Old problem, new log

Discussion in 'Malware Help (A Specialist Will Reply)' started by Troubleduser, Jan 29, 2008.

  1. Troubleduser

    Troubleduser Private E-2

    Hello ppl!

    I have exactly the same problem as Americzech posted on11-21-07, 00:41

    So here is the first SmitFraud report
     

    Attached Files:

  2. Troubleduser

    Troubleduser Private E-2

    and here´s the second one.
     

    Attached Files:

  3. Troubleduser

    Troubleduser Private E-2

    And.. that didnt go to well..
    Although I got back some use of my computer, there is still no way of getting to the control panel and I get the following message at safe startup;
    "Runtime error 217 at 027CE3EC"
    Should I proceed with the steps of "read & run.." that I actually can proceed with?

    Thx alot ppl, you are doing a great service to a lot of ppl. Have told all of my friends about your page.
     
  4. Troubleduser

    Troubleduser Private E-2

    Think I´m in the clear! Although I couldnt go through all the steps in the "Read & Run..", I got back so much control that I could re-install avast, and then take it step by step (babysteps..)!

    Thx again, just for existing! Wouldnt known where to go otherwise!
    /MS
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on what I saw in your logs from SmitFraudFix it is strongly recommended that you complete as much of the below as possible and attach the other logs that are requested.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  6. Troubleduser

    Troubleduser Private E-2

    Hello again!
    As you probably can tell, I was a bit premature in my celebrations..
    Problems still persisting even after the "Read & Run.."-troubleshooter.

    1. Avast picks up (and puts in quarantine) a trojan at every upstart, C:\Program\Common Files\Microsoft Shared\Speech\Wab64.dll

    2. Can´t seem to remove the old Java, Java(TM) 6 Update 3, manually from within the control panel. Something about transforming searchpath.. (cant really translate the swedish text to english that well, sry!)

    3. Combofix and Spybot ran well, but AVG refused to produce a report! Checked and doublechecked that the settings was in place, ran it twice, but it still wouldnt produce a report. AVG found a medium-threat trackingcookie named Tribalfusion, I "applied all actions" and it was deleted.

    4. MGTools got an errormessage "It couldn´t initiate the program correctly (0xc0000135). Click OK to finish the program."
    It didn´t seem similar to the errormessages mentioned in the "Using MGTools-guide".

    As an added "bonus" I ran Vundofix just to doublecheck and attached it´s log.

    Would be enormously grateful if someone could take a look at the logs and see if there is something to do or if I just should leave it.

    Thanks a million!
    /MS
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This error is occurring because you do not have the Microsoft .NET Framework software installed from Microsoft Update.

    First let's remove a bad service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Network Connection Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteNetCM into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now uninstall Viewpoint Manager (Remove Only) as requested in step 1 of the READ ME.

    Also uninstall Norton WMI Update since you do not have Norton installed anymore.



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_04\bin\jusched.exe"
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  8. Troubleduser

    Troubleduser Private E-2

    First of all, thx for all the help!
    Followed your instructions to the letter but..

    Norton refuses to uninstall. "Insert the Norton WMI Update" disk and press ok.
    Don´t have the disk..

    And I got the same message as mentioned before when I tried to run GetLogs.bat, "It couldn´t initiate the program correctly (0xc0000135). Click OK to finish the program."

    My PC seems to be working correctly, but I feel quite unsure if I really am completely virus free..

    /MS
     

    Attached Files:

  9. Troubleduser

    Troubleduser Private E-2

    Installed the .Net Framework and ran MGTools again. Got no error message.
    Attaching the log.

    /MS
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running this: Norton Removal Tool (SymNRT)

    Also see if the below program can uninstall Java(TM) 6 Update 3

    Your Uninstaller! 2008


    Your logs are not clean of malware.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  11. Troubleduser

    Troubleduser Private E-2

    Hello!
    Norton WMI and Java(TM) 6 Update 3 are now gone forever!

    But some confusion still lingers on..

    And yet I shall remove all my malware removers?

    And step 13 was hard to follow to the letter..

    Without a link..
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! Here is the link that was not in the previous message.

    How to Protect yourself from malware!

    This link should hopefully address any questions you have.
     
  13. Troubleduser

    Troubleduser Private E-2

    Ok, will work through the list!
    My system seems to work fine now and let me first say that Im eternally grateful to you people at MajorGeeks.com!
    You will from now be my first (and only) choice when downloading any program at all and I have already started to spread the word of your greatness and helpfulness to me.

    Keep up the great work!
    /MS Sweden
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Thanks for spreading the word. ;)

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds