Need help please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by kingokrap, Feb 21, 2007.

  1. kingokrap

    kingokrap Private E-2

    Ok, where to begin. First off last Monday (2/12) I bought a new external DVD burner and installed the software that came with it (Nero) and everything was peachy for a while. I began copying alot of the video files I had onto DVDs and then I deleted a bunch of them (around 11 gigs worth) I defragmented and then on Saturday (2/17) I began noticing things were not right. I found that I could no longer play avi files at all. Not with Media Player. Quick time. Nothing. When I tried to use Windows Media player the video would come up and just freeze at the very beginning. I could manually move the progress bar and sometimes the video would actually start to play, but it would skip along and wasn't playing smoothly and there was no audio. I went ahead and tried to burn a DVD out of them ( I had already made a few previously) and when the preview screen came up before the option to burn the DVD, it wouldn't even play the video. I can play other video files (mpeg, wmv etc) but no avi. Also, I can't remember exactly, but about the same time my computer seemed to slow down a little and things got choppy. By that I mean that when I open Internet Explorer and scroll down a page, it sort of skips along instead of the smooth scrolling action I'm accustomed to. I also noticed that when I start up windows (I have XP home by the way) the blue screen at the beginning no longer smoothly appears but seems to skip into view (sorry can't think of a better way to describe it). Also, all of my restore points before 2/19 were deleted at some point. And then comes the big event, I'm pretty sure I happened Sunday night (2/18). I went to restart my computer and when it came back up I got a message (sorry I didn't write it down exactly) that said something along the lines of: "I will need to reactivate windows because of new hardware being installed" I couldn't connect to the internet so I called the phone number and went through the automated process of reactivating my copy of windows. I thought it might've had something to do with installing my DVD burner. But then I remembered I had some work done on my computer last year. I had a new motherboard installed (ASRock Model P4VM800). But I haven't had any problems until now.

    I went through the steps for the READ ME RUN ME thread and here's what went down. First off I started doing this late Monday night (2/19) but I was at the hospital all day Tuesday and didn't get to finish things until today. Also, my I have both internet and telephone service through the cable company (what a fantastic time we live in) and if I completely disconnect the modem from the computer I lose phone service. So I disconnected the Ethernet cable (that's the one that looks like a large phone wire right?) and the USB cable connecting the modem to the PC. I left the incoming cable line connected to the modem as well as the phone line that connects to the wall. But when I disconnect the USB and Ethernet lines I can't go online so I'm assuming that was enough. OK SpyBot found no problems. I can't remember exactly what Counter Spy found but I'll attach the log. I ran Bitdefender and Panda ActiveScan. I can't remember what BitDefender found but I've got the log. I do remember Panda had found 29 spyware items (yikes!). Next I ran the GetRunKey and got an error message that read:

    C:\WINDOWS\System32\cmd.exe
    C:\PROGRA~1\SYMANTEC\S32EVNT1.DLL. An installable virtual device driver failed DLL initialization. Chose 'close' to terminate the application.

    It had 'close' and 'ignore' buttons. I pushed close and it closed. I ran it again and pushed ignore and it ran and I got a log. The exact same error message appeared when I ran ShowNew. So I hit ignore and it ran and I got a log. I also ran HiJackThis according to the guide and got that log as well. I didn't do Step 8 System Restore Toggle because I just want to wait to hear back from someone before I proceed.

    Sorry for the long-winded message but I just wanted to get everything posted that I thought was relevant. And sorry for not being exact with the times things occured.

    Oh yeah, one more thing. I had a Windows Update pop up on Monday. I downloaded it and went to install it but it wouldn't install. I tried numerous times and I went to the Windows Update site and tried but no luck. The update was for- Security Update for Microsoft .Net Framework, version 2.0 (KB92270) and (KB917283). Don't know if it's related to anything above, but just thought I'd throw it out there.

    Any help would be greatly appreciated.
     

    Attached Files:

  2. kingokrap

    kingokrap Private E-2

    Here's my other three logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [ipvs32.exe] C:\WINDOWS\ipvs32.exe
    O4 - HKLM\..\Run: [iedb32.exe] C:\WINDOWS\iedb32.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [3E7C.tmp.exe] C:\DOCUME~1\GLENBL~1.YOU\LOCALS~1\Temp\3E7C.tmp.exe
    O4 - HKLM\..\Run: [3E7C.tmp] C:\DOCUME~1\GLENBL~1.YOU\LOCALS~1\Temp\3E7C.tmp.exe
    O4 - HKLM\..\Run: [3E7B.tmp.exe] C:\DOCUME~1\GLENBL~1.YOU\LOCALS~1\Temp\3E7B.tmp.exe
    O4 - HKLM\..\Run: [3E7B.tmp] C:\DOCUME~1\GLENBL~1.YOU\LOCALS~1\Temp\3E7B.tmp.exe
    O20 - Winlogon Notify: geedc - C:\WINDOWS\system32\geedc.dll (file missing)

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\hp\bin\FondleWindow.exe C:\hp\bin\KillIt.exe
    C:\New Downloads\l2mfix.exe C:\WINDOWS\Downloaded Program Files\WildApp.inf C:\WINDOWS\inf\polall1r.inf C:\WINDOWS\inf\polmx2.inf C:\WINDOWS\system32\Agent.dll C:\WINDOWS\system32\mm\linkd.exe C:\WINDOWS\Temp\~592746.tmp C:\WINDOWS\Temp\~665233.tmp
    C:\DOCUME~1\GLENBL~1.YOU\LOCALS~1\Temp\3E7B.tmp.exe
    C:\DOCUME~1\GLENBL~1.YOU\LOCALS~1\Temp\3E7B.tmp.exe
    C:\WINDOWS\ipvs32.exe
    C:\WINDOWS\iedb32.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click the processes tab and stop any of the above .exe processes. Click the box to unregister the dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  4. kingokrap

    kingokrap Private E-2

    OK, did as you instructed. First off, things are still slow, like the windows start up blue screen I mentioned before as well as the slow, choppy scrolling in Internet Explorer. I still can't play avi files either. When running KillBox, when I copy and pasted the 8 file paths you listed, the only one that showed up in the box was the first path (C:\hp\bin\FondleWindow.exe C:\hp\bin\KillIt.exe )Also, I DID get the PendingFileRenameOperations prompt. Also, when I ran GetRunKey and ShowNew I got the same error messages that I mentioned in my first post. I just hit ignore to run them. Also, just wondering if you could tell if the problem I'm having playing avi files and the problems I mentioned about the Windows update (by the way I no longer have the Windows Update Icon in the corner of my screen) is related to a malware problem or if it could have to do with the huge deletion of files I mentioned. Or are they problems for another forum. I thought about uninstalling and then reinstalling Windows Media Player but I thought I'd better wait to find something out. I've attached the three new logs you requested. Again, any help is greatly appreciated.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go back and do what was requested in step 3 of the READ & RUN ME. You ignored that step and it is part of your problem. You have Avast and Norton Internet Security installed. You biggest improvement will come from uninstalling Norton.
     
  6. kingokrap

    kingokrap Private E-2

    Ok, I used the Norton Removal Tool from Symantec's website. I didn't realize Norton's was so hard to get rid of. I thought I had gotten rid of it a long time ago. Do I need to do anything else or does the Removal tool do the trick. Is there a way I can definitely find out if Norton's is gone?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The Norton tool should be adequate for the removal. However, you can do a search for anything with the "norton" name in it.

    Is this your internet home page? If not, run HJT and fix it.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pwinsider.com/index56.asp

    You may uninstall Counterspy and any other items that we had you download.

    Your logs look clean, so we need to do the final steps.
    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  8. kingokrap

    kingokrap Private E-2

    I did the norton search and the only thing that came up was a .jpg file. I got rid of that. pwinsider.com is my homepage. I used to get a warning from my antivirus program when I went to that site. I think it was EXP/Agent.B, but I haven't seen anything about that for a couple of weeks now. I ran Pocket KillBox per your instructions and deleted the things you listed, uninstalled Counterspy. I went through Step 8 and toggled system restore. I installed Zone Alarm firewall. Glad to see everything looks clean. I do have a couple of quick questions about running antivirus and spyware scans. How often should I run scans? Daily? Weekly? Should I always reboot into safemode? Again, thanks for your help. My computer is still a little choppy when using internet explorer, I'm going to install Firefox tomorrow. Do I need to uninstall Internet Explorer first? And I'm still having problems playing the avi files, but I'm going to look around your forums tomorrow and see if I can find some answers since I'm assuming it's not malware related. Thanks.
     
  9. kingokrap

    kingokrap Private E-2

    I just noticed I have a Veritas Software folder in my Program Files folder. It has sgtray.exe in it, which I've noticed is always running in the background. Should I delete this as well. I looked up Veritas and the first thing on the list was Symantec and I know they're connected to Norton. I don't have anything for Symantec, Norton, or Veritas in my Add/Remove Programs list. Thanks
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Running scans is really a user decision, based on surfing habits and sites visited. If you use any P2P software, I would scan everything that is downloaded and then scan after each days usage.

    sgtray.exe is a utility from VERITAS Software Corporation which installs itself on the system tray bar, and serves to remind you to backup your files. This is a non-essential process. Disabling or enabling it is down to user preference.

    You do not need to uninstall Internet Explorer to download and run Firefox.

    You should post in the software section regarding the other issues, although your choppy display could be related to the video settings.
     
  11. kingokrap

    kingokrap Private E-2

    OK, thanks for all your help.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem ....safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds