Like the subject line says I was a bozo and unwittingly allowed some malware to disable my Task manager. I have followed advice here and other forums and now appear to be free of trojans, viruses , tracking cookies, etc. However , even adding the redegit command line to restore the task manager, no luck. My current HJT log is as follows:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:22:20 AM, on 04/05/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
It looks to me as if you still have some infection in there. Please let us know what type of "trojans, viruses" you have/had, and what steps you performed to clean.
I'll do my best, but if any errors were made in your cleaning, I may not be able to undo those.
Any registry editing that you do may be prevented because you are running AVG's Guard feature that monitors registry changes.
Please disable that:
Open AVG Anti-Spyware. The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right-click on AVG AS in the system tray and uncheck "Start with Windows".
Go to Start > Run and type: services.msc
Press "OK".
In Services, click the "Extended tab" and scroll down the list to find AVG Anti-Spyware Guard.
When you find the guard service, double-click on it.
In the Properties Window > General Tab that opens, click the "Stop" button.
From the drop-down menu next to "Startup Type", click on "Manual".
Now click "Apply", then "OK" and close the Services window.
Please post a fresh HijackThis log and address the following questions:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.
A list of P2P's is here:
http://www.castlecops.com/t204179-P2P_programs_we_ask_that_you_remove_first.html
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.
** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.
I look forward to your reply.
The instructions in this topic are only for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance, and you will make a cleanup of your system more difficult.
Message Edited by Bugbatter on 05-04-2008 01:29 PM
I certainly appreciate the help. The AVG version I am running is the freeware one and it has no resident shield available. The report on the AVG scan is as follows: --------------------------------------------------------- AVG Anti-Spyware - Scan Report ---------------------------------------------------------
+ Created at: 9:39:16 PM 03/05/2008
+ Scan result:
C:\Documents and Settings\Maverick\Cookies\maverick@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Maverick\Cookies\maverick@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Maverick\Cookies\maverick@msnservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Maverick\Cookies\maverick@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Maverick\Cookies\maverick@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
::Report end
However , the AVG virus scanner has a resident shield, which I will disable and try the above . I did use the microsoft website free virus scanner and it found and removed one virus, but did not tell me which . I ran Panda but the free version does not tell you which viruses or remove them. However , it did say that it identified some viruses though.
The log for the AVG scanner is clear also, though there were some trojans identified and cleaned. As for the redegit file I tried this fix.....REGEDIT4
Also , I have not posted anywhere else, just used the Dell help and Microsoft XP help. Its my computer, and I am note adverse to wiping the hard drive and starting over, though I was told that formating the hard drive and reloading doesn't really work with XP. I am not sure on that one.
I did have limewire on the computer, I took it off some time ago. I do not have any other P2p programs . I do not and have never had any cracked software.
Here is the latest log from HJT....
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:04:55 PM, on 05/05/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
Please launch Hijackthis and place a checkmark next to the following:
O4 - HKLM\..\Policies\Explorer\Run: [71NG8if1KS] C:\Documents and Settings\All Users\Application Data\lofqtohi\hilorylq.exe
Close all other windows and click "Fix Checked". Close HijackThis.
Reboot into Safemode:
Turn on the computer.
Immediately begin tapping the F8 key.
Use the arrow keys to highlight Safe Mode and press the Enter key.
Configure to show all files/folders:
Go to Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Uncheck: Hide protected operating system files
Click on Apply.
Next go to the side of the Search box and select All files and folders. Go down to More advanced options.
Be sure the first three boxes are selected:
Search System folders
Search Hidden Files and folders
Search SubFolders
Please delete the following folder if it still exists:
C:\Documents and Settings\All Users\Application Data\
lofqtohi
Rehide protected folders/files:
Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Check: Hide protected operating system files
Click on Apply.
Reboot normally.
Please download to your desktop
Malwarebytes' Anti-Malware from
Here or
Here
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply. Also include a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process; if asked to restart the computer, please do so immediately.
Let me know if you are still having a problem with the disabled Task Manager.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:55:36 PM, on 05/05/2008 HI,
done as laid out. Malwarebytes detected 2 ,and removed, in the registry. The search only found the log file of HJT . The redegit fix was from this site , I believe, in a task manager discussion. I, mistakenly thought XP was Xp and that the fix did not have to be computer specific. It was the only thing I tried beside virus scans and your current suggestions. I am going to reboot now and see if the Task manager works.
Sean
Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
No luck with the task manager. I am still getting the disabled by administrator box. Interestingly , the task manager does work in the other personality on this computer. One that isn't used and was on here when the computer arrived.
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run.
Please follow these steps to remove older version Java components and update.
Following that, please run Notepad and paste the text between the lines into a new file. Do not copy the dotted lines.
* Make sure that Word Wrap is turned off in Notepad - (click the Format menu and uncheck Word Wrap)
Important:
Make sure there are NO blank lines before REGEDIT4
Make sure there is one blank line at the end of the file
Make sure that you have copied all of the text (e.g. Don't miss the first 'R'.)
-------------------------------------------------------------------------------------------
Save the file to the desktop as
fix.reg and make sure the "Save as Type" field says "All Files".
Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.
Let me know how things are running after that. If all is well, we'll flush System Restore, and I'll give you some prevention tips. Although, I suggest that you keep Malwarebytes' Anti-Malware updated and use it as an on-demand scanner as needed in the future.
Eureka! (He said with a roar of laughter) . My long lost Task manager is back. I seriously owe you a beverage of your own choosing. Your help has and is greatly appreciated. I was planning on updating the Java, I just was not sure which version to choose. Done now though :-)
Sean
Here is the latest HJT log:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:34:12 PM, on 06/05/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
After something like this it is a good idea to purge the Restore Points and start fresh.
If everything is running well.... To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.
Reboot.
Go back in and turn System Restore ON. A new Restore Point will be created.
Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.
You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:
1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update:
http://v4.windowsupdate.microsoft.com/en/default.asp
4. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known
vulnerabilities.
6. If you have not already done so, you might want to install
CCleaner and run it in each user's profile:
http://www.ccleaner.com/ ** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.
7. Practice Safe Surfing with with
TrendProtect by Trendmicro.
TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine.
TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the page currently open is safe, unsafe, trusted, or unrated, or whether it contains unwanted content.
The following color codes are used by TrendProtect to indicate the safety of each site.
Red for Warning Yellow for Use Caution Green for Safe Grey for Unknown
8. You might consider installing SpywareBlaster:
http://www.javacoolsoftware.com/spywareblaster.html It will:
Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
Block spyware/tracking cookies in Internet Explorer and Mozilla Firefox.
Restrict the actions of potentially unwanted sites in Internet Explorer.
Tutorial here:
http://www.bleepingcomputer.com/forums/tutorial49.html Periodically check for updates.
Bugbatter
4 Apprentice
•
20487 Posts
455
0
Posted May 4th, 2008 16:00
It looks to me as if you still have some infection in there. Please let us know what type of "trojans, viruses" you have/had, and what steps you performed to clean.
I'll do my best, but if any errors were made in your cleaning, I may not be able to undo those.
Any registry editing that you do may be prevented because you are running AVG's Guard feature that monitors registry changes.
Please disable that:
Open AVG Anti-Spyware. The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right-click on AVG AS in the system tray and uncheck "Start with Windows".
Go to Start > Run and type: services.msc
Press "OK".
In Services, click the "Extended tab" and scroll down the list to find AVG Anti-Spyware Guard.
When you find the guard service, double-click on it.
In the Properties Window > General Tab that opens, click the "Stop" button.
From the drop-down menu next to "Startup Type", click on "Manual".
Now click "Apply", then "OK" and close the Services window.
Please post a fresh HijackThis log and address the following questions:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.
A list of P2P's is here: http://www.castlecops.com/t204179-P2P_programs_we_ask_that_you_remove_first.html
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.
** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.
I look forward to your reply.
The instructions in this topic are only for this Forum member.
Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance, and you will make a cleanup of your system more difficult.