It's almost so stupid that it's funny..

Discussion in 'Malware Help (A Specialist Will Reply)' started by TroelsM, May 17, 2005.

  1. TroelsM

    TroelsM Private E-2

    Yes. Youre right. One should not open clips from unknown sources, but i did anyways. Or maybe i F***** up in a nother way, but the thing is that I got the About:Thingy again. I dont know if there´s any other problems, because SG probably removes some of the S*** before I see it...

    I got a ton of antispyware that hos safed my computer from a total breakdown but I still get a warning from SpywareGuard every 5 minutes saying that something has been blocked...

    I followed the thread about removing the damn thing but it dos'nt seem to work as the problem keeps comming back.

    I'm writing my final Thesis ( 2 weeks left) and I need help now! -please..
    Tell me what to do. I need my computer 3 more weeks.

    Please xcuse my poor english.

    TroelsM
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. TroelsM

    TroelsM Private E-2

    Hi.

    I have done so, but th tutorial did'nt help me fix the problem. The online scan from Symantec (Symantec Security Check) found a few things but i could'nt do anything to remove the found objects? I ran It all in safe mode and my screen-res in safe mode is only 400*600 (or somethinf like that). I wonder if there were an "remove"-button "outside" my screen... can the Symantec Security Check be done in normal mode?

    Other than that everything worked fine. ( I'm still having problems, but the tools worked, -maybe..).

    HSRemove found 8 things that were fixed, but the next scan also ends up with 8 "new" things.

    I tried to remove some things with Hijackthis, but the each time i run HJ there´s a lot (5-10) of R1's, an 02 and the R3 "Default searchhook is missing"

    I hope this helped.

    TroelsM
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME FIRST is not always going to fix all problems but it does remove many things and gets systems into a known state to work from thus making our jobs easier.

    Complete the steps in my instructions.
     
  5. TroelsM

    TroelsM Private E-2

    Ok. I will do so.

    I will attach a HJ-log to the next post.

    What about the problems with the Symantec online scanner? I cant see if is supposed to find and fix problems og just find them? Am I missing something here?

    TroelsM
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about it! Just finish the other steps.
     
  7. TroelsM

    TroelsM Private E-2

    Ok. Back again.

    I have done all steps in the "Read-me-first" and made i HJ_Log.

    Spybot found these 4 things.
    -CoolWWWSearch.Aff.Vinshow
    -Winpup
    -Startpage
    -UrlSearchhook.atlpz

    CWShredder and Kill2Me didnt find anything

    HSRemove found 10 things the first time and 8 the next.

    After running HSRemove i started i browser and were send to a HS-removed-page-thingy, so something probably worked.

    So, what do I do now?

    TroelsM
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hijackthis logs must be from normal boot mode.

    Note: HSremove and about:buster are only to be run for HSA and about:blank hijack problems which you do not have. You would know if you did.
     
  9. TroelsM

    TroelsM Private E-2

    Ok.

    Ok, something is still not right, i guess... I still get a lot of warnings from Microsoft Antispyware but I dont know if its beacuse the virus is gone and now some of the IE settings have been changed back to normal?

    Some of the HJ_entries dosn't seem right, but I won't delete anything before you have seen it. So here it is.

    And thank again.

    TroelsM
     

    Attached Files:

  10. TroelsM

    TroelsM Private E-2

    Just reboot'ed ( dont know the english term or spelling). There is definetly (that wrong too, right?). There is still something wrong and the about:blank homepage is not completely gone.

    Please help.

    TroelsM
     
  11. TroelsM

    TroelsM Private E-2

    Just got an "Only the best" -popup... that´s not good, right?

    TroelsM
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now you see why I wanted the log from normal boot mode. Now I do see why you were running HSremove. You do have an HSA hijack problem. It just was not showing before in safe mode.

    After we fix your current problems you must get your Windows updates. You are way out of date and that represents a major security risk to you.

    Make sure you have System Restore disable and you have viewing of hidden and system files enabled per the READ ME FIRST.

    You need to print or save these instructions locally because after this reading this sentence you will need to physically unplug your connection from your cable, ADSL, or dial-up modem to your PC and then you MUST exit all browsers and DO NOT run any again until requested.

    Okay, unplug your internet connection and exit browsers now!!!!

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:

    regsvr32 /u C:\WINDOWS\syssd32.dll

    then click OK. If a dialog box confirming this action appears, click OK. If you get an error message, just OK out of it and continue.


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\mfctg.exe
    C:\WINDOWS\system32\msvj.exe

    After killing those processes click the Back button and just leave HijackThis running while you do the next steps (we will come back to it).

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Network Security Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now back in the HijackThis window, click the button that labeled 'Delete an NT Service" . Now copy/paste the following into the box that opens, and press "OK":

    Network Security Service

    Okay now exit out of HijackThis.

    Now restart HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (I'm double checking to make sure they have not restarted which they do sometimes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\mfctg.exe
    C:\WINDOWS\system32\msvj.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (DO NOT OPEN ANOTHER BROWSER UNTIL AFTER POWER DOWN AND POWER UP, see below):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\htgyi.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\htgyi.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\htgyi.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\htgyi.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qyqad.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\htgyi.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\htgyi.dll/sp.html#37049
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {EE624C92-92FD-079F-E433-D27DEE7419AF} - C:\WINDOWS\syssd32.dll
    O4 - HKLM\..\Run: [netbt.exe] C:\WINDOWS\netbt.exe
    O4 - HKLM\..\Run: [msvj.exe] C:\WINDOWS\system32\msvj.exe
    O23 - Service: Network Security Service - Unknown - C:\WINDOWS\system32\d3jr32.exe (file missing)

    Then exit HJT after clicking FIX

    Run Windows Explorer and look for and try to delete the below files:
    C:\WINDOWS\mfctg.exe
    C:\WINDOWS\system32\msvj.exe
    C:\WINDOWS\system32\htgyi.dll
    C:\WINDOWS\syssd32.dll
    C:\WINDOWS\netbt.exe
    C:\WINDOWS\system32\d3jr32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. If you cannot find or delete them, note which ones and continue (tell me the results when you come back here).

    - Run about:Buster and save the log to ab1.log (make sure you let it do the second scan).

    - NOW PULL THE POWER PLUG TO YOUR PC! Yes, you read that correctly. This is very important! I do not want you to power down the normal way.

    - After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

    - Now use the same procedure as above to try to delete any files that would not delete in the above step. Note any that still do not delete and continue.

    - Empty your Recycle Bin and delete all files in the c:\windows\prefetch folder. In fact as an additional measure do the following, run Ccleaner that you installed while running the READ ME FIRST.

    - Run HSremove and then run about:Buster again and save the log to ab2.log (let it do second scan)!

    - Immediately after about:buster completes, reboot in normal mode. (you do not need to pull the powser plug here. Just reboot.)

    - Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    - Plug your cable to the internet back in now.

    - Open and close a couple of IE sessions and then with IE closed get a new HJT log.

    - Now come back here and post both about:Buster logs and the new HJT log. And tell me what happened during the procedure.

    Let me know anything else that you notice.
     
  13. TroelsM

    TroelsM Private E-2

    Ok, I might be a bit slow today, but i cannot find a button labeled "Delete an NT Service" in HJ-This. Where is it?

    TroelsM
     
  14. TroelsM

    TroelsM Private E-2

    Crap! My bad. I was using an old version of HJ-This. Hope this dos'nt affect anything else.

    TroelsM
     
  15. TroelsM

    TroelsM Private E-2

    Hi again.

    when I tried to delete "Network Security Service" with HJ-This I could not do so. Aperently ( spelleing?) HJ-This could not find the file.

    The files netbt.exe and d3jr32.exe was'nt in the folder. All the others were deleted in normal mode.

    The AB-logs were safe'd as the same filename. I could not cahnge the name.

    The AB-log and HJ-Log is attached.

    TroelsM
     

    Attached Files:

  16. TroelsM

    TroelsM Private E-2

    hi

    It seems that I cant get rid of the about:blank homepage. I actualley think that it i´s one of the protection programs that wont let me change the page.

    Other than that everything is fine now.

    TroelsM
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It maybe that Regfreeze and/or Microsoft Antispyware are blocking the changes. You must either figure out how to disable their protection or you may need to uninstall them to do the final fixes. Uninstalling may be the best thing to do. You can reinstall them after making the fixes.

    The below lines need to be fixed:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qyqad.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qyqad.dll/sp.html#55135
    O23 - Service: Security Agent (scagent) - Unknown owner - C:\WINDOWS\system32\scagent.exe" start (file missing)

    For the O23 line you will probably need to do the below:

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Security Agent (or you may need to look for the short name scagent ) Now right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now back in the HijackThis window, click the button that labeled 'Delete an NT Service" . Now copy/paste the following into the box that opens, and press "OK":

    Security Agent

    If that does not work, try the short name: scagent

    Okay now exit out of HijackThis. And let me know where things stand now.
     
  18. TroelsM

    TroelsM Private E-2

    Hey. Back again, -and this time without virus.

    I think I got rid og the R1's and the SCAgent. I reboted a couple of times and they don't come back. My startpage is back to normal, and I'm one happy trooper...

    Thanks.

    TroelsM
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds