Need help understanding HJT log, etc.

Discussion in 'Malware Help (A Specialist Will Reply)' started by pastorricky, Jul 30, 2006.

  1. pastorricky

    pastorricky Private E-2

    I ran through the steps in the "READ & RUN ME FIRST" section in order to remove any and all malware on my system. There were a couple of them that have been removed. Included on this thread are the requested logs. I don't really understand the HJT log. Do the logs show anything that I need to do now?

    Thank you,
    Rick

    P.S. It seems that I was suckered into a scam registry cleaner - RegCure. The program, itself, contains a malware (DollarRevenue) detected by Panda. I have emailed the "company" for a refund (~ $20), but no reply. What can a consumer do in situations like this?

    P.S.S. How can I remove EVERYTHING associated with an unwanted program from my computer? (I tried removing AOL, but there still seem to be these remainder files - such as one on the HJT log.)
     

    Attached Files:

  2. pastorricky

    pastorricky Private E-2

    Two more questions, if i may ask them here.
    what is the Prefetch folder? Do i need it?
    Should I "fix" everything that CCleaner finds - registry, windows, applications?
    Thank you,
    Rick
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That detection is more than likely a false detection. The file name that Panda is finding in the installation program is the same as one associated with DollarRevenue! Just ignore this! If they respond to your email, they may also tell you that it is a false detection.

    Are you saying you no longer need AOL to be installed? Did you uninstall ALL of it from Add/Remove programs?

    You can use the below to remove the remaining AOL service!

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to AOL Connectivity Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    AOL ACS

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.
     
    Last edited: Jul 31, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need the Prefetch folder. Think of it like a cache that Windows uses to speed up loading of frequently used applications.

    NO!!!!! Do not fix everything using Ccleaner. Only use it like we specify in the READ ME. Do not fix Issues it indicates in your Registry.

    You should uninstall AdwareAlert if it is installed. If it is not installed, have HijackThis fix the below line:
    O4 - HKLM\..\Run: [adwarealert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot


    You don't really have any malware problems! What is your reason for posting?

    You do have other things to address but they are not malware! Like updating to the current Sun Java version.
     
  5. pastorricky

    pastorricky Private E-2

    Posted from Chaslang: You don't really have any malware problems! What is your reason for posting?

    Thank you very much for your help! I greatly appreciate it!
    After I installed RegCure and ran it (it came up with well over 900 invalid entries!), I ran another anti-spyware program that found two unidentified BHOs. This happened a second time after running RegCure. (At least, that is the sequence that I remember.) And, I discovered that there are at least two RegCure sites. One of them, which I used to purchase RegCure was titled McAfee-Security.com. However, McAfee is not, apparently, related to RegCure (McAfee has another registry cleaner advertised on their official site). The McAfee SiteAdvisor site said that RegCure was misleading folks by using the McAfee name. The use of McAfee's name really bothered me - and the apparent possible unkown BHO problem (which I'm really ignorant about what that means). Anyway, I just got suspicious. So, I requested a refund of the purchase price, and wanted to make sure that there were not any real "malware" issues on my computer. This is why I went through the processes outlined on Major Geeks. (Probably a little too much paranoia.)

    I am fairly new to Major Geeks, and want to learn more about computers - that is why I had other questions. Thank you for your help. I will try to look for better places for other questions that may come up. (Is there a different thread I should go to in order to find out more about the other issues mentioned in the logs I sent earlier?)

    Rick
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be better if you specifially gave me a log fro the program or told me which BHO (this is a Brower Helper Object). Just because it is unknown to the program, it does not mean it is bad. Many valid programs use BHOs and the antispyware programs do not necessarily know about all programs in the world. Especially since new ones come out each day.

    McAfee-Security.com says the below on their site:
    They are not owned by McAfee but they imply they are affiliated with McAfee. This may of may not be true. McAfee should be able to tell you that. However either way RegCure is a product of Pareologic and has nothing to do with either McAfee or McAfee-Security. Never buy from a third party when you can buy from the 1st party. Especially a third party that seems to be falsely using McAfee's name to trick people.

    You can ask any malware or security related questions you like in this forum.

    Did you do the other things I requested? Uninstall AdwareAlert and fix the AOL service?

    As for your other issues I mentioned (and there is one minor malware issue from Dell) let's fix them.

    First look in Add/Remove programs for any of the below (or similar MyWay stuff) and uninstall if found:
    MyWaySA
    My Way Search Assistant
    MyWaySearchAsssistant


    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\MyWaySA <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.
     
  7. pastorricky

    pastorricky Private E-2

    chaslang,

    Thanks for all the great help! I have run through all the procedures that you outlined. When I booted in safe mode to delete the MyWaySA folder, it was not there.
    Here is the new HJT log. Should I do anything with backup folder that HJT created (with backups)?

    Thank you for the information about RegCure. (You do a very thorough job!) I was looking for a way to clean up the registry (obviously!) when I purchased it. However, I would like to follow Major Geeks' suggestions for cleaning up the reg (from the Must Have list of programs).
    (You also mentioned that I need to update Java, so I will do that, too.)

    Thank you,
    Rick

    p.s. after running a search on the C drive, I found several more AOL "things" - is it okay to simply delete them? (I would like to get rid of things that aren't serving any purpose.)
    C:\Documents and Settings\All Users\Application Data\AOL (a folder)
    C:\Documents and Settings\All Users\Application Data\Viewpoint Experience Technology\UserShell\AOL9 (a folder)
    C:\Documents and Settings\All Users\Application Data\Viewpoint Experience Technology\UserShell\AOL9Plus (a folder)
    My Computer\AOL1.JPG
    My Computer\AOLFINI.GIF
    My Computer\AOLOBE.ISP
    C:\I386\AOL1.JPG
    C:\I386\AOLDial.dll
    C:\I386\AOLFINI.GIF
    C:\I386\AOLFINI.JPG
    C:\I386\AOLOBE.ISP
    C:\WINDOWS\SYSTEM32\AOLDIAL.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\New Components\AOLArt.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\New Components\AOLShell.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\New Components\AOLUsersShell.dll
    C:\WINDOWS\SYSTEM32\OOBE\SETUP\AOLOBE.ISP
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Leave the Backup files for a week or so and then delete them when you are sure you will no longer need them. (Just a safety net!)

    For the AOL stuff, only delete the following (some of the other stuff was integrated into your system by Dell.

    C:\Documents and Settings\All Users\Application Data\AOL <--- the whole folder
    C:\Documents and Settings\All Users\Application Data\Viewpoint Experience Technology <--- the whole folder
    My Computer\AOL1.JPG
    My Computer\AOLFINI.GIF
    My Computer\AOLOBE.ISP
    C:\WINDOWS\SYSTEM32\AOLDIAL.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology <--- the whole folder
    C:\WINDOWS\SYSTEM32\OOBE\SETUP\AOLOBE.ISP


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. pastorricky

    pastorricky Private E-2

    chaslang,

    Thanks for all your help! I've now completed all that you suggested and will follow the protection from malware link you gave.
    I am really impressed with this site and will recommend it to my friends!

    Rick
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds