Ceres Keeps Coming Back! Search Engine Keeps Changing!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LCarrier, Mar 17, 2005.

  1. LCarrier

    LCarrier Private E-2

    Everything went fine, however after rebooting, the line

    O4 - HKLM\..\Run: [ihlclvr] c:\windows\system32\sofhaqs.exe

    had changed to a new file name. I fixed the new line, as well as the one ending in wupdt.exe. I then ran HJT again to get the new log. As you will find in the posted log, now we have the following line.

    O4 - HKLM\..\Run: [txkykb] c:\windows\system32\tjufdg.exe

    As you can see, it keeps changing once it's deleted, even if I keep the computer on, which I will right now.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Repeat the steps with Pocket Killbox again on the below items:

    c:\windows\system32\tjufdg.exe
    O4 - HKLM\..\Run: [txkykb] c:\windows\system32\tjufdg.exe

    However this time say no to allow Pocket Killbox to reboot your PC. Instead I want you to pull the power chord to your PC (yes you read that correctly). I want to try to prevent it from spawning on shutdown. Again make sure no browsers are opened and that you are physically disconnected from the internet.

    After doing that, if you still have the problem, run the steps below:

    - Download Finditnt2000xp

    - Extract all the files from the FInditnt2000xp into its own folder.
    - Then run find.bat. Post the log it creates back here as an attachment.
    - also post a curren HJT log.
     
  3. LCarrier

    LCarrier Private E-2

    Wow, I think pulling the power cord actually worked.....here's my newest HJT log. When I turned the computer back on, I ran HJT and nail.exe was back, but not that other returning file name. I ran ABIremover, and then got another new scan/log from HJT. Looks good so far from my eyes. I'm going to reboot the proper way now and run HJT one more time to see if anything changed. I'll post the log in a new post.

    By the way, I have not yet downloaded Finditnt2000xp because I may no longer have a problem. Let me know, thanks!
     

    Attached Files:

  4. LCarrier

    LCarrier Private E-2

    Okay, I rebooted properly and my log still appears to be clean. See attached and let me know. Thanks!!!!!!!!!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. LCarrier

    LCarrier Private E-2

    It's been 4 days and I'm still malware free! I now have Microsoft AntiSpyware up and running and kept SpySweeper uninstalled. Thanks again!!
     
  7. LCarrier

    LCarrier Private E-2

    BTW, I'm being asked if I want to block Browser Helper Object kb290333.dll ({FB153DCE-822E-47ec-8D00-2706E7864B37}) c:\windows\kb290333.dll from being added to Internet Explorer.

    Should I?
     
  8. LCarrier

    LCarrier Private E-2

    Browser Helper Object: BHO kb290333.dll {FB153DCE-822E-47ec-8D00-2706E7864B37}

    Disabled date: 6/1/2005 4:56:03 PM

    Details: Browser Helper Object deactivated

    Registry Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB153DCE-822E-47ec-8D00-2706E7864B37} decativated on 6/1/2005 4:56:03 PM
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is may be a new file if it just started disabling it on 6/1/05 (today). You should delete that file and also look for an O2 BHO line in your HJT log. It could look something like:

    O2 - BHO: (no name) - {FB153DCE-822E-47ec-8D00-2706E7864B37} - C:\WINNT\KB290333.dll
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds