Adware,Spyware,viruses! Please Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bonnielass, Dec 1, 2006.

  1. bonnielass

    bonnielass Private E-2

    Have run through the read me first thread and have posted logs. Havent posted log for counterspy because it found nothing. Spybot found 3 hkey's and deleted them.

    Problems: Computer is running slow also have an icon on my task bar telling me i have critical system errors,

    2 new shortcuts to online security guide at softwaresprotect.com and security troubleshooting at asecuretest.com on my desktop.

    Browser was crashing and refused to load pages, but this seems to be ok now after scans.

    New programs installed in my program files called virusburster and video activex object.

    Before using your read me first thread I uninstalled virusburster using add/remove programs successfully but couldnt uninstall video activex object i hope i havent made things worse.

    Please help me someone:confused:
     

    Attached Files:

  2. bonnielass

    bonnielass Private E-2

    Here are the other logs. Forgot to mention that I couldnt do online scans in safe mode so did them in normal.
     

    Attached Files:

    Last edited: Dec 1, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. bonnielass

    bonnielass Private E-2

    Hi thanks for your reply :) I have attached the log rapport.txt for step 1.
     

    Attached Files:

  5. bonnielass

    bonnielass Private E-2

    Here is the second rapport and the other 3 wanted.

    Things seem to be running fine now, everything on my desktop that shouldnt be there has gone and things are running alot faster. :)
     

    Attached Files:

  6. bonnielass

    bonnielass Private E-2

    Here is the new hjt log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's speed things up some more. While I look at your logs, you go to Add/Remove programs and uninstall the CounterSpy trial program and then reboot.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Continue here after uninstalling CounterSpy as requested.

    Okay let fix a few remaining items and also do a few more tweaks that will also improve performance.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Viewpoint Media Player (Remove Only)

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)

    After clicking Fix, exit HJT.
    Use Windows Explorer to delete the below if found:
    C:\Program Files\Video ActiveX Object <--- the whole folder:

    Now attach a new HJT logs and tell me how the above steps went.

    Make sure you tell me how things are working now!
     
  9. bonnielass

    bonnielass Private E-2

    Hi again! Counterspy removed and rebooted.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay continue with message number 8!
     
  11. bonnielass

    bonnielass Private E-2

    Video activex object wasnt there, followed all instructions and things seem to be working well. Hjt log is attached.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  13. bonnielass

    bonnielass Private E-2

    When i right click on my computer and select properties it doesnt give me the option to click on the system resource tab.

    If every thing is ok then i thank you and wish all those around you a very merry christmas and happy new year! If only everyone helped those around us like you have then it would be a different world we live in. Thank you:)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does your user account have Administrator priviledges?

    Try the below!

    Copy the bold text below to notepad. Save it as fixSR.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Does the System Restore tab show now!
     
  15. bonnielass

    bonnielass Private E-2

    Managed to get it and will follow the steps on how to protect against malware.Thanks again for your help chaslang!!!!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds