Mozilla Firfox And Winsock

Discussion in 'Malware Help (A Specialist Will Reply)' started by HECK, Jul 18, 2005.

  1. HECK

    HECK Corporal

    ok i got mozilla firefox and i ahvent touched IE for about 9 mths. anyway, i came down with a bad virus. i cant connect to the net, well i can, but mozilla wont access the net. i have the connection computer on my start bar tray but no access via AIM or mozilla. i did HJT and its showing a few counts of this "O10 - Unknown file in Winsock LSP: c:\windows\system32\smfilter.dll " and others. i used the lsp program recc. by you, it removed it but it keeps popping up. anyone know how to remove this? and also it seems to be and it seems to be hiding under "HKEY LOACL MACHINE_SOFTWARE_MICROSOFT_INTERNET EXPLORER" then its under URL SEARCH HOOK .... or something. i got this information viz WinMaid i beleive. ive ran spybot and all. trsut me i have all the progs that you all reccomended. i have had these since i got hijakec via about:search hompage and all them goodies. its sayin also something about filter hijacks... Thanks alot to all that respond.

    p.s. im not on my computer obviously. we have several comps. so ill be checking this alot.

    ;) much apper.
     
  2. HECK

    HECK Corporal

    here is a line that its the filter hijack from WinMaid

    C:windows\system32\mpg2splt.ax
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. HECK

    HECK Corporal

    chaslang, i already did all of this but here is the log file... but the log is clean now. this was before the problem. like i said i removed the windsock but it seems to b under the reg now per Winmaid ... but i dont know here ya go thanks man.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but you did not run all the steps of the READ ME FIRST according to your HJT log. I see no signs of the BitDefender and RavAntivirus online scans being run.

    Is this log from safe mode.\?

    You have no AV, no firewall, and have a very old OS.
     
  6. HECK

    HECK Corporal

    whats AV? and i kno my os is old. i had a firewall but gotte to be very restrictive. do u reccomend any? and also. i have ran them previously. but i cant get into the net. so i cant run them. arent they the ones that are ran via the net? and also this isnt from the safe mode. thanks im doing the scans again in safe mode.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What tools and what versions are you running? You need to make sure you have what we give in the READ ME FIRST.

    AV = antivirus

    Firewalls and AV's are recommended in the below, but we will do this later:

    How to Protect yourself from malware!
     
  8. HECK

    HECK Corporal

    i had an anit virus but i cant seem to find it. i used spy bot, ad aware, about: buster, HSR, Stinger, CWSHREDDER, ccleaner and i belive thats it. but i gota check what versions they are. what ima have to do is load all the progs on a CD and then bring them to the infected comuter since i dont have access to the net.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what you will have to do. Make sure you use the links in the READ ME FIRST to download from. Then you will have the proper versions. The only problem you will have is getting the updates if you cannot get online on the problem PC. For things like Ad-Aware SE and Spybot S&D, the updates can be download and installed manually too.
     
  10. HECK

    HECK Corporal

    hey, i finally got back to the computer. and the one that has the spyware on it seems to be getting a littel better. i downloaded some programs on my laptop then sent them to my other comp. i downloaded the new LSP winsock files with one of MG.com's files. now i can get on the net and i upgraded my programs. they were all up to date expcet CCleaner. now sometimes i get this error come up. its the blue screen. it says:


    The problem seems to be caused by the following file: Win32k.sys

    PAGE_FAULT_IN_NONPAGED_AREA

    Technical Information.

    *** STOP:0x00000050 ( 0xB0EA64EF, 0x00000000, 0xBF924FDA, 0x0000000 )
    win32k.sys - address BF924FDA base at BF800000, Date Stamp 411033AF


    Do you kno what this is? thanks Chaslang. im using a program to try to clean the registry if that wil help i dont know. i thought id take a chance..

    thanks
    again

    anthony
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. HECK

    HECK Corporal

    chaslang, i pretty much got it fixed i beleive. it was a malware problem. there was a virus in there and AVG got it out. well found ti and i went into the windows file and i deleted it my self. but im still gettin this problem wit the blue screen. thanks chaslang.

    anthony
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may still be worthwhile checking your log for other problems. As I said in my previous post, the other problem is more than likely not malware.

    I see you posted in the Software Forum. Did you look at the links I gave you?
     
  14. HECK

    HECK Corporal

    yep and i did the microsoft one. thanks again ok ill post a log using HJT.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of dates with your Windows updates and that is a big problem. You must get updated. Which means you still need to follow ALL the steps in the How to protect thread I gave to you. You also still have no firewall.

    Are you using some kind of libraries from PJ Naughter: http://www.codeproject.com/library/pj.asp

    The below lines in your log is what I'm questioning:

    C:\WINDOWS\System32\MsBAfd.EXE
    O23 - Service: MS Service (MSHelper) - PJ Naughter - C:\WINDOWS\System32\MsBAfd.EXE
     
  16. HECK

    HECK Corporal

    so what are u saying about the pj nuaghter thing? and also with those lines i cant deleted them HJT wont let me. well they will be deleted but willl pop back up after reboot. and about my updates, this will explain why...

    but its windows XP professional.and im still on service pack one. i cant update for some odd reason. its sayin my key is invalid. but the place where i got my computer rebuilt about 3 years ago at had a bad problem of using one copy of windows XP and selling it as a new copy. so bascially he was loading the software using the same key on everyones computer. he isnt in business anymore im guessing for this reason? but i cant update....
     
  17. HECK

    HECK Corporal

    as far as the firewall goes, i just installed sygate's firewall.
     
  18. HECK

    HECK Corporal

    i was thinking about the msbafd.exe and i tired to delete it, and it wont let me, so ijust renamed it and put bad infront of it just so ikno its no good. will this work? thanks

    anthony
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was asking if you run something by PJ Naughter. Do you? I did not say to remove it. I just wanted to see if you new what it was. I never saw it before. You cannot just delete it that way.

    You do not have WinXP SP1. You have WinXP. Look at you version shown in your HJT log. You have IE SP1. You must purchase a valid license so you can get upgrades.
     
  20. HECK

    HECK Corporal

    chaslang, alright thanks again. where can i get a valid id from? and what do i tell them when i get it? like why do i need one? and one more thing the pj naughter i dont kno what i run by him... maybe it was part if a virus i dont kno...

    thanks
    anthony
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would say you should goto any retail store and purchase a copy. Watch for sales. The other alternative would be a reputable online mail order store. Ask this question in the Software Forum. I'm sure you would get a load of responses.

    You still have not directly answered the question about PJ Naughter. Do you use or want it?
     
  22. HECK

    HECK Corporal

    the pj thing, i dont know where it came from. and i hve the slightest idea of where it came from ro why i have it. so your guess of me having it is the same as mine. and can i jus buy a KEY CODE or do i have to buy the whole XP software?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ask about the Key Code thing in the Software Forum but it will probably cost you the same amount. Also you really want to buy something where you have the original bootable XP CD. It would be even better if you just bought WinXP SP2 on CD. Without a bootable CD you could eventually have problems that require a CD to repair it and you would still be up a creek without a paddle.

    Do you want to remove the PJ stuff since you do not know what it is?

    If so, first run Control Panel, Add/Remove Programs and see if you can find it in there. Let me know.
     
  24. HECK

    HECK Corporal

    ok will do with the cd key. and about that pj naughter thing, cant find it anywehre and even did a search using the windows search option. maybe i didnt doit right but ill try it again. im tired now, so ill get to it the first thing in the morning. Thanks abunch again

    anthony
     
  25. HECK

    HECK Corporal

    ok did the search and i couldnt find it anywhere...
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to MS Service (or look for MSHelper) Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    MS Service

    If that does not work, look for: MSHelper

    After doing the above exit HJT this and if told that you need to reboot to complete the process, do not reboot yet. We will restart HJT to use different options in a few lines.

    As a double check, Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O23 - Service: MS Service (MSHelper) - PJ Naughter - C:\WINDOWS\System32\MsBAfd.EXE


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\System32\MsBAfd.EXE

    Now reboot in normal mode and check your HJT log to make sure that the service no longer shows.
     
  27. HECK

    HECK Corporal

    hey chaslang, its not there anymore, here is my log.

    Thanks

    anthony
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So how is everything running now?
     
  29. HECK

    HECK Corporal

    not to be a d!ck, but when i removed the ram, ( thats what was throwing the blue screens ) everything wentback to normal, ( what had happened i put the wrong speed ram into my MB and then it was throwing them codes) but then after i did waht all you said it cleared that damn pj naughter sh!t. Thank god for you chaslang. but i need to find some cheap pc133 ram... haha you got ne used.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! You never said anything along the way that you had made hardware changes.

    Oh well! Problem solved now and your PC is cleaner too?
     
  31. HECK

    HECK Corporal

    yeo its cleaner thanks.

    anthony


    do you reccomend any other programs for cleaning?

    oh and also my girlfriend has the Aurora problem. i got rid of most of the files and all she had on her comp. but i havent gotten rid of it yet. any suggustons.?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most of what we recommend is in: How to Protect yourself from malware!

    Also I recommend Ewido Security Suite

    For you girl friends computer run the READ ME FIRST and also do the below. If still having problems afterwards, start a new thread and make sure you indicate what you have already run.

    - download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover
    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet.

    - Now while still in safe mode, run the abiremover.exe but make sure you are physically disconnected from the internet (unplug your cable to be sure). Just click install, wait (explorer window will disapear)

    - When abiremover finishes just reboot into normal and see how things look.


     
  33. HECK

    HECK Corporal

    heythanks abunch again. and also how come on my laptop when i sign on i get a balloon that says" Duplicate name exists on network" is this because i have my desktop online and my laptop at the same time and its detecting that the two have the same name? i have no viruses on my laptop or anything. becasue at first i thought it was a cirus tryint o duplicate my name and all but then it turned out to not be that. so imjus thinking that it is the other computer that is connected on our wireless.

    Thanks

    Anthony
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Each PC on the network must have a unique name.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds