I still have huge problems even after READ & RUN ME FIRST

Discussion in 'Malware Help (A Specialist Will Reply)' started by ruffak, Dec 2, 2007.

  1. ruffak

    ruffak Private E-2

    ok i did all the istruction stated in the READ & RUN ME FIRST thead, and i even had problems along the way. 2 problems actually:
    -after i did the AVG anti-spyware scan, it did not make a report for me even though it found an infected file and i unchecked the "publish report only if infected file was found" box.
    -my second problem was when i was using MGtools.exe . i ran the first step in disabling the USER ACCOUNT CONTROL, and it said it was successfull, but when i run GetLogs.bat USER ACCOUNT CONTROL pops up again and again and again like a virus, no matter what i press, i dont even get a chance to close the program.!!!

    Now about the malware i have. it's an adware i think, pop-up adds come up everytime i open IE, and everytime i click a link, everytime i go to any website, and my laptop became extremely slow. i've had it for about 5-7 days now. i was using my laptop normally, no weird websites visited or anything, but i think it was around the time i installed a home networking program called "Network Magic" , but the other 2 computers which are connected in my network dont have it. i was using norton, and it didnt pick it up, so i did a scan and it verified it as vundo.trojan, and it wouldnt delete it or anything. so i downloaded the program the recommended called vundofix and it didnt work, downloaded 2 different programs to fix it, one is called FIXvundo(different from the one norton recommonded) and another one, both didnt even find it.
    Then i downloaded avast and removed norton,avast also found infected files, and i delete them and it says successfully removed, but still i open IE and there they are. i also tried ad-aware 2007, but no use either. seriously im really desperate to get this fixed cause my laptop is runnig extremely slow, my next move is basically formating my pc, and thats a huge issue, you are my last hope, i would greatly appreaciate it. thanks
    attached is the only log i obtained.
     

    Attached Files:

  2. tunered

    tunered MajorGeek

  3. samtal

    samtal Corporal

  4. ruffak

    ruffak Private E-2

    i read i should do the HiJackthis log, so i did.
    and i downloaded the vundofix application from this website to fix the problem. wut happened was it found 2 files, and when i delete them, screen goes blank once then comes back then goes blank again and never comes back, instead my pc just reboots after like 30 sec. by itself.
    something else, all the ads and gif pictures on websites, even majorgeeks website suddenly change and start flashing " u have adware do a scan now " but only on my default browser (IE). i swear to god its like its evolving or something.
    please help me on this. much appreciated. thanks
     

    Attached Files:

  5. ruffak

    ruffak Private E-2

    ok i managed to get the mgtools.exe working and attached the zip file. the only thing i still cant obtain is the log file for AVG anti-spyware, simply because it wont make one. even after i double checked the settings and did anther scan, it found an infected file but wouldnt give me a log.
    just in case though, does it make it a log file and store i somewer without apearing under the reports tab in the program?
     

    Attached Files:

  6. ruffak

    ruffak Private E-2

    Re:huge malware problems even after READ & RUN ME FIRST

    Avast keeps finding viruses by itself, but AVG anti-spyware doesnt and says everything is ok. i attached the avast log. hopefully that will help. and btw does it usually take 5 days for some1 to help me..??!!
     

    Attached Files:

  7. ruffak

    ruffak Private E-2

    Ok now it seriously became worse. i opened my pc today and now whenever i go to any website either in firefox or IE, it cant show pictures, and instead starts flashing "spyware remove", and for lets say im on youtube and click on the picture instead of the link, pop ups come up like crazy, and before it used to be one at a time, but now multiple pop ups at once. sometimes but not always when i press a link, a new browser window opens and tells me BAD GATEWAY and my computer freezes completely. please tell me what should i do. thanks in advance
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: huge malware problems even after READ & RUN ME FIRST

    Sorry about that, but no it does not normally take that long. This happened because you did not originally post in the Malware Forum with your problem and this caused you to slip by unnoticed. This was due to the fact that your thread was eventually moved to the malware forum, but since it had a number of posts in it, it probably looked like someone was already working on it. Also each time you posted a message, you lost your place in the work queue as explained here: Don't Bump! It Only Hurts You!!!

    I'm working thru your logs now and will post with a fix in a little while.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First we need to cleanup some left over services from Symantec.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Lic NetConnect service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • LiveUpdate Notice Service Ex
      • LiveUpdate Notice Service
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste CLTNetCnService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • LiveUpdate Notice Ex
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now uninstall the below old versions of software:
    Java(TM) SE Runtime Environment 6
    LiveUpdate Notice (Symantec Corporation)

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {D1224678-95D3-4469-9685-6AB719C12957} - C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [BM3b2de365] Rundll32.exe "C:\Users\mo2men\AppData\Local\Temp\qimkjvna.dll",s
    O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\mo2men\AppData\Local\Temp\ljhff.dll,c
    O4 - HKCU\..\Run: [BM3b2de365] Rundll32.exe "C:\Users\mo2men\AppData\Local\Temp\qimkjvna.dll",s

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    C:\Users\mo2men\AppData\Local\Temp\qimkjvna.dll
    C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    C:\Users\mo2men\AppData\Local\Temp\qimkjvna.dll
    C:\Users\mo2men\AppData\Local\Temp\ffhjl.ini
    C:\Users\mo2men\AppData\Local\Temp\ffhjl.ini2
    C:\Users\mo2men\AppData\Local\Temp\IpAdrSet.log
    C:\Users\mo2men\AppData\Local\Temp\mo2men.bmp

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now delete the below folder if it exists:
    C:\Program Files\Common Files\Symantec Shared

    Now copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
    that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. ruffak

    ruffak Private E-2

    sorry for the late reply, had an exam yesterday.
    omg than you sooo sooo much seriously. you are unbelievable. till now looks like everything is back to normal. no pop ups, ads on websites are back to normal. so hopefully i did everything right. i attached the mglogs.zip file like you said. and when you say Avenger you mean the AVG Anti-spyware?? yea about that it still doesn't make logs when i do full system scans, but does when i do memory scans.
    Again thank you soo much you are amazing. i'll give it a couple more days, if nothing comes up till then, then i'll be allright.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some items we were trying to fix did not get fixed last time. Make sure that you exit ALL browsers before clicking fix in HijackThis!!
    We need to remove another bad service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DomainService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {26892337-7EA8-4D58-BFE3-67FF6ED1CF5F} - C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    O2 - BHO: (no name) - {77A2773C-ACE5-4632-9AD1-FDFC994BE696} - C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    O2 - BHO: (no name) - {B98267BC-2CFB-4128-BB20-1A7D98E2B9C2} - C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    O2 - BHO: {b599540a-10c7-142a-d654-5c8d6df241fc} - {cf142fd6-d8c5-456d-a241-7c01a045995b} - C:\Windows\system32\fyvqddxb.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [381ed0f9] rundll32.exe "C:\Windows\system32\gophapjo.dll",b
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Windows\system32\gophapjo.dll
    C:\Windows\System32\bdsqfixf.exe
    C:\Windows\System32\pbkkjcyr.exe
    C:\Windows\System32\frbwlack.dll
    C:\Windows\System32\fyvqddxb.dll
    C:\Windows\System32\gophapjo.dll
    C:\Windows\System32\iwjpmkbj.dll
    C:\Windows\System32\jagkkdwn.dll
    C:\Windows\System32\yudekrdc.dll
    C:\Windows\System32\bnjwgqrx.ini
    C:\Windows\System32\cdrkeduy.ini
    C:\Windows\System32\ojpahpog.ini
    C:\Windows\System32\drivers\11BA2788-6475-4E8D-8169-CFC805E27698.cxv
    C:\Users\mo2men\AppData\Local\Temp\ffhjl.ini
    C:\Users\mo2men\AppData\Local\Temp\ffhjl.ini2
    C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot look for all of the above files we had Pocket Killbox attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created
    Make sure you tell me how things are working now!
     
  12. ruffak

    ruffak Private E-2

    ok 2 problems which i think you will also notice from the mglogs report.
    HJT couldnt fix

    O2 - BHO: (no name) - {77A2773C-ACE5-4632-9AD1-FDFC994BE696} - C:\Users\mo2men\AppData\Local\Temp\ljhff.dll

    everytime i do the scan it pops back up again
    also Pocket Killbox couldnt delete some of the files, so i deleted them manually, all of them got deleted except

    C:\Users\mo2men\AppData\Local\Temp\ljhff.dll

    an error kept coming up that it was used by another program
    and the 2 files

    C:\Users\mo2men\AppData\Local\Temp\ffhjl.ini
    C:\Users\mo2men\AppData\Local\Temp\ffhjl.ini2

    kept coming back everytime i deleted them. i rebooted the pc in safe mode an deleting them, but that didnt work either.
    thanks for ur time.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we will try this a different way since Killbox cannot remove the files since they are hooked into several running processes.

    Let's begin with by removing a service from VundoFix which should not be running.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to VundoFix Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteVundoFixSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now let's cleanup from Pocket Killbox
    • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    • Now close/exit Pocket Killbox
    Continue by downloading a tool we will need: Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    Run Process Explorer by double clicking on the procexp.exe file.
    • Step 1 - unhook DLL from rundll32.exe
    • In the top section of the Process Explorer screen double click on rundll32.exe to bring up the rundll32.exe Properties form.
    • Click on the Threads tab at the top.
    • Once you see this screen click on each instance of the ljhff.dll files (if found) and then click the kill button.
    • After you have killed all instances of any of ljhff.dll under rundll32.exe click ok.
    • (If you do not find ljhff.dll , just continue on.)
    • Step 2 - unhook DLL from lsass.exe
    • Next double click on lsass.exe to bring up the Properties form.
    • Click on the Threads tab at the top.
    • Once you see this screen click on each instance of the ljhff.dll files (if found) and then click the kill button.
    • After you have killed all instances of any of ljhff.dll under rundll32.exe click ok.
    • (If you do not find ljhff.dll , just continue on.)
    • Step 3 - unhook DLL from explorer.exe
    • Next double click on explorer.exe to bring up the Properties form.
    • Click on the Threads tab at the top.
    • Once you see this screen click on each instance of the ljhff.dll files (if found) and then click the kill button.
    • After you have killed all instances of any of ljhff.dll under rundll32.exe click ok.
    • (If you do not find ljhff.dll , just continue on.)
    • Step 4 - unhook DLL from iexplore.exe
    • Next double click on iexplorer.exe to bring up the Properties form.
    • Click on the Threads tab at the top.
    • Once you see this screen click on each instance of the ljhff.dll files (if found) and then click the kill button.
    • After you have killed all instances of any of ljhff.dll under rundll32.exe click ok.
    • (If you do not find ljhff.dll , just continue on.)
    Now just exit Process Explorer.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {0CB5E62A-BEC4-4815-AB47-684C5C779443} - C:\Users\mo2men\AppData\Local\Temp\ljhff.dll
    O2 - BHO: (no name) - {CCC4C770-86E8-4FDB-94A1-0C96E28F7342} - C:\Users\mo2men\AppData\Local\Temp\ljhff.dll

    After clicking Fix, exit HJT.


    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have the below icons on your Desktop (double click the thumbnail to expand it)
    [ CFScript.jpg
    • Now refer to the above image and use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.

    Make sure you tell me how things are working now!
     
  14. ruffak

    ruffak Private E-2

    well i think it worked, but not completely. i mean the pop ups stopped coming up, but the pictures on websites still dont show but instead falsh "malware detected" or "fix now". well pictures show but only until the page finishes loading then they become like that. now i did everything you said, no problems came up, i have no idea whats causing the flashing pictures though.
    and for some reason MgLogs would not get attached. ill try posting it after a lil while in another reply. but combofix's log is there.
    thanks so much for your time.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must make sure you re-ran GetLogs.bat to create a NEW log. You cannot attach the same log as previously attached.

    Quick do the below ASAP!!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  16. ruffak

    ruffak Private E-2

    ok i did that and i ran getlogs.bat 2 minutes ago, and it said it created a new log, but when i come to upload it and press on the upload button, it says "internet explorer cannot display the webpage", but that didnt happen when i tried attching the combofix log.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you log into MajorGeeks, make sure you are checking the box that says remember me. Then try again to upload the file.

    Otherwise try attaching using Mozilla Firefox.
     
  18. ruffak

    ruffak Private E-2

    it didnt work even when i checked the remember me box, and it also didnt work when i tried uploading it via firefox. the only way it got uploaded is using another computer. is that a problem caused by the malware?
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly it is related to the malware. Did you run the fixME.reg patch given in message # 15?
    • If so, was that before or after getting the logs that are in MGlogs.zip.
    • If not, please run it now! Also tell me if you received a success message on adding it to the registry.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [BM3b2de365] Rundll32.exe "C:\Windows\system32\lwdvlfbv.dll",s


    After clicking Fix, exit HJT.


    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should now have both ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now refer to the above image and use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.

    Make sure you tell me how things are working now!
     
  20. ruffak

    ruffak Private E-2

    i dont remember exactly if it was before or after i made the mglogs, but i did it again just in case.
    and just to let you know atfirst HJT wouldnt delete

    O4 - HKLM\..\Run: [BM3b2de365] Rundll32.exe "C:\Windows\system32\lwdvlfbv.dll"

    but then i tried again after i let combofix do its thing, and it worked it got deleted i think.

    well pics on websites are back to normal now so im guessin finally all remaining malware has been removed, but give a couple of days to make sure, and im here if i did anything wrong or there's still something else.
    thanks alot for your time. much appreciated. :D
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  22. ruffak

    ruffak Private E-2

    well im happy to tell u that everythin is goin great. pc back to its old self. u have been a major help to me seriously, and i really appreciate the time u spent solvin my problems. thanks alot.
    i read ur thread on keepin my self prtected from malware and viruses, but i have a quick question, do u by any chance have any idea how i got this malware? so that i stay away from it.
    thanks alot :D. i let u get back to bein a malware hero :D. tc.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not easy to say exactly where; however, common places for infections like this are:
    1. questionable download sites especially anything porn, game cheating, software cracking,...etc sites
    2. downloading special codecs to view video files
    3. P2P and Torrent downloading (which can be related to # 1)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds