Mucho Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by smilejack1, Feb 13, 2007.

  1. smilejack1

    smilejack1 Private E-2

    I just started a new job with an old friend, and because he barely knows how to right-click, his computers are a disaster and I've become his default IT person, even though I don't know a whole lot more. I've already removed lots of crap via SpyBot and AdAware and CCleaner, but for various reasons, I suspected there might be more on the machine, so I did the "Read and Run Me First" routine, and the BitDefender log confirms my suspicions. The computer isn't misbehaving in any significant way, but all these Trojans and such trouble me greatly. Any advice concerning which of these things I should worry about and how to remove them will be greatly appreciated.

    PS: I botched the process to save the BitDefender log. I have an HTML and a Word file on my machine. I'm going to attach the word file, and if it doesn't help, please notify me and tell me what to do. If I need to run the scan or even the whole Run Me First procedure, I will.

    PPS: Embarrassingly, I seem to have botched the CounterSpy log. Again, tell me what to do...
     

    Attached Files:

  2. smilejack1

    smilejack1 Private E-2

    Re: Mucho Malware: More Logs

    Here's the active scan log. I just realized that I haven't completed the Hijack This procedure, so I'll finish it and then post that too. Last train to Dorkville...
     

    Attached Files:

  3. smilejack1

    smilejack1 Private E-2

    Re: Mucho Malware Hijack This Log

    here's the Hijack This log...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Mucho Malware Hijack This Log

    Welcome to Majorgeeks!

    You did not get your HJT log attached. Before trying to attach one, please do the below.

    Based on your GetRunKey log, you skipped step 2 of the READ ME or you did not complete all of it properly. Please do step 2 again and make sure you do all steps. I will ask for a new log later.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Think-Adz Search Assistant removal <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\aaf.exe
    C:\WINDOWS\invupd.exe
    C:\WINDOWS\invupdi.exe
    C:\WINDOWS\system32\edaabe_s.dll
    C:\WINDOWS\system32\winpfg32.sys
    C:\WINDOWS\system32\swinnpem.exe
    C:\WINDOWS\system32\swinnpes.exe
    C:\WINDOWS\system32\xmltok.dll
    C:\WINDOWS\system32\analiz.exe
    C:\WINDOWS\system32\msfyir.exe
    C:\WINDOWS\system32\specialfile.exe
    C:\WINDOWS\system32\kyhwp.exe
    C:\WINDOWS\system32\uctmtdfxf.exe
    C:\WINDOWS\system32\wvsvc.exe
    C:\WINDOWS\system32\systemwin32s.exe
    C:\Documents and Settings\Owner\lc2.html
    C:\Documents and Settings\Owner\Local Settings\Temp\sahagent.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr1D4B
    C:\Documents and Settings\Owner\Local Settings\Temp\temp.frC6C7
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
    Last edited: Feb 14, 2007
  5. smilejack1

    smilejack1 Private E-2

    Re: Mucho Malware - hjk log attempt 2

    Round 2 commences
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must attach all of the logs I requested before we can continue.

    You also need to answer my question about how things are working.
     
  7. smilejack1

    smilejack1 Private E-2

    Thank you for assistance, and I apologize if my many blunders have made it more difficult for you to render it. It's not that I'm a complete idiot, it's that I'm dealing with this problem with one hand and 6 other office crises with the other. Thanks and apologies again.

    I've followed your instructions (correctly, I hope) and attached the requested logs. The computer isn't misbehaving in any significant way. It wasn't before, either. I was just worried because there was obviously a ton of junk on this machine, and I was worried about potential malfunctions and security threats and being a spammer or a hacker or somesuch without even knowing it. Thanks again for your help...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's hard to understand considering all the malware and other issues you had/have.

    You still seem to have multiple antiviris/security suites installed. We asked that you not do this in step 3 of the READ ME. Please choose which one you want. Either CA eTrust or Symantec and then uninstall the other. This is a massive waste of system resources and can make either program less effective. It is also making it difficult to fix some of your problems. Some of what I asked you to fix did not get fixed.

    When you added the fixME.reg patch into the registry by double clicking on it, did you get a success message? Did you get a popup warning from your protection software about a change being made? You need to allow this to run or obviously the fix will not work.

    Let's start again (with some new steps too) BUT make sure you have uninstall one of the antivirus applications now before continuing.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Make sure you save it exactly as requested (all files) and save it to your Desktop. You did not do this last time.
    Make sure you tell me if you get a success message for doing the above. Or if you get a failure of some kind, tell me the message. DO NOT let you protection software block the change.

    Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software"
    C:\Program Files\Sunbelt Software

    Also delete the below folder:
    C:\Documents and Settings\The Real John Wright\Start Menu\Programs\Startup\Think-Adz.lnk

    Run HijackThis and select the following lines (some may not be found if the above fixME.reg patch works) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: (no name) - {2DEA8791-C2B7-48E1-8992-8E8E6A6FE789} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Bar Ding lolt] analiz.exe
    O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swinnpem.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    After clicking Fix, exit HJT.
    Now reboot in normal mode


    Now right click Start and select Explore. Navigate to the below files and delete them if found:
    C:\WINDOWS\system32\analiz.exe
    C:\WINDOWS\system32\swinnpem.exe

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  9. smilejack1

    smilejack1 Private E-2

    Thank you for your help and especially your patience.

    I have followed the latest instructions. The following notes apply:

    1) I received a success message after running the fixME.reg patch.

    2) The following folders did not appear where I was instructed to look, so I was unable to delete them:

    C:\Documents and Settings\All Users\Application Data\Sunbelt Software"
    C:\Program Files\Sunbelt Software
    C:\Documents and Settings\The Real John Wright\Start Menu\Programs\Startup\Think-Adz.lnk

    3) The following files did not appear in HijackThis:

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Bar Ding lolt] analiz.exe
    O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swinnpem.exe

    4) The following files were not visible when I right-clicked Start:

    C:\WINDOWS\system32\analiz.exe
    C:\WINDOWS\system32\swinnpem.exe

    The computer seems fine.

    I want to comment on a few things from your earlier messages, and I hope you understand that I'm not bickering or being contentious.


    From your most recent message:

    >"You still seem to have multiple antiviris/security suites installed. We asked that you not do this in step 3 of the READ ME. Please choose which one you want. Either CA eTrust or Symantec and then uninstall the other. This is a massive waste of system resources and can make either program less effective. It is also making it difficult to fix some of your problems. Some of what I asked you to fix did not get fixed."<

    I don't think I do have multiple security suites installed. The only Symantec product that I am aware of on this machine is Norton Ghost, which is a backup product. After I read the above, I checked 4 of the 5 user accounts on this machine (see a note about user accounts way below), and found nothing else from Norton in Add/Remove programs, nor in Start/All programs, nor on the MSCONFIG Startup tab (and I've been running various combinations of Norton Anti-Virus/System Works/Internet Security at home for 6 years, and thus have some idea of what the Startup entries look like).

    Also from your most recent message:


    >"When you added the fixME.reg patch into the registry by double clicking on it, did you get a success message? Did you get a popup warning from your protection software about a change being made? You need to allow this to run or obviously the fix will not work."<

    I did run it, and got a success message. I've forgotten the exact words, but it was quite similar to the one I got after running the second fixME.reg patch you instructed me to run.

    And from the message before your most recent message:

    >"Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Think-Adz Search Assistant removal <-- should have been uninstalled in step 0 of the READ ME
    "<[

    It was several days ago, but I'm fairly certain I did uninstall Think-Adz, also. In fact, when I first began trying to clean up this machine, a "Think-Adz" entry appeared in MSCONFIG/Startup, as did a "swinnpem" entry, and when I unchecked them, they re-checked themselves on subsequent bootups. Then I found Think-adz in Add/Remove Programs and uninstalled it, and it reappeared there, too. These are the reasons I first contacted you.

    Which leads to one other issue I probably should have mentioned in my initial post. This machine has a user account named "David Crowley", and as he is out of the country for several months and we don't know his password, I was unable to run Ccleaner on his account, as instructed in the "Read Me".

    I want to make sure you understand why I have mentioned the above matters. I'm not trying to be defensive or belligerent. I just want to make sure you have all the relevant information. I understand that you do this on a volunteer basis and I have the highest respect for your efforts. In fact, if you or the site have a need for a skilled free-lance writer, I'm eager to assist, and if you own a house in the Dallas/Fort Worth which needs roofing, siding, or windows, my company will give you the brother-in-law price. Thanks again for your help...
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm note sure how you are looking for them but the first two are gone;however the ThinkAdz.lnk file is still there. See for yourself in the newfiles.txt log you just uploaded. You MUST use Windows Explore to look for it. Do not use Windows Search if that it what you are doing. You still need to delete this file.

    Also delete the below folder from a rogue tool that you should not use:
    Code:
    "C:\Program Files\
    SPYWAR~1      Feb  9 2007              "SpywareBot"

    Note: The fixME.reg patch merged in this time properly. The last times it did not. I know this based on the contents of your GetRunKey log.

    Not True! Look at the HijackThis log you just posted!

    I asked also asked you to uninstall CounterSpy, but it still shows in your HJT log as being installed. It is however not showing in the newfiles.txt log which means it was uninstalled. These problems may be occurring due to the multiple security suites still running. Registry entries (including the malware ones we are trying to fix) are not getting cleaned up.

    Let's go thru your HJT log and point things out! I will show Symantec/Norton AV in BROWN, Norton Ghost in BLUE, CA eTrust in PURPLE and other malware (some I ask you to delete a few times & one is new) in RED. They are in your HJT log. If I can see them, you should be able to see them.

    The below are directly quoted from you current HJT log! If Symantec AV did not exist, it could not be running as it is!

    It seems to be uninstall now based on your last newfiles.txt log.

    Running CCleaner on his account may be the least of the problems. He could have malware infections in his account.

    My proposal at this point is that we start working on removing all the Symantec Antivirus stuff to make sure it is not the cause of our difficulties in fixing things. Due to the fact that both it and CA eTrust are still running it may really be necessary to uninstall (temporary) both of them to get this fixed properly.

    What do you think?

    I will start posting things later tonight, but in the mean time relook at the malware which you said you did not see in your HJT log and fix it (all the RED items from above). Also fix the O4 line for CounterSpy. Also delete the below file:

    c:\windows\system32\crsss.exe <---- Becareful!!!!! Do not confuse this with csrss.exe which is a valid file. Notice how the first rs is reversed from the valid file.
     
  11. smilejack1

    smilejack1 Private E-2

    Truly bizarre. I'm going to go into work tomorrow solely to deal with this.

    Questions before I try what you recommend:

    I think I was using My Computer instead of Windows Explorer to look for

    C:\Documents and Settings\All Users\Application Data\Sunbelt Software"
    C:\Program Files\Sunbelt Software
    C:\Documents and Settings\The Real John Wright\Start Menu\Programs\Startup\Think-Adz.lnk

    Would that have made a difference?

    Also, about this:

    I will start posting things later tonight, but in the mean time relook at the malware which you said you did not see in your HJT log and fix it (all the RED items from above). Also fix the O4 line for CounterSpy. Also delete the below file:

    I'm not quite sure what you mean when you say "fix it". Do you mean to run HJT again and remove it that way?

    Also, I'm quite ready to uninstall both AV programs (or anything else you recommend). But how will I be able to do this if Norton AV does not appear in Add/Remove programs?

    Also: I spent a good deal of time today working on this and I was quite thorough. I am virtually certain I did not see what I said I did not see, even though the various logs contradict me. Is that possible? And if I go back tomorrow and see (or not see, rather) the same things, should I take screenshots and post those? I'm also certain I uninstalled CounterSpy, yet there it is in the HJT log, as you noted. Is it possible both things are true?

    Also, at this point, does it matter which user account I'm in n when I perform the operations you recommend?

    Finally, the data in the David Crowley user account which we would have to have is probably available via Shared Documents. If necessary, I could probably get it out that way and delete the account. Would this help?

    I wish I could adequately express how much I appreciate your assistance...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! My Computer is Windows Explorer. As I said the first two are gone, but ThinkAdz.lnk is not.

    No there is a lot more involved since there are running processes and services. Yes HJT will be used in some steps but it is not so straight forware. I will start posting steps for you as soon as I can. Been too busy to get started on it yet and it will take some time to work up the procedure.

    I'm going to work up manual stepsl however, give the following a try and see it can help us get rid of some of it. NOTE: Before running the following tool, I want to warn you that it will try to remove ALL Sysmantec products (including Norton Ghost). See the list on the download page. You can always reinstall Norton Ghost after we get your problems resolved (but make sure you only install Norton Ghost and nothing else). Run this Norton Removal Tool (SymNRT) Attach a new HJT log afterwards!


    No! Unless the logs were not obtained in the correct order in the procedures. The logs do not lie. As I said CounterSpy is uninstalled but one startup is trying to load (seen in HJT). I still feel that the multiple antivirus applications are making it difficult for things to be removed properly (even uninstalls are not working properly - the AVs are probably blocking registry changes).

    You must be in the user account that you posted the logs for.

    No! There is a lot more to it than that! Each user account has their own registry data too.
     
  13. smilejack1

    smilejack1 Private E-2

    I read your latest post this morning and came to work, booted up (in selective start up with only vital apps running) opened Firefox to re-read your post, and then checked for C:\Documents and Settings\The Real John Wright\Start Menu\Programs\Startup\Think-Adz.lnk and the other files we've been discussing. I used Windows Explorer. Think-adz was not there, I'm certain of it. I then downloaded a trial version of Screenshot Utility (found here http://www.screenshot-utility.com/ ) and installed it, rebooted in Normal mode, opened Firefox again to view your post, and checked for Think-Adz, and it was visible. I deleted it. I have made no other changes to this machine.

    This machine has so much junk on it, that when I boot in normal mode it barely runs, so I've been booting in selective mode except when you instructions specifically say other wise. If that might account for the discrepancies between what you see and I see, tell me, and tell which way I need to boot. I can provide a list of what I run in Selective mode if you need it.

    Next, I deleted "C:\Program Files\
    SPYWAR~1 Feb 9 2007 "SpywareBot"

    Next I ran Hijack this. I've taken a screenshot of all the entries beginning with 04 - HKLM. It's too big to post, but I can e-mail it to you. It shows that neither of the following appear:

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Bar Ding lolt] analiz.exe

    I've looked in the HJT log I posted yesterday, both the copy on my hard drive and the copy that exists here on majorgeeks in my post yesterday, which you referred to in this passage (your words in red, mine in green):


    3) "The following files did not appear in HijackThis:

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Bar Ding lolt] analiz.exe
    O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swinnpem.exe


    Not True! Look at the HijackThis log you just posted!"

    I do not see them therein. As you can see, an entry similar to

    O4 - HKLM\..\Run: [Bar Ding lolt] analiz.exe

    appears, both in yestreday's logs and today's screenshot, but beginning with HKCU. This entry is in yesterday's HJT log, but not the HKLM variety.

    Thinks Adz was not here today, although I can see it was yesterday. Is it not there today 'cause I just deleted the folder?

    Also, I checked the timestamps on the three logs, and i did them in the correct order - GetRun, then ShowNew, then HJT. And, just in case you need documentation,I have screenshots of those timestamps if you need verification, as well as screenshots of MSConfig, showing that the only Symantec/Norton product appearing there is Ghost appears there, and of Control Panel/Add Remove, showing the same about Norton/Symantec.

    I'm going to post this and thentry the Norton Removal Tool. Thanks again for your help...
     
  14. smilejack1

    smilejack1 Private E-2

    I tried the Norton Removal Tool. I got an error message saying it was expired and directing me to this link http://service1.symantec.com/SUPPORT/sharedtech.nsf/docid/2006050909471013 .

    I followed the instructions there and tried the Tool again, and got the same message.

    I've also tried to delete c:\windows\system32\crsss.exe , but it is not visible there. I have a screenshot verifying this.

    This post and the last detail EXACTLY what I've done to this machine since post #9, yesterday (Friday) at 15:04. I will make NO other changes until I hear from you again. Thanks yet again...
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in step 0 of the READ ME, you must remain in Normal Startup mode for us to be able to help you. Yes this can be the cause of discrepancies and it is the reason for step 0 saying what it says. Please get in Normal Startup mode, check for the items mentioned in your HJT log and fix them if found.

    Now I will give you steps to remove the Norton stuff that is probably the reason for you PC being so slow.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Event Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Symantec Password Validation
      • Symantec Settings Manager
      • Symantec Core LC
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste ccEvtMgr into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • ccPwdSvc
      • ccSetMgr
      • Symantec Core LC
    • Now exit HJT and reboot when it tells you it needs to.

    After reboot, attach the below new logs while in Normal Startup mode
    • GetRunKey
    • ShowNew
    • HJT
    If there are any other programs that you can uninstall (i.e., you don't need them - consider doing so).
     
  16. smilejack1

    smilejack1 Private E-2

    Followed your instructions. See attached logs.

    As far as your advice to uninstall unnecessary software, I'm planning to do so, but first I've got to figure out who uses what around here. If there's anything that you think might be contributing to the current malware, problem, however, just say the word and it's gone...
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\swinnpem.exe GID002
    O4 - HKCU\..\Run: [start uploading] crsss.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\crsss.exe
    C:\WINDOWS\system32\swinnpem.exe
    C:\WINDOWS\System32\IPX32d56.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  18. smilejack1

    smilejack1 Private E-2

    All steps completed as instructed. No error messages or other noteworthy phenomena.

    Norton Ghost no longer works due to the components we removed. I'm going to uninstall it unless you tell me I shouldn't.

    Other than that, the machine seems fine...
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have on more left over line to fix with HJT. Fix this:
    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe

    I would uninstall all of the below if they show in Add/Remove Programs.

    LiveReg (Symantec Corporation)
    LiveUpdate 2.6 (Symantec Corporation)
    Norton Ghost 10.0
    Notifier

    Then reboot! If you really need Norton Ghost, then reinstall it but make sure that you only install Norton Ghost and none of their other junk! It does not make sense that they should require all that garabage to be installed and running just to use Norton Ghost. If they do, you should find another product to replace Norton Ghost.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  20. smilejack1

    smilejack1 Private E-2

    One more time: I am very grateful, both for your help and your patience...
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds