Format c:????

Discussion in 'Malware Help (A Specialist Will Reply)' started by smith75, Dec 5, 2005.

  1. smith75

    smith75 Private E-2

    Hello,

    I have been battling a virus for a week or so now & have finally admitted defeat!
    I'm on the verge of going into DOS and typing 'Format c:' but before I do I thought I would post my Hijack log here to check whether there is anything obvious I've missed (could well be!). I would really appreciate any advice anyone could give.

    Syptoms: Slow PC, Huge Dr Watson log (about 4Gb) & numerous viruses that I delete but keep coming back!

    I am now running AntiVir & have been getting numerous messages this evening along the following lines,

    C:\WINDOWS\SYSTEM32\.EXE

    Contains a signature of the (dangerous) backdoor program BDS/Small.EO Backdoor server programs.

    I always delete the file but this does seem to stop the problems.

    I should say that I've done some of the obvious stuff like running AntiVir, Bitdefender, Spybot, Microsoft Antispyware.

    Thanks for any help provided.

    Edit by chaslang: Inline log removed
     
    Last edited by a moderator: Dec 6, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post HJT logs inline. Also before they are posted, standard cleaning procedures must be followed.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .

    Are you sure about the below:
    Is it really just .EXE without any base filename?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note, If this C:\Program Files\Popup & Privacy Defender for IE\pdie.exe is from pcsecurityshield.com (the same as the company who had just Privacy Defender ) is is more than likely garbage. See info about them and Privacy Defender here: http://www.spywarewarrior.com/rogue_anti-spyware.htm


    You also have the below worm:

    http://www.sophos.com/virusinfo/analyses/w32hwbota.html


    It shows in the below service:
    O23 - Service: Hardware Clock Driver - Unknown - C:\WINDOWS\System32\hwclock.exe (file missing)
     
  4. smith75

    smith75 Private E-2

    OK thanks. I have also posted on techguy & the etiquette is different there. I know I should have checked the rules here before posting - I was just be lazy - sorry (these problems have worn me out!).

    I did run all the steps in the attached thread although I didn't make notes about the problems I encuntered. I will run through them again.

    It really is a .exe with no filename, I copied the text from the AntiVir log.

    The C:\Program Files\Popup & Privacy Defender for IE\pdie.exe relates to www.synergeticsoft.com & I'm pretty sure they're ok.

    Thanks again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you already ran ALL the steps in the sticky thread and in the order specified! You do not need to do them again. Did you run at least two of the online scanners?

    Did you enable viewing of hidden and system files per the READ & RUN ME? If so, look in the system32 folder to see if you can find a file with a .exe extension and no base filename. Try sorting the folder by Modification Date too to see if any strange filenames show up with recent dates.


    It is a pretty big coincidence that they have the exact names as previous products by pcsecurityshield. I still wonder about this product. Also it does not look to me like Privacy Defender is worth spending any money on since you can already do what it does using IE and maybe another free tool like CCleaner. And as far as popup blockers, I don't see them being needed but a free browser like FireFox (which is recommended over IE) has built in popup blocking.
     
    Last edited: Dec 5, 2005
  6. smith75

    smith75 Private E-2

    Yes, I ran BitDefender & Kaspersky.

    Yes, I also did this. There's no file with a .exe extension and no base filename and strange filenames with recent dates.

    I am now using FireFox but I had this software installed for 2 years with no apparent problems.

    Late yesterday evening I ran another virus scan using AntiVir. This found the virus TR/Proxy.Ranky.DB.1 which was sucessfully deleted & since then my system has been much better. I still get frequent prompts to connect to the internet for no apparent reason which makes me think the problem hasn't disappeared.

    I've attached a Hijack log which looks OK but I'm not 100% sure!?

    Thanks for your help so far, I would welcome any further suggestions!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not followed the instructions in
    Downloading, Installing, and Running HijackThis

    You need to do this and get the proper version of HJT. Then attach a new log from Version 1.99.1

    Also we need to get rid of the below service showing in your HJT log.
    O23 - Service: Hardware Clock Driver - Unknown - (no file)

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Hardware Clock Driver ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Hardware Clock Driver

    Now exit HJT but DO NOT reboot yet. We need to re-run HJT and make some other fixes first.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O19 - User stylesheet: (file missing)
    O23 - Service: Hardware Clock Driver - Unknown - (no file)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Dec 6, 2005
  8. smith75

    smith75 Private E-2

    Thanks again for this

    I was doing fine until I got to the following instructions,

    When I pasted "Hardware Clock Driver" into the message box that appeared I got the following message back: Service 'Hardware Clock Driver' was not found in the Registry. Make sure you entered the short name of the service., vbExclamation.

    Should I just ignore this & proceed as per the instructions?

    Thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did the first part with Services.msc work okay?

    Does it still show in services.msc? If so, look near the top of the window to the right of the text that says Service Name: What name is to the right? That should be the short name. What ever it says there is what we want to use in HJT. Also look under the text that says Path to executable:

    Do you see anything in that box? If so, tell me what.

    Proceed with the remaining steps anyway and post the follow up HJT log.
     
  10. smith75

    smith75 Private E-2

    Yes.
    Yes, it was disabled & the service name was hwclock.
    No, it was empty.

    I have followed all the steps & attached the log. Hardware Clock Driver no longer appears in services.msc. I seem to have aquired wuauclt.exe which looks a bit suspect, should I just fix it?

    I sure you're tired of hearing it by now but I feel I should say thanks again!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! That is Windows Update service for automatic updates.

    You're welcome!

    If everything is working okay now, you should check out the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds