Clean Computer Please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by fancykiss, Feb 4, 2007.

  1. fancykiss

    fancykiss Private E-2

    Can someone please help me clean my comp. I did the malware removal and my system is still slow. Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to attach the other three requested logs:
    - CounterSpy
    - Bitdefender
    - PandaActiveScan

    Also note the objective of the READ & RUN ME is to remove malware. This does not necessarily mean it will speed up the operation of your PC. While in some cases it will, in most cases slow PCs are cause by what you are running. This appears to be the majority of your problem. You do have malware but you major issue is just all the junk you are running (much of which is thanks to what Dell put on your PC).

    Once I see the other logs we can continue further, but here is a start!

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2
    Kazaa Media Desktop 2.5.1 <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!
     
  3. fancykiss

    fancykiss Private E-2

    Thank you so much for your quick response! I have attached the other two logs. Im currently having trouble w/running the Panda Scan but will post as soon as I receive it. I have uninstalled the other programs. Thank you!:D
     

    Attached Files:

  4. fancykiss

    fancykiss Private E-2

    Im also having trouble deleting Kazaa. I searched it on here and downloaded the Kazaabegone and have attached the log. Can you please help me! Thank you!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you attached was a copy of your Desktop.ini file.

    You cannot find Kazaa because your ran CounterSpy and it removed it. Look at the log.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you are complaining of a slow PC, some of the steps I'm giving below will address this too. Many things I will be mentioning are not malware. They are just not needed.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\alex quiroz\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
    O2 - BHO: (no name) - {9CD19BCF-4124-4FF8-8C0E-45D50D2C7EBc} - (no file)
    O2 - BHO: (no name) - {B7CF842E-448F-4804-BB09-356CC0BE6C06} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [System Log Event] lsas.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
    O4 - HKLM\..\RunServices: [System Log Event] lsas.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe /q
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm86744US
    O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
    (file missing)
    O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control
    Pad\VerizonControlPad.Exe (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O15 - Trusted Zone: http://www.winfixer.com

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\ClockSync <--- the whole folder
    C:\windows\system32\lsas.exe

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT
     
  7. fancykiss

    fancykiss Private E-2

    Ok I did all that you asked. Thank you so much! :) Here are my logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those logs are not from the same user account as last time. They are from eliza ross

    We did not fix anything in this account.

    Please post the logs from the same user account we started with which is alex quiroz
     
  9. fancykiss

    fancykiss Private E-2

    O okay sorry about that! I was on another account. Here they are... Thank you!
     

    Attached Files:

  10. fancykiss

    fancykiss Private E-2

    Please disregard the earlier post. These are the correct logs. Thank you!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you uninstall the current version of Sun Java (version 6) that you had installed when you started this thread? In message number 2 I only told you to uninstall these:
    But you also uninstall this Java(TM) SE Runtime Environment 6 which is the current version. And now you installed J2SE Runtime Environment 5.0 Update 10 which is old.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    You logs are clean! You just need to get the proper Java version installed.

    Are you having any other malware problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds