Need your help Please!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thearizonarabbit, Sep 22, 2004.

  1. thearizonarabbit

    thearizonarabbit Private E-2

    First off- you guys are fantastic. Reading your forum has helped me before. Now I have a new problem. Started off as a browser hijack and then got worse. Won't let my Norton Antivirus load and didn't let my Window's Media player load until CWSShredder fixed that problem (supposedly. I haven't reloaded the player yet). Heres the stats:

    Operating system: Windows XP Home edition w/SP1
    ISP: Comcast cable

    Steps taken so far: Followed all the steps (exactly as written) in the Read me first article- disabled restore, enabled viewing of hidden folders downloaded/installed all software mentioned, Installed HJT in its own folder, booted in safe mode and ran the online Virus scanner-Trend Micro ( it found 17 trojans and deleted them), tried to run Symatec Security Check but at the end of scan when results page should come up, I get a blank browser window only!, Ran Stinger- no problem, Ran all other programs (S$D, Spybot, etc. - no result), CWshredder did find SearchAssitant and deleted it. Last- ran HJT and deleted redirect entries and search assistant entries. This has helped but Norton still won't work and my systems still slow! Any advice you give will be followed to the letter! Thanks guys!
     
  2. Kodo

    Kodo SNATCHSQUATCH

    It could be one of the viruses disable Nortons. Some have been known to do this. The resolution to that is to reinstall it.

    Please upload your HijackThis log as a TXT file only so we can see what's up.
     
  3. thearizonarabbit

    thearizonarabbit Private E-2

    Ok, heres the log. I should note that after taking all the steps I mentioned in my previous post- my browser seems to be ok but don't know if theres residual nasties left or not. Unfortunately, Norton antivirus is still not working. Email and Auto Protect are disabled and I can't get them back up. My computer came with the all-in-one software on restore CD's but they won't let me selectively re-install a particular software like norton. Its wipe the disc, reformat, or nothing! Any suggestions?
     

    Attached Files:

  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Small logfile, but tricky:

    First one I am unsure of:
    C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE

    This one.. do you have any SiS drivers installed? If not, this is probably W32/Gaobot.CR virus so remove it:
    C:\WINDOWS\system32\slserv.exe

    Next 3, again, suspect, but I do not know what they are because of the short filename. As in the first post, please check into them and remove if needed:
    O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
    O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
    O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE

    These can be removed:
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
     
  5. thearizonarabbit

    thearizonarabbit Private E-2

    The entries txtbrg stand for Text Bridge- a software that came with my scanner and has been problem free. I don't know what SiS is, please explain. Also, any suggestions on how to get my norton re-installed? Any web sites with files, etc. I can download from? Also took out those buttons you suggested. Thanks for your help. Ran Rav antivirus search (online) and found other sys32 nasties (ms32.exe,nts-hhnt.exe,PEntororms.exe, and SyPE.exe). I removed all but the ms32.exe. Wasn't sure about it. Any thoughts?
     
  6. thearizonarabbit

    thearizonarabbit Private E-2

    Hello Major Attitude!

    I was just wondering what you meant when you repied to my post? You wrote:
    .. do you have any SiS drivers installed? If not, this is probably W32/Gaobot.CR virus so remove it:
    C:\WINDOWS\system32\slserv.exe

    I don't know what SiS means. Of course I know what drivers are. My computer's still slow and my Windows media player and Norton antivirus seem to be corrupted to not run. Thanks for all yall's help!
     
  7. Kodo

    Kodo SNATCHSQUATCH

    SiS is a chipset manufacturer for motherboards etc.
     
  8. thearizonarabbit

    thearizonarabbit Private E-2

    Thanks Kodo and the rest of you guys- Keep up the good work! We out here in la la land appreciate the help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds