problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by slater1, Jun 14, 2006.

  1. slater1

    slater1 Private E-2

    hi,

    i have had problems with my computer for a long time now...ive had some fixed here before only to have different infections and more infections since.

    my latest infections are really stuffing my computer up. im not sure exactly what it is....but i have feeling there is alot of things wrong like hi-jacking, trojans etc etc.

    i have done all i can with downloading spyware and other programs but nothing will fix it up.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. slater1

    slater1 Private E-2

    i will do that tomorrow mate.

    also i just did a scan with my xoftpsyse...and it picks up ace password sniffer. It says it removes it but then on next reboot it appears agian....
     
  4. slater1

    slater1 Private E-2

    hey chaslang...just reading through the tutorial you gave me...a little confused at this point:

    ...so, simply all i do is: step 5 and then reboot into safe mode with networking then do step 6?

    and also at what point do i disable system restore/hidden files...i am still a little confused with that. do i do it after step 6?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't disable system restore until your PC has been declared to be clean! We will tell you when that is!

    Run all the other steps 1 thru 7 exactly as indicated.
     
  6. slater1

    slater1 Private E-2

    ok i did what it said in the tutorial.

    i have attached

    HJT
    bitdefender
    panda scan
    counterspy


    Now thing is ive rebooted back to normal mode did a scan with counter spy and it has found trojans and messenger plus! bundler, which were not in the scan when i did it in safe mode....and still has all the other things that were in the scan during safe mode with over 100 registry keys infected.

    *edit....the panda active scan log is waaay to big to upload. can only upload counterspy, HJT and BDscan.

    also teh hijackthis log says i have alot of processes opened...but i did not have that many opened. ethier that or i dont have a clue how to turn those things off.
     

    Attached Files:

    Last edited: Jun 16, 2006
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why is it so big? Is just mostly due to loads of cookies being found?

    Compress the pand log into a ZIP file and upload the ZIP file.

    I see traces of both Antivir and Avast but Avast seems like it may have been uninstalled but not correctly. Is it true that you are only trying to use Antivir?

    Are all of the below purchased or are they trials?
    SpyCatcher 2006
    XoftSpySE
    Spy Sniper
    CounterSpy
    Spyware Doctor

    Did you install WinPcap to help you capture or monitor packets for some reason? It is not malware, but could be used for that. So unless you install it, I have to question why it is there.

    I also see Live Update from Symantec. Do you have any Symantec software installed, or did you have any at one time.
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
     
  8. slater1

    slater1 Private E-2

    it found over 3,000 "spyware". not sure of exactly what it ws tho.

    i dont know how to do that.

    i uninstalled avast and installed antivir, yes i am only trying to use antivir...i didnt know there were other ways of removing it other then add/remove programs.

    spysniper is only a trial so is spycatcher. spyware was downloaded form download.com and the rest are purchased.

    i do not know what wincap is mate. so no i didnt install them for that.

    i did have anti-virus from symantec....i also thought i uninstalled that properly.....

    as you can see im not very good with computers.


    is there any hope of getting it fixed?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install WinZip? If so, just right click on the file and select add to Zip.

    I'm not sure I follow you completely. But let's start by uninstalling ALL of these that you did not purchase. I assume that includes the below:
    - SpySniper
    - SpyCatcher
    - SpywareDoctor ????

    I assume you meant you purchased both CounterSpy and XoftSpy? Is that correct? You really shoud only use one program like this.

    You should also uninstall Ares because it comes bundled with malware!

    After doing the above, continue with below.

    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    Now click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Automatic LiveUpdate Scheduler ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Automatic LiveUpdate Scheduler

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to. After reboot get a new HJT log and attach it.
     
    Last edited: Jun 17, 2006
  10. slater1

    slater1 Private E-2

    I cant stop it. it says:

     
  11. slater1

    slater1 Private E-2

    ok this is getting very weird and confusing.

    i rebooted and went back to the msc window and selected liveupdater and it now says its stopped. i then put disabled on pressed apply and went on to the HJT part but the HJT error comes up saying that liveupdate scheduler is enalbed/or still running.

    but it says stopped and is on disable??

    the attachment you asked for is added also:
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At the end of my previous instructions I did say:

    Your uninstall log shows the below three items which we have been discussing. Since you do not need anything from Symantec and also do not know what WinPcap is, all three of these should be uninstalled using Add/Remove programs.

    LiveReg (Symantec Corporation)
    LiveUpdate 3.0 (Symantec Corporation)
    WinPcap 3.1 beta3


    After uninstalling them, attach a new HJT log.
     
  13. slater1

    slater1 Private E-2

    ok here is my HJT log after uninstalling those from add/remove programs.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have both CounterSpy and SpywareDoctor installed. Since your previous answer to my questions about these applications was not too clear. I''ll ask two questions:

    1) Is CounterSpy a free version or a paid version?

    2) Is Spyware Doctor a free version or a paid version?

    Another question! You implied you purchased XoftSpy. Why don't I see it running? It also was not in your installed programs list.


    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to rpcapd ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    rpcapd

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\RunOnce: [VcCleanUp.exe] C:\DOCUME~1\dimity\LOCALS~1\Temp\VcCleanUp.exe /F C:\PROGRA~1\COMMON~1\SYMANT~1\LiveReg\ /RemoveAll
    O23 - Service: rpcapd - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\SpyCatcher 2006 <--- delete the whole folder
    C:\PROGRAM FILES\ALWIL SOFTWARE <--- delete the whole folder
    C:\Program Files\WinPcap <--- delete the whole folder
    C:\Documents and Settings\dimity\Local Settings\Temp <--- delete all files and subfolder in this Temp folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jun 20, 2006
  15. slater1

    slater1 Private E-2

    you said in your other post that i should keep only 1 of xoft or counterspy. so i kept counterspy.

    And everything is a free version...im sorry i didnt know exactly what you meant...i have now removed all of the programs.

    I have removed spyware doctor...i cant see it in my add/remove programs.

    i will do the rest and reply with results.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My comments were based on you telling me what was a trial and what you had purchased. Apparently you did not purchase any antispyware applications! Is that correct?

    If that is correct, you are going to need one realtime antispyware blocking tool. Once you get your PC upgraded to WinXP SP2 you could use the free Windows Defender package.
     
  17. slater1

    slater1 Private E-2

    yes that is correct....im sorry i mis-understood when you asked that question first.

    can you suggest a free realtime antispyware blocking tool then untill i get SP2?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's worry about that a little later. First finish doing what I requested in message number 14.
     
  19. slater1

    slater1 Private E-2

    Ok. Did everything you said.

    Somethings tho: couldnt find these in when i did the HJT log. YES hidden files are viewable.

    O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\RunOnce: [VcCleanUp.exe] C:\DOCUME~1\dimity\LOCALS~1\Temp\VcCleanUp.exe /F C:\PROGRA~1\COMMON~1\SYMANT~1\LiveReg\ /RemoveAll
    O23 - Service: rpcapd - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

    Also couldnt find these two:

    C:\Program Files\SpyCatcher 2006
    C:\Program Files\WinPcap


    everything seems to be working alright. i have attached my HJT log.



    Cheers
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks better but I still see CounterSpy:

    O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe

    Did you uninstall this free trial version? If so, just have HJT fix that O4 line.

    I also see the below which is from SpyCatcher. Did you use Add/Remove programs to uninstall SpyCatcher!
    O20 - AppInit_DLLs: interceptor.dll

    Did you uninstall this free trial version? If so, just have HJT fix that O20 line. You will probably receive an error message when you try to fix that line. Just ignore it and exit HijackThis. Then immediately reboot your PC. Get a new HJT log and attach it.
     
  21. slater1

    slater1 Private E-2

    i uninstall everything using add/remove. Both have now been fixed with HJT as you said.

    new HJT log is attached.

    Also mate can i ask what these are:

    O4 - HKLM\..\Run: [YMDCApp] YMDCApp.exe

    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe


    and should this be having an effect on my firefox? i rebooted and now my firefox bookmarks have gone and it says that mozilla has been updated.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was getting to this one, but wanted to cleanup all the other items first. Do you or did you ever have an x-logic mp3 player installed? If you did then that is what it is for.

    If you never had that MP3 player or similar, this could be a Trojan. And we will have to fix it by having HJT fix that O4 line?

    Then you will need to reboot into safe mode and locate the below file and normally I would delete it. But to be safe (incase you need it) just rename the file. Rename it to YMDCAPP.XXX

    C:\windows\system32\YMDCApp.exe

    Then reboot into normal mode and attach a new HJT log.


    This is a valid program. Used by virtual CD programs like Alcohol (or similar) to access CD images protected by SecureROM.

    No! None of this has anything to do with Firefox. If you just got an update it was probably configured to do auto updating.
     
  23. slater1

    slater1 Private E-2

    i used to have MP3's which i used on the computer but that was a long time ago and ive used another persons on here in recent times but i dont think it is a x-logic mp3 player.

    i will do the below right now.

     
  24. slater1

    slater1 Private E-2

    ok...couldnt find C:\windows\system32\YMDCApp.exe
     
  25. slater1

    slater1 Private E-2

    sorry for the triple post...

    my HJT is attached...after remvoing the O4 item and rebooting as i said in my last post i couldnt find C:\windows\system32\YMDCApp.exe
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay! HijackThis delete it while fixing the O4 line and save it in its backup folder.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  27. slater1

    slater1 Private E-2

    Ok mate thank you very much.

    One Thing tho when i ran counterspy when i had it installed it found ace spyware guesser.....would that still be there or has it been removed with teh instructions you gave me?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't remember seeing anything named like that in your CounterSpy log, but if you allowed CounterSpy to fix/delete it then it should be gone.
     
  29. slater1

    slater1 Private E-2

    ok just did the restore points thingy.

    thanks for your help.

    Where can i ask about getting SP2? before when i tired to install it it said i needed to back everything up and i dont know how you do that...seems like really advanced stuff. also if i get SP2 will i still have all the programs etc that i have now?

    and what FREE spyware blocker do you suggest i get?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a recommendation! Not a requirement. And you get SP2 from Windows update which is step 1 of the How to protect thread.

    Yes. It does not erase what you have.

    When you have SP2 installed you can use Microsoft Windows Defender which is free. Until then you can use SpywareGuard (mentioned in the How to protect thread) and also you could use Spybot's Teatimer. We did not recommend using it in the READ & RUN ME because it gets in the way and we prefer other applications (paid ones like Spy Sweeper). But using Teatimer is a much better idea than having no protection and it does work.
     
  31. slater1

    slater1 Private E-2

    yeh but i might stuff up.


    once agian thanks for your help if i need any help with the above ill let you know.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds