Major Thanks and Hope this keeps working!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by fragilethunder, Nov 7, 2005.

  1. fragilethunder

    fragilethunder Private E-2

    Ok,
    Thanks to you guys and my mom, I have seemingly been able to fix all the bugs in this computer. It did take about 2 days, but...
    I went to your directions and followed them...
    running win 98 made it so I could only get some programs to work, but in the end, it seems to have eliminated the vx2 program that was infecting this computer.
    After several reboots and safe mode attempts...I finally got my isp connection to work again, then I installed ccleaner, hijackthis, and updated spybot and ad aware - . Did you guys know that the autodialer vx2 program could actually disconnect you from the internet? It did! But, I kept at it, though it was really hard and frustrating to have faith at some points...
    So after running the 4 programs mentioned above, and trying the L2mefix and finding it won't work on win 98...I still ended up with a clean system...at least that is what ccleaner, spybot and ad aware are reporting...I am now able to use this computer again, after almost a year of it being disabled by these evil, mean, bad, horrible, aweful...etc...viruses.
    This computer kept coming up with new problems, every time I signed on to try to fix them, and there would be more after each online visit...
    So, I am appending the most recent log I ran from hijacker, just to make sure it is really clean...please let me know if you see anything in it that still needs to be dealt with.
    Thank you Major Geeks! You are so wonderful!!!!
    Much Love and Hugs
    fragilethunder
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log still shows a few infections, please follow the steps below:

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
     
  3. fragilethunder

    fragilethunder Private E-2

    My step by step process is below quoted text and the Hijackthis log is attached...

    I read the read and run me first tutorial.
    I am running Windows 98 on a customized computer and using an AOL dial-up connection.
    I do not have sys restore on win 98 so could not disable it.
    I enabled hidden and system files.
    I downloand and/or updated ad aware, ccleaner, spybot and hijack this plus Kill2me and cwshredder. I ran ccleaner and adaware - ccleaner found lots of cookies and removed them.
    Spybot could not be updated, when I tried it said ===
    I ran Kill2me and cwshredder.
    I ran bit defender and trojanscan online. Both found some things but I cannot say what, I saved the logs from both. I was not able to use any of the other online programs, the pages either did not load or I got errors.
    Then I unplugged the phone from the computer and rebooted into safe mode.
    In safe mode, I deleted several programs using add/remove programs. I removed the AIM and AOL toolbars, real player, the virus program Innoculate (could not update), the AIM and MSN IM programs.
    I removed a few non critical windows components.
    I increased security level in browser.
    Then I ran Cclean, it found nothing
    Then I ran adaware, it found nothing
    Then I ran spybot S and D, it found nothing.
    Then I ran hijack this (I didn't know I was supposed to wait) and saved a log.
    Then I shut all the way down and restarted.
    Then I reran Hijack this and saved another log. I was doing both safe and normal modes to see the differences from the changes I had made to components and program deletions.
    The I went online to report all of this and found I needed to follow a procedure for Hijackthis and followed the procedure, moving the program from desktop to C drive.
    I disabled msconfig - changing it from selective start to normal start which loads all programs, etc.
    I then rebooted.
    Then I closed all the programs I knew I did not need, including my mcafee virus program. ( the one that now comes with AOL) I forgot to turn it back on till now...
    then I re-ran hijackthis and am appending the log file from that. Let me know if all seems clean now.
    Thanks again for your wonderful service.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download Spy Sweeper
    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post along with a fresh HJT log.
     
  5. fragilethunder

    fragilethunder Private E-2

    I downloaded and ran spy sweeper.
    I have attached the new logs from spy sweeper and after I spyswept, I did a hijackthis and am attaching that log as well.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Spy Sweeper

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O16 - DPF: {A5891628-B7A7-470D-B181-FA43C75A734B} - file://C:\WINDOWS\wdlall.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\WINDOWS\about.htm

    C:\WINDOWS\wdlall.cab

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds