Need Help! :D

Discussion in 'Malware Help (A Specialist Will Reply)' started by Azurewrath, Jun 16, 2007.

  1. Azurewrath

    Azurewrath Private E-2

    Hiya! I got a virus, no idea what from, well, I followed the steps in the sticky, and I got a bunch of logs for you guys v_v It's really annoying, it seems like randomly at certain times, my computer will just go slooooooooow, but regularly it seems perfect, also, I get popups, lots of popups, even in firefox, the popups come up in IE, most of them are broken links, but some bring me to Monster.ca, gambling sites, etc.
     

    Attached Files:

  2. Azurewrath

    Azurewrath Private E-2

    Thats the Hjt and AVG logs. :)
    Edit: ahh the AVG log wont attach, lemme fix that.
     

    Attached Files:

  3. Azurewrath

    Azurewrath Private E-2

    Sorry I'm such a spammer @_@

    So, about these scans. All the spyware ones seemed to remove everything, but the online scanners were only able to remove about half the stuff it detected,
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You must allow programs to fix what they find. You did not have AVG Antispyware fix what it found. You took no action. You must run it again and Quarantine or Delete what it finds this time. Then attach a new and make sure it is the complete log (do not cut of the top like you did last time.

    Also you skipped or just did not perform step 2 of the READ ME properly, please do it now.

    Also you did not attach the requested log from BitDefender. Please attach it.

    Now Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    VSAdd-in for Internet Explorer <-- should have been uninstalled in step 0 of the READ ME

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [SfKg6w] C:\WINDOWS\djlrua.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
    O20 - Winlogon Notify: winowl32 - winowl32.dll (file missing)
    O20 - Winlogon Notify: winuqw32 - winuqw32.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds