Supermwindow

Discussion in 'Malware Help (A Specialist Will Reply)' started by selinebacker42, Jul 6, 2008.

  1. selinebacker42

    selinebacker42 Private E-2

    ive getting really aggrivated with my computer because it keeps freezing up when i get on the internet. i look at my processes and explorer is using up alot of memory. i really would like some help on this please, i looked at the other forums and it didnt really solve my problem. here is my hijackthis log.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. selinebacker42

    selinebacker42 Private E-2

    yeah ive done that too. i forgot to mention that.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but no you have not. If you did and still have problems, you should be attach the 4 logs that were requested at the end of the procedure. Based on your first log, you definitely have not even installed and run what we requested. If you want our help then please follow the instructions already given.
     
  5. selinebacker42

    selinebacker42 Private E-2

    ok. so combofix wouldnt work. it said it expird evertime i tried to install it. but here are the rest of the logs.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you need to make sure you download the current version from the link in the READ & RUN ME. Try downloadling the current version and then try running it. Based on your other logs, we will probably need to use ComboFix to manually removed some malware.

    You also need to uninstall the below as requested in step 1 of the READ & RUN ME:
    Java 2 Runtime Environment, SE v1.4.2
    Viewpoint Media Player


    Is your copy of Spyware Doctor a paid version that actually removes/fixes problems?
     
  7. selinebacker42

    selinebacker42 Private E-2

    ok so i removed viewpoint and java runtime. and spyware doctor is expried. and i just tried to run combofix again...and it says "the current date is saturday, 7/10/08. please download a newer version". and im downloading it from the read and run me first thing.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on the ComboFix icon on your Desktop and select Properties.

    Then tell me what you see for Size. Give both the MB and bytes information.
     
  9. selinebacker42

    selinebacker42 Private E-2

    2.48 mb...2,609,562 bytes..
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is the correct size.

    What is the date on your computer set to? I bet it is August 9, 2008 or August 10, 2008
     
  11. selinebacker42

    selinebacker42 Private E-2

    ahhh thank you very much :-D that was it. heres my log
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but you did not rename it and run it as requested. You don't need to run it again, but we will be using it later. Becareful to follow instructions properly.

    Now that ComboFix was run and it remove a load of malware files, we need to get a new MGlogs.zip file to see what remains for us to do.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  13. selinebacker42

    selinebacker42 Private E-2

    ok. im really sorry about messing up on the directions. i know you guys have a lot on hand. heres the attachment. im tryin the best i can.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay begin by uninstalling your expired copy of Spyware Doctor immediately.


    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
    O20 - AppInit_DLLs: vohjlcvp.dll


    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. selinebacker42

    selinebacker42 Private E-2

    i got to the fixme.reg part and it asked to merge, but gives me this error message: cannot import fixme.reg. not all data was successfully written to the registry. some keys are open by the system or processes. should i continue you without that?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes after I see the new logs, we will know what work and what did not.
     
  17. selinebacker42

    selinebacker42 Private E-2

    ok, here it is.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps: ​
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. selinebacker42

    selinebacker42 Private E-2

    ok THANK YOU SO MUCH. everything is normal. what about spybot do i uninstall?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    See step 9!;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds