winfixer malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ppreheim, Mar 4, 2006.

  1. ppreheim

    ppreheim Private First Class

    I just got a malware that keeps popping up winfixer menu's as well as other adds. I am currently working my way through the do this first thread. Does anyone have any thoughts on this while I am doing that?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Once you have completed the READ ME, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. ppreheim

    ppreheim Private First Class

    Ran all the steps in the "do me first" thread, and then ran the special removal items and the Virtumonde aka Trojan Vundo Removal thread removed the pop ups. Thanks Majorgeeks, saved me again.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You most likely have more issues than just the Vundo, I would recommend following the steps and attaching the requested logs.

    It's up to you whether you want to procede but I would stongly recommend it.
     
  5. ppreheim

    ppreheim Private First Class

    I did all the scans before I did the special removal stuff. IN safe mode I was not able to save the scan logs however. Bitdefender found some stuff but the other online scan did not. I ran a hijack this and it is posted as an attachment. Thanks in advance
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway

    O2 - BHO: WTLHelper Object - {BD6CD737-34E1-4864-8697-83EC081F1989} - C:\WINDOWS\system32\pmkji.dll (file missing)

    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.

    After you complete the above, reboot and let me know how things are running.
     
  7. ppreheim

    ppreheim Private First Class

    Did as informed. No pop ups so far. HJT posed. Thanks again.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log looks good, are you having any current problems?
     
  9. ppreheim

    ppreheim Private First Class

    Not that I can tell. Thanks!!!!!!!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ is currently moving and is not available!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds