My computer is sick 8(, please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kimm.y, Nov 22, 2004.

  1. kimm.y

    kimm.y Private E-2

    hey.
    I have the DyFuCa.Internet Optimizer virus, (I think, I concluded this because it's usually those files that my search and destroy program can't delete). I think I may also have some other bugs. I dl'ed the latest version of Ad-aware from your site, and I have scanned it many times tonight, and the four files that it cannot delete, are:
    C:\WINDOWS\System32\winend32.exe
    C:\WINDOWS\elitetoolbar\EliteToolBar
    Version54.dll
    C:\Silent093.exe

    Also, I notieced that whenever I restart my computer, to perform another scan, my computer has many more bugs to clean out, as if the files regenerate once I shutdown. In fact, I have found, that when I tried to delete certain files manually, they reappear immediately. I currently have the latest Search and Destroy remover, as well as, the lastet ad-aware, (mentioned before), and also the free version of ad-ware spy, which I tried to delete from the control panal (add/remove programs) but was told it had to be done manually. I do not know anything about computers, so I do not know how do delete files manually. The constant pop-ups/computer freezing excessive build up of files..et cetera are creating a huge problem for me. I'm worried about my computer, I'm very dependent on it, mainly for school, so any help would be..really great. Thanks.

    kimm.y
     
  2. PhilliePhan

    PhilliePhan Guest

  3. kimm.y

    kimm.y Private E-2

    Thanks for your reply, I did all the steps on your web page, on both of my computers. I think things are all right, the excessive pop ups have gone away, and the freezing has essentially stopped. I do however, find myself having to do a sweep everyday (at least on my laptop). Maybe that's normal though, I don't have an anti-virus program on the laptop. Anyway, the only things I found to be left over (and suspicious) were a folder called "Found.000" with a file in it named "Found.000" and a .vbs file named PMB which I tried to delete but it keeps coming back. They seemed suspicious to me, but maybe they aren't? Again I am not familiar with computers so if these things are normal, let me know. Also, before I found this website, I had tried to fix my computer myself, by trying to manually delete things that the spyware remover programs could not delete, and also things that I thought shouldn’t be there (obviously this was dumb, but I was frustrated). Anyway, I deleted IPROF32.dll, and I know this because I get this error that pops up on my desktop when I log on saying it couldn’t find that file. I’m sure it’s some windows file and may not be replaceable, but if you know where I might be able to re-download it and install it, that would be cool. I realize you guys are really busy, but I want to make sure that everything is gone so that I do not run into problems again. Thanks.

    Kimm.y
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Found.000 folder (and folders with similar names) occur from running the disk error checking. Right-click the folder, select properties. Go to the security tab and click advanced. You can take control of the folders on the owner tab. For the security tab to appear in a WinXP Pro system, you must disable simple file sharing in the control panel/folder options/view tab. For a WinXP Home system, you must restart in safe mode and logon as
    administrator. More details here:

    HOW TO: Take Ownership of a File or Folder in Windows XP [Q308421]
    http://support.microsoft.com/?kbid=308421

    Is disk error checking running automatically on your system.
     
  5. PhilliePhan

    PhilliePhan Guest

    Hi Kimm.y,

    You definitely need AV - Here's a good FREE one: AVG Free Edition

    The only place I found IPROF32.dll was a site that charged for the download. Perhaps a little Googling will unearth a free download?

    If you'd like us to take a look at HijackThis Logs for your machines to ease your mind, go ahead and send them to us. Be sure to follow the directions below.

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Chas or I will take a look when one of us gets a chance.

    PP :)
     
  6. kimm.y

    kimm.y Private E-2

    Thanks for the reply. Attached are my HijackThis logs for both computers. I forgot to mention, that with my home computer, I am not running WINXP (like I am on the laptop), I'm running a dual-boot WIN2000 and WIN98, so when I right clicked the FOUND.000 folder, I did not have all the options listed. I did however, go to the 'sharing' tab and made sure that I was not sharing that folder. Another thing I just noticed...when I log onto my home computer, I get a pop-up taht says "Error loading H:\Program Files\Wild Tangent\Apps\CDA\cdaEngine0400.dll (The specified Module could not be found.) If you have any idea what that pertains to, please let me know. Thanks guys!

    kimm.y
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have HijackThis installed incorrectly. We do not want it on your Desktop. This is where you have it:
    C:\Documents and Settings\Kim\Desktop\scan programs\hijackthis\HijackThis.exe

    Put it in a folder like:
    c:\program files\hijackthis\HijackThis.exe

    The Winword program should not be running when scanning:
    C:\Program Files\Microsoft Office\Office\WINWORD.EXE

    Next time you run the READ ME FIRST, please do not skip the Symantec online scan.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FIRST YOUR LAPTOP:

    I would recommend using Add/Remove programs to uninstall Viewpoint Manager unless you know you use it. About 99% of all users have no idea what it is. It is crap the AOL installed without asking you.
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below processes and if found End them:
    l?gonui.exe
    amstream.exe
    vtF.exe
    Sgz.exe
    VirtualBouncer.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
    O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
    O4 - HKLM\..\Run: [EZ2p2Gy] C:\windows\temp\EZ2p2Gy.exe
    O4 - HKLM\..\Run: [hIIY] C:\windows\temp\hIIY.exe
    O4 - HKLM\..\Run: [5wJ9zoQB] C:\WINDOWS\Temp\5wJ9zoQB.exe
    O4 - HKLM\..\Run: [c1adc88f0c11] C:\WINDOWS\System32\amstream.exe
    O4 - HKLM\..\Run: [vtF] C:\documents and settings\kim\local settings\temp\vtF.exe
    O4 - HKLM\..\Run: [Sgz] C:\documents and settings\kim\local settings\temp\Sgz.exe
    O4 - HKCU\..\Run: [Dwueg] C:\WINDOWS\System32\l?gonui.exe


    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\VBouncer <--- delete the whole folder
    C:\windows\temp\EZ2p2Gy.exe
    C:\windows\temp\hIIY.exe
    C:\WINDOWS\Temp\5wJ9zoQB.exe
    C:\WINDOWS\System32\amstream.exe
    C:\documents and settings\kim\local settings\temp\vtF.exe
    C:\documents and settings\kim\local settings\temp\Sgz.exe


    Now empty your Recycle Bin and goto c:\windows\Prefetch and delete any similarly named files you see there.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For your Home Computer

    You have HijackThis installed incorrectly. We do not want it on your Desktop or in Documents & Settings. This is where you have it:
    H:\Documents and Settings\kitty1\Desktop\scan programs\HijackThis.exe
    Put it in a folder like:
    H:\program files\hijackthis\HijackThis.exe

    Also, you may need LSP-Fix so download it here just in case: http://www.majorgeeks.com/download4180.html
    Please download it, but do not use it yet.
    Are you sure you ran all steps of the READ ME FIRST of this PC. I would expect those steps to clean up the New.Net problem but you may have that disable if you have not updated Spybot or never fixed a bug of theirs. Make sure you have updated to
    Spybot - Search and Destroy DSO Exploit Fix - http://www.majorgeeks.com/download4392.html
    and then update to todays detections list. Then run a scan and clean what it finds.

    Make sure you have viewing of hidden files enabled.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Is this next line with www.orbitexplorer.com something you recognize? If so, skip it otherwise fix it too.
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.orbitexplorer.com/cgi-bin/IESearch.cgi?bid=&affid=1cj
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - H:\Program Files\NewDotNet\newdotnet6_38.dll
    O4 - HKLM\..\Run: [New.net Startup] rundll32 H:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "H:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

    Boot into safe mode and use Windows Explorer to delete:
    H:\Program Files\NewDotNet <-- the whole folder
    H:\Program Files\WildTangent <-- the whole folder
    c:\counter.cab

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the future, please only work one PC problem per thread. It always leads to confusion when trying to deal with multiple PCs at the same time. It is just as problematic as working on two users problems in a single thread.
     
  11. kimm.y

    kimm.y Private E-2

    Ok I followed all the steps on both computers. Attached is the HJT log for the laptop. I think it's ok now. My Home computer, however, is screwed. I followed all the steps, and found that I could not manually delete the folders listed. The NewDotNet folder, for example, said that my access was denied, and that it might be in use. I did not understand exactly what you meant when you said to use windows to delete those folders, I assuemd you meant to just go into my computer and then H:\ Program files, and delete them from there, if you meant something different, please explain again (sorry). Then, after trying to delete those files, and failing, I decided to run search and destroy one last time, and I think I forgot to close all programs when asking it to fix my computer, ( I was doing many things at once) and I think I messed things up, because now, whenever I boot, it won't even make it to the password prompt before the screen goes black. I checked my computer temperature, and the CPU temp was at 107 F and the system temp was at 95 F, which seems pretty normal. [I thought maybe it had overheated]. I then booted into BIOS, and while I was just looking around, it blacked out. So it seems pretty serious. please help....

    thanks.
    kimm.y
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On your Laptop, have HJT fix the below line and it should be finished:
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML

    When I said to delete the files, I said use Windows Explorer. There are many ways to bring this up. One is to click Start and select Explore. Then you navigate to the appropriate files or folders and right click on them and then select delete.

    You could also right click on MyComputer and select Explore.

    Exactly what did you delete from H:\Program Files (if anything)?
    What did you have Spybot fix?
    Did you try booting in safe mode?
     
  13. kimm.y

    kimm.y Private E-2

    Laptop completed - thanks so much.

    On the Home computer, I did not delete anything from H:\Program Files, I tried to delete the NewDotNet folder but was not allowed to. I could not find the other two things listed. So nothing was deleted. When I ran search and destroy, I remember that there were 5 things that came up, but I do not remember what they were (i realize this does not help, sorry.) I tried booting in safe mode, and also in windows 98, (and of course in my normal windows 2000 mode), all blacked out. I made it to the desktop one time, but it blacked out within 10 seconds of arrival.

    kimm.y
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This will be difficult unless we can boot. Try physically disconnecting (unplug cables) from the internet and booting to Win 2000 in safe mode. If you get it to boot, immediately bring up Task Manager (CTRL-ALT-DEL) and click Processes. Start ending all unnecessary processes. Hopefully we can do that before something shuts you down. Do not shut down the following windows processes (shut everything else down)

    taskmgr.exe
    smss.exe
    winlogon.exe
    services.exe
    lsass.exe
    svchost.exe
    spoolsv.exe
    nvsvc32.exe
    regsvc.exe
    MSTask.exe
    Explorer.exe
    rundll32.exe

    If you are still running now, try running Spybot and restore what you previously fixed. Note also before running a scan SpyBot S&D you need to fix some default settings or it will ignore New.net and some other issues. So run SpyBot and click on Mode and change to Advanced Mode. Then click Settings, Ignore Products and in the right window pane where the products are listed, right click and Deselect All. (about 4 of them, including new.net where selected to be ignored by default). Now run the scan.
     
  15. kimm.y

    kimm.y Private E-2

    I was able to get to the desktop. When I got to the processes tab, this is what showed up:

    (not in this order)

    System Idle Process
    System
    csrss.exe
    winmgmt.exe
    smss.exe
    winlogon.exe
    services.exe
    lsass.exe
    svchost.exe
    explorer.exe
    taskmgr.exe

    I tried ending the first 4, (like you said) but was unable. This is what popped up: " unable to complete this operation: The operation is not valid for this process"

    I next went and restored those files deleted in the last search and destroy sequence. That was done successfully, however, after that, my screen blacked out. I noticed that the moniter turns off, the computers stays on...does that mean anything? Like the moniter light goes from green to yellow.

    kimm.y
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a new one! Sounds like something is putting your monitor into a standby mode. Post a new HJT log if you can get one from normal boot mode.
     
  17. kimm.y

    kimm.y Private E-2

    I was able to do a hijack this log, but when i was trying to e-mail it to myself, the computer shut off. I've been trying and trying to get back to the desktop but it just won't work. So I can't retrieve it. Do you think it's a hardware problem?

    kimm.y
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could be! Can you boot it in safe mode now?
     
  19. kimm.y

    kimm.y Private E-2

    nope 8(
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you get any error messages when trying to boot into safe mode or into normal mode?
    How far does it boot in each mode?
    Try disconnecting cables that would connect you to the internet and booting?
    Can you boot from your Windows XP CD into the Recovery Console?

    1. Insert the Windows XP installation CD-ROM, and then restart your computer.
    2. When the computer starts, press F12.
    3. Start your computer from CD-ROM, and make sure that you select the drive that contains the Windows XP installation CD-ROM.
    4. In the Microsoft Windows Recovery Console, select R for repair, and then press ENTER.
    5. Select the installation number for the problem installation.
    6. Type the password for the administrator account of that installation, and then press ENTER. You receive a drive:WINDOWS> prompt, where drive is the drive on which Windows XP is installed.

    Let me know if you can do that. If so, perhaps you can locate the HJT log file you created and save it to the floppy drive. You will have to do this from the command prompt in the recovery console. But obviously you need to know where you saved the log to (the directory you installed HJT into).
     
  21. kimm.y

    kimm.y Private E-2

    I'm still having troubles trying to get my computer to post, one of my friends is going to try switching around hardware from his mom's computer to mine, to see if he can narrow things down. If it's not hardware, I'm going to try again to get that Hijack This log, and I will get back too you as soon as I find out. I have not encountered any errors when booting in safe mode, the moniter simply shuts off, and I am going to try booting from the CD once I get my computer back. Thanks for the reply, I will get back to you.

    Happy Holidays,
    kimm.y
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What hardware are you switching around? Let us know what happend.
     
  23. kimm.y

    kimm.y Private E-2

    My friend tried putting his mom's vid card into my computer and apparently my computer fried his mom's card. He also said that one of my hard drives was spinning super fast, which was not normal. He thinks that it might be fried too. And I guess he tried taking everything out and put things back in with different combos, but he told me it was "too much to explain", so I don't know, I guess that doesn't help. He thinks I should build a new one using the "barebones package" which is like 200 dollars, I don't know...
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No offense but it sounds like your friend should not be working on computers.
    The Video card should not get "fried" nor should the hard disk if properly removed and re-installed using the proper cables etc.
     
  25. kimm.y

    kimm.y Private E-2

    oh.

    good to know.
     
  26. kimm.y

    kimm.y Private E-2

    Since my friend didn't know what he was doing, I decided to take it to this other guy I know and he figured out what was wrong with the computer. The fan on my video card was broke and so my computer was overheating. The hard drive was not fried, nor was the motherboard. Everything seems to be working ok now, so I just wanted to let you know what was going on. Thanks for all your help.

    Best,
    kimm.y
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good to hear Kimm! You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds