Random Number.exe Keeps Appearing - Need Some Assistance

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mickey07, Nov 28, 2006.

  1. Mickey07

    Mickey07 Private E-2

    Hi Gang,

    Here is the summary situation.

    A random file number (ie. 269949818.exe) keeps booting in the background. While it does this it appears it is attempting to load Iexplore to show me one of those Ed McMahon-esque pop-ups telling me "I have almost definately won something."

    It would appear all I have actually won is a headache. Anyways, I have run through your steps 1-7 and will attach the according log files 3 at time, to this, and the following post.

    If anyone has a suggestion, I am game for trying.

    Thanks in advance.
     

    Attached Files:

  2. Mickey07

    Mickey07 Private E-2

    Second batch of logs. Once again, thanks.
     

    Attached Files:

  3. Mickey07

    Mickey07 Private E-2

    Final bizzaro symptoms I forgot to mention -
    1. Turns off Pictures and Display Video in my browser
    2. I cannot disable System Restore per your instructions

    That's it. Last post, I swear.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We did not ask you to turn off System Restore yet. That is only done once you are clean.

    We did however ask for a HijackThis log in step 7. I'll will ask you for one at the end of the below steps.



    You need to delete the below email archive that Bitdefender found.
    C:\Archives\Backup 06.06\Mail Archive 06.06\archive.pst=>[Subject: Regions Bank: Urgent Notification From BiIIing Department [Mon, 11 Apr 2005 18:39:19 -0100]][From: Regions]=>(body)

    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_04
    Mozilla Firefox (1.5.0.7)

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Make sure viewing of hidden files is enabled (per the tutorial).

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\ogysteo.exe
    C:\WINDOWS\system32\xpRecovery.dll

    Now run Ccleaner.

    Now reboot in normal mode

    Also delete all files in the below folders except ones from the current date (Windows may not let you delete the files from the current day).
    C:\Documents and Settings\Mike\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Nov 29, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds