something isn't right

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ahjan, Aug 7, 2004.

  1. ahjan

    ahjan Private E-2

    i got the new adaware, but whatever is stopping my computer, it still won't let me near Merijn. is that where the cure is?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot tell what the cure is because I'm still not clear on what the problem is. Your still not feeding me complete info. You need to provide more complete info and better feedback to each message I send you. Answer ALL of these questions completely and make sure for each case that you are using Internet Explorer. In any of the steps if you have a problem write down the EXACT message and put it in you next message.

    1) Can you get to this web page: http://www.spywareinfo.com/~merijn/downloads.html
    2) If so, can you download CWShredder from there (or anything else for that matter)?
    3) Can you get to this page: http://www.majorgeeks.com/download4086.html
    4) If so, can you download CWShredder from there?
    5) If the answer to 3 or 4 is no, (this is just a test but it is a good program) can you get to this page: http://www.majorgeeks.com/download1385.html
    6) If so, can you download Belarc Advisor 6.1f file with no problems?
    7) What version of Ad-aware are you running and what is the reference file (or definitions file) version?
    8) Where did you download Ad-aware from?

    Now please shutdown ALL applications especially Internet Explorer, FireFox, and Netscape and run HijackThis. Do a scan and save your log. Post a HijackThis log as a text file attachment back here.
     
    Last edited: Aug 14, 2004
  3. ahjan

    ahjan Private E-2

    i try and do all of these things you tell me on both internet explorer and on firefox. i don't know if there is a difference or not because it always seems to get the same results

    1. in internet explorer when i try to log onto the spywareinfo.com website it says this page cannot be displayed and when i try and log on in firefox it says the connection was refused when attempting to contact www.spywareinfo.com

    2. i cannot download cwshredder either from internet explorer or firefox because i cannot get to the website

    3. i can get to http://www.majorgeeks.com/download4086.html on both internet explorer and firefox

    4. when i clik on merijn using either internet explorer or firerfox on the majorgeeksdownload 4086 page on explorer it says this page cannot be displayed and on firefox it says the connection was refused when attempting to contact www.spywareinfo.com

    5.the answer to number 4 was no, so i tried to get to www.majorgeeks.com/download1385.html and was able to get there on both inernet explorer and firefox

    6.i was able to download belarc with both browsers.

    7. the version of adaware is adaware se personal and i downloaded it from the link that major attitude gave me on the #2 post -http://forums.majorgeeks.com/showthread.php?t=35407
    the results of the scan was 9/9 objects and all were IE Cache and were data miners. i removed them. the definition file is def file se 1r3 12.08.2004. there were no newer updates available.
    also when i downloaded the software advised me to uninstall vx2 and adaware6.0 which i did.

    Then i closed all applications including internet explorer, firefox, i don't have netscape and then i ran hijack this and am including the log. if you have any further questions just please be very specific and i will answer. thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In step 4, why are you trying to connect to Merijn again? You already know that it does not work! Try Downloading from the Majorgeeks links (there's two of them) or the Planet Mirror link.

    For step 7, I wanted the version number of Ad-aware not just the name (Ad-aware SE is program name). Click on the icon on the upper right that is an "i" and get the version number. The current version is 1.03.

    Sounds to me like you just have a problem getting to Merijn for some reason. Normally this could be due to things I already had you check. Like an entry in your hosts file or the Restricted Zones Setting. You could go back and double check them.

    Does you Norton stuff include a firewall? If so, perhaps you have blocked going to that www.spywareinfo.com. If you do have a firewall, just try disabling it for awhile to see if that changes anything.

    Your HJT log is basically clean. You could just have it fix these two lines since the files are missing anyway:
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
     
  5. ahjan

    ahjan Private E-2

    1. where is the planet mirror link? please be very specific.

    2. the version of adaware is 1.03

    3. i attached the hosts file. and downloads in the internet options dropdown security tab is enabled and there is nothing listed in the restricted sites.

    4. i could find no mention of a firewall in my norton's. it is just the anti virus version. is there a firewall somewhere in internet explorer or maybe in comcast?

    5. and i removed those lines from the hijackthis log.
     
  6. ahjan

    ahjan Private E-2

    here is the hosts file, i hope. the hosts file is not showing up and it says because i have already atttached it. but it does not seem to be here that i can see unless they mean when i attached it in my post #25.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already gave you the link that has both Majorgeeks links and the Planet Mirror link:
    " 3) Can you get to this page: http://www.majorgeeks.com/download4086.html"

    They are on almost every single download page from MG's. How could you be missing them? They are right in the middle of the page in bold print Download Locations:

    And how have you been doing any downloads if you do not know where to click?

    You do not just have Norton Antivirus. You also have Nortons Firewall. You show it in you HijackThis log (C:\Program Files\Common Files\Symantec Shared\ccProxy.exe). I think you need to step back and understand what you have put on your PC. It is clear you do not know exactly what all the applications are that you have installed. But at anyrate, I repeat what I said before, disable the firewall and see if that resolves the problem with getting to Merijn. That appears to be your only issue. You should be able to just use Task Manager (hit CTRL-ALT-DEL and click processes) to end the following processes (this does not uninstall them, they will rerun again on next reboot):

    ccSetMgr.exe
    ccEvtMgr.exe
    ccProxy.exe
    navapsvc.exe
    SNDSrvc.exe
    ccApp.exe

    After ending those processes, try going to Merijn's site and see if it works.

    And yes you already attached your hosts file in message #25, you needed to give it a different name for the upload to work. But if it is still exactly the same just tell me (I doubt that is the problem anymore though).
     
  8. ahjan

    ahjan Private E-2

    i was able to download cwshredder and i ran it and it found a trojan. the message said it was a cool web search byte verifier bug in microsoft java virtual machine (MS Java VM) and is already classified as a trojan strain byAV companies. It seems to be installed by certain popups on adultwarz galleries. it is unknown which popups. it said i could prevent it from happenening again by closing the hole or to remove msjavavm altogether since it is not supported anymore anyway. if you have windows xp without sp1a then install that.

    that is the good news. at that moment comcast went out. so i had to "recycle" my modem & router and turn off both computers. so i was unable to download the SP1a or to remove ms java vm, which i do not know how to do anyway. when i rebooted it was back. so now i have to start over. but i have to leave now to help my sister take my nephew back to school and will not be back until much later today. in the meantime when i ran shredder again i got this message"CWShredder v1.59.1 scan only report
    Please understand that a CWShredder 'Scan only' report
    might not be sufficient to troubleshoot an infected system.
    You can use HijackThis for that:
    http://www.merijn.org/files/hijackthis.zip
    http://www.spywareinfo.com/~merijn/files/hijackthis.zip

    Windows XP (5.01.2600 SP1)
    Windows dir: C:\WINDOWS
    Windows system dir: C:\WINDOWS\System32
    AppData folder: C:\Documents and Settings\janice\Application Data
    Username: janice

    Found Hosts file: C:\WINDOWS\System32\drivers\etc\hosts (734 bytes, A)
    Shell Registry value: HKLM\..\WinLogon [Shell] Explorer.exe
    UserInit Registry value: HKLM\..\WinLogon [UserInit] C:\WINDOWS\system32\userinit.exe,
    Found Win.ini file: C:\WINDOWS\win.ini (607 bytes, -)
    Found System.ini file: C:\WINDOWS\system.ini (227 bytes, -)

    - END OF REPORT -
    and i cannot update shreddr either. when i come home i will uninstall and reinstall shredder because it won't get rid of it now. i do not know why. then i need to know how to get rid of this java thing and i will also try and update windows although i thought i had. also since i have never been on an adult warz web site and it said it didn't know which popups i do have a clue for whoever fixes these things. since my computer is so new i had no popups until recently. i don't know how i got it but it has something to do with something called "Gain" that is the only thing on my computer that is causing popups so it has to be the link to this trojan. i don't know how to get rid of the gain thing either if you could help with that. it doesn't show up in add/remove programs so i don't know how to find it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no update for CWShredder 1.59.1. That's the current version. You did not click the correct button. You clicked Scan. You need to click the Fix button.

    You do not need to do what ever it is that you meant by,
    "when i come home i will uninstall and reinstall shredder because it won't get rid of it now".

    Just run CWShredder and click Fix.

    To remove the Microsoft Java stuff see this thread by Major Attitude: http://forums.majorgeeks.com/showthread.php?t=25834

    The Gain Bundle crap is installed with a variety of different applications. You should go back to running Ad-aware SE and SpyBot S&D again. Make sure you have the current versions and UPDATES before running. Ad-Aware SE reference just updated today. And SpyBot updated on 8/11/2004. Make sure you are running Ad-aware SE not Ad-aware 6.0. You can also checkout this link which may help: http://webpdp.gator.com/gain/about-gain-01.html
     
    Last edited: Aug 16, 2004
  10. ahjan

    ahjan Private E-2

    1. i clikked fix and it says my system is clean now. what is the "hosts are found"? is that a bad thing?

    2.I updated spybot and it found two things which i removed

    3. updated adaware - it said build SE1R4 16 08 2004 Date 16 08 2004 and removed 23 items.

    4. i tried to remove java, i have tried it over and over but it says could not locate INF file 'java.inf'. does that mean it already gone from my system? the programs menu shows a java web start and belarc shows java web start and javaw.exe

    5. the gain link told me how to get rid of gain. my programs only lists a gain publishing and that shows about gain and gain publishing. i never get to an item that tells me what gain supported software i have which their instructions told me i find. is this gain publishing the thing i should be looking for. when i clik on the about gain item i get a message which says GMT has changed or moved. do you want to delete which i said yes to. but the gain publishing item remains in my program menu. if i right clik on it will i be able to delete it that way?

    6. also when my computer was still nutso, whenever i went to the sites you gave me which had the major geeks1, major geeks 2, and planet mirror links on those sites and i clikked on those links they were totally non functional. that's why i didn't always know what you were talking about. i would clik on everything until i could get to the site and then i couldn't do anything there either. everything was just locked up. i'm telling you this just so you don't think i'm totally crazed.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1. Thats okay! It's just telling you that you have a hosts files which is normal. But that message displays when you click scan not when you click fix.

    2. What did SpyBot find? Was it anything serious or just cookies?

    3. What did Ad-aware SE find? Was it anything serious or just cookies?

    4. MS Jave is probably already removed. And seeing those files in BelArc is normal.

    5. Since Gain does not show in Add/Remove programs, I would like to see a HijackThis log (posted as an attachment using the current version of HJT).

    6. Okay! But is everything working properly now!
     
  12. ahjan

    ahjan Private E-2

    1. spybot found DSO Exploit and Alexa

    2. adaware found 21 negligible entries which were MRU's a d
    IE Cache Entry - cookie adserver.com
    IE Cache Entry - cookie tribal fusion.com
    IE Cache Entry - cookie centerport.net

    Everything else seems to be working great! Thank you very much. you showed incredible patience.

    i have a couple questions also.

    What do i use belarc for?

    Should I always use Mozilla when using the internet? And should i put it on my other computers?

    I know you said i have a norton firewall, but i don't know how to get to it or how to set it up. I stopped using it on my old computer because it totally kept me off the internet. I guess that is one way to protect your computer. but i don't know how to tweak it to allow me to go where i want to and how to keep out everything else.

    Should i always delete stuff from spybot and adaware and not keep it in quarantine?

    i was going to buy spysweeper for this computer, but is spy blaster the same thing; is it as good or better or are they two different things?

    is there anything i installed in this process that i don't need and should take off this computer or should i leave everything and use them all, all of the time.

    Finally how does all this transfer to my old windows 98 computer. i am assuming they both have the same thing since they both started acting weird the same time.

    And now something totally new and different. when i got the new dell (not the laptop that you have fixed for me), my husband asked me to transfer his address book from the windows 98 outlook express to comcast email. it took a lot of research because there really is very little devoted to the address book, but i had to change it to some strange file extension and send it to comcast email. I did it but when it got there it had multiple entries for the same people. and he cannot delete or edit these names. there is an error message that says some entries cannot be deleted or edited. log out and try again. bottom line it takes forever to boot up, he is nearing capacity for the address book altho most are duplicate entries. if he tries to edit, it becomes a new entry whcih also cannot be deleted or edited. he wants to use outlook on the new computer, but is afraid to transfer the file again. my address book that i did the same way is fine. my girl friend said it is probably a read only file, but she couldn't figure out how to fix it either.
     
  13. ahjan

    ahjan Private E-2

    i had trouble attaching the hijackthis log. i'll bet that surprises you.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are up to date with you Microsoft Critical Updates, you can ignore the DSO Exploit that SpyBot gives you (it is a bug in SpyBot). You can also disable SpyBot from detecting it in Advance Mode, Settings, Ignore Products.

    The Belarc Advisor builds a detailed profile of your installed software and hardware and displays the results in your Web browser. It is a system info tool that gives you a bunch of information about your system, the software you are running, the installed MS patches, etc. It is just a useful thing to have sometimes. I only had you download (way back) to test you download capability but I chose something that we could have used for collecting system information.

    At the current time Mozilla FireFox (or did you mean Mozilla 1.72) is a safer choice that Internet Explorer and you may find that you prefer it. It would not hurt to use it on all your PCs.

    As far as your Norton Firewall, you will have to read the manual. I have never used it or even seen it in action. Every firewall has pretty similar things that you the user will have to do in setting it up. You need to give approval for each application that you run to get access to the Internet or your local network. The firewall builds a list for Trusted Zones and Internet Zones based upon what you tell it.

    Unless you are absolutely sure you know what you are doing, it is best to allow items cleaned up with SpyBot and Ad-aware to remain in quaratine at least for a few days to make sure you did not need the item. You can delete from the quaratine later.

    You can use SpywareBlaster and SpywareGuard (both free and the work well to compliment each other) and provide yourself with pretty good protection. SpySweeper is good too but you have to buy it. Which is better can be a matter of personal preference and requires a lot of objective testing.

    Your log looks pretty good other than one line from AOL that shows this ACSd.exe.
    I assume you are running AOL 8.0 or older. Perhaps you should update to 9.0. That executable process caused problems with PC slow downs and resource hogging in the past. See this link and scroll down to find ACSD.EXE:
    http://www.answersthatwork.com/Tasklist_pages/tasklist_a.htm

    Most of what we have down applies to your Win98 PC too but that's a different thread (to come I assume if you have a problem).

    Your question about converting address books for Outlook to Comcast email belongs in a different forum (most likely the Software Forum).
     
  15. ahjan

    ahjan Private E-2

    1. i am up to date with all critical updates from microsoft

    2.i am using mozilla firefox. that was what you told me to install. i don't know if there is an advantage to 1.72 over firefox or what.

    3. i'll study up on norton to know what it is all about.

    4. i installed spyware blaster. now how does it work. it does not scan. is it just working in the background to keep stuff out? also where it says it has disabled internet explorer, disabled restricted sites protection, and disabled firefox protection, is that a good thing or if you have them all up and runniing aren't you better protected. or would they have conflicts with each other. i thought i was using firefox for better protection, but if this has disabled it do i still need firefox? if i am using this, is the norton firewall a separate protection protecting you against different stuff or do i not need to use the norton firewall?

    5. do i still need vx2 or does it only work with adaware 6.0?

    6. i am not using aol, it just came with the computer. should i uninsatll it.

    7. how do i get all these setup shortcuts for all the spy and virus software off my desktop or do i need them. if i need them can i put them in the unused desktop icon?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    4. SpywareBlaster does not scan. It is a protector. You need to choose what items to protect. You should enabled IE, Restricted Sites, and Firefox protection.
    Yes you still need a firewall for proper protection. A firewall is much different than what SpywareBlaster is doing.

    5. The VX2 cleaner pluging only worked for Ad-aware 6.0

    6. If you don't need AOL then get rid of anything related to it ASAP.

    7. I would keep Ad-aware and SpyBot on my desktop if I were you. Run scans with them frequently. You should also be performing periodic scans with your virus software too. Why would you want to remove them from your desktop? Yes you can always remove them and then run them from Start, Programs too. That's up to you to decide. Just do not uninstall them.
     
  17. ahjan

    ahjan Private E-2

    i do have adaware and spybot on my desktop. what i want to get rid of and move to the unused desktop icon thing is the icon for adaware that says aawsepersonal, house call netscape ( do i even need that one), plvx2cleaner,aboutbuster.zip, psa201se_us.exe,spybotsd13.exe, ccsetup112.exe,firefoxsetup, advisor.exe, and a2freesetup.exe. i am leaving the icons Ad-AwareSE Personal, About Buster, spyware blaster, hijackthis.zip, Spybot - Search & Destroy, HSRemove.exe, Belarc Advisor, a2 Start Center,cwshredder,zip, and delcwssk.zip. is realplayer part of one of these programs? do i need it?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why in the world are you downloading stuff to your Desktop? Stop doing that. You are making a ton of un-necessary cleanup work for yourself and for me. I hate programs that do that by default. It is a stupid idea. People recommend it because they say it will be easy to find. I say, you need to learn how to use your computer. So make yourself a directory like c:\downloads and when you download programs download them there. You can even make subfolders as you download under the download directory to categorize the downloads. And you should give the subfolders names that represent the program itself so you can tell what the file is 3 or 4 months from now. For example: do you think you will know in a few months what this is: ccsetup112.exe. But if it was in a folder named c:\downloads\DriveCleaners\CCleaner V1.12 it would be easy to know what it is.

    You should move all of these off your desktop to the download directory (its better to save them in case you need to reinstall for some reason):
    aawsepersonal <--- this is a .exe file (aawsepersonal.exe)
    house call <---- what is this from? Did you download a program to your desktop?
    netscape <---- what is this anyway. Is it a shortcut run Netscape or to install it. Looks to me like this is the shortcut to run it. If so, you may want to keep it.
    plvx2cleaner,
    aboutbuster.zip
    psa201se_us.exe
    spybotsd13.exe
    ccsetup112.exe
    firefoxsetup
    advisor.exe
    a2freesetup.exe

    This next group of 5 could all be in a SpywareTools folder and you can run them from there. Obviously they would need to be extracted from any ZIP files they are in.
    hijackthis.zip
    About Buster
    HSRemove.exe
    cwshredder.zip
    delcwssk.zip

    Do not put EXE or ZIP file downloads on your Desktop anymore.

    You must have downloaded Realplayer or something you used like Netscape did. If you do not need it and do not plan to use Netscape and the features that require it, uninstall it from Add/Remove Programs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds