Done with runme first

Discussion in 'Malware Help (A Specialist Will Reply)' started by kevinlee, May 5, 2007.

  1. kevinlee

    kevinlee Private E-2

    ok boys , its been a long nite, here are my logs, thx in advance
     

    Attached Files:

  2. kevinlee

    kevinlee Private E-2

    Two more
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would help if you would tell us what problems you are having .....unless you just wanted a check-up.

    Let's start with this:
    Please find and delete these:
    C:\Program Files\DAEMON Tools\SetupDTSB.exe

    Use add/remove programs to uninstall:
    viewpoint Manager (Remove Only)"
    Viewpoint Media Player
    C:\ijji

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  4. kevinlee

    kevinlee Private E-2

    Thx for the response.......I had some spyware I beleive and pc was kind of slow, here r my new logs:
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The three RO items are still showing in the HJT log ....
    and you still have "IJJI" in your add/remove items list......was there a problem removing any of those items?
     
  6. kevinlee

    kevinlee Private E-2

    I didnt notice that ...cant remove those RO items, tried a few times .

    and the c:/ijji folder is from a game that my kids play, (Golf King) is this spyware

    Here is the link:
    http://www.ijji.com/
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you installed the "ijji" .....go ahead and keep it. However, please use add/remove to uninstall:
    WhenU SaveNow ----> produces pop-ups! (Then see if HJT will remove the RO items

    Let me know how things are running.
     
  8. kevinlee

    kevinlee Private E-2

    One down
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The RO items are still there, but not a problem...just left over clutter.

    Are you having any other issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  10. kevinlee

    kevinlee Private E-2

    Thx, much much better and Im even trying Firefox.......so far so good;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds