Having Some Issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by chunky_chic, Dec 26, 2008.

  1. chunky_chic

    chunky_chic Private E-2

    Hi. I am unable to connect to some sites....ie myspace.come, iconator.com and a few others. This has been going on for a few weeks now. I am using Windows XP SP2. I have wireless connection on this computer and my fiance laptop, they are both on the same wireless connection. I am able to go to these sites on the laptop but not the desktop that I normally use. I have ran all the scans from the Read and Run Me First section and will be posting the logs from those scans now.

    SAS and ComboFix here

    View attachment SUPERAntiSpyware Scan Log - 12-26-2008 - 10-21-38.log

    View attachment ComboFix.txt
     
  2. chunky_chic

    chunky_chic Private E-2

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to BYMABKQMUQX
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    Now do the same for: Cpq780nph
    * Click OK until you get back to Windows.

    * Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste BYMABKQMUQX into the box that opens, and press OK
    Now do the same for: pq780nph
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and tell me how things are running.
     
  4. chunky_chic

    chunky_chic Private E-2

    Hi. Thank you so much for the quick response. I do have a small update - the same night I posted my original post, I had let windows updates download and install. Keep in mind, I have not done this in forever because this is my boyfriend's desktop and for some reason he is scared of the updates and now I may know why. After it finally finished (including installing sp3) my wireless internet stopped working. For hours I attempted everything I could think of to get it to work but nothing so I decided to uninstall sp3 but for some reason, I got a message saying the uninstall failed so I decided maybe a system restore would work but it failed as well. Then I rebooted and got a message about the autocheck file was missing and then it starting looping the reboot screen continously and never logging onto windows so I did a windows repair via the boot cd. I am *still* having the same internet issues though prolly cause I didn't do a clean install but my boyfriend has a lot of things on this computer that I don't want to be responsible for losing, heh. Anyway, I am running the things you have listed but I have ran into trouble. When I run the mgtools analyse and get to the remove a nt service part, I enter Cpq780nph but it says it is still running even though I do not find it in services.msc or even on my hijack scan list. Do I need to run complete new scans to post for you? Sorry if this is long and confusing.


    -Michelle
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, please attach new scans:
    SAS
    MBAM
    Combo
    And please uninstall MGTools, including the MGLogs. Then please download the latest version of MGTools.exe from the Read and Run First instructions.

    It is never a good idea to install anything, esp. updates, when your system is infected.
     
  6. chunky_chic

    chunky_chic Private E-2

  7. chunky_chic

    chunky_chic Private E-2

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean...though I want you to uninstall Viewpoint Media Player and then delete C:\Documents and Settings\Shel\Local Settings\Application Data\WildTangent.

    Tell me what problems you still have.
     
  9. chunky_chic

    chunky_chic Private E-2

    I got those things done. My computer is running much much better now and I can access the websites I couldn't previously :). You're the bestest. Thanks so much!!

    Hugs
    Michelle
     
  10. chunky_chic

    chunky_chic Private E-2

    Oh - one last thing. What about installing windows updates, should I or no?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes you should keep your system updated.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  12. chunky_chic

    chunky_chic Private E-2

    Thanks again. Please tell me how I work around my net not working once SP3 is installed?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you saying you have no network connections?

    Did you open SAS / preferences / repairs and try fixing your internet connection?

    This is something you may wish to address in the software section ( do check your device manager to be sure there are no errors with regard to you internet cards).
     
  14. chunky_chic

    chunky_chic Private E-2

    I only have no internet connection on this desktop pc when I update to SP3. The laptop has vista and the connection will of course still work on it. I will try updating and if I have issues again with my connection, I will address it in the software division. Thanks again for everything!
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds