Posting of Log Files

Discussion in 'Malware Help (A Specialist Will Reply)' started by Denise_M, Aug 22, 2006.

  1. Denise_M

    Denise_M MajorGeek

    Hi,

    This post is a carry-over from a post at http://forum.majorgeeks.com/showthread.php?p=835704&posted=1#post835704. I originally posted under software because I thought that I needed to change settings in either Windows or Sygate firewall. My original questions were about being deluged with requests from Sygate to allow dll permissions, some files that Sygate was asking me to permit that I researched and found that they may be malware, and ASP.NET and Background Intelligent Transfer Service wouldn't start. I received a message when I tried to ASP.Net that said, "aspnet_state could not be read." I decided to run Trend Micro Housecall and received this message: "MS06-033 -Vulnerability in asp.net could not allow information disclosure." It turned out that the problems with my pc might be due to malware though.

    All of the required programs that I was able to run showed no malware. I couldn't run BitDefender in either Safe Mode with Networking or in normal mode. A box popped up that had a yellow triangle in it with the words "yes" "no" in it (no other words). When I pressed either yes or no, the box closed and nothing happened.

    SpyBot found that I don't use Microsoft Firewall and Automatic Updates aren't enabled.

    I've attached newfiles.txt, runkeys.txt and hijackthis 082206.log to this post. I'll also be attaching a document that I created. I ran SpyNoMore and it found a number of problems with my pc but it wouldn't fix them unless I buy the program. I put the information that it gave me into a .doc file and it's attached to the next message. I don't know if these are legitimate problems since none of the other programs found the problems but I'd appreciate it if someone would tell me how to fix the problems if they are problems.

    My pc still runs extremely slow. There are times that I have to wait about a minute to open a file and I have to double click it a second time for it to open. The same happens with things like Turn Off Computer, opening a website, opening Control Panel, etc. This doesn't happen each time, but often. It always takes between 30 to 45 seconds for files and websites to open. When I check a box, it takes about 3 to 4 seconds before it's checked. There are times when I have 2 instances of iexplore.exe, java, or AVG running. I always have at least 5 or 6 instances of svchost.exe running. Also, when I scroll, it's choppy.

    I use Dial-a-Fix to run Idle Tasks every few days, but in Windows Task Manager, my System Idle Process runs at about 40% and about 3 or 4 times a minute, it will spike to between 80% to 100% for periods that last about 10 seconds (I have 768M of RAM).

    A couple of times, when I rebooted, a message popped up for about 10 seconds. Part of it says "Instruction at 0x6a2a2fec" but I couldn't catch the rest of it because the box closed too fast.

    ASP.NET finally started and is on Automatic (I don't know why it started . . . it didn't start when I tried to start it). Background Intelligent Transfer Service won't start. I receive a message that says, "The system cannot find the specified file."

    I also have Messenger and I can't uninstall it.

    eSellerateEngine.dll is still in C:\Windows, so it may not be the virus file. http://www.2-spyware.com/file-esellerateengine-dll.html (courtesy of TimW)

    Since receiving message that I need to start ASP.NET, I just completed a Trend Micro House Call. It found that ASP.NET is a vulnerability and recommended that I clean it, and I did. It also gave me a link to Microsoft site entitled, "Microsoft Security Bulletin MS06-033
    Vulnerability in ASP.NET Could Allow Information Disclosure (917283)."
    ASP.NET http://www.microsoft.com/technet/security/Bulletin/MS06-033.mspx

    I found a neat little feature on SpyBot though. There's a setting for Start-Up items and you can pick and choose which items you don't want to start. Before I found this handy tool, I tried to uninstall QuickTime and Yahoo Messenger but they wouldn't uninstall, so I deleted all of the files that a search brought up (using hidden and system files). When I rebooted, QuickTime and Yahoo Messenger were still in my system tray. So I was happy that SpyBot has this feature.

    This is about all the information that I can give you, as meager as it is. I'd appreciate it if someone could check the attached files and/or recommend additional tests that I can run to see if there's more malware in my pc.
     

    Attached Files:

  2. Denise_M

    Denise_M MajorGeek

    This is the document that I created that contains the results of the SpyNoMore scan. Please review the information and let me know what you think. Are they really malware and, if they are, how can I remove them.

    Thanks again . . . Denise
     
  3. Denise_M

    Denise_M MajorGeek

    Ooops . . . forgot to attach the file in the last post *blushing*, so I'm attaching it to this post.

    Denise
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the log from PandaActiveScan.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SpyNoMore is junk! If you have it installed, uninstall it!

    Is your copy of Spyware Doctor a paid or free version?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not really have any malware problems that could be causing you problems. We can however cleanup some garbage.

    Use this Disable/Remove Windows Messenger to Remove Windows Messenger.

    Use this Your Uninstaller! 2006 to uninstall anything you wanted to uninstall but could not uninstall with Add/Remove programs.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O1 - Hosts: 212.227.104.169 www.winmx.com
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Windows\eSellerateEngine.dll

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Problems with ASP.NET and BITS not running are not malware and should really be discussed in the Software Forum. You could however try the below procedure we use to sometimes fix Windows Update problems and also issues with BITS not running.

    Copy the contents of the below Quote Box into Notepad. Then click File and then Save As. Change the Save as Type to All Files. In the File Name field enter C:\WinUpFix.cmd and then click save. This will create the WinUpFix.cmd file in the root folder of drive C.
    Now while you can directly run the WinUpFix.cmd file by double clicking on it, that will not allow you to see any errors if any do occur. So a better method is to run it from a command prompt window. Click Start, Run, and enter cmd and click OK. This opens the command prompt window. In the command prompt window type the following lines each followed by the enter key:
    cd c:\
    WinUpFix.cmd

    See if this helps.
     
  7. Denise_M

    Denise_M MajorGeek

    Thanks, chaslang, for your review and recommendations.

    I uninstalled SpyNoMore and Spyware Doctor right after I ran their scans because they were versions that had to be paid for.

    I looked thoroughly at the results of the Panda scan page and didn't see any button, link or otherwise to request a copy of the results, and I clicked on a few things just to see if something would pop up, but nothing did. I know that there's more information in the results of the scan than the fact that it found 0 of everything, but the option to create a log or report wasn't on the page. I'll run it again in Safe Mode with Networking though.

    I reset webpages every few weeks and I did it when I booted up a few minutes ago.

    As to the remainder of your recommendations, I'll be starting on them very shortly.

    Thanks again . . . Denise
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Denise,

    The below link is given in step 6 of the READ & RUN ME:

    Using PandaActiveScan

    If you look at this link you will see in step 7 it says:
    If you don't select this and select My Computer instead, you will not get an option to save the log.
     
  9. Denise_M

    Denise_M MajorGeek

    Hi chaslang . . .

    I got down your list as far as

    C:\Windows\eSellerateEngine.dll doesn't appear in Windows Explorer. I unchecked Do not show hidden folders and Hide protected operating system files. When I browse for the file, it's in the folder C:\Windows and when I search for it, the search results shows that it's in C:\Windows.

    Before I proceed with the remaining steps, I thought I should ask you if I should delete it with a browse.

    And I'll make sure that I click on Local Disks when I run the scan again.

    Denise
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are the one the said the file existed in your first message. That was the reason I included it. If it does not exist, that's fine. Just continue.
     
  11. Denise_M

    Denise_M MajorGeek

    The file does exist. It is located in C:\Windows. I can click on my C drive, click on Windows and the file eSellerateEngine.dll is located there.

    When I do a search for the file, it shows up in the results of the search. The location is reported to be in C:\Windows.

    When I open Windows Explorer, I cannot locate the file.

    My question is: Does the file have to be deleted only through Windows Explorer or can I open C:\Windows and delete the file?

    Denise
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and that is exactly what I said to delete. If you are not seeing it then you did not follow the directions in step 2 of the READ & RUN ME.


    Just right click on it from your search windows and select delete.
     
  13. Denise_M

    Denise_M MajorGeek

    Yes, Sahib!

    Only folders show up in my Windows Explorer. All of the miscellaneous files that are in my C:\Windows folder don't show up when using Windows Explorer, except for files that are named $NtUninstallKB904706$. I have Windows XP. So I double-checked because it might have been just as bad to remove the file while not in Safe Mode for all I knew . . . that's why I'm here. I read the READ Me and I followed your directions. . . I'm good at that.

    Now . . . do you have high blood pressure?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's double check! Do the below step by step.

    - Right Click Start.
    - Select Explore
    - Select the Tools menu and click Folder Options.
    - Select the View Tab.
    - Under the Hidden files and folders heading select Show hidden files and folders.
    - Uncheck the Hide extensions for known file types option.
    - Uncheck the Hide protected operating system files (recommended) option.
    - Click Apply.
    -Click OK.
     
  15. Denise_M

    Denise_M MajorGeek

    They're unchecked . . . have been since I started the procedure last night.

    I'm attaching the new HJT log.

    My pc is running faster, as it used to, but it ran faster the last time I followed procedures, but then the speed degraded to a crawl within 10 days. Maybe all the bad files/errors weren't completely corrected the first time.

    I had originally posted my pc problems in the Software forum because I thought that Sygate/Windows needed setting changes. I was referred to Malware Removal, so here I am . . . and thanks for your help :D

    I'll be doing the fix for problems with ASP.NET and BITS not running now. I'll go into dos and I'll let you know if there's an error.

    Denise
     

    Attached Files:

  16. Denise_M

    Denise_M MajorGeek

    I followed the procedure you gave me, all except for changing my home page. When I ran winupfix.cmd, the following was received:

    When I typed NET HELPMSG 3521, it said
    I'm going to run another Panda scan and I'll post the results in the morning.

    Thanks again for your help.

    Denise
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you one more thing to try for this! If it does not help, you will have to pursue this remaining issue in the Software Forum because it is not a malware issue.

    Click Start, Run and enter services.msc
    Click "OK"

    Please check that the following Services are started:
    • Automatic Updates
    • Background Intelligent Transfer Service (BITS)
    • Cryptographic Services
    • Remote Procedure Call (RPC)
    • System Restore Service
    To verify that BITS is correctly configured :
    1. Double-click `Background Intelligent Transfer Service.`
    2. In the Startup type box, click Manual, and then Apply.
    3. Click the `Log On` tab, and then verify that the service is enabled in every hardware profile that you have listed. If the service is disabled in one or more hardware profiles, click the hardware profile, Enable, and then Apply.
    4. Click the General tab and then Start.
    If BITS starts successfully, go back to step 2 above and change the Startup Type to Automatic.
     
  18. Denise_M

    Denise_M MajorGeek

    All of the services are started except BITS. It's set on Manual but wouldn't start. I received an error message that stated:

    "Could not start the Background Intelligent Transfer Service on Local Computer. Error 2: The system cannot find the file specified."

    The Log On tab contains Profile 1 - Enabled. The path to the executable is
    C:\WINDOWS\system32\svchost.exe -k netsvcs.

    Denise
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One last thing to try, and then you must work this in the Software Forum if it does not help.

    Click Start, Run, and enter sfc /scannow and click OK. This may ask for your Windows XP CD if any files are missing or corrupted.

    Then you could retry starting BITS and see what happens.
     
  20. Denise_M

    Denise_M MajorGeek

    I've already tried it. My Windows XP disc came with SP1 only. When it asks me for SP2, it won't accept the SP2 file that I downloaded from Microsoft that's in my hdd. I also burned SP2 to a data disc but it still won't accept it.

    Thanks much for all your help.

    Denise
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! What file is it looking for?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  23. Denise_M

    Denise_M MajorGeek

    chaslang, I don't know what file it's looking for. It asks me to put my SP2 disk into the drive. When I direct it to the SP2 file in my pc, it tells me that it's not the original and asks me to put the original disk into the drive. When I put the one that I burned into the drive, it tells me that it's not the original and asks me to put the original disk in the drive. I've had my Windows XP with SP1 on it for a long time. Microsoft downloaded SP2 to me and it was installed. So I don't know why my pc thinks I had an original SP2 disk.

    Denise
     
  24. Denise_M

    Denise_M MajorGeek

    This did the trick. BITS has started and it's on automatic.

    Thanks chaslang and Halo :)

    Denise
     
  25. Denise_M

    Denise_M MajorGeek

    Will this work for Windows XP Home edition? My daughter's pc is a mess . . . she doesn't try to fix it, but I thought that I'd try to clean hers up a bit. I've run CCleaner, RegSeeker, PC onPoint, flushed DNS, deleted cookies/online and offline files/cleared history, repaired permisions, registered dll's, etc, but it crashes constantly.

    When I have the time, I'll run the whole gamut of tests at http://forums.majorgeeks.com/showthread.php?t=35407 , but I thought that I'd give this a try if it's compatible with XP Home.
    Denise
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That patch only applied to fixing problems for the PC we were working on in message # 6. It is not something that need to be done or even applies to any other PC. PC crashing is not always a malware problem. It could be but it does not have to be. You could find malware and remove all of it and the PC could still be crashing. The best way to understand what is going on is for you to run the READ ME and start a new thread for this new PC. Make sure you state the fact that it is a new PC and not the same as in this thread so that everyone understands this and does not merge you back to this thread.
     
  27. Denise_M

    Denise_M MajorGeek

    Ok, thanks.

    Denise

    P.S. I found out the reason for my inability to run BitDefender. The free program is good for only 30 days. I uninstalled the BitDefender program that was in my pc, downloaded a new version, and I received the same message (that my 30-day limit has expired).
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But we do not ask you to download Bitdefender antivirus trial. We ask you to use the online scanner which is totally free.
     
  29. Denise_M

    Denise_M MajorGeek

    I tried both ways. When I was in Safe Mode with Networking, as discussed in a previous post, and in regular mode, BD will not run a scan for me. I get a box with a yellow triangle in it with the words "yes" and "no". Maybe I phrased it improperly, but when I downloaded the program, I couldn't get it to scan for me either. If anyone lives near Connecticut, they are welcome to come to my home and try it. . . you're all welcome . . . food's on the house, BYOB.

    Denise
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you just said you used the 30 day free trial. That is not the online scanner. That is the full antivirus program.

    But based on your previous HJT log, I see the below which are all from the online scanner:
    They don't mean that it successfully ran. They just mean it downloaded its active x components. You could easily uninstall this. Open IE and click Tools and select Uninstall Bitdefender Online Scan V8. Then you could reboot and try it again if you like. But at this point I'm not sure why you need to unless you are having malware problems.
     
  31. Denise_M

    Denise_M MajorGeek

    I did use the 30-day free trial and I tried to run the on-line scanner. Both of them wouldn't run for me.

    I didn't have the 30-trial until I decided to try the downloaded version. It must have kept a history and knew that I ran the program from Safe Mode with Networking over 30 days ago because I received the message as soon as I downloaded, installed and tried to run it.

    I receive the same message for both of them: a box with an exclamation point in it with the words "yes" and "no," and the program wouldn't run if I clicked on yes or no.

    In order to uninstall it via your method, I have to close all windows and I'm in the middle of a project, so I'll try it later.

    Thanks for your advice.

    Denise
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds