Have tried everything

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Exxtol, Oct 30, 2005.

  1. Exxtol

    Exxtol Private E-2

    Okay.........about a week ago I was infected with PC Guard, World Anti Spy, and god knows what else. My laptop was a mess. I've run every program that was asked of me on this site and still I am only able to operate my laptop in safe mode with networking. Only safe mode with networking. when i access my laptop in normal mode i cannot access the start menu--when i do access it the menu freezes (meaning it will not minimize). Additionally when i access anything else on the desktop it will not engage. After about 5 minutes the screen goes blank. When i press control at delte, the task manager appears. I have attempted to shut down my comp via the task manager but it does not. HELP ME PLEASE!!! What's wrong with my laptop?? Any ideas.......i have ran CCcleaner, Adware SE, Spy Catcher, Ewido, Norton, etc. I have no more pop ups or messages about spyware, but still I can't access my comp in normal mode. What am i doing wrong here?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. Exxtol

    Exxtol Private E-2


    Yes, that is what i meant. Okay I will try all of that and keep you posted. Thank You.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you post the smitfiles.txt log as requested in that link.
     
  6. Exxtol

    Exxtol Private E-2

    Okay...........I tried everything that manual asked of me. Well the start up menu did not freeze on me like before and i noticed other programs were able to load up on start up. However, the computer was functioning extremely slow. So slow I just finally decided to shut it down. It was unable to shut down correctly. I had to do it manually. Should i copy and paste the results of the logs of the programs that I have? Or what?
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As BJ just indicated and as I said before, attach the smitfiles.txt and HJT logs. Do not cut & paste them here.
     
  9. Exxtol

    Exxtol Private E-2

    Okay once again I cannot boot into normal mode. I noticed that the instructions say I must be in normal mode to run a HJT........should i still run it, or post the other logs?
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, why cant you get into normal mode? What does it do?

    If you cant get into normal mode attach a HJT log from Safe Mode, also attach the smit logs.
     
  11. Exxtol

    Exxtol Private E-2

    Well I can get into normal mode, but the start menu freezes once i click on it. Additionally, I cannot open programs. When i try and access the task manager it does not work. I will run the HJT and post it in an hour or two when i get home!
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    10-04, Attach a HJT log and the other logs!
     
  13. Exxtol

    Exxtol Private E-2


    Okay here is the HJT........give me some time to post the rest!
     

    Attached Files:

  14. Exxtol

    Exxtol Private E-2


    Here is the log to BitDefender......
     

    Attached Files:

  15. Exxtol

    Exxtol Private E-2

    here are the results to running smitrem. I could not attach the SpybotSD text because the file was too big.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your OS and IE versions are way out of date and represent a major security risk. Once any current problems have been completely fixed you must get updated.

    Okay SmitRem took care of most of your PSGuard and Smitfraud problems. You should notice they are gone now. One item from them still remains. You may or may not still have Virtumonde problems. We will see.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\System32\hp3690.tmp
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\System32\pmnoo.dll (file missing)
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
    O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: pmnoo - C:\WINDOWS\System32\pmnoo.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Security Toolbar <--- the whole folder
    C:\WINDOWS\System32\hp3690.tmp

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  17. Exxtol

    Exxtol Private E-2

    Okay, first off let me just say thanks for guiding me through this.
    Okay now back to things. I tried accessing my computer in normal mode. I was able to run HJT, however the file type was giving me problems and would not attach. So I attached my the log i was able to get from safe mode. However when I accessed the start menu it froze. I was able to access my computer from the desktop but it also "hung/froze". I could not access the task manager through atl, control, delete. Additionally, I was not able to find the file C:\WINDOWS\System32\hp3690.tmp. Any more suggestions?? Thanks.
     

    Attached Files:

    Last edited by a moderator: Nov 1, 2005
  18. Exxtol

    Exxtol Private E-2

    Okay, first off let me just say thanks for guiding me through this.
    Okay now back to things. I tried accessing my computer in normal mode. I was able to run HJT and have the log attached. However when I accessed the start menu it froze. I was able to access my computer from the desktop but it also "hung/froze". I could not access the task manager through atl, control, delete. Additionally, I was not able to find the file C:\WINDOWS\System32\hp3690.tmp. Any more suggestions?? Thanks.
     
    Last edited by a moderator: Nov 1, 2005
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not quote messages unless it is required for context! It only clutters up the thread.

    Why did you post two messages with almost the same info?

    The below item is still in your HJT log

    O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\System32\hp9E18.tmp

    Did you fix it using HJT? Are you sure you had ALL BROWSERS closed before clicking fix?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please explain what this means in more detail. We need a HijackThis log from normal boot mode. I'm not sure what you are trying to say about the file type was given you problems and would not attach. It should be no different than what you did in safe mode. Just save the log to a file name with a .log extension (which is the default and upload it). If you cannot upload it, post it inline (copy and paste).

    Does the below files exist:

    c:\windows\system32\taskmgr.exe

    Did you install this: SpyCatcher 2006
     
  21. Exxtol

    Exxtol Private E-2

    Sorry. What i was trying to say is that i could not open the file log that I saved when I ran it through normal mode. Anyway I will just paste the log file form when I ran it in normal mode. Yes the file you mentioned above I do have. But i could not find that other file you were talking about. Oh and i did not mean to post the same post twice. Here is the log file form normal mode:

    Logfile of HijackThis v1.97.7
    Scan saved at 6:13:16 PM, on 11/01/05
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Edit by chaslang: Old HJT version log removed
     
    Last edited by a moderator: Nov 1, 2005
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please delete this version of HJT and run the proper one like you did in your previous message.

    Also please answer questions.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could not open it using what?

    Did you get an error message?
     
  24. Exxtol

    Exxtol Private E-2


    No, no. I meant that I could attach it through this website. It said something about the file not being supported. It wasn't from an error message from my computer.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you did not name the file properly. You must just use the default file extension type which is .log

    When HijackThis saves a file, the default name is always hijackthis.log

    If you change the name to some other extension that is not allowed to be uploaded, you will get that error.

    And you still have not answered previous questions.
     
    Last edited: Nov 1, 2005
  26. Exxtol

    Exxtol Private E-2


    What questions? The file that you mentioned in your previous post I do have. However, I couldn't not find the file you wanted me to delete. It was not there. Yes i have spy catcher 2006 installed. Just a question--what was wrong with the log file that I edited and pasted? That has been the only scan that I have been able to run in Normal mode. Unfortunately, right now i cannot access it in normal mode.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The questions in messages 19 & 20. That you now answered! All but this question:

    You also have not posted the proper HJT log yet.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wrong version of HJT as indicated in the message!

    Logfile of HijackThis v1.97.7

    Your previous logs were from the correct, properly installed version.
     
  29. Exxtol

    Exxtol Private E-2


    Ahh okay I understand. I will try and run it from normal mode (if i can access it), but for now here is the log file from safe mode.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not need a safe mode log! They are not helping.

    I would recommend at this point that you uninstall Ewido (I still see a service for it running) and also uninstall SpyCatcher for now because they may actually be blocking fixes.
     
  31. Exxtol

    Exxtol Private E-2


    Okay I will uninstall both........and keep trying to start up in normal mode.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After uninstalling them:

    - run SmitRem again and save and attach the log

    - run only step 8 from this link: SpySheriff (aka SpywareNo) Removal This will add a patch to the registry.

    Then reboot and post the smitfiles.txt log and new HJT log from normal boot mode (hopefully) and give me some status.
     
  33. Exxtol

    Exxtol Private E-2

    Okay, bear with me. I did not see this post. I did not uninstall the programs that you told me too yet. But i was able to run hijack this in normal mode! Hear's the log.
     

    Attached Files:

  34. Exxtol

    Exxtol Private E-2

    Okay I uninstalled both ot those programs. I ran smitrem again, but i was not able to save the log file. How would i save the fiel so i can attach it? Also how do you copy everything in the quote to the notepad?
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to uninstall those programs. And I would uninstall this too unless you use it: Viewpoint Manager (Only one person in thousands of have talked to even knew what it was but even he never used it.)

    Then run the steps in message 32!
     
  36. Exxtol

    Exxtol Private E-2


    How do i save the log file from SmitRem??
     
  37. Exxtol

    Exxtol Private E-2

    Also how the heck do i copy the quote in step 8 to the notepad??! I copy it, but I don't know how to copy it to the notepad.
     
  38. Exxtol

    Exxtol Private E-2


    Nevermind, I was able to successfuly do Step 8. Now how do i save a log file for smitrem??
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The same as you did last time in message # 15.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds