no tool bars or download

Discussion in 'Malware Help (A Specialist Will Reply)' started by bazza08, Apr 5, 2007.

  1. bazza08

    bazza08 Private E-2

    Hi all

    I hope someone can help me; a friend brought his laptop round for me to fix he said he got an email from Microsoft saying it was an update. I told him they don’t send updates by email!! But now he cannot download anything and he has no tool bars or tabs in ie7, it has one bar the address bar and right clicking on it will not open tools nor will pressing Alt. has anyone else had this email???

    Thanks Bazza08
    :cry :cry
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Yes their are a few going around, one notable one is this one http://www.networkworld.com/news/2007/033007-new-virus-comes-disguised-as.html

    Best bet for your friends PC is for you or them to follwo the below and attach all the logs requested.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. bazza08

    bazza08 Private E-2

    Hi
    Sorry it has taken so long to reply problems at home

    I have run AVg with nothing found, I have run spybot and nothing found
    I cannot run bitdefender it says “could not load the online scanner.
    And when I try to run Panda active scan it says scan started click the bar above to start the download but there is no bar !!
    I have attached the HJT, runkeys and newfiles for you to look at
    Thanks Bazza08
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run AVG Antispyware! Please run it and attach the log or run CounterSpy as requested in the READ ME.

    Based on your newfiles.txt log, Panda was never started. It would appear in add/remove programs if it was. This it sounds like you actully did not get passed the initial steps. Are you using Internet Explorer to do the scans. Uninstall this old Sun Java version: Java 2 Runtime Environment, SE v1.4.2_05

    You have a service left over from Symantec that needs to be removed.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SymWMI Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymWSC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    Also please install rename HijackThis.exe as requested and also only attach a HijackThis log from normal boot mode as requested in the READ ME. Attach a new one from normal boot mode after renaming.

    Is the below something you configured?
    "PostOOBE"="C:\\WINDOWS\\system32\\wscript.exe C:\\DRIVERS\\POSTOOBE.NEC //E:VBS"


    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

     
    Last edited: Apr 8, 2007
  6. bazza08

    bazza08 Private E-2

    Hi m8

    yes i am using ie7,ican go to different sites but i cannot seen to interact with them like downloading and the like, with panda it says click on the bar to start but no bar appears!

    When i try to do below instructions it says "the service you entered is system-critical! It cant be deleted.”

    Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    At the lower right, click on the Config button
    Then click the Misc tools button
    Select Delete an NT Service
    Copy/pasteSymWSC into the box that opens, and press OK
    If you receive any error messages just ignore them and continue.
    Now exit HJT and reboot when it tells you it needs to.



    dont know what this is m8!!
    "PostOOBE"="C:\\WINDOWS\\system32\\wscript.exe C:\\DRIVERS\\POSTOOBE.NEC //E:VBS"


    all new log attached
    thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My directions did say to ignore error messages! It was deleted as desired.


    Put a copy of the C:\DRIVERS\POSTOOBE.NEC file into a ZIP file and attach it here.
     
  8. bazza08

    bazza08 Private E-2

    hi M8

    here is the file you wanted

    thanks bazza08
     
  9. bazza08

    bazza08 Private E-2

    sorry lol
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that does not look like a problem!

    I don't think your problem with IE is currently due to malware since none of the scans show any problems. You may want to take a look at the below:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;555130

    If that does not help, try uninstall Windows Internet Explorer 7.
     
  11. bazza08

    bazza08 Private E-2

    hi chas

    thank you for all your help m8 at least i know i have no problems,i uninstalled then reinstalled IE7 and it seems to have sorted out the problem

    thanks again m8

    bazza08
    ;) :wave
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds