Help removing malware - computer 3

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by KenB2014, Feb 12, 2006.

  1. KenB2014

    KenB2014 Private First Class

    Ran the procedures on another computer and removed a good deal of junk.

    Files are attached.

    Thanks
     
    Last edited: Mar 10, 2007
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    O4 - HKLM\..\Run: [oatfvsudud] C:\WINDOWS\System32\hmqnza.exe

    O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\Ebates_MoeMoneyMaker Delete this whole folder if it exist!

    C:\WINDOWS\kwv2.dat

    Next, run CCleaner to clean up cookies and temp files.

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:


    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and then scan with HijackThis and attach the new log.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  3. KenB2014

    KenB2014 Private First Class

    I removed the two lines with HJT.

    Ebates_MoeMoneyMaker folder doesn't exist. I uninstalled the program when I started the cleanup process.

    I removed kwv2.dat and ran CCleaner.

    System restore points flushed and new point created.

    New HJT log is attached.
     
    Last edited: Mar 10, 2007
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log looks good, are you having any further problems?
     
  5. KenB2014

    KenB2014 Private First Class

    No, the computer is running well. Thank you for the help.
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds