malware removal done what next?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ibar, Jun 22, 2007.

  1. ibar

    ibar Private E-2

    attached are two of the logs and my next message will have runkey and newfiles txt..now what?:cry
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Actually there are 4 other required logs that you need to attach.

    SuperAntispyware - since you have Win ME and cannot run CounterSpy or AVG Antispyware
    Bitdefender - from step 6
    runkeys.txt - the log from GetRunKey.bat
    newfiles.txt - the log from ShowNew.bat


    And more importantly, you need to explain why you are posting here. You did not mention what problems you are having.
     
  3. ibar

    ibar Private E-2

    thanks for the welcome and reply,

    The computer runs very slowly often sometime it loads pages fast and moments later it can take 30 seconds to load the same page. sometimes it freezes and gives an explorer error that closes the explorer. on every startup there is a message that says it can't find printray.dll- maybe I deleted it??, when I tried to update the explorer i got the error message that ntdll.dll to shutdown the system was missing and the updates would not load, the attached bitdefender log is from today because I didn't save the other one,
     

    Attached Files:

  4. ibar

    ibar Private E-2

    more logs, thanks for taking the time to look at this,
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your main issues may not be malware. It could be just due to all the applications, toolbars,....etc you are running. You really need to think whether you really need all this stuff and uninstall what you don't need. If you don't need it to get connected to the internet, then think about uninstalling it. I will give you a few things to do and ask a question or two below, but the above is all something you need research and decide outside of this forum.

    Is that jibberish for Propel Accelerator valid?
    Is people PC you ISP and are you on dialup? Consider uninstalling anything from them that is no required to get connected. People PC has been known to display adware.

    Uninstall SuperAntiSpyware now since we are finished with it.

    Let's remove some unnecessary startups and a malware item which should help things a little. If any of the item I suggest to remove below are known to be used by you and you need them to always run at startup, then you can skip fixing them but just remember they are not required and are wasting system resources. They can be run when you need them.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O4 - HKLM\..\Run: [Digital Dashboard] C:\Program Files\Compaq\Digital Dashboard\DevGulp.exe
    O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
    O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
    O4 - HKLM\..\Run: [srng] \Program Files\Srng\Srng.exe
    O4 - HKLM\..\Run: [PPCRunonce] C:\WINDOWS\SYSTEM\PPCRunOnce.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime

    Do you MS Money? Do you really need it to always run at startup? If not, fix it too otherwise skip it.
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"

    Do you use the below Calendar reminder program for Works? If not, fix it too otherwise skip it.
    O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Compaq Knowledge Center.lnk = C:\Program Files\Compaq Knowledge Center\bin\silent.exe
    O4 - Startup: Microsoft Office (2).lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete the below if found:
    c:\windows\system\unPPC.exe
    C:\Program Files\ContraVirus <--- the whole folder
    c:\program files\Srng <--- the whole folder
    C:\WINDOWS\Favorites\Health <--- the whole folder

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Delete all files in the below folder:
    C:\WINDOWS\TEMP\

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds