THANKS or, my "Do what I want" key missing

Discussion in 'Malware Help (A Specialist Will Reply)' started by Deaf Smith, Apr 27, 2005.

  1. Deaf Smith

    Deaf Smith Private E-2

    After repeated botched attempts to find and use the "do what I want" key on my keyboard to fix real and/or perceived problems, I finally bit the bullet and actually followed the detailed and specific directions on "Don't post until you do this" sticky on this board.

    It wasn't fun, pretty or quick, but after several six-packs and much invective I think I have both fixed my problems and actually learned something.

    I still have a couple of persistant trojans hidden in archive files but I am now a true believer and think the answer is hidden somwhere in this forum.

    Anyway, thanks to eveyone that contributed to this effort; this site and forums are a real asset to those of us who are only minor or wannabe geeks.

    Thanks again
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Please do not make duplicate threads. I deleted the other one with similar info in it.
     
  3. Deaf Smith

    Deaf Smith Private E-2

    Maybe I spoke too soon.

    Since downloading the MS patches/fixes my maching has slowed down 30-50% online. No change offline I can see. Will the MS patches slow processing?

    When I first tried to run the online scans with the "don't post untill ....." I couldn't do the in safe mode but they apparantly worked in normal.

    After than and subsequent reboots/restarts my desktop and program bar has changed EVERY time. Sometimes a program will load and start, and somtimes not with no apparent pattern.

    I have rerun the proceedures in the "Don't ask questions until you do this"
    with no observable effect.

    Comments?? Suggestions???
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please perform the following steps:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. Deaf Smith

    Deaf Smith Private E-2

    I'm back!!

    I have run HJT as instructed. Help2Go and HJTlog identified 15 files for fixing.
    I was able to remove 13 of them. Two files in group 23 named "Service:AntiVir Service - Unknown owner" and "Service: AntiVir Update -Unknown owner" would not remove after two attempts/HJT reruns. (see attached log)

    Two files in a folder labeled RECYCLYER S-1-5-21-1214440339-1343024091-854245398-1000 AND S-1-5-21-1214440339-1343024091-854245398-1001
    were identified as trojans by TrojanHunter were not marked by HJT. They were identified as system files when I tried to delete them.

    System is faster and consistant so far after HJT. Any thoughts about the remnants?


    I made logs before and after both HJT scans: hijackthis.log and hijackthis2.log. MajorGeeks couldn't see log 2. attached is #1. Before removal. What happened?

    Thanks again for the help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really need to see your log after removal otherwise I will just be telling you to fix stuff you may have already fixed. You should be able to upload the second log. The only thing that may prevent that is if the file contents have not changed or if you used the same filename.

    Did you empty your Recycle Bin?
     
  7. Deaf Smith

    Deaf Smith Private E-2

    Attached is my latest HJT log file.

    I reran the entire process and the last time I ran CCleaner and deleted the result, the system froze completely when I tried to log onto the internet. After my peoplepc internet screen came up no mouse or crtlAltDel. I had to turn the power off to reboot. I restored the deletions and everything worked. Tried everything again with the same results. I looked at the delete list and didn't see anything I could identify with a dialer, etc. Any ideas?

    Thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What delete list? Are you talking about CCleaner? I have no idea what items it is telling you to delete without seeing them, but I have never had a problem when just using Ccleaner to delete temp files (do not use the Issues tab). What part of Ccleaner did you run?

    You appear to have multiple antivirus applications installed. You must only use one. So pick the one you wish to keep and uninstall any others.
     
    Last edited: May 2, 2005
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would also disable Spybot's Teatimer function.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [Microsoft Synchronization Manager] msn_update.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\system32\msn_update.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds