CoolWWWSearch.LoadBat and Family

Discussion in 'Malware Help (A Specialist Will Reply)' started by liverunited8, Feb 3, 2005.

  1. liverunited8

    liverunited8 Private E-2

    Hi all!! Recently, I noticed that my computer started having pop ups. I am running Windows Xp SP 2. initially, the pop up blocker was working fine until i started seeing a few coming up. I downloaded spybot - search and Destroy and scanned my system with it. It constantly found CoolWWWSearch.Loadbat and a whole lot of its other friends all under CoolWWWSearch but spybot could not eradicate it. I did a quick search on google using CoolWWWSearch and found Tinas case. Our case seems the same though my problem has yet to be exploded to that extend. I seriously hope that someone can help me before I have to reformat my computer. Thanks in advance.
     
  2. TheOldThug

    TheOldThug First Sergeant

    Welcome

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)
     
  3. liverunited8

    liverunited8 Private E-2

    I have followed the instructions that were given in that thread. All the detectors did detect spywares. The list included VX2, look2me and quite a few other irritating stuff. The pop ups had this addresses on them: http://69.20.61.245/info@nictechnetworks.com/ad-armorie.htm and http://www.spotresults.com/cgi-bin/search.cgi?keywords=02467d305d08c2e2729e34b55dc280a0 Can someone please help me to get rid of these spywares? Whenever I am connected to the internet, i will receive these pop ups, even when i am playing online games. Please Help me!!
     
  4. TheOldThug

    TheOldThug First Sergeant

    If you still have a problem then do the following:

    Please try to turn OFF any applications that are not needed It makes it much easier to look at the HJT log.
    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT

    Good Luck :)
     
  5. liverunited8

    liverunited8 Private E-2

    Hi everyone! i have finally managed to scan my computer with hijack this. i really hope someone can help me!! Thanks!
     

    Attached Files:

  6. TheOldThug

    TheOldThug First Sergeant

    At the minimum it looks like you have a VX2 infection. i have asked Chaslang to take over this thread. Hopefully he can fit it into his busy schedule, so please be patient.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First Step:

    Please download the following tools and save them where you will be able to find them. I save stuff like this to a C:\downloads\Spyware-Stuff folder and I put each in their own subfolder. It makes it easy to find. Only run what I given your directions for and make sure you download them from the links below:

    HijackThis 1.99.1 <--- you need to get this new version which just came out

    L2MeFix Tool

    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Pocket KillBox


    Second Step:

    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINDOWS\system32\ntsmod.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [ntsmod] C:\WINDOWS\system32\ntsmod.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\ntsmod.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.

    Now reboot in normal mode and continue with the below steps.

    Third Step:
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!


    Fourth Step:

    Extract all the files from the Generic Detection Tool into its own folder.

    Then run find.bat. Post the log it creates back here as an attachment. Make sure you wait long enough for it to complete. A notepad window will popup with a log file in it when done. You will need to post that log later when you come back here.


    Fifth Step:

    Get a new HJT log using version 1.99.1. Now reconnect to the internet and come back here and post as attachments the l2mfix log the find.bat log (normally already named output.txt) and the new HJT log (this will require two posts as only two attachments can be made in a message). Based on those logs, we will determine the next steps. Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  8. liverunited8

    liverunited8 Private E-2

    This is the new Hijack this log. I could not attach this so i copied it.

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Feb 19, 2005
  9. liverunited8

    liverunited8 Private E-2

    this is the output.txt log file.

    Warning! This utility will find legitimate files in addition to malware.
    Do not remove anything unless you are sure you know what you're doing.

    Find.bat is running from: C:\Spyware Detector\NO2\finditnt2000xp\Find It NT-2K-XP

    ------- System Files in System32 Directory -------

    Volume in drive C has no label.
    Volume Serial Number is C0E6-4C0A

    Directory of C:\WINDOWS\System32

    02/18/2005 08:13 PM 222,923 bzhserv.dll
    02/18/2005 08:12 PM 224,811 u6ru0g99e6.dll
    02/18/2005 08:08 PM 224,811 idrtprio.dll
    02/18/2005 08:05 PM 222,923 n86qlij518o.dll
    02/18/2005 09:21 AM 222,923 kpdsmsno.dll
    02/16/2005 05:37 PM <DIR> dllcache
    02/15/2005 09:07 PM 224,111 i860lijm18oa.dll
    02/15/2005 10:11 AM 225,091 l8j8li1u18.dll
    02/14/2005 01:18 PM 226,134 l88m0il1e8q.dll
    02/14/2005 10:41 AM 224,111 gpjsl3171.dll
    02/12/2005 11:07 PM 224,111 lt2027fmg.dll
    02/10/2005 11:38 PM 224,111 m0640ajqedoe0.dll
    02/05/2005 12:19 PM 225,168 enpul1791.dll
    08/20/2004 01:09 AM <DIR> tewinext
    06/14/2004 12:55 AM 848 KGyGaAvL.sys
    06/01/2004 01:05 AM <DIR> Microsoft
    12/26/2003 05:49 PM 204,800 archlib.dll
    09/30/1999 07:21 PM 166,672 mstext35.dll
    09/28/1999 09:42 PM 1,050,896 msjet35.dll
    09/09/1999 10:06 PM 252,688 msexcl35.dll
    09/09/1999 10:06 PM 168,720 msltus35.dll
    08/25/1999 02:57 PM 415,504 msrepl35.dll
    06/10/1999 09:34 AM 24,848 msjter35.dll
    06/10/1999 09:34 AM 123,664 msjint35.dll
    06/07/1999 06:59 PM 250,128 mspdox35.dll
    04/25/1999 05:00 PM 287,504 Msxbse35.dll
    04/25/1999 05:00 PM 368,912 Vbar332.dll
    04/25/1999 05:00 PM 252,176 Msrd2x35.dll
    25 File(s) 6,258,588 bytes
    3 Dir(s) 5,092,913,152 bytes free

    ------- Hidden Files in System32 Directory -------

    Volume in drive C has no label.
    Volume Serial Number is C0E6-4C0A

    Directory of C:\WINDOWS\System32

    02/16/2005 05:37 PM <DIR> dllcache
    01/21/2005 05:14 PM 488 WindowsLogon.manifest
    01/21/2005 05:14 PM 488 logonui.exe.manifest
    01/21/2005 05:14 PM 749 cdplayer.exe.manifest
    01/21/2005 05:14 PM 749 wuaucpl.cpl.manifest
    01/21/2005 05:14 PM 749 ncpa.cpl.manifest
    01/21/2005 05:14 PM 749 nwc.cpl.manifest
    01/21/2005 05:14 PM 749 sapi.cpl.manifest
    12/08/2004 09:11 PM 10,828 WeHelp.GID
    08/20/2004 01:09 AM <DIR> tewinext
    06/14/2004 12:55 AM 848 KGyGaAvL.sys
    06/01/2004 02:02 AM 8,628 amecsa.GID
    10 File(s) 25,025 bytes
    2 Dir(s) 5,092,925,440 bytes free

    ------------ Files Named "Guard" ---------------

    Volume in drive C has no label.
    Volume Serial Number is C0E6-4C0A

    Directory of C:\WINDOWS\System32


    ------ Temp Files in System32 Directory ------

    Volume in drive C has no label.
    Volume Serial Number is C0E6-4C0A

    Directory of C:\WINDOWS\System32


    ------------------ User Agent ----------------

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{E13FF810-C31B-4226-A13B-19A5365FE8D1}"=""


    ------------- Keys Under Notify -------------

    REGEDIT4

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
    "Asynchronous"=dword:00000000
    "DllName"=""
    "Impersonate"=dword:00000000
    "Logon"="WinLogon"
    "Logoff"="WinLogoff"
    "Shutdown"="WinShutdown"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
    "Asynchronous"=dword:00000000
    "DllName"="C:\\WINDOWS\\system32\\n86qlij518o.dll"
    "Impersonate"=dword:00000000
    "Logon"="WinLogon"
    "Logoff"="WinLogoff"
    "Shutdown"="WinShutdown"


    ------------- Locate.com Results -------------

    C:\WINDOWS\SYSTEM32\
    bzhserv.dll Fri Feb 18 2005 8:13:38p ..S.R 222,923 217.70 K
    cdplay~1.man Fri Jan 21 2005 5:14:10p A..HR 749 0.73 K
    enpul1~1.dll Sat Feb 5 2005 12:19:26p ..S.R 225,168 219.89 K
    gpjsl3~1.dll Mon Feb 14 2005 10:41:16a ..S.R 224,111 218.86 K
    i860li~1.dll Tue Feb 15 2005 9:07:06p ..S.R 224,111 218.86 K
    idrtprio.dll Fri Feb 18 2005 8:08:08p ..S.R 224,811 219.54 K
    kpdsmsno.dll Fri Feb 18 2005 9:21:28a ..S.R 222,923 217.70 K
    l88m0i~1.dll Mon Feb 14 2005 1:18:22p ..S.R 226,134 220.83 K
    l8j8li~1.dll Tue Feb 15 2005 10:11:26a ..S.R 225,091 219.81 K
    logonu~1.man Fri Jan 21 2005 5:14:16p A..HR 488 0.48 K
    lt2027~1.dll Sat Feb 12 2005 11:07:36p ..S.R 224,111 218.86 K
    m0640a~1.dll Thu Feb 10 2005 11:38:12p ..S.R 224,111 218.86 K
    n86qli~1.dll Fri Feb 18 2005 8:05:28p ..S.R 222,923 217.70 K
    ncpacp~1.man Fri Jan 21 2005 5:14:10p A..HR 749 0.73 K
    nwccpl~1.man Fri Jan 21 2005 5:14:10p A..HR 749 0.73 K
    sapicp~1.man Fri Jan 21 2005 5:14:10p A..HR 749 0.73 K
    u6ru0g~1.dll Fri Feb 18 2005 8:12:08p ..S.R 224,811 219.54 K
    wehelp.gid Wed Dec 8 2004 9:11:04p A..H. 10,828 10.57 K
    window~1.man Fri Jan 21 2005 5:14:16p A..HR 488 0.48 K
    wuaucp~1.man Fri Jan 21 2005 5:14:10p A..HR 749 0.73 K

    20 items found: 20 files, 0 directories.
    Total of file sizes: 2,706,777 bytes 2.58 M

    -------- Strings.exe Qoologic Results --------


    --------- Strings.exe Aspack Results ---------

    C:\WINDOWS\system32\ha1.ax: .aspack
    C:\WINDOWS\system32\ha2.ax: .aspack

    -------------- HKLM Run Key ----------------

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AME_CSA"="rundll32 amecsa.cpl,RUN_DLL"
    "CTStartup"="C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE /run"
    "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
    "SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
    "razertra"="C:\\Program Files\\Razer\\razertra.exe"
    "Jet Detection"="C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe"
    "QuickTime Task"="\"D:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
    @=""
    "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
    "WINDVDPatch"="CTHELPER.EXE"
    "gcasServ"="\"D:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
    "Installed"="1"


    
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach logs like these from now on. If you have a problem attaching, you probably just need to rename the file. Use a naming convention for each subsequent upload like hjt1.log, hjt2.log, etc That usually works well.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this ProxyServer line something you set and need:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 213.56.68.29:80

    You appear to be missing a bunch of Service that you may need. Do you recognize all of these and are you having any problems with the what they are related to:

    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
    O23 - Service: CPU_UNIT - Unknown owner - %FinsServer%\bin\CpuUnit.exe (file missing)
    O23 - Service: ETN_UNIT - Unknown owner - %FinsServer%\bin\EthernetUnit.exe (file missing)
    O23 - Service: FgwSocketProxy - Unknown owner - %FinsServer%\bin\FgwSocketProxy.exe (file missing)
    O23 - Service: MapAgent - Unknown owner - %FinsServer%\bin\MapAgent.exe (file missing)
    O23 - Service: NameSpaceServer - Unknown owner - %FinsServer%\bin\NsServer.exe (file missing)
    O23 - Service: SerialUnit - Unknown owner - %FinsServer%\bin\SeriUnit.exe (file missing)
     
  12. liverunited8

    liverunited8 Private E-2

    Regarding the proxy server, I am using a cable modem and has no configurations dealing with the proxy. unfortunately, i do not know if the modem did something related to the proxy. I guess we can just delete it and i can just install back the modem if anything goes wrong.

    I have never seen these services before. Have you seen them in your other cases before? I know one the fgwsocketproxy but i am not using it so i guess we can delete it.

    I guess we can delete all of them, unless stated otherwise by you..
     
  13. liverunited8

    liverunited8 Private E-2

    By the way, i also experience periodical winlogon illegal operation. Its prompts me to ignore the problem or debug it. either way my computer will just restart by itself illegally. Could this be related to spyware/malware.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HijackThis fix the R1 line with the ProxyServer and let's see what happens. Make sure you can still connect ok. We can always have HJT restore it from backup.

    I'm going to check some of those service out and I will let you know. The first one is for your Brother Printer. Do not fix these lines!!!! I think HJT is falsely reporting the files as missing when they are not. But there could be some other issue with the services because the name of the services are all coming up as - unknown -
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are some big issues we need to work thru before we worry about this. One step at a time. I'll be posting some more things to do soon.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the following tools and save them where you will be able to find them. I save stuff like this to a C:\downloads\Spyware-Stuff folder and I put each in their own subfolder. It makes it easy to find. Make sure you download them from the links below:

    L2MeFix Tool
    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126
    Pocket KillBox

    Only run what I ask you to run!

    First Step:

    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing


    Second Step:

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log. Save this log to post later.

    Third Step:

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log later when the remaining steps are completed.

    Fourth Step:

    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment (do it later when we reconnect).

    Fifth Step:

    Reconnect to the internet and come back here and post both logs from the L2Mfix. And the Generic Detection Tool's find.bat log (normal named output.txt).

    Based on those logs, we will determine the next steps.

    Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  17. liverunited8

    liverunited8 Private E-2

    This line has been changed:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 213.56.68.29:80

    to

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711

    I know that 127.0.0.1 is my own add. So what do I do with this line?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Fix it! And continue with my other steps!
     
  19. liverunited8

    liverunited8 Private E-2

    I cannot open the manage attachments. Whenever i click on it, a blank window just appears and does not seem to be loading. I cannot upload all the logs for you now.. What should I do?
     
  20. liverunited8

    liverunited8 Private E-2

    This is the l2mfix.bat log file. report2.log
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you said Manage Attachments does not work! I guess it is okay!

    I'll be waiting for the other attachements!

    But you are not following directions:

     
  22. liverunited8

    liverunited8 Private E-2

    This is the findit log file(output) and first l2mfix log file(report3)
     

    Attached Files:

  23. liverunited8

    liverunited8 Private E-2

    This is the second l2mfix log file.(log.txt)
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HJT and if you see any of the below fix them while no browsers are open:
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch

    Then reboot an post a new HJT log. How are things running?
     
  25. liverunited8

    liverunited8 Private E-2

    Hi! this is the new HJT log file. before I rebooted, I played counterstrike online. Surprisingly, I did not experience any pop ups unlike last times, whenever I play half way, pop ups will occur and i have to alt + tab back to CS. Just curious, what is my status now and what about the other applications that you told me to download?
     

    Attached Files:

  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Since Chas! Is not here at the moment, I viewed your HJT log and there is a few entries that needs to be fixed.

    Go ahead and do another scan with HijackThis and Check the Boxes for the following:

    Again, make sure All Browser Windows are Closed when you Click FIX.


    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)

    O23 - Service: CPU_UNIT - Unknown owner - %FinsServer%\bin\CpuUnit.exe (file missing)

    O23 - Service: ETN_UNIT - Unknown owner - %FinsServer%\bin\EthernetUnit.exe (file missing)

    O23 - Service: FgwSocketProxy - Unknown owner - %FinsServer%\bin\FgwSocketProxy.exe (file missing)

    O23 - Service: MapAgent - Unknown owner - %FinsServer%\bin\MapAgent.exe (file missing)

    O23 - Service: NameSpaceServer - Unknown owner - %FinsServer%\bin\NsServer.exe (file missing)

    O23 - Service: SerialUnit - Unknown owner - %FinsServer%\bin\SeriUnit.exe (file missing)



    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    After you have completed these few task, reboot and post a fresh HJT log.

    Thanks Bj:)
     
  27. liverunited8

    liverunited8 Private E-2

    This is the new HJT log file.
     

    Attached Files:

  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Lets try this again, Have HJT fix this entry. Be sure to close all open browsers before fixing anything.


    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)


    After you remove this entry, reboot and post new HJT. How are things running? Are you still experiencing any problems?
     
  29. liverunited8

    liverunited8 Private E-2

    Hi.. Here is the new one.its much better now... so far hasn't seenm one yet...
     

    Attached Files:

  30. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    For some reason this entry keeps coming back. Do you know what the Brother Popup Suspend Service is at all?

    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
     
  31. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Im assuming that the Brother Popup Suspend Service is related to the Brother printer, correct? :confused:
     
  32. liverunited8

    liverunited8 Private E-2

    Yes... I think so.. I do have a brother printer connected... I dun think its that important anyway...
     
  33. liverunited8

    liverunited8 Private E-2

    Now the pop ups has stopped appearing... so does that mean thats it?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Earlier in reference to some of the services that said file missing you said
    So what was this for. I'm assuming the rest were for it too.

    I don't think any of these really have the files missing. That is why I did not have HJT fix them to begin with. I have a feeling there could be a bug in HJT when for some reason it does not identify a service owner and it says - Unknown owner - It then goes on to report the file as missing which I now in most if not all cases is not true.
     
  35. liverunited8

    liverunited8 Private E-2

    I am still now sure what this is for... but in any case, i had HJT fixed all up and I haven't had any errors so far... I have rebooted 2 or 3 times already and played numerous online games and no pop ups. So I guess thats it right ?? Thank you so much for all the help!!! Companies will need people like you to help!!!
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds