Malware reports beyond my understanding

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gvfbgvfb, May 14, 2007.

  1. gvfbgvfb

    gvfbgvfb Private E-2

    Hi, thanks for your clear guidance, it got me through last time but now I'm getting uncomfortable. I have gone through READ & RUN ME FIRST as far as step 6B/7:
    - Spybot found Update disable's (I couldn't find the SDHelper)
    - BitDefender found nothing
    - Pandascan found two things
    Do you think I have a problem?

    Log's attached for bd, panda and getrunkey in this mail and for shownew and hjt in the next.

    Advice gratefully received.

    Thanks


    John
    System is a Dell Dimension E520 running XP with SP2.
     

    Attached Files:

  2. gvfbgvfb

    gvfbgvfb Private E-2

    HJT and Shownew logs too.

     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You don't have any major problems to worry about. We just have a few things to do. Some you missed while running the READ ME.

    Uninstall the CounterSpy trial (you forgot to attach the log but I don't need it now) since we are finished with it.

    Also uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    SearchAssist <-- should have been uninstalled in step 0 of the READ ME but there is a chance that it does not show. Let me know.
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.
    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  4. gvfbgvfb

    gvfbgvfb Private E-2

    Chas, many thanks for your great help.

    Apologies for missing SearchAssist and Viewpoint Media Player in the READ ME. CounterSpy had found not threats so I forgot to attach the log.

    I did try to load the version of Java in the READ ME but got confused. (I seem to remember that the download was a problem when I tried the link, guess I should have uninstalled the installed version first).

    All the steps below seemed to work okay and the machine now seems quicker.

    After the last re-boot I re-ran ShowNew and HJT (analyze.exe) - logs attached. The only odd sign was a window popping up from a red shield shaped symbol in the TaskBar saying that I have no Firewall running. I left it alone as I think the Windows firewall is running but am not sure how to tell.

    Many thanks


    John
     

    Attached Files:

    Last edited by a moderator: May 18, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No, you are using McAfee and it is providing your firewall. If that red shield is showing it means it is disabled and you need to enable it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds