Some problems leftover. Logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nikko56, Sep 16, 2008.

  1. Nikko56

    Nikko56 Private E-2

    Here's the first three logs. I tried to attach the SAS log and it said it was invalid. I'll try to post it again.
     

    Attached Files:

  2. Nikko56

    Nikko56 Private E-2

    It still says the file type is Invalid for uploading:confused

    Should I run SAS again to get a new log?


    --------------------------------------------------------------------------

    Other issues with this computer that I encountered while doing the Read and Run me thread are below. I'm not sure if they are relevant but just incase.....

    1.) When I tried to delete programs from the Add/Remove List there were some that could not be removed
    - Card Board Deluxe 2
    - Balloon Kaboom
    - Bears and Bees
    - Brigade Balloon
    - Super Word Slide
    - Wiz Solitare
    - LivReg (Symnactac Corporation)
    - Macromedia Shockwave Player
    - MVP Solitare Clubs Edition
    - No Match
    - Puzzle Master 4 Special Edition
    - Puzzle Monkey
    - Solitare Master 3 Special Edition

    2.) Everytime I Restart the computer I get a window that says "Found New Hardware" for Multimedia Audio Controller. Install disk and click next......

    I think I deleted this during the Add/Remove Programs step. I'm not sure what it is and if I need it.

    3.) Also when Shutting down I get an End Program box for a "CicerolUIWndFrame" Again I don't know what that is ???

    4.)When I was running ComboFix a window popped up that said "Boot Partition cannot be enumerated correctly" The only option was to click OK which I did.

    5.) and Lastly when I was finished with running MGTools I never saw the command Prompt window that had the image "GetLogs-Final.jpg" like the instructions said


    That's it for now:eek: Thanks in advance for the help.

    Kat
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What file type did you save the SAS log as? It should have been as a text file.

    You should not have uninstalled the MultiMedia drivers...you will need to go to the website of your computer manufacturer and look for downloads - drivers and reinstall that. (You can post in the drivers or software section to get additional help with this if you need).

    Next, for this - LivReg (Symnactac Corporation) it is part of Norton and should also not be uninstalled.

    Then for this issues -> CicerolUIWndFrame:
    Go to the "Control Panel" / "Add/Remove Programs" / "Microsoft Office," click on the "Change" button / browse to "Office Shared Features," "Alternative User Input," and select for Speech and Handwriting Recognition (both) "Not available" from the drop-down box.

    Repeat for any other Office XP installations (i.e.: if you have Frontpage or other components that were installed seperately). This may also apply to Office Outlook.

    Now to the malware issues:

    Please right click the desktop / properties / desktop / customize / web and uncheck all checked boxes and remove all but My Current Home page.

    I want you to use a different computer and change all of your passwords in any online sites you use.

    Now I want you to use windows explorer to find and delete:
    C:\Program Files\SpySpotter3
    C:\DOCUMENTS AND SETTINGS\Susan\LOCALSETTINGS\Temp\bwgo00023510.exe

    Now Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely, you are not trying to attach the SAS log. The log is here:
     
  5. Nikko56

    Nikko56 Private E-2

    That's what I probably did:eek:

    Thanks Chaslang. Here's that log



    I hate norton..... Don't remove it?

    This is the history of this computer. It's my mother-in-laws and she got it years ago for her business and had a the guy who sold it to her, set it all up. She knows nothing about computers. Not that I'm much more experienced... Anyway. The business is closed now and it's a home computer that has gotten infected... when? I haven't a clue. I didn't even know it was infected when I started the Read and Run me thread. I was just going to check., So anyway... my point is that a lot of the family have used it and so do they all have to change their passwords to everything they can think of ever possibly visiting on this computer from who knows how long ago? I will already assume the answer is yes.


    And a bit off topic, I have a question or myth, I hope you can clear up. My father-in-law is.......passionate and vigilant... about viruses. There are 4 computers in the house and they use a wireless router to get internet. The internet has a password and key to block outside users and as far as I know they are not connected to share. (i.e. no printer or computer sharing within the network) But even if they were shared... WOuld a virus beable to get them all infected if only one computer was infected intialnally? And when the web browser is not being used but the internet connection is still active... Can you get infected? ...Same question but in respect to being in Standby Mode or Sleep Mode? And here's a crazy question..... what if the computers are all turned off.....can you still get infected?

    To be honest I can't give him a true answer since I honestly don't know for certain. I assume no. But we all know assumption are the root of all F ups... So that's why I'm asking.



    Alright back to the task at hand. I did everything you said and it worked!:) Thank You!

    Kat
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not unless you plan on uninstalling Norton. ( There are other freeware AV's that you could use).

    This was the culprit so no except for any one using the web from this date:
    2008-09-16 18:22 --------- d-----w C:\Program Files\SpySpotter3

    As to your next question:
    If you are not trasnering files or having a network sharing...then probably no.
    Having a firewall on all computers will reduce the possibility of infection on each computer.
    And I have never heard of a computer being infected in standby or sleep mode....the internet/nic card is not running at that point.

    You did not delete this file:
    C:\DOCUME~1\Susan\LOCALS~1\Temp\bwgo0001d433.exe

    Are you having any other issues?

    Let's do a little house cleaning:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  7. Nikko56

    Nikko56 Private E-2

    We've tried to uninstall Norton many times but I'm sure you know of the difficulties of trying to do that. As far as I know Norton is uninstalled except for that one program left in the Add\Remove section.


    The computer is still a little slow on start up.

    Also the list of games and other programs that I made in the first post are still there and I still can't get them to uninstall.

    Other then that It's looking pretty good.


    I got the success message and also deleted the temp file.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ---> from your last log in the add/remove programs:
    LiveReg (Symantec Corporation)
    Norton AntiVirus 2002
    Perhaps you should run Norton Removal Tool

    As for the games, you can always just find the folders and delete them manually and then run ccleaner ( both the cleaner and the issues sections -- > be aware to make the backup when asked.)

    You can post in the software section regarding your slowness. :)

    If you are not having any other malware problems, it is time to do our final steps:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below

      * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combo-fix folder from combofix.

    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds