About Blank Nightmare

Discussion in 'Malware Help (A Specialist Will Reply)' started by sheilab38, Nov 13, 2005.

  1. sheilab38

    sheilab38 Private E-2

    I am pretty sure I have the about blank hijacker on my computer along with several others. Can you help me. I will need really simple instructions if possible. Thanks and here is a copy of my hijack this log.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download LSP-Fix

    After download is complete, Run LSP-Fix

    Check the Box labeled "I know what I'm doing" and then click on the farlsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move farlsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    (Note: If the file farlsp.dll is already in the remove section, then just click FINISH.)

    Now run HijackThis and fix the following:
    Post a fresh HijackThis log when finished with the above.
     
  3. sheilab38

    sheilab38 Private E-2

    Okay, I think I did everything right. Here is the new log and thanks for your help.
     

    Attached Files:

  4. sheilab38

    sheilab38 Private E-2

    Oh, also the reason I didn't take out any of the iespell stuff is that is the spellcheck program I use in my job. Wanted to make you aware in case that would wipe it out. I don't want to lose it because if is for medical spell checking.
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Uninstall Spyware Cleaner this is a rogue application and affords you no real protection.

    Now scan and have HJT Fix the following:
    Post a fresh HijackThis log after you have completed the above.
     
  6. sheilab38

    sheilab38 Private E-2

    I am sorry if my last message may have offended when I said I did not delete the i.e. spell. I am not professing in any way to know what I am doing. It is just that the transcription company that I work for put that in there because it is a medical dictionary and we have to use it to check our work. I was not sure if by deleting those files if it would wipe all of it out or change my ability to use it. I was just making you aware of this. Thanks......sb
     
  7. sheilab38

    sheilab38 Private E-2

    Ok, this is my new log after deleting the last files.
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You didn't offend me. I told you to fix those lines, because IEspell appeared to be broken. If IEspell is working gine then don't worry about it.
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackThis log looks OK. How is your computer running?
     
  10. sheilab38

    sheilab38 Private E-2

    My start page is still not right and when I load it it says at the bottom "done but with errors on page". Also, I noticed today when I went into a search it looked like it flipped me over to double click, not sure.
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please run Panda Online Scan. After the scan attach the log to your next post. Also please follow the below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post all three logs as attachments
     
  12. sheilab38

    sheilab38 Private E-2

    :rolleyes: Finally I am able to get these logs back to you. Have been tied up with work all week. Hope these are what you are looking for. Thanks.
     

    Attached Files:

  13. sheilab38

    sheilab38 Private E-2

    Here is the last log.
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I need the RKFiles Tool log.
     
  15. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  16. sheilab38

    sheilab38 Private E-2

    Hi.

    I have been out of town on vacation but I am back and want to finish this up. I ran the pocket kill and deleted. I know that I am no computer whiz but when I go to Windows Explorer for the next step I cannot find these files. How on earth do I find them. I tried doing a search.
     
  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Then the files were sucessfully deleted by pocket killbox. Using WIndows Explorer to check for and delete the files is a secondary check.
     
  18. sheilab38

    sheilab38 Private E-2

    I hope that I did this all correctly. Attached is a new hijack log.
     

    Attached Files:

  19. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Do you recognize this program; C:\Program Files\Print!\print!.exe.

    Scan with HijackThis and fix teh following:
    Follow these instructions
    Running Spy Sweeper
    .

    I still need the RKFiles Tool log.

    Come back here after you have finished the above and post the Spy Sweeper and RK Files logs; along with a fresh HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds