Just got infected.

Discussion in 'Malware Help (A Specialist Will Reply)' started by nigneil146, Mar 8, 2009.

  1. nigneil146

    nigneil146 Private E-2

    I think I just got infected. I was on zshare in firefox with adblock and it wouldnt display the page. Stupid me opens it in IE and I start getting popups. ZoneAlarm pops up asking to let run32.dll access the internet. I deny and yank the ethernet.

    Im running spybot now. The only other tool I have that you recommend is hijackthis.

    Im not sure if I should plug back in to go online and download the other tools in the read me first.

    Thanks in advance!
     
  2. nigneil146

    nigneil146 Private E-2

    Well I connected back up and ran through the run and read first. Everything seems fine, but can someone please look through my logs just to make sure.

    Thanks
     

    Attached Files:

  3. nigneil146

    nigneil146 Private E-2

    Thanks again.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please make sure msconfig is in normal startup mode.

    Using keygens and cracks is a good way to get infected.

    You did not remove your old Java....go to add/remove programs and uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0"

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    c:\windows\SYSTEM32\savupipa.dll
    c:\windows\SYSTEM32\jenanibi.dll
    c:\windows\SYSTEM32\yisupego.dll

    Now run CCleaner.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds