Malware Nightmare: Am I OK now? All steps ran

Discussion in 'Malware Help (A Specialist Will Reply)' started by janed1031, Jan 14, 2006.

  1. janed1031

    janed1031 Private E-2

    Hi,
    I have been dealing with this since before the holiday--so maybe now that I have followed all of your steps, I am OK, but who knows?
    I ran steps 1-7 in "read & run me first". I have attached my 'Panda Active Scan', but my 'bitdefender' scan exceeded the file size (mine was 272 kb?) so it wouldn't let me attach.

    I also ran the special removal procedure for "about: blank" (simplified) and I have attached the log from about:Buster as well. That program seemed to find many errors related to CoolWWWSearch that had been identified on AdAware and Spybot but kept re-appearing. Finally, I am attaching my HJT log. I hope that I did this all correctly, and that my problem is gone, but could someone take a look and see?
    Thanks,
    Jane
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Follow the directions for Smitfraud, SpySheriff, SpyAxe & PSGuard Removal.

    Now scan and have HJT Fix the following:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.


    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Follw the directions for Running Ewido Security Suite.

    Post the Ewido log, smitfiles.txt, and a fresh HijackThis log.
     
  3. janed1031

    janed1031 Private E-2

    OK, I did all of this, and the computer is running about 100x faster than it did this morning! I will attach the smitfiles, ewido log and a new HJT log. Please let me know if I need to do anything else, but otherwise THANK YOU so much!!
    Jane
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix teh following:
    REBBOT

    Post a fresh HijackThis log.
     
  5. janed1031

    janed1031 Private E-2

    here you go, HJT log #2.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds