Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Members Search

>>> Get Paid to Hang Out Here! Activity = Points = Prizes. Want to Know More? <<<

Reply
 
LinkBack Thread Tools
  #11  
Old 14-08-2007, 10:31 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 01:30 AM
Posts: 4,905
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default How can I remove vicious malware?

OK lets try the Smitfraud removal again. Be sure you run it in Safe Mode. We will work on getting your settings back after this is gone.

Please do the following...
Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

Reboot your computer in Safe Mode.
If the computer is running, shut down Windows, and then turn off the power.
Wait 30 seconds, and then turn the computer on.
Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
Ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
Login on your usual account.

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Run CCleaner.
Do a fresh HJT scan and post a new HJT log along with a rapport.txt log
(2 attatchments)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #12  
Old 14-08-2007, 11:04 PM
No Avatar
CJ Member
 
waynestep is offline
 
Join Date: Aug 2007
Last Online: 08-05-2008 01:03 AM
Posts: 11
iTrader: (0)
waynestep is on a distinguished road
Default How can I remove vicious malware?

Hi,

I've run smitfraud in safe mode - it didn't prompt that wininet.dll was infected, and the rapport txt file attached.

Also ran CCleaner and HJT and the log file for latter is attached,

Kind regards

Wayne
Attached Files
File Type: txt smitfraud clean 14aug07.txt (1.3 KB, 13 views)
File Type: txt hijackthis log file 14aug07.txt (10.8 KB, 11 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #13  
Old 14-08-2007, 11:14 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 01:30 AM
Posts: 4,905
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default How can I remove vicious malware?

Have you gotten any of the controls back?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #14  
Old 14-08-2007, 11:23 PM
No Avatar
CJ Member
 
waynestep is offline
 
Join Date: Aug 2007
Last Online: 08-05-2008 01:03 AM
Posts: 11
iTrader: (0)
waynestep is on a distinguished road
Default How can I remove vicious malware?

No- still no control panel and when iIclick on the system program access and defaults I get the same restrictions messages.

Not looking good?

Wayne
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #15  
Old 15-08-2007, 12:04 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 01:30 AM
Posts: 4,905
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default How can I remove vicious malware?

Run HJT and select Do a system scan only. Check and remove these entries.
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\vtr159.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum348.txt
Close all windows before fixing.

Install and run this SUPERAntispyware Free Edition
When you have SAS open click the preferences.
General and Startup tab Only have checked
Show splash screen on startup
Use XP style menus
Check for program updates when the application starts
Do not scan when SuperAntiSpyware starts
Realtime Protection Tab
Uncheck everything there
Then scan your computer
Have it fix what it finds.
If anything other then cookies are found then please save the log.
From SUPERAntispyware start page click Preferences>Statistics/Logs Tab>Highlight The Log>View Log
Add the log in the next post.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #16  
Old 15-08-2007, 01:02 AM
No Avatar
CJ Member
 
waynestep is offline
 
Join Date: Aug 2007
Last Online: 08-05-2008 01:03 AM
Posts: 11
iTrader: (0)
waynestep is on a distinguished road
Default How can I remove vicious malware?

Hi,

done everything you said and the superspyware log attached. Following re-boot, I still have no control panel and continue to get same restrictions messages when trying the set programme access and defaults.

Bit of a swine this one - thanks for your help so far.

I'm off to bed now, another early start in the morning,

Regards

Wayne
Attached Files
File Type: txt superanti spy log 15aug07.txt (2.1 KB, 10 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #17  
Old 15-08-2007, 01:50 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 01:30 AM
Posts: 4,905
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default How can I remove vicious malware?

Yes this is where we start having fun.

Download this. Open it and check all of the boxes as it will not hurt anything. Dial-a-fix

Then go to Windows Update just to be sure nothing is missing.

If you get any error messages from anything at all. I need to know the exact message word for word/number.

Let us know if this helps.

Also a fresh HJT log.

Last edited by evilfantasy : 15-08-2007 at 02:02 AM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #18  
Old 15-08-2007, 05:54 PM
No Avatar
CJ Member
 
waynestep is offline
 
Join Date: Aug 2007
Last Online: 08-05-2008 01:03 AM
Posts: 11
iTrader: (0)
waynestep is on a distinguished road
Default How can I remove vicious malware?

Hi,

Have done as requested - no error messages, but the dail a fix scan was interrupted right at the start stating there were restrictions on the computer and it could not scan - it related to the adjust date and time check box. After clicking OK it started to scan the other areas - I've attached the log on the dial a fix scan if it helps.

Also HJT log attached.

Regards

Wayne
Attached Files
File Type: txt HJT Log 15aug0717.45.txt (10.9 KB, 10 views)
File Type: txt dial a fix log 15aug07.txt (14.7 KB, 8 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #19  
Old 15-08-2007, 06:30 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 01:30 AM
Posts: 4,905
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default How can I remove vicious malware?

Download this file - Link removed at posters request.
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Attach this log to your next reply

Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.

Last edited by Dave Hybrid : 30-08-2007 at 12:28 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #20  
Old 15-08-2007, 11:47 PM
No Avatar
CJ Member
 
waynestep is offline
 
Join Date: Aug 2007
Last Online: 08-05-2008 01:03 AM
Posts: 11
iTrader: (0)
waynestep is on a distinguished road
Default How can I remove vicious malware?

Hi,

Combo fix log attached

regards

Wayne
Attached Files
File Type: txt combofix log 15aug07.txt (10.1 KB, 12 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with a malware/virus winspywareprotect badproduce Virus, Spyware & Security 8 12-06-2008 09:28 PM
Malware Removal - Help VNani Virus, Spyware & Security 23 10-04-2008 01:29 AM
malware log antbann Virus, Spyware & Security 4 01-03-2008 09:31 PM
Malware! Can't access Add/Remove Programs! trevy3 Virus, Spyware & Security 17 19-11-2007 06:50 PM
Slow Computer? It May Not Be Malware evilfantasy Virus, Spyware & Security 0 26-10-2007 07:51 PM


Copyright ©2006 - 2008 Computer Juice - Forums - Free PC Help, IT Support and Repairs.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape