How am I looking? (A few logs)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jack Bando, Apr 17, 2007.

  1. Jack Bando

    Jack Bando Private E-2

    New to the forums, heard this was the place to go for PC help.

    My only problems I've had recently are PC occasionally freezing at the login screen (all 3 times it was very cold in the room) and once or twice total lockup a few minutes into using the PC.

    Anyways, I included a few logs, hopefullly someone can look them over and see if I have a problem and don't know it.

    (I tried my best to follow every rule thread I read, but if I missed something, I apoligize in advance)

    Thank you for your help
     

    Attached Files:

  2. Jack Bando

    Jack Bando Private E-2

    another log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the other logs that were requested in the READ ME:
    • CounterSpy
    • BitDefender
    • PandaActiveScan
    Uninstall the software as requested in steps 0 & 6 of the READ ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME



    I see Deal Info in your install programs list. Do you know what this is? Does it show in Add/Remove Programs?
     
    Last edited: Apr 17, 2007
  4. Jack Bando

    Jack Bando Private E-2

    Thanks Chaslang for replying

    I didn't have those first three logs the first time because it wouldn't save/upload, wouldn't scan, and wouldn't scan respectively. Did this time.

    (This CS scan was done in normal mode. I did the first one in safe mode, quaratined everything, but had to reinstall CS due to it always saying "Can't open, might be updating.")

    I unistalled that whole list. I didn't see the "get rid of the older Java's" suggestion, and was worried if I uninstalled Java 5.0 Update X, the current model would malfunction. I missed the ViewPoint lines on the list of things to get rid of, oops.

    I have no idea what Deal Info is, it's not on my Add/Remove list, I don't want it, and couldn't even find any idea of what it was from Google.

    Thanks for all the help so far.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ss7S3sg] wdihim.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\sepsd.bin
    C:\WINDOWS\system32\KDP2e0b.dll
    C:\WINDOWS\system32\wdihim.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)


    If Killbox does not reboot just reboot your PC yourself.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Are you having any malware problems at this tim?
     
  6. Jack Bando

    Jack Bando Private E-2

    Problems while doing the list:

    1)O4 - HKLM\..\Run: [ss7S3sg] wdihim.exe wasn’t there anymore.
    2)wdihim.exe wouldn’t go in Killlbox paste.
    3)After looking for the file by hand, it wasn’t there.

    (Would Sophos Anti-Rootkit, AdAware SE, or Avast AntiVirus get this file out on its own? I used them sometime this week after my first post.)

    Did this get rid of that Deal Info thing?

    And, no, I don't see anything my PC is doing wrong or suspicious. (besides the occasional freeze at XP login during cold weather, a once or twice freeze when I made it to the desktop while some programs were still loading, and the very rare auto restart when I try to open a video file in Media Player Classic. I mainly made my original post to make sure everything was okay, I thought it was, but look at all the junk you help me pluck out in the last few days.)

    Thanks for helping
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You changed your PC back into a state where you are using MSconfig to control startup! We cannot fix things if you do this! You must not use MSconfig. See step 0 of the READ ME. Get in Normal Startup mode, reboot, and attach new logs and stay in normal startup mode while we clean things up. And in fact even after we clean things up, you should not use MSconfig to control startups. If you don't need things that are running, uninstall them or permanently delete the from the registry to prevent them from starting up. I do suggest that you uninstall the CounterSpy trial now since we are finished with it anyway.
     
  8. Jack Bando

    Jack Bando Private E-2

    Oops, sorry about that. Guess I turned it back to the other startup mode after the original scans.

    Still have no idea what Deal Info is, so how do I get rid of it/figure out what it is?

    I don't know if this question belongs on the Malware board, but it has been bugging me (please point me to correct board if this isn't it.) Windows Update wants me to DL Update#816093:Microsoft Virtual Machine Security Update. Problem is, I've downloaded it before, and before that, and so on. I DLed it 20 minutes ago, it's still asking me to DL it again.

    Thanks for all your help so far.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Getting Uninstall Programs List From The Registry and attach the log. This will help us figure out how to remove.

    Note my next steps will have some repeats of previous instructions due to the fact that you had turned MSconfig on which prevented previous steps from working.

    Post it in the Software Forum. It sounds like the installation is failing to install properly which will cause it to keep trying.
     
  10. Jack Bando

    Jack Bando Private E-2

    Here's the GetUnKey log.

    Apparently from me skimming the log, Deal Info is connected to EarthLink (My ISP) somehow. If you come to the same conclusion AND think it's not harmful, then I don't want to get rid of it in case it's very important for Earthlink to operate.

    I posted that Q I had on the software forum, thank you.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is from Earthlink! I seriously doubt that it is needed just to have internet acces, but don't worry about it.



    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also delete the below folder:
    C:\Documents and Settings\Owner\Application Data\Viewpoint

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    Do you need to share Windows Media files over a network? If not, fix the below too.
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  12. Jack Bando

    Jack Bando Private E-2

    Those two folders were gone after the uninstall of CS.

    Everything looks/feels good, but I just want to make sure in case I'm wrong.

    Thanks.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to delete the below folder:
    C:\Documents and Settings\Owner\Application Data\Viewpoint


    Other than that, you are clean! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. Jack Bando

    Jack Bando Private E-2

    Everything's done. Thanks
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds