Help with malware problems!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nyczmic, Jul 16, 2006.

  1. nyczmic

    nyczmic Private E-2

    I use Zonealarm and i've already followed through the Read & Run me first processes. Two viruses Win32.SillyDl.AGC and a virus in C:\WINDOWS\system32\a4ac978b.exe infected with Win32.ExplorerHijack was identified. Some spyware and adware were also found on my system so i've attached the required logs and i'd appreciate any addition help to have my system clean up comepletely.

    Thanks
    -Mike
     

    Attached Files:

  2. nyczmic

    nyczmic Private E-2

    bumpingg this up...help needed please!
     
  3. AbbySue

    AbbySue MajorGeeks Administrator

    Threads are answered oldest to newest. By bumping your thread you are bumping yourself to the end of the queue. Please be patient and someone will respond with further instructions as soon as possible.

    Good Luck!:)
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    << The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Using Add or Remove Programs in the Control Panel; uninstall the following:
    ViewPoint (Everthing)

    Windows Messeger is running in teh background on this computer, and represents a security risk. Disable Windows Messenger by running Shoot The Messenger. If you are using this as your IM client then replace it with MSN Messenger.

    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  5. nyczmic

    nyczmic Private E-2

    I'm really sorry about making that second account and posting the same message because of my impatience to solve the problem, but thanks so much for all the help.

    I'm not sure if i've uninstalled all of ViewPoint because i couldn't find it on Add or Remove Programs so instead i deleted all the Viewpoint Folders i could find by using Windows Explorer. Also, i couldn't find
    on Hijack This which may be because I ran a scan by Zone Alarm and deleted some files that had the SillyDL before recieving your post.

    Otherwise everything is running fine and again, i'm really sorry for causing problems by that second account but thanks so much for the help.

    I've attached the fresh HijackThis.log below,

    Thanks!
    -Mike
     
  6. nyczmic

    nyczmic Private E-2

    Sorry, forgot to attach the fresh HighjackThis.log..here it is.

    thanks
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Reboot

    Post a fresh HijackThis log.
     
  8. nyczmic

    nyczmic Private E-2

    Thanks, heres the fresh hijack this log

    -Mike
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds