first timer

Discussion in 'Malware Help (A Specialist Will Reply)' started by gracie312, May 12, 2005.

  1. gracie312

    gracie312 Private First Class

    Hi, I was referred to this site by my brother, a major computer geek. I've been having problems with browser hijackers, spyware, adware, etc. I read a few posts and used Hijack This first. Still having problems, I read on and used the one with all the downloads. I followed the instructions exactly and am still having problems. My browser home page keeps changing, I'm having trouble logging into Hotmail, and there are disgusting links in my favorites folder. I keep removing all this stuff with Spybot S&D and Adaware, but they keep coming back! Also there is an error message on my desktop that reads exactly as follows... "Security Warning, A fatal error in IE has occured at 0028:COO11E36 in VXDVMM (01). Error was caused by Trojan-Spy.HTML.Smitfraud.C, *System can not funtion in normal mode. Please check your security settings. *Scan your PC with any available anti-virus/spyware remover programs to fix the problem." This message has been on my desktop for weeks. I never had these problems until HP tech support crashed my hard drive and I had to send the entire PC to them in California to be repaired. The trouble started shortly after I got it back from them. I have tried everything I know to fix this. Can anyone help me? ................Chris
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. gracie312

    gracie312 Private First Class

    Don't mean to sound dumb but exactly where should I run HijackThis from? I just want to be sure before I do it. Better safe than sorry.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Gracie,

    If you are still not sure what is meant, after you unzip hijackthis.exe from the downloaded file (named HijackThis.zip) and you put it in a folder that you need to create call C:\Program Files\HJT, you should now navigate to that folder using Windows Explorer and double click on the hijackthis.exe file. If desired you can make a shortcut to that file on your Desktop, but the Desktop shortcut must run the file named C:\Program Files\HJT\hijackthis.exe.
     
  5. gracie312

    gracie312 Private First Class

    Chas, here is the log file you requested. Please let me know what to do next. Oh and by the way, I think it is a great thing you are doing with this web site. Thank God for people like you in the world!!!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your OS and IE versions are way out of date and represent a major security risk. After we fix your current problems, you must get updated.


    Please unzip and run the RegSrchTool
    Please make sure that your Anti-Virus app does not have Script Blocking enabled. If so, disable it to allow the tool to run.

    Please enter the following into the Search Box: stsheets

    Please save the results of this search and attach them.


    Then, please unzip and run the Locate.zip Tool
    DoubleClick on the locate.bat to run it and attach that log.

    Post the two logs as attachments!
     
  7. gracie312

    gracie312 Private First Class

    Ok, ran RegSrchTool and all I got was a little message box that said "Search completed in 37 seconds.No instance of "stsheets" was found.

    Then ran Locate.zip Tool by double clicking on lacate.bat. A dos window popped up with the heading that said "C:\WINDOWS\System32\cmd.exe.

    I didn't get any log files to attach. What does this mean? This thing seems to be getting worse everytime I get online.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you are logged in as the same user you posted the log for. You must have stsheets in your registry. It shows in your HijackThis log and that means it is in your registry.
     
  9. gracie312

    gracie312 Private First Class

    I only log in one way, but I'll try again right now.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still get no matches, post a current HijackThis log from right now.
     
  11. gracie312

    gracie312 Private First Class

    Chas, I got a log for regsrchtool but it won't attach and still not getting anything from locate.bat. Still want a hijackthis log?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I do not need a HJT log but I do need the output from regsrch. Post it inline (copy and paste) if necessary.
     
  13. gracie312

    gracie312 Private First Class

    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "stsheets" 5/16/2005 6:35:30 PM

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tapeq]
    "StsPath"="\\??\\C:\\WINDOWS\\stsheets.dat"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tapeq]
    "StsPath"="\\??\\C:\\WINDOWS\\stsheets.dat"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tapeq]
    "StsPath"="\\??\\C:\\WINDOWS\\stsheets.dat"

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Styles]
    "User Stylesheet"="C:\\WINDOWS\\stsheets.dat"

    [HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Styles]
    "User Stylesheet"="C:\\WINDOWS\\stsheets.dat"

    [HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Styles]
    "User Stylesheet"="C:\\WINDOWS\\stsheets.dat"

    [HKEY_USERS\S-1-5-21-1354289438-648664656-3238835185-1003\Software\Microsoft\Internet Explorer\Styles]
    "User Stylesheet"="C:\\WINDOWS\\stsheets.dat"

    [HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Styles]
    "User Stylesheet"="C:\\WINDOWS\\stsheets.dat"
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixsts.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixsts.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.



    Run HijackThis and select the following lines (if they are still there) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O9 - Extra button: Microsoft AntiSpyware helper - {1A0BC945-C3AC-4A53-BA90-AA9D5C02463A} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1A0BC945-C3AC-4A53-BA90-AA9D5C02463A} - (no file) (HKCU)
    O9 - Extra button: Microsoft AntiSpyware helper - {3C2CF138-44E8-46FB-A4CE-2CF4BAD21C9E} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3C2CF138-44E8-46FB-A4CE-2CF4BAD21C9E} - (no file) (HKCU)
    O9 - Extra button: Microsoft AntiSpyware helper - {69127CDB-0905-46E5-B2BC-B8D1870769F3} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {69127CDB-0905-46E5-B2BC-B8D1870769F3} - (no file) (HKCU)
    O9 - Extra button: Microsoft AntiSpyware helper - {A51785CD-F39E-44F3-9033-99F7C33E8682} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A51785CD-F39E-44F3-9033-99F7C33E8682} - (no file) (HKCU)
    O9 - Extra button: Microsoft AntiSpyware helper - {AE37A41A-A088-45C6-A7D8-314F7268BB0D} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AE37A41A-A088-45C6-A7D8-314F7268BB0D} - (no file) (HKCU)
    O9 - Extra button: Microsoft AntiSpyware helper - {EC3B00BD-D4C2-4DF3-9BE7-DF53AAB8172D} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {EC3B00BD-D4C2-4DF3-9BE7-DF53AAB8172D} - (no file) (HKCU)
    O19 - User stylesheet: C:\WINDOWS\stsheets.dat


    Now exit HJT.

    Then reboot and post a new HJT log
     
  15. gracie312

    gracie312 Private First Class

    Chas, Here is latest HJT log. Hope I did this right. What next?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing has changed! Did you merge what I gave you into the registry and then run HJT and fix the lines?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that's not completely true! The O9 lines are gone.
     
  18. gracie312

    gracie312 Private First Class

    Chas, I followed your instructions exactly from the previous post.
    I tried to get online this morning to work on this problem but couldn't get to any websites. So I ran Spybot S&D and then went into Spyware Blaster to Immunize and block websites. Apparently it worked for now, because I was then able to get to this website. I'm going to run Hijackthis again and attach the log. Could you please look at it for me and see if anything has changed?
     
  19. gracie312

    gracie312 Private First Class

    I've attached my latest Hijackthis log file. I saw web-tracer as the first item but didn't want to delete anything until you looked at it. Let me know what to do next. Thanks again for all your help!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will have to repeat what we previously did!


    Please unzip and run the RegSrchTool
    Please make sure that your Anti-Virus app does not have Script Blocking enabled. If so, disable it to allow the tool to run.

    Please enter the following into the Search Box: stsheets

    Please save the results of this search and attach them.

    Do not reboot your PC after posting this because it may change the actual registry key values making my fix not work.
     
  21. gracie312

    gracie312 Private First Class

    Here is the regsrchtool log. I should probably mention that the smitfraud thing is gone off my desktop and now the background is just black. Don't know if this means anything or not but couldn't hurt to mention it. Also, am having a lot of trouble getting online and to this website. This is something new.............Chris
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks to me like you did not successfully merge the registry patch in last time! Please make sure your follow the below steps exactly and when you come back you must provide me feedback on exactly what happens.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixsts.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixsts.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Run HijackThis and select the following lines (if they are still there) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    O19 - User stylesheet: C:\WINDOWS\stsheets.dat



    Now exit HJT.

    Then reboot and post a new HJT log. Also remember to give feedback.
     
  23. gracie312

    gracie312 Private First Class

    OK, here is the log file. I followed your instructions exactly but when I rebooted and ran hijackthis, one of the web tracer lines was still there. So I clicked fix it and rebooted again and ran HJT again and the web tracer line was still there. So I saved and attached the file. When I got back online, instead of opening to global something, it opened to about blank. so something has changed but obviousley not for the better. What next? Thanks again for your help................Chris
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well actually right now it looks a little better. Some of the R0 lines are gone and more importantly the O19 line is gone. This is good. I'm not sure why the R0 line will not stay fixed.

    Try the below!

    - Boot into safe mode with no network support and make sure no browsers are running
    - run HijackThis and fix the below line:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm

    - delete this file if found: C:\WINDOWS\stsheets.dat

    - Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Afterwards reboot to normal mode and start working of the steps in the below link. I hope that you are not on a dialup connection.

    How to Protect yourself from malware!
     
    Last edited: May 23, 2005
  25. gracie312

    gracie312 Private First Class

    I followed insturctions from last post and deleted the ro lines with web tracer in them and 019 was there again so I deleted that also. Reset the web settings and am going to start working on the "protect yourself from malware thing. You didn't say if I should run HJT again and attach a new log or not. Let me know if I need to do that. I'll be online line for a while working on this. Thanks again..........Chris
     
  26. moyupae

    moyupae Private E-2

    Wow. Simply hats off to you, Chas. I cannot believe your patience and persitance with this. You have my vote for honorary geek of the week!

    Rock on!
     
  27. gracie312

    gracie312 Private First Class

    Chas, I went thru the steps for protecting against malware but as I was doing the steps I was having problems with IE going back to the web tracer setting. I reset about 10 times but it won't stay set. I ran HJT again and the 2 RO lines for web tracer are back again and so is line 019 with stsheets on it. I don't understand why none of the fixes are working? Please help!?!? .............Chris
    P.S. HJT log is attached. It is HJTlog524
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are going to have to get some other things fixed on you PC first. Refer to the How to Protect yourself from malware! thread and install a Microsoft Antispyware. Do a full scan with it after booting in safe mode. The reboot normal mode and go to step 1 in the How to Protect thread and goto Windows Update and select Custom Install. Get all of you updates/patches except WinXP SP2. It is not a good idea to upgrade to SP2 while having any problems.

    Do you have System Restore disabled?

    Double check how you have ZoneAlarm setup and make sure it is doing its job. Also check which applications you are allowing in an out of your PC.
     
  29. gracie312

    gracie312 Private First Class

    ok, downloaded Avast! and Microsoft AntiSpyware but haven't run them yet. While checking Zone Alarm I found a lot of things that I'm not sure about. First of all it says there are 200 programs ok'd for the internet! Here are some that I don't recognize. Can you take a look and tell me if they are ok or not?

    Agent Module
    BackWeb 137903.exe
    btfdpjid.exe
    Cassandra
    Client Server Runtiime Process
    COM Surrogate
    DAO 3.5 setup
    Dr. Watson Postmortem Debugger
    dumpsprep.exe
    ereg
    Generic Host Process for Win32 Server
    ICE 2.6 (there are 9 of these)
    iinstall.exe (not a typo)
    Inno Setup Installer
    Installer for Windows Installer
    Malicious Software Removal Tool Update Stub
    MmjbUpdt.exe
    zbloader.exe
    zloader.exe
    WMI
    wmplayer
    WebReg application
    Visual C# Command Line Compiler
    Usernit Logon Application (not a typo)
    Unwise.exe
    Stop.00009_4.exe
    Shadow Bar Module
    mqspbkup.exe
    mptsgsvc.exe
    muyvslxq.exe
    Run a DLL as an App
    Removes the Home Search virus
    MS DTC Console program
    PML Driver
    Search assisstant
    Self Extracting Cabinet (13 of these)
    Services and Controller App
    Self Extracting Messenger
    Meanwhile, I'm going to run the Windows Spyware program and see if it does anything. Thank You, Thank You, Thank You! I'll check back shortly....Chris
     
  30. gracie312

    gracie312 Private First Class

    Hi Chas. Went back and ran MS antispyware and it seemed to do the trick! This is what was found...
    180search assisstant (adware)
    Spyware.Melkosoft (browser modifier)
    Spyware.abspics (spyware)
    Trojan Downloader Agent.JD (trojan downloader)
    Search ToolBar (adware)
    Adware.Sorted Links (browser plug-in
    55 total infections found, all deleted, restored browser settings.
    Then ran hijackthis and saw the 2 RO webtracer lines and the line 019 thing. Fixed those and saved file. It's attached. Also downloaded Mozilla Firefox and am using it now. Can you check it out and see where I am with this thing? I still don't have any options to change my desktop background. Is there any way to restore all the things that were changed during all this mess? Thanks a bunch. ...............Chris
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks moyupae and D3m3nt3d. Yes there is nothing like hands on! Remote fixing by forum messages is sometimes painful.

    I'm not sure what is blocking the changes in this case. I have fixed literally dozens of these this way and it always worked the first time.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Gracie,

    Deny (block) all access local and internet for the below:

    btfdpjid.exe
    dumpsprep.exe
    iinstall.exe
    Stop.00009_4.exe
    mqspbkup.exe
    mptsgsvc.exe
    muyvslxq.exe

    You forgot to post that last log. Post it now. Is everything still working okay?
     
  33. gracie312

    gracie312 Private First Class

    Ok, went into Zone Alarm and denied access to the programs you listed. Then ran HJT and the 2 RO lines for web tracer were there as well as the line 019. clicked fix and scanned again. Still have one RO web tracer line. It just won't allow deletion. What can I do? I'm using Firefox now along with most of the other programs you recommended. I'm gonna run MS Anti Spyware again and see if it finds anything. Will let you know what I find out..........Gracie
    BTW the HJT file is called hijackthislog52605.
     

    Attached Files:

  34. gracie312

    gracie312 Private First Class

    Pt.2 of post.....Ran MS AntiSpyware and it found "about.blank" and said it was deleted. Then ran Spyware Blaster and found webtracer and another browser page...http://.search.msn.com/{SUB RFC1766}/srchasst/srchcust.htm. This one was listed in another spyware program as not being IE's default browser page. Then ran Spybot S&D. It found CoolWebSearch and 2 other registry hijackers. I clicked fix and it said they were fixed. So I tried getting online with IE and the home page opened as "about.blank". I don't understand why this stuff keeps coming back!?!?!? I even emptied the recycle bin after each deletion. Any suggestions? I saved the Spybot log file. Should I attach it? Let me know. Sorry this is so frustrating! :( I hope you will still help me clean up this mess? Thanks again for all your help to date!!!............Gracie
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I mentioned in message #28, you need to get your Windows Updates installed. So goto: Windows Update

    and select Custom Install and get all of your Updates except WinXP SP2. Let me know when you complete that. If you are working via dial-up, this will take a very long time.

    After getting your updates post a new HJT log! Also post your Spybot log if it still finds any problems.

    Do you have other user accounts on this PC? If so, run the cleaning tools on those accounts too.
     
  36. gracie312

    gracie312 Private First Class

    FYI: I am using a DSL connection and there are no other user on my pc. Also, I did get the Windows updates but I will go back and check for anything I may have missed. Will post logs thereafter. Thanks
     
  37. gracie312

    gracie312 Private First Class

    Updated Windows with all but SP2. Ran Spybot S&D, log is attached. Ran HJT, the 2 RO lines with web tracer in the were still there and so was 019 line. Clicked on fix, then rescanned and they were still there. Did this 3 times with same result. This log is also attached. After all this, when I opened IE, it went right to glode something in the address bar. When I first booted up today It was still going to MSN. Don't know why it reverted back to globe. Anything else I can do to get this stuff off my pc? Thanks for your time. .............Gracie
     

    Attached Files:

  38. gracie312

    gracie312 Private First Class

    Chas, got back online to check in here, browser is still going to globe something. I ran MS anti-spyware and it came out clean. I don't get it!?! :eek: ...............Chris
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why this is proving to be this difficult. I have never had this much of a problem with webtracer. Here is what I want you to try this time. Make sure you print or save these instructions locally because it is very important that you remain physically disconnect (unplug the cable to your DSL modem) and you have no browsers open at any time until I ask you to do so.

    Make sure your still have that fixsts.reg file from previous instructions.

    Okay, disconnect now and exit all browsers before continuing.

    - Uninstall Microsoft Antispyware for now. It could be getting in our way at this point. We will reinstall later once we fix this problem.

    - Reboot to safe mode.

    - Then double-click on the fixsts.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Run HijackThis and select the following lines (if they are still there) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rl.webtracer.cc/-/?bayzm
    O19 - User stylesheet: C:\WINDOWS\stsheets.dat

    Now exit HJT.

    - Delete: C:\WINDOWS\stsheets.dat also empty your Recycle Bin and goto C:\windows\Prefetch and delete all files in that folder.


    - Remember do not connect to the internet until requested.

    - Now we need to Reset Web Settings (please leave majorgeeks as your home page for now):
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    - Then reboot in normal mode get a new HJT log before connecting any cable to the internet.
    - Now connect your cable to the internet and get a second HJT log.
    - Now open your browser and come back here and post both HJT logs. Name them so I know which is which.
     
  40. gracie312

    gracie312 Private First Class

    Ok Chas, followed your instructions exactly. The HJT logs are named before and after. Everything looks ok so far except that my desktop background is still black with no option to change it. Let me know how it looks after looking at the logs. Thanks..........Gracie
     

    Attached Files:

  41. gracie312

    gracie312 Private First Class

    Pt. 2 of post.........Sorry forgot to add a few things....Did the fixsts.reg. It said the items were added sucessfully but I never saw anything come up the REGEDIT4 lines on it. Reset web setting as instructed. Then ran HJT before and after connecting to the internet. HJT logs are attached and named before and after.
     
    Last edited: May 29, 2005
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Looks clean now. If you are still clean, complete the steps in the below link to help keep you that way (MS Antispyware can be reinstalled now too):

    How to Protect yourself from malware!
     
  43. gracie312

    gracie312 Private First Class

    Chas, can you tell me how to restore the desktop background? I lost something during all this. When I click on properties on the desktop I only get two tabs, screen saver & settings. Settings only allows me to change resolution. I think the trojan desktop hijacker did something to it. Thanks..........Gracie
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below registry patch and let me know if it helps.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixdt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixsdt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes

     
  45. gracie312

    gracie312 Private First Class

    Absolutely wonderful!!! My desktop is back to normal. Chas, I can't thank you enough! I hope you know how much people like me appreciate people like you and the rest of the MajorGeeks crew! I'm going to ask God to bless you for all your selfless work, so be expecting something great to happen very soon. ................Gracie
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! And thanks for the blessing. I hope it's it helps me win the lottery. ;)
    It's tough trying to figure out how to send 4 kids to college. :eek:
     
  47. gracie312

    gracie312 Private First Class

    Hi Chas! I'm back! I've got this thing on my pc. Norton anti-virus detected it but none of the other spyware programs pick it up and Norton says it can't fix it. It's called "tapeq.sys" and is located here...C:\windows\system32\drivers\tapeq.sys. I tried to delete it from this file but couldn't. Any idea how to get rid of this thing? I can't understand where it came from with all the stuff I've got protecting me. I'd really appreciate your help on this. Thank....Gracie
     
  48. gracie312

    gracie312 Private First Class

    Thanks. I think that worked. I'll find out tomorrow after I run the anti-virus stuff again. I was able to delete it from safe mode though. Norton told me what and where it was. That's how I knew it wasn't a driver.
    Thanks again.....Gracie
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For files like this (when not sure what they are for), it is always a good idea to right click on the file and select Properties and then look for a Version tab (not always available) and then look thru the Item names to gather info on the file. If there is no Version tab, it does not definitely make the file bad but it could be another indicator that it is bad.
     
  50. gracie312

    gracie312 Private First Class

    Hey Chas, I don't know what just happened but I was online and the computer suddenly rebooted itself. I sent the error message to microsoft and it took me to this website. I copied the info below. It says something about an online crash. I'm wondering if it has anything to do with that driver I deleted yesterday?!?! How can I find out?.........Gracie


    | microsoft.com guide


    Online Crash Analysis | Corporate Error Reporting | Online Crash Analysis Worldwide
    Browser security settings may impair site functionality

    JavaScript and cookies must be enabled

    Microsoft Online Crash Analysis uses JavaScript and cookies to display content correctly.

    To upload your error report or check the status of a previously submitted error report, ensure that your browser security settings meet the following requirements:

    JavaScript must be enabled.
    Cookies must be enabled.

    Error Caused By A Device Driver

    Thank you for submitting an error report. Microsoft is unable to specifically determine what caused the problem you reported. To troubleshoot the problem, please see the information below.

    Analysis

    A device driver installed on your system caused the problem; however, we cannot determine the precise cause. Depending on which situation is applicable to you, please do one of the following:

    If this problem occurred after you installed a new hardware device on your system, the problem might be caused by the driver for the device. If you know the manufacturer of the device, contact the manufacturer's product support service for assistance.
    Some software, such as firewall and anti-virus software, also installs drivers. If this problem occurred after you installed new software, the software might have installed a driver that caused the problem. If you know the manufacturer of the software, contact the manufacturer's product support service for assistance.
    If you don't know the driver's manufacturer and need help diagnosing and resolving this problem, contact your computer manufacturer's product support service.
    Updated drivers might be available on the Microsoft Windows Update website. At Windows Update, you can have your computer scanned and, if there are updated drivers available, Windows Update will offer a selection of drivers that you might be able to use.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds