Help please! - hijackthis log

Discussion in 'Malware Help (A Specialist Will Reply)' started by gina06, Jan 22, 2006.

  1. gina06

    gina06 Private E-2

    Hi! I've tried the steps from the article "READ & RUN ME FIRST Before Asking for Support", but I'm still having problems. The Panda ActiveScan detected 18 threats and what's more, I have over 52 processes running!
    Here are the files you asked me to attach.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs and uninstall the following:

    MessengerPlus! 3

    Please see the below thread on how to install and run Spy Sweeper and Ewido Anti-Malware. After you ran both programs, attach the logs to your next post along with a fresh HJT log from normal mode.
     
  3. gina06

    gina06 Private E-2

    There you go

    Logs from Spy Sweeper and ewido.

    I now have over 60 processes running, I know this isn't normal, but I really don't know which processes should I have on startup and which ones are not necessary.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Ewido

    Spy Sweeper


    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.outheabojavtuqzl.com/8uf9DmEZRWYDhsa/lqtmvcrec6oMo8uy4q6DWHCSveW7bt_y yYTM51EMlBM7W7/T.html
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

    O2 - BHO: (no name) - {B8FF281E-0071-D097-470B-5E4E2BABBEBD} - C:\DOCUME~1\User\APPLIC~1\GREATM~1\loud 4.exe (file missing)

    O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
    O4 - HKLM\..\Run: [itchbatmagsphone] C:\Documents and Settings\All Users\Application Data\close glue itch bat\cakeboob.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [proc wma] C:\DOCUME~1\User\APPLIC~1\TITLEN~1\more keep warn.exe

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\MessengerPlus! 3 Delete this whole folder if it exist!

    C:\Documents and Settings\User\Application Data\TITLEN~1 Delete this whole folder if it exist!

    C:\Documents and Settings\All Users\Application Data\close glue itch bat\cakeboob.exe

    Next, run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.

    Note: Remember to get all updates before doing the scans.


    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    • Temporary Files
    • Temporary Internet Files
    • Recycle Bin
    And Click OK.


    After you complete the above, REBOOT to normal windows and proceed with the rest of this fix...

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:


    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.

    After you complete the above reboot once more and then scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. gina06

    gina06 Private E-2

    Thank you! But still...

    I still have a lot of processes running, I have 56 right now :confused:.

    Good news is I appear to be free from malware, thank you very much! I've been struggling for months trying to get rid of that cakeboob.exe bstrd! posing as IEXPLORE.EXE.

    Here's the latest hijackthis log.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It's normal to have around that many, your HJT log looks good.

    Are you having any further problems?
     
  7. gina06

    gina06 Private E-2

    Oh thank you! I thought it wasn't lol!
    Everything's great now! Thanx again!
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds