Help!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by trek2200, Dec 6, 2005.

  1. trek2200

    trek2200 Private E-2

    I truly hope I have followed all the pre-posting instructions as they were many and took quite a while. I really appreciate the help. I have attached the hijack log but the page said my system spec report was too large to attach. I can attach it and the logs from my pre-posting scan if needed. Thanks in advance
     

    Attached Files:

  2. trek2200

    trek2200 Private E-2

    Here is a little of the specs report. Let me know if you need more. Thanks again.


    Computer:
    Operating System Microsoft Windows XP Home Edition
    OS Service Pack Service Pack 2
    Internet Explorer 6.0.2900.2180
    Computer Name MICHAEL (Michael-Office)
    User Name Owner
    Logon Domain MICHAEL

    Motherboard:
    CPU Type Intel Celeron 4E, 2666 MHz (5 x 533)
    Motherboard Name Unknown
    Motherboard Chipset Intel Brookdale-G i845G
    System Memory 502 MB (PC3200 DDR SDRAM)
    BIOS Type AMI (08/18/04)
    Communication Port Communications Port (COM1)
    Communication Port ECP Printer Port (LPT1)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in step 7 of the READ & RUN ME. As a result, you did not install HJT properly and you do not have the proper version of HijackThis. The version you have is very old.

    Make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .

    Also please tell us what problems you are experiencing.
     
  4. trek2200

    trek2200 Private E-2

    I had downloaded the newest version of HJT last night. I then turned around and ran an old version I had downloaded several months ago. Sorry about that. Anyway, I ran another scan and have attached the log. The problem I am having is pop-upsover, and over, and over and over. I actually closed 47 of them from the 8 hours I was at work today. Thanks in advance and again I am sorry about the screw-up on the last log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to srvss safe (or if not found look for srvss) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    srvss safe

    If that does not work try entering the short name: srvss

    Now exit HJT but do not reboot. We will reboot after fixing a few items below by running HJT again.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\srvsc.exe <--- should already be gone due to above steps
    C:\windows\system32\dh9012.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\system32\igps.exe"
    O4 - HKLM\..\Run: [0cw80lwc.dll] RUNDLL32.EXE 0cw80lwc.dll,b 360746000
    O4 - HKLM\..\Run: [dh9012] c:\windows\system32\dh9012.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\i0600ajmedoa0.dll <--- this will come back! Probably renamed. We will get it later.
    O23 - Service: srvss safe (srvss) - Unknown owner - C:\WINDOWS\srvsc.exe <--- should already be gone due to above steps

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\srvsc.exe
    C:\windows\system32\dh9012.exe
    C:\WINDOWS\system32\i0600ajmedoa0.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. trek2200

    trek2200 Private E-2

    IE seems to be working properly but new firefox windows are still opening as tabs in one browser not actually popping up. I have attached a new HJT log. There was one HJT process you mentioned might have a different name. It was not there and there was no C:\WINDOWS/system32\i0600ajmedoa0.dll file to delete. Don't know if that made a difference. Other than that instructions were followed to the letter. Thanks again
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because it renamed itself as I said it would. See your new log. It is now:

    O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\o4ro0e93eh.dll

    Here is what I want you to do. It seems to me like you may be using an old version of SpySweeper. Uninstall it! Then reboot and then follow the instructions in the below thread for using this new version of SpySweeper (make sure you do the update) and post the log as requested.

    Running Spy Sweeper

    Afterwards also attach a new HJT log.
     
  8. trek2200

    trek2200 Private E-2

    I seem to be running fine now. I have attached the HJT log and Spysweeper log. Thank you again!!!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Your log is now clean. If you are not having any other malware problems, it is now recommended that you follow the steps in the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds