Well, I believe I'm clean, but..

Discussion in 'Malware Help (A Specialist Will Reply)' started by whatchamacallme, Jul 12, 2006.

  1. whatchamacallme

    whatchamacallme Private E-2

    I think I got everything off my system, but I'm not 100% sure. If someone could look over my log, that would be wonderful.

    Spybot did not come up with any issues.
     

    Attached Files:

  2. whatchamacallme

    whatchamacallme Private E-2

    UPDATE: I just opened my Windows Explorer and a Mirar popup came up. What shall I do now?
    UPDATE EDIT: Spybot is also now coming up with multiple issues.
    Smitfraud-C.
    ABetterInternet.Aurora
    HotsearchBar
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow proper procedures given below that are require before posting HJT logs. Make sure you install HJT properly.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  4. whatchamacallme

    whatchamacallme Private E-2

    Ah, I'm sorry for not doing all that beforehand.

    I believe I really am clean now.

    Thanks. If I have any more problems, I'll be back. ^_^
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about that! I tend to doubt it. You really should complete the whole procedure and attach the requested logs. I saw some problems in your HJT log that are not going to go away just by running the procedures. Manual steps will be needed to get the rest of your problems after the READ ME has been completed.
     
  6. whatchamacallme

    whatchamacallme Private E-2

    OK.

    Here are the logs.

    I don't have a Pandascan Log for some reason.. I could have sworn I saved it..

    I can do another Pandascan if you need it.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\Common Files\{DCCE0494-07DA-1033-0121-050915040001}\Update.exe


    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O15 - Trusted Zone: *.elitemediagroup.net
    O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.elitemediagroup.net/cabs/mediaview.cab


    After clicking Fix, exit HJT

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot and then delete the below folder:
    C:\Program Files\Common Files\{DCCE0494-07DA-1033-0121-050915040001}


    Let me know the results and also attach a new HJT log and also run the below very fast scan (it takes only about 3 to 5 seconds to run).

    Run the below procedure and attach the runkeys.txt log.
     
  8. whatchamacallme

    whatchamacallme Private E-2

    I believe it all worked, but there's still some weird processes running?
     

    Attached Files:

  9. whatchamacallme

    whatchamacallme Private E-2

    I'm pretty sure there's still something wrong, because the IE "Information Bar" popup keeps appearing.. which tells me that something's exploiting IE?

    I'm using Flock (a FF variant) so nothing should be using IE.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the below procedure and attach the newfiles.txt log.
    Also do the below!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
    Last edited: Jul 16, 2006
  11. whatchamacallme

    whatchamacallme Private E-2

    Ok, I added that to the registry and ran that scan.
     

    Attached Files:

  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Boot to Safe Mode and delete the following:
    C:\WINDOWS\Tagasuarus2.exe
    C:\WINDOWS\tkbll.dll
    C:\WINDOWS\system32\hvzead7v.exe
    C:\WINDOWS\system32\wnsintsv.exe
    C:\WINDOWS\system32\SET823.tmp
    C:\WINDOWS\system32\SET831.tmp
    C:\WINDOWS\temp\TMP0000009376370FD4054621F4
    C:\Documents and Settings\Alex\Local Settings\TEMP\0w619A.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\5l01AC.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\5wl48D.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\75o39E.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\b123.exe
    C:\Documents and Settings\Alex\Local Settings\TEMP\baul4tu5.exe
    C:\Documents and Settings\Alex\Local Settings\TEMP\bf41B8.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\dz836B.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\g4uE4.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\HomePage_04.gif
    C:\Documents and Settings\Alex\Local Settings\TEMP\hpzcoi00.log
    C:\Documents and Settings\Alex\Local Settings\TEMP\hpzcoi01.log
    C:\Documents and Settings\Alex\Local Settings\TEMP\ic4199.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\jfa34A.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\jx21B0.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\kja34B.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\loqDC.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\mellow.gif
    C:\Documents and Settings\Alex\Local Settings\TEMP\ml43AC.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\nuz1A7.tmp
    C:\Documents and Settings\Alex\Local Settings\TEMP\o1836C.tmp
    C:\Documents and Settings\Alex\Local Settings\Temp\pn319F.tmp
    C:\Documents and Settings\Alex\Local Settings\Temp\ugl390.tmp
    C:\Documents and Settings\Alex\Local Settings\Temp\xbl484.tmp
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds