help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ophelia3431, Sep 8, 2006.

  1. Ophelia3431

    Ophelia3431 Private E-2

    ok so i got lost somewhere in step 4 of the do me before you post stuffs

    so ill post the log and see if anyone can help anywho or atleast help me figure out step 4(yeah i know im sounding like an idiot here)
    in any event there has been some funny stuff going on with this PC
    I thought it was more or less secure
    sygate firewall and norton antivirus are installed
    I also run spybot weekly along with adaware and ace utilities
    whatever this is I cant figure it out with my limited knowledge

    so if you could please help me id surely appreciate it
    Thanks In Advance
     

    Attached Files:

  2. Bladesofhalo

    Bladesofhalo MajorGeek

    Post this thread in the malware forum as our malware experts can help you better.
    Request this thread be moved to malware.
     
  3. Ophelia3431

    Ophelia3431 Private E-2

    DOH!!!
    ok now i really feel like an idiot
    sorry about that and thanks for requesting the move to the proper place
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi, while HJT is a good application for finding browser hijacks it cannot, find all malware on your PC, so your best options is to run the below guide and attach the logs requested, then one of our malware guys will give them a look and post some more tailored removal instructions to clear up any last reminents,


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis

    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. Ophelia3431

    Ophelia3431 Private E-2

    thanks
    unfirtunately for the life of me i cant get the first part of step 4 to work the dang little window that pops up is empty even with the "windows xp" fix that is linked to done
     
  6. Ophelia3431

    Ophelia3431 Private E-2

    first two log file thingies
    ran everything in safe mode and they found nada will put the other logs up in just a sec
    thanks loads again
     

    Attached Files:

  7. Ophelia3431

    Ophelia3431 Private E-2

    sorry it took me so long to get these up my modeem pooped out on my just as the last one of these was finishing
    here are the last 2 logs along with hijack this

    thanks loads
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Then uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (1.5.0.3)
    Viewpoint Media Player


    Now run the below and save a log and attach here when you come back:

    Qoologic Removal Procedure


    Now boot into safe mode and delete the below files (some may be gone already):
    C:\WINDOWS\justin_bundle.exe
    C:\WINDOWS\system32\adrot-uninst.exe
    C:\WINDOWS\system32\icon_justin.exe
    C:\WINDOWS\system32\ts_justin.exe
    C:\WINDOWS\system32\uninstIcn.exe
    C:\WINDOWS\system32\dqxsxy.exe


    Do you know what the below file is for?

    C:\WINDOWS\blfap.dll

    If not, then run it thru the below online file scanner:
    http://virusscan.jotti.org/

    Attach the results here?

    Now attach new logs from:
    - GetRunKey
    - ShowNew
    - HJT

    How are things running?
     
  9. Ophelia3431

    Ophelia3431 Private E-2

    Mozilla Firefox (1.5.0.3) i downloaded both updates and uninstalled both of the other things recommended
    but how so i install a marticular version of mozilla
    i dont actually use mozilla very often so im not really familiar with how it works

    thanks again for all your help
     
  10. Ophelia3431

    Ophelia3431 Private E-2

    oks so the qoologic remover didint find anything (log attached)
    also i was able to delete everything but C:\WINDOWS\system32\dqxsxy.exe (i couldnt find it)
    the Jotti reseults are as follows:

    File: blfap.dll
    Status: OK
    MD5 4c51c1a77270d341126106b410b77238
    Packers detected: -
    Scanner results
    AntiVir Found nothing
    ArcaVir Found nothing
    Avast Found nothing
    AVG Antivirus Found nothing
    BitDefender Found nothing
    ClamAV Found nothing
    Dr.Web Found nothing
    F-Prot Antivirus Found nothing
    Fortinet Found nothing
    Kaspersky Anti-Virus Found nothing
    NOD32 Found nothing
    Norman Virus Control Found nothing
    UNA Found nothing
    VirusBuster Found nothing
    VBA32 Found nothing


    the pc is actually running ok at the moment
    although i was searching for a file awhile ago and something flashed across the screen and too dang fast for me to see anything
    that btw hasnt happened before... very weird thanks again
     

    Attached Files:

  11. Ophelia3431

    Ophelia3431 Private E-2

    Qoologic log

    thanks again
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you installed the new version it overwrote the old version so you should be OK!

    Are you having any other problems?
     
  13. Ophelia3431

    Ophelia3431 Private E-2

    no not really
    although i do wish i cold figure out how to keep adobe from starting all the dang time
    thanks loads and loads
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to the below service?

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    This is [FONT=Verdana, Tahoma, Arial, sans-serif]Adobe's license management service that is used to make sure you are not using a pirated copy of their software. It does this by examining your hardware on your computer and asking you to reregister if this changes. This can not be disabled as it will reenable when you use one of their products. Thus you may need this to run (unless you don't need anything from Adobe other than a simple PDF reader).[/FONT]


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. Ophelia3431

    Ophelia3431 Private E-2

    so far so good
    thanks for the info onadobe and for the linkage
    ill start looking at that now

    again thanks for the help and for the forum
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds