Virus help, unsure if problem has been removed.

Discussion in 'Malware Help (A Specialist Will Reply)' started by wilfordbrimley, Nov 15, 2006.

  1. wilfordbrimley

    wilfordbrimley Private E-2

    I'd like to say thanks in advance to anyone who can help me with this.

    Here's the summary of the problem to date:
    playercodecxxxx.exe was downloaded on my computer. I've since realized this was a problem.
    http://www.jahewi.nl/rogues/playercodec/playercodec.html

    My current problems have been crashes of firefox (illegal plugin operation of shockwave flash, normally I wouldn't think it was related to any virus but it started at the same time as the other problems, and at the same time this was downloaded), and continual repetitive but seemingly random crashes of explorer, where it freezes, and I need to kill the process and restart it from ctrl+alt+del. I have another problem where after running msinfo32.exe.

    At some point either spybot or symantec found a version of the zlob worm in a scan which has since been deleted.

    TeaTimer is running, but only because I had installed it before I read instructions here against it.

    I followed the instructions posted here for use before using HijackThis. Bitdefender found a virus during it's scan. I'll post the logs from bitdefender, panda activescan (which found nothing but cookies), and the getrunkey and shownew logs, as well as the hijackthis log.

    What I'm hoping is that someone can tell me if my computer is now clean. I've still had the explorer.exe crashes, and my question is whether it is related to any malware, or if I need to look elsewhere for the solution to the problem.

    Below are my Panda Active Scan log, Bitdefender report log, and my runkeys.txt. I'll post another post underneath this with the logs from shownew and hijack this. Thanks again for any help people can offer.
     

    Attached Files:

  2. wilfordbrimley

    wilfordbrimley Private E-2

    Here are the shownew and hijack this logs.

    Thanks again for any help people can offer me.
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please disable Spybot's TeaTimer so it will not block anything we try to fix!How To Disable TeaTimer

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/entry/index.asp?DestURL=http://support.dell.com/us/en/kb /document.asp?DN=1083458&st=3791951&segID=5DS&appindex=DS

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)

    O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - https://register3.valueactive.com/mpp_229/webolr/OCX/FlashAX.cab

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.

    After you complete the above, REBOOT and proceed with the rest of this fix...

    Once you have completed this post, follow this thread below.

    WareOut Removal

    After the thread above is completed fix the below entries below with HJT.

    Once you complete this post, reboot once more and attach a fresh HJT log.
     
  4. wilfordbrimley

    wilfordbrimley Private E-2

    Thanks very much for your very fast help. I've followed the steps you recommended and I've attached the fresh hijackthis.log as well as the fixwareout log, though I'm not sure if you'll need it. Thanks again.
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log looks good, are you having any further problems?
     
  6. wilfordbrimley

    wilfordbrimley Private E-2

    Everything seems good so far. The problems with firefox and explorer.exe that I had earlier are no longer occurring. I've had explorer.exe develop some sort of memory leak and task manager showed it was using 270k, but after killing and restarting it, it returned to normal levels and stayed there. If I do encounter more problems I'll post about them.

    Thanks so much for your help, I really appreciate it. In the future I'd like to be able to solve these problems myself, is there anyway to learn about how to interpret the hijackthis results so that I can fix any problems myself?
    Thanks again.
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes there is actually, you can read the HJT Tutorial to learn more about the different entries.

    The best way to learn about Malware is to read around the Malware Removal forum looking at different threads. Read how we removed things differently in each thread, eventually you will catch on.

    Surf Safely!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds