Winfixer and Look2me found among others

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Wingman77, Jan 18, 2006.

  1. Wingman77

    Wingman77 Private E-2

    Hey,
    Thanks for posting such helpfull information. I have followed the steps in the Do this first thread and the special removal threads. I know that some items were found and am not sure if I am clean or not. Panda virus scan found something and I'm not sure if it is gone or not. I know I was getting a winfix popup prior to running through this gauntlet of programs in the two threads. I will post my HJT and L2m logfiles.
    Thanks for your help
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post the required logs from step 6 of the READ & RUN ME.

    Are you still having any malware problems?
     
  3. Wingman77

    Wingman77 Private E-2

    Here is my bitdefender info. I tried to run Panda a second tiime but it will not start running. I'm going to continue to try to get it to work. It ran the first time I tried to get it going and I saved the file but can't seem to find it now.

    Thanks
     

    Attached Files:

  4. Wingman77

    Wingman77 Private E-2

    I think I just found my panda log saved under administrator file. Here it is.
    Thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log does not really show any malware. Just a few items to fix.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and do not reboot if it asks you to do so. We will reboot later.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    After clicking Fix, exit HJT.

    Run Windows Explorer and find the below files and delete them (if found):
    C:\WINDOWS\system32\pmkjj.dll
    C:\WINDOWS\system32\jjkmp.ini
    C:\WINDOWS\system32\jjkmp.ini2
    C:\WINDOWS\system32\jjkmp.dat
    C:\WINDOWS\system32\jjkmp.tmp
    C:\WINDOWS\system32\Tools\Restart.exe

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot your PC and attach a new HJT log.

    How things are working now.
     
  6. Wingman77

    Wingman77 Private E-2

    Thanks for your help with this. Here's the file.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your clean! How is everything running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds