Advice needed please ..

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by angelbabe, Sep 27, 2004.

  1. angelbabe

    angelbabe Private E-2

    Hi :)

    I have been struggling for yonks with various spyware and virus issues for for days, but think i have more or less sorted it ... I HOPE :D

    I managed to get shot of Downloader.Agent.2BN and 2BM by doing AVG scan in safe mode and as spybot and adaware would not complete scans, I went to regedit and deleted some obvious things and also got hjt to fix some.

    I have now noticed that the 4 infected files are back in my startup :( HJT also shows them. What i would like to know is if these are safe for me to let hjt fix. Here are the names of them

    C:\WINDOWS\SYSTEM\APPIT.EXE
    C:\WINDOWS\ADDCX.EXE
    C:\WINDOWS\NTES32.EXE
    C:\WINDOWS\SYSTEM\APILE32.EXE

    According to Startup Inspector for windows these files dont exist :confused:

    I dont know if this is relevant, but PC takes about 20 mins to boot up and makes a heck of a noise. Seems to take the longest when it gets to this part of startup.

    C:\ > Rem [Header]
    code prepare code page
    code prepare function completed

    Are these essential to getting windows up and running? :eek: scuse my ignorance .. i am somewhat PC knowledge *challenged* :p

    Any help would be appreciated please.
     
  2. DaRkKn1qHt

    DaRkKn1qHt Private First Class

    I do not believe those files to be essential at boot up. You might want to try Easy cleaner.
    http://majorgeeks.com/download414.html

    It cleans the registry and a couple of other folders on your computer. It also has a better view of what starts when your computer boots, and allows you to disable these items.
     
  3. angelbabe

    angelbabe Private E-2

    :) Thanks for your reply

    Will the Easy Cleaner remove them safely? When I did scan with AVG last nite it said they were critical files or something. Doing scan in safe mode earlier today did move them to vault. From my latest hjt log all else seems pretty clear. I did a good clean with CC Cleaner.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    When you did all of your cleaning out of spyware and virii, did you turn off system restore ( if you ar using XP or ME )? as a reboot can & will bring back most if not all of the removed files.

    turn off system restore.. reboot and do the exact steps you did before as you seem to have followed the correct procedure bar the system restore turning off and see if that keeps those 4 removed files from returning?


    if ok after say a couple of reboots then enable system restore again.




    on a side note ... its been ages since I heard that expression YONKS ... :)
     
  5. angelbabe

    angelbabe Private E-2


    :) Hi :)

    I am using windows 98SE. and in my limited knowldege, have not found any option to disable any system restore. I am a bit of a PC *virgin* so am learning things as I go along by trial and error. At this rate I will soon be joining the ranks of geek :p

    I have been sat here trying to pluck up the courage to just hit delete of those files :D Have installed easy clean and so far most of it is greek, but as i am persitent by nature, i will get the hang of it sooner or later :)



    on a side note ..... as far as i know YONKS is a South African saying ... which I am :cool:
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Ah Win98 sadly doesnt have system restore so that avenue is out the window!

    Doing a few searches of those file names I tend to agree with DaRkKn1qHt in that they dont seem like ligitimate windows files..

    not used EasyClean myself but it does have an undo feature, one program I am used to is Regcleaner http://majorgeeks.com/download460.html I find this easy to use to remove any unwanted startup items from the registry ( also does a backup incase they are needed )

    run RegCleaner the click Startup List... are those files listed in their? if so have a quick look under the heading "Loaded From" of they are coming from a part of the registry like HKEY_LM\Run then tick the box and click remove selected.


    ah I see a south african in the UK... I remember that word in my younger days from the North West of the UK and its meaning is the same I guess Yonks = Ages ;)
     
  7. DaRkKn1qHt

    DaRkKn1qHt Private First Class

    I have found it easy to boot into safe mode and manually remove the files when they are stated as being critical. Some virus when in effect can not be deleted because they are open. Boot into safe mode by continually pressing F8 at startup
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based upon your filenames I would say you have the HSA aka Only the Best hijacker. If so, you can delete those filenames as much as you want and they will be replaced by new ones. You need to clean up all files and registry entries that the hijacker puts on your PC.

    First you need to follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal > If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    After that you may have to proceed to: When all else fails - Generic Solution to HSA (Only the Best) & About:Blank hijack
     
  9. RCCGRUNT

    RCCGRUNT Private E-2

    Might I suggest to try Stinger.exe also. I don't know if it will fix the problem but it can't hurt. I would say go with chaslang on this.
     
  10. angelbabe

    angelbabe Private E-2



    Hi :)

    YES!! YES!! I kept on getting popups saying only the best and my homepage kept on changing to About Blank. I have done a search in regedit and deleted what i could find. I plucked up the courage and did a fix with HJT.... Log is looking much better, am now running AVG to see if i am clear. Will let u know as soon as it is completed.
     
  11. RCCGRUNT

    RCCGRUNT Private E-2

    Did ya downlad Stinger? It actualy finds viruses on your system than other AV overlook. It's very helpful trust me.
     
  12. angelbabe

    angelbabe Private E-2

    ok, thanks .. will install it as soon as AVG is done. It better had be totally IDIOT PROOF though :p

    How on earth this got on my pc in the first place is beyond me .... my motto is ..... surfing without protection is like having unsafe sex !! ;)

    I am in North West .... Blackpool ... i know .... SHAME ;) Yonks = Ages
     
  13. RCCGRUNT

    RCCGRUNT Private E-2

    No matter how protected you think you are stuff will still make it onto your machine. Somethings lie dorment for sometime before they make themselfs known.
     
  14. angelbabe

    angelbabe Private E-2

    Hi :)

    I will download that as soon as AVG is through scanning. If AVG shows that I am clear does it mean the critter is gone .... FOREVER?

    I did try and do a scan with S&D and it stopped running when trying to scan for something called Adgoblin...PC sounded like a tractor, lights on CPU were like a disco and it just stopped scanning..his happened every time i tried. Adaware also stopped b4 scan was finished. I did run CW shredder before running them.

    Just a thought ... wud it not be easy to see what is on pc by me putting HTJ report (in text form) ?
     
  15. RCCGRUNT

    RCCGRUNT Private E-2

    It would help. ;)
     
  16. angelbabe

    angelbabe Private E-2

    :) :) :) :) :) :)

    Right Guys ... AVG has given me an all clear .... for now at least. I will however follow the other advice to ensure it stays like that ... as soon as i have had a JD and Coke ... or three :p

    Thanks you have all been most helpful *insert kisssmiley* ;)
     
  17. angelbabe

    angelbabe Private E-2

    ;) I thought it might ... that is why i subtly suggested it :p

    Here u go :)

    Logfile of HijackThis v1.98.2
    Scan saved at 22:51:51, on 27/09/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\AOL 7.0\WAOL.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\HIJACKTHIS.EXE

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O1 - Hosts: 64.91.255.87 www.dcsresearch.com
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - https://register.btopenworld.com/templates/btwebcontrol.cab
    O16 - DPF: {C56CE781-A6FC-4706-8B32-6EB4622155DF} (MediaConnect Control) - http://plugin.euro-infomedia.com/mpv0.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
    O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4394/mcfscan.cab
     
  18. RCCGRUNT

    RCCGRUNT Private E-2

    Ok it isn't looking to bad now. The mmtask.tsk I might be alittle lerry of. Did you download and run Stinger?
     
  19. angelbabe

    angelbabe Private E-2

    Hi :) I have done a bit more *house cleaning* since this report using my initiative and have a better report..can i post it? :D I also downloaded all critial windows updates.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't volunteer help like this if you do not know how to analyze HJT logs. mmtask.tsk is a valid Windows process.

    Stinger should have already been run a long time ago, if the READ ME FIRST thread had been followed correctly.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  23. angelbabe

    angelbabe Private E-2

    I realised the mmtask.tsk is a valid windows process. I have run several scans and results are system is clean.

    Thanks everyone for help and advice :) I have learnt a heck of a lot in the process of eliminating these critters. :)
     
  24. angelbabe

    angelbabe Private E-2

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds