943,907 Members | Top Members by Rank

Ad:
You are currently viewing page 2 of this multi-page discussion thread; Jump to the first page
Sep 19th, 2006
0

Re: Three infections

Sorry for jumping in, but you are infected. Please run HJT again, select do system scan only, and check these items.

F1 - win.ini: run=lxcgppls.exe

O21 - SSODL: rjgoitr - {CDEFEE3D-EDCB-4226-931B-90E184C11CAC} - C:\WINDOWS\SYSTEM\hehesox.dll


Click Fix Checked.

__________________________________________________

Please download Pocket Killbox by O^E.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\SYSTEM\hehesox.dll


  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

____________________________________________________

Please download and install ewido anti-spyware tool
  • Close all other Applications Select language click Ok
  • Click I Agree
  • Click next
  • Click Install
  • Click Finish
  • Wait Ewido will open main screen automatically.
  • Wait again a few minutes and Ewido Should Auto update itself. If it doesn't click update at top of screen.
  • This in very important to get updates
  • When updating has finished. Close Ewido.
If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE

    You MUST manage to get into Safe Mode for the fix to work.
Make sure to close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
  • Open Ewido
  • Click on scanner top of Ewido sceen
  • Click on Settings
  • Under How to Act click on Recommended Action choose Quarantine
  • Under How to scan all boxes should be selected
  • Under Possibly unwanted software all boxes should be selected
  • On right side under Reports: click on Automatically generate report after every scan.
  • Under What to scan select scan every file
  • Click On scan Tab
  • Click on Complete system scan
  • Let the program scan the machine It can take awhile give it time.
  • When scan has finished At bottom of screen click Apply all Actions
  • Click Save report
  • Click Save Report as (Save as window's screen should pop up.)
  • Click desktop
  • Click Save
  • Exit ewido
Reboot back to normal mode

________________________________________________

Ewido should kill most of it.

Post back with the ewido log, and a new HJT log.
Team Colleague
Reputation Points: 84
Solved Threads: 99
<Insert title here>
tayspen is offline Offline
1,542 posts
since Jul 2005
Sep 19th, 2006
0

Re: Three infections

Click to Expand / Collapse  Quote originally posted by tayspen ...
Sorry for jumping in, but you are infected. Please run HJT again, select do system scan only, and check these items.

F1 - win.ini: run=lxcgppls.exe

O21 - SSODL: rjgoitr - {CDEFEE3D-EDCB-4226-931B-90E184C11CAC} - C:\WINDOWS\SYSTEM\hehesox.dll


Click Fix Checked.

__________________________________________________

Please download Pocket Killbox by O^E.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\SYSTEM\hehesox.dll


  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

____________________________________________________

Please download and install ewido anti-spyware tool
  • Close all other Applications Select language click Ok
  • Click I Agree
  • Click next
  • Click Install
  • Click Finish
  • Wait Ewido will open main screen automatically.
  • Wait again a few minutes and Ewido Should Auto update itself. If it doesn't click update at top of screen.
  • This in very important to get updates
  • When updating has finished. Close Ewido.
If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE

    You MUST manage to get into Safe Mode for the fix to work.
Make sure to close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
  • Open Ewido
  • Click on scanner top of Ewido sceen
  • Click on Settings
  • Under How to Act click on Recommended Action choose Quarantine
  • Under How to scan all boxes should be selected
  • Under Possibly unwanted software all boxes should be selected
  • On right side under Reports: click on Automatically generate report after every scan.
  • Under What to scan select scan every file
  • Click On scan Tab
  • Click on Complete system scan
  • Let the program scan the machine It can take awhile give it time.
  • When scan has finished At bottom of screen click Apply all Actions
  • Click Save report
  • Click Save Report as (Save as window's screen should pop up.)
  • Click desktop
  • Click Save
  • Exit ewido
Reboot back to normal mode

________________________________________________

Ewido should kill most of it.

Post back with the ewido log, and a new HJT log.
OK, I KNOW THIS IS GOING TO BE HARD TO UNDERSTAND BUT THIS OTHER GUY WHO JUMPED IN OVER THE ONE WHO WAS HELPING ME OUT, I WANT YOU TO KNOW THAT'S OK AND YOU SEIZED THE MOMENT!! I MUST SAY "QUITE ALOT OF INSTRUCTION FOR THIS OLD MAN. HOWEVER I DID THREE "AVG" SCANS AND FOUND THIS TIME 9 TROJAN VIRUSES. (SPELLING) WHEN I WAS GOING TO CONFIRM AND RE-SCAN "AVG" PROMPTED SAID IT HEALED ALL 9. WELL, I RE-SCANNED ANYWAY 3 MORE TIMES AND ALL THREE SHOWED A CLEAN SLATE. SO FOR NOW I AM GOING TO LEAVE IT AT THAT. "AVG" WILL PROMPT ME ALWAYS WHEN THERE IS A PROBLEM.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
takethetime is offline Offline
11 posts
since Sep 2006
Sep 19th, 2006
0

Re: Three infections

I believe I have some not right when I click "contron, alt and delete"
can I can the start up program and list it on the sight?
Reputation Points: 10
Solved Threads: 0
Newbie Poster
takethetime is offline Offline
11 posts
since Sep 2006
Sep 19th, 2006
0

Re: Three infections

Sorry for confusing you, just trying to help .

Not sure I understand your last post.
Team Colleague
Reputation Points: 84
Solved Threads: 99
<Insert title here>
tayspen is offline Offline
1,542 posts
since Jul 2005
Sep 19th, 2006
0

Re: Three infections

I know you are trying to help and thanks. Basically I scalled my computer with AVG three times and the first time it said it healed the virsuses. Then I scalled two more times to be sure and the program said there were no viruses found. But I found something funny when I clicked "control-alt-delete" some of the programs running in the background were unusual. So, I was wondering if you want me to run a different scan? I can't think of the name but I know where it is and how to do this.

takethetime
Reputation Points: 10
Solved Threads: 0
Newbie Poster
takethetime is offline Offline
11 posts
since Sep 2006
Sep 19th, 2006
0

Re: Three infections

There is an exellent scanner out there called ewido (www.ewido.net). It does a great job. Here are detailed instructions how to use it. If you have any problems post back .

Please download and install ewido anti-spyware tool
  • Close all other Applications Select language click Ok
  • Click I Agree
  • Click next
  • Click Install
  • Click Finish
  • Wait Ewido will open main screen automatically.
  • Wait again a few minutes and Ewido Should Auto update itself. If it doesn't click update at top of screen.
  • This in very important to get updates
  • When updating has finished. Close Ewido.
If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE

    You MUST manage to get into Safe Mode for the fix to work.
Make sure to close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
  • Open Ewido
  • Click on scanner top of Ewido sceen
  • Click on Settings
  • Under How to Act click on Recommended Action choose Quarantine
  • Under How to scan all boxes should be selected
  • Under Possibly unwanted software all boxes should be selected
  • On right side under Reports: click on Automatically generate report after every scan.
  • Under What to scan select scan every file
  • Click On scan Tab
  • Click on Complete system scan
  • Let the program scan the machine It can take awhile give it time.
  • When scan has finished At bottom of screen click Apply all Actions
  • Click Save report
  • Click Save Report as (Save as window's screen should pop up.)
  • Click desktop
  • Click Save
  • Exit ewido
Reboot back to normal mode

And, if you add that log into your next post. I can help you kill the rest of the viri .
Last edited by tayspen; Sep 19th, 2006 at 11:39 pm.
Team Colleague
Reputation Points: 84
Solved Threads: 99
<Insert title here>
tayspen is offline Offline
1,542 posts
since Jul 2005
Sep 20th, 2006
0

Re: Three infections

Ok, I printed out the instructions and I will have to take these steps very slowly and then I will add the report to the next post.

as my id say: take the time.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
takethetime is offline Offline
11 posts
since Sep 2006
Sep 20th, 2006
0

Re: Three infections

We may have a problem. I am running Win98SE and Ewido anti-spyware tool is for win2000 and XP. Suggestions!!

takethetime
Reputation Points: 10
Solved Threads: 0
Newbie Poster
takethetime is offline Offline
11 posts
since Sep 2006
Sep 23rd, 2006
0

Re: Three infections

Will apparently I don't seem to be having a problem now with trojans etc. I want to thank the two guys that did instruct me somewhat.

takethetime
Reputation Points: 10
Solved Threads: 0
Newbie Poster
takethetime is offline Offline
11 posts
since Sep 2006

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Pages won't load, HELP!!!
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: win min and yoursearcher.com





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC