Help me please

Discussion in 'Malware Help (A Specialist Will Reply)' started by chap897, Aug 12, 2005.

  1. chap897

    chap897 Private E-2

    I have followed all of your steps of what to do before I post. I could not run Bitdefender and Ravantivirus in safe mode becasue I had no firewall, got alot more spyware and had to start over again. I think I cleaned out the Icannnews because that is no longer showing up in my "Norton Connections" I do have a few processes that I have not been able to kill using anything. It keeps either restarting right away or changing it's name. I have been able (supposedly) to block it from entering on my startup programs tho. I keeps have the same "MD5" id. Here is what Microsoft AntiSpyware said about it:
    vwpqjz.exe
    File name: vwpqjz.exe

    Description: Unavailable
    Publisher: Unavailable
    File path: C:\WINNT\system32\vwpqjz.exe
    File version: 1.1.0.7
    Copyright: Unavailable

    Technical Details:
    Original file name: Unavailable
    MD5: 39792e0dcb91faa72bc2ebc1b3220e90.

    Do you want me to post my HJT log? As an attachment or paste? Please help me - I've been messing with this for over a week. Thanks!
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. chap897

    chap897 Private E-2

    Wow that was quick!! Here it is. Thanks.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the following two files, create a folder on your desktop, call it TSC. Save these 2 files there!

    Sysclean Package

    Pattern.zip

    Once you have these downloaded into the folder you just created, REBOOT INTO SAFE MODE!

    Once in Safe Mode double click the file sysclean.com. When the system cleaner loads, click SCAN to start the scanner. After you complete the scan reboot and attach a fresh HJT log.
     
  5. chap897

    chap897 Private E-2

    I had problems with the sysclean package. Kept saying files were missing. So I went back into normal mode, did what it said. It was saying the virus "defs" package was missing. But I had the zip file you told me to load and the one they told me to load. But I went back into safe mode, ran it again and got the same error message. I was able to run it (don't know if it did any good) by not closing the error message. I also ran all my other spyware det. programs in safe mode and cleaned the hard drive again while in safe mode. Now Spyware Doctor detected Aurora files on the registry. Had it fix them. Here is my new HJT log. So far since I've been back on line I haven't had any problems. Nothing weird is showing up in my running processes or start up programs. Or any weird pop ups.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  7. chap897

    chap897 Private E-2

    I ran it again - this time no problems. Here is my new HJT. Am I clean???

    Thank you for all your help! :)
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean!

    Are you having any further problems?
     
  9. chap897

    chap897 Private E-2

    No I do not appear to be having any other problems. Thank you so much!!!
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds