malware-virus about blank

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mcejsul, Jan 23, 2007.

  1. mcejsul

    mcejsul Private E-2

    Not quite sure howthis all happened? Hadn't use LapTop( Dell Inspiron 600M, Windows XP) in a while do I thought I would go to Dell Support and update. Started to download a driver and thing my computer started freaking out.
    Received an "adriss.exe" error nd did asearch whichbrought me to a thread on this site. also have "taskdir.exe" and about :Blank amoung other things. Everthing happened after this download.
    I tried my best to run through all of the procedures listed in the read me process.
    I will try to upload attachments but first time sobear with me.
    Thanks, in advance.

    MCEJSUL
     

    Attached Files:

  2. mcejsul

    mcejsul Private E-2

    Here ae a couple more of the reports that I was able to get.
    mcejsul
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are alot of things we need to do, but lets start with this:


    Download Pocket KillBox Save it to your desktop or a place easy to find.
    Do not run it yet.


    Re-Run Counterspy and have it remove/quarantine all items.


    spywaresheriffremoval


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Next, you will be entering items into Pocket KillBox. Please select the “Delete on Reboot” Option. Copy&Paste each of the file names listed below into the box one by one, making sure Delete on Reboot is Checked for each entry. Click the Red X for each entry, but DO NOT Allow your machine to be rebooted until the last item has been entered:


    Once you have completed this fix attach:
    HJT log
    ShowNew
    GetRun

    Let me know how things are running.
     
  4. mcejsul

    mcejsul Private E-2

    TimW,

    Thank you for your assistance. I think I followed all of your steps, the spyware sheriff removal(Did not find any of these files listed), Poket Killbox. Attached are the three files you requested.

    Thanks
    Mike
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fix.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.




    Use Pocket KillBox to delete the following:

    Is this your Internet home page = http://earthswellness.unfranchise.com/?

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey - please download the current version first!
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  6. mcejsul

    mcejsul Private E-2

    TIM,
    After I did this I thought I proably should have waited until we were done. However, i downloaded IE 7. will this mess up what We have done so far?
    Or am I set to follow your next steps?
    Sorry about that.
    Mike
     
  7. mcejsul

    mcejsul Private E-2

    Tim,

    Here are the files you requested after I did what you said in your last post.
    My Home page is www.earthewellness.unfranchise.com. I am a distributor in a network marketing company.
    Things seem to be running OK. I do have difficulty getting to a couple of websites I usually frequent. Such as www.cbssportline.com. i will click on thefavorite andit will begin to load and then I will get a "IE has to close...do you want to senderror report.
    One of the programs (McAfee perhaps?) will give me a "Buffer overload" message when going to somesites.
    On start up, I have also received a "C:\windows\system32\mfplat.dll is not a valid windos image" error.
    I have also had difficulty recognizing my Wireless network but I'm sure that is a totally other issue.
    Tnaks again
    Mike
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are looking clean.

    I would suggest that you uninstall IE7 (it will revert back to IE6) and see if that helps. If you wish to keep IE7, you may want to peruse the software section or post a thread there for IE7 fixes.

    You may uninstall any software that we had you download for the analysis.

    Then run CCleaner.

    A google search for mfplat.dll will get you the download for that .dll. You could first try renaming it to mfplatold.dll and restart the computer. It should reinstall the correct one.

    Be sure to read this thread: How to Protect yourself from Malware.
     
  9. mcejsul

    mcejsul Private E-2

    Tim ,
    Thank you,again for all of your assiatance.
    I am currently running counter spy and it states I have the following

    Storm Worm Generic

    Trojan-Proxy.w32.lager.gen Backdoor

    Mike
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell it to remove/quarantine whatever it finds .....this may be coming in thru the Wildtangent or the WeatherBug programs...post the log please.
     
  11. mcejsul

    mcejsul Private E-2

    Did the Counter spy again when I got home and all there was a cookie (Tribal Fusion).
    Mcafee blocked IE from loading about Blank as my home page.
    A trojan downloader was removed.
    Still having Issues with IE but Firefox seems fine, may stick with that.
    No luck with MFPlat.dll but working on it. Goggle it and it to me to reistry booster and tried that but would not help. Click on Windows media Player in Start-programs and it says that must be in administrator to finish the loading??
    I know i need to post that somewhere else but just venting.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing any problems in your logs.

    (If you are running IE7 ...you may wish to uninstall and revert to IE6..just my opinion!)

    Now we need to Reset Web Settings:

    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\username\Local Settings\Temp\
    and Cookies.

    You may uninstall any programs that we asked you to install for the analysis.

    Re-run CCleaner to finish up.

    Turn of system restore, restart and re-enable it.

    Tell me how things are running.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think I forgot to ask you to delete this file:
    C:\WINDOWS\system32\lnwin.exe

    Then do the above.

    If you have any problems, let me know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds