Results from scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by kc5uyr, Jul 22, 2007.

  1. kc5uyr

    kc5uyr Private E-2

    Attached are the log files from the scans that were run from the run me first pages. Appreciate your help.

    Thanks
    David
     

    Attached Files:

  2. kc5uyr

    kc5uyr Private E-2

    Here ars the rest of the logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please explain what malware problems you are having. This should always be part of a request for help.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Uninstall the below software:
    Java(TM) SE Runtime Environment 6 Update 1
    Sunbelt CounterSpy <-- we are finished with this trial program now
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Now Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp.coupons.com/r3302/Coupons.cab

    After clicking Fix, exit HJT.

    Now delete the below file if found:
    c:\windows\ss3unstl.exe

    Also delete the below folder if found:
    c:\windows\180Solutions

    Now let's fix a PurityScan infection you have.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. and don't forget to attach the ComboFix log
    Make sure you tell me how things are working now!
     
  4. kc5uyr

    kc5uyr Private E-2

    Hello Chaslang:

    Thanks for your assistance in this. Had problem with pop-up's from Outerinfo.
    AOL's Spyblocker also detected Purityscan. I don't like AOL, but wife likes to use it.

    Ran the program to uninstall Window's Messenger.
    Uninstalled the three software program's you had listed. Sorry I missed the Viewpoint Media Player :eek::eek:
    Ran HJT, fixed the 4 items you had listed.
    Deleted c:\windows\ss3unstl.exe.
    Deleted c:\windows\180Solutions
    Ran Combofix

    Will attach logs.

    Thanks
    David
     

    Attached Files:

  5. kc5uyr

    kc5uyr Private E-2

    One other logfile

    Had no problems with programs.
     

    Attached Files:

    Last edited: Jul 23, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to tell me how things are working now.

    Your logs are clean. You just need to delete the below left over folder from CounterSpy being uninstalled.

    C:\Documents and Settings\Owner\Application Data\Sunbelt Software


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  7. kc5uyr

    kc5uyr Private E-2

     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds