Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome ( Log In | Register )
Easy as 1,2,3!

2 Pages V  < 1 2  
Reply to this topicStart new topic
> Fraud.Sysguard malware, Sloe IE Startup Baseline
oldman960
post Nov 16 2009, 12:43 AM
Post #16


SuperMember
Group Icon

Group: Classroom Teacher
Posts: 3,905
Joined: 27-April 08
Member No.: 78,707
Operating System: win98se, XP pro



Hi

According to the last OTL log Teatimer should be running.

PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

We'll look at that in a bit.

IE was fine while browsing, but it hung when you reopened it? Is browsing speed still ok?

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :

CODE
:OTL
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found

:Commands
[Reboot]


Then click the Run Fix button at the top
  • Let the program run unhindered


Thanks
Go to the top of the page
 
+Quote Post
cherfxst
post Nov 16 2009, 08:20 AM
Post #17


New Member
*

Group: Authentic Member
Posts: 14
Joined: 14-November 08
From: Indiana, USA
Member No.: 82,397
Operating System: Windows XP Home Version 2002 Servic Pack 3



I ran code you gave me, but tea timer still didi not appear.

Now don't be mad at me. I did something on my own.
I went into GLARY utilities and looked at the startup entries. TeaTimer was in there twice, once as enabled and once as disabled. I deleted the entry that said disabled and rebooted. Now I have TeaTimer in the Srartup tray.
Hope wat I did was OK.

What next?
Go to the top of the page
 
+Quote Post
oldman960
post Nov 16 2009, 12:51 PM
Post #18


SuperMember
Group Icon

Group: Classroom Teacher
Posts: 3,905
Joined: 27-April 08
Member No.: 78,707
Operating System: win98se, XP pro



Hi cherfxst,

That's ok as long as you found the problem with Teatimer. It's strange that OTL reported it as running, unless it was just the tray icon that was disabled. No matter, you got it sorted.

The fix wasn't for teatimer, it was for a possible search redirect.

Your browsing speed still OK and no search redirects?

Go to the top of the page
 
+Quote Post
cherfxst
post Nov 16 2009, 02:56 PM
Post #19


New Member
*

Group: Authentic Member
Posts: 14
Joined: 14-November 08
From: Indiana, USA
Member No.: 82,397
Operating System: Windows XP Home Version 2002 Servic Pack 3



IE is still hanging quite a it. I had to do a reboot to get IE to work again.

Now TeaTimer not in system tray again, but t shows enabled in Glary Utilities. ZoneAlarm was in system tray twice for awhile, but it is only there once now. ZoneAlarm shows up twice in Glary Utilities once as enabled and once a disabled. Don't know if this means anything?

The real annoyance for me is IE hanging constantly and some times having to reboot to get IE working again. Also that my notifier in the EBAY toolbar is not working.


Go to the top of the page
 
+Quote Post
oldman960
post Nov 16 2009, 04:41 PM
Post #20


SuperMember
Group Icon

Group: Classroom Teacher
Posts: 3,905
Joined: 27-April 08
Member No.: 78,707
Operating System: win98se, XP pro



Hi cherxst,

You are using IE8. Did IE8 ever work properly or did the problems start after you installed it?

I'm not sure what's happening with your icons. I don't know enough about Glary to say if it could be a problem.


Let's see if we can get a better GMER log. Please run it in Safe Mode.


You may want to copy and paste this next set of instructions into a notepad as you will be in safemode without access to this thread.



Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.


Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop



Please post the log.

Thanks
Go to the top of the page
 
+Quote Post
cherfxst
post Nov 17 2009, 12:07 PM
Post #21


New Member
*

Group: Authentic Member
Posts: 14
Joined: 14-November 08
From: Indiana, USA
Member No.: 82,397
Operating System: Windows XP Home Version 2002 Servic Pack 3



Yes , I am running IE8 and have hated it ever since I installed it. Don't remember why I didn't like it. Maybe it is when the slow downn started. Really can't remember.

I ran GMER in SAFE MODE, the first time, it did not give me a message about ROOTKIT and the log was empty.

I ran GMER the second time. I got a pop up ox that stated "GMER hasn't found and System Modifications".
The log (gmer.txt) file is blank.

Go to the top of the page
 
+Quote Post
oldman960
post Nov 18 2009, 08:53 AM
Post #22


SuperMember
Group Icon

Group: Classroom Teacher
Posts: 3,905
Joined: 27-April 08
Member No.: 78,707
Operating System: win98se, XP pro



Hi cherfxst,

We could uninstall IE8 and see if the browser issues go away. Can you recall if you installed IE8 before you installed Service Pack 3?

Thanks
Go to the top of the page
 
+Quote Post
cherfxst
post Yesterday, 09:11 AM
Post #23


New Member
*

Group: Authentic Member
Posts: 14
Joined: 14-November 08
From: Indiana, USA
Member No.: 82,397
Operating System: Windows XP Home Version 2002 Servic Pack 3



Hi,
I'm pretty sure I installed IE8 before SP3.
Go to the top of the page
 
+Quote Post
oldman960
post Yesterday, 09:36 PM
Post #24


SuperMember
Group Icon

Group: Classroom Teacher
Posts: 3,905
Joined: 27-April 08
Member No.: 78,707
Operating System: win98se, XP pro



Hi cherfxst,

If you would like to try uninstalling IE8 to see if at least some problems are resolved, please follow these instructions.

Uninstalling IE8 will revert you back to the last version of IE that you had with your customizations. There is a very slight chance (very remote) that after the uninstall the previous version may not open. That is a fixable condition. Before doing the uninstall, you should download an alternative browser. You can get FireFox from HERE .

If you installed IE8 before you installed SP3, then SP3 will need to be uninstalled first. This can be determined by IE8 not being uninstallable, that is there is no option to uninstall Internet Explorer 8.

To uninstall IE8
  • Close all programs.
  • Click Start, and then click Control Panel.
  • Click Add or Remove Programs.
  • In the list of currently installed programs, click Windows Internet Explorer 8, and then click Remove.


If you need to uninstall SP3
  • Click Start, and then click Control Panel.
  • Click to select the Show Updates check box.
  • Click Windows XP Service Pack 3, and then click Remove.
  • Click Finish to restart the computer after the removal process is complete.
Go to the top of the page
 
+Quote Post

2 Pages V  < 1 2
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 20th November 2009 - 05:55 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy