![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
red circle with white X appears in sys tray. Continues to install Winreanimator sofware, which appears to be fake spyware removal. I followed all instructions on what to do first. I cannot run combofix, spybot, or superantispyware. when I try to run these programs, absolutly nothing happens. No error message or anything. I was able to run MGtools and have attached log.
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
See if you can get started by running the below procedure. Attach the log if you can run it.
Virtumonde aka Trojan Vundo Removal Is your copy of Spyware Doctor a paid version or free trial? If free, uninstall it now. Download and run FindAWF by noahdfear.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
Thank you for the quick reply!
vundofix will also not run. I uninstalled trial version of spyware doctor. |
|
#4
|
||||
|
||||
|
Your PC is very badly infected. This is due to not having proper protection installed. This MUST BE corrected after we remove all of your malware.
Double-click the FindAWF icon.
Quote:
Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {393C2547-B2AB-422C-87AF-385238C73416} - C:\WINDOWS\system32\hggggef.dll O2 - BHO: (no name) - {3F5767BD-784E-41C9-90EF-1E6B67AC09B0} - C:\WINDOWS\system32\vturo.dll O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1535.exe 61A847B5BBF7281337983D466188719AB689201522886B092CBD44BD8689220221DD3257 O4 - HKLM\..\Run: [WinReanimator] "C:\Program Files\WinReanimator\WinReanimator.exe" /hide O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O20 - AppInit_DLLs: cru629.dat O20 - Winlogon Notify: hggggef - C:\WINDOWS\SYSTEM32\hggggef.dll NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue. After clicking Fix, exit HJT. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
Quote:
Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day). C:\WINDOWS\Temp C:\Documents and Settings\administrator.MIBANKERS\Local Settings\Temp Now run Ccleaner! Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger. Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
Again, thank you for responding.
Since my last post, I ran combofix, spybot, and superantispyware. I did this by renaming the executables to "1234.exe" or smilar. I still followed all your instructions and am attaching all logs. The braviax and winreanimator are not problems anymore. There is still some sort of spyware constantly trying to redirect and/or open ie to ad sites. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
You don't need to attach the hijackthis.log file. It is already part of MGlogs.zip You said you ran ComboFix but based on your logs it does not look like it was run because thousands of bad files showing in your log would have been removed by ComboFix. Also you did not attach a log from it. Please run it now from the command prompt with the /killall option as instructed in the READ ME. Attach a log when you finish.
Double-click the FindAWF icon.
Quote:
Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: IE - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Program Files\WinBudget\bin\matrix.dll O2 - BHO: (no name) - {6B6A55A9-72B1-4B03-BB0B-9DD746C4E396} - C:\Program Files\.\laxik777444.dll O2 - BHO: 0 - {C93DA5BA-C54F-4302-EAB3-3B8A066469DD} - C:\Program Files\MSN\qulaf.dll O4 - HKLM\..\Run: [mehebor] C:\Program Files\microsoft frontpage\mehebor77798.exe O4 - HKLM\..\Run: [braviax] braviax.exe O4 - HKLM\..\Run: [BM755c313f] Rundll32.exe "C:\WINDOWS\system32\wxmmdecq.dll",s O4 - HKCU\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe O4 - HKCU\..\Run: [JavaCore] C:\Program Files\JavaCore\JavaCore.exe O4 - HKCU\..\Run: [Tlda] "C:\DOCUME~1\ADMINI~1.MIB\MYDOCU~1\FNTS~1\chkntfs.exe" -vt yazb O4 - HKCU\..\Run: [Sfnf] "C:\Program Files\Common Files\?asks\w?auboot.exe" O20 - Winlogon Notify: dvdfscte - dvdfscte.dll (file missing) O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing) After clicking Fix, exit HJT. Now download The Avenger by Swandog46, and save it to your Desktop.
Quote:
Now run Ccleaner! Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Red Circle w/ White X -- braviax.exe -- System Defender | tlrich | Malware Removal | 2 | 02-13-08 21:27 |
| malware help please | newbielee | Malware Removal | 3 | 01-06-08 18:04 |
| Malware problem not fixed with Malware Removal instructions | aagarwal584 | Malware Removal | 9 | 12-27-07 01:19 |
| ran all the steps in "Read & Run Me First malware removal guide," still have malware | aarond95 | Malware Removal | 10 | 10-24-07 23:40 |
| malware? | iainb | Malware Removal | 1 | 10-09-07 20:19 |