Not sure what infection I still have

Discussion in 'Malware Help (A Specialist Will Reply)' started by markslade, Oct 8, 2007.

  1. markslade

    markslade Private E-2

    but after completing the read and run first I am still having problems. PCCillian won't run and most of the rest of my startup won't. Other than that the only other symptom is popups appearing in IE ...mostly for porn sites......please find attached my logs.....
    Thanks for any help
    Mark
     

    Attached Files:

    Last edited: Oct 8, 2007
  2. markslade

    markslade Private E-2

    rest of logs....
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't really that much in the way of malware. First let's remove a bad service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to MSIEUpdater_1
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMicrosoft IE Updater_1 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    Now uninstall the CounterSpy trial since we are finished with it. Then delete the below folders which may be left behind:
    C:\Documents and Settings\Owner.Laptop\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Uninstall the below old versions of software:
    Java(TM) SE Runtime Environment 6 Update 1

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Are you still having problems? If you still have problems with PC Cillin, you should consider uninstalling it, rebooting and then reinstalling it.
     
    Last edited: Oct 8, 2007
  4. markslade

    markslade Private E-2

    Thanks Chas....counter spy found virtumonde(among others).....so maybe that was the worst of my problem.
    Completed all of your suggested steps. Have not noticed any pop ups...but will leave it connected for a while to be sure.
    Still am missing all of my startup icons that showed in the taskbar....such as ati panel....synaptics....quicktime.....and pc cillin still won't start. If I try to start it to do a scan I get an error message that says "The feature is still loading. Please wait a moment, and then try again." Guess I'll try to re-instal after you reply to this.
    ATI just came up....5 minutes after boot up.....but none of the others.
    Also is it normal for IEXPLORE to be running on startup?? Task manager shows IE running....even though I can't see it anywhere. I can shut it off through task manager....but on re-boot it shows up again....
    Thanks for the help
    Mark
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do what I suggested at the end of my last message?


    This could all be related to issues with PC Cillin.

    No it is not normal if you are not opening a browser and are not doing any automatic updating.

    Attach a new HJT log and also run the below and attach the requested log:

    Running GMER to detect rootkits
     
  6. markslade

    markslade Private E-2

    No, not yet. Can't get to the disc's...they are in storage. Also wanted to wait for your reply to my last message. Should I just uninstall it for now. Need to update it anyway.
    Ran gmer and new hjt....they are attached. I ran them with IE not running and normal boot.
    Thanks
    Mark
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just uninstall Trend Micro PC-cillin Internet Security 2006
    Then reboot and if you do not have the disks for the above install the below as replacements.
    Also install the below for some additional protection that will not waste any system resources:

    SpyWare Blaster Install it, click Download Latest Protection Updates, Check for Updates, and then Enable All Protection, then exit. SpywareBlaster is not a malware scanner or removal tool and uses no system resources except a little disk space. It does a great job of preventing malware from being installed in the first place! It blocks the popular spyware ActiveX controls, and also prevents the installation of any of them from malicious websites.


    After doing the above, are you experiencing any other problems?
     
  8. markslade

    markslade Private E-2

    Got the disc's. Went ahead and upgraded PC Cillian. Also installed spywareblaster.
    Other than the missing items in the task bar everything seems to be OK. PC Cillian keeps finding smitfraud on boot up and deletes it...but it's there again on re-boot. Haven't noticed the popups. Apparently the reason IE was running was because ATI and Power DVD were trying to access the net. Don't know why but PC stopped them.
    Mark
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would guess this is because it is in System Restore and my final instructions should take care of that.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  10. markslade

    markslade Private E-2

    Thanks Chas. On my way out the door to catch a plane. Will let you know tomorrow nite how things are.....again Thanks a Bunch!!!!!
    Mark
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I'll be here. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds