![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello,
I have pum.hijack.taskmanager and pum.hijack.regedit virus on my system which just does not seem to go away. Cold delete the same a couple of times, howvere they r back again after restart. Pls help. I use malware bytes anti malware tool to delete the virus. Thx |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to MajorGeeks, Reema
Please read ALL of this message including the notes before doing anything. Please follow the instructions in the below link: READ & RUN ME FIRST. Malware Removal Guide and then attach the requested logs to your next reply when you finish these instructions.
__________________
"Education never ends, Watson.... It is a series of lessons, with the greatest for the last." Free malware removal from MajorGeeks Support MajorGeeks! |
|
#3
|
|||
|
|||
|
Hi,
The virus is still there after running all the steps provided in the link. Basically my task manager and regedit both are disabled. ComboFix.txt was not created. My system blanked out for like 3-4 hrs after which it just shut down. I did not run again. Also my system crashed when running MGtools since it could not get the data it was expecting. regedit would not work(cause of the pum.hijack virus) and hence the data expected by MGTools could not be found. I guess that might have just caused the crash!!The logs were created though. Lemme know how I ca proceed. Thx for ur help!!! ![]() Reema |
|
#4
|
||||
|
||||
|
Please download RogueKiller to your desktop.
Then download OTL by Old Timer to your desktop.
*Are you having any other problems besides Task Manager and Regedit not running?
__________________
"Education never ends, Watson.... It is a series of lessons, with the greatest for the last." Free malware removal from MajorGeeks Support MajorGeeks! |
|
#5
|
|||
|
|||
|
Hey,
Attaching the 2nd lot of files. Besides tskmgr ad regedit being disabled, the system becomes very very slow and just hangs at certain points, even if I am not running anythig at all! Thx |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
You're welcome, Reema
Please move OTL.exe directly to your desktop, not here: C:\Documents and Settings\pari\My Documents\OTL.exe Please attach these logs from running the R & R ME FIRST procedure: Quote:
Uninstall: BabylonToolbar Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator) Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts. Copy the text in the code box below and paste it into the text-field.Code:
:otl
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | System | Stopped] -- system32\DRIVERS\tdx.sys -- (tdx)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\pari\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\phsjun.sys -- (asc3360pr)
IE - HKU\S-1-5-21-790525478-1580818891-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=111808&tt=060612_5_&babsrc=HP_ss&mntrId=30576304000000000000001aa0ff4b2b
IE - HKU\S-1-5-21-790525478-1580818891-725345543-1003\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-790525478-1580818891-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-790525478-1580818891-725345543-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=111808&tt=060612_5_&babsrc=SP_ss&mntrId=30576304000000000000001aa0ff4b2b
IE - HKU\S-1-5-21-790525478-1580818891-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O4 - HKLM..\Run: [Browser companion helper] C:\Program Files\BrowserCompanion\BCHelper.exe /T=3 /CHI=gmdfpnpdmnjaffhcdbobdjpolhpacaem File not found
O7 - HKU\S-1-5-21-790525478-1580818891-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-790525478-1580818891-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-790525478-1580818891-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-790525478-1580818891-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-790525478-1580818891-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\S-1-5-21-790525478-1580818891-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\pari\My Documents\Downloads\*.tmp files -> C:\Documents and Settings\pari\My Documents\Downloads\*.tmp -> ]
:commands
[purity]
[emptytemp]
[resethosts]
button.If the fix needed a reboot please do it. Click the OK button (upon reboot). When OTL is finished, Notepad will open. Close Notepad. A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run. Attach this log to your next message. (How to attach) * Can you now use Task Manager, Regedit? Are you able to run MGTools.exe now?
__________________
"Education never ends, Watson.... It is a series of lessons, with the greatest for the last." Free malware removal from MajorGeeks Support MajorGeeks! Last edited by dr.moriarty; 06-13-12 at 11:34.. Reason: add questions |
|
#7
|
|||
|
|||
|
Hi,
OTL.exe doesn't seem to work. ![]() My system just crashes and then restarts. This is immediately after running OTL.exe. Happens everytime I run OTL.Attaching the remaining logs you asked for. Thx. |
|
#8
|
||||
|
||||
|
Hello Reema
![]() dr.moriarty is out for a little while so I will help you in the meantime. __ Do you have your Windows XP SP2 disc? Let me know this first as it can potentially change which route we take next. Thanks. |
|
#9
|
|||
|
|||
|
Hey there,
Yes I do have the cd. PLs help quick..I have a new problem at hand now, my system shuts dow every few minutes now. The problem just seems to be getting worse. ![]() Thx |
|
#10
|
||||
|
||||
Please delete your old copy of ComboFix and download the latest copy here and run an additional scan.Attach the latest ComboFix.txt when finished. (How to attach) |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Hey,
It ran this time!! Yay!! Attaching log. Thx again!! |
|
#12
|
||||
|
||||
Delete items detected by RogueKiller.Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator) When it opens, press the Scan button After the scan has completed, press the Delete button. When it is finished, there will be a log on your desktop called: RKreport[3].txt Attach RKreport[3].txt to your next message. (How to attach) Run the following customized scan using OTL by OldTimer.
|
|
#13
|
|||
|
|||
|
Hey,
Pls find files attached. Reema |
|
#14
|
||||
|
||||
Fixing items using ComboFixMake sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it. If it is not on your desktop, the below will not work. Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts. Open Notepad and copy/paste the text in the below code box into Notepad: Code:
KillAll:: ClearJavaCache:: Collect::[4] C:\WINDOWS\system32\drivers\phsjun.sys DirLook:: C:\rei C:\_OTL Driver:: WinDefend asc3360pr File:: c:\windows\AegisP.inf G:\Autorun.inf FileLook:: C:\WINDOWS\system32\drivers\phsjun.sys Folder:: C:\Documents and Settings\pari\Application Data\Babylon C:\Documents and Settings\All Users\Application Data\Babylon Registry:: [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System] "DisableRegistryTools"=dword:00000000 "DisableTaskMgr"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"=dword:00000000 "DisableTaskMgr"=dword:00000000 "EnableLUA"=dword:00000000 Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release. ![]() This will launch ComboFix. Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. Allow ComboFix to update itself if prompted. When ComboFix finishes, a log will be produced at C:\ComboFix.txt Attach this log to your next message. (How to attach) |
|
#15
|
|||
|
|||
|
Hi,
Do I use the new copy of Combofix you posted yesterday or the one before that? Thx |
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
We always want to use the latest version of ComboFix. ComboFix may have updated since you downloaded it last time. Allow it to update.
|
![]() |
| Tags |
| disabled, hijack, taskmanager, virus |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Hijack virus...new to forum | CyranodeBergerac | Malware Removal | 3 | 10-23-10 20:35 |
| hijack virus clean? | bradjay | Malware Removal | 3 | 09-24-10 10:11 |
| Have a DNS virus. Looking for help with HiJack This Log | Rugbymuffin | Malware Removal | 5 | 01-23-09 11:39 |
| issue with virus/needs help with hijack this | roastm | Malware Removal | 1 | 02-06-06 08:17 |
| Need help with hijack and/or virus | tbo | Malware Removal | 3 | 11-13-05 23:24 |