possible pepper?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by zakrz1, Aug 19, 2004.

  1. zakrz1

    zakrz1 Private First Class

    can someone please check my log? I deleted some crap in program files (or at least I think I did...) and did a search where one post indicated it was relate dto pepper... Thanks in advance!
    Logfile of HijackThis v1.98.0
    Scan saved at 7:00:23 PM, on 8/19/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
     
    Last edited by a moderator: Aug 20, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: Per the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File > your log file file has been removed. Read the bold print again!!!!! We did not ask for your log.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    "Do not to install Hijack This to the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT"


    However you should have follow the stuff below before even thinking about using HijackThis.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal > If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. zakrz1

    zakrz1 Private First Class

    Sincerest apologies! I'll do my best to follow the rules!
    At this point,1. I keep getting an inetkeepw.dll popping up in BHODemon!? and
    2. saw something along the line of Pgate or something like that (I failed to write it down) and deleted it via control panel add/remove programs.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you run everything in the tutorials? What did they find?
    And when you do have problems or see popups or error messages (whatever) alway right down the EXACT message. That is very important. Even the order of the words matters. It make it easier when searching for info to know the exact message or the exact name of some piece of malware detected by a scan.
     
  5. zakrz1

    zakrz1 Private First Class

    I've run spybot, spyware blaster loaded, adaware, cwshredder, trendmicro, panda, virobot; cleaned all temp and cookies. Keep getting error loading C:\Program Files\.....\inetkw.dll every 5 seconds or so! I saw it come up in BHO demon and deactivated it.
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi,
    Ok, if you get an error about a program loading, the question is where is loading from? Check our admin tools section for a startup manager like this one: http://majorgeeks.com/download.php?det=4317

    If you can find this program loading, then remove it from the list in one of those programs. A Trojan scan might be a good idea as well.

    Let us know please!
     
  7. zakrz1

    zakrz1 Private First Class

    I ran the program, however all seem to be OK; Can I post my hijackthis log? Weird thing that I tried 3 times burning a .jpg CD and each time it froze up...!? Plenty of memory and CPU was way low....
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Post your log as an attachment.

    Usually this problem looks something like the below and is cleaned as described below(yours may be similar but will not necessarily be exactly the same):

    Fix this in HJT after shutting down your browsers:
    O2 - BHO: Browser - {046D6EA4-15E3-4b27-8010-45BD78A9219E} - C:\PROGRAM FILES\INTERNET KEYWORD\INETKW.DLL
    O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\INETMGR.EXE
    O4 - HKLM\..\Run: [30AGP5] C:\WINDOWS\SYSTEM\30AGP5.exe

    Reboot in safe mode and delete
    C:\PROGRAM FILES\INTERNET KEYWORD <-------- The whole directory

    So see if you can figure out your problem from the above by comparing to your log.
    It is possible the O2 line may be block on your PC because of BHO Demon.
     
  9. zakrz1

    zakrz1 Private First Class

    Cleaned up, log attached!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see one! And everything is okay now? If so, we don't need a log.
     
  11. zakrz1

    zakrz1 Private First Class

    One user can't logout until I stop the pcflashbang.exe process (doesn't sound right to me...). There is a C:\PCFlashbang directory. Log attached! Thanks!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you edit your log file? There are a load of Windows Processes not showing. Do not edit the HJT log files. Always post the whole log unless we ask for something specific. Editing out lines is not the same as running the scan after shutting down all unnecessary processes. Right now from your log I would have to wonder if Windows would even run since so much is missing.

    You also did not follow all the directions. You HijackThis version is out of date. Please download version 1.98.2 and repost a complete log using it.
     
  13. zakrz1

    zakrz1 Private First Class

    No, I did not edit it, just saved as a .txt Here's another one.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's a complete log but you still did not use HJT version 1.98.2. Please get the correct version. 1.98.0 has bugs.

    And are you saying you do not know what this is: C:\PCFlashbang
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you changing things? You log is different now. You also have now installed BHODemon? Also, SpyBot Teatimer is new too.

    You are not making it easy to work on this if you keep doing things that I'm not asking for.

    And now C:\PCFlashbang is gone!

    In fact what problem's do you have now?
     
  16. zakrz1

    zakrz1 Private First Class

    I have not changed anything! I have had BHO demon for a cople of months now. PCFlashBang directory is still there! I'll enter another log, but please believe me I am not doing anything without your expertise!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Absolutely not TRUE! Please look at the previous two logs and tell me something has not changed.

    Your last two are basically the same except this time you shut down winzip before running HijackThis. But the previous two are not the same. And the first one you said you did not edit but there was obviously stuff missing as you can see from the next two logs.

    In the first log BHODemon did not show. In the second and third it did.

    PCFlashBang is no longer in your HijackThis logs. As far a directory on your PC, I cannot see it. PCFlashBang only showed in your first log and not in the second and third.

    SpyBot Teatimer did not show in the first log but was in the second and third. So something has changed why they are in the logs. So either the first log was edited or BHODemon and Teatimer were installed or enabled after the first log was made.

    But let's drop this discussion and get on with any problems.
    If you still have a directory with PCFlashBang in it, just delete it.
    Are there any other problems?
     
  18. zakrz1

    zakrz1 Private First Class

    PCFlashBang deleted; all looks Ok now! Thanks!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! Your welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds