It is currently Tue Sep 01, 2026 4:05 pm


Win ME..had 881 spies still no Internet Access

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Win ME..had 881 spies still no Internet Access

Postby CanadianTek » Sun Oct 31, 2004 3:04 am

Hey Folks,

This IBM NETVISTA, AVG had told us "Warning: Hidden extension.exe" and had indeed found a Virus/trojan in a file called currans.jpeg.exe

Make a long story short, spybotted, ad-awared, bazooka'd.. found 881 spies..
cleaned them all out..

of course one of the infections was part of wininit.ini (but also came in .exe, .bak, .log, wininit.tmp and wininitlog.old and wininit.sav flavours..) - cleared that up

went to go to the net..

"this page cannot be displayed"

Removed tcp/ip protocol, re-installed tcp/ip protocol, rebooted.. same

ping 192.168.0.1 ... unreachable
ping 127.0.0.1 was fine.. cable is fine..

no ? or ! or X in the device manager.. everything seems to be ok..

so.. here is the hjt log..

if you see anything glaring.. or obvious.. heck, even inobvious .. let me know..

any other ideas as to how to restore net accessibility.. would be greatful


Logfile of HijackThis v1.98.2
Scan saved at 9:35:41 PM, on 30/10/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\TEKS2GO UTILITIES\AVG ANTIVIRUS\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\TEKS2GO UTILITIES\AVG ANTIVIRUS\AVGCC32.EXE
C:\TEKS2GO UTILITIES\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\TEKS2GO UTILITIES\SPYWAREGUARD\SGMAIN.EXE
C:\TEKS2GO UTILITIES\SPYWAREGUARD\SGBHP.EXE
C:\TEKS2GO UTILITIES\HIJACKTHISV1-98-2.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico Internet Service
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://lc2.law13.hotmail.passport.com/cgi-bin/login"); (C:\Program Files\Netscape\Users\SecureIP.CAND.EB05929\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Teks2Go Utilities\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\TEKS2GO UTILITIES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] c:\TEKS2G~1\AVGANT~1\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Teks2Go Utilities\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] c:\TEKS2G~1\AVGANT~1\Avgserv9.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: SpywareGuard.lnk = C:\Teks2Go Utilities\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O12 - Plugin for .avi: C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\PLUGINS\npavi32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sympatico.ca
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/Z4/heartbeat.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw11fd.law11.hotmail.msn.com/act ... Atchmt.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/23cc4ed3393b2f1441 ... RdxIE6.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/ ... acscom.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe

thx
User avatar
CanadianTek
Geek
Geek
 
Posts: 90
Joined: Fri Jun 11, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Cactus » Sun Oct 31, 2004 3:17 am

A few things to remove...

**(Always create a Folder for HiJackThis anywhere but your Temp/Temporary Internet Folders. This is where it will save the backup files needed if there's a problem.)**


Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/23cc4ed3393b2f1441 ... RdxIE6.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -



Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and Reboot.

Turn on System restore,before opening your browser goto TOOLS>INTERNET OPTIONS and make sure your Homepage is correct,if not ,type the URL you would like in the HomePage box.

Now re-run HJT and post a new logfile back here.


Cactus
User avatar
Cactus
Geek Alumni
 
Posts: 1330
Joined: Sat Nov 30, 2002 1:00 am
Location: Somewhere...

Thanks given:0
Thanks received:0
Top

Postby Restek » Sun Oct 31, 2004 2:41 pm

User avatar
Restek
Geek Alumni
 
Posts: 1002
Joined: Tue Sep 18, 2001 1:00 am
Location: Uk

Thanks given:0
Thanks received:0
Top

Have Done HJT thing, also registry mechanic 804 probs

Postby CanadianTek » Sun Oct 31, 2004 6:00 pm

The network is a simple Rogers Cable modem (Terayon) to a D-Link 514 Router

The rj-45 then goes to a linksys EtherFast 10/100 Compact USB Network Adapter (usb100m is the model number) - used for 2 reasons a) no ethernet port in pc and b) user actually subscribes to sympatico high speed dsl with a USB Speedstream Modem

Now Sympatico uses Access Manager.. a software program to assist in the cross communications between REAL internet IP .. and the DSL's PPPoE

ANY TIME you take a system out of a DSL environ, snap it into a Rogers Home network, you can access the NET.. directly by just clicking on IE icon.. without loading the AM interface.


However, even with the HJT fixes implemented AND the 804 problems removed via Registry mechanic, - still cannot get to the internet.

WORSE... prior to HJT fixes, and subsequent to implementing fixes...

When I went to Right Click, My Computer, Properties, Performance Tab, File System, Trouble shooting..

the CHECKMARK ... WAS already in the DISABLE SYSTEM RESTORE... tried removing checkmark, APPLYING, ok'ing and rebooting as required, ... and it reboots, comes back and still says, disabled... and we witness that there is 6 gigs of stuff sitting in _RESTORE folder.. (containing 5 hidden folders and 5 files (one of which is hidden) )

SOOOOOO tried it in SAFE MODE... could not get the "tick mark" to stay off - always reboots and comes back as "Disable System Restore"

have done a few searches to see if anybody else has this problem in Win Me.. but not much success..

(am i missing something?)

thanx again for any insight..

here is HJT report too

Logfile of HijackThis v1.98.2
Scan saved at 11:58:31 AM, on 31/10/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\TEKS2GO UTILITIES\AVG ANTIVIRUS\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\TEKS2GO UTILITIES\AVG ANTIVIRUS\AVGCC32.EXE
C:\TEKS2GO UTILITIES\ZONEALARM\ZLCLIENT.EXE
C:\TEKS2GO UTILITIES\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\TEKS2GO UTILITIES\SPYWAREGUARD\SGBHP.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\TEKS2GO UTILITIES\HIJACKTHISV1-98-2.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico Internet Service
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Teks2Go Utilities\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\TEKS2GO UTILITIES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] c:\TEKS2G~1\AVGANT~1\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Teks2Go Utilities\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] c:\TEKS2G~1\AVGANT~1\Avgserv9.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: SpywareGuard.lnk = C:\Teks2Go Utilities\SpywareGuard\sgmain.exe
O12 - Plugin for .avi: C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\PLUGINS\npavi32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sympatico.ca
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/Z4/heartbeat.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw11fd.law11.hotmail.msn.com/act ... Atchmt.ocx
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/ ... acscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
User avatar
CanadianTek
Geek
Geek
 
Posts: 90
Joined: Fri Jun 11, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Cactus » Sun Oct 31, 2004 6:04 pm

There's nothing in your Logfile that would be causing this problem.
The log is clean.. :wink:

Cactus
User avatar
Cactus
Geek Alumni
 
Posts: 1330
Joined: Sat Nov 30, 2002 1:00 am
Location: Somewhere...

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Mon Nov 01, 2004 3:33 am

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

WinME and MS critical updates.. the saga continues..

Postby CanadianTek » Fri Nov 05, 2004 5:12 pm

Thx GeekGirl -- double checked, there is ample space..

Managed to get it connected to the net..

Downloaded 3 Microsoft Critical Updates.. for win Me / IE 6.. then..

:P barfff.. it choked..

NOW cant get back to the net.. Mozzilla FireFox can..

i can't believe one of microsoft's own critical updates.. is now keeping it from the net..

went back in and did add/remove of those ms updates.. to see if that would give me net access back...

bzzzzzzzzt.. no show..


SOOOOOOOO.. im thinking maybe.. just maybe.. 1 of the original 881 spies, or 12 viruses

may have corrupted part of the o/s
and now must decide..

Reformat with owners original copy of winMe, or run the IBM Recovery utility from the hidden d: partition.. ???

Question.. not being a BIG winME fan.. - does Win Me have a "Repair" mode like xp? and or win98.. if so.. how do i get there..

..........and if it exists, does it just molest/replace the original o/s files, leaving "my documents" untouched in and intact????

or

Should i use the ibm recovery utility, which, im pretty sure formats and bulldozes over all the problems.. ? (including data and documents)..

....... well i tried to run hjt, it did, i clicked on save log.. and the hour glass popped up.. and never came back, ctrl+alt+del to end the process/task.. gave me a blue "system busy" message.. yet.. it was not connected to the net..

so i am convinced there are more demons running around in this thing, pressing return just brings me back to a black screen.. about 2 minutes later the screen finally comes back saying

hijack this is not responding

and

msgsrv32 is not responding

trying to end task on either of those.. resulted in a hang..

|| << this close.. close enuf to see daylight.. hope.. ..pooched.. was getting to the net that one time.. just a fluke?


any feedback, input.. greatly requested, .. appreciated.. etc..

thx

CT
User avatar
CanadianTek
Geek
Geek
 
Posts: 90
Joined: Fri Jun 11, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

its ok to close this one now..

Postby CanadianTek » Mon Nov 15, 2004 10:08 pm

the re-installation of Win Me ... re-vitalized the other wise crippled o/s..

which was fine.. until i did the microsoft updates..

but the neat thing about reinstalling the o/s was.. Win Me detected that it was already there.. and gave the option to reinstall just the o/s files .. without reformatting.. i accepted that option.. and all worked well.. the net came back, the spies, bugs, pop ups that the system was previoiusly plagued with.. was fine too..

Thanx again for your help and suggestions..

CT
User avatar
CanadianTek
Geek
Geek
 
Posts: 90
Joined: Fri Jun 11, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron