Unsure of instructions/can't download programs

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimmys, Dec 22, 2006.

  1. jimmys

    jimmys Private E-2

    I have XP sp2 media center version 2002. I'm using Norton Systemworks 2005, plus the other assorted junk that comes from Micro Soft.The windows firewall is disabled. I have an AMD athlon 64 3500+ processor.I also have GHOST SURF PLATINUM 2006 which is currently disabled. this program is however the only spyware sweeper to find ELITE BAR on my system. I ran several on-line sweeps, SPY SWEEPER & SPYWARE DOCTOR. I now show Clear Search and Aurora on the computer!

    I printed all the instructions in READ & RUN ME FIRST, downloaded all the programs,set them up per the instructions,and started to clean.

    I ran the first one, Ccleaner and it deleted ALL the stuff I'd downloaded!! I thought that the default setting referred to in the instructions were the way it came.I must be wrong. Now when I try to download GETRUNKEY and SHOWNEW I only get a 220 something MB file when it should be 60 something + KB. All of the files were in C:/Windows/Temp/temprec. I've used this location before and never had a problem.

    How can I get the files I need to redo this to download? One other thing, I used FireFox this morning to download everything but switched to IE7 later since it is needed to run the later on-line sweeps.

    Do I need to uncheck everything but the temp. files in IE? which files from the other categories should be selected, Windows Explorer and System? Anything else I need to do, please let me know.
     
    Last edited: Dec 22, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    NOTHING that you need should ever be downloaded into any kind of Temp folder. We even mention this in the READ & RUN ME. Temp folders are constant hiding places for all kinds of malware. In addition ALL standard cleaning process will empty Temp folders. The word Temp implies that you don't need it.

    I'm not sure what you are saying about GetRunKey and ShowNew. They are tiny files. Download them again to the location indicated in the READ ME and also extract them to a folder name as indicated and you should not have any problems. I repeat, DO NOT use a Temp folder for anything you want to keep especially while running malware cleaning procedures. Otherwise it will be deleted.


    Everything in Ccleaner should be kept at the defaults.
     
  3. jimmys

    jimmys Private E-2

    Thanks, about getting the files, GETRUNKEY AND SHOWNEW, both show they are 60+ KB files when you get to their download page but I'm only showing 220 something MB when the download completes? Just wondering whazzup!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean! Did you mean to say "only" 220 MB? (leave out the something it is not needed and just makes things more confusing). 220 MB is about is huge and it is not the GetRunKey.zip or ShowNew.zip files that you are looking at. If you download GetRunKey.zip right now to a new folder (use C:\MGtools ), tell me three things:

    1. How long did it take to download?
    2. What is the size of the GetRunKey.zip file in bytes! (It should be 68,257 bytes)
    3. When you double click on the zip file, what do you see in your zip extraction program that runs.
     
  5. jimmys

    jimmys Private E-2

    what I meant was there was a difference in the size that showed on the download page and the size that showed in my download folder. It's not important now since I got the files and they seemed to run fine.

    I'm still having a problem with IE. No matter what I do, my home page is redirected to HTTP://runonce.msn.com/runonce2.aspx and this is not the URL that shows when IE first opens! That is a MICROSOFT.COM link.My home page should be "GOOGLE.COM"

    I also get an error message that says an app. failed because wtsapi32.dll could not be found. This is the location that "spycatcher" says has the "ELITEBAR" spyware in it.SpyCatcher is part of GHOST SURF from TENEBRIL. I've marked this for removal by spycatcher but I can't tell if it's being cleaned or not.It still shows in the found log in SC.

    Anyway, here are the log files that I can find.I'm still looking for the others.
     

    Attached Files:

  6. jimmys

    jimmys Private E-2

    Here is the COUNTERSPY log, I just found it again!

    I ran the READ AND RUN ME FIRST instructions. I can't find the PANDA ACTIVESCAN file. Would it be helpful to rerun the scan?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already attached the Panda log. Howver, you still need to attach logs from BitDefender and HijackThis (make sure the directions in step 7 are followed).


    Below is a general comment and somethings for you to do.

    The Program Files folder is not a good or recommended pace to store installation or other EXE files like you are doing below:
    Code:
    "C:\Program Files\"
    3600_e~1.exe  Nov  8 2006    17131232  "3600_enu_win2k_xp.exe"
    firefo~1.exe  Nov  5 2006     5900416  "Firefox Setup 2.0.exe"
    instal~1.exe  Nov 17 2006     1410680  "install_flash_player.exe"
    leechg~1.exe  Dec  9 2006     2617864  "LeechGet_201650.exe"
    leechg~2.exe  Dec  9 2006      729664  "leechget_browser_plug-in_2004_1.10.exe"
    mspt32.zip    Nov 14 2006      405964  "mspt32.zip"
    shockw~1.exe  Nov 17 2006     2599088  "Shockwave_Installer_Slim.exe"
    wrar361.exe   Nov  9 2006     1035090  "wrar361.exe"
    If you want to keep these, it is highly recommended you save them someplace else. Malware likes to try and hide here and you are making it easier for them to do so. The Program Files folder should only be a location containing subfolders that contained the installed versions of programs not the installers or anything else.

    Are your copies of Spyware Doctor and Spy Sweeper paid versions or free trial versions?

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0

    The below registry patch that Halo sent to me, should help with your redirect to MSN.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  8. jimmys

    jimmys Private E-2

    I thought I sent the HJT last night. Here it is. I can't find the BitDefender log. I thought I put it in the file with the other reports.

    SPYWARE DOCTOR is a trial version. SPY SWEEPER is paid but expired. I thought I was having conflicts with GHOST SURF so I let SPY SWEEPER lapse.

    Can't get the patch for the reg. to merge, error message;
    "CANNOT IMPORT C:\DOCUMENTS & SETTINGS\HP_ADMINISTRATOR\DESKTOP\fixME.reg. THE SPECIFIED FILE IS NOT A REGISTRY SCRIPT. YOU CAN ONLY IMPORT BINARY FILES FROM WITHIN THE REGISTRY EDITOR."

    I put the "exe" files in the programs folder because I thought they were program files. Do I even need to keep them? The less junk I have on the HD the better, I think.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Spyware Doctor trial! Also uninstall the Counter Spy trial that was installed while running the READ ME. You should consider resubscribing to Spy Sweeper. You need a realtime blocking tool like it. You should consider reinstalling it and using it. Even an out of date version is better than no blocking tool at all.

    This means you did not follow the instructions on how to save the file. Following them exactly.

    That are not program files. They are what you downloaded. They are the files that you install the programs from. Once installed you don't need them unless you are worried about having to reinstall them. In most cases it is easy enough to download again if ever needed. Unless your internet connection is slow or the downloads are very large. Either way, they should never be put in C:\Program Files to begin with. Suggestion: Create a C:\Downloads folder and save your downloads there. Even create subfolders within the C:\Downloads folder to categorize or to give the folder a name so you know what the file is for. For example: Wouldn't a folder named like C:\Downloads\MasterSplitter 4.li be easier for you to recognize a few months from now than what mspt32.zip is?
     
  10. jimmys

    jimmys Private E-2

    I'm ok on the uninstalling some items. As for SPYSWEEPER I think I'm going to try to get GHOST SURF to run right, the SPYCATCHER PROTECTOR seems to be a better program.

    I retried the regedit, this time I included the REGEDIT4 at the top of the text and it worked.

    I've rerun Bitdefender and the log is attached.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SpyCatcher has never been near as good as Spy Sweeper! If they have some how made leaps and bounds recently, that would be great but I tend to doubt you can believe much of what they write. Too many people have come here with all kinds of infections and had SpyCatcher installed before hand.

    So what was the result? Did it fix your problem? (Note this was actually not even a malware problem?)

    At this point, I'm wondering why you are posting in this forum. You have no malware.
     
  12. jimmys

    jimmys Private E-2

    Thanks, I posted because SpyCatcher was constantly hitting me with a popup saying it had stopped "ELITEBAR" from from running and I was getting intermittent "busy" signal from my curser. I assumed this meant something was running and I could not find out what. If nothing is showing up in the scans I appreciate the help and info from your site.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. jimmys

    jimmys Private E-2

    this one is, GOOGLE opens fine in IE. I'll have to reinstall GHOST SURF and see if SPY CATCHER shows anything.

    What forum would I use for questions about GHOST SURF? I thought it was the ELITEBAR blocking it from running properly, but if there's no malware something else is wrong and getting help from tech. support is next to impossible.

    Anyway, thanks for the help and advise.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Software Forum!

    Did you buy it? If not, don't expect support. If you did and they do not help, return it and get your money back because you don't want a tool that does not provide adequate tech support.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds