Logs after running "Read and run me first"

Discussion in 'Malware Help (A Specialist Will Reply)' started by bjagd02, Feb 20, 2007.

  1. bjagd02

    bjagd02 Private E-2

    Now my girlfriends computer is infected...again...

    CounterSpy detected no problems...

    AIM stopped working, wont reinstall, blue screen on desktop, SmitFraud detected.

    Thank you again!
     

    Attached Files:

  2. bjagd02

    bjagd02 Private E-2

    more posts.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not follow the instructions in the Read and Run First - uninstall HJT and re-install properly and re-name it.

    C:\Documents and Settings\Staples\Desktop\STUFF\Anti Virus,Spy\hijackthis\analyze.exe
    It should be in C:\HJT\analyse.exe

    This may be part of your problems, but we need to do a few things first:
    C:\\Program Files\\Warez


    You did not un-hide the files:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new logs for:
    ShowNew
    GetRun
    HJT
     
  4. bjagd02

    bjagd02 Private E-2

    Read and run me first says to put HJT in program files but i will follow your instructions.
    I hope I did it right this time.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall these:
    Viewpoint Media Player
    WildTangent GameChannel
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6

    Reboot and install:
    Java Runtime 6

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop


    After clicking Fix, exit HJT.
    Run CCleaner to delete your temporary files,

    Other than those few minor items, I don't see any problems. You may uninstall any programs that we had you download.

    I would recommend that you scan everything that you download prior to running.

    If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  6. bjagd02

    bjagd02 Private E-2

    Thank you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds