    O2 - BHO: Class - {D197DBF5-A960-6CAE-20A1-FFCAF4879290} - D:\WINDOWS\system32\addux32.dll
    O2 - BHO: Class - {F8BC1A45-7B4A-22E4-33E9-C2F9AB913A1B} - D:\WINDOWS\system32\msaa.dll
    O4 - HKLM\..\Run: [mfcyr.exe] D:\WINDOWS\system32\mfcyr.exe
    O4 - Startup: PowerReg SchedulerV2.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - D:\WINDOWS\system32\javazk32.exe

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now run Pocket Killbox.

    Now, Copy and Paste D:\WINDOWS\system32\srbpy.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste D:\WINDOWS\apirz32.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.


    Now, Copy and Paste D:\WINDOWS\system32\addux32.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste D:\WINDOWS\system32\msaa.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.


    Now, Copy and Paste D:\WINDOWS\system32\javazk32.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste D:\WINDOWS\system32\mfcyr.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    If you get an error message about Pending Operations, just reboot your PC yourself.

    Now get a new HJT log and post it here. And tell us how these steps went and how things are working.

    PLEASE DO NOT REBOOT after posting your log. If you are still infected, it could mutate making the next steps I would post ineffective.
     
  5. flipflop

    flipflop Private E-2

    Hey chas;
    Well, shoot...didn't work. The process went as directed until I got to killing javak32 in Pocket KillBox. It said "...already closed, or protected by Windows". In services.msc, found Network Security Service and stopped/disabled, but did find 11FB... The 'Delete NT Service' in HJT did find 11FB... Now, your instructions did not SAY to delete the service, just click back and scan; so I didn't. Sorry if that was overly literal and that messed up the process.

    Anyway, the HJT scan revealed R1 about:blank, R3 SearchHook missing, O4 mfcyr.exe, O4 SchedulerV2, 09 extra button (no name)...bdoscandel.exe and O9 extra tools...bitdefender...bdoscandel.exe. That's it. Fixed what was found. All of this was done with no browser or programs running. (NOTE: most if not all are back according the the latest log)

    I ran P KillBox and typed in the first item D:\...srbpy.dll; then realized the printout I was looking at said to copynpaste; so I started up IE again to get back to this thread. Again, I hope my literal-ity in reading the instructions didn't mess things up.

    Anyway, P KillBox found apirs32, javazk32 and mfcyr; all selected for delete on re-boot; which I did...went online...and here we are.

    Looking forward to your reply. No, really :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My instructions did say to Delete the Service.

    Opening your browser in the middle of the process was not a good idea. It is best to stay totally disconnected with all browers closed when fixing these things.

    Your old OS and no firewall are making this more difficult. What type of internet connection do you have (dial-up, cable, DSL)? We really need to get some Windows Updates installed since you are so out of date. I don't like doing them while there is still an infection but we sometimes have no choice. They will be quite large. We will not do this yet, but we may have to.

    We are going to need to get some other protection installed on your PC first. Let's start with a firewall.

    Goto this thread: How to Protect yourself from malware!
    And see step 3 and install one of the two free firewalls. After installing it make note of anything that you get popups on trying to get in or out of your PC. If you do not recognize it, do not allow it any access.

    Follow the steps below.

    - First run CCleaner before doing the below.


    - Download this trial version of Ewido Security Suite

    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:


    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report


    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report. And tell me if you are still having any problems. This log could get quite large and you may need to compress it into a ZIP file to upload it.


    Post this Ewido log and then go back and run the Ewido steps again and post the second log in a new message.
     
  7. flipflop

    flipflop Private E-2

    My bad on the faux paus'.
    You said:
    "Your old OS and no firewall are making this more difficult. What type of internet connection do you have (dial-up, cable, DSL)? We really need to get some Windows Updates installed since you are so out of date"

    Attached are txt files on the OS and my update history...latest of which was Aug 25th. I am running a dial-up at 21.6-24.0 Kbps...yup "K"bps...I'm lucky to get a dial tone.

    Am preparing to follow the latest instructions, will re-post with results.

    Thanks for your patience.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Windows XP is up to SP2 level. You are still on just plain old WinXP from the last log you posted. Even WinXP SP1 or SP1a would be very useful. With dial-up speeds, that will take a long time.

    I'll be waiting for the other logs.
     
  9. flipflop

    flipflop Private E-2

    Oh dear;
    Well, I overnight downloaded SP2 for XP and installed. Then installed a firewall (turned off XP's); loaded and ran Ewidow per instructions, then safe booted and ran Ewidow again. Saved the report (106 items found) and normal booted. Attempted to get back on the 'net, but every page tried gave me a DNS not found error. Even about:blank couldn't find a place to go. On the positive side, the web settings were reset to default....and stuck! I am posting this from a work computer.

    May I assume that Ewidow needs a backup restore? Since I can't communicate through my infected computer, I will get the reply off of WEBtv...now THERE's a stable system :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really did not want you to do a WinXP SP2 upgrade. Sorry if that was not stated very clearly. I wanted to see the results of the two Ewido scans before deciding what to do next.


    Please post a current HJT log if you can. Also post the Ewido logs.
     
  11. flipflop

    flipflop Private E-2

    Things seem to be going well now. Pretty much. about:blank is gone. Ewido scans 0 objects. First cold boot since this a.m went like this ... sygate 'enocuntered a problem' error over top of d-box for SG registration (closed both) > launch IE > auto to msn.com (my pick prior to last shutdown)>Ewidow update popup > MG.com > readposts > Home via icon > msn.com (what a wonderful feeling that was) > closed IE > re-opened IE > auto msn.com (whew!) > exit IE > disconnect > re-start. Launch IE > same 2 sygate d-boxes + one sygate box about Generic Host Process for Windows/system32 has changed...wants access to the network..and before I could click No or CnP the text, it vanished and the website went DNS error > same error all websites. exit IE > re-start > launch IE > here I am, feeling pretty good, but a little jumpy yet.

    Before Reports from HJT and Ewidow this post; after's to follow.

    If this works I will remember MajorGeeks.com in my will. :)
     

    Attached Files:

  12. flipflop

    flipflop Private E-2

    After's
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You are still infected but we got rid of a load of hidden file related to the infection.

    We have some more work to do. Do not power down or reboot. Give me some time to work up another fix.

    The bad service is now:

    O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - D:\WINDOWS\system32\winxo32.exe (file missing)

    See if you can locate it and stop and disable it now. Make sure it stays stopped and disabled. Let me know. Also see if you can see the file: D:\WINDOWS\system32\winxo32.exe
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I don't know if you found the service to stop and disable so I'll include the instructions here.

    You MUST now copy (do it right now) the steps below locally to your PC so you can run them while offline with NO BROWERS opened during the whole time. Also you will need to be able to copy and paste in a strange set of characters so you must have copied this locally.

    OK! Exit all browsers and physically unplug your cable to the internet now. Do this before continuing.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Workstation NetLogon Service (or if not found loook for 11Fßä#·ºÄÖ`I) ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, go back to HJT and select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Workstation NetLogon Service

    If that does not work try entering the short name: 11Fßä#·ºÄÖ`I
    NOTE: There is a space in front of the 11F so make sure you start with a space.
    You will need to cut and paste the short name since the characters are not easily typed.

    Now exit HJT but do not reboot if it tells you one is needed.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Now restart HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\urvgy.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\urvgy.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\urvgy.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: Class - {6537283D-964A-CBD4-C67B-7091E7AC8979} - D:\WINDOWS\msbn32.dll (file missing)
    O2 - BHO: Class - {6D02CB4B-4013-E595-ADFC-13B9C08788F9} - D:\WINDOWS\system32\ipgu32.dll (file missing)
    O2 - BHO: Class - {FD55E8C7-3546-B25A-6A5D-99EFC7458DF8} - D:\WINDOWS\system32\mfcli.dll (file missing)
    O4 - HKLM\..\Run: [sysit32.exe] D:\WINDOWS\system32\sysit32.exe
    O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - D:\WINDOWS\system32\winxo32.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now run Pocket Killbox. (note: if pocket killbox does not find any of the below files, just keep on going to the next steps).


    Now, Copy and Paste D:\WINDOWS\msbn32.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.



    Now, Copy and Paste D:\WINDOWS\system32\ipgu32.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.


    Now, Copy and Paste D:\WINDOWS\system32\mfcli.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.



    Now, Copy and Paste D:\WINDOWS\system32\winxo32.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.


    Now, Copy and Paste D:\WINDOWS\system32\sysit32.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.


    At this point I want you to physically pull the power plug (yes that's what I said) to your PC. We need to do this to prevent a graceful shutdown which is where the problem can respawn. After shut down, wait a minute and then plug your cable back in.


    Now reconnect your cable to the internet and open and close your browser a couple times (don't surf - just open and close).

    Now with all browsers closed, get a new HJT log.
    Now come back here and post your log.
    And tell us how these steps went and how things are working.


    PLEASE DO NOT REBOOT after posting your log. If you are still infected, it could mutate making the next steps I would post ineffective.
     
  15. flipflop

    flipflop Private E-2

    Ok, tons of fun. Stopped all browers and pulled phone jack.

    Was able to find WNL Service and disable > Apply (was already stopped, but set to Auto) > curiosity took me to the Log On tab, where is showed Hardware Profile 1 ENABLING the service, so set to Disable > Recovery tab > set 'no action' on all fails > apply > ok.

    >HJT > Delete NT Service > WNL Service not found > copied character name from Word doc > not found > copied character name from Notepad > FOUND and deleted (this time!) > Sys Restore still off; Hide files still unchecked.

    >HJT > and found every line but 023 WNL Service > Fixed > exit. > reset web settings > no option for Delete Offline content > ran P KillBox > 0 finds.

    > PULLED THE PLUG > Re-energized and re-connect phone jack > on re-boot, Sygate error msg (happens on every boot-file attached to next post) > dont send >checked taskmanager and DrW running furiously (70% of CPU), frozen dialog boxes > DrW Postmoretm error msg (file attached to next post) > stopped service on DrW in Taskmanager > d-boxes cleared.

    >IE > MajorGeeks > DNS error (several attemps) > ran HJT to gen log (attached) no choice but to shutdown > choice of Off 'with' updates or Off 'without', selected 'with' > shutdown w/ "update 1 of 1" on splash screen > finished with auto Power Off.

    Cold start > Sygate error msg > IE > MajorGeeks > exit IE > IE > MajorGeeks (Ewido did auto update) > exit IE > HJT to gen log (attached) > IE > MajorGeeks > where I am now.

    Couple of questions: 1)the NWL Services properties box, in the Log On tab has a password option. If this was set, would this thwart a respawn? Or should I just shut up? 2) Overall, the cleanup is working well; should I be concerned about the Sygate and DrW errors at re-boot - or is that for another forum? 3) Since Ewido is running, I have disabled Norton auto-protect - is that advisable? Since it "saw" but did nothing about the original Trojan.Downloader I am suspect of it.
     

    Attached Files:

  16. flipflop

    flipflop Private E-2

    Sygate and DrW Postmortem error msg texts
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log is clean now.

    Are you still having malware problems?

    I would not disable Norton's autoprotect. You still need it or anothe antivirus application. Don't forget that Ewido is also just a 15 day trial too and it works together with your AV to provide greater protection.
     
  18. flipflop

    flipflop Private E-2

    That's good news, chas. Thanks for all your help. You are a Geek god! This forum is a great service to the internet community. Your mother must be proud of you.

    No popups (Google blocker says -0-, has for days). Web home access is stable. No recent DNS errors. Services are clear. I plan on a re-boot and shakedown cruise real soon, here. My hope is THIS post is my last. :D Although I will still hang onto my notes from this session, you betcha'.

    If the DNS error problem (and other issues like an A: drive check about 3 min after launching IE; double refresh of desktop icons at system startup; "send error report" msgs at startup for Sygate and DrW) don't clear up at next re-boot, I think I'll cruise the other forums. I certainly will update IE, and look into an alternative browser. I definitely plan to buy Ewido - seems cheap enough.

    Thanks again
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds