Hello, my name is David and I am new to bullguard forums. I must admit that i use ZoneAlarm simply through recommendation. However, having reaed the help given in this forum i felt i had come to the right place to sort out the mess that is my computer. Recently, ZoneAlarm picked up the following threats, yet could not treat them: win32\oneraw!generic, win32\reckmess.L, win32\reckmess.M, win32\secdrop.JU and win32\Nnitwiz.G. After a bit of amateurish research I found that i may have a problem relating to Smitfraud. I subsequently downloaded smitfraudfix and ran it. However, problems have persisted and i have had to 'kill' suspiscious programs using ZoneAlarm such as 'PestTrap Control', 'bikini.exe', 'loader for you', 'bw~unin' and various other things. I also use Spybot and Spywareblaster. Recent scans with all three spyware/anti-virus software have shown nothing but my computer is slow and every time i try to access the internet, so too does "generic host process for win 32". Indeed, it also tries to act as a server. A recent scan with Panda's free online service showed the following:
Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\xlibgfl254.dll Adware:adware/sahagent Not disinfected c:\windows\system32\Agent.dll Potentially unwanted tool:application/mediapipe Not disinfected c:\program files\License_Manager Adware:adware/block-checker Not disinfected Windows Registry Adware:adware/fastvideoplayer Not disinfected Windows Registry Adware:Adware/SecurityError Not disinfected C:\Documents and Settings\Dee\Application Data\xlibgfl254.dll Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Dee\Cookies\dee@server.iad.liveperson[1].txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Dee\Cookies\dee@www.myaffiliateprogram[1].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Dee\Cookies\dee@xiti[1].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Dee\Desktop\SmitfraudFix\SmitfraudFix\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Dee\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Dee\Local Settings\Temporary Internet Files\Content.IE5\ARVL22LZ\SmitfraudFix[1].zip[SmitfraudFix/Process.exe] Adware:Adware/Itbill Not disinfected C:\Program Files\fsupport\notifier.exe Potentially unwanted tool:Application/MediaPipe Not disinfected C:\Program Files\License_Manager\license_manager.exe
And a recent scan with hijackthis showed:
Logfile of HijackThis v1.99.1 Scan saved at 19:03:40, on 08/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Finally, I have not recently been able to use start, run, msconfig to view services.
If anyone can help, it would be very much appreciated. I am at school and have a lot of what may seem unimportant to most, but school work that is very important to me.
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.
Reboot into SafeModeby tapping F8 after the BIOS has loaded.
The Windows Advanced Options Menu appears.
Ensure that the Safe mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button.
Doubleclick the "drweb-cureit.exe" and click "ok" in the prompt window that will open , asking "start the express scan now".
It will first make a quick scan of your system, let it clean what it find, and when it says "done"
Click on the green screwdriver-
Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select -Delete
Click on the drive(s) you want to scan . A red dot will mark the selected drive(s) . Then hit the greenarrow in lower right corner It will now scan yourdrive(s), say yes to all
After the scan, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
Start Superantispyware/rightclick on the black/yellow bug in tray.
Hit - Scan Your Computer - button
Click on the drive(s) you want to scan. Put a check in - Perform Complete Scan, then next
it will scan now. When scan have finished, put a checkmark withall items it found. Next, after cleaning, let it Reboot
Start Superantispyware again –
Click Preferences and then click the statistics/logs tab.
Click the dated log and press view log and a text file will appear.
Post this log along with fresh hijackthis log, Dr.Web and tell how things are running?
Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention.
Touch, first and foremost, thank you very much for taking the time to look at the information I sent. I have carried out all the procedures you requested and the results are shown below. My computer is running well apart from a few things; my internet is still slow, especially on start-up and also when I log on to my computer, just before my desktop icons load I get messages saying that applications "sgtray.exe" and "DMXLauncher.exe" failed to initialise properly. I have a suspiscion this is due to the fact that I may have stopped their processes in ZoneAlarm a while back. Should I trust these processes and allow them in ZoneAlarm?
HijackThis Log:
Logfile of HijackThis v1.99.1 Scan saved at 15:24:16, on 14/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Adware.Zango Toolbar/Hb C:\Documents and Settings\Dee\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1 C:\Documents and Settings\Dee\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\2 C:\Documents and Settings\Dee\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad C:\Documents and Settings\Dee\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static C:\Documents and Settings\Dee\Application Data\ZangoToolbar\v3.0\ZangoToolbar C:\Documents and Settings\Dee\Application Data\ZangoToolbar\v3.0 C:\Documents and Settings\Dee\Application Data\ZangoToolbar\zbar_1169834805.log C:\Documents and Settings\Dee\Application Data\ZangoToolbar
Once again, I thank you for your time and if I may, one more question....Although it is likely that all this stuff got on my computer prior to installing ZoneAlarm. I cannot help feeling slightly let-down by its services. Surely the scans I have done (including byte level scanning and deep inspection scans) should have found and removed whatever you have enabled me to hopefully fix? Should I consider changing Antivirus/spyware products?
Sorry Touch, I forgot.....ZoneAlarm still detects that "Generic Host Process For Win32" tries to access the internet. It no longer tries to act as a server but if I don't grant it access to the internet, I can't use the internet!
Went to Add/Remove Programs but neither spywarecleaner.exe or any variation was there. The only thing apart from ZoneAlarm and the software you had me download was AOL Spyware protection and I certainly did not put that there.
Logfile of HijackThis v1.99.1 Scan saved at 14:51:37, on 16/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You may want to print this or save it to notepad as we will go to safe mode.
Re-start your PC in Safe mode, by holding down the F8 button during the initial start up procedure. Use the up and down arrow keys to select Start PC in safe mode and hit the enter key. This will start your PC with only essential Windows programmes running.
Delete the following files or folders (delete item in bold). Please do not be concerned if any of the items are not found as they may have been automatically removed by actions I had you take earlier in the cleaning process.
Touch, I checked the Program Files both before and after using HJT. Neither time could I find anything relating to Spyware Cleaner. My HJT Log is below and unfortunately O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot is still there. I recently had to kill DrWatson Postmortem Debugger in Zone Alarm if that means anything to you.
Logfile of HijackThis v1.99.1 Scan saved at 21:23:33, on 23/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Bloody hell Touch, now I can't find the !!!! thing to fix in a HJT Log either in safe mode or in normal mode. Here's an up-to-date Log anyway. My internet is still extremely slow when a new explorer window is opened or when I connect. The ZoneAlarm internet monitor for incoming and outgoing events goes mad when I do either of these. Is there any other program Log file that might give you a better idea? Other than this, computer running fine, just slightly slower than normal probably due to the amount of antivirus and antispyware running (Spywareblaster, Spybot, ZoneAlarm, SuperAntispyware and DrwebCureit). Any ideas as to why McAfee is in HJT Log? I totally removed that from computer. Or so I thought. Certainly no sign of it in add/remove programs or program files.
Logfile of HijackThis v1.99.1 Scan saved at 00:17:26, on 01/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
I suggest you install theseto protect You against hijackers/malware in the future:
Spywareblaster Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software. Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
Spywareguard SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
IE Spyad IE-SPYAD adds a long list of sites and domains associated with known advertisers, marketers, and crapware pushers to the Restricted sites zone of Internet Explorer.
Visit Microsoftand check for Critical Security Updates Microsoft Update
How are things running now ?
Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention.
Touch, things running okay. Unfortunately hyperlink for Spywareguard did not work. Ran IEReg, closed itself when finished so not sure if it did whatever it was meant to do. Internet still has tendancy to be very slow. ZoneAlarm Monitor for Inbound and Outbound Events still goes mad the odd time. Computer slow on start-up. No sign of suspiscious behavior, just worried about tendancy to be slow. Here's HJT Log. If all good, I thank you very much for your time and effort and will be recommending Bullguard to friends.
Logfile of HijackThis v1.99.1 Scan saved at 11:42:51, on 12/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
1. Double click on combo.exe & follow the prompts. 2. When finished, it will produce a logfile located at C:\ComboFix.txt. 3. Post the contents of that log in your next reply.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention.
Hi Touch, first of all, I apologise the length of time this is taking. Believe me, I want to get it over and done with as much as you. Here are the reesults from ComboFix as requested. Thanks again, David
"Dee" - 07-03-13 22:18:43 Service Pack 2 ComboFix 07-03-14.1 - Running from: "C:\Documents and Settings\Dee\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\hosts
((((((((((((((((((((((((((((((( Files Created from 2007-02-13 to 2007-03-13 ))))))))))))))))))))))))))))))))))
Touch, things running very well. Probably being a bit pedantic but I still reckon that the internet is slow on connection and opening of a new IE window. If such slow operation is due to an excess of antivirus/spyware products then which of the following should I get rid of now the problem is gone....ZoneAlarm, SuperAntiSpyware, Spywareblaster, Spybot or DrWebCureIt? Unfortunately I cannot see DrWebCureIt in Add/Remove Programs nor can I even find its program file. I therefore would not know how to get rid of it. I would like to do so however if it is using unnecessary space. Once again Touch, I thank you for your time and effort. It has been much appreciated.
Double click on rustbfix.exe to run the tool. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). Post the content of these logfiles and tell how things are running.
Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention.
Unfortunately just same as usual. Computer slow on loading desktop and internet slow on connection and opening of new IE window. Any other Logs you'd like to see that might help?
Download and install: http://www.filehippo.com/download_ccleaner/ For a basic version of CCleaner with no Yahoo Toolbar, select the second or third install option as follows: Even if you selected Option 2 or 3, if you do not want the Yahoo Toolbar installed: Uncheck "Add CCleaner Yahoo! Toolbar", as it is checked by default during CCleaner Setup
1.Before first use, check under Options, Advanced, and UNCHECK "Only delete files in Windows Temp folder older than 48 hours".
2.A pop up box will appear advising this process will permanently delete files from your system.
3.Then select the items you wish to clean up.
In the Windows Tab:
Clean all entries in the "Internet Explorer". If you prefer to keep your cookies, uncheck the Cookies entry. Deleting cookies will require re-entry of user names and passwords on next visit to sites that require users log in.
Clean all the entries in the "Windows Explorer" section.
Clean all entries in the "System" section.
Clean all entries in the "Advanced" section.
Clean any others that you choose.
In the Applications Tab:
Clean all (optionally, except cookies) in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.
4.Then click the "Run Cleaner" button and it will scan and clean your system. Click exit.
And tell how things are running now?
Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention.
Touch, things running well. Internet seems to be quicker now. CCleaner was much more advanced to the one i'd been using. Is my computer clean now? If so, I am eternally grateful. If not, what else do I need to do?
To completely and immediately remove any infected file or files in the data store, turn off and then turn on System Restore. To do so, follow these steps: System Restore
Here are some additional software you may wish to consider using, to prevent malicious software installing in your PC - >
IE-SPYADSIE-SPYAD is a Registry file (IE-ADS.REG) that adds a long list of known ad/spy servers and domains to the "Restricted Zone" of Internet Explorer. (Choose between IE-SPYAD and IE-SPYAD2). Freeware
Spyware GuardBackground process to check applications as they begin to run for known spyware and malicious code, produces an alert if necessary.
Freeware. SpywareBlasterFrom the same company as Spyware guard, this is not a scanner, it blocks malicious objects and code from being downloaded, in addition to blocking access to sites known to download malware. Spyware Blaster runs silently in the background and does not need to be open to protect your PC.
Touch, thank you once again for all your help over the past couple of months. My computer is definitely running better now and there are little to no signs of suspiscious behaviour. During the time I have spent liasing with yourself, I have become quite interested in the whole process of cleaning and protecting a computer. If you don't mind me asking therefore, what exactly was it that had infected my computer? Lol, I promise this will be the last you'll hear from me in this thread unless otherwise asked!
Currently it is Saturday, November 21, 2009 12:46 PM (GMT +1) There are a total of 73.031 posts in 17.116 threads. In the last 3 days there were 14 new threads and 70 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil. 38 Guest(s), 0 Registered Member(s) are currently online. Details