Not sure what to do!

Discussion in 'Malware Help (A Specialist Will Reply)' started by LabLady, Aug 10, 2006.

  1. LabLady

    LabLady Private E-2

    Okay, I admit - I'm a wimp! You've got me scared! I have tried logging on using two User Names that I have used before. I could get logged on, but could not post, or use some of the options. My other choice was to register as a totally "new" person so I could at least post here and ask for some advice!

    I am having trouble with my work computer. It was running great until my boss' grandson was allowed to use the internet. It started running slowly, and I was getting some funky error messages. So, I went in and cleaned up what I could find of his "leftovers". Lots of bad websites, etc.

    Before you rag on me about following the rules here, I HAVE done that! I went to the "New? Start Here" page and followed the download suggestions. I used some of those to help clean up my computer. I have also read the "Read and Run Me First" page and did all that, EXCEPT for Step 4. I could not access the GetRunKey or the ShowNew pages. I may be able to do that now, since re-registering.

    Also, when following the "Disable And Enable System Restore" when I did the disable, my computer got hung up. I waited and waited, and finally clicked Control-Alt-Delete, getting a "Not Responding" message. Duh! LOL So, what do I do about that?

    Before I try posting a HiJack log (according to the rules), is there something else I should try? I'm going to try continuing with all the "Read And Run Me First" things, but do you think I need to? When I ran some of the suggested downloads, I didn't get much except for the two that had to be paid for in order to delete the bad files. Both found about 126 files that are "bad". My employer will not let me pay for more "stuff" this month. The other scans I have done have found nothing. My computer, however, is still running sluggishly, and I'm getting those blasted hang-ups, not respondings, etc.

    Suggestions????
     
  2. LabLady

    LabLady Private E-2

    Okay, I got into the GetRunKey file, downloaded it and followed the instructions up to "Upload the runkeys.txt file here as an attachment". What does that mean, please? Do I post it to this forum?
     
  3. matt.chugg

    matt.chugg MajorGeek

    when you make a post there is a paperclip button which you can use to attach the files. Attach the runkeys, shownew and hjt logs to your next post and then make another post and attach your activscan and bitdefender logs.

    You will need the 2 posts as you can only attach 3 files per message
     
  4. LabLady

    LabLady Private E-2

    Thanks! So, you don't think I need to do anything else at this point, just do the scans and post them here? I will do that shortly. Thank you for the help! I'm getting pretty frustrated with this computer. Wouldn't be so bad, but I'm the bookkeeper, and I need to have access to the financials.
     
  5. matt.chugg

    matt.chugg MajorGeek

    Running the scans will probably clear up some problems, but some may need manual removal. by running these scans you can remove the easy stuff and then once I have seen the logs I (or one of the other people who work on this forum) can help you with a fix for the more stubborn infections.
     
  6. LabLady

    LabLady Private E-2

    I'm still somewhat confused. The CCleaner is one that is asking for payment before doing a cleanup. I have run it, but do not see where there is a way to save the file. Do I just copy it and paste it to a Word doc.??? Sorry for the confusion. I'm just trying to make sure that I'm doing all I need to before posting a log here.

    I have got the GetRunKey and ShowNew logs. Should I post them now or wait?
     
  7. LabLady

    LabLady Private E-2

    HiJack Log

    Here is my Hijack This log:
     

    Attached Files:

  8. LabLady

    LabLady Private E-2

    GetRunKey & ShowNew logs

    Here are the GetRunKey & ShowNew logs:
     

    Attached Files:

  9. LabLady

    LabLady Private E-2

    Whew! Got some help from a friend with CCleaner. I ran it and deleted a bunch of stuff. Should I re-run the HiJack This, ShowNew, and RunKeys?
     
  10. matt.chugg

    matt.chugg MajorGeek

    Yes please sorry for the slow response, Please be patient and I will help you as soon as I can.
     
  11. LabLady

    LabLady Private E-2

    No problem.

    I know you all are BUSY!

    Here are my new files. Today, for some reason, I could not get in to Safe Mode, so ran them in Windows.
     

    Attached Files:

  12. LabLady

    LabLady Private E-2

    Won't let me attach the new RunKey log, so I copied and pasted it.

    Edit: Attached log
     

    Attached Files:

    Last edited by a moderator: Aug 11, 2006
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Our READ & RUN ME does not ask you to run The Cleaner. We ask you to download and run CCleaner which is a totally free drive cleaner not a malware cleaning tool. In addition we do not ask for a log from CCleaner nor do we want or need one.

    We do however need the online scans to be run in step 6 and we need the logs from them.

    Also note that you were NOT suppose to disable system restore yet. It tells you that about 3 times.

    You need to follow ALL of the directions in the READ & RUN ME.
    • you did not run any of step 6. Run those two online scanners and attach the two requested logs
    • you are using MSconfig to control startups which we specifically request that you not do. This is covered in step 7 of the READ ME. We will take care of this in the registry patch I will give below which will also remove some hidden malware along with some other unnecessary items.
    • also you did not follow the directions in step 7 for installing HijackThis and renaming the executable file. Thus you installed it exactly where we specify not to install it and have it name incorrectly which will allow certain forms of malware to hide from a scan. Please install and rename HijackThis as requested.
    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below file (delete it after booting in safe mode if it will not delete in normal mode):
    C:\windows\firewall_anti.exe



    Who is downloading (and why) the below huge files? And why are the being saved into the root folder of your boot drive. This is a bad idea.
    bingo.qbw Aug 8 2006 25972736 "BINGO.QBW"
    bingoq~1.nd Aug 8 2006 315 "BINGO.QBW.ND"
    bingoq~1.tlg Aug 8 2006 720896 "BINGO.QBW.TLG"
    debughlp.exe Jul 13 2006 79512 "DebugHlp.exe" <--- do you know what this is
    northi~1.nd Aug 11 2006 337 "North Iowa Fair Association.QBW.ND"
    northi~1.tlg Aug 11 2006 196608 "North Iowa Fair Association.QBW.TLG"
    northi~2.qbw Aug 11 2006 105451520 "North Iowa Fair Association.QBW"
     
    Last edited: Aug 12, 2006
  14. LabLady

    LabLady Private E-2

    Yeah, this is why I hesitate to ask for help here. Sorry. I know I'm not "geeky" enough, but I came here as a last resort to TRY to get my computer fixed without having to spend $60.00+ an hour of money we do not have.

    That said, this is taken from the sticky post above, "Read and Run Me":

    "4: Downloading Tools

    Download the following tools and save in your favorite download folder or create one, for example C:\Spyware Tools or C:\Downloads. ( It is not a good idea to download them to any folder within C:\Documents and Settings.) And then install, update, and configure as indicated below. Do not run the scans until later when indicated. Also DO NOT confuse the word download with the actual installation of the program. You should install all programs to their recommended (by the install program). default installation folders. First you download the files and then you install (if the program requires it) the program.

    CCleaner.............Install only, then exit. We will run tools later. MAKE SURE you uncheck the option to install the Yahoo Toolbar when installing CCleaner. We do not want ot install any unnecessary baggage. It will install by default unless unchecked.

    Also it is recommeded to login to any other User Accounts on the PC and run CCleaner on each on. This can reduce scan time and logs from the later scanning you will do below. This can be done in either safe mode or in normal boot mode since some user accounts will not be visible in safe mode."

    Okay, so before I did post my question/problem here, I thought I would first follow all the steps you had listed in the "Read and Run Me" and try fixing my computer without posting here and being made to feel like a low-life. I also think you misread my post. I said, "The CCleaner is one that is asking for payment before doing a cleanup."

    When I first tried to run CCleaner, it DID ask me for a payment before it would clean the files. I deleted CCleaner, then re-installed it.

    And, please note that I did ask if there was something else I should do before posting here. I probably misunderstood MattChug when he said to attach the runkeys and shownew files, then attach activscan and bitdefender logs. I DID post the runkeys and shownew files, but ran out of time at work and did not get a chance to post the activscan and bitdefender logs. SORRY!

    As to the system restore thing, your directions are a bit confusing in this area. I had disabled system restore, then re-read the directions and re-enabled it. Again, I'm SORRY for being a dolt.

    I am not using msconfig to control startups. I touch msconfig as a last resort because I'm still not all that comfortable making those kinds of changes to my computer. Please understand that even though this is "my" computer at work, the boss lets anybody and everybody use it. I have very little control over what happens in the office, and even less control in what happens there when I'm not there. I TRY to be protective of my computer, but the boss is the boss and I need my job! Again, SORRY!

    As to the huge files... The QBW files are Quickbooks files. That is the program I use for our financials. I do not know why they are being saved to the root folders of the boot drive as I did not set the program up. I do know that after the grandson had been on my computer, the way I back up QB has changed. I did not make that change, and I have had TWO people (both techs) in to fix the problem. QB is suppose to back up to DISK, and it does, but it is also doing something that I cannot right. That is another reason I resorted to asking for help here. I cannot afford to have the financial files messed with.

    So, as I am posting this from my home computer, I will try HARDER tomorrow to follow ALL the steps (even though they can be a bit confusing) before I ask for help here again. I don't get a lot of free time at work to do all this, nor, as I have stated several times before, do we have the money to hire someone at $60.00+ per hour to fix this. That's part of the reason this is slow going for me. I'm trying to save us money, but I guess you think I shouldn't even use a computer.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read this link: CCleaner Slim (No Yahoo Toolbar, English)

    CCleaner is a totally free application and does not require any payment. It always works for free. There are many other Disk Cleaning programs and some could even have similar names but CCleaner is Freeware. When you put "The" in front of CCleaner, I assumed you meant The Cleaner which is not free and is a malware cleaning tool which is not on out list of tools to use.

    It is a rather hard to make it any clearer than telling you in bold print three times that you do not disable it yet. We also start this step by saying read all of it first.
    Yes you were and it shows in the runkeys.txt log that you were set for Selective Startup and not Normal Startup. That is what the below registry key tells us:
    Whoever is saving them to that location should be told to stop. This is a dangeous location to save anything that contains critical information.

    You can work at whatever pace you want to work at, but faster is always better in malware situations. If you wait too long inbetween steps, it can make steps you already ran become a waste of time. Some malware can reinfect you immediately upon reboot or shutdown. Some malware can download dozens of other malware components. So if you remove a bunch but did not get the root source yet, and then wait a couple days to finish off other steps......well you could just be totally reinfected again. We don't mind working with people who are novices and we do understand that it can be frustrating and difficult for them; however, since we cannot fix it for you, we need all of our steps to be run so that we can collect all the correct information to work up proper fixes to be applied to the PC. Much like getting a physical at the doctors office. ;) After all the lab results are back we can make a better diagnosis.
     
    Last edited: Aug 17, 2006
  16. LabLady

    LabLady Private E-2

    Thanks for the reply. Guess I'll just have to have our tech come pick up my computer over the weekend.

    Any changes made to this computer have been done by somebody else (my work computer is NOT my own, and the boss lets anybody and everybody use my and my co-worker's computers, much to our dismay). So, if our board complains because we are spending too much money on computer maint., then the boss will have to account for it. 'Course, she won't tell them the truth - that anybody can use our computers and infect them with what ever is out there...

    Thanks again, and I'll try not to be a bother any more.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's up to you how you want to handle this. We can help you fix your problems for free or you can send it to a tech and get it fix which often times results in an incomplete fix. The majority of people who are supposedly computer techs know very little about malware. However, your PC really did not show very much in the way of malware and that was why I asked for the logs from the two online scanners.

    Did you do ALL of what was requested in message # 13. If not, you should complete all of those instructions and then attach a new GetRunKey log and a new HJT log.
     
    Last edited: Aug 17, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds