flashtrack flashenhancer

Discussion in 'Malware Help (A Specialist Will Reply)' started by iceman_2727, Jun 13, 2005.

  1. iceman_2727

    iceman_2727 Private E-2

    Virus, help needed Please!

    Firstly, I apologize if I posted in the wrong forumn...I had no idea where to place this.

    Here are my system specs:

    Computer
    Operating System Microsoft Windows XP Professional
    OS Service Pack Service Pack 1
    Internet Explorer 6.0.2800.1106 (IE 6.0 SP1)

    Motherboard
    CPU Type Mobile Intel Pentium M, 1500 MHz (3.75 x 400)
    Motherboard Name IBM 2373UN1
    Motherboard Chipset Intel Odem i855PM
    System Memory 512 MB (DDR SDRAM)
    BIOS Type Phoenix (03/04/03)

    Storage
    Disk Drive HITACHI_DK23EB-40B (40 GB, 5400 RPM, Ultra-ATA/100)
    Optical Drive MATSHITA UJDA745 DVD/CDRW

    Partitions
    C: (NTFS) 13960 MB (5579 MB free)
    D: (FAT32) 21650 MB (6881 MB free)

    Here's my problem:
    In an email disguised as being from my school, the subject line was "Warning Message: Your services near to be closed." I, unwittingly, clicked on the attached file. Now, my antivirus (Symantec) will not run, I cannot edit my registry, and the task manager will not run. I'm not sure by any means, but I think I have W32.Mytob.H@mm. I've downloaded a removal tool and ran it, but to no avail. Any help would be GREATLY appreciated as to how to get this off my computer.

    Thanks.
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  3. iceman_2727

    iceman_2727 Private E-2

    This nasty adware program refuses to be removed. I've disabled system restore and used adaware, spybot, and microsoft antispyware on it...but it continues to return.

    Has anybody else dealt with this before? Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It has not been than difficult to remove. Did you follow the directions Shadow_Puter_Dude gave to you. Specifically have you run ALL the steps in the READ ME FIRST sticky thread?

    Also did you look in Add/Remove propgrams for FlashEnhancer? Uninstall if found.

    If the above does not help (you must complete the READ ME FIRST), then follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. iceman_2727

    iceman_2727 Private E-2

    I've tried the aforementioned steps (except for one, which I elaborate on at the end of this post). In add/remove programs, the flashtrack uninstaller is present. When clicking to remove this program, it gives me a URL to uninstall it from. I've used this URL, with it confirming that the program has been uninstalled. However, on every restart, it still attempts to install a BHO that spywareguard and microsoft antispyware immediately recognize. I deleted it's main folder from the registry (C:\Program Files\Fla), but all programs (spybot, adaware, microsoft antispyware) find three more that re-appear after every restart.

    The one step I was forced to omit was a scan in safe mode. It's not my computer, and the owner's password/ID will not log me in to safe mode. Since it is a work-issued laptop, I'm guessing it takes administrator status.

    As I said, it's not my computer, so I don't have it to scan with HJT for the moment. Will do this though when I can. Thanks for all your help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! The only way I can help you from here is with a HijackThis log. You should inform people that passwords will be needed inorder to boot into safe mode. They can always change them to something temporarily for you to use and then change them back later. If people want their PC's fixed, safe mode boot can be required and they will have to provide you password access.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds