Please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by MolokoVeck, Sep 1, 2005.

  1. MolokoVeck

    MolokoVeck Private E-2

    Okay, I recently installed a Sony CD/DVD burner combo drive and a G-Force FX 5200 videocard on my system. I have a Dell Dimenson 3000 P4 2.8 GHz 512 MB RAM. After installation it seemed fine. I can run HL2 no problem and I can burn CDs and DVDs. I noticed that when I tried to play a store bought DVD the sound was choppy. I updated my BIOS and soundcard drivers and WMP gave an error when trying to play a DVD saying I needed to change my resolution and color settings and wouldn't play it anymore. I downloaded media player classic but it gave an error after the Warning screens at the beginning of the DVD and wouldn't play and then my system crashed. I also am unable to access my system info or anything through explorer because every time I try I get an explorer.exe has failed error. I have gone through all of the spyware/trojan steps, could you please look at my logfile? Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problem could be more of a Software or Hardware Forum problem but we will take a quick look at your log to see if there is any visible malware.

    Please follow the directions below to properly attach your log:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. MolokoVeck

    MolokoVeck Private E-2

    Thanks for taking a look, I know I might have more problems than this will fix, but I also know some of this stuff shouldn't be in my log, so here it is...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there a reason you did not run the RAVantivirus online scan? This is a required step.

    Also you installed HJT exactly where we request in not be installed:
    C:\Documents and Settings\MolokoVeck\My Documents\HJ\HijackThis.exe

    Please fix this before continuing. Just follow my directions in my previous message.

    Spybot has a bug we need to work around.

    Fixing SpyBot's Ignore Products Bug:
    I want you to run SpyBot and get into the Advanced mode by selecting Mode and then
    Advanced mode. Then select Settings and the in the left column select Ignore Products.
    In the right window pane make sure the All products tab is selected. Then in that
    window, right click your mouse and choose "Deselect all". Now in the left pane click
    at the top on SpyBot S&D and then choose Search for Updates. Download any updates
    required. Now click Check for Problems. Fix any that are found.

    Hopefully that will address the new.net stuff. But I will include it in my steps below just in case.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\NewDotNet

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

     
  5. MolokoVeck

    MolokoVeck Private E-2

    Okay I did all of that, the new.net stuff was fixed by spybot. The reason I did not run RavAntivirus is because the instructions say "select Auto Clean then click Scan My PC" after you press the "click here" button, but there is no Auto Clean option, it just allows me to select certain files to scan. Anyway, I am able to access system and everything now, so it seems like that is cleared up. Here is my updated logfile. Thanks for your help!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you click the underlined text that says click here. it brings you to another page where at upper right there is an option for Autoclean which is right under the Scan My PC option. There are 4 more options to the right of this too. One of which is Scan a File.

    Click on the below. This is where I goto after I click the underlined click here!

    http://www.ravantivirus.com/scan/indexie.php


    At anyrate, your log is now clean. Are you having any other problems?
     
  7. MolokoVeck

    MolokoVeck Private E-2

    I was using firefox and you have to use internet explorer for RavAntivirus to work. Sorry bout that, anyway, the only problems I am having now are that if I try to play a DVD with WMP it says it can't play it and that I have to lower my resolution and color, but I just think that is because WMP is crappy. Media player classic will play the dvd, but when it is playing the sound is choppy, and it is like that for any other player I try as well. I guess I will hop over to the hardware section and post there or something, or just get a friend to help me on that issue. Anyway, thanks for helping me clean up my computer.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds