ran all steps in ''READ & RUN ME FIRST" now need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by nahmad, Jun 6, 2009.

  1. nahmad

    nahmad Private E-2

    On 6-2-09, I was trying to check connectivity and picture quality on my new purchased LCD TV with Toshiba Lap top (Satellite-2405-S201). I visited the following sites using Internet Explorer:


    As soon I disconnected the laptop from the TV, I started getting three pop up messages (Antivirus System Pro Alert, Widow Security Alert and Spyware Alert) from an icon created in my system tray. These messages wanted me to purchase Antivirus System Pro Alert software and clean my computer. Even after I disconnected the internet these messages kept on popping.

    I ran full scan with Symantec antivirus and it quarantined the following files:
    1- urqpo.dll.bad (C:\VundoFix Backups\)-Trojan.Vundo
    2-winrpo32.dll.bad (C:\VundoFix Backups\)-Trojan.Nebuler
    3-destrub[1].js (C:\Documents and Settings\nahmad\Local Settings\Temporary Internet Files\Content.IE5\NGVBEDR9\)-JS.Downloader

    Symantec was able to partial clean (1)-it is still in quarantine; completely cleaned (2) and (3) I deleted.

    Then I ran the steps in” READ & RUN ME FIRST”. I must commend Major Attitude of MajorGeeks.com for writing such good instructions ( I consider myself a novice in this area, but I was able to complete the total process without any difficulty).
    My connection to Internet Explorer is not working, I followed your instructions to repair but it is still not working. Mozilla Firefox is working fine.

    Logs are attached. Please let me know what I need to do next.

    Thanks for your help.
    nahmad
     

    Attached Files:

    Last edited by a moderator: Jun 8, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need much more RAM in this system:
    Total Physical Memory 256.00 MB
    Available Physical Memory 39.05 MB

    I'm surprised you can run what you have installed!

    Let's just do this:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please reboot your system.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. nahmad

    nahmad Private E-2

    Dear Tim W,

    Thanks for responding to my post.

    I am unsuccessful in removing J2SE Runtime Environment 5.0 Update 6

    I followed the following procedure while internet connection was on:
    Control Panel-->Add or Remove Programs--> J2SE Runtime Environment 5.0 Update 6
    -->Are you sure you want to remove J2SE Runtime Environment 5.0 Update 6--> ok-->
    Window Installer- Preparing to remove--> J2SE Runtime Environment 5.0 Update 6- You Already have this version of JRE installed. Please uninstall the product through add/remove utility (This is exactly I was doing) before reinstalling.
    Presses O.K.
    Please wait while window configure J2SE Runtime Environment 5.0 Update 6-->
    Add/Remove program--> Fatal Error during installation

    Then I disconnected the internet connection and tried the Add/Remove program with the following result:
    1-Preparing to remove
    2- Window Installer-The feature you are trying to use is on network resource that is unavailable

    Click OK to try again (I tried it does not work), or enter an alternate path to a folder containing the installation package ‘jre1.5.0_06-iftw-msi’ in the box below.

    Use Source: http://javadl.sun.com/webapps/download/GetFile/1.5.0_06-b05/windows-j586//

    I tried to use the above link but I got ‘Not Found’ message

    I searched for file jre1.5.0_06-iftw-msi ----None found

    I can find the folder ‘jre1.5.0_06’ but it does not contain file ‘jre1.5.0_06-iftw-msi’

    I am at a loss and I need further guidance to remove J2SE Runtime Environment 5.0 Update 6

    Thanks
    nahmad
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use this tool:
    Java Removal.

    Then continue with the instructions and attach the new log.
     
  5. nahmad

    nahmad Private E-2

    Dear Tim W:

    Thanks a lot. With your guidance, I was able to remove J2SE Runtime Environment 5.0 Update 6.

    Then, I followed your instructions and I was able to perform all the tasks without any problems. MGlog.zip is attached.

    The lap top is running OK except Internet Explorer is still not working. Also, I will try to add more RAMs after done with the clean up.

    Looking forward for further instructions.

    Thanks, nahmad
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still need to clean out this folder:
    C:\Documents and Settings\nahmad\Local Settings\temp\

    As to IE, exactly what do you mean by it is not working. Please explain exactly what happens.

    This may be something you will need to address in the software forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds