HELP!!!! Somebody please read this.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by speedstar, Oct 6, 2004.

  1. speedstar

    speedstar Private E-2

    I've read and applied the tutorials. I have all spyware, antivirus and adaware installed. I have zone alarm firewall. I have detected w32/Backdoor.CFB w/Stinger antivirus. None of the other programs detect anything before the computer locks up. Stinger locks up also but it tells me that I have the w32/Backdoor.CFB. Upon start up something disables my firewall about 75% of the time. I downloaded symantecs removal tool but my computer locks up about half way through removal. I disabled system restore as instructed by symantec to no avail. I have also ran in safe mode with the same results.

    Could somebody give me some advice. I'm lucky I was able to type this without locking up please help. I'm running windows me.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Hijack This and extract the executable to its own directory.

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!
    You may want to try having no connection to the internet when running your scans (unplug cables to your PC).
     
  3. speedstar

    speedstar Private E-2

    Thanks for the reply. I put HJT in a folder like you suggested but I got a error message saying it was in a temp folder.
     

    Attached Files:

    • hjt.txt
      File size:
      5.4 KB
      Views:
      4
    Last edited by a moderator: Oct 6, 2004
  4. Kodo

    Kodo SNATCHSQUATCH

    you ran the program from an archive.. make sure you put it in it's own folder, go to that folder and then execute the program.
     
  5. speedstar

    speedstar Private E-2

    kodo, I had HJT on my desktop but i deleted it and put it in it's own folder(C:\Program Files\HJT) as you and chaslang directed but I keep getting the message that it has been started from a temporary folder. Any suggestions.
     
  6. speedstar

    speedstar Private E-2

    kodo, I was running hjt from the zip, sorry, here is a new log
     

    Attached Files:

    • hjt.txt
      File size:
      4.8 KB
      Views:
      1
    Last edited by a moderator: Oct 6, 2004
  7. Kodo

    Kodo SNATCHSQUATCH

    sorry to tell you this but you must redo the tutorial again. You did not disable system restore as advised. Disable system restore for WinME , run the tutorial again and then post a new log.

    http://forums.majorgeeks.com/showthread.php?t=35407
    MajorGeeks Support Forums - READ ME FIRST: Basic Spyware, Trojan And Virus Removal.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also I have a couple questions!
    1)Where did Stinger say the virus was? I hope it was not in c:\windows\explorer.exe
    2) Do you know what this is: C:\Program Files\WordWeb\wweb32.exe
     
  9. Kodo

    Kodo SNATCHSQUATCH

    WordWeb I'm pretty sure is Spyware..
     
  10. speedstar

    speedstar Private E-2

    chaslang, I never actually got a log from stinger but when it found w32 it locked up and it was on windows\explorer.exe. This C:\Program Files\WordWeb\wweb32.exe is a program called wordweb it is a dictionary.
     
  11. speedstar

    speedstar Private E-2

    Kodo, I had disabled my system restore. I went back and read the tutorial as you advised, repeated the steps and the "disable system restore" was checked.
     
  12. Kodo

    Kodo SNATCHSQUATCH

    ok,
    please post a new log
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All I new of it is that it is supposed to be a free theasaurus and dictionary. I have no idea if it is spyware or not. But usually anything like this that comes for free, comes with baggage.
     
  14. Kodo

    Kodo SNATCHSQUATCH

    did some more searching and I could not verify this to be true. I was not able to download the file here to test. I removed the entries from the LoJack database for now.
     
  15. speedstar

    speedstar Private E-2

    sorry it took so long. My system's been locked up. Here is a new Logfile of HijackThis v1.98.2

    log
     

    Attached Files:

    • hjt.txt
      File size:
      5.4 KB
      Views:
      3
    Last edited by a moderator: Oct 6, 2004
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Speedstar,

    Please do not post logs inline! Always post them as attachments. You must give them a different name each time.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there a reason why you did not run the TrendMicro online scan as the tutorial requests?
    Please run it?

    Also do you know why this Norton Preload utility is running at startup and why it needs a file from your floppy drive?

    O4 - HKLM\..\Run: [NAV Premend OEM Utility] A:\0107301.SYM\PREMEND.EXE -silent


    You can fix the three below lines using HijackThis
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)

    Then go to the link below and run the removal tool (FxAgentB.exe)
    http://securityresponse.symantec.co...moval.tool.html

    The link to the tool is in the first sentence of the above link. Instructions are there too.

    Let us know how this works.
     
  18. speedstar

    speedstar Private E-2

    chaslang, I'm not sure how to post log's as a attachment. I have not ran trendmicro yet. I think I might have tried a few day's ago but system locked up. I will try again now. I have no idea about the norton utility. I think I got that upon trying to do a online scan the other day.
     
  19. speedstar

    speedstar Private E-2

    chaslang, I tried running trendmicro. I can't get through it without my computer freezing up. It is the same thing with every anti-virus, spyware, adaware, ect.. program that I run. The only one that even told me I had w32/backdoor.cfb was stinger. I will remove the 09 entries as per your request.
    I have ran the fxagent b several times with the same freeze up problems. I will try again.
     
  20. Kodo

    Kodo SNATCHSQUATCH

    make sure you run the fxagent in safe mode.
     
  21. speedstar

    speedstar Private E-2

    Kodo, I ran fxagent in safe mode, same problem. I have ran all of the program's in safe mode, same problem.
     
  22. Kodo

    Kodo SNATCHSQUATCH

    speed star.. sit tight for a bit. Chas and I are discussing some other options. You and another person have a nasty that we are having difficulty helping to remove.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As Kodo said, we are looking into a couple issues like yours which are very difficult to fix. In the mean time I want you to do the following:

    Download ProcessExplorer from: http://www.sysinternals.com/files/procexp9x.zip

    Unzip it and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.


    To post attachments you need to click the Go Advance button under your message window. Then scroll down until you see Manage Attachments and click that button. Then click Browse... locate the file on your PC (make sure you save it to a file ending in .txt) then click the upload button. Then close the Manage Attachments window and Submit your message.
     
  24. speedstar

    speedstar Private E-2

    Chaslang, Kodo, sorry about the delay, here you go:
     

    Attached Files:

  25. speedstar

    speedstar Private E-2

    Chaslang, Kodo, are you guy's still looking at this?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes,

    I could not see anything strange. But please remember not to run programs from inside the ZIP files. You had WinRAR running ProcessExplorer from the ZIP.

    Could you please download, install and run a-squared (a²) Free edition 1.2
    It's free but requires an email address for registration.
    Let me know if it finds anything.

    Also run these and tell me the results:
    TrojanScan online scan
    ADS SPY - Alternate Data Streams Spy from Merijn
     
  27. speedstar

    speedstar Private E-2

    chaslang, I ran a-squared and it locked up. This is frustrating. I'll try the other 2 you listed.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try running it in safe mode? Also when running it, try shutting down all applications that you can. No browsers running and close everything that is in your tray down (even other virus applications - you can physically disconnect you PC from the internet to protect yourself while all these things are shutdown).
     
  29. speedstar

    speedstar Private E-2

    I did'nt run in safe mode but I will do it now. I will also shut down all of my application's as you suggested. Let me ask you something, I have 112mb of ram if I add more ram to my system will that allow my computer to get through a scan any easier.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a rather strange amount of memory to have. Memory is pretty cheap these days and it is always good to have more. Whether it would allow you to complete scans any easier, I cannot say for sure. But make sure you disable you other virus scan application (for this current issue) otherwise for each file accessed by A2 two scans will occur, thus making it take longer.
     
  31. speedstar

    speedstar Private E-2

    well I guess what I meant to say was I have 128mb of ram and windows is using 14-16mb so in essence I have 112 free. Anyway I ran A2 in safe mode and it got through about 100,000 objects and locked up. I left it there for about a hour to see if it would move. It didn't. So I don't know what to do.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you shut down all other application, especially virus/spyware scanners, when doing this?

    Did you try these yet:
    TrojanScan online scan
    ADS SPY - Alternate Data Streams Spy from Merijn

    Also in normal boot mode, run Ad-Aware SE and click Scan now but select Perform full system scan. Fix anything it finds (let me know if it does find anything).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds