Registry CURRENT_USER corrupted ? ..or is it ?

Discussion in 'Malware Help (A Specialist Will Reply)' started by tones_ie, Jul 5, 2008.

  1. tones_ie

    tones_ie Private E-2

    Attached Files:

  2. tones_ie

    tones_ie Private E-2

    last log...superantispyware
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what all of those strange registry keys are from, but it does not appear to be due to any remaining malware. I would not worry about them since you say the PC is running fine. Your logs are clean, but I have some minor cleaning for you to do. Perhaps those entries are related to all the games some one is playing. I see loads of games and online games. Examples:
    Code:
    2008-07-05 04:09 --------- d-----w C:\Program Files\iWin.com
    2008-07-05 04:09 --------- d-----w C:\Program Files\iWin Games
    2008-06-25 04:32 --------- d-----w C:\Documents and Settings\Owner\Application Data\iWin
    2008-06-05 04:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpinTop Games
    2008-06-02 21:47 --------- d-----w C:\Documents and Settings\Owner\Application Data\Flood Light Games
    2008-06-02 21:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Flood Light Games
    2008-05-29 13:41 --------- d-----w C:\Program Files\Animal Agents
    2008-05-28 23:45 --------- d-----w C:\Program Files\The Hidden Object Show
    2008-05-28 03:47 --------- d-----w C:\Documents and Settings\Owner\Application Data\QSGames
    2008-05-28 03:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\QSGames
    2008-05-27 17:00 --------- d-----w C:\Documents and Settings\Owner\Application Data\SultansLabyrinth
    2008-05-27 16:59 --------- d-----w C:\Program Files\The Sultan's Labyrinth
    2008-05-27 04:08 --------- d-----w C:\Program Files\Caribbean Pirate Quest
    2008-05-21 05:16 --------- d-----w C:\Documents and Settings\Owner\Application Data\Gogii Games
    2008-05-21 05:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Gogii Games
    2008-05-20 09:01 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-05-20 05:10 --------- d-----w C:\Program Files\Games
    2008-05-20 03:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Astar Games
    2008-05-20 03:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\MythPeople
    2008-05-17 13:23 --------- d-----w C:\Documents and Settings\Owner\Application Data\Gaijin Ent
    2008-05-15 22:59 --------- d-----w C:\Documents and Settings\Owner\Application Data\EleFun Games
    2008-05-15 21:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kristanix Games
    2008-05-14 22:29 --------- d-----w C:\Program Files\IncrediGames
    2008-05-14 18:42 --------- d-----w C:\Documents and Settings\Owner\Application Data\MysteryStudio
    2008-05-14 04:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intenium
    2008-05-12 20:57 --------- d-----w C:\Documents and Settings\Owner\Application Data\Sudden Games
    2008-05-12 20:25 --------- d-----w C:\Documents and Settings\Owner\Application Data\Games


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  4. tones_ie

    tones_ie Private E-2

    Hi again,

    yea the pc belongs to a neighbor...all she uses it for is games and email...:) to each their own...lol Im kinda the guy they come to for help...i know a little but learning more and more every day hanging out here reading ure fixes to posts :)

    while i was waiting on a reply here...i ran an online scan with Kaspersky...below is the result....im gonna go and say their NOT a threat? if they are please let me know...i didnt action them as of posting.


    Code:
    KASPERSKY ONLINE SCANNER 7 REPORT
     Saturday, July 5, 2008
     Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
     Kaspersky Online Scanner 7 version: 7.0.25.0
     Program database last update: Saturday, July 05, 2008 19:24:44
     Records in database: 916362
    --------------------------------------------------------------------------------
    
    Scan settings:
    	Scan using the following database: extended
    	Scan archives: yes
    	Scan mail databases: yes
    
    Scan area - Folder:
    	C:\
    
    Scan statistics:
    	Files scanned: 106393
    	Threat name: 3
    	Infected objects: 1
    	Suspicious objects: 15
    	Duration of the scan: 01:40:39
    
    
    File name / Threat name / Threats count
    C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{E38B60C8-F3E6-41BF-A165-7E8BABF840C9}\Microsoft\Outlook Express\Sent Items.dbx	Suspicious: Trojan-Spy.HTML.Fraud.gen	4
    C:\My Games\Acropolis\Acropolis.exe	Suspicious: Type_Win32	1
    C:\My Games\Azkend\Azkend.exe	Suspicious: Type_Win32	1
    C:\My Games\Bliss Island\bliss.exe	Suspicious: Type_Win32	1
    C:\My Games\Bricks of Egypt 2\BricksOfEgypt2.exe	Suspicious: Type_Win32	1
    C:\My Games\Caveman Rock\CavemanRock_F.exe	Suspicious: Type_Win32	1
    C:\My Games\Dropheads\dropheads.exe	Suspicious: Type_Win32	1
    C:\My Games\eTaco\Taco.exe	Suspicious: Type_Win32	1
    C:\My Games\Flower Quest\FlowerQuest.exe	Suspicious: Type_Win32	1
    C:\My Games\Flying Leo\FlyingLeo.exe	Suspicious: Type_Win32	1
    C:\My Games\Granny in Paradise\granny_download.exe	Suspicious: Type_Win32	1
    C:\My Games\Ice Breaker\ice_breaker.exe	Suspicious: Type_Win32	1
    No errors adding reg fix or running uninstall of combfix.... :)

    Thanks again :)
     
  5. tones_ie

    tones_ie Private E-2

    Opps...in all the excitement, i forgot to ask...any idea why the trend micro folder always opens at startup?
    C:\Program Files\Trend Micro\Antivirus

    thats wat i started trying to fix...lol
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not threats. Just more junk due to excessive game playing. ;)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally this means a registry entry for the program is not setup properly. I would guess that the program is not properly installed. Since you last MGlogs.zip file was incomplete and we need it to look further into this, I will have to ask you to do the below and watch for error messages. Also make sure that you accept the license agreement from TrendMicro HijackThis if it pops up. Since it did not run last time I'm assuming that the license was not accepted by clicking on it twice as instructed in the Using MGtools link.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log:
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds