computer moron needs your help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by wildhorses, Mar 7, 2006.

  1. wildhorses

    wildhorses Private First Class

    I have downloaded some winks from zango and now I am having a hard time getting rid of them I don't know if I am in the right forum for this if not please redirect me:) thank you,..can someone please tell me how to get rid of these as they are some form of malware whether they pose a threat I do not know?? I have went to my add remove programs and deleted them they came off the list but are still sitting in my msn messenger service I also went to windows explorer
    and uninstalled them but to no avail they did not budge from my msn messenger please can someone help me out here:):eek: :confused:
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You didn't learn the first time not to download winks from such sites as they will infect you everytime, lol.

    Anyway, go back and run thru the READ ME once again and post the requested logs.
     
  3. wildhorses

    wildhorses Private First Class

    Hi, actually I did not download again, it was still left on my system since i last posted ok I am going to do everything again from scratch:)
     
  4. wildhorses

    wildhorses Private First Class

    ad aware se said there was 9 critical errors, so i removed it all, spy bot search and destroy says there are no immediate threats at this time, now I am going to go on with the other scans........just wondering since I had counter spy on my system for the trial period allowed, can i download it again for free or is it no good too me now?? Thanks again for your help!
     
  5. wildhorses

    wildhorses Private First Class

    here are the scans for your review...........I hope it is not much of a mess....Thanks again, now onto Hijack this scan:)
     

    Attached Files:

  6. wildhorses

    wildhorses Private First Class

    here is my hjt log for your review I hope all is well, now I will wait to hear back from you:):confused:
     

    Attached Files:

  7. wildhorses

    wildhorses Private First Class

    please can someone get bsck to me about my previous posts........thank you!
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


    Weird?
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please be patient, we are very busy in this forum as come in when we have time.

    Have you downloaded and ran Counter Spy? If not, please do so and attach the log.

    Please see the below thread on how to run WinPfind and attach the log.
     
  10. wildhorses

    wildhorses Private First Class

    oh I am sorry please forgive my ignorance, I do understand that you all have lives too sorry :)
    anywho can I still run counterspy even tho my trial is up? will it work for me?
     
  11. wildhorses

    wildhorses Private First Class

    here is my WinPFind log for your review>I hope I did this right and really hope someone gets back to me soon...........Thanks again for your kindness in helping me.:)
     
  12. wildhorses

    wildhorses Private First Class

    why can't I see my WinPFind?Please can someone help me??
     
  13. wildhorses

    wildhorses Private First Class

    can someone please look at my WinPFind log please

    I have been waiting for some help I do realize that you are all busy but I have been waiting for 3 days now? please can someone look at it for me thank you:):confused:
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because you did not attached it. See the below link for info on attachments:

    HOW TO: Attach Items To Your Post

    If your CounterSpy trial is up, it is not going to be useful to you. Just uninstall it or buy it if you liked it.
     
  15. wildhorses

    wildhorses Private First Class

    here is my WinPFind log please review it:)
    for some reason when I go to uplaod it won't go through it says that it already has been uploaded ?:confused:
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After attaching your WinPfind log, continue to the below.

    Look in Add/Remove programs for MediaGateway and uninstall if found.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.herbalstoday.com/?Enter=Website%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20CLICK%20YES%20TO%20ENTER%20WEBSITE
    O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\MediaGateway <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  17. wildhorses

    wildhorses Private First Class

    ok I see what happened why I can't attach my WinPFind it has been a thread all on it's own, if you get what I mean.........Look in the page where you can post new threads for some reason it was posted on its own:)
     
  18. wildhorses

    wildhorses Private First Class

    I went and pressed control alt and delete and I did not see a processed tab
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about that! If should not have been in the message to you! It is part of a boiler plate which does not apply in your situtation.

    Why did you start a new thread for and put the WinPfind log there? All communication about your current problems should be in this thread.

    I'll merge it back later.

    BJ is in the process of moving. That is why he has not responded.
     
  20. wildhorses

    wildhorses Private First Class

    oooops i am really sorry about that, I just thought someone had forgotten about my thread.:)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just finish what I just gave you!

    Also look in Add/Remove programs for anything related to AskJeeves and uninstall if found. I see a reference to an AskJeeves toolbar in your WinPfind log.
     
  22. wildhorses

    wildhorses Private First Class

    here is my hjt log for your review, also I looked in my add remove programs and did not see anything with ask jeeves...........another question I was wondering is pop cap malware? I wanted to play a game of zuma :confused:
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! Are you having any other malware problems?

    Various opinions exist on popcap. Some believe there are privacy issues and questions on things that it downloads to your PC. Personally I would not use it. If you want games, either buy a Playstation etc or purchase other games for your PC, or play the ones that MGs offers in the Arcade.
     
  24. wildhorses

    wildhorses Private First Class

    Thanks alot for all the help you have given me I really appreciate it I don't think I have any other malware problem thank you:)
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    It is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  26. wildhorses

    wildhorses Private First Class

    I am running windows 98 SE can you tell me how I use this system restore please and thanks alot:)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! As indicated in step 1 of the READ ME. System Restore only applies to WinMe and Win XP systems. Just work your way thru the How to protect thread.
     
  28. wildhorses

    wildhorses Private First Class

    great thanks again and now I will go and look at how I can protect myself thanks again.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  30. wildhorses

    wildhorses Private First Class

    sorry I just went and read my emails and I got an email from panda software and it claims that they have found 3 viruses and 7 infected files, that was just after I did the panda scan do I have something to worry about here or was that taken care of already?? Please email me back thanks a bunch.........Wildhorses!
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run a full scan with Panda and attach the log here. Run it in normal boot mode. I would bet most are just cookies.
     
  32. wildhorses

    wildhorses Private First Class

    sorry I did not get back to you thank you for all the wonderful help you have given me:)
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! But are you having anymore problems. Did you run Panda again?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds