Hijack Thislog help, Scans Complete

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dan Armstrong, Jun 8, 2007.

  1. Dan Armstrong

    Dan Armstrong Private E-2

    I have ran all the scans from Run me First and I consider myself an Advanced User. I have used your site for 3 or more years and think you guys are awsome. I have learned a lot from your website and would like to thank you for helping us all out on the big pains we have out there.

    The machine I am trying to clean is a teachers and she is a good friend of the families. She came to me and asked me to work on her laptop. It was running slow and the printer stopped working erery since she let my 15 yr old nephew download music on it.
    I didn't find anything from the regulars like Kazza or Limewire on this machine but I did see where AVG found a lot of Trojan Horses and Spyware and quarintined it around Feb and March of this year. I followed the instructions on your Malware Run Me First post and the only thing left it seems to find is Tribalfusion in the cookies even after i manually deleted it and used CCleaner to cleanup afterwards.
    I would very much appreciate it if you guys would have a look at the results and let me know if you see anything to be concerned about before I install all the updates. Yes one thing thats wrong is she doesn't keep it updated so this machine doesn't even have SP2 installed.
    Thanks
    Dan Armstrong
    I will post a second post with the rest of the files you guys need.
    Again thanks for the help and I think your site roks.
     

    Attached Files:

  2. Dan Armstrong

    Dan Armstrong Private E-2

    Re: Hijack Thislog help, Scans Complete Part 2 Attachments

    Here is Pandascans attachent and it is the last. Bitdefender said it was clean. Pandascan is the only one left finding anything.

    Thanks again for the help.

    Dan Armstrong
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack Thislog help, Scans Complete Part 2 Attachments

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Then uninstall the below as requested in step 0 of the READ ME
    Viewpoint Media Player

    Now rename HijackThis.exe as requested in the READ ME and then attach new logs form ShowNew and HJT.
     
  4. Dan Armstrong

    Dan Armstrong Private E-2

    Hello Chaslang,
    Sorry for not reading thouroughly. I have done everthing you instructed and here are the new files.
    Thanks for your help.

    Dan
     
    Last edited: Jun 9, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this PC does not have much in the way of malware. It is just out of date with ALL Windows Updates!


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [restrictanonymous] 
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. HJT


    Make sure you tell me how things are working now!
     
  6. Dan Armstrong

    Dan Armstrong Private E-2

    Chaslang
    Thanks for your help. The machine seems to be running fine. I did get an error message when I was removing items in hijakthis. error #52 Bad filename or number in sub getlongpath (square symbol.exe) actually a square. Went back and checked and I think it still removed everything. I am getting a runtime error when opening your site but it could be Windows updates. If you think it is safe to go do all my updates now on windows I will.

    Thanks again
    Dan
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. Dan Armstrong

    Dan Armstrong Private E-2

    Hey Chaslang,
    I would like to thank you and this awsome site for all the help and I am sure the school teacher who owns this machine very much appreciates you guys also. Everything seems to be working fine now. I still have to do a lot of updates and reinstall her printer but I think it will be ok now. Can you point me towards where I can make a donation to your website to help keep it up and running and to show my appreciation for all the good info I have found on this site in the past.

    Thanks again Majorgeeks,

    Dan Armstrong
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Thanks but Major Geeks is not setup to accept donations.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds