System HiJacked...blank screen...scan logs attached - Help Plz

Discussion in 'Malware Help (A Specialist Will Reply)' started by toclark2, Aug 26, 2005.

  1. toclark2

    toclark2 Private E-2

    Comments/questions (make sure you answer all questions):
    C:\Documents and Settings\Marisa\My Documents\My Webs\_private\aim.exe <--- Why do you have aim here? This is not a normal installation.

    Deleted previously through Add/Remove programs not sure where your seeing still...?

    Not since we started this effort.

    Add/Remove - none were listed


    Confirmed per tutorial.

    No we can kill this...

    None of these files/folders where present to be deleted. I did notice several files that were definitely suspicious, but I'm a little leary about deleting them without a direction from you.
    * WMSysPr9.prx
    * WMSysPrx.Prx
    * P2Pgasvc.dll
    * P2Pgraph.dll
    * P2Pnetsh.dll
    * P2Psvc.dll

    I noticed a section in CCleaner under Application tab, Internet Section; a box for Kazaa?

    reset

    rebooted in normal mode HJT log attached.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below are all valid files! Just leave them alone.

    * WMSysPr9.prx
    * WMSysPrx.Prx
    * P2Pgasvc.dll
    * P2Pgraph.dll
    * P2Pnetsh.dll
    * P2Psvc.dll

    I asked about Stopzilla because it was in your HJT log. See for yourself.

    Please download and run this: Kazaa Spyware Removal

    You did not answer why AIM is installed like it is.

     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. toclark2

    toclark2 Private E-2

    latest
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use the Kazaa removal tool? Did it tell you anything?

    Where did the below come from:

    C:\Documents and Settings\ToddJune\Desktop\SpyKiller\HijackThis.exe

    You should not be using this. We delete that way back in message # 2!!!
     
  6. toclark2

    toclark2 Private E-2

    Kazaa tool confirmed spyware files removed.

    Where did the below come from:

    My bad when I got the desktop back I went looking for HJT in my designated spyware folder to pin to the start menu. I unpacked it again and didn't remember we changed it to its own folder, force of habit sorry...

    My daughter installed it on her account initially.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most programs (including AIM) should be installed to there default folders as given during the installation. It just makes things easier. Especially when trying to recognize malware. Something not running from the correct folder is always a red flag.

    So how are things working now?
     
  8. toclark2

    toclark2 Private E-2

    Things are working fine...desktop is back...no signs of ill-effects.

    I'm attaching the last HJT log (unrequested) for a final perusal and if there's nothing specific I think we're done.

    Thank You Very Much...
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. toclark2

    toclark2 Private E-2

    Just a note...I'm starting up a seperate thread for an infected peer PC in my home office. Its got the Virtumundo virus...

    When I began the implementation of the protection tutorial Ewido picked it up.

    None of the tutorial apps clean this bug out...I see there are some other threads dealing with it. However, none are similar enough to run on my machine.

    I didin't want you to get the idea that another outbreak occured on the PC we worked on this past week.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I just noticed the other thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds