Help me please...

Discussion in 'Malware Help (A Specialist Will Reply)' started by mama2two, Oct 17, 2006.

  1. mama2two

    mama2two Private E-2

    1st off sorry but I am not a technical person and I dont know all the names for stuff on a computer so I'll call it what I call it and hope you know what I am talking about...lol...I have been putting up with this stupid thing blinking in my bottom right hand corner(i call it my task bar is that right? lol) its a question mark and a circle with an X in it and a bubble comming up saying critical system error...also my homepage has been changed to some stupif site trying to sell me their software to get rid of a virus that I know has sumthin to do with their site and that blinky thing...anyways..lol ....pleas ehelp i have read through the sticky saying to read before posting and I have done step by step..here are my logs...I didnt do that hijack program cause I wasn't sure if i needed to or if I wouild screw up this computer by doing it...so if i need ot just tell me but until then here are the other logs...thanks:)
     

    Attached Files:

  2. mama2two

    mama2two Private E-2

    here is the other log...
     

    Attached Files:

  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi, No you wont screw up your PC by running Hijackthis so long as you dont remove anything yourself, just attach the log and one of the malware experts here will issue you wuth further detailed instrcutions of what to remove, even when you do remove items Hijackthis ( if you install it in the mentioned location ) creates a backup of whats removed so it can easily be restored.

    SO please yes, attach the Hijackthis log :)
     
  4. mama2two

    mama2two Private E-2

    here is my HJT log:) please help me!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions for ShowNew like you did with GetRunKey. You must extract the files from the ZIP file and run shownew.bat from a Windows Explorer window. You did it correctly with GetRunKey but not ShowNew. Did you see any error messages while trying to run ShowNew?

    I'm going to post two messages! This is the first! Complete this procedure completely including attaching the requested log before doing the second procedure.

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.

    Now attach new logs from:
    - GetRunKey
    - ShowNew <---- make sure your run it properly this time.
    - HJT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds