help needed! can't get rid of malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by bspbr, Jul 19, 2006.

  1. bspbr

    bspbr Private E-2

    hi! I have a problem with a strange malware that keeps adding "_zskwrkni05"something entries to hijackthis and I can never get rid of them. also, whenever I stay online for more than a couple of minutes, things start to get slower and it seems like I'm sending and receiving a whole lot of data I'm not aware of. I've run all the steps in the read me first zone, updated adaware, spybot and everything, but I still get these symptoms and results in hijackthis. I have attached the log for you guys to see.

    help is very appreciated! thanks!
     

    Attached Files:

  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    You can remove any lines that end with (file missing)

    This seems fishy:
    O4 - HKLM\..\Run: [ÿ_zskTE]UWB`KRCZC[]_] C:\WINXP\system32\_zskwrkni05\_][CZCRK`BWU]ET.exe
    O4 - HKLM\..\RunServices: [ÿ_zskTE]UWB`KRCZC[]_] C:\WINXP\system32\_zskwrkni05\_][CZCRK`BWU]ET.exe
     
  3. bspbr

    bspbr Private E-2

    things got a bit worse now. as I turned the computer on, it tried to connect to the internet automatically and a balloon came down every 30 seconds or so saying my computer was in danger. I shut it off, rebooted in safe mode and ran adaware and spybot.

    spybot picked up "brave sentry" and "smitfraud". rebooted, ran HijackThis and still got this log.

    the "zskwrkni" entries keep getting added as soon as I ask HijackThis to fix them. I've tried it like a billion times!

    please, help! thanks!
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Let's backup a little here, I need you to go back and run all the steps of our tutorial.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (
    these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds