Trojan damage help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Agahnim, Sep 4, 2004.

  1. Agahnim

    Agahnim Private E-2

    I have reported before that I had a problem with when I click on My Documents, My Computer, and Internet Explorer, Internet Explorer crashes and I couldn't get on the internet or access my files but everyone that helped here gave me dead links. I found out through another source that it was two Trojans and Norton Anti-Virus got rid of the two Trojans but didn't fix the damage that was done. I need a program or something that would fix the damage that was done. Does anyone know of a free program that will help me with this. Before giving me a link this time, check it first to see if it is active and working and not "Page can not be found!".
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You made it sound like you received a lot of dead links. You only received one dead link! The actual link to Trend Micro is: http://housecall.trendmicro.com/housecall/start_corp.asp

    If there is "True" damage to your file system. Running virus or trojans scanners will not fix the problem. They can in many cases remove viruses and trojans. But if you file system is truly damaged in some form, you will have to repair it by hand. Or reinstall you system.

    My statements are only referring to what you indicated when you said the damage was done. If what you meant was that you still have other malware on your system then follow thru with our normal procedures require that you first follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    IMPORTANT: If you already have any of the programs linked in the tutorial please double check your version against our links to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. Agahnim

    Agahnim Private E-2

    I tried all the steps that applied to me except two because Step 2, I don't have Windows XP and Step 4 will just causes me crash again because I can't get on Internet Explorer or My Computer. Micro Trend doesn't work because this is what I get:

    Page Not Found
    Sorry, the web page you're looking for was not found

    www.trendmicro.com/housecall/install.asp

    A report about this error has been sent to the webmaster. The page may have been moved or removed. If you got here by typing an address into your browser's address window, please check your spelling. To continue, try entering a keyword into the search form above or find your topic in the site map below.

    I tried the free scan on Panda Software but it does the same thing also. If it works for you, then it must not work on Firefox.

    I just found my Window's 98 CD so I am gonna try reloading my damaged programs and files from that.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why didn't you use the link I gave you below in my last message for TrendMicro? It works fine.

    And the link to TrendMicro is in step 5 of the READ ME and it is the same as mine. It works fine too.
     
  5. Agahnim

    Agahnim Private E-2

    I just tried to reload from my Windows 98 disk but Explorer Crashes when I try to do it. GRRRRR!!! I hate goddamn viruses! :mad: It now looks like I will have to wait next year to get it repaired at the shop because I cannot afford it. I wish I had a job but because of damn Bush, jobs are now so hard to get now days.
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    You failed to acknowlede Chaslangs mention of a working link above and it took a couple threads before you accidentally gave us any system specs, but thats probably Bushs fault too. My final advice, if you opt to read this one is to boot into safe mode and use a free antitrojan program like A2: http://majorgeeks.com/download4281.html

    Good luck.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are you trying to reload? Are you trying to use SFC?

    Why do you keep using the wrong link for TrendMicro? The one you keep referring to is always going to give you a page not found. USE THE ONE I GAVE YOU.
     
  8. Agahnim

    Agahnim Private E-2

    I just did use the link you gave me and it starts the load, I see the program, but as it stops loading, the page changes and brings me to that wrong link I copied up. I dunno why it is doing that. Stupid thing. I am going to try it again with a different browser and see if it works on that one.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. Agahnim

    Agahnim Private E-2

    I used HijackThis before so I didn't do any fixing. Here are the log files for it:

    edit by chaslang: log changed to an attachment
     
    Last edited by a moderator: Sep 5, 2004
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not pay attention to the READ ME FIRST or HijackThis tutorial and what I just told you.

    You are running an old version of HijackThis and you did not put it in your message as an attachment!
    You need to get the correct version. And attach a new log.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is this: C:\PROGRAM FILES\CRAZY BROWSER\CRAZY BROWSER.EXE

    Well I know it is a browser, but do you use it?

    What is your expected home page?
     
  13. Agahnim

    Agahnim Private E-2

    My expected Browser is Internet Explorer but because of the problem, I use FireFox. I just downloaded Crazy Browser just to use that free online virus scanner you gave me and it worked but I didn't scan yet because I was working on other things. My homepage is www.cox.net the homepage of my ISP. All the problems started when I first downloaded this free spyware program given free to Cox Digital Cable TV and Internet subscribers.

    I did the update but I could only access the program from Find on the Start Menu since I cannot go into my Program Files the easy way. And I did read the tutorial for this program.

    When ready to link this document up, I discovered an unbridge.reg in My Documents. This is the first time I seen it there. None of my spyware and virus scanners detect it. What is it? I never loaded such a program? I got it on as a screenshot marked.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so why don't you uninstall Crazy Browser for starters.
    What is the name of the program you downloaded from cox.net? Is it still installed?
    What do you mean you did the update? What program are you talking about?
    Is WeatherBug still installed on your system?
    Do you really need all of those tools bars? Google, Yahoo, AIM, COX, seems a bit too much.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The unbridge.reg file is a file used to merge changes into your registry. I have no idea who put it there. If you rename it to unbridge.txt, you can upload it here as an attachment and I can look at it.

    I need answers to my previous questions before going to much further but here are a few things to fix with HijackThis. (No sense letting Cox advertise on your IE window. :) ) Please note: select the lines but don't click FIX until you exit all browser sessions (including the one you are reading this in):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/065451910e6b85871901/netzip/RdxIE601.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
     
    Last edited: Sep 5, 2004
  16. Agahnim

    Agahnim Private E-2

    It's name is Authentium. I uninstalled it.

    I updated Hijack This.

    I uninstalled it awhile ago but I dunno why bits and pieces of it remains.

    I only have Google. I don't see any toolbars for Yahoo, AIM, and Cox. I only wanted google, not the others.
     
  17. Agahnim

    Agahnim Private E-2

    Here's the unbridge thing. What do these unbridge programs do to your computer?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay they were not all toolbars but some were. In addition to Google you also have an AIM toolbar, a an application from COX which is still part of Authentium (a popup blocker or something), and Yahoo Messenger stuff. Do you use both Yahoo Messenger and AIM? See the lines below:


    O2 - BHO: AIM Helper - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - C:\PROGRAM FILES\AIM TOOLBAR\AIMHELPER.DLL (file missing)
    O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - C:\PROGRAM FILES\COX\APPLICATIONS\APP\AUTHBHO.DLL
    O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - C:\PROGRAM FILES\COX\APPLICATIONS\APP\AUTHBHO.DLL
    O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It has one line in it, to remove a registry entry that you do not have anyway. I have no idea were it came from. But it does not do anything on its on unless you double click on it or another program on you computer tries to use it to make changes to the registry.
     
  20. Agahnim

    Agahnim Private E-2

    Oh my god! It's fixed!!! :rolleyes: But how?! I just came back onto the computer and pressed Internet Explorer by mistake out of habit to get online and a window popped up without crashing! It could've been dozens of things I've done to try to fix it with virus scanners and the stuff you told me to do. Thanks for your help and sorry for being a pain but when stuff like this happens to me, I get stupid because I don't know what to do, I get pissed off at my computer, and I too afraid to do it by myself so I won't make the problem worse. :confused: This saves me from taking the computer to the shop. Whatever I've done, it worked but I wish I knew what was causing the problem so I can know what to do about it in the future if this happens again. Again, thanks.
     
    Last edited: Sep 6, 2004
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm happy to hear it al worked out for you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds