Done everything in the read me first..

Discussion in 'Malware Help (A Specialist Will Reply)' started by shonuff5, Dec 26, 2005.

  1. shonuff5

    shonuff5 Private E-2

    except the spybot. Spybot reboots my computer everytime i try to run it, in safe mode, and in normal mode. The problem my computer is having is internet explorer just closes itself out, or my computer just reboots itself. Thanks for all help in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete step 6 of the READ & RUN ME (if possible) and then step 7.
     
  3. shonuff5

    shonuff5 Private E-2

    Ok, the online virus scans keeps rebooting my computer also, so I am not able to get the logs, but i do have the HJT log. Thank you.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The link for HijackThis indicates we need logs from normal boot mode.
    Using logs from safe mode can be ineffective.

    You also show part of Symantec Antivirus still running and you have TrendMicro. Double check to make sure all of Symantec AV is uninstalled. We may need to remove this manually. Also answer the below questions:
    1) What are you using the below for:
    O23 - Service: FireDaemon Service: winsecure (winsecure) - Sublime Solutions Pty Ltd - C:\WINDOWS\security\FireDaemon.exe

    2) Do you recognize the below:
    O18 - Protocol: bt2 - {1730B77B-F429-498F-9B15-4514D83C8294} - C:\PROGRA~1\BT2Net\BT2PLU~1.DLL (file missing)
    O18 - Filter: application/x-bt2 - {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} - C:\PROGRA~1\BT2Net\BT2PLU~1.DLL
     
    Last edited: Dec 26, 2005
  5. shonuff5

    shonuff5 Private E-2

    I do not know what the files below are, but i was able to run bitdefender in normal mode, and i dleted the part of norton anti (i think) that remained on the computer.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you should empty your XoftSpy and TrendMicro quarantine folders.

    Are you sure that you do not know what the BT2Net stuff is? It may be some kind of P2P file downloading tool. I'm including it in the stuff below to fix but if you know that it is okay then just skip steps related to it. Look in Add/Remove programs and uninstall BT2Net if found.

    And a new question do you know what the below 3 lines are for. mscoree.dll can be valid if it is a Microsoft file (it would be for Microsoft .NET Runtime Execution Engine) but the way it shows in your log it does not appear to be for Microsoft.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to FireDaemon Service: winsecure (or if not found look for winsecure) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for the below service:
    Symantec Network Drivers Service (if not found use, the short name: SNDSrvc)

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    FireDaemon Service: winsecure

    If that does not work try entering the short name: winsecure

    Now repeat the above step with HJT for the below service:
    Symantec Network Drivers Service (if not found use, the short name: SNDSrvc)


    Now exit HJT and but do not reboot if it tells you it is necessary.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes (these may already be stopped but we need to check):
    C:\WINDOWS\security\FireDaemon.exe
    C:\WINDOWS\security\winsecure.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    F2 - REG:system.ini: Shell=
    O2 - BHO: MySafe BHO - {856DD04C-56EA-48FF-95FB-B2367FB39AEB} - blank (file missing)
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab
    O18 - Protocol: bt2 - {1730B77B-F429-498F-9B15-4514D83C8294} - C:\PROGRA~1\BT2Net\BT2PLU~1.DLL (file missing)
    O18 - Filter: application/x-bt2 - {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} - C:\PROGRA~1\BT2Net\BT2PLU~1.DLL
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: FireDaemon Service: winsecure (winsecure) - Sublime Solutions Pty Ltd - C:\WINDOWS\security\FireDaemon.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Common Files\Symantec Shared <--- the whole folder
    C:\Program Files\BT2Net <--- the whole folder
    C:\WINDOWS\security\FireDaemon.exe
    C:\WINDOWS\security\winsecure.exe
    C:\WINDOWS\security\logs\backup <-- delete all files in this folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. shonuff5

    shonuff5 Private E-2

    When i tried to delete the FireDaemon Service: winsecure, it said windows cannot delete it because the system needed it, and the folder C:\program files\BT2Net, I couldn't find.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like it fixed it anyway. Just double check to make sure all the files for it are gone.

    I forgot to post the rest of my question last time. Here is the full question and lines that go with it.

    And a new question do you know what the below 3 lines are for. mscoree.dll can be valid if it is a Microsoft file (it would be for Microsoft .NET Runtime Execution Engine) but the way it shows in your log it does not appear to be for Microsoft.
    O2 - BHO: Trixie.Bho - {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} - mscoree.dll (file missing)
    l/AcroIEAppend.html
    O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL
    O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL

    Do you know what this maybe? What is Trixie?
     
  9. shonuff5

    shonuff5 Private E-2

    Trixie is for the windows validation. Don't know what the mscoree.dll is.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What Windows Validation? This is not part of the Genuine Windows validation process and mscoree.dll that your system is loading is being used while running this BHO. What are you using it for? Is the a legal copy of Windows?

    Copies of Windows that have been validated will have lines like below in a HijackThis log:


    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
     
  11. shonuff5

    shonuff5 Private E-2

    Trixie is just a script that by passes the validation process, but if it's causing me a problem, I have no problem deleting it.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you mean bypasses as in illegal? If so, then yes you should remove it.
     
  13. shonuff5

    shonuff5 Private E-2

    I have removed trixie, my computer still reboots sometimes. Did you see anything else wrong?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not based on your HJT log. There are other scans you could run to see if anything else is hiding in your PC. You could run: Running Ewido Security Suite and post the log. You could also retry the online scans now but if your computer reboots itself frequently and in short time frames, they will probably not complete. It is possible that your problems are hardware or software related. Perhaps a memory related issue or possibly overheating. You may need to work this in the Hardware or Software Forum if Ewido does not find anything.

    You could also try running sfc /scannow from a command prompt window but this will possibly require a Windows XP SP2 CD if any files are found to be missing.
     
  15. shonuff5

    shonuff5 Private E-2

    Did you have a chance to check out the Bitdefende log i posted? I was able to run the BitDefender in normal mode, and it said i had 4 viruses, i think.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to the non-text log posted in message # 5?

    We already fixed any problems in steps I gave you in message 6.
     
  17. shonuff5

    shonuff5 Private E-2

    Here is the scan report from Ewido.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that fixed a few more things but I doubt it changed anything related to your reboots. Did it?

    Did you run sfc /scannow yet?

    There is plenty of info for sfc available on the web. i.e., http://www.updatexp.com/scannow-sfc.html
     
    Last edited: Dec 29, 2005
  19. shonuff5

    shonuff5 Private E-2

    No, what is sfc/snannow? The reboot don't happen alot, but seem to happen when i'm using internet explorer, so i have been using firefox instead.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I posted this in message # 14.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds