had porn showing up-did read & run me first

Discussion in 'Malware Help (A Specialist Will Reply)' started by Smeelittle, Mar 2, 2008.

  1. Smeelittle

    Smeelittle Private E-2

    First of all, thanks for the very informative stickies! You made a complex subject understandable.

    I went through the Read and Run Me First Malware removal, and did all my updates and ran all the programs for my XP system. My system already seems to be running better. Although I do keep getting a warning dialog box telling me that windows can't find Java 6.1.03, as if I was trying to open it. I have downloaded and installed Java .04 as per your instructions.

    Could you please check the Combofix log and Mglogs I've attached to be sure I've gotten all the problems before I create a new system restore point?

    Hopefully I haven't missed anything, but if I have, then meds for the flu are my excuse!

    Thanks again.

    C.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing any malware..though you may wish to fix these:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Are you still having issues and if so, what exactly.
     
  3. Smeelittle

    Smeelittle Private E-2

    Thank you very much for your prompt reply, and the help.

    As far as I can tell, everything seems to be all better now that I have done everything on the read me file. Search and Destroy found a bunch of stuff, and Ccleaner cleaned up more stuff. Is there anything else it would be a good idea to run every so often? Ever since my son downloaded frostwire for a brief time last year I kept having porn show up randomly in my internet history, even when I had been on the computer all day *not* looking at 'busty broads from Birmingham' or 'hot Korean coeds'!

    Oh, do I leave the regedit file on the desktop, or do I delete it now that it's gone to the registry?

    Thank you again, Tim!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just keeping your anti-virus updated and do the preventative measures .....(and keep the kid off the computer ....:D).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    *How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds