I Read The Sticky "read this before..." thread and here is my log...

Discussion in 'Malware Help (A Specialist Will Reply)' started by zachary, Aug 4, 2006.

  1. zachary

    zachary Private E-2

    I tried to run everything I could run in that thread, but for some reason a couple things couldnt dowload, like those 2 windows shownew and getrunkey. Anyways, I have some spyware installed that is really anoying the &^$^% outa me. Im sure its on the harddrive because they pop up even when I am not online. After installing and running all that I could I ran HIJACKTHIS and here is the log...

    Thanks

    Z
     

    Attached Files:

  2. zachary

    zachary Private E-2

    Oh, BTW this is the 2nd log after the first removal process of the obvious stuff.
     
  3. matt.chugg

    matt.chugg MajorGeek

    WHat about the other logs ? Bitdefender, Activescan, Shownew, and Runkeys ?
     
    Last edited by a moderator: Aug 4, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like you ran ALL of the READ & RUN ME. Please run ALL of it. If you cannot run something explain why and what happens. I see no reason why you cannot download and run ShowNew & GetRunKey and you did not run Windows Defender or either online scanner.

    Why are you running without an antivirus program, without an antispyware program, and without a firewall!

    Please attach the below log too!

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  5. zachary

    zachary Private E-2


    First of all chaslang thanks for taking the time to respond :)
    I am not much of a techy at all...so let me apologize for my ignorance first. I run yahoo anti spy and Adaware all the time, I guess that didnt help much...
    Ok to address the points...
    Bitdefender stopped working in the middle, so much spyware was opening that my computer crashed, I am talking about hundreds (yes hundreds) of pop-ups (same thing happened while running panda). I had many spywares and many of them were detected my various anti-spy programs, but many more still remain obviously. Also, I couldn't find system restore on my computer, maybe I dont have that?!? So I did actually run those programs....to be cntd...too many popups...
     
  6. zachary

    zachary Private E-2

    ....contd.... too many popus were happening and I didnt want to risk and IE failure and lose all my typing...

    I am going to try and download windows defender and the other 2 things again now, I hope it works. And I'll post that other log u requested too.

    BTW, thanks so much to whoever helps me. I have spent around 15 hours (no joke, maybe even more :( ) trying to get rid of this crapo. My frustration is very very high, and I am ready to buy a new computer because of this (anyways my current computer is 6 years old)

    THANKS YOU ALL!

    Z
     
  7. zachary

    zachary Private E-2

    here is the uninstall list and an updated hijacklist log.

    Z

    I might have deleted some safe things by accident, I was getting real desperate. I hope it doesnt come back to bite me to hard.


    now I am going to download the other things...
     

    Attached Files:

  8. zachary

    zachary Private E-2

    BTW, I forgot to mention that I did run windows defender, but it didnt seem to find anything or it didnt run at all, I dont remember. I just tried to run it again and it says it needs GDI+ which comes from a windows pack I dont have, eventhough I am up to date with the updates !?! I cant figure it out. I think it ran the first time I tried this morning.
    Anyways here are the other 2 files runkeys.txt and nefiles.txt.


    Z
     

    Attached Files:

  9. zachary

    zachary Private E-2

    I am going to be away from my computer for the next 20 hrs or so, but when I get back I will finish running everything I can

    Z


    If it helps I can tell you the websites that open (or at least some of them)..

    free888.com
    firstadsolution.com
    bannerconnect.net

    among others...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually according to your HJT logs, neither Bitdefender nor PandaActiveScan were ever started. This means the scans themselves were never run. So I assume what you really meant was that you tried to run them but actually never go to the point of actually running the scans.

    It looks to me like you have been experimenting too much on your own and have deleted too many things that you should not have been touching. You HJT is very small and indicates that you have been removing stuff on your own. You are probably looking at a reinstall if things do not work properly. But I will give you somethings to do anyway (even though I'm not sure it is going to help you resolve all your problems).

    First goto Add/Remove programs and uninstall all of the below:
    Java 2 Runtime Environment, SE v1.4.2_06
    KaZaA Media Desktop
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player (Remove Only)

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot your PC but boot into Safe Mode.

    Run Windows Explorer and locate the below files (make sure viewing of hidden files is enable per the READ ME):
    C:\WINNT\system32\bez6n4r21.exe
    C:\WINNT\system32\n9nyb.exe
    C:\WINNT\system32\wnsintsv.exe
    C:\WINNT\system32\winnb58.dll
    C:\WINNT\system32\atmtd.dll.tmp
    C:\Program Files\Common Files\{80DE3EC4-0277-1033-0724-000525200001} <--- delete the whole folder if found

    Now reboot into normal mode and let me know what your status is.

    This PC has no protection software and is going to get re-infected pretty quickly if you don't get it protected ASAP. You should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Aug 5, 2006
  11. zachary

    zachary Private E-2

    chaslang, first of all thank you very very much for helping me. Secondly, I am 100% (most definitely 100% guaranteed) positive that both bitdefender and pandascan started to run and I had to stop them or the computer just crashed in the middle. I really did run them. I am not sure how you see otherwise, but maybe I deleted the files that show that ran afterwards? Is that possible? I dunno, but please believe me, I did attempt to run them and they started to run.


    I will now attempt the other advice you just told me, but I "think" that its "mostly" fixed now and I will certainly read that link "how to protect yourself from malware" immediately and implement those protective measures.

    thx again for ur time,

    Z
     
  12. zachary

    zachary Private E-2

    ps (dumb question probably) what is a HJT log?
     
  13. zachary

    zachary Private E-2

    For some reason the kazaa wont uninstall through that thing but I deleted it a long time ago.
     
  14. zachary

    zachary Private E-2

    Well, I just did all that stuff and rebooted and so far nothing popped-up yet, so far so good.
    The only thing that is still happeing is whenever I open Internet Explorer a window pops up and says "preparing to install Microsoft Office XP with Frontpage". (I must have deleted something important, eventhough MS office seems to be working fine) Anyways, the install doesnt go through because it says it needs something from the original cd which I cant find and might be in a different country right now (due to a move) and it will take me at least a week to get it. I was wondering how I could temporarily turn off Windows Installer or temporarily stop it from trying to install that program?

    So far nothing has popped up yet. Should I wait to make sure I'm clean before going through with that "protecting from yourself from malware" link, or can I do it already?

    Z
     
  15. zachary

    zachary Private E-2

    ok, some stuff just popped up. same stuff as before, just maybe not as many.

    Z
     
  16. zachary

    zachary Private E-2

    yeah, the stuff is still here on my computer...
     
  17. zachary

    zachary Private E-2

    while reading the spyware FAQ. I read about the "trusted sites" thingy with IE.
    well I checked it and there was one thing there:

    ntdll.dll:adgate.info

    I removed it.

    Z
     
  18. zachary

    zachary Private E-2

    I forgot to retry Bitdefender and panda. I will do it now...

    Z
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HJT = HijackThis

    Are you still having problems?
     
  20. zachary

    zachary Private E-2


    Yes, most definitely. Same as before.

    I am running bitdefender right now and one major problem is that I need to be online to run it and I have to sit by the computer for the next 5 hours or so till it finishes running so I can close all the windows that popup. Last time I just let it go for a while and when I came back bitdefender had stopped running and there were hundreds of popups. It seems I need to babysit it.

    Z
     
  21. zachary

    zachary Private E-2

    so far bitdefender has deleted 2 files.
     
  22. zachary

    zachary Private E-2

    Well bitdefender just finished. It said it deleted like 23 files or something...

    here is the log.
     

    Attached Files:

  23. zachary

    zachary Private E-2

    PLEASE somebody help me... I am getting so desperate!!!!

    Z
     
  24. zachary

    zachary Private E-2

    heres the pandascan log and an updated HJT log....

    please pleaaaaaaase help.... I am going nutzzzzzzz here.
    ........... ahhhhhhhh........
    I have been babysitting my computer running these scans for 6.5 hours straight now.

    ps why are the other programs (such as adaware etc... not finding all this stuff that panda found!?!??)
     

    Attached Files:

    Last edited: Aug 6, 2006
  25. zachary

    zachary Private E-2

    the reason that they didnt show up in the HijackThis log is probably because I ran Hijackthis and deleted a bunch of stuff after the bitdefender and pandascan as per the order outlined in the "READ AND RUN ME FIRST"

    Z
     
  26. zachary

    zachary Private E-2

    I am going craa--a-a-zy. pls help as soon as u can...
    anyone?


    Z
     
  27. zachary

    zachary Private E-2

    chaslang, did u give up on me??? :(

    Z
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I just cannot be here all the time and we are very busy. One thing you must learn though is to post once and then wait for any answer. Each time you post another message you are hurting yourself. You send yourself to the bottom of our work queue each time you post. We work from oldest to newest order. When you bump your thread by adding unnecessary messages or to post intermediate incomplete information rather than waiting until your scans are complete, you loose your place and make it take even longer to get an answer. The moral.....don't bump and when you actually have all necessary information to post. If you are running 3 scans, don't post messages saying you are running them and don't post after each scan. When you complete all 3 scans, then post all logs and any other information. You posted 8 messages after my last one! There should have been only one!


    The reason what didn't show up???? What are you deleting? You should only be doing what we give you and nothing else. If you are referring to the Bitdefender and PandaActiveScan lines in your HJT log, you should not be removing them.

    Was this PC upgraded from Windows ME to Windows 2000??? I see files in a _Restore folder which is not part of Windows 2000.

    Start by downloading - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Administrator\Application Data\tvmcwrd.dll
    C:\Documents and Settings\Administrator\Application Data\?asks\rundll32.exe
    C:\Documents and Settings\Administrator\Local Settings\Temp\dia152.exe
    C:\Documents and Settings\All Users\Application Data\SecTaskMan\chkntfs.dll.q_63A4001_q
    C:\Documents and Settings\All Users\Application Data\SecTaskMan\spoolsv.dll.q_63A4001_q
    C:\Documents and Settings\zechariaz\Local Settings\Temp\~187280.tmp
    C:\Documents and Settings\zechariaz\Local Settings\Temp\~19352.tmp
    C:\Documents and Settings\zechariaz\Local Settings\Temp\~632852.tmp
    C:\Documents and Settings\zechariaz\Local Settings\Temp\~972012.tmp
    C:\RECYCLER\S-1-5-21-1085031214-1343024091-1708537768-1003\Dc6.dll
    C:\WINDOWS\Downloaded Program Files\SbCIe01f.dll
    C:\WINDOWS\SYSTEM\freedial.exe
    C:\WINDOWS\SYSTEM\stub.exe
    C:\WINDOWS\TEMP\newnet\kazaa-298.exe
    C:\WINNT\Digital Signature 20020312.htm
    C:\WINNT\Downloaded Program Files\CONFLICT.1\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.10\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.11\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.12\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.2\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.3\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.4\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.4\HDPlugin1019.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.5\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.5\HDPlugin1019.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.6\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.6\HDPlugin1019.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.7\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.8\HDPlugin1018.dll
    C:\WINNT\Downloaded Program Files\CONFLICT.9\HDPlugin1018.dll
    C:\WINNT\inf\alchem.inf
    C:\WINNT\inf\biini.inf
    C:\WINNT\MDialer\Dial05-t5.exe
    C:\WINNT\system32\ezsys.exe
    C:\WINNT\system32\gbhordm.exe
    C:\WINNT\system32\y102-d.exe
    C:\_Restore\TEMP\A0052418.CPY
    C:\_Restore\TEMP\A0064507.CPY
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot, run PandaActive Scan again and attach a new Panda log.

    Make sure you tell me how things are working now! I suspect some of your problems are due to deleting thinsg you should not have been touching. Looks like you even delete a couple files for some Windows Services:
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (file missing)
    O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINNT\System32\mspmspsv.exe (file missing)
     
    Last edited: Aug 6, 2006
  29. zachary

    zachary Private E-2

    chaslang, my bad. I had no idea how it worked. my bad, sry. thanks for being patient with me anyways.
    before I forget...I now have a firewall and I run AVG. Im attaching a new HJT log too. I still have that windows installer problem which Im sure its due to accidentally deleting something from MS Office, as u said, again my bad :( But to get to the important thing....yes the spyware is still here. its still the same exact stuff. I ran panda overnight and had to close about 50 windows this morning. is spyware often this stubborn?

    Z

    p.s. no "pendingfilerenameoperations" prompt came up when running killbox
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this which may help fix your problem with Office:

    Windows Installer CleanUp Utility


    Most of what is in you Panda logs is just backups from what we fixed with Killbox. And a bunch of other items are just cookies which are not problems.

    Run Killbox and click File, Cleanup, and Delete all Backups

    Now run Windows Explorer and locate the below file and delete it:
    C:\WINNT\Digital Signature 20031130.htm

    Now do a new PandaScan and attach the log. Ignore cookies.

    Are you still having actual malware problems? If so, tell me exactly what they are. If they are popups, tell me what the popups say and where they are coming from.
     
  31. zachary

    zachary Private E-2

    I did everything u said. I am attaching the panda log. yeah, its mostly cookies. also, AVG found a couple trojans today. The firewall pops up pretty regularly, like every 5 minutes or so I guess, though it varies a lot, even when I am not surfing the web. not sure if thats normal or not, should I post or send u the IPs that are attepmting access?
    I am definitely still being plagued by malware, mostly popups I guess.

    here are the sites that come up (these are the IE Explorer page titles):

    ad.bannerconnect.net
    ad.firstadsolution
    buycheapadvertising.com
    Powered by ZEDO
    - - (Offering a "free" blackberry or palm)
    Helping Charities Grow
    ads01revenue.net
    ads0.revenue.net
    Netflix ad
    Amazon.com ad (pretty rare, I've only seen like twice today)
    Passion.com ad (by far the most common, like 40 today so far)
    A few "antispy" scanners that I'm pretty certain are not legit and are actual spyware)
    I never click on any of them and just close them immediately.


    Z

    p.s. the windows installer software u gave me fixed the problem perfectly, thanks.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Running Ewido Anti-Malware and attach the requested Ewido log.


    After running Ewido, download the latest version of ShowNew (same link as in the READ ME) and then attach a new log from it.
     
  33. zachary

    zachary Private E-2

    Here are the files. I think there is a newer version of Ewido than what you wrote the directions for, based on 3 things. 1) I didnt have the option to not install any of those parts you mentioned. I even uninstalled and reinstalled again to make sure I didnt miss anything in the installation procss 2) There is no OK to click after you select Scan every file 3) It didnt give me an option while scanning to clean infected files or Remove and backup. Anyays, I hope I did it ok though.


    Z
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay first let's get you version of Sun Java updated. Install this:Sun Java Runtime Environment

    Now run Windows Explorer and look for the below folder and delete it if found:
    C:\WINNT\BDE

    Now also locate and delete the below files.
    C:\Program Files\Internet Explorer\hoxynaga.html
    C:\Program Files\NetMeeting\kybeqi.html

    Now empty your Recycle Bin

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now open Control Panel and select Add/Remove Programs and uninstall the below:
    J2SE Runtime Environment 5.0 Update 6 <--- this is the old version
    KaZaA Media Desktop
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One more thing I forgot to mention! Run Pocket Killbox and on the top menu click File, Cleanup, Delete all Backups.


    Now tell me what problems remain on your PC. If you are still getting popups, describe what is in the popups and give any URLs if they appear.
     
  36. zachary

    zachary Private E-2

    ok, i did all that. so far since I ran ewido there havent been any problems. do u know what the problem might have been and where it came from? also, kazaa doesnt uninstall -- error loading "c:\winnt\system32\cd_clint.dll"

    Z
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had a load of different malware problems! Where they came from only you and the other people using the PC can say. Using Kazaa or anything like it is a major cause of problems like this.

    Try using the below to remove Kazaaa:

    Your Uninstaller! 2006


    If you are not having any other malware problems, you should work thru the below link:


    How to Protect yourself from malware!
     
  38. zachary

    zachary Private E-2

    I will try that Uninstaller. I already read that link very carefully and implemmented everything (except uninstalling MS java cuz I didnt get that, is it a big problem?). Another question in regards to those suggestions. You say to adjust the activex controls, but you also say to use mozilla firefox. why would I need to tweak my IE activex controls if I will be using firefox now? Also, will firefox work for everything? Cuz I tried to watch a video on nba.com and it wasnt working on firefox.

    Thanks so so much again for all your unbelievable help!

    Z
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't have MS Java. You have Sun Java already. See message number 34 where I told you you need to update to the current version.

    You will still have IE on your PC and you will need it for various websites especially Microsoft. Thus you need to make sure IE is configured to be safer. FireFox will be usable most of the time but not always. You will typically get a message from a website if they do not like the browser you are using. Rule of thumb......if you have a problem accessing of downloading etc from a website, quickly try IE to see if it works. There are all kinds of plugins that can be installed to use with FireFox. That is however a topic for the Software Forum.
     
  40. zachary

    zachary Private E-2

    Chaslang, it has been like a week now and no problems with my computer. I really want to thank you and the majorgeeks.com forum for all the unbelivebale help and altruistic work you do.
    I love you chaslang!!! :)

    Z
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy to hear things are still working well! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds