Ok...now what?

Discussion in 'Malware Help (A Specialist Will Reply)' started by mae_west, Jan 22, 2006.

  1. mae_west

    mae_west Private E-2

    Hi,

    I ran all the scans and am attaching the hijack this log file. The counterspy log file said the 5 threats could be ignored.

    I have been having problems with the blue screen of death, programs freezing, slow start up for programs and general strangeness on what has been (up til about a 2 weeks ago) and almost perfect machine for the past year. Even tho I am running windows ME :(

    I used to run all the old removal tools (stinger, cw shredder, kill2me)about once a month and everything would be all tidy after. After dropping by the site yesterday and finding new removal tools available, and having run these new programs, I find I have gozilla and wildtangent showing up in the counterspy scan ( I thot they were gone bye bye).

    My log files are showing all sorts of miscellaneous crap. And I ran the 2 scans that you suggested prior to the HJT log.

    PS are there any scanners to replace Bitdefender and panda available to mozilla users? What I mean is can I sub Micros scanner for these other two? I really hate bringing up that blue e (of course, I will if need be), as I am now paranoid after being a mozilla user for so long now.

    * I have Windows ME (sigh), and I run AVG free, ZoneAlarm, I run regular scans with AdAware SE. I did just sign on for gmail... I hope that wasn't a bad thing.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only Trend Micro has a version to work with FF. But we don't use that in our recommended default steps.

    Where is the Panda log?
     
  3. mae_west

    mae_west Private E-2

    I can't get to anything else now. I keep getting " Runtime error 216 at 030D5E7A" and the hourglass.
    I may have to take evasive action...
     
  4. mae_west

    mae_west Private E-2

    Panda scan log?

    Here it is.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Panda scan log?

    I don't believe that your problems are really malware related but we have few things to clean up.

    Is the below really a game that you downloaded? Is it clean?
    C:\WINDOWS\Start Menu\Programs\Games\Stress Game.exe

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Additional step to delete bridge.dll:

    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\Windows\Downloaded Program Files\
    attrib -r -h -s bridge.dll
    del bridge.dll

    exit

    Now locate the below files with Windows Explorer and delete them:
    C:\WINDOWS\SYSTEM\ALXRES.DLL.bak
    C:\WINDOWS\INF\BI8.INF
    C:\WINDOWS\Desktop\outlook express\Jokes\wpad.eml[wpad.exe]

    Now reboot and post a new Panda log.

    You can also tell me if there is any improvement but I doubt these were related to your problems.
     
  6. mae_west

    mae_west Private E-2

    Hi Chaslang,

    I added the registry entry, but cannot do part 2. Computer gives error message " Windows cannot find 'cmd'. You may have typed the name incorrectly or another open program cannot find a system file. To search" etc etc.


    Mae
     
  7. mae_west

    mae_west Private E-2

    PS the stress game is clean ( I just ran an AVG scan on it) and it came from a reliable source.

    I see the wordpad joke is no longer in the file, so something happened to it. I can't say if it came from a reliable person.
     
  8. mae_west

    mae_west Private E-2

    I'm not feeling good, so my brain is a bit fuzzy. I typed in command and away we went. Sorry it took my brain so long to catch that.

    Attaching the latest Panda scan.

    thanks for your help,
    Mae
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. It is cmd on Win NT, 2K and XP. For Win 9X and Me it should be command to get to the command prompt. Use that and run the steps because the below file is still found by Panda:

    C:\WINDOWS\DOWNLOADED PROGRAM FILES\bridge.dll

    Are you sure you did that registry patch? Did it say it was successfull? It still shows in your log and it should have been removed by the patch.

    Also empty your Recycle Bin and cleanup the FireFox cookies if you want them not to show in a Panda scan. But note that cookies will just keep coming back when you surf. It is normal.
     
  10. mae_west

    mae_west Private E-2

    Attaching latest Panda log.

    Patch said it was successfully added to registry, but I did it again and that one was successful as well. Recycle bin is empty now, and firefox clean up is done.

    Mae
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks to me like something is blocking the file deletion and the registry change because your log still looks the same.

    Is the version of CounterSpy you have a paid version? If not, uninstall it and repeat the fixes. Also you make sure you close all browsers before trying the fixes.

    Are you sure the deletion of the file is working properly? You must make sure that your command line prompt is showing that you are in the C:\Windows\Downloaded Program Files folder befroe trying to delete the file.

    If this does not work, we may need to delete the file after booting your PC in MS-DOS mode.
     
    Last edited: Jan 23, 2006
  12. mae_west

    mae_west Private E-2

    You are right..the command prompt comes up C:\WINDOWS\Desktop. How can I change that? I know nothing about this stuff.

    I also cannot delete one file from Sunbelt (counterspy)(no doubt probs with ME). I get an error message when I try to empty the recycle bin, because I had to manually delete it. It still has 12 days left on the free trial.

    Mae
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was already in my instructions. The first command to run is:
    cd C:\Windows\Downloaded Program Files\

    Make sure the prompt now shows the correct path.

    Try it after reboot. Or try it in safe mode.
     
  14. mae_west

    mae_west Private E-2

    I did that- 3 times. After I type in cd C:\Windows\Downloaded Program Files\ it comes up:"Too many parameters - Program".
    The prompt stays at:
    "C:\WINDOWS\Desktop".
    I have tried it with the "Windows" all in caps too.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try putting quotes around the path info like below:

    cd "C:\Windows\Downloaded Program Files"


    Does that work?
     
  16. mae_west

    mae_west Private E-2

    That did it. Here is a new log file. I re-ran all the scans (minus counter spy which is deleted). Also did cw shredder and kill2me.

    Mae
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried the registry patch (see msg # 5) again since uninstalling CounterSpy?
     
  18. mae_west

    mae_west Private E-2

    Yup. Howz it look now?

    M
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! The below is still there!

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{014DA6C9-189F-421A-88CD-07CFE51CFF10}

    Do you know how to use the registry editor and how to take Ownership of a registry key?

    If not then download and install the below which may be easier to use:

    Registrar Lite

    Then run Registar Lite and navigate your way to that registry key. Once you have selected it, click on the top menu where it says Security and select Take Ownership. It should respond with a message telling you which user has taken ownership of the registry key (ir should be the user account you are login on with). Click OK.

    Then right click on the key and select Delete. Let me know if that removes the key.
     
  20. mae_west

    mae_west Private E-2

    I don't have windows xp, so I cannot use the security feature.

    I can access the key thru regedit, but don't know how or what to modify.

    Mae
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I forgot you had Win ME.

    If you installed Registrar Lite then use it to locate that key and see if you can just delete it. Try it in safe mode if necessary. Make sure you shut download ALL browsers and antivirus and antispyware applications first.
     
  22. mae_west

    mae_west Private E-2

    I went into safe mode and manually deleted it. I checked RLite and the key is not there.
    I did another panda scan; should I run some more scans?

    Mae
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! If your Panda log no longer displays the registy key, you should be okay.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  24. mae_west

    mae_west Private E-2

    Thank you so much!!!! thank you for all of your help- you are a wizard!

    I try to follow the guidelines as much as possible for avoiding malware, but my 8 year old likes to frequent tv sites to play games, and I am sure that is where some of this crap comes from.

    Mae
    PS I am hoping to get a new HD and install Xp (ooooh, the modern world!), but until then I must put up with the quirks of ME.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    What is your CPU speed and how much RAM do you have in your PC?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds