I have viruses galore help please

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by volkmt, Aug 1, 2006.

  1. volkmt

    volkmt Private E-2

    Ok well I will start off by telling you that I do have virus protection programs and some virus removers on my computer.
    They are: Charter High Speed Security Suite - F-secure
    System Mechanic 6
    HijackThis V. 1.99.1
    SmitfraudFix

    I have rid myself of a lot of viruses but there are some that my virus removers cannot get for some reason. I looked at the list of viruses/spyware/malware that my F-secure program listed in the quarintined section and they are as follows...

    VX2
    Adware.Maxifiles
    GetMirar
    WebHancer
    Windows vunerability
    UCmore
    EzuLa
    Adware.Look2Me

    Also this is a warning that the supposed "Myspace trackers" will seriously mess your computer up full of worms and Trojan things.... DONT CLICK THEM

    Thank you for your help and patience, I do appreciate it. :)
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com, please follow the steps below:

    [​IMG] Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    [​IMG] Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    [​IMG]After doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    [​IMG] Downloading, Installing, and Running HijackThis

    [​IMG] When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. volkmt

    volkmt Private E-2

    Just to make sure I understand what you are saying, I should download all of the programs in step 4 to a new folder in my C Drive and then follow all of step 5 and check back with you to see what happened?

    I believe my Charter can get rid of some viruses and trojans so I am unsure of downloading the Panda Software. what are your thoughts?
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Run as much as you can but most importantly run step 6 and attach those logs.
     
  5. volkmt

    volkmt Private E-2

    Ok I have done steps 1-6 and I will attach the hijackthis log after I run it shortly. I still have this file that comes up as an Adware.Maxifiles other than that my computer seems to have gotten rid of a majority of the viruses. Thank you so far.
     
  6. volkmt

    volkmt Private E-2

    I believe this is the correct way to attach the hijackthis log file. Thank you in advance.
     
    Last edited: Aug 2, 2006
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You must relocate your HJT and also rename your HJT. You must also close ALL browsers before running HJT.
    If you ran steps 1-6 then I need your logs from step 6.
     
  8. volkmt

    volkmt Private E-2

    I apologize for posting incorectly the last time. I have the logs and I should be able to have them readable for you this time. again im sorry about that.

    Along with the Adware.Maxifiles, I now have a Trojan-Downloader.Win32.Zlob.gi and other Trojan files appearing on my computer. :eek:
     
    Last edited: Jan 28, 2007
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download LSP-Fix

    After download is complete, Run LSP-Fix

    Check the Box labeled "I know what I'm doing" and then click on the winsflt.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move winsflt.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    (Note: If the file winsflt.dll is already in the remove section, then just click FINISH.)

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic 6\delay.exe
    O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:


    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and let me know how things are running.
     
  10. volkmt

    volkmt Private E-2

    Hey thank you very much for your help. It has been a couple days since I did those last few steps you said I should do. As far as I can tell my computer seems to be doing fine. Thanks again :) Mitch
     
  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds