results of "read & run me first" for removal of Win32.BHO.je

Discussion in 'Malware Help (A Specialist Will Reply)' started by thevioletstorm, Jun 28, 2008.

  1. thevioletstorm

    thevioletstorm Private E-2

    Ok, so I have been having problems with my "new" HP Laptop running Vista 32 bit. Running slower, and no matter what antivirus I put on it, IE gets hijacked 100% and cannot get on the internet. Firefox about 50% of webisites load, others load for a second and then either "this page cannot be displayed" or "this page cannot load". I was thinking all this time it was my AV (using Nod32) so after every attempt at changing settings, I ended up putting Kaspersky on and to my surprise I still have the same problem.
    After doing a scan with Spybot, I discovered Win32.BHO.je, after googling it realized it could very well be my problem. Spybot said that it fixed it originally, but I didnt really believe that it could kill such a trojan.

    I followed the steps to your READ & RUN ME FIRST, and am ready to post the results for the applications I ran. First SuperAntispyware log, second Malwarebyte log, third Combofix log, and I have attached the MGlogs.zip to my post.
    Thank you in advance for the helpful steps, I am interested to know what you see because after re-installing Nod, I still, after all that, had the same dang problem with IE not working, and at this point am QUITE frustrated.
    HELP!!!!!
     

    Attached Files:

    Last edited by a moderator: Jun 28, 2008
  2. Lev

    Lev MajorGeek

  3. thevioletstorm

    thevioletstorm Private E-2

    Apologies............Here are the attached logs.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    While you did have a few minor items to remove, it may be that your problems are due to what you are running. There are no remaining malware issues to address.

    Who is the owner of this PC and who is the Administrator?
    Who is responsible for installing CyberSitter?
    Who is responsible for turning on WebCheck which is website monitoring software?

    Using tools like the above, especially if you don't know how to use them properly are going to result in inability to access various websites. Webcheck is this: http://www.auditmypc.com/process/webcheck.asp

    Note while it does not matter at this point since we have no malware to remove, you did not put your PC into Normal Startup mode with MSconfig as requested in step 1 of the READ ME. However it does matter in regards to the fact that you should not be using MSconfig like this as mentioned in step 1 of the READ & RUN ME.
     
    Last edited: Jul 2, 2008
  5. thevioletstorm

    thevioletstorm Private E-2

    Sorry for not replying quickly.

    Well I am glad that I killed everything there was to kill on my laptop.

    I am the owner of it and there is only one account on it, which is the administrative account.
    I did the installing of cybersitter, as I have young children that enjoy the net and would like them to be protected from encountering questionable content.

    That being said, I have no idea what "WebCheck" is and if I am responsible for turning that on, I had no idea. Unless it is part of cybersitter??

    So I am getting cyber sitter is a bad thing? I usually disable it when I am using the computer but if that is causing the heavy filtering that I am experiencing even when it is disabled then, yes that is surely my problem. IE does not work at all if I have an antivirus on, but as soon as I unistall it, it works fine.
    About the start up mode, I REALLY did go in and change it, when I saw this in your reply I went in to double check and yes, for some reason my change didnt stick, not sure why, maybe I didnt restart right after I did it. But I have changed it back to normal start up now that you brought it to my attention.

    So is your suggestion to remove cybersitter? I am checking the link for the webcheck that you attached. Still not sure what that is.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about this! I was probably running without enough sleep. :eek: This is okay. It is a default DLL and nothing to worry about.

    No I'm not saying that. Many people use it. But since you are having problems accesing various websites, I have to wonder if it is related to CyberSitter since you do not show any malware issues.

    Are you saying that if you completely uninstall your antivirus program that you have no problems at all access websites from either IE or FireFox? Do the antivirus programs that you have tried include builtin firewalls?

    Are you sure that you are not blocking anything in your firewall?
     
  7. thevioletstorm

    thevioletstorm Private E-2

    Yes, its the strangest thing, when I completely uninstall either AV that I have tried, (Nod32 3.0 and Kaspersky 8.0) IE and firefox works 100%. When I install either of them, IE doesnt work 100% and firefox about 50% website access.

    I had thought that I had a virus, but now that is ruled out, I am back to square one.

    I dont use a separate firewall, and am not completely sure if these AV's have one that is doing this. I am just using the standard set up. I dont know that I am knowledgeable enough to confidently play with the settings.

    Could it be Vista?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have no antivirus programs installed and then download and install the below and tell me if you still have a problem.

    Avast! Home Edition

    Based on seeing "Marsu-Fix" in your logs, can I assume that you are using a cracked version of NOD32? If so, you should not be using this and can lead to problems like you are experiencing. If you are using cracked software, you need to uninstall and delete all of them now. We cannot help you resolve problems while possibly infected software is being used due to installing cracks and keygens.


    Vista does have it's own firewall but should not be blocking sites unless you block them. And it should not have anything to do with having an antivirus program installed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds