Is my PC clean? Please check my files

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by StillKickin290, Feb 10, 2008.

  1. StillKickin290

    StillKickin290 Private E-2

    Hi,
    I’d greatly appreciate some help examining my scan files (I didn’t get a report from AVG, but the ComboFix and MGtools zip files are attached). The zip files are pasword protected as requested by chaslang.

    My SpyBot S&D scan came up clean and AVG Anti-Spyware only found a tracking cookie, but here’s some background info on my PC that could be useful:

    1) About 2 weeks ago I got a pop-up message saying D E P had stopped a program from running in a protected area. The program listed in the pop-up was Windows Explorer (!).

    2) My PC hung during AVG AntiVirus UN-install (MG instructions said to only have 1 AntiVirus package and I also have CA eTrust AV) and I had to eventually “kill” the uninstall process. Now AVG AntiVirus doesn’t/can’t run anymore but it’s not completely un-installed (still shows in my Start Menu).

    3) The last several times I’ve turned off my PC, I get a window saying “CAV Tray not responding” (even though CA anti-virus normally appears to be up and running fine).

    Any help will be greatly appreciated!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just wanted to other helpers know I'm working this thread, and also to let you know I was able to extract the files from the ZIP.

    I will look at your logs and let you know what I see.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you setup your new computer, do not use your family name anywhere.

    Let's take care of the left overs from AVG AntiVirus.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to AVG7 Alert Manager Server
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • AVG7 Update Service
      • AVG E-mail Scanner
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste Avg7Alrt into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • Avg7UpdSvc
      • AVGEMS
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Delete the below files.
    C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\SET8FD.tmp
    C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\SET8FE.tmp
    C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\SET901.tmp
    C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\SET902.tmp

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.


    Here are a couple things you missed from step 1 of the READ ME.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 9
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now delete the below folder if it still exists:
    C:\Program Files\Grisoft\AVG7


    There is only one item I see in your logs that I question and I get hits on it only at Asian websites and one German site. Do you know what the below file is:
    C:\WINDOWS\System32\EBUtil2.dll

    It is hooked into winlogon.exe, explorer.exe, and spoolsv.exe. If unknown, put it into a ZIP file and attach it here.

    Are you having any problems?
     
  4. StillKickin290

    StillKickin290 Private E-2

    I might not finish all the steps you listed until after I get home from work today, but I since I don't know what the EBUtil2.dll file is I thought I'd post it per your request.

    Thanks so much for the help.
     

    Attached Files:

  5. StillKickin290

    StillKickin290 Private E-2

    I realize that "bumping" this thread will push me down the list, but I wanted to let chaslang know that I did all the procedures in his post and everything went fine. The requested questionable .dll file is attached to my previous post.

    Thanks again for all your help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a problem. It is a file related to Epson printers.

    Are you having any problems at this time? If not, work thru the below:


    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    2. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    3. After doing the above, you should work thru the below link:
     
  7. StillKickin290

    StillKickin290 Private E-2

    System Changes after Running ComboFix and MGTools

    After running the recommended cleaning procedure, including ComboFix and MGTools, my system had three changes:

    1) My screen saver was turned off
    2) My default browser was switched from Firefox to Internet Explorer
    3) My clock was changed to "military time" display and the date order is reversed from how it was; (ie, it currently says 2008-02-12)

    I'd first like to double check that these are "normal" changes (it's happened two times now).

    Second, I was able to easily correct the first two items, but I can't figure out how to change the format of my clock back - the clock properties don't have any options for view formatting. The clock thing is no big deal, I'd mainly like to make sure these are "normal" changes since they aren't mentioned in the sticky.

    Thanks
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: System Changes after Running ComboFix and MGTools

    Did you do all of the final steps I gave you in your thread where you should have posted this message? ( In fact, I'm merging you back to that thread too.) Did you do the combofix /u

    Normally when ComboFix finishes running the standard clock time is already re-established. The Uninstall is also supposed to correct it.

    However resetting the clock yourself pretty easy to do. You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    The screen saver and browser change are typical effects of running cleaning procedures. Since so many malware programs hijack desktops and browsers and manipulate registry keys, the easiest thing for cleaning programs to do is to put them back to defaults because it is too difficult to really distinguish between things you may have configured and what malware may have done.
     
  9. StillKickin290

    StillKickin290 Private E-2

    Thanks for the instructions. My clock was reset to the correct time after the original cleaning procedure, just with a different display format. Running combofix /u also didn't correct the format, but the helpful instructions you gave did allow me to do so manually via Control Panel -> Regional Language Options.

    Sorry for starting a new thread. I did so because I thought that the questions about the browser change, etc were of general interest to anyone using the MG cleaning procedure, not specific to my original problem, and I'm not up on MG posting protocols. Thanks for merging them.

    This may not be important, but I had to run combofix /u twice before it completed the uninstall. The first time it started working (progress bar moved) and then up popped a message saying "Windows can not find C:\WINDOWS\System32\Kmd.exe. Make sure you typed the name correctly...". (Note: Combofix WAS installed to my desktop)

    I tried a second time (without changing the text in the RUN field, which was typed correctly...with the space). This time two different command windows opened for a minute and then I got a message saying "Combofix is uninstalled".

    I guess I'm suspicious of everything my PC does that's a little abnormal! If the above behavior is not of concern, then I suppose I'm all done for now. I'll post any additional malware related questions to this same thread. Thanks again for all the help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix is just behaving a little strange lately. There have been some new features added (kmd.exe) is one and all the bugs are not quite worked out yet. Thanks for the feedback as others may run into the same behavior.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds