Major Cleanup

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jigzaw, Feb 19, 2007.

  1. Jigzaw

    Jigzaw Private E-2

    I have brand new laptop, but have been experiencing a major loss of CPU power and I have been "tagged" by a rather annoying pop up. So in an last attempt to save me the hassle of formating my pc I have turned to you.

    I have followed the READ ME & RUN ME to the t and present here the following logs. All except the Counterspy, which for some reason didn't work and the Panda which didn't want to give me any pop up with any log :( But it did say that no threats where found.

    It seems to be okay, the comp, but I'd still like it if you'd be so kind as to check my logs for anything I have missed :)

    Tnx in advance.
     

    Attached Files:

  2. Jigzaw

    Jigzaw Private E-2

    The rest of the logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall these:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 9

    Reboot your computer and install: Java Runtime 6

    Use windows explorer to delete these:
    C:\Documents and Settings\All Users\Application Data\first4warnfork
    C:\Documents and Settings\Nils\Application Data\plan64noun



    Now copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [Warn fork program support] C:\Documents and
    Settings\All Users\Application Data\first4warnfork\trans scr.exe
    O4 - HKCU\..\Run: [Copybore]
    C:\DOCUME~1\Nils\APPLIC~1\PLAN64~1\Boldteam.exe

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  4. Jigzaw

    Jigzaw Private E-2

    Ok, TimW. Did what you said and here are the new logs. Mind you, these following lines where nowhere to be found in HJT:
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is still showing in your logs, so just delete the whole folder.
    C:\Program Files\plan64noun.

    You may wish to: Kill the messenger.

    Otherwise your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds