Hijackthis will not scan - need to get rid of this virus!

Discussion in 'Malware Help (A Specialist Will Reply)' started by VeronicaC, Apr 19, 2006.

  1. VeronicaC

    VeronicaC Private E-2

    Hi there,
    I think I have a virus. My home page keeps changing to viruszone.com and my Office XP applications won't open. I cannot get to Symantec.com or run Norton. I just downloaded Hijackthis and as soon as I try to run it, I get a message saying it could be a possible hijack and then it just disappears. Each time I click on it, it shuts down within seconds. I do not know what to do...
    Please help!!
    thank you,
    Veronica
     
  2. VeronicaC

    VeronicaC Private E-2

    ok, miraculously, I was able to get a HT log. I just kept clicking over and over again until it worked. I tried to post this message from my infected pc but it keeps kicking me out. I have disconnected my pc from the network and am using my laptop. Please, please take a look at this log when you have a minute. Any information would be really appreciated. I can't find anything on viruszone.
    thank you,
    Veronica
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You really should be running ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support before posting a HijackThis log. I will give procedure below to try to help work around your current problems. But based on what I see, you could have other hidden problems and the READ ME should be run afterwards to make sure you are clean.

    Download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the newdotnet7_22.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move newdotnet7_22.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\elvnwrtp\csrss.exe
    C:\WINDOWS\system32\elvnwrtp\smss.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://popnav.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - URLSearchHook: (no name) - <default> - (no file)
    F3 - REG:win.ini: load=C:\WINDOWS\system32\elvnwrtp\csrss.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\elvnwrtp\csrss.exe
    O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll (file missing)
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
    O16 - DPF: TruePass EPF 7,0,100,684 - https://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
    O16 - DPF: {41F31718-2B9D-4F76-85E2-DD11BBA99F8D} - http://install.spywarelabs.com/DistID/2501031120/BundleOuter2501031120.EXE
    O16 - DPF: {9076A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - http://www.fizzlewizzle.com/installfiles/powertools.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Accoona <--- the whole folder
    c:\program files\newdotnet <--- the whole folder
    C:\WINDOWS\system32\elvnwrtp\csrss.exe
    C:\WINDOWS\system32\elvnwrtp\smss.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. VeronicaC

    VeronicaC Private E-2

    Re: Hijackthis will not scan -cannot follow instructions given

    ugh,this is a nightmare. I was able to do the Lsp fix and the hoster download but cannot continue with the HighjackThis instructions as it closes as soon as I open it. I thought I would skip it and try to boot in safe mode and surprise, surprise, I can't do that either. I am so frustrated. I did a bit of research and think I may have a variation of the W32.Kelvir.BA but the fix on Symantec is ridiculous as it says to run a virus scan after you disable system restore yet it very clearly says this virus ends services and processes for AVP programs. Am I looking at a re-format situation here?

    Should I just take it in and have this bad boy stripped?

    I would be grateful for any information you could provide...
    thank you,
    Veronica
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijackthis will not scan -cannot follow instructions given

    Locate hijackthis.exe and right click on and select rename. Change the name to myhjt.com

    Now try to run myhjt.com

    If that runs, complete the procedure!
     
  6. VeronicaC

    VeronicaC Private E-2

    Hi there,
    I was able to rename and start to run it but it dies about 3 seconds into it again...

    should I try to boot in safe mode from Dos??
    Thanks,
    Veronica
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WinXP does not have DOS but you could try running the whole procedure in safe mode to see if it will work.

    The two processes below that are running are what's causing you this problem.
    C:\WINDOWS\system32\elvnwrtp\csrss.exe
    C:\WINDOWS\system32\elvnwrtp\smss.exe

    Do not confuse these with the below which are valid:
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\smss.exe

    If you cannot do the procedure in safe mode, let me know if you can get the below program to run:

    ProcessExplorer for Win NT/2K/XP
     
  8. VeronicaC

    VeronicaC Private E-2

    thank you so much for all of your help but I cannot run this either. It flashes up for a second. I have tried to boot to safemode about 20 times and to no avail. I even tried Msconfig from Run but that died too.

    Shall I give up??
    Veronica
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not yet! Which version of Windows XP do you have? Is it Home, Media, or Pro. Do you have a bootable Windows XP SP2 CD?

    Tell me if you can run Windows notepad or Windows wordpad.

    Also tell me if you can get this to run: Pocket KillBox

    Also tell me if you can open a command prompt window by clicking Start, Run and enter cmd and click OK.

    Also see if you can follow the directions in the below links and run the scans.

    Running Spy Sweeper

    Running Ewido Anti-Malware

    If you can run the above scans, attach the two requested logs here.
     
    Last edited: Apr 20, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if the below will run (it needs regedit to work and the malware could block it):

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If it does add into your registry, IMMEDIATELY REBOOT.
    And then try to complete those steps with HijackThis from message # 3.
     
    Last edited: Apr 20, 2006
  11. VeronicaC

    VeronicaC Private E-2

    Hi there,
    I have XP Pro and I'm pretty sure I could dig up the CD. The scan is still running so I will have to wait to try the cmd
    I'm pretty sure I can run notepad but again, i can't try it yet. As it is, each thing that I download, I have to save from my laptop to the network and then I grab it off of my pc. I can't even post to majorgeeks.com from my pc anymore. good times...
    I will do everything you've asked as soon as (if it ever) stops running!
    Thanks again for all of your help. I would be lost without it!
    Veronica
     
  12. VeronicaC

    VeronicaC Private E-2

    ok, yes, I can get to command prompt. I am attaching the spy sweeper file but other than that, the ewido and killox won't work. The fixme.reg didn't work either. I got an error that it was not a valid win32 file (or something like that)
    I guess we're running out of options... the spy sweeper did say I had a back door trojan and that my IE was hijacked. Gee, really??

    Could there possibly be any more options??
    Thank you,
    Veronica
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the Spy Sweeper log. Also download and try the registry patch again. I had a typo in it. You must download and save it again.

    Since you have Win XP Pro.

    • goto a command prompt and enter the below command
      • tasklist /svc > c:\tasks.txt
    • then upload that tasks.txt file her (it should be located in the root folder of drive C)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Please download The Avenger by Swandog46 to your Desktop.
    • Double click on Avenger.zip to open the file and extract avenger.exe to your Desktop
    • Copy the below quoted text (which is a script for Avenger) into your clipboard by highlighting it and pressing CTRL+C
    • Now, run The Avenger program by double clicking its icon on your Desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    The Avenger will automatically do the following:
    • It will Restart your computer. (When the script being executed contains "Drivers to Unload", The Avenger will actually reboot your system two times.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the reboot, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    Please copy/paste the content of c:\avenger.txt into your next message.
     
    Last edited: Apr 20, 2006
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the steps in my last two messages do not help, try the below:


    Download MsnVirRem.exe to your desktop.
    • First close any other programs you have running as this will require a reboot
    • Double click MsnVirRem.exe to run it
    • Once open, click the button labeled Search and Destroy Your computer will now be scanned for Infected Files
    • When scanning is finished you will be prompted to reboot only if infected, Click OK
    • Now click the REBOOT Button.
    • After the Reboot, you will receive file not found errors! Please acknowledge them and continue.
    • A Message should popup from MsnVirRem if not, double click the program again and it will finish.
    • Please Post the contents of C:\msnvirrem.log
    • See if you can now run HijackThis to get a new log. If so, attach it.
     
  16. VeronicaC

    VeronicaC Private E-2

    Hi there,
    Ok, this morning I tried the tasklist cmd and it didn't work. It wasn't a recognizable command. Sorry about not attaching the sweeper log, my head was full of cotton, attached now.
    I was able to load and run avenger with a few errors but I think we killed at least one of the bad files. Again, attached..
    I'm not sure if I should proceed with your next items?

    don't you sleep???
    Veronica
     

    Attached Files:

  17. VeronicaC

    VeronicaC Private E-2

    hi again,
    I went ahead and ran the msnvirrem and it worked and destroyed three files and rebooted. Oddly, the log is blank so I won't bother attaching it. I was able to then use HT no problem (stuff is actually working!!) so I will attach it. I can now go to Symantec so I'm sure the other sites work too. Word still won't open but I'll deal with that later.
    You're a ROCKSTAR!! i can't believe you didn't give up and kept giving me more fixes. I will go back and follow the other steps later (I have to go to work)
    Veronica
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's great news! I'm happy to hear we beat this baddie.
    Since you can now run programs let's immediately add a firewall to your system ASAP. So goto to step 3 in the below link and download and install ZoneAlarmFree.

    How to Protect yourself from malware!

    You will need to reboot after installing ZoneAlarm. After reboot continue with the below.

    Since you already Ewido from my previous instructions, see if you can complete a scan with it now. Attach the log.

    Uninstall Spy Sweeper unless you plan on buying it.

    Rename myhjt.com back to hijackthis.exe to avoid having it look like malware itself.
    Run MSconfig and select Normal Startup!!!!

    Use HJT to fix the the items previously listed in message # 3. Some lines are already gone.

    Then after the fix and the reboot. Attach a new HJT log.

    Since you had such a baddie installed we probably should be safe and run all steps in the READ & RUN ME now.
     
  19. VeronicaC

    VeronicaC Private E-2

    Re: Hijackthis will not scan (you Killed IT!! THANK YOU!)

    Hi,
    I think I have finally done everything you've asked. I will attach the two logs. (hmm, can't seem to find one of them?? Let me know if you still need it!)
    It's weird that I can't launch Norton anti virus anymore or open word. I think I will uninstall and reinstall Office and see if that helps with Word. Should I uninstall Norton and try reinstalling that as well?

    Other than that, everything is just as it should be and I am breathing a HUGE sigh of relief. I cannot thank you enough for all of your hard work and brains to knock this B#$$# off my PC. You really saved me!!!

    Veronica
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hijackthis will not scan (you Killed IT!! THANK YOU!)

    Well Veronica, it seems we are not finished yet!

    You have about 8 to 10 more new malware problems that have showed up. They may have been hiding and were not able to show themselves before or they may have found a way in before you got the firewall. And if Norton is broken, that makes it easier too.

    Before I can work up a fix I want to see if any of them are in Add/Remove programs.

    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  21. VeronicaC

    VeronicaC Private E-2

    Nice. I can't believe this isn't over yet. The good news is I found out that Word will act up if Norton is buggered so I was able to remove Norton, reinstall and now both Word and Norton are working great. I did another system scan on Norton and it only brought up some adware, which I removed.

    Attached is the HT uninstall scan. Please let me know how I should proceed.

    Thanks again!
    Veronica
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it would be best not to run or install anything unless I request it. You could just keep changing the symptoms or cause things to spread by doing so.

    The only thing I note from your Uninstall Programs list is that you do not have the current versions of the below programs:
    Java 2 Runtime Environment, SE v1.4.0_01
    Java Web Start
    Mozilla Firefox (1.5)
    Spybot - Search & Destroy 1.3


    Do not do anything with the above yet! We will update these later after removing any malware.

    Okay since you ran Norton again and things may have changed, I will need to see a new HijackThis log. After attaching it, do not run anything else to try and fix any malware issues. Please wait for my next instructions.
     
  23. VeronicaC

    VeronicaC Private E-2

    HI there,
    Sorry about the Norton scan. It prompted me after I re-installed it and I thought it wouldn't hurt.
    Here's the latest HJT file...

    THanks!!
    Veronica
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It's good we got a new log! Two more baddies showed up! I going to give you a quick fix with HijackThis and then afterwards I want you to run a couple scanning tools. I will tell you what to run and when.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
    O4 - HKLM\..\Run: [XupiterStartup] C:\Program Files\Xupiter\XupiterStartup.exe
    O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
    O4 - HKLM\..\Run: [SearchEnhancement] "C:\Program Files\scbar\v1\scbar.exe" /U
    O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
    O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\System32\internetfeatures.exe
    O4 - HKLM\..\Run: [msnarrator] C:\WINDOWS\msnarrator.exe
    O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
    O4 - HKLM\..\Run: [iefeatures] C:\WINDOWS\System32\iefeatures.exe
    O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
    O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
    O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
    O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Xupiter <--- the whole folder
    C:\Program Files\PrecisionTime <--- the whole folder
    C:\Program Files\Common Files\GMT <--- the whole folder
    C:\Program Files\Date Manager <--- the whole folder
    C:\Program Files\scbar <--- the whole folder
    C:\Program Files\Power Scan <--- the whole folder
    C:\WINDOWS\System32\stcloader.exe
    C:\WINDOWS\System32\internetfeatures.exe
    C:\WINDOWS\System32\iefeatures.exe
    C:\WINDOWS\Belt.exe
    C:\WINDOWS\msnarrator.exe
    C:\WINDOWS\MSMGT.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see Ewido installed anymore. Did you uninstall it? Looks like you may have uninstalled it when I asked you to uninstall Spy Sweeper, but I only wanted Spy Sweeper uninstall and I did ask for you to retry Ewido in message # 18.

    I want you to run a full scan with it (per the instructions for Ewido in message # 9) and attach the log.
     
  26. VeronicaC

    VeronicaC Private E-2

    Hi there,
    Ok, I did the HJT fix and have successfully booted into safe mode (for the first time!!) When I go to WE to delete the files listed, none of them exist?? I definitely have my files properties to show hidden files. Should I just continue on with the steps??

    Sorry about deleting Ewido and CCleaner. After I thought everything was done, I didn't see the point in keeping them. I did run Ewido when you asked me to but that was the log I couldn't find!! I will run it again and send you the log.

    In my start menu, I have an EXE that's called Otter Tips and I have never seen this before.

    I'll do the rest right now and send you the HJT first..
    Thanks!!
    Veronica
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, just continue thru ALL steps and attach the new HJT. Then run Ewido and attach the log .

    It was not in your last HJT log things were getting added each time you posted a new one. I would delete it!
     
  28. VeronicaC

    VeronicaC Private E-2

    Great, thanks. I cannot see my Network in safemode so I wasn't able to grab the ccleaner. I had to reboot back into Normal so I could download it but my desktop came up with no icons and I couldn't click on start. ARGH!! I don't know what's going on but I had to hard boot my pc so we'll see what happens after it checks my system file. (I know I can opt out of this but even when I hit a key to stop it, it starts anyways.)

    Again, thanks for everything. I'm getting pretty disheartened now though... I totally thought we had this!
    Veronica
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are referring to.
     
  30. VeronicaC

    VeronicaC Private E-2

    HI,
    Sorry for the confusion. If you incorrectly shut off your pc, when you reboot it asks to if you want to scan the files. You can hit any key to avoid doing this but that never seems to work for me. It's not relevant here and I should stop my incessant ramblings!!

    So, I have done what you've asked. Attached is the latest HJT log and the Ewido log. If it's ok, let me know and I will disable System restore etc, as per the step 1 instructions.

    Thanks so much!
    Veronica
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now you can uninstall Ewido! Don't uninstall anything else (like CCleaner), the other tools are all good to keep around.

    You still have one problem that seems to have been missed from my previous instructions. So let's repeat the steps for just it.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [msnarrator] C:\WINDOWS\msnarrator.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\msnarrator.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  32. VeronicaC

    VeronicaC Private E-2

    Hi there,
    I was able to fix the file in HJT but when I try to find it in Explorer to delete it, it's not there. Shall I still proceed with the remaining instructions??

    Thank you!!
    Veronica
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It mayhave been remove by HJT this time or even the previous time.

    If it is gone from your log, you should be ready for the final steps below! ;)

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Veronica,

    If you still have the C:\msnvirrem.log file. Please attach it here. It really should not be an empty file. There should be something in it even if it is only some default text information.
     
  35. VeronicaC

    VeronicaC Private E-2

    Hi there,
    Sorry for the delay in responding, I been avoiding my computer!:rolleyes:
    I will attach the MSNVIRREM log here. Other than that, I did everything you asked in the last post, including the system restore instructions.

    Should I just get rid of MSN as this must be where it originated? I have told my kids not to use it anymore as I'm too worried about going through this again. What do you think??

    I cannot thank you enough for all of the time and efforts you have put forth for me and this nasty virus. I was one step away from dropping it off at the local computer shop for a re-format. I have told everybody at work about MajorGeeks and I really think you should be charging for the service.

    I'm in Canada but if there's anything I can do for you, just holler!

    Veronica
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for attaching it. I guess Avenger had actually removed the files first.

    MSN is not the cause of the problems. It is where the you surf and what you download/install or even click on that can be the problems.

    You're welcome again and thanks for the plugs with your fellow workers. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds