Announcement Banner
UNSOLVED

mcbrit

updated

22 years ago

M

mcbrit

9 Posts

0

4030

January 18th, 2005 22:00

computer won't do anything! help!

i am far from a computer guru, and i need help!  I recently just dowloaded the mcafee security suite.  Found were numerous viruses and trojans which were deleted.  Ever since then my computer won't do anything.  The virus scan takes forever, but never comes up with any viruses.  I can't get online (i'm at work now).  I can't to much of anything.  Please help!
 
Lisa
  • Midnight Star

    4791 Posts

    415

    0

    Posted January 19th, 2005 18:00

    Lisa,

    Let's see what's running on your system that might be causing the problem; post up a hijackthis log for analysis. Try following ChrisM's instructions pinned at the top of this forum, or just post back and i'll see if I can help you get one posted.

    Mike.
  • mcbrit

    9 Posts

    415

    0

    Posted January 20th, 2005 00:00

    Mike,
       I was able to actually get onto my computer.  I uninstalled all of my McAfee stuff and ran a free scan which found these 2 trojans...ASUNE.B  C:\WINDOWS\JAV\javasys.exe
                                                             STARTPAG.BA  C:\msods.exe
     
    It said that these were "not cleanable"  what does that mean & how do i get rid of them?  I don't know how to do hijack & need some advice as to what security i should put on my computer as Mcafee is horrible.  Thanks in advance for your help!
     
    Lisa
  • Midnight Star

    4791 Posts

    415

    0

    Posted January 20th, 2005 14:00

    Lisa,
     
    I'll see what I can do.
     
    -
     
    First off, your going to need these three things:
     
    1.  Run a 3-rd party firewall; or the SP2 firewall at minimum.
    2.  Run an anti-virus program.
    3.  Keep your windows updates upto date.
     
    -
     
    Are you using dialup, or broadband?
     

     
    Download, then unzip to " C:\HJT", the newest version of HiJackThis; version 1.99.0. Now, let's do the following: 
       
     1.  Click " Scan" 
     2.  Click " Save log" 
       
     Notepad will pop-up with a copy of your system long, then: 
       
     1.  " Edit | Select all" 
     2.  " Edit | Copy" 
       
     Next, let's " Reply" back to this post, then: 
       
     1.  Right-click on the message body. 
     2.  Select " Paste"  
        
    Then just " Post" the message, and we'll analyze your log shortly, then post back any recommendation(s).
     


    Go to www.trendmicro.com, and then:
     
    1.  Click " Free Online Scan".
    2.  Click " Scan now, it's free".
     
    It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
     
    1.  Select all available drives.
    2.  Check(tick) " Auto Clean".
    3.  Click " Scan".
     
    When it completes, post back the full filename of any files that cannot be cleaned or deleted.
     


    After all the scans are completed, post back the results, along with a new HiJackThis log.
     
    -
     
    Mike.
     
     
  • mcbrit

    9 Posts

    415

    0

    Posted January 25th, 2005 23:00

    Mike,
    Here is my Hijack this log.  what virus protection & spyware, firewall do you recommend?  Thank you for all your help!
     
    ~Lisa
     
    Logfile of HijackThis v1.99.0
    Scan saved at 8:41:29 PM, on 1/25/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
    C:\Program Files\Verizon Online\VisualIPInsight\IPClient.exe
    C:\Program Files\Verizon Online\VisualIPInsight\IPMon32.exe
    C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\specificmail\SPCM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
    C:\Program Files\Microsoft Broadband Networking\MSBNUtil.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Lisa Lamontagne\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dslstart.verizon.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://pzpkmi.t.rack.cc/hp.php (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://pzpkmi.t.rack.cc/hp.php (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://pzpkmi.t.rack.cc/hp.php (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {F2A4407B-FFBC-4A1F-A18A-0F68C3E0FC9E} - C:\WINDOWS\System32\dakii.dll (file missing)
    O2 - BHO: (no name) - {FCEBAE92-D027-0BD7-35ED-623641669EDF} - C:\WINDOWS\System32\xoaebog.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPMon32.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SPCM] C:\Program Files\specificmail\SPCM.EXE
    O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/15bdd2707bbeb4854223/netzip/RdxIE601.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
     
  • Midnight Star

    4791 Posts

    415

    0

    Posted January 26th, 2005 00:00

    Lisa,
     
    I would say yes, but try doing a google search on those, just to see what others also think; Wilders security mentions 'spyware' for the media player - to what extent, and what information is being disclosed, i'm not sure.
     
    Mike.
     
  • Midnight Star

    4791 Posts

    415

    0

    Posted January 26th, 2005 00:00

    Lisa,
     
    I use Norton's on both my systems, with ZoneAlarm (free) as the firewall on one. Just keep in mind, that no amout of anti-(software) can prevent your system from getting 'infected' if you visit a malicious web site, or download and run malicious software.
     
    GreyMack posted a very informative link here on this thread: http://forums.us.dell.com/supportforums/board/message?board.id=si_newusers&message.id=19329#M19329, reguarding security software performance.
     
    -
     
    Let's see if we can get your system cleaned off...
     


    Go to Add/Remove programs and remove(uninstall) the following, if present:
     
        Viewpoint Manager (toolbar)
     
    The above could appear anywhere within the entry. Be careful not to remove any personal or system software.


    Download, unzip to your desktop CWShredder and run it, then:
     
    1.  Click " Check For Update"
     
        ( If an update isn't available, skip to step #4.)
    2.  Click " Click here to Download the upate".
    3.  When the new version has been downloaded, click " Save".
    4.  Click " Fix ->"
     


    Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:
     
    regsvr32  /u  xoaebog.dll
    regsvr32  /u  ViewBar.dll
     
    It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.



    Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done ' cleaning' off your system, we're going to ' flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.
     
    Also move the " Backups" folder, for HiJackThis, if present.
     


    Run HiJackThis and click " Scan", then check(tick) the following, if present:
     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://pzpkmi.t.rack.cc/hp.php (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://pzpkmi.t.rack.cc/sp.php (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://pzpkmi.t.rack.cc/hp.php (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://pzpkmi.t.rack.cc/hp.php (obfuscated)
     
    O2 - BHO: (no name) - {F2A4407B-FFBC-4A1F-A18A-0F68C3E0FC9E} - C:\WINDOWS\System32\dakii.dll (file missing)
    O2 - BHO: (no name) - {FCEBAE92-D027-0BD7-35ED-623641669EDF} - C:\WINDOWS\System32\xoaebog.dll
     
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
     
    O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
     
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/15bdd2707bbeb4854223/netzip/RdxIE601.cab
     

    Now, with all windows closed except HiJackThis, click " Fix checked".
     


    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
     
    folders...
     
        C:\Program Files\Viewpoint
     
    files...
     
        C:\WINDOWS\System32\xoaebog.dll
     


    Post back a new log.
     
    -
     
    Mike.
     
  • Midnight Star

    4791 Posts

    415

    0

    Posted January 26th, 2005 00:00

    Lisa,

    To remove those trojans, you'll need to disable system restore, then re-run the anti-virus scan, then re-enable system restore when it completes and the files are removed.

    TROJ STARTPAG.BA    <=== this is the one that changes your IE start page.

    -
     
    Mike.
     
  • mcbrit

    9 Posts

    415

    0

    Posted January 26th, 2005 00:00

    OK, you lost me on the first step...i went to remove Viewpoint Manager (toolbar)  and these are what i have for Viewpoint:

    Viewpoint Manager (Remove Only)

    Viewpoint Media Player (Remove Only)

    Viewpoint Toolbar (Remove only)

    should i remove all of them?

     

    ~Lisa

  • mcbrit

    9 Posts

    415

    0

    Posted January 26th, 2005 00:00

    Mike,

    after i ran the Trendmicro scan these files came up uncleanable:

    TROJ ASUNE.B            C:\System Volume Information\...

    TROJ STARTPAG.BA        C:\System Volume Information\...

     

    I was able to delete them, but will they come back?  My computer runs so incredibly slow, but at least i can get onto the internet now.  Before it took about 15 minutes just to get to my home page.  I really appreciate any help.  Thanks again

    ~Lisa

     

  • mcbrit

    9 Posts

    127

    0

    Posted January 26th, 2005 09:00

    Mike,

     How do i disable system restore?  i am VERY computer illiterate & i am just barely squeaking by here.  I read about viewpoint & i am still confused so i am just gonna delete all three.

     

    ~Lisa