DeepScan:Generic apparent infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ron_possible, Jan 23, 2007.

  1. ron_possible

    ron_possible Private E-2

    First off, thanks for the forum; it helps to have a starting point in fixing problems. I'd appreciate some help in ridding this PC of the problem(s.)

    I've gone through "Read and Run Me First" from top to bottom, following the directions, and still see the same symptoms:

    Very slow windows boot in normal mode;
    very slow application response times in normal mode;
    Realplayer loads automatically;
    many processes load and stay resident.

    Various spyware/malware detection tools (as specified in the directions) have identified:

    adware888bar
    VBS/Psyme
    DeepScan:Generic.Mitglied.C9059518

    This note will include attached Counterspy, Bit Defender, and Panda ActiveScan logs.
     

    Attached Files:

  2. ron_possible

    ron_possible Private E-2

    Here are the second set of logfiles:

    GetRunKey
    ShowNew
    HijackThis
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    It appears that you have no antivirus application installed! Why?????? I see signs that McAfee was installed at one time but not it appears broken at best.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to McAfee Framework Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMcAfeeFramework into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_01

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run this ViewpointKiller to remove Viewpoint Media software.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Common Files\{E4B942B6-050F-1033-1114-010430200001} <--- the whole folder

    Now run Ccleaner.

    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. ron_possible

    ron_possible Private E-2

    First off, chaslang, thanks for the assist.

    In response to your question, I uninstalled McAfee because it appeared it was infected as well. Once I clean all the malware, w/ your help, I will uninstall CounterSpy (see #4 below) and reinstall McAfee.

    After following the latest set of directions below, here's what I see:

    1) the boot process is faster.
    2) RealPlayer, and the update, do not automatically start.
    3) the unexplained iexplore.exe process does not automatically start.
    4) CounterSpy seems to be a resource hog! Eventually the scans take less memory, but it does run for a bit.

    Short answer is that the problem SEEMS to be fixed. I'll continue to monitor. Logs requested are attached. Thanks, again, for your help.

    Ron
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is but it cleans lots of bad stuff. Our final steps always include steps to remove it anyway. But since we are finished with it anyway, let's dump it.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\nicole\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Before I can give you final steps, I need to see the follow up HJT log I requested. You forgot to attach it.

    Did you run ViewpointKiller? I still see Viewpoint Manager (Remove Only) in your newfiles.txt log. Run ViewpointKiller again and attach a log from it. I want to see what it is missing in removing this. Also run the below and attach a log from it as requested:

    Getting Uninstall Programs List From The Registry
     
  6. ron_possible

    ron_possible Private E-2

    Dang, didn't attach the HijackThis log from yesterday.

    Ok, CounterSpy uninstalled.

    C:\Documents and Settings\nicole\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software
    were both deleted.

    HJT run, log attached for today's run.

    ViewPointKiller run, log attached for today's run.

    UninstallProgramsFromRegistry log attached.

    Thanks, again

    Ron
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You attached a log from GetRunKey. I need the log from the GetUnKeys program I asked you to run. It is C:\GetUnKey.txt
     
  8. ron_possible

    ron_possible Private E-2

    Double Dang - can't follow directions!

    Here is the GetUnKeys log.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you did not use the kill Viewpoint Manager option in ViewpointKiller. Wasn't it reporting to you that it found Viewpoint Manager????

    Delete your old ViewpointKiller.log,
    Open ViewpointKiller,
    Select the File menu,
    Select Kill Viewpoint Manager,
    select Yes to the prompts,
    then attach the new Viewpointkiller log here.


    Also attach a new log from ShowNew.

    Other than the fact that reinstalling all the McAfee stuff has probably slowed your PC down to a crawl, how are things working.
     
    Last edited: Jan 25, 2007
  10. ron_possible

    ron_possible Private E-2

    Well, you're right about McAfee and slow.

    Got rid of old ViewpointKiller log.
    Killed Viewpoint manager.

    New Viewpointkiller log attached.

    Thx!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can always uninstall it and use something that will not be so resource hungry.

    Looks like it worked this time. You forgot the new ShowNew log I asked for.
     
  12. ron_possible

    ron_possible Private E-2

    (Very Belated) Thank you.

    Ron
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds