Hijack This!, other logs- problems for approx. 2 yrs.

Discussion in 'Malware Help (A Specialist Will Reply)' started by GuitarRon89, Jun 10, 2007.

  1. GuitarRon89

    GuitarRon89 Private E-2

    I've had malware and spyware problems for about two years now, since about 2005, and I've always referenced this place for help. I just got around to fully running everything today, reading every little detail and following the instructions fully (something the younger me did not do), and I found there were a lot of problems. Unfortunately, I could not save my first Bitdefender log, but when I ran it again, there were less programs in the problem descriptions, so I'm not sure if that's a good or a bad thing. Either way, here are my logs and thanks, in advance, for your help.

    -Ron
     

    Attached Files:

  2. GuitarRon89

    GuitarRon89 Private E-2

    Other files attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first thing you need to do is install HijackThis into the proper folder as requested in the READ ME. It does not belong in Quicklaunch and this is a bad place to locate it. There is no reason of HJT to be in Quick Lauch anyway. You have it here:
    C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\analyse.exe

    It needs to be here:
    C:\Program Files\HJT\analyse.exe

    The second thing to do is step 3 of the READ ME. You have Avast and Norton Internet Security installed. Uninstall one of them now.

    Then download and from now on use the correct versions of ShowNew and GetRunKey. You are about a year out of date with ShowNew and a little out of date with GetRunKey. You must always work from the current online copy of the READ and RUN ME.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_06
    Java(TM) SE Runtime Environment 6
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    You have the below installed and they are about 3 years out of date! Uninstall them and install the current versions:
    a-squared Free 1.6
    a-squared Personal 1.6
    SpywareBlaster v3.4


    Is the below R1 search Bar valid? I tend to doubt it! If not valid, add it to the HJT things to fix list below.
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.krizkhbyiwjdq.net/AOuDnItSUvZDcZnQy8RXnqyBjOte2EFHO8Rlm9oucLhw7D_NeTdVmuVZbsSD3v/W.html



    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://adsonwww.com/servlet/ajrotator/128447/0/viewHTML?zone=enternet
    R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\HP_Owner\Desktop\Etc\misc\office\PFILES\MSOFFICE\TEMPLATE\1033\PAGES\SEARCH_T\search.html
    O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
    O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
    O20 - Winlogon Notify: URL - ? ???? (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey - make sure you use the current version
    3. ShowNew - make sure you use the current version
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. GuitarRon89

    GuitarRon89 Private E-2

    Quick question: Can I do this just flat-out or would I have to run all the scans again?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do exactly what I wrote in message # 3 and do it in the order written.
     
  6. GuitarRon89

    GuitarRon89 Private E-2

    Okay, thank you.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just attach the requested logs when you finish. Be sure to use the proper versions of GetRunKey and ShowNew.
     
  8. GuitarRon89

    GuitarRon89 Private E-2

    Avenger, GetRunKey, and ShowNew logs attached here.
     

    Attached Files:

  9. GuitarRon89

    GuitarRon89 Private E-2

    HJT log here.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You ignored my instructions about having only one antivirus installed. You still have all of this from Norton:

    LiveUpdate 2.5 (Symantec Corporation)
    Norton AntiVirus 2004 (Symantec Corporation)
    Norton AntiVirus Parent MSI
    Norton Internet Security
    Symantec Network Drivers Update


    And you also have avast! Antivirus

    Make up your mind which one you want and uninstall the other now. Until this is done we cannot go any further.

    Also you need to tell me how things are working.
     
  11. GuitarRon89

    GuitarRon89 Private E-2

    I remember uninstalling the Norton ones, though. Matter of fact, it asked me to reboot every time and I did. Suppose I'll just try again. Also, things have been running relatively the same.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It shows in your logs! Does it show in Add/Remove programs?

    The same as what?
     
  13. GuitarRon89

    GuitarRon89 Private E-2

    I know it shows in the logs, I'm not sure why. Norton Anti-Virus shows in the Add/Remove Programs menu, but whenever I click it, it gives me an error message that basically says I can't uninstall it. Would going to the program files folder and deleting it do anything?

    The same as before. It's relatively slow, but I think that's because of RAM. At least the programs don't seem as buggy as before, though.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would definitely make it impossible to uninstall it. Give this a run: Norton Removal Tool (SymNRT)

    After running the above attach new logs from ShowNew, HJT, and also run the below and attach a log. We remove any left overs manually.

    Getting Uninstall Programs List From The Registry


    Yes having insufficient RAM is a big problem however running two antivirus programs is also a big drain on system resources. Let's see how things improve once we get rid of all of Norton.
     
  15. GuitarRon89

    GuitarRon89 Private E-2

    Okay, I've run all of those programs, there should be no more Norton on here, and my computer is running a little smoother after I ran that program.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Norton Internet Security is still showing in your uninstall list in the registry. The below will fix this.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Also delete the below folder from Viewpoint Media:
    C:\Documents and Settings\HP_Owner\Application Data\Viewpoint


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. GuitarRon89

    GuitarRon89 Private E-2

    Thank you for all your help and patience!!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds