any ideas please?

Discussion in 'Malware Help (A Specialist Will Reply)' started by noviceseeking.lol, Feb 14, 2007.

  1. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hi before anybody tells me off for not doing the pre help routine you request BEFORE requesting your help can you please read my problem!

    EVERY firewall,antivirus,spyware,hacker,rootkit programi install just unstantly ends up hooked and i cant use them!

    I HAVE TRIED to do online scans but i am running I.E.7 and alot of them dont work with IE.7 (or maybe its just this malware i have?).

    I am unable to roll back to IE.6 ( i have tried) and spybot/adaware dont clear/detect the problem!

    I have managed to run rootkithookanalyzer 2.0 (downloaded from your website tools) and attach the report but wonder where to proceed from here?

    No firewall or antivirus i have installed works at all so i have to limit the time i am online as i am sure whatever it is is active even in safe mode (as i am now). it APPEARS TO ME (although i have only limited experience so i could easily be wrong) that there is also something hiding my screen at times (like smitfraud?) but smitfraud removal doesnt work.

    any suggestions would be greatly appreciated and my apologies for not BEING ABLE to follow your recommended procedures!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you mean by "hooked". Do you mean that the program hangs or stops running or crashes?

    There is nothing related to malware in the log you attached. You need to work thru the READ & RUN ME and complete all steps possible. Even if you cannot run online scans, you should be able to do many other steps. Start at the beginning and do all steps in the order requested and attach all logs that you can get. The log you did attach shows that you already have several tools installed like CounterSpy for one. Can't you run it and attach a log?

    When you come back also tell us exactly which steps you could not do! Again many of the steps should still be possible. Make sure you uninstall all requested items mentioned in step 0, make sure you have only ONE antivirus application installed (step 3).
     
  3. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hi Chas thanks for your assistance!

    msconfig normal start up applied.

    when system boots message: "autoch program not found-skipping autocheck"

    i removed several junk programs and other cleaning tools ii had tried myself that i freeware downloaded.

    updated spybot (fixed potential exploit as required)
    installed/updated counterspy but the active protection keeps on disabling itself??
    Current antivirus is avg free as my last antivirus blueyonder pcguard is rubbish but when the control centre is opened it shows the antivirus database is out of date (even though i updated it earlier today and there are no other updates?)
    And i did have a panda internet security2007 free trial installed when all these probs cropped up (or i noticed them?) but the firewall and the updates kept disabling themselves so i uninstalled it!

    SAFEMODE:

    Ccleaner (log attached) clean???
    Spybot (no probs detected)
    Counterspy (no probs detected)
    Avg no probs detected
    Get Run key and Show new logs attached!
    Hijack this renamed analyse.exe and log attached.

    Reboot normal mode

    After running all these I also ran a lavasoft ad-aware scan-log attached.

    I have noticed that occassionally my windows warning in the botton right hand corner flickers on saying anti virus is out of date? this happens frequently but only for a second then disappears? (it is supposedly upto date and no other updates available)

    Counterspy's active protection keeps disabling itself??

    Also if i right click on anything my pc tries to load/install blueyonders pcguard? as far as i am aware i have removed all parts of this program and if you let it run through to install itself it says insert disk? but it stops you right clicking on what you want until you have closed the pcguard warnings down?

    Hopefully this information will help you to help me!


    I am UNABLE to successfully run ANY online scans as they either crash or hang.
    several of them i think dont yet support IE.7 but panda just doesnt run it requests i accpet the active x control but then doesnt install/run?

    thanks!
     

    Attached Files:

    Last edited: Feb 15, 2007
  4. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hijack this and lavasoft log attachments only.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks to me like you never got PCGuard uninstalled completely. The same is true for Panda Antivirus.

    Let's beging by removing items from Panda!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Panda Process Protection Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Remote Packet Capture Protocol v.0 (experimental)
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste PavPrSrv into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • rpcapd
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    PCguard <-- if you don't find this, make sure you tell me since it is in your registry.

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [PCguard] "C:\Program Files\blueyonder\PCguard\Rps.exe"

    There is no reason to run HJT at startup so, I recommend you fix the below too:
    O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan


    After clicking Fix checked, exit HJT..

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now locate the below files and delete them if found:
    C:\xx2
    C:\xx3
    C:\xx4
    C:\xx5
    C:\xx6

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  6. noviceseeking.lol

    noviceseeking.lol Private E-2

    Thanks Chas requested logs attached!

    1)when re-booting still get the autoch program not found-skipping autocheck message displayed.

    2) still get pcguard trying to load/start up when right clicking on anything?
    was UNABLE to uninstall as it isnt anywhere to be found on my system (although as you said it is in the registry?)

    3)when the desktop is loading a window flashes for a fraction of a second (unable to see anything in it.it is about the size of a spybot window approx)
    then disappears or is strangled? dont know if thats relevant or not but has only just started happening.

    4)as stated could not locate either pcguard or anything to do with blueyonder as they supply pcguard?

    5)panda process protection service located (was supposedly already stopped?)
    start up set to disable as instructed!
    Also Remote Packet Capture Protocol v.0 (experimental) WAS located (again was supposedly stopped)
    start up set to disable.

    BOTH were set to be removed by hijack this delete an NT service.

    J2SE Runtime Environment 5.0 Update 10 uninstalled as instructed
    PCGUARD not located?

    Sun Java Runtime Environment downloaded and installed (after reboot)

    ?Sunbelt CounterSpy trial was uninstalled - BUT the folders that SHOULD have been left behind in:

    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    WERE NOT THERE (or anywhere else as far as i can see???)

    my system is set to show all hidden files etc?

    but program did appear to uninstall correctly.

    Hijack this jobs done:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [PCguard] "C:\Program Files\blueyonder\PCguard\Rps.exe"

    There is no reason to run HJT at startup so, I recommend you fix the below too:
    O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan


    web settings reset INTERNET EXPLORER 7.
    homepage reset to www.majorgeeks.com.

    registry edited as instructed (seemed to work fine).

    C:\xx2
    C:\xx3
    C:\xx4
    C:\xx5
    C:\xx6

    ALL OF THESE FILES WERE FOUND AND DELETED.

    Ccleaner run.


    Dont think the problem is cured but i think ya gave it a kick in the nuts and let it know your coming!


    requested new logs attached! :)
     

    Attached Files:

    Last edited: Feb 16, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs free from malware!

    This is not a malware problem. Sounds to me like you deleted your c:\windows\system32\autochk.exe file. Possibly when you were deleting things on your own. You will need to replace this file from a copy on your Windows XP SP2 CD or perhaps you have an I386 folder on your PC that has a backup of the file.

    You should not be getting this anymore since we finished removing the file from startup. Let me know if you are;however, this is also not a malware problem. It is just poor software design from PCGuard. You may need to use a registry cleaning tool to remove all traces of PCGuard. Please run this: Getting Uninstall Programs List From The Registry and attach the requested log. I want to use it to find the real registry key name for PCGuard in the uninstall programs list.

    Not sure what it is but it is probably just one of your applications loading.

    You did not show any malware in your logs to start with and you still do not. Any problems that you are having are not malware. They are just due to the software that has been installed in the past and that had never been properly uninstalled. In addition if you have been experimenting with varities of malware detection/removal tools and deleting things on your own, you may have complicated things. At any rate, based on your logs, you do not have any malware.
     
  8. noviceseeking.lol

    noviceseeking.lol Private E-2

    Thanks Chas

    attached is the unkey log.

    I do have an i386 folder on my pc but have no idea how i would use it to fix that start up message? or delete the pcguard nuisance that is still happening!

    Also i amgoing to use outpost free firewall and avg free until i can get to the shops ( a few days) to buy an internet security package.

    Is there a product you guys recommend?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Windows Explorer (right click Start and select Explorer). Look in the i386 folder for a copy of the autochk.exe file and right click on it and select copy. Then navigate to your c:\windows\system32 folder and select it. The hit CTRL-V to paste in a copy of the autochk.exe file. Make sure you check to see if the file is actually copied into the c:\windows\system32 folder.

    Let's continue with this a little. However the I'm not sure we will be able to remove the right click feature that is still happening. You might have to resort to reinstalling the junk and then uninstalling it (but not while AVG or Outpost are installed). We shall see!!!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    • Download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Copy & paste the following string 83CDADBF-C060-444D-B17D-5742C425CC19 in the top area of the form and then click "Ok".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.
    NNNNNOOOO! Do not waste your money on one of those massive resource hogs! The free tools we recommend here are quite sufficient and will not bring your PCs to its knees tryin to run nothing but process related to the security suite. They are all pigs and they don't work that well anyway. Stick with AVG Free and Outpost or ZoneAlarm or other we recommend in the How to Protect yourself from malware! link!

    Now attach the log from the Registry Search and a new log from ShowNew.
     
  10. noviceseeking.lol

    noviceseeking.lol Private E-2

    Chas:

    copied over the backup file from I386 as instructed BUT that file was supposedley already in the system 32 folder. (so thinking it maybe corrupted i replaced it anyways)........no difference still have the start up probs.

    right click thing with pcguard still annoying the hell outta me....lol

    will use my time to read the geeks how to protect myself from malawere guide rather than go shopping :D !

    Reg Edit went smoothly (far as i can tell anyways.lol) seemed to work to me!

    system still seems a little scratchy but maybe thats just me and the right click thing?

    logs attached!

    ALSO (forgot to mention) whenever i open my IE.7 it says internet explorer is not ur default browser-although it is supposed to be?


    thanks.
     

    Attached Files:

    Last edited: Feb 17, 2007
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I only have one more thing to try related to this, if it does not work you will have to pursue the problem with your ISP or try the Software Forum since it is really totally unrelated to malware.

    Download the attach BUreg.zip file and extract the BUreg.bat from it to your Desktop. Then double click on the BUreg.bat file. When it finishes (in a few seconds) you will have a file name C:\BUreg.txt Attach this file to your next message.


    Again not malware. Just tell it to be your default. Here is an example with more info:

    http://www.wellesley.edu/Computing/Netscape/Browsers/pc_ie-n7x.html#ie
     

    Attached Files:

  12. noviceseeking.lol

    noviceseeking.lol Private E-2

    BuReg log attached.

    Chas i have made my IE the default browser but for some reason its not accepting it.

    As you said its probably a screwed up registry somewhere.

    i would prefer to uninstall IE.7 anyways and go back to IE.6 but it wont let me do that either.
     

    Attached Files:

    Last edited: Feb 18, 2007
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot and attach a new log from the below procedure

    Doubleclick regsearch.exe to start the program.
    Copy & paste the following string 83CDADBF-C060-444D-B17D-5742C425CC19 in the top area of the form and then click "Ok".
    Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.


    Are you still having the same problem with PCGard?

    Your IE7 issues will have to be reported in the Software Forum.
     
  14. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hi Chas

    The problem has now changed a little (but much for the better) now if i right click on anything windows installer flashes briefly -(as it did b4 pcguard tried to load)-as if searching for something to install but then disappears and allows me to carry out the right click function!

    Reg Edit seemed to go smoothly.

    Reg search log attached.

    I know you are sure that my remaining problems are now software related (and i am sure most of them are as my registry is probably messed up) BUT i just cant shake the feeling that a nasty is lurking somewhere?

    I have 10mb broadband and my internet is usually instant but its almost at dial up speed its so slow. (its not the antiphising thing i have that switched off currently).
    It could just be my browser is twisted up (IE7) and i need a word with your software guys? i dunno my pc knowledge isnt great.......but something doesnt FEEL right if ya know what i mean?
    Is there a final malware test i can run for you to look at before you refer me to software?

    anyways i know you guys are flat out helping everyone at the minute and its great you give up your time to help us out-it would be a messed up surfing world out there without you and your comrades in arms thats for sure!
    :)

    Hi Chas just edited this as I have just noticed that although the ONLY thing I am doing on my pc is usind IE7 to browse the geeks site my outpost firewall is pulling 48 on my cpu?
    now thats just weird isnt it?
     

    Attached Files:

    Last edited: Feb 18, 2007
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Windows Installer CleanUp Utility to see if it finds anything else to cleanup; however, anything else on this topic belongs in the Software Forum.

    You have not shown me any evidence of any malware based on your problems being reported or based on the information in the logs. Perhaps if you had ran BitDefender and PandaActive scan they may or may not have found anything.

    Try using FireFox instead of IE7. Is there any improvement?


    Again try FireFox and see what happens. IE7 has sometimes been problematic for many people. Perhaps you should consider working with someone in the Software Forum on uninstall IE7 and using IE6.
     
  16. noviceseeking.lol

    noviceseeking.lol Private E-2

    Chas

    can run the online scans now ( they are clean as you already know:) )

    i think the only issues i have left are related to IE.7 and that final right click problem (pcguard doesnt load now but windows installer pops up then disappears).
    Obviously as you said they are software related issues.

    Thanks for all your help!
    I will ask your software guys about uninstalling IE.7 (if thats what they advise) and going back to IE.6. (what i really want is just to have IE. available for online scans but to actually run firefox or something else as my browser!)
    anyways thanks again and keep on fighting the good fight!
    :wave
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You need IE for more than online scans. There are many sites that will require IE and Microsoft Update is one of them. Without IE you cannot get many updates from Microsoft.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds