shuts down mcafee and explorer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by filipeb, Sep 22, 2004.

  1. filipeb

    filipeb Private E-2

    I cannot open Mcafee VirusScan or Firewall (when I try to run them, the window opens and closes quickly) and I cannot even search the web for anything with the word 'virus' because Explorer shuts down when I try.

    I have gone through your tutorial, installed and used all the suggested programs, done it in safe mode, etc. and still nothing!

    I found that I can't even open a Word file with the word virus in the title.

    This is really frustrating me... can you help?

    Thanks,

    FB
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    And then post a HijackThis log as a .txt file attachment to your message. To do this save the log file to a .txt file rather than the default .log and select manage attachments in a message and upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. filipeb

    filipeb Private E-2

    Thank you for responding so quickly.

    Now when I click on the Hijack This link on your website so that I can download it, Explorer shuts down. I was able to get in there before, but now I can't.

    What do I do now, then?
     
  4. Izanbard Prince

    Izanbard Prince Private E-2

    I had that one, I eventually formatted and restored.

    It's a pain in the ass.
     
  5. Kodo

    Kodo SNATCHSQUATCH

    go to start.. run.. paste this in it and hit enter

    http://files1.majorgeeks.com/files/76444b3132fda0e2aca778051d776f1c/spyware/hijackthis.zip
     
  6. filipeb

    filipeb Private E-2

    I tried to cut and paste that in Run and it didn't work... it just won't run.
    I find it very strange that I was able to get into it before, that is, when I already had the other problems, and now I can't. I mean, I don't know anything about spyware and viruses, but it seems this one learned something.

    Is there anything I can do now, since I can't seem to find a way to get Hijack This to work?

    Thanks for all the help so far.
     
  7. filipeb

    filipeb Private E-2

    Ok, maybe this will help, since I can't get Hijack This...

    Every time I run Spybot SD these two things come up: DSO Exploit and Kazaa.Irc.Spybot13.World and everytime I run AdAware these two things come up: something that ends in Winlogon."Shell" and something that ends in System."DisableRegistryTools" ...
    Again, I don't know much about this, so I have no clue what these are... but I do know that every time I delete them with these programs and every time they come back.

    Still having all the same problems... can't open or run McAfee, Explorer shuts down when searching for virus related things, and now can't download Hijack This, which appears to be what could help me the most right now.

    What to do?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ignore DSO Exploit with SpyBot. It is a bug.
    Did you run CWShredder during the tutorial? Did you select FIX?
    Please try downloading and running WinMaid: http://www.majorgeeks.com/download4303.html

    Post its log.
     
  9. filipeb

    filipeb Private E-2

    Yes, I did run CWShredder during the tutorial, apparantely to no avail.

    I was able to download WinMaid :) but it gets stuck when it is scanning :rolleyes:

    Should I try to re-install it or something?
     
  10. filipeb

    filipeb Private E-2

    Since I haven't yet been able to run WinMaid, I've attached a list of the results of the online scan I did, in hopes that it may help.

    This is really frustrating...

    Thanks again for the help so far.
     

    Attached Files:

  11. Dawniepoo

    Dawniepoo Private E-2

    I am sorry I should have read this before I posted. This is the exact same problem I am having with this computer!! I mean identical. I am like you at a loss for ideas on what to do. May go see if I can burn Hijack This to a disk at home and bring it back here. Think that would work?

    This did the same thing you are talking about. At first I was able to get into certain antivirus sites then all of a sudden those were blocked too. On the last computer I was working on I just wiped it all out and redid the whole thing, but I am hoping to avoid that this time. Oh, what to do??!!?? lol
     
  12. Kodo

    Kodo SNATCHSQUATCH

  13. Dawniepoo

    Dawniepoo Private E-2

    I found the virus that was causing it. It will not let you go to antivirus sites, or at least certain ones. Try going to http://housecall.trendmicro.com It worked for me this time and I was actually able to scan the computer, find the viruse, delete all but two which were currently running proicesses which I ended and deleted them too. Good luck, :D
     
  14. filipeb

    filipeb Private E-2

    So, I know it's infected with this W32.Tibick shit, but how do I remove it? It won't let me go to the links you guys posted. The place where the scan worked is Symantec Security, but I don't know what to do to clean the infected files. I heard it's bad to have more than one anti-virus program in the computer, but does that apply since I can't open, run, or uninstall McAfee? How the hell am I supposed to fix this problem if it does apply?

    Any suggestions?

    Again, thanx for the help.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first thing you need to do is to stop downloading cracks and keygens! Look at all those files and they are all infected. That is where you problems are coming from.

    Boot in safe mode and delete the whole msview directory. Also delete (you may have to use Task Manager to end the processes if running before deleting):


    C:\WINDOWS\system32\apvxdwin.exe <--- this is Troj/Killav-L and it attempts to terminate anti-virus and security-related processes.

    C:\WINDOWS\system32\svcnet.exe <--- W32/Gaobot.LZ. also Worm.P2P.Tibick [Kaspersky]

    Delete the keys from the registry (if found):HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    Svcnet = "svcnet.exe"

    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    Svcnet = "svcnet.exe"

    Also see this http://securityresponse.symantec.com/avcenter/venc/data/w32.tibick.html
     
  16. filipeb

    filipeb Private E-2

    Ok, I'll try that now... I have to say though, I've never downloaded "cracks" or "keygens", cause I don't even know what the hell those are!

    I'll post again once I've done what you said.

    Thanks for the help!
     
  17. filipeb

    filipeb Private E-2

    Ok... I deleted the msview, the Troj/Killav-L thing, and the W32/Gaobot.LZ. thing... however I did not delete the keys from the registry, cause, to be honest, I don't know how to do that.

    Also, when I click on the link, it gives me a "page not available"...

    The problems are still here.

    Next step?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it
    3) In the left side panel, start by clicking on the word Registry with the two little computers next to it.
    4) Now copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    5) Click the "Go" button to the right (or hit Enter)
    6) Find: "svcnet.exe" on the right side panel and right click on it and select Delete

    Repeat steps 3 thru 6 but this time for step 4 paste this line in:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

    Then double check what I gave you in message #15 and make sure all the items were actually deleted.

    Let me know if you are able to do all the above.
     
  19. filipeb

    filipeb Private E-2

    Ok... what I found using RegLite, as you told me, was apvxdwin.exe... that's the only thing that looked familiar. I did not find svcnet.exe.

    I can't download the W32 Removal tool, cause it won't let me get to the page. (I didn't see W32/Gaobot.LZ on the list of variants though... does that mean even if I did run it, it wouldn't clean that one?)

    Also, I'm not positive how to check if the files were really deleted. As you can tell I'm not too computer savvy...

    What should I do next?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You only said you found apvxdwin.exe. Did you delete those entries from the registry using Registrar Lite? And did you then boot in safe mode and delete the file.

    To delete the files you must have viewing of hidden files enabled and you should run Windows Explorer and navigate to C:\WINDOWS\system32\apvxdwin.exe and delete it.

    You run Windows Explorer by right clicking on Start and then select Explore.
     
  21. filipeb

    filipeb Private E-2

    Yes, I deleted the file.

    I went back into safe mode and ran Symantec's Scan again, and this time it only found one infected file, and it was infected by "IRC Trojan"...

    The file was something like bak.exe, and when I tried to delete it, I got a message saying the file could not be deleted.

    Could this be the thing that's still causing my problems, or have I not found it yet?

    I'm going to make sure I got all of the W32 out, but I'm almost positive I did.

    What now?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the problem (bak.exe or whatever it was called) process and End it.

    Then try to delete the file yourself (in safe mode) using Windows Explorer?

    You may need to figure out where it is located unless Symantec told you that info.
    It could be in a number of places:
    c:\windows
    c:\windows\system
    c:\windows\system32
    c:\documents and settings\username\local settings\temp (where username is your user name)

    Can you run HijackThis yet? If you still have a problem, try renaming hijackthis.exe to hijackthis.com and running it. If it runs, save a log and post it here as an attachment.
     
  23. filipeb

    filipeb Private E-2

    I did not find the file (the processes tab in task manager appears empty), but I ran the Symantec scan again in safe mode and this time it came up clean.

    I still can't even download Hijack This, cause it won't let me.

    I did download WinMaid, but every time I try to run it, it gets stuck and doesn't respond.

    What can I do? This is making me go crazy.

    Thanks for the help.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can download and run CoolWWWSearch.SmartKiller (v1/v2) MiniRemoval

    It gives a very short answer like CoolWWWSearch.SmartKiller (v1/v2) has not been found on your system if you are not infected with this version.

    Can you download and run CWShredder?

    If still having a problem, PM me with an email address and I will email HJT to you.
     
  25. filipeb

    filipeb Private E-2

    I had downloaded and run both you mentioned, and nothing.

    I will PM you my email.

    Thanks again!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! This means that you were able to run them. Right?
    Did you click FIX in CWShredder? What version do you have?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After you extract the hijackthis.exe file from the ZIP, if it will not run for you, try renaming it to hjt.com (I'm trying to hide it from whatever is shutting it down. You may have to be real fast and click Scan and the Save log before the malware process can shut it down.)
     
  28. pegg

    pegg MajorGeek

    Hey Chas -- great job. I was just thinking, based on his response to this note of yours (what are cracks and keygens???) and since I can't answer it for him -- you (or someone) may want to answer this sometime after all the other major problems are resolved.

    If this is the source of his problems, then he needs to avoid making the same problems start back up.
     
  29. filipeb

    filipeb Private E-2

    I did run CWShredder... I have version 1.59.0.1.

    I'll try the Hijack This stuff now.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please double check that CWShredder version again. 1.59.1 is the latest version.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cracks and keygens are made by software pirates. Cracks are used to deprotect software completely. Keygens are used in an attempt to create the key codes (user names and passwords or serial numbers) needed to install or make the software fully functional. Both are illegal and you get what you pay for. Most of the time people go to sites with these cracks or keygens will come away with some unexpected and undesirable side affects (especially if they actually attempt to use them).
     
  32. filipeb

    filipeb Private E-2

    I received the email you sent me, but am still unable to download Hijack This... after I choose its destination and click save the window pops up and closes quickly. I tried changing the name and that didn't work either.

    I double checked my CWShredder and it is the most current version.

    By the way, I never downloaded these cracks and keygens (cause I really had no clue what they were)... could they have come as music files from a file sharing program?

    What else can I do to get Hijack This by whatever is stopping it?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes file sharing programs are notorious for also sharing viruses and other malware with you. Even if you did not download it directly. One you are on there network you drive is shared and you can get all kinds of crap on your PC.

    You know I don't remember you ever saying what OS you had.

    Download ProcessExplorer from one of the links below (choose the one for your OS type):
    for Win9x/ME - http://www.sysinternals.com/files/procexp9x.zip
    for WinNT/2K/XP - http://www.sysinternals.com/files/procexpnt.zip

    Unzip it and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".

    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
  34. filipeb

    filipeb Private E-2

    The exact same thing happens when I click on the link to ProcessExplorer... the window quickly pops up and goes away!

    I have XP by the way.

    This tricky thing is blocking my access to all these files!

    What do I do!!!?
     
  35. bella

    bella Private E-2

    Hi Guys,
    Im new to this, so I dont know if I'm posting to the right area. Recently I found that I was infected by 12 different Trojan Viruses. I came here and I followed the instructions step by step for removing them. However, it said to run trend micro's scan and symantec security check, which i couldnt do from safe mode. I did everything else, and got rid of alot of problems with my computer that i wasnt even aware were an issue before I did those steps.
    My problem now is that I still have 1 of the trojans on here and I cant get it off. Ive looked all over for information on it but cant find any. Its called TROJ QDOWN.L, and they are located in the following files :
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\QDOW_AS2.DLL
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.2\QDOW_AS2.DLL
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\QDOW_AS2.DLL
    C:\NULL

    I found this information by running the scan from trend micro. It gives me the option to delete these files, but I havent done that because I'm scared it's going to mess up my computer and I dont want to have to crash it yet again.
    Can someone please help me??
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please click Start, Run, and enter the following command
    notepad c:\windows\system32\drivers\etc\hosts

    When the notepad window opens hit CTRL-A to select all the info in the window then hit CTRL-C to copy all the info. Then come back here and paste the info into a new window.

    Alternately, when the notepad window comes up you could chose File, Save As, and save the file to a new name like myhosts.txt. Save it where you can find it. Then upload it here as an attachment.
     
  38. filipeb

    filipeb Private E-2

    Here it is...

    127.37.67.75 www.symantec.com
    127.199.192.18 securityresponse.symantec.com
    127.179.97.49 symantec.com
    127.218.91.136 www.mcafee.com
    127.104.202.169 mcafee.com
    127.31.182.121 us.mcafee.com
    127.148.7.49 www.sophos.com
    127.250.83.46 sophos.com
    127.39.178.242 www.viruslist.com
    127.198.14.151 viruslist.com
    127.134.89.245 f-secure.com
    127.150.100.95 www.f-secure.com
    127.53.26.108 kaspersky.com
    127.56.152.96 www.avp.com
    127.66.170.49 www.kaspersky.com
    127.171.96.230 avp.com
    127.124.194.208 www.networkassociates.com
    127.156.236.136 networkassociates.com
    127.218.45.165 www.ca.com
    127.123.86.121 ca.com
    127.152.222.8 my-etrust.com
    127.75.231.169 www.my-etrust.com
    127.250.228.118 secure.nai.com
    127.57.176.5 nai.com
    127.180.24.45 www.nai.com
    127.157.103.181 trendmicro.com
    127.98.203.201 www.trendmicro.com
    127.245.142.57 housecall.trendmicro.com
    127.163.230.187 www.pandasoftware.com
    127.246.69.158 www.bitdefender.com
    127.163.64.166 www.ravantivirus.com
    127.202.97.85 www3.ca.com
    127.65.14.22 v4.windowsupdate.microsoft.com
    127.16.147.68 windowsupdate.microsoft.com
    127.25.181.10 www.windowsupdate.com
    127.69.202.51 windowsupdate.com
     
  39. filipeb

    filipeb Private E-2

    I found these two files that looked suspicious in my registry... one is DLLDisk "syssrv.exe" and the other is LXSUPMON. They could be harmless files that I need, but I thought I'd check.

    Thanks.
     
  40. Kodo

    Kodo SNATCHSQUATCH

    your hosts file should like like this

    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost

    If there is anything after the local host entry, please delete it and then click file save , not file save as.
     
  41. filipeb

    filipeb Private E-2

    I don't understand... is what I pasted not the correct list?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! What Kodo is telling you is that none of those lines should be there. You need to make it look like the info he gave you. Only the 127.0.0.1 localhost line should be in there. All of your antivirus websites are being redirected.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See this on syssrv.exe:

    http://securityresponse.symantec.com/avcenter/venc/data/trojan.redro.html


    Do you have a Lexmark printer?
    LXSUPMON in for Lexmark Status Update Monitor. System Tray icon which enables you to monitor your Lexmark inkjet printer (ink cartridge level, nozzle checks, head cleaning, print progress, etc...).
     
  44. filipeb

    filipeb Private E-2

    Ok... how do I make the list look like the one he gave me? Am I not getting something? I'm confused here...

    (I'll try to take care of the syssrv.exe problem...)
     
  45. Deimos

    Deimos Private E-2

    Hi, open your host file with notepad and manually delete the entries that Kodo told you shouldn't be there. When you're done, save the file. Make sure that you go back and check that the host file didn't get saved with a .txt extension on it and you should be all set.
     
  46. filipeb

    filipeb Private E-2

    Ok, I think I was able to edit that list.

    I wasn't able to delete syssrv.exe from the registry. It just comes right back.

    For one thing, I've been using Registrar Lite, cause when I type regedit in the run box nothing happens. So I couldn't really follow all the steps listed.
     
  47. filipeb

    filipeb Private E-2

    Well, I opened the hosts list and everything I deleted was back!

    What am I doing wrong here? Nothing seems to be working... I still have the same problems.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you cannot download anything or run anything, this is not going to be easy.
    Can you at least bring up Task Manager using CTRL-ALT-DEL and copy what you find in the processes list back here.

    I know you said it was empty last time but that should not be. What OS did you say this was?
     
  49. filipeb

    filipeb Private E-2

    I managed to run Hijack This!!!

    I tried viewing the Processes tab again and again in Task Manager, and it was always coming up blank, like something was hiding it... then one time it came up and I ended the syssrv.exe ... then I was able to run Hijack This!

    So, attached is the log...

    Hopefully now we can really make some progress!

    Thanks for the help! Really!
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like some of the things I had you look for and delete a while back with Registrar Lite are still here.
    First you must get HijackThis into its own directory. You are running it from the ZIP file and will not get any backups of items we will be fixing.
    Extract it from the ZIP into a folder like c:\Program Files\HJT or c:\HJT . DO NOT put it on your Desktop either.

    After fixing the above.
    First you must disable system restore and make sure you have enable viewing of hidden files as per the tutorial.
    Now look in Control Panel, Add/Remove Programs for anything like MyQuickSearch or MyBar etc and if found uninstall it.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/
    F2 - REG:system.ini: Shell=Explorer.exe,syssrv.exe -shell

    If the below lines for MyQuickSearch are still present, fix them too.
    O2 - BHO: MyQuickSearch Search Assistant BHO - {04011C11-2F3B-44ed-977C-270CA669C6B2} - C:\Program Files\MyQuickSearch\SrchAstt\1.bin\MQSSRCAS.DLL
    O2 - BHO: mqsBar BHO - {0E677221-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL
    O3 - Toolbar: My &Quick Search - {0E677229-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL

    I would uninstall this ViewMgr crap unless you know you really need it. AOl sneeks it in.
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    Also fix these lines:
    O4 - HKLM\..\Run: [DLLDisk] syssrv.exe -services
    O4 - HKLM\..\RunServices: [DLLDisk] syssrv.exe -services
    O4 - HKCU\..\Run: [apvxdwin.exe] apvxdwin.exe
    O4 - HKCU\..\Run: [DLLDisk] syssrv.exe -drivers
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O19 - User stylesheet: (file missing)


    Reboot in safe mode and use Windows Explorer to delete:
    syssrv.exe
    apvxdwin.exe

    The could be in any number of directories. Try the following
    c:\windows
    c:\windows\system
    c:\windows\system32
    c:\documents and settings\username\local settings\temp (where username is your login name)

    If you cannot find it using Windows Explorer use Windows Search:

    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter syssrv.exe
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders

    Then click the Search button.
    When found right click on it and select delete.

    Repeat for the other file.

    Empty your recycle bin and also check c:\windows\Prefetch for filenames with these two programs in them. If found, delete them too.

    Now reboot normal and let's see where we are at.

    This syssrv.exe can be a real baddie. See these:
    http://securityresponse.symantec.com/avcenter/venc/data/trojan.redro.html
    http://vil.nai.com/vil/content/v_101120.htm

    Did you ever run the TrendMicro online scan from the READ ME tutorial.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds