something isn't right

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ahjan, Aug 7, 2004.

  1. ahjan

    ahjan Private E-2

    i have two computers, one a dell with Pentium 3 processor at 800 MHz, a 40 gig HD that is only about 20% used and 384SDRAM memory running windows 98 and if i do say so until recently it was running optimally. The other is a dell laptop with a Pentium M, 1.5Hz, a 40 gig HD which is new, and 512MB, 333MHz 2, running Windows XP. I regularly run CW Shredder, Stinger, Adaware, Spybot, Norton's, and Spysweeper on the old computer. I also update windows. The old computer started running a little slow and when I ran everything it cleaned it, but I could not update CW Shredder. And when I try and run it I get the following message : You have a variant of the CoolWebSearch Trojan (CWS Smart Search 2) that has attempted to close CW Shredder. To counter this CW Shredder is now starting with a random string of text in the title bar. CW Shredder is still functioning fine, it has not been corrupted. If you feel you should not be getting this error and you are not infected, restart CW Shredder and this warning should not occur again. I tried downloading CoolWWWSearch.SmartKiller(v1/v2)Mini Removal and it tells me it is downloaded, but when I try and openit, the computer says the file is not there. The computer is running slow and at time on the internet, I get black patched or cannot open things. The new computer only has Norton, Adaware, Spybot, and I just downloaded CW Shredder which when I run it, it says some hosts are present and I get the same error message. I can't download any updates for CW Shredder nor the Mini Removal tool. I have updated windows on the new laptop as well. I tried running the old computer in safe mode and ran all the scans and they show nothing. I haven't disabled system restore on the laptop, but then I am not at the point where I am fixing it yet anyway. Help! Help! Help! It is 2am and has been a very fruitless day.
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. ahjan

    ahjan Private E-2

    i have meticulously followed you instructions, only on the laptop because it did not work. I downloaded and used in the safe mode CCleaner, Adaware with VX2 plug in, Spybot (updated yesterday), Kill2Me said I have no parasites,About Buster, and HSRemove. A2 removed two and I thought I was home free. I used the thread from Chas Lang which said I was clean. Nothing from any of these, but A2. I still can't update CWShredder and it still repeats the message about the variant CWSSMart Search2. I also still get the follwing message after running the scan. "Found hosts file C:\Windows\system32\drivers\etc\hosts\734bytes,A CWS.msconfig Registry value:HKLM\..|Run [msconfig] C:\windows\PCHealth|Help Ctr|Binaries\msconfig.exe\auto shell registry valuw:HKLM\..\winlogon[shell]explorer.exe" I also ran an updated norton's. This is where I am at.
     
  4. suesman

    suesman First Sergeant

    Removed. You linked out for Hijack This, when you should have linked to the tutorial which explains not to post Hijack This log files as cut and paste making us work more now. You are unable to analyze Hijack This log files, so you should not be instructing people to post them. Frustrating. Thanks for understanding.
     
    Last edited by a moderator: Aug 7, 2004
  5. ahjan

    ahjan Private E-2

    Attached file for you, you didnt know :)
     

    Attached Files:

    Last edited by a moderator: Aug 7, 2004
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Your hijack this is out of date, please download a new copy from us here. Apparently the link you were given has not updated, another reason we like you to download from us: http://majorgeeks.com/download3155.html

    In the meantime, heres some general tips and read the Hijack This tutorial, you got this far, you will be able to do some cleanup yourself. Chaslang may have more, I had to look a few up, but this does not look bad, so I will get you started:

    Check add\remove programs for suspicious items.

    Disable Nvidia Driver Helper Service in control panel, administrative tools, services. Its not needed. This assumes this is the XP machine. Please give us details on the machine in question, one at a time is hard enough :)

    Remove:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    Tutorial:
    http://forums.majorgeeks.com/showthread.php?t=38752
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Agreed Major! In addition to getting the newest HijackThis, you need to put it into its own directory and stop running it from the Desktop. Make a directory like c:\Program Files\HJT and put it in there.

    Also, since you are having problems updating CWShredder, stop trying to update it. Download the latest versions of both of the following from MGs CWShredder and CoolWWWSearch.SmartKiller(v1/v2)Mini Removal.

    Run those versions and see what happens. Also try running them after booting into safe mode.

    You should also run Ad-Aware configure for "fullscan". This is a special configuration. See how to do that here. Also, do this fullscan in safe mode.
     
  8. suesman

    suesman First Sergeant

    Did I say I knew how to analyze them? I think that was a bit harsh man. Ok, sorry about linking to another site, won't happen again.
     
  9. ahjan

    ahjan Private E-2

    should i delete the old hijackthis.exe, hijackthis.zip, and the old log file before i continue? if i download a new cwshredder, do i delete the old versionof that? and what is the mgs i am supposed to download cwshredder and the mini removal program (which i have tried to download multilpe times and when i try and open it it says it can't be found)also what other details do you need on my xp machine? please be patient and go slow here, i am old and this is making me feel older. thanks
     
  10. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Just to clarify, why would you tell someone to post a Hijack This log file if you cant help them? Who is going to analyze it then? Exactly. I call that hit and run support. Your right, it was a bit harsh and I apologize, but this hit and run support I am seeing with generic responses and no follow up must stop. Now.

     
  11. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Yes, delete all old Hijack This files before installing a new version. Same with CWShredder, but check add\remove programs to see if they can uninstall first, then delete old files.

    From there, I apologize for the thread getting messy, please follow Chaslangs instructions a few posts up and check back with us please.



     
  12. ahjan

    ahjan Private E-2

    i could not find hijakthis and cwshredder in add/remove. everything there appeared to be stuff i knew, so i deleted them. i cannot download an updated version of hijackthis from the link you gave me. it just keeps saying this page cannot be displayed and sometimes when i clik on it to open the merijn, it won't even attempt tp open the page. it's like you never clicked on it. i disabled the nvidia driver helper. i don't know where to find the BHO stuff you want me to remove (unless those were lines in the now deleted hijackthis log). also what other info do you need about my xp machine. i have to finish this soon hopefully as i will be leaving my current location and taking my laptop with me, but leaving the old windows 98 machine here until i return in 16 days. help!!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis and CWShredder do not use an installer, so they are not going to be in Add/Remove programs. All you need to do was delete the old versions and download the new ones (putting them in their own directories as stated previously.

    If you are unable to download HijackThis & CWShredder, try the info below to get EXE versions direct from Merijn. These alternate links should always work:

    HijackThis direct download: http://209.133.47.12/~merijn/files/HijackThis.exe
    CWShredder direct download: http://209.133.47.12/~merijn/files/CWShredder.exe

    The redirection is probably because of a Coolwebsearch variant (CWS.Aff.Tooncomics or CWS.Dreplace) that intercepts your download to prevent downloading my programs.


    The BHO lines were shown in you previous HijackThis log. If you already fixed them, they will no longer show.
     
    Last edited: Aug 9, 2004
  14. ahjan

    ahjan Private E-2

    i tried the alternate links and all i get is "this page cannot be displayed" for both of them. Is there some way, i can get the mini removal tool also or don't i need it. i'm thinking i need everything and a miracle too!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try downloading the attachment from this message. It has the mini removal tool in the zip.
    Then run it and let us know where you stand. If it runs and finds stuff to fix, run CWShredder afterwards.
     

    Attached Files:

  16. ahjan

    ahjan Private E-2

    i tried downloading from the link you sent, and has happened before whenever i tried to download the mini removal tool, i download, but when i try and open it i get "coolwwwsearch.smartkiller(v1/v1)miniremoval cannot be found on your system."
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to be careful what you write. You do not get that message when you open the ZIP file. Yo get that message when you run the executable file within the ZIP file. That message is telling you that your system is not infected with the version it looks for (i.e., that's good).

    So when you download CWShedder from this link, what happens:
    http://www.majorgeeks.com/download4086.html

    I'm asking about just downloading the file. Can you download the file?
    If yes, can you unzip the executable file out of the ZIP file?
    If yes, can you run cwshredder.exe?
     
  18. ahjan

    ahjan Private E-2

    i don't have to be as careful with what i write, as thinking about what i just read. but i am truly a neophyte here and you guys have walked me through an amazing amount of computer fixing. i never could have done it without you. not that we are quite there yet. when i try and download the file from the link you provided, it takes me to the majorgeeks page with the merijn link. but no matter how many times i try and get to it, it tells me that the page cannot be displayed. it must be so cool to know as much as you do about how computers work and how to fix them. i really respect that. anyway, i feel there is hope here and we are getting close.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, we need to check a few things:
    1) with Internet Explorer open you need to click Tools, Internet Options, and then the Security tab. The selected the Restricted Sites icon and then the Sites button below it will become active. Click the Sites button and scroll thru the Websites list and make sure none of the valid sites you are trying to access are in that list. If they are, click on it and then select remove.

    2) again from Internet Explorer click Tools, Internet Options, Security, click Custom Level, and scroll thru the settings until you see Downloads. Make sure they are not disabled.

    3) I would like to see your hosts file but I am not sure if we are still talking about your WinXP system or your Win98 system. I assume it is the XP one since that is what your last HJT log indicated. So click Start, Run, and in the open dialog box enter the following:
    notepad c:\windows\system32\drivers\etc\hosts

    Then copy all the information from the hosts file back here (as an attachment).
     
  20. ahjan

    ahjan Private E-2

    well i got it open in notepad,but i didn't know how to attach it, so i saved as a .txt file and tried to attach it through the maage attachments thing, but i didn't know how to do that either. i am talking about the xp machine now. help.

    when i went into internet options there were no web sites on the restricted sites list. then i did the custom level thing and downloads says enabled. Download unsigned Activex controls says disable and download signed activex controls says prompt.

    sorry i get stuck so often. i really am a have limited computer knowledge.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just click on Manage Attachments, then click the Browse button and locate the file on your computer that you want to upload. Then click the Upload button. If that works okay, you will see it in a list. The click close this window. That's it.


    The other options for Download and ActiveX were set okay.
     
  22. ahjan

    ahjan Private E-2

    where is it?
     
  23. ahjan

    ahjan Private E-2

    i tried it again. i opened it in the run command line, clik post reply,manage attachments, name of file just like in the run line, upload, when finished close, submit reply. but, i don't see it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before my last reply you said you had already save it as a .txt file. You did not need to use the run command to get to the hosts file again. Just upload the .txt file you saved already.
    If you forget where it is, save another copy to a .txt file and upload it. You cannot just simply upload the hosts file because a filename with no dot extension is not uploadable.
     
  25. ahjan

    ahjan Private E-2

    well i uploaded the txt file, i hope.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your hosts file looks okay too. I'm not sure why you cannot download the files. Can you download anything at all from any website?

    Hope so! Try downloading Mozilla FIreFox: http://www.majorgeeks.com/download2248.html

    If you can download it, install it and try using it to download the new HijackThis and CWShredder and of course running them. Post a new HijackThis log attachment.

    If you cannot download at all, PM me with an email address and I can try to email HJT and CWShredder to you. Perhaps that is one way to get them on your system.

    I forget.....do you have a virus scan application installed and running. Try using each of the below online scans and tell me what they find:
    http://housecall.trendmicro.com/housecall/start_corp.asp <--- select Auto Clean
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm
    http://www.ravantivirus.com/scan/
    http://www.bitdefender.com/scan/licence.php
     
  27. ahjan

    ahjan Private E-2

    after working an hour, i have the following:
    i do have norton, updated and have run it several times. it shows nothing.
    housecall the timer comes up when i clik on the free scan, then it tells me i do not have netscape, and should download it, but it never shows up and so when i clik at that point i get the timer and unltimately an error notoice i can only partially read which says an error has occurred.
    panda says page doesn't exist, altho i am at the website at that point.
    ravantivirus says it ceased online scanning 9/2/03.
    bit defender says it supports only activeX enabled browsers. this makes it unavailable for netscape family browsers.
    i tried all of these thru mozilla and also thru comcast.
    i did download mozilla successfully however, when i try and download either hijack or shredder i get the same message which is "the connection was refused when attampting to contact 209.133.147.12" that's all for now.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The IP address you gave (209.133.147.12) is for the State of North Carolina ( NS1.NET.STATE.SC.US)
    Perhaps all of your problems are with an external firewall. Where are you trying to do this stuff from?
    I assume it is not at home.
     
  29. ahjan

    ahjan Private E-2

    i was in park city utah on vacation. i have the old dell there with windows 98, which i have not attempted to fix at all. i came home to arlington hts illinois today. my computer at home here is fine. i just opened the laptop and will try tommorrow to download some of that stuff from here and see if that works based on what you are telling me. i'll let you knoe my progress.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could it also be due to you using Netscape to do the downloading? I was overlooking that! I just assumed you were using Internet Explorer to do downloading.
     
  31. ahjan

    ahjan Private E-2

    my mistake. i copied the number wrong. it was 209.133.47. 12. i was using internet explorer,but it told me for two of those downloads that i should use navigator. i just tried to download shredder and hjack again. the page could not be displayed on comcast for either site, on firefox it said the connection was refused when trying to contact 209.133.47.12 for both sites.
     
  32. ahjan

    ahjan Private E-2

    my mistake. i copied the number wrong. it was 209.133.47. 12. i was using internet explorer,but it told me for two of those downloads that i should use netscape. i just tried to download shredder and hjack again. the page could not be displayed on comcast for either site, on firefox it said the connection was refused when trying to contact 209.133.47.12 for both sites.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That IP address (209.133.147.12) is for the State of North Carolina ( NS1.NET.STATE.SC.US)

    Why is you system trying to go there in order to connect to Majorgeeks?
    Who is you ISP?

    Try this

    Click on the the word 'this'
     
    Last edited: Aug 12, 2004
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And which PC are you using right now!
     
  35. ahjan

    ahjan Private E-2

    the laptop with xp. the one with windows 98 stays in utah. my computer at home in illinois is unaffected and i hope it stays that way. i was so tired las night i missed your this. how do i make it a directory or as it is asking me to do, to make it a different folder.please be very specific here.
     
  36. ahjan

    ahjan Private E-2

    i am not turning off my computer now until i hear ffom you. this morning when i went to your website with firefox, i could get to the site, but it refused to connect me to your support forum. when i went on explorer, i got to the site, then it took a long time, but ultimately it let me get to the support forum. weird, huh?
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure where you are referring to here. Do you mean when you clicked the link I gave you and the file starts to download? Then you click save. At this point there are icons at the top of the popup window that allow you to navigate around on your harddisk and to create a new folder and give it a name. The little down arrow will quickly let you see a sort of My Computer like view. Move your mouse over the icons. I'm sure you will see it is pretty easy.
     
  38. ahjan

    ahjan Private E-2

    i think this is the log. i made it a txt file. does this work?
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So what is the purpose of this log now. (And is this the whole log? It looks like some info was cut off.)

    Also, this jumping back and forth between a Win98 PC and a WinXP PC has me dizzy.
    Why are we working on this WinXP system now? Do you have download problems on this PC too?

    The only items I see are the two items Major Attitude gave you way back in the #6 post (and I guess you never fixed them):
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
     
    Last edited: Aug 12, 2004
  40. ahjan

    ahjan Private E-2

    i am working only on the xp laptop. you asked where i was and that was why i told you where each macine was. but i am only working on the xp laptop. i think this is the whole log, but i can remove those lines and then do i delete the old log and run it again.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alrighty! You should be able to just overwrite the old log (.txt) file when you save the log.

    Are you having any problems downloading and installing/running programs now?
     
  42. ahjan

    ahjan Private E-2

    i have removed the two BHO lines, now what do i do? just as a benchmark, i have tried downloadin cwshredder from the merijn site and all i get is this page cannot be displayed.
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What program are you using when you try to download (i.e., what is your browser)? Also, what is your default browser?

    I'm asking this because several times (especially when I asked you to run the online scans) you mentioned Netscape.
     
  44. ahjan

    ahjan Private E-2

    when you told me to download firefox, during setup i told it to make it my default browser, but it did not. i tried it a second time and the same thing happened. i have a desktop icon, but even that doesn't aways take me to firefox. more often it goes to microsoft internet explorer and i have comcast broadband here and in utah. the illinois broadband i sometimes have problems with, but in utah have not had any problems with that. anyway, i can get to firefox, but sometimes it requires a little effort. i don't use netscape, those websites were telling me i had to use netscape to get to their sites and use their scans. but i kept getting error messages saying either i didn't have netscape or they couldn't find it on my computer.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you are not using Netscape right?

    And when you just tried to download CWShredder which browser was running?
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way awhile back you said RavAntivirus online scan was taken offline 9/2/03, I don't know what you are clicking or using but I'm starting to wonder about everything you have been telling me. I just did a complete online scan with Rav just now and it works fine. See results below:

    Scan started at 8/13/2004 11:52:32 AM

    Scanning memory...
    Scanning boot sectors...
    Scanning files...
    Scanned
    ============================
    Objects: 65856
    Directories: 4929
    Archives: 4397
    Size(Kb): 98783
    Infected files: 0
    Found
    ============================
    Viruses found: 0
    Suspicious files: 0
    Disinfected files: 0
    Mail files: 836
     
  47. ahjan

    ahjan Private E-2

    I am not using netscape. When i tried to download cwshredder, i tried on microsoft explorer and got a page cannot be displayed. i also tried on firefox and got connection was refused to spywareinfo.com. i'll try all those scaning links again, but i told you what happened when i tried before. The Rav thing was a whole page about stopping the scan.I'll try again tho.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you goto the Rav page the first thing you do is click in the middle of the page where it says "

    To continue without subscribing click here. ​



    Then on the next screen check the Auto Clean button and then click Scan My PC.
    When its done you can copy and paste the output of what it finds (like I did) back here. If it does not find anything, just say so.
     
  49. ahjan

    ahjan Private E-2

    this is like the twilight zone.

    i went to Trend micro no viruses (the left side of the page was the same, but the right side of the site page was different from when i tried it the first time)

    panda no viruses but 15 messages - what's that?

    rav - no viruses

    bitdefender - memory ok
    master boot record ok
    partition 1 (primary) ok
    partition 2 (primary) (active) ok

    the las time, i never got security warnings, whatecer i clikked on would not respond either. did removing those things this morning allow me on those sites now? i was reading about a mirror site for merijn called merijn.richardthelionhearted.com in case you can't reach cwshredder or is this a ruse?
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't go to any other mirror sites right now! Try getting the files from Majorgeeks. All of the files you need are listed right in the following link:
    http://forums.majorgeeks.com/showthread.php?t=35407

    See if you can download stuff now (like CWShredder, HijackThis, the new Ad-aware etc).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds