Oh, Great Major Geeks, Please Take Pity On Me!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SarahMays, Sep 24, 2007.

  1. SarahMays

    SarahMays Private E-2

    OK. I think I did all of the Read & Run First Steps.

    Background: I started using IE again bc so many sites didn't like firefox. I now know I shouldn't have fallen for it! My first clue to any problem was when I attempted to use Adobe Photoshop and got an error message about the registration and names. I took a look around and noticed new "programs" in the Add/Remove Programs List and then saw that I didn't really have the option to actually remove any of them. No programs are running quickly or well, Photoshop/Illustrator isn't working at all, everything is just acting super quirky.

    I will attach my logs. I was unable to get a log from Panda. Please let me know if I'm leaving out anything important.

    Thank you so much!
    Sarah
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need the rest of the logs:
    ShowNew
    GetRun
    HJT
     
  3. SarahMays

    SarahMays Private E-2

    Sorry about that!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    C:\Documents and Settings\Sarah Mays\My Documents\download\analysis.exe
    Is exactly where we ask you not to install HJT
    Please uninstall it and reinstall to:
    C:\Program Files\HijackThis\analyse.exe

    You may uninstall Counterspy as we no longer need it.

    Then Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
     
  5. SarahMays

    SarahMays Private E-2

    New logs, as requested.

    Thank you!
     

    Attached Files:

  6. SarahMays

    SarahMays Private E-2

    And Avenger...
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is looking better.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now lets reset your IE defaults
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me how things are working now.:)
     
  8. SarahMays

    SarahMays Private E-2

    I still have the same problems. Everything is moving very slowly and the Adobe Creative Sute won't run. Should I just uninstall and reinstall it? Also, the files that look new to me (they could be just fine, but I don't recall seeing them before) on the Add/Remove Software list are:

    Bonjour
    CR2
    ESSBrwr
    ESSCDBK
    ESScore
    ESSgui
    ESShelp
    ESSini
    ESSPCD
    ESSPDock
    ESSSONIC
    ESSTOOLS
    essvatgt
    essvcpt
    HLPPDOCK
    kgcbaby
    kgcbase
    kgchdat
    kgchlwn
    kgcint
    kgckids
    kgcmove
    kgcvday
    KSU
    WIRELESS

    I'm not sure if this information is helpful or not. I really appreciate the time you've put into this.
    Sarah
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    These are related to your Kodak program and do not need to be removed (nor do the others in your list):
    ESSBrwr
    ESSCDBK
    ESScore
    ESSgui
    ESShelp
    ESSini
    ESSPCD
    ESSPDock
    ESSSONIC
    ESSTOOLS
    essvatgt
    essvcpt
    HLPPDOCK
    kgcbaby
    kgcbase
    kgchdat
    kgchlwn
    kgcint
    kgckids
    kgcmove
    kgcvday

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now, please do the following:
    1. Click Start > Search.
    2. Click All files and folders.
    3. In the "All or part of the file name" box, type:

    hosts

    4. Verify that "Look in" is set to "Local Hard Drives" or to C:.
    5. Click More advanced options.
    6. Check Search system folders.
    7. Check Search subfolders.
    8. Click Search.
    9. Click Find Now or Search Now.
    10. For each Hosts file that you find, right-click the file, and then click Open With.
    11. Deselect the Always use this program to open this program check box.
    12. Scroll through the list of programs and double-click Notepad.
    13. When the file opens, delete 127.0.0.1 www.microsoft.com if found.
    14. Close Notepad and save your changes when prompted.

    Attach a new GetRun log and tell me how things are running.
     
  10. SarahMays

    SarahMays Private E-2

    Thank you, Tim. When I searched the "hosts" files, there were many files with the 127.0.0.1 ********, but none were 127.0.0.1 www.microsoft.com.

    Everything seems to be running a bit better with Firefox. The Adobe programs still have that strange error message and IE runs crazy slow.
     
    Last edited: Sep 25, 2007
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try uninstalling and reinstalling the adobe programs.

    Please attach a new GetRun log ( you may have to rename it...as in getrun3).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds