Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

SCANS I DID HOPE THESE ARE RIGHT


  • This topic is locked This topic is locked
54 replies to this topic

#16 m0le

m0le

    Can U Dig It?


  •  Avatar image
  • Malware Response Team
  • 34,528 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:10:04 PM

Posted 26 February 2011 - 05:51 AM

FixCleaner seems to have an adware infection.

You should remove the folder as well as the file

Use Windows Explorer to find and delete this folder:

FixCleaner

As an example:
To delete C:\WINDOWS\badfile.dll
Double click the My Computer icon on your Desktop. Or click on the Windows KEY + E.
Double click on Local Disc (C:\)
Double click on the Windows folder,
Right click on badfile.dll and then from the menu that appears, click on Delete


How's the machine running?

Edited by m0le, 26 February 2011 - 05:51 AM.

Posted Image
m0le is a proud member of UNITE

BC AdBot (Login to Remove)

 


#17 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 26 February 2011 - 03:52 PM

Oh wow, I ran malwarebytes this morning and I have a whole new problem. I must have activated it somehow, don't remember but I was half asleep anyway.

Plus I keep getting this popup message about "potentially harmful stuff".

Here's what malware found:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5887

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

2/26/2011 2:42:12 PM
mbam-log-2011-02-26 (14-41-40).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 308898
Time elapsed: 31 minute(s), 31 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
c:\program files (x86)\common files\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> 3328 -> No action taken.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchSettings (PUP.Dealio) -> Value: SearchSettings -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\SEARCH SETTINGS\SEARCHSETTINGS.EXE (PUP.Dealio) -> Value: SEARCHSETTINGS.EXE -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files (x86)\youtube downloader toolbar\widgihelper.exe (PUP.Dealio) -> No action taken.
c:\program files (x86)\common files\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> No action taken.


I just saw your note to me don't know why didn't see it before about Fix Cleaner.
I don't think I have Windows Explorer or if I do it doesn't work.
Is there another way to do it?

I thought things were getting better but today its been increased popups of that ordinal dll thing missing. :woot:

Edited by kcsummer, 26 February 2011 - 03:56 PM.


#18 m0le

m0le

    Can U Dig It?


  •  Avatar image
  • Malware Response Team
  • 34,528 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:10:04 PM

Posted 26 February 2011 - 04:56 PM

Okay, can you run MBAM again but make sure that everything is checked, and click Remove Selected


Then please run ESET

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Leave the top box checked and then check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image
NOTE: If no malware is found then no log will be produced. Let me know if this is the case.
Posted Image
m0le is a proud member of UNITE

#19 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 26 February 2011 - 07:54 PM

I cannot locate that c:\windows\badfile you refer to?

I will rerun the other 2 as you suggest now.

Edited by kcsummer, 26 February 2011 - 07:55 PM.


#20 m0le

m0le

    Can U Dig It?


  •  Avatar image
  • Malware Response Team
  • 34,528 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:10:04 PM

Posted 26 February 2011 - 08:30 PM

I cannot locate that c:\windows\badfile you refer to?

That was just an example file to show you how to delete files/folders. :lol: All we want is for the FixCleaner folder to go.
Posted Image
m0le is a proud member of UNITE

#21 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 27 February 2011 - 12:17 AM


I cannot locate that c:\windows\badfile you refer to?

That was just an example file to show you how to delete files/folders. :lol: All we want is for the FixCleaner folder to go.

thank you, here is the results of the Malwarebyte:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5888

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

2/26/2011 11:12:47 PM
mbam-log-2011-02-26 (23-12-47).txt

Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 309235
Time elapsed: 31 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
:thumbup2:

#22 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 27 February 2011 - 01:43 AM

I did the ESET again and it said one problem found. But when I clicked on finish this screen popped up saying I should buy something else and I couldn't get rid of that screen so eventually I got that page closed but then I lost the report so I am having to scan again.

#23 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 28 February 2011 - 10:54 PM

I have got a deadline and have been on my Apple computer all day I will run another scan later tonight when I get through with this. Thanks mole.

#24 m0le

m0le

    Can U Dig It?


  •  Avatar image
  • Malware Response Team
  • 34,528 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:10:04 PM

Posted 01 March 2011 - 05:34 AM

No problem. I will be back on the 3rd of March - see my signature. :)
Posted Image
m0le is a proud member of UNITE

#25 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 01 March 2011 - 01:58 PM

Okay, mole, thank you. I will run one then right before you are coming back I will run late afternoon Wednesday. :busy:

#26 m0le

m0le

    Can U Dig It?


  •  Avatar image
  • Malware Response Team
  • 34,528 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:10:04 PM

Posted 06 March 2011 - 05:46 PM

Are you ready to continue?
Posted Image
m0le is a proud member of UNITE

#27 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 06 March 2011 - 09:48 PM

Yes, Mole, not meaning to keep you waiting. So tell me what you want to do now. Since you've been gone I am still having trouble with the iertutil.dll issue and I found a link on Microsoft help forum which I thought might help but I couldn't get it to work. Some people suggested to download another Internet Explorer to see if it would fix the missing/corrupt .dll file but whatever I try to install it says I have the wrong one (I have 32/64 bit computer and I guess each is seperate.

Anyway, I have run scans when I seem to have more trouble and the only thing that showed up was an Adaware problem.

I have totally lost track in the confusion what you want me to do and where we are in this.

I'm sorry to be slowing you down but if you tell me what to do I will take care of it asap.

Thanks Mole.

#28 m0le

m0le

    Can U Dig It?


  •  Avatar image
  • Malware Response Team
  • 34,528 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:10:04 PM

Posted 07 March 2011 - 08:11 AM

You can start with another ESET scan - you said the last one didn't provide a scan.
Posted Image
m0le is a proud member of UNITE

#29 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 07 March 2011 - 09:38 PM

Okay, Mole, I have it started scanning now, I forget how long this one takes but I just started the scan.

#30 kcsummer

kcsummer
  • Topic Starter

  •  Avatar image
  • Banned
  • Member rank image
  • 434 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:04 PM

Posted 08 March 2011 - 09:21 PM

I did do the scan you requested last night and it came up negative on anything harmful or different. When I tried to save the log it seems my computer was locked up (I feel asleep so it was hours later) and I couldn't save it but it was okay.

Since I cannot get anywhere with this iertutil.dll missing internet explorer file it appears I will have to reinstall everything/wipe out what I have. If I do that and there is something wrong/virus/trojan, etc. will it be reinstalled.

I have been using a backup service and I'm not sure about that either, would it pick up a bug if there was one so it would be reinstalled?

I will run any other test you say. Thanks Mole




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users