Read and Run Complete, still issues, pls help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by sdamos, Jul 24, 2006.

  1. sdamos

    sdamos Private E-2

    Greetings all. I ran through the steps in the Read and Run first and I am still experiencing popups and they are very annoying. Please help me. Here is my HijackThis report:

    Inline log converted to attachment

    Thanks,
    Shannon
     

    Attached Files:

    Last edited by a moderator: Jul 24, 2006
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Hi Shanon..Welcome to MajorGeeks!:)..It does seem you missed a few things.

    First, please remember as stated in the Read & Run Me First all logs are to be attached, not copy/pasted into a post.

    You have HijackThis installed incorrectly:

    You have it here --> C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

    This is exactly where we specify not to put it. The instructions indicate:
    - not a temp folder
    - not on the Desktop
    - no sub folder of C:\Documents and Settings

    Please install it where recommended so that the backups created by HJT are in a safe location.

    C:\Program Files\HJT\HijackThis.exe

    Also please take note of the very important note about the need to rename HJT after installing it correctly...this is toward the bottom of the Read & Run Me guide with the installation instructions for HJT.

    Please attach the logs from your BitDefender and Panda ActiveScans from Step 6 of the Read & Run Me.

    I don't see where you have windows defender installed from step 4. Was there a problem? If you are unable to install WD, we suggest you try CounterSpy.

    Did you skip or have difficulty with any of the other steps in the initial clean up guide? It is very important that you let us know if you were unable to complete any of the steps and why so that we can help you. There is no such thing as to much information!:)
     
  3. sdamos

    sdamos Private E-2

    Ok, I have attached the reports from following the procedures. Many items were found by Panda, of course you have to pay to remove them. Please assist.

    Thanks,
    Shannon
     

    Attached Files:

  4. sdamos

    sdamos Private E-2

    Anyone, please?
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    << The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  6. sdamos

    sdamos Private E-2

    Tasks completed, HJT log attached. Let me know if there is anything else.

    Thank you for your help!
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    << The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    REBOOT

    Post a fresh HijackThis log.
     
  8. sdamos

    sdamos Private E-2

    I have version 1.5.0_06 of the Java installed and the website is instructing me that that is the latest version. I am not seeing a newer one on the site?

    I removed the suggested items using HJT. I am no longer seeing those annoying popups, thank you. Here is my report again. Is there anything left?

    Thanks,
    Shannon
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  10. sdamos

    sdamos Private E-2

    Will do, thank you very much for all of your help. It is appreciated.

    Regards,
    Shannon
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're Welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds