I did the 8 steps, Here are my results

Status
Not open for further replies.
Uninstall BitTorrent DNA from add/remove programs in controlpanel.

Download HostsExpert: http://www.majorgeeks.com/Hoster_d4626.html

Choose one of the servers at Majorgeeks....save the file on your desktop

Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager
Run HostsXpert 4.2 - Hosts File Manager from its new home
Click on "File Handling".
Click on "Restore MS Hosts File".
Click OK on the Confirmation box.
Click on "Make Read Only?"
Click the X to exit the program.

Reboot, update malwarebyte, run a complete, have it to fix what it find.

Attach fresh hijackthis log, along with new malwarebyte log -in this topic

And tell how things are running now ?
 
touch, I had to run to work and will not be able to get to my computer till later this afternoon. I will try to do it as soon as i can. I really appreciate your help.
 
Touch,

Hope you are still around, I did the above steps and it seems to be running alot better. Even went I did the 8 steps yesterday I havent received a pop-up. I hope my logs look better.


Josh
 
I also had a quick question...

Now that I have removed the virus and I have all of these programs, I was wondering what are the best programs to keep and which virus protection should i be running on a regular basis. As virus software i ran nod32 but it allowed me to get the virus. I then purchased pctools spyware doctor. I wanted to know what the best programs to keep my system protected from future attacks. My friend is also looking to purchase virus protection, so any recommendations would be greatly appreciated.

Thanks,

Josh
 
Regarding your question about safety programs, is it okay if we wait until the computer is clean?
Because there is apparently still some infection on it.

Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080310
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKUS\S-1-5-19\..\Run: [nipufagagi] Rundll32.exe "C:\WINDOWS\system32\hagejuwi.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [nipufagagi] Rundll32.exe "C:\WINDOWS\system32\hagejuwi.dll",s (User 'NETWORK SERVICE')
O4 - Startup: FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe
O20 - AppInit_DLLs: dtwjdw.dll yodwzp.dll C:\WINDOWS\system32\vuzivavi.dll imseii.dll


Please download Combofix from:
http://subs.geekstogo.com/ComboFix.exe

And save to the desktop.

Open notepad and copy/paste the text in the quotebox below into it:

Killall:
Snapshot::
File::
C:\WINDOWS\system32\vuzivavi.dll
C:\WINDOWS\system32\imseii.dll
C:\WINDOWS\system32\dtwjdw.dll
C:\WINDOWS\system32\yodwzp.dll
C:\WINDOWS\system32\hagejuwi.dll
Folder::
C:\Program Files\FrostWire

Save this as:
CFScript

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

Then attach fresh combofix log, along with new hijackthis log.
 
sorry, I didnt mean to get ahead of myself.

I followed your steps and here are my results. I hope were better off.

- Josh
 
Should I continue using Limewire? => https://www.techspot.com/vb/topic124748.html

Uninstall File Sharing/P2P Programs

During the cleaning process all File Sharing Programs should be uninstalled
This is to avoid any possible reinfection of any malwares through file sharing

We reserve the right to withdraw our support:
  • If such programs are found in your logs
  • Should you not agree to their removal.
As they are normally set to bypass your Firewall and Anti-Virus software
Filesharing/P2P Programs serves as a constant threat to your computer
 
Status
Not open for further replies.
Back