O.K. please help...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Justshootme, Sep 18, 2006.

  1. Justshootme

    Justshootme Private E-2

    I have tried to follow all the steps in "read me first" but I can't find the .bat files you refer to in step 6B. What's up with that?
     
  2. Justshootme

    Justshootme Private E-2

    I think Im ready for your help now!!!

    Justshootme:


    O.k., let’s try this again. After your reply, I went back thru your instructions and did as much as I could. Spybot identified the CoolWWWSearch Trojan on our system! I downloaded Spybot and found it two weekends ago. I thought it was fixed. I was on-line with McAfee tech. Ran system in safe mood (administrator status; tech downloaded a fix file; that didn’t work either. He deleted temp files and cookies. That didn’t work. I download Microsoft Window Malware Software Removal.exe; didn’t work. I followed steps for About:Blank and have posted on your website to the best of my abilities. Also disabled system restore until this is resolved. I think I identified a bad 04, but I can’t delete w/ Hijack, not even in Admin.Mode/Safe Boot. Went through steps in "Special Removal Procedures" . Couldn’t find the HKEY_LOCAL keys in “chalang’s” generic solution. Still have about:blank page. Help! Much thanks.

    |EDIT: removed inline log
     
    Last edited by a moderator: Sep 19, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were supposed to download the ZIP files and extract them at the beginning of step 4.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    @Chas, found a dupe thread, merged but your post ended up out of context.


    @Justshootme, as you mentioned that you had tried to follow the steps in the read me, you need to re-read and follwo them closely and attach the requested logs, your HJT that has been deleted was installed and run from a ZIP file and not renamed as specified to analyze.exe, these steps are designed to help you find all malware on your PC, do please follow the below,

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. Justshootme

    Justshootme Private E-2

    Ready, are you?

    Justshootme:

    This is the first of two posting w/attachments.O.K., here is the breakdown of what I did:
    1) Ran an update of all scanning applications. Made sure hidden files were unhidden; went back and reinstalled HijackThis properly ( I hope).
    2) Ran Ccleaner in Safe Mode on all accounts, found some tracking cookies
    3) Ran Spybot in Safe/Admin., found CoolWWWSeach and CoolWWWSearch Toolbar, fixed it (I think).
    4) Ran Microsoft Malicious Software Removal Tool in Safe/2nd account, found nothing. Couldn’t find the application in Safe/Admin.
    5) Tried to run Windows Defender in Safe/Admin – couldn’t do it, so ran it in Safe/2nd account, found nothing.
    6) Ran BitDefender in SafeMode/Admin., found nothing
    7) Ran Panda ActiveScan in Safe/Admin., was unable to print report because I couldn’t click on “save report” – didn’t have a max. sized window. Had to run Panda in regular boot!

    I hope you can help me now. I have tried to follow your instructions to best of my abilities. Thanks in advance.
     

    Attached Files:

  6. Justshootme

    Justshootme Private E-2

    2nd of two threads:

    Here are the reminder of my uploads.
     

    Attached Files:

  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI Please keep all your posts in this one thread as if the information is posted in separate threads then they will get lost or deleted as duplicates.


    You will need to run Hijackthis again as you have not re-named it to analyze.exe ( C:\Program Files\HJT\analyse.exe\HijackThis.exe ) but renamed the folder it goes in, instead. reason for re-naming the .exe file is that namy new malwares are not picked up if the .exe is not re-named, they have become wise to Hijackthis.

    Then once run Hijackthis as analyze.exe please attach a new log in this thread only.
     
  8. Justshootme

    Justshootme Private E-2

    O.K. I hope I have renamed this thing correctly. Here is my hijack log.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Ready, are you?

    You also hvae not followed the directions for using GetRunKey and ShowNew. YOU MUST EXTRACT ALL files from the zip file into a folder and you must exit your WinZIP (or whatever program you use to extract them) and then you must locate the GetRunKey.bat and ShowNew.bat files using Windows Explorer and double click on them to run them. This is explained in the download page for each program. We only need the runkeys.txt and newfiles.txt log. We do not need or want the other intermediate temporary files that are created.


    Also you never told us what you malware problems are?
     
  10. Justshootme

    Justshootme Private E-2

    Alright, I hope I did these correctly. Look, I'm new at this--it's taking all my time to figure out your instructions and how to do these things. Anyway, our system runs slow, especially at startup. This thing was changing our homepage; it opens strange non-functioning half-windows; about:blank page is driving us crazy--and yes, I ran throught the Special Removal Procedures sticky thread. Didn't work.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you do not have an about:blank hijack problem so there was nothing for that procedure to fix.

    You don't have malware problems! I would suspect that you biggest problem is what McAfee is doing to your PC. Just look below in the quote box. This is all the stuff showing in your HJT log that only pertains to McAfee:
    McAfee is bringing your PC to a crawl is my bet!

    And while I don't have much experience with the following, I would be they are not help either. These are items shown in your uninstall programs list that I can see in your log from ShowNew.

    Windows Live Messenger
    Windows Live Outlook Toolbar (Windows Live Toolbar)
    Windows Live Sign-in Assistant
    Windows Live Toolbar Feed Detector (Windows Live Toolbar)
    Windows Live Toolbar MSN Extension (Windows Live Toolbar)
    Windows Live Toolbar
    Windows Media Connect
    Windows Media Format 11 runtime
    Windows Media Format SDK Hotfix - KB891122
    Windows Media Player 11
    Windows Media Player Hotfix [See Q828026 for more information]
     
  12. Justshootme

    Justshootme Private E-2

    O.k. we're have been considering yanking McAfee for one of your free AV/FW sites.I know how you folks feel about 'resource hogs' like McAfee. But we still have an about:blank page! And tell me please how to yank the google toolbar and the windows live messenger! I don't remember purposely saying yes to either. We DID have the CoolWWWSearch Trojan and its Tools bar which Spybot says it fixed. What now? Are all the files/register stuff associated with it gone??
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: READ THE WHOLE BELOW MESSAGE BEFORE DOING ANYTHING.

    Did you uninstall McAfee already? If not, are you going to? Make sure you get an antivirus and a firewall installed immediately. See the ones in this link: How to Protect yourself from malware!

    In fact you should download the new antivirus and new firewall programs before uninstalling McAfee. Then disconnect your cable to the internet and uninstall ALL of McAfee's software. Make sure it is all gone by peaking at a new HJT log afterwards. Once it is all removed, install the new antivirus and firewall. Then you can reconnect to the internet.

    Windows Live Messenger can be uninstalled via Add/Remove programs just like most programs should be uninstalled including Google Toolbar.

    After you uninstall all this stuff attach new logs from GetRunKey and HijackThis.
     
  14. Justshootme

    Justshootme Private E-2

    We're considering going with EX Armor 2005 from CA Associates for our AV/FW. It's offered free from our cable high speed supplier, RoadRunner. What's your opinion of CA Associates. You do still insist that we do not have a malware problem??? Spybot found CoolWWWSearch and its Toolbar. Can I assume it's fixed? We STILL have the about:blank page.
     
  15. Justshootme

    Justshootme Private E-2

    Correction, EZ Armor 2005, not EX!!
     
  16. Justshootme

    Justshootme Private E-2

    STILL getting about:blank window, sometimes I get this half-window that doesn't function at all and I have to end my internet connection and start over. HELP!
     
  17. Justshootme

    Justshootme Private E-2

    Here is THE very latest:

    1. Unistalled most of the Windows Messenger Live crap WHICH got rid of about:blank page!!!!!

    2. Unistalled ALL of McAfee Security Suite

    3. Installed and updated Avast! Home Edition:
    Found & Quarantined the following:
    File C:\WINDOWS\Downloaded Program Files\bdcore.dll ERROR 0xc000000D {An invlaid parameter was passed to a Service or function}
    File C:\WINDOWS\Downloaded Program Files\libfn.dll ERROR 0xc000000D {An invalid parameter was passed to a Service or function}
    File C:\WINDOWS\system32\ActiveScan\pskavs.dll is infected by win32:CTX

    4. Installed and updated ZoneAlarm

    5. Oh, unistalled Google Tool Bar, and 2 versions of Sun Java; we have the JRS vers. 5.0, update 6; adjusted Active X security settings from your article on Protecting computer from Malware.


    Wheww!!! Would appreciated your feedback from #3, was my computer communicating w/remote computer??????
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And did you notice a significant increase in performance?

    All three of those are false postives! bdcore.dll and libfn.dll are part of Bitdefender Online scan. And pskavs.dll is part of PandaActive scan (I even mentioned this one in the READ & RUN ME).

    And no I would not use the stuff from your ISP. It will more than like be a combination of software from multiple vendors or it will be another huge security suite resource hog log McAfee.

    You can use HJT to fix the below left over that McAfee did not remove when you uninstalled it:
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

    You can also fix the below if desired. They are not malware but are not needed and removing them will also increase PC performance:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab

    As I said from the before, you had no malware!
     
    Last edited: Sep 23, 2006
  19. Justshootme

    Justshootme Private E-2

    System performance has improved dramatically!!!

    I still have this 04:

    HKCU\...\Run:[ctfmon.exe]C:\WINDOWS\system32\ctfmon.exe

    Your “About:Blank and HAS (ask only the Best)Hijackers – Generic Solution” specifically mentions this in ‘How to Identify Hijacker Lines: An example” as a bad file line” identifier! It follows the format “notice the name in [] is an exact match of the file name at the end of the line”. I had HJT fix this line and it KEEPS COMING BACK! If this is not a hijacker line, what is it? I attached my latest HJT log.

    Otherwise:

    I restored the ActiveScan dll; but I have following in quarantine:

    kernel32.dll C:\\WINDOWS\system32
    winsoc.dll C:\\WINDOWS\system32
    wsock32.dll C:\\WINDOWS\system32

    Can/should I restore or delete?

    I fixed your suggestions w/HJT.

    I like the Avast and ZoneAlaram. My question is this: do you recommend any other freeware to handle popups/spyware that my McAfee suite was covering?

    P.S., you’re an angel! Thank you.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it was bad, I would have had you fix it. It is a Windows system file. You can read about it here: http://www.liutilities.com/products/wintaskspro/processlibrary/ctfmon/

    None of your logs showed any evidence of those kind of lines. And while the above ctfmon.exe sort of matches that description, it is not an unknown process.

    Why are these in quarantine? Who deleted them? They are required system files.

    I don't really find popup blockers to be necessary but FireFox has one builtin the you will find useful. Everything you need for protection is covered in the How to protect link I gave you in a previous message.

    Thanks! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds