read&runme: DONE. Now...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by marysmail, Jun 16, 2008.

  1. marysmail

    marysmail Private E-2

    Hello. I just finished with the read & run me instructions. I did it cause lately I found my comp moving extremely slowly.

    I'm attaching the logs, if someone could check them for me and tell me if there's anything I should do.

    Thanks!

    Mar.-
     

    Attached Files:

  2. marysmail

    marysmail Private E-2

    And the rest...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall SUPERAntispyware now since we are finished with it.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) SE Runtime Environment 6 Update 1
    Now reboot!
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Do you know if the below process is something for your keyboard?
    C:\WINDOWS\StopHid.exe

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe

    You should whether you really need the below to be loading at startup and remove any that you do not need.
    O4 - HKLM\..\Run: [iTunesHelper] "G:\Progs\iTunesHelper.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [NBJ] "C:\Archivos de programa\Ahead\Nero BackItUp\nbj.exe"
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Archivos de programa\DNA\btdna.exe"
    O4 - HKCU\..\Run: [updateMgr] "C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
    O4 - HKCU\..\Run: [eMuleAutoStart] C:\Archivos de programa\eMule\emule.exe -AutoStart
    O4 - Startup: CNNAlerter.lnk = C:\Archivos de programa\CNN.com Desktop Alerter\CNNAlerter.exe

    After clicking Fix, exit HJT.




    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. marysmail

    marysmail Private E-2

    Hi, CL. Thanks for the reply.

    Well, followed all your steps:

    *uninstalled windows messenger following your link, but it kinda "auto-reinstalled" back after rebooting. weird..?
    *I've got no idea of what the C:\WINDOWS\StopHid.exe is. I do have a thingie for my keyboard (volume control, etc.) though... maybe it's that?
    *got the "success" message from fixme.reg
    *I'm attaching the files you asked for.

    Thanks again,
    Mar.-
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You forgot to tell me how things are working.
     
  6. marysmail

    marysmail Private E-2

    G'morning there...
    Yes, sorry! It's a lot better, faster.
    Only thing I notice is that things get slower after a while of having iTunes running... I'm pretty sure that didn't use to happen before.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That I cannot help you with. You could try putting back the iTunes startup entry that you removed with HijackThis. The below line is what I referring to:

    O4 - HKLM\..\Run: [iTunesHelper] "G:\Progs\iTunesHelper.exe"

    I doubt this will have any effect but it is worth a try. You can restore it from by running C:\MGtools\analyse.exe and selecting Open the Misc Tools section. Then click the Backups button. Find the above line in the list. Put a check mark on it and then click the Restore button.

    Nothing else had anything to do with iTunes. The only real malware items were the avpo.exe and Knight entries.
     
  8. marysmail

    marysmail Private E-2

    Cool. Well, I take it they've been taken care of...

    I haven't done Step 4 and so on (from the read & run me) yet. Should I?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should do all of the below but make sure you have restored the iTunes item first if you plan to. Once you do the below, the HijackThis backups will be gone when the MGtools folder is deleted.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. marysmail

    marysmail Private E-2

    Last time I had spyw trouble I was also asked to delete that

    O4 - HKLM\..\Run: [iTunesHelper] "G:\Progs\iTunesHelper.exe"

    so I just left it alone, deleted and buried. It seems to reappear somehow...


    So, I'm done with step 4, etc. Guess I should be safe (at least for a while...)

    Thank you, Master, you're a life saver. A patient one.

    Mar.-
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a malware issue. I is just an unnecessary startup that adds to the slow PC dilemma. The problem is that iPod software will quite possibly automatically reinsert this into your startups as soon as you use your iPod. You can even see a comment about this here: http://www.bleepingcomputer.com/startups/iTunesHelper.exe-2349.html


    You're welcome. Surf safely.
     
  12. marysmail

    marysmail Private E-2

    Ok, so it will come back on its own... good. Karmic exe. Thanks for the link and the help.

    Have a great week!

    Mar.-
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Thanks! Enjoy the summer malware free. ;)
     
  14. marysmail

    marysmail Private E-2

    Unfortunately, it's winter down on my side of Earth... but I'll try my best to keep it clean TILL summer hits me again...

    Speaking of... I think you should get your hands around Vampire Weekend's 1st album... 11 tracks of pure summer music. Give 'em a try under the sun.:)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! Welcome enjoy the snow then. :-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds