I have something I can't get rid of!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by abbyg, Mar 19, 2005.

  1. abbyg

    abbyg Private E-2

    AHHH!!! I am infected yet again!!! I just went through this about a week or two ago and I can't believe I have already gotten another bug! Avast! is going insane and I can't stand it! MajorGeek friends, I NEED YOUR HELP!!! I went through Major Attitude's virus removal post and I have had zero results! This is a major problem! I was just about to install a Windows XP upgrade, because I am not protected enough (I haven't been able to install the service pack due to somebody downloading pirated XP on my computer without my consent). Anyway, I don't even know what is wrong, except for that I believe something in the System32 folder is infected. Avast! just keeps popping up, not allowing me to do ANYTHING on my computer without telling me there is a virus a million times. Thanks for your help, friends!

    Abby
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Lets see if I can help you without AbbySue chewing me out for it :p HAHA!


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. abbyg

    abbyg Private E-2

    Ok, I am attaching the log file. What a mess my computer is! I have so many messages popping up on my computer telling me that there are infections, I can hardly even get here to post! It's awful. I don't even know what happened either. I was looking for a picture of something on a search engine and I clicked on a site and all of a sudden my computer was loaded with something! How awful. Anyway, just to update you from the last time we chatted, Bjgarrick, just after we finished with my last problem, my fiancé's computer crashed due to a bad memory stick, so we found ourselves shopping around at CompUSA and Best Buy and while we were at Best Buy, we found a $40 upgrade for Windows XP Home Edition, so we each bought one (he, coincidentally, also has a pirated version of XP and therefore cannot download the service packs). Anyway, we didn't even get a chance to download these things before I got infected again! Geez. Well, thanks for your help, yet again!

    Abby
     

    Attached Files:

  4. abbyg

    abbyg Private E-2

    By the way, I don't think AbbySue ever read the message I sent her. :(

    Abby
     
  5. abbyg

    abbyg Private E-2

    How come it says "unread" then?
     
  6. AbbySue

    AbbySue MajorGeeks Administrator

    *sigh* Because my security settings don't even so much as give me the option to confirm or deny.

    As for replying...the topic was closed and not up for discussion.

    Please resume the original topic of this thread "I have something I can't get rid of!!!".
     
  7. abbyg

    abbyg Private E-2

    No kidding! Can I get some help? My computer is a total mess! Thanks again, friends!

    Ab
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Abbyg,

    When you previously were here with a problem. BJ posted in one of his messages the following:
    You should have done all of that. You still have not updated your OS and IE versions and are going to continue having problems unless you do that. You now have an HSA hijacker problem. And you need to begin by following the steps in the READ ME FIRST. Step 2 of Getting Prepared discusses stoping and disabling the Network Secuity Service. You need to do this. The line that shows this service in your HJT log is:

    O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\ipva.exe
     
  9. abbyg

    abbyg Private E-2

    Ok, as I said previously, I did look at AND DO EVERY STEP OF Major Attitude's post - the READ ME FIRST deal. I have never posted on here without doing those steps first. I have not been able to update my OS, due to somebody downloading a pirated version of Windows XP on my computer. I JUST went out and bought an upgrade that I think will solve this problem, but I need to talk to Microsfot before I do anything with that. I'm not really sure what the problem is with IE, but I have been mostly using Opera. I have been here more than just that one time for help and I have looked at and followed the steps in both of those posts before. I guess I tried to make that clear when I started this thread, because I knew that at least one person would try to tell me to look at those posts, even though I thought I had followed all the steps. I guess I will try to go back and do it all again. I am just so sick of this crap being on my computer every time I try to do something. Sigh. Thanks for your help.

    Abby
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    abbyg,

    I apologize for any inconvenience you may have experienced here. I will let Chaslang handle you from now on so nothing will go wrong. Good Luck and I hope you get fixed up.

    Best Luck
    Bj:)
     
  11. abbyg

    abbyg Private E-2

    Thank you, friend! Well, I went through the whole thing again and it appears to have worked a little better this time around. Let me know if you would like me to post a log file - just to be sure! Thanks again!

    Abby
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, go ahead and post a current HJT log for Chaslang.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ,

    You could have continued with this. I was just trying to get abbyg started by seeing if she could stop and disable the NSS process.

    Abbyg,

    What do you mean it worked a little better this time? Were you able to end the NSS?
    Post your HJT log and let's see where you are at?

    As far as you inability to update, you are going to have to address this issue. Which will mean getting a legal copy of WinXP installed. If you keep running with this old version and no updates, you will constantly be having malware problems.
     
  14. abbyg

    abbyg Private E-2

    Well, I am not getting constant pop-ups from Avast! telling me that I have viruses. Actually, I have gotten none so far. I have posted my HJT log for you to take a look at. I am addressing, as I mentioned previously, the problem with XP. I just need to talk to Microsoft (hopefully tomorrow) to make sure it will be ok to install the XP upgrade, and then I think I will be able to get the service packs and all that jazz. I know how important that is! Anyway, thanks for spending your time helping me, guys!

    Ab
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You didnt attach anything?
     
  16. abbyg

    abbyg Private E-2

    Very true, BJ! I thought that I had, but I guess not. Ok, here it is... for REAL!

    Ab
     

    Attached Files:

  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    We appreciate your help but we do not assist users by PM or any other means. We help everyone in the forum by posting in these threads so stick to this please. Also, we have started this thread so we would appreciate if you would let us finish it.

    Thanks!
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Abby, I dont see any problems in this log except for this line below. Other than this you look ok. Also, was you able to disable the service Chaslang mentioned earlier?

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R3 - Default URLSearchHook is missing


    FINAL STEP

    Reset Web Settings & Default Security Settings:


    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK


    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.
     
  19. abbyg

    abbyg Private E-2

    BJ,

    Hooray! Yes, I was able to disable that NSS thing, by the way. I will attach my HJT log once again so you can make sure I did what I was told! ;) Thanks so much, yet again, for helping me with my endless computer issues, BJ, Chaslang, everyone who pitched in! I will call Microsoft TODAY with my questions so that I can hopefully be on my way to making the OS safe! Thank you, thank you, thank you!!! Take care and let me know if I need to do anything else!

    Abby
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right now your log looks clean Abby! Are you having any problems at the moment?
     
  21. abbyg

    abbyg Private E-2

    Nope! I feel as clean as I look! The only thing that has happened (and this could be random) since we were working on this problem is that every so often (and sometimes repeatedly and very often) my mouse cursor will temporarily freeze for a few seconds and then start to work again. This is very annoying!!! I haven't tried re-booting the computer yet though, so maybe that would fix it. I have to run out the door to work, but I will try a re-boot and let you know if that fixed it when I get home, otherwise, if you know why that might be happening, I would love to know! Thanks again for all of your help (that is to everybody who took a look at this thread)! Computer illiterate folks like me really appreciate smarties like all of you!

    Abby
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have seen issues like mouse freezing on some PC that were due to some of the scanning type tools that were install. However this happened more frequently on older OS PC's (like Win9x). I found on two identical PC's running Win98Se, one would freeze for a couple seconds every 30 seconds or so and the other would not. Again they were identical in hardware and software. After stopping SpySweeper on the one that had freezes, the mouse freezing no longer occurred. If your freezing problem happens frequently enough, you should be able to find if another item is causing it by slowly ending applications using Task Manager until the problem goes away.
     
  23. abbyg

    abbyg Private E-2

    Sounds good. Will do! I have only been on my computer for a couple of minutes so far and it hasn't done it yet, but if it starts, I will try doing that. Strange that it had never done it up until this point with the same scanning tools on my computer, but I trust you. I did have to re-download a couple of things. Maybe it is one of them. Thanks again for all your help!

    Abby
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The problems that I noticed were normally very reproducible. They almost always occurred on the PC where it was a problem. So you could have a different issue. It could be some kind of software conflict. Shutting down each running application could help to located the problem but only if it is occurring regular enough to debug.
     
  25. abbyg

    abbyg Private E-2

    I can't seem to figure out what is making my cursor freeze like that! Sometimes it doesn't really do it and then sometimes as soon as it unfreezes, it freezes back up again! It is so annoying! Is there anything I can do to fix this? I tried disabling every program I could, I think and I re-started my computer, just to be sure. What else is there? :mad:

    Abby
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What and how did you disable the programs?

    What I wanted you to try was shutting down (using Task Manager) evrything while the problem seemed to be occurring to see if there was an effect. Rebooting is not what you want to do since you have said that it clears the problem.

    It is hard to diagnose problems like this unless they occur frequently enough to experiment on.
    Does it ever happen if you stay in safe mode?
    Does it only happen if online?
     
  27. abbyg

    abbyg Private E-2

    I disabled everything that wasn't neccessary to run my computer.

    Yes, I used the task manager and clicked on things and then on "End Process". It was still freezing after I shut everything down. I tried doing things one at a time. Nothing was helping, which is why I shut down the computer (well, re-started it). You misunderstood me. I never said that it cleared the problem when I rebooted the computer. I said that I had never tried doing that and maybe it would help. I tried doing that after I tried disabling all those other programs. It did NOT help anything. Upon re-booting, the cursor still froze MANY times. That was when I posted my last response on here to you.

    This problem DOES occur frequently enough to experiment on - that is why it is so annoying! If it was just once in a blue moon, I would probably just deal with it. I have never tried being in safe mode, so I am not sure if it happens there or not. It was not happening, to my knowledge when I was in safe mode fixing the spyware problem though. I have a cable internet connection, so my computer is always online. Therefore, I guess I haven't really tried being offline either. Should I try being in safe mode and being offline? Grrr... the cursor just froze again.

    Abby
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay if if happens often enough, then first try running in normal mode with your cable from the cable mode to your PC disconnected (physically you are now offline). Run for awhile doing some stuff (obviously no web access stuff). See if it still happens.

    If so, then try booting in safe mode (still no cable plugged in). Does it still happen?
     
  29. abbyg

    abbyg Private E-2

    I ran the computer in normal mode with the cable unplugged. It still happened. I put the computer in safe mode with the cable unplugged. It still happened. I hope that is not a really bad sign! :( What now?

    Abby
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have another mouse you can try?
     
  31. abbyg

    abbyg Private E-2

    I do as a matter of fact, and it would appear that it must have been something with the mouse or something, because I have tried two others and they both seem to be working fine. I have only had that mouse for two years or so. It is an HP USB optical mouse. Do optical mouses (mice?) have a really short life span or something or do I need to update drivers or what? My fiancé said that he has had bad luck with opticals, so I was just wondering about that. Anyway, thanks for helping me pinpoint the problem!

    Abby
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no experience with them. You could check in the Hardware Forum.

    But at least we are all fixed up. Right?
     
  33. abbyg

    abbyg Private E-2

    Right. My computer is fine. Thanks again for your help!

    Abby
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Abby! I'm happy we got this all worked out.
     
  35. abbyg

    abbyg Private E-2

    I just thought I would let you know that the hardware folks got me all straightened out and my mouse is now working just fine. You guys are awesome!!! :D

    Abby
     
  36. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Glad you got it working abby! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds