How do I know if I'm clean and secure

Discussion in 'Malware Help (A Specialist Will Reply)' started by wannabeageek, Dec 18, 2005.

  1. wannabeageek

    wannabeageek Private E-2

    I have done all the steps on Read and Run Me First (quite a few times). For some reason the steps wouldn't clean my cpu completely until recently. I have had problems with the Coolwwwsearch ... run the CWShredder to try to kill this off with success. My computer was fine, another words no hijacking of my homepage, but a few weeks later and my cpu started running very sluggishly. That's when I started the whole process of cleaning my cpu over again. I seem to be back in action, but I'm not sure how to tell if my system is completely clean. I am currently running Avast home edition for my antivirus and Microsoft antispyware, as well as running Zone Alarm for my firewall needs. I have turned off my Windows firewall. Just curious as to how I know if I'm clean, secure, and clear. Today, I started having problems with my System Idle ... not sure where that came from, but I couldn't surf the net due to the fact that the System Idle Process was taking up 99% of my cpu usage.:eek: I feel like I am losing it here!LOL.

    On a side note: How do I know what programs are running on my system? How do I look at which programs are staring when I start my cpu? I guess what I'm looking for is a way to do my surfing without any unnecessary programs running. Any help would greatly be appreciated. Thanks.:confused:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Idle is not a process. It is the time your CPU spends relaxing. Thus having it at 99% is good.

    Task Manager will show most of your running process (not always) but it will not show everything the loads at startup. Msconfig will also show some items that load but is also not going to show everything.

    If you think you have malware problems, make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. wannabeageek

    wannabeageek Private E-2

    Thanks for the help Chaslang. I ran Hijackthis and I'm attatching the log file.

    System Idle Process was the "image name" that I read off of the task manager.:confused: Just trying to make sure I'm calling it by the right name. Anyhow, maybe it had nothing to do with surfing the web. For some reason my server couldn't be found. I thought System Idle might have something to do with it. My server was available for about 15 minutes and then it would freeze up ... and nothing would work.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said, System Idle Process is not a process. It is just how much idle time your processor actually has remaining. It shows in Task Manager just so that is easy to see how much free CPU time you have left.

    I don't know what you mean your server cannot be found. What server are you talking about? Are you saying you are getting a message while trying to surf about a server being unavailable? That could be:
    - due your ISP
    - due to the site you're trying to connect to
    - or it could be due to malware.

    I do see some malware and I'll post a fix soon!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You appear to be running both Avast and Symantec antivirus programs. You must use only one and uninstall the other as per step 3 in the READ & RUN ME. However it looks like Symantec may be partially uninstalled. Had you previously tried to uninstall it?

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {798A115F-4CDC-085F-69E2-7E5DD1711A21} - C:\WINDOWS\sdkaj32.dll (file missing)
    O2 - BHO: Class - {7E138803-B04F-E7FE-F90D-174F78CA6C63} - C:\WINDOWS\appso32.dll (file missing)
    O2 - BHO: Class - {89AD1952-81D3-510D-278A-AD565369AC73} - C:\WINDOWS\ntdc.dll (file missing)
    O2 - BHO: Class - {9341B059-25B9-C093-AEB4-FF0CB478B147} - C:\WINDOWS\sdkyz.dll (file missing)
    O2 - BHO: Class - {954026FA-30BA-49A8-99A7-1546227CFE9F} - C:\WINDOWS\winit.dll (file missing)
    O4 - HKLM\..\Run: [ipbi.exe] C:\WINDOWS\system32\ipbi.exe
    O4 - HKLM\..\Run: [creu.exe] C:\WINDOWS\system32\creu.exe
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):

    C:\WINDOWS\sdkaj32.dll
    C:\WINDOWS\appso32.dll
    C:\WINDOWS\ntdc.dll
    C:\WINDOWS\sdkyz.dll
    C:\WINDOWS\winit.dll
    C:\WINDOWS\system32\ipbi.exe
    C:\WINDOWS\system32\creu.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. wannabeageek

    wannabeageek Private E-2

    I did try to uninstall symantec at an earlier date. I went back and did a search through windows for symantec and deleted all the files that I found. I also tried to "fix" the symantec files I saw on my hijackthis log. Some still seem to be there.
    I followed your message, fixing the files through hjt and reset my web browser. I ran hjt again and am posting the log. My system seems slow still, but I think I need to do some house cleaning. I'm looking for that lean mean fighting machine that I once knew. Thanks again for your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well let's first try the simple method of fixing the Symantec stuff and if HijackThis complain, we will do the longer method.

    Run HijackThis and select the below lines and click fix:

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
    O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
    O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)

    Did it work or did it complain?
     
  8. wannabeageek

    wannabeageek Private E-2

    No complaints from HJT ... the files just said they weren't going to budge. I tried to fix the files a few times and they would not delete. Rescan results after fixing showed them still there.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Symantec Event Manager (if that is not found use the short name ccEvtMgr ) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.


    Now repeat the above for each of the below services (the short name is noted in the ( ):
    Symantec Password Validation Service (ccPwdSvc)
    Norton AntiVirus Auto Protect Service (navapsvc)
    ScriptBlocking Service (SBService)
    Symantec Network Drivers Service (SNDSrvc)
    SymWMI Service (SymWSC)

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Symantec Event Manager

    If the long name is not found, use the short name: ccEvtMgr

    Now repeat the above for each of the below services (the short name is noted in the ( ):
    Symantec Password Validation Service (ccPwdSvc)
    Norton AntiVirus Auto Protect Service (navapsvc)
    ScriptBlocking Service (SBService)
    Symantec Network Drivers Service (SNDSrvc)
    SymWMI Service (SymWSC)


    Now exit HJT and reboot. After reboot, verify that all the O23 service lines no longer appear.
    How are things working now?
     
  10. wannabeageek

    wannabeageek Private E-2

    All symantec line 23 items were gone on reboot. I uploaded the log.
    Everything seems to be running fine. Haven't really test-driven it since the fix, but I'll get back to you on that. I think it's time to wade through and get rid of some dead weight.

    Thanks for helping me get rid of that stubborn Norton. He just didn't seem to want to say goodbye. I do feel like I'm on the right track!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds