look at my logs please

Discussion in 'Malware Help (A Specialist Will Reply)' started by quicksilver11, Jul 13, 2007.

  1. quicksilver11

    quicksilver11 Private E-2

    Ran all scans in the malware removal guide and this is what I come up with
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install and rename HijackThis as requested in the READ ME. This is a necessity! You have it here which is unacceptable:

    C:\Program Files\HijackThis.exe

    You must have it like this and make sure it is in its own folder as shown:

    C:\Program Files\HJT\analyse.exe

    Then you will need to attach a new HJT log.

    Also uninstall Viewpoint Media Player as requested in step 0 of the READ ME.


    Also please attach the other requested logs:
    CounterSpy - only for Windows XP, 2K, & NT users
    Bitdefender - from step 6
    Panda Scan - from step 6


    Also please tell us what malware problems you were having that caused you to run the READ ME and also what problems are you currently still having.
     
    Last edited: Jul 13, 2007
  3. quicksilver11

    quicksilver11 Private E-2

    here are some more files i had run hijackthis it said there was some infection and also aspyware thing kept popping up telling me to download some sort of spyware thanks.
     
  4. quicksilver11

    quicksilver11 Private E-2

    i hope one of the last logs i sent was the one from counterspy, heres a hijack one and i should have said hijack free not hijackthis.
     

    Attached Files:

  5. quicksilver11

    quicksilver11 Private E-2

    I will try this again
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is not a malware scanner or detector. It will not tell you if you have infections.

    Let's try this again. You need to rename HijackThis properly as requested in step 7 of the READ ME. You renamed the folder not the exiecutable file as requested. You have this:

    C:\Program Files\analyse.exe\HijackThis.exe

    You need to have this:

    C:\Program Files\HJT\analyse.exe

    Fix this now before continuing!


    I don't know what that log.txt file is but it is not a log from CounterSpy. Did you save one?




    Run this Disable/Remove Windows Messenger to remove Windows Messenger.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jul 13, 2007
  7. quicksilver11

    quicksilver11 Private E-2

    the computer will not allow me to enter the fixme.reg that i put on the desk top. It says cannot import C Documents and settings\owner\Desktop Fixme.reg. The specifed file is not a registry script you can only import binary registry files from within the registry edition. I have done up to this step so far. Ihope these are the counterspy logs I done another last night Thanks again.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means you may not have follow the directions EXACTLY. You must create and save the file exactly as written. If you leave out the REGEDIT4 line, or if you put a space above the REGEDIT4 line then you will get and error like that. The first line of the file must be REGEDIT4 . Make sure you did not include the text saying Quote:

    Only the black bold print should be in the file and it must be name with the .reg extension.

    Try doing those steps again. Even if you have a problem again, complete all the remaining steps!

    No that is not a log from CounterSpy. The READ & RUN ME tells you how to create a log.
    If it is still finding problems, make sure your Quarantine them and attach a log. If it is not finding any problems, we do not need a log and you can just uninstall it now since it is only a trial program and we would be finished with it if it found nothing. It may be easier for you to get a log from CounterSpy by running it in normal boot mode.
     
  9. quicksilver11

    quicksilver11 Private E-2

    still can not get that stuff to load i used copy and paste sorry for all the trouble
     

    Attached Files:

  10. quicksilver11

    quicksilver11 Private E-2

    I hope I got the file right this time
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure in the future that your HJT logs are from normal boot mode unless otherwise requested. You last log was from safe mode. We still need to get the registry patch added. I see that you are not saving it to your Destop. Where are you saving it to?

    Try the following. Download the attached fixME.zip file to your Desktop. Then extract the fixME.reg file from it. Extract it to your Desktop. Then locate the fixME.reg file on your Desktop and double click on it. Say yes to the prompt. Do you get a success message about adding it to the registry?
    • If yes, attach new logs from GetRunKey and HJT.
    • If no, tell me exactly what happened.
     
  12. quicksilver11

    quicksilver11 Private E-2

    Hello I can not find the zip file from your last email, I can see on my desktop something that says fixme.reg looks like a little blue cube but it still will not let me use it when i double click it sorry. Thankyou.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry I forgot to attach the ZIP file. Here it is, unzip it and overwrite the previous file on your Desktop.
     

    Attached Files:

  14. quicksilver11

    quicksilver11 Private E-2

    I unzipped the file and it worked thanks for all the help it is very very appreciated Thank again
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so now attach new logs from GetRunKey and HijackThis.

    How are things working?
     
  16. quicksilver11

    quicksilver11 Private E-2

    Things seem to be working I hope I can keep it that way. Thanks
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks better.

    Put your system back into normal startup mode (step 0 of the READ ME) and then uninstall the CounterSpy trial since we are finished with it. It you don't go back to normal startup mode first, it will not completely uninstall.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds