Major Problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by primetime, Oct 11, 2004.

  1. primetime

    primetime Private E-2

    hey guys, i have had a problem for a while and have attempted numerous solutions but have not been successful. I have run through all the steps recommended before posting.

    here is the history:
    1- I have been unable to download windows service pack 1 or 2 (tried 20 or more times for a couple of months). When i try to download them i get this message "...system\ftp.exe is in use or running.." I have closed down everything and even attempted to download in safe mode.

    2- apparently i am unable to run certain programs because the computer will not recognize me as the administrator (i have tried to reinsert myself as system adminstrator but i still can't get full access. (when i try to download some major programs (like a stock trade station) i was unable to because of this problem)

    3- The program that appears to be the cause of the problem appears to have the ability to regenerate itself after numerous attempts to delete it through hijack this and through adaware. I downloaded "browser sentintel" and a few times a day i get this broswer alert:
    Name: birdrule
    Executable: C:\PROGRA~1\THEAXI~1\waveseek.exe
    Location: HKLM Software\Microsoft\Windows\CurrentVersion\Run
    Run Once: No

    4- WHen i ran trend micros scan it came up with 8 viruses called troj.swizzor.r. I couldnt get the rest of the name, but they all had "\theaxis\" in the name so it is definitely related.

    5- when i ran adaware it came up with 146 critical objects. I have had adaware for a while and this is not uncommon. I run adawre a couple of times a day and i usually get 8 or 146 critical objects each time (even if i am not using the computer). the objects are pretty much the same and one is listed as an LOP.

    6- all the other virus and spyware scans came up clean.

    7- Its been a few hours since i finished all the steps and i just got a new alert from "browser sentinel" that the waveseek program was trying to install itself again. and i just ran adaware and this spyware came up with this spyware: c:\docume~1\alan\locals~1\temp\sta4f.exe

    8- attached is my hijack this log. i have gone through the process of getting rid of the unwanted programs on hijack this before (too many to count), but i am hoping that you guys can find something new or figure something out before i have to uninstall windows.

    i hope i laid things out as clear as possible. if you need to know more info let me know.

    thanks in advance!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    No one requested your log, you posted it as a .doc file not .txt, you are running HJT from your Desktop, and you did not shut down your browser (IE) before running.

    You need to fix this line:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hyeaaamrxmpijhi.net/1iXKlNwYKkBr1GTnAmSIT6ai4H4qwCg18fBg6btXmmyTYEoeNkWnJzfxtxFN2aod.html

    And what are all those O16 lines with gosystemrs.fasttax.com used for?
     
  3. primetime

    primetime Private E-2

    sorry about using word file, i forgot to attach it as text. I had read the tutorial before and deleted all the items suggested but it didnt prevent the problem from reappearing. I have been guided through a few other hijack this procedures and deleted the "search assistant" line a few times. unfortunately it keeps coming back.

    the problem i have is not something that can be solved through hijack this. I just posted the hijack this log as added information.

    thanks again, and sorry for the problems
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it keeps coming back, you have other hidden processes running. Have you look at AppInit_DLL?

    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:
     
  5. primetime

    primetime Private E-2

    chaslang, nothing came up in the value field.

    the value name was AppInit_DLLs

    the keyname was HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

    the type was REG_SZ
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download FINDnFIX from here: http://downloads.subratam.org/FINDnFIX.exe

    Run FINDnFIX.exe, it will extract some files to a folder called c:\findnfix
    Use Windows Explorer to bring that directory up. Now if necessary print the remaining instructions because you will be disconnecting from the Internet in the next step. I want you to physically unplug your analog modem phone line or ADSL/Cable modem ethernet cable to your PC so that there is no way any running program get get access to the Internet from your PC.

    Disconnect your network connection now and exit all browser sessions!

    In the c:\findnfix directory double click on the file !log!.bat
    This will run the program and it will create a log.txt file (it will also pop up in notepad when done). Be patient, it takes a little while for it to scan thru all the files it needs to look for.

    When it is finished, reboot your PC and reconnect your network connection.
    Come back here and post as an Attachment your log.txt file from FINDnFIX
     
  7. primetime

    primetime Private E-2

    when i tried to run !log!.bat, i got this message:
    "windows cannot access the specific device, path or file. you may not have the appropriate permission"

    this is something i have seen before. i have two user accounts on my computer. Mine is listed as the administrator (when i check the user accounts) but for some reason i am not always recognized as such. When i switch the administrator over to the other user i get the same message.

    again, thanks for your time.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you please reboot! And make sure you login as the administrator and try it one more time.
     
  9. primetime

    primetime Private E-2

    i did it it again, and still the same message.

    Maybe this will clarify things a bit. When i reboot in normal mode i get two users, me and my wifes. when i reboot in safe mode i get two users listed, me and "Administrator."

    I tried to run the program from my user and my wifes, and then in safe mode i tried it again using my user and the "Adminstrator." neither worked.

    thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'm not sure were the problem is with executing the log.bat file. I have never had any problems with it. Some permission is not correct somewhere but I don't know where.

    Let's try this:

    Download the VX2 finder. The shut down ALL applications especially Internet Explorer and disconnect from the internet. No run VX2finder and select "click to find abetterinternet". Then select "make log" and copy/paste the log back here as an attachment.
     
  11. primetime

    primetime Private E-2

    i tried to attach the file but it said that it was an invalid file. I saved it as a txt. and when i tried to upload it i got this message: vx2.log: Invalid File Type

    i tried it a few times with no luck (and read the instructions a few times). sorry, but here is the log:

    Log for VX2.BetterInternet File Finder (msg126)

    Files Found---

    Additional Files---

    Keys Under Notify---
    crypt32chain
    cryptnet
    cscdll
    igfxcui
    ScCertProp
    Schedule
    sclgntfy
    SensLogn
    termsrv
    wlballoon


    Guardian Key--- is called:

    User Agent String---
    {9A8855C7-0738-4D49-BB62-3A309D5357AB}
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try rebooting in safe mode and fixing that line with HJT.
    Then while in safe mode:

    Reset Web Settings by clicking Start, Control Panel (for some systems it may be Start, Settings, Control Panel) and select Internet Options. Then click Programs and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like (i.e., www.majorgeeks.com). Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log.
     
  13. primetime

    primetime Private E-2

    I couldnt find that line in hijack this. I also can't post a hijack this log properly because for some reason i am unable to attach it properly.

    I can say that since i ran all the programs you suggested i have not encountered the same spyware problems. In fact i only get very minor ones picked up by adaware. So the problem is only the inability to download windows update. Let me know what you want me to do next.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a HJT log. To do this you need to make sure you name the file with an extension of .txt
    The default for HJT is to create a file that ends in .log. Make sure when you try to upload it the file extension is .txt.

    When you click Save log in HJT a notepad window opens with your log in it. All you have to do is:
    1) click File, Save as
    2) in the popup window, change the Save as type to: All files
    3) change the file name from hijackthis.log to hjtlog.txt
    (hjtlog.txt is just an example. Anything ending in .txt is fine.)

    Note: each time you upload a log you need a different name or the upload manager will block the upload since it assumes the file has already been uploaded.


    What message do you get when trying to perform a Windows Update?
    How do you attempt to update?
     
    Last edited: Oct 15, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds