Going mad. Please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wsmitty, Dec 22, 2004.

  1. wsmitty

    wsmitty Private E-2

    I have on this computer I am working on some problems. Everytime I fix them, They keep coming back. I have followed your instructions to the tee several times.

    What I have in application data is a freelite folder. in the freelite folder are these exe files:
    flaw memo.exe
    king loud log multi.exe
    Itch Math Bows.exe
    "and various nonsense letters".exe

    I delete them and clean them out of the registry and they keep coming back even in the registry. Does anyone know what type of files these are? adware, virus?

    I also get something trying to change my webpage to www.zvafsirovjohm.com and I keep telling WinPatrol not to change it.

    I delete that in the registry and it comes back.

    Any help would be greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. wsmitty

    wsmitty Private E-2

    No this is a different computer that I am fixing for someone.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! If you have followed ALL the steps from READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal and you still have a problem then follow the guidelines below for posting a HijackThis (HJT) log.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  5. wsmitty

    wsmitty Private E-2

    Attached is my HJT txt file. I have 4 users on this computer and 3 of them have this freelite folder with those files in their application data folder. I scanned them with Norton and it came up ok. I also did all the steps that you have suggested on the website and nothing.

    Thanks for any help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
    O9 - Extra button: Support - {2348B58C-260C-4347-9092-E2A622A468E3} - http://www.comcastsupport.com (file missing) (HKCU)
    O9 - Extra button: ComcastHSI - {4ED99DE9-DD44-4C4D-B7FA-3774E4F54891} - http://www.comcast.net (file missing) (HKCU)
    O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binaries/IA/netia32_EN_XP.cab
    O16 - DPF: {B3A5878E-5B4C-4D12-9156-4D7FD8D0AF6C} (Cltbuilder Class) - http://www.one2one.com/static/class/one2oneSvc.cab
    O23 - Service: .NET Framework Service - Unknown - C:\WINDOWS\svchost.exe (file missing)


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    I have seen files similar to the ones you mention many times. We normally just fix the lines that show in HJT (you had none) and then boot to safe mode and delete the files. Always worked.

    Perhaps Winpatrol (in what ever it is doing to protect you) stops certain things from loading that we need to see and kill in order to fix all those. On the other hand, it may just be that we need to see each of user logs and fix each one first.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds