Help! Still infected with WINFIXER,BLACKWORM,and AFF Popups!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rakelly52586, Mar 4, 2006.

  1. Rakelly52586

    Rakelly52586 Private E-2

    Hi, i am brand new to this site, i have been searching the web everywhere to figure out how to stop these pop-ups on my computer. There are winfixer, blackworm alerts, and adultfriend finder. They are quite aggravating! Anyways i have done the advice by following the directions on the READ & RUN ME FIRST Before Asking for Support Thread. Now i have the hijack log, i have read many other posts with hijack logs to see if mine is similiar, but i still am not sure, I do not want to delete something thats important. To be safe, I'm asking if anyone can look at my log and pick out the things i need to fix! Thanks so much. :eek:
     
  2. Rakelly52586

    Rakelly52586 Private E-2

    Hijack LOG

    This is my hijack log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijack LOG

    Welcome to MGs!

    You must not skip steps in the READ & RUN ME. You must run ALL steps from step 0 to step 7 and you must follow the directions. Here is what I observer from your log.

    - step 0 does not appear to have been run because I see WeatherBug in your log
    - Microsoft Windows Defender not run
    - step 6 not run at all. You must run these and attach the logs!
    - step 7 not follow because HijackThis is not installed properly.

    Did you skip anything else????

    Go back and complete all steps and add one more item to complete before attaching a new HJT log. Here is what I want you to add. Run the below and attach the requested log:

    Virtumonde aka Trojan Vundo Removal
     
  4. Rakelly52586

    Rakelly52586 Private E-2

    Hi, thanks for replying! Well i did do step 0 but i did not delete weatherbug, b/c i use it everyday, and i did download Windows Defender. but it did not fully install b/c an error popped up saying the copy of Windows I'm running couldnt be validated. And error also popped up when i used bitfender. but i'll try again and attach the logs. thanks
    Oh, also, i did download the Virtumonde Removal, probably about 10 times, then i realized that i didnt save it to the desktop first, but it worked this time, it removed some stuff i recognized in my hijack log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Weather Bug is a source of malware. Try this instead: Weather Watcher

    You should have attach the VundoFix log I requested.

    Sounds like your copy of Windows is not legit. Thus you will not be able to install all Microsoft software and updates.

    I assume things are working better already??
     
  6. Rakelly52586

    Rakelly52586 Private E-2

    Hi again, ok i removed weatherbug, im just going to use weatherchannel.com, sorry i forgot to attach the vundofix log, but i have the logs for BitDefender and Panda ActiveScan, also how can i make my windows copy legit? i bought my computer from gateway, do i need to register for windows?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Empty your Norton AntiVirus Quarantine folder.

    Why do you have folders like the below on your PC:
    C:\Documents and Settings\Owner\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\My Documents\setup.exe

    You should not have so many My Documents subfolders continuing like this. You should make sure nothing is stored in them that you need and then delete the below and anything beneath it (only keep the the first level My Documents folder).
    C:\Documents and Settings\Owner\My Documents\My Documents

    Also boot into safe mode and delete the below:
    C:\PROGRAM FILES\Lycos <-- the whole folder
    C:\PROGRAM FILES\MyWay <-- the whole folder
    C:\PROGRAM FILES\se <-- the whole folder
    C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll
    C:\WINDOWS\SYSTEM32\osmim.dll
    C:\WINDOWS\SYSTEM32\SHAgentNew.dll
    C:\WINDOWS\SYSTEM\UpdInstall.exe
    C:\WINDOWS\INF\alchem.inf
    C:\WINDOWS\INF\biini.inf
    C:\WINDOWS\woinstall.exe

    How is everything working now!

    As far as a valid WinXP is concerned.... did you buy the PC from Gateway with WinXP already installed on it? If so, ask them what your license key is.

    If not, you need to buy a valid license copy from a store or can obtain one online thru Microsoft. Have you tried going to Microsoft update and validating your copy?
     
  8. AbbySue

    AbbySue MajorGeeks Administrator

    In my expereince, Gateway computers usually have a sticker on the back of the computer case with the windows key on it. Sometimes they are pretty small and hard to see but it should be there. If there is no sticker, then you will need to do as chaslang suggested.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.....if it was shipped with WinXP on it.
     
  10. AbbySue

    AbbySue MajorGeeks Administrator

    That's correct chas..my bad for omitting that from my post. Thanks for clarifying the info.:)
     
  11. Rakelly52586

    Rakelly52586 Private E-2

    Hello! yes everything is well!! i havent had one pop-up yet! thank you so much!!
    Yes, i do have a validated copy of Windows (it came shipped from Gateway, the liscense number is on my computer), and i now can have Microsoft Updates, went to the Microsoft website to get validated

    I have fixed the long file path for the MyDocuments folder, i honestly dont know how that happened, probably by someone in my family.

    I also have done everything you asked on the previous post.

    As for Windows Defender, it works, it removed everything, but failed on these two things...
    file:
    C:\Documents and Settings\Owner\UserData\Start Menu\Programs\Startup\PowerReg Scheduler.exe

    startup:
    C:\Documents and Settings\Owner\UserData\Start Menu\Programs\Startup\PowerReg Scheduler.exe

    and

    C:\Documents and Settings\Owner\Application Data\tvmknwrd.dll


    Thanks again for you help!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can just have HJT fix that startup entry.

    My previous message requested that you delete this yourself.
     
  13. Rakelly52586

    Rakelly52586 Private E-2

    Yes, there were two types of dll files, one was tvmcwrd.dll and the other was tvmknwrd.dll, i just deleted the one you said, i wasn't sure about the other one.
    Thanks so much for everything, i havent had any problems, do i need to run another hijack log or anything, or am i finished?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I did not notice the change in names. Yes the tvmknwrd.dll file should be deleted too.

    No I do not need another HJT log unless you are having any other malware problems.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Mar 7, 2006
  15. Rakelly52586

    Rakelly52586 Private E-2

    alright, i'm sure glad i came and asked for help here rather than trying to fix it my self! lol! thanks so much again!! :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds