Infected Computer, requesting assistance please.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dabluebery, Apr 4, 2007.

  1. dabluebery

    dabluebery Private E-2

    Hi Everyone, First post here.

    My computer is very sick with adware, I'm sure of. I've been through this before and I'm only slightly retarded so usually I can fix problems myself, but right now I'm in over my head.

    I'm getting unsolicited popups with browsers running & without browsers running, appearing out of nowhere.

    I've also had something open up an Outlook Express Email, fill it out, and leave it for me to send, asking for some kind of software solicitations.

    Third bad thing that happens is for some reason, when I right click on something (from my desktop, like "my computer," let's say) the computer starts installing software. It says it's Symantec Antivirus but I can't imagine why a legitimate program would operate this way.

    I've run all of the steps required for you guys to offer assistance and didn't have many problems. The only problem I had, where I deviated from your instructions, was when I ran counterspy. It didn't let me quarantine anything in safe mode, so I ran it in Windows "Normal" startup.

    In looking at everything, I can tell there are some problems but I've given up on tackling them on my own because I don't seem to be finding the root problems, just the obvious stuff that happens as a result of the underlying issues.

    Obviously the BHO's and the O20 tying itself to Winlogon are major bad news but I've been unable to remove those files and I'm throwing the towel in and asking for help. To follow are my attachments for all the tools I ran, at your request.

    Thanks in advance, I appreciate it.
     

    Attached Files:

  2. dabluebery

    dabluebery Private E-2

    Some more files for your review.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  4. dabluebery

    dabluebery Private E-2

    Hi. Thanks for checking in. I ran the combofix and have new files. I'm not sweating the fact that I still have popups and such because I don't think we tackled those yet. Files for review;
     

    Attached Files:

  5. dabluebery

    dabluebery Private E-2

    And who could forget Hijack this;
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's correct! ;) We are going to fix them now.

    You are have Mozilla Firefox (1.0.7) installed. This is extremely out of date and is a security risk. Uninstall this old version and install the new versions from: Mozilla Firefox

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Do you know what the below fairly new files are from?
    Code:
    C:\WINDOWS\system32\drivers\
    core.sys      Mar 31 2007       72320  "core.sys"
    coreca~1.dsk  Mar 31 2007      182323  "core.cache.dsk"

    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of kbddlv.dll once and then click the kill button. After you have killed all of the kbddlv.dll under winlogon click ok. (If you do not find the dll, just continue on.)
    Next double click on explorer.exe and again click once on each instance of kbddlv.dll and kill it. (If you do not find the dll, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of kbddlv.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {a37ae940-26ef-4e60-8986-9fb58f5df09c} - C:\WINDOWS\system32\kbddlv.dllsinst.cab
    O20 - Winlogon Notify: kbddlv - C:\WINDOWS\SYSTEM32\kbddlv.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\system32\fontqxet.dll
    C:\WINDOWS\system32\kbddlv.dll
    C:\WINDOWS\system32\rasqervy.dll
    C:\WINDOWS\system32\sdfinacs.dll
    C:\WINDOWS\system32\wuasirvy.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Documents and Settings\Marek\Application Data\Viewpoint

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  7. dabluebery

    dabluebery Private E-2

    Thanks for your help so far.

    Your first question was about those two files that are located in "system32/drivers". I have no idea what they are.

    All of the steps you gave me worked fine. I've created and attached the files you asked for.

    I still have problems, even after reboot. The "right click" problem, for starters. All of these stupid anti-virus scanners pop up with messages about infections. When I ran my hijack this log, I noticed there were several things there which I'd normally delete, because I know they're bad. These are new files which have appeared since the last Hijack log I uploaded. I resisted the urge to delete them because I figure you know best anyway.

    I'm trying to minimize the damage and I've noticed that using a browser escalates the problem. Starting with the last round of steps, I'm not opening a browser at all on the infected computer. I made all the updates and changes you suggested by transferring files back and forth via email between my laptop and my desktop. I'm posting to you now from my laptop.

    Thanks again, here are new files.....
     

    Attached Files:

  8. dabluebery

    dabluebery Private E-2

    Is there a specific name for what I've caught? Or names?

    In general, why did I get sick in the first place?

    I admit I have been, to this point, generally averse to protective software. In the past, I've caught things before, but nothing as severe as this infection, which has been seriously hindering me for almost a week. Usually when I've caught something previously, it's not so serious that I can't fix it myself with a little browsing and learning. This is the first time I've truly been in completely over my head.

    Since the problems I've encountered have been relatively minor, I considered them past of the "cost of doing business." In other words, I found those problems and fixing them more palatable than running strict software that I felt was too invasive and too much work for not enough "protection" reward. If I have to 'Ok' 1000 good files to protect myself from the 1 bad file, it's not worth it.

    This may no longer be true, after my bout with whatever this is.

    Can someone suggest a plan for protecting myself in the future, considering these factors? A protection piece that's minimally invasive, a software package that won't try to control other aspects of the computer that I like to handle myself, etc.

    I suspect it's just not possible. Maybe I should switch to a less prevalent, less exploited operating system if I revel so much the "lassiez faire" approach, and use emulators for PC software I "need."

    Again, thanks for all the help.

    Rob
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had and still have a variety of problems! Names are not always too important since each scanning type program may refer to them by a different name. To name just a few:
    • PurityScan
    • NewDotNet
    • Virtumonde and WinlogonHook
    • Trojan.Downloader-Heltrans.Process aka Troj/Banker-FAT
    Could be any number of reasons
    • inadequate and/or outdated protection
    • non-updated software including your Windows OS
    • poor surfing and downloading habits
    • not being careful what you click on including things in emails
    • ..............etc.
    The stickies cover this and we will point this out in final steps too, but no protection software is perfect. And the key lies with you being better educated and being more careful.

    Not true! I'm probably connected and do more surfing than most people and I never have any infections. Again responsibilities begin and end with you.

    Let's continue with your fixes!!! I'll post the next steps in another message.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
    O2 - BHO: DeskalertsBHO - {5298B64F-C3F6-4e81-8A30-627CA3671C7C} - C:\Program Files\DeskAlerts\deskbar.dll (file missing)
    O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\tmp1B4.tmp.dll
    O2 - BHO: (no name) - {5B8976BC-7699-8F2F-6398-07AC89B85F56} - C:\WINDOWS\system32\ffuscnk.dll
    O2 - BHO: 0 - {6A92454D-DDC7-4E99-469B-5621BC497E9F} - C:\Program Files\Internet Explorer\lafuveni.dll (file missing)
    O2 - BHO: Helper Class - {890C7964-9320-4055-BE11-7D7B562A6417} - C:\WINDOWS\system32\mstrans.dll
    O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [nwpiolh.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nwpiolh.dll,hzdgzkg
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s

    After clicking Fix, exit HJT.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Internet Explorer\lafuveni.dll
    C:\Program Files\NewDotNet\newdotnet7_48.dll
    C:\WINDOWS\funnies.exe
    C:\WINDOWS\NDNuninstall6_38.exe
    C:\WINDOWS\NDNuninstall7_48.exe
    C:\WINDOWS\system32\ffuscnk.dll
    C:\WINDOWS\system32\lsasss.exe
    C:\WINDOWS\system32\mstrans.dll
    C:\WINDOWS\system32\nwpiolh.dll
    C:\WINDOWS\system32\tmp1B4.tmp.dll
    C:\WINDOWS\system32\cookie.dat
    C:\WINDOWS\system32\ps.dat
    C:\WINDOWS\system32\wab.dat
    C:\WINDOWS\system32\drivers\core.sys
    C:\WINDOWS\system32\drivers\core.cache.dsk
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\NewDotNet
    C:\Program Files\DeskAlerts

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  11. dabluebery

    dabluebery Private E-2

    Hi.

    I ran the first bunch of steps you asked for, but was unable to delete the file "newdotnet7_48.dll"

    It is in use, and can't be deleted. Also, when I deleted both the program files folders you asked for, it started installing the "Symantec Antivirus" thing that keeps popping up. Even when I double click the folder or perform any action relating to those files, it does this.

    So, this software is installing itself under the following circumstances;

    1) right-clicking on any file or the desktop
    2) clicking on any of the folders or files within you asked me to delete (clicking, double clicking, right clicking, deleting, etc.)

    I have included the files you asked for. I don't know how the browsers are running because as I already mentioned, I don't need to run them to post to you.

    Oh, one last thing. I followed an instinct and deleted an extra set of (O2 / O4) files in Hijack this.... for "web buying". This keeps reappearing, and was something I deleted before I sought assistance from you in the first place. Sorry for deleting these files. I deleted the corresponding 'Program Files' folder for this application, and it gave me the same "clicking" trouble with installing software.

    Rob
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Web Buying is something that was installed. You need to go to Add/Remove programs and uninstall it if you do not want it.

    Also uninstall New.net Domains 7.48

    I believe your Symantec Antivirus may be infected. Please uninstall it and then run the below tool:

    Norton Removal Tool (SymNRT)

    Then delete all visible folder you see from Symantec or Norton. There will be a bunch. You can quickly see a few by looking in your log from ShowNew and searching for Symantec.

    Then attach new logs from
    • GetRunKey
    • ShowNew
    • HJT
     
  13. dabluebery

    dabluebery Private E-2

    Ok.

    I've done the latest step. Fortunately, the "clicking - software" installing problem is gone. After I ran the Norton removal tool, and completed the required startup, I was greeted with a popup on Windows reboot which was (I believe) a symantec page that was talking about how my browser had been hijacked and I was at risk. I didn't deal with it, just closed it as soon as I could.

    I deleted as many Norton and Symantec folders as I could find. Not sure if I got all of them. Gun to my head, I seriously doubt it.

    New files included. Still not opening a browser because I speculate that we're still getting there. But maybe I see light at the end of the blah blah blah....
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Pocket Killbox and select File, Cleanup, Delete All Backups

    You don't really need to keep alot of the stuff you are storing in the below folder:
    "C:\Documents and Settings\Marek\Desktop\Virus Stuff\"

    Much of this is logs that you already attached here and thus is is already saved.
    And other items are things you don't need long term like:
    Code:
    avgas-~1.exe  Apr  2 2007     6469352  "avgas-setup-7.5.0.50.exe"
    ccsetu~1.exe  Apr  3 2007      460320  "ccsetup138_slim.exe"
    counte~1.exe  Apr  3 2007    37514904  "counterspy.exe"
    hijack~2.exe  Feb 16 2005      218112  "HijackThis.exe"     [COLOR=purple][B]<-- the proper one is already in  C:\Program Files\HiJackThis[/B][/COLOR]
    jre-6u~1.exe  Apr  3 2007    13801120  "jre-6u1-windows-i586-p.exe"
    norton~1.exe  Mar 31 2007      816736  "Norton_Removal_Tool.exe"
    proces~1.htm  Apr  5 2007       53240  "Process_Explorer_d4566.htm"  [B][COLOR=purple]<-- should have been in its own folder like many other things[/COLOR][/B]
    proces~1.zip  Apr  5 2007     1539243  "ProcessExplorer.zip" [B][COLOR=purple]<-- should have been in its own folder like many other things[/COLOR][/B]
    procexp.chm   Aug 16 2006       72056  "procexp.chm" [B][COLOR=purple]<-- should have been in its own folder like many other things[/COLOR][/B]
    procexp.exe   Nov  1 2006     3623736  "procexp.exe" [B][COLOR=purple]<-- should have been in its own folder like many other things[/COLOR][/B]
    spybot~1.exe  Apr  2 2007     5037072  "spybotsd14.exe"
    taskma~1.exe  Apr  1 2007     1542248  "taskmanager17.exe"
    vundofix.exe  Mar 31 2007       96768  "VundoFix.exe"
    xpprof~1.exe  Apr  3 2007       94208  "XPProfiles.exe"

    What is the below file?
    "C:\Documents and Settings\Marek\My Documents\"
    sav101~1.exe Mar 31 2007 30607182 "sav10.1.5u.exe"

    What is in the below two folders?
    "C:\Documents and Settings\All Users\Application Data\
    {1DCE7~1 Mar 24 2007 "{1DCE73BC-3833-4B83-9956-133C60FF6A24}"
    {7EE9B~1 Feb 18 2007 "{7EE9BBE6-99A6-4999-8EE3-4C523FE97C43}"

    Can you now delete the below folder?
    C:\Program Files\NewDotNet

    Also delete the below folders:
    C:\QooBox
    C:\VundoFix Backups

    Also delete the below files:
    C:\ComboFix.txt
    C:\ComboFix-quarantined-files.txt
    C:\FxNdotN.exe
    C:\FxNdotN.log
    C:\VundoFix.txt

    Did you forget to fix the below files with Killbox or did it not fix them?
    C:\WINDOWS\system32\drivers\core.sys
    C:\WINDOWS\system32\drivers\core.cache.dsk

    Was your HJT log obtained before uninstalling Symantec? I still see some of it running. I will post a fix for that in my next message.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Event Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Symantec AntiVirus Definition Watcher
      • LiveUpdate
      • SAVRoam
      • Symantec Network Drivers Service
      • Symantec SPBBCSvc
      • Symantec AntiVirus
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste ccEvtMgr into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • DefWatch
      • LiveUpdate
      • SavRoam
      • SNDSrvc
      • SPBBCSvc
      • Symantec AntiVirus
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Now restart HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now locate the below folder and delete it if found:
    C:\Program Files\Common Files\Symantec Shared
    C:\Program Files\Symantec AntiVirus

    Now run Ccleaner
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  16. dabluebery

    dabluebery Private E-2

    Hi.

    I am going out so I didn't do some of the little things like reorganize and delete files I don't need because I wanted to send an update ASAP.

    You asked me what the files and folders were in your first message. I have no idea what they are. Hopefully nothing I'd miss, I wait for you advice on them.

    I still cannot delete the newdotnet folder and it is appearing in my hijack this logs even after I try and fix them.

    I don't think I forgot to delete files with killbox but I did this time around.

    I'm guessing I ran HJT before I deleted all the symantec stuff (though I thought I was smarter than that) In any event, most of the following instructions you gave me about deleting symantec and norton stuff was irrelevent because I didn't find most of the files. For example, none of the stuff you told me in "services.msc" was even there.

    Ok, that's all for now. Thanks.

    Rob
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But one questions was not do you know it was what is in the folder:
    For the C:\Documents and Settings\Marek\My Documents\sav10.1.5u.exe file, just delete it.

    Uninstall AVG AntiSpyware and shutdown SpySubtract (did you purchase SpySubtract), then try fixing the line in HJT. Then reboot into safe mode and try deleting the folder.

    Any luck?
     
  18. dabluebery

    dabluebery Private E-2

    Hi.

    In both those random folder names, there were separate versions of a computer game I play, called "Baseball Mogul." It's a text-based sim and I seriously doubt there's anything wrong with them. They were beta last month, and came out with the 2008 version this month. I trust this stuff.

    I uninstalled and shut down what you asked, but could not delete the newdotnet object in hijack this. It deleted, then just reappeared.

    However, on restart in safe mode, I ran hijackthis again, deleted the file (seemingly successfully) and then deleted the folder, no problem

    You didn't ask, but I've posted a group of very recent logs, since I did that stuff and rebooted in normal mode.

    Rob
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. Now you need to get protection software (antivirus, antispyware, and firewall) in place which will be covered in the link at the end of the below steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. dabluebery

    dabluebery Private E-2

    Chas,

    Something is still wrong. Everything is much better, but I'm still getting popups in and out of browser sessions.

    Rob

    Next steps, please. I haven't deleted anything yet from our virus regimen.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in message # 14, I ask you if your forgot to have Pocket Killbox fix the below files
    Code:
    "C:\WINDOWS\system32\drivers\"
    core.sys      Mar 31 2007       72320  "core.sys"
    coreca~1.dsk  Apr  6 2007      161849  "core.cache.dsk"
    I don't think you ever answered.

    Try fixing them again!

    Download the current version of ShowNew just updated last night. Attach a new log from ShowNew.
     
  22. dabluebery

    dabluebery Private E-2

    I deleted those files and am currently still getting popups in IE. I haven't had time to download the good stuff yet, I planned on doing so once I was clean. I hope I haven't infected myself with more crap by opening a browser prematurely. Popups have more or less stopped when outside a browser so we're getting there. Thanks for your help.

    File......
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not get them deleted. They are still there. Put them into a ZIP file and attach them here.

    You MUST install an antivirus and firewall NOW.
     
  24. dabluebery

    dabluebery Private E-2

    I've been away for a few days. You most recently asked me to put those files in a zip folder and post them. I cannot, they are in use.

    Rob
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try doing it in safe mode. Also when zipping the first file, just right click on it and select Add to Zip which should create a new zip file with a simiar name to the file being zip (that is assuming you have WinZip). Then just drag anf drop the other files to the ZIP.
     
  26. dabluebery

    dabluebery Private E-2

    here they are
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download FileASSASSIN and save to your desktop

    Create a new folder on C:\ called FileASSASSIN and extract (unzip) it to that folder.
    • Now print the below instructions because you need to reboot into safe mode and keep all browsers and other unnecessary applications closed before doing the below.
    • Once in safe mode, open the C:\FileASSASSIN folder and double-click on FileASSASSIN.exe.
    • Select the following files to delete by copying and pasting onto the text area or select it using the (...) browse button.
    C:\WINDOWS\system32\drivers\core.sys
    C:\WINDOWS\system32\drivers\core.cache.dsk



    • Select a removal method. Start with "Attempt FileASSASSIN's method of file removal."
    • Click delete and the removal process will begin.
    • If that did not work then, start FileASSASSIN again and this time check "Use delete on reboot function from windows.".
    After doing the above, reboot into normal mode and attach a new log from ShowNew.

    Are things running OK?
     
  28. dabluebery

    dabluebery Private E-2

    Hey. The computer is running pretty well. I'm using my browser right now, no popups, which is a change only since I deleted those files. New file attached.

    Will you be able to ascertain everything from this file, like if I reinfected myself with something along the way?

    Thanks for all your help so far.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You clean! Just delete the zip file we made:
    C:\WINDOWS\system32\drivers\core.zip

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds