Virus's?

Discussion in 'Malware Help (A Specialist Will Reply)' started by dennisremote, Apr 28, 2007.

  1. dennisremote

    dennisremote Private E-2

    Spybot Search & Destroy finds Smitraud C and DailyToolbar. No other anti this.that finds anything.
    Ad-Watch finds changes to the Registry on boot up in Normal. They include files called susp.exe and taskdir.exe. Also there are changes to the MSConfig at start up ( Normal start ).
    A Search does not find the two file, using the normal Windows Search ( for files and folders ).
    Spybot S&D will remove them if I am in Safe Mode, but they are straight back again when I resume in normal Mode.
    Appreciate guidance to remove them.
    ps. some Desktop icons had the .lnk extension added but this seems to have resolved somehow. In All Programs .url has been added to some of them.
    Dennisremote.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.


    If you are still having problems at this point (and I would bet you will) then please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. dennisremote

    dennisremote Private E-2

    Thank you so much Chalang, i do appreciate your help.
    If i do not always do things right - forgive me, I am a senior citizen.
    I will try.
    Hopefully the file from the Smitfraud C, 'rapport.txt' will be attached ok.
    Dennis
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!


    Yes it is, but now you need to do step 2 and attach the second copy of rapport.txt.

    Then if still having problems, continue on with my other instructions.
     
  5. dennisremote

    dennisremote Private E-2

    Hi

    I am getting confused with the amount to be done in step two, but mainly the general Read This...........list.
    However here is what I have so far, together with that other file you needed. I called it rapport2.
    After a Safe mode start then to a Normal, the box comes up with ,' you are in Diagnostic Mode, even though the system is set to Normal start. If I dont check the box the Utility box appears so I set it again even though it is already set to Normal. I set it off Normal than straight back to Normal so thay I can set 'Apply' which is otherwise greyed out. So something is altering that setting.
    I could not run CCleaner in Admin as it was not on the Desktop. I have run it when signed in myself.
    I have manage to get, but not run, Getrunkey.zip; Shownew.zip and Counterspy, but they may not be saved where you would have liked, I was getting very confused by then.
    I think I have the Sun Java file too somewhere. Oh to be young with a sharpe brain.
    I thought I had to run Bitdefender too? So I did - it found nothing, I could not see how to save a file 4 you.
    Also ran online, Panda which found 1 infection SPYWARE
    2 Hacking tools and
    5 Rootkits.
    It cleared 2 infections of one type or another, again no log and the printscreen did not seem to work to get you a file to see.
    Thats about up to date.
    I have a cataract op tomorrow May 1st so might be a bit slow getting back.
    Thank you - Dennis.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NO! Step 2 is only in the second quote box! What is after the second quote box is what you need to do if still having problems after step 2 is completed. Are you still having problems?

    You did not attach the second rapport.txt file.

    I don't understand what you are trying to tell me. If you used MSconfig to get into safe mode, then you need undo that by select Normal Startup or you will get the box saying you are in Diagnostic mode.

    It does not need to be on your Desktop to run it. You can just goto the C:\Program Files\Ccleaner folder where you unstalled it and locate the ccleaner.exe file and run it by double clicking on it. You can also create a shortcut on your Desktop to make it easy to run. Just hold down the right click button on the ccleaner.exe file and drag it to your Desktop and then release the mouse button. Now select Create Shortcuts Here. From then on, you can just double click the shortcut. This works for any application.

    Why not? What problems are you having?

    I'm not sure what you mean. How did you save it? Did it find any malware?


    The above info is not useful. It is only info the Panda prints to the screen while it is running and does not provide good information since it is inaccurate. I need a log from when the scan completes. The READ ME explains how to do this. Run Panda in normal boot mode which will make it easier for you to get a log.
     
  7. dennisremote

    dennisremote Private E-2

    Hello
    I did tell you I am an old git and can get confused.
    I did at least try to attach that rapport file. I will try again.

    The utility box setting IS at Normal startup, so why does it keep coming back saying I am at Diagnostic startup? Just tried a printscreen to show you but that has stopped working.
    You are saying yourself NO! dont go further, then asking me why I did not run getrunkey etc??
    No wonder it is confusing. You are asking too much of me - can we please go ahead in single steps?
    Dennis.
    The MG system will not accept the file, rapport, as it is 533.8K long with MG's limit of 250.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you run MSconfig, which button is selected on the General tab?


    Yes I need the second rapport.txt log. Are you sure you are looking at the correct file? I have never in literally thousands of logs seen one that was more a few K in size.

    You can compress larger files into a ZIP file and upload the ZIP file as an attachment.


    Note: You still did not answer my question! Are you having malware problems? If not, I really don't need anything else from you, but it is always safer to do a full malware check on a PC that has been infected.
     
  9. dennisremote

    dennisremote Private E-2

    MsConfig - General Tab = Normal
    Maybe I am at fault as I have always restarted and held down F5 ( not F8 on this computer) Then restart always starts up in Normal.

    I do not know how to create a zip to send you that 533KB file? Even zipped will it reduce to under 250?
    Yes there is Malware, at least I think so, Spam by emails is now massive, like the computer inside is transparent to everyone.
    The Favorites list in IE has a url added to most.
    The computer is slow.
    Downloads are slow, this uses a DSL connection.
    Dennis.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First are you really sure that it is the output from SmitFraudFix? Load the file into Wordpad or notepad and then copy and past only the first 20 lines into your next message.

    But to answer your question, yes ZIP'ing the file could compress it as much as 85 to 90% depending on the content. Here is one of many links that exist on the internet explaining the use of WinZip. http://www.johnsmiley.com/cis18.notfree/smiley032/smiley032.htm

    Spam is rarely malware. It is most frequently due to the fact that users like yourself have managed to get yourselves added to spammers lists. and then you may have made it worse my clicking on things that say "To unsibscribe click here" or to "Send an email to......" . All that does is confirm your email address as valid and then it adds you to hundreds (maybe more) of other spammers lists.

    I don't know what you mean.

    To most what?

    May or may not be malware. Often times users of DSL also foolishly download and use free internet security suite tools from their ISP. These tools are notorious for slowing PCs down to a crawl especially on DSL connections which are slow to begin with.
     
  11. dennisremote

    dennisremote Private E-2

    I believe the file to be the correct one.
    I worked on putting it in to Notepad then just copied a section from the start that should be under 250KB. It worked out at a little over 100KB. I had done this b4 I got your email so its still a lot longer than you wanted. At least you'll be able to see if it is the right one. I have named it rapport2(a).txt
    I would still need to send 3 times more if you need see it all.
    Thanks for the info on zip'ing, that could be useful, I'll study it.
    Ok on spam too. Perhaps a change of screen name from time to time?

    'like the computer inside is transparent...........]like it is wide open to anyone on the internet to get infomation from this computer.
    In IE when I bring up the Favorites list, say Home Depot, it has changed from that to Home Depot.url
    MG have provided lots of link to downloads that may also slow the computers down - how are we to know the good from the bad and ugly?
    Dennis
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now I see why it is so large. You have used one of those prorgrams to create a massive Hosts file which restrict access to thousands of bad websites. The problem with programs like this is that they slow your PC down, they make it too easy for malware to hide in the extremely long hosts file that is created, and they make debugging other malware problems (like yours) become a pain because the hosts file is excessively large which makes all logs looking for malware large.

    Attach the last few hundred lines from the rapport.txt file here.

    Then immediately run the below.



    Also download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Then please continue on with the steps in the READ & RUN ME sticky.
     
  13. dennisremote

    dennisremote Private E-2

    I must have done it wrong, saw nothing at all about Restore Microsft's Host Fle. Sorry.
    I had downloaded Winzip as you gave me the download site and info.
    I have created a file which is quite short and will include here.
    I am to have my cataract operation tomorrow and prob won't be about for a few days so I dont know if you will wait or not. to continue
    Thanks - Dennis
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good luck with the surgery!! Just come back to this thread whenever you can and we will continue. If it takes a few days that's fine but your thread will be down many pages by then.

    Your next steps are still to run the READ & RUN ME FIRST Before Asking for Support procedure.
     
  15. dennisremote

    dennisremote Private E-2

    Thanks your wishes re op- seems to have gone well.
    I managed to run that Host file ok this time somehow. So I could click on to make the Host file back to Windows own.

    I'll try continue as per your last instruction now where I left off the Read and Run Me First...

    Dennis.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm happy to hear the surgery went well. Just attach the 6 logs from the READ & RUN ME once you finish all the steps.
     
  17. dennisremote

    dennisremote Private E-2

    Ok.
    I have done the best I am able with getting logs needed so such as it is they or some are included. I do have to say that I find all we have to do formidable for a non geek though. Split up it would be far easier.
    I checked out the MSConfig settings in the Utility box, Although set at normal it always tells me I am in Diagnostic Mode at start up. The computer thinks I am but the setting is just not so. Maybe part of my infection?
    Did you not say that MSConfig MUST not controll start up? It certainly seems to be doing that.
    Ran Spybot S&D, it still finds DailyToolbar and Smitfraud C and 'Fix' says it has fixed but run again and they are always still there. Went into Advanced-Settings - Select 'Ignore Products' All Products, chose Deselect All. They were already deselected though - closed Spybot.

    Download Counterspy.exe
    Ran - found infestations. 'Delete' re-ran infections still there or were removed and re-wrote back in. Ran again on Quick - 3 infections there - Quarantined. Re-run still there.
    All programs that find anything cannot rid the computer of them.
    Re ran Spybot S and D, infections there.
    Installed Sun Java as per instructions. Could not find where as not given any chance to put wher I wanted. Did not know if supposed to run or what?
    Installed Bitdefender - ran. Did not get any of what the instructions say I should have got so best could do was get a printscreen shot.
    Panda -saved to Desktop.
    Get runkey.zip saved tin C:/MGeekstools. Ran
    Shownewfiles.zip.
    Ran file in C:\newfiles.txt
    Now to try send you some files.
     
  18. dennisremote

    dennisremote Private E-2

    More scan.logs or printscreen jpg's
     
  19. dennisremote

    dennisremote Private E-2

    Hi Chaslang.

    I think I did not successfully send the files from Bitdefender and CounterSpy.
    I have tried again so..............

    Dennis
     

    Attached Files:

  20. dennisremote

    dennisremote Private E-2

    This printscrren shot may be useful?
    Attached
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the directions exactly as written and attach ALL 6 logs. We do not ask you to keep running things multiple times. You must also FIX what the scanners found. You did not tell CounterSpy to fix what it found. Look at the log for yourself. You told it to Ignore the malware. You also did not need to run SuperAntiSpyware since you ran CounterSpy.

    Until you attach the 6 requested logs in the READ ME, there is not too much I can do for you. The logs we need are:

    • CounterSpy - only for Windows XP, 2K, & NT users
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    Thus far you have attached BitDefender which found nothing and CounterSpy but you told CounterSpy to ignore what it found. Run it again in NORMAL boot mode (not safe mode) and Quarantine or Delete what it finds.
     
    Last edited: May 6, 2007
  22. dennisremote

    dennisremote Private E-2

    Hi

    I think I am getting it right now.
    Here are the first three logs from:-

    Counterspy
    Bitdefender
    Panda.

    Will work on getting the other three.

    Dennis
     

    Attached Files:

  23. dennisremote

    dennisremote Private E-2

    Hi

    Here are the final three other log text files.


    Dennis

    ps one of the Save text file boxes was in Spanish.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please re-read step 7 of the READ ME. You have HijackThis installed here:

    C:\Documents and Settings\Den\Desktop\HijackThis.exe

    That is exactly where we specify not to install it and you did not rename it as required! Please correct this now.

    You also skipped step 3 of the READ ME. You have AVG Antivirus, NOD, and PCSecurityShield installed. You must uninstall two of these now.

    You are also running Spybot's TeaTimer which we specifically requested that you not use in the READ ME.
    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!

    Now uninstall the below old versions of software as requested in step 6 of the READ ME.
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Also uninstall CounterSpy now since we are finished with it. In the future, you should install programs like CounterSpy properly into their recommend installation folders which are normally in C:\Program Files. It does not belong here: C:\MGeekTools\
    It is not a Major Geeks tool and installing it like this could cause conflicts with anything else you put in this folder and it makes it look like malware posing as CounterSpy.


    After doing the above. Attach new logs from ShowNew and HijackThis.

    Also please explain what your current malware problems are (if any)!
     
  25. dennisremote

    dennisremote Private E-2

    Hi Chaslang.

    Attached are the two logs.
    I'm sure I stopped TeaTimer? Stopped now anyway, hopefully.
    I uninstalled AVG 7.5. The other prog was my old antivirus program - PCSecurityShiedAntiVirus. This is not installed even though remnants seem to be in places within the computer. It has been cropping up with the two nasties, susp.exe and taskdir.exe as reported at startup after a Safe boot to a normal boot, reported by Ad-Aware. That program let me 'Block' them from changing the Registry values.
    There is Nod32 now left, my bought recently antiv program.
    The J2SE Runtime Environment 5.0 Updates 10,3,6 and 9 are uninstalled Now Counterspy uninstalled also.
    As for Malware, it seems pretty well ok with the computer. I did get one Save box where you had to pick Html or txt which was in Spanish.
    There appears to be no apparent faults. I think I have things installed now in suitable places.
    Dennis.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's still trying to load according to your HJT log.

    I uninstalled AVG 7.5. The other prog was my old antivirus program - PCSecurityShiedAntiVirus. This is not installed even though remnants seem to be in places within the computer. It has been cropping up with the two nasties, susp.exe and taskdir.exe as reported at startup after a Safe boot to a normal boot, reported by Ad-Aware. That program let me 'Block' them from changing the Registry values.[/quote] How could PCSecurityShield be showing two nasties if it was uninstalled. OR when you said "It" and "That program" (both are rather vague) did you mean Ad-Aware. Are you still detecting these? If not, we probably don't care.

    As for Malware, it seems pretty well ok with the computer. I did get one Save box where you had to pick Html or txt which was in Spanish.
    [/quote]Please be mroe specific/exact! When did this "Save box" occur? What were you running or doing? Where you online? Were you dowloading something? Were you running some other program? Is this still occurring? If not, we probably don't care.

    Let's continue with your cleanup!

    Since you have a paid version of Ad-Aware with Ad-watch running, uninstall SuperAntispyware and Windows Defender now.

    • Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Core LC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymantec Core LC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - (no file)
    O4 - HKLM\..\Run: [VrProxyd] D:\Program Files\PCSecurityShield\ShieldAntivirus\vrproxyd.exe
    O4 - HKLM\..\Run: [VrSchedule] D:\Program Files\PCSecurityShield\ShieldAntivirus\Vrres.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    D:\Program Files\PCSecurityShield <--- the whole folder
    C:\Documents and Settings\Den\Local Settings\Application Data\Symantec <--- the whole folder
    C:\Documents and Settings\All Users\Application Data\avg7 <--- the whole folder
    C:\Documents and Settings\All Users\Application Data\Symantec <--- the whole folder
    C:\Program Files\Symantec <--- the whole folder
    C:\Program Files\Common Files\Symantec Shared <--- the whole folder
    C:\Program Files\spybotsd14.exe

    Now run Ccleaner

    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT
    Make sure you tell me how things are working now!
     
  27. dennisremote

    dennisremote Private E-2

    Dear Chaslang,

    Attached are the two files you wanted.

    Uninstalled SuperAntiSpyWare and Windows Defender.

    Then Click on Start- Run - typed sevices.msc into box - OK- Scrolled to Symantec Core LC.
    Right clicked entry- selected Properties then press Stop Service.
    When stopped set the Start-up to Disabled.
    Scrolled to Symantic Core LC- pressed Stop Service and set Start-up to Disabled. Clicked back to Windows Desktop.

    Ran HJT on the None of the above button.
    Clicked Config button - Misc Tools- selected Delete an NT Service
    Not sure than how to Copy/Paste - from where? How to do it?
    Tried typing in,' Symantec Core LC', into the box and pressed OK.
    There was an error message but you said there would be anyway.
    Exited HJT but it did not tell me to reboot.

    Selected following lines, made sure nothing was open- reading this from printout hardcopy.
    Booted to Safe Mode and used Windows Explorer.
    The one beginning D/prog Files/PCSecurityShield does not exist.
    The next 6 were all dealt with successfully as per your instructions.

    Ran Ccleaner.
    Rebooted into Normal - obtained files from:-
    Shownew
    HijackThis

    Ad-Aware was the program that reported Changes to the Registry to answer your question. It reported the susp.exe file/Reg change whatever it was and the Taskdir.exe file. It also reported 3 files all PCSecurityShieldAntivirus and one Msconfig Registry alteration. 6 files/Reg changes in all.
    Now it does not report any of these. I have no idea how any files were reported of PCSecurityShield as it was uninstalled weeks ago and was my previous antivirus program. Maybe that was part of my virus infection? Intended so that you could not get rid of the program so you would buy it again??
    Your other question. It was when saving a log for you. The one that you wanted changing from a html to a Txt. I can't remeber which - you probabky will though. You said ,' we can just change the extension back when we get it to read. In that Save box the wording was Spanish. I can't see any other Spanish anywhere else, so prob forget it? I was not online.

    I missed a step. I have now gotten that FixMe.reg merged into the registry.
    I think you will need new HJT and Shownew files so I will create them and attached now.
    Dennis.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you forget to fix the below line with HijackThis? Try again.

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    It is not malware, it is a left over from you having Spy Sweeper installed at some point.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  29. dennisremote

    dennisremote Private E-2

    Hi again Chaslang
    Looks like you cracked the problem.

    I did miss that HJT 20 file - now corrected/cleared that up.
    1 We did use Killbox/Pocket Killbox.
    2 Combofix is deleted.
    3 SdFix - did not use it.
    4 Vyndofix - not used it.
    5 Fixwareout - we did not use it.
    6 Avenger - did not use it.
    7 FixMe.reg - yes did use, now deleted
    8 Shownew and GetRunkey were used. Zips and other files from the zip and all locations cleared up/removed.

    Am slowly digesting the 'How to protect yourself from Malware.

    Used the link given in that advice to Uninstall the microsoft Java as stated. Went to the Sun Java site but did not know what to download as there were about 6 to 8 variations? Anyway I think I got it earlier under rhe Read This.......

    So now it is time to say thank you for all your time, effort, patience and quite a bit of frustration.
    Ya dun gud!
    Thank you - Dennis.
     
  30. dennisremote

    dennisremote Private E-2

    Hi Chaslang

    There is a postscrpt. I installed a2, one of the suggested programs in the protect from further infections theme. It found 31 items but did delete all of them. It produced a report you may be interested in.
    Thanks again - Dennis.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it found nothing that is a problem. Those are all false positives.

    SpySubtract is a valid program. You probably had it installed at some point.

    C:\WINDOWS\drivers\audio\install.exe - is more than likely something for your sound card.

    C:\WINDOWS\nircmd.exe is not a dialer. It is a command line tool from NirSoft ( see: http://www.nirsoft.net/utils/nircmd.html ) and it is on your PC due to running SmiFraudFix which makes use of it.

    And cookies are not problems.
     
  32. dennisremote

    dennisremote Private E-2

    Understood.

    Thank you very much for your pesistance and knowledge to crack the problem. A service to computer users of great importance. Akin, for us, to flying an aeroplane/driving a car without the foggiest idea of whats going on under the hood.

    Dennisremote

    ps - THE END.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds