need help!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by d.deeper, Dec 11, 2004.

  1. d.deeper

    d.deeper Private E-2

    grograms in my computer haven't been working properly.ie appears to be like in the picture
    everytime i try to browse file from computer.i'm using mozilla firefox right now.and other programs just shut itself down without any warning message like when i try to add shared folder to slsk, it just suddenly shuts down.and i've been trying to follow instructions on how to get rid of spyware but it still doesn't work.and i can't save log file on hijackthis,either.when i click "save log" the program just disappears.please help me.
     

    Attached Files:

  2. Matacumbie

    Matacumbie Rocky Top

    d.deeper,

    It sounds like your in the right forum. Usually symptoms like this are indicative of a BHO (Browser Helper Object) that create hooks in Internet Explorer. You might have other malware so I would suggest the Basic Spyware, Trojan And Virus Removal tutorial listed below.

    Follow the steps here, http://forums.majorgeeks.com/showthread.php?t=35407 and be sure to follow each step in each section.

    Keep us posted on your progress and results. Also include your operating system and latest updates in your next post.

    Steve
     
  3. d.deeper

    d.deeper Private E-2

    i have a few questions.do i have to do an online scan at Trend Micro's Free Online Virus Scan
    and at Symantec Security Check in safe mode?because when i am in "safe mode with networking support" i can't connect to the internet.

    by the way.my os is windows xp pro sp 1.

    thanks.
     
  4. PhilliePhan

    PhilliePhan Guest

    Please do both of them in Normal Mode. Then, attach a HijackThis log as per the instructions in the HJT Sticky Post.

    Steve or I will check back when we get a chance.

    PP :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! Seems we are not reading! Right at the end of step 1 in Scanning And Cleaning Steps it clearly states:

     
  6. d.deeper

    d.deeper Private E-2

    i have done everything posted in the threads but i'm still having the problems.
    is there anything else i can do?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Please also tell me what your expected Home Page should be.
     
  8. d.deeper

    d.deeper Private E-2

    since HJT shuts down everytime i click on "save log" as i mentioned before,i decided to post image files captured from the program.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need more info. I need the processes that are running, your OS and rev level, and you IE version and rev level.

    Go here: http://www.spywareinfo.com/~merijn/winfiles.html

    And download and reinstall the notepad.exe file for your windows version. It also tells you which dirctory to put it into. I am guessing that the hijacker removed your notepad.exe or corrupted it.

    Then see if you can get a real HJT log to post.

    You should uninstall LimeShop!
     
    Last edited: Dec 14, 2004
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would like you to goto SysInternals and download ProcessExplorer: http://www.sysinternals.com/files/procexpnt.zip

    Extract it from the ZIP file and run it. Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager (even if I say by mistake to use Task Manager). Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
  11. d.deeper

    d.deeper Private E-2

    i have windows xp professional service pack 1 and ie6 sp1.



    it didnt work.

    i have attached the process list on this post.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to uninstall this: Messenger Plus! 3 It is bad! Contains LOP and other problems.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try two things:
    1) in normal boot mode shut down the below processes using Process Explorer
    StyleXPService.exe
    NVSVC32.EXE
    MsgPlus.exe
    RuLaunch.exe
    firefox.exe
    msnmsgr.exe
    iexplore.exe Do not have any browsers runnning!!!!!
    flashget.exe
    winzip32.exe

    Exit Process Explorer.
    And close down everything you can that you see in the system tray.
    Now run HJT and try to save a log. Does it work!
    2) If you boot in safe mode, are you able to use HJT and save a log.
     
  14. d.deeper

    d.deeper Private E-2

    i already uninstalled messenger plus 3 and tried those two things as you posted but
    i am still not able to save log file and programs still dont work properly.btw i had installed "flyakite" not long ago.but i already uninstalled it but my system restore was turned off when i first installed it.so it 's not completely removed.as my system icons and stuff still look like mac icons.is it the cause of the problems?and is there any way to fix the problems other than
    to format my hdd.?

    thanks
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you already uninstalled Messenger Plus 3, why does it show as running in your process list?

    MsgPlus.exe 2028 Messenger Plus! Patchou C:\Program Files\Messenger Plus! 3\MsgPlus.exe

    and it was in your HJT log.

    Did you uninstall Lime Shop?

    You need to have HJT fix the O4 - line related to Cryptograhic Service

    Then boot into safe mode and delete:
    c:\windows\system32\tdsts.exe

    Then reboot in normal mode and let me know what's up!

    Make sure you get the latest HijackThis 1.99
     
    Last edited: Dec 16, 2004
  16. d.deeper

    d.deeper Private E-2

    i cannot find c:\windows\system32\tdsts.exe in my computer.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was in your log. What about the rest of the things I suggested?


    Please download the following tool: Pocket KillBox

    Run Pocket Killbox and choose the Delete on Reboot option. Enter the following into the box for Full Path of File to Delete c:\windows\system32\tdsts.exe
    Select the Delete on Reboot button.
    and press the Delete button (red X) and then Yes or OK until your machine reboots.


    Now post a new HJT log and let us know if you had any problems doing these steps.
     
  18. d.deeper

    d.deeper Private E-2

    i have done everything you suggested.
    and it said "PendingFileRenameOperations Data has been removed by External Process!"
    after i clicked yes and ok.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you still posted your HJT log as images, I assume you still have all the same problems. Like you cannot even save a log and programs randomly shutdown?
     
  20. d.deeper

    d.deeper Private E-2

    yes,you understand it correctly.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are all you file associations messed up?

    For one example, if you double click on a .txt or a .log file, does notepad open with the file contents?

    What about other associations? Check you file associations list in Win Eplorer, Tools, Folder Options, File Tpyes.

    You said "and programs still dont work properly" . Excactly what does that mean?

    Have you checked around in the Software Forum to see if anyone knows anything about "flyakite"?
     
  22. d.deeper

    d.deeper Private E-2

    i did it!the problems are really about flyakite
    i found the search about how to replace comctl32.dll and it works.
    problems solved.

    thanks again for your patience anyways. :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm glad to see you got it worked out and we fixed a few other problems along the way too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds