Problem with Wireless connection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Davidmouche, Feb 17, 2007.

  1. Davidmouche

    Davidmouche Private E-2

    Hi

    I have had some problems with my wireless internet connection (IntelPro wireless and Windows wireless manager) so I carried out the Malware removal procedure.

    Here are my logfiles. Thank you for having a look at it.

    David
     

    Attached Files:

  2. Davidmouche

    Davidmouche Private E-2

    More logfiles
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I tend to doubt your problems with your wireless connection are related to malware. Let's fix what I do see though.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.811.com/saecs.html
    O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now locate the below folder and delete it if found:
    C:\Program Files\Common Files\NSIS

    Now locate the below file and delete it if found:
    C:\WINDOWS\system32\1164358768.exe

    Now run Ccleaner.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  4. Davidmouche

    Davidmouche Private E-2

    Hi

    Thanks for your help. After I have some other Wifi/XP related failing connection issues, Malware does not seem to be problem as you pointed out.

    Still here are the logs...

    Following the paths, I could not locate
    C:\Program Files\Common Files\NSIS
    and
    C:\WINDOWS\system32\1164358768.exe

    The rest went fine.

    Cheers

    David
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The C:\WINDOWS\system32\1164358768.exe file was in your last log from ShowNew. Double check a new log from ShowNew yourself, do you see the file listed. Check you previous log first so you will see what I mean and where it was located.
     
  6. Davidmouche

    Davidmouche Private E-2

    Thanks chaslang. Using Explorer I could not see the file but a "search for files" revealed it.
    Now deleted.

    I did the same search for NSIS and a zip file showed up in Spybot. I have deleted that too but I wonder about this one.

    nsis.xmd (in C:\WINDOWS\BDOSCAN8\plugins)

    Should I delete that one too ?

    All the best

    David
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is from Bitdefender OnlineScan.
     
  8. Davidmouche

    Davidmouche Private E-2

    Understood. ;)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds