Can someone help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by nascarhunee, Oct 25, 2007.

  1. nascarhunee

    nascarhunee Private E-2

    I am trying to clean up a used computer for my son. I have done the maintanence everyone should do I found in this forum. I have gotten as far as start up items. I dont know which ones to keep or delete. there is a whole list of them. PLEASE help.:confused
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!
    Once we see your logs, we can tell you what needs removing. :)

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. nascarhunee

    nascarhunee Private E-2

    Tim,
    I am computer stupid. So please be kind. I have gotten to the getrunkey.zip step, I am lost. I clicked on the attachment and saved to downloads. How do I unzip?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try something that might be easier for you:

    Download: MGtools.exe and save to the root folder of the drive where you have installed Windows (Typically this would be C:\ and thus you would have a C:\MGtools.exe file after downloading).

    run the MGTools.exe program by double clicking on it.
    • It will create a folder named MGTools in the root folder of the hard disk where Windows is installed ( typically C:\MGTools ).
    • It will also automatically extract a bunch of files into this folder.
    • It will the automatically start running three batch ( .bat files are batch programs ) programs in that folder.
    • It will sequentially run GetRunKey.bat, ShowNew.bat, and GetUnKey.bat and then will also run a file named analyse.exe which is a copy of HijackThis.. Each of these programs will create logs respectively named runkeys.txt, newfiles.txt and GetUnKey.txt. You will notice a command prompt window open and messages will appear in this window. This window will close when the scans are complete for all Win 2K and XP users. Win 9x and ME users will have to close this window manually but only when the scans complete.
    • You may see a popup window with a license agreement for TrendMicro HijackThis. Make sure you click the I Accept button.
    • If you see HijackThis open and/or a log from HijackThis open in notepad, just close HijackThis and the notepad window.
    These log files while be placed in the root folder of your Windows drive. The log file will also automatically be put into a ZIP file named MGlogs.zip which you will be uploading as an attachment to your message in the forum. Unlike older versions of the programs, no popups of the logs will appear when they finish running during this initial installation. At a later time, running any of the individual batch files will still cause the logs to automatically pop up.

    Don't forget to attach the MGLogs.zip file to your message in the Malware Forum.

    At a later time to get new logs as requested, you can individually run any of the batch files by double clicking on them from a Windows Explorer window. Windows Explorer is easily opened by right clicking Start and selecting Explore. The batch file will create a new log and will also update the MGlogs.zip file with each new log created. The person helping you my either request the MGlogs.zip file or the individual logs named runkeys.txt, newfiles.txt and GetUnKey.txt. If you rerun GetLogs.bat (which is the easiest thing to do), it will create 4 new logs to be easily uploaded via the MGlogs.zip file.
     
  5. nascarhunee

    nascarhunee Private E-2

    Tim,
    This seemed alot easier than it looked. I hope I did it right
    Thanks so much :)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Okay ...good.

    I am leaving for the day, so please do the following:

    1. Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\regscan.exe

    If you can't delete it:
    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    HJT
    Avenger
     
  7. nascarhunee

    nascarhunee Private E-2

    Tim,
    I tried everything you said and this is what I got:
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are making progress....
    Attach new logs for:
    ShowNew
    HJT
     
  9. nascarhunee

    nascarhunee Private E-2

    Tim,
    I am sorry what is the shownew?
     
  10. nascarhunee

    nascarhunee Private E-2

    here is the hijack this log
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member



    NewFiles log....
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now...

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach the new logs from:
    HJT
    Avenger
     
  13. nascarhunee

    nascarhunee Private E-2

    sorry,
    here it is
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT.

    Reboot your computer into Safe Mode

    Right click start / explorer and then delete this file. (Do not be concerned if they do not exist)

    C:\WINDOWS\SYSTEM\blank.htm

    Reboot into normal mode and:
    Let me know if you have questions about this ....you should be able to right clcik on the "blank.htm" and do delete.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now re-run the GetLogs.bat and attach the zip file.
     
  15. nascarhunee

    nascarhunee Private E-2

    Tim,
    I ran hijack this and only found the first item you listed. The other was not there. it was HKLM\..run: [gctlqts] C:\mljpojaq.bat

    I also ran in safe mode and was unable to delete C:\windows\system\blank.htm. It was not there.

    I copied the text you provided and tried to merge with the registry and recieved this error message: Cannot import C:\documents and settings\Jennifer\My documents\fixME.reg. This specified file is not a registry script. You can only import binary registry files from within the registry editor.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The HJT line is still there ...so let's do this:

    Turn off all of your anti-virus and anti-spyware programs ...then:

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach the new logs from:
    HJT
    Avenger
     
  17. nascarhunee

    nascarhunee Private E-2

    How do I know what anti virus or spyware I have running?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  19. nascarhunee

    nascarhunee Private E-2

    Tim.
    It is telling me I am not an admistrator and cannot complete. Remember, someone gave us this computer so I have no idea who the administrator is.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then it is time you were ...

    Reboot into safe mode .....log on as administrator ...you should not need a password...just hit enter ....if you are able to do that (no safe mode password protected admin account), then go to control panel / user accounts / click on yours and change the type to administrator.

    Restart your computer and log back into your account. You should have full admin priviledges.
     
  21. nascarhunee

    nascarhunee Private E-2

    I cannot log in as administrator with out a password in or out of safe mode
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  23. nascarhunee

    nascarhunee Private E-2

    I dont know how but I did it. I am not the administrator. Can I delete any old accounts on there?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did what.....log in as administrator in safe mode? If so...yes you can delete old accounts as well as change your account permissions (IE: to administrator) and add acccounts if you wish ....
     
  25. nascarhunee

    nascarhunee Private E-2

    Tim,
    I am now the administrator. I ran hijack this and R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm was not listed.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then that is good!!

    Run a new HJT scan and attach it so I can look at it.
     
  27. nascarhunee

    nascarhunee Private E-2

    Tim this is what I got when I ran avenger
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is good .....give me a new HJT log.
     
  29. nascarhunee

    nascarhunee Private E-2

    is that the mglogs?
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If that would be easier ....but I really only need the log from running HijackThis again.
     
  31. nascarhunee

    nascarhunee Private E-2

    I just cant remember how to get the logs from hijack this.

    I am sooo sorry for being so computer dumb:confused
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-read the fourth post ....and don't worry ...it's all good.:)
     
  33. nascarhunee

    nascarhunee Private E-2

    Tim,
    I hope this is what you need.
    Thanks for being supportive. I appreciate it.
     

    Attached Files:

  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well some how you got a re-direct.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Are you having any other problems?
     
  35. nascarhunee

    nascarhunee Private E-2

    what is a redirect? And what other kind of problems? Besides being very very slow. Can you tell from the information I am sending you if there are any viruses on this darn thing.
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It means that instead of going to Yahoo ..it is sending you somewhere else.

    Your logs look clean ....what is slow? Start up or running programs? Has it always been slow?

    download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  37. nascarhunee

    nascarhunee Private E-2

    Its slow to start up, and when running programs. When I ran a spysweeper I came up with 3 trojan viruses. That was before I started all this with you.
     
  38. nascarhunee

    nascarhunee Private E-2

    when I ran atf cleaner it has freed 16.984 MBs.
     
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may wish to use a Startup Manager

    Keep your virus definitions up to date (make sure they auto-update and please follow this guide:
    You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!

    Let me know if you have questions about the start up programs.
     
  40. nascarhunee

    nascarhunee Private E-2

    is there anyway I can bypass the windows sign in? I know my personal computer I do not have to do that.
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to Start, Run and type in "control userpasswords2"

    Select your login name from the 4 listed (Administrator, Guest and ASPNET) and uncheck "Users must enter a username and password to use this computer" and click ok. At the next dialog box, simply make sure your name is in the username field and the password fields are blank.
     
  42. nascarhunee

    nascarhunee Private E-2

    how do I use the start up manager. I ran it and have no idea what to do from there.
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me what is listed in it .....
     
  44. nascarhunee

    nascarhunee Private E-2

    i tried saving the log and sending but it saved as a html log and I cant upload to send to you
     
  45. nascarhunee

    nascarhunee Private E-2

    system tray
    user fault check
    quick time task
    adobe photo download
    hp software update
    adobe reader speed launcher
    sun java update sched
    msn client
    msn client
    flags
    office startup.lnk
    hp digital imaging monitor
    hp photosmart premier
     
  46. nascarhunee

    nascarhunee Private E-2

    Tim,
    at shut down I get a message that says something about hpqimzone.exe.
    what's that about?
     
  47. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's part of your HP software that is running when you try to shut down ...

    You can put a check mark next to these items in the startup manager and have it stop them:
    quick time task
    adobe photo download
    hp software update
    adobe reader speed launcher
    sun java update sched
    msn client
    msn client
    office startup.lnk
    hp digital imaging monitor
    hp photosmart premier
     
  48. nascarhunee

    nascarhunee Private E-2

    Okay, thanks for the info.
    I have installed the AVG free edition and it is running, thus far it has found 26threats. They are: obfustat.SQD, I-Worm/Sobig.F, I-worm/Bagle.Z, Dropper.Exebind. All in different files and Paths.

    Maybe I should just chuck this thing to the street and forget it.
     
  49. nascarhunee

    nascarhunee Private E-2

    Tim,
    AVG is finally done. It found 105 threats, it moved 1 to vault and deleted
    104. I am guessing its ok now?
     
  50. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds