This is a MESS - Malware, Viruses, etc. HELP!

Discussion in 'Malware Help (A Specialist Will Reply)' started by rsbrowning, Dec 28, 2006.

  1. rsbrowning

    rsbrowning Private E-2

    I have followed all the steps of the read me first (I didn't do the HiJack this).

    This is 1 of 2 for the reports required.
     

    Attached Files:

  2. rsbrowning

    rsbrowning Private E-2

    Here is 2 of 2 with required reports.
     

    Attached Files:

  3. rsbrowning

    rsbrowning Private E-2

    Here is my HJT log....
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run CounterSpy again and this time have it Quarantine or Delete everything it finds instead of ignoring it.

    Then run the below!


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  5. rsbrowning

    rsbrowning Private E-2

    Here is SmitFraudFix log...

    Now going to Step 2.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you re-run CounterSpy too and fix everything?
     
  7. rsbrowning

    rsbrowning Private E-2

    Yes I did...

    Here are new log files - I completed Step 2

    It is taking my system about 3 minutes to launch (hard drive light stays on solid). Could this have something to do with the Malware / Spyware.

    Also - as you can see, I use AVG - however, windows doesn't recognize it as an Anti Virus and gives me an alert every time I reboot - - is there something that can be done about this - or just a Windows thing.

    Not wanting to throw more at you - I just don't know if this is part of the problem.

    Thanks for your help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you fixed everything with CounterSpy, uninstall it now since it is only a trial. Do this now before continuing.

    You MUST ALWAYS refer to the current online version of the READ ME and make sure that you are getting the tools from it. You are WAYYYY out of date with your versions of ShowNew and GetRunKey. Get the current versions from the links in the READ ME and attach proper logs.

    You need to disable the Windows Security Center from trying to manage your security. Tell it you will manage things. However you need to install a real firewall first. You are using the Windows firewall which is not adequate. Install this ZoneAlarmFree
     
  9. rsbrowning

    rsbrowning Private E-2

    I downloaded Zone Alarm - - -

    Attached are the new ShowKey and GetRunKey logs.

    Also - I am running Peer Guardian - are you familiar with this program - - do you recommend it? It seems to have conflicts with Zone Alarm.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know of the program! It is a firewall of some sorts which is design for only one purpose to protect you from getting in trouble for downloading using P2P applications. As far as I know it is not a full blown firewall which will protect you from malware. And you need the latter which is what ZoneAlarm will do. As far as conflicts with ZoneAlarm, well I'm not familiar with those. You could ask in the Software Forum or you could try another free firewall from the below:

    We have some more work to do!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    Mozilla Firefox (1.5.0.9)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox



    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now run GetRunKey again and attach a new log!
     
  11. rsbrowning

    rsbrowning Private E-2

    Everything went well - when I ran the FixMe - all looked good - no errors. I checked, and some of the registry keys still remained - so I went onto the next step "Permission for Everyone"

    Following the steps, I was unable to delete some of the remaining registry keys (am I right to assume that if I but the ket in the address and it just came up as "Root" that the key was deleted?). I have rebooted in Safe Mode with Network (for Internet Access).

    When I launch Registar Lite - it appears that it is opening (shows in the task bar at the bottom) but I can't see it on the screen. I have tried closing it and reopening it several times with the same result.

    What do you suggest.
     
  12. rsbrowning

    rsbrowning Private E-2

    Here is a new GetRunKey log - if it helps.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! But be careful. You don't want to make a mistake anywhere and delete the Root key. If you did that you would be reinstalling your OS.

    The below keys still remain
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR

    Which means you need to do part 2 again! ONLY DELETE at the LEGACY_NETWORK_MONITOR level. DO NOT DELETE at the Root key level. Make sure that you get the Permission set to everyone. You can even set the permission at the Root key level to Everyone, but just don't delete the Root key.

    Are you still having this problem?
     
  14. rsbrowning

    rsbrowning Private E-2

    When I try to delete the 3 remaining keys with RegisterLite - both in Normal boot and SAFE MODE - I get an Access Denied.

    The below keys still remain
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member



    Use Registry Lite set set permissions to Everyone but set it at a higher registry key level. Set it at the below levels:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root

    Then try to delete the lower level LEGACY_NETWORK_MONITOR subkeys. If that does not work, move one level higher to the below keys and repeat trying to delete the LEGACY_NETWORK_MONITOR subkeys. Also use the Take Ownership feature (like we did in message # 10) of Registrar Lite if necessary.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum
     
  16. rsbrowning

    rsbrowning Private E-2

    I can't get this to work - I still get access denied - even the subkeys.

    It work on most of them when I did the 1.6.07 post. Why am I having such problems with these few.

    Also - Alarm Zone keeps locking me out of the internet and I have to reboot. It brings up information screens - but doesn't ask me to accept or declined. Any suggestions.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ift could be from the malware or it good be an antivirus,antispyware, or firewall program blocking changes. Boot into safe mode, disconnect (by unplugging cable) from the internet, shut down ALL unnecessary processes including antivirus, antispyware and ZoneAlarm.

    Then goto a higher level like HKEY_LOCAL_MACHINE\SYSTEM and take ownership and also set permissions to everyone if necessary. And then try deleting the below individual keys:
    Not sue! You may have a required process blocked. You may need to look at the list of processes and make sure you have not blocked anything needed. Otherwise uninstall, reboot, and reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds