|
#21
|
||||
|
||||
|
We have a process for dealing with this, I would just like to make it simpler that is why I am trying a few things first.
*Hold down your windows key + R *Type cmd *hit enter at the prompt type ipconfig /flushdns HIT ENTER ipconfig /registerdns HIT ENTER netsh int ip reset resetlog.txt HIT ENTER netsh winsock reset HIT ENTER |
|
#22
|
||||
|
||||
|
Yes I do think that would work, and I was going to ask you if you were on the infected computer or had access to another computer
|
|
|
|
#23
|
|||
|
|||
|
It worked! I have combofix and sdfix logs attached. and fresh hjt!
spybot is still showing these keys trying to change, and i keep denying. and one is brastk. i guess its still not gone, exactly, but at least we're getting somewhere, right? :] |
|
#24
|
||||
|
||||
|
Yes, give me a few to go through the logs and get the script put together.
|
|
#25
|
||||
|
||||
|
Ok, one more then we will go for the script. I am just trying to get as much removed as possible to save myself from more work
http://users.telenet.be/marcvn/tools/haxfix.exe A red "dos window" (dos box) will open with this options: Select * 1. Make logfile After running option 1, you will get a new menu with all options: Select * 2. Run auto fix ------------------------------------------ Afterwards, please run me a fresh combofix log |
|
#26
|
|||
|
|||
|
ok, ran it through smoothly :]
attached is new combo log! |
|
#27
|
||||
|
||||
|
Now we are getting there - do you have the haxfix log -
Run CFScript Open notepad and copy/paste the text in the code box below into it: NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it. Also .. Pay particular attention to this :- Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it) Quote:
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log. |
|
#28
|
|||
|
|||
|
sorry, you didn't ask for that log :] here it is, i'll do the next step now!
|
|
#30
|
|||
|
|||
|
okie doke, here are the new logs!
|
|
#31
|
||||
|
||||
|
Getting better - I need more info from you
1) Did you pay for AVG AS, it looks like it might be the old stand alone one which no longer updates. - if this was from before they did away with it, and now it's bundled product. 2) Did you pay for Norton? And would you be willing to remove it to install a free product that will increase your protection. ========================================== Run CFScript Open notepad and copy/paste the text in the code box below into it: NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it. Also .. Pay particular attention to this :- Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it) Quote:
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log. |
|
#32
|
|||
|
|||
|
Sorry to take long, had a long day! Here are the new logs you requested.
|
|
#33
|
||||
|
||||
|
Almost there buddy,
Disable Teatimer
Remove bad HijackThis entries
Now you can turn tea timer back on See if you can make it through the 8 steps - http://www.techspot.com/vb/topic58138.html |
|
#34
|
|||
|
|||
|
ok, did the 8 steps. was able to download links! during scans though, Avira kept showing the keys trying to get in, but i denied them. will that be enough to have that program to keep them away? here are the logs from the 8-steps.
|
|
#35
|
||||
|
||||
|
This thing is still downloading the same malware. Or the tools aren't removing it.
Update Avira and run a full scan with it, let it remove anything it finds Keep your recycle bin empty ======================================================== KillBox
Boot into safe mode and have hijackthis fix these entries, with nothing else open. You may want to copy this into notepad and save it to your desktop so that you have it while in safe mode ========================================================== You are now in Safe mode and should have from HERE DOWN saved into a notepad. Make sure teatimer is disabled: Disable Teatimer
========================================================== Launch Hijackthis now from safe mode, and check the following: O2 - BHO: (no name) - {c5af42a3-94f3-42bd-f434-3604832c897d} - (no file) O4 - HKCU\..\Run: [12CFG94-z641-2SF-N31P-5M1ER6H6L1] C:\RECYCLER\S-1-5-21-7661557338-4881073579-043968640-8610\winigon.exe O4 - HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe O4 - HKCU\..\Run: [jsg8jfgfdfhfhf] C:\DOCUME~1\JOJO'S~1\LOCALS~1\Temp\winlogun.exe O4 - HKCU\..\Run: [xsjfn83jkemfofght] C:\DOCUME~1\JOJO'S~1\LOCALS~1\Temp\winlogin.exe O16 - DPF: {cafeefac-0014-0002-0000-abcdeffedcba} - O16 - DPF: {cafeefac-0015-0000-0011-abcdeffedcba} - O20 - Winlogon Notify: vtUnlKDW - C:\WINDOWS\ O20 - Winlogon Notify: zaimmnid - C:\WINDOWS\ Close any windows, and click Fix Checked. Close hijackthis. --------------------------------------------------------------------------------- Still in safe mode:
-======================================================== Now let it restart into normal mode, run a fresh scan with hijackthis Also let me know if Avira found anything. Attach the hijackthis log scanned after the reboot to normal mode, and we can go from there Last edited by Blind Dragon; 11-21-2008 at 10:30 AM.. |
|
#36
|
|||
|
|||
|
Blind,
I'm currently doing the next step (i'm on my boyfriend's laptop), and i don't understand how to get all the paths into the Killbox program? I copy one, paste it in the line, but then how do I get the next one to go in? I can't figure out how to get them all in (and yes, I have "All Files" selected). |
|
#37
|
||||
|
||||
|
After you paste one click the red button with white cross, then if it ask to reboot select 'no'
After you paste the last one and click the button, click 'yes' when it ask to reboot |
|
#38
|
|||
|
|||
|
alright, here is new hjt and avira log~!
|
|
#39
|
||||
|
||||
|
Nicely done! Looks like we got it, just be careful what you allow to connect with Comodo, if you don't recognize something - google the file name before allowing it - or come ask me what it is.
======================================================= Update your Java Runtime EnvironmentMany types of malware like to exploit out of date Java versions!GO HERE Click on Verify Java If you need to update your version:
==================================================== One more scan, if it comes up clean we can clean up and secure the system Run Kaspersky Online AV ScannerIn order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
|
|
#40
|
|||
|
|||
|
again, sorry for the long wait, really busy here before the holidays :]
|
![]() |
| Tags |
| hjt, spyware |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Malware/spyware problems - fling.com and bogus spyware popups | Virus & Malware removal | 4 | 11-13-2008 10:41 AM | |
| Corrupt Anti-Spyware + Spyware Comparsion | Virus & Malware removal | 2 | 07-05-2008 08:22 PM | |
| Spyware has killed my computer! Tskmgr will not open, keeps reloading spyware | Virus & Malware removal | 12 | 12-14-2005 02:51 AM | |
| desktop: spyware infection:your computer is infected with spyware | Virus & Malware removal | 2 | 12-03-2005 05:14 PM | |
| Trojan.Downloader.KavSvc and Unclassified.Spyware.61 Spyware | Virus & Malware removal | 6 | 08-05-2005 10:47 AM | |
All times are GMT -4. The time now is 01:47 PM.





Update your Java Runtime Environment
Run Kaspersky Online AV Scanner