![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi everyone!
My com was very messed up when i detected my com was infected by 2fiji.com virus. Fortunately i managed to remove it (thank you guys oh so much). Now, i've cleaned up my com but for some unknown reason (unknown to me at least) i am unable to connect to a few sites. I've run combofix and MGtools and my logs are attached. Any assistance is gladly and very much appreciated! |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Let's start with this:
Please use add/remove programs to uninstall: J2SE Runtime Environment 5.0 Update 6" ava(TM) 6 Update 11" Java(TM) 6 Update 7 Now let's use ComboFix to remove a bunch of malware files. * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it! o If it is not on your Desktop, the below will not work. * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ): Code:
KILLALL::
Drivers::
cpzsjsz
NetSvc::
cpzsjsz
File::
c:\windows\system32\xzxemnpv.dll
Registry::
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cpzsjsz]
"ServiceDll"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1108db1a-bb1f-11dd-86f7-001f3b4d211b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38f4cbc8-d16f-11dd-8763-001f3b4d211b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5bc8eb94-b0bb-11dd-86af-001f3b4d211b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ffd2421c-d0ab-11dd-875e-001f3b4d211b}]
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing! * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop. If it asks you to overide the prvevious file with the same name, click YES. * Now use your mouse to drag CFscript.txt on top of ComboFix.exe * Follow the prompts. * When it finishes, a log will be produced named c:\combofix.txt * I will ask for this log below Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. Now download and install: Java Runtime 6 Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#3
|
|||
|
|||
|
Hi Timw,
Thank you so much for your reply. I have followed the instructions step by step and attached are the logs. Please advise. Thank you. |
|
#4
|
||||
|
||||
|
Still one more thing that needs to die:
* Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it! o If it is not on your Desktop, the below will not work. * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ): Code:
KILLALL::
RegLockDel::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ffd2421d-d0ab-11dd-875e-001f3b4d211b}]
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing! * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop. If it asks you to overide the prvevious file with the same name, click YES. * Now use your mouse to drag CFscript.txt on top of ComboFix.exe * Follow the prompts. * When it finishes, a log will be produced named c:\combofix.txt * I will ask for this log below Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. Attach that log and we'll see if we can send you on your way. ![]()
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#5
|
|||
|
|||
|
Hi timw,
Attached is the file. Currently i can already connect to some of the sites i originally couldn't connect to (microsoft, anti-viral) so it looks like i'm almost done!!! Please advise. Thank you. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Looks good. If you are not having any other malware problems, it is time to do our final steps:
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#7
|
|||
|
|||
|
Hi TimW,
I've completed the steps and have an anti virus software installed. Recently, i've managed to find out where the 2fiji.com virus came from but i couldn't seem to detect it with Malwarebytes's anti malware program. Is it actually a malware? |
|
#8
|
||||
|
||||
|
Yes it is and often affects your desktop or may drop into other folders.
Are you having issues with this? If so, please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Attach the C:\MGLogs.zip
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| cannot connect after malware removal | jangoer | Networking | 10 | 11-15-11 08:23 |
| Partway through XP malware removal process, many programs are unable to fetch updates | Ozzard | Malware Removal | 1 | 04-04-09 18:34 |
| Cannot connect to https sites after virus removal | det4100 | Malware Removal | 6 | 03-10-09 13:59 |
| Unable to run Malware removal proggys | Gensuknives | Malware Removal | 2 | 05-11-08 20:56 |
| A lot of adult sites being redirected...followed malware removal steps. Still problem | Phishie | Malware Removal | 5 | 02-09-07 12:55 |