Need Help With HijackThis

Discussion in 'Malware Help (A Specialist Will Reply)' started by petie42pu, Jul 13, 2008.

  1. petie42pu

    petie42pu Private E-2

    So I just installed and ran hijackthis becaue I cannot seem to get rid of a couple of adware problems no matter what I do. I have reinstalled my OS a few times, used S&D, etc.... So now I have a report from the scan and need some help in digesting it. I am pretty familiar with computer issues, but this one is too advanced me. Can someone help a gal out?
    Thanks!
     
  2. petie42pu

    petie42pu Private E-2

    I actually just read the tutorial and it was really great. But I think I still have a problem as only one of the items reported on the log looked suspicious. What else can I do to get rid of the adware/spyware that I have?
     
  3. petie42pu

    petie42pu Private E-2

    How do I get rid of spy/ad when I've done everything that I (limitedly) can?

    I actually just read the tutorial on hijackthis (which I should have done before I posted my stupid question) and it was really great. But I think I still have a problem as only one of the items reported on the log looked suspicious. What else can I do to get rid of the adware/spyware that I have other than S&D? I have reinstalled my OS and my cheesy Verizon spyware removal tool keep showing me the same problems everytime I restart my computer.
     
  4. petie42pu

    petie42pu Private E-2

    Re: How do I get rid of spy/ad when I've done everything that I (limitedly) can?

    I wanted to add a few more pieces of info regarding things I have done: 1) I disabled Windows Messenger. 2) I have uninstalled J2SE Runtime Environment 5.0 3) Have run CCleaner and 4) Eusing Reg Cleaner. (And I hope I am not violating any rules yet.)
     
  5. petie42pu

    petie42pu Private E-2

    Ran Read & Run - Here are my logs

    Attached are my logs from the read & run. Please let me know if there are additional steps I need to take to keep up my PC. Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please remain in one thread for your current malware problem. I merged the 3 threads you started back into one.

    You did not run the very first scan that was requested from SUPERAntiSpyware!

    What are your exact problems? You need to be much much more specific and tell us exactly what the problem is and where it is being found.

    Your logs are not showing any malware problems.
     
  7. petie42pu

    petie42pu Private E-2

    I am very sorry about the multiple threads. Regarding my issue I will try to be as specific as possible. After I run my anti-virus/spy/mal removers and then restart my pc, I find that if I re-run my Verizon Anti-Spyware again, I come up with errors and detections again. I have attached a text file which shows what I have removed from various scans (my most recent included).

    Additionally, I thought that I did run the SUPERAntiSpyware but apparently I did not. I have run it now according to the instructions. As it did not find any concerns in the first run, I shut down my pc and re-ran it again after restarting (as i have done with other removal tools). That run showed no errors again.

    So, I am confused as to what is truly problematic. I hope this is more fully detailed. Thank you so much!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cookies are not problems! See step 11 of the below:

    How to Protect yourself from malware!

    And koolynoody.net is just something added to your Domains registry key by Spybot to protect you. Thus your Verizon AntiSpyware program is incorrect. They are looking at the name of the site rather than looking at the value in the registry key which is set to a 4 which means it was put into the Restricted Zone to block you from going to that site.

    Also the detection of MGtools\process.exe is totally incorrect.
     
    Last edited: Jul 14, 2008
  9. petie42pu

    petie42pu Private E-2

    Logs attached for Zlob removal...still have virtumonde

    chaslang-
    Although my Read and Run logs don't show any real problems, I have still found that i have Zlob and Virtumonde. When I run S&D, I can see it going through both but it doesn't bring them up as problems. I have gone through the procedures for the Zlob removal and have attached the before and after cleaning logs. I am unsure what to do next for Virtumonde and/or continuing problems with Zlob if there are any.
    Thanks!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Logs attached for Zlob removal...still have virtumonde

    You have found it where?

    I'm not sure what you are saying, but I think you are referring to what you see at the bottom of Spybot while it is running. This is not what it is detecting. This is what it is currently scanning for. The list at the end is what is detected. Thus it sounds to me like it detected nothing.
     
  11. petie42pu

    petie42pu Private E-2

    Ok. Thank you.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Now let's cleanup from running all the tools.



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  13. petie42pu

    petie42pu Private E-2

    Thank you so much. I have completed all of these steps. Let's hope I don't do anything to screw it up!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds