some one help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by haroldcoffin, Jan 10, 2006.

  1. haroldcoffin

    haroldcoffin Private E-2

    i have a mess. coming up in the bottom right saying my computer is infected i have run multi spy ware and anti virus and it still show then it keeps down loading spy striker v2.5 and i remove and it does it does it again.i have ad ware se and spy bot in now i have tried the removel steps of spy ware and still have the problem i have avg for virus and it keeps showing a bug everyday i cant get this out any help would be great.also when i open the exploxer page it says a hacker was in and goes to secrety page.HELP:eek:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    Well this is all covered in one of our stickies you should have read:
    READ & RUN ME FIRST Before Asking for Support

    But I'll give you something to run to go after SpywareStriker. Hang on a few minutes for my next post.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attach GetRunKey119.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment.

    This will help us in our on going fight against malware. After posting the above log continue on to run the steps in the below link and when it completes, post the requested smitfiles.txt log as an attachment.

    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal
     

    Attached Files:

    Last edited: Jan 11, 2006
  4. haroldcoffin

    haroldcoffin Private E-2

    i run the get run key and it still came back im going to run the hijack this and the smitrem in safe mode and see what that does ill post the finds in a little bit.thank you for the help so far
     
  5. haroldcoffin

    haroldcoffin Private E-2

    ok ran the hijack this and the smitfiles and still infected like hedi fliess in vegas at the avn awards.and good old spyware stike is back again ive ran ever thing from avg , adware se,spybot,c cleaner,and looked in the add remove and still nothing running panda now ill post results in a few mins thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are supposed to attach the log from getrunkey. It is not supposed to removed anything. It is a log to find the problems. Please follow the directions and attach the log.

    Then complete the steps with SmitRem and attach the smitfiles.txt too. Make sure you donwload SmitRem.exe from the link in my message. Even if you already had it downloaded, download it again and use the new version. Delete any old copies you had first.

    You must follow our directions and only do what we request and you must attach the logs we request. We cannot help you if you do not help us.
     
  7. haroldcoffin

    haroldcoffin Private E-2

    heres the files from the scans panda and smitfile please help someone this is really getting old:mad:
     

    Attached Files:

  8. haroldcoffin

    haroldcoffin Private E-2

    heres from the key thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are using Msconfig to stop a bunch of items from loading at startup. Some of them you should actually uninstall completely. It would be best to first select Normal Startup (not use msconfig). Then use Add/Remove programs to uninstall
    MyWebSearch Email Plugin or MyWebSearch or MyWebSearch Bar or anything else from MyWeb or MyWay
    Viewpoint or Viewpoint Manager

    You did not run SmitRem per the directions indicated in the link I gave to you. Or you did not re-download and use the version in the link. It you did, your problem with Spyware Strike should be resolved. It is VERY IMPORTANT that you download the tool again. It was just changed recently to fix Spyware Strike. I still see a couple items in your registry that relate to this that should be fixed by running the new SmitRem tool.
    Also the tool MUST be run in safe mode as the directions indicate. Are you running it in safe mode.

    Also make sure you have viewing of hidden and system files enable per the READ ME and tell me if you see the below files:
    c:\windows\system32\netwrap.dll
    c:\windows\system32\waitwain.dll
     
  10. haroldcoffin

    haroldcoffin Private E-2

    yes i can it in safe mode for smitrem ill delete it and download again i see none of the things you said to delete in add remove programs tough way ????and im in noramal mode but dont see them in the list im going to reload smitrem.and go to safe mode ill post results in a few thanks agian
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Huh! I don't know what you are saying!

    Yes I can what? Are these supposed to be two different sentences?
     
  12. haroldcoffin

    haroldcoffin Private E-2

    sorry just tring to get this done.i think i got it because its not poping in the bottom right of screen any more i deleted the smitfile and redownloaded it and run it again and c cleaner as well everything looks ok now i thank you and i hope this may help others here .god bless the geeks enemys, enemy also im posting the results of the scan does everthing look right to you ?
     
  13. haroldcoffin

    haroldcoffin Private E-2

    o i have another ? i didnt see any of the myway or myweb or viewpoint in the add and remove programs where would they be also i didnt see the 2 files you named.is this ok and what can i do to prevent this again
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not post the log!

    You should also re run GetRunKeys and attach a new log from it.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They showed in the runkeys.txt log (look in it) as being stopped from running by msconfig. Run msconfig and look at it it. You probably have them unchecked. Maybe you already uninstalled them at another time?
     
  16. haroldcoffin

    haroldcoffin Private E-2

    heres the logs sorry.alos my system says it found a virus called tojanhorsezlob i healed it 4 times it came back each time then i moved it to the vault what is this ?
     

    Attached Files:

  17. haroldcoffin

    haroldcoffin Private E-2

    i also did as you said and reran the gunkey here is the report from that
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually I never asked for a HijackThis log. You must run the standard cleaning procedures in this Sticky thread READ & RUN ME FIRST Before Asking for Support before posting HJT logs.

    You SpywareStike problems appears to be gone. If you are having other problems, the full sticky should be followed so we can uncover any other possible hidden malware. HijackThis is not a malware scanner and only shows a limited amount of info. HJT logs can infact be clean while a PC is badly infected.
     
  19. haroldcoffin

    haroldcoffin Private E-2

    ok i think ever is good now here is the bit log thank you for your help
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to see the PandaActiveScan log too. Please attach it.

    Are you saying everything is working okay now?

    I do see two files from you BitDefender log that you should make sure were delete. Look for the below and delete if found:

    C:\WINDOWS\system32\zzjluyjk.dll
    C:\install.htm
     
  21. haroldcoffin

    haroldcoffin Private E-2

    ill have to do a nother panda scan and then post but things are working good now so far ill post report when its done
     
  22. haroldcoffin

    haroldcoffin Private E-2

    look for the 2 files in safe mode or normal mode ?
     
  23. haroldcoffin

    haroldcoffin Private E-2

    ok i ran the panda scan again and i looked for the 2 files you named and did not see them but panda said that im still infected ???? heres the report and thank you again for all the help.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Boot into safe mode and find and delete (tell me what you find):
    C:\WINDOWS\SYSTEM32\kyf.dat
    C:\WINDOWS\SYSTEM32\FLEOK
    C:\WINDOWS\system32\wiatwain.dll

    Reboot into normal mode and then do another PandaActiveScan. How do things look now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds