![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
ive tried the past "read me and run first "posts. and tried all those tests, but my problem stil persists.
theres are so many popups.! i was wondering if i should do a system recovery. but ive done a lot of those in the past 2 months.. like 3-4. so. any other possible ways? i dont wanna do "hi-jack this" unless i have to! thankss! reply.asap. dads getting mad at the pop ups ![]() Last edited by romy; 05-14-07 at 16:47.. Reason: tagasauras is the name of the specific malware i cant remove.. |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
herES my hijack this log..
does it help? |
|
#3
|
|||
|
|||
|
heres my SPYBOT report..
|
|
#4
|
||||
|
||||
|
Welcome to Majorgeeks!
Quote:
Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
Downloading, Installing, and Running HijackThis Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
heres my CounterSpy results
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
You did not allow CounterSpy to fix what it found. There is no sense in running the scans unless you fix what they find. Run it again and Quarantine or Delete what it finds. Attach a NEW log.
Then after you attach the 5 other requested logs, we can get started.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
here are the other 2.. bdscan
and the panda.. also. the getrunkey... and yea i will run the counterspy scan again sorry! EDIT: THE newfiles.txt is in a new thread..as well as the counterspy.results. thanks Last edited by romy; 05-15-07 at 22:25.. |
|
#8
|
|||
|
|||
|
i have to post a new thread..since im only allowed 3 attachments..
this is my newfiles.txt and counterspy scan results..ill attach as soon as its done scanning. ty! |
|
#9
|
||||
|
||||
|
No you do not need to start a new thread!!! You just need to add another message in the same thread! Please remember that.
I'm merging this back to your original thread. You did not attach the new log from CounterSpy after fixing what it found! You also forgot to attach the last requested log which is HijackThis. Your original log was obtained before the other scans were run and may not be the same anymore. Please attach a new HJT log. You also need to do the below which was requested at the beginning of step 6 in the READ ME. Uninstall the below old versions of software: Java 2 Runtime Environment, SE v1.4.2_03 Make sure you reboot after uninstalling the above! After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
||||
|
||||
|
I also noticed signs of a Deluxe Communications infection! Please run the below too:
Do not mouseclick combofix's window while it is running. That may cause it to stall.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
counterspy wasnt finsih scanning so here it is
sry |
|
#12
|
|||
|
|||
|
heres the hijack thiss
and the combofix.txt |
|
#13
|
||||
|
||||
|
You still do not have HijackThis.exe renamed to analyse.exe as requested in the READ ME and as specified in message # 4. Please rename it now, but do not attach a new log yet!
You will find that things will go a lot faster and smoother if you take care to follow instructions properly and completely the first time. By the time you reply to this message, we will be at 14 messages and this should not have taken more than 4 to be at this point. Start by downloading a tool we will need - Pocket KillBox Save it to its own folder somewhere that you will be able to locate it later. Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes. C:\WINDOWS\sys010746796011.exe After killing all the above processes, click Back. Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sys010746796011] C:\WINDOWS\sys010746796011.exe After clicking Fix, exit HJT. Now run Pocket Killbox by doubleclicking on killbox.exe
Select:
C:\Documents and Settings\HP_Administrator\Application Data\Dxcknwrd.dll C:\WINDOWS\Downloaded Program Files\SysInfo.dll C:\WINDOWS\Downloaded Program Files\sysinfo.inf C:\WINDOWS\Downloaded Program Files\unagiuninst.exe C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf C:\WINDOWS\casinom.exe C:\WINDOWS\invupdi.exe C:\WINDOWS\sys010746796011.exe
If Killbox does not reboot just reboot your PC yourself. Now attach the below new logs and tell me how the above steps went.
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#14
|
|||
|
|||
|
im sorry for not following ur steps correctly the first time.
Quote:
but i continued with ur other steps. here are the logs u requested! thanks so much :] also im not getting any popups..so far.. i think its working! :] |
|
#15
|
||||
|
||||
|
Did you receieve a the Pending Operations error message I mentioned when deleting files with Killbox! It did not delete them successfully. Did you use Delete on Reboot as requested?
Boot into safe mode and run Windows Explorer (right click Start and select Explore). Then navigate to the below files and right click on them and delete them: C:\WINDOWS\casinom.exe C:\WINDOWS\invupdi.exe C:\WINDOWS\sys010746796011.exe Then reboot in normal mode. It appears that you did not install the new Sun Java version as I requested in message # 9. Install the current version of Sun Java now from: Sun Java Runtime Environment Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall: C:\Documents and Settings\All Users\Application Data\Sunbelt Software C:\Program Files\Sunbelt Software Now get a log from ShowNew and attach it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
no i didnt receive the pending operations error mesage.
and yes i checked marked "delete on reboot" and yes i did download the sunjava u requested but i will re-download itt and i will post the ShowNew in just a few minutes Last edited by romy; 05-16-07 at 18:58.. Reason: posted shownew |
|
#17
|
||||
|
||||
|
Quote:
Your malwar files are gone now. After getting Sun Java reinstalled. Move on to the final steps below. If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#18
|
|||
|
|||
|
hey
thank u so much for the helpp :] i performed all the steps u told me. but some of the folders u asked me to delete were like already deleted.. so i didnt find emm but yea thanks ! |
|
#19
|
|||
|
|||
|
when i run spybot search and destroy
im still getting that i have the issues (tegasauras..and such) i press "fix selected issues" but im still getting them.. and the popups i get one every like half hour or so. |
|
#20
|
||||
|
||||
|
Attach a log from Spybot!
What are the popups for? Is there a URL indicated? Do they occur when no browsers are open? Attach a new HJT log?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Can't remove popups | pschimme | Malware Removal | 1 | 02-24-07 17:39 |
| First post - please help me remove popups | Van Damme | Malware Removal | 8 | 08-17-06 07:19 |
| popups and malware that I can't seem to remove | betenoire | Malware Removal | 2 | 06-19-06 03:04 |
| Unable to remove Malware causing web popups | emzyme | Malware Removal | 9 | 02-12-06 17:40 |
| Excessive popups associated with IE, not with immedeate web page | blaz0033 | Malware Removal | 5 | 10-28-04 01:22 |