still have viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by dashadowman20002, Dec 28, 2005.

  1. dashadowman20002

    dashadowman20002 Private E-2

    i ran through all of the programs on the page. and the active search said i still have 2 viruses, and 23 spywares in my system 1 of the viruses were in my operating system. any help will be appreciated, thank you.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Did you buy Ewido or Trojan Hunter? If you did not uninstall so they will not block any parts of the fix I will post shortly.

    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    After you complete the above, reboot and attach a fresh Panda Log & Bit Defender log.
     
  3. dashadowman20002

    dashadowman20002 Private E-2

    ok... lol i got through all of those again. after i did bit defender i went and uninstalled my CE-DP stealer program.. and then deleted the folder that was left of it. and the panda one i ran after i delted it but heres the 2 logs , and i uninstalled ewido and trojan hunter
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I need a fresh HJT log from normal mode.
     
  5. dashadowman20002

    dashadowman20002 Private E-2

    ok got the hijack this log
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    (Don't run it yet)

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    O2 - BHO: (no name) - {5BD74B88-8040-A194-4346-DE38074E91CD} - C:\WINDOWS\System32\tzcmbiq.dll (file missing)
    O2 - BHO: - {ef1bf8fa-65c5-4efc-8993-eff9590e1031} - C:\WINDOWS\system32\viwl.dll

    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:


    C:\Program Files\SearchRelevant ←–– Delete this whole folder if it exist!

    C:\Program Files\CA\eTrust PestPatrol\core\Quarantine ←–– Delete everything in this folder!

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\system32\rasakhlp.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINDOWS\system32\viwl.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINDOWS\NDNuninstall6_98.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.
    After you complete the above, reboot and let me know how things are running.
     
  7. dashadowman20002

    dashadowman20002 Private E-2

    thank you very much, went through and did all that, and am noticing my comp a little faster, and glad to know i got rid of a bunch of stuff in here. thank you very much.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds