Adware/Malware Infected PC

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Blackhawk0221, Oct 19, 2006.

  1. Blackhawk0221

    Blackhawk0221 Private E-2

    I have read and followed all of the steps and procedures (except for #8 because the Malware was never removed).
    I am trying to get rid of egwn.net and gad-network.com and 'nothing' has worked so far.
     

    Attached Files:

  2. Blackhawk0221

    Blackhawk0221 Private E-2

    em.gad-network.com has taken me away from this forum site 3 times in 5 minutes to a pop-up page...

    egwn.net has hijacked me once in the same time period!

    This is driving me crazy!!

    More files below...

    Sure would appreciate some help: John
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not attach a log from Bitdefender as requested.


    Did you add the below two settings for SeachAssitant yourself? If not, add these to the lines to fix with HJT below.
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gophersearch.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gophersearch.com/

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O16 - DPF: {CB5D474E-A510-40A4-B5A4-838933BCBA64} - http://es6-scripts.dlv4.com/binaries/egaccess4/egaccess4_1065_XP.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
    O18 - Protocol: bw+0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {680D3296-61BD-4CCD-9B5B-9D7F42A01C4B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\egaccess4_1065.dll

    Additional step to delete files in the Downloaded Program Files folder :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s MediaPassX.dll
    del MediaPassX.dll
    attrib -r -h -s MediaAccX.dll
    del MediaAccX.dll
    exit
    Now run Ccleaner.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. Blackhawk0221

    Blackhawk0221 Private E-2

    Requested Bitdefender Log file attached...

    Thank you for your assistance: John
     

    Attached Files:

  5. Blackhawk0221

    Blackhawk0221 Private E-2

    Followed above procedure 'to the letter'...

    Within seconds of logging on to Internet Explorer, which went right to the Major Geeks home page, your Advertisement sidebar was 'hijacked' by gad-network.com and immediately displayed "Sexy Girls" and then "Crazy Girls" popup links that are connected to gad-network.com.

    So, I guess it is accurate to say that it didn't work...

    I have read at other sites, upon doing a 'search' for gad-network.com, that this Malware hides in the files/programming for Microsoft Internet Explorer.

    Sure would like to get this cleared up.

    Thank you for your assistance: John

    Files attached as requested.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because we are not done yet. Those previous steps were just to fix other problems you had.

    Now let's continue.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.1_01
    Viewpoint Media Player <--- should have been uninstalled in step 0 of the READ ME!


    Boot into safe mode and use Windows Explorer to delete the below files:
    C:\WINDOWS\system32\ojauefx.exe
    C:\WINDOWS\system32\ojauefx.dat
    C:\WINDOWS\system32\ojauefx_navps.dat
    C:\WINDOWS\system32\ojauefx_nav.dat

    Make sure you find and delete all of these. If you have any problems, finding them make sure you have follow the directions in step 2 of the READ ME. If you still have problems locating them or deleting them, tell me when you come back.
    Now reboot into normal mode and continue.


    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now attach new logs from ShowNew and HJT.

    Also tell me how things are working.
     
  7. Blackhawk0221

    Blackhawk0221 Private E-2

    Steps completed...files found and deleted.

    Popups no longer taking over Major Geeks Main page advertising block...this is good!

    Viewpoint reinstalled itself after reboot...I used Add/Remove programs. Second time went to file location to delete and would not delete files...says they are 'being used by another program'.

    That version of Java 2 also uninstalled...even though Add/Remove says it is still there and would not function to Remove the file. So I went to file location in Programs and right clicked and deleted. Add/remove says it is still there...strange?!

    Files attached...

    Thank you for your assistance: John
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is due to AOL being sneaky and reinstalling it on you. Use this: ViewpointKiller

    Let me know if that helps!

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    6. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds