Need help with adoginhispen, skitodayplease virus

Status
Not open for further replies.

mendez1658

Posts: 7   +0
hey, anybody can help me with this annoying virus, i been having this problem for a while now. Heres my hijackthis log file.

thanks in advance
 
FindAWF

Download FindAWF.exe and save it to your desktop.
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to Press any key to continue.
  • Press 1 and then Enter, and the FindAWF tool will begin scanning your computer for the infected AWF files and the backups the trojan created.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt which will automatically be saved to your desktop or to the same location as FindAWF.exe.
  • Attach the AWF.txt file in your next reply.
 
Ok,

DELDOMAINS

Download Deldomains.
  • Save it to your desktop.
  • Right-click DelDomains.inf and select: Install (no need to restart)
  • You may not see any noticeable changes or prompts; this is normal.
Note: The DelDomains.inf file will remove ALL entries in the Trusted, Restricted, and Enhanced Security Configuration Zones. Any entries that you had will need to be entered again. You will have to reimmunize with SpywareBlaster, and/or Spybot after doing this, and reinstall IESpyads if you use any of these programs.

Open Internet Explorer

click tools -> internet options.

Then, click the privacy tab and click the sites button. In the address bar type

Warning! Do not click the links below in the qoute box.



Click ok, then ok again and close IE. reboot your system.

Check if it's still there

Fix AWF Infection Step 2
Copy the file paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
"C:\Program Files\ltmoh\bak\Ltmoh.exe"
"C:\Program Files\QuickTime\bak\QTTask.exe"
"C:\Windows\ehome\bak\ehtray.exe"
"C:\Windows\System32\bak\ctfmon.exe"
"C:\Windows\System32\bak\hkcmd.exe"
"C:\Windows\System32\bak\HWKeyPlus.exe"
"C:\Windows\System32\bak\HWTabTray.exe"
"C:\Windows\System32\bak\igfxpers.exe"
"C:\Windows\System32\bak\igfxtray.exe"
"C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
"C:\Program Files\Microsoft Office\Office12\bak\GrooveMonitor.exe"
"C:\Program Files\OLYMPUS\OLYMPUS Master 2\bak\FirstStart.exe"
"C:\Program Files\OLYMPUS\OLYMPUS Master 2\bak\MMonitor.exe"
"C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe"
"C:\Program Files\TOSHIBA\TOSCDSPD\bak\toscdspd.exe"
"C:\Program Files\TOSHIBA\TOSHIBA Applet\bak\thotkey.exe"
"C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\bak\SmoothView.exe"
"C:\Program Files\TOSHIBA\Tvs\bak\TvsTray.exe"
"C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE"
"C:\TOSHIBA\IVP\ISM\bak\pinger.exe"
"C:\Windows\System32\DLA\bak\DLACTRLW.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe"
"C:\Program Files\Common Files\Adobe\Updater5\bak\AdobeUpdater.exe"
"C:\Program Files\Common Files\Adobe\Updater5\bak\AdobeUpdater.exe"
"C:\Program Files\Common Files\Adobe\Updater5\bak\AdobeUpdater.exe"
"C:\Program Files\Common Files\Adobe\Updater5\bak\AdobeUpdater.exe"
"C:\Program Files\Intel\Wireless\Bin\bak\ifrmewrk.exe"
"C:\Program Files\Intel\Wireless\Bin\bak\ZCfgSvc.exe"
"C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe"
"C:\Program Files\MyWebSearch\bar\1.bin\bak\mwsoemon.exe"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak\VERSIO~2.EXE"
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Press 2 then Enter
  • Notepad will open a file named FindAWF.txt. It will appear with instructions to click below the line and paste the list of files to be restored.
  • Right click below this line and select Edit, Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
  • The program will proceed to move the legit files and will perform another scan for bak folders.
  • It may take a few minutes to complete, so please be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please attach the AWF.txt file in your next reply.


This thread is for the use of mendez1658 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Fix AWF Infection Step 3

Copy the paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\Program Files\iTunes\bak
C:\Program Files\QuickTime\bak
C:\Windows\ehome\bak
C:\Windows\System32\bak
C:\Program Files\Google\GoogleToolbarNotifier\bak
C:\Program Files\Microsoft Office\Office12\bak
C:\Program Files\OLYMPUS\OLYMPUS Master 2\bak
C:\Program Files\Synaptics\SynTP\bak
C:\Program Files\TOSHIBA\TOSCDSPD\bak
C:\Program Files\TOSHIBA\TOSHIBA Applet\bak
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\bak
C:\Program Files\TOSHIBA\Tvs\bak
C:\Program Files\Yahoo!\Messenger\bak
C:\TOSHIBA\IVP\ISM\bak
C:\Windows\System32\DLA\bak
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\bak
C:\Program Files\Common Files\Adobe\Updater5\bak
C:\Program Files\Intel\Wireless\Bin\bak
C:\Program Files\Java\jre1.6.0_03\bin\bak
C:\Program Files\MyWebSearch\bar\1.bin\bak
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\bak
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Select Option 3 from the menu and press Enter.
  • Press any key to continue.
  • A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
  • Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
  • The program will proceed to remove the folders and will perform another scan for bak folders.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please attach the AWF.txt file in your next reply.
Before you close FindAWF, Select Option 4 from the menu and press Enter.
When it's finished the tool will return to the main menu.
Press E to close FindAWF.

This thread is for the use of mendez1658 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Delete Files and Folders
  • boot into Safe mode, see how HERE.
  • Right Click on the start button and chose explore
  • Show all hidden files and folders, see how HERE
  • Navigate to the following files and folders and delete them(if still present)

C:\Program Files\ltmoh\bak<---------This Folder

  • Empty the recycle bin.
  • Boot back into normal mode and then run FindAWF option 1

***DO NOT USE MSCONFIG TO BOOT INTO SAFE MODE***
 
Status
Not open for further replies.
Back