sticky malware- restricts hjt and related

Discussion in 'Malware Help (A Specialist Will Reply)' started by brilliantjeni, Apr 5, 2007.

  1. brilliantjeni

    brilliantjeni Private E-2

    Fiance downloaded rotten torrent 5 days ago and then tried to fix it by downloading the evil spylock, not knowing it was scamware. Since, I've scanned (norton, spybot, kaspersky, panda activescan, spyhunter) and found spylock, spylocked, zlob, trojan js, pettrap, tracker trojan, agentczz, and a few other nasties. My biggest challenge however, is that whatever infection is left, it's restricting my access to certain websites and will not let me run hjt, combofix, windelf kil, and several others. Websites restricted are ones that include the words "sp yware" and "hj this" and "windel fkil," etc- just closes the browser immediately. I was able to run silentrunner and get a log if that helps? I also have the scan from panda activescan, and from smitfraud.

    Any help is soooooo much appreciated!

    Smitfraud:

    Edit by chaslang! Inline log attached.
     

    Attached Files:

    Last edited by a moderator: Apr 6, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do not post any logs inline! Read and follow the sticky threads!

    You appear to have only run one part of SmitFraudFix. Did you run the actual fix which is option 2.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Also delete the below file:
    C:\WINDOWS\system32\hjthis101.dll

    This file may be hidden which means you need follow the directios here: How to view hidden, system files & folders!

    Please do not start multiple threads for the same problem! Your other thread has been deleted.
     
  3. brilliantjeni

    brilliantjeni Private E-2

    As I said in my previous post, my reason for the duplicate posting, was because the infection would not let me access the previous one. Nor, will it let me access the "sticky threads" section you reference. The browser immediately closes. So please accept my apologies for not following instructions.

    As for your directions- can I run this in normal mode? Safe Mode freezes on startup. Thank you!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That does not really make much sense. I find it unlikely that the infection would know the difference between two threads.

    Yes but it may not work in normal boot mode.


    Try following the below two procedures which are just a part of the READ ME.
    Did you renamed hijackthis.exe to analyse.exe before trying to run it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds