Spyware pop-up help! (hijack this log)

Discussion in 'Malware Help (A Specialist Will Reply)' started by hihiimjamie, Aug 15, 2006.

  1. hihiimjamie

    hihiimjamie Private E-2

    I've been getting pop ups CONSTANTLY for the past week or so (Daily News Junkie and Zedo are two of the popular ones, but there have been others as well) I've been running ad aware, spybot, and hijack this but so far nothing seems to be helping.

    Inline, unrequested log removed
     
    Last edited by a moderator: Aug 15, 2006
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to Majorgeeks!

    Many people, or more accurately stated, MOST people are under the very mistaken misconception that HJT is a malware removal tool. It is not. HJT is simply a tool that is used to identify browser hijackers and in specific cases it will show entries for 'some' malware that is for instance running at startup, along with a few other things but it by no means shows everything. Certain forms of malware are coded in a way so that once hijackthis.exe is executed it automatically hides itself unless additional steps are taken to reveal it first. Anyone who has an infected computer and is relying on HJT without the benefit of running additional scans such as BitDefender, Panda ActiveScan, CCleaner, etc. and following specific instructions for using HJT are more than likely still infected. In most cases, where there is one virus/trojan there are more lurking.

    Keeping the above in mind, please complete the below steps and attach the requested logs to your next post so that you may be assisted by one of our Malware Fighters. You are currently running HJT from a temporary location so please be sure to follow the steps for properly installing and renaming HJT before using it.

    Please follow our standard cleaning procedures which are necessary for us to provide you support.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat[/b]
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. hihiimjamie

    hihiimjamie Private E-2

    I was unable to download both GetRunKey and ShowNew properly and I'm not exactly sure what the problem with that was. The Bitdefender site wouldn't allow me to click "I Agree" on the statement page and the page had a line of gibberish across the top:

    ""; var HTMLBody = document.body.innerHTML + OtherJsScript + IESP2JsScript + XOnErrorEvScript + WinOnLoadEvScript + XObj + ""; document.write( HTMLHeader + HTMLBody ); window.location.reload(); } "

    So I didn't run the Panda Active Scan since it said to be sure to run Bitdefender first.

    When I ran spybot in safe mode it found zero problems, and I'm pretty sure that I've correctly attached my newest HijackThis log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in the READ & RUN ME and install HijackThis exactly where we requested. Also you MUST rename HijackThis.exe as specified. DO THIS NOW before continuing.

    Explain why you cannot download GetRunKey.zip and ShowNew.zip. What happens? Do you really mean "download" or do you mean "run"?
    Did you download other programs like Spybot without a problem?

    Run this: Qoologic Removal Procedure and attach the log.

    Now run this: Look2Me VX2 Removal and attach the Look2Me-Destroyer log.



    Make sure viewing of hidden files is enabled (per the READ ME).
    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Overlay Components ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Windows Overlay Components

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot into safe mode.

    While in safe mode run Windows Explorer and delete the below file:
    C:\WINDOWS\ikxuggw.exe

    Now reboot into normal mode and attach a new HJT log.
     
  5. hihiimjamie

    hihiimjamie Private E-2

    When attempting to run GetRunKey.zip and ShowNew.zip the zip file they have downloaded in will not open or unzip properly, and that's basically as much information as I can give. I didn't receive any error messages during the process.

    I have done everything I was instructed to do up until running HiJackThis. when I changed the name of the program to analyse I received a message saying something along the lines of some programs do not function properly when you change the name but I continued anyways as instructed and now when I click on the program it pops up an "open with" window and wants me to choose what type of program I want it to be opened with.

    I've attached both the Qoologic and Look2Me logs.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you are doing something wrong. Do you have WinZip on the PC? Also are you sure you know where you are extracting them too? Did you download and extract HijackThis from the ZIP file or did you already have it on your PC?


    Then you are not renaming the file exactly as requested. The file MUST have a .exe extension at the end of the name (the period is important). You must renamed to exactly this: analyse.exe
     
  7. hihiimjamie

    hihiimjamie Private E-2

    Sorry about the mix up there, turns out I had forgotten the period. Alright, here's the log.
     

    Attached Files:

  8. hihiimjamie

    hihiimjamie Private E-2

    Okay, I re-tried the GetRunKey.zip and ShowNew.zip and was able to get them to work so I have attached those logs as well.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here are the directions from the very first paragraph of the link (for installing HJT) given in step 7 of the READ & RUN ME:
    Note the second sentence which mentions DO NOT.

    Now observe where you have it installed:
    Step 7 also said do not use MSconfig to control startups. Notice the below from your HJT log:
    This means you are using MSconfig. You must run msconfig and select Normal Startup.

    You also did not download and install the version of Spybot S&D as given in the READ ME. You are running a two year old version: "Spybot - Search & Destroy 1.3" Please download, install, update, Immunize, and run a scan with the proper version as requested in the READ ME.

    You also did not update you Sun Java version as stated in step 6 and this is probably the reason you could not run Bitdefender. Your Sun Java Version is v1.3.1_04 and the current version is 1.5.0 update 8. You are a couple years out of date. Update as requested and then try running Bitdefender and then Panda.

    Things will go much faster in instructions are followed the first time!

    So you must install HJT correctly and you must select Normal Startup in msconfig! Do this now before trying to continue on to my next message which will be posted later.


    Also uninstall the below via Add/Remove programs:
    SearchHelper Bar
    The Best Offers
     
    Last edited: Aug 17, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have done what is in Message # 9 first before you continue with the instructions in this message!

    You will notice from the length of the below fix, that you have a load of malware problems.

    Start by downloading - Pocket KillBox

    Extract them it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\windows\system32\oodsregp.exe
    C:\WINDOWS\ikxuggwA.exe
    C:\Program Files\Common Files\{30D1982A-0702-1033-1028-020409200001}\Update.exe
    C:\PROGRA~1\COMMON~1\roqu\roqum.exe
    C:\Program Files\System Files\System.exe
    C:\Program Files\PSLister\PSLister.exe
    C:\PROGRA~1\COMMON~1\roqu\roqua.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
    O3 - Toolbar: SearchHelper - {B6A5B638-6025-4C2C-A899-867B416453D2} - C:\Program Files\SearchHelper\SearchHelper.dll
    O4 - HKLM\..\Run: [{19-98-82-2A-ZN}] C:\windows\system32\oodsregp.exe CORN003
    O4 - HKLM\..\Run: [ikxuggwA] C:\WINDOWS\ikxuggwA.exe
    O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\nwinppex.exe CORN003
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\RunServices: [winlog] winlog.exe
    O4 - HKCU\..\Run: [roqu] C:\PROGRA~1\COMMON~1\roqu\roqum.exe
    O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
    O4 - HKCU\..\Run: [PSLister] "C:\Program Files\PSLister\PSLister.exe"
    O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\nwinppex.exe
    O4 - Startup: Z_Start.lnk = C:\WINDOWS\SYSTEM32\ZICORN003.exe
    O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Jamie O'Neil\Start Menu\Programs\Startup\Think-Adz.lnk
    C:\Documents and Settings\Jamie O'Neil\Start Menu\Programs\Startup\Z_Start.lnk
    C:\Documents and Settings\Jamie O'Neil\Local Settings\Temp\iehelper.exe
    C:\Program Files\Common Files\{30D1982A-0702-1033-1028-020409200001}\Update.exe
    C:\Program Files\Common Files\roqu\roqum.exe
    C:\Program Files\Common Files\roqu\roqua.exe
    C:\Program Files\SearchHelper\SearchHelper.dll
    C:\Program Files\System Files\System.exe
    C:\Program Files\PSLister\PSLister.exe
    C:\626_101newer.exe
    C:\ac3_0003.exe
    C:\dfndrff_7.exe
    C:\dist13.exe
    C:\drsmartload45a8a.exe
    C:\drsmartload46a8a.exe
    C:\drsmartload.exe
    C:\drsmartload849a8a.exe
    C:\Installer3.exe
    C:\kybrdff_7.exe
    C:\MTE3NDI6ODoxNg.exe
    C:\MTE3NDI6ODoxNgnew.exe
    C:\numbsoftnew.exe
    C:\nwnmff_7.exe
    C:\stub_113_4_0_4_0newer.exe
    C:\warebundlenewer.exe"
    C:\webnexmknew.exe
    C:\WINDOWS\ikxuggwA.exe
    C:\WINDOWS\pf78.exe
    C:\WINDOWS\pf79.exe
    C:\WINDOWS\srvubbnudn.exe
    C:\WINDOWS\srvyldtnef.exe
    C:\WINDOWS\ssqbn.exe
    C:\WINDOWS\SYSC00.exe
    C:\WINDOWS\system32ghynf.exe
    C:\WINDOWS\system32bez6n4r21.exe
    C:\WINDOWS\system32n9nyb.exe
    C:\WINDOWS\unin101.exe
    C:\WINDOWS\uni_eh.exe
    C:\WINDOWS\v1201.exe
    C:\WINDOWS\win3208681904234.exe
    C:\WINDOWS\win32086819042342006.exe
    C:\WINDOWS\wnu_7.exe
    C:\WINDOWS\bttkbax.dll
    C:\WINDOWS\streamhlp.dll
    C:\WINDOWS\SYSTEM32\bez6n4r21.exe
    C:\WINDOWS\SYSTEM32\cvn0.exe
    C:\WINDOWS\SYSTEM32\dwdsregt.exe
    C:\WINDOWS\SYSTEM32\ghynf.exe
    C:\WINDOWS\SYSTEM32\iqqr.exe
    C:\WINDOWS\SYSTEM32\n9nyb.exe
    C:\WINDOWS\SYSTEM32\nwinppex.exe
    C:\WINDOWS\SYSTEM32\nwinppez.exe
    C:\WINDOWS\SYSTEM32\oodsregp.exe
    C:\WINDOWS\SYSTEM32\redistributor.exe
    C:\WINDOWS\SYSTEM32\tsuninst.exe
    C:\WINDOWS\SYSTEM32\VSL05.exe
    C:\WINDOWS\SYSTEM32\wfxqhv.exe
    C:\WINDOWS\SYSTEM32\wnststr.exe
    C:\WINDOWS\SYSTEM32\ZICORN003.exe
    C:\WINDOWS\SYSTEM32\zqskw.exe
    C:\WINDOWS\SYSTEM32\aaa00000.dll
    C:\WINDOWS\SYSTEM32\bszip.dll
    C:\WINDOWS\SYSTEM32\mop73f88.dll
    C:\WINDOWS\SYSTEM32\NCMSEVT.DLL
    C:\WINDOWS\SYSTEM32\QHSNAME.DLL
    C:\WINDOWS\SYSTEM32\redist.dll
    C:\WINDOWS\SYSTEM32\w003c814.dll
    C:\WINDOWS\SYSTEM32\w0044aa2.dll
    C:\WINDOWS\SYSTEM32\w24106fe.dll
    C:\WINDOWS\SYSTEM32\w241af92.dll
    C:\WINDOWS\SYSTEM32\winlog.exe
    C:\WINDOWS\SYSTEM32\xeymi.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete them if found:
    C:\Program Files\Common Files\{30D1982A-0702-1033-1028-020409200001}
    C:\Program Files\SearchHelper
    C:\Program Files\System Files
    C:\Program Files\PSLister
    C:\Program Files\Common Files\roqu

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Jamie O'Neil\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
  11. hihiimjamie

    hihiimjamie Private E-2

    I'm sorry I wasn't aware my spybot was an older version since I downloaded it off of this site the last time I needed help, which was over a year ago. My mistake. I have downloaded and run the proper one now and it found a significant amount of new threats which I fixed. (A grand total of 50 problems were found)

    I have selected Normal Startup, and updated my Java... but I am still getting the same line of gibberish across the top fo the Bitdefender rsite. And I'm sorry for the inconvenience, but I'm afraid I do not understand what you are asking me to do with HJT... I know I probably sound like a fool, but could you please explain in more detail what you are asking and where I should install it?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have HJT installed here:

    C:\Documents and Settings\Jamie O'Neil\My Documents\Hijackthis\analyse.exe

    That is exactly where step 7 indicates not to install it. Install it like below:

    C:\Program Files\Hijackthis\analyse.exe

    or even

    C:\Program Files\HJT\analyse.exe
     
  13. hihiimjamie

    hihiimjamie Private E-2

    I haven't had any more popups yet... hopefully that's going to last. (Scratch that, a small one from atwola.com just popped up)

    Mostly all of the steps went cleanly and well, I think I have HJT in the proper place now as well.

    I was unable to locate C:\windows\system32\oodsregp.exe and C:\Program Files\System Files\System.exe in the process manager so I'm guessing they may have already been deleted.

    And the following were no longer in my log to delete as well:
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
    O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"

    In my C:\Documents and Settings\Jamie O'Neil\Local Settings\Temp folder there are 5 items remaining that couldn't be deleted..
    me_dbloiVMck50suA0
    me_gMtTfZPXM1eHo9K
    me_u9erY55Z5eoRgVr
    me_FRKG9ikNlR4FBLr
    me_Lgv1Xh4offfWoLn

    The past 2 times I have rebooted my computer I've gotten an error that says WJView Error
    ERROR: Could not execute Main : The system cannot fidn the file specified.

    Logs are attached
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure it was a popup? Or do you mean you got a message about a cookie?


    Run HijackThis and have it fix the below line:

    O4 - HKLM\..\Run: [Care2GTU] wjview /cp:p "C:\Program Files\Care2GTU\System\Code" Main lp: "C:\Program Files\Care2GTU"

    Then exit HJT and reboot. Let me know how things are looking now.
     
  15. hihiimjamie

    hihiimjamie Private E-2

    Yes it was definitely a pop up, I also got one recently that said something about "you have not completed the scan" and said that my computer was "tracking all the adult sites" I have visited (which is a grand total of zero by the way) so I'm completely positive that isn't an actual error message.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are those the exact messages you received? It is important to always give exact word for word information in any messages received (even punctuation/capitalization should be exact). Also if any URL's are mentioed, give them too but just leave spaces between things so they are not clickable. Like www majorgeeks com Notice I just replace the periods with spaces. This protects people from clicking on the links by mistake.

    Please run a new PandaActiveScan and attach the log.

    Now Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note: process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  17. hihiimjamie

    hihiimjamie Private E-2

    I'm only receiving one popup now, and it's the one mentioned before. I'I've attached a picture of it.

    I ran both SmitfraudFix and PanaActiveScan and have attached the log to the SmitfraudFix, but my PandaActiveScan log is too large for an attachment. What would you like me to do with it?
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Compress the Panda log into a ZIP file and attach that. You could also split the file into smaller pieces.

    Now to continue your fix!

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.
     
  19. hihiimjamie

    hihiimjamie Private E-2

    Okay here's the log.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about the rest of message # 18?

    Did you notice why the Panda log was so big? All that junk you have been downloading was infected and much of it still may be. You need to stop downloading all this illegal stuff (cracks and cracked software) and consider not downloading from where ever you are downloading this stuff from otherwise you will always have malware problems. After finishing message # 18, you should delete the c:\!Killbox folder and then you should run Panda again and save a new log so we can see what remains to be cleaned up. If it still detects all those files as being infected, you will have to delete the following folder and everything in it

    C:\Documents and Settings\Jamie O'Neil\Complete\
     
  21. hihiimjamie

    hihiimjamie Private E-2

    Actually all of the crap was from ONE downloading mistake I made by trusting someone I shouldn't have... normally I don't download any type of software. Here's the smitfraudfix log, sorry it took longer.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay if you have deleted what I mentioned in message # 20, and also make sure you empty your Recycle Bin, then you should run Panda again and attach the new log. There was a load of stuff being detected and we could have some additional manual cleaning to do.
     
  23. hihiimjamie

    hihiimjamie Private E-2

    Okay I deleted killbox, and here's the log from the Panda scan.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\Documents and Settings\Jamie O'Neil\Local Settings\Temporary Internet Files\Content.IE5\QRY7TU9O\xpl[1].wmf
    C:\Documents and Settings\Jamie O'Neil\Local Settings\Temporary Internet Files\Content.IE5\SD2FON6P\xpl[1].wmf
    c:\windows\inf\biG.inf
    C:\Documents and Settings\Jamie O'Neil\Application Data\tvmcwrd.dll
    c:\windows\alchem.ini
    c:\windows\didduid.ini
    c:\windows\kwv2.dat
    c:\windows\offun.exe
    c:\windows\satmat.ini
    C:\Program Files\MSN\vigybe.dll
    C:\Program Files\PSHope\upd.exe
    C:\warebundlenewer.exe
    C:\WINDOWS\diexvq.exe
    C:\WINDOWS\INF\satmat.inf
    C:\WINDOWS\SmFtaWUgTydOZWls\asappsrv.dll
    C:\WINDOWS\SmFtaWUgTydOZWls\command.exe
    C:\WINDOWS\SmFtaWUgTydOZWls\mAIQuqo0nVxitq5P.vbs

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Program Files\PSHope

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from PandaActiveScan.

    Make sure you tell me how things are working now!
     
  25. hihiimjamie

    hihiimjamie Private E-2

    Sorry for the very late reply, school started up again and I just haven't had any time. Everything seems to be running fine now and I did everything in the last post without any problems, but the Panda scan did find some items. I've attached the logs you requested.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot wait 2 months to do fixes. Even waiting a week can typically require running the whole READ & RUN ME over again.

    Manually delete all the malware files that Panda found and don't wait so long to do it this time. The stuff in the Panda log is what you were supposed to fix with Killbox. I guess you did not do it properly.

    You risk the chance for total reinfection when you do this.
     
  27. hihiimjamie

    hihiimjamie Private E-2

    I'm not sure how it would be possible that I did it wrong because I followed what you said exactly.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your Panda log!

    Try again!
     
  29. hihiimjamie

    hihiimjamie Private E-2

    Alright, I re-did post number 24, and I deleted the killbox! folder again list post 18 said to do. Then I re-ran panda and have attached the log I received from it.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still missed one!

    C:\Documents and Settings\Jamie O'Neil\Application Data\tvmknwrd.dll

    Either delete this file manually or use Pocket Killbox to delete it.

    How is everything working now?
     
  31. hihiimjamie

    hihiimjamie Private E-2

    Alright, took care of that one and rebooted, everything seems to be running totally perfectly now.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds