Can't complete online scans - Laptop

Discussion in 'Malware Help (A Specialist Will Reply)' started by chadwilson7, Aug 24, 2006.

  1. chadwilson7

    chadwilson7 Private E-2

    This is not the same system as any of my other posts

    I went through all the read me steps a couple of weeks ago and everything checked out. It did find some things at that time but fixed them all.

    Yesterday I couldn't get online at all so I went back through all the steps again. Now Ican access select sites but couldn't complete either online scan.

    I'm attaching the other logs.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not disable MSconfig as requested in step 7 of the READ ME?

    Can you tell me what the below is for?
    C:\Program Files\Config2500\Utility\Config2500.exe

    Are your copies of Ewido & Spyware Doctor free versions or paid versions? If free, please uninstall them now.

    Did you setup the below proxy server settings?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 219.93.174.102:554



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab

    After clicking Fix, exit HJT.:
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Aug 25, 2006
  3. chadwilson7

    chadwilson7 Private E-2

    ****Can you tell me what the below is for?
    C:\Program Files\Config2500\Utility\Config2500.exe

    This is a wireless LAN config utility that came bundled with my WLAN drivers. I uninstalled it and my WLAN quit working so I downloaded and reinstalled the drivers and it's back.


    ****Are your copies of Ewido & Spyware Doctor free versions or paid versions? If free, please uninstall them now.

    gone



    ****Did you setup the below proxy server settings?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 219.93.174.102:554

    No

    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program
    Files\Messenger\msmsgs.exe" /background

    ... I couldn't find these two.

    Things still seem to be the same. Browsing is slow and I still can't connect to many sites (such as Yahoo Mail)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure if you have a DSL modem or a cable modem, but here is what I want you to do. Power off your modem for a minute. Then turn it back on. Then power cycle your router too. Any change?

    As far as browsing being slow, shut the below off! You are running it at startup. That means you could have hundreds of people connecting to you and downloading at all times.
    C:\Program Files\BitTorrent\bittorrent.exe

    You can stop the above from loading and also fix that unknown Proxy Server by having HJT fix the below lines:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 219.93.174.102:554
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
     
    Last edited: Aug 26, 2006
  5. chadwilson7

    chadwilson7 Private E-2

    This one is a laptop and I normally use it with a wireless connection(dial up @ home).

    I had hjt fix those two lines and that seemed to do the trick. I guess it was the proxy.

    Does HJT primarily deal with startup items or other things too?

    Thanks for your help!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It deals with many things but is not a malware scanning tool. You must be careful playing with HJT on your own. You can read more about some of the other areas of the registry it reports info on in the below link. Just remember one thing, HJT only shows what is in various registry keys but that does not mean they are bad nor does it mean they are good. See this:

    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. chadwilson7

    chadwilson7 Private E-2

    I'll check that out.

    I'll create a system restore point but first I need to make sure there's not anything else I can check. I'm having some trouble again not being able to get through to a few sites.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What sites?

    Has anything changed in your HJT log? Are you blocking the site in your firewall or in an antispyware program? Is it in your Restricted Zone or IE?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds