Negative Effects and Affects from Spyware... is anyone out there familiar?

Discussion in 'Malware Help (A Specialist Will Reply)' started by da_vinci1452, Apr 18, 2005.

  1. da_vinci1452

    da_vinci1452 Private E-2

    Hello out there... it's been years since I've done more than put in a new dvd player I am afraid to say. I have encountered both Maleware and spyware on my Dell 8100 running XP pro SP2 OS.

    It's seems I am unable to erase or otherwise remove this unwanted germ in my pc. I have followed the steps listed in "Basic Spyware" with the exception of "Trend Micro's Free Online Virus Scan" that simple does not seem to run on my pc. That's okay neither does the newest version of Limewire either. Not to digress I am stuck with ads and pop-ups. Additionally, some of my basic OS is now corrupted or missing i.e. my solitaire game that comes with the basic OS, the selection of cursor types like 3d or what have you. Of course this is just what I have discovered to date... and finally, whenever I reboot I receive a box from the Windows Task Manager that states my "rundll32.exe" is not responding and I must choose to end it manually or wait a few seconds and it will shut the "rundll32.exe" down for me. I have been out of the loop with this stuff since I was laid off in the network industry about four year ago. I am at a loss to know how to repair the pc I must use for both work and play. Can anyone help? It will be truley appreciated.

    All good kilobytes,

    Da_vinci in Los Angeles, CA.
    da_vinci1452@yahoo.com
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Limewire contains adware anyway. You should not be using it.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. da_vinci1452

    da_vinci1452 Private E-2

    Chaslang,

    Thanks for your reply. I have done as recommended. The log file is a attachment to this posting.

    I don't know if I must reinstall my OS to get some of it's basic features back. whichever the case - it seems to me this sort of melicious stuff should be criminal and prosecuteable. argghhh! If I went over to a strangers house and rekeyed the locks would it be a crime? hmmm... Well anyways - if you would be so kind please review the attached log file. I am truly thankful.

    Your connection in Los Angeles.

    da_vinci1452

    da_vinci1452@yahoo.com
     

    Attached Files:

  4. da_vinci1452

    da_vinci1452 Private E-2

    Chaslang,

    I don't know if this matters but I will tell you what software I have run to try and stop this mennace to society:

    Adaware SE
    Spybot
    Norton System Works 2003/the Antivirus is up to date
    Spyware Blaster
    CCleaner
    Spyware Nuker 2005 - full version
    and of course - I've just run HJT.

    - This kind of remind me of this latin phrase I heard in school many years ago...

    Ne invoces expellere non possis (translated from latin it means roughly :
    Do not call up that which you cannot put down).

    I think my daughters owe me a new pc. Only problem they are 11 and 13.
     
  5. da_vinci1452

    da_vinci1452 Private E-2

    By the way.. would you happen to know if there any hope of restoring Solitaire, 3d pinball, my 3d cursors, etc??
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\DOCUME~1\JOHNNY~1\LOCALS~1\Temp\bs52.tmpbsx32\bbi2.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr51.dll
    O2 - BHO: C:\WINDOWS\lbbho.dll - {704AAF32-C94D-4960-B0C5-2EA623080EBB} - C:\WINDOWS\lbbho.dll (file missing)
    O2 - BHO: SST - {FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} - C:\Program Files\Lycos\sst.dll (file missing)
    O4 - HKLM\..\Run: [cfgmgr51] RunDLL32.EXE C:\WINDOWS\cfgmgr51.dll,DllRun
    O4 - Global Startup: PowerReg Scheduler.exe
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)
    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\cfgmgr51.dll
    C:\Documents and Settings\JOHNNY~1\Local Settings\Temp\bs52.tmpbsx32\bbi2.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.


    If you are having problems with Windows games you should discuss that in the Software or Game Forum. You may be able to just reinstall them.
     
  7. da_vinci1452

    da_vinci1452 Private E-2

    Chaslang,

    I have attempted to follow your instructions however, there have been a couple of hitches. Everything was going per your instructions up to and including entering safe mode and deleting "C:\WINDOWS\cfgmgr51.dll". The next step I could not complete as the file could not be found "C:\Documetnts and Settings\JOHNNY~1\Local Settings\Temp\bs52.tmpbsx32\bbi2.exe".

    All was as to be expected until I opened the folder "bs52.tmpbsx32" and found it empty. I have no hidden files that I am aware of so all should have been shown to my understanding. So - I improvised (in retrospect not always a good idea with pc's) and deleted the entire folder as it was empty.

    Then upon running Ccleaner the folder "c:windows\Prefetch" was not to be found.

    After this I did reboot into regular operating status and am now posting the new log from HJT.

    Any Ideas?

    da_vinci1452
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about the file you could not find. Deleting the folder was okay.

    You picked up a new problem - ShopAtHome.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\SahAgent.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\system32\SahAgent.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\SahAgent.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. da_vinci1452

    da_vinci1452 Private E-2

    Chaslang,

    I followed your instructions and all went as they stated it would... until I rebooted my pc out of safe mode only to find that my quick launch bar and several program have disapappeared off the face of the earth - well at least off of my list of programs. Mozilla Fox-Fire browser is gone. Netscape Navigator is gone (I had previously thought that it would be a sound idea to migrate away from IE.) However, things haven't work like I planned. Some rather odd thing have happened. For instance, my printer can not be found and I am unable to reinstall it. I saw a box appear in Windows that stated "the operation could not be completed" with a red cricle and a white "x" through it as a Icon. When the pc rebooted it offered a similar box stating something to the effect of an "Inproper Handle" ??? with an all black screen. :eek: I'm totally lost.

    I am wondering if perhaps backing up my meager collection of photos and mp3's. might be in order. Your thoughts are appreaciated.

    I am at a loss for what to do next as I am slowly diminishing the functionality of this pc yet norton say no virus... and "Malware" was present when running spybot and Spyware Nuker 2005.

    signed confused in Los Angeles.

    da_vinci1452
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Fixing SAHagent would not cause those problems. Here is some info on it: http://www.liutilities.com/products/wintaskspro/processlibrary/sahagent/

    It is malware and needed to be remove and that is all my steps did.

    Are your applications like Mozilla and Netscape still functioning correctly when you try to bring them up using other methods. If so, just add them back to your quicklauch bar.

    I would guess your priter has not been working for awhile.

    When exactly did you get
     
  11. da_vinci1452

    da_vinci1452 Private E-2

    Hi Chaslang,

    I didn't mean to infere that your instructions had caused these issues. In fact I am certain that the original problems of Malware/spyware/adware or what have who knows what else have is what did this. I am nothing but thankful for your assistance - truly. It is obvious that you know your stuff.

    My printer stopped working along with the ability to add a printer at or before the same time that these add box's showed up. however, the printer was working just a few days before. It seems to me that something has been able to either erase or disable/corrupt several basis parts of my Windows XP Pro OS such as changing my cursor style, adding removing printers, solitaire, 3D pinball, and who knows what else. I have noticed one consistancy here. These are all part of the OS when one installs XP Pro on a pc. They all worked fine until all this started so I can only work under the assumption that these are all related symptoms to the problem at hand. They may indeed requite several fixes. Equally as bad is that I have not the slightest idea precisely what started this series of unfortuneate events.

    To answer you question:

    The splash box appeared stating something about an incorrect or improper handle - as my pc rebooted from safe mode.

    The other splash box appeared when I attempt to reinstall my printer and it basiscally stated that it could "not complete the function" - for reasons I do not fully understand.

    Something appears to have corrrupted a portion of my OS or at least earased part of it's subfeatures at the same time this spyware appeared.

    I will now check out the link you gave me and hope to hear from you soon.

    Thanks again for all your input and help look forward to your reply.

    da_vinci1452

    p.s. I have attached another log file.
     
    Last edited: Apr 20, 2005
  12. da_vinci1452

    da_vinci1452 Private E-2

    Chaslang,

    sorry the log file had to go in a seperate message.

    da_vinci1452
     

    Attached Files:

  13. da_vinci1452

    da_vinci1452 Private E-2

    Chaslang,

    Your other question: my applications are found in the programs list i.e. start/programs/etc.

    It appears the quicklaunch including the "showdesktop" icon have all been removed. hmmm That's one I don't know how to find again. lol! a puzzlement.

    da_vinci1452
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can add items back to QuickLaunch by simply dragging and dropping and select Create Shortcut here.

    For you printer problem, I wonder if any of your services have been stopped. Like spoolsv.exe.
    Click Start, Run, and enter services.msc and click OK.
    Look thru the list of services for Print Spooler and make sure Startup Type is set to Automatic and that the Service status is Started.

    When you tried to reinstall it, what happen? You may want to work this out in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds