HELP with Next step (READ ME - RUN ME)

Discussion in 'Malware Help (A Specialist Will Reply)' started by JoeyAnyc, Feb 24, 2006.

  1. JoeyAnyc

    JoeyAnyc Private E-2

    Okay, I'm trying to do everything in the right order, as requested. I have followed instructions to the best of my ability.

    My computer is in safe mode and I ran ALL of the programs and fixed the problems. I'm at the point where I suppose to connect to the internet and run the last two programs. I think I'm suppose to go back into normal mode to be able to connect to the internet. Is this correct?

    My next questions, I suspose to Disable System Recovery after removing everything. My question is - do I Disable while still in safe mode - or normal mode?

    Thanks for the help.

    Joey
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs Joey!

    No step 6 indicates that it is run in safe mode too if you PC allows you to connect to the net in safe mode. Otherwise run them in normal boot mode. You must save this logs as indicated too and then attach them to your next message. Also follow step 7 exactly (in normal boot mode) to attach a HijackThis log.

    System Restore should not be touched until we verify that you are clean.
     
  3. JoeyAnyc

    JoeyAnyc Private E-2

    OH - Thank you so much.

    Sorry I missed that. I've been very careful to make sure I follow the instructions. I had the scanners run while I was sleeping. Today I overlooked the Safe Mode and Networking.

    I'm nervous going through all of this, not knowing much about computers. I do apologize. I will be back with the scanning results in a couple of hours (it seems).

    MUCH THANKS

    Joey
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No need to apologize! Just take your time and follow the steps as best as you can. Don't be afraid to ask questions on something you don't understand or if something is not working right for you.
     
  5. JoeyAnyc

    JoeyAnyc Private E-2

    I can't thank you enough. Right now I'm running the online scan with Panda ActiveScan. Half way through the scan, I got a "Choose Profile" window pop-up.The options are:

    PROFILE NAME: MS Exchange Settings / PstLoadTmp000 / PstLoadTmp001 / PstLoadTmp002 OR NEW option button

    At the bottom of the window, there is an Option box where you can check to: Set as Default Profile OR Show Logon Screens for all information services

    Any suggestions? I'm not sure what to do. Thank you.

    Joey
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did your Bitdefender scan complete and did you save the log? If yes, just skip Panda for now and attach the Bitdefender log followed by the HijackThis log per step 7.
     
  7. JoeyAnyc

    JoeyAnyc Private E-2

    Yes - I did BitDefender and saved it. Currently, Panda isn't complete but did find 69 Spywares so far. Just wanted to pass this on while I contine to Step #7
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try closing that other "Choose Profile" window and saving a log from Panda or you could just choose the MS Echange one and let it continue then save a log.
     
  9. JoeyAnyc

    JoeyAnyc Private E-2

    Being that I'm over half way throught the scanning process on Panda, I'll just choose "MS Exchange..." and let it finish. It's going to take some time - long ass scan!

    Anyways, in the meantime - was reading through the Instructions for loading, installing, and running HijackThis. There's a section on MSconfig I'm not clear on. I'm still in safe mode with Networking. When I go to Start>Run>msconfig, the System Config Utility Window comes up. Under the General Tab, right now the option for Selective Startup Menu is selected. There are two options before that for Normal Startup and Diag. Startup. Is THIS where I should select Normal Setup? I'm not sure if this is the "Startup Manager" you are refering to where I have to make these changes.

    Still scanning...

    Joey
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is where you must select Normal Startup. It may be in selective startup right now because you have booted in safe mode. Check again when you are in Normal boot mode (just before getting your HJT log) to make sure you are in Normalt Startup mode.
     
  11. JoeyAnyc

    JoeyAnyc Private E-2

    Okay, I'm now in Normal Mode and Normal Startup.
    I'm going to run HJT.
    Which logs should I post and where too?

    Joey
     
  12. JoeyAnyc

    JoeyAnyc Private E-2

    Okay - I think I followed everything correctly.

    Here's the logs from BitDefender - Panda - HJT

    FYI - Back in normal mode and still having the same problems.

    Anxiously awaiting...

    Joey ;)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! Did you forget to run CCleaner on the joey angeli account! I wonder why so many cookies still show in your Activescan log.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not save the Bitdefender log per the instructions in the READ ME. What you posted is just a summary log that does not help us at all since it only states some virus names but does not say where they were found or if they were cleaned.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove programs and uninstall BearShare
    Did you install Hidownload? See: http://www.hidownload.com/
    This next BHO line is from them:
    O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [JadieVirus] C:\WINDOWS\winview.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} - http://207.188.7.150/235b23ab8d4e6df61e21/netzip/RdxIE.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/09e9ed48227c6c1b7301/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\winview.exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  16. JoeyAnyc

    JoeyAnyc Private E-2

    Oh, is this the right file for Bitefender?
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That is the correct way to save the log. Looks look Bitdefender fixed what it found.

    Did you complete my previous steps? Attach the followup HJT log.

    Are you having anymore malware problems?
     
  18. JoeyAnyc

    JoeyAnyc Private E-2

    Yes - I DID run CCleaner. Should I run it again? I think I did it right.

    I am going to complete the list tomorrow (Saturday).

    I will post my follow-up log when I'm done.

    Thank you so much. I can't tell you how much I appreciate this!!!

    Joey
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But was Ccleaner run while logged into the joey angeli user accont login? Don't worry about it doing it again. I was just curious why so many cookies remained on that account. Cookies are nothing to be that concerned with even though every spyware scanner points them out. Just post the follow up log when you finish and let me know how things are working.
     
  20. JoeyAnyc

    JoeyAnyc Private E-2

    Yes, I was logged under Joey Angeli.

    As for BearShare, it's not located under Add/Remove Programs and I tried finding it's file. Can't seem to locate it.

    I did download Hidownload, but don't need it. I can't locate that one either.

    Just wanted to let you know before I start the above instructions.

    Joey
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay add the below to the list of things to fix with HJT:

    O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
    O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause

    Then in safe mode, also delete:
    C:\WINDOWS\system32\HDBHO.dll
    C:\Program Files\BearShare <--- the whole folder if found
     
  22. JoeyAnyc

    JoeyAnyc Private E-2

    OKay, I followed all the instructions, including the additional ones.

    After in Safe Mode, I couldn't find the following to delete...

    C:\WINDOWS\winview.eve
    C:\Program Files\BearShare (no foler or files)

    I went back into Normal Mode and re-ran HJT with all windows closed. New file attached. My computer is still Majorly dragging.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! You speed problems may just be due to all the junk you are loading and running all the time especially all the AOL stuff. You should remove all stuff you don't need to use. This however is not a malware topic. I'll give you a few tips though:

    You have McAfee Antivirus but you also have AOL stuff running

    If you are going to keep all the AOL junk running, you probably should uninstall Windows Defender.

    You don't need any of the below to load at startup:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Program Files\Programs\MFIndexer.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    Why do you need the below to always run? Can't you just run them when needed:
    O4 - HKCU\..\Run: [Eyeball Chat] "C:\PROGRA~1\Eyeball\EYEBAL~1\EyeballChat.exe" -min
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
     
  24. JoeyAnyc

    JoeyAnyc Private E-2

    Thanks for the info. I actually don't need ANY of the programs to Start Up. They just do. I never knew how to disable that. I wish that none of it started up until I want it to.

    As for anti-virus, I HATE the new AOL one that keeps coming up. I have to contact them to get rid of it all together. Mcafee I thought I had that shut off. I am going to try and figure out how to clean up my system and stick to the preventive programs that are listed on this board.

    Any advise would be great. So should I disable System Restore and follow Step 1 now?

    Thank you.

    Joey
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutting off an AV is not the same as uninstalling. You must only use one antivirus application and UNINSTALL all others. AOL may have an option to uninstall there protection/security system. I don't know since I do not and would not use it.

    The below program is useful for control startups.
    Startup CPL

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds