Question - about advice given for same problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shewolf, Feb 5, 2007.

  1. shewolf

    shewolf Specialist

    I know that before we make a post of a problem we are having regardless if its Malware of if its in something else with another forum at MG we are to do a search to see if that problem is already covered.

    Well I have a question... if we are having the same exact problem as to what you have helped someone else with do we follow those steps? If so do we post results as well or just follow the steps given?

    More specifically recently Chas helped someone with System Doctor Spyware and my friend is having the same issues. She gets an IE pop-up for System Doctor and in the help that Chas gave it is a 2 step process and said for that person to post a log after Step 1 before continuing on to step 2 so if someone is having the exact same problem do they start their own post and post the log from step 1 as well as the other logs that are necessary for posting from Read Me First?

    Just curious as to how its best to handle things like this.. I know that you guys are extremely busy and that for some reason Spyware/Malware is at a High Peak.. (grrrr)..

    Thanks..
    Darla
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are sure that the user has the exact same problem, yes you can begin with those steps and attach the logs here, but you will notice that at the end it still recommends doing the READ & RUN ME no matter what the outcome is.
     
  3. shewolf

    shewolf Specialist

    getting rid of system doctor spyware on friends computer

    I am in the process of getting rid of System Doctor from a friends computer and am posting the logs as I go.. Following the SmitfraudFix step by step posting the first step log.. will do step 2 and then read me first.. and post those logs..

    Hopefully this will help her computer as she is paying for DSL but it has become so slow that its like she is on Dial-Up. I do know she is infected with the System Doctor spyware because she gets the pop up for that.. just like the guy was getting in thread System Doctor spyware

    Once all steps are done and complete I would appreciate any feedback to make sure that this computer is clean..

    Thanks,
    Darla
    ps.. her computer infomartion is XP SP1 (once I get rid of the spyware I will be doing all the updates on her computer including going to SP2). Want to get rid of the spyware first because its sooo slow that it takes forever to download something or install something.
     

    Attached Files:

  4. shewolf

    shewolf Specialist

    Re: getting rid of system doctor spyware on friends computer

    2nd part of SmitfraudFix (step 2) log

    will work thru Read Me First and post those logs as I go..
    thanks...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: getting rid of system doctor spyware on friends computer

    You did not attach anything!
     
  6. shewolf

    shewolf Specialist

    sorry about that..here is the 2nd step log file..

    thanks..
    Darla
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay continue on to the READ & RUN ME and attach all 6 requested logs. It does not appear that SmitFraudFix is fixing anything.
     
  8. shewolf

    shewolf Specialist

    Ok I have finally completed all the scans..

    I realize that this doesn't and won't necessarily solve the problem of this computer being snail slow.. but before it became infected it was running at DSL speeds for internet and now its slower then dial up..
    Also, currently well after infection even start up is snail slow..

    Thanks for any help you can give me to help my friend out..

    Oh and sp2 is installed on the computer I didn't think it was..

    Darla
     

    Attached Files:

  9. shewolf

    shewolf Specialist

    2nd post of logs
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no sense in running CounterSpy unless you have it fix what it finds. Run it again and quarantine all the malware. Then attach a new log from CounterSpy.

    You are complaining about slow startup as well as normal operation being slow. Stop running junk like below (especially loading it multiple times). These are totally unnecessary. Read this: http://www.dslreports.com/faq/1247
    O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l

    Also you don't need to run Ccleaner at every startup! This slowing down boot up too.

    We will have HJT fix later on below.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger.

    You did not do step 2 of the READ ME at least not exactly as specified. Do it now!

    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [maillovetimecomp] C:\Documents and Settings\All Users\Application Data\delete software mail love\Window Enc.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKCU\..\Run: [Inside Amok] C:\DOCUME~1\Owner\APPLIC~1\AXISBA~1\Bolt stop mapi.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
    O4 - HKCU\..\Run: [DellSupport] "C:\PROGRA~1\DELLSU~1\DSAgnt.exe" /startup
    O16 - DPF: {F80B9305-A013-11D2-BD23-00A024978908} (Accurad Image Control) - file://D:\viewer\accuradimage.cab

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\All Users\Application Data\delete software mail love\Window Enc.exe
    C:\Documents and Settings\Owner\Application Data\Axisbaitaim\Bolt stop mapi.exe
    C:\WINDOWS\Downloaded Program Files\CONFLICT.2\Install.inf
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Documents and Settings\Owner\Application Data\Axisbaitaim
    C:\Documents and Settings\Owner\Application Data\Warez
    C:\Documents and Settings\All Users\Application Data\delete software mail love

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. shewolf

    shewolf Specialist

    I am sorry I thought I did quarantine it came up not disinfected and that nothing was put into quarantine. I will run again and see if it allows me to quarantine anything the 2nd time around.

    I did look in the Windows folder and Show Hidden Files and Folders was marked and there was no blue screen for me to click to show folders it showed files/folders.

    I will re run CounterSpy and go back over Step 2 of READ ME and then do the rest of the things you have listed & follow them. This is NOT my computer and will go over to her house soon as she tells me that it is convenient for her and then post the new logs you have requested.

    Thanks for the help..
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are multiple steps to do there! You must do each of them! Basicly it what you must do is show hidden files and folders, show system files, and show extensions.
     
  13. shewolf

    shewolf Specialist

    Maybe I am missing something in Counter Spy but I ran it for the 2nd time once the scan is done it gives me a pop up to view results. I can not find anything to let me quarantine the items found during scan.

    I ran in safemode both times should I run in normal boot mode and see if I can get a quarantine option?

    Also, please let me know when I can (if I can) uninstall Counter Spy.

    I will run the rest of the things in your instructions and then post back etc.. .

    Darla
     
  14. shewolf

    shewolf Specialist

    Finished running all the steps and everything went good.

    Regarding step 2 from READ ME I did have everything checked/unchecked as specified but I think that when I went to use the scroll I accidentially rechecked the Hide Protected operating system files. Everything is NOW checked/unchecked per Step 2 instructions. Sorry about that before..

    I did make a post earlier this morning regarding Counter Spy. Counter Spy is giving me problems.. I can't find anything to show to quarantine the items found. So, since I am at a friend's house working on her computer and it is hard for me to come back whenever I am going to go ahead and run that AVG anti spyware.. and post that log here..

    I did re run a new HJT log after fixing I am attaching 4 logs 2 HJT (before fix and after fix) and the new GetRun and ShowNew.

    Darla
     

    Attached Files:

  15. shewolf

    shewolf Specialist

    2nd post for updated log files requested

    Also, there are several items in start up that really don't need to be there.. like HP products (hphupd,hpztsb09, etc), igfxtray, wrk detect, still have BCMSMMSG (dunno what that is for sure).. Can I remove these things via HJT to keep them from starting up or is there a special procedure other then unchecking the box?
     

    Attached Files:

  16. shewolf

    shewolf Specialist

    here is the AVG anti_Spyware log file.. I was able to do quarantine with this program but not with Counter Spy.

    Also, when I ran AVG Anti-Spyware it detected 105 problems why did this detect more then Counter Spy??

    Thanks,
    Darla
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps the trial period for CounterSpy has already expired on this PC. Maybe it was even used in the past. Don't worry about it! We will remove them manually.

    Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now and since it does not work for you anyway! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying you are not using any HP products like a printer,scanner...etc? If so, then uninstall the software from Add/Remove programs. Just be aware that if you have the hardware and uninstall the software certain features may not work (or you may not be able to use it at all). This is not a malware forum topic. I see the below:
    hp instant support
    HP Memories Disc
    HP Software Update


    Here is some info on these:


    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe <--- Gives quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel You can fix this if desired with HJT.
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe <-- BCM voicemodem driver. Required for dial-up if you have one of these modems
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe <-- Checks for updates to MS Works. You can always do this manually, thus you can fix this with HJT.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Basically this is creative counting. They only found one problem named Starware and by simply deleting the folder, all of it would be gone. The question is why didn't AVG find all the things that CounterSpy found since they were never fixed. ;)

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below files and delete it if found:
    C:\Documents and Settings\Owner\My Documents\HiddenAudibles 1.0.exe
    c:\program files\moviepass terms.html
    c:\documents and settings\owner\desktop\moviepass terms.lnk
    c:\documents and settings\owner\desktop\moviepass.url
    c:\documents and settings\owner\desktop\movieland.url

    Now locate the below folder and delete it if found:
    C:\Documents and Settings\Anthony Knop\Application Data\Starware
    c:\program files\moviepass

    How is everything working? Your logs are clean.
     
  20. shewolf

    shewolf Specialist

    So far things are really going better, she is not getting the pop-ups like she was getting.

    I will remove the stuff per your recent posting directions and I will get back to you in a few days to let you know how things are going. As in the past she could go a day without pop-ups and I want to give her time to see how it goes.

    As for speed it is better, still slow on start up (faster in Selective Start-up Mode) but I think that is because there are soooo many things starting up when in Normal Boot Mode. I sat down last night and googled everything in her start up and figured out which ones we can and can't un-check. What I would like to know is if there is a way to remove the ones we can un-check for good? I realize this isn't for the Malware forum so will search the other forums for an answer or if you have the link to where that answer is at in MG can you post it for me please?

    Sorry this is so long winded thank you for your time and help and again I will get back to you in a few days with how things are running.

    Darla

    ps. I do have one question if a person leaves there computer on 24/7 is that good or bad? I feel as though computers need to be turned off on a regular basis to allow them to "re-generate" themselves (probably wrong choice of words but.. ). She does not turn the computer off and was wondering if when the computer goes into sleep mode or hibernate mode if its the same as turning it off? If she does need to shut down the computer how do I explain it to her so she can understand the reason? She is not computer literate.. Thanks..
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • First, if you don't need the program, uninstall it.
    • Second, if the program gives you the ability thru settings not to load at startup, then use that method next.
    • Third, if there is an O4 line showing for it in HJT, fix it with HJT which removes it from the registry so it will not load at startup. If you make a mistake or change your mind later, you can always restore from HJT's backups.
    There are many viewpoints on this. I'll try to write this in non-technical terms. I personally think it is better to shutdown the PC completely when not in use. Leaving it on long term can lead to large amounts of temporary files and other clutter which can slow down performance. It can also lead to some applications failing or causing errors due to the potential problems caused by another application that may not have even been run for a day or two. Many programs do not due a good job cleaning up after themselves when exited and this can result in what is referred to as a memory leak. This could eventual cause problems with various other programs running properly. Shutting down (which is also a reboot) clears this up. Is she really truly using full hibernate mode? Many people eventually run into problems with sleep and hibernate not working properly form them. That does not mean she will have a problem.

    Perhaps when you get her startup to be faster, she will not be so reluctant to shutting down. ;)
     
  22. shewolf

    shewolf Specialist

    Her computer is working a lot better now, she no longer gets the IE pop-ups, computer runs much faster, and she also has taken to shutting it down/off at night.

    Thanks for all the help..
    Darla

    have one question about malware and files..

    In the course of cleaning up her computer I found a folder it is C:\RECYCLER it lists a few files with like a recycle icon and the files begin with the letter S I also have this on my computer and was wondering where this folder came from and if it is safe to just delete the contents of that folder? It has nothing to do with the Recycle Bin as the Recycle Bin is empty but the files in the RECYCLER folder contain content thanks
     
    Last edited: Feb 14, 2007
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! RECYCLER is the name of the Recycle Bin folder. After doing step 2 of the READ ME, it is no longer hidden, so now you see it when you did not see it before.

    If you are not having any other malware problems, it is time to do our final steps (make sure your friend reads the How to protect thread too! )
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds