Hate to bother anyone, but...HELP! Please?

Discussion in 'Malware Help (A Specialist Will Reply)' started by BROTHER DION, Jan 2, 2005.

  1. BROTHER DION

    BROTHER DION Private E-2

    I've had problems with my PC for a couple of months now. Errors on pages, never opens on my prefferred home page, headings on the browser appear "broken", Kind of just slow and lathargic in general. Six people use this poor thing including 4 teens and their friends. I've done the "read me first" thing several times, but that doesnt really help. Maybe i've done it wrong or something, but I could use a little help if you could please. This computer is only 1 1/2 yr. old, and it's on dial-up. I've wrote down the results of the basic spyware/trojan removing process: Trend Micro's Free On-line Scan- Had to install activex first, then it found and cleaned 1malware, and ended with 0 infected files. Symantec Sec. Check - Security check indicated the pc is trojan and hacker vulnerable, and the virus scan took an extremely long time to just download actvex , again. And never did complete a scan. I had to boot in normal mode because I couldnt get connected in safe mode. Avert Stinger - This one wont allow me to update, but I ran it anyway finding no problems. CCleaner - This one also seems to not run correctly. It does a very quick scan and then abruptly closes. Spybot S&D - This found 1 problem, "altnet 1 entry, could not be fixed". If you need more info, just let me know. Thanks for your time
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you have followed ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal please read below:

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed,including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. BROTHER DION

    BROTHER DION Private E-2

    OK I'll do all that "red me first" business once again and get back to you. Thanks for such a speedy response
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ, said if you have already run ALL the steps, follow directions and post you HJT log. You do not need to run the REA ME again if you already ran all of it.
     
  5. BROTHER DION

    BROTHER DION Private E-2

    OK well I went ahead and ran the read me first stuff, including reinstalling all the clean-up utilities and up-dates and plug in,etc. So , judgeing by chaslang's post I will be allowed to go through the HJT tutorial, download, and and send that to you, as an attachment, of course. Correct?
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    That is correct!
     
  7. BROTHER DION

    BROTHER DION Private E-2

    Great !!! Thanks. This is a bit scary for me so I'll need to take some time to be sure I do it, "as if someone was holding a gun to my head", (LOL) correctly.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your not sure what you are doing, do not delete/fix anything with HijackThis. Just post your log as an attachment and we will look at it.
     
  9. BROTHER DION

    BROTHER DION Private E-2

    Really sorry to have taken so long with this, but i've been working ALOT. I think I'm ready to go through with the HJT thing this evening if you are. Anything else I need to know befor I get started? And thanks again for your patients and expertice :cool:
     
  10. BROTHER DION

    BROTHER DION Private E-2

    OK I've downloaded the HJT prog. to it's own separate file in the c drive under program files / HJT. Now what Sir?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just exit all browsers (like Internet Explorer) and run HJT and save a log file. Then come back here and post the log file as an attachment to your message. Make sure you have HJT 1.99
     
  12. BROTHER DION

    BROTHER DION Private E-2

    I will do that and catch you tomarrow
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! We'll be here (at some point ;) )!
     
  14. BROTHER DION

    BROTHER DION Private E-2

    OK here is my HJT saved log file sent as an attachment.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not install HJT like we asked. You have it here:
    C:\DOCUME~1\DION\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    This means you are running it from the ZIP file. Follow the directions in message number 2 and extract it into a folder of its own like c:\Program Files\HJT.

    You must do this before continuing or you will not get backups.

    You should uninstall these as they are junk:
    SpyKiller
    BestPopUpKiller

    Uninstall them from Add/Remove programs. See the below link for info on SpyKiller. It's a rogue/suspect spyware removal tool. And the other program is by the same company and should not be used either:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    While in Add/Remove programs look for anything saying WildTangent and uninstall it too.

    You also have Spybot installed improperly:
    C:\Documents and Settings\DION\Desktop\Unused Desktop Shortcuts\Spybot - Search & Destroy\TeaTimer.exe

    Uninstall it, reboot, and install it again and allow it to install in the default folder it suggests. This time do not use TeaTimer.

    EDIT: Okay! What did you do? I also see C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe. How did you get two TeaTimers and two Spybots running?

    Uninstall both of them and start over as I said above.
     
    Last edited: Jan 17, 2005
  16. BROTHER DION

    BROTHER DION Private E-2

    YIKES!! Dredfully sorry. I will take care of those things ASAP.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me know when you finish with that.
     
  18. BROTHER DION

    BROTHER DION Private E-2

    Let's try this again. I hope this is correct, but you are dealing with a "rookie" here. Also, I couldn't find wildtangent in the add/remove program area. Nor could I find "best pop-up killer". And I'm pretty sure I got rid of the spybot S&D. And I dumped "Spykiller".
     
  19. BROTHER DION

    BROTHER DION Private E-2

    Aaaaaaaaarrrg!!!!!!!!!!!!!!
     
  20. BROTHER DION

    BROTHER DION Private E-2

    Here it is... I hope
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well accoring to your log, you still have TeaTimer running and you still have both SpyKiller and BestPopUpKiller. We take care of all of these below.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.

    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.

    Now quit Spybot!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: (no name) - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - (no file)
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM\blank.htm
    C:\Program Files\WildTangent <-- the whole folder
    C:\Program Files\SpyKiller <-- the whole folder
    C:\Program Files\BestPopUpKiller <-- the whole folder

    Now empty your Recycle Bin and go to c:\windows\Prefetch and delete all files there too.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  22. BROTHER DION

    BROTHER DION Private E-2

    OK I believe I did this correctly. Although, I could not find the windows system blank file or the wild tangent file in the program files. please respond as to where else I may find these. And I did find the spykiller and the best pop-up files and deleted those in safe mode. Also , when I went to send a new HJT log, I saw there was a back-up file. Is that a problem? Thanks for all
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis makes backups of things we fix. They are put in the Backup folder which is in the same folder from where HJT is run. Get me that new log. You'll have to give it a new name, because you cannot upload the same filename again. Just add a number to the end of it make it hijackthis2.log (this time). I usually shorten the whole name myself and use an incrementing number each time (like: hjt1.log, hjt2.log.....etc)
     
  24. BROTHER DION

    BROTHER DION Private E-2

    OK Dr. C. Here is my 2nd HJT log. Also , I found 2 more files that I'm not familiar with. Spyware doctor and screen saver.com. And as far as I know I no longer have Spybot S&d anylonger. I just wasnt confident that I was installing it correctly at this point
     
  25. BROTHER DION

    BROTHER DION Private E-2

    Gggrrrrrrrrr!
     
  26. BROTHER DION

    BROTHER DION Private E-2

    I dont understand why I cant post my log right now. Been a long day.
     
  27. BROTHER DION

    BROTHER DION Private E-2

    1234
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said
    What are the full file names including the path? For example the Teatimer.exe file I show below in your HJT log is the file name. The path to the file is C:\Program Files\Spybot - Search & Destroy


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: (no name) - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - (no file)
    O4 - HKLM\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Program Files\Spybot - Search & Destroy <-- the whole folder

    Now reboot in normal mode and post a new HJT log.
    And tell me what problems remain.
     
  29. BROTHER DION

    BROTHER DION Private E-2

    OK the path to those 2 other files I mentioned are C:/programfiles/spywaredoctor and c:/programfiles/screensaver.com. Here is my 3rd log and while in safe mode I did find spybot S&D and deleted the whole folder. Unfortunately, I forgot to do this with the system restore turned off. Hope that is not a problem.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Restore should still be off! You should not be turning it on until all of the problems have been resolved.

    Be careful how you write things. The spaces between words can be very important. Also whether you use / or \ matters.

    c:/programfiles does not exist but c:\Program Files does

    Delete the below (I assumed there were spaces as indicated):

    C:/Program Files/Spyware Doctor <--- delete the whole folder
    C:/Program Files/screen saver.com

    You have to remember to exit all browsers before running HJT. You still had IE running.

    If you delete and have uninstalled Spybot S&D, why is it still in your HJT log. Are you forgetting to click the Fix button or do you have your borwser open when trying to fix things. All the items I asked you to fix previously are still there. Below I repeat the steps again.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: (no name) - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - (no file)
    O4 - HKLM\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Program Files\Spybot - Search & Destroy <-- the whole folder

    Now reboot in normal mode and post a new HJT log.
    And tell me what problems remain.

    Do you have any other spyware related programs installed? Like SpywareBlaster or anything else?
     
    Last edited: Jan 21, 2005
  31. BROTHER DION

    BROTHER DION Private E-2

    Greetings again Dr. C. I did what you said. 2 of the 4 things that I was to fix with HJT. were not listed. Those two would be...02-BHO: (no name)-{014DA6C1-189F-421a-88CD-07CFE51CFF10}-(no file) and 04-HKLM\..\Run:[SpybotSD Teatimer] C:\Program Files\Spybot Search & Destroy\Teatimer.exe. These 2 items were not listed after I did my last HJT scan. After rebooting in safe mode I also did not find C:\Program Files\Spybot-Search & Destroy. And yes I do have other spyware removal programs installed as directed by the "Read Me First..." tutorial. For the first time in a long time I was able to start my system and have it go to my prefferd start page. But when I view other web sites, I find that instead of where ther should be a picture there is only a box w/ a small square with an X in it. System restore remains off. And thanks again.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you remember to exit browsers before running HJT. You must ALWAYS do that.
    I saw this in your log: C:\Program Files\Internet Explorer\iexplore.exe

    What other spyware scanner removal programs are still installed? SpywareBlaster and Ad-Aware SE? Any others?

    If you still have SpywareBlaster installed, run it and on the first screen select Disable All Protection. Then exit SpywareBlaster.

    No run HJT and tell me if the below line still shows:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
     
  33. BROTHER DION

    BROTHER DION Private E-2

    Doc C, About the spyware removal programs, I have Ad-Aware SE, CWShredder which doesnt allow me to update, About Buster, Kill2me,CCleaner, Avert Stinger which also doesnt allow me to update, HSremove, and Spywareblaster. I did what you said with Spywareblaster, and ran HJT. The line 06-HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel Present, is still there. I did not fix or post a log because I wasnt clear on if you wanted me to do so. Peace
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of CWShredder?
    What version of Avert Stinger? This one requires a new download. Just updated again today. Always check for new versions here on MGs by clicking the links in the READ ME and comparing them against what you have.

    Try fixing that O6 line with HJT? Tell me if that works.
     
  35. BROTHER DION

    BROTHER DION Private E-2

    OK, I got everything up-dated, and I got that 06-HKCU...line fixed. Now what ?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can now fix this line with HJT:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

    Then delete the C:\WINDOWS\SYSTEM\blank.htm file.

    Then reboot and get a new HJT log and post it. Also tell me if you are having any problems.
     
  37. BROTHER DION

    BROTHER DION Private E-2

    The only file I could find that resembled the one I should delete is C:\WINDOWS\PCHealth\HelpCtr\System\PANELS\BLANK.HTM. That was after I did a search for that file C:\WINDOWS\SYSTEM\blank.htm. Again ...sorry this is taking so long
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Don't worry about the file, but you forgot to do the last part of my instructions:

    Then reboot and get a new HJT log and post it. Also tell me if you are having any problems.
     
  39. BROTHER DION

    BROTHER DION Private E-2

    Well here it is. I've done the best I can. ALL windows/browsers were closed, and Internet Explorer was not on. I guess I can live with the way things are now. My computer is performing alot better. Existing problems are again not opening preffered start page and receiving "adult entertainment" e-mails even after blocking sender and unsubscribing etc.
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you said you got the O6 line fixed:
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    It is still there! I have a feeling that the below is getting in the way:
    C:\winstart commander 2002

    Do you use this program? Do you like it?
     
  41. BROTHER DION

    BROTHER DION Private E-2

    NO!! I hate that stupid thing! Can I get rid of it with HJT? If not then how? It seems like it hides on me.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look for it in Control Panel's Add Remove programs and uninstall it from there. This is the proper way to uninstall a program. If it does not have an uninstall, we will look into other methods.
     
  43. BROTHER DION

    BROTHER DION Private E-2

    winstart commander 2002 is NOT listed in contol panel's add/remove programs
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First double check and look for it under different names, like UWCSuite or WS or maybe even something related to Business Logic Corporation. If you still do not find an uninstall in Add/Remove programs, try doing the below steps.

    Make sure you have system restore disabled and viewing of hidden files enabled.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Restart WSC Setting] C:\PROGRA~1\blcorp\UWCSuite\WSC\wscrestp.exe
    O4 - HKLM\..\Run: [C:\winstart commander 2002] C:\winstart commander 2002


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\winstart commander 2002 <--- the whole folder

    C:\Program Files\blcorp\UWCSuite\WSC <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Let me know if you have any problems finding or deleting any of these files.


    Now reboot in normal mode and post a new HJT log.
     
  45. BROTHER DION

    BROTHER DION Private E-2

    Never did find C:\wistart commander 2002, but I did find C:\Program Files\blcorp UWCSuite\WSC and fixed that. No Problems with any error msgs.
     

    Attached Files:

  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay!

    But something is still putting the below restriction in your log:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Try fixing it with HJT. If it comes back immediately or after a reboot, we need to find out what.

    If you still have any pieces of the below install, uninstall them and then reboot:
    SpywareBlaster
    SpywareGuard
    Spybot S&D
    SpySweeper
    SpySubtract

    Now tell me if the O6 line is finally gone. If so, then use HJT and try to fix:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
     
  47. BROTHER DION

    BROTHER DION Private E-2

    OK I fixed those two lines. I didnt see them after reboot. What next? I still cannot start on my preffered start page. But things are improveing ALOT.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Get me your current HJT log!

    And when you say you "cannot start on my preffered start page", did you set your desired home page.
     
  49. BROTHER DION

    BROTHER DION Private E-2

    @#%&!!!! Wow man! Those two lines came back. None the less, here is my newest log.
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try doing the below while physically disconnected (unplug your cable) from the internet and with all browsers (including this one closed). So print or save these instructions locally so yo can work offline. Do not open any applications or browsers unless specified.

    OK! Unplug now and close browsers.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Symantec\DeepSight Extractor\ExtractorService.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\EarthLink 5.0\ConMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    After clicking Fix, exit HJT and any other programs you have running!!

    - NOW PULL THE POWER PLUG TO YOUR PC! (yes you read that correctly) I do not want you to power down the normal way.

    - After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

    - Run HijackThis and check to see if the below lines came back. If so, fix them again:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.

    Now reboot in normal mode, plug in your cable, and run your browser and come back and post a new HJT log. And tell us how things are working.


    Side Note:

    The below process from EarthLink is considered spyware. You should disable it. See the links I included
    C:\Program Files\EarthLink 5.0\FastLane\ARUpld32.exe
    http://www.liutilities.com/products/wintaskspro/processlibrary/arupld32/
    http://startup.iamnotageek.com/srch-ARUpld32.exe.html
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds