ran read and run me first but still having problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by cuchulain64, Oct 29, 2008.

  1. cuchulain64

    cuchulain64 Private E-2

    I have run the read and run me first but had a few issues.

    I could not connect to internet with either IE or firefox so had to download updates and install them separately.

    Attached log files

    Still can't get online. I can ping other machines on network but can't get outside.

    please advise
     

    Attached Files:

  2. cuchulain64

    cuchulain64 Private E-2

    mgtools log
     

    Attached Files:

  3. cuchulain64

    cuchulain64 Private E-2

    please help this is my work pc infected as i tried to clean pc for friend so i started a new thread for multiple pc's.

    I am not trying to speed up response to first pc as it is slowly working through solutions thanks to Timw.

    I know this is a bump but i can't help it
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Although I have a few things for you to do, your logs are pretty clean. So this may just be a network setup issue. Try the below:
    • Go into Control Panel -->Network Connections.
    • Right click on your connection
    • and click Properties.
    • On the Properties page, highlight Internet Protocol(TCP/IP)
    • Click Properties. This will bring up another page.
    • Select Obtain DNS Server Automatically.
    • Click the ok button. The page will close.
    • Press ok on the page in front of you.
    • Restart the computer.
    • Reconnect to the Internet using Internet Explorer.
    Any change? If not, try running this: XP TCP/IP Repair


    Do you know what the below files are for?
    Code:
    2008-09-09 15:07 530,822 ----a-w C:\WINDOWS\java\Packages\Y8VFFNPZ.ZIP
    2008-09-01 13:07 0 ----a-w C:\Documents and Settings\colmo'brien\test.dat
    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. cuchulain64

    cuchulain64 Private E-2

    Yes it was a DNS Issue working fine now. browsing ok.

    No I have no Idea what they are

    I use AIM will this not re-install as soon as i start Aim again.? I missed that line first time but have un-installed now.

    Fixme.reg merged successfully

    Everything seems fine now I have attached the mglogs.zip
    but when i try to attach combofix it say's i have already attached this file in earlier post. I didn't re-run combofix should I Have?

    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete those two files that you said you were unfamiliar with.

    Yes the Viewpoint software will be reinstalled anytime any AOL software is updated. This software should be uninstalled each time they install it. They should not be installing this unnecessary junk.

    You're logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds