coolpics.com virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by sneakytwo, Oct 26, 2006.

  1. sneakytwo

    sneakytwo Private E-2

    i ran the read and run me first stuff. i cannot edit registry, have no run cmd in start menu, and browser gets pointed to coolpics.com plus in yahoo im there is a new status line that points to coolpics and people on my yahoo list are getting msgs from my computer. pls help and thanks
     

    Attached Files:

  2. sneakytwo

    sneakytwo Private E-2

    2nd msg
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Somehow you slipped by us for this I apologize. The first thing I notice is that your OS is way out of date which represents a critical security threat. You must update to Service Pack 2 and Internet Explorer 7 to be well protected, at the moment you are wide open to infections.

    Once you we get your system cleaned you must update or else you will continue to have problems with malware.

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thecoolpics.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.allvantage.com/myvantage
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = -

    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O21 - SSODL: JEFGIAHH - {2CF33D67-38F5-2E37-0A9D-25185A0E33AC} - C:\WINDOWS\System32\Nepkehof.dll (file missing)
    O21 - SSODL: mtkle - {5B2F990C-63C7-42AA-ECAB-9B415CB75BA0} - C:\WINDOWS\System32\alajcl32.dll (file missing)

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:

    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and then scan with HijackThis and attach the new log.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  4. sneakytwo

    sneakytwo Private E-2

    Thanks for looking at this. Computer is much better, and I updated everything.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Are you having any current problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds