Cannot Remove Program

Discussion in 'Malware Help (A Specialist Will Reply)' started by Global2004, Jan 18, 2007.

  1. Global2004

    Global2004 Private First Class

    Hello All!

    Please forgive me if I've posted in the wrong forum.

    My boy downloaded Morpheus Ultra 5.1 on our home computer. I went into our Control Panel - Add or Remove Programs and selected Change/Remove.

    There is a pause, then our ZoneAlarm brings a Security Alert.

    A~NSISu_.exe is trying to access the trusted zone.
    Identification: Not available in ZoneAlarm
    Application: A~NSISu_.exe
    Destination: 127.0.0.1:port 2556

    I selected "Deny". After that the ZoneAlarm warning goes away and a small blank Internet Explorer window opens up. Then nothing.

    I close the IE window and retry removing the program again and the same thing happens.

    I've Googled A~NSISu_.exe and have not been able to get any good information on this and whether or not I should "Allow" it.

    Can anyone help me with this? I dont want to create a bigger problem but I would like this program off our computer.

    Cheers.
     
  2. Lev

    Lev MajorGeek

    That file can be part of the uninstaller program but it can also be potentially dangerous. So I'm going to ask the moderators to move your thread to the Malware Forum, where you will receive expert technical assistance with this :)
     
  3. Global2004

    Global2004 Private First Class

    Thank you Lev.

    I've started the Malware removal process now.

    I'm having a problem at starting the computer in Safe-mode. I get to the Boot.INI and select SafeBoot "Apply".

    I then get a dialog box "System Configuration" An Access Denied error was returned while attempting to change a service. You may need to log on using an Administrator account to make the specific changes.

    It then says to Restart computer, but nothing happens.

    To go back and give you a bit of history, we learned we had pirated Windows XP Pro and got the popups. We purchased the software from Microsoft inserted the disc and it updated our system. On the pirated version , when we would startup our computer it would go to the blue screen, with the administrators box to select. When we installed the new XP Pro whenever we start our computer the Blue screen appears with "Windows". No box to select. We just click the screen and it starts.

    How do I set up or get to Administrators account?

    Thanks for all the help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some of your problems may not be due to malware! They may just be corruption in your OS. This could have occurred by upgrading your pirated version to a legit and I assume XP SP2 version.

    Please follow as much of our standard cleaning procedures (given below) that your problems will allow. If you cannot do steps in safe mode just do them in normal boot mode. The more you do the better. The more logs you get us the better to.

    There are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. Global2004

    Global2004 Private First Class

    "I HAVE RUN ALL THE STEPS IN THE STICKY"


    Thanks for helping me out Chaslang.

    I could not get into SafeMode using the start-run-msconfig-safeboot
    however I was able to get to safemode by restarting the computer and selecting F8.
    This did bring up the startup page with Administrator and Work. I entered my password and did most of the steps in Administrator.

    I ran CCCleaner, Spybot S&D, AVG Anti-Spyware, BitDefender.
    I could not get a connection when I tried to run PandaScan while in Safemode, so I ran it in normal boot mode.

    I ran GetRunKey, ShowNew and HijackThis. I will post these results in my next post.

    Thanks,
    Global
     

    Attached Files:

  6. Global2004

    Global2004 Private First Class

    Here are the results of GetRunKey, ShowNew and HijackThis.

    One other questions Chaslang, and this could perhaps be answered once the other problems are delt with, but how can I stop certain programs starting when the computer reboots.

    Specifically: QuickTime (Not sure if I even need this program)
    DVD43
    Windows Messenger
    Skype
    IObitDefrag (Just recently loaded after reading,
    "Basic computer maintenance everyone should do", by
    Major Attitude)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6

    Make sure you reboot after uninstalling the above!

    Try uninstalling Morpheus Ultra 5.1 again, but this time allow the A~NSISu_.exe program to run. This is part of the uninstaller.

    I don't like the looks of the below to files! Any idea what they are?
    Code:
    "C:\WINDOWS\"
    spoois.exe    Jul  8 2006       97820  "SpooIs.exe"
     
    "C:\WINDOWS\"
    win32s~1.dll  Jul  8 2006          43  "win32SpooIs.dll"
    

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    The first question is do you need those programs. If not, you should uninstall them. Otherwise continue on to the below.


    If you stop IObitDefrag from loading, it defeats the whole purpose of how the program works. Thus you need to decide if you want the program or not.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Jan 23, 2007
  8. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    I uninstalled the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6

    I could not get my computer to reboot. Start-Turn Off Computer-Restart. I tried this several times with no luck so I held in the button on my tower to turn off the computer. I waited a few seconds and then turned it back on.

    I uninstalled Morpheus Ultra 5.1, and allowed the A~NSISu_.exe program to run. This seems to have worked. It is no longer listed in my Add/Remove Programs list. However, when you click on Start-Programs...Morpheus Ultra is listed.

    I installed the current version of Sun Java from the link you provided.

    I ran Disable/Remove Windows Messenger and removed Windows Messenger.

    I copied the bold text you provided to notepad and saved it as fixME.reg to my desktop. I was sure the "Save as" type was set to "all files" Once I saved it I double clicked on it and allow it to merge with the registry.

    I tried to restart my computer but am continuing to have the same issue. Once I click on Restart, nothing appears to happen. Although one of the small icons (SoundMax Control Panel) in the lower right corner of my screen has a red circle with a line through it.

    Now regarding the two files you were concerned with, they ring a bell. This is a link to a post on MajorGeeks I sent back on July 16, 2006. You helped me back at that time. I've added a bit of I wrote to you back then.

    http://forums.majorgeeks.com/showthread.php?t=97218

    4) Major concern last week. We leave our computer on and hooked up to the internet 24/7. We turned on the monitor one day and found five items open or changed.
    i) Internet Explorer was open and the address was: http: //badars.phpnet.us/ SpooIs.exe
    ii) Our control panel was open and Windows Firewall was hi-lighted.
    iii) A black DOS window was open and one line of text caught my eye. C:\WINDOWS>SpooIs.exe -install Access is denied. (I have screen shots of this)
    iv) Our AVG had been removed
    v) Our Skype name had been changed to something rude.


    I've attached the new logs for you to have a look at. If there is anything else you require, please let me know.

    Cheers,
    Global
     

    Attached Files:

  9. Global2004

    Global2004 Private First Class

    One additional note Chaslang. After submitting my last post I restarted my computer by turning off the computer at the tower. When the computer rebooted I noticed my HP Director Icon (for my scanner) had changed to the same icon as SpywareBlaster.

    I also took note of the icons in the bottom right had corner of my screen.
    ATI, Skype, QuickTime, ZoneAlarm, IObit, AVG, Sound Max, Local Area Connection, Volume, Safely Remove Hardware, DVD43 and ATI.

    I selected restart and some icons closed.
    ATI, QuickTime, AVG, SoundMax, DVD43, ATI

    I selected restart again-Nothing Happened.
    So I closed Skype in the bottom left.

    I selected restart and nothing happened.
    I closed IObit in the bottom left and tried Restart.

    This time the computer restarted.

    Not sure if this info is of any help to you, but thought you should know.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no idea what this is but I doubt it is malware.


    Not malware! Just known problems with IObit defrag. See: http://www.iobit.com/Forum/viewtopic.php?p=450&sid=1d778187ac2955a2ce1bd20f0ebaae8b

    You may want to consider uninstalling this to resolve all of your shutdown problems. The alternative is that you must always remember to shutdown IObit Smart Defragger before doing anything else to cause a PC shutdown or reboot. It will also make it difficult to remove malware since many things we do like to cause auto reboot.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat this is not malware but a known problem with IOBit

    Not malware! Just sounds like you have something disabled or shutdown in your hardware provisioning.

    Yes! Put copies of these two files into a ZIP file and attach them here.
    Becareful the letter before the second S that looks like a lower case L is actually an uppercase i.

    Ignoring your shutdown/restart problems which are not malware, are you having any malware problems at the current time?
     
    Last edited: Jan 24, 2007
  12. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    It appears there are no Malware problems. Although my pages load very slowly while I'm surfing. Any thoughts or suggestions?

    Could you explain to me what fixME.reg was suppose to do?

    I have attached the Spools zip file with this post.

    Global
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just to be sure, let's check for rootkits! Run the below procedure and attach the requested log.

    Using Sophos Anti-Rootkit

    "QuickTime Task"=- <--- stop quicktime from loading at startup
    "MSConfig"=- <--- stop MSConfig loading at startup to control processes

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
    "bootini"=dword:00000000 <--- part of the settings to make sure you are in Normal Startup mode. You were not based on your log.


    I'm not seeing anything obviously bad about them although two online scanners do question the spooIs.exe file. But 20 others said no problem. Could this have anything to do with Playstation Portable??? Also SpooIs.exe does not even seem to be a valid Win32 application. Please rename SpooIs.exe to SpooIs.xxx. Then after a reboot (which we will do later) let me know if you notice any problems running anything or get any error message that may be related to this application being missing. This could possibly be some kind of ftp server. Not necessarily a valid one! But based on some things I'm seeing they seem to lead towards a Serv-U type application which would be an ftp server.

    Please tell me what version of IObit SmartDefrag you are running.


    If pages are still loading slow, try the below and let me know if it improves anything.

    Run HJT and fix the below lines.
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

    Then exit HJT and reboot. Any improvement.

    Now attach a new HJT log.
     
  14. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    I have run Sophos Anti-Rootkit and attached the requested log.

    We have no Playstation Portable on our system.

    I have renamed SpooIs.exe to SpooIs.xxx

    I will let you know if I notice any problems running anything or getting any error message that may be related to this application being missing. At this point I'm not noticing anything.

    I'm running IObit SmartDefrag Beta 2.01

    I have run HJT and fixed the requested lines. I then exited HJT and rebooted the computer.

    I have attached a new HJT log.

    QuickTime and DVD43 still loaded after rebooting the computer.

    Cheers,
    Global
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Disable the auto defrag feature (or smart defrag. I don't run it so I'm not sure what it is called.

    More than that came back. Windows Defender must be getting in the way. Let's disable it.

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.

    Now repeat the previous HJT fix on any lines that still remain

    Any change!!!!
     
  16. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    I have disabled the auto defrag feature of IObit SmartDefrag.

    I have disabled Windows Defenders Real time protection.

    I have repeated HJT, however no lines remained to be fixed.

    I will attach a HJT log.

    Web pages still load very slowly.

    Cheers,
    Global
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see this!
    O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup

     
  18. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    I opened HJT and fixed the following:

    O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab

    I have also attached a new HJT log.

    We are aware WinVNC is loaded on our computer and it is password protected. My wifes type of work may require her to use this in the near future so we would prefer not to uninstall at this time. Your thoughts?

    We primarily use Firefox to browse the web. Although we do use Explorer the odd rare time.

    After comparing both browsers they appear to load at the same rate. I will take your advice and call our ISP.

    I found that the pages loaded at about the same rate in Safemode.

    When do you suggest we re-enable IObit and Windows Defender?

    ***Here's something odd you might be able to explain to me. When I went into safemode, the logon page came up with Administrator and user named Work. I entered my Administrator password and the desk-top opened. Not all of my icons were on the desktop. Ie: Firefox shortcut was there and Explorer was not.

    I logged off and changed to "Work" user. There all my icons from normal boot mode were. Strange.

    I should also mention that when I'm in either Administrator or Work and go into msconfig and select safeboot, normal or selective boot, I get the dialog box that says:

    An Access Denied error was returned while attempting to change a service. You may need to log on using an Administrator account to make the specific changes.

    I look forward to hearing from you Chaslang.

    Cheers,
    Global
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach it.

    As long as you are the one that installed it and you have it password protect, it's ok!

    Then I would definitely check with your ISP but before doing that, first tell me if you have a router in between your PC and your ISP's connection. Also is it cable or DSL! I hope it is not dial-up.


    I would not enable smartdefrag since it is what is responsible for your inability to reboot. Just use IObit to defrag your harddisk at your own convience. I don't think autodefrag is a good idea to begin with. Windows Defender can be enable after I confirm your log is clean. It may have auto enable after reboot anyway.

    Not odd at all . You did not install and configure everything under the Administrator account. You installed and configure under the Work account. Some programs; however, will install to all accounts when installed or give you the option to decide whether it is a single user install or all user install.


    Disable ZoneAlarm and see if you can run MSconfig.
     
  20. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    My apologies regarding the HJT log. I've attached it now.

    We have a router between our computer and our ISP connection. We have DSL.

    After reboot, Windows Defender Real Time Protection was still disabled.

    I disabled ZoneAlarm and ran msconfig. When I selected the BOOT.INI tab and checked SAFEBOOT then OK, I recieved the same message.

    I have restarted ZoneAlarm.

    Cheers,
    Global
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Power cycle the DSL modem and your router and see if anything changes.

    Okay enable it.

    Then you are doing more than what you are describing. You are tying to disable a service someplace that you should not be disabling (like Vsmon for ZoneAlarm for example).
     
  22. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    Windows Defender Real Time Protecting was re-enabled.

    You'll forgive me Chaslang but what you said in this quote is a bit over my head.

    I called my ISP and they had me goto http://speedtest.telushosting.com/ to run a speed test on my computer. It was called an 8Meg Test to check my Speed Transfer rate. According to them the acceptable rate for a 1.5 Mbits connection, transfer rate : 95 - 195 KB/sec. My system tranfer rate was at 110KB.

    They tweeked things at their end and my transfer rate went up to 170 KB/sec. However my IE pages still loaded very slowly.

    They then had me bypass my D-Link DI-704UP Router and go straight into my computer from the D-Link DSL-300G ADSL Modem. There was some connectivity problems for a few minutes but now the pages are loading much quicker. I'm happy with the speed.

    Does this sound like the router was the problem? Is there anything you can help me with to test to see if the router is shot and if I should get a new one?

    The PC Service that built our computer for us had us run our computer through the D-Link DI-704UP Router as a firewall. Our printer is still hooked into the router and it is working fine. We have no other computers currently in our home that would require to be on a network to access the printer.

    Should I have any concerns not having the router hooked up as an additional firewall? You have seen several of my HJT logs and know that I have ZoneAlarm installed. Is this fine or are there better firewalls out there that I should look at?

    Thanks Chaslang, you have been a world of help so far. My wife and I appreciate all the time and effort you've put in helping us with our issue.

    Cheers,
    Global
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was part of the reason why I was suggesting the power cycle of the router and the modem. Many routers do have various issues working with cable or DSL modems and can sometime cause problems like this. Sometime a firmware upgrade will fixit and other times a new router by a different manufacturer is the solution. This is not a malware problem that we can do anything about in this forum. As I said above, try getting new firmware for your router or try a new router.

    I do recommend the added security of having the router and its hardware firewall installed. And yes you also should have ZoneAlarm (a software firewall). It is just fine and is one that we recommend.

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds