Infected or damaged files??

Discussion in 'Malware Help (A Specialist Will Reply)' started by bneilson, Dec 29, 2006.

  1. bneilson

    bneilson Private E-2

    I'm not sure what's going on with my OS. It's my son's system, Dell Inspiron 6000 and he brought it home from college in early Nov. all jammed up. I finally got Win XP to boot with a rescue disc from Bart's. All the icons on desktop were changed to Microsoft Word symbols, but all the extensions for the programs were changed to .lnk, and Windows didn't recognize how to open anything. I finally connected to the internet and ran several different programs for viruses. We were using Norton, now McAffee. I restored most of the extensions with fixes from Doug Knox's website. I am sorry, I don't remember specifics. I've had to deal with 2 major holidays and a large family since then. He took it back to school and finished up the semester. However, just before Win XP opens when started, a random window opens. Usually from c:\windows\system32\, but while doing the Read and Run Me stuff, there were just little squares in the place of a file name on the window. I have to click on the window in order for XP to finish opening. I followed the instructions before posting. I was unable to run the scans in safe mode for some reason. Various pests were found. Bitdefender was the only one that removed anything. Vundofix did not find anything. My logs are attached. Thank you for any help you can give me.
     

    Attached Files:

  2. bneilson

    bneilson Private E-2

    Here are the rest of the logs.

    Bonnie Neilson
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Normally something like this is the sign of a corrupted or null entry in one of the Startup locations.

    If your son has taken the PC back to school, how do you plan to fix anything we find.

    You need to rerun CounterSpy and allow it to fix what it found! You had it ignore everythiong. You definitely need to get that PC MightyMax fixed. Do this before countinuing on to the below where I will say to uninstall CounterSpy.

    You need to get a couple antispyware applications removed. I'm surprized this PC runs at all with all of the junk McAfee is running and then add to it AVG Antispyware, CounterSpy, Spy Sweeper, and Windows Defender.
    • Is AVG Antispyware the free version from the READ ME? If yes, uninstall it.
    • If CounterSpy is the free trial from the READ ME, uninstall it now.
    • Is Spy Sweeper a paid version or free trial? If paid keep it and uninstall Windows Defender.
    • If Spy Sweeper is the free trial version, uninstall it and keep Windows Defender.
    You saved a load of stuff to the C:\Documents and Settings\Andrew Neilson\Desktop folder. You should either delete most of these files or move them to a more permanent location that does not clutter up the Desktop.

    What is this folder C:\Program Files\SpywareRemover

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Are you using some kind of program to control startups? I see a load of things being indicated as control in msconfig registry entries but MSconfig itself is not being used. Thus something else must be controlling them.


    Make sure viewing of hidden files is enabled (per the tutorial).
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: (no name) - {812ADD54-7C7E-4257-AC67-742FE57D7D63} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.
    Then reboot into safe mode and delete the below if found:

    C:\Program Files\PC MightyMax <--- the whole folder
    C:\Program Files\VSAdd-in <--- the whole folder

    Now run Ccleaner .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Jan 3, 2007
  4. bneilson

    bneilson Private E-2

    Thank you for taking so much time out of your life to help me. Things seem to be running much faster. For the life of me, I could not get Counterspy to do anything except Ignore. I had the box checked to quarantine and for 2 days and last night I tried all I could think of. I ran 8 scans and the results always came up in a separate window with nothing to click on. I removed the PC MightyMax with Trendmicro's Housecall after I read one of your responses to someone saying they must get Counterspy to fix the threats. After getting your response last night, and having no luck with Counterspy, I ran AVG in it's place. We subscribe to McAffee and Adaware and I have SpyBlaster(free) on there. Everything else was just extra. The task scheduler has only one page, processes. I just noticed that. I'm not very familiar with this computer. The extra window is still coming up. C:\windows\system32\mui\0414\xpob2res.dll occasionally, but most often gibberish squares. Last night when I was running the newfiles scan, it just kept scanning. I left it at 2am and this morning, it still said it was scanning! I reran it and stopped it again after 30 min. when the log seemed complete. Thank you again for all this time. I have taken my larger computer to a small repair shop twice when it has gotten viruses and they have just erased everything and started new, so all the pictures and docs I hadn't yet backed up to CD's were lost, they aren't big on saving stuff.:))
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    I don't understand what you mean! What extra window? And when are you getting this? xpob2res.dll is a valid Windows file.

    ShowNew should run in less than a minute. Did you have any problems the first time you ran this and attach logs in your second message?

    Please complete my previous instructions and attach the requested logs. If you cannot get ShowNew to run, then just attach the other logs.
     
  6. bneilson

    bneilson Private E-2

    OMG!! What an idiot I am. I thought I had attached these logs!! Sorry, to waste your time.:(
     

    Attached Files:

  7. bneilson

    bneilson Private E-2

    The window opens right after the XP logo and just before the logon box with Andy's name and password. That seems to be all that's wrong. I figured out how to restore the task manager to normal. Thanks.

    BN
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to address this issue in the Software Forum as it is not related to malware.

    Your logs are clean, but I have some more for you to do. Also I have a question that I'll ask first.

    Why aren't you using Ad-Aware's Adwatch feature? It is probably better to use that then to have Windows Defender running.

    You need to delete the below left overs from CounterSpy:
    C:\Documents and Settings\Andrew Neilson\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now use HJT to fix the below remnants of McAfee's Popup Blocker and Spy Sweeper.
    O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds