Directions followed ... Please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by sgood, Feb 13, 2007.

  1. sgood

    sgood Private E-2

    Hello again ... I followed the directions from the link Halo sent ... log files are attached. Please help if you can -- my son needs this computer to do school work and it is running EXTREMELY slow.

    While running the BitDefender ... the scan was running for about 14 hours -- it said it had 10 minutes left and the computer rebooted itself. The log at the time said it found 5 viruses, 30 infected files and cleaned only 29 of them. I do not have that log since the computer rebooted. I did run BitDefender again and that log is attached.
     

    Attached Files:

  2. sgood

    sgood Private E-2

    Additional logs attached ...
     

    Attached Files:

  3. sgood

    sgood Private E-2

    One more attachment ...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Were you unable to run Counterspy?

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please use add/remove programs in the control panel to uninstall:

    Viewpoint Media Player

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://66.103.153.158
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - Global Startup: Forget Me Not.lnk = ?
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab

    After clicking Fix, exit HJT.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\wsys.dll

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.


    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  5. sgood

    sgood Private E-2

    Hi Tim .... Thank you for your help

    I did as instructed and attached the logs. I did not receive the error you mentionedabout Killbox ... but I did receive an error message with HJT. I ran it, checked the boxes you indicated, then clicked fix -- it started to run, came up with the error, "Unexpected error occurred! Error #52 (Bad file name or number) on Sub GetLongPath(?exe) Please send a report to merijin@spywareinfo.com, mentioning what you were doing and what version of Windows you have. Message has been copied to your clipboard." Then HJT continued to run.

    My computer has improved -- JUST a little .... it is still taking about 25 minutes to boot and usually takes 1-2 minutes for a program to start after you double click it. I know there is a lot running that doesn't need to be running. I also see some things in startup and I don't understand why they're there. I uninstalled AOL a long time ago, yet it still shows in Add/Remove -- click on it and it says there are no versions on my computer -- yet "aol" is all over the place. I know that isn't all of the problem -- the computer was running okay not too long ago.

    If you have any other suggestions, they would be greatly appreciated!!! Thank you ....
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can do a search for AOL and remove all that it finds.

    Please uninstall thru add/remove programs in the control panel:
    Google Web Accelerator

    If this folder exists, delete it:
    C:\Documents and Settings\Owner\Application Data\Viewpoint

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    Delete on Reboot
    then Click on the All Files button.
    Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\main.sys
    C:\WINDOWS\system32\wsys.dll

    Return to Killbox, go to the File menu, and choose Paste from Clipboard. Choose the box for unregister .dll's before deleting. Then click on processes and see if winlogon.exe and main.sys is showing. If it is, put a check mark next to it and click End Task.

    Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)

    After clicking Fix, exit HJT.

    Please download HOSTER and then follow the below steps.
    • Unzip HOSTER to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program.
    NOTE: Running this utility will reset your HOSTS file to it's original state!


    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  7. sgood

    sgood Private E-2

    I started a search for AOL and sent some items to the Recycle bin ... some could not be sent since they were "in use".

    I went to uninstall Google Web Accelerator thru add/remove, but it did not show there.

    I did delete the folder "Viewpoint" as instructed.

    I ran the Killbox as instructed and received no errors. It did not show winlogon.exe or main.sys when I clicked on processes.

    When the computer rebooted after Killbox, I had no internet. I restored the aol files I had sent to the recycle bin, but still no internet. I rebooted a few times, attempted reconnecting thru my Linksys monitor, but still no internet.

    I used my TravelDrive along with my work laptop to complete the rest of the instructions. The logs are attached.

    My computer is in sad shape ... it is still taking forever to reboot, taking a long time to start and end programs, and I now have no internet. Please help!!!!
     

    Attached Files:

  8. sgood

    sgood Private E-2

    As far as the internet ...

    I went into the control panel - Admin - Services ... stopped and restarted the DHCP.

    I also went into CMD and did ipconfig/release and ipconfig/renew. With the renew, I was given an error message ... " Unable to contact your DHCP server. Request has timed out." Any suggestions?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you not connection wirelessly? Can you connect wired?
    Have you checked your setting in Port Monster, as they may have been changed?

    Have you tried reinstalling your wireless device and drivers?

    Does this folder exist?
    C:\Documents and Settings\Owner\Application Data\googlewebacchosts
    C:\Program Files\Common Files\AOL
    delete them if found.

    To Reset Web Settings:

    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Report back.
     
  10. sgood

    sgood Private E-2

    The desktop not connecting wirelessly. I am too far from the modem to attempt to connect wired. The laptop I am on now is connected wirelessly.

    I do not know where Port Monster is or where to find it. ?????????

    I have uninstalled and re-installed before, but I do not remember how to do it.

    Both of the folders existed and I deleted both ... after ending process of AOLHostManager.exe (2 of them) in Task Manager.

    I did reset the web settings -- no internet. I rebooted the computer and still no internet. :(

    In ipconfig, I have no DNS suffix .... IP is 169.254.66.68 ... subnet is 255.255.0.0 .... and there is nothing beside Default Gateway.

    The last reboot still took 13 minutes .... besides the no internet, do you have any suggestions from the logs I posted this morning?

    I really do appreciate all of your help!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start / run / type "cmd" without qoutes ....when the command prompt opens, type
    "ipconfig /all" without qoutes.

    Do this on both computers.

    In the meantime, under the wireless properties, is it set to obtain an ip address automatically. You may have to shut down the computer, turn off the router and the modem and restart them in the reverse order.

    Post the results of the ipconfig for both.
     
  12. sgood

    sgood Private E-2

    I am attaching both IP configs ... I haven't shut down the router yet (afraid of totally losing internet on laptop lol) ... but will after I post. If I get internet back, I'll repost immediately the results ... if not, I'll repost on Monday from work.
     

    Attached Files:

  13. sgood

    sgood Private E-2

    I made it back .... on laptop. My desktop still has no internet.

    I shut down desktop, shut down laptop, unplugged router and modem. Waited about 2 minutes, then plugged in modem, then router ... then restarted desktop, then laptop.

    The bad news is still no internet on the desktop ... the good news is it booted in 9 minutes -- boot time is getting less.

    Any suggestions???
     
  14. sgood

    sgood Private E-2

    I missed one of your questions .... Yes, the desktop is set to obtain IP address and DNS automatically.
     
  15. sgood

    sgood Private E-2

    I was/am totally frustrated with my desktop ... it was a choice of throwing it through the window -- or taking it to the modem to see if it would connect wired. I moved the computer -- hooked it up wired ... and still the same thing. I called Comcast, thinking MAYBE they could help. That was a big mistake. I think the computer is in worse shape now than it was before. The person at Comcast knew absolutely nothing and it was obvious she was reading word for word through a manual. When I go into Network Connections now, it says my Wireless is "Not Connected." I am attaching a new file from ipconfig/all. It is a lot different than what I posted before.

    Help!!! Please!!!!
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    On the Ethernet usb connection :
    Ethernet adapter Wireless Network Connection 2:

    Media State . . . . . . . . . . . : Media disconnected
    Description . . . . . . . . . . . : Linksys Wireless-G USB Network Adapt
    er #2

    Input these figures manually:
    IP Address. . . . . . . . . . . ... : 192.168.1.130
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 192.168.1.1
    DHCP Server . . . . . . . . . .. . : 192.168.1.1

    You can delete the connection #3 that they created.

    Then reboot and open a browser and put in this address:
    192.168.1.1 ...you should have a user and password box pop up to access your router.
    Let me know if you do.
     
  17. sgood

    sgood Private E-2

    I went into Network Connections, right clicked on Wireless, scrolled to Internet Protocol, clicked Properties, entered the IP address, Subnet mask and Default gateway as instructed. I did not see a place for DHCP Server, so I entered the 192.168.1.1 in the DNS server.

    I rebooted and pulled up a webpage and entered the 192.168.1.1 and was taken to http://errorpage.comcast.net/?cat=web&con=dc&safe=on&q=errorpage.net

    IPconfig/all does not show IP address as it still says "Media State .... :Media disconnected" I am not sure how to get it to be "Connected".
     
  18. sgood

    sgood Private E-2

    Now I'm even more confused. After I posted last, I went to the Linksys monitor and clicked to connect. It asked if I wanted it to "Obtain IP Address Automatically" and I clicked no. It went back to the info screen and said, "You are connected to the access point, but the Internet cannot be found." BUT .... the little computer icon in the tray shows me as connected with Signal Strength: Excellent. If I try to pull up a webpage, or put the IP address in the address bar, I am still taken to an "errorpage.comcast.net" ?????

    Ipconfig/all now shows the manually entered numbers.

    What do I try next?????
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Compare the settings for your browser between the desktop and the laptop.
    Also see it you can have the linksys do the auto config.
    If you have a firewall turn it off.
    Can you see the laptop in your network?
     
  20. sgood

    sgood Private E-2

    Internet is back up and running ... I am posting from my desktop. :)

    I've attached logs ... is there anything else you see that should be done? The computer is still soooo much slower than it was a week ago.

    You have done so much already to help me .... thank you so much! You truly are a miracle worker in my mind.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall Counterspy.

    Run KillBox again and have it delete this folder, or right click start / explore and scroll to the folder and delete it manually.

    C:\WINDOWS\system32\thxcfg.ini


    What is in your startup files (click start / run / and type msconfig ...go to the last tab and tell me what all is there ...some things you may wish to uncheck to see if your system runs faster.)

    Have you defragged the drive lately?

    PS..good to know you are connected again!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds