malware infected laptop - followed read me guide

Discussion in 'Malware Help (A Specialist Will Reply)' started by whocares741, Feb 26, 2007.

  1. whocares741

    whocares741 Private E-2

    My friend heavily infected his computer with malware and asked me, the most tech savvy person he knows, to help fix it. Now I don't know too much about malware removal, but I ran the guide in the read and run me first. When I first got the laptop, there were some pop - ups and this fake notification in the system tray about spyware. From what I can tell, the pop ups are gone but the notification still sits in the system tray and pops up every once in a while, even in safe mode. Any help would be appreciated.
     

    Attached Files:

  2. whocares741

    whocares741 Private E-2

    Here are the other logs. Counterspy and the online scans were run in normal mode since the resolution in safe mode wasn't able to fit the programs.
     

    Attached Files:

  3. whocares741

    whocares741 Private E-2

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to navigate to this folder and delete it
    C:\WINDOWS\SYSTEM32\hjpprpu.dll

    Next use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java 2 Runtime Environment, SE v1.4.2_06
    My Way Search Assistant

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.

    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - (no file)
    O3 - Toolbar: (no name) - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - (no file)
    O23 - Service: Terminal Connections (terms) - Unknown owner - C:\WINDOWS\system32\terminals.exe (file missing)

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  5. whocares741

    whocares741 Private E-2

    Thank you for your help so far. I did as much as I could. When I tried to delete hjpprpu.dll, i got the error that said access is denied, make sure the disk is not full or write-protected and that the file is not currently in use. I also could not find My Way Search Assistant in the Add/Remove programs file list. Lastly, when I ran hijackthis! to delete this:

    O23 - Service: Terminal Connections (terms) - Unknown owner - C:\WINDOWS\system32\terminals.exe (file missing)

    it was not there. I did everything else that was requested though.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Reboot and run Pocket Kill Box and have it delete this item (unless you can delete it thru windows explorer):

    C:\WINDOWS\SYSTEM32\hjpprpu.dll

    Make sure that you check the box to unregisster .dll's if you use PKB.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - Global Startup: LimeWire 4.2.6.lnk = C:\Program Files\LimeWire\LimeWire 4.2.6\LimeWire.exe

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  7. whocares741

    whocares741 Private E-2

    Ok, I did everything as requested. The laptop seems ok right now, the popup thingy is gone! Hopefully everything is clean.
     
  8. whocares741

    whocares741 Private E-2

    hm didn't post the logs.
     
  9. whocares741

    whocares741 Private E-2

    Ok this is going to be the post with the actual logs. For some reason, the laptop has a hard time connecting to my own network, so I have to plug it in directly.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds