Malware issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by tennohaika, May 10, 2007.

  1. tennohaika

    tennohaika Private E-2

    Hi! I don't know if some of you guys remember me but I had troubles with my PC
    a year or so ago :cry But with the help of this forum I was able to fix my computer! Anyway for the past week my PC has been acting up, so I ran some scans and turns out I have new occupants and the old friend apropos started to screw with my PC. I've followed the scan directions and ran the program to get rid of Apropos and I will be posting along with the other scan reports with my HJT report.
     

    Attached Files:

  2. tennohaika

    tennohaika Private E-2

    The file named log is the program to get rid of Apropos.
     

    Attached Files:

  3. tennohaika

    tennohaika Private E-2

    And here is my HJT log... And I had to run panda scan and bit defender on normal boot up since I am unable to connect to the internet (switched to wireless few weeks ago). For now I will be on my laptop and report back whatever things you guys need :cool
     

    Attached Files:

    Last edited: May 10, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have all of the below antispyware programs running. Are AVG, Ewido, and Spyware Doctor paid programs or free trials?
    AVG Anti-Spyware 7.5
    ewido security suite
    Spyware Doctor 5.0
    Windows Defender


    Did you update Internet Explorer on Feb 21st?
    Code:
    "C:\Program Files\Internet Explorer\"
    iexplore.exe Feb 21 2007 623616 "iexplore.exe"
    Uninstall the below as requested in step 0 of the READ ME.
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Also uninstall the below old Sun Java versions as requested in step 6 of the READ ME.
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2

    You did not do step 2 of the READ ME. Run the below registry patch which will automatically do this for you.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O23 - Service: ELZ - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\ELZ.exe (file missing)
    O23 - Service: HZYD - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\HZYD.exe (file missing)
    O23 - Service: QUO - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\QUO.exe (file missing)
    O23 - Service: VUJTJFAVKUP - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\VUJTJFAVKUP.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\common files\InetGet2 <--- the whole folder:
    C:\WINNT\winup.exe

    Now run Ccleaner

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: May 10, 2007
  5. tennohaika

    tennohaika Private E-2

    I had no problem taking the above steps, deleted all the things asked and here are the update log files. Uninstalled Ewido and Spyware Doctor, and including AVG they were free. It seems like it started to pick up the pace on loading and such:major Oh I forgot, I didn't understand when you asked about updating IE explorer on the 21st?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just was questioning whether you recently updated your IE version since the file date was showing up as Feb 21st which is unusual. Did you update to IE7 around that date?

    I gave you the wrong registry patch in the last message! I gave you what you already had. The below is what I should have given you, but you don't need to do it now since your logs are clean!
    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. tennohaika

    tennohaika Private E-2

    Thank you very much! I really don't know what happend with IE explorer thererolleyes I'm quite sure I didn't do that my self.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You probably installed IE7 at that time. It may have been an auto update if you don't remember doing it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds