Downloading not Allowed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gingerh1, Nov 1, 2004.

  1. gingerh1

    gingerh1 Private E-2

    I don't know what is going on, but since my computer has been acting strange lately...and from what I have read, I probably have spyware or even Trojans in there somewhere so I proceeded to your page for recommendations to clean my computer. Every time I try to download Spybot or Ad-ware, from any web page, it immediately jumps to a blank white page with a little icon in the upper left hand corner with those colored blocks, then does nothing. I was able to download AVG Freeware Virus protection, but not the other two. What could be preventing me from installing those two programs on my computer? Running WIN98 SE Any help would be greatly appreciated!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can do any of the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    Try to do them in the order written. Skip anything you have a problem doing and let me know which you had problems with.

    Have you run a full scan with AVG yet. If not, please do so in safe mode.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. gingerh1

    gingerh1 Private E-2

    O.K. I've printed out the Sticky thread you mentioned. Ran full scan (in normal boot) with AVG, found Trojan Horse Backdoor Agent.2.H which it deleted. Step 1 did not apply as I am running Win98 SE.
    Step 2 - In "run", no file found with the name "services.msc" Since I do encounter the "about:blank" all the time.
    Step 3 - Already have "enabled" viewing hidden files and extensions.
    At this time, restarted computer
    Step 4 - Tried again to download Ad-Ware SE (thru CNet) had the same problem, shows downloading, but program never downloads, continues with the download motion arrow forever and nothing ever happens. If you click on the "your download should start in a few seconds, if not click here" the page turns white with the little icon with the colored boxes.
    What do you think I should do now?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about the Scanning And Cleaning Steps?Are you able to do any of those as indicated (in safe mode where possible)?


    Can you download any of the programs listed?
     
  5. goldfish

    goldfish Lt. Sushi.DC

    What about from MajorGeeks? Lots of mirrors, have a go with them.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks Goldie! I missed the fact that Ginger is not clicking on the links given in the READ ME FIRST to do the downloads. But if this is like similar problems I have seen, it will not matter which site is used.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ginger,

    Step 4 gives you all the links to download files from and they are all from MG's. Please try downloading from our links as the read me indicates.
     
  8. gingerh1

    gingerh1 Private E-2

    After trying to download from other sites last week, I finally found your web page in my search for a download from somewhere, even a "ftp" site with no luck - I've tried everyone of the MG links with the same response. BTW, I rescanned with AVG in Safe Mode, and everything checked out this time...no viruses.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have downloading enabled?

    See Tools, Internet Options, Security, Internet Custom Settings, and look for Downloads
     
  10. gingerh1

    gingerh1 Private E-2

    Actually, that was the first thing I checked last week when I first tried to download Ad-ware and everything is enabled. Also, someone asked if I had tried to download some of the other programs.....yes, and they won't download either.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So right now, the problem is: no matter where you go and no matter what you try to download...you cannot download? Right?


    Do you have a copy of HijackThis on this PC or can you get it there some how?
     
  12. gingerh1

    gingerh1 Private E-2

    Where do you find that program? ----Found it and just downloaded - will unzip and see what it is all about.
     
    Last edited: Nov 1, 2004
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you could not download anything??? Did you download it using a different PC?

    Make sure you have version 1.98.2 and place it into the correct folder as we specify in our HJT tutorial.
     
  14. gingerh1

    gingerh1 Private E-2

    My original post stated that I was unable to download Ad-ware and Spybot, but that I ws able to download AVG. Then after your post of steps, I tried scanning the system in "safe-mode" with AVG and found 1 Trojan that was deleted. Even now, I am unable to download Ad-ware, Spybot nor any of the others recommended in your steps off of MG's links. It seems to pick and choose what I can and cannot download. What up with that. Anyway, attached is the HijackThis v1.98 log I just ran, maybe you can look at that and see if there is anything listed that prevents me from downloading those programs.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please save the log files as a .txt file from now on. You must just change the save as type in HijackThis.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have several issues in your log I'm working on including Gain Bundle crap. You need to stay away from programs like Kazaa.

    Look in Add/Remove programs for Gain, CME, BonzaiBuddy, PrecisionTime, and Date Manager and uninstall them if found.

    Also any WildTangent stuff should be uninstalled.

    Do this and post your results while I work on your log.

    I will leave in lines (in my fix procedure) relate to the above crap assuming they are not uninstalled.
     
  17. gingerh1

    gingerh1 Private E-2

    In Add/Remove I was able to remove PrecisionTime and Date Manager. There was a listing for "Wild Tangent Web Driver" but everytime I clicked on the name it would pop backup to the top of the list and do nothing. Tried it several times with the same result. I know I have tons of trouble with the GAIN crap, I've tried several times to search out its many embedded programs, but just couldn't find them all, that goes for Kazaa too. There is nothing listed in the Add/Remove for GAIN, CME or BonzaiBuddy. A scan I did a while back through a free service, popped up with registry issues on Gator, InetSpeak, GAIN and Wurldmedia embedded in the registry but the registry is so complex, I didn't want to get into that with my limited knowledge.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay ignore anything I have below that is already fixed.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\WINDOWSIE.DLL
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\SYSTEM\WWJIRYJ.DLL
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\SYSTEM\MOB030612.DLL
    then click OK. If a dialog box confirming this action appears, click OK.

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    PRECISIONTIME.EXE
    DATEMANAGER.EXE
    MOSTAT.EXE

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: WindowsIE.clsIS - {2E12B523-3D4C-4FAC-9B04-0376A8F5E879} - C:\WINDOWS\WINDOWSIE.DLL
    O2 - BHO: TChkBHO Class - {9B01F341-A326-11D7-873C-00E02950AB65} - C:\WINDOWS\SYSTEM\WWJIRYJ.DLL
    O2 - BHO: IEHlprObj Class - {1BAB1320-B42E-11D6-873C-00E02950AB65} - C:\WINDOWS\SYSTEM\MOB030612.DLL
    O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
    O4 - Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
    O4 - Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O4 - Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://a1440.g.akamaitech.net/7/1440/291/02000089/central1.clevercontent.com/02000089/cccabs/CleverContent.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://tab.webex.com/client/latest/training/ieatgpc.cab
    O16 - DPF: {8A8F3D75-6564-4599-A7DC-313B43A89E1D} - http://www.kazaa.net.cn/digital/AdInstaller.ocx

    Boot into safe mode and use Windows Explorer to delete (if they exist):
    C:\PROGRAM FILES\PRECISIONTIME <--- the whole directory
    C:\PROGRAM FILES\DATE MANAGER <--- the whole directory
    C:\PROGRAM FILES\COMMON FILES\CMEII <--- the whole directory
    C:\Program Files\Common Files\GMT <--- the whole directory
    C:\PROGRAM FILES\WILDTANGENT <--- the whole directory
    C:\Program Files\AWS <--- the whole directory
    C:\WINDOWS\SYSTEM\MOSTAT.EXE
    C:\WINDOWS\WINDOWSIE.DLL
    C:\WINDOWS\SYSTEM\WWJIRYJ.DLL
    C:\WINDOWS\SYSTEM\MOB030612.DLL

    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  19. gingerh1

    gingerh1 Private E-2

    O.K. that's done - see what you think.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Only one line remains to be fix with HJT (make sure not browsers are open when fixing):
    O2 - BHO: (no name) - {2E12B523-3D4C-4FAC-9B04-0376A8F5E879} - (no file)


    How are things working now? Can you now download and run the tools in the READ ME?
     
  21. gingerh1

    gingerh1 Private E-2

    Fixed that last line through HJT - still cannot download ad-aware from MG site. Another person in the office has it loaded on her computer, so I decided to make a bold decision and emailed all the files from her cmptr to mine and set up the directories exactly as they are on her computer, also made sure all of the files were in the right folders. Opened the program, but I get an alert message "error while loading the Ad-aware reference file". The program comes up fine, but still indicates, "reference file is not loaded or invalid" with a "Warning, file not found or corrupted". When you try to download the updated reference file, it stops at 5% on the status bar and says it is finished. It will scan just fine, but without current updates, I would think it is useless.

    Let me ask another few questions, why is the default start page in HJT "about:blank"? Doesn't that start pop-ups? Also, the information you post about disabling System Restore, that doesn't apply to people running WIN98 SE...right?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot email (same as a copy) the files from Ad-Aware from one PC to the other. It must be installed. You should have tried emailing the Ad-Aware SE installation file from the other PC to you. Then try to install it.

    Your default page was not about blank. It was
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.bellsouth.net/

    Are you saying your log has now changed since the last one? If so, reboot your PC and immediately after reboot and before doing anything else, get a new HJT log and post it here.

    You are correct about System Restore. It does not apply to Win98SE.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download ProcessExplorer from: http://www.sysinternals.com/files/procexp9x.zip
    Unzip it to a folder (create one for it. I suggest C:\SysInternals). It does not require an install. Now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can show and kill things that Task Manager cannot.
     
  24. gingerh1

    gingerh1 Private E-2

    I didn't mean to confuse things, I guess I didn't explain well enough. What I meant was in HJT there is a box on the right under "other stuff" where you can click on Config. When you do this another screen comes up, Configuration - Main, there are several lines: Default Start Page, Default Search Page, Default Search Assistant & Deafult Search Customize. I just noticed on the first line the "Default Start Page" has listed "about:blank". This threw me for a loop and wondered why it would say that, it hasn't redirected or changed anything, was just wondering???

    How would I locate the Ad-aware installation file on her computer?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! That's not a problem. That is not what you have on you system. It is what HijackThis will set things to when fixing unwanted pages. It has no idea what your start page should be so about:blank is the standard default. The other three items for searches are Microsoft defaults. You can change the Default start here to what you want and HJT will use it any time it has to reset those items.

    You would have to determine where she downloads files to and look there or do a search on the PC using Windows search. Look for aawsepersonal.exe . This is asuming she even has it. Otherwise you would have to download it again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds