Spyware? Apps Hanging

Discussion in 'Malware Help (A Specialist Will Reply)' started by NotResponding, Nov 21, 2005.

  1. NotResponding

    NotResponding Private E-2

    Hi all,

    Having problems running (in particular) internet explorer in XP Home, which "hangs" pretty much as soon as it's launched, displaying the "Not Responding" message at the top. Ctrl+Alt+Del closes the app. Problem also occurs in MSN messenger, and starting to get same problem in windows explorer, Help, and occasionally Office apps.

    I have followed the spyware cleaning instructions (Adaware, Spybot, Antispyware, etc) - Adaware located and removed a couple of nasties. Search and Destroy and Antispyware both locate spyware, but when I click on fix/clean, these programs hang too! Very frustrating.

    I am using wireless LAN at home, using 2mb broadband connection.

    Also, I ran the registry file check using the XP disk just in case.

    Any thoughts? Thanks in advance.

    p.s. I have SP2 installed, and I've just installed Firefox to work around the problems - it seems to work fine at the moment.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run them in safe mode with no connection to the internet available buy unplugging the cable?

    Make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. NotResponding

    NotResponding Private E-2

    Yes - I've tried the procedure in both Safe and Normal modes. Same problem each time.Note that I had to use the F8 option, because when I launched msconfig, it didn't present me with a boot.ini tab?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But was your cable to the internet unplugged?

    Follow the bold print instructions in my last message.
     
  5. NotResponding

    NotResponding Private E-2

    I removed my wireless card, so I guess that's the same as removing the internet cable?

    Please see HJT log attached.

    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see no signs of the online scanners being run from the READ & RUN ME. Did you skip them? If so, was it not possible to run them due to your problems?

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [System Update4] c:\docume~1\conor\applic~1\winnet.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\Documents and Settings\conor\Application Data\winnet.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Why do you have the below service running when you are using Symantec AV.
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

    Did you have Mcafee and uninstall it? If so, it is not completely gone and we will have to fix this.
     
  7. NotResponding

    NotResponding Private E-2

    I couldn't run most of the online scanners because IE is a problem, and the only one that would run on Firefox didn't work.

    I ran the HJT fix you suggested, but I can't locate the winnet.exe file - it's not in the directory as expected, nor did it turn up on a file search?

    I ran CCleaner anyway, but it just hangs like before when I attempt a scan.


    Also, I did uninstall McAfee, and any help to fix this would be appreciated!

    Thanks
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the followup HJT log I requested while I work on a fix to remove the McAfee service.

    HJT probably deleted the winnet.exe file for you.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to McAfee SecurityCenter Update Manager (or if not found look for mcupdmgr.exe) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    McAfee SecurityCenter Update Manager

    If that does not work try entering the short name: mcupdmgr.exe

    Now exit HJT and reboot. After reboot, verify that the O23 service line no longer appears.
    Delete the below folder if it exists:
    C:\Program Files\McAfee.com
     
  10. NotResponding

    NotResponding Private E-2

    Ok, I've done the McAfee work, which seems to have worked ok.

    Please see attached new HJT log.
     

    Attached Files:

    • HJT.txt
      File size:
      10.1 KB
      Views:
      3
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, I assume you still have a problem with IE not working.

    Boot into safe mode. Does IE load and run in safe mode?
     
  12. NotResponding

    NotResponding Private E-2

    Hi and apologies for the delay. Still got problems with IE.

    I started the pc in safe mode, and IE certainly launches and I can use the address bar to locate files etc. (Obviously not internet - all disconnected!)

    However, I tried a few of the IE options and it hangs if I try to "delete files" or " clear history". I have noticed that all microsoft office apps hang too - particularly Excel and Word.

    Also, I have just noticed that the windows games have disappeared and everything in the "entertainment" folder has gone too!

    Any thoughts?

    Thanks a lot
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure that your problems are malware related but let's dig a little deeper. I see you have SpySweeper and Ewido installed. Update both of them (if possible) and then run full scans with them per the below links. Post the logs from both:

    Running Spy Sweeper...

    Running Ewido Security Suite
     
  14. NotResponding

    NotResponding Private E-2

    Ok, I've run Spysweeper and Ewido - please see attached logs.

    Thanks
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and run LSP-Fix ( NOTE: Don't do anything with the tool other than just report what you find! )

    Tell me what you see under the Keep column also tell me if there is anything under the Remove column.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds