pre-HJT steps queries: steps 2 and 4

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tkjdnow, Aug 20, 2006.

  1. tkjdnow

    tkjdnow Private E-2

    If I use the internet to download security tools, and have followed directions to
    uncheck protected system files
    cannot the computer be totally ravaged? Should I not download the tools, then uncheck protected files before running the tools? Do I have the order right?

    Also, should I create a folder labled Security Tools like your directions for the HJT folder, and put in all of the tools except HJT?

    I am using a Toshiba Satellite M55-S325 laptop, with and Intel Pentium Processor740 (1.73 Ghtz), 512 MB DDR SDRAM, 100GB (5400 RPM) HDD, DVD SuperMulti Layer drive, 802.11b/g wireless, ilink 1394. I have 73GB free on the hard drive. Task Manager shows 64 processes running.

    My CPU spikes and stays at 100%, Word and InterVideo WIN DVD freeze, Firefox and IE fail to load Google, time out, and sometimes just vanish.

    I run Adaware SE 1.6, SpyBot with Teatimer, SpySweeper.

    Fix-It utilities found these a few weeks ago, and could not fix. Went to v-com, and followed directions, all sweeps say I am clean, but computer is ill.

    TROJ_LOWZONE.GEN as a zip\web.exe file
    JAVA_BYTEVER.K counter class -- 2 0f them
    JAVA_BYTEVER.A-1 gummy class -- 2 of them
    JAVA_BYTEVER.K verifer Bug -- 2 of them
    JAVA_BYTEVER.A worker class -- 2 0r them
    JAVA_BYTEVER.K Xeyond class -- 2 of them


    Will follow all steps as soon as I understand them.
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    By enabling the viewing of protected system files, enables us to see things that are hiding on the system that shouldn't be there. The system won't get ravaged.

    Creating a folder for the downloads, is just fine. As long as you can easily access the folder.

    Disable Spybot's TeaTimer function.
     
  3. tkjdnow

    tkjdnow Private E-2

    Read & Run Step 4 hang-up re: spybot

    Spybot is in my Program Files, but does not show in add and remove programs. How can I delete it to re-install from your site as per instructions?
     
  4. tkjdnow

    tkjdnow Private E-2

    Update to that ... went to all programs-spybot-uninstall, and got message that C: program files spybot was corrupt and could not be uninstalled.
     
  5. tkjdnow

    tkjdnow Private E-2

    read & run steps completed =unknown spyware

    All steps were followed with these exceptions. As per above post, the uninstal file of SpyBot is corrupt and I could not install new one from your link. I was ale to fix ignore products bug, but was NOT able to disable TeaTimer. SpyBot found, and said it fixed the following: (However, every time I run spybot it finds and says it fixes these)

    Windows Security Center Firewall Disable Notify
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityCenter\FirewallDisableNotify!=dword:0

    Windows Security Center AntiVirus Disable Notify
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityCenter\AntiVirusDisableNotify!=dword:0

    Also, I ran Panda in normal boot mode as per Using PandaActiveScan. One spyware entry.

    Attached are logs. HJT log to follow in additional post.

    Below is info from previous post.

    I am using a Toshiba Satellite M55-S325 laptop, with and Intel Pentium Processor740 (1.73 Ghtz), 512 MB DDR SDRAM, 100GB (5400 RPM) HDD, DVD SuperMulti Layer drive, 802.11b/g wireless, ilink 1394. I have 73GB free on the hard drive. Task Manager shows 64 processes running.

    My CPU spikes and stays at 100%, Word and InterVideo WIN DVD freeze, Firefox and IE fail to load Google, time out, and sometimes just vanish.

    I run Adaware SE 1.6, SpyBot with Teatimer, SpySweeper.

    Fix-It utilities found these a few weeks ago, and could not fix. Went to v-com, and followed directions, all sweeps say I am clean, but computer is ill.

    TROJ_LOWZONE.GEN as a zip\web.exe file
    JAVA_BYTEVER.K counter class -- 2 0f them
    JAVA_BYTEVER.A-1 gummy class -- 2 of them
    JAVA_BYTEVER.K verifer Bug -- 2 of them
    JAVA_BYTEVER.A worker class -- 2 0r them
    JAVA_BYTEVER.K Xeyond class -- 2 of them

    Look forward to your response, thanks
     

    Attached Files:

  6. tkjdnow

    tkjdnow Private E-2

    Second post with HJT file

    Attached is HJT file
     

    Attached Files:

  7. tkjdnow

    tkjdnow Private E-2

    So sorry, forgot to attach bitdefender log. This is really very hard to keep straight.

    Also, I am now running 77 processes and which is way too many, and random icons appear and disappear in the task bar. Also a blue and white message box next to the start utton. Nothing stays long enough to ID.
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run ShowNew again and post newfiles.txt. Your last log is very incomplete and only contains the uninstall key data.
     
  9. tkjdnow

    tkjdnow Private E-2

    findnew log attached. 5 entries only.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Uninstall J2SE Runtime Environment 5.0 Update 1

    Clear the Java cache

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files

    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.

    About half of the runing processes on your computer are Toshiba processes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds