Another messed up computer!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rolnthndr, May 27, 2010.

  1. Rolnthndr

    Rolnthndr Private E-2

    Hello everyone,
    I have an older dell desktop with winxp sp3 ie8 installed with 2 user accounts one is admin the other is restricted. I thought that browsing with the "guest" user account would prevent any infections from accessing the admin side and make my www carefree.....wrong again.My problem is the admin acct. is working fine but the "guest" user acct. has an res:ieframe.dllerrorhtm and will not allow access to the internet.I used the "read me" forum to try to fix the problem attached are the log files for the diagnostics I have already run.
    As part of the repair process I removed AVG8.5 and replaced it with Avast! free edition,it was the AVG that let this problem happen and you recomended the Avast so I changed them.I am able to use the web and will anxiously await your diagnoses.
    Regards, Rolnthndr
    ps:Great site!!!
    pps:I need to send another post with the root log.
     

    Attached Files:

  2. Rolnthndr

    Rolnthndr Private E-2

    Hello again,
    I sent you the root log and not the mbam log,here it is.I will check in often in case I haven't sent you what I was supposed to.
    Regards,Rolnthndr
     

    Attached Files:

  3. Rolnthndr

    Rolnthndr Private E-2

    Hello again,
    I was looking through other threads and realized that I missed an attatchment
    the mglog.Here it is hope this helps you fogure out my issue.

    Thanks,Rolnthndr
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, Rolnthndr

    I also need the log from running ComboFix.

    dr.m
     
  5. Rolnthndr

    Rolnthndr Private E-2

    Hello Dr M.
    I am looking for the log files for combofix and I do not see the 'txt' file extension.If you could give me a file name I can send it promptly.In other threads you made a point of not running combofix back to back I will wait for further instruction.

    Thanks again Rolnthndr
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Rolinthndr

    Let's get things started by doing this:

    Please set MSconfig for "Normal Startup mode" as instructed in the READ & RUN ME First guide.

    You were instructed to only run each scanner one time - you ran MBAM & SAS three previous times before attaching the logs that show nothing. I need to see what was detected and removed.

    Attach these logs in your next reply:
    *Your ComboFix log is shown here: C:\ComboFix\ComboFix.txt

    I strongly recommend that you clean up this account's Desktop immediately leaving only links.[ C:\Documents and Settings\PC User\Desktop] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    * You should increase your installed RAM to atleast 1GB for running XP without experiencing system lags.
    Total Physical Memory ------ 768.00 MB
    Available Physical Memory -- 432.16 MB

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.


    Step 3:
    Now Copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Step 4:
    Using Windows Explorer - navigate to and delete:
    • C:\$AVG8.VAULT$

    Step 5:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 6:
    Now install the latest Sun Java Runtime Environment

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited: May 28, 2010
  7. Rolnthndr

    Rolnthndr Private E-2

    Hello again,
    first off sorry for the mixup,Iam working on the steps you layed out in the previous post.I will send the lods to you as soon as I get them so far I am in normal start with the required restart.

    Thanks for the patience R
     
  8. Rolnthndr

    Rolnthndr Private E-2

    Hello Dr M,here are the Supera logs,I will send you a more descriptive post after I catch-up.The other 2 "mbam" logs will be in another post

    Thanks again R
     

    Attached Files:

  9. Rolnthndr

    Rolnthndr Private E-2

    Hello again,
    here are the 2 "mbam" logs. Working on the other items....

    Thanks again R
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    I'll look over those logs and wait for the new MGlogs.zip.

    dr.m
     
  11. Rolnthndr

    Rolnthndr Private E-2

    Hello,Good morning,
    whew what fun eh? Dr m. this is a real journey I followed the plan and have attatched the results.More bad news the "guest" user acct. still has the iefield.dllerrorhtm. The good news is everything you requested in the long post has been done and worked well.
    I will upgrade the ram when the next computer show hits town.I moved most of the shortcuts and files off the desktop.One of the two files was not on the HJT scan only the BHO wormrader was listed,I had BHO fix it after closing ie browser.I was wondering...is my problem common,rare or shit just happens?Thanks again,R
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, Rolnthndr

    iefield.dllerrorhtm is an unknown - what is the full filepath of its detection?

    Do you recognize this folder? c:\documents and settings\Guest\Local Settings\Application Data\wwpsduabj



    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the "Input script here:" part of the window.
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    * Now update the definitions for MBAM and SAS > re-boot your pc > log into the "Guest" account and run "Quick scans" with those two scanners.



    Please attach to your next reply:
    • updated mbam-log.txt
    • updated SAS Scan log
    • C:\avenger.txt
    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited by a moderator: May 28, 2010
  14. Rolnthndr

    Rolnthndr Private E-2

    Hello dr m,
    I see you stayed up late last night.I have trouble seeing the error code in the bottom left corner of the ie browser window,I am able to see it flash when the error occurs then it disappears.However by opening and closing the browser many times I was able to get this "ieframe.dll dnserror.htm".The next set of logs will be attatched to my next post.

    Thanks again,R
     
  15. Rolnthndr

    Rolnthndr Private E-2

    Good morning,
    I updated mb and sas and ran them both, here are the log files.In your last post there is a file that you wanted me to evaluate "c:\documents and settings\Guest\Local Settings\Application Data\wwpsduabj"I don't think this is anything I need,or downloaded,it may be deleted.Hey doc I found some logs in the guest user account application files.I sent one attatchment with this post,I wonder if the guest user acct. is acting as a virtual pc with none of the scans that I am performing in the admin acct getting the bad info from the guest user acct.More "guest" user logs in the next post.

    Thanks again R
     

    Attached Files:

  16. Rolnthndr

    Rolnthndr Private E-2

    Hello,
    Here are the other log files I found under "guest" I believe that the mb that is in admin is not the same mb that I used in "guest" I tried to update mb in the guest user account and it did not upgrade.This is due to the dns error in the guest ie browser.I wonder why mb in the admin doesn't upgrade the guest mb at the same time?I checked the c:\documents and settings\Guest\Local Settings\Application Data\wwpsduabj file in guest and it is an empty file I deleted it and there were 3 other files that were empty that I deleted also.

    Thanks again, R
     

    Attached Files:

  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Good Afternoon!

    Yep - I stayed up abit last night.

    Tell me, which version of IE were you using in the guest account that received the error?

    I'm noting that you have already tried using XP TCP/IP , while I confer with my colleagues about your problem.

    dr.m
     
  18. Rolnthndr

    Rolnthndr Private E-2

    Heh doc,Good afternoon!,
    the guest user has ie8 installed in december 2009. The tcip program was one of the steps in the read me first post.I downloade it from mg and ran it early on maybe tuesday.The admin side of the box is working great!Let me know if you want any feedback I am much better at working the fixers now.

    Thanks again,R
     
  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    Thanks for the feedback - it may take a little time for my next reply, please be patient.

    dr.m
     
  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    rolleyes

    Well, Rolnthndr -

    It seems that I experienced "target fixation".. and forgot about my surroundings!

    *From the guide How to Protect yourself from malware!
    * I suggest that you do the above and follow that guide's advice about creating a restricted account.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  21. Rolnthndr

    Rolnthndr Private E-2

    Heh doc,
    I finished everything you refered to in your last post.The guest user account is still not working,I disabled it and opened a new user "DR.M" in your honor.
    Both the admin acct. and the DR.M acct. are working fine. I was able to transfer my files from guest over to DR.M without bringing any malware with them.I REALLY appreciate you and the whole Majorgeeks team (army is more like it) for the prompt, knowledgeable,and last but not least thoughtful service you provide.

    Much Thanks, Rolnthndr
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Speaking for the entire team.."You're Welcome", Rolnthndr!

    "Best of Luck" and I hope to see you around the forums,
    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds