[B]online scan and zone alarm in safe mode[/B]

Discussion in 'Malware Help (A Specialist Will Reply)' started by davepicc, Jul 10, 2005.

  1. davepicc

    davepicc Private E-2

    Hey guys-
    I'm running through all your spyware steps for the third time and when I go into safe mode to run Trend Micro's and Symantec security check Zone Alarm keeps shutting them down at the end of the scan thinking someone is trying to hack my computer- so I'm not getting the final results. I'm running Win XP SP1/Dell Dimension 8300/2GB RAM. Is is safe to shut Zone Alarm off during the scans??? Thanks for any help.

    Dave
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No do not shutdown ZoneAlarm. Try running the scans in normal boot mode.
     
  3. davepicc

    davepicc Private E-2

    Hey chaslang-
    Thanks for the reply and your help. I already have done that twice with no viruses or any malware in normal mode. Actually I might have done it three times. That was before I fixed my corrupted registry with scannow though (when my registry was corrupted I wasn't able to use IE so I used Trend Micro with Firefox) so I wanted to do it again to be safe with internet explorer. I figured before I updated from WinXP SP1 to SP2 nothing could be overkill.

    Dave
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So are you having any problems with malware right now?
     
  5. davepicc

    davepicc Private E-2

    Well I got a dreaded blue screen error last night after trying to run Mcafee stinger in safe mode. I did a Win XP repair (see this thread http://forums.majorgeeks.com/showthread.php?t=66618 ). The guys over there wanted some one from the Spyware Specific forum to chime in because they weren't sure. If you could check it out whenever you get a chance I'd really appreciate it. Thanks again for all your help.

    Dave
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still sounds like a Windows software problem to me but if you want to check for malware, we can do that. Based on you original message, I'm assuming you have run all steps in the READ ME FIRST. So please follow the below steps exactly:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  7. davepicc

    davepicc Private E-2

    Re: online scan and zone alarm in safe mode ATTACHMENT

    Hey chaslang-
    Thanks a lot for helping me out.

    Dave
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: online scan and zone alarm in safe mode ATTACHMENT

    Okay Dave! Let's get started.

    First you need to stop using MSConfig to disable startup items from loading. We need to be able to see everything that could load. So run msconfig and select normal startup. If asked to reboot, do not reboot yet.

    Download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the newdotnet6_38.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move newdotnet6_38.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.


    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing <--- LSP-fix may have fixed this already
    O15 - Trusted Zone: *.line6.net
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2324a8dab41da4c80e05/netzip/RdxIE601.cab


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\newdotnet <--- the whole folder


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. davepicc

    davepicc Private E-2

    Hey chaslang-
    Sorry for the msconfig thing- I was reading a RECORDING magazine article today on how to get XP optimal for audio recording. One of the major things was taking stuff off your startup like messenger, etc. I was hoping it might fix something.

    OK- did everything you said. I was not able to find the newdotnet program file folder though at the very end when I booted in safe mode? It just wasn't there. I did remove it from "LSP- Fix" though and it was already in the remove section so all I had to do was click finish. When I got to HJT the newdotnet was no where to be found- even under 10 like you listed. I did remove 15 & 16 like you said. Thanks so much for all your help again.

    Dave
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your log is clean of malware items. Are you still having any problems?
     
  11. davepicc

    davepicc Private E-2

    Hey Chaslang-
    My system seems to be running a lot better- I'm glad I posted the log. I can't thank you enough for all your help. :)

    Dave

    p.s. Do you think it would be wise to still run a Win XP repair just to fix any corrupted files before I update to SP2?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It should not be necessary to run a repair and that could just bring your PC back to an older point in time. Depends on what version of Win XP is on your CD. But this is more of a topic for the Software Forum. I would however just go get the SP2 update.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds