Hello

Discussion in 'Malware Help (A Specialist Will Reply)' started by bohink, Jun 8, 2007.

  1. bohink

    bohink Private E-2

    I am newly registered to the forums, but not to the great advice from those at Major Geeks.com. Got great help in removing spyaxe with HJT and smitrem. It has been awhile and now I find myself with new problems. I find my calendar going back in time and my browsers coming up with "Page not found" after a short time on line. The computer will even shut down in the middle of any task and then tell me it recovered from a serious condition after taking forever scanning the hard disk. I get phantom audio and when I control-alt- delete I see no tasks running....strange behavior I can't explain

    I am going to attempt the malware removal procedure, but need to know what is meant (how to) by emptying (delete, shred, send to recycle?) the quarantine folders of antivirus and antisyware. I found the webroot quarantine file, but cannot locate the McAfee file. I also have spybot, but when I run a fix it only sees 64 files and tells me things are just dandy.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Emptying your quarantine files just makes your logs smaller ....we can deal with it later...doing the scans and attaching the logs that are requested is the important part. Do remove questionable programs and run CCleaner .....
     
  3. bohink

    bohink Private E-2

    Thanks Tim. I do not see anything questionable or out of the norm. I'll run the CCleaner.
     
  4. bohink

    bohink Private E-2

    Wow, there was a ton of junk in there.....gone now
     
  5. bohink

    bohink Private E-2

    Hmmnn...no... explore... in the start menu...How do I get that back?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start / run / type "sfc /scannow" without qoutes ...have your xp cd handy ...run it twice.
     
  7. bohink

    bohink Private E-2

    Did the scan twice?... I fell asleep and woke to a rebooted computer...don't know if the second scan completed.... Still no.. explore... on the start menu... have to go to work...will try to catch up to any new advice or instructions....thanks
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And what happens if you go to Start / run / type "explorer" without qoutes?

    Can you still run and attach the requested logs?
     
  9. bohink

    bohink Private E-2

    My documents folder comes up...???
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is explorer ...you just need to expland the items.
     
  11. bohink

    bohink Private E-2

    Wouldn't opening my documents be the same thing?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what problems you are having and can only assist if you follow the Read and Run First instructions as best as you can and attach the requested logs.
     
  13. bohink

    bohink Private E-2

    Tim, I'll do the best I can. I am pretty tied up with other obligations at this time. I'll need to find the time to try and tackle the problem. Right now my problem is trying to find the hidden folders in windows. That is where I am now. seems i can't get there following the instruction....thanks
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    This set the folders to unhidden.
     
  15. bohink

    bohink Private E-2

    Tim, the file is saved to the registry...I have another problem....

    when downloading Highjack this there was a trojan attached and my antivirus detected it and stopped the download.

    Did I miss something?

    I needed to remove and reinstall spybot S&D to get the updates. I also downloaded getrunkey and shownew.
     
  16. bohink

    bohink Private E-2

    I got the HJT from the author site and got the trojan Mcafee quarantined....Got the app from your site in Fl... Now in my download folder....
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I did not understand your last message ....you should download everything from MG's download sites ....and you may have to stop S&D when running or downloading them ...though I'm not sure why ....what exactly is happening?
     
  18. bohink

    bohink Private E-2

    Tim, I have clicked the author site to download the HJT. S&D was not running. I got the trojan detected and cleaned message from McAfee. continued and then downloaded from MG's site. I now have the HJT in my download file.

    I also downloaded counterspy. Do I need to install the HJT and counterspy or will they run from that location...??? Please advise
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your copy of McAfee is way out of date with its updates if it is detecting this. This is a well know very old issue with McAfee. Update it to current definitions. If you cannot do that, it means you do not have a supported antivirus program and that it is out of date and not useful. Which means you need to uninstall it and use something else or you need to pay for updates.
     
  21. bohink

    bohink Private E-2

    Updates from McAfee are up to date.

    This is what testing my firewall returned:

    Unable to Probe
    The IP address requesting this page is different from the IP address of your computer. This indicates that your computer is behind a proxy or NAT. These devices allow you to access the Internet by relaying traffic, typically from multiple computers, through a single IP address.

    We are unable to directly probe your computer, you should take comfort from this. You have that much more protection between your computer and the Internet.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having a malware issue...I suggest you post whatever problem you are having in either the software or hardware sections.
    If you are having a malware issue, post the requested logs now!
     
  23. bohink

    bohink Private E-2

    Tim, it appears that after running Spybot S&D and the Counterspy that my computer is now free of whatever malady it had. Spybot fixed 11 problems and the Counterspy quarantined 5 items. I appreciate the help I did receive but a little disappointed in not having some questions I asked answered directly.

    My original post contained the problems I was having:

    I find myself with new problems. I find my calendar going back in time and my browsers coming up with "Page not found" after a short time on line. The computer will even shut down in the middle of any task and then tell me it recovered from a serious condition after taking forever scanning the hard disk. I get phantom audio and when I control-alt- delete I see no tasks running....strange behavior I can't explain


    thanks again.... I'll try and keep up with this stuff....
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your questions weren't answered because you did not supply the requested logs for us to see what is happening in your computer ......counterspy found a few things, but it does not mean that it has removed all the possible malware from your computer!!

    That is why we need you to do all the things in the proper order from the Read and Run First thread.
     
  25. bohink

    bohink Private E-2

    Ok, when I find the time to finish the process I will continue with it. Don't get me wrong, I appreciate everything you do and the help you offer. This stuff is not as second nature for all of us. The Read and Run first is a bit to understand and getting all the tools into the machine to fix it takes time. Especially, when it wants to shut off whenever it feels like it. This is the longest it has run in a week.
     
  26. bohink

    bohink Private E-2

    Here is what I came up with. I reran CCleaner, Spybot and counterspy in Safe Mode. Followed instructions with Bitdefender and Panda ActiveScan in Safe Mode with networking and ran getrunkeys and shownew to this point.


    Bitdefender txt is too large. It found numerous problems and deleted them. what would be the best way to show you?
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Manager

    Now
    1. Download this file - ComboFix
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ComboFix
    Avenger
    GetRun
    ShowNew
    HJT ----!!
     
  28. bohink

    bohink Private E-2

    Tim, I removed the viewpoint manager, but when i went to download the ComboFix I come up with a 404 not found message???
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  30. bohink

    bohink Private E-2

    Thanks Tim,

    Here is what you request
     

    Attached Files:

  31. bohink

    bohink Private E-2

    along with...
     

    Attached Files:

  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are making good progress....

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, esit HJT

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ShowNew
    GetRun
    HJT
     
  33. bohink

    bohink Private E-2

    Thanks Tim, Moving right along...here are the results. After doing the fix in HJT and checking the log I find only yesterday's result....??? Cannot or it won't upload the file. There is now a folder titled backups, however....
     

    Attached Files:

  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You only need to save it with a new name...HJT2 ...same with other repeated scans ....

    How are things running?
     
  35. bohink

    bohink Private E-2

    Things are running very smoothly, I thank you very much! almost..almost like a new computer. I am grateful for your help and apologize for thinking I had much of the problems solved. Little do I know of the demons that were deep inside this thing. I need to do a serious clean up of all the other crap I don't need. I used to know a little about this stuff, but lost pace with new technology every second and little time to keep up with it.

    Here are the scans...revisited
     
  36. bohink

    bohink Private E-2

    Oops!
     

    Attached Files:

  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach a new:
    HJT
    Avenger
     
  38. bohink

    bohink Private E-2

    Tim there was a problem. I did step 1 with HJT and it showed the three problems to fix after checking them. After running the avenger and pasting the file to delete the machine rebooted and was in the process when a no disk prompt came up. The notepad came up behind it with nothing in the log...empty...I had to reboot the computer to get rid of the no disk prompt???

    Rescanning HJT...

    are still there. Tried to fix again with no success.
     

    Attached Files:

  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now attach new logs from ShowNew and from HJT.
     
  40. bohink

    bohink Private E-2

    Tim, ran ATF and here are those logs. Would have liked to got on here earlier today. I'll try and catch up.
     

    Attached Files:

  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please boot into safe mode.

    Use windows explorer to find and delete:
    C:\WINDOWS\SYSTEM\blank.htm

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT

    Now boot into normal mode and attach a new HJT log.
     
  42. bohink

    bohink Private E-2

    Hello Tim, I used windows explorer and typed in the address: C:\WINDOWS\SYSTEM\blank.htm and got a cannot display message. Don't know what folder to look in manually if I am doing this right at all.
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have Viewing of Hidden Files Enabled?
    What exactly is the error message?
    Can you not scroll down and expand windows/ then click on system / ...and see if it is there.
     
  44. bohink

    bohink Private E-2

    My hidden files come up as ghosts, Where do I enable viewing. I opened a couple and they show empty windows

    The message reads:The page cannot be displayed
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    According to your GetRun...your hidden files are enabled to view. What do you mean by "ghosts" and what files did you click on that show empty windows?

    I take it that you could not open explorer and click on system ( in the windows folder) ---> was that empty?
     
  46. bohink

    bohink Private E-2

    Found a bunch of hidden files in SYSTEM32 that had a prompt to show hidden files. It wasn't in there.
     
  47. bohink

    bohink Private E-2

    No windows was not empty. A ghost of the file like it is transparant I just got the same prompt for windows. File is not in the system

    folder picsvr is 1 that is empty

    I believe I may have been looking at hidden files all along?????
     
  48. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not system 32 ....you should have this:
    local disk( C:\windows(expand)\then just a folder named system....right above system 32 ...click on it and you should see a bunch of .dll's and device drivers....do you also see the blank.htm?
     
    Last edited by a moderator: Jun 28, 2007
  49. bohink

    bohink Private E-2

    I don't see it, Tim. If everthing is in alphabetical order it is not where it should be.??
     
  50. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Doubt it is alphabetical.....
    DownloadCWShredder.

    then attach a new HJT log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds