spyware/trojan help

Discussion in 'Malware Help (A Specialist Will Reply)' started by raid0220, Oct 18, 2006.

  1. raid0220

    raid0220 Private E-2

    OK so I've been having some problems, after getting some infection on about 10/10-10/11. The original problem started off by installing something and ever since I have had fake critical system error messages, and virus/trojan alerts that anytime they are clicked on take me to place like virusblaster website. before this site was recommended to me I ran a few differnt scans, but something has also wiped out all of my personal files.

    I have followed every step so far and am still having problems. So now I am kind of at a stand still. I am attaching bitdefender scan, panda active scan, and runkeys log files and I'll post another with getnew and hjt.
     

    Attached Files:

  2. raid0220

    raid0220 Private E-2

    ok here are the other 2 log files.
     

    Attached Files:

  3. raid0220

    raid0220 Private E-2

    Oh yeah and before I forget, since know this is critical here are my computer specs.

    Alienware area51
    windows xp sevrice pack 2
    intel pentium 4a 2ghz
    mtherboard, intel maryville D850mv (5pci,1agp, audio)
    chipset, intel tehama i850
    512 mb rdram
    bois AMI (11/14/01)
    nvidia GeForce FX 5900 ultra (256 mb)
    creative audigy platinum sound card
    HD1, maxtor 6l020j1 (20 gb, 7200 rpm, ultra ata/133) drive c:
    HD2, HDS72252VLAT80 (250 gb, 7200 rpm, ultra ata/100) f: & g:
     
  4. matt.chugg

    matt.chugg MajorGeek

    Using add/remove programs which can be accessed from the control panel, uninstall the following:



    Download and install Sun Java Runtime Environment 5.0 Update 9


    Download

    - Pocket KillBox

    Extract to its own folder somewhere that you will be able to locate later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)



    Run HijackThis. Click the 'Do a system scan only' button.

    Place a checkmark in the box next to the following lines:

    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)


    If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.


    REBOOT to Normal Mode.

    Let me know how things are running now

    Post a fresh HijackThis log, a fresh newfiles log and a fresh activescan log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds