Need A Little Help With Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by HealthCo, Oct 16, 2007.

  1. HealthCo

    HealthCo Private E-2

    Back again, though I never really want to to do this sometimes. Anywho, same story. My brothers computer has some junk on it and I have done the stuff in the READ&RUN thread. I couldn't get rid of things this time. I think it's a trojan. Well here are all the things the thread told me to put up, exept the the HJT log which I will do when prompted.
     

    Attached Files:

  2. HealthCo

    HealthCo Private E-2

    And the other ones too.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the HijackThis log requested in step 7 of the READ ME.

    No problems other that what was already cleaned and one item below. You need to explain what problems you are actually having.

    I suggest you uninstall the below:
    Web Savings from Ebates

    And you should delete the below file:
    C:\WINDOWS\system32\xmltok.dll.off

    Also CCleaner did not work properly, so do the below.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.
     
  4. HealthCo

    HealthCo Private E-2

    Okay, will do. Sorry about not putting the HJT log up, from what I remember from last time I needed help I wasn't supposed to post it untill later. And the problem I'm having is that the computer has stuff that doesn't want to go away and I can't get it to go away. Nothing seems bad but I want to stop it before it gets worse.

    EDIT: Ebates doesnt want to uninstall. I gives me an error. It says (in an error window):
    "WJView Error
    ERROR: Could not execute Main: The system could not find the file specified."
     
    Last edited: Oct 17, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is a direct quote from step 6 C of the READ ME. Notice the last bullet item. ;)
    Th word stuff does not mean anything to me. You will have to be specific since your logs show no malware.

    See if this will uninstall it: Your Uninstaller! 2006
     
  6. HealthCo

    HealthCo Private E-2

    Okay well I got an adware detection in activescan. I think a trojen was there as well but bit defender got rid of it. I'm sorry for not doing things the right way here, but I learn from my mistakes and will be sure not to make them again. I'll do all the things you want me to do now and I will put up a HJT log too, okay? I'm sorry I overlook things that would help you help me. :(

    EDIT: Actually in step 7 said I did't need to right away. And here it is:
     

    Attached Files:

    Last edited: Oct 17, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely not true. This was explained in step 6 of the READ ME too in the online scans section.


    On the contrary! It says it is okay to attach a log if you are still having problems and you have done the other steps. In addition step 6 comes before step 7 and step 6 does say if you still need help that you should also attach a HijackThis log. ;)

    Have you completed all the other instructions?
    Did Your Uninstaller uninstall Web Savings from Ebates ?

    I still don't know what you mean by "stuff" or what your problems are.

    You should uninstall the CounterSpy trial program since we are finished with it now.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    O2 - BHO: (no name) - {2898379A-A812-4285-8DBF-7DE39EE66D46} - (no file)
    O2 - BHO: (no name) - {FBBAFFBE-5A8F-4B71-B742-DFB0107415DB} - (no file)
    O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.


    Now reboot your PC
    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  8. HealthCo

    HealthCo Private E-2

    Okay. You're making me a little frustrated. I'm not gonna make it a big deal so I'll drop it. I don't think I said stuff in my post before.

    Anyway, here is what I can remember of my problems. I said last time that adware was being found. It did kinda sound like I said my adware is a trojan, but what I meant was that there was a trojan that I had. I know for sure cause bit defender said there was one and it tried to disinfect it but couldn't, so the files were deleted. But I have one adware left and it is in the regestry. Or atleast Activescan thinks it's there.

    Now the Your Uninstaller! did remove Websavings from Ebates. And I have completed the other insructions before your last post. I uninstalled CounterSpy as well and will do the other stuff right after it.

    I have one question though, What is nwiz .exe? I searched it in google and I read it was malware. I had noticed it in my HJT log.

    I know we're almost done with this and you won't have to deal with me anymore, I will hope to never bother you again. But I want to thank you for all the help you've given me, and I would like to apologize for the things I didn't do.
     

    Attached Files:

    Last edited: Oct 18, 2007
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is a quote from message # 4.

    Are you referring to the below from your activescan log?
    If so, don't worry about it. It is not an active problem and since Panda is not reporting exactly where they think this is, we cannot do anything about it anyway. And since it is not active, it is not worth the effort.

    No it is not malware. It is for your graphics card. It is the NVIDIA nView Wizard

    There is no need to apologize. I understand that following the steps and doing all the things we ask can be difficult especially if you are not a PC expert. ;)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But I still see the below in your HJT log:

    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe

    Did you uninstall it before or after getting your HJT log? Make sure it is uninstalled and that the above lines do not show a new HJT log anymore. Then also delete the below folders if they still exist:
    C:\Documents and Settings\admin\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  11. HealthCo

    HealthCo Private E-2

    I did uninstall first. It was still on the HJT scan after. So don't think I did't do things.
    The red one couldn't be deleted.

    You said that the adware Activescan was not important, so removal won't be needed? If that's true, than thank you for the help. I don't mind doing some quick little logs from scans before we finish if you think I should or want to make sure.

    The post I was saying I didn't say stuff in was this one:
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That normally means it is still installed or something from it is still running. Did you fix those lines I mentioned in HijackThis? If yes, then try deleting the C:\Program Files\Sunbelt Software folder again. If it does not delete, attach a new HJT log.

    That's true. Anytime Panda just indicates something is in the registry but it provides no supporting information, it is just a benign registry trace that could be left over after the major items have been removed. It could also be a false indication.
     
  13. HealthCo

    HealthCo Private E-2

    I was being stupid and didn't end the process of the file that couldn't be deleted, but then I realized it and did it. I got rid of those lines and removed the folers. I will put up a new HJT log just to be sure. But yes I have done every thing you told me to in your last two posts.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Part of CounterSpy is still there. We will fix this below.

    Actually according to your HJT log you have not completed the instructions in the How to protect yourself thread. At a minimum I can see you have no realtime antispyware protection and you have not installed a true bidirectional firewall. In addition, you should install SpywareBlaster if you have not already done so.


    Consider running this Disable/Remove Windows Messenger to remove Windows Messenger which is a frequent cause of unwanted popups.


    Now let's finish with CounterSpy.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Service: Sunbelt CounterSpy Antispyware
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSBCSSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot attach a new HJT log.
     
  15. HealthCo

    HealthCo Private E-2

    Okay. I will do the protection thing once we are done here. I put my new HJT scan up.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    CounterSpy is gone now! Just follow those instructions to get your PC properly protected now.
     
  17. HealthCo

    HealthCo Private E-2

    Okay. Thanks for the help. I appriciate it greatly. I'll get all That needs to be done to protect this computer.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds