Help with WinInetHook Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by swalsh19, Aug 17, 2006.

  1. swalsh19

    swalsh19 Private First Class

    I have tried everything to be rid of this stupid thing. i have run all the scans you ask, with exception to Windows Defender as I'm receiving an error that it can't update. I have uninstalled and re-installed 3x with same error.

    Microsoft Malcious Removal Tool said it deleted the file but I ran the virus scans and Activescan found it and deleted it again, and Bitdefender found it but couldn't do anything...

    Please help I would appreciate it.
     

    Attached Files:

  2. swalsh19

    swalsh19 Private First Class

    Other files...
     

    Attached Files:

  3. matt.chugg

    matt.chugg MajorGeek

    Did you try running counterspy instead of windows defender ?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks.

    Note if you can not run Windows Defender the READ ME tells you to run CounterSpy and attach the log from it. (Uninstall Windows Defender first before using CounterSpy!)

    Also you did not attach the log for Bitdefender properly as the directions in step 7 indicate. You only posted a log summary which is not useful. Don't worry about re-running it now as it would not find anything to report. But in the future you must follow the directions exactly as they are written or you will get the wrong log.


    Sorry Matt! Did not see you here!!!
     
  5. swalsh19

    swalsh19 Private First Class

    Thanks guys fo he replies. My bad on the Counterspy... Geez that ooks like the old Microsoft Anti-Spyware program. Is this where Microsoft got it from?

    Anyhow I ran the Counterspy and it found some registry keys, no files infected. I re-ran the Bitdefender and it found a different file then last time infected with the WinInethook infection. It successfully deleted it. I was hoping maybe it would find the file it couldn't fix last time.

    Anyways any help would be appreciated. I was reading another similiar posting and you got them to run the SmitRem file. I was thinking of doing this myself, but I thought perhaps I should wait for your response first.
     

    Attached Files:

  6. swalsh19

    swalsh19 Private First Class

    I re-ran Hijackthis, newfiles and runkeys attached in case needed...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not allow CounterSpy to fix what it found. Please run it again and this time make sure you fix the problems instead of ignoring them.

    Then download and install the current Sun Java version: Sun Java Runtime Environment

    Now goto Add/Remove programs and uninstall the below:
    Java 2 Runtime Environment, SE v1.4.2_05


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Reboot into safe mode and delete the below files:
    c:\windows\switchagreement.txt

    Now while in Safe Mode disable System Restore (read the instructions in step 1 of the READ ME). Then reboot into Normal mode and enable System Restore.

    Now tell me how things are working
     
  8. swalsh19

    swalsh19 Private First Class

    Seems like everything now is running fine with one exception.

    Windows Defender will not update. I have tried the version here at majorgeeks and the one directly from Microsofts site. They both come back with this error.

    I'm thinking this maybe a BETA issue... I may just look into getting Counterspy as it works well!!!


    Thanks again! BTW: Is there a spot to donate to the website for this service?


    Steve
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below! It works sometimes!
    1. Remove the current signature file. To do this, click Start, click Run, then copy and paste in the following bold print text to avoid a typing mistake and then click OK!
      • Msiexec /x {A5CC2A09-E9D3-49EC-923D-03874BBD4C2C},
    2. Open Windows Defender. To do this, click Start, click Programs, and then click Windows Defender.
    3. Check for new definitions. To do this, click the Help options arrow next to the Windows Defender Help icon, click About Windows Defender, and then click Check for Updates.
    If that does not help, check out some of the below links (the above appears in them too):
    http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=395648&SiteID=2
    http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=368240&SiteID=2

    Or even use this that searches MSDN for the error number:
    http://search.microsoft.com/results.aspx?mkt=en-US&setlang=en-US&q=0x80240022


    Also try updating after disabling any firewall or antvirus software that is running!


    Not via the website! Many of us do have PayPal accounts where you can donate if desired. You would have to PM me with an email address and I could send you the info. It's purely optional!


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Aug 18, 2006
  10. swalsh19

    swalsh19 Private First Class

    OK I fixed the BITS non-running error, and it looks to be quite popular. maybe you may want this for a sticky...


    As noted an a previous post of a link to a batch file, I just created it, ran it and hey presto, bits service could be started

    run notepad and paste into it the following lines

    regsvr32 oleaut32.dll
    regsvr32 jscript.dll
    regsvr32 vbscript.dll
    regsvr32 msxml.dll
    regsvr32 softpub.dll
    regsvr32 wintrust.dll
    regsvr32 initpki.dll
    regsvr32 cryptdlg.dll

    save the file as c:\fixbits.bat

    command prompt and run c:\fixbits.bat, it will pause on each line then you get a regsvr windows dialog with confirmation, IMPORTANT NOTE, it took almost 20 seconds to register initpki.dll

    once batch file has run then type

    NET START BITS

    and, as in my case, all is successful the service will show started successfully and running windows update AT LAST got the updates

    Hoooooraaaaahhhh !!!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We already have one sticky procedure on a related fix: Fixing Windows Update Problems (Win 2K and XP)

    This is really not a malware forum topic though and we cannot afford to have the whole page for each viewer filled with nothing but stickies. Thus the above link and about 80 more are hidden in the Malware Forum. We just give links to them when necessary.

    I'm happy to hear you got your problem fixed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds