Finished with READ & RUN ME FIRST!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lamilucy, Jul 17, 2007.

  1. lamilucy

    lamilucy Private E-2

    I have not asked any questions beforehand, but I have run all the steps in Read & Run Me First and here are the first 3 logs. Sure have learned a lot going through this, let me know how my computer looks.

    Remaining logs will follow.

    Thanks you geeks!!!!
     

    Attached Files:

  2. lamilucy

    lamilucy Private E-2

    OK, apparently my log from new files is too large, I will try to add to this post, if not, don't know what to do.

    OK won't work and I don't know what to do, will add other logs and wait for an answer.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your newfiles.txt log should not normally be too large to post unless
    • you have a ton of new files on your system
    • or you did not install it where requested and the folder you put it in has lots of files
    • or some strange error occurred
    You could put the newfiles.txt log into a ZIP file and attach it and then I will know why it is so large.

    You did not create the log from BitDefender as requested in the READ ME. All you attach is a scan summary and it is of no use to us.

    You need to uninstall BearShare if it is installed.

    However I have to ask what malware problems are you having? You did not tell us the reason for your post.
     
  4. lamilucy

    lamilucy Private E-2

    I'm sorry, I am so not a geek and this is all new to me, so forgive me. The problem I was having was having my browser hijacked and porn pop-up everywhere. Also, my newfiles.txt file is 273 mb and the limit is 250 on your post. Can I cut and paste part of it to a new txt file and sent it in two parts?
    To tell you the truth, I don't know how to make a zip file, only to upzip them.
    As for the bitdefender file, apparently I did something wrong, will try again and send you the file.

    I guess I need the Boot Camp, I want to be a geek like you.
     
  5. lamilucy

    lamilucy Private E-2

    OK, I ran another bdscan and have attached it. It does look different from the other one, although, I have no idea what I did wrong the last time. Hope this helps. Also, what to do about the newfiles scan?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think you mean 273 KB not 273 MB. ;) Split the file in half and attach it as two separate attachments (please do not post it inline as that will corrupt the formatting making it too hard to read).

    If you have WinZip installed, you can just right click on the file and select Add to Zip
     
  7. lamilucy

    lamilucy Private E-2

    You guys are so patient with all us non-geeks, so don't shoot me for asking this stupid question. What do you mean by not posting it in line? Does that mean on the same post?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The text you are reading in this message would be consider inline text. So if you just copied and pasted you logs into your message, that would be inline. What you did in your first two messages is the correct way to post logs and that is as attachments to your message. ;)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To keep you moving along, here are somethings to do even though I still need to see your log from ShowNew.

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Did you configure the below gophersearch settings yourself? If not, add them to the list of things to fix below with HJT.
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O8 - Extra context menu item: Web Rebates. - file://C:\PROGRAM FILES\WEBREBATES4\websrebates\webtrebates\toprC0.htm
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe (file missing)
    O9 - Extra button: (no name) - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - (no file)
    O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/21a798273d1864254e16/netzip/RdxIE601.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.20.19/ttinst.cab
    O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) - http://209.190.5.106/display/PopupSh.ocx
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\Profiles\ryan\Start Menu\Programs\lord of the rings.exe
    C:\WINDOWS\Profiles\ryan\My Documents\lord of the rings.exe
    C:\WINDOWS\SYSTEM\SBUtils\SBWinet.dll
    C:\WINDOWS\SYSTEM\SBUtils\SBWebCtl.dll
    C:\WINDOWS\SYSTEM\Popular Screensavers.scr
    C:\WINDOWS\Downloaded Program Files\PopupSh.ocx
    C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15-3.inf
    C:\WINDOWS\Profiles\vickie\My Documents\My Received Files\sinstaller2.exe
    C:\WINDOWS\Profiles\marcus\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\java.class-e96aca2-2914d5d0.class
    C:\WINDOWS\Profiles\alyssa\Application Data\Wildtangent\Cdacache\00\00\0B.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\WINDOWS\SYSTEM\SBUtils

    Now run Ccleaner!

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. lamilucy

    lamilucy Private E-2

    OK, here are my newfiles logs in two parts. And no, I did not configure gophersearch, don't even know where it came from, just that it kept hi-jacking my browser and changing my home page.

    Also, my son, 18, is adamately opposed to removing bearshare because he uses it to download music and says he can't download it again because the link is gone. Is there a major problem with bearshare, didn't notice any problems from it before.

    Ok, will start on the other assignments you've given me and we'll see what happens.

    I really appreciate your taking the time to help.
     
  11. lamilucy

    lamilucy Private E-2

    Opps, forget to attach the files! Duh!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not attach it! However wait until you complete my previous procedure and then get NEW logs from each of the below and attach them.
    • GetRunKey
    • ShowNew - split the file into two parts if still necessary. Make sure you are using the current version which is 0.36
    • HijackThis
    Bearshare comes bundled with malware. In addition no P2P download sites are really safe. They are the most frequent source of the malware problems people come to this forum to get removed. Did you notice it being detected in the log from SuperAntiSpyware. The below (also in your log) may have come from Bearshare
    • Adware.WhenU
    • Adware.MovieLand/MediaPipe
    • Adware.180solutions ZangoSearch
    • Adware.180solutions Seekmo
    • Adware.Zango Toolbar/Hb
    • Trojan.NewDotNet
    It's your PC in the end but there are safer tools to use that do not come bundled with malware. However, don't ask about them in this forum since we don't recommend any of these programs be installed. Some forums will not even work on malware removal until all P2P or torrent type downloaders are uninstalled.
     
  13. lamilucy

    lamilucy Private E-2

    OK, finished HJT and deleting files, and have run ccleaner, things are working fine now. Will run getrunkey, shownew, and HJT again and will send logs. In the meantime, here are the logs from shownew I thought I attached yesterday, don't know what happened there!
     
  14. lamilucy

    lamilucy Private E-2

    They didn't attach again, I put them in and uploaded, what happened?
     
  15. lamilucy

    lamilucy Private E-2

    OK, finished all of the above, my newfiles logs were still too large so I had to break them into three, will attach all logs and wait for you to tell me what to do next. I did get a rename message when I deleted C:\WINDOWS\SYSTEM\SBUtils
     
  16. lamilucy

    lamilucy Private E-2

    Something is wrong, my attachments are not uploading, HELP!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only attach the new logs! If you are still having problems attaching files, make sure you watch for error messages in the Manage Atttachments window. The errors do not standout and you could miss them. Make sure the files are not too large. Also if you have problems here are other tips they may help:
    • only upload one file at a time. Then try uploading the 2nd, and then the 3rd. Remember only three can be attach in one message.
    • click Refresh a couple of times and them try again.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you are talking about with a rename message??
     
  19. lamilucy

    lamilucy Private E-2

    A window popped up and said that renaming, deleting, or something else to this file may cause problems, don't remember exactly what it said.

    Trying again to attach logs.
     

    Attached Files:

  20. lamilucy

    lamilucy Private E-2

    Yeah it worked, here are the other ones.
     

    Attached Files:

  21. lamilucy

    lamilucy Private E-2

    It is telling me that I have already attached the HJT log, did you get it, won't let me attach it again.
     
  22. lamilucy

    lamilucy Private E-2

    Trying one more time to attach HJT log
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you are attached the same old log! You must get a new log (from today) as requested and attach it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below unnecessary files
    C:\Program Files\analyse.exe
    C:\Program Files\ccsetup140_slim.exe

    Delete the below folders. The first is malware
    C:\Program Files\NewDotNet
    C:\Program Files\Analysethis

    Uninstall the below old Sun Java Versions
    J2SE Runtime Environment 5.0 Update 7
    Java 2 Runtime Environment, SE v1.4.2_10

    Since I still see Bearshare, I assume this means you have decided to keep it and the malware that comes with it?
     
  25. lamilucy

    lamilucy Private E-2

    OK, I deleted everything you told me to delete. The add/remove programs in the control panel will not let me uninstall the Java files you told me to uninstall. It tells me that this action only applies to programs that are installed. Is there another way to do it? Also, yes I plan to unstall bearshare, but I need to find another program he can use that is compatible with me. Can you point me in the right direction to look for one?

    Think we are almost done?

    Can't tell you how much I appreciate you help.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost. As I stated in my previous message you need to attach a new HJT log from today. The last log you posted was from 7/16/2007 and it still shows all the items I asked you to fixing including the gophersearch.com stuff which you said you did not configure. I also stated you should add those to the list of things to fix with HJT.
     
  27. lamilucy

    lamilucy Private E-2

    Ok, I'm sure you are quite tired of me by now, but here we go. I have run another HJT log, the other one must have been in the analysethis folder that you told me to delete. As you will see, I unstalled bearshare, but my son reinstalled it last night. As soon as he gets his music downloaded onto disk, I will uninstall again.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to delete the below:
    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    And only use the renamed file in the future (if you have malware problems again):
    C:\PROGRAM FILES\HIJACKTHIS\ANALYSE.EXE


    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  29. lamilucy

    lamilucy Private E-2

    Chaslang,

    Finished with above and computer is running great. Thank you so much for your time. I've learned a lot and will continue to learn from this site. You guys are awesome.

    Thanks again!!!!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds