What is going on--is this a virus/spyware problem, or what?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SDJ, Sep 2, 2004.

  1. SDJ

    SDJ Private E-2

    Hey, how`s it going everyone!

    I have just registered in order to try and find help for my problem[ and hopefully learn a few things along the way].

    The problem:
    I can`t run\open: IE, control panel, my network places, my

    computer/documents/music/pictures, 'search' and 'run'. I figured that it was a

    virus/spyware because after clicking each of the above mentioned icons

    [from the start-up menu] what happens is that applications

    appear only for a blink of an eye and then disappear together with all the

    items/icons from the desktop. I see only desktop theme for 2

    seconds and then all of the items/icons reappear. After I restarted the

    comp. in safe mode everything was ok. I ran antivirus[e Trust EZ] and

    antispyware[Spybot-S&D] scans [ while in safe mode] , but to no avail--the

    problem remains.

    Any ideas?

    Thanx!


    My comp. info: OS : Win Home Edition, version - 5.1.2600
    Processor: amd athlon(tm) XP 2200+
    Memory : 256 MB RAM
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete all the steps in the below READ ME FIRST thread, but where it implies optional for the online scans. Make sure you run those online scans. Also make sure you run CWShredder too.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >


    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. SDJ

    SDJ Private E-2

    Hi chaslang.

    Hmmm, well I went through the thread carefully, but I had already done most of the stuff suggested there exepct for the CCcleaner scan, which I downloaded, and HijackThis, which I also downloaded and have the logfile.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you double check that you have the same versions of all items and did you run all of them as indicated (some were to be run in safe mode)? If the answers are yes and yes, post your HJT log as an attachment (after reading below). Otherwise complete the steps as indicate and if still having a problem, post the HJT log now.

    Please also run the TrendMicro online scan indicated in the READ ME FIRST link (you can skip the PandaSoftware online scan). Select Auto Clean!

    Before creating your HJT log and posting it, you should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File > Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  5. SDJ

    SDJ Private E-2

    It seems that I don`t know how to upload it. :rolleyes: I can save it either in rtf. format, or as it is with a .log extension, but I can`t upload either of those...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Save the log to a .txt file or rename the one you already save from hijackthis.log to hijackthis.txt and then upload it using Manage Attachments.

    So you are saying you ran everything. Right?
     
  7. SDJ

    SDJ Private E-2

    Damn, I just don`t know how to save it to a .txt file; it always comes out as a rtf. document!

    Yes I ran everything that you said[actually I did it a lot of times in the last couple of days: I have been scaning it with updated versions of antivirus and antispyware software while in safe mode. Today I added scanes with Pandasoftware and CCcleaner. Panda actually found 25 viruses[I was really surprised because I thought that constantly updated EZ AV was doing a good job] and cleaned it from the computer, but after I restarted the comp. I still couldn`t open IE, control panel, my network places, my computer/documents/music/pictures, 'search' and 'run'.
     
  8. SDJ

    SDJ Private E-2


    ////
     
  9. kis_c

    kis_c Private E-2

    The problem with IE may not be a spyware/virus problem. I had the same problem and ended up reinstalling IE and then Service Pack 1 before installing Mcafee's Internet Security. Once I did that it cleared up. I had orginally installed Mcafee's and then Service Pack 1 and nothing that used IE would work.

    However, I need to post a different issue. After installing Service Pack 1 to IE I ended up with an authentication problem that is described in one of Microsoft's KB articles. Now I can't authenticate on secured sites like banks and MS netpassport. Go figure. :rolleyes:
     
  10. Just Playin

    Just Playin MajorGeek

    Right-click on the Hijack This log and select rename then enter "hijackthis.txt"-without the quotes.
     
  11. SDJ

    SDJ Private E-2

    That`s what I did the first time but what comes up after I click 'upload' is hijackthis.txt.log...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Guys!!! It is real easy to do when you are saving the log within HijackThis.
    After scanning, you click Save Log. When the window comes up, click on the box that is labeled "Save as type:" and change the select to "All files (*.*) then go up to the box labeled "File name:" and change the file name from hijackthis.log to hijackthis.txt.

    A .rtf cannot be changed into a .txt file. The name can be changed, but the contents will still be .rtf.

    SDJ,

    I don't think much of EZ Trust. So how do you feel about it now?
     
  13. SDJ

    SDJ Private E-2


    ok...Well, I have it becuse it comes with the internet service that I have...

    I ran HijackThis again[in safe mode] and saved and renamed another logfile...

    So here you go...thanx.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not pay attention to the READ ME FIRST and HJT Tutorial. You are using an old version of HJT. Get the proper version from those links (ver 1.98.2). Also do not install it to your Desktop. Re-read my first message. Last do not run it in safe mode right now. I need to see a HijackThis log after a normal boot. All I could see thus far is this:

    1) You need to uninstall Kazaa (it is a bad thing to have) unless you enjoy having spyware, viruses, and trojans infiltrate your system.

    2) These need to be fixed:
    O2 - BHO: Tubby - {9EAC0102-5E61-2312-BC2D-4D54434D5443} - C:\WINDOWS\System32\MTC.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    3) C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    Do you use AOL? If so you should upgrade to newer version. See this http://www.answersthatwork.com/Tasklist_pages/tasklist_a.htm and scroll down to ACSD.EXE.
     
  15. SDJ

    SDJ Private E-2

    Ok, I downloaded the ver 1.98.2 and put it in a folder of it`s own[instead of the desktop], but I couldn`t open it after a normal boot[just like IE and other stuff], so I had to ran it in a safe mode.

    I stoped using AOL (9.0) 9-10 months ago.

    Should I copy HJT to the desktop?
     

    Attached Files:

  16. SDJ

    SDJ Private E-2

    It seems that the problem is solved. Yesterday I fixed the things you mentioned HJT found that could present harm, but I still had the problem. Today I ran HJT again in safe mode and saw that 'O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)' was still in the comp., so I fixed it again and after a restart, the problem was gone. However, today, HJT`s logfile wouldn`t register 'running processes' on the beginning of the log; instead it was starting with R1`s. That means that I still didn`t get rid of that AOL thing [C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe]. I typed it in 'search' but I couldn`t delete it from there. Any thoughts?

    Once again, thanx for your help!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis only shows items starting at the R1 entries until you save the log. When you save the log you will get the running processes.

    You said you stop using AOL. Did you uninstall it? If not, uninstall it. If you already did uninstall it then the lines I show will have to be fixed with HJT.

    Make sure you have enabled viewing of hidden files & folders:
    http://forums.majorgeeks.com/showthread.php?t=37650

    You still have not fixed one of the items I gave you last time. So here is that line again and some additional items to fix with HJT (DO NOT CLICK FIX UNTIL YOU HAVE EXITED ALL BROWSER SESSIONS):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.scanthenet.com/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://ie.search.psn.cn/
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: Tubby - {9EAC0102-5E61-2312-BC2D-4D54434D5443} - C:\WINDOWS\System32\MTC.dll
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: Read Me.lnk = C:\Program Files\Opera7\Readme.txt
    O4 - Global Startup: Software License Agreement.lnk = C:\Program Files\Opera7\License.txt
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} - http://www.stop-sign.com/pub/download/scandl_cnry.cab
    O19 - User stylesheet: (file missing)

    Then reboot in safe mode and delete:
    C:\WINDOWS\System32\MTC.dll
    C:\Program Files\America Online 9.0 <---- the whole directory (unless uninstall took care of it)
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe (unless uninstall took care of it)

    Now reboot normal & run HJT and post a new HJT log attachment.

    Questions:
    1) Do you really want to keep Kazaa?
    2) Do you use ICQ?
     
  18. SDJ

    SDJ Private E-2

    I unisnstalled AOL, and HJT doesn`t seem to detect these:

    C:\WINDOWS\System32\MTC.dll
    C:\Program Files\America Online 9.0 <---- the whole directory
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe

    However, I can find bunch of AOL components still in the computer. In the registry, under HKEY_CLASSES_ROOT there are a lot of files that start with
    AOL, for example:

    -AOL.MimeController
    -AOL.Instant Messenger.Config.File
    -AOL_Publish.AOL_Publish
    -AolCalSvr.ACApptTypeCombo

    and others. Is it safe to delete those?

    " Questions:
    1) Do you really want to keep Kazaa?
    2) Do you use ICQ? "

    I don`t use those programs a lot. ICQ was on the comp. when I bought it[I beleive I opened it twice alltogether], and I`ll probably take your advice and ininstall Kazaa--I stoped using it some time ago. How big a threat is ICQ?

    Here is the log...
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Other then Kazaa your log looks pretty good. ICQ is not really a problem but if you do not use it, I would uninstall it.

    There are a couple of lines from BroadJump too that I would like to see removed but you may need them for your SBC DSL connection along with connecting to Yahoo. I'm not really sure.

    I would not edit that remaining AOL stuff from your registry. It is not necessary right now. If you decide to do that in the future, backup your registry first.
     
  20. SDJ

    SDJ Private E-2

    I`ll take your advice.

    thank you chaslang, keep up the good work... ;)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     
  22. qwallis

    qwallis Private E-2

    Hello All,
    I had exactly the same problem (no explorer, my computer, control panel and i-explorer etc) and struggled with it. Tried all the usual stuff and more, get to internet options, (you will have to take a round about route to get there), then the programs tab, click manage Add-ons and disable the ones using MTC.dll
    That sorted it all out. Computers now running sweet, clean and I can sleep again.

    Hope that helps. :)
     
  23. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I would like to see your Hijack This log, I would place money you still have some problems if that was all you did without any spyware or virus scanning. Start a new thread if you want attention to me with your Hijack This log file..
     
  24. qwallis

    qwallis Private E-2

    I haven't run (don't have) Hijack this. But I am fairly sure that I was clean before I disabled and deleted the unsigned "browser helper element" and "toolbar" which were using the MTC.dll
    I had run Adware, Spy sweeper, Virus removal tools and Virus scans (all current and updated, which did find and remove various elements), had then run sfc /scannow trying to replace any damaged / lost files, and had fully updated (SP2 etc). None of which helped with the explorer problem, which was exactly as described at the start of this thread.

    I found this forum while looking for info on MTC.dll (of which there isn't much). So just thought I'd post with what I did as a relevant suggestion, as it worked for me when I was having exactly the same issue. Think the unwanted browser elements didn't install properly (after all they defeated their own objective) and just left the PC slightly f**ked up

    So now the PC is running Ok and I can sleep.
    Cheers.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds