newbie needing help

Discussion in 'Malware Help (A Specialist Will Reply)' started by antoniog77, Jul 9, 2006.

  1. antoniog77

    antoniog77 Private E-2

    Hello I am new here and would appreciate any help whatsoever. I believe I am infected with a malware or trojan. My homepage has been changed from yahoo, I am gettin numerous popups and overall the pc seems to be much slower. Here is some info about my pc: dell dimension with pentium r4 cpu 3ghz with 256mb of ram, windows xp sp2 and 50gb hard drive. I have run the read & run me first programs. If there is anything else I need to do please let me know. The problem has not been solved yet thanks in advance
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Sorry to say but you will need to run through the Read ME again as your HJT log was run from the exact location we insist it is not run from a Temp folder and run from inside a RAR file

    C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX06.531\HijackThis.exe

    Also mentioned in the guide is not to have any browser windows open when running HJT

    C:\Program Files\Internet Explorer\iexplore.exe


    Please do follow the standard cleaning procedures verbatim as it may take alot longer to remove your malware if not, these are well tested procedures that do help if followed... cheers :)


    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. antoniog77

    antoniog77 Private E-2

    I have run everything again and the following viruses were found by bitdefender
    trojan downloaders HTML, VB.IN, ADLOAD, QOOLOGIC, AND PURITY/S
    panda found dialers on the pc
    I had to run panda in normal boot mode it would not work in safe mode. I am attaching the new logs
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have ignored step 3 of the READ ME.

    Please uninstall ALL but one antivirus program from your PC.

    Then run the below because your logs show signs of a SpywareQuake infection.

    SpywareQuake & SpyFalcon Removal Procedure

    Attach the smitfiles.txt log afterwards!

    I see Spy Sweeper and PC Tools Spyware Doctor! Are these free versions of paid versions. If free trials, uninstall them.
     
  5. antoniog77

    antoniog77 Private E-2

    before I proceed with your instructions, I just had some questions about my virus protection removal. I have mcafee firewall only and zone labs firewall also. The only actual antivirus I have is norton, which one should I remove
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your HJT log you have more than just McAfee's Firewall running. You have their whole security center running too:
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe

    Obvious choice is to uninstall all of McAfee. Just like with antivirus applications, you only want one firewall.
     
  7. antoniog77

    antoniog77 Private E-2

    I will continue tomorrow and post results then have to put the baby to bed. Thank you for your help
     
  8. antoniog77

    antoniog77 Private E-2

    I uninstalled mcafee and ran the spyquake falcon removal. I did not see any of the files it said to delete, here is the smitfiles log also. If there is anything else I need to do please let me know
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a new HJT log now and also tell me how things are running!
     
  10. antoniog77

    antoniog77 Private E-2

    things seem to be running fine, I was able to finally return my homepage to yahoo. Here is the hijack log
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean but did you knowingly install the below toolbar?

    O2 - BHO: Big Fish Games Toolbar - {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - C:\PROGRA~1\BFGTOO~1\BFGTOO~1.DLL


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  12. antoniog77

    antoniog77 Private E-2

    no my wife may have installed it though
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check with her! I'm not saying it is malware, but anything that you did not knowingly install should always be removed especially if you know you don't use it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds