troubles plus download trojan...

Discussion in 'Malware Help (A Specialist Will Reply)' started by mae_west, Jan 22, 2005.

  1. mae_west

    mae_west Private E-2

    I am having a hard time accessing the spyware specific posts as I keep getting the "operation aborted" error message, so here I am posting my own problems and hoping someone can tell me sumptin' good...

    I did all the stuff in the "tutorial":

    1)I disabled system restore
    2)I could not do the scans from trends and symantec in safe mode because the option for network support was not available, so I did them in normal and then went to safe mode for
    3) Stinger (got a Kernel32 error message after I shut it down), c- cleaner (after I finished cleaning I had a look around and my computer froze up while I was at the uninstall programs place); ad-aware and the plug-in- but when I clicked on the plug-in and tried to run it it did nothing. I ran the scan anyway- if the plug-in was highlighted, does that mean that ad-aware was using it during scanning?
    4)also spybot (+), shredder and kill2.

    Now I am back in normal mode.

    The symantec scan said "c:\Program Files\ddm\ddm.d.exe is infected with download trojan". I know it is low risk, but should I make it go away? And how would I do that?
    ***I need free programs.

    all other scans were okay, in that there were no infected files or other viruses found. Download trojan was not found anywhere but symantec.

    I am now getting those operation aborted messages and do not know what to do with the trojan (are they related in some way? is download t. the reason I have been having so many error messages?) I also get alot of error messages regarding a missing notepad.exe file, which I probably deleted somewhere along the line. Can I get another one?

    I am going to put my system restore back on, because I have to get up early for work tomorrow and cannot do anymore on the computer for today. I started scanning this afternoon after lunch. If I have to do all the scans again, I will wait for wednesday which is my day off and I can spend all day fiddling with the computer (and learning, yes- learning).

    I would really enjoy hearing from anyone who can tell me what is going on in my computer. I am trying to learn, but it is slow. This is an excellent site, and I wish I had stumbled on to it sooner. You people should congratulate yourselves for how you are helping people. Thank you for your hard work.

    Mae

    PS I initially did all this clean up because I have that Websavingsfromebates thing in my add/remove programs file and cannot get rid of it, as well as cleandisk 2000 (which I am sure I uninstalled long ago). I also had the wild tangent crap in my settings folder from downloading those free games from McDonalds last monopoly promo (live and spend all day learning how to not live like that again!)
    I also just switched back from (Telus) Freedom Anti-virus (zero knowledge product) because the upgrade did not like me using zone alarm and ad-aware- I think they wanted me to buy their products (tsk tsk- they went bye bye instead).
    I am back on AVG and Zonealarm, plus all my new friends I downloaded today.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are only supposed to use CCleaner to clean files by just clicking the Run Cleaner part. Nothing else. No one said anything about uninstalling anything. Only click that one button and nothing else.

    Some hijackers are known to delete certain system files. You can get notepad here:

    Do not put system restore back on unles your problems are fixed. It would just be a waste of time.

    From what I know of Zero Knowledge, their name says it all. You are much better off with AVG

    You should do the below:


    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. mae_west

    mae_west Private E-2

    thank you for your time.

    I did not try to uninstall from c cleaner, I was just looking around when it froze. I wanted to see if websavingsfromebates was still listed (it is).

    I read about the hijackthis, but I am afraid it is a bit over my head. I need a day to figure out what to do, because allthough it seems like plain language, I have never dealt with these things and it seems quite complicated.

    I will attach the log file asap.
    Mae
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to do anything fancy with it! That's why I'm here. Just following my directions here on downloading it and putting it in the proper directory. Shut down browsers and get a log. Then upload the log.

    By the way I just added a new message you may have missed with the link to get a copy of the notepad file you need (I forgot to added it previously). See below.
     
  6. mae_west

    mae_west Private E-2

    Hi!

    Before I actually upload the log, can you tell me if this is a proper file to have it in? I am putting all my spyware programs etc into one file on my desktop so they are easy to find. Is it okay to put the log file in there as well?
    C:\WINDOWS\Desktop\pc protection\hijackthis.log

    I don't want to screw this up.

    I also disabled system restore and re-ran all the scans this afternoon, so everything is up to date. I took a quick look at the log file (but no touchy!) and it looks like there is a lot of crap in there- something to do with coupons.
    anyway, I will check back and then upload if it is okay.

    Mae
    PS I downloaded a copy of notepad.exe, but when I click on it is says it can run because of an error in notepad.exe - or something like that. I must have done something really wrong.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not a good idea. And there are files and there are folders (aka. directories). hijackthis.log is a file. pc protection is a folder which is a subfolder of Desktop etc.

    It is a better idea to store executable programs where they are installed by their installation programs if they have one. Otherwise, if they have no installer program, put them in for example like I said for HijackThis:

    C:\Program Files\HJT or C:\Program Files\HijackThis

    Yes you could do this:
    C:\Program Files\pc protection\HJT
    C:\Program Files\pc protection\about:Buster
    C:\Program Files\pc protection\HSremove

    Now if you want to be able to run any of these quickly from your Desktop you can make a shortcut to them on your Desktop (but they still really run from the place they are stored).

    The copy of notepad you downloaded was in a ZIP file. Did you unzip it and copy it to the proper folder for your OS? Directions are at the link I gave you.
     
  8. mae_west

    mae_west Private E-2

    Howdy,

    My hijackthis.exe is saved at C:\Program Files\HJT. I won't bother with a shortcut to the desktop for now.

    My log file is saved at C:\WINDOWS\Desktop\pc protection\hijackthis.log. Can I upload from there?

    New notepad is now working fine- thank you.

    Mae
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why don't you save a new HJT log file to the directory HJT is now running from and post that one. Delete the old one.
     
  10. mae_west

    mae_west Private E-2

    Hi,

    Okay, lets see what's what...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using the PC Doctor demo, look for an uninstall in Add/Remove programs and uninstall it.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX (file missing)
    O2 - BHO: DNSProxyObj Class - {FF4E2C50-BCF3-47cf-952A-A512F5B5D0E8} - C:\WINDOWS\SYSTEM32\DNSPROXY.DLL

    Do you use this CouponBar tool bar? If not, fix this next line too.
    O3 - Toolbar: Coupons - {FB986A68-EAE4-11D4-9BD1-0080C6F60B6A} - C:\WINDOWS\COUPONBAR.DLL


    O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
    O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm
    O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {340FBD92-B7BB-11D2-8299-00104B27F81B} (ScanCtl Class) - http://outpost.zdnet.com/updates/resources/updates.cab
    O16 - DPF: {1D8A63E5-F219-11D4-9BD1-000039051213} (CouponTBInst Control) - http://ftp.coupons.com/code/CouponBar.cab
    O16 - DPF: {C3EF17D6-2201-11D4-9F0E-00B0D011B1AE} (Communities.com Passport) - http://cartoonorbit.cartoonnetwork.com/orbiter11002/ie/orbiter.cab
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
    O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.150/13d13dfc95afcc402e23/netzip/RdxIE.cab
    O16 - DPF: {A28DAC07-0D34-4A90-A0E6-CEE27208C86D} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.cab
    O16 - DPF: {E2CF5C45-7CCC-11D4-9BD1-0080C6F60B6A} (CouponsComBrxpdf2 Control) - http://ftp.coupons.com/brxpdf2.cab
    O16 - DPF: {E389B374-BB5A-4A73-ACF4-3CE63E4C1DE9} (Brxpdf5 Control) - http://ftp.coupons.com/brxpdf5.cab
    O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/3112/ftp.coupons.com/r3112/brix6ie.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1437a6f2c97c62582f01/netzip/RdxIE601.cab
    O16 - DPF: {412F2472-59BC-4CCB-A3D4-C16A7D57CDCF} (CouponsIncIECtl Class) - http://a19.g.akamai.net/7/19/7125/1290/ftp.coupons.com/v7/brix7ie.cab
    O16 - DPF: {330110A5-F627-4DD7-B0F1-24D09C4DA870} (CouponsIncIECtl1 Class) - http://a19.g.akamai.net/7/19/7125/1404/ftp.coupons.com/v7/cpnsie1.cab
    O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://rimmel.ai-media.com/save/makeover.cab
    O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/3113/ftp.coupons.com/r3120/cpbrxpie.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.freedom.net/viruscenter/onlineviruscheck/cabs/cssweb.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} - http://www3.ca.com/virusinfo/webscan.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://www.pcpowerscan.com/pcpowerscan.cab
    O16 - DPF: {2B4F4FA8-814A-11D7-B31B-0002A500B281} (FASetupStart Control) - http://a1776.ff.fullaudio.com.edgesuite.net/f/1776/8819/1d/software.fullaudio.com/musicnow/3.0.0.60/setup.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM32\DNSPROXY.DLL
    C:\WINDOWS\realtime.exe

    and if you fixed the CouponBar item above, delete the below file too:
    C:\WINDOWS\COUPONBAR.DLL


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. mae_west

    mae_west Private E-2

    Chas,

    I followed your instructions but could not find C:\WINDOWS\realtime.exe or C:\WINDOWS\COUPONBAR.DLL. I did not see them in the windows folder.

    Here is log #2. HJT was set to fix or delete 27 items. It looks like some are still there, so does that mean they are fixed? I NEVER use anything called coupon bar, but may have downloaded it in the early days of my surfing.

    I have been getting some "Msimn has caused an error in MSVBVM60.DLL" and "Winmgmt has caused an error in WBEMESSL.DLL" messages lately. That last one comes up twice in a row. Have not seen them since I did this new HJT fix, but will let you know if I see them again. I had to uninstall .NET Framework 1.1 and re-install the distributable(?) yesterday, and so was finally able to install the SP1 for that as well (over 20 attempts in 4 months to install that before I stumbled on the right forum!)
    I also deleted Piolet from my various folders and yet it still exists in add/remove, as does websavingsfromebates.

    Thankyou again for all of your help!!!! :)
    Mae
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something in your log is bugging me. This line:

    MSIE: Unable to get Internet Explorer version!


    What version do you have?

    You said:

    I don't understand! What is still there?
     
  14. mae_west

    mae_west Private E-2

    Hi Chas,

    I went to windows explorer>WINDOWS\VCM\IEXPLORER to get my version, as right clicking for properties had no info. It is v.6.0.2800.1106- which is the current is it not? I saw that line too, but I will leave the deciphering of the log to the pros.

    I saw that coupons.com (O16 - DPF: {1D8A63E5-F219-11D4-9BD1-000039051213} (CouponTBInst Control) - http: //ftp.coupons.com/code/CouponBar.cab) is still in the HJT log, so would that mean it is "fixed" or could not be fixed because I could not find C:\WINDOWS\COUPONBAR.DLL to delete while in windows explorer (safe mode)?
    (** I put a space in after http: so that the link is not clickable)
    Mae
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is the correct version of IE but what is it doing in a folder called C:\WINDOWS\VCM\IEXPLORER

    It should normally be running from C:\Program Files\Internet Explorer

    Where did you get this PC from?

    Right click on iexplorer.exe and select Properties and then the Version tab. Get version information. There should be a bunch of info on that tab.

    Have HJT fix the other O16 line. Must have missed it the first time. Let me know if that does not work.
     
  16. mae_west

    mae_west Private E-2

    Chas,

    I can run internet explorer from program files, but there was no tab there to get version info.The info from my last post came from the properties/version tab at the VCM folder.

    My computer is a generic. I bought it about 4 1/2 years ago, at a local computer store. It has Windows Me, and came with IE v.5. ??, but I do all my updates and updating to v.6 was one of them.

    No, you did not miss that 016 line. I checked it and clicked fix for that one. It just came back.

    Mae
     
  17. mae_west

    mae_west Private E-2

    Chas,

    I re-ran the HJT and "fixed" that 016. I checked the new log and it is gone now.

    Also, when I got up this morning and checked the computer, that DLL error message was there again - the Winmgmt has caused an error in WBEMESS.DLL. When I close it, it pops up again. How can I fix these dll errors? I had a problem last year where when I clicked on a link it opened into a blank window. I had to go to the library and use their computers to find the answer and I had to fix about 10 dll files before my computer worked properly. Is this the same type of problem?

    Mae
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure about that. Sounds like you have had some kind of corruption in your OS if you had to replace some DLL files. You my get some ideas on these problems by posting a question in the Software Forum. But also understand that Win98 is rather old too, so I'm not sure what answers you will get.

    Do you get any other messages about missing DLLs and are the words you gave above the EXACT word for word message and the complete message?

    Your log was clean so there is no "visible" malware at work!
     
  19. mae_west

    mae_west Private E-2

    The two messages I get the most frequently are:

    Winmgmt has caused an error in WBEMESS.DLL. Winmgmt will now close. (this one usually pops up twice in a row). Yesterday I could not get this error message to close out after I ran the Trends Micro's free online virus scan; it just kept popping back up after I clicked the x or close. I could not shut down my computer, and gave up and shut it off ( I know, bad, bad).

    and

    Msimn has caused an error in MSVBVM60.DLL. Msimn will now close. This one has something to do with visual basic.

    Mae
     
  20. mae_west

    mae_west Private E-2

    Thank you for all of your help Chas, you have been so great! I appreciate all of the time you have spent helping me. I am so glad to have all the spyware tools now, and to know that things are clean.
    Does this mean I can turn on my system restore?
    What about websavings from ebates? Should I just ignore it?

    I have posted at the software forum about my dll probs- thanks for pointing me that way.

    Mae
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Okay so what exactly appears in Add/Remove programs that you want to remove?
    And I assume you have tried using uninstall?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds