Me again needing help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tammylyne, Sep 29, 2005.

  1. Tammylyne

    Tammylyne Private E-2

    OK I downloaded something accidently..I was walking my friend via telephone on a download she wanted and it downloaded on my computer.After downloading I could not sign on to aol then everytime I would reboot I got this blue screen telling me something about a fatla error..can someone check my log and let me know if I am OK..I promise I will not download anything ever again :(
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Tammylyne

    Tammylyne Private E-2

    [- Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc. ]

    OK did all the steps but did it in reg mode not sure how to run an online scan in safe
    CC gave me an error message of overload?
    Bitshredder found trojan and virus(password stealer) and was unable to update(Now a little background.The program I was guiding my girlfriend through(the blind leading the blind here :rolleyes: ).that I accidently downloaded was a spyware program she wanted to put on her computer to monitor her teenage daughters online activity called remote assistance)
    Rav found an infected files in my documents and settings folder I had it set to autoclean but it did not say that it cleaned it.I ran another scan on that folder alone and no infections were found.Log is attached below
    Thanks so much for helping me!
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    From Add or Remove Programs in the Control Panel uninstall the following:
    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now scan and have HJT Fix the following:
    Open Windows Explorer navigate to and DELETE the following:

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. Tammylyne

    Tammylyne Private E-2

    here is the new hijack file.Did ever step you asked..spybot did find something called my websearch and cleaned it for me
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HJT log shows no signs of malware infection. What problems are you having?
     
  7. Tammylyne

    Tammylyne Private E-2

    When I run the bitdetector scan it says my AIM instant messenger.exe is found infected with Adware.wheater bug and update failed ?
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please run Panda Online Scan. After the scan attach the log to your next post. Also please follow the below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post all three logs as attachments.
     
  9. Tammylyne

    Tammylyne Private E-2

    OK did everything you needed but can only attach 2 files at a time.So will make 2 posts,in second pot will be the 3rd txt file.I hope I did this OK :)
    thanks again for your help
     

    Attached Files:

  10. Tammylyne

    Tammylyne Private E-2

    POST 2 attaching 3rd file
     

    Attached Files:

    • log.txt
      File size:
      653 bytes
      Views:
      2
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    f Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    REBOOT

    Run ExplorerXP and delete the following:


    Empty your Microsoft Anti-Spyware Quaratine
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds