outlook.exe problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sickie, Feb 24, 2006.

  1. Sickie

    Sickie Private E-2

    Dont know if anyone can help me, im a bit of a novice with a pc and I naievely thought i was completely protected by Avast. Got bitten in the ass couple of days ago when it all hit the fan whilst downloading off Limewire.
    Have uninstalled lime, gone through the steps posted, done them all except panda, as avast wouldnt let it through. Also bought Spyware Doctor and installed Spyware Guard and Spyware Blaster (closing the gate after the horse has bolted???).
    On boot up, Internet explorer keeps trying to connect, Spy Doc says something like outlook.exe prevented from running bearshare.exe, an when I ran bdscan it couldnt disinfect or delete outlook.exe, said it was a Trojan Dropper.

    Can anynbody help???
     

    Attached Files:

  2. Sickie

    Sickie Private E-2

    ooops, ran hijack from zip folder, heres is log again incase it makes a difference
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\outlook\outlook.exe
    C:\WINDOWS\system32\winlog.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
    O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
    O4 - HKLM\..\Run: [winlog] winlog.exe
    O4 - HKLM\..\RunServices: [winlog] winlog.exe
    O4 - Global Startup: svchost.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\outlook <--- the whole folder
    C:\WINDOWS\system32\winlog.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Now I want to locate a bad file on your system named svchost.exe but there are also good ones with the same name so do not delete anything. Just tell me what is found.

    Click Search and the Select "All files and folders"
    Enter svchost.exe in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    • Search system folders
    • Search hidden files and folders
    • Search subfolders
    Then click the Search button. Report pack to me the exact locations where it is found.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Feb 24, 2006
  4. Sickie

    Sickie Private E-2

    Killed processes in Hijackthis ok,
    fixed lines ok,
    booted to safe ok,
    deleted folder C:\program files\outlook ok,
    UNABLE TO DELETE: C:\WINDOWS\system32\winlog.exe

    When I came to delete C:\WINDOWS\system32\winlog.exe it gave me the error msg, looked for read only, was unchecked, went to task manager to kill process, and got msg: Unable as critical process. Copied tasks (see attach) in case this will help you.

    Completed rest of instructions ok,

    Upon reboot to normal mode, IE didnt try to connect itself this time, but Spyware Guard gave me message:

    ATTEMPT TO CHANGE IE SETTINGS
    IE search page changed to http://

    I clicked "restore old value"
    It did this about 5 times, clicked restore value each time, then it stopped.

    Havnt disabled/enabled system restore yet, is that right?

    Thanks for your time and help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you were trying to delete C:\WINDOWS\system32\winlog.exe
    And not winlogon.exe

    Check again for ONLY winlog.exe!
     
  6. Sickie

    Sickie Private E-2

    Yeah, I was trying to delete the wrong one, lol

    Have removed winlog.exe now

    Upon return to normal mode, I got another alert msg from Spyware Guard for attempt to change ie settings, but only 1 this time, not 5
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a good thing Windows stopped you. Otherwise you would no longer be able to boot your PC and login. NEVER EVER delete anything you are not told to delete. You must be very careful to match file names and paths (the location of the file) exactly. Otherwise, do not touch it.

    Either allow the change or uninstall Spyware Guard for now. It is probably just the changes we were trying to make.
     
  8. Sickie

    Sickie Private E-2

    Have rebooted again, and nothing....

    No Spyguard warnings
    No rouge Internet Explorer
    No automatic downloading of virus'
    No infected files off any of the scans
    NO MORE HEADACHE!

    Everything seems to be working fine now.
    A BIG thankyou to chaslang, and all the people at Majorgeeks. Possiby the most usefull and helpfull website I have ever found/used.

    Thanks again
    Dave

    :D
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Dave! If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds