Did the Read-me...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Asdf456, Sep 26, 2008.

  1. Asdf456

    Asdf456 Private E-2

    Hello all,

    last year around this time I thought i have removed some viruses/malware from my pc. Around November, I got the same problems back after searching for the best youtube videos on a search engine (not youtube.com...I was bored). I tried fixing the problems, which were [noticeably] frequent IE popups when running firefox and now a slow startup, for awhile, but I didn't and then stopped trying for awhile, which is bad since it's been around 10 months. I did the Read-me and this time I want to be sure I'm rid of all the malware and such, hence my post. When running the scans, the Super Antispyware resulted in a blue screen. Thanks for all the help.
     

    Attached Files:

    Last edited: Sep 26, 2008
  2. Asdf456

    Asdf456 Private E-2

    Super Anitspyware log
     

    Attached Files:

  3. Asdf456

    Asdf456 Private E-2

    Since scanning I've been to this site, gmail, google and that spike tv network website (which is the cause for most of my concern). I realized after that I probably shouldn't be using the internet except for this site. If I've compromised the scans, let me know and I'll do them again. Note: not trying to bump this, I would have just edited a post if I were within the half hour limit, however if this is seen as one then I'll just wait.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually the scans did a good job. :)

    Just a few things to deal with:

    Can you tell me what this is (if you don't know, delete it).
    C:\WINDOWS\SmVhbm5lIFByb3Zvc3Q

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
    Last edited: Sep 30, 2008
  5. Asdf456

    Asdf456 Private E-2

    I don't know which lines to select in HijackThis because the quote box is empty...

    So I deleted C:\WINDOWS\SmVhbm5lIFByb3Zvc3Q (it was empty), and that's as far as I got so far.
     

    Attached Files:

    Last edited: Sep 30, 2008
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have edited my last post......my head must have been somewhere else ( no shouts from the peanut gallery!!)

    Continue on please. :)
     
  7. Asdf456

    Asdf456 Private E-2

    Here it is
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good...are you having any other issues?

    In the meantime:
    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  9. Asdf456

    Asdf456 Private E-2

    I couldn't remove Windows Messenger, I chose 'Uninstall windows messenger' and I received an error-message: "Run-time Error '429': ActiveX component can't create object"

    Also, I already created a fixME.reg file, so do you want me to replace the old one with this one or choose a different name?

    In msconfig, there's a smax4pnp and a hkcmd...those ok? There's also Microsoft Office in the startup, which seems weird, with command C:\PROGRA~1\MICROS~4\Office\OSA9.EXE -b -l
    I dunno, it just seems odd. Sorry for all the questions.

    I don't know if it matters at this point, but previous scans had come up with Smitfraud-C.Coreservice (or something to that effect) and I think a virtumonde virus. I only bring this up because of how hard they seem to be to remove, and I want to make sure they're gone without having done extra scans at this point.

    Startup may be a bit slow still, but other than that, things seem ok.
     
    Last edited: Sep 30, 2008
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have posted two reg. fixes for you. If you have done the first one, you can delete it from your desktop and then create and run the second one.

    You may wish to use a Startup Manager

    If you get a success message after running the second fixme.reg...then If you are not having any other malware problems, it is time to do our final steps:
     
  11. Asdf456

    Asdf456 Private E-2

    I appreciate all the help I've received...however now I ask you quickly look over the scan logs again...I was stupid and hadn't checked back here in awhile, I hadn't used the computer in awhile either, and since then the computer had been used and picked up some virtumonde thing (found it with superantispyware and did some of the other scans [don't think combofix displayed a disclaimer). Then after someone did some google searching, I ran all of the scans again, and they seem to be clean...but I want to make sure before continuing to the final steps (which I'll do in a timely fashion this time)...thanks for all the help, and sorry for the annoyance. After this I shouldn't be bothering you anymore.
     

    Attached Files:

  12. Asdf456

    Asdf456 Private E-2

    here's the last one (saved it to the desktop)
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem...your logs are clean. :)
     
  14. Asdf456

    Asdf456 Private E-2

    Wow I've been gone awhile
    Due to a winsoc error I got rid of the antivirus and firewall in trying to fixing it, and now only have online armor (which I disabled today to run combofix since that caused the error last time). Since then I've had possible issues, hence the combofix, mgtools, malwarebytes, and superantispyware scans (forgot to run spybot).

    Anyways, I'm set to reactivate it and get something like comodo for antivirus as soon as I know I'm good in which case I'll really be out of your hair for I'll take extra-precaution and have all teh recommended security and whatnot.

    I ran malwarebytes twice because the first it had five detections (registry things in the microsoft folder...probably not too good) and upon restart to finish removing them something came up saying I didn't have permission for something (sorry for the lack of specifics), so thats when I disabled my firewall and ran it again, but that time it didn't find anything (I'm attaching both logs in a post after I post this).

    So without further delay, mind one more once over of the logs?
     

    Attached Files:

    Last edited: May 27, 2009
  15. Asdf456

    Asdf456 Private E-2

    malwarebytes
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are still clean. :)
     
  17. Asdf456

    Asdf456 Private E-2

    Cool, thanks muchly
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem...:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds