Computer was in bad shape

Discussion in 'Malware Help (A Specialist Will Reply)' started by KenB2014, Apr 29, 2007.

  1. KenB2014

    KenB2014 Private First Class

    My son was given a computer that was almost not usable. After multiple attempts with removal software and sfc, I got it running well enough to follow the "Read and Run Me First" steps.

    I attempted to attach my initial cleaning CounterSpy file, which I ran when I was unable to follow the step-by-step removal procedures because Add/Remove and many other windows functions would not run. The report was 2853 kb and too big to post because of all it found. The posted file, CounterSpy.txt, was run when following the guide.

    I was unable to post the bdscan.txt file because of its size. It was 496 kb. Is there another way to post it?

    The computer is running pretty well, but is very slow at times when various programs or services are run, such as install or uninstall. I will run sfc again after we get everything cleaned up and see if that helps. This is an HP a1210n Media Center PC and they do not ship the disks with it, therefore, it is difficult right now to repair the WinXP installation. During sfc, it requested Windows XP Professional CD2, which I believe contains the HP specific program files.

    Do you know of a source for the HP version of the disks?

    Thanks. Ken
     

    Attached Files:

  2. KenB2014

    KenB2014 Private First Class

    additional files attached
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    sfc = System File Check

    Where System means Microsoft Windows. It has nothing to do with HP files. If you ran SFC and it asked for a disk, then you are missing Windows related files. You need a CD to replace them. Or if you know the names of the files and if they are DLL files, you can sometimes download certain DLL files from sites that make certain Windows DLLs available.


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [{20C42DD8-0898-1033-0729-050507190001}] "C:\Program Files\Common Files\{20C42DD8-0898-1033-0729-050507190001}\Update.exe" te-110-12-0000132
    O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\iiihef.dll",realset
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: mfcerf - mfcerf.dll (file missing)

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Program Files\Common Files\{20C42DD8-0898-1033-0729-050507190001}\Update.exe
    C:\Program Files\Common Files\{30C42DD8-0898-1033-0729-050507190001}\Activate.exe
    C:\Program Files\Common Files\{30C42DD8-0898-1033-0729-050507190001}\Uninst.exe
    C:\Program Files\NeoAudio\ezStubMthreeFS.exe
    C:\Program Files\Norton AntiVirus\Savrt\0553NAV~.TMP
    C:\Program Files\Screensavers.com\Installer\bin\siuninst.exe
    C:\Program Files\support.com\backup\Ne\newdotnet6_98.dll
    C:\Program Files\support.com\backup\Ne\newdotnet7_14.dll
    C:\Program Files\support.com\backup\Ne\newdotnet7_22.dll
    C:\sstray.exe
    C:\StubInstaller.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\{20C42DD8-0898-1033-0729-050507190001}
    C:\Program Files\Common Files\{30C42DD8-0898-1033-0729-050507190001}

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. KenB2014

    KenB2014 Private First Class

    Regarding the System File Checker...there's a lot of misinformation out there about this particular message. sfc is requesting a CD disk 2 and many are incorrectly saying it is HP specific because, evidently, Media Center is on a single disk. I'm not sure what is causing it, but I found a kb article that explains that these files are not required for system operation and to ignore those warnings during sfc. Ignored.

    I ran the steps that you gave me and it all went smoothly. Error messages I was getting on startup (five), resolved after the HJT fix and .reg fix.

    It seems that functions, such as remove programs, are running at normal speed now. Before, the task manager showed services hogging the CPU for several minutes to accomplish a task.

    Attached are the three files you requested. Thanks.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow my instructions. The first thing I asked you to do was to uninstall CounterSpy! Did you skip any other steps? Please always complete all steps and in the order given. Uninstall it now!


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new log from GetRunKey!


    Are you having any other malware problems?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! It seems that GetRunKey still shows CounterSpy installed but your HJT log and ShowNew do not show it. In what order did you complete the steps?
     
  7. KenB2014

    KenB2014 Private First Class

    I did follow all the steps exactly and in the order listed. I uninstalled Counterspy and checked for those folders and they were not there after the uninstall. Is there something in the files that I uploaded that contains CounterSpy remnants? It was removed from the Add/Remove programs list and the Start menu after the uninstall.

    I just checked the uploaded files and found a CounterSpy reference in the HJT log (04 entry) as well as the GetRunKey file.

    I did the fixME.reg change and attached the new file.

    I ran HJT again and that 04 entry is no longer there.

    The computer seems to be running great...it was almost not functional when I started.
     

    Attached Files:

    Last edited: May 1, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Perhaps another reboot was just required. Your logs are good now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. KenB2014

    KenB2014 Private First Class

    I completed the final steps and followed the "How to Protect Yourself..." section.

    The computer is running great. As always, thanks for the excellent help.
    Ken
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds