Using GetRunKey txt file

Discussion in 'Malware Help (A Specialist Will Reply)' started by alphaboy1906, Aug 28, 2007.

  1. alphaboy1906

    alphaboy1906 Private E-2

    i think this is what im supposed 2 do...post my txt results
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you are working thru the READ & RUN ME because you have malware problems, you need to attach all of the requested logs and you should also tell us what problems you are having. To be specific here is the full list of logs requested in the READ ME and you only attached two of them:
    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    Make sure you have run all steps in the READ ME and in the order written. Based on your ShowNew log I can already tell you did not run ALL steps. If you ran GetRunKey and ShowNew before running all or any or the steps in front of them, you will have to run GetRunKey and ShowNew again and attach new logs.

    Note I can already see that you did not uninstall Viewpoint Media Player as requested in step 0 of the READ ME. Also you did not uninstall the below two old Sun Java versions and then install the current version as requested in step 6:

    J2SE Runtime Environment 5.0 Update 6
    Java(TM) SE Runtime Environment 6 Update 1
     
  3. alphaboy1906

    alphaboy1906 Private E-2

    I Think I Did It Right This Time All My Malware Logs

    I have already follwed the instructions on the READ & Run Me First Page...Ok my problem is with my internet, everything works fine except searches. When I go to a search engine an type something in like "John Elway" (who is clearly a person) the results come back with ads for sites like shopping.com with the title being john elway - Compare & Save at Shopping.com and i get the same exact results no matter where i search. I dont get sites dat are actually usefull until about result number 8, and when i go to the next page of results the same exact shopping type results are there again until result number 16.
     

    Attached Files:

  4. alphaboy1906

    alphaboy1906 Private E-2

    Re: I Think I Did It Right This Time All My Malware Logs

    The Other Logs
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I Think I Did It Right This Time All My Malware Logs

    You forgot to uninstall J2SE Runtime Environment 5.0 Update 6 as I requested in message # 2. Please uninstall it now.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger.


    Also download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. alphaboy1906

    alphaboy1906 Private E-2

    The avenger link keeps saying Internet Explorer cannot display the webpage
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Works fine for me so it must be at your end. Try download the file attached to this message and using it.
     

    Attached Files:

  8. alphaboy1906

    alphaboy1906 Private E-2

    the logs
     

    Attached Files:

  9. alphaboy1906

    alphaboy1906 Private E-2

    And It didnt work....the searches still are showing results instead of websites
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not showing any malware that is known to do this but the C:\sccfg.sys we deleted came back. Thus we will have to dig deeper.

    Do you or did you ever use a program named Folder Lock?

    See if you can manually locate the C:\sccfg.sys file using Windows Explorer and delete it if you can. Then manually create a NEW FOLDER in the root of drive C and name it sccfg.sys This should keep the file from being recreated!


    Go to Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.




    Since I'm not sure which browser you are using, let's clear the cache in each one.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Now open FireFox
    • click Tools
    • then select Clear Private Data...
    • on the next form leave the defaults that are selected and click the Clear Private Date Now button
    Now try again your searches again.


    If you still have the same problem, continue with the below:
    • Which browser are you running (Internet Explorer or FireFox) when you do these searches?
    • Try both browsers and tell me if the samething happens with both browsers. Be sure to close the other browser before trying each one.
     
  11. alphaboy1906

    alphaboy1906 Private E-2

    Yea i have folder lock on my computer now....should i still go ahead wit your last instructions?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip the first part that refers to sccfg.sys.

    Start from the line saying
     
  13. alphaboy1906

    alphaboy1906 Private E-2

    i ran the searches on ie7 and firefox and the searches are still comiin up with shoppin results.....my fsbl log is attached
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How do you connect to the internet (dial-up, cable modem, DSL modem)?
    Do you use a router? Which one?

    If you have a cable or DSL modem, power cycle it.
    If you use a router, power cycle it.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log ( c:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Attach the log from ComboFix and also attach a new log from HJT.

     
  15. alphaboy1906

    alphaboy1906 Private E-2

    i use dsl....an dont use a router...im in an ampartment complex for college an it comes with the room....an how do u powerc cycle it?...an the internet cant display the link for the combofix
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you cannot power cycle it since you don't have access to it is what I would assume.

    I'm now suspecting the problems may not be on your PC. Can you get someone to plugin another PC to your connection and see what happens?

    Do you mean your connection provided from your college is blocking it? Perhaps you need to speak to the IT department at your school especially if this is a school PC.


    Were you able to do the fixME.reg patch? If yes, attach a new HJT log.

    Also run a new scan with CouterSpy from Normal Boot mode and save a new log and attach it here. Make sure you quarantine or delete anything it finds. Then uninstall CounterSpy since we are finished with it.
     
  17. alphaboy1906

    alphaboy1906 Private E-2

    Umm i dont think its the connection i just moved here an it was happenin with the searches when i did them at home...but i had some plug in there laptop an the searches came out fine. and about the web page not bein displayed...im not on campus, its jus sayin Internet Explorer cannot display the webpage....but here are the 2 logs
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try FireFox and tell me what happens.

    None of your logs are showing any problems so it could be just some kind of configuration issue on your end or some software you are running (possibly any protection software like McAfee, Windows Defender or your firewall).

    Uninstall CounterSpy now since we are finished with it.

    Are you still having the search problems? Do they occur in both FireFox and Internet Explorer?
     
  19. alphaboy1906

    alphaboy1906 Private E-2

    The Same thing happens with firefox also...an i have McAfee and windows defender...i uninstalled counterspy...an the searches show up the same on both IE an Firefox...
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what I said in my last message and I said your problems may possibly be related to them. i.e. since we don't see other issues you may want to try uninstalling them to see what happens. If that does not change anything we may need to try and check if anything is getting hooked into your explorer.exe process, or your browser processes when they load. Something like this would not always show up in logs especially if it is something new that no one knows about yet which means they would not specifically look for it.

    You never specifically answered my question from message # 16 about the fixME.reg patch. Did the patch add into the registry properly? Did you receive a success message?


    See if you can download the ComboFix.exe file onto another PC and then copy it to your PC somehow. Then run the procedure.
     
    Last edited: Sep 3, 2007
  21. alphaboy1906

    alphaboy1906 Private E-2

    Ohh ok...Well i installed them both after the problem with the internet started...so i guess it might be in the explorer.exe process, but that doesnt explain y it happens in firefox also...an im sorry about not answering the question in #16 ...but it said "Were you able to do the fixME.reg patch? If yes, attach a new HJT log." so i thought by attaching the log that would signify it working....but yea it worked an i got the success message...as far as the combofix i have 2 wait till tuesday so i can use a computer at skool.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay to keep things moving along then also make sure to download the below ProcessExplore program at school and then do the below steps.


    Please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplore.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list as ielist.txt.
    • Now click on exlorer.exe
    • And then click on File and then Save As. And save the process list as explist.txt.
    • Now open up one FireFox session and in Process Explorer select the firefox.exe process
    • And then click on File and then Save As. And save the process list as fflist.txt.
    • Post all 3 of these logs back here as attachments too (along with the combofix log)
     
  23. alphaboy1906

    alphaboy1906 Private E-2

    i didnt leave or anything we had a family emergency an i went outta town...but i finally got combo fix an ill run it 2nite wen i get home
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you complete the instructions in both messages # 14 & 22
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds