Alert Maliscious script System[1].exe.js

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Levithian_666, Sep 14, 2004.

  1. Levithian_666

    Levithian_666 Private E-2

    Help please can't get rid of this... Also Im running XP and my information bar keeps popping up saying IE has restricted this fil from showing active content that could access your computer : click here for more information, wanted to know if the two were connected because they started doing this at the same time... Please help...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Levithian_666

    Levithian_666 Private E-2

    Chaslang, thanks for sending that link, btw it did work to let ya know. It took of System[1].exe.js... But there is still one pending problem maybe you can help me with. To help protect security IE has restricted this file from showing active content that could access your computer. Click here for options... Could you send me the security I need to adjust or what I need to do please and thankyou..
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still getting that message?

    Do the below:
    Run Internet Explorer and click this sequence Tools, Internet Options, Security, Internet.
    Click on the lower right the Default Level button then click OK.
    Now click the Custom Level button.
    In the ActiveX controls and plugins section:
    1) set "Download signed ActiveX controls" to 'Prompt'.
    2) set "Download unsigned ActiveX controls" to 'Prompt'
    3) set "Initialize and Script ActiveX controls not marked as safe" to 'Disable'.
    Now when software attempts to be installed on your system, you will be asked whether you want ActiveX objects to be executed.

    Some people recommend putting sites that you know and trust into the "Trusted Zone" in Internet Option,Security. I recommend not doing that. This way if anything ever appears there at all, you know it should not be there and you do not need to guess what to do with it (always
    remove it).

    If you are having other problems do what I gave you in my first message:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  5. Levithian_666

    Levithian_666 Private E-2

    I don't know maybe its a script problem I did what you said and it didn't work... Ichecked through the first post link thing you had on it, but no cigar. Cannot fix it... When I go to information on Information Bar Help when it pops up it says to stop blocking file and software downloads with the information bar :Open Internet Explorer.
    On the Tools menu, click Internet Options.
    On the Security tab, click Custom Level.
    Do one or both of the following:

    To turn off the Information Bar for file downloads, in the Downloads section of the list, under Automatic prompting for file downloads, click Enable.
    To turn off the Information Bar for ActiveX controls, in the ActiveX controls and plug-ins section of the list, under Automatic prompting for ActiveX controls, click Enable. But this doesn't work either... I haven't a clue what to do next...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. Levithian_666

    Levithian_666 Private E-2

    All steps ran, but without any results. going to bed now tired of working on this thing probably wont be on till tomorrow 3pm est ish...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download HijackThis version 1.98.2 and following the guidelines in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    Post your HijackThis log as a .txt file attachment.

    Make sure you shutdown all un-necessary applications (especially all browsers) before running a scan. Do NOT run Hijack This from the Desktop, a temp folder or choose run from inside the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  9. Levithian_666

    Levithian_666 Private E-2

    Here it is...
     
  10. Levithian_666

    Levithian_666 Private E-2

    Screwed up let me see if I can fix...
     
  11. Levithian_666

    Levithian_666 Private E-2

    K here it is hopefully worked this time
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay go back an read that HJT tutorial again though. I'm still going to work on your log but note a couple points you missed from the tutorial:

    Make sure you shutdown all un-necessary applications (especially all browsers) before running a scan. Do NOT run Hijack This from the Desktop, a temp folder or choose run from inside the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT


    You had three browsers open! Don't do that anymore.
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    And you put HijackThis on your Desktop! Fix this!
    C:\Documents and Settings\John\Desktop\Extract\hijackthis\HijackThis.exe
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First check Add/Remove Programs to see if there is an uninstall for MyWay or MyWeb or MyWebSearch or something similar. If so, use it to uninstall.

    Please bring up Windows Explore by right clicking Start and then choose Explore. Now select your C drive. Just look thru the directory list and tell me how many directories begin with \progra (disregard whether uppercase or lower case). If more than just \Program Files , tell me exactly whatelse. I'm wondering why HijackThis shows the two below items differently:
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    Okay now for the cleanup:
    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u MYBAR.DLL
    then click OK. If a dialog box confirming this action appears, click OK.


    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End it:
    KHost.exe
    upload 32 coal.exe or coal.exe
    PLATFORM KIND.exe or kind.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gsvzazwznjlvhzd.info/6KElRtUgXZMrLMnmDb66hQzHuTmPJz2Tf7_Qk8sM5M0NSeGNobHU3miRyPnpZp6f.htm
    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O2 - BHO: (no name) - {F43C1C15-A7FC-5A09-DE8A-74F3F7B74A54} - C:\PROGRA~1\DEFAUL~1\WAY SAFE.exe
    O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O4 - HKLM\..\Run: [Enc Creative] C:\PROGRA~1\Freecorn\upload 32 coal.exe
    O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
    O4 - HKLM\..\Run: [Chic cake for hide] C:\Documents and Settings\All Users\Application Data\dent window chic cake\PLATFORM KIND.exe
    O15 - Trusted Zone: *.05p.com
    O15 - Trusted Zone: *.clickspring.net
    O15 - Trusted Zone: *.mt-download.com
    O15 - Trusted Zone: *.my-internet.info
    O15 - Trusted Zone: *.searchmiracle.co
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab

    Now reboot in safe mode and delete:
    C:\Program Files\MyWay <--- the whole directory
    C:\PROGRA~1\Freecorn <--- the whole directory
    C:\Documents and Settings\All Users\Application Data\dent window chic cake <--- the whole directory
    C:\WINDOWS\kdx\KHost.exe

    Reboot normal mode and create a new HijackThis log to post. And tell me how the above steps went and how things are working.
     
  14. Levithian_666

    Levithian_666 Private E-2

    Will do when I get back home, but one question... I am fairly new to computers so do you mean look through the directory list meaning the whole list? or what? sorry I dont understand
     
  15. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi,
    What he means is he suspects c:\progra~1 could be a problematic folder because there should be (and is) a c:\Program Files directory. So to be sure, he would like you to browse your drive using Windows Explorer and see if there are and folders starting out c:\progra

    An easy way to do this is to double click My Computer on your desktop, then click the c:\drive where you will see a list of all folders on your computer. Make sure there is nothing starting out progra EXCEPT for "Program Files"

    Hope that helps.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly MA! Thanks for the backup!

    I want to be sure on this one. I have seen it a couple time recently and I starting to wonder if it is just a qwirk in HijackThis reporting. Sometimes the path is spelled out and sometime it uses the 8 character name abbreviation. Have seen it on c:\Documents and Settings too. So I want to be sure we do not have bogus directories.
     
  17. Levithian_666

    Levithian_666 Private E-2

    Okay got it nothing with c:\progra~1 at all so must be just a screwup in Hijackthis.. K will do therest of the steps around 3 cause I must go now, Ill inform you right away if it helps...
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You are looking for anything on your C drive in the root directory (that is c:\) that begins with progra (ignore upper/lower case). You have at least one. And that is c:\Program Files.
     
  19. Levithian_666

    Levithian_666 Private E-2

    That is what I meant nothing with C:\progra except Program File.. :D
     
  20. Levithian_666

    Levithian_666 Private E-2

    Hmm guys, wondering if I should keep going was doing the RegSvr32 thing and this what it come up with... "LoadLibrary("MYBAR.DLL")failed - The specified module could not be found... Wondering if i should just skip that or what?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's fine! Just keep going with the steps.
     
  22. Levithian_666

    Levithian_666 Private E-2

    Sigh, heres the HiJackThis log file, but didn't help problem...
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had a bunch of problems! Some of them are now fixed.

    Did you fix this line with HJT:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.jdggqhbyaebukkdqvkf.com/6KElRtUgXZMrLMnmDb66hQzHuTmPJz2Tf7_Qk8sM5M2/GiCbIDGFtXiRyPnpZp6f.html


    It's back. Did you no that Messenger Plus installs spyware & a lop hijacker and that's why we don't have it as a download on Majorgeeks? Did you read the license agreement?
     
  24. Levithian_666

    Levithian_666 Private E-2

    MSN Messanger and Messenger Plus 3 are gone... Yes I read through the license agreement briefly, but not thorughly. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.jdggqhbyaebukkdqvkf.com/...iRyPnpZp6f.html. I fixed it again...
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not need to get rid of MSN Messenger. It is okay. It is from Microsoft. The Messenger Plus 3 is the one that is problematic. If you need a messenger program, my friends here on MG's recommend one of these 3 "Multi" format programs GAIM or Trillian or Miranda. All are downloadable here http://www.majorgeeks.com/downloads33.html .

    Does that R0 line still show in a HijackThis log? Just take a look yourself.
     
  26. Levithian_666

    Levithian_666 Private E-2

    Yeah, I'll download it again another time, No the R0 line does not appear on HiJackThis log file... If it helps at all my homepage on IE is www.sympatico.msn.ca and it says "IE has restricted this file from showing active content that could access your computer" But there is no active content on it (Or none that I can find) Was just thinking that... maybe it could help not sure...
     
  27. Levithian_666

    Levithian_666 Private E-2

    Maybe you coudl tell me the things I should have checked (Disable Enable Prompt) in ActiveX-Downloads-Miscallaneous-Scripting etc... maybe someone might of screwed around with it. I have four brothers and sisters, someone could have screwed with it while on computer not sure...
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  29. Levithian_666

    Levithian_666 Private E-2

    Its always the simplest things that can sneak by you... Somehow in Tools - Internet Options - Advanced - Security. Allow active content from CD's to run on my computer and Allow active content to run in files on My computer weren't checked so I checked them and no more Information Bar... The third link that you posted had the info on it I needed... But... yes another but, :D sorry... For some strange reason when I go to look at my emails I log in but I get a blank screen. At the bottom it says "Done" but it wont display any of the contents of my inbox... If there is anything simple like fixed the problem before start at that then move on... :D
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For this one, I think yo need to post you OS, your mail reader program, and your problem in a new thread over in the software forum.
     
  31. Levithian_666

    Levithian_666 Private E-2

    K will do thanks for help Chas...
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds