Please help remove malware from my PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by NoBull, Jul 2, 2006.

  1. NoBull

    NoBull Private E-2

    Ever since being dumb enough to click on a link to download a new codec for WMP, I've had malware on my PC. Symptoms are listed below.

    1) A little yellow warning triangle with a black exclamation point in it in the system tray giving a spyware warning : "System Alert : Popups" and saying something about "OHPE ver 4.12_23" being installed and managing popups. If I click on this triangle it brings up IE on one of a few different pages wanting to sell me "spyware removal software" I have not done anything but close these pages.

    2) Popup's from "adultfriendfinder.com", "Monaco Gold Casino", "Live Saety Center" and Security Help Center" (these ar ewhat I've made note of so far. I'm sure there are more).

    4) about:blank ( I have yet to follow the process to try to remove this one. I will do that shortly.

    I have followed the instructions in the basic spyware removal thread. Installed all the tools. Run all the procedures. It found and removed a few things, but it didn't appear to get rid of any of my symptoms.

    I'm attaching the HJT logfile as well as the bdscan.txt and activescan.txt logfiles.

    I would appreciate any help in getting rid of this stuff.

    Thanks,
    Finn
     

    Attached Files:

  2. NoBull

    NoBull Private E-2

    It appears I've fixed my issues.

    I took a look at the hijackthis logfile and looked up all running processes etc. that I didn't know on google. A couple came up as malware. Found 2 tools to fix these issues. Smitfraudfix and Ewido. After running those, I am now clean.

    :)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I'm happy to hear your got your malware fixed. You should however also do the below:

    Uninstall Viewpoint Toolbar as mentioned in step 0 of the READ ME.

    Also you should use HijackThis to fix the below lines:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  4. NoBull

    NoBull Private E-2

    Thanks Chas. I removed viewpoint and those 3 registry entries as well. It's good to be clean :D
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds