Please Help!! Viruses just love me and won't go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by bobbybb, Mar 27, 2006.

  1. bobbybb

    bobbybb Private E-2

    Hello all who was kind enough to view this message,
    I am under attack and am losing. After spending much needed time reading your forum I have gathered up the courage to try to request some help of my own (please do not kill me if there is some problems, I am, after all a newbie at this). Along with two attached .txt files (online scan bitdefender is ready to go but exceeds the size limit for this site, any advice?) I have ran:

    Ccleaner
    AdWare-SE (with VX2 Plug-In)
    SpyBot S&D
    Microsoft Windows Defender/ Mal. Remover
    Stinger
    HSRemove
    CWS Shredder
    Spyware Blaster

    Using Trend Micro free online scan I found that I have WORM_AGOBOT.AP, WORM_AGOBOT.KA, TROJ_DROPPER.AJE, TROJ_ADCLICK.BJ, TROJ_DLOADR.AA. However, it can not remove them. Is there any hope?

    Thank you all for your time in reading this horror show that is this thread (please let me know if I screwed up something)
    Bobby
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    If you compress the log into a ZIP file and then upload the ZIP file, it may meet the size limit.

    You have a load of problems! This is going to require a bunch of work and some more scans will be needed. Some of these scans will fix some problems and some of them are just need to help me locate hidden files so we can prepare a procedure for you to use to get things cleaned up.

    First run the procedure in the following link and attach the Ewido log:

    Running Ewido Anti-Malware


    Now download and install Spy Sweeper Install it and get the update but do not start the scan yet!

    Print or save these steps to a notepad file locally to refer to if necessary because ALL browsers (including this one) must be closed when you do the following.
    • Run Spy Sweeper but do not start a scan yet.
    • Close ALL browser sessions and exit any other programs that are running except SpySweeper (and notepad if you needed it to view these instructions).
    • Open Task Manager by pressing CTRL-SHIFT-ESC.
    • In Task Manager's Process list, locate explorer.exe. Right click on it and select End Process . Do not be alarmed! This will make your Desktop with icons disappear. It is only temporary.
    • Now run a full scan with Spy Sweeper and save a new log to spysweeper.txt. You do this by clicking Session Log in the upper right corner, copy everything in that window and then pasting it into another notepad window.
    • Now in Task Manager click File, New Task (Run...) and enter explorer.exe and click OK. Your Desktop should come back
    • Now attach the new Spy Sweeper log here.
    • Now reboot and run a new Spy Sweeper scan and attach this last log here (yes that is two scans with SpySweeper, one to hopefully fix, and one to make sure it fixed).
    After doing all of the above attach the Ewido and Spy Sweeper logs and then attach a new HJT log so we can continue with manual cleaning steps. I may need you to run two other scanning tools. I'll know when I see the next HJT log.
     
  3. bobbybb

    bobbybb Private E-2

    Thank You so much for your help!! As of right now I am dwnlding the EWido and Spysweeper, I also compressed my bitdefernder file and would like to post that now. once again thank you so much. I will be posting all of those logs soon! B

    B
     

    Attached Files:

  4. bobbybb

    bobbybb Private E-2

    I can't seem to be able to install bot Ewido and Spysweeper, both downloads are saved to the desktop but do not appear. When searched ewido gomes up but does not install. I cant even find spysweeper
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you download other programs from the READ & RUN ME?
    Are the downloads completing?
    When you try to install Ewido, what happens? Any error messages?
    Try installing it in safe mode.

    Do not download them to your Desktop! Create a folder (like suggested in the READ ME) and download the files to this folder rather than the Desktop.

    You did not follow the preliminary house cleaning instructions of the READ ME. That is why your Bitdefender log is so big. You should have emptied your housecall\Quarantine folder. Also you did not follow the instructions for creating the Bitdefender log. It should be an HMTL file. The way you saved it, it is too annoying to read (too many line wraps at incorrect places and too much merging of info with no spacing).

    In fact, it looks like you may have skipped ALL of step 0. Did you look for those programs that are listed and uninstall them?

    All the P2P downloading is infecting you with every piece of malware known to man!! You need to stop using the P2P programs, uninstall them, and delete all the stuff downloaded with them. As you can see in your Bitdefender log, Housecall had all this junk quarantined due to infections. And now your PC is really messed up from all of this.

    Please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Also download and run this: Kazaa Spyware Removal


    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
    Last edited: Mar 28, 2006
  6. bobbybb

    bobbybb Private E-2

    Im very sorry that alot of my stuff is incorrect, I SWEAR I read the "read me" I just must of got confused.
    1. I read and followed the "0 section" regarding "pre clean-up" and on my Add/Remove Programs the only program I could not delete was "Web Savings from Ebates" because that has been there for years and will not remove. I get error message, "ERROR: Could not Execute Main: Syst Can not find file specified."

    2. When I try to install Ewido, Spysweeper, Hoster, Kazaa Spyware Removal to a folder on the C drive the download completes and nothing appears, no icon, nothing. I went to START-SEARCH and then typed in "ewido" found a file, double-clicked it and got an error message saying this file is corrupted due to various reasons including a virus. I dwnlded ad-aware, spy-bot, stinger many months ago from your website, howver very recently (2 days ago) I dwnlded Windows defender perfectly, so I have no idea why this is happening. I also tried to go to your wesite during a safe boot with networking and the same thing happened, No icons for installation

    3. About my Bitdefender, I had no idea how to delete my, "housecall\Quarantine folder" I thought that since it was part of Trend Micro's free online scanner this would not be an issue, I apologize profusely for my oversight. I just taught myself right now, so this won't be an issue anymore (would you like me to re-attach a new bd scan file?) Also about the format of the log file for bd, sorry about that too, I read the instructions but was very confused.

    4. In regards to P2P, at the time the bitdefender log was taken all of those programs were already uninstalled. I kept certain music and certain videos in folders, these definately should be deleted right?

    Also I would just like to say that when I last dwnlded Windows defender from ur website I had not ran hijackthis with the "Normal Start-up feature" from msconfig. Then when I clicked Normal Start-up and rebooted all hell broke loose, I ran hijack this and anything else I needed, then quickly tried to change back the start-up to where it once was. Do you think this has any connection with why these scanners won't show up?

    Thank you so much for your time and patience with me. I appreciate all your time and effort!!!! You are my life saver!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure exactly what is going on but let's see if we can make any progress using manual steps and HijackThis.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link...e.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    F3 - REG:win.ini: load=??? ??? ??? ? ? ?Iu ? ?
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe,hfgtkub.exe
    O1 - Hosts: 217.116.231.7 aimtoday.aol.com
    O1 - Hosts: enu.com
    O1 - Hosts: enu.com
    O1 - Hosts: henu.com
    O1 - Hosts: henu.com
    O1 - Hosts: .whenu.com
    O1 - Hosts: .whenu.com
    O1 - Hosts: c.whenu.com
    O1 - Hosts: c.whenu.com
    O1 - Hosts: nc.whenu.com
    O1 - Hosts: nc.whenu.com
    O1 - Hosts: inc.whenu.com
    O1 - Hosts: inc.whenu.com
    O4 - HKLM\..\Run: [newname] C:\windows\newname5.exe
    O4 - HKLM\..\Run: [dyavqeeA] C:\WINDOWS\dyavqeeA.exe
    O4 - HKLM\..\Run: [errorhandler] C:\WINDOWS\errorhandler.exe
    O4 - HKLM\..\Run: [expload.exe] C:\WINDOWS\system32\expload.exe
    O4 - HKLM\..\Run: [ms046242591075] C:\WINDOWS\ms046242591075.exe
    O4 - HKLM\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
    O4 - HKLM\..\Run: [WinStart001.EXE] C:\WINDOWS\System\WinStart001.EXE -b
    O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\Toolbar\winnet.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [WebSavingsfromEbates] wjview /cp:p "C:\Program Files\WebSavingsfromEbates\System\Code" Main lp: "C:\Program Files\WebSavingsfromEbates"
    O4 - HKLM\..\Run: [t] C:\WINDOWS\System32\dpwzzs.exe
    O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
    O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
    O4 - HKLM\..\Run: [msbb] C:\WINDOWS\System32\msbb.exe
    O4 - HKLM\..\Run: [Microsoft Tray] C:\Program Files\KaZaA\My Shared Folder\YU GI OH GAME EXE. (WORKS GREAT) MUST SHARE..exe
    O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
    O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
    O4 - HKCU\..\Run: [media_manager] C:\Program Files\ebkrdr\mediaman.exe
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/Activ...veLauncher.cab
    O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k00719/sb028.cab
    O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
    O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\f4j20e1oeh.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\WildTangent <-- the whole folder
    C:\Program Files\Common Files\Toolbar <-- the whole folder
    C:\Program Files\WebSavingsfromEbates <-- the whole folder
    C:\Program Files\NEWDOT~1 <-- the whole folder. This is probably NEWDOTNET or something similar.
    C:\Program Files\KaZaA <-- the whole folder
    C:\Program Files\Common Files\CMEII <-- the whole folder
    C:\Program Files\System Soap Pro <-- the whole folder
    C:\Program Files\ebkrdr <-- the whole folder
    C:\Documents and Settings\Owner\Application Data\Lycos <-- the whole folder
    C:\Documents and Settings\Owner\Local Settings\Temp\tp7543.exe <--- delete all files and subfolders in this Temp folder
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\KZCZ2VWN\rcverlib[1].exe

    C:\WINDOWS\Temp\Cookies\ <--- delete all files and subfolders in this folder

    c:\WINDOWS\System32\zzb.exe
    C:\WINDOWS\System\WinStart001.EXE
    C:\WINDOWS\System32\dpwzzs.exe
    C:\WINDOWS\System32\msbb.exe
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\SYSTEM32\Agent.dll
    C:\WINDOWS\SYSTEM32\aupdate.conf
    C:\WINDOWS\SYSTEM32\rk.bin
    C:\WINDOWS\SYSTEM32\sysfile.dll
    C:\WINDOWS\system32\d18.dll
    C:\WINDOWS\system32\dwdsregt.exe
    C:\WINDOWS\system32\msietn.dll
    C:\WINDOWS\system32\NLNP13.dll
    C:\WINDOWS\system32\qmdsregk.exe
    C:\WINDOWS\system32\SHAgentNew.dll
    C:\WINDOWS\sysupd.exe
    C:\WINDOWS\Downloaded Program Files\bridge.dll
    C:\windows\newname5.exe
    C:\WINDOWS\dyavqeeA.exe
    C:\WINDOWS\errorhandler.exe
    C:\WINDOWS\system32\expload.exe
    C:\WINDOWS\ms046242591075.exe
    C:\WINDOWS\drsmartload2.dat
    C:\WINDOWS\Qm9iYnkgQmVlYmU\kA62sB40kAp5sAo.vbs

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: My previous instructions should help to get us started but I do not expect it to fix all the problems you have. Some of them will return. They require special steps to remove but if you cannot download anything, we are going to have a problem removing them since we need other tools to find hidden malware files.
     
  9. bobbybb

    bobbybb Private E-2

    Ok followed instructions to a tee. Here is the new HJT file. I still am having the same problem downloading and installing programs. I tried "hoster" again but to no avail. I also went to downloads.com and tried to download anything and still the same problem (this time it was a codec, the download completed but when I went to look in the destination I put it in, it was not there) Now when I use START>SEARCH>__ nothing appears liek it did the first time when i searched for ewido.
    With regards to the last step, certain files could not be found to delete from Windows Explorer
    When the computer starts up I get a "WIndows Installer" window that tries to copy files but continually gets error messages. I have to use task manager to stop it.

    Ok, its been a long night (for both of us Im sure) once again I cannot express how grateful I am for your continuing support!
    B
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When did your problems with not being able to download anything begin?

    You have HijackThis and you have Windows Defender (fairly recent). And other items from the READ ME. When did you download and install these? Was it after you had already run the READ ME that you started having problems downloading.

    I see both Symantec and AVG antivirus applications. You should go to Add/Remove programs and uninstall all Symantec/Norton items you see. Tell me if this works or not. We may need manual steps to remove it.

    I noticed you did not fix the below line last time. Did you choose not to fix this on purpose?
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain

    I missed one item last time! Power Scan. Look in Add/Remove programs for Power Scan and uninstall if found. Whether it had an uninsall or not, then look for the below line in HJT and have HJT fix it.

    O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe

    Then boot into safe mode and delete the C:\Program Files\Power Scan folder.

    Now reboot normal mode and attach a new HJT log. Any change to your problems.

    Do you know what the below is being used for:
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\CPUIDLE\srvany.exe

    srvany.exe can be a valid Windows service but I'm not sure if this is where it runs from when valid. I would expect it to be running as: C:\WINDOWS\system32\srvany.exe Most PCs do not have this running. See the below for some info about the valid Windows program. Does it sound like something you are doing?

    http://www.liutilities.com/products/wintaskspro/processlibrary/srvany/
     
    Last edited: Mar 29, 2006
  11. bobbybb

    bobbybb Private E-2

    Ok lets talk about srvany.exe first. Truthfully, I have no idea what this is. I went to the link provided, and when I realized that I don't even know what the difference between an "executeable" and a "service" is, I knew that this has nothing to do with me.

    Please let me know if I did something wrong here, but when I ran hijackthis and checked the log (which is attached) I could neither find,

    " O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain "

    nor,

    " O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe, "

    in the HJT log file. I searched it numerous times to be sure, I mean I'm pretty sure I had HJT fix the WildTagent line previously, I would assume that you are still seeing it though. Also I did not find PowerScan in the Prgram Files folder.

    With regards to the downloading issue. I first saw your website a couple of months ago, at that point I had downloaded the following: Ad-Aware SE, CCleaner, CWShredder, basically EVERYTHING but HJT, Windows Defender, Mal. Spyware Remover. I downladed those things about two days ago today, they worked fine.

    When I was running in safe boot mode with networking for the first time, I finished all my scanning and everything else I had to do, I turned off system restore (this wasn't right was it), rebooted in normal mode. That was the same reboot that I had hit "Normal Start-up" where many of the previously un-checked boxes on the start-up tab became checked again. This is the point where the downloads stopped.

    Also, there was one especially annoying feature of a Windows Installer program trying to copy files on to my hard drive that results in errors that pop up repeatly until I use task manager to close it (this happens during start-up only). I feel it might be important to note that I did go back inot msconfig and uncheck alot of stuff that I knew 100% where detrimental which did resolve in the aforementioned program to stop. I then went back into Normal Start up from msconfig for the HJT scan.

    I realized that no downloads from the internet work. I right clicked your logo and saved it to my desktop (I KNOW your not supposed to do this, I remember, but I wanted to see the actual destination place) I saw the htm. file for a second on the screen then it vanished. I am very worried

    Sorry for writing a novel here
     

    Attached Files:

  12. bobbybb

    bobbybb Private E-2

    I just used another computer to download Ewido, Spysweeper, Hoster, KSR,I burned them on a CD and put them in my "spyware protection" folder. I know this is retarded but I just want to make sure it's ok to run these (saying if it will even work)!!! I dont want to screw up now and do something even worse
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then maybe we should try disabling it and see what happens.

    You previous log showed both of them still being there. Take a look for yourself. Did you run any other scans inbetween these last two HJT logs. Perhaps something removed them for you.

    That was a really bad thing to do. Now you have no restore points to revert to, if we cannot get the download issue resolved.

    Do you have a list of all items that you were not allowing to startup?

    Can you download in safe mode?

    Does the Windows Installer program also run in safe mode? Sounds like the problem could be due to an incomplete install of some application. Windows Defender does not seem to be installed correctly. Does it work?

    Do you have your Internet Explorer Security settings setup to allow downloads:
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to cpuidle ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.
    Now reboot and get a new HJT log. Let me know if anything changes and if you get any error messages or cannot run any particular applications.
     
  15. bobbybb

    bobbybb Private E-2

    Ok Here is a rough idea of some of the items i unchecked in start-up. Please note this is just to give you an idea i dont have an actual list:

    O4 - HKLM\..\Run: [newname] C:\windows\newname5.exe
    O4 - HKLM\..\Run: [dyavqeeA] C:\WINDOWS\dyavqeeA.exe
    O4 - HKLM\..\Run: [errorhandler] C:\WINDOWS\errorhandler.exe
    O4 - HKLM\..\Run: [expload.exe] C:\WINDOWS\system32\expload.exe
    O4 - HKLM\..\Run: [ms046242591075] C:\WINDOWS\ms046242591075.exe
    O4 - HKLM\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
    O4 - HKLM\..\Run: [WinStart001.EXE] C:\WINDOWS\System\WinStart001.EXE -b
    O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\Toolbar\winnet.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [WebSavingsfromEbates] wjview /cp "C:\Program Files\WebSavingsfromEbates\System\Code" Main lp: "C:\Program Files\WebSavingsfromEbates"
    O4 - HKLM\..\Run: [t] C:\WINDOWS\System32\dpwzzs.exe
    O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
    O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
    O4 - HKLM\..\Run: [msbb] C:\WINDOWS\System32\msbb.exe
    O4 - HKLM\..\Run: [Microsoft Tray] C:\Program Files\KaZaA\My Shared Folder\YU GI OH GAME EXE. (WORKS GREAT) MUST SHARE..exe
    O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
    O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
    O4 - HKCU\..\Run: [media_manager] C:\Program Files\ebkrdr\mediaman.exe
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/Activ...veLauncher.cab
    O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k00719/sb028.cab
    O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
    O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\f4j20e1oeh.dll (file missing)

    Here is a list of unchecked items now on start up:
    WkDetect
    MsnMsgr
    RUNDLL32
    nwiz
    PSfree
    --chain of square boxes
    SNDMon
    America Online
    SpySubtract

    In safe mode the installer does not appear, also windows defender is not working now, it was before. It does appear that my IE settings are ok
    Attached is my newest HJT log, ewido scan and only one spysweeper because on the second one it came up clean with no option to save log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of those items (O4 thru O20) where bad and we have now removed them.

    Run msconfig and select Normal Startup if not already in that mode. And then reboot and attach a new HJT log.

    Seems like Spy Sweeper fix a lot. Are you still having problems?

    You did not answer my question as to whether you can download in safe mode.


    ........Edit........ how did you get Ewido and SpySweeper if you cannot download?
     
  17. bobbybb

    bobbybb Private E-2

    So as of now not alot of problem just this downloading thing. And no I could not download in safe mode. Also whats interwsting, I went to look at my log, which I then was prompted to log in, when I did I got to the proceed page where it did not automatically bring me back. I hit hte proceed button and it seemed to be blocked from moving, i right clicked the link and hit open innew window that was blocked, I think so how these might be related, you agree?
     
  18. bobbybb

    bobbybb Private E-2

    Re: Please Help!! Viruses just love me and won't go away

    --------------------------------------------------------------------------------

    I just used another computer to download Ewido, Spysweeper, Hoster, KSR,I burned them on a CD and put them in my "spyware protection" folder.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So then specifically the answer to the below is No????
     
  20. bobbybb

    bobbybb Private E-2

    No I can not dwnld in safe mode
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay have you gone back to msconfig and selected Normal Startup yet. Please do not disable anything from loading at anytime unless I ask you to do so. Get into normal startup and then tell me if you see items in msconfig that are still unchecked. If there are, first make sure you definitely are still in Normal Startup mode and thentell me which ones.

    Also uninstall MS Windows Defender!
     
  22. bobbybb

    bobbybb Private E-2

    Unistalled Defender, when clicked normal start up ALL boxes are checked, should I re-boot?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! And then attach a new HJT log. Make sure you leave it in Normal Startup now unless I request you to change it.

    Also use your other PC to download Mozilla FireFox
    Install it on the problem PC and see if you can download.
     
  24. bobbybb

    bobbybb Private E-2

    Cant get to other PC right now room is occupied for the night. I rebooted in normal startup and did not close any running programs here is the new HJT file.

    By the way once again let me just say thank you again for all of your hard work with me and everybody else who you deal with. You must have alot of patience!!!

    Spysweeper has given me an alert window named, "start-up shield" asking me to remove items I have not just installed or update. Do u want a list?
     

    Attached Files:

  25. bobbybb

    bobbybb Private E-2

    Oh my god, I just tried to dowload Firefox and it worked!!!!! Its in a folder in the C drive,
    The windows Installer changed to a copy window with an error message that says, "Internal Error 2908. {EBB15EA3-83A9-46E8-866E-C3C30A1A444F} When pressed ok another window pops up. This does not stop
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Most of the time! But I do lose it once in awhile. ;)

    Yes! Tell me exactly what it is saying. It could be just things that it is seeing for the first time since you just installed it. By the way, is this the first time you have rebooted since cleaning things with Ewido & Spy Sweeper?
     
  27. bobbybb

    bobbybb Private E-2

    I dont know how to take a screen shot so I will write them down as best as I can.

    SpySubtract.lnk
    America Online 7.0 Tray Icon.lnk
    Acme.PCHButton
    Microsft Works Update Detection
    MsnMsgr
    PopUpStopperFreeEdition
    Symantec NetDriver Monitor
    NvCplDaemon
    nwiz
    RealTray
    S3apphk

    I am pretty sure I have rebooted after I scanned both ewindo and spyswp so this would not be the first time, no
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you still have SpySubtract installed? Do you use it? Is it a trial version?

    Do you use AOL?
     
  29. bobbybb

    bobbybb Private E-2

    both of those no
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay sounds like SpySweeper may have fixed your download problems!

    Download and run the below and see if you can use it to resolve Windows Installer issues.

    Windows Installer CleanUp Utility
     
  31. bobbybb

    bobbybb Private E-2

    Windows Installer Clean setup will not run because another installtion is in progress, do u want me to go to task manager and close the main problem then try again to install Windows Cleanup Utility.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tha't what I expected. There is a failed install somewhere. You had two msiexec.exe processes running. You can try killing them and see if it let's you. Then to run the Cleaner. Either way continue with the below.

    We need to fix a few items you should not have trying to load from Norton. Since you are using AVG, you do not want or need these.
    Also there are a few items that are not required to load at startup, and a few you do not use. It is better to just have HijackThis fix them rather than using MSconfig like you were.

    Run HijackThis and select the below lines and then click Fix checked.
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
    O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
    O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\spysub.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    Then exit HJT and delete any of the below if found:
    C:\Program Files\America Online 7.0 <-- the whole folder
    C:\Program Files\interMute <-- the whole folder
    C:\Program Files\Symantec <-- the whole folder
    c:\Program Files\NORTON~1 <-- the whole folder

    Then after running Windows Installer cleanup and fixing the above, reboot and attach a new log.

    Now let me know your status. Time for me to get some sleep. Got an early day tomorrow and only had 4 hours of sleep yesterday.
     
  33. bobbybb

    bobbybb Private E-2

    ok installed windows cleanup but do not know what exactly ro remove. Here is my new Hjt file

    Here is the list of windows cleanup:
    (All Users) 1310
    1310_Help
    1310Tour
    1310Trb
    Aio_Scan
    AioMinimal
    AioSoftware
    Copy -i just noticed this, I will remove since it seems to be the
    cause
    CreativeProjects
    Director
    DocProc
    Fax
    HP DLA
    HP RecordNow
    HP Software Update
    HP SystemDiagnostics
    Instantshare
    J2SE runtime Envir 5.0 Update 3
    " " 6
    Micro Office
    Micro Works
    Photo Gallery
    Print Screen
    QFolder
    QuickProjects
    readme
    Scan
    Skins HP 1
    " " 2
    TrayApp
    Unload
    Web Fldrs
    Web Reg
    Win Defender Signatures
    Works Suite OS Pack
    Overalnd [2.1.4]
    Overland ]2.1.6.2]
    Win Installer Clean up

    As on now installer still starts at start-up. At this point I will remove "Copy" reboot and then post a new HJT file. Thanks!
     

    Attached Files:

  34. bobbybb

    bobbybb Private E-2

    That seemed to do it!!! As of now there are no more problems on my end of things please let me know if I still need to do anything at your leisure. Honestly I do not know what I would not have done if it had not been for you and everybody on your team. you guys are like, incredible..
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You should uninstall the old Sun Java version (J2SE runtime Envir 5.0 Update 3 ) since you have the latest version installed.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds