Followed Malware and Hijack This Guides, Here are the Logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by WtH1971, Apr 5, 2007.

  1. WtH1971

    WtH1971 Private E-2

    My computer had been getting progressively slower over the last couple fo months. I have run McAfee's Security Pack and used Ad-Aware SE Personal, Spybot Search and Destroy and Spyware Blaster for close to two years. Nevertheless, things kept getting worse until my DSL connection began running like a dial-up connection.

    FYI, before I began the Malware and HJT processes, I ran the step-by-step basic computer maintenance procedure you recommended. I also ran through a number of your recommended malware removal tools (Norman Malware, Avast, Kill2me, CWShredder, Kaspersky Free Cleaner) in Safe Mode with the System Restore shut off.

    CWShredder found and removed three tracking cookies and Kill2Me said it removed the Look2Me bug. The others found a clean system. However, my browsers (Firefox and IE) showed little improvement. So I decided to press on with the Malware process first and then the HJT process for good measure.

    The logs follow below:
     
  2. WtH1971

    WtH1971 Private E-2

    Note: I could not get either the Counterspy Log or the Panda Active Scan Log. I ran Counterspy and it found nothing, but when I couldn't download the log I ran the scan again immediately. The second time I got the same result (clean scan but no log).

    The Panda scan I had the same problem. I came up clean twice, but I could not get the log to download. As with the Counterspy, I ran the scan again right away. Being that all four scans came up clean, I shrugged and moved on to the next step hoping for the best.

    All of these process I ran with Internet Explorer. Counterspy was in safe mode. The Bitdefender and Panda scans were in regular boot mode per instructions.

    The HJT log will be in the next post.
     

    Attached Files:

  3. WtH1971

    WtH1971 Private E-2

    Here is the HJT log. Things seem to be going much faster on my browser now, but I just wanted you to check out what I have to make sure I'm not missing anything.

    Thanks for your help. This has been quite a learning experience so far. :cry
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on the logs posted thus far. You slow down is not due to malware. I have a few things for you to do which will help a little, but your problems may be due to what you are running. That is McAfee Security, SiteAdvisor, Google Toolbar AND Yahoo Toolbar and Yahoo Companion.

    Start by uninstalling the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also uninstall Viewpoint Media Player which should have been uninstalled in step 0 of the READ ME!

    You can also do the below which may help a little. Some of these are just unnecessary startups!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup

    After clicking Fix, exit HJT.

    Now reboot! Did doing the above help?
     
  5. WtH1971

    WtH1971 Private E-2

    Thanks very much. All of this did help and now the PC is running like its old self.

    I appreciate the time. ;)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds