Drives shared as C$ and E$ without my knowing!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Denise400, Mar 17, 2008.

  1. Denise400

    Denise400 Private E-2

    Hello there. I am always so grateful for the help I've had on this forum, and thanks to everyone for reading this.

    I seem to have a problem at the moment.

    My C: drive and secondary HDD E: seem to have the suffix '$' to them and be shared every time I start up my computer, but I did not set this or allow this! Every time I turn off sharing they are shared again upon restarting.

    I was told to edit the registry key AutoShareWrks at SYSTEM\CurrentControlSet\Services\LanManServer\Parameters which was not there and which I created, set to zero, but with still no luck. The drives are still Administrative Shares whenever I restart.

    Obviously I am now suspecting foul play. Can anyone help me out? Thanks so much for any advice you can give me.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I tend to doubt this is a malware issue but the only way to really know for sure is for you to complate the procedure further down. Note, the registry key someone told you to edit, only applies if you are using Novell software.

    To determin if you have malware, please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    If you cannot run certain steps, just note what happens at each point and then continue on thru ALL steps. When you return, tell us what happened and attach any requested logs you were able to get. Do note, without logs, we can not do much to give you specific help and can only guess which is not a good thing to do.
     
  3. Denise400

    Denise400 Private E-2

    Thank you chaslang.

    Have run and attached the logs as instructed, unfortunately it still hasn't been fixed but everything seemed to run smoothly enough. Deleted a few cookies in the process, but that seemed to be all that happened.

    Very grateful to you all for taking the time to help me out.

    Any ideas what might be up?
     

    Attached Files:

    • log.zip
      File size:
      5.1 KB
      Views:
      2
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the MGlogs.zip file that was requested too.
     
  5. Denise400

    Denise400 Private E-2

    Apologies chaslang - that slipped my mind!

    Attached, thank you.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know where/when you got the version of MGtools you are running but you are WAY out of date. You need to always work from the current online version of the READ ME. Please download the current version of MGtools and get a new log and attach it. Also make sure you are in normal boot mode not safe boot mode as your last log was. Also make sure you save and run MGtools.exe to c:\ and not like you did last time which was:

    C:\Documents and Settings\CaptainKeys\My Documents\Messin'\MGtools.exe
     
  7. Denise400

    Denise400 Private E-2

    Hello.

    Updated MGTools and run again. Have attached the new log here.

    Do hope this all is right now, thanks for the patience!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well your problems do not appear to be related to malware. I suggest that you post a question about this in the Software Forum. However I do have some steps that you should perform which are unrelated to your problem.

    Uninstall the below old versions of software as requested in the READ ME:
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 3
    Now reboot your PC after uninstalling the above.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Then you should do the below:
    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. After doing the above, you should work thru the below link:
     
  9. Denise400

    Denise400 Private E-2

    Thanks an awful lot for the patience chaslang.

    I'm relieved to know it's likely not malware, and this does let me get on with things with a little more confidence...

    So grateful to you, and I'll perform all the steps you suggested - Thanks again!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds