Back Web Lite??

Discussion in 'Malware Help (A Specialist Will Reply)' started by coralou, Jun 26, 2005.

  1. coralou

    coralou Private E-2

    I ran spybot and found 59 entries from back web lite. Two of them are files and they rest are registry values. What the heck are these?

    Should I do more than just "fix selected problems"?

    Thanks!
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yeah, go ahead and fix those entries with Spybot. After you have removed those entries procede with the below.

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. coralou

    coralou Private E-2

    Here is my HJT log.

    thanks!
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Viewpoint

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Virus Removal\CCleaner\ccleaner.exe" /AUTO

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O15 - Trusted Zone: *.musicmatch.com (HKLM)

    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.sparedollar.com/sdImage/XUpload.ocx

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Navigate to and DELETE the following folder if it should remain:

    C:\Program Files\Viewpoint

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    After you complete the above REBOOT, Scan with HijackThis and attach the new log.
     
  5. coralou

    coralou Private E-2

    When I rebooted I received an error message ~ A problem has occured.........
    Here is the info listed at the bottom ~

    **stop: 0x0000007E,oxc0000005,0x00000000, 0xF8ACE384, 0xF8ACE080

    Thanks!!
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Reboot a few times and see if you get the error again.

    Your HJT log is clean, are you having any further Malware issues?
     
  7. coralou

    coralou Private E-2

    Thanks for you help bigarrick!!

    Can you tell me what my issue was ~ virus, spyware? Should I be changing passwords?

    Do I need to change my name and join the witness protection program? ;)

    Thanks!
     
  8. coralou

    coralou Private E-2

    I was looking over my HJT log. I see a couple of lines with AOL in them ~ can I delete these? I don't use AOL.

    When I try to remove AOL from the control panel it states that there are no versions installed. I would just like to remove all of it if possible. I am trying to clean out all of the useless junk on my computer.

    Thanks!!
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Boot into Safe Mode and delete the below folder and then have HJT fix the AOL entries, should take care of it for you.

    C:\Program Files\Common Files\AOL
     
  10. coralou

    coralou Private E-2

    Everything seems to be working great ~ Thanks so much for your help!!
     
  11. coralou

    coralou Private E-2

    It seems I was wrong. This is the only site I can access. I can't get online at all using IE. Ack ~ I don't know what I have done.

    I removed 2 entries in the HJT log (aol). I couldn't get online at all. I did a systems restore and managed to get on this site but no others :(
     
  12. coralou

    coralou Private E-2

    Ok ~ I had changed the system configuration from normal to selective start up. I had 48 processes running and thought I could stop some of those from loading.

    I can now surf the web. I think I will leave well enough alone......

    Thanks!
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you did a System Restore it probably brought back some problems so attach a fresh HJT log.

    Any problems as of right now?
     
  14. coralou

    coralou Private E-2

    I went into msconfig and chose selective startup. I couldn't get onilne so I went back and selected normal startup.



    I did both of thses things around the same time so I don't know which one ( if either) I managed to screw up.

    After I am off line for a couple of hours I have to rebot in order to get online.

    I knew after I did the restore that i might have brought back my original problem but I hated to come back here and ask you to look at it again :eek:

    Here is my HJT log.

    Thanks!!
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean, are you having any further Malware problems?
     
  16. coralou

    coralou Private E-2

    No more malware problems.

    THANKS!!!
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  18. coralou

    coralou Private E-2

    LOL ~ I actuall did read that. I installed all of the reccommended programs.

    I had the Kerio (?) firewall and somehow made a mess of it. I use ebay and could not sign on when I had the firewall on. I believe I actually allowed something that i shouldn't have and blocked something that I needed.

    I switched to zone alarm and I love it!!!

    Thanks again!!
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ive been using ZA for a while now and I love it. Never had a problem out of it.

    Surf Safely!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds