Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
May 30 2009, 01:03 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-May 09 Member No.: 337,226 |
However, still having the following symptoms of something still wrong on my computer: - Norton AntiVirus has been detecting a Backdoor Trojan virus of some kind popping up - setup_u.exe. It does get quarantined - yet it seems to keep coming back. - After running a Google search, when clicking on a link in the search results the browser (FireFox or IE) sometimes gets "hijacked" and brought to a separate site - usually some type of advertisement. Clicking the back button and re-clicking on the search result then gets me to the site I'm supposed to go to. - Ad-Aware, Spybot SD, and Malwarebytes are all finding NOTHING. - It would seem there is a registry entry I need to delete to clean this up, but I have found that I now can not run cmd.exe or regedt32.exe. MS Installer seems to be having issues as well, so I'm having trouble getting alternative scanning software to use to see what's going on. Was going to try re-installing the Installer based on Symantec recommendations, but when I try to move the old files by renaming them, the files keep coming back, almost as if I did a copy. Per the prep guide, I downloaded DDS.scr and tried running it - but nothing happens (a command window opens for a fraction of a second, but it is blank, and then goes away before I can even blink), so unfortunately there is no output to attach here. So I guess the first thing would be if someone could tell me how to get DDS.scr to work, or has any idea what is going on based on what I am describing above. Alternatively I could supply the TrendMicro HijackThis log, but I'll wait for some feedback first. Thanks in advance for your assistance. |
|
|
|
May 31 2009, 10:29 PM
Post
#2
|
|
![]() Bleepin' Cynic ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 10,437 Joined: 11-November 06 Member No.: 94,959 |
Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.
Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet. alternate download link Note: The file will be randomly named (i.e. 5mkuvc4z.exe). Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Scan with Dr.Web CureIt as follows:
-------------------- The power of accurate observation is commonly called cynicism by those who haven't got it.
—George Bernard Shaw |
|
|
|
Jun 4 2009, 05:16 AM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-May 09 Member No.: 337,226 |
Thanks for the information. I finally had the time to run a complete scan with Dr. Web and it found the following:
A0163199.reg;C:\System Volume Information\_restore{43172125-0AD0-4909-9479-AC28ACD763FE}\RP1230;Trojan.StartPage.1505;Deleted.; Other than that, I still can't run cmd.exe or regedt32.exe, although I guess I'm lucky as Norton, Ad-Aware, SD and Malwarebytes are all still able to run, so I'll keep using them for now to contain the issue. |
|
|
|
Jun 4 2009, 04:29 PM
Post
#4
|
|
![]() Bleepin' Cynic ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 10,437 Joined: 11-November 06 Member No.: 94,959 |
Please print out and follow these instructions: "How to use SDFix". This program is for Windows 2000/XP ONLY.
When using this tool, you must use the Administrator's account or an account with "Administrative rights"
-------------------- The power of accurate observation is commonly called cynicism by those who haven't got it.
—George Bernard Shaw |
|
|
|
Jun 5 2009, 09:35 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-May 09 Member No.: 337,226 |
After multiple attempts, I can't get SDFix to run in safe mode or regular mode. What happens with SDFix is the same thing that happens when I try to run cmd or regedit: all the icons on the desktop disappear for a few seconds, then gradually come back as if nothing happened.
Not sure what the next step is - as always, appreciate your assistance. Thanks. This post has been edited by Jeff Melnik: Jun 6 2009, 11:20 AM |
|
|
|
Jun 7 2009, 04:26 PM
Post
#6
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 22,922 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
Topic reopened
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jun 7 2009, 11:32 PM
Post
#7
|
|
![]() Bleepin' Cynic ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 10,437 Joined: 11-November 06 Member No.: 94,959 |
Can you please update Malwarebytes, run a quick-scan and post the log.
-------------------- The power of accurate observation is commonly called cynicism by those who haven't got it.
—George Bernard Shaw |
|
|
|
Jun 8 2009, 05:53 AM
Post
#8
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-May 09 Member No.: 337,226 |
OK, here's the latest quick scan log - "nothing malicious found"...
-------------------------------- Malwarebytes' Anti-Malware 1.36 Database version: 1945 Windows 5.1.2600 Service Pack 3 6/8/2009 6:51:22 AM mbam-log-2009-06-08 (06-51-22).txt Scan type: Quick Scan Objects scanned: 94040 Time elapsed: 18 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Jun 8 2009, 06:40 AM
Post
#9
|
|
![]() Bleepin' Cynic ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 10,437 Joined: 11-November 06 Member No.: 94,959 |
What symptoms are you currently experiencing?
-------------------- The power of accurate observation is commonly called cynicism by those who haven't got it.
—George Bernard Shaw |
|
|
|
Jun 8 2009, 06:52 AM
Post
#10
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-May 09 Member No.: 337,226 |
A file called "setup_u.exe" keeps popping up - fortunately Symantec AV identifies it as a Trojan Horse and quarantines it. Seems to happen at least once a day, usually triggered by a Google search.
|
|
|
|
Jun 8 2009, 06:59 PM
Post
#11
|
|
![]() Bleepin' Cynic ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 10,437 Joined: 11-November 06 Member No.: 94,959 |
Please download ATF Cleaner by Atribune & save it to your desktop. alternate download link DO NOT use yet.
Please download and install SUPERAntiSpyware Free
Double-click ATF-Cleaner.exe to run the program.
Scan with SUPERAntiSpyware as follows:
-------------------- The power of accurate observation is commonly called cynicism by those who haven't got it.
—George Bernard Shaw |
|
|
|
Jun 10 2009, 05:29 PM
Post
#12
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-May 09 Member No.: 337,226 |
Sorry for the delayed response. I had an issue with MS Installer which was preventing me from installing SuperAntiSpyware. I downloaded the latest version of Microsoft installer and that resolved the issue.
I ran ATF Cleaner in Safe mode. Should I run SuperAntiSpyware in safe mode as well? Thanks. |
|
|
|
Jun 10 2009, 05:33 PM
Post
#13
|
|
![]() Bleepin' Cynic ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 10,437 Joined: 11-November 06 Member No.: 94,959 |
Yes, run SUPERAntiSpyware in Safe Mode.
-------------------- The power of accurate observation is commonly called cynicism by those who haven't got it.
—George Bernard Shaw |
|
|
|
Jun 11 2009, 04:17 AM
Post
#14
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-May 09 Member No.: 337,226 |
OK, here is the log output. The last entry seemed suspect, so I'm glad that got picked up.
I will have to keep an eye to see if I still have the Google redirect issue, which had been popping up again recently. After doing a Google search, clicking on a link would occasionally take me to a random advertising site instead of the page for the link that I clicked on. Other than that, still can't run cmd or regedt32. -------------------------------------- SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 06/11/2009 at 00:06 AM Application Version : 4.26.1004 Core Rules Database Version : 3931 Trace Rules Database Version: 1874 Scan type : Complete Scan Total Scan Time : 01:34:54 Memory items scanned : 216 Memory threats detected : 0 Registry items scanned : 5966 Registry threats detected : 0 File items scanned : 25859 File threats detected : 42 Adware.Tracking Cookie C:\Documents and Settings\new\Cookies\new@2o7[2].txt C:\Documents and Settings\new\Cookies\new@at.atwola[1].txt C:\Documents and Settings\new\Cookies\new@ar.atwola[1].txt C:\Documents and Settings\new\Cookies\new@advertising[2].txt C:\Documents and Settings\new\Cookies\new@ar.atwola[3].txt C:\Documents and Settings\new\Cookies\new@specificmedia[1].txt C:\Documents and Settings\new\Cookies\new@ads.bridgetrack[2].txt C:\Documents and Settings\new\Cookies\new@ads.pointroll[1].txt C:\Documents and Settings\new\Cookies\new@msnportal.112.2o7[1].txt C:\Documents and Settings\new\Cookies\new@interclick[1].txt C:\Documents and Settings\new\Cookies\new@tracking.foxnews[1].txt C:\Documents and Settings\new\Cookies\new@tacoda[2].txt C:\Documents and Settings\new\Cookies\new@serving-sys[1].txt C:\Documents and Settings\new\Cookies\new@casalemedia[2].txt C:\Documents and Settings\new\Cookies\new@oasn04.247realmedia[2].txt C:\Documents and Settings\new\Cookies\new@adlegend[2].txt C:\Documents and Settings\new\Cookies\new@fastclick[2].txt C:\Documents and Settings\new\Cookies\new@247realmedia[2].txt C:\Documents and Settings\new\Cookies\new@ad.yieldmanager[1].txt C:\Documents and Settings\new\Cookies\new@collective-media[1].txt C:\Documents and Settings\new\Cookies\new@atwola[1].txt C:\Documents and Settings\new\Cookies\new@insightexpressai[2].txt C:\Documents and Settings\new\Cookies\new@cdn4.specificclick[2].txt C:\Documents and Settings\new\Cookies\new@specificclick[2].txt C:\Documents and Settings\new\Cookies\new@trafficmp[1].txt C:\Documents and Settings\new\Cookies\new@tribalfusion[1].txt C:\Documents and Settings\new\Cookies\new@d.mediaforceads[2].txt C:\Documents and Settings\new\Cookies\new@c7.zedo[2].txt C:\Documents and Settings\new\Cookies\new@revsci[1].txt C:\Documents and Settings\new\Cookies\new@edge.ru4[2].txt C:\Documents and Settings\new\Cookies\new@zedo[2].txt C:\Documents and Settings\new\Cookies\new@mediaplex[1].txt C:\Documents and Settings\new\Cookies\new@media6degrees[1].txt C:\Documents and Settings\new\Cookies\new@atdmt[2].txt C:\Documents and Settings\new\Cookies\new@questionmarket[2].txt C:\Documents and Settings\new\Cookies\new@bs.serving-sys[2].txt C:\Documents and Settings\new\Cookies\new@realmedia[1].txt C:\Documents and Settings\new\Cookies\new@apmebf[2].txt C:\Documents and Settings\new\Cookies\new@ad.wsod[2].txt C:\Documents and Settings\new\Cookies\new@imrworldwide[2].txt C:\Documents and Settings\new\Cookies\new@doubleclick[2].txt Application.PowerReg Scheduler C:\WINDOWS\PSS\POWERREG SCHEDULER V3.EXESTARTUP ------------------------------------------------------------- |
|
|
|
Jun 11 2009, 04:04 PM
Post
#15
|
|
![]() Bleepin' Cynic ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 10,437 Joined: 11-November 06 Member No.: 94,959 |
Try the fix at Kelly's Korner.
Lift Restrictions - TM, Regedit and CMD - #275 on the left. Right click on it and save the .vbs file to your desktop. Then, double click on the file icon (on your desktop) to run the script. You may need to reboot your computer for the changes to take affect. Also, log on as an administrator, go Start > Run and type: "cmd". In the window that appears type: "netsh winsock reset". When the program is finished, you will receive the message: "Successfully reset the Winsock Catalog. You must restart the machine in order to complete the reset." Close the command box and reboot your computer. Go Start > Run > type: "cmd" In the window that appears type: "ipconfig /flushdns". Close the command box. Go Start > Control Panel > Network Connections. Right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and and choose Properties. Double-click on the Internet Protocol (TCP/IP) item. Select the radio button that says "Obtain DNS servers automatically". Reboot. Warning: Some Internet Service Providers need specific DNS settings. You need to make sure that you know if such DNS settings are required before you make this change. -------------------- The power of accurate observation is commonly called cynicism by those who haven't got it.
—George Bernard Shaw |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 7th November 2009 - 09:17 PM |