Adware/dialup still on computer after procedure...

Discussion in 'Malware Help (A Specialist Will Reply)' started by iloqin, May 3, 2006.

  1. iloqin

    iloqin Private E-2

    I followed the instructions and did the readme first and thank god it helped me reset almost everything. I did the panda active scan afterwards because it was the last process mentioned, or at least the last process I did and it still came up with a few things that could be potentially dangerous...

    I want to try to have a total complete adware free computer, so it kinda bugs me that cookies and whatnot are still there. If you can explaint o me how to get rid of these few things I'd appreciate it. Thanks.

    And I'll post the previous logs incase something looks odd and shouldn't be there. The previous logs were created before the panda active scan. That was the last part before it reached the...

    You have a few options now if you still have problems at this point:

    Thanks for any information.
     

    Attached Files:

  2. iloqin

    iloqin Private E-2

    Oh and this is the HJT log that I ran earlier, but didn't save. So I ran it again and this is how it looks...
     

    Attached Files:

  3. iloqin

    iloqin Private E-2

    And I suspect that the 2 lines in the hijackthis log that look like this:

    O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\system32\runsrv32.exe
    O4 - HKLM\..\Run: [Transponder] C:\WINDOWS\system32\susp.exe

    Are harmful, and not helpful, is that correct? If so how do I remove them? thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not follow the directions in step 7 of the READ & RUN ME. You are using MSconfig to control startups. We will disable it in the procedures below.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Service Manager ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    WSCM

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O2 - BHO: winapi32.MyBHO - {AF79D4A2-725D-4627-9E34-08C04833D798} - C:\WINDOWS\system32\winapi32.dll (file missing)
    O2 - BHO: (no name) - {e52dedbb-d168-4bdb-b229-c48160800e81} - (no file)
    O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\system32\runsrv32.exe
    O4 - HKLM\..\Run: [Transponder] C:\WINDOWS\system32\susp.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\BTGrab.dll
    C:\WINDOWS\dlmax.dll
    C:\WINDOWS\system32\runsrv32.exe
    C:\WINDOWS\system32\susp.exe
    C:\WINDOWS\System32\service.exe <--- only delete service.exe if found. DO NOT delete services.exe!!!

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. iloqin

    iloqin Private E-2

    Here is the reply...

    I think it's clean, but as far as windows goes... there is a strange pause after I log in all the time. And when I click on things and whatnot nothing shows up 'til aobut 2 minutes later. Then everything I clicked on (whether a file on my computer or winamp or internet explorer or some program) all show up at once.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is free of malware!

    Are you saying this pause only occurs when you first loging and that everything is fine afterwards?
     
  7. iloqin

    iloqin Private E-2

    Yes, that's what I'm saying. And can you explain to me about system restore? Since I am clean of bugs. I right click my computer, then check the box that turns off system restore. Then reboot again, scan, and if nothing pops up. Then check off the box, and post a log of HJT?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't need another HJT log. You are already clean. Just complete the below steps! You lag a startup is probable due to all the stuff you are load at startup. What is all that Message Queue stuff loading for?

    It is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. iloqin

    iloqin Private E-2

    i hope I did this right... just to be sure here is the HJT file
    I re-checked my MSconfig, it was clear before, but now there are 2 spaces for blank items again... =\
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said in my last message, I did not need another HJT log. You were already clean. You just needed to toggle system restore and then you need to work thru the How to protect thread.
     
  11. iloqin

    iloqin Private E-2

    You are the man =) Thanks again. And I posted this on my guild mates website. We play World of Warcraft. So hopefully you get a bunch of hits and maybe some donations! Thanks again.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks for the reference! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds