Several attempts to remove malware failed...help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Scott0246, Jan 21, 2006.

  1. Scott0246

    Scott0246 Private E-2

    I have worked through the process to remove malware on your site three times. Although it did a good job getting rid of a lot of stuff, I am still getting pop-ups. I attached all of my logs. Subsequent to creating these, I deleted what I could manually. However, some files (like the netinstaller.exe) I couldn't find.

    Any help that you could give me would be appreciated. I have been working on this all day and have just about had it.

    Scott
     
  2. Scott0246

    Scott0246 Private E-2

    Not sure logs same through.
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your logs did not post.

    Please attach your logs again.
     
  4. Scott0246

    Scott0246 Private E-2

    Sorry...hopefully it works this time.
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You have HijackThis installed incorrectly. Please install HijackThis to C:\Program Files\HJT.

    Uninstall MySearch and Winfixer 2005 if they exist.

    Download and install
    - ExplorerXP

    Run ExplorerXP; navigate to and delete the following:
    Follow the directions for
    Smitfraud, SpySheriff, SpyAxe & PSGuard Removal
    and Running WinPfind by OldTimer.

    Post the smitfiles.txt and WinPFind.txt files when finished with the above.
     
  6. Scott0246

    Scott0246 Private E-2

    I seem to have the same files, but maybe in different locations?

    I don't seem to be having as many pop-ups. Anything that I can do to get rid of the rest of these?

    Scott
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Those are not the logs I asked for; post smitfiles.txt and WinPFind.txt as previously requested.

    HijackThis is still installed incorrectly. Move HijackThis to the correct folder per the instructions for Downloadng, Installing, and Running HijackThis.

    Whatever you are disabling with MSConfig, enable it. We need to see everything.
     
  8. Scott0246

    Scott0246 Private E-2

    Sorry, here are those logs.

    Also, I noticed that if I log on to XP under my wife, she gets a lot more pop ups than me. Do I have to run certain apps logged on as her as well.

    I appreciate your patience with all of this.

    Thanks,

    Scott
     

    Attached Files:

  9. Scott0246

    Scott0246 Private E-2

    I did a little more searching under my wife's ID. The adware that keeps popping up is called Zeno. If I pull up the task manager, there is a process called kwingsap.exe that runs Zeno. If I stop the process, the adware disappears. I have found and deleted that file several times, but I can't seem to get rid of it for good.

    Scott
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please post a fresh HijackThis log with all startup processes enabled. Don't use MSConfig to disable any startup processes.
     
  11. Scott0246

    Scott0246 Private E-2

    Here you go. I see a few suspect things on here that I haven't noticed before.
     

    Attached Files:

  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the directions for Running Spy Sweeper.

    Post teh SpySweeper log and a fresh HijackThis log when done.
     
  13. Scott0246

    Scott0246 Private E-2

    See attached.
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download FixAprop to your Desktop.

    Reboot to Safe Mode.

    Run FixAprop.

    Reboot to Safe Mode.

    Run Microsoft AntiSpyware and let it fix what it finds.

    Reboot to Normal Mode.

    Your Spy Sweeper definitions are out dated update teh definitions and run it again. Post a new Spy Sweeper log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds