Still needs some cleaning and tinkering....

Discussion in 'Malware Help (A Specialist Will Reply)' started by AMarie, Mar 31, 2006.

  1. AMarie

    AMarie Private E-2

    hi, i am not new to this site - i have been helped immensely before and find i am in a mess again. now with my work computer. my daughter was hunting around for some guitar music and next thing you know i had popups and adware.... even lost the internet all day due to new.net and other junk. i have followed all the "do this first" programs and have several logs to give up here if anyone would be so kind to run through them to see if i need to clean up anything else. i sure do appreciate all the help and have another pc in the spare room that i will need your help with soon as well.

    thanks..... a bunch, anne marie
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please do not attach PDF files. Just leave the logs as text files and attach them.

    Also please follow the directions in step 7 of the READ ME to install HijackThis properly. You are running it like this:

    C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.684\HijackThis.exe

    This means you are running it exactly how we ask that it not be run. That is, directly from the ZIP. Please install it to the recommended folder.

    Before continuing I want to get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  3. AMarie

    AMarie Private E-2

    hi chaslang!

    thanks for taking time to help me number one. attached is your uninstall.txt file that you requested.

    thanks! anne marie ;)
     
  4. AMarie

    AMarie Private E-2

    uh..... forgot the file..... doh! :rolleyes:
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = -
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard6.exe
    O4 - HKLM\..\Run: [newname] C:\windows\newname6.exe
    O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad6.exe
    O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
    O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
    O20 - Winlogon Notify: Nls - C:\WINDOWS\system32\e420lefm1h2a.dll (file missing)
    O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\guard.tmp (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\LocalService\Application Data\NetMon <-- the whole NetMon folder
    C:\Program Files\Common Files\VCClient <-- the whole VCClient folder
    C:\windows\mousepad6.exe <--- delete any files using the starting with the text mousepad and ending in .exe (like mousepad1.exe, mousepad2.exe...etc)
    C:\windows\newname6.exe <--- delete any files using the starting with the text newname and ending in .exe (like newname1.exe, newname2.exe...etc)
    C:\windows\keyboard6.exe <--- delete any files using the starting with the text KEYBOARD and ending in .exe (like KEYBOARD1.exe, KEYBOARD2.exe...etc)
    C:\windows\GIMMYSMILEYS3.EXE <--- delete any files using the starting with the text GIMMYSMILEYS and ending in .exe (like GIMMYSMILEYS1.exe, GIMMYSMILEYS2.exe...etc)
    C:\WINDOWS\keyboard21.dat
    C:\WINDOWS\kwv2.dat

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.
    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. AMarie

    AMarie Private E-2

    hi chasling,

    everything seems really normal! (yay) here is the latest HJT logfile attached. thanks, anne marie
    ps - some of those files that you had me remove were not there.... is that right? hmm. ;)
     

    Attached Files:

  7. AMarie

    AMarie Private E-2

    chas,

    sorry..i was just reading through all the posts for my thread and i noticed that i did not extract the hijackthis program out of the rar file..... i have done that now and have reattached a new logfile.... if it makes a difference.

    : ) anne marie
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well actually you needed to do it first! It's too late now since you aready did the fixes. If something had gone wrong in the procedure you would have no backups and would be in big trouble. Now that you have it correct, at least it is ready for the next time you need it (hopefully not).

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds