What do I need to Remove?

Discussion in 'Malware Help (A Specialist Will Reply)' started by c1cdj, Mar 17, 2008.

  1. c1cdj

    c1cdj Private E-2

    RE: Read Me & Run Me First

    I followed the instructions in Read Me & Run Me First. All seems to be working fine. My question is that I have a valid version of Windows XP Pro that was installed while using my computer at the office. I no longer work there and my computer is now at home. I get a message from Windows that I am no longer considered valid because my copy now has a blocked Volume License Key. I also was not given the Windows disk. I know I'm going to have to do the upgrade thing they want you to do but am unable to afford it yet. I get Automatic Updates but I know they probably aren't complete. Am I at least partially protected after doing the steps in Read Me & Run Me First? :confused
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Read Me & Run Me First

    Welcome to Major Geeks!
    That is not the main goal of the READ & RUN ME, although taking some of the steps in there (like with Spybot's Immunize and updating Sun Java) do given some added protection. The goal of the READ ME is to remove malware from your PC and you do not appear to have any.

    If you wish to look into to protection, that is in another sticky thread:

    How to Protect yourself from malware!
     
  3. c1cdj

    c1cdj Private E-2

    I read a note somewhere on your site telling someone to remove certain things after using the READ ME & RUN ME FIRST guide. I used it and submitted my logs. I was just wondering if I needed to remove anything.
     
    Last edited by a moderator: Mar 20, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can do the below.

    1. UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type cf /u in the runbox and click OK.
      • Note: The space between the cf and the /U, it must be there.
    2. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
     
  5. c1cdj

    c1cdj Private E-2

    I think I messed up. I deleted combofix (cf.exe) before I read your message now McAfee keeps saying it is detected way down in the bowels of my computer where I cannot go. Will I still be able to do the READ ME & RUN ME FIRST again as suggested by Tim? I am still having problems with my cpu running at 100%. I watched McAfee scan for 5 hours right by some porn sites listed as domains. I also rec'd a message from McAfee that an infected e-mail had been deleted. When I initially did R&RMF all was well for a couple of days and then started getting slow again. I went to pacs portal and it says there are all kinds of things running put there by worms and trojans! McAfee supposedly killed JS Wonka and PUPER KK and the Zlob CD & Zlob CE have also been in here.
    Tim wants me to attach the logs from my scan, but I already sent them to you for the one and only time I've done it. You said I did not appear to be infected. Do I do the R &RMF again or are there other things you suggest? I would really appreciate working with you since you are somewhat familiar with my situation.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just download it again to your desktop and then use the uninstall command.

    I have no idea what you mean.

    Again I don't know what you are referring to. Are you working in another thread with Tim? If so, then work in that thread only.

    In your first message in this thread you said
    If you are having problems you should be completing the READ ME and attaching the logs as requested. No logs = No help. Also if you are working in another thread, I repeat stay in that thread.

    You said things were fine, and then they became bad again. Thus the answer is start over again. Make sure you look carefully at the READ ME cleaning instructions for your Windows version because they have changed. ComboFix is not in the steps right now.
     
  7. c1cdj

    c1cdj Private E-2

    I am beginning all over again. I started with The Special Removal procedures for SmitFraud/Zlob. Attached is the first log.
     

    Attached Files:

  8. c1cdj

    c1cdj Private E-2

    Special Removal Procedures, SmitFraud/Zlob, second log attached.
    Also, during my reboot, I got a message from both Super Anti Spyware and McAfee saying something wanted to change my Comcast Homepage to something else and I had to block the change. In addition, my desktop is now blue instead of black as I had it. What do I do to change it back?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running SmitFraudFix? You do not have a smitfraud/zlob infection.

    If you are having malware problems, you need to run the READ & RUN ME and then afterwards if you still have problems, attach the requested logs and tell us what problems you are having but as I stated in message number 2, your first set of logs showed no malware so I'm not sure what you are trying to accomplish unless you really have become reinfected. Again if you feel you are reinfected, run the READ ME.
     
  10. c1cdj

    c1cdj Private E-2

    I've had problems since Feb 26. I was having hundreds of pop-ups saying I had a back door trojan and wanting me to purchase their programs to remove it. My CPU began running at 100% with stuff taking forever to open or not opening at all, the hourglass was coming up for no reason continually and when it did the whole screen would "burp" or skip almost blink.
    I am unskilled at more than basic computer maintenance. I went to Symantec for guidance, downloaded Norton System Works and ran it daily after McAfee Security Suite, which is supplied by Comcast. McAfee removed PUPER and JS WONKA. Norton removed a bunch of other stuff, my trial expired, and I uninstalled it but kept McAfee. Still having pop-ups of a backdoor trojan and a new toolbar appearing on IE browser, I searched online for malware removal, did online scans which pickedup and tried to remove Zlob CD.
    I found Major Geeks, immediately signed on and did the READ & RUN ME FIRST, sent in my logs and every thing seemed to work for a couple of days. System began running at 100% again, the constant hourglass and screen blinking, stuff asking for registry changes and internet access. In one of your messages you said to start over with R&RMF, so I did. At the very begging of R&RMF it has Special Removal Procedures if you know what you have so I ran SmitfraudFix due to Zlob being the thing that kept showing up in all of the scans repeatedly. Even after running SmitfraudFix, as I rebooted, a pop-up asked me to change my homepage and I blocked the change.
    I do not know how to do this stuff. I've owned my computer since 2000 and I know that there is a problem. I am hoping to learn alot from you. Please, Mr. chaslang, help me. I had intended to continue on with my second time of R&RMF after I heard from you regarding the SmitfraudFix logs.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please just skip the Special Removal Procedures and run the rest of the READ ME and attach all of the requested logs. You will notice that ComboFix is not in the READ ME at this time. Make sure you use the current online version of the READ ME.
     
  12. c1cdj

    c1cdj Private E-2

    I have finished Read & Run Me First. Attached are the only logs generated. Super Anti-Spyware did not find anything and made no log. SpyBot Search and Destroy did not find anything. I'll wait to hear from you before continuing. Let me know when it's time to toggle system restore.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not really show any major problems other than what Malwarebytes already removed. I do have a few things that you should do though.


    First you must get out of the habit of saving downloads into the C:\Program Files folder. This folder should only contain installed programs, not downloaded files. If you need the below files, move them somewhere else or delete them.
    Code:
    C:\Program Files\
    defrag~1.exe Mar 24 2008 1978240 "DefragSetup.exe"
    firefo~1.exe Mar 18 2008 6029648 "Firefox Setup 2.0.0.12.exe"
    micros~1.lnk Mar 12 2008 104 "Microsoft Outlook.lnk"
    spybot~1.exe Mar 16 2008 9722720 "spybotsd152.exe"
    supera~1.exe Mar 16 2008 6342680 "SUPERAntiSpyware.exe"
    winmx353.exe Feb 1 2008 823296 "winmx353.exe"

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh309190.dll/201
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) -

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now run Ccleaner!
     
    Last edited: Mar 29, 2008
  14. c1cdj

    c1cdj Private E-2

    I have completed everything you told me to and set my homepage to MajorGeeks.com.
    I await further instructions.
    When do I toggle System Restore?
     
  15. c1cdj

    c1cdj Private E-2

    McAfee froze up trying to tell me about registry changes that were trying to be made and a bunch of other stuff when I did the Reset Internet Explorer. I decided to run Malwarebytes again. Log is attached. Should I do something else?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown or uninstall McAfee then and do the steps again as all it did was block you from making the changes we were trying to make. That's is unless it gives you the option to allow the changes. Then just allow the changes. You are the one making the changes so you need make sure you accept them.
     
  17. c1cdj

    c1cdj Private E-2

    I re-did the Reset Internet Explorer and this time it seemed to go ok. What else can I do to get this baby "right" again? Are there any other things I need to run? Is it safe to continue on as normal? Do I do a toggle system restore yet?
    I'm ready for the next step, sir.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  19. c1cdj

    c1cdj Private E-2

    I am becoming frustrated with this!!! I did the things listed in your last thread except remove MGTools. I feel the need to keep it.
    Upon reboot after turning back on System Restore, Super Anti-Spyware popped a box up, again, saying that I was being asked to change my home page from Majorgeeks.com to msn........redirect..... I forget it all but I blocked the change. I decided to again run Malwarebytes. It turned up, and I deleted,
    Trojan.Agent C:\windows\system\SYSRegC.dll.
    What does all this mean? Is there STILL stuff in here that I haven't addressed?
    Is there more I could do? I am SO READY for this hassle to be over and done.
    Also, after the reboot, the Java Icon showed up in my tray. I went to the Java file in Program files, in the Bin, I found jusched.exe and deleted it.
    Probably not the thing to do but I'm about to lose all my patience.
    What do you suggest?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why?? This is what I asked you to change your home page to back in message # 13? What's the problem? You should not be blocking the change. It is what we were trying to do.


    This was deleted previously. However it is just due to what you installed on your PC. Are you the one who installed Max Registry Cleaner? If not then uninstall it. It is not malware so Malwarebytes is incorrect in deleting it.

    It is just the autoupdate program for Sun Java and is not a problem. You can disable autoupdating if you prefer.
     
  21. c1cdj

    c1cdj Private E-2

    I changed my homepage as instructed in thread #13 to Majorgeeks.com. The box that popped up upon reboot wanted me to change it to something at www.msn.....and I blocked it to keep my homepage at Majorgeeks.com.
    I subscribed for a year to Max Registry Cleaner, BEFORE I found you guys, because my computer was running so slowly that I thought it would help. My subscription will expire in Sept. but I will gladly uninstall it if you think it would be beneficial.
    There are still things going on. Web pages that only open blank but the address shows correctly in the address bar and it says "done" at the bottom. The hour glass popping up and blinking for no reason at all, nothing was asked to open. The programs I do want to open are taking FOREVER to do so and open up like a web page on dial up.
    Is there nothing more I can do to resolve this ?
    I'd give anything to have the knowledge that you guys have.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Beneficial to what? I definitely would not have it load at start. You should only clean the registry when really needed and that is rarely.

    Which browser are you using? Which ever it is, try another browser and does the same thing happen.


    Your logs were previously clean. Let's try a couple more scans. And let me ask addition questions.

    Why are the below proxy settings required?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = actsvr.comcastonline.com

    Have you ever consider that all the stuff McAfee has running may be causing you problems?

    Do you have any software installed from Symantec because I had seen some services related to Symantec?


    Run this Trend Micro Housecall and attach a log from it.

    Also run this Running GMER to detect rootkits and attach the requested log.
     
  23. c1cdj

    c1cdj Private E-2

    I do not know about the proxy settings and they probably should not be there. Had downloaded Norton System Works in the beginning to try and get rid of this, trial expired and I uninstalled it.
    McAfee Security Suite comes free with Comcast but I will gladly uninstall it as it's protection has not impressed me. They do offer only the Virus Scan would that be better? I will go with whatever you suggest on this. What else could I use if not McAFee?
    Trend-Micro Housecall did not give option for log nor could I figure out how to do it. Results were 1 grayware; ADWARE_MEMWATCHER. During cleaning I saw the words Trojan many times, Sober Worm and several other worms and something to do with drivers as well. GMER log is attached. What now?
     

    Attached Files:

  24. c1cdj

    c1cdj Private E-2

    I have uninstalled McAfee and have chosen to use
    Antivir
    a-squared
    Comodo Firewall
    Comodo BOClean
    Spybot
    Spyware Blaster

    Every single thing I've downloaded, updated and run had picked up and deleted malware of some kind or another. I have been really infected and have seen the words Trojan and Worm so many times I'm scared all over again.
    During my Spyware Blaster install, when it tells you to enable all protection, Comodo Firewall kept asking me to allow Spyware Blaster to modify registry keys. All I was seeing were adware and porn sites. I kept saying "ok" to allow it to do so for awhile thinking it was going to remove all of them, then got scared that it was protecting them instead so I quit and decided to write to you.
    This was part of one of them:
    Registry Key \Software\Microsoft\Windows\Current User\Internet Settings\Zone Map\Domains\celeb-dialer.de
    I need some way to get into this area and delete all these malware, adware, porn domains or what ever they are so they're gone for good. I know this is where my problem lies and, now that I gave Comodo permissions for Spyware Blaster, I feel like they'll never go away. Do I continue on with enabling protection for Spyware Blaster? If so do I "allow" or "deny" Spyware Blaster to change the registry?
    I am seriously trying to correct this problem. I am trying to comply with all you've told me to do.
    I will await your directions.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that it completely and properly uninstalled? It often leaves things hanging around. It may be a good idea to run this: McAfee Consumer Product Removal Tool

    It is a good idea to reboot after running the above McAfee tool!

    And while we are running removal tools, let's run one for Symantec to make sure all their software items are gone too:Norton Removal Tool (SymNRT)


    It is a good idea to reboot after running the above Symantec tool!


    You need to allow Spyware Blaster to make all those changes. That is how it gives you protection from all of those bad items. Just disable Comodo while enabling Spyware Blaster's protection if Comodo keeps stopping you.

    No you don't! You don't have a problem. As stated above, those were all things Spyware Blaster was writing into your registry to protect you. Do you really think we would have you run tools that would infect you???
     
  26. c1cdj

    c1cdj Private E-2

    I Ran both the McAfee and Norton Removal Tools. All is now fine with Spyware Blaster.
    In thread # 22 you asked about some proxy sttings. I answered your questions in thread # 23 and wondered what, if anything, I needed to do about it. Also, in thread # 23 I attached the requested GMER Log, LuResult.txt, and didn't know if you'd had the change to review it.
    In this thread I'm sending the logs from my installs of Antivir and a-squared as well as one I did from Malwarebytes. There are 2 locked files that cannot be scanned and a couple of other things.
    Another scan with Trend Micro Housecall turned up ADWARE_MEMWATCHER again and I deleted it but I think it just keeps coming back or is not completely removed. This is the one where when watching the cleanup scan you see, SOBIG Worm, SOBER WORM, TROJAN.Agent...and lots of others.
    Are there any other scans I can do. I'm not ready to give up yet.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! They appear to be for your ISP.

    Yes it was clean.

    You are wasting your time. All you are doing is detecting valid software and removing it with these scans. We also already covered the fact that you have Max Registry Cleaner. You need to ignore that detection of uninstall Max Registry Cleaner. I'm not sure what you think you are looking for but you don't have any malware on your PC. I cannot comment on what Housecall is finding since you are not giving me a log. And one of your other items is just in System Restore which will disappear after you disable and then reenable System Restore.
     
  28. c1cdj

    c1cdj Private E-2

    I don't know how to get a log from Trend Micro Housecall. Please could you tell me how to do it? It may pick up the same thing as before, and I can send it to you. If it also proves to be nothing, I will gladly be able to call this done. I am so ready for closure.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check to see if the below folder has any logs in it. This is where it used to save them. Hopefully it has not changed.

    C:\Documents and Settings\UserName\.housecall\log\

    Note: replace UserName with your actual user account name.
     
  30. c1cdj

    c1cdj Private E-2

    Thank You! I just couldn't figure it out. :eek:
    Here are the logs from the 2 scans I did.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no valid problems showing in this log. As I stated in message # 2 of this thread, you really did not have any malware. Just a couple minor non-desirable things like Kontiki and some minor junk SAS had already removed.
     
  32. c1cdj

    c1cdj Private E-2

    Ok. I want to thank you and Tim for all of your help. I apologize for taking up so much of your time. We may now close this thread and, if I have anymore trouble, I'll start a new one.
    I admire all of you at Major Geeks, you guys are super! :wave
    Thank You again.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds