trying to get rid of derbiz.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by inneedofhelk, May 8, 2005.

  1. inneedofhelk

    inneedofhelk Private E-2

    Please i have tryed all that is asked and no luck !!!!
    Even my task manager has been somehow disabled by administrator

    HELP HELP HELP
     
  2. inneedofhelk

    inneedofhelk Private E-2

    Please i have tryed all that is asked and no luck !!!!
    Even my task manager has been somehow disabled by administrator

    HELP HELP HELP
     

    Attached Files:

  3. inneedofhelk

    inneedofhelk Private E-2

    ok tryed all but format my hard drive !!!!
    please help, this is a new log after all
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the future, please do not post HJT logs unless they are requested. Read the Announcement!

    We first need to remove the below service:
    O23 - Service: distributed.net client (dnetc) - Unknown owner - C:\WINDOWS\system32\iosdt\iosdt.exe (file missing)

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to distributed.net client (dnetc) ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":
    distributed.net client (dnetc)

    Now exit HijackThis.

    Are you booting to the below offline page on purpose:
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
    If not, add it to the list of items to fix below with HJT.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://community.derbiz.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteykc32.exe
    O4 - HKLM\..\Run: [ASDPLUGIN] C:\WINDOWS\system32\uk_nm.exe -N
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/DownloadAccess/ie/bridge-c283.cab
    O23 - Service: distributed.net client (dnetc) - Unknown owner - C:\WINDOWS\system32\iosdt\iosdt.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\uk_nm.exe
    C:\windows\system32\eliteykc32.exe <--- also delete any other files that begin with elite and end with .exe. There could be a bunch of them.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. inneedofhelk

    inneedofhelk Private E-2

    ok tryed what you asked and here is the new log I hope all is well ,but i think its the same and while im typing this the biz come up
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remember to exit browsers ( C:\Program Files\Internet Explorer\IEXPLORE.EXE
    ) before using HJT. If you do not, do this if can be impossible to fix problems.

    You forgot to answer my question:

    Also, you did not get the below item fixed:
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteykc32.exe

    Repeat the steps again and make sure you look for ALL files beginning with elite and ending with exe and delete them.

    You also now have an Elite Toolbar problem. Please run this: EliteToolbar Remover

    Now reboot and then post a new HJT log and let me know how things look.
     
  7. inneedofhelk

    inneedofhelk Private E-2

    ok ive done it again and that offline page is something that came with the pc when i bought it?its packard bell offline blank page just one small logo !!

    ok i do close all explorers but i cant use task manager to make sure its not running because some how its been disabled by administrator ,im hoping the biz cause that and it comes back or im sitting with another problem
    ok here is the new log must it in safe mode or normal i sent both

    THanks for all the help so far and im sure you will beat this derbiz thing
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     
  9. inneedofhelk

    inneedofhelk Private E-2

    ok great its been about three hours online now and no biz so it worked thanks.BUT still got no task manager got any help there??
    ctrl - alt - del or right click on the taskbar everbody i know (and me used to get ) task manager but now its saying disable by administrator
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log showed it running! Take a look for yourself.

    Who is the Administrator of the PC?

    Do regedit and msconfig run?
     
  11. inneedofhelk

    inneedofhelk Private E-2

    I see it how to get rid of it,is it wrong sorry not to sure i see it in the log but cant find it in the tick window
    Im the administrator what must i do with regedit and where is the other sorry just stupid
     
  12. inneedofhelk

    inneedofhelk Private E-2

    I mean get rid of the explorer.exe
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you save a log in HJT, you will see c:\windows\system32\taskmgr.exe in your process list. You can even look in the previous log you posted and see it. Also HJT has its own Process Manager where you can see the process list without saving a log.

    I just wanted you to try running regedit (do not do anything with it). I just want to see if it runs. The same goes for msconfig.

    To run regedit or msconfig: click Start, Run, and enter regedit or msconfig and then click OK. If they run, that is all I wanted to know.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are talking about. Why would you want to get rid of explorer.exe? It's you system shell. You need it.
     
  15. inneedofhelk

    inneedofhelk Private E-2

    Originally Posted By chaslang by the way you still had C:\Program Files\Internet Explorer\IEXPLORE.EXE running.Thats what i meant you asked me about it?
    did run regedit and msconfig both work
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I did but your last message said explorer.exe. They are not the same files.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter secpol.msc and click OK.

    Now in the left column look for Software Restriction Policies. Work your way thru the subfolders there and see if there are any restrictions on running taskmgr.exe.
     
  18. inneedofhelk

    inneedofhelk Private E-2

    SORRY type o ,tryed the secpol.msc windows cant find the file

    About the administrator well im the only one to use the pc,loging in to safe mode and i got the choice of me or the administrator
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So if you logon as administrator can you bring up Task Manager?
     
  20. inneedofhelk

    inneedofhelk Private E-2

    yes in safe mode it works
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you tried running secpol.msc where you in safe mode or normal boot mode and who were you logged in as? This file should be readily available.

    You should be able to find it at c:\windows\system32\secpol.msc

    Try locating it and double clicking on it from Windows Explorer.
     
  22. inneedofhelk

    inneedofhelk Private E-2

    Im in normal mode loged in as me tryed to change to administrator in normal but cant!
    looked for the file c:\windows\system32\secpol.msc not there found a taskman.exe and a taskmgr.exe
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you enabled viewing of hidden and system files per the read me? Check again that the below are set correctly:

    Right Click Start.
    Select Explorer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.

    Try double clicking on taskmgr.exe. Does it run?
    Are you saying that you (when logged in as you) do not have administrator priviledges?
     
  24. inneedofhelk

    inneedofhelk Private E-2

    taskmgr.exe says its been disabled by administrator
    Not sure if i have administrator priviledges just know there are two profiles
    One the administrator and then me in safe mode
    Normal mode dont have the administrator choice
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you check the settings I asked you to check?

    Login as Administrator. Bring up Control Panel and aelect User Accounts.
    Now select Change an account. Select your user name account.
    Now select Change my account type. Make sure you are a Computer administrator. If not, change it and then click Change Account Type.

    Now reboot and login as you and see what happens.
     
  26. inneedofhelk

    inneedofhelk Private E-2

    im Login as Administrator and in safe mode we both are administrator
    Did check the settings and all are right,ive got all administrator rights
    About the iexplorer.exe how can i get rid of it?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not want to get rid of iexplore.exe. It is your browser (Internet Explorer). You just do not want it running when you use HijackThis. For example, the message you are reading right now is in an Internet Explorer session. If you run HijackThis and save a log or run the Process Manager in HijackThis's Misc Tools you can see iexplore.exe running. It will show as :
    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    or a similar shortened named may show. One process per browser window will show. If you close this current browser window and any others you have opened, none of them should be showing as running.

    Let's get back to Task Manager. If you make a copy of the c:\windows\system32\taskmgr.exe file in your c:\ folder and then rename it mytm.exe, does it run okay.

    Also look in c:\windows\system32 and sort the folder by Type and look for all files ending in .msc Tell me what you find. You may have to first click View and select Details and then you may have to right click on the bar that shows the columns with Name, Size, Date Created, etc and then enable Type.
     
    Last edited: May 11, 2005
  28. inneedofhelk

    inneedofhelk Private E-2

    ok the taskmanager rename didnt work same,ok the msc file here we go
    certmgr.msc, ciadv.msc, compmgmt.msc, devmgmt.msc, dfrg.msc, diskmgmt.msc, eventvwr.msc, fsmgmt.msc, lusrmgr.msc, ntmsmgr.msc, ntmsoprp.msc, perfmon.msc, servises.msc, wmimgmt.msc
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Seems like 3 .MSC files are missing.
    GPEDIT.MSC
    RSOP.MSC
    SECPOL.MSC

    Are you running XP Home or Pro? I'm not sure if there is supposed to be a difference with which files should be there but I have the above three on all my XP Pro systems.

    Do you have an i386 folder on your PC? Like c:\i386 or c:\window\i386
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below!


    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixtm.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixstm.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.

     
    Last edited: May 11, 2005
  31. inneedofhelk

    inneedofhelk Private E-2

    Thanks alot that worked
    I got it all back THANKS
    Ok now how can i make more virtual memory i use the windows def settings
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    You should discuss your virtual memory question in the Software Forum.
     
  33. ugly bob

    ugly bob Private E-2

    Hey, I'm having similar problems to everyone with derbiz, I have downloaded a whole load of spyware stuff (MS, Spyblaster, Spybot....etc) it still keeps coming back. here is my hijack this thing, can some one browse it for me?
    Thanks a lot

    Ugly bob
     
    Last edited by a moderator: May 18, 2005
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post in your own thread and read the announcement and follow the sticky thread procedures first. Do not post HJT logs unless requested.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds