Warning! Spyware threat detected! System error #1752

Discussion in 'Malware Help (A Specialist Will Reply)' started by cardgramm, Apr 15, 2006.

  1. cardgramm

    cardgramm Private E-2

    This is my first posting here, so I hope I'm doing this right and in the right place.

    I have followed the seven steps, to the best of my ability, and I still have the blue screen and the error that was reported by firecypher on 4-4-06.

    I ran in safe mode, unplugged from the Internet:
    1) Ccleaner
    2) Microsoft Windows malicious Software Removal Tool and got "No Malicious Software"
    3) Ran Ad-Aware SE
    4) Ran Spybot Search & Destroy & Immunized (No Teatimer)
    5) Could run Microsoft Windows Defender (so I guess I don't have SP2 downloaded--like I should)
    6) I downloaded latest Sun Java
    7) Ran Bitdefender - log attached
    8) Ran Panda Active Scan - log attached
    9) Ran HijackThis - log attached
    10) I also got the uninstall_list.txt from HijackThis

    I saw that you had firecypher run ewido, so I'm in the process of doing that, too, but it isn't ready yet.

    I hope I did this right. I don't know why my HijackThis log has an X on it. Hijack This is in my Program files in MyComputer, but it doesn't show up on the Program Menu.

    Thank you.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Your problem may or may not be malware.

    You totally ignored step 3 of the READ & RUN ME. You have both McAfee and Symantec antivirus applications installed. The worst combination of resource hogs you could choose. Pick the one you prefer and uninstall the other.

    Uninstall the below old version of Sun Java since you already have the new version.
    Java 2 Runtime Environment, SE v1.4.1_02

    Now use Add/Remove programs to uninstall:
    WexTech AnswerWorks

    Is your copy of Ewido the paid version or the free trial version? If it s the free trial, how long ago did you install it.

    What is this following that you installed from InterMute?
    O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe

    Is it a paid version or a free trial version or their security package?

    Now run the steps in the following link: SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal


    You need to locate all the items Bitdefender pointed out in your email Inbox and Delete Items email folders and remove them manually.


    Now attach a new HJT log and the smitfiles.txt log so we can continue
     
    Last edited: Apr 16, 2006
  3. cardgramm

    cardgramm Private E-2

    Thank you for your help.

    I plan on following all your suggestions, but a couple major things concern me.

    1) re: step 3. Until a few days ago, I thought I only had only McAfee installed. I used the uninstall for Norton. Now neither Norton nor Symantec shows up in the control panel - add & remove programs. I thought it was gone, and then the old incomplete, unrunable, unupdated Norton showed up on my program list again this morning. So I used Explore and deleted it again, and it is supposedly sitting in my Recyle bin. Is that adequate for removal? I'm waiting to dump it until I hear back.

    Now I found Live update 1.90-Symantec, last used 8-29-04. I attempted to remove it and got the message, "you still have some symantec applications registered with Live Update...." I don't know where they are. How do I get rid of this Norton/Symantec stuff?

    I was planning on deleting McAfee and using one of the free ones that are suggested in your documentation about Keeping Your Computer Clean and Secure. Is that still advisable?

    2) Uninstall the below old version of Sun Java since you already have the new version.
    Java 2 Runtime Environment, SE v1.4.1_02

    I tried this at one point yesterday and it wouldn't let me. I just attempted it again and get "The install Shield Engine (iKernel.exe) could not be launched. No such Interface supported.)

    3) WexTech AnswerWorks is removed.

    4) Is your copy of Ewido the paid version or the free trial version? If it s the free trial, how long ago did you install it.

    It's the free version and I installed it Friday. It just updated itself this am.

    4)What is this following that you installed from InterMute?
    O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe

    Is it a paid version or a free trial version or their security package?


    I'm embarrassed to admit it, but it has been on my computer since I got it a year 1/2 ago, and it pops up once a day, asking me to purchase it. I haven't and I haven't figured out how to get rid of it. I think it is compliments of HP. It is not listed in the Control Panel - add remove as InterMute or I would have deleted it 1 1/2 years ago. I just found the file for InterMute in the Program files in My Computer. Can I simply delete it?

    5) With regard to the BitDefender scan, I think I'm in the wrong place if I'm supposed to be able to read html. I don't know what is in my email Inbox, which is stored with SBCglobal.net. If you have a document somewhere that I can read to help me with this. I am pretty good at following directions.

    Nevermind, I dumped it into Front page and I printed it out. All the things found in the Outlook Inbox were on drive G: a harddrive connected to my computer that came from an old laptop that a computer guy saved after the motherboard burned up. I saved the harddrive for documents basically. With that in mind, how should I manage the stuff on drive G:?

    Since I can't access the email on G:, should I delete all of Outlook Express or does it matter?

    6) Now I'm off to run the steps in SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal.

    Again, thank you for your help and in advance for answering all my questions.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what your timing was. In the uninstall list you posted, I saw Norton and Symantec listed. I saw these:
    LiveUpdate 1.90 (Symantec Corporation)
    Norton Internet Security
    Norton Internet Security
    Symantec Script Blocking Installer

    If they are still listed, try uninstalling them again. Do LiveUpdate last? If that does not help, try using the below link and let me know what happens.

    Norton uninstall tool

    This is up to you on whether you like McAfee and pay to keep it up to date.


    2) Uninstall the below old version of Sun Java since you already have the new version.
    Java 2 Runtime Environment, SE v1.4.1_02

    I tried this at one point yesterday and it wouldn't let me. I just attempted it again and get "The install Shield Engine (iKernel.exe) could not be launched. No such Interface supported.)

    Just remember it expires in 15 days and will loose functonality and the ability to update. At that point it may be considered an unnecessary resource hog.

    Only you know what you need and don't need. Delete all stuff on drive G that you do not need. If you don't need any of the email stuff save by Outlook then delete all of it.

    We will fix the Intermute stuff later!
     
  5. cardgramm

    cardgramm Private E-2

    This has been a very interesting experience. The Warning message is gone, now and so is the blue screen ultimately, but now I have a white screen that won't let me select properties. "Not available." I thought things seemed better today, until I had all this problem with Panda ActiveScan (2.)

    I do get this error message when booting up, " Task Panel exe - E60Cmmon.dll was not found."

    1) I could not remove Norton by the automatic download. I'd click OK and find myself off the Internet, but I think I got it removed, following the 3 step instructions given if the automatic doesn't work, ie MSIFIX.bat, SymNRT.exe, SYMMSICLE...

    2) I haven't been able to complete Panda Activescan today. About 1/3 through it asks to save as a Profile, I say okay to the first choice and it says there is a fatal error. Now I have 36 spywares and about 3 hacker programs. I did save it but the only format that it allowed was documento de texto.txt, so I hope you can read Spanish. I've attached that file, and have no idea where that came from. (no hablo espanol)

    This is the error I got-- "Managed MAPI Service Catastrophic Failure. Unknown error."

    I am attempting it again. I unhooked g:, the harddrive from my old laptop and selected local drives. I did get that completed and it also saved in documento de texto.txt. The complete report on this scan pf 041706-2.

    3) I worked through the SpywareStrike, Smitfraud, etc. I will also attach my smitfiles.txt. I only have to delete one item in the list via Windows Explorer---
    C:\WINDOWS\SYSTEM32\intell321.exe

    4) Since I already worked throught the READ & RUN ME FIRST section, I didn't do it again. Should I?

    5) I was able to remove Java 2 today, which I wasn't able to do yesterday.

    Intermute seemed to float around more today, opened a couple times.



    Thanks again.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This has something to do with your ISP (Earthlink) software and is not malware. It has to do with the below startup line in your HJT log:

    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\InterMute <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    We may need to remove some Symantec items manually. I will know when I see your HJT log.
     
  7. cardgramm

    cardgramm Private E-2

    I will follow your instructions ASAP, but wondered--this is probably a very stupic question. Since I've recently terminated Earthlink service, I probably should uninstall it in the control panel, right?

    I don't think I'm careful enough about getting rid of stuff I don't need. Part of the problem is that I don't always know what I really do need.

    Just for the record are the wrestling sites as contaminated as the porn sites?

    Thank you.
     
  8. cardgramm

    cardgramm Private E-2

    I got everything done before I left for work, except delete this line

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    It was not there. As I mentioned before, I used the manual removal of Symantec items. Did I still leave some behind?

    My computer boots up very slowly compared to usual (I read somewhere that Ewido makes it run really slowly--is it time to remove it?), and the desktop background is still white, but no Warning. It is unaccessible to change properties, giving this location,
    file://C:\WINDOWS\warnhp.html not available.

    Other than being slower at times, it seems functional, but I haven't used any work applications from this computer at home.

    I have attached the latest HJT log. Thank you.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than like McAfee is the main cause for your system starting up or running slowly. It is a resource hog. However, if you did not purchase Ewido you should uninstall it because you should not run it at the same time as MS Antispyware or similar applications. But note the MS Antispyware has been replace by Windows Defender.

    Your HJT log is clean. You just have too much stuff running.

    Also yes, you should uninstall all Earthlink software if you no longer need it.

    Try running only step number 8 from the below procedure:

    SpySheriff (aka SpywareNo) Removal
     
  10. cardgramm

    cardgramm Private E-2

    Well, I've finally had a chance to do step 8 as you directed. It says it added the fixadt.reg , then I got a Microsoft Antispyware notice that said it blocked the Internet Explorer URL: but I couldn't get down the rest, something to do with google and msn. When I restarted my computer, I was still unable to make changes to my white screen.

    I tried to install Microsoft Defender (so I could uninstall Microsof antispyware), but it says I need Service Pack 2, which I thought I had, but eventently don't. Hence, part of my problems I guess.

    I have attempted to uninstall Earthlink 5 times. It asks my if I'm sure, I say yes, and absolutely nothing happens. suggestions?

    How do I limit all the stuff I'm running? I realize this is very basic, but what do I really need to have running with I start this computer, and how do I get rid of the rest of it.

    Is it important that I keep getting all those HP downloads?

    Also, could you please give me the file where I can get the information on keeping my computer clean, and running efficiently. I can't remember where I found it and I didn't print it out.

    I'm attaching another HJT log to make sure it is still clean.

    Thank you for all your help.
     
  11. cardgramm

    cardgramm Private E-2

    I forgot the HJT log. It's attached. Well, that's not working. Do I need to delect some of the earlier uploads?

    Thanks again.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you still have the installation file for MS Antispyware available on your PC? If so, I would like you to uninstall it and then reapply that registry patch. If you do not have the installation program available, just shut down MS Antispyware and then reapply the registry patch. The reboot. If you get any messages from MS Antispyware after reboot, just allow whatever changes it is complaining about to occur. We are the ones making the changes.

    Have HJT fix the below line:
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart

    Now download and install this Your Uninstaller! 2006 Use it to remove the Earthlink software.

    This is not necessarily a malware topic but which programs are you referring to? You have to be the one who knows what you use and do not use. All I can ask is what do you use. Do you need Google Desktop Search, Yahoo Pager, etc? However the below can be fixed with HijackThis because they are not needed:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\FrontPage\Office\OSA9.EXE

    What HP downloads? Do you mean the below:
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

    It's part of our finally steps! If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Apr 23, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds