Followed READ ME First and still have problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrs58, Jul 25, 2006.

  1. mrs58

    mrs58 Private E-2

    I am having problems with popups -- winantivirus.com, anti spiware, casino, and more. i followed all the directions in the READ ME FIRST string and am not sure how to proceed next. I've attached the logs for bitdefender, panda, and htj

    please help
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Reboot to Safe Mode.

    Delete the following:
    c:\windows\system32\nkctzsyalh_nav.dat
    C:\Documents and Settings\Maria Sullivan\Favorites\Insurance

    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    Reboot to Normal Mode.

    Post a fresh HijackThis log.
     
  3. mrs58

    mrs58 Private E-2

    thanks for the support. did as below and attached frsh hjt log. so far when i clicked on IE no pop ups... let me know if u think its clean

    many thx
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  5. mrs58

    mrs58 Private E-2

    Many Thanks for your support! My computer is now back on track.
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're welcome.
     
  7. mrs58

    mrs58 Private E-2

    Hi -

    I thought the computer was clean, but It's back - I went online today and more pop-ups appear. winantispyware.com page, a casino page.

    I ran spybot in normal mode and magiccontrolagent appeared again.

    The only thing i did after the disable system restore is to load the new java and zone alarm and backed up my quicken files onto a thumb drive.

    When i restarted i got the black screen saying that there was a problem with a device driver and windows was shutting down, but it never did so i had to hard start the computer.

    I do run windows XP and am on a wireless home network... could it be something on another computer that i access files on?

    Any advice on how to proceed this time?
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Post fresh logs fron BitDefender Online, Panda ActiveScan and a fresh HijackThis log.
     
  9. mrs58

    mrs58 Private E-2

    Hi -

    here are the fresh logs. i didn't do all the cleanup steps prior to running the scans so there were 13 spyware items detected by panda & no viruses.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackThis log is clean.

    Install Java Runtime Environment (JRE) 5.0 Update 7 available from http://java.sun.com/javase/downloads/index.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Reboot to Safe Mode.

    Open Windows Explorer and delete the following files:
    c:\windows\system32\nkctzsyalh.exe
    c:\windows\system32\nkctzsyalh_nav.dat

    Reboot to Normal Mode.

    How is your computer running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds