Trouble

Discussion in 'Malware Help (A Specialist Will Reply)' started by joejoe1987, Feb 27, 2005.

  1. joejoe1987

    joejoe1987 Private E-2

    I am currently having trouble deleting the CWS_NS3 adaware program (spy sweeper cannot delete it). I have also gone through the HSA removal process, but have failed. I am now facing msov32.exe, winpu.exe, and ipcn.exe, as well as the brew.dll virus (will not let me delete it!). Please help...I have a log file ready. Thank you!
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi JoeJoe,

    Generally, it is a good idea to start with the Cleanup Tutorial below. I realize some of the steps may be redundant, but try them anyway. (Especially the Online Scans!! - Do them in Normal Windows boot if you can't in Safe Mode!!)

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    There are only a few of us Volunteers who regularly offer advice in this forum. Running through the above Tutorial will remove a lot of stuff that would otherwise clog a HijackThis Log and save us valuable time.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99.1) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis! Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99.1

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’ve been tied up with work lately and cannot visit this forum too often these days, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  3. joejoe1987

    joejoe1987 Private E-2

    Attached is my "hidden streams" in the form of a log... i am still having problems, mainly will brew.dll....help me please! Should any of these streams be deleted? I cannot attach my log because there is an error with brew.dll
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps that PP gave you! Run the READ ME FIRST and then post a HijackThis log attachment if still needed.

    Are you saying you cannot run HijackThis VERSION 1.99.1 at all?
     
  5. joejoe1987

    joejoe1987 Private E-2

    I followed the steps, I ran the hijack this program and when i went to save a problem arose with the brew.dll file. It would not let me save the log.
     
  6. joejoe1987

    joejoe1987 Private E-2

    What should I do????
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please be clear! Did you run all the steps in the READ ME FIRST thread?

    Explain what you mean problem with the brew.dll file?
     
  8. joejoe1987

    joejoe1987 Private E-2

    I followed ALL of the steps. When the problem still existed when I rebooted in normal mode, I was going to create a log file and post it. However, when I went to save the log file a message came up saying the brew.dll was not found during loading? So, when I found the file manually, I went to delete it and it would not let me. Also, I have a downloader trojan that will not delete. Do you need to know anything else?
     
  9. joejoe1987

    joejoe1987 Private E-2

    I have all of the downloads from PP's prompt as well as spy sweeper and spy hunter and Norton antivirus 2005... they are not deleting these problems.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run any of the Alternative Scans?

    SpyHunter is not very good! Did you buy it?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there a line like the below in your HJT log:

    O21 - SSODL: OLE Module - {03B1C4D9-BC71-8916-38AD-9DEA5D213614} - C:\WINDOWS\SYSTEM\brew.dll
     
  12. joejoe1987

    joejoe1987 Private E-2

    I did buy that program-oops! and no that line is not there
     
  13. joejoe1987

    joejoe1987 Private E-2

    brew.dll is in system 32...does that help?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you boot in safe mode, can you rename brew.dll to brew.ddd ?

    I repeat:

    Did you run any of the Alternative Scans?
     
  15. joejoe1987

    joejoe1987 Private E-2

    I have not tried that...why?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because it appears to be causing you some kind of problem?

    You said you get a message when you try to save a HijackThis log mentioning this file.

    Did you run any of the Alternative Scans?
     
  17. joejoe1987

    joejoe1987 Private E-2

    I ran all of the scans in pp's prompt... other than that...no.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should try some of the Alternative Scans!

    And try: booting in safe mode and see if you can rename brew.dll to brew.ddd ?

    Then boot normal and see if you can save a HijackThis log to post.
     
  19. joejoe1987

    joejoe1987 Private E-2

    I have a conference call so I will post the log tomorrow if successful...thank you for your time!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Let me know what happens. By the way does notepad work okay on your PC? Can you run notepad on a .txt or a .log with out any problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds