My computer hates me.HELP

Discussion in 'Malware Help (A Specialist Will Reply)' started by mavman23, Dec 19, 2006.

  1. mavman23

    mavman23 Private E-2

    I am doing the "READ AND RUN" page!! I am trying the bitefinder now but it is taking hours and hours. Here are some of my logs please help.
     

    Attached Files:

  2. mavman23

    mavman23 Private E-2

    Oh and my symptoms are: I have a constant critical system errors icon flashing bottom right by the clock. A yellow flashing icon that says my system is infected, and when I click it, it takes me to virusbusters. Cant reboot in safe mode. It just stops working and I have to manually shut it down. (porn)Pop ups when I'm not even on the internet. And my system is having trouble starting properly. (ie) sometimes it will come up and nothing will work. I will click on icon and nothing. U have got it ti boot up in debugging mode, and it works sometimes. It's like the start up doesn't get all the way finished b/c the program icons that load down by the clock (usually 10 or 11) won't load. Only 3 or so will load including the old Critical system error message. Please help I have a bad feeling
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    The steps in the READ ME need to be completed in the order given. Like running BitDefender and Panda before getting to GetRunKey & ShowNew. Otherwise things that we see in the log and spend time working up procedures to fix could just be a waste of time since what you ran afterwards may have already fixed them.

    At anyrate, I can see that you do have a problem that will not be completely fixed by the READ ME. You have a SmitFraud infection that you more than likely got because you downloaded codecs to play some video or similar (bad idea) or possibly due to downloading something from myspace (another bad idea).


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    Now also attach the BitDefender and Panda ActiveScan logs requested in the READ ME.


    How are things working now?

    Did you install and do you use WinVNC3? If so, you will need to reinstall it since you had CounterSpy delete some of its settings. It is hard to sometimes know what is good and what is bad. So tools like CounterSpy will question tools like this which could serve malware purposes. Thus this puts the burden back on you to know what you have installed and what you did not install and thus also decide what to delete and not to delete.
     
  4. mavman23

    mavman23 Private E-2

    Thanks for helping me out!! Here is the rapport and the bdscan ( it finally finished 7hours later!!!) I will move on to step 2 now. Thanks
     

    Attached Files:

  5. mavman23

    mavman23 Private E-2

    ok... I cannot reboot in SAFE MODE. I get a blue screen with a STOP message saying "0x000000001e blah blah.... and then KMODE_EXCEPTION_NOT_HANDLED" It does this every time I try to reboot in safe mode. several times. I will wait to hear back before continuing! Thanks again!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if something messed up a registry key and is preventing safe boot mode from working. Download GetSB.zip from the below link. Save the file into the same folder where you put GetRunKey.zip or ShowNew.zip. Then also extract the GetSB.bat from the ZIP file into a folder where either GetRunKey.bat or ShowNew.bat are located. Then double click on GetSB.bat from a Windows Explorer prompt. It will create c:\safeboot.txt attach this file to your next message.

    http://forums.majorgeeks.com/attachment.php?attachmentid=49901&d=1165266055
     
  7. mavman23

    mavman23 Private E-2

    When I unzipped the file it was a safeboot.reg not a .bat file. I clicked the safeboot.reg and clicked ok but there was no safeboot.txt to find..???? did I do something wrong??
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! That was the second step (if we need it it). Here is the correct link for what I want you to do.

    http://forums.majorgeeks.com/attachment.php?attachmentid=49890&d=1165263049


    Keep the other safeboot.reg file too until I see if we need it.
     
  9. mavman23

    mavman23 Private E-2

    ok here is the log you requested.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That looks fine!

    Did you ever complete the rest of the READ & RUN ME? Like the PandaActiveScan and step 7 for HijackThis. I really need those logs to try and work up a manual fix since you cannot get into safe mode.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way you need to download and use the current versions of GetRunKey and ShowNew. You are using outdated versions which means you did not download them while running the READ ME or you did not download them from Majorgeeks!

    Download the current versions now so that any future logs will be correct.
     
    Last edited: Dec 20, 2006
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try to get started fixing these problems even without HijackThis and the Panda log.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_07
    Mozilla Firefox (1.5.0.7)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\All Users.WIN2K\Start Menu\Online Security Guide.url
    C:\Documents and Settings\All Users.WIN2K\Start Menu\Security Troubleshooting.url
    C:\Documents and Settings\All Users.WIN2K\Desktop\Online Security Guide.url
    C:\Documents and Settings\All Users.WIN2K\Desktop\Security Troubleshooting.url
    C:\Program Files\Brain Codec\pmmon.exe
    C:\Program Files\Brain Codec\pmsngr.exe
    C:\Program Files\Brain Codec\isamonitor.exe
    C:\WIN2K\system32\czuejisn.exe
    C:\WIN2K\system32\xxfgmy.dll
    C:\WIN2K\system32\ssmute.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Antivirus-Golden
    C:\Program Files\Brain Codec

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\TestaP\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Also attach your PandaActiveScan log. It will often pickup things other scans do not.

    Make sure you tell me how things are working now!
     
  13. mavman23

    mavman23 Private E-2

    ok I think I have done everything you asked so far... Here are all the rest of the logs. Thanks again for all your help. Oh and when I rebooted I am not getting the critical system error icon. Maybe making progress!!
     

    Attached Files:

  14. mavman23

    mavman23 Private E-2

    and here is HJT log, should I go back to step 2 now where I got sidetracked (safe mode)???
     

    Attached Files:

    Last edited: Dec 20, 2006
  15. mavman23

    mavman23 Private E-2

    ok well safe mode is still a no go...
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat message number 11 now!
    Get the correct versions and attach new logs for GetRunKey and ShowNew now!


    Note: your safe boot mode issue is probably not malware.
     
  17. mavman23

    mavman23 Private E-2

    well I DID get them from the read me now thread, but I will try it again!!! Is there a certain version I am suppose to be using?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not recently (like from the date of your first mesage which was 12/20)

    You are using GetRunKey V 1.50 from 10/27/2006
    And ShowNew V 0.22 from 11/26/2006

    You got your logs on 12/19/2006 and by that date GetRunKey was already V1.52 and ShowNew was V0.25.

    Yes! The ones in the download links given in the current READ & RUN.
    GetRunKey V1.53 from 12/20/2006
    ShowNew V0.25 from 12/16/2006
     
  19. mavman23

    mavman23 Private E-2

    ok well here they are again. dont know how the others were old versions but hope these are right!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Those are the current versions.

    Note to chaslang: All other logs are clean! Just HJT fixes left!

    Uninstall the CounterSPy trial now as it is no longer required. Uninstall it before you continue with the below.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,
    R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {ae18da4e-be15-4925-81bb-890c04af0200} - C:\Program Files\Brain Codec\isaddon.dll (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WIN2K\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WIN2K\web\related.htm

    After clicking Fix, exit HJT.

    Now use Windows Explorer to delete:
    C:\Program Files\Brain Codec <--- the whole folder, if found (probably will not be)


    Now run Ccleaner.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot your PC

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  21. mavman23

    mavman23 Private E-2

    ok i think things are getting better. the above steps went fine as far as I can tell. here are the requested logs again.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean. If you still have problems with safe boot mode, you should post a message in the Software Forum describing exactly what you have tried and what happens. Give complete error messages if you get any.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  23. mavman23

    mavman23 Private E-2

    ok thanks very muh for al your help!!

    Paul Testa
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds