earn2life

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nicksimec, Oct 27, 2007.

  1. nicksimec

    nicksimec Corporal

    i did a prevx scan and it said this is generic malware how do i remove it
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. nicksimec

    nicksimec Corporal

    yeah i am having problems with getrunkey i downloaded it and extracted it and then when i click on it has acess denied a bunch of times and a thing saying windows need your permission to continue registry editor click continue and so on you click continue nothing happens the message appears again same if you click cancel and you cant exit getrunkey
    also i did a spyware doctor scan it says i have 5 threats with 117 infections
     
  4. nicksimec

    nicksimec Corporal

    im haveing a problem with shownew too im using vista could this be it also i think i got the virus from screensaver.com
     
  5. nicksimec

    nicksimec Corporal

    well heres a scan not sure if its the right one yeah its the right one



    virus scan.jpg
     
  6. nicksimec

    nicksimec Corporal

    should i fix these with this tool
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Knowing it is Vista makes a big difference> and yes you can fix those items!

    Vista Cleaning Procedure

    Note: Some programs (like MGtools mentioned later and maybe other tools too) may not run on restricted user accounts so you may need to temporarily change the user account to an admin type account and then complete the scans.


    Step 1: Downloading Tools

    In this section we are going to download tools we will use. We will install and configure the programs and then run scans at a later point so please only download right now.

    The tools should be downloaded and saved in your favorite download folder or create one, for example C:\Spyware Tools or C:\Downloads. ( It is not a good idea to download them to any folder within C:\Documents and Settings.) It is also a bad idea to download and save anything you need into any kind of Temp folder. Malware hides in Temp folders and standard cleaning practices will delete everything from Temp folders.

    Now download the below tools:Step 2: Installing Tools and Running Scans
    • Now run ComboFix by double clicking the combofix.exe & follow the prompts.
      • When finished, it will produce a log ( C:\combofix.txt ) for you.
      • Note: Do not mouseclick combofix's window while it is running. That may cause it to stall.
    • Now follow the directions in the below link for running MGtools It also explains possible reasons for not being able to run MGtools
    Step 3: Do You Still Have Problems
    • Yes, I’m still having problems
      • Start a new thread and clearly describe in detail the problems you are having and how long ago they started. Think about what you were doing at the time.
      • Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
        • C:\ComboFix.txt
        • AVG Antispyware log
        • MGlogs.zip
      • Be patient after posting your logs and wait for one of the helpers to get to you. It can take a while to read thru all of the logs and to create individual fixes for you.
    • No, I’m not having any problems
      • If you are sure everythingis okay and that you do not need to request any help, then jump to the next step below.
    Step 4: Enable User Account Control (UAC)
    • While running the MGtools procedure, we had you disable UAC. Now we need to enable it again to help keep you safe.
    • You can either respond to the security notice in the System Tray alerting you to enable UAC or you can do the below.
      • navigate into the \MGTools folder just created in the root of your Windows boot drive.
      • locate the EnableUAC.reg file and double click on it.
      • This registry patch is used to enable the User Account Control feature
    • Now continue on to step 5
    Step 5: Toggle System Restore
    • You only need to Toggle system restore if malware had been found during the cleaning procedures. If no malware was found, there are no infected restore points to worry about, thus you can skip to the next step.
    • Once you are sure all malware problems have been removed follow the below steps:
    Why we toggle System Restore!
    If you have been infected with any trojans, spyware, etc, they could have been saved in System Restore and are waiting to re-infect you. Since System Restore is a protected directory, your tools can not access it to delete files that may contain viruses. Even though your tools may say they are deleting them, they are not! The reason for doing this after your system has been completely cleaned of problems, is so we can remove possible infected restore points. When you disable system restore, it removes restore points! ​
    We only toggle System Restore after you are clean because keeping even infected restore points around while we are fixing things may prove useful if something goes wrong during the process. An infected restore point could be better than none at all!
    Make sure you attach the files form MGTOOls in your next reply.
     
  8. nicksimec

    nicksimec Corporal

    i already have counter spy do i need AVG
     
  9. nicksimec

    nicksimec Corporal

    i just tried to download MGtools to C drive it said i dont have permission to
    do it says contact the admin instead would you like to save to nick simec
     
  10. nicksimec

    nicksimec Corporal

     
  11. nicksimec

    nicksimec Corporal

    my clock just changed from 5 24 to 17 24 malware?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Counterspy is fine ....yes let spy doctor fix the items it found....are you not logged in as an administrator account?
    Don't worry about your clock ...
     
  13. nicksimec

    nicksimec Corporal

    there is only one acount and it is admin
     
  14. nicksimec

    nicksimec Corporal

    so i dont have to boot in safe mode
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, you shouldnt have to...

    Please disable it so you can get the logs.
     
  16. nicksimec

    nicksimec Corporal

    here the combo fix log might have to do it again because counter spy might of interfered with it
     

    Attached Files:

    • log.txt
      File size:
      16.7 KB
      Views:
      4
    Last edited by a moderator: Nov 4, 2007
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It ran without a problem ....can you get the other logs?
     
  18. nicksimec

    nicksimec Corporal

    here is spybot logs after i did the scan a new internet explore link was on my desktop not a shortcut also there is now somthing call qoobox on my computer do i delete it?
     

    Attached Files:

    Last edited by a moderator: Nov 4, 2007
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Qoobox is the quarantine file from ComboFis ...please attach the logs from MGTOols ...
    ShowNew
    GetrunKeys
    HJT
     
  20. nicksimec

    nicksimec Corporal

    you didnt tell me to get show new or getrunkey or hijackthis i still cant download MGtools admin problems again
    also counterspy didnt pick up any problems but was probly out of date
     
  21. nicksimec

    nicksimec Corporal

    problems other problem is when i open it the right way registry editor want to open and it doesnt work


    getrun key.jpg


    show new.jpg
     
  22. nicksimec

    nicksimec Corporal

    ok i rebooted my computer some scan came on before it completely started back up and then when it turned i got a security centre warning and i tried to turn it on and it couldnt any ideas?


    security.jpg

    security 2.jpg
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    At this point, delete everything you have installed/used up to this point.

    Let's bypass using MGTools and run them manually, first, see the threads below and try to attach the log.

    If they will not run properly in normal mode, try them in Safe Mode.

    Also, download Trend Micro HijackThis 2.02 and attach a log. Be sure you install it to C:program Files\HJT and rename it to "analyzethis.exe".

     
  24. nicksimec

    nicksimec Corporal

    get run keys log
     

    Attached Files:

    Last edited by a moderator: Nov 6, 2007
  25. nicksimec

    nicksimec Corporal

    edit by bjgarrick: log attached properly
     

    Attached Files:

    Last edited by a moderator: Nov 6, 2007
  26. nicksimec

    nicksimec Corporal

    i dont think its trend micro version i think i acindently used hijackthis do you know any good free anti virus programs i have AVG
     

    Attached Files:

    Last edited by a moderator: Nov 6, 2007
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.

    Pre-Instructions:
    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed.

    Step 2:
    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    Again, make sure ALL browser windows are closed when you click FIX.

    Step 3:
    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Step 4:
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Step 5: Begin here after rebooting from Step 4!
    Next Reset Web Settings & Default Security Settings

    Note for IE 6 users:
    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites. For IE 7 users, simply click the "Reset all zones to default level" button.

    Note for IE 7 users:
    Select Internet Options, then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.


    Step 6:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Step 7:
    After you have completed ALL of the above in the correct order, please attach the following logs.
    • HijackThis Log
    • ShowNew Log
    • GetRunKey Log
    • Avenger Log
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Also, did you set the policies below?

    Correction - Part of Vista!
     
    Last edited: Nov 10, 2007
  29. nicksimec

    nicksimec Corporal

    i cant do do step 4 i have vista and it dosent work on it and i found O3 earn to life thing in hijack this delete it?
     
  30. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ah! I didn't think about you running Vista, follow the below.

    Download Pocket KillBox
    • Save it to your desktop or a place easy to find.
    • Do not run it yet
    Reboot into Safe Mode and manually delete the following folders.

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\swsys1.bmp into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINDOWS\swsys2.bmp into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.

    Once you complete the above, attach fresh logs from the below.

    • HijackThis Log
    • ShowNew Log
    • GetRunKey Log
     
  31. nicksimec

    nicksimec Corporal

    Quote:
    C:\ProgramData\TRYMEDIA
    C:\Program Files\screensavers.com
    C:\Users\Public\Application Data\Starware316
    i could only find one of these TRYMEDIA
    im going back to safe mode are you sussposed to be allowed on the internet in safemode cause i cant
     
  32. nicksimec

    nicksimec Corporal

    logs
     

    Attached Files:

    Last edited by a moderator: Nov 8, 2007
  33. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you choose "Safe Mode w/ Networking" yes you should be able to access the internet if you use Cable/DSL. Dialup will not work in Safe Mode.
     
  34. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I never saw an answer from my question in post 28?
     
  35. nicksimec

    nicksimec Corporal

    i dont think and i dont know how
    should i put the files i didnt find in killbox and delete them that way
     
  36. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Correction - Part of Vista!
     
    Last edited: Nov 10, 2007
  37. nicksimec

    nicksimec Corporal

    ok done i also still have the earn2life toolbar also i cant get security centre working
     
  38. nicksimec

    nicksimec Corporal

    Logs
     

    Attached Files:

    Last edited by a moderator: Nov 10, 2007
  39. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.

    Step 1:
    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    Again, make sure ALL browser windows are closed when you click FIX.

    Step 2:
    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Step 3:
    Next, we need to run Killbox again just like you did before.

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\Windows\Downloaded Program Files\Earn2Life.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.
    Step 4:
    Now we need to REBOOT into Safe Mode. Once in Safe Mode navigate to and delete the following two folders.

    Step 5:
    Next we need to run CCleaner to cleanup any leftover junk files.

    CCleaner Slim (No Toolbar) 2.02.527

    Step 6:
    After you have completed ALL of the above in the correct order, please attach the following logs.
    • HijackThis Log
    • ShowNew Log
    • GetRunKey Log
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited: Nov 10, 2007
  40. nicksimec

    nicksimec Corporal

    in step 5 am i in normal mode or safemode and can i just use regualar CCleaner
     
  41. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Normal mode and be sure you have the latest version.
     
  42. nicksimec

    nicksimec Corporal

    i just found a folder on my computer called VIRUS!@#$% but with more symbols it is empty
     
  43. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Delete it, where was it located?
     
  44. nicksimec

    nicksimec Corporal

    i deleted it it just apperad on my desktop at 2:03 or somthing
     
  45. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Go back to Post 39, Step 6 and attach fresh logs.
     
  46. nicksimec

    nicksimec Corporal

    ok here they are and does it matter that get runkey and shownew are in downloads not in any files
     

    Attached Files:

    Last edited by a moderator: Nov 16, 2007
  47. nicksimec

    nicksimec Corporal

  48. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, have HJT fix the entries below...

    Next, reboot into Safe Mode and delete the following...

    C:\Program Files\Adverbux <-- Delete the whole folder!
    C:\Program Files\objectdock_freeware.exe

    Once you complete the above, reboot and attach fresh logs from the below.

    • GetRunKey
    • ShowNew
    • HijackThis
     
  49. nicksimec

    nicksimec Corporal

    there was adverbux tool bar stuff cause i unistalled it yesterday
     
  50. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay, procede with my previous post and attach the requested fresh logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds