Virus gone? No idea what to look for in logs.

Discussion in 'Malware Help (A Specialist Will Reply)' started by rpole, Sep 5, 2007.

  1. rpole

    rpole Private E-2

    First off, let me say THANK YOU, this site is awesome. I 'think' I may have gotten rid of the garbage by going thru the Read & Run Me First stuff. But, I would like to be sure and I have no idea what to look for in the logs.

    Quick background..I had been problem free for a long time since using EZ trust firewall and AV anti-virus, but a couple days ago I got the Virus Protect Pro junk. Before finding this site I followed some stuff on bleepingcomputer and was able to get rid of the shield on the taskbar and the VPP pop ups but was getting other pop ups at an unreal rate. This is my 3rd evening working on this as the pop ups were so bad it made doing things almost impossible. I 'think' after running Panda or one of those the pop ups stopped. So, as of now I 'think' things are taken care of since there are no pop ups anymore. Oh, and for awhile I was getting some memory or some other error every time I'd restart '3x2000002' or something like that. I no longer get that either.

    From going through the site some I know you guys have a ton of problems you respond to. If you could look through the logs and let me know if there is anything else that needs to be done, that would be much appreciated.

    Here are the logs. One thing though, I ran AVG twice (cuz CounterSpy wouldn't run) and both times after I clicked 'apply all actions' then clicked on Reports it tells me there's no reports to be shown??? So, I do not have the AVG log.

    Once again, thank you very much.
     

    Attached Files:

  2. rpole

    rpole Private E-2

    here are the last 2 logs...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below old versions of software:
    Java 2 Platform, Enterprise Edition 1.4 SDK
    Java 2 Runtime Environment, SE v1.4.2_06
    AVG Antispyware <-- we are finished with it now and you already have Pest Patrol installed.

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {47B83D78-F986-4E96-9769-2C55EF14DA0B} - C:\WINDOWS\System32\__c00CCAA4.dat (file missing)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: Protection Bar - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - C:\Program Files\Security Tools\iesbpl.dll (file missing)
    O20 - AppInit_DLLs: C:\WINDOWS\System32\__c0067602.dat

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. rpole

    rpole Private E-2

    Thanks a ton chaslang! Everything seems to be going well right now. No problems running the steps you posted, just a couple notes. When installing Sun Java Runtime Environment it told me it was not recomended for my operating system. The other thing is I didn't run CCleaner in safe mode this time, should I have?? ShowNew said file not found in the black box but the log appeared. Here are the logs requested and once again, THANKS!

    I will wait for a response to reboot and disable system restore plus do some of the other things mentioned in other threads for prevention and what not.

    For some reason it is telling me upload failed for avenger.txt. I have to go to work now but will work on this this afternoon. Sorry.
     

    Attached Files:

  5. rpole

    rpole Private E-2

    oops, I guess I could have put the HJT log in the previous post. and it's telling me I already uploaded the HJT log in this thread. Another thing I will deal with when I get home.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means you did not get a new log! You must attach a new log. Not the same log.:)
     
  7. rpole

    rpole Private E-2

    I should have gotten up earlier today to work on this. Between the dogs and kids (including a 5yr old w/ a broken arm who requires a little more time right now) I didn't give myself enough time. Trying to work this stuff in w/ everything else hasn't proven to be the best method. I blame it on my leaving the pump on on the pool while backwashing and draining a couple feet of the water. :cry Oh well, it's the end of the season anyway. I will sit down and dedicate some time to finish up your last requests and hopefully get everything right.

    Thanks again.
     
  8. rpole

    rpole Private E-2

    The Avenger file wouldn't attach cuz it was empty?? My fault on the HJT log as no new log was created from just the scan. I reran Avenger, then getrunkey and shownew and then HJT again. From the Avenger log, 2 things didn't work? I'm attaching all the new logs.

    As always, THANKS!
     

    Attached Files:

  9. rpole

    rpole Private E-2

    and HJT...
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean however please attach the below file to your next message.

    C:\WINDOWS\hvccgeuh.txt


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  11. rpole

    rpole Private E-2

    thank you Thank You THANK YOU!

    There have not been any noticeable problems.


    All the help is much appreciated. This site is great and I will be visiting it often. Hopefully mostly lurking and learning and not being a PITA.

    Here is the requested log...
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You'e welcome. Surf safely!


    Okay you can delete the C:\WINDOWS\hvccgeuh.txt file, it is just a temporay file from Avenger.
     
  13. rpole

    rpole Private E-2


    I will! I'm sure not-so-safe surfing is what brought this all on. rolleyes
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is normally the case for most people coming here. ;)
     
  15. rpole

    rpole Private E-2

    just one more quick, pseudo related question. I'm going through and removing/uninstalling stuff I don't use anymore. when doing so Call of Duty 2 says it was last used 8/28/07. I haven't played that game in many months. is that something malare may try to hide in or something of the sorts? I don't mean to clutter this board (hence not starting another thread) and don't want to take a bunch of time. just curious.

    thanks.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The dates in Add/Remove programs indicating when a program has last been used do not always seem to be accurate. I have seen this many times before. For example right now Ccleaner is report as last being used on 5/30/2004 on my PC and I just used it this afternoon. There are at least 5 others in my Add/Remove programs list that I know are reporting incorrect dates. Sometimes the report from Add/Remove programs shows old dates and sometime it shows new dates. I would not worry about it.
     
  17. rpole

    rpole Private E-2

    thanks! I don't see a tip of the hat smilie so you'll just have to pretend it's there. lol
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :)

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds