Hi unlucky-online2,
So you can run hijackthis in (normal mode too?) and obtain the log but just cannot copy and paste it or send it here to TomCoyote?
Please try the following steps: If one does not work, please try the next step but let me know what is happening. Hopefully you will be able to do the following and reply (maybe more than once to post everything) giving logs, etc.
What happens if you rename hijackthis.exe to removal.exe? Can you run it and post(reply) with it?
If the above does not work then
Download Itty Bitty Process Manager (IBProcMan.zip)(direct download)
http://www.merijn.org/files/ibprocman.zip
Try running that - it will provide a 'task manager' like process in which you can stop running processes. Don't stop any yet, just list all that it has so I can check them and give advice.
======
SeDebugPrivileges
Download
VX2Finder by
Option^Explicit from here and save it to your Desktop.
Double click to run it.
Click the
Restore Policy button on the right hand side, and then
OK in the
Administrator Policy window that opens.
Close the program.
STEP 1.
======
Hoster
Please download
hoster.
- Unzip Hoster.zip
- Open Hoster.exe.
- Then click on "Restore Original Hosts"
- Close program when complete.
- Empty Recycle Bin
Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
STEP 2.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
- Download GMER and extract it to the C:\program files\GMER folder.
- Run the Gmer.exe program by double-clicking the executable file (gmer.exe) in Windows Explorer.
You may be prompted to scan immediately if GMER detects rootkit activity. - If you are prompted to scan your system click "yes" to begin the scan.
- If you are not prompted, Click the "Rootkit" tab, then click "Scan".
At the end of the scan, click "
Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in a reply here.
STEP 3.
Now STEP 4.
run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner
Next Click on
Launch Kaspersky Online Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click
Yes.
- The program will launch and then begin downloading the latest definition files:
- Once the files have been downloaded click on NEXT
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
- Standard
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK
- Now under select a target to scan:
- Select My Computer
- This will program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.
STEP 5.
======
WinPFind
Please Download the following tools to assist us in removing this infection! Download WinPFind from
http://www.bleepingcomputer.com/files/winpfind.php- Right Click the Zip Folder and Select Extract All
- Extract it somewhere you will remember like the Desktop
- Don’t do anything with it yet!
Reboot.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode
- Doubleclick WinPFind.exe
- Click on Configure Scan Options.
- Remove all the checkmarks under Folder Options on the left side by clicking the button Remove All, uncheck Run Addon's and click Apply.
- Click Start Scan
It will scan the entire System, so please be patient! This scan may take awhile
Once the Scan is Complete
- Reboot your computer into normal mode.
- Go to the WinPFind folder
- Locate WinPFind.txt
- Copy the results from the WinPFind.txt file and post the results in your next reply.