This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] help with winself.exe

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let's clean out the files that Kaspersky found and uninstall combofix. I'll look into the red x that's still on the C drive. Also, is the Google Toolbar still installed and working? There are entries in the HijackThis log but show files missing.


First, you should empty out your Trend Micro Internet Security quarantine folder:

C:\Program Files\Trend Micro\Internet Security 12\Quarantine

Next,

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\Documents and Settings\destiny cruz\Desktop\SmitfraudFix.exe 	
    C:\Program Files\America Online 9.0\download\SmitfraudFix
    C:\SDFix 
    C:\VundoFix Backups
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0R8EK0TT\update[1].upd 	
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0R8EK0TT\update[2].upd 	
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0R8EK0TT\update[3].upd 	
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0R8EK0TT\update[4].upd 	
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0R8EK0TT\update[5].upd 	
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NXQBV2E0\update[1].upd 	
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\TH3U0DSS\1[1].exe 	
    C:\WINDOWS\system32\kexxfbcm.dll 	
    C:\WINDOWS\system32\kjclerkv.dll 	
    C:\WINDOWS\system32\tojhrpni.dll 	
    purity 
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.
To fix the C drive icon do the following:

Backup Your Registry with ERUNT

* Please use the following link and scroll down to ERUNT and download it.
http://aumha.org/freeware/freeware.php
* For version with the Installer:
Use the setup program to install ERUNT on your computer
* For the zipped version:
Unzip all the files into a folder of your choice.

Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe

~~~~~~~~~~~~~~~~~~~~~~~~~

Now let's fix the Red X on your C drive.

Open Notepad.
Copy everything inside the code box below (Starting with REGEDIT4) and paste it into a new notepad file.
Change the Save As Type to All Files and save it as fix.reg to your Desktop.

Note: Please copy and paste all the text at once, and check that there is NO blank line above REGEDIT4 and one blank line at the bottom.
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon]


Then double-click on the fix.reg file, and when it prompts to merge say yes.
I was able to run OTMoveIt2 and it did what is was supposed to do but I was unable to find a the log folder. I also did what you said to get rid of the red x and finally it is gone! Thank You.
Glad things are better…

Did you check the location I gave for the log file?

A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log).

Yes, I think the Malware took out the toolbar (or the process of removing the Malware). Does it still show in Add or Remove Programs in Control Panel. I would suggest you uninstall it from there if possible, if not let me know. Then download it again and re-install it. Let me know how you make out…
I was able to uninstall it and then download it again. Also, how do I get my time back to a twelve hour clock instead of twenty four hours?
For the time issue, did you do the combofix uninstall routine? If that doesn't do it… Go to Control Panel, Date, Time, Language, and Regional Options, click the item 2nd down in the list which says change the format of numbers…., click the time tab, go to time format and set it as h:mm:ss tt, the big H is 24 hr the small h is 12 click ok, and ok again…hopefully that will do it
In addition to updating and using what you currently have you may want to consider the following:

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
A tutorial on installing & using this product can be found here:
Using SpywareGuard to protect your computer from Spyware and Malware

Use Zoned Out -
Zoned Out will block access to malicious websites so you cannot be redirected to them from an infected site or email. Instructions for set up and use can be found at the website.

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Here is a great link to a post here on securing your PC after an attack.
http://www.castlecops.com/t7736-So_how_did…irst_place.html
Ok I will download those Thank You so much for your help. I also have a question should I run SDFix and the other programs you told me to download and keep on a regular basis or not?

I also have a question should I run SDFix and the other programs you told me to download and keep on a regular basis or not?

No, those tools should only be run with the supervision of an expert. They are also constantly updated so even if you did need to run them again you would want to download fresh copies.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI