Debilitated PC Please Help Logs inclosed

Discussion in 'Malware Help (A Specialist Will Reply)' started by Special_k, Jan 17, 2008.

  1. Special_k

    Special_k Private E-2

    This is my bosses computer My Way search assistant is ONE of the problems I have had this thing since before Christmas, He says that it all started after he installed Yahoo. I uninstalled Yahoo internet explorer and helpers it toggles from not opening any windows after IE opens, to reinstalling the my way bs. It is making me crazy Can someone please help?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to run AVG Antispyware and this time do not Ignore what it finds! There is no sense in running the scans if you are not going to fix what they find. ;) Select Quarantine. Save a new log and attach it when you come back.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKCU\..\Run: [SpywareBot] D:\SpywareBot\SpywareBot.exe -boot
    O4 - HKUS\S-1-5-21-35770512-463249621-1365895117-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
    O4 - HKUS\S-1-5-21-35770512-463249621-1365895117-1006\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User '?')
    O4 - HKUS\S-1-5-21-35770512-463249621-1365895117-1006\..\Run: [SpywareBot] D:\SpywareBot\SpywareBot.exe -boot (User '?')

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!



    Delete the below folder (is this an external drive?)
    D:\SpywareBot

    Now reboot

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.


    Don't forget to attach the new log from AVG Antispyware too.



    Make sure you tell me how things are working now!
     
  3. Special_k

    Special_k Private E-2

    Thank you for your reply. HJT does not run independantly, I am familiar with HJT.
    The zip file when I clicked on it ran a dos window, then it said click any key to exit.
    I am enclosing the files but did not have an option to fix.
    I also reset ie browser settings, another point, This pc has mdm error when boots. I am running this pc without its monitor, and am using a spare and its mouse or keyboard. I am also using spares for these items. Another point is that this pc gets pissed and will not allow me to run all the fixes suggested ( or many other things) without restarts and some things run in safemode like the mg tools were run in safe mode and the log obtained in regular mode, it did it like four times just trying to access my computer so i gave up and ran it in safe mode, however it also did it four or more times while just trying to log onto internet explorer. This maybe why SpywareBot was in the d drive and in search I have been unsuccessful in finding it. This pc is a dell and has only a cd/?rw? Am going to reboot and run cc dcleaner and attach logs
    Logs attached. Thank you K:confused
     

    Attached Files:

    Last edited: Jan 18, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are referring too. I did not ask you to run a Zip file??? I asked you to run C:\MGtools\analyse.exe It runs just fine according to your MGlogs.zip file. You must follow instructions exactly as they are written.
     
  5. Special_k

    Special_k Private E-2

    Hi, This is not my computer I am working on MGTOOLS shows up as a zip
    file. I did not find access to MGTOOLSanalyse.exe maybe it is somewhere else I am unaware of? HJT is Hijack This ( by trend micro) I thought it was part of MGTOOLS, and I thought it replicated a log file which you had already gotten from me about my bosses PC. Isthere another way to retrive Analyse.exe that I DONT know about? I am not trying to be disobedient, just am now confused. When I downloaded MGTOOLS on his PC it showed up as a zipfile. When I double clicked on it it ran the dos windows with corresponding programs(?) Which then made the log files that I attached in the second post. I am confused please advise.
    (K)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still not sure what your are talking about. The installation file for MGtools is named MGtools.exe. It is not a ZIP file. It is a self-extracting executable.

    The folder is C:\MGtools and the file is named analyse.exe Thus the full path name as given in my instructions was C:\MGtools\analyse.exe and that is what you would see from a Windows Explorer window when trying to run the analyse.exe file by double clicking on.

    Yes it is! I'm not sure what your point is.

    I repeat! Is is not a ZIP file. It is named MGtools.exe and if you downloaded it where we requested you will see it as C:\MGtools.exe Not C:\MGtools.zip You will also see a folder named C:\MGtools Inside of this folder is where all the programs that are part of MGtools reside including analyse.exe which we have mentioned.

    One you have installed MGtools you don't need the MGtools.exe file anymore. In fact please delete the C:\MGtools.exe file and maybe that will remove some of your problems since you appear to be missing the point of how this all works. As I stated in message # 2 I wanted you to run C:\MGtools\GetLogs.bat which will get you a new C:\MGlogs.zip

    You need to run the C:\MGtools\GetLogs.bat again now because your last log was obtain from safe boot mode and you need to be in normal boot mode when you get the new log. Then attach this new C:\MGlogs.zip file.
     
  7. Special_k

    Special_k Private E-2

    Sorry I must have been running the get logs zip, when then inflated the log files and ran the get logs bat file.. sorry I was a dork:eek:
    Enclosed are the new logs and completed all tasks step by step am awaiting assistance. BTW font in notepad etc, it HUGE..have no idea. Also noted MDM error, twice during boot sequence. Also windows security has error antivirus, saying it is out of date for Avast, saying not updated, witnessed updating today. Still shows red X my private pc does not have such error,could be just different version of XP?
    (K)
     

    Attached Files:

    Last edited: Jan 24, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean!.

    Not malware problems. Change your font size in notepad. And for the MDM eror you need to create a message in the Software Forum and give the EXACT word for word message and also say exactly when it occurs. You should also test to see if it occurs when you boot in safe mode.

    Uninstall Avast. Reboot. Delete the C:\Program Files\Awil Software folder. Download a new copy of Avast from the below link and reinstall it:

    Avast! Home Edition
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds