1. castamayor

    castamayor Private E-2

    I would appreciate any help I can get with this.

    I'm having a problem with getting taken to the winfixer2005 page and other random pages. I also notice that the automatic updates on Microsoft AntiSpyware are always turned off, even though I turn them on. I've scanned with the Microsoft product (the product Microsoft bought from Giant software) and with the free version of spysweeper. I've also used the online panda software scan. I've scanned for viruses with F-Prot. Nothing is found, except some cookies. I delete the cookies and after a while, the same thing occurs.

    Is it possible to pick up a cookie when browsing that hijacks the browser until the cookie is deleted?

    I looked at the hijackthis log and didn't notice anything. I used the automatic parser online and read the FAQ - all seems ok.

    I'd like to find the people who put out winfixer and punch them in the face.

    Thanks.
     
  2. castamayor

    castamayor Private E-2

    Just a followup - I see pscr.dll and can't find a use for it. I also can't delete it, even in safe mode. It's viewable in windows, but in DOS safe mode, it becomes hidden. I changed the attribute to -h but still could not delete it because it was in use. Could this be the problem?

    Thanks
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it. Automatic parsers are far from perfect. We can get this fixed up for you but first some standard cleaning make sure no other problems are hiding in your PC.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. castamayor

    castamayor Private E-2

    Thanks.

    Nothing found until I ran the Trend micro scanner in safe mode. It found the vundo trojan.

    After removing it, I see that the Microsoft AntiSpyware update function is still disabled, and now F-Prot isn't updating, although that could just be a glitch on the F-Prot server. The pscr.dll is still there.

    I've attached the logfile from hijack this.
     

    Attached Files:

  5. castamayor

    castamayor Private E-2

    Winfixer still pops up.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.


    Please print these instructions out for use in Safe Mode.

    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINNT\ServicePackFiles\i386\pscr.dll
    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINNT\ServicePackFiles\i386\rcsp.*
    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:

    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINNT\ServicePackFiles\i386\pscr.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: pscr - C:\WINNT\ServicePackFiles\i386\pscr.dll


    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Once your machine reboots please attach a new HJT log from normal mode.
     
    Last edited: Sep 15, 2005
  7. castamayor

    castamayor Private E-2

    Thanks chaslang.

    The log is posted.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! The Virtumundo problems is gone. I assume you are not having anymore popups?

    Do you know what the below is for:

    O23 - Service: Parcipsx - Unknown owner - (no file)
     
  9. castamayor

    castamayor Private E-2

    I don't. Should I use hijack this to remove it?

    I do notice that the microsoft antispyware still is not set to update automatically, even though i placed that setting back in. I scanned with it but found nothing.

    I haven't surfed enough to get a sense of popups, but I'll do so now.
     
  10. castamayor

    castamayor Private E-2

    No more popups.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if HJT can fix! It may not be able to do so if the service is really running.

    Are you saying you disabled autoupdates for MS AS and it keeps re-enabling them.
     
  12. castamayor

    castamayor Private E-2

    Just the opposite. i enable updates for MS AS and something disables them.

    I'll try HJT and post back.

     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you double click on the MS AS tray icon and do Help, About. Do you see the same as below for version and definitions?

    Microsoft AntiSpyware Version: 1.0.615
    Spyware Definition Version: 5755 (9/15/2005 10:49:58 PM)
     
  14. castamayor

    castamayor Private E-2

    I see:

    Microsoft AntiSpyware Version: 1.0.615
    This version expires on: 12/31/2005
    Spyware Definition Version: 5757

    But I updated it manually.
     
  15. castamayor

    castamayor Private E-2

    HJT doesn't remove it. I can't find that service running in the services window. Nor can I find any service running that I think could be associated with it. Tonight, I'll do an online scan in safe mode.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why MS AS keeps disabling autoupdates. Are you sure when you enable them, they are actually getting enabled?


    Download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad file as an attachment too. Call it service.txt.
     
  17. castamayor

    castamayor Private E-2

    I think it's saving the setting. It reports that it does.

    Here is the attached file. Thanks again for your help with this.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's just try the below:

    Run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Parcipsx

    Now exit HJT and reboot if it asks you to do so. Then look at a new HJT log and see if that entry is gone.
     
  19. castamayor

    castamayor Private E-2

    I tried this in normal mode and in safe mode and it couldn't be deleted either way because it is in use.

    I thought perhaps that I could take the drive out and hook it up to one of my usb adaptors and place the drive on another machine as a usb device and delete the file that way. I did a search however and could not find Parcipsx*.* on the machine, even when I set the settings to show all hidden and OS files.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file name does not necessarily have to be anything like the Service name. And it could even be getting started via another process. The key is to figure out what & where. I have no info on this service.

    If you know how to use regedit (or similar), look up the below registry keys and see if you can locate the service and any info on how it is starting:

    Services that start when your computer starts:
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

    Services that start with the svchost:
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Svchost]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Svchost]

    If you do not know how to use regedit, just let me know.

    Also do the below:

    Download the Registry Search Tool from here:

    http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    Parcipsx

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread.
     
  21. castamayor

    castamayor Private E-2

    I searched the registry and couldn't find anything named RunServices. I don't have the other paths, but do have [HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Svchost] Under that I have BITSGroup, DComLaunch, HTTPFilter, LocalService, netsvcs, PCHealth, and termsvcs.

    Here is the paste from the program:

    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "Parcipsx" 09/17/2005 10:29:40 PM

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Parcipsx]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Parcipsx\Security]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Parcipsx]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Parcipsx\Security]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parcipsx]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Parcipsx\Security]

    [HKEY_USERS\S-1-5-21-1606980848-2111687655-1801674531-500\Software\Microsoft\Internet Explorer\TypedURLs]
    "url8"="http://auto.search.msn.com/response.asp?MT=Parcipsx+service&srch=5&prov=gogl&utf8"

    [HKEY_USERS\S-1-5-21-1606980848-2111687655-1801674531-500\Software\Microsoft\Search Assistant\ACMru\5603]
    "000"="Parcipsx"

    [HKEY_USERS\S-1-5-21-1606980848-2111687655-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
    "c"="C:\\Documents and Settings\\Administrator.JK-1\\Desktop\\Parcipsx.txt"

    [HKEY_USERS\S-1-5-21-1606980848-2111687655-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt]
    "b"="C:\\Documents and Settings\\Administrator.JK-1\\Desktop\\Parcipsx.txt"
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we are going to do a registry patch to try to remove this but first I would like to have you backup your registry to be safe.

    Please download and install Erunt. Use it to create a backup of your registry. Then continue with the below.

    First a question, did you save the output from regsrch to Parcipsx.txt on your Desktop as shown in the below two lines?

    [HKEY_USERS\S-1-5-21-1606980848-2111687655-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
    "c"="C:\\Documents and Settings\\Administrator.JK-1\\Desktop\\Parcipsx.txt"

    [HKEY_USERS\S-1-5-21-1606980848-2111687655-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt]
    "b"="C:\\Documents and Settings\\Administrator.JK-1\\Desktop\\Parcipsx.txt"

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixit.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixit.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
    Then reboot into safe mode and run the below steps with HJT again (with no browsers running):

    Run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Parcipsx

    Now exit HJT and reboot (in normal mode). Then look at a new HJT log and see if that entry is gone.
     
  23. castamayor

    castamayor Private E-2

    Yes I did save the output from regsrch to Parcipsx.txt to the Desktop.

    I'll do this later today when I get home. Thanks again for helping me out.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! I'll be waiting for the results.
     
  25. castamayor

    castamayor Private E-2

    Everything went ok until I tried to delete the NT service. It was still running.

    No browsers were runing.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about this but I neglected to put a minus sign at the beginning of each registry key to indicate that it is to be deleted. I also want to change the order of the strings so I'm rewriting the directions here to avoid any confusion (notice the difference with the minus sign):

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixit.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixit.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
    Then reboot into safe mode and run the below steps with HJT again (with no browsers running):

    Run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Parcipsx

    Now exit HJT and reboot (in normal mode). Then look at a new HJT log and see if that entry is gone.
     
  27. castamayor

    castamayor Private E-2

    It's gone. After i applied the reg file, I then tried to delete the NT service through HJT. It couldn't fine Parcipsx in the registry. i rebooted, checked the log, and it was gone.

    Than you so much for this.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds