More fabulous help, please...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bronco_b, Sep 17, 2006.

  1. Bronco_b

    Bronco_b Private E-2

    What a wonderful service you all continue to provide to us poor users! I came here in February because I was experiencing the exasperating WinFixer popups. After carefully following Chaslang's excellent, well-written instructions I eliminated Virtumonde/Vundo and

    repaired a Powerpoint error at bootup. Thank you, thank you, thank you!
    Now I am experiencing a Norton notice pertaining to DiskClean so I turn to MajorGeeks for help again.

    ATTACHMENTS:
    bdscan.txt 9/17 8:28am
    Activescan.txt 9/17 9:05am
    hijackthis.log 9/17 9:46am

    Available for future attaching:
    rkeysxxx.txt (19kb) 9/16 @ 9:28am
    runkeys2.txt (18kb) 9/17 9:15am
    newfiles2.txt (51kb) 9/17 9:22am

    I have attached the three indicated files. If I have overlooked something or if you need any of the other three, I'll do whatever it takes. Please do your magic for me once

    again....

    Thank you in advance.

    Bronco Bill in Reno
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI Bronco Bill

    Do please attach the other logs you have as well, in the Getrunkeys and ShowNew as they also help diagnose the malware on your PC.
     
  3. Bronco_b

    Bronco_b Private E-2

    Okay, here are three more attachments....

    rkeysxxx.txt (19kb) 9/16 @ 9:28am
    runkeys2.txt (18kb) 9/17 9:15am
    newfiles2.txt (51kb) 9/17 9:22am

    I must have run the runkeys and newfiles out of sequence the first time since the first editions were empty.

    Thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are using old copies of ShowNew and GetRunKey. Please download and use the current versions of the programs. We only need the logs requested. The other files (like rkeysxxx.txt) are temp files that go away after the program completes.

    You must always refer to the online version of the READ ME. Running from stored local copy like you must have done will only cause problems in that you will not be following our current procedure and you will probably not have the correct versions of programs.
     
  5. Bronco_b

    Bronco_b Private E-2

    My apologies. As a matter of fact, I was using a 9/8 printout.

    Here are the newly created files.

    Thanks, and sorry...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat! You are using old versions of the programs! You MUST download the current versions from the links in the READ ME. Download both GetRunKey.zip and ShowNew.zip and attach new logs from both of them. 9/8 is ten days ago.
     
  7. Bronco_b

    Bronco_b Private E-2

    Am I embarrassed!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not really have to many problems!
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab

    After clicking Fix, exit HJT.
    Additional steps to delete files in the Downloaded Program Files folder :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s SAIX.dll
    del SAIX.dll
    attrib -r -h -s UDC6_0001_D18M1108NetInstaller.exe
    del UDC6_0001_D18M1108NetInstaller.exe
    exit

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and attach new logs from HJT and GetRunKey.

    Make sure you tell me how things are working now.
     
  9. Bronco_b

    Bronco_b Private E-2

    Here's the latest files. Everything seems to be back to normal, I must say! However, I'll also let you know if the dreaded "DriveClean" shows up again or not during the night.
     

    Attached Files:

  10. Bronco_b

    Bronco_b Private E-2

    Well done, sir!

    Norton usually picks up DriveClean during its early-morning sweep. This morning there was nothing. Thank you again!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good, but those two registry keys are still present. Did you add the fixWLK.reg registry patch as requested. Did you get a success message? Both of those are still present in your log from GetRunKey.
     
  12. Bronco_b

    Bronco_b Private E-2

    Sorry for the delay, thanks for your patience. We're in the process of moving and this important project was superceded by that....

    I backed up to your post of 9-19 and ran fixWLK again. Yes, I received a success message. According to that post, there were no processes to end in Task Manager. (But NMain.exe was running pretty much constantly at a 50% level this a.m. until I rebooted after my Prefetch reboot.)

    HiJackThis did not have the line
    O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freewar...eanerstart.cab
    HJT log attached (HijackThis 9-23.log)

    After exiting HJT I went to the Downloaded Program Files folder.
    SAIX.dll not found
    UDC6_0001_D18M1108NetInstaller.exe not found

    Deleted 125 files from c:\windows\Prefetch
    Rebooted
    Attached new logs from HJT and GetRunKey.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds