Online or off?

Discussion in 'Malware Help (A Specialist Will Reply)' started by RayDunne, Jan 25, 2005.

  1. RayDunne

    RayDunne Corporal

    Hi, I'm new here, but I did all the reading first. I have been maintaining my comp 4 a few years now and Bside Windows problems, haven't had 2 many issues, KOW. I am fairly confident of myself with a comp, but I still get stuck once in awhile and I'm very glad that U ppl R here 2 help. So without wasting NEmore time I'll get 2 it.
    I just have a quick question. I read the thread about "read me before you ask 4 support" and I have a good understanding of what I need 2 do. I was just curious as 2 whether I should run all of the scans and fixes while the machine is online or off. I have a second comp that is "clean" 2 use if NEthing happens 2 the 1 I am working on, which is my wife's sisters machine. She got a massive infestation of all sorts, really bad, and asked me 2 look at it because she has no cash 4 a pro and she knows I am good at keeping mine out of trouble. NEway, I installed ZoneAlarm, but whatever she got seems 2 know how 2 disable the internet lock and I was wondering if I should completely unplug the wire, after I update the prog.s of course, or if it OK 2 run the process with the machine online? NE info would help, and again, thanx 4 bieng here, I work 4 free 2 :confused:
     
  2. TheOldThug

    TheOldThug First Sergeant

  3. shewolf

    shewolf Specialist

    Run things just exactly as it says in the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    you will do somethings via online in normal boot mode and then it will have you switch to safe mode depending upon your OS (Operating System).

    Win9x (Windows 95, 98, 98SE) users boot normal mode


    And Windows XP, 2000, NT, ME, users boot in "safe mode with networking support" (and remain in there)

    So as you can tell it depends upon your operating system as to if you should be in Normal or Safe Mode..
    Follow all directions in the tutitorial and report back here what problems still exist and be as specific as possible the more information we have the better we will be able to help you.

    Please also tell us what Operating System you are on and if you are on WinXP we need to know what Service Pack (SP1 or SP2) you are using..
    Welcome to MG.. :)
    SW:)
     
  4. RayDunne

    RayDunne Corporal

    OOps sorry, the comp I'm cleaning is running XP Home and all updates R current so I believe it has SP2. Thanks 4 the info, I'm going 2 Give it a shot, B back soon w/ results. :)
     
  5. RayDunne

    RayDunne Corporal

    Hi, I'm back. No luck yet. I got as far as trying 2 run the Symantec online virus scan. I disabled System Restore, booted in safe mode and ran the Trend Micro scan with no problems. The scan found 16 threats and deleted them in short time, maybe 10 mins. I ran it a second time 4 fun and it found nothing. Hooray! Yeah, right! I tried 2 run the Symantec scan and got a bunch of pop-ups. After closing those I got 2 the scan part and got it running. It was very slow, but I let it run 4 a couple of hours. In the meantime, I tried 2 come here 2 C if was suppose 2 B that slow. I couldn't get IE 2 work at all so I just let it run. After it got about 75'/. done, the window just dissappeared, poof!!! I tried 2 get it going again, but IE won't have it. I rebooted, in safe mode again, and got it started again, after pop-ups were closed, and it was still slow and I lost IE 4 NEthing other than the scan. The pop-ups R various ads 4 scanners and junk. So instead of waiting a few more hours 4 the same result, I'll C if I can try something else. I'm stumped. I run Norton AV that's with System Works Premier 2005, can I update and run that instead of the online scan?
     
  6. RayDunne

    RayDunne Corporal

    Hi, I'm back, getting really frustrated here. I keep losing connectivity in safe mode. Properties say connection is alive, but nothing works after the 1st couple of operations I do. I am trying 2 get the Symantec scan 2 run, but I can't get past the part where it teies 2 open CD. Have 2 b quick, keeps shutting down now, b back later on "clean" comp, just want 2 get this posted in hopes of reply, please help.
     
  7. shewolf

    shewolf Specialist

    Ok we will go ahead and have you read the following tutitorial on attaching a HJT (Hijackthis) log file.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!


    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    After you post back with your log file as an attachment please be patient as it will be read by someone with more experience in dealing with HJT logs. Many are extremely busy with helping others and with things in their daily lives so please be patient.

    SW:)
     
  8. RayDunne

    RayDunne Corporal

    OK, this is gonna take me sum time to ingest, but I'll do my best. Another quicky tho, could I have infected my other comp by sharing the net cable from a Motorolla Surfboard cable modem ie;swithing cable back and 4th?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any PC connected thru your cable modem to the internet is susceptable to infections from the internet if not properly protected. So if you have problems on one chances are you have problems on the other. Since most people are creatures of habit, I would expect the PCs are configured very similar and that you surf in similar places on both. So they could have similar problems.

    In your case since one PC is only connected at a time, the first PC is not infecting the second.
     
  10. RayDunne

    RayDunne Corporal

    Thanx Chas, My main comp doesn't seem 2 B hijacked yet as I am pretty careful myself and try 2 keep up on security. I was just curious, because I saw a couple of strange processes in Task Manager. The comp I'm fixing is a favor 4 my sister in law and they haven't been careful at all. I was just hoping that I couldn't infect my comp with this junk she has by plugging my modem in2 it and then putting it back in mine. I also have used a CD-R to get files from my comp 2 hers and put it back in mine 2 write more files on. I haven't taken NE files from her comp 2 mine so I hope I'm safe there 2. I really dont want whatever she has, because it is damn nasty.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should still check your PC out. You did say you had unrecognized processes running. You don't have to see a hijack to have malware on your computer. There are thousands of malware problems that do not hijack your home page.

    You should follow the previous instructions Shewolf gave to you and post that HJT log on your problem PC (that is if you still have a problem).
     
  12. RayDunne

    RayDunne Corporal

    I didn't take any chances, I ran the full process described in the http://forums.majorgeeks.com/showthread.php?t=35407 successfully on my main comp. I had a bad memory stick and since I removed that, it has been performing better than it ever has. Thanx 4 all the info Chas. This experience is giving me a new respect for security. As for sis's machine, I am still in the process of ingesting the info in post #7 of this thread, from shewolf. She also has other issues to be resolved before I can continue. I think her memory is fried 2. I couldn't get a video signal the last time I plugged it in and that was how I found my memory problem. I had 2 stix in mine and after a few mysterious crashes, I pulled out the second stik and no video, I put that one in the first slot after removing the bad stik from it and BINGO, comp runs like a dream. Then I ran all tests from here and I seem 2to be OK for now. Sorry to get off track from my original post but her comp is taking a backseat, as she has a borrowed machine and I am working on my own projects now. I want to fix hers out of sheer determination at this pint so I want to keep this thread open, but I will start a new one for my stuff. Thanx again for any and all help.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But why are you so reluctant to post a HijackThis log. It only takes a couple minutes to post. You did say there were unrecognized processes running. You really should get them checked out.
     
  14. RayDunne

    RayDunne Corporal

    For my comp? I will tomorrow if you want. I posted this thread for my sis's comp, and I haven't got that far on hers yet and I didn't post one for mine because I didn't want to sidetrack from this thread, too much anyway, seeing as how I already have.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For whichever PC you thought you saw unknown processes on!
     
  16. RayDunne

    RayDunne Corporal

    Hi, the log 4 my comp. sorry took so long, just trying to understand how things work w/ limited time. :)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This PC is in serious need of updating you WinXP version and Internet Explorer versions. You must go to Windows update and get your updates. Running with these versions is a big security risk.

    Did you buy SkyKiller? It was long on a rogue/suspect spyware removal list. Recent versions have been remove from that list but the software is still consider not very good. You should uninstall it if installed.

    Do you use this WebFerret stuff? It is debateably considered spyware.
    O3 - Toolbar: Search - {A58686ED-FC46-44C3-95C6-4A812AB776F1} - D:\Program Files\FerretSoft\WebFerret\FerretBand.dll
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to disable Spybot's Teatimer because it may interfere with making the below fixes.
    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.

    I have one more question. Why are you have msconfig run? What processes are you inhibiting from loading? I really need to see a HJT log without anything being restricted from loading.

    Run msconfig and select Normal startup, then reboot and post a new HJT log.
     
  19. RayDunne

    RayDunne Corporal

    OK, I've updated, restarted in normal boot mode and ran HJT. I saved a logfile from that. As for Sky or SpyKiller, I don't know where that came from. My wife and kids were using this comp for awhile, so maybe something they did, or I just forgot. I do use Webferret and have for years without any problems that I was aware of, but if it is bad, I'll get rid of it and SpyKiller also, but haven't as yet because I want to see what you suggest. I ran HJT again, saved a log, which is probably the same as the first one after update, but saved anyway. All of the values that you wanted me to fix were not there after updates and reboot, but I selected the ones that were, closed everything and clicked fix. The first two and the fourth value were there and I fixed in HJT and saved a third log. This is the one I am posting, because it is the most recent, but if you need any of the others, let me know. As for msconfig, I had it like that, because there are alot of things in there that I don't want or need for one reason or another. I have been using this comp for almost four years and have done alot of things to it. There is alot of junk in there that I don't even have anymore and I don't know how to clean it up. So that's where I am at, let me know what to do.
    Thanx for all the help so far,
    Ray.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall (if installed) SpyKiller. I bet it is not. If not, just fix the below line using HJT and then reboot in safe mode and delete the D:\Program Files\SpyKiller folder.
    O4 - HKCU\..\Run: [SpyKiller] D:\Program Files\SpyKiller\spykiller.exe /startup

    If you like Webferret and trust it, leave it be. It is just one of those that has bordered on questionable. I see know reason to remove it.

    As for using msconfig, that was my reason for saying to stop using it. Tell me which stuff in your log you do not want to use anymore (ever) and we will work on removing them the right way. There are also better choices for Startup Managers to use than msconfig. They enable you to control what you load at startup making it easier to sometimes load other programs.
     
  21. RayDunne

    RayDunne Corporal

    I got rid of SpyKiller, it wasn't installed as you thought, so I did it with HJT. Which log are you referring to when you asked me what I wanted to remove? I do like Webferret and have never seen any problems related to it. I have been using it as long as I have owned computers, so I will keep it for now, but I will check into it. One other thing I would like to mention is that something seems to be bogging me down real bad at shutdown and startup. Haven't had mch time to look into it yet, but if you have any quick suggestions it would be appreciated. I don't mean to stray off track here and you must have alot to do, so if you're too busy I can probably figure that one out. I don't see anything strange in TM. It is taking an unusually long time to shut down, it doesn't hang, the HD is going like crazy. And the same at startup, loading the tray, but I don't see anything weird there either. I would also like more info on alternative to msconfig.
    Thanx,
    Ray
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The last HJT log you posted without msconfig limiting anything. What I'm asking is what stuff is now showing in your log that you would like to permanently uninstall (or delete) and which stuff would you possible want to just not load at various times (I don't personally care for this method but some find it useful.) There are also some items that maybe loaded at startup that are just not necessary to allow a application you may use to work later.

    The more things that are running, the longer it takes to load them and startup and vice versa to shutdown.
     
  23. RayDunne

    RayDunne Corporal

    Here are the lines from the HJT log that I posted last that I am concerned about. I know nothing about some, but others I definitely want out. The file has a small note with each line with my reference to each.
    Thanx again,
    Ray
     

    Attached Files:

    • run.txt
      File size:
      1.3 KB
      Views:
      4
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My comments are in red!! I attach some more things you should think about.

    1.) No longer installed
    O4 - HKLM\..\Run: [QD FastAndSafe] D:\PROGRA~1\PANICW~1\POP-UP~2\dpps2.exe

    Okay so have HJT fix that line and then delete the below folder (after reboot) if it exists:
    D:\Program Files\PANICW~1

    2.) Don't know what it is, always wonder?
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    See this: http://www.liutilities.com/products/wintaskspro/processlibrary/nwiz/

    3.) No longer installed
    O4 - HKLM\..\Run: [NeroCheck] D:\WINDOWS\System32\NeroCheck.exe

    If Nero is uninstalled, have HJT fix that line and then delete the file after reboot. What are you using to burn CD/DVDs?

    4.) Don't know what it is, new to me
    O4 - HKLM\..\Run: [KernelFaultCheck] D:\WINDOWS\system32\dumprep 0 -k

    Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out


    6.) No longer installed
    O4 - HKCU\..\Run: [Y!TunnelBasic] D:\Program Files\Y!TunnelBasic V1.1 Build 178\YTunnel.exe

    Okay so have HJT fix that line and then delete the below folder (after reboot) if it exists:
    D:\Program Files\Y!TunnelBasic V1.1 Build 178


    7.) Heard it eas no longer used???
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
    C:\WINDOWS\SYSTEM\MSJAVA.DLL

    See the READ ME FIRST thread and use the the MSJVM Removal Tool 1.0a.
    Then install Sun Java. As indicated.


    8.) No longer installed
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
    http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

    This is for the online scan. You can always fix O16 lines. They will just be redownloaded if and when you return to the site.

    9.) Don't recognize, not installed unless part of ZA
    O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) -
    http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab

    Fix as above in 8!

    10.) Don't recognize, don't like
    O23 - Service: GEARSecurity - GEAR Software - D:\WINDOWS\System32\GEARSec.exe

    See this: http://www.liutilities.com/products/wintaskspro/processlibrary/gearsec/
     

    Attached Files:

  25. RayDunne

    RayDunne Corporal

    I want to thank you very much, you all have been very cool, it is nice to have a clean comp. I will try harder to stay out of trouble now that I have learned quite alot about how this stuff works. I am still working on another computer for my sis in law and will have a much better understanding of what to do so that I may not require so much assistance. I vow to fight this crapware with all I have and I will recommend this site in any way I can. You guys and gals rule. Thanx a bunch.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  27. RayDunne

    RayDunne Corporal

    Hi, just wanted to post a follow up to let evryone know that all my problems have been solved by the wonderful people who help us all out in here. I have been free and clean since just after my last post here and have been following safety precautions and all is well. I have also learned a great deal from these posts and intend to fight malware to the end of my computing days. I'm strapped right now but as soon as possible I will make any contributions to the cause that I can, both here and to the freeware vendors and I would encourage anyone who has the means to do so to help out as well as we need more people and programs to fight this crap. Maybe someday the scumbags will give up if we all fight as hard as we can. :cool:
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a nice wish Ray! But I doubt the trouble makers will ever go away.
     
  29. RayDunne

    RayDunne Corporal

    Hi chas, just a little wishful thinking. :) I'm in the poor house right now, but I feel the need to do something to help out. I want to fight this stuff as much as possible. I am no expert, but I am pretty good following directions and learning. Just wondering if there is anything I can do to help out manually? I wish to fight this crap with all I have in me. Never really thought much of it before I was attacked myself, now I'm on a mission :mad:
     
  30. RayDunne

    RayDunne Corporal

    Just a little note to anyone reading this thread, I am finding that alot of this crap is coming from the kiddie sites that my oldest son likes to go to to play online games. Everytime he uses the computer, we pick up some kind of crap that I have to spend an hour or so getting rid of. I don't want to tell him he can't use the computer anymore, but everytime I tell him a site is bad and he finds another one, it seems to be full of it too. We bought a second computer for them for x-mas so that mine will stay clean, and I have to sit down at theirs a couple times a week and run all these scans and fixes. They don't understand what to do when the programs pick stuff up so I just let them run it and fix as needed, but I seem to be spending an awful lot of time on this. Guess that's just how it goes. :mad:
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes sites like that are typically trouble. Also P2P downloading programs (like Kazaa and many more) open the doors to problems.

    Did you complete all the steps in the link I gave you (
    How to Protect yourself from malware! )
     
  32. RayDunne

    RayDunne Corporal

    Yes, I completed all the steps in that link and things are working out well for myself on my pc, but my son is 8 and doesn't have the understanding of what to do when a program asks what to do and I'm not always here to guide him. I explain what I can and help him when I can and eventually he will know better what to do, but I have a 5 year old also who will be right behind him to do the same, so I'm looking forward to a few more years of fun taking care of their machine before this settles down and then who knows what other kinds of threats these scabs will dream up in the meantime. I don't mind so much now that I have a good idea of what to do, I actually find it kind of fun. I'm bored now that my comp is clean, need something to fight, but not bad enough to go looking for it ;)
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I sure your kids will give you some problems to battle soon enough! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds