???i've Done Everything U Asked??

Discussion in 'Malware Help (A Specialist Will Reply)' started by ReneeSoriano, Jan 30, 2007.

  1. ReneeSoriano

    ReneeSoriano Private E-2

    I obeyed ur rules.
    I read all the 'read and run me' guides first.
    Uninstalled everything I could see.
    I even did the special removal tools.
    Emptied my drive of 'junk' (temp files etc.)
    Did MSconfig
    CCleaner
    Ran ALL the steps.
    Spybot
    CounterSpy
    Boot in safe.
    Bitdefender
    Panda Active scan
    GetRunKey and ShowNew.
    And hijack this.
    all will be attached.
    HELP.
    This is my desktop
    Winxp and now my brand new laptop is doing the same thing?
    I think it all started a couple days ago with my router.
    I have a cable modem, but accessed two connections through a Dlink router.
    Last week, the router continually shut off the modem every 15
    or 20 minutes. The router would only assign a DHCP after being manually restarted, and then connectivity would be gone again after a few minutes.
    Is there any other program I can try?
    PLEASE>
     

    Attached Files:

  2. ReneeSoriano

    ReneeSoriano Private E-2

    Just some more attachments for you guys?
     

    Attached Files:

  3. ReneeSoriano

    ReneeSoriano Private E-2

    just a few more
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Messenger Plus! Live...you might consider removing this program (look at your first Counterspy log) as most of your malware was coming in thru it.

    Please download FixWareout by LonnyRJones from one of the two below links and save it to your desktop.

    http://downloads.subratam.org/Fixwareout.exe

    http://www.bleepingcomputer.com/file...Fixwareout.exe

    * Run Fixwareout.
    * Click Next,
    * then Install,
    * make sure Run fixit is checked
    * and click Finish.
    * The fix will begin; follow the prompts.
    * You will be asked to reboot your computer; please do so.
    * Your system may take longer than usual to load; this is normal.

    When you run fixwareout, just follow the prompts, you will need to restart when prompted.

    After rebooting (restart) back into normal boot mode, make sure you have all web browsers closed.

    * Go into Control Panel -->Network Connections.
    * Right click on your connection
    * and click Properties.
    * On the Properties page, highlight Internet Protocol(TCP/IP)
    * Click Properties. This will bring up another page.
    * Select Obtain DNS Server Automatically.
    * Click the ok button. The page will close.
    * Press ok on the page in front of you.
    * Restart the computer.
    * Reconnect to the Internet using Internet Explorer.
    * Now come back here and attach the log from fixwareout. It is located at c:\fixwareout\report.txt

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = yyy
    O17 - HKLM\Software\..\Telephony: DomainName = yyy
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = yyy
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = yyy
    O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = yyy

    After clicking Fix, exit HJT.

    Please attach new logs for:
    GetRun
    ShowNew
    HJT

    And tell us how things are running.
     
    Last edited by a moderator: Jan 31, 2007
  5. ReneeSoriano

    ReneeSoriano Private E-2

    I am so happy with the quick response you guys are doing.
    Well here goes.
    I did uninstall messenger live, installed fixwareout.exe.
    Installed, pc did a re-boot.
    Configured Network settings in control panel. Did another reboot, and

    windows would not load.

    'NTLDR not loaded'
    'NTLDR not loaded'

    I had to manually restart computer and toggle ALT F8.
    Once in the screen I chose to reboot, and it allowed me,.

    Does NTLDR not mean network of some kind?
    The first three files attached are txt files of my system and
    what it was supposed to do.
    Neways, ran hijack this, closed all browsers, fixed the 8 HKLM issues.
    Saved files.
    And here I am

    -couple extra ??
    Is any version of messenger safe to download? My kids absolutely love it?
    Also, since I've had this problem with my computer, my memory is only 63% out of 250GB, and there are at lease 500 000 files in the computer.
    Is there anything I can do besides reformat?
    Oh yah, and can you check my attachments.
    Not asking too much am I?

    Renee
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you run CCleaner as asked in the Read and Run First instructions?

    I need you to attach the three logs that were asked for:
    ShowNew
    GetRun
    HJT
     
  7. ReneeSoriano

    ReneeSoriano Private E-2

    Morning!
    Thought I was being so computer savy I forgot to attach
    the files. Yah, I'm a dork.
    Here are the three files, also I did NOT run CCleaner before doing all this.
    Should I do it all over again?
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and run this: HSRemoval

    Follow the directions with the program or:
    1. In internet options/advanced, uncheck "Enable third-party browser extensions"
    2. Boot in safe mode.
    3. Run an updated Add-aware. Use Custom scanning, and check "Scan within archives".All memory and registry options should be checked.
    4. Delete all entries in quaratine list.
    5. Run hsremove.exe
    6. Reboot in normal mode.
    7. Run hsremove.exe again.
    8. Go to internet options in CP, or right-click ie shortcut. (Don't start ie).
    In General, reset homepage to desired URL Like http:\\www.majorgeeks.com.

    attach a new
    ShowNew
    HJT
     
  9. ReneeSoriano

    ReneeSoriano Private E-2

    OK.
    Did it all.
    And still it's taking me to some runonce homepage?
    Ive attached the details.
    Tonight I will attempt to fix my laptop if I can get
    this one right.
    Thank you for helping.
    Do I need to reinstall IE7?
    HELP!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly I think you need to uninstall IE7, but that is up to you. Is this happening with any other browser? Your HJT log shows that you have set your home page to MajorGeeks. You could post in the software section if you are still having problems with IE7.


    Do you know what these are and if not delete them?
    C:\program files\ebgcInfra
    C:\program files\ebgcRes
    C:\program files\ebgcSDK

    Please run HJT and have it fix these:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm G
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843


    Now uninstall:
    J2SE Runtime Environment 5.0 Update 10
    and install:
    Java Runtime 6.

    Are you having any other malware issue?
    If not, we will have you uninstall any downloads used for the ananlysis and then toggle the system restore (IE: turn off system restore, restart the computer, turn system restore back on.)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds