hlep download getrunkey

Discussion in 'Malware Help (A Specialist Will Reply)' started by jball23, Apr 23, 2007.

  1. jball23

    jball23 Private E-2

    I'm trying to download the getrunkey to remove the spyware from my computer and everytime i click to download it, it goes to a log in screen. so i log in again and this happens over and over. what am i doing wrong?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At the top right area of your browser Window where you Login to Major Geeks, you must click the Remember me check box when you login.
     
  3. jball23

    jball23 Private E-2

    I tried that. It keeps me logged in until i click on the getrunkey.zip to download then it goes to the log in screen. I log in again and check the remember me box and it shows the welcome screen for a second then goes right back to the log in screen.
     
  4. jball23

    jball23 Private E-2

    I can download the shownew without any problems it is just the getrunkey that i am stuck on.
     
  5. jball23

    jball23 Private E-2

    NEVERMIND. I GOT IT! I was on my brothers computer trying to fix it for him and it would not stay logged on for whatever reason, (yes, i clicked the remember me box). I got on my computer and downloaded on it just fine. Now i have to transfer it to his. Thanks anyway guys.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you will be back to attach logs since you appear to be working on the READ ME.
     
  7. jball23

    jball23 Private E-2

    Ok, here are the logs. I hope I got everything you need. After doing all this I can tell that the computer is not as slow as before, but, the malware wiped is still on there even after i did the special procedure. I noticed after doing the malware removal guide that it could not find the files or execute some of the commands. Thanks so much for trying to help me.
     

    Attached Files:

  8. jball23

    jball23 Private E-2

    Here are the others. Thanks again!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  10. jball23

    jball23 Private E-2

    here is the first one. It didn't take long at all to scan.
     

    Attached Files:

  11. jball23

    jball23 Private E-2

    here is the second report. I think (cross my fingers) that the problem is fixed.
     

    Attached Files:

  12. jball23

    jball23 Private E-2

    Here are the others. Should I go ahead and do the toggle system restore?
     

    Attached Files:

  13. jball23

    jball23 Private E-2

    I was looking at the properties on my computer, and in the system restore tab, the box beside "turn off system restore" is already checked before i done anything to it. So for the toggle system restore i just go and uncheck it right? Oh, and how much disk space should be used for the system restore? And also i noticed a "browser protection volume" program in the add/remove programs, is it supposed to be there? To me is sounds like something sneaky. Thank you for all of your help, it is GREATLY appreciated! Hopefully this is all the questions so you can get to helping someone else.
     
    Last edited: Apr 25, 2007
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will get to your questions later! First let's finish with the cleanup! We have a little more to to.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 10

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Please run this procedure Getting Uninstall Programs List From The Registry and attach the requested log.

    Also how are things currently running?

    Do you have anything from Symantec stil installed? I see the below service trying to load but I don't see any Symantec products installed:
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
     
  15. jball23

    jball23 Private E-2

    Things seem to be running great! The malware wiped is gone from the home page. As for the symantec program I don't know what it is, so i asked my brother (it is his computer) he doesn't know either. Should I try to delete the file? Here is the log you asked for. Thanks!!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Services are not so straight forward to remove. The below will remove it.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Lic NetConnect service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteCLTNetCnService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now goto Add/Remove Programs and uninstall the four below items which are all part of the Video Ax Object infection you had (this is part of the SmitFraud family of infections):
    Browser Protection Volume
    Internet Explorer Secure Plug-in
    Security Messenger
    Screensavers Installer Version 2

    Then as a backup to the above uninstall (just in case they don't uninstall or you cannot find them), use the below registry patch. Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MalwareWiped 5.8] "C:\Program Files\MW\MalwareWiped 5.8\MalwareWiped 5.8.exe" /h
    O15 - Trusted Zone: http://forums.majorgeeks.com
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\tecerscg.txt
    C:\Program Files\MW <--- the whole folder
    C:\Program Files\Common Files\Symantec Shared <--- the whole folder
    C:\Program Files\Video AX Object <--- the whole folder

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds