Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Jul 22 2008, 07:46 PM
Post
#16
|
|
![]() W.A.M. (Women Against Malware) ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 1,731 Joined: 3-January 05 From: South Carolina, USA Member No.: 8,530 |
QUOTE Also any direction or advice you can provide on how I may remove malware myself would be appreciated. Is it possible to delete the offending part of the file and restore it? Is there a process I can follow to repair such infected files as those found on my original scan by Avast? I suggest you apply to BleepingComputer's Malware Removal Training Program, Learn how to use HijackThis to remove malware!. -------------------- You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators) Malware Removal University Masters Graduate Join The Fight Against Malware ![]() |
|
|
|
Jul 22 2008, 10:35 PM
Post
#17
|
|
|
New Member ![]() Group: Members Posts: 13 Joined: 10-June 08 Member No.: 215,337 |
Hi Susiebaby, Thanks - will do when slots are available. In the meantime are you going to do anything with all the scans and information I have sent or you have requested from me so far? I hope it has not been all for naught? Regards, Nimshie29 |
|
|
|
Jul 22 2008, 11:40 PM
Post
#18
|
|
![]() W.A.M. (Women Against Malware) ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 1,731 Joined: 3-January 05 From: South Carolina, USA Member No.: 8,530 |
I am retired on Social Security Disability. Please be patient with me as I am
-------------------- You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators) Malware Removal University Masters Graduate Join The Fight Against Malware ![]() |
|
|
|
Jul 23 2008, 10:15 AM
Post
#19
|
|
![]() W.A.M. (Women Against Malware) ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 1,731 Joined: 3-January 05 From: South Carolina, USA Member No.: 8,530 |
You may want to print this page. Make sure to work through the fixes in the order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
Step 1 In normal mode, run an online antivirus check from at least two and preferably three of the following sites BitDefender Computer Associates Online Virus Scan Panda's ActiveScan Trend Micro Housecall Windows Live Safety Center Free Online Scan This scanner from Trend does not require an Active X to run.
Step 2 Please download Spybot-S&D. Please check this link, Using Spybot- Search and Destroy To Remove Spyware From Your Computer, for instructions on how to download, install and use Spybot-S&D. Run this program as soon as possible. Step 3 Please download Ad-Aware 2008. Please check this link, Ad-Aware 2007/ 2008 for instructions on how to download, install and use Ad-Aware. Run this program as soon as possible. Step 4 I recommend using Spyware Blaster. Please download SpywareBlaster. SpywareBlaster helps to:
Step 5 The ATF-Cleaner program is for XP and Windows 2000 only. ATF-Cleaner features include:
Instructions:
If needed, Tutorial on ATF Cleaner with pictures. Do not run it yet. Step 6 Please disconnect from the Internet. Please close ALL browser windows (including this one). Step 7 During the process of removing malware from your computer, there are times you may need to use specialized fix tools. Certain embedded files that are part of these specialized fix tools may be detected by your antivirus or anti-malware scanner as a RiskTool, Hacking tool, Potentially unwanted tool, a virus or a Trojan when that is not the case. These tools have been carefully created and tested by security experts so if your antivirus or anti-malware program flags them as malware, then it is a False Positive. Antivirus scanners cannot distinguish between good and malicious use of such programs; therefore, they may alert you or even automatically remove them. In these cases, the removal of these files can have unpredictable results and unintentional results. To avoid any problems while using a specialized fix tool, it is very important that you temporarily disable your antivirus and/or anti-malware programs before using the specialized fix tool. When your system has been cleaned, it is important that you enable your security programs to avoid reinfection. Please disable the following programs: Windows Defender
Step 8 Is this your Internet Service Provider (ISP)? If this is not your ISP, you need to use HijackThis to fix item(s). O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au O17 - HKLM\System\CS2\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au O17 - HKLM\System\CS3\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au Step 9 Now we will address the HijackThis fixes. Please run HijackThis and click Scan Place checks next to the following entries (make sure not to miss any): R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\pchealth\helpctr\System\panels\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\pchealth\helpctr\System\panels\blank.htm O2 - BHO: XBTBPos00 - {A50B6E91-4081-4B37-BEA1-AD98A3CD51BA} - (no file) O3 - Toolbar: eMusic Toolbar - {F8CC9B08-C14F-4A5C-B73B-518AFECC067A} - (no file) Close all browsers and other windows except for HijackThis, and click Fix Checked to have HijackThis fix the entries you checked. Step 10 Optional Fixes is the name that we use for fixes for unnecessary programs that load during startup and run in the background. These programs are not required to start automatically as you can start them manually if you need them. You would not be removing the program itself, just removing them from your startup. Your computer may be sluggish due to the many programs loading during startup and running in the background that are not necessary. Windows has a facility for starting programs at startup time. Some of these programs are required for your computer and the applications installed on it to run correctly. A good example of such a program is a virus-checking application that must always run, constantly checking for and isolating or removing files with viruses. Other such programs are not strictly required, or are optional. In some cases, you can gain significant performance enhancements by disabling the automatic startup of these programs. In many cases, the functionality offered by the programs is still available by starting the programs manually by, for example, starting the program from the Windows Start->Programs menu. Media players and instant messaging programs often fall into this category. In fact, it is common for many modern software applications, when installed, to add programs at startup that add items to the system tray or shortcut (context) menus in Windows Explorer to provide quick access to the features and functions of these applications. While they may be useful, they do increase boot time and consume system resources. It is advised that you disable these programs so that they do not take up necessary resources or slow the boot time. Other than ScanRegistry, SystemTray, StateMgr, antivirus program entries, and firewall program entries, very few others need to load and run. Read the articles below to see if it applies to your computer problem with being slow to respond. Slow_Computer_Check_here_first_it_may_not_be_malware. Help! My computer is slow! 50 Tips for a Super Fast PC 4 Ways to Speed Up Your Computer's Performance It's not always malware: How to fix the top 10 Internet Explorer issues If you decide that you want to stop the Optional Fixes in your startup, let me know and I will give you a list with instructions. You would not be removing the program itself, just removing them from your startup. Step 11 Let’s run ATF-Cleaner to ensure no malware is hiding in temporary folders and for general computer cleanup to free space on your computer. Step 12 Please run HijackThis in Normal Mode and post a new HijackThis log so I can make sure that all the malware was deleted according to plan. Please post the list of file names and locations for any files that can’t be cleaned / deleted that were reported after you completed the online scans. Please advise me of any problems you still have. -------------------- You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators) Malware Removal University Masters Graduate Join The Fight Against Malware ![]() |
|
|
|
Jul 23 2008, 09:02 PM
Post
#20
|
|
|
New Member ![]() Group: Members Posts: 13 Joined: 10-June 08 Member No.: 215,337 |
Thanks for that Suebaby,
I have copied it and will work through it when I get over the flu. I am on an aged pension that was a disability so please excuse my slow take-up and lack of concentration at times. I am in no hurry for the results. How does one get a password to enter the Training Program without having to wait please? Have a peaceful day, Nimshie29 |
|
|
|
Jul 24 2008, 02:42 PM
Post
#21
|
|
![]() W.A.M. (Women Against Malware) ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 1,731 Joined: 3-January 05 From: South Carolina, USA Member No.: 8,530 |
Take your time. I have good days and bad days so I know how it feels to be slow. I do not know of any passwords to get into training. After you are clean and if you have not begun training here at BleepingComputer Malware Removal Training program, if you want to know about other training sites, let me know.
-------------------- You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators) Malware Removal University Masters Graduate Join The Fight Against Malware ![]() |
|
|
|
Sep 4 2008, 10:32 AM
Post
#22
|
|
![]() W.A.M. (Women Against Malware) ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 1,731 Joined: 3-January 05 From: South Carolina, USA Member No.: 8,530 |
This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
-------------------- You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators) Malware Removal University Masters Graduate Join The Fight Against Malware ![]() |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 12th October 2008 - 09:49 AM |