I have tryed everything and still have problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by julianjordan, Sep 14, 2004.

  1. julianjordan

    julianjordan Private E-2

    Hi, before posting this thread, I installed and run all the antivirus and spyware programs you suggested. I even run hijackthis and finally could eliminate the searchmiracle from my system.

    However, everytime I start my computer, a small ie window appears every once in a while with search results on casinos and phorno.

    Can I attach my log to see if you see anything wrong?

    Thanks for your help.

    Julian
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First check Add/Remove programs for anything that does not belong there and then
    you should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    And then post your HijackThis log as a .txt file attachment. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. julianjordan

    julianjordan Private E-2

    Attached log file as you asked

    Hi, attached is my log. I have done everything you suggested on the READ ME FIRST BEFORE ASKING FOR SUPPORT, and followed the hijackthis tutorial.

    You asked me to attach my log on a new thread, and here it is.

    Thanks for your help

    Julian
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Attached log file as you asked

    My message mislead you about (new thread). It was a cut & paste from the HJT tutorial which assumed you did not have a thread already. I merged you back into your original thread.
     
  5. julianjordan

    julianjordan Private E-2

    Ok, great, thanks. I'll be waiting for your help.

    Julian
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Attached log file as you asked

    You should have run EVERYTHING from the READ ME FIRST tutorial. You did not. I see no evidence that the online scans were run.

    Run HijackThis and have it Fix the below lines:
    O4 - HKLM\..\Run: [Windows service] slserv32.exe
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winohy32.exe
    O4 - HKLM\..\RunServices: [Windows service] slserv32.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    Are these two below lines what you expect for your start page and search page? If not, have HijackThis fix them too:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/All%20Users/Documentos/Mis%20documentos/Mis%20Webs/Portal/HOME.HTM
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com

    Make sure you have enabled viewing of hidden file per the read me.
    Reboot in safe mode and delete:
    C:\WINDOWS\System32\slserv32.exe
    C:\windows\system32\winohy32.exe

    You should also get yourself over to Microsoft Update. You are way out of date with WinXP and with Internet Explorer.
     
  7. julianjordan

    julianjordan Private E-2

    Thanks!! I did it and I think it is working fine.

    I did the online scan yesterday, in fact it took a couple of hours to finish. Maybe I did something wrong since you couldn't detect it.

    Thanks a lot for your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds good! Just check another HJT log yourself and make sure all those items I gave you to fix are gone and did not come back.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds