Problems removing programs and trojan removal Windows Me

Status
Not open for further replies.

libby1

Posts: 12   +0
Hello . New member here . I had posted this in the Introductions Forum and was advised to post it here . I apologize if this is not the correct place to put this . I did a search of forums and found some similar problems to mine . However they had either been locked by the time I found them or the remedies mentioned did not wholly apply to my older system ( Windows Me ) . I did a scan using SuperAntiSpyware which found some trojans and a couple of Registry entries . I have also found some entries in my Add/Remove Programs files which cannot be removed . I have read the Updated Viruses/Spyware/Malware preliminary Removal Instructions which consists of 8 steps . I have problems with Step 1 ( Temporarily Disable Real Time Monitoring Programs ) . I know some of my programs which I should disable but I am not sure about other programs . I have downloaded Ccleaner mentioned in Step 3 but I am hesitant to use it as I am unfamiliar with it and I understand it can cause problems if the wrong items are "cleaned" . Step 4 mentions to download Malwarebytes' Anti-Malware . Unfortunately they do not support my Windows Me . I have downloaded Hijackthis mentioned in Step 7 . Therefore it looks like the only logs I could post would be from SuperAntiSpyware and Hijackthis . Would this be sufficient or would I need more ? I would also like to know if I should run scans in Safe Mode and also enable " Show hidden files and folders " and uncheck " Hide file extensions for known file types " and also uncheck " Hide protected operating system files " ? Could you also tell me which forum would be best to post this in ? Again I am sorry if this is a breach of this forums etiquette but I really need help here and had no idea where else to post this . I thank you in advance for any help you can extend .
 
libby1 you got here, that's great
And you have attempted the New Preliminary Removal Instructions
But concerned about a few things.

The "RealTime monitoring programs" are things like Antivirus or even Spybots S&D (if installed)
Do you actually have an Antivirus software installed?
Have you tried to update it and run a full scan?

You are correct about Malwarebytes not being Windows ME compatible, even Ad-aware won't work (plus many others) It's just that Windows ME is sooo old now. Not only that, it had many faults that MS even admitted to, and then decided just to scrap it all together.

I wonder if you are best to try to backup all your user data to CD or floppy, and think about updating to at least Xp (which is also now old)
I'd say you could find a really cheap Xp box on eBay for just a couple of hundred dollars (although I'm not suggesting that is the best option for a computer shop, just wondering why you want to stay with the unsupported Windows ME (maybe cost was the reason)

At least CCleaner works with ME, so yes go ahead and run it. Although I can't see any issues in doing so, it's still best to backup first, if you can

Your thoughts?
 
Hi . Thanks for your speedy reply . Yes , finances are definitely the reason for not upgrading my platform . I wonder if before I attempt anything I could attach logs from Hijackthis and SuperAntiSpyware and you could have a look and have a better idea of what is happening . Please let me know and also if I should do the scans in Safe Mode and with hidden and system files showing . Thanks again .
 
Actually I normally don't view the HJT logs (they can get really big, and sometimes there is just too much to check) probably a bit of laziness on my behalf, but thankfully others are willing to spend the time on them.

You didn't say if you had Antivirus or if you have scanned fully (but I suspect yes) if not do that first, before providing any logs

You do not need to manually turn on Hidden and system files, because the scanning programs already scan these areas
Running in Safe Mode, really only helps, if you cannot remove a bug in Normal mode; so to avoid this issue, many support members say scan in Safe Mode (instead of scanning twice!)

Yes run the CCleaner fully, and the scans (like updated Antivirus) then attach
attach.gif
the logs. I might even check them yet. As long as you have done the above first :)
 
Hi Kimsland . Ok I will follow the Preliminary steps and post the logs . As I mentioned the only one I won't be able to complete is Malwarebytes . Thanks very much .
 
Don't forget Antivirus scan

And if you reply back, make sure you say "I scanned with my updated Antivirus software too" (ideally also tell me what Antivirus software you are using - probably None or worse yet, Norton)
 
Hi Kimsland . Sorry I took so long to get this done . After I had finished cleaning with Ccleaner and fixing items found by SuperAntiSpyware I ran the Avast AV ( updated ) and Spybot . I had tried to update the Spybot before running it but it kept coming back with an error " Application Error : Exception EinvalidCast in module SDUPDATE.EXE at 000730EB . Invalid class typecast " . I never had this problem with Spybot update before . I had to keep restarting the computer each time it happened . I am wondering if Ccleaner or SAS fixes have anything to do with this ? The Spybot scan itself worked fine and everything showed ok except for minor cookies . The Avast scan also was fine with nothing found except for an entry in the results which stated " c:\W9XUNDO.DAT . UNABLE TO SCAN . NOT ENOUGH STORAGE IS AVAILABLE TO PROCESS THIS COMMAND " . I have attached the HJT and SAS log files . As I mentioned in my first post I also have some programs which cannot be removed in Add/Remove programs . They are : Deewoo Network Manager , Enhancement Browser Tools Agadoo , Enhancement Browser Tools Radbanner and MySidesearch Search Assistant Bfinding . Please let me know if you want me to post any other logs . Thanks for your help .
 

Attachments

  • hijackthis.txt
    5.8 KB · Views: 5
you have some parts of avg on your comp

these i think should be removed

Code:
O24 - Desktop Component 0: (no name) - http://www.vaxxine.com/kilbirni/g&s0005.JPG
O24 - Desktop Component 2: (no name) - C:\WINTEST\Desktop\Shortcut to PIC_0001.JPG.lnk
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = vaxxine.com
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = vaxxine.com
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 85.255.116.134,85.255.112.5
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINTEST\bdoscandel.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINTEST\SYSTEM\MSDXM.OCX

How ever do not remove anything but these look suspicious to me

it seems bitdefender entries are there, why do you have them?

Java is outdated Update

Control panel
Java
update tab
update now


Adobe is outdated update that too
 
Hi . I have AVG Free Edition 7.5 installed and I also tried the online scan with Bitdefender edition for Windows Me . it seemed to work fine until near the end of the scan and then just locked up . This was a few days ago . The entries referring to vaxxine are from my previous dial up connection which is no longer active . Desktop Component 2 refers to a picture on my desktop and I have no idea why it is mentioned . I am not sure what entries 016 , 09 and 03 are referring to . Thanks
 
Hi Kazi . I just noticed you mentioned updating Adobe and Java . I cannot update these as my WIndows me will not support any higher versions . Thanks
 
Well you should remove the vexxine people don't like seeing a big log and check because they are lazy, and any symtoms happening?

you read my post wrong, i did not ask you to uninstall avg
 
The reason I don't remove the vaxxine is because I have many important files stored with them and I may have to reengage them as an ISP in the future . The symptoms I am concerned about is that the programs which I mentioned cannot be uninstalled ( have invalid uninstall commands ) which leads me to believe they are spurious and therefore could be doing something ( probably not good ) on my computer . I did not knowingly install these programs and God knows where they came from .

uninstall avg ? i never mentioned anything about uninstalling it .
 
Thats ok . I will wait for Kimsland to take a look and perhaps offer some suggestions . Thanks again .
 
I have AVG Free Edition 7.5
This version is old and I believe cannot even be updated any longer

Please un-install it fully. Sadly the new AVG Free Version 8 does not work with Windows ME (I think this may continually be an issue here for you)

I have then checked Avira free Antivirus and found the same issue (not ME compatible)

But Avast Free Antivirus is :) (free email registration required for continual updates)

Please uninstall AVG install Avast, update it. Then run a full scan
Then provide another HJT log in another reply.

Hear from you then
 
Hi Kimsland . My AVG gets autoupdated daily with no problems . I have had it installed for years and it has found numerous viruses over that time . I already have Avast Free installed ( not Avira ) . I did another full scan with updated Avast and again nothing was found except for the one result I mentioned in my previous post . This said : " c:\W9XUNDO.DAT . Unable to scan . Not enough storage is available to process this command " . Also as I mentioned before I have some programs which cannot be removed in Add/Remove programs . They are : Deewoo Network Manager , Enhancement Browser Tools Agadoo , Enhancement Browser Tools Radbanner and MySidesearch Search Assistant Bfinding . Should I be concerned about these unknown ( to me ) programs ? I was thinking of running a scan with bitdefender online scanner . What is your opinion on this ? I have attached the new HJT log . Please let me know if you want me to post any other logs . Thanks once again for your help .
 
You can remove these last two: (Tick and fix)
O24 - Desktop Component 0: (no name) - http://www.vaxxine.com/kilbirni/g&s0005.JPG
O24 - Desktop Component 2: (no name) - C:\WINTEST\Desktop\Shortcut to PIC_0001.JPG.lnk

Also you cannot have 2 Antivirus softwares installed together (Basically live protection won't work) Please remove one, preferably AVG

You also now have a number of Spyware and adblocking programs starting up. Although it is good to have at least one (so they tell me!) I would uninstall them all, and then just download and scan when required

Your Java still requires updating, just go here and test it: http://java.com/en/download/installed.jsp?detect=jre&try=1

You can try MyUninstaller to uninstall those broken Add/Remove programs: http://www.nirsoft.net/utils/myuninst.html

In Internet Explorer, you can also run a reset (from Tools->Options->Advanced->Reset) That may help

I noticed MSConfig is in Diagnostic mode too.
You can download MSConfig Cleanup utility here: http://www.majorgeeks.com/MSConfig_Cleanup_d4642.html
It would be best to use Startup Control Panel in future: http://www.mlin.net/StartupCPL.shtml

After that, is it all ok now or not?
 
Hi . Kimsland . Sorry it took so long to get back to you . I tried to find out from the Sun website if I should uninstall previous JRE 5.0 versions before installing JRE 5.0 Update 16 ( there are no further updates for my windows Me ) . I am still unclear on whether I should have uninstalled first ( I waited for a reply from there Customer Support ) . No reply so I went ahead and installed Update 16 and left the other 2 intact . I deleted the two components that you mentioned from the HJT entries . I uninstalled AVG and also Adaware . I reset IE as you suggested . I also downloaded Startup Control Panel as you suggested . I downloaded the MSConfig Cleanup utility from majorgeeks as you suggested but as they mention on their site its' use is very limited for Windows Me and it didn't work . I also downloaded the MyUninstaller you mentioned however it had no more success in removing the unwanted programs than I had . My major concern right now is getting rid of these programs since I have no idea where they came from or what they may be up to . It is beginning to look like it's going to be no simple job to get rid of them or at least find out what they are doing . I have included another HJT log if this will be of any help in accomplishing this . Thanks for your help and please let me know what you need from me in order to remove these programs .
 
Remove these:
O4 - HKLM\..\Run: [MSConfigReminder] C:\WINTEST\SYSTEM\msconfig.exe /reminder
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 85.255.116.134,85.255.112.5

You also still have all these installed:
Bitdefender online scan
superadblocker
SUPERANTISPYWARE
SpybotSD
ZONELABS
googletoolbar2
Avast (obviously leave alone)

Yes you can remove the old Java entries

You can download Windows Installer CleanUp Utility, and hopefully remove those Add/Remove entries.
Otherwise use this tool: http://www.intelliadmin.com/blog/addremovecleaner.exe
It works well on Xp, hope ME shows it ok too

System Restore should also be temporarily turned off, then back on (if wanted) This will remove all the present restore points
I'd even state do a CCleaner on your system again

Report back once done all, again
Also let me know how's it all going too
 
Hi Kimsland . I removed bitdefender , superadblocker , and googletoolbar2 . there were about 6 entries for googletoolbar2 so I removed all of them . An error message appeared in HJT when I checked the bitdefender to be fixed . It asked if I wanted to send this info to HJT to help them . I clicked "yes" and the message disappeared . I did another HJT scan and that particular bitdefender entry was gone ( I think it mentioned uninstall ) but another bitdefender entry was there which did not mention uninstall . I checked this entry to be fixed and it worked . I have no idea what happened as I had only seen one entry for bitdefender to begin with . The Sun customer rep finally replied to my query about removing the previous JRE entries . He said that some applets might require these so I have left them alone for now . I downloaded the Windows installer cleanup utility but it did not remove the entries . I then downloaded the addremovecleaner and it removed them . However how will I know for certain that all traces of these are gone from my system ? I noticed that my google toolbar is now missing . I can do without this assuming it was necessary to remove all the googletoolbar2 entries . However I also noticed that I can also no longer watch video clips of news stories that I click on ( the page displays an error message ) . I can read the text and pictures but no video will play . These by themselves are not that important to me however more importantly is that if I click on the Address bar at the top of my IE page it hangs and I have to do the CTRL+ALT+DEL thingy to close the page down and then reopen IE . Also my Search for Files or Folders function on my computer is behaving strangely . It cannot find files that I search for nor can I do the Browse function and open a folder ( for example the program folder ) . It does not do this all the time but periodically . Also when I try to open files a message tells me that I do not have enough memory to do this and I should close some open programs and try again . In fact when I tried to attach my HJT log to this message I had real difficulties . This Techspot web page also loaded with "Errors on page" . When I clicked on this for more info it said "not enough storage is available to complete this operation" . I never had this problem before . I hesitate to do the Ccleaner and delete System Restore points until I get this resolved . I have manged to attach another HJT log . Hope you can help . Thanks
 

Attachments

  • hijackthis .txt
    3.9 KB · Views: 5
In CCleaner there is also a Registry button (to the left)
If you click on that and do a full registry scan and repair all, hopefully some of the faults will be gone.

ME does fault easily (hence why MS scapped it) In just about all circumstances (of fault condition) MS recommends to backup and install ME fresh (then the drivers and so forth)

I tend to try to repair the faults, and generally get there (eventually), but you might want to contemplate a fresh install.

You can visit this page: http://www.adobe.com/shockwave/download/flash/trigger/en/2/index.html
To get your web pages to show the animations again

You can go here: http://www.microsoft.com/windows/downloads/ie/getitnow.mspx
To re-install Internet Explorer. Or you can go to Add/Remove programs in Control Panel, selecting Windows components, then untick IE, then when done, re-tick it, to install it again.

With ME it's always just going to work, and even then, for only 6Months !
 
Hi Kimsland . Couldn't do anything with my computer for the last week . I finally had to get some local tech help . Thanks for trying anyway . Windows Me is definitely a problem to work with .
 
Status
Not open for further replies.
Back