Computer still infected.

Discussion in 'Malware Help (A Specialist Will Reply)' started by brandyn, Jun 21, 2007.

  1. brandyn

    brandyn Private E-2

    Hello,

    I had some severe computer problems. Four things that stood out were 1) The explorer application would close leaving no taskbar or anything 2) IE windows would pop up, despite the fact that I never use IE 3) The windows installer would not work and 4) Windows Media Player would close and I was not able to watch any WMP files on Firefox.

    I got a little scared because of this, and ran a registry booster and Spyware remover that may have made things worse (I have since then uninstalled both). Then I found this site and felt a little more calm.

    I ran everything you said to in the read and run me topic. The only thing was that I could not connect to the internet in safe mode, so I ran that (Edit: by 'that' I mean Panda and ActiveScan) in normal boot. It seemed to fix a lot - The taskbar never disappears, windows installer works again, and WMP doesn't close. However, I still can't play videos on Firefox and I still get random pop ups, though not nearly as frequent. The scanners I ran said my computer was still infected, and I also get a popup from the bottom right hand corner that talks about programs harming the integrity of my computer. Also, I run NOD32, with Tiny Personal Firewall, and if there are any other anti-virus programs or firewalls running, I am not aware of them.

    Thanks in advance for any help you can give. I hope I didn't forget anything from the sticky. Apologies if I did. From this site, I also found a really nice defrag program, and CCleaner is awesome. Thank you for getting me into those, too. The other logs will be posted in the next post.
     

    Attached Files:

  2. brandyn

    brandyn Private E-2

    Here are the other logs. Thanks again for any help.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Media Player


    1. Now Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Do you know what these are? If you didn't install them or know what they are, delete them.
    D:\p2k\Blanch\Blanch.exe
    C:\Documents and Settings\brandyn\Start Menu\Programs\Startup\Blanch.lnk

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After ckicking fix, exit HJT

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
    * ComboFix
    Be sure to tell us how things are running.
     
  4. brandyn

    brandyn Private E-2

    When I go into add/remove, Viewpoint Media isn't there. However, when I go into uninstall on CCleaner, it's there, but when I try to uninstall, it says "uninstaller not found." Should I manually look for files associated with the program and delete them, or use a different method to uninstall it? Should I go through with all the other steps (like running combofix) without removing the program?

    Also, Blanch is a user-made program that works like the dock from Mac, only more organized. I've had that program since my last computer, and it never caused a problem, at least not that I'm aware of.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do a search for viewpoint and delete any folders that you find ...also do not "fix" the associated lines in HJT that reference blanch...9 O4 - Startup: Blanch.lnk = D:\p2k\Blanch\Blanch.exe )

    Do all the rest in the order given and attach the new logs.
     
  6. brandyn

    brandyn Private E-2

    Everything seems to be working better for now, but I don't know if that means my computer is clean or not.

    Edit: It's a miracle! I can watch videos online now! Thanks!
     

    Attached Files:

  7. brandyn

    brandyn Private E-2

    HJT log.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    Avenger
    ShowNew
    HJT
     
  9. brandyn

    brandyn Private E-2

    I couldn't find that specified file in HiJack This, but I uploaded my log anyway. Just in case.

    Thank you for all your help.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Viewpoint Media Player is still showing in your add/remove list. If you have done a thorough search for any associated files or folders and they do not exist ...then:
    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  11. brandyn

    brandyn Private E-2

    All done, I guess. Thanks a million times over. One last thing. During this whole ordeal, system scans from NOD32 said my computer was just fine. This leads me to believe my computer has been infected for longer than I thought. Do you know much about the reliability of NOD? And if you suggest getting a new anti-virus program, which one from the link you gave me would you suggest?

    And again, thank you for all your help.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If Nod is a paid for version...keep it updated. If not, uninstall and download either AVG free or Avast ...again keeping them updated!
    No anti-virus is 100% effective ...which is why we link you to the "How to ...." thread.
    Good luck and safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds