Search and Destroy won't clean

Discussion in 'Malware Help (A Specialist Will Reply)' started by kimm.y, Feb 17, 2005.

  1. kimm.y

    kimm.y Private E-2

    Hey guys-
    I'm having trouble with my Search and Destroy program. I' ve been successful using CCleaner, Adware, CWShredder, Kill2me, About:Buster, and HSRemove. But when I try to fix the selected probelms with search and Destroy, it goes about half way, then the whole program shuts down. The problems listed are as follows: Elitum.EliteBar
    Alexa Related
    DyFuCa.InternetOptimizer
    Exact Advertising.BarginsBuddy
    Haxdoor - H
    Look2Me.TopConverting
    MaxSpeed
    TwainTech
    WildMedia

    While trying to delete these using S+D, I kept getting pop-ups of "Failed to load ZIPDLL.DLL, and UNZDLL.DLL" Also, one of my other programs said that it delted Look2Me if it was present. However, S+D showed it still being present. From what I know, I ran the updated versions of these programs. I updated Adware, S+D, and cwshredder. If you guys have any idea what the problem might be, I'd appreciate the help in removing these things. Thanks.

    kimm.y
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. kimm.y

    kimm.y Private E-2

    I dl'ed S+D from that "READ ME FIRST" thread. I did all the steps on that thread. I then dl'ed three updates for S+D from google, (Detection updates 2005-02-16), (FileAlyzer 1.1i), and (Advanced check library update 2004-10-14). All scans were done in safemode.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But what does your Spybot version say!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are still here, I need to know you OS and would like to see you HijackThis log before I give you some additional steps that may be need.

    Getting late here though! Gotta get some sleep!
     
  7. kimm.y

    kimm.y Private E-2

    Still here, thanks for waiting.
     

    Attached Files:

  8. kimm.y

    kimm.y Private E-2

    I run win xp
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need a HijackThis log from normal boot mode! The one you posted appears to be from safe mode!

    You still did not answer this:

    Spybot does not appear to be installed properly. Your SDhelper.dll file is missing. Some malware does cause this to happen.

    You may want to just quickly try, uninstalling Spybot, REBOOT, reinstall, update and run.

    Have HijackThis fix the below to lines for MaxSpeed (did you uninstall this)?
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)

    Some of your Sony VAIO files appear to be missing. You may need to reinstall these.
    O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
    O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
    O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
     
    Last edited: Feb 19, 2005
  10. kimm.y

    kimm.y Private E-2

    I have spybotsd13.exe. I uninstalled and reinstalled the program, like you said I used the program to find and install all the updates. I noticed however, that certain updates (Detection rules, English help, English help for teatimer, English language) had an ! with a red circle and a diagonal line through it (the typical do not sign). Next to the download, it said “!!! bad checksum !”. I’m not sure exactly what that means. Um, but then I ran the program, and it found no immediate threats. So maybe I just needed to uninstall and reinstall it?

    I don’t remember ever uninstalling maxspeed…I don’t know what maxspeed is.

    I had HijackThis “fix” the two programs you listed. That went ok. I also saved the log, and did this in normal boot mode this time.

    Where exactly do I go to reinstall those items listed (I realize this may seem like a dumb question but I am not computer savvy.) Google or something? Thanks for the help.
     
  11. kimm.y

    kimm.y Private E-2

    did the attachment work? I'm going to try it again.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    No, It did not attach.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As BJ said you did not attach your log!

    Let's wait on the other items related to your Sony VAIO Media for awhile. I not sure if the files are actually missing or something else is going on with HijackThis. I am noticing when HijackThis has a problem with identifying the service name it has a field labeled as - nknown owner - and then it also indcates the file is missing. I have seen multiple cases where the files are still there.
     
  14. Tricky888

    Tricky888 Private E-2

    Hi Kimm.y

    Had same prob with the checksum thing on download recently. Advice from one of our fellow major geekers suggested changing the download server as theer si a problem with one of them. When you get the list of available downloads then go to the update button and there should be a drop down menu. Select one from the list other than the one at the top and that should then work.

    Hope it does. Wow, here's me, a complete tech dunderhead giving advice! However, must admit as above that it is plagiarised.

    Happy hunting.
    Tricky
     
  15. kimm.y

    kimm.y Private E-2

    Thanks for the advice. I will try an attach the log again.
     
  16. kimm.y

    kimm.y Private E-2

    It's telling me that I have aleady attached that file on the thread, and won't let me attach it again. I'm a bit confused, because this is a new HijackThis log, from normal boot mode. I tried changing the name of the log and that didn't work. Any ideas?
     
  17. kimm.y

    kimm.y Private E-2

    Here, I redid the HijackThis scan, and made a new log. This one seems to be working.
     

    Attached Files:

    • HTJ.log
      File size:
      4.7 KB
      Views:
      4
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please Update your HJT to Hijack This 1.99.1 and post a new log using the new version!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    She already has the correct version! The problem is that she ran the wrong one.

    Kimmy delete the old version so you do not have this problem again.
     
  20. kimm.y

    kimm.y Private E-2

    sorry about that.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your log looks clean now! Are you having anymore problems?
     
  22. kimm.y

    kimm.y Private E-2

    glad to hear, thanks so much. The only other thing I've noticed, is that my song file names are blue like a hyperlink. It seems a bit weird. I don't know.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand that one! What are you running that shows them as hyperlinks?

    You should run the steps in the below thread to help avoid future problems:

    How to Protect yourself from malware!
     
  24. kimm.y

    kimm.y Private E-2

    hey-
    I don't know why the file names are doing that. I don't think I'm running anything? Anyway, I scan and rescaned my computer a million times yesterday using the two main scan programs, adware and spybot S+D, and now, for some reason, Spybot is showing that I have DyFuCa.InternetOptimizer, and Elitum.EliteBar that it can't remove, even after reboot. I noticed too, that Haxdoor-H comes up after every reboot. When I run S+D, S+D is able to fix the problem, (Haxdoor - H) but like I said, once I reboot, it comes back. I have absolutely no idea why S+D just a day ago said I had no problems on my computer, and now it's showing that I have two (or three). But it's probably causing the mp3 names to be weird. I clicked on your link in the reply but I got "no thread specidfied. If you followed a valid link, please notify the webmaster". So, I just went back to that "Don't Post until you have read this" thread, and did the steps on protecting your computer. I downloaded the windows Updates, Removed Microsoft Java, (using the MSJVM Removal Tool). I have that AVG virus protector, and that updates itself. This link, the final step in that thread "Install Sun Java here: http://java.sun.com/getjava/index.html " Did not work for me. Should I go somewhere else? I want to make sure I download the right file. And do you have any ideas on what to do about the DyFuCa. and Elitum spyware? Should I try and repeat all the steps in that thread again? I did not do that yet, because it takes a bit of time, but if you think that would do the trick, let me know. Thanks for reading, I know this is long and you are busy.

    kimm.y
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do this:
    How to Protect yourself from malware!

    There is nothing wrong with the link! And it also is just a few links above the READ ME FIRST. Unless you get all protections in place you will just keep having problems.

    When I said, "What are you running that shows them as hyperlinks?" What I meant was what program are you running where you see the MP3 files showing up as links? Are you talking about Windows Explorer?


    Try this English language link for Sun Java. Looks like they changed their links:
    http://java.com/en/download/download_the_latest.jsp
     
  26. kimm.y

    kimm.y Private E-2

    ok I did all the steps in that link. I use internet explorer usually, but I just dl'ed firefox now. When I see the mp3's highlighted like hyperlinks, I'm simply opening the folder I have labeled music on my desktop. Nothing else is open at that time. I just noticed that some of my picture names are blue too. But not all of them.
     
  27. kimm.y

    kimm.y Private E-2

    also, should I uninstall internet explorer now that I have firefox?
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I believe what youre describing is that you have "Disk Compression" enabled. Lets try to disable it.

    1) Open My Computer

    2) Right click on C:\ and select Properties.

    3) On the General Tab look at the next to last check box. Should be named "Compress drive to save disk space"

    4) If checked, uncheck it and choose "Apply changes to C:\, subfolders and files"


    This should take care of your BLUE file names.
     
  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    IE comes integrated into Microsoft Windows, you cannot uninstall. You can choose not to use it but it stays installed.
     
  30. kimm.y

    kimm.y Private E-2

    "IE comes integrated into Microsoft Windows, you cannot uninstall. You can choose not to use it but it stays installed"

    oh ok.

    I did recently do a disk cleanup or whatever to try and get more space. I don't think it helped to much. But when I went to uncheck that box you told me to uncheck, it was already unchecked.
     
  31. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    When you see a BLUE file name, all this means is that Windows has compressed it to save disk space. Disk Cleanup has the ability to compress old files to save space. Windows compresses these files when your not using them and when you are using them, windows will decompress them and compress it again when you finish, very little performance loss when you open it, if any. Nothing to really worry about unless you just dont like it.
     
  32. kimm.y

    kimm.y Private E-2

    oh ok, glad to hear the Blue files aren't anything to worry about. Thanks.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you are OK now Kimmy.y
     
  34. kimm.y

    kimm.y Private E-2

    I hope so. Thanks for all the help guys. You guys rock.

    Oh, and I noticed that you guys have fun quotes at the top of the site. One just came to mind, feel free to use it (if you don't already have it or whatever) "You want Geek with that?"

    peace.
     
  35. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I Like It :D
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Send your quote to Corporal Punishment. I'm not sure if it is in the list or not.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds