Still Infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hamilton Dan, Oct 20, 2006.

  1. Hamilton Dan

    Hamilton Dan Private E-2

    hello, this is my first post here, hopfully i have followed everything right.
    I compleated all of the read me steps. many infections were found and cleaned, but im sure many more remain.
    Im now prity sure this is why my connection speed is down so low.
    here are my logs, with the rest of them in the next post.
    thanks in advance for any and all help.
     

    Attached Files:

  2. Hamilton Dan

    Hamilton Dan Private E-2

    rest of the logs..
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Note: You did not follow the directions for running ShowNew and GetRunKey. As a result your logs are incomplete and the below fix may also be incomplete. Please install them and run them as directed next time (at the end of this fix).

    Start by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Dan Chainey\My Documents\Downloads\anti spy\antispy16\activate_crack.exe
    C:\Documents and Settings\Dan Chainey\My Documents\Downloads\performance test\PerformanceTest.5.0.Build.1033_CRKEXE-FFF.zip
    C:\Documents and Settings\Dan Chainey\My Documents\Downloads\performance test\start.exe
    C:\WINDOWS\Downloaded Program Files\AdToolsX.dll
    C:\WINDOWS\Downloaded Program Files\WinCtlAdX.dll
    C:\WINDOWS\Downloaded Program Files\WinServAdX.dll
    C:\WINDOWS\Downloaded Program Files\WinTaskAdX.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew


    Make sure you tell me how things are working now!
     
  4. Hamilton Dan

    Hamilton Dan Private E-2

    Hey thanks for you resopnse.
    sorry for the error with the getrunkey and shownew.
    i had run all the scans last week and posted the results, i didnt seem to have ( or notice )the errors. my post last week was one that got deleted. so when i ran all the scans again yesterday i missed the part about the errors with the getrunkey and shownew. hopfully i have run every thing proparly now.

    i had no problems using the fixme.reg file
    and again , no problems using pillbox, also i did not get the message "PendingFileRenameOperations"

    i still seem to be running a little slow, ie downloading at very slow speeds like an average of 20-30 kb/sec, with a cable connection, i think that is far to slow. but i have been having some trouble with my cable provider. They have already come out once to boost my signal. so once i know my pc is clean of all maleware and spy ware, i can go back to them to see if the problem is there connection


    here are the requsted new logs.and thanks again for all the help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Just a couple more things to do. I had a couple typos in the registry patch so we need to repeat part of it.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Also you need to goto Add/Remove Programs and uninstall the below which was requested in step 0 of the READ ME.
    Viewpoint Manager (Remove Only)


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
    Note: This is up to you if you want to try it before calling your cable company.

    1. Try uninstalling all of the McAfee Software you have installed.
    2. Replace it with a free antivirus (like AVG from the above How to Protect link) and install a free firewall like ZoneAlarm (also in the above link)
    See if that changes anything related to your download problems. If not you can always just uninstall the items you just installed and reinstall McAfee if you prefer it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds