many many virii

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by deadmeat08, Apr 22, 2006.

  1. deadmeat08

    deadmeat08 Private E-2

    well, i've been trying to clean up my parents computer the past couple days. its being reamed by malware. i went through your "READ & RUN ME FIRST Before Asking for Support" instructions last night. every program found at least one piece of naughty software. and, of course, Panda Active scan found more. theres also an annoying little program that pops up out of the system tray to tell me that i'm infected and that i should click "here" for antivirus software to remove it.... right....
    heres a link to a screen shot of the popup, in case it helps at all: here

    i've included the logs generated by Panda ActiveScan, BitDefender, CounterSpy, and HijackThis.

    i'm to the point where i'm not sure where to go from here. any and all help anyone can give me would be greatly appreciated.

    thanks,
    -travis
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. deadmeat08

    deadmeat08 Private E-2

    alright. so, i went through the smitRem procedure. i only came across two files on the lists: C:\WINDOWS\system32\xenadot.dll and C:\WINDOWS\SYSTEM32\interf.tlb.
    i was able to delete interf.tlb, but not able to delete xenadot.dll. it said that the file was possibly in use.

    i have attached my smitfiles.txt

    thanks for the help,

    -travis
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have the latest form of SpywareQuake and will need to follow a slightly different procedure that also uses SmitRem. Run the below and attach the new smitfiles.txt log

    SpywareQuake Removal Procedure

    How are things working now? Were you able to rename and then later delete the xenadot.dll file?
     
  5. deadmeat08

    deadmeat08 Private E-2

    done and done.
    i've attached the smitfiles.txt incase you can still tell if something is there. but, as far as i can tell, the symptoms have cleared, and things seem to be back to normal again.
    thank you very very much. you've helped me so much.
    it is much appreciated.

    thank you

    -travis
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds