Can Anyone Help Me?

Discussion in 'Malware Help (A Specialist Will Reply)' started by g3455h, Mar 12, 2006.

  1. g3455h

    g3455h Private E-2

    I recently noticed my computer acting very weird and suspected spyware and/or a virus was doing it. I found this site and did the steps that were provided and ran all the programs. I dont know what to do from here so if someone can help me remove the stuff on my computer i would really appreciate it. I have attached a hjs log and the activescan i did. Oh and by the way all this infection seems to do is cause error messages to show up when i close Internet Explorer for now.
     

    Attached Files:

  2. g3455h

    g3455h Private E-2

    Sorry i forgot the smitfiles and bitdefender logs.
     

    Attached Files:

  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Empty Norton Quarintine
    Empty Norton Protected Recycle Bin
    Empty the Recycle Bin
    Empty the Java Cache: http://fxtrade.oanda.com/help/clear_cache.shtml

    Copy the contents of the below Quote box to Notepad. Save As FixReg.reg to your desktop. Do not run it yet.
    Scan and have HJT Fix the following:
    Locate FixReg.reg and double-click on it; answer 'Yes" when asked if you want to merge with teh registry.

    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Clear System Restore: How to Disable System Restore

    Follow the directions for Running Ewido Security Suite

    Update to the latest version of Java. https://sdlc3b.sun.com/ECom/EComActionServlet;jsessionid=EEAD97CE28B92A4F0525C5A3B676A0E0

    Post the Ewido Log and a fresh HijackThis log.
     
  4. g3455h

    g3455h Private E-2

    I can not find the norton protected recycle bin, so can you point me in the right direction to find it?
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Right click on your recycle bin and select empty Norton Recycle Bin.
     
  6. g3455h

    g3455h Private E-2

    Ok i finshed the process and here are the Ewido log and HijackThis log.
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now scan and have HJT Fix the following:
    Open Windows Explorer, navigate to and delete the following file:
    REBOOT

    Post a fresh HijackThis log.
     
  8. g3455h

    g3455h Private E-2

    Here is the fresh HijackThis log.
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log is clean.

    How is your computer running?
     
  10. g3455h

    g3455h Private E-2

    Ok my computer is running completely normal now, but i am still getting an error message when i close internet explorer and the error message pops up twice when i start my computer even though i am not running internet explorer to my knowledge. Well it's alright if it cannot be fixed because i use firefox 90% of the time anyways. Thanks a whole lot for your help.
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    What is the error message? Word for Word.
     
  12. g3455h

    g3455h Private E-2

    Here are screen shots of the error message, #1 is the initial message and #2 is the technical info on the error.
     

    Attached Files:

  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  14. g3455h

    g3455h Private E-2

    Here is the WinPFind scan.
     

    Attached Files:

  15. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Delete teh following:
    If you are still getting IE error messages, post in the Software Forum. This does not appear to be malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds