READ AND RUN ME FIRST finished, posted hjt log

Discussion in 'Malware Help (A Specialist Will Reply)' started by WrestlrPK, Feb 23, 2006.

  1. WrestlrPK

    WrestlrPK Private E-2

    I've gone thru all the stuff on read and run me first page. a couple things that i got from that are:

    ad-aware couldn't remove the following:

    c:\windows\system32\izq.dll
    c:\windows\system32\guard.tmp

    spybot couldnt remove:

    Smitfraud-C. (18 flies)
    all files were of format:
    HKEY_USERS\S-1-5-21-16455-22239-842925246-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ZoneMap\Domains\www.____

    I also could not run Microsoft Defender cuz i didnt have right CD.
    Had to run BidDefender in normal mode.

    And i was unable to run Active Panda Scan b/c IE wasn't working.

    I have attached my hjt log.

    the only problems i'm having right now is pop-ups like crazy on my comp. I've had multiple viruses, trojan, ect in the past and attempted to fix them myself so i think i might have so left overs from those.

    also, when i go thru all the stuff on microsoft anitspyware i have a bunch of windows host files that i can never get rid of. any help would be great guys

    hjt log is attached
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Operating System and Internet Explorer versions are WAY out of date and represent a major security risk. After we fix your current problems, you must get updated. You need to install Service Pack 2 for security purposes.

    Please see the below thread on running the L2MeFix Tool.

     
  3. WrestlrPK

    WrestlrPK Private E-2

    I have attached the two logs from the L2MFix that I did.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  5. WrestlrPK

    WrestlrPK Private E-2

    ran spy sweeper and enwido. enwido found nothing. have attached spy sweeper, enwido, and new hjt logs.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs for the following and uninstall them if found:

    Ewido

    Spy Sweeper

    Microsoft AntiSpyware


    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    R3 - Default URLSearchHook is missing

    O4 - HKLM\..\Run: [applx.exe] C:\WINDOWS\applx.exe
    O4 - HKLM\..\Run: [win3206502415232] C:\WINDOWS\win3206502415232.exe

    O20 - Winlogon Notify: ssldr - C:\WINDOWS\
    O20 - Winlogon Notify: wancp - wancp.dll (file missing)

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\WINDOWS\applx.exe

    C:\WINDOWS\win3206502415232.exe

    Next, run CCleaner to clean up cookies and temp files.

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:


    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and then scan with HijackThis and attach the new log.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. WrestlrPK

    WrestlrPK Private E-2

    Looks like that worked. No more popup problmes. Thanks alot for the help, you guys are great.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please attach a current HJT log to confirm your clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds