Teenagers Strike Again - More malware!

Discussion in 'Malware Help (A Specialist Will Reply)' started by AlisenV, Jul 18, 2007.

  1. AlisenV

    AlisenV Private E-2

    Hello wise Majorgeek friends,

    I am trying again to clean the stuff that has made its way onto this pc, and followed your steps as faithfully as I could, and am attaching the logs I produced.

    A couple of notes:

    • I can only use the internet in safe mode with networking
    • We cannot use any instant messaging - so I deleted what I think are all messenger programs, and will reinstall on a clean machine
    • When the PC is in regular mode, there is a "shadow" around the mouse, obviously some sort of program is doing it, but I don't know what one.

    Thanks in advance,
    Alisen
     

    Attached Files:

  2. AlisenV

    AlisenV Private E-2

    More logs for your viewing pleasure...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2

    Reboot and install:
    Java Runtime 6

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    The shadow around your mouse is probably set in your mouse properties ...go to the control panel and click on mouse and change it.

    How are things running now?
    What problems are you still having?
    Attach a new HJT log.
     
  4. AlisenV

    AlisenV Private E-2

    Thank you for your quick reply!

    I uninstalled the java, rebooted and installed the new one as you requested.

    I still cannot access the internet unless I am in safe mode.
    I looked on mouse properties (control panel) and everything is set for "normal" meaning there are no settings for a shadow. I only mention the shadow because it might be indicative of one of those programs that come packaged with something else...I could be wrong.

    I am attaching the hjt log from after I deleted the two lines you suggested.

    Thanks for any ideas,
    Alisen
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try resetting your browser ....
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Tell me if that helped.
     
  6. AlisenV

    AlisenV Private E-2

    I wish I could say it helped, but I still need safe mode to use the Internet!

    It did work, I got a message saying it merged successfully.

    Attached is the latest hjt log.

    Could this have anything do do with running AVG and CounterSpy? And which one should I delete?

    So frustrating!

    Alisen
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may uninstall Counterspy as it is a trial application.

    You said the registry patch merged successfully but you still can not use the internet in normal mode ...what exactly happens? Or doesn't happen?

    Try running
    IEFix.

    Run HJT in safe mode and attach the log.
     
  8. AlisenV

    AlisenV Private E-2

    OK - I ran the IE fix. And am attaching the safe mode hjt log file

    BUT - this issue happens with FireFox as well as IE, in fact I rarely use IE unless FireFox won't work (like with Panda Active Scan)

    And what happens is the browser opens, I try to access a site, and it times out. Not just one site, I've tried a variety of sites.

    Additionally, instant messaging does not work - the program says it is connected, but doesn't allow interaction with other computers. I deleted all of the im programs, I think, as I know my son installed some "enhanced" parts to them. Don't know what or how it affected the pc.

    It seems like something is blocking access to the Internet. I cannot use the Avast Antivirus unless I am in safe mode, for updating, though now I think I can scan with it in regular mode.

    And I know all those scans I did originally showed problems - aren't they affecting what's going on here too?

    Thanks for all your help,
    Alisen
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have start pages in safe mode but not in normal mode...attach a Get Run log from both normal and safe modes ...
    Did you do any registry "cleaning" prior to posting here?

    Have you tried uninstalling Firefox and re-installing?

    One other question ....have you compared your IE and Firefox settings between safe and normal modes? Esp. security settings.
     
  10. AlisenV

    AlisenV Private E-2

    OK -

    Attached getrunkeys for safe and normal modes.

    Registry cleaning - there is this thing that's called registry mechanic that loads on normal boot, and scans. Before I began the process here, I "fixed" the registry problems. I think my son has been routinely doing that on each startup.

    I did not uninstall/reinstall firefox because the problem is both firefox and ie. I will do it if you think it's really necessary.

    I compared the settings for firefox in both modes, and they were exactly alike, including the start pages. The only difference is that in safe mode, on the tabs for "feeds" the icons for bloglines, my yahoo and google are there, and on normal mode, they are not. The words are there, but no icon.

    IE is the same in both modes. It's on a custom security setting, and I was going to reset it but wasn't sure. Again, with the problem with both browsers, logic tells me it is something else.

    What about the virus/malware shown in the panda and bitdefender scans? Couldn't that be related?

    Well, that's it for now,
    Alisen
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you have set as your homepage in normal mode? If it will not stick:
    In IE, click on Tools>Internet Options>Advanced tab, and scroll down to the 'Browsing' section.
    Uncheck the box next to "Enable third-party browser extensions (requires restart)"> 'OK'.
    This will disable all IE extensions, toolbars, browser helper objects (BHO's)- some of which you might want to keep. You can re-enable the wanted ones later.(Note that your HJT log in normal mode shows no BHO's).
    Close all instances of IE, then restart it.
    See if you can now reset your homepage to the URL of choice, using the standard method.
    If you can, and the Homepage you want 'sticks' after subsequent restarts, then one of the IE extensions that you disabled is responsible. To determine which one, you will have to disable them selectively, one by one, til you find the guilty party.

    The other possibility is that Spybot is stopping any changes:
    Open Spybot>Mode>Advanced Mode>Tools>IE tweaks. Uncheck the 2 boxes next to the entries that begin "Lock IE..." Reboot

    Or your Firewall is doing the same.

    The items from your Panda and Bitdefender scans have been taken care of ...you are malware free ...

    Yes...try setting your security back to default. And it wouldn't hurt to uninstall Firefox and reinstall to see if that makes a difference.

    Also, please click Start, and then click Run.
    In the Open box, type regedit, and then click OK.
    In Registry Editor, locate the following subkey, if it exists:
    HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
    See if the ResetWebSettings value or the HomePage value exists in this key,
     
  12. AlisenV

    AlisenV Private E-2

    Tim -

    After much thought - I finally noticed that my firewall was not accessible, not in the system tray, etc. So.. I uninstalled it - and voila, it works. So for right now am using Windows firewall, but will be reinstalling some better firewall soon.

    Thank you for all of your help!

    Alisen
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That would do it .....
    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds