Almost clean, almost

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wsn, Jan 13, 2006.

  1. wsn

    wsn Private E-2

    Hijack This, Panda and Bitdefender logs, HELP!

    Hi,
    I have been having problems with my computer bogging down. After hitting control, Alt, Delete I noticed that some applications were using 100% of my CPU, even if the applications were not running. A friend referred me to MajorGeeks, and I am glad he did. It sure is nice to know that I am not alone.
    I currently use Norton Antivirus and the Windows Firewall.
    Anyways, I followed all 7 of the steps. I have attached the Hijack This!, Panda and bitdefender logs. I can not believe all of the things that showed up during these scans. How do I go about deleting the entries on the Panda, bitdefender & Hijack this! logs?
    Any help would be greatly appreciated.
    Thanks,
    Mario
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Welcome to MGs.

    Do you have the full log from BitDefender? What you posted only gives the names of the malware but not where it found them. Normal logs always show the path and name of the file that is deemed to be malware.
     
  3. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I will rerun bitdefender and post the log.
    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Don't worry about it now but didn't you just save the full log to a file when first run?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Your HJT log does not really indicate any malware problems. Are you having any?

    A few minor things can be fixed from the Panda log.

    The below file can be deleted:
    C:\WINDOWS\SYSTEM32\MYDLL.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    You may want to also run this KazaaBegone
    Since I can see remnants of Kazaa having been on this PC.
     
  6. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Here is the new bitdefender log. I thought I saved the full log the first time. This time it looks different. I deleted C:\WINDOWS\SYSTEM32\MYDLL.dll
    file and yes I did have Kazaa on this computer. Instant mistake! I thought that I had already removed all of it but I will use the Kazaa begone program.
    Should I go and delete everything that shows up in the bitdefender log?Thanks,
    Mario
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Most of what is in your BitDefender log is just saying the files are clean. However, it would be a good idea to dump the Norton AntiVirus Quarantine folder to make sure all the bad stuff is removed.
     
  8. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    test
     
  9. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Hi,

    I deleted the Quarantined files. I ran Kazaabegone and it pulld up some things. I told kazaabegone to search for installed components only , not search & destroy.

    Any ideas on what I don't need?
    Can I let it delete or destroy everything?

    Thanks again,
    Mario
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Did you install or do you use InstallShield\Professional yourself. It is a valid application?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I don't think I've ever used Installshield\professional. I thought it was some sort of Windows thing. What is this?
    REGKEY: [MediaLoads] HKLM\Software\Microsoft\DownloadManager
    Thanks,
    Mario
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    You don't need it then and it is not part of normal Windows.

    See the below for additinal info about MediaLoads:
    http://www.doxdesk.com/parasite/DownloadWare.html
    http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073183

    Just let the tool fix the stuff found.
     
  14. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Well, I let kazaabegone delete everything. I followed those 2 links you gave and in going through my registry, I found some KDX stuff. Is this bad? I thought I read somewhere that KDX was a trojan?

    The registry info is:

    HKEY_CLASSES_ROOT\KDX.Api
    HKEY_CLASSES_ROOT\KDX.Api.1
    HKEY_CLASSES_ROOT\KDX.Collection
    HKEY_CLASSES_ROOT\KDX.Collection.1
    HKEY_CLASSES_ROOT\KDX.Frame
    HKEY_CLASSES_ROOT\KDX.Frame.1
    HKEY_CLASSES_ROOT\KDX.Host
    HKEY_CLASSES_ROOT\KDX.Host.1
    HKEY_CLASSES_ROOT\KDX.Install
    HKEY_CLASSES_ROOT\KDX.Install.1
    HKEY_CLASSES_ROOT\KDX.UI
    HKEY_CLASSES_ROOT\KDX.UI.1

    Thanks again,
    Mario
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    It probably has to do with the below that you or someone else using the PC downloaded:
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/zd/kdx.cab

    It is a legit entry but may no longer be supported by GameSpot. See the below:

    GameSpot DLX Secure Delivery Plug-In
     
  16. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Three things.
    1. I followed that link to Game Spot, and then tried to follow the link to the cleaner but I get an error 404 message. Here was the link I tried to follow.
    http://content-stage.kontiki.com/support/KClean.exe
    I even called a friend and he coudn't access it either.

    2. I purposely left my computer on all day today to see if any programs started using my cpu @ 100%.
    Sure enough, msmsgs.exe was using 100% of my CPU.
    I ended the process and then rundll32.exe starting using 100% of the CPU.
    So, I ended that process and then couldn't get anything else to work.
    Should I start the whole process over again, or can I just work on those to processes?

    3. THANK YOU SO MUCH FOR HELPING ME WITH THIS! Even though I feel like I know more than the next person when it comes to computers, I don't know what I would have done without your help.

    THANK YOU
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    You're welcome!

    Use the following to remove Windows Messenger: Disable/Remove Windows Messenger

    You don't need it and it has been known to allow popups to occur on PCs. This is not the same thing as MSN Messenger which is more secure.

    First look in Add/Remove programs for Kontiki or Secure Delivery and uninstall in found. Now have HJT fix the below line:
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/zd/kdx.cab

    Please download the attach GetRunKey120.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment.

    Now also attach a new HJT log. I want to make sure nothing else has found its way into your PC.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Let's get an installed programs list from HijackThis too.
    Run HijackThis, click Open the Misc Tools section
    Click "Open Uninstall Manager"
    Click "Save List" (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I found secure delivery in add/remove programs and uninstalled it.
    I ran runkey and attached it.
    I ran hijack this! and the log is attached. I could not find the file:
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743}
    I did not have Hikack this! delete anything.

    I also attached the hijack this! uninstall list.

    Thanks,
    Mario
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    When you uninstall Secure Delivery, it removed the O16 line.

    You look to be clean. Are you having any other malware issues?
     
  22. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I just have one last question.
    When I hit control, alt, delete, I see two lines which stand out to me:
    adservice.exe & adusermon.exe

    Are these normal?
    I am suspicious everytime I see ad in anything on my computer.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Just looking at your HJT log can tell you what they are for. Take a look. Notice that they are from Iomega. Probably you have Zip drive.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  24. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    You are right, it's iomega zip drive stuff.
    Thanks again for all of your help.
    Mario
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    You're welcome! Make sure you work thru the How to protect thread.
     
  26. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I was looking at my registry last night because I remembered seeing Altnet somewhere. I think Altnet was from Kazaa. I tried to delete it out of registry, but it wouldn't let me delete it.

    HKEY_LOCAL_MACHINE\SOFTWARE\Altnet

    Is there another way to get rid of it?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    You may need to just take ownership of the registry key and then you should be able to remove it.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Just in case you don't know what "take ownership" means:

    Right click on the key name to highlight it and select Permission menu option. Then in the Security windows. Click Advanced . Now click on each user (one at a time) and click the Edit button. The make sure everyone has a check mark on "full control". Then press apply and ok and attempt to delete the key again.
     
  29. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Well,
    I tried the permission thing and even though I have everything checked, it will still not delete. As a side note, everytime I do a ad-aware scan it notes it, quarantines & deletes it. But, it always come back.
    I don't get it?
    Any more ideas?
     
  30. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Should the only thing checked be full control?
    Permissions for administrators, allow Full control & read
    Under Advanced:
    Everything is set as allow.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    When you set it to Full control, everything underneath should automatically be check (i.e., full control).

    Try the above again and also the Ad-Aware scan but first do the below:

    Right click on the MS Antispyware icon in the system tray and select Shutdown Microsoft Antispyware and approve the shut down when it asks you.

    If Ad-Aware still shows it, post the Ad-Aware log the shows exactly what it is finding.

    Also tell me if you see the following:
    C: \ Program Files\Altnet
    C:\Altnet
    C:\My Altnet Shares

    Also please download RegSrch.zip

    Unzip the archive to your desktop and double click on the VBS file.
    (If your AntiVirus alerts, allow the script to run.

    Now enter altnet

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and attach it in this thread.
     
    Last edited: Jan 16, 2006
  32. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Everything is checked.

    As far as these items:
    C: \ Program Files\Altnet - Don't see it
    C:\Altnet - Don't see it
    C:\My Altnet Shares - Don't see it

    I will run the other things now
     
  33. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Here are the two logs
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    You have not followed the instructions in the READ ME properly. As a result, you do not have the proper version or Ad-Aware SE. You were supposed to check all of our links to make sure you have the correct versions. Is there anything else that may not be updated properly? Check to make sure.

    Start by downloading and installing and updating the correct version of Ad-Aware SE.
    Then do the below:


    Right click on the MS Antispyware icon in the system tray and select Shutdown Microsoft Antispyware and approve the shut down when it asks you.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    No run the new Ad-Aware SE 1.06 and see if Altnet is still detected.
     
  35. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I had updated the definitions for Ad-aware, but I didn't realize there was a newer version. I am downloading and installing it now.
     
  36. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I had the correct version on the other programs, just not ad-aware.
     
  37. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Altnet was detected by ad-aware. Here is the log.
     

    Attached Files:

  38. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    oh yea, I did the fixme.reg thing before I ran the scan with ad-aware.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    That's the same registry key as in the list in my registry patch that was merged in.

    Are you sure MS Antispyware was shutdown first before applying the patch?
     
  40. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Yes, MS Antispyware was shutdown. Should I try it again?
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    No! Do you have Administraor priviledges on the account you are logged in with?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Where I was headed in my last message was this:

    I want you to boot in safe mode and login to the Administrator account.

    Then run regedit and navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Altnet

    Try what we did in message # 28 to set the Permissions so that you (the Administrator) have full control. Then try to delete it.

    If that does not work, back up in the registry to have the below key selected:

    HKEY_LOCAL_MACHINE\SOFTWARE

    That's one level higher now try to take full control over the Software key. Once you have full control of the Software key then try to delete the Altnet key.

    Let me know the results. You have to make sure you get control/permissions set properly and you will be able to delete this key. The only reason Ad-Aware and the previous edits did not work is due to a permissions setting being incorrect.
     
  43. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I tried it again. I turned off MS Anitispyware
    Then did the fixme.reg
    Then did the ad-aware.
    Altnet still shows up.

    Should I try to do this same thing in safe mode?
     

    Attached Files:

  44. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    ok, I'll give it a shot.
    Thanks
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    My last message said to do the steps in safe mode!
     
  46. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    I didn't realize you had responded. Sorry
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Okay just let me know if that works. If not, we will have to give another scanner a try. I have used it in the past and it has sometimes worked. I was trying to avoid installing another tool.

    If necessary download, install, and update this trial of Spysweeper

    Then run a scan with it and save the log. Attach the log here later. Also let me know if it was successful at removing Altnet.
     
  48. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Well, it would not let me remove it.
    I made sure the administrator had full control of:

    HKEY_LOCAL_MACHINE\SOFTWARE &
    HKEY_LOCAL_MACHINE\SOFTWARE\ALTNET

    I will try the spysweeper tool later tonight.
    Thanks again,
    Mario

    P.S. After, I am done with this whole thing (if ever!), should I remove some of the programs I have downloaded?
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Let's discuss that later when hopefully we get this last item removed.

    Did you complete all steps in the How to protect thread?
     
  50. wsn

    wsn Private E-2

    Re: Hijack This, Panda and Bitdefender logs, HELP!

    Here is the Spysweeper log.
    It found Altnet & DELETED it!!!!!!!!!!!!!!!!!!!!! :) :) :) :) :) :) :) :)

    :D

    I haven't gone through & completed all the steps in the How to protect thread? But, that is next.
    Now, which programs should I keep, and which ones should I uninstall?

    THANK YOU.
    Mario
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds