Help for me too please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimrod, Feb 21, 2006.

  1. jimrod

    jimrod Private E-2

    I keep losing the net with the message incurred problems and have to close, you know the send don't send one. Now this is happening ALL the time.
    I have run AVG, Macafee, adaware and spybot, and nothing seems to be there.
    But not sure if this is linked but when I tried to update spamkiller(on request) I got the system32 page.

    On top of that my system is very slow and my net connection 1gig/2gig is horrendously slow.

    Something wrong, I know not what and please any help slow, deliberate and in layman's terms(that said all the help I ever get on here is first class)

    Thanks in advance
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
     
  3. jimrod

    jimrod Private E-2

    Okay to the best of my ability here goes
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I see the only scan you ran was the Bit Defender scan, go back and run the Panda scan also and attach the logs from both scans.
     
  5. jimrod

    jimrod Private E-2

    hope this is what you want
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, I also need the Bit Defender log.
     
  7. jimrod

    jimrod Private E-2

    Macafe has told me I have new poly win 32 virus but cannot remove or quarentine it. I didn't scan for this indeed I thought my macafe was disabled.
     
  8. jimrod

    jimrod Private E-2

    this is the best i could do with the defender file.

    PS I have been kicked out of this site three times in as many minutes, with the sorry he are experiencing problems thing.
     

    Attached Files:

  9. jimrod

    jimrod Private E-2

    i know you wont, but please don't forget me.
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  11. jimrod

    jimrod Private E-2

    Hi, saved the ewida but now cant find it, have a new hijack this, but had to copy it to word as it would not attach.
     

    Attached Files:

    Last edited by a moderator: Feb 25, 2006
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The first thing we need to address is your antivirus programs. You need to uninstall all but one. Running more than one will cause conflicts on your computer so pick one and uninstall the others. Also, you can uninstall Ewido and then procede with the below...

    Please EXTRACT HijackThis from the ZIP File to a Safer location. Here's how:

    To create a new folder:
    • Click START > My Computer > Local Disc C: > Program Files
    • Now, Right Click on an Empty Area and select New > Folder & name it HijackThis and ENTER
    To Extract HijackThis:
    • Now, Right Click your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder
    • (C:\Program Files\HJT) and click Next.

    After you have completed the above steps to relocate HJT, run it from the new location. Please save your HJT log as a .txt file and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.
     
  13. jimrod

    jimrod Private E-2

    Do do have the extract all option when right clicking hijack this.
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Extract the contents, right click and select Extract.
     
  15. jimrod

    jimrod Private E-2

    Sorry if I am being dumb, firstly just noticed I put do do instead of do not!!!!
    When I right click on hijack this I get Extract files, extract here and extract to hijack this. None of which, if clicked, allows a 'next' command!!!!!
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Right click and select "extract to hijack this", doing this will extract it to it's own folder. You must run HJT from a secure location such as C:\Program Files\HJT
     
  17. jimrod

    jimrod Private E-2

    okay here is the latest, sorry i was away for a few days.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not reading and following the instructions BJ is giving to you. You must not run HijackThis.exe directly from the ZIP file. Here is what your log shows:

    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\Jim\LOCALS~1\Temp\Rar$EX00.269\HijackThis.exe

    This means you are using WinRAR to run hijackthis.exe directly from inside the ZIP file. You MUST extract the hijackthis.exe file from the ZIP file. Use the Extract option of WinRAR. You must also etract it to the proper folder as instructed. DO NOT EXTRACT it to any Desktop location, Temp folder, or and subfolder of Documents and Settings.

    WinRar does ask you where you want to Extract to
    You just have to navigate to the folder where you want to extract it to. This means you need already have the C:\Program Files\HJT folder created. Step 7 of the READ ME explains how to do this.
     
  19. jimrod

    jimrod Private E-2

    Last attempt, I really appreciate the support, but if I can't get it now I never will!!!!!!!!!!!!!!!!!!!!!!!!!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you got it! ;) Just another note: It is best to not have browsers running when using HijackThis. You had 4 opened:

    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    If you do not shut them down, it causes two issues:
    1. We cannot tell if you are running them or malware is doing it. Many forms of malware do open hidden iexplore.exe processes and we need to know that.
    2. More importantly, many fixes will NOT work, if browsers are opened while trying to make the fixes.
    Also note that you skipped step 3 or the READ & RUN ME. You have both AVG7 and McAfee installed. You must uninstall one of these now. Then attach a new log so we can be sure it uninstalled properly.

    BJ should be back soon to continue working with you.
     
  21. jimrod

    jimrod Private E-2

    I uninstalled macaffe as instructed.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but attach the new HJT log for BJ to verify. McAfee and Symantec have habits of not uninstalling properly. Make sure you have no browsers opened this time too.
     
  23. jimrod

    jimrod Private E-2

    latest
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I suspected, all of the McAfee items are still there. Are you sure All of it has been uninstall via Add/Remove programs.

    Manual removal may have to be used.
     
  25. jimrod

    jimrod Private E-2

    the only bit that is there I cannot remove. not sure how to do it manually.
     
  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What happens when try to uninstall via Add/Remove Programs?
     
  27. jimrod

    jimrod Private E-2

    The Macafe uninstall wizard is there but the optioned are shaded and the cannot be highlighted. It has no size next to it either.
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I've seen that before, if your have more than one application installed there is a certain order you have to uninstall them.

    Do you have more than one application from McAfee installed? If so, try to uninstall others and see if it's still greyed out.
     
  29. jimrod

    jimrod Private E-2

    I have no more installed, I took every thing out the greyed ones were never installed.
     
  30. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Your Uninstaller! 2006 5.0.0.221 and save to your desktop. Install and run the program, choose "Pro Mode" when it prompts.

    Locate the McAfee products and uninstall them this way. This will force the removal so this should take care of it.
     
  31. jimrod

    jimrod Private E-2

    Seems to have done it but still on the log
     

    Attached Files:

  32. jimrod

    jimrod Private E-2

    Should I be doing something else?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ will not be around for awhile. I'll try to pickup where he left off.

    I assume what you are trying to do is get rid of all the McAfee stuff so that is what I will start with.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to McAfee WSC Integration (if that is not found, look for the short name: NetDDEsrv)... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above steps to stop and disable for the following services:
    McAfee Task Scheduler ( or if not found, look for the short name: McTskshd.exe)
    McAfee SecurityCenter Update Manager (or if not found, look for the short name: mcupdmgr.exe )

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    McAfee WSC Integration

    If that does not work, use the short name: McDetect.exe

    Now repeat the Delete NT Service steps for:
    McTskshd.exe
    mcupdmgr.exe

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now continue with the below as a double check to make sure all of the McAfee items are removed.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\mcafee.com

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  34. jimrod

    jimrod Private E-2

    Thanks kindly, I do hope the other chap is having a well deserved break.

    Here goes followed all steps, however some things were not there to remove.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is not a vacation! Just a bunch of personal issues!

    But that is what we expected. The HJT log was a double check as I stated.

    Everything looks good now. Are you having any other malware problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds