Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by cockle73, Apr 8, 2007.

  1. cockle73

    cockle73 Private E-2

    Hi, i seem to be having a few problems. 1 - i get runtime error when trying to run quicktime. 2- won't let me run i tunes due to audio config. 3- cant get rid of ultimate cleaner. I have run all my spyware removals, but still doesnt work.
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. cockle73

    cockle73 Private E-2

    Thanks for replying to my message. I have already done what you had asked before i posted the log. Do you think i have missed something? Apologoies if i have
     
  4. cockle73

    cockle73 Private E-2

    apologies, i forgot to run these 2
     

    Attached Files:

  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    I'd say yes to missing something....


    According to your Hijackthis log you have not done what was listed in my post, otherwise your Hijackthis log would not have been run from the ZIP file and with Hijackthis's original file name still evident as the guide highlights Hijackthis.exe should be renamed to analyze.exe, reasons for this are some malwares are sneeky and hide themselfs from this scan so will go un-noticed.

    Then you would have a total of 6 logs to attach....


    • CounterSpy
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis



    You need to uninstall the old version of Java

    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Please do re-read the guide and follow it in the order laid out and repost the logs again, which is a tried and tested method of ours to aid the removal of malware ( Ultimate Cleaner ) you have on your PC and any others as malware these days does not come alone.

    Sadly their are no shortcuts to ridding your PC from malware, not following the guide just extends the time taken to help us, help you :)
     
  6. cockle73

    cockle73 Private E-2

    apologies...will start again
     
  7. cockle73

    cockle73 Private E-2

    Here you go , apologies for earlier
     

    Attached Files:

  8. cockle73

    cockle73 Private E-2

    and these...fir some reason it wouldntlet me save a log for counter spy
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What you mention as a problem in message # 1 about runtime errors is not a topic for this forum. Ultimate Cleaner issues are a topic for this forum.

    Before we can get started we need to take care of a few issues with your over use of antispyware programs. You have NINE installed:

    AVG Anti-Spyware 7.5
    Spy Sweeper
    SpyHunter
    Spyware Doctor 3.8
    SpywareBot 3.6.0.3
    SpywareGuard v2.2
    Sunbelt CounterSpy
    Windows Defender
    XoftSpy


    First I need to know if any of the below are paid versions:

    AVG Anti-Spyware 7.5
    Spy Sweeper
    SpyHunter <-- this should be uninstall no matter what
    Spyware Doctor 3.8
    SpywareBot 3.6.0.3 <-- this should be uninstall no matter what
    Sunbelt CounterSpy
    XoftSpy
     
  10. cockle73

    cockle73 Private E-2

    paid for most of them , but had some of them for ages....will uninstall the ones u have told me to.

    I need to know the exact list of what is paid and what is free! Only one of the below should be installed and used as an active blocker:
    AVG Anti-Spyware 7.5
    Spy Sweeper
    Spyware Doctor 3.8
    SpywareGuard v2.2
    Sunbelt CounterSpy
    Windows Defender


    And SpywareGuard is too old to be of much use anymore! Any of the others are better choices so add SpywareGuard to the list of things to uninstall too. If Spy Sweeper is paid, I would keep it and uninstall ALL others!
     
    Last edited by a moderator: Apr 10, 2007
  11. cockle73

    cockle73 Private E-2

    AVG Anti-Spyware 7.5 purchased
    Spy Sweeper purchased
    Spyware Doctor 3.8 purchased
    SpywareGuard v2.2
    Sunbelt CounterSpy PURCHASED (I THINK)
    Windows Defender
     
  12. cockle73

    cockle73 Private E-2

    Xsoft Was Also Purchased
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall All except one! As I stated below, I would keep Spy Sweeper if it is the current version of the program. Spyware Doctor 3.8 is out of date. I doubt you purchased CounterSpy since you just installed it on April 4 the which is probably when you started running the READ ME.

    As far as I know Xoftspy provides no active protection and is only a scanner. If it is a blocking tool, I would uninstall it too.

    When you get finished with the above, attach new logs from ShowNew and HJT. Also tell me if you are having any problems. I expect your PC will be a lot faster after uninstalling all of these.
     
  14. cockle73

    cockle73 Private E-2

    Looks good ...Thanks
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now let's make some more improvements and fixes!

    Shutdown Spy Sweeper before doing the below! And after the reboot (which you will do during the procedure), if SPy Sweeper mentions seeing changes to your setting, be sure to approve the changes since we are the one making the changes.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" /R
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below folders and delete it if found:
    C:\Documents and Settings\Paul\Application Data\eAcceleration
    C:\Program Files\eAcceleration
    C:\Program Files\SpywareBot
    C:\Program Files\Common Files\eAcceleration

    Also delete the below file if found:
    C:\Program Files\MSN Messenger\riched20.dll

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  16. cockle73

    cockle73 Private E-2

    Did as you said. . Wouldnt let me delete file
    C:\Program Files\MSN Messenger\riched20.dll (access denied)

    Also, Something about Dr waton came up and the system just stopped. Had to reboot.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you exit MSN Messenger which you appear to run at startup and also exit ALL browsers before fixing. If that does not work, do the same from safe boot mode.

    Not helpful! When you receive any kind of message or error message, you must tell us exactly (word for word) what it says.


    Your logs are clean! Are you having any malware problems?
     
  18. cockle73

    cockle73 Private E-2

    i will give that a go thanks.....not been on the pc for a while but looks ok other than that...thanks
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds