Have done the "run me first"

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ophie, Feb 23, 2007.

  1. Ophie

    Ophie Private E-2

    Hi there,

    I just inherited a computer from my brother-in-law which he was going to throw in the garbage because he got so many virus' he gave up on it. So I've been working on it for a couple of days. I think I've done all of the steps I was supposed to and have managed to clean a TON of stuff off by doing the "run me first" as well as the "special removal instructions" for the virus "Smitfraud".

    I still seem to have an issue with a little yellow shield in my taskbar that is some form of spyware - (an imitation of the yellow triangle with the exclamation pt.) I had another one that imitated the windows shield but got rid of that one.

    At any rate, I'll post the logs most of which, after several attempts are running clean.

    As always, thanks in advance.

    Ophie :)
     

    Attached Files:

  2. Ophie

    Ophie Private E-2

    more logs
     

    Attached Files:

  3. Ophie

    Ophie Private E-2

    last log
     

    Attached Files:

  4. Ophie

    Ophie Private E-2

    Have also now done the special removal for "spyware quake" and "spyware falcon" Here's the log for that.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Now
    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to MSWindows
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste MSWindows into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {4D763ACD-8742-E2A2-C41A-073D5F7A40A5} - (no file)
    O4 - Startup: .protected
    O4 - Global Startup: .protected
    O20 - Winlogon Notify: mljhgeb - mljhgeb.dll (file missing)
    O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe" /service (file missing)

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Windows\System32\urdvxc.exe
    C:\-15275~1
    C:\protec~1
    C:\yclbtpg.exe
    C:\WINDOWS\system32\dpqcerql.ini

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  6. Ophie

    Ophie Private E-2

    Is it weird that I don't have MS Windows in services.msc?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Possibly not if the file is missing ....and it would be MSWindows ...do you have Network Windows Service?

    Do the rest and post the logs after you are done.
     
  8. Ophie

    Ophie Private E-2

    So it turns out that there was an issue with the Windows installation and we ended up having to reformat. Just getting everything back on now but its looking like reformatting took care of the last of the spyware issues. Once I have everything re-installed, I'll re-run all the scans but I'm pretty sure we're looking good.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you did a complete reformat you will wipe everything...malware included. You should be wary of what you either download or install from "copied" software.
     
  10. Ophie

    Ophie Private E-2

    Yes, it looks like everything has run clean. So my brother-in-law was going to junk a perfectly good Pentium 4 with a 3 hundred gig hard drive and nice video card. Guess its my husband's lucky day! Thanks again for all your help and I will be careful with what I install for sure.

    Ophie :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds