Just double checking....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lpontius1, Jul 29, 2008.

  1. lpontius1

    lpontius1 Private E-2

    Had a browser/desktop hijacker coupled w/ an annoying "buy this anti-spyware package" spyware program.I just want to make sure it is absolutely gone and there's nothing else waiting to surprise me later.

    (I'm installing protection software as we speak, so hopefully this won't happen again on this computer.)

    Thanks!
     

    Attached Files:

  2. lpontius1

    lpontius1 Private E-2

    Also here is my mglogs.zip file...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have some more workt to do along with getting properly protected.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of Sun Java as requested in step 1 of the READ & RUN ME.
    Java 2 Runtime Environment, SE v1.4.1
    Java 2 Runtime Environment, SE v1.4.2_07
    Java(TM) 6 Update 2

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [s9201] "C:\Documents and Settings\All Users.WINDOWS\Application Data\SecuriSoft SARL\WinSpywareProtect\wspwprtct.exe" /autorun
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O20 - AppInit_DLLs:

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. lpontius1

    lpontius1 Private E-2

    Hello again! I ended up installing AVG 8.0 & ThreatFire. System seemed to become unstable so I uninstalled Threatfire. I'll be looking into antispyware software to find something else to use. I ended up having to do system restore twice b/c Internet Explorer & Control Panel would not run and the computer would hang during shut down. At one point, Windows was shutting down for about 5 hours. Those problems were all fixed by the system restores.

    I was not able to uninstall Java 2 Runtime Environment, SE v 1.4.1. I received this error: "The Install Shield Engine (IKernel.exe) could not be launched. No such interface supported.) I did try to uninstall several times, but eventually (after about 3rd or 4th try) Add or Remove Programs froze and I had to restart.

    When I ran analyse.exe, I noticed some entries for Adobe Photo Downloader & AOL Fast Start. These are not in the Add or Remove Programs list and I don't really want them, so how would I remove them?

    Fixme.reg was successfully entered into the registry.

    I tried to attach the combofix.txt file, but it is 760KB and the attachment manager would not let me. I'm not sure why it is so large b/c the last combo fix log was not anywhere near that big.

    So anyway, many thanks, you guys are always life savers... :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just an FYI for the future. Once you start working in a forum like this to remove malware, do not do anything on your own. Only do what we requested. Doing otherwise can cause problems and/or confusion. It is best to wait until we have finished our work and then you can do what you like.

    Copy the bold text below to notepad. Save it as fixJava.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Are you referring to lines you see in HijackThis.

    AOL does not appear to be installed, so you can do the below to remove to service:

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to AOL Connectivity Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteAOL ACS into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but and reboot when it tells you it needs to.

    After reboot, delete the below folder if it exists:
    C:\Program Files\Common Files\AOL


    Your PC shows the below is installed from Adobe, which is where all your Adobe items have come from.
    Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
    Adobe Flash Player 9 ActiveX
    Adobe Flash Player ActiveX
    Adobe Reader 8.1.0
    Adobe Reader 8.1.2 Security Update 1 (KB403742)
    Adobe Reader 8.1.2
    Adobe Shockwave Player
    Adobe SVG Viewer 3.0
    Adober Photoshopr Album Starter Edition 3.2


    You can compress it into a ZIP file and attach it; however it looks like everything worked.

    Your logs are clean. Are you having any other malware problems.
     
  6. lpontius1

    lpontius1 Private E-2

    The computer appears to be running much better now and I'm not noticing anything that sets off any alarm bells, but I included the latest combofix log just in case you wanted to take a look.

    Anyway, many many thanks for all your time! You guys are awesome :cool!!!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log is clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds