Followed guides but still get popups (hijackthis log included)

Discussion in 'Malware Help (A Specialist Will Reply)' started by loyzari, Apr 10, 2008.

  1. loyzari

    loyzari Private E-2

    So I've followed the XP Cleaning procedure and it found tons of stuff to remove, but I'm still getting popups. I've included a HIJACKTHIS log so if anyone can help, I'd greatly appreciate it. If other information is needed I'll gladly supply!

    Some curiosities:
    COMBOFIX won't run. When I double click on it it just shows the initial progress bar, then nothing.
    SMITFRAUDFIX won't run either. Double clicking on the exe just flashes a black screen up for a split second then goes away.
    (I've followed the instructions to the T so I'm sure it's not user error.)

    Thanks in advance!
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi loyzari,
    Welcome to Major Geeks!

    If you followed the XP Cleaning procedures to the T as well as the page which preceeds them called READ & RUN ME FIRST, then you will at least have managed to get the MGTools installed. The HijackThis you posted is an older version which you did not get from the current instructions and it's installed incorrectly. What your log does show me is that you have some serious infections. It takes quite a lot of effort on our part to help you. In order to do this effectively, we need for you to supply us with the right logs run in the right order or an explanation as to what went wrong in the process.

    Combofix won't run and neither will SmitFraud Fix. Can you run CCleaner, Spybot S&D, SuperAntiSpyware and MalwareBytes? Try these please and let me know what results you get. Tell me whether they run or not and if not, what happens. Then install and run the MGTools according to the instructions and attach the MGlogs.zip which you'll find directly under C when you browse to upload your attachment here.

    Thanks.
    abri
     
  3. loyzari

    loyzari Private E-2

    abri,

    Thanks for your help!
    I couldn't get MGTools to run either, that's why I used a different HIJACKTHIS install. MGTools returns an error when it tries to run "VER |FIND" in the batch files and subsequently quites without running.

    CCleaner, Spybot SAS and MalwareBytes all run fine. Spybot, SAS, and MalwareBytes all return with no threats found. I've also run these online scanners: BitDefender, ESET, Trendmicro Housecall and each return with no threats found either.
     
  4. abri

    abri MajorGeek

    Hi loyzari,

    Please try the following:

    First look to see if the find.exe file is missing. It should be in system32 and also in system32/dllcache and also in an i386 backup folder if one exists. If it's missing, it should have caused a Windows File Protection error and asked for the Windows CD.

    If that is missing, tell me. Please do the following as well:
    • Click Start --> Settings --> Control Panel
    • Double click System (You may need to change to classice view on xp)
    • Click on the Advanced tab
    • Click Environment Variables at the bottom
    • In the LOWER list, click on the PATH variable and click edit.
    • Copy and paste what you find here in your next post.
    • Click OK twice to complete this.

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds