Malware Help:All steps completed, Just making sure...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by t3hCyborg, May 25, 2006.

  1. t3hCyborg

    t3hCyborg Private E-2

    Hello all, I'd like to start off by saying that I just can't tell you how helpful your site has been to me. I called myself safe before for just virus scanning and using AdAware, but there was so much I was (obviously) missing. I have completed all the steps and I have found a lot of things I didn't even know I had.

    I'll start off with what led me to your site. A few days ago, I booted up my computer, instantly my SpyBot resident scanner went off saying that there has been a registry change. I did not recognize it, so instantly I punched in my query into google, and there you were.

    Now, after looking up the file, I saw that it could possibly be the sign of my computer being infected by a rootkit. I panicked, but luckily, your sticky thread on what to do first helped tremendously.

    The problem lies here: I did not notice any signs of a virus or rootkit on my own, so I do not know if my problem has been truly fixed. Yes, the scans did find things, and yes, I did repair and fix as needed. This is for my peace of mind on the safety of my system. Attached are my HijackThis log, my CounterSpy log and my Panda: Active scan log.

    If you could, just check them and see if I still have any problems, please.

    Once again, I am TREMENDOUSLY grateful for this website and all of your help, present and future. Thanks so much!

    //t3hCyborg
     

    Attached Files:

  2. t3hCyborg

    t3hCyborg Private E-2

    My computer also seems to be running a little slower than usual... What do you think this could be?

    Some of the new Anti-Malware programs run on start-up, but I don't think they would consume that much memory...
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    But that is where you are wrong! All active protection software can require significant amounts of a PC's system restources.

    Questions:
    1. Is there a reason you did not attach the requested BitDefender log from step 6 of the READ ME?
    2. Did you install the free trial version of CounterSpy while running the READ ME?
    3. Why didn't you allow CounterSpy to fix the problems it found? Run it again and don't choose to Ignore problems. FIx/Delete them.
    4. Did you run CounterSpy because you could not run Windows Defender?
    5. Did you get an error message while trying to install or run Windows Defender?
    6. Is you Windows OS legal and authenticated with Microsoft (it does not seem to be)?
    7. The Read Me specfically indicates to disable/not use Spybot's Teatimer. You have it running. Did you just install Spybot while running the READ ME or did you already have it installed? Disable it now or fixes further down may not work.
    8. Are the below items that Panda picked up something you download and need to have (why on your Desktop)
    If you do not need them, delete them.

    You problem with your PC being slow is due to what you are running. We can look into this after all my questions are answered.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} -
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} -
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
    O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in) -
    O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in) -
    O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in) -

    After clicking Fix, exit HJT.:

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
    Last edited: May 26, 2006
  4. t3hCyborg

    t3hCyborg Private E-2

    Okay, chaslang, I have done everything you advised, I'll answer your questions now:

    1. Is there a reason you did not attach the requested BitDefender log from step 6 of the READ ME?
    Yes, there is. I did not see an option to receive a log, possibly because BitDefender said that my system was fine.

    2. Did you install the free trial version of CounterSpy while running the READ ME?
    Yes, I did.

    3. Why didn't you allow CounterSpy to fix the problems it found? Run it again and don't choose to Ignore problems. FIx/Delete them.
    It was an accident, didn't see it due to SafeMode resolution. I have re-run it and fixed the problems as you said

    4. Did you run CounterSpy because you could not run Windows Defender?
    Yes, that is precisely why. I have a bad habit about not updating my system, sometimes.

    5. Did you get an error message while trying to install or run Windows Defender?
    Yes, which is why I went with CounterSpy.

    6. Is you Windows OS legal and authenticated with Microsoft (it does not seem to be)?
    Yep, it sure is. (Legit, that is... It is legit.)

    7. The Read Me specfically indicates to disable/not use Spybot's Teatimer. You have it running. Did you just install Spybot while running the READ ME or did you already have it installed? Disable it now or fixes further down may not work.
    Sorry, didn't really look around for it, so I didn't disable it. I looked around and found it. It is currently disabled.

    8. Are the below items that Panda picked up something you download and need to have (why on your Desktop)
    Definitely don't need them. I have deleted them.

    The new HJT and CounterSpy are attached. I have fixed the items from HJT as per your instructions.

    Let me know of anything else I need to do and if my system is safe again...

    Once again, thanks for your help.

    //t3hCyborg
     

    Attached Files:

  5. t3hCyborg

    t3hCyborg Private E-2

    Sorry, wrong HJT. I forgot to remove one file, the up-to-date log is attached below.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!


    You need to validate your OS with Microsoft. That is why you could not install Windows Defender. Once validate with Windows Genuine Advantage, you should be able to install it. One installed, uninstall CounterSpy which is only a trial anyway and will expire.
     
  7. t3hCyborg

    t3hCyborg Private E-2

    I have done everything you have said.

    Chaslang, and the whole MajorGeeks community, I can't thank you enough for all your help and this website as a whole. I don't know where I would be without your guidance, so once again, thanks x 10 ^ 999999999999999999.

    I'll keep you in mind and reccomend you to my friends. Thanks!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks for recommending us. Surf safely
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds