steplee loves majorgeeks!

Discussion in 'Malware Help (A Specialist Will Reply)' started by steplee, Aug 5, 2006.

  1. steplee

    steplee Private E-2

    I love you guys! It's awesome what you do here for everyone :D


    Can you help me with another computer this time? I followed all the directions (correctly, I hope!) and I ran all the scans you recommend and I have attached 3 logs-- BitDefender, Panda ActiveScan, and HJT.

    Please let me know if there is any hope for this machine!

    Thank you :D
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    • Save it to your desktop or a place easy to find.
    • Do not run it yet
    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe \RESET

    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJ

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\Common Files\Totem Shared Delete this whole folder if it exist!

    Next, run CCleaner to clean up cookies and temp files.

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINNT\NDNuninstall6_98.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\System32\newone.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINNT\Downloaded Program Files\f3initialsetup1.0.0.15.inf into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.

    Once you complete this fix, reboot to normal mode and then procede with the next set of instructions.


    Please see the below threads...
    Once you have followed each thread you should attach these three logs to your next post.
    • WinPFind.txt
    • runkey.txt
    • newfiles.txt
     
  3. steplee

    steplee Private E-2

    3 text files attached
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    A fresh HJT log please.
     
  5. steplee

    steplee Private E-2

    HJT log attached.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs look ok to me, are you having any current problems?
     
  7. steplee

    steplee Private E-2

    I gave it a few days of use by the family... and no popups, no random toolbars, no problems.

    Is this when I do the System Restore clearing?
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You can if you like.

    You should see this article on How to Protect yourself from malware!

    Surf Safely!:)
     
  9. steplee

    steplee Private E-2

    Cool-- will do. Thanks so much, once again! :D
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds