Desktop Hijacked by totalpcprotection

Discussion in 'Malware Help (A Specialist Will Reply)' started by SkinzyB, Oct 2, 2006.

  1. SkinzyB

    SkinzyB Private E-2

    Last night my desktop was hijacked by totalpcprotection. I have read through the other two post on this subject and started going through the sticky thread Read ME & Run Me First. I am having several problems completing these tasts. 1. I downloaded the CCleaner and ran it on my User Account (I only have one) and then booted into safemode to run it on my admin account and it is not showing up for me to run it there.
    2. I already have my computer set to show hidden files but I cannot uncheck the Hide extensions for known file types option and I cannot uncheck the Hide protected operating system files options. If I click to many times trying to change these settings I am redirected to of course the totalpcprotection site.
    3. I already have Spybot Search and Destroy on my computer and have had since I built it, but it has been tweeked and I do have the tea timer running also.

    I haven't downloaded the GetRunKey.Zip and ShowNew.Zip yet since I have had problems with the steps ahead of those. Should I continue doing what it will let me and ignore what it wont let me do?

    System Specs From AIDA32(off your site)
    Motherboard - ASUS P5WD2 Premium
    CPU - Intel Pentium 4 3.00GHz 3010 MHz L2 cache 2MB
    RAM - 1023MB (It is DDR-2)
    OS - Windows XP Professional w/ SP2
    Video - ATI Radeon 9200 Pro

    I have multiple hard drives connected to my computer at this time including a 300Gig partitioned into 30Gig (for OS and Programs), and 250gig for storage.

    Another 300Gig and 120Gig (for storage), and a 40Gig (out of my moms computer as I was trouble shooting it and saving files for her when this happened)

    All these drives are IDE

    If you need more information let me know, as I am not going anywhere soon with this mess.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just locate it manually from Window Explorer and run it. Look in C:\Program Files\Ccleaner and double click on ccleaner.exe. If you want, you could even right click on ccleaner.exe and drag it to your Desktop. And when you unclick, just select Create Shortcuts Here.

    Skip this for now.

    Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!

    Yes just complete ALL steps that you can and attach the logs as requested. Just tell us when you come back about any other problems.

    You may want to be selective when running the Bitdefender and Panda online scans and just have it scan the one main hard disk (I assume drive C) or these scans could take a very long time to scan thru those three harddisks.
     
  3. SkinzyB

    SkinzyB Private E-2

    I think I solved my problem but I am attaching my logs for review incase you spot something else that may be a problem. Thankyou so much for your help.
     

    Attached Files:

  4. SkinzyB

    SkinzyB Private E-2

    Here is the other one. Do I still need a Hijack This Log?
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two messages! This is the first! Complete this procedure completely including attaching the requested log before doing the second procedure.

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is my second message. Make sure you have follow the first procedure before doing the below.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.

    Now also attach new logs from ShowNew and HJT!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds