pc clean up help request (part 1)

Discussion in 'Malware Help (A Specialist Will Reply)' started by SpiderWiz, Jan 19, 2007.

  1. SpiderWiz

    SpiderWiz Private E-2

    Hello all,

    I started down the path of cleaning up the malware/spyware path cause of a problem I have been having with my router. It got to the point I had to restart the router daily. I replace the router and after a couple days I was back to restarting the router. By restarting, I mean I would unplug the power, wait a minute or so. I had read a few place that it could be low signal from road runner. I connect them and was told that it was something on my pc flooding the ports. Couple additional things, this was happening to both wireless and wired computers. Also, I was it got to the restart point, I was unable to reach the router (192.168.1.1). So I followed you Read and Run me first guild. Attached are the file. I will say I had several things that was cleaned up at each stage of the process.
     

    Attached Files:

  2. SpiderWiz

    SpiderWiz Private E-2

    pc clean up help request (part 2)

    Attached are the rest of the files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: pc clean up help request (part 2)

    Welcome to Majorgeeks!

    I doubt the problems you are describing with having to reset your router have anything to do with malware but let's fix what I see and go from there.

    In the future please on run on copy and the correct copy of HijackThis at a time. Your log showed the below:
    C:\Program Files\HJT\HijackThis.exe <--- delete this copy
    C:\Program Files\HJT\analyse.exe
    You have Ad-aware 6 Professional installed. Did you know that this is way out of date? Ad-aware SE is the current version.
    Uninstall CounterSpy now since we are finished with this trial which will expire. It also could get in our way.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSNet\RSEDNClient.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\RSNet\RSEDNClient.exe
    D:\Program Files\RSNet\RSEDNClientUninstaller.exe
    D:\WINDOWS\Coder\_1-hags-1-0-.exe
    D:\WINDOWS\RSEDNClientUninstaller.exe
    D:\Program Files\Logitech\Resource Center\installers\wildtangent\blastrb2.exe
    C:\Program Files\RSNet <--- the whole folder
    D:\Program Files\RSNet <--- the whole folder

    Now run Ccleaner.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. SpiderWiz

    SpiderWiz Private E-2

    Thanks a lot for your response.


    In you first step, I didn't have a copy of hijackthis.exe in the c:\program files\hjt\hijackthis.exe.
    At least that I could find. However, I searched for that file and removed all the copies I found.
    I removed Ad-aware 6 Pro and CounterSpy.


    In your second step, I couldn't find the file C:\program files\RSNet\RSEDNClient.exe, I did find
    that file on the D: drive. I removed that file.

    The rest of the step went with no problems.

    Attached are the log files

    Again thanks for your time and help.
     

    Attached Files:

    Last edited: Jan 20, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At the time you attached your HJT log in message # 2, you had both of those running. Look at the log for yourself. You probably ran HijackThis.exe and never shut it down before renaming the process and running it again.

    Your logs are clean! Just delete the below two folders leftover from CounterSpy:
    C:\Documents and Settings\Thom Waller Jr\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. SpiderWiz

    SpiderWiz Private E-2

    Thanks again for all you hard work. I really appreciate the assistance.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds