1. ashpash@i12.com

    ashpash@i12.com Private E-2

    There is no sign of kpwn1.exe in the HJT log....which is good news yeah?? Still worried about that encrypted file although it doesnt change name at all.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah those lpt type named files are another symptom of Gromozon. It is strange that it was not found the first time. I would run the tool one more time to see if it comes up clean! Did this file really get deleted? The second scan should tell us!

    Can you see this file? It may only show as PXR2.tmp. If you can see it, try deleting it. If you cannot see it try installing and using the below tool and see if you can find it:

    ExplorerXP

    If so, see if it can delete the file. If not, see if you can delete the whole Temp folder. If the Temp folder does delete, you must create a new Temp folder (right away) so that you still have the below:

    C:\Documents and Settings\Administrator\Local Settings\Temp

    If the above options do not work to delete the file, we could try a trick from a command prompt window but I need to know how the file name actually appears. If it is just PXR2.tmp in the C:\Documents and Settings\Administrator\Local Settings\Temp folder, you would have to open a command prompt window and change to that folder and then enter the below command

    del \\.\PXR2.tmp

    There is a space between del and the first \ and then no more spaces! Ignore the underline! The editor here in the forum automatically adds that because it thinks this is a link!


    If you still can not delete the file, you may have no rights to do it.

    In XP Professional Edition you can right click on it and select Properties. From the Protection Windows you can grant to your user all required rights on that file. If you can't see that option unselect disable simplified sharing from Folder Option.

    In XP Home Edition you should see the "Protection" tab from the safe mode. You can also use some tools of Resource Kit such as ntrights.exe, cacls.exe e takeown.exe.


    Another possible useful tool which may help with removal of the additonal files isDarkSpy Anti-Rootkit 1.0.5 Test Version . You need a copy of WinRaR (like WinZip) to extract the files.
     
    Last edited: Sep 16, 2006
  3. ashpash@i12.com

    ashpash@i12.com Private E-2

    Ran Gromozon again and attached the log.......love it, love it!!! I couldn't delete that file any way other than ExplorerXP. When it was sent to the delete bin I used ExplorerXP again to fully delete it. Great!!

    I double checked the uninstall programs in CrapCleaner and LinkOptimizer is listed although there's nothing in program files for this, It's listed in add/remove programs also. Should this be there??

    Should I flush System Resore now?
     
  4. ashpash@i12.com

    ashpash@i12.com Private E-2

    Sorry....forgot to attach log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use CCleaner's ability to uninstall the LinkOptimizer? If not, give it a try. When you get it removed, yes flush System Restore and then move on to the below:


    How to Protect yourself from malware!
     
  6. ashpash@i12.com

    ashpash@i12.com Private E-2

    I have 3 different ways to uninstall this LinkOptimizer, I have tried CrapCleaner, Your Uninstaller2006 and Add/Remove programs. Everytime it opens up IE (Which is not the default browser) with a button to press. I have attached a screenshot of the page. I do not want to click on uninstall as I have a feeling it will infect me with something. Any ideas?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. ashpash@i12.com

    ashpash@i12.com Private E-2

    Here ya go.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay try the below and let me know the results after a reboot!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  10. ashpash@i12.com

    ashpash@i12.com Private E-2

    This seems to have done the trick, thanks. I have flushed my System Restore, hope this was ok.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that's fine! Make sure you work thru the How to protect thread!

    I'm happy we got this fixed and that you did not have to goto a PC repair shop and reinstall your OS.
     
    Last edited: Sep 24, 2006
  12. ashpash@i12.com

    ashpash@i12.com Private E-2

    I will certainly work through that list. Cant thank you enough, I have saved Just over $300.00 but I still need to get my OS sorted at some stage.

    Thanks again for your patience and perseverance in helping me with this PITA, I would love to return the favour but I think you have this under control ;)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I'm happy I could help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds