my computer sucks

Discussion in 'Malware Help (A Specialist Will Reply)' started by mocone, Mar 7, 2007.

  1. mocone

    mocone Private E-2

    hey guys,

    i will thank you in advance, because you guys have hooked me up in the past. my computer has been slow for a while now. i added an external drive to free up space on my c: drive. i ran IObit to defrag. it helped somewhat. then i ran spybot and found something stubborn. attached are my logs as per the malware removal instructions. i hope they are all correct. i also have getrunkey and shownew logs i will send along with hjt log. thanks again for all your help.

    mocone
     

    Attached Files:

  2. mocone

    mocone Private E-2

    hey guys,

    here are the rest of my logs. thanks!!!!

    mocone
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run this WareOut Removal and attach the requested log.

    Also complete step 7 of the READ ME and attach a HijackThis log. Make sure it installed properly and also renamed as requested.

    Tip: You need to stop extracting and installing programs into a common folder like C:\spyware tools
    This is dangerous becomes you can overwrite files from one application with anothers which could break to application or worse....make it operate strangely. In addition, things installed like this can quickly be assessed to be malware since they do not appear to be installed into there default folders or at least folders named for the exact application. For example you installed Sunbelt CounterSpy here and it belongs in C:\Program Files\Sunbelt CounterSpy which makes it easy to know who the files belong to. And also CounterSpy's files cannot be overwritten if installed into its own folder.

    The below looks like malware
    Code:
    taskma~1.exe  Sep  4 2005     1502848  "taskmanager16.exe"
    But it is probably Security Task Manager if I make a guess. Are you getting my point? ;)
     
  4. mocone

    mocone Private E-2

    hey chaslang,

    man, i'm sorry. every time i think i might actually be sending you things correctly i screw something up. do shownew and getrunkey need to be moved to different folders also? if so where? was counterspy the only one you noticed in the wrong location? anyway, i will make another attempt at this. sooo, please don't laugh as i send you my hjt.log and fixwareout.log. sorry again if something else is screwed up.

    thanks for your help
    mocone
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While they will run from where you had them you should follow the directions given for them. The directions suggested that you install them to C:\MGtools That will isolate them from anything else which in the long run can prove to be an advantage if troubles arise.

    Just about everything in that folder either needed to be installed properly into its default C:\Program Files folder or should have at least had an appropriately created and named subfolder which was named for the application it related to. For example if you did the made the below folder:

    C:\spyware tools\Security Task Manager

    and saved taskmanager16.exe into the above folder, you would know what it is 6 months from now. And so would we when we see it in a log. ;) Note these are just important tips that can help you keep your PC more organize and make things easier for you and people like us malware fighters. It does not mean things will not work like you were doing, but it definitely could eventually become a problem since installing multiple unrelated applications from different people/companies could lead to overwritten of files with the same names.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_06
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now!


    You still did not rename HijackThis.exe as required. See step 7 of the READ ME. This can be critical in todays malware world. Rename it and attach a new HJT log.

    After doing all of the above also attach a new log from ShowNew.
     
    Last edited: Mar 9, 2007
  6. mocone

    mocone Private E-2

    hey chaslang,

    so i will attempt this again....
    here is the hjt log. i removed the programs you suggested and got the newest java runtime. i also renamed hjt. hope it's right.

    thanks again
    mocone
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    Why are you loading Internet Explorer at startup? If you don't need this (and I know of no reason why you should) then fix this next line. If you do need it for some reason then skip only this next line with iexplore.exe
    O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    c:\windows\system32\loadctr32.exe
    C:\WINDOWS\System32\csjog.exe
    C:\WINDOWS\system32\SBFC.dat
    C:\WINDOWS\system32\SBRC.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. mocone

    mocone Private E-2

    hey cahslang,

    so i followed your steps with hjt . went well. then i used killbox, but when i got to the part where i needed to highlight to clipboard none of the files were there.
    killbox said there were no files. anyway, here are the new logs you requested.

    thanks again
    mocone
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! The below two files are still there:

    C:\WINDOWS\system32\SBFC.dat
    C:\WINDOWS\system32\SBRC.dat


    You can just delete these manually using Windows Explorer. They are not problems. They are left overs from CounterSpy.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. mocone

    mocone Private E-2

    hey chaslang,

    thanks for all the help. i deleted the two files through windows explorer, did the finishing touches and everything seems to be working great. thanks again for your time and expert advice.

    take care
    mocone
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds