SpywareQuake Smitfiles.txt review

Discussion in 'Malware Help (A Specialist Will Reply)' started by pcboy, Jun 24, 2006.

  1. pcboy

    pcboy Private E-2

    Hello,

    I am new to here. I found this forum very helpful. Thank you so much for your time and your helps. Yesterday, I did accidentally run a program that has SpywareQuake in there.

    I did follow the instruction in this thread: http://forums.majorgeeks.com/showthread.php?t=88420. However, I still see a few popup windows happen when I turn on my computer. I don't know if I was missing anything.

    Please help me review my smitfiles.txt file. I very much appreciate if you can let me know what are the next steps. How can I get rid of the spyware.

    Thank you,
    pcboy
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Run the SpywareQuake procedure again. It has been update with about 7 more forms of the infection and some new files. Make sure to download the fixquake.zip file again since it has changed.

    The file you will be looking for to delete is actually C:\WINDOWS\g30068234.dll

    Attach your new smitfiles.txt log and tell me how things are working.
     
  3. pcboy

    pcboy Private E-2

    Chaslang,

    Thanks for your help. I did followed the Spywarequake removal procedure one more time already. However, I couldn't delete this file at all, C:\WINDOWS\g30068234.dll. I have tried to delete it through safe mode, command prompt, and boot as normal. I always got the same message that the g30068234.dll is used by other program.

    Please adive me what should I do to remove this file. Also, I have attached my new Smitfiles.txt for your review again.

    Thank so much for your help.
    pcboy
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look to me like you are downloading the new fixquake.zip file and using the new registry patch. I see the below in you log:

    "{259BA022-2005-45E9-A965-10EDB9C00605}"="Windows Updater"

    This should be removed by using the registry patch. Also per the procedure, if you cannot delete a file, we also made a suggestion to rename the DLL and then delete it later after another reboot. So while in safe mode run the NEW registry patch (make sure you download it again. I updated it 4 times yesterday.) and then rename g30068234.dll to g30068234.ddd. Then run smitrem again and save the new log. Then try to delete the above file after your next reboot.

    Come back and post the new smitfiles.txt log and let me know what happened.
     
  5. pcboy

    pcboy Private E-2

    chaslang,

    I did download the new fixquake file last time. Now I did downloaded the Fixquake one more time and followed the procedure again. However, I still couldn't rename the g30068234.dll file to the DDD extension at all. I couldn't rename it and I couldn't delete it. I always got the message saying that the file is used by other program. Please advice what should I do next.

    Attached is my new logfile for your review. Thank you so much for your time and your helps in this matter.

    Thanks,
    pcboy
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you must have other malware on your PC or that you may have something installed that is blocking changes to your registry.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  7. pcboy

    pcboy Private E-2

    Hi chasleng,

    Thanks for your helps. Attached are the logfiles for your reviews. I also have Norton Antivirus on my computer, my norton catched Trojan.Nebuler, Downloader, Adware.purityscan. And I also I see OuterInfo popup.

    Unfortunately, I couldn't upload the Activescan.txt file since it's 261K, whereas you only allow on 250K file to upload here. If you would like, I can chop the file into two parts.

    Please advice what to do next in order to clean all of these.

    Thanks and I very much appreciate your helps.
    pcboy
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you probably have a load of cookies or you did not empty your Quarantine & Norton NProtect folders before running the scans. See step 0 of the READ ME. (Edit: after looking at your Bitdefender log, I see my assumption is correct!! Empty them NOW!)

    You can either compress the Panda log into a ZIP file and upload the ZIP or you can split it. I need this log before continuing.

    Why is regsrv32.exe running 8 times? What were you running when you obtained the HJT log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds