at the end of my rope.....

Discussion in 'Malware Help (A Specialist Will Reply)' started by casub7775, May 7, 2006.

  1. casub7775

    casub7775 Private E-2

    Hello....thanks for taking the time to read my request.

    My problem: I cannot access my yahoo personal web page nor my yahoo e-mail account on my home desktop pc....each time I try, I get redirected to the front page asking for my account name and ID. At first, my browser kept redirecting me to "antispylab.com" and kept trying to change my startup home address....

    I found your website, specifically, the page titled "Read and Run Me First Before Asking for Support".....I HAVE DONE EVERYTHING ON THAT PAGE THREE SEPERATE TIMES....I SKIPPED NOTHING....ALL THE SCANS HAVE BEEN DONE...YES, ALL of them, including CWShredder and Kill2ME

    It helped...actually, I had it fixed and was using my personal webpage and email in SAFE-MODE....then I DISABLED SYSTEM RESTORE, just like I was instructed to do...and then rebooted in normal mode....guess what....still can't access my yahoo personal page and e-mail. I can use the internet though. ALso, it doesn't seem to be redirecting like it was before......I even deleted my SBC/Yahoo and Internet Explorer stuff and reinstalled...still didn't fix the problem...

    So, things are better...but for me not to be able to access my web page and e-mail is disasterous...

    Please help...I'm totally frustrated...

    I'm attaching the logs for Bit-defender, panda active scan, and Highjack this.
    Please advise me if you think you see the problem....I reviewed old forum topics and I saw nothing that seemed to be similar to my problem....

    Thanks so much for your time....
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeek!

    Well you did not quite do everything as instructed. You did not follow the directions for installing HijackThis in step 7 and thus are running it exacly how we request that it not be run (directly from the ZIP file). And also in step 7 we specifically request that you not use MSconfig to control startups which you are still doing. Install HJT as per the instructions in step 7 before continuing to the below! We will fix the msconfig issue in the below steps!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Uninstall or shutdown Windows Defender before doing the below.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {1C2ED83E-EE73-CA15-5AC1-E21F4CCE399E} - C:\WINDOWS\system32\d3dd.dll (file missing)
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O2 - BHO: (no name) - {e52dedbb-d168-4bdb-b229-c48160800e81} - (no file)
    O4 - HKLM\..\Run: [msoe.exe] C:\WINDOWS\system32\msoe.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\system32\runsrv32.exe
    O4 - HKLM\..\Run: [Transponder] C:\WINDOWS\system32\susp.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\exuc32.tmp
    c:\windows\system32\INNERADINSTALL.LOG
    C:\WINDOWS\system32\msoe.exe
    c:\windows\system32\runsrv32.exe
    C:\WINDOWS\system32\susp.exe
    c:\windows\system32\tcpservice2.exe
    c:\windows\system32\txfdb32.dll
    C:\WINDOWS\system32\SplWbr.dll
    C:\WINDOWS\system32\xmltok.dll
    c:\windows\BTGrab.dll
    c:\windows\dlmax.dll

    Additional step to delete files in the Downloaded Program Files folder :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s iwonslot1,0,2,5.inf
    del iwonslot1,0,2,5.inf
    exit

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. casub7775

    casub7775 Private E-2

    at the end of my rope..version 2

    Thanks for the reply....sorry about that....I did not run HJT properly the first time...but I think I did this time...I followed your reply step by step, but had several problems....

    1. after running the HJT, I "fixed" what you told me to, but 2 lines were not present:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    just letting you know...maybe it doesn't matter (and yes, I had the show hidden files, etc. checked as described in the tutorial).

    2. MOST IMPORTANT PROBLEM IN MY OPINION:

    after going to safe mode, I began deleting what you instructed in Win Explorer...however, there were 2 items I could not delete (they were not checked as read only..AND, when I went to Task Manager...I tried shutting down all processes one by one...some simply would not shut down b/c they are critical....others I tried to shut down initiated a shutdown timer that shut the whole computer down...so I don't know what to do about that...)...the 2 I couldn't delete are:

    c:\windows\system32\runsrv32.exe
    c:\windows\system32\tcpservice2.exe

    3 others that were on your list were not present in explorer:

    C:\WINDOWS\system32\msoe.exe
    C:\WINDOWS\system32\susp.exe
    C:\WINDOWS\system32\xmltok.dll


    Again, I think this is the biggest problem...but I tried everything I know to do.

    I also did the start..run...cmd thing...it stated it could not find iwonslot1..otherwise, I think it was okay.


    3. I reset the Web settings..although, when I accessed my Int. Explorer icon...under properties..and then Program Tabs, I DID NOT SEE a "Reset Web Settings" tab/button....anyway, I did everything else there.


    4. Finally, I rebooted in normal mode....and the first thing I saw was a pop-up box titled: "Smart Bridge Alerts:motiveSB.exe-Entry Point Not Found" and then under that it read "The procedure entry point GetProcessImageFileName W could not be located in the dynamic link library PSAPI.DLL".......man, I have no idea what that means...but I thought I should tell you anyway.

    I still can't access my Yahoo personal page nor my e-mail...it keeps re-routing me to the initial log-in page.

    Also, when I try to re-boot....windows is not shuting down...it seems to lock up/hang-up.

    I'm attaching the new HJT log.....listen, I REALLY APPRECIATE all of the help...you guys are awesome in my book!!!!!!!!!!!!!!!!!!!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: at the end of my rope..version 2

    Please do not start new threads! You must remain in one thread for your problem. Starting new threads will only delay you from getting help and could result in someone just telling you to run the READ & RUN ME again.

    Trying deleting the two files that would not delete before now. They are no longer in your HJT log loading at startup and it may be possible to delete them now. Tell me what happens.

    Your issue with Smart Bridge is not malware. It is related to your ISP software. You really need to talk to them about this. It sounds like the PSAPI.DLL file may be missing. This is a Microsoft Windows system file. You may need to get a copy from a backup or download the file and get it back into your C:\windows\system32 folder. Check to see if the file is missing.

    When/why did you install IE 7? This is a beta version and really should only be used by beta testers and advanced PC users who can deal with the potential problems it may cause you.

    Your Yahoo problems also may not be related to malware, but to be sure what it is from you must first make sure those two other files are deleted and you get your PSAPI.DLL file problems resolved.
     
  5. casub7775

    casub7775 Private E-2

    sorry for the new thread...well, as for the Internet Explorer 7 thing....I deleted my old one b/c I thought it might help...and when I went to Microsoft, I downloaded it.

    I checked in explorer and the PSAPI.DLL is indeed there....should I delete it and download a new one? If so, where do I find a copy of it to download?

    Finally, the two files we talked about (runsrv32.exe and tcpservice2.exe) will still not delete..I get the error that it is "being used by another person or program"....what does that mean and how do I close the program so I can delete it? I don't think I know how to identify the programs in Task Manager. Anyway, I really wish I could delete these 2 things to see if it would fix my problem!

    Again, thanks for the help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before or after your problems began? Note: IE cannot be deleted or uninstalled. It is an integral part of the OS and without it you cannot access many websites and you will not be able to download and install many Microsoft Updates.

    If it is in c:\windows\system32 then you probably do not need to download it. This is all probably due to installing IE 7. This is not a malware problem and as such you would be better off discussing it in the Software Forum. Re-registering the proper version of PSAPI.DLL may help but I'm not sure.


    Run the below procedure and attach the runkeys.txt log. I want to see if there is any indication of why Task Manager is getting disable.

    Using GetRunKey
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: May 8, 2006
  8. casub7775

    casub7775 Private E-2

    I tried to access the link you put in (http://forums.windrivers.com/showthread.php?t=75854) and it gave me a pop-upbox saying the administrator has banned my IP address...that's funny...I've never seen this website before/never heard of it??????????

    As for deleting BBMedic (http://bbmedic.ntlworld.com/medic/index.html)..I looked for it under Add/Remove programs and even searched for it...I don't see it on my system.

    I ran HJT and fixed O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe....I have attached a HJT log, which was run after I fixed the above.

    I also did the get run key program...the log is attached.

    Finally, I deleted IE 7 and rebooted....IP 6 magically appeared back on my desktop...although it's funny....there is no address line anymore (you know...the line where you can type different addresses to go to)....I checked the toolbar to show with no success. Again, I tried to delete those 2 programs in system32...still won't let me.

    I noticed in the get run key program, it ID malware according to the statements at the end. Man, this is by far the worst computer problem I have ever had.....I picked up something that is really messing things up...I hope that whomever devised this virus/worm (or whatever it is) is really happy with his work...it sure is causing me grief!!!!!!!!!!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Starnge! I wonder if they have an IP address range or your ISP blocked. I try to put it into a file you can view.

    Did this fix the problem with getting the message about the DLL file?

    Don't worry we will get it fixed! We just needed to locate some hidden info that the runkeys.txt log revealed. Note that report at the end for Miscellaneous Malware was blank. You misinterpreted what was being said however you are the second person to question this so I modified the program (version 1.36 is available) and reworded it. When I ask you to run it again (later) make sure you redownload it to get the new version already available.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot your PC into safe mode and see if you can delete those two files! Also delete C:\WINDOWS\system32\runsrv32.dll if found!

    Then reboot into normal mode and get a new runkeys.txt log (download the GetRunKey.ZIP program again to get the new version. Let me know if the new info at the end makes it more clear to you about what is being reported).
     
    Last edited: May 9, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The attached ZIP file contains a file that is a complete Web Archive. Extract the file from the ZIP and double click on it. It should show in your browser automatically.
     

    Attached Files:

  11. casub7775

    casub7775 Private E-2

    Actually, the problem with the SmartBridge thing (PSAPI.DLL) is not happening now...I don't know exactly if it was fixing it w/ HJT or b/c I deleted IE 7...anyway, it's not happening now. I looked at the site you gave me...yes, I think it was the same thing.


    I did the fixme.reg and booted into safemode, but I'll be damned...I still can't delete those 2 stupid files....I just don't understand?????? Anyway, I'm attaching the new GetRunKey (yes, the newer version sounds better to me) log and a new HJT log just in case.

    Oh, I was able to delete C:\WINDOWS\system32\runsrv32.dll....but even with this deleted, I still could not delete the runsrv32.exe.

    I was thinking about either taking the computer onto the roof and drop kicking it to the moon or just putting my fist through the monitor....my better half doesn't think that's a good idea...so I guess I'll refrain for now....
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.
    C:\windows\system32\runsrv32.dll <--- just to make sure it did not come back
    C:\windows\system32\runsrv32.exe
    C:\WINDOWS\system32\susp.exe

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):
    C:\windows\system32\runsrv32.dll
    C:\windows\system32\runsrv32.exe
    C:\WINDOWS\system32\susp.exe

    Now reboot into normal mode and let me know how things went.
     
  13. casub7775

    casub7775 Private E-2

    Pocket Killbox worked!!!!!!!!!! Man, it was great to finally delete those files.

    However, my main problem, which is not being able to access my SBC Yahoo personal page and e-mail is still present. Every time I try to log in it sends me back to the log in page...over and over....like it's being hijacked or something. Any ideas on how to identify the cause of this specific problem and fix it?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I do not know what your problem with Yahoo is but it does not appear to be malware. Maybe you need to uninstall all of the SBC Yahoo software reboot and then reinstall. You HJT log did show something related to Yahoo Companion as missing:

    O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll (file missing)

    Other than that, check with Yahoo or SBC (whoever controls the place you are logging into). Perhaps your account is no longer valid or you are not using the proper account name and password (maybe someone change it - just a wild guess). Also try shutting down all of the McAfee software and logging in.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds