smanager.7.exe + "buffer overrun" on explorer.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by ihateregistering, Jun 3, 2007.

  1. ihateregistering

    ihateregistering Private E-2

    Before posting I decided to see if anyone else has experienced my problem, and closely followed the instructions chaslang gave tfelix until he was instructed to use explorer.exe. I'm aware of the many trojans I have atm, but I'm also half tempted to just wipe my computer clean and then put the files that I backed up on the computer. At the same time, I don't want to re-install everything, so unless you say that there is no way to save my explorer.exe from being overflowed, help would be greatly appreciated.

    Something that should be noted, yesterday I booted from my Gateway OS disc, without using the recovery system, so I have been able to see my start menu and my icons, as long as I don't hit 'OK' on the warning that tells me that explorer.exe should be terminated. I'm aware of how to run programs through the tax manager so that walk through can be skipped :).
     

    Attached Files:

  2. ihateregistering

    ihateregistering Private E-2

    Files cont.
     

    Attached Files:

  3. ihateregistering

    ihateregistering Private E-2

    Sorry for wasting your time with the explorer.exe question. I was being silly and didn't look in the other forums. (>.<) I'm going to attempt to copy the explorer.exe file from my sister's computer, but that doesn't really solve the rest of my malware issues.
     
  4. ihateregistering

    ihateregistering Private E-2

    I did a little bit more research, and I think I might have gotten rid of most of the issues. Vundo made my explorer.exe to work, but whenever I run Spybot - S&D, I keep getting the smitfraud c-888 toolbar, or something like that. But the smitREM found nothing.

    Pandascan incoming, but my computer was really slow on the upload.
     

    Attached Files:

  5. ihateregistering

    ihateregistering Private E-2

    pandascan
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay...

    Uninstall HJT then re-download and install it as directed in the Read and Run ....!!

    Use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\tezchiby.exe

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  7. ihateregistering

    ihateregistering Private E-2

    Here you go
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm sorry to seem to be so trite.....but the instructions are to download to its own folder and REMANE it to analyse .....why? Because alot of the newer malware "sees" the program working and hides.

    One more time ...and we may get it cleaned.
     
  9. ihateregistering

    ihateregistering Private E-2

    Sorry
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 7
    Counterspy

    Use windows explorer to find and delete:
    C:\Documents and Settings\Owner.YOUR-DC3E0B8F38\Application Data\F?nts---> this will probably appear as Fonts...check the creation date..May 31, 2007
    C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Attach new logs for:
    ShowNew
    GetRun
    HJT
     
  11. ihateregistering

    ihateregistering Private E-2

    I've done everything you said, but when I ran HJT to remove

    It wasn't there. The only thing that ran with (no file) was
    Would you like me to remove that one instead? Otherwise it doesn't seem like it exists. HJT is still named analyse.exe
     
    Last edited: Jun 5, 2007
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The registry fix took care of it....do not remove the other 02 line!

    Please attach the requested logs.
     
  13. ihateregistering

    ihateregistering Private E-2

    Here you go
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  15. ihateregistering

    ihateregistering Private E-2

    Thank you very much :)
     
  16. ihateregistering

    ihateregistering Private E-2

    One last thing, when you had me create the fixME.reg file, it created an ehthumbs.db on my desktop. Am I allowed to delete that?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes ......all logs and downloaded programs (esp. counterspy if you do not want to keep it till the trial runs out.)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds