Need help with hijackers and possible viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by hagarluver, Oct 28, 2006.

  1. hagarluver

    hagarluver Private E-2

    Hello,

    I am running Microsoft Windows XP Professional SP2. I am currently using the Microsoft Firewall, AVG and Spybot S&D. I have read through the read & run me and just about everything else pertaining to this topic in the forums.

    First of all, when I would open up IE it would redirect to the safeiepage that said I had W32.Myzor.Fk@yf and numerous system warning messages would pop up through the yellow triangle sign at the bottom right hand corner and porn popups. I tried to system restore a couple of different dates and it wouldn't do it. So I turned off the system restore and restared in safemode. Then I ran hijack this and had this program take off an RO-HKLM (search assistant called as.starware.com/dp/search), 02-BHO (c:\Program Files VideoKeyCodec\isaddon.dll) and 021-SSODL:contrabandists. Then I ran the smitRem.exe. After I did this I logged back into normal mode and ran Panda ActiveScan. I've attached all 3 reports.

    The highjack this was able to take care of the IE redirection to the safeiepage and I haven't received any more popups and warning messages, but Panda is still reporting hijackers, spyware and possible viruses.

    Would you please help me lol :) ? If you need anymore information please let me know.

    Thank you soooooo much!!
     

    Attached Files:

    Last edited by a moderator: Nov 3, 2006
  2. matt.chugg

    matt.chugg MajorGeek

    Your HJT log looks as if it was run from safe mode or that you are editing startup entries with another program.

    Please run HJT from Normal Mode and post a new log.

    Please also post the other 3 logs we requested in the Read and Run Me

    ShowNew
    RunKeys
    Bitdefender Online
     
  3. hagarluver

    hagarluver Private E-2

    Thank you for your help. I ran HJT in normal mode and I've also attached the other reports needed.
     

    Attached Files:

  4. hagarluver

    hagarluver Private E-2

    Here's the 4th file.
     

    Attached Files:

  5. matt.chugg

    matt.chugg MajorGeek

    Using Add/Remove programs from control panel uninstall the following

    Reboot into safe mode and delete the following folders

    post a new activescan and new shownew log.
     
  6. hagarluver

    hagarluver Private E-2

    Hello,

    I removed p2pnetworks from the control panel uninstall.
    I then rebooted into safe mode and went into program files
    and none of the files you have listed to delete were there.
    So I ran the Panda scan and then I rebooted into normal mode
    to run the shownew.bat.
     

    Attached Files:

  7. matt.chugg

    matt.chugg MajorGeek

    what is this?! where did it come from?

    reboot into safe mode and delete it!

    C:\WINDOWS\pss\Skunk.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds