did all the steps. attached is all the logs.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Adzan, Apr 13, 2007.

  1. Adzan

    Adzan Private E-2

    im still quite lost.. but i did all the steps. posting the logs..
     

    Attached Files:

  2. Adzan

    Adzan Private E-2

    this is the other two logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O23 - Service: chiu888.3322.org - Unknown owner - C:\WINDOWS\system32\chiu888.3322.org.exe (file missing)
    O23 - Service: Remote Procedure Call System(RPCS) (RpcS) - Unknown owner - C:\WINDOWS\system32\RpcS.exe (file missing)
    O23 - Service: Print Spoolres (spoolers) - Unknown owner - C:\Program.exe (file missing)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\Totem Shared\Update\WindowsEx.dll.041
    C:\WINDOWS\Downloaded Program Files\607008.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. Adzan

    Adzan Private E-2

    all the steps ran smoothly.. i think its going to be okay right?

    btw.. i deleted my norton anti virus which has already expired years ago..
    is it safe for my comp or do i need to get a new one?
    could you recommend me a good anti virus? a freeware anti virus would be good..
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download any of the freeware anti-viruses here: http://www.majorgeeks.com/page.php?id=20

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Remote Procedure Call System
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    *Do the same for - Print Spoolres.
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste RpcS into the box that opens, and press OK.
    * Do the same for - spoolers.
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Internet Explorer\down(0).exe
    C:\Program Files\Internet Explorer\down(1).exe
    C:\Program Files\Internet Explorer\iexprt.cn
    C:\WINDOWS\3917812.dll
    C:\WINDOWS\WHKEY.DLL
    C:\WINDOWS\wh.DLL
    C:\WINDOWS\system32\Systen.dll
    C:\WINDOWS\system32\RpcS.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
    Last edited: Apr 14, 2007
  6. Adzan

    Adzan Private E-2

    during the HJT procedure i only manage to find this line.

    O20 - Winlogon Notify: BITS - C:\WINDOWS\System32\Systen.dll

    is it because i miss some steps?

    anyway.. i just choose that and continued.

    this is the latest logs.. btw.. thanks for helping me till this stage..
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to find these programs and uninstall them:
    C:\Documents and Settings\Adzan\Application Data\SystemDoctor 2006 Free
    C:\Program Files\Common Files\DriveCleaner Free
    They are both roque programs that will give you false popup warnings.

    For some reason, your shownew log is not showing all of it....it is missing your add/remove program list.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/chzl/default/popcaploader_v10.cab
    O20 - Winlogon Notify: BITS - C:\WINDOWS\System32\Systen.dll (file missing)

    After clicking fix, just exit HJT

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds