Laptop Problems - After Vundo Fix..Chaslang Plz Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bowlersaid, Sep 4, 2007.

  1. Bowlersaid

    Bowlersaid Private E-2

    Master Chaslang,

    Here are the aforementioned logs from the laptop in question.

    I started with a problem with :

    Dirve Cleaner 2006
    Command Service

    and on shutdown something called End Program - Sample

    Please let me know what U think...

    Mark
    The_Bowler
     

    Attached Files:

  2. Bowlersaid

    Bowlersaid Private E-2

    Re: Laptop Problems Chaslang Plz Help (2 of 2)

    The other files are below...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Laptop Problems Chaslang Plz Help (2 of 2)

    Let's do a quick jump start while I look thru the rest of your logs.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here are the next steps!

    Uninstall the CounterSpy trial now since we are finished with it.

    Also uninstall the below:
    UltimateBet
    UltimateBuddy
    Viewpoint Media Player

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1A00A28B-D791-4D35-AFC7-37AD23638B1a} - (no file)
    O2 - BHO: (no name) - {32CE0D1B-3B8E-46C3-B82F-E2AA3D137CBE} - C:\WINDOWS\system32\pmkjj.dll (file missing)
    O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\ayqyqapp.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  5. Bowlersaid

    Bowlersaid Private E-2

    Re: Laptop Problems Chaslang Plz Help (2 of 2)

    OK, results from first steps
     

    Attached Files:

  6. Bowlersaid

    Bowlersaid Private E-2

    Problems with this step....
    Could not find these lines at all in the HJT

    Other steps and results are below....
    Hjt log will be uploaded next attachment
     

    Attached Files:

  7. Bowlersaid

    Bowlersaid Private E-2

    Current Log HJT

    Current HJT
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay run HJT again and fix the below lines:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {854b5c75-23da-4d9b-b2b4-53c667e47ecf} - C:\WINDOWS\system32\wgiyxpa.dll (file missing)
    O2 - BHO: (no name) - {BC7E7EB0-41B9-4B6B-B2FD-46DDEE0E21F8} - (no file)
    O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)

    Then reboot and attach a new log from HJT.

    How are things working?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ** WARNING **

    While it is your choice in the end, sites and programs like below are not recommended. People get all kinds of infections fro various online gambling sites.
    PartyPoker
    Poker Academy
    Poker Tracker Version 2.05.02
    PokerAce Hud (remove only)
    PokerStars
     
  10. Bowlersaid

    Bowlersaid Private E-2


    Log attached...
    Scans running ...

    Mark
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. This PC is totally unprotected!!!

    If you are not having any other malware problems, it is time to do our final steps (just like on your previous PC )
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  12. Bowlersaid

    Bowlersaid Private E-2

    Ok, closing steps finished restore points cleared and new one set

    As for protection... I had cleared the system of McAfee, the bloated piglet...
    And Zone Alarm - it was giving me problems...
    Was looking to "clean it up" then get new protection per recommendations.

    Protection Link Worked Through now...
    The Results...

    Windows Updated
    AVG AntiVirus Installed and updated (scan run)
    A2 Free Installed (Scan Run)
    Windows Firewall Disabled
    Comodo Personal Firewall Installed
    C Cleaner (Already on board)
    Comodo BO Clean Anti-Malware Installed
    Spyware Blaster Installed and Enabled
    Active X Securities adjusted
    Switched from IE to Mozilla Firefox
    Sunjava (Already on board)

    Question o wise one...
    Do I have duplicates here?
    Seems like a lot 'o stuff :confused

    Your thoughts please Master Chaslang
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can live without A-Squared. The only things that will be actively running if you remove A-Squared are:
    • AVG AntiVirus
    • Comodo Personal Firewall
    • Comodo BO Clean Anti-Malware
     
  14. Bowlersaid

    Bowlersaid Private E-2

    Clean (I think) but seems laggy now....

    O wise one...

    After we cleaned up the laptop (But before all the protection) it was fast again.

    Now with all the protection it seems a little laggy (opening programs and the like) I guess I don't mind waiting a little if it keeps me clean...:cry

    Is there something we can look at or do that might tweak the speed without sacrificing my security?:confused

    Thanks for your thoughts and/or recommendations,
    Mark

    Dell Inspirion 8600
    Intel Pentium M processor 1600MHz 1.59 Ghz
    Ram = 512
    Running XP Pro 2002 with SP 2
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Clean (I think) but seems laggy now....

    More RAM would be a great idea! I don't recommend less than 1 GB;)

    However even without the additional RAM, you can help reduce some of your problems by stopping a load of unnecessary junk from running at startup. These are not malware but you don't need them. You can always restore them from the backups that HJT makes if you change your mind about them later.

    That said, have HijackThis fix the below lines.
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [bacstray] BacsTray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?

    Also I don't recommend the below be used since I prefer to get updates when I want them. You will have to decide on your preferences.
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup


    You can also uninstall A2-Squared to see how much impact it has on you since it leaves a service running.
     
  16. Bowlersaid

    Bowlersaid Private E-2

    The Pursuit of Speed -

    Thanks for the suggestions...

    Removed the recommend lines, un-installed A2:boxing

    Had a thought about IOBit Smart Defrag Program..
    I had installed it on this system in a pursuit of speed, perhaps that should be
    curtailed as well....:tas

    Below I have included a current HJT log take a peek, with an eye towards speed

    As for the RAM, I agree more is better lol... recommend a vendor?
    OR should I just call DELL ?

    Thanks again for everything....
    Mark
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: The Pursuit of Speed -

    I recommend not using any on the fly defragging. Only defrag when you want to.

    Fix the below line:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    I had already given other recommendations!

    I also tend to doubt that the below service from Dell is of any real use:
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe


    Post this in the Hardware Forum and I'm sure you will get suggestios.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds