BoonPie MalWare removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dobbie, Mar 17, 2006.

  1. Dobbie

    Dobbie Private E-2

    I have performed all required steps prior to running HIJaak This. I have ran CCleaner, ADAware, SpyBot Search and Destroy and SpyKill Deluxe. Also I have rescanned the system and have removed the 1 cookie that was found and it is no longer on my system....

    I keep getting the "BoonPie" infection. What mal ware am I suppose to remove to get rid of this "BoonPie"???:eek:

    Also I have noticed that there are some "file not found" messages in the registry..... Can I safely remove these lines of code from the registry safely???

    I am attaching the required files / logs and the HiJaakThis log.

    Again, I thank you for anyhelp you can provide....:)

    Any Help you can provide is greatly appreciated....


    System Info:
    MS XP Pro (Windows Media Edition) w/SP2
    Internet Explorer 6.0.2900.2180

    CPU: AMD 2066 MHz (10x207)
    System Memory: 1024
    BIOS Award Modular 10/27/05
    Mother Board: GA-K8NF-9 F9
    CPU ID: AMD Athlon 64 Processor 3200+

    Printer: HP 2410 AIO Photosmart

    Video Adapter: NVIDIA GeForce 6200 TurboCache (128 MB)

    Monitor: Sync Master 198T/910T Sync Master Magic CX901T

    Audio Adapter AC'97 [NoDB]

    Disk Drives:
    Maxtor One Touch II (firewire)
    WDC WD16
    WDC WD20
    WDC WD800
    ATAPI 52X CDROM (52X CD-ROM)
    AXV CD/DVD-ROM SCSI CdROM Device (Virtual DVD-ROM)
    DVDRW 16X16X

    Memory:
    Used 509MB
    Free 513MB

    SWAP Space:
    Total: 2461MB
    Used: 509MB
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not attach the two logs from step 6 nor your HJT log from step 7. Did you run ALL steps in the READ ME. You did not mention a few things like MS Windows Defender and Malicious Software Removal Tool or the online scanners from step 6. Do not attach a HijackThis log if all steps have not been run.

    I don't know what you are referring to about file not found messages in your registry but you should not be playing in the registry unless you are an expert on your PC.
     
  3. Dobbie

    Dobbie Private E-2

    I am sorry i thought I had already attached all of the required logs but I apparently blew it and did not send... for this Im apoligizing...... I will attach to this reply . I will attach the Bitdefender and panda active scan logs ...and the hijaak log.

    Also I did run the MS malicious software removal tool... it came up negative
    Also I did run MS Windows defender
    Also I did run CCleaner
    Also I did run Ad-Aware...
    Also I did run Spy Bot Search and destroy and Ignored products ...
    Also I did run Spy-Kill Deluxe and killed i cookie
    Also I have and Ran Nortons AV and came up clean

    Attached:

    BitDefender Online Scanner - Real Time Virus ReportBitDefender Online
    Scanner - Real Time Virus Report
    Generated at: Thu, Mar 16, 2006 - 21:17:17

    Activescan.txt is attached....

    Logfile of HijackThis v1.99.1
    Scan saved at 6:40:28 AM, on 3/17/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) ... attached...

    I hope the hijaak log gets there... there was a red X in the "attached Files" area next to the hijaak log entry...

    I thank you for the rapid response you have already provided........
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are referring to a Spy-Kill Deluxe which is by the same company as Spy-Kill or another company who had SpyKiller, it is a rogue tool that should not be used and should be uninstalled. See this list:

    http://www.spywarewarrior.com/rogue_anti-spyware.htm
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have any major malware issues.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O3 - Toolbar: (no name) - {17939A30-18E2-471E-9D3A-56DD725F1215} - (no file)
    O3 - Toolbar: (no name) - {8E718888-423F-11D2-876E-00A0C9082467} - (no file)
    O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  6. Dobbie

    Dobbie Private E-2

    Good Evening... I have removed Spy-killer.

    Additionally, I have ran spyware doctor again and found: C:\Documents and Settings\JOSEPH\Cookies\joseph@tribalfusion[2].txt...

    I guess you can get these cookies all the time... no problem I deleted it again.

    Everything seems to be working great... I want to thank you for you help in this matter....

    a new HJT log is attached....

    If this is your weekend.... have a great one..... if not have a great evening.....

    Dobbie
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes cookies will always be on your PC anytime you surf they are typically not a problem to be concerned with. You can clean them using tools like Ccleaner which also give you the options of which ones to keep.

    Did you purchase Spyware Doctor, if not, you should uninstall it to avoid wasting the resources on an application that is not going to help you fix problems.

    The same question applies to Ewido! Did you buy it or is it the trial? When the trial is up it will not be that useful to you. Are you going to buy it?

    Your log is clean! Are you having any malware problems? Have a nice weekend youself! Thanks!
     
  8. Dobbie

    Dobbie Private E-2

    Just thought i would try out ewido.... but it appears that the other tools i got from this site will work just as well so i wont be using it in the future.

    Again, thanks for your assistance in this matter and have a great weekend (if this is your weekend... otherwise, have a great day....).
    Dobbie
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  10. Dobbie

    Dobbie Private E-2

    Finished step one and on the way to "protecting myself from malware...." Again thanks..

    Dobbie

    PS

    surfing the site and it has some great information...
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds