something has taken over

Discussion in 'Malware Help (A Specialist Will Reply)' started by jjroyer, Feb 8, 2005.

  1. jjroyer

    jjroyer Private E-2

    Something has taken over my computer. I have run all the pre-posting steps, also have Pc-cillin internet security 2005 installed. I was hoping that the extensive package of downloaded spyware programs etc. would clean off the problem but alas it hasn't.

    After I re-boot my computer, within 30 minutes any attempts to use it bring up a "system dangerously low on resources" message. Additionally, I frequently get another un-solicited windows pop up stating that "there is currently no connection available to the internet" and asks if I would like to try again or work offline.

    I am running windows 98 on a pentium 3 with 96 megs of ram.

    I have checked the startup files and very little is checked to start up at re-boot. I downloaded a process explorer and have not seen anything un-identified running (that I know of )

    I have very few problems with my online usage. In fact, if I get online, the computer does not seem to have its freeze up problem.

    I don't know if this is a spyware/malware problem but would welcome any suggestions.

    thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. jjroyer

    jjroyer Private E-2

    Thanks for the quick reply.

    Attached is the hjt logfile.

    Thanks,
    jeff
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never ran the TrendMicro online scanner! Is there a reason for that?


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R3 - URLSearchHook: (no name) - _{33B62B75-26DC-67DB-24D3-4DF1BD7CD9D7} - (no file)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE (file missing)

    After clicking Fix, exit HJT.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Question:
    Did you change this or did AOL do it to you? Do you want them to be your Start Page?
    O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
     
  5. jjroyer

    jjroyer Private E-2

    Attached is the new hjt log file.

    I thought I had run the trend micro house call before but remembered that I was booted off before it finished running. I ran it again today.

    Eliminated the lines as suggested. Do not know why line 014 reads as it does.

    Alas, still having the same difficulties. The window still continues to appear saying that no connection to the internet is available. Also, the computer locks up after a period of time from lack of system resources and requires control/alt/delete to reboot.

    I have noticed that my pc-cillin real time scan frequently pops up a message saying it has detected something and under "action taken" it remarks "denied access". I don't know if this means the problem file blocked access for removal by trend micro or if trend micro blocked access.

    Any other suggestions?

    thanks
    jeff
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How do you connect to the internet (dial-up, cable, or DSL)? Looks like DSL?
    Who is your service provider?

    What browser do you use? Did you allow your browser access to the internet in your firewall?

    Try temporarily disabling your firewall. Can you connect now?

    Are you still having problems with resources being low?
     
  7. jjroyer

    jjroyer Private E-2

    I am using dial up through aol.

    I switched to Firefox after I started having all these problems. It really cut down on all the bad traffic.

    I don't have a problem connecting to the internet - the message box that frequently pops up comes un-solicited and is never associated with me actively trying to get online. It makes me wonder if there is some sort of malware that is trying to send information out.

    I still have a systems resource problem.

    Maybe a new computer is the solution?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so know I'm confused! Earlier you said:
    I thought this meant you had no internet connection. When does this popup exactly? Does it ever popup even when you have not dialed into AOL? Like when you just boot up and do nothing? Is this a popup from AOL? What exactly "word for word" does it say?

    How much of yous system resources are available after boot?

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". Click Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     
  9. jjroyer

    jjroyer Private E-2

    chaslang-

    sorry for the confusion!

    The window pops up un-solicited. This morning it came up just after re-booting.

    It is a windows type box with a blue band at the top in which is written "Work Offline"
    The text within the box reads:

    "No connection to the interent is currently available. To view internet content that has been saved to your computer, click Work Offline.

    Click Try Again to attempt to connect."

    Then below that are two buttons, one for Work Offline and one for Try Again. If work offline is selected, the window temporarily disappears and then comes back. A second click on Work Offline makes it go away. A single click on Try again makes it go away. It also randomly pops up at other times other than just at re-boot.

    When I re-boot the computer, my system resources are around 94% free.

    Attached is the startup file from hjt.

    I appreciate your attention and time - time has got to be the most valuable commodity we all have.

    jeff
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please reboot your computer and do not close this window that pops up.

    Then run only HijackThis and get a new log and post it here.

    Also please look for this file on your PC:

    C:\WINDOWS\SYSTEM\WGOCK32.DLL

    Tell me if you find! If you do, right click on it and select Properties and then the Version tab (if it has one) and go thru the version info. This particular file name has been asociated with ZestyFind or Look2Me.

    Did you run the Kill2Me program in the READ ME FIRST thread?
     
  11. jjroyer

    jjroyer Private E-2

    You know how when your car is making a funny sound and you take it to the shop it always DOESN'T make the sound when you need it to? I haven't been able to get that little window to pop back up this afternoon.

    In the meantime, I searched but did not find wgock32.dll. The closest thing I did find was WeOCK32.DLL which was 305 kb large and had been created today.

    I mentioned in an earlier post some questions I have about how my pc-cillin was operating. I modified the program from it's default settings on real-scan mode and now it has been quanantining some files that I think previously had remained in the computer. I will see if that has a positive effect.

    As soon as I get that little pop-up again I will run hjt again and post the file.

    thanks
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL!!

    That WeOCK32.DLL file sounds suspicious and maybe the samething as wgock32.dll renamed. Considering it was just created today, I would be very suspicious. It may be renaming itself each time you boot. Did you install anything new today that could possibly have added this file. Try getting Properties, Version info from the file.
     
  13. jjroyer

    jjroyer Private E-2

    I think we may have nipped it in the bud.

    For the first time in two months I left my computer on last night and was able to sit down and get online without a control/alt/delete first.

    The combination of finding those lines in hjt combined with the new settings on the pc-cillin seems to have cleaned off the problem for now.

    If anyone else is having a similar problem - A manual scan finds no viruses, the online scan found no viruses, but they seem to get detected by the real-time scan feature. The default setting on pc-cillin real time scan for what to do with an infected file is "recommended action" - seems to make sense. I switched it to take a specified action of cleaning or quarantining and suddenly started nabbing stuff. The interesting thing is that a particular virus would be associated with several different files before it was successfully quarantined.

    Thanks for all your help!! I have started implementing my new-found knowledge of these methods and hjt to clean out my in-laws computer.

    jeff
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds