Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Virus or trojan or spartan or something  (Read 17860 times)

0 Members and 1 Guest are viewing this topic.

NJDAVE

    Topic Starter


    Rookie

    Re: Virus or trojan or spartan or something
    « Reply #30 on: April 15, 2008, 06:26:35 AM »
    Hi,

    I've been away so I wasn't able to try your suggestion 'till just now.

    I ran the Vundofix then added the file C:\WINDOWS\system32\hmxmnqlq.exe.  Vundofix rebooted the machine then I ran Hijackthis again.

    The current Hijackthis log file still shows that file.

    Crap.

    David


    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Virus or trojan or spartan or something
    « Reply #31 on: April 15, 2008, 08:43:15 AM »
    Lets try this. Download Autoruns and search for the related entry and then delete it.
    • Create a new folder on your hard drive called AutoRuns (C:\AutoRuns) and extract (unzip) the file there. (click HERE if your not sure how to do this.)
    • Open the folder and double-click on autoruns.exe to launch it.
    • Please be patient as it scans and populates the entries.
    • When done scanning, it will say Ready at the bottom.
    • Scroll through the list and look for the startup entry related to the file hmxmnqlq.exe
    • Right click on the entry and choose delete
    • Reboot your computer and see if it returns.

    NJDAVE

      Topic Starter


      Rookie

      Re: Virus or trojan or spartan or something
      « Reply #32 on: April 15, 2008, 11:09:07 AM »
      I ran Autoruns as you described then rebooted and hmxmnqlq.exe was gone!

      I also rebooted and logged on for each of my separate user accounts, checking for the existence of hmxmnqlq.exe in each one.  It's not there in any of them.

      I've attached a new log from Hijackthis for you to verify.

      Is my computer now clean?

      David

      [recovering space - attachment deleted by admin]

      NJDAVE

        Topic Starter


        Rookie

        Re: Virus or trojan or spartan or something - Oops!
        « Reply #33 on: April 15, 2008, 12:52:57 PM »
        evilfantasy,

        I got your message and realized that I sent you the wrong Hijackthis log. 

        The log attached to this message is the one that I created after running Autoruns and rebooting, etc.  This one does not have evidence of hmxmnqlq.exe (I think).

        David

        [recovering space - attachment deleted by admin]

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Virus or trojan or spartan or something
        « Reply #34 on: April 18, 2008, 12:45:01 PM »
        Hello. Sorry it has taken so long to get back to you. Looks like it is gone indeed.

        Let's clear out the programs we've been using to clean up your computer, they are not suitable for
        general malware removal and could cause damage if launched accidentally and will help secure the work you have done.
        .
        • Click START then RUN
        • Now type Combofix /u in the runbox
        • Make sure there's a space between Combofix and /u
        • Then hit Enter.
        .
        .
        The above procedure will:
        • Delete:
          • ComboFix and its associated files and folders.
          • VundoFix backups, if present
          • The C:\Deckard folder, if present
          • The C:_OtMoveIt folder, if present
          • Reset the clock settings.
          • Hide file extensions, if required.
          • Hide System/Hidden files, if required.
          • Set a new, clean Restore Point.
          .
          Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

          1. Double click OTMoveIt2.exe to launch it.
          Vista users right click and choose Run As Administrator
          2. Click on the CleanUp! button.
          3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
          4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
          5. Once complete exit out of OTMoveIt2

          Set a New Restore Point to prevent possible reinfection from an old one
          Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
          • Go to Start > Programs > Accessories > System Tools and click System Restore
          • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
          • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
          • Next go to Start > Run and type Cleanmgr
          • Click OK
          • Click the More Options Tab.
          • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
          .
          Use the Secunia Software Inspector to check for out of date software.
          • Click Start Now
          • Check the box next to Enable thorough system inspection.
          • Click Start
          • Allow the scan to finish and scroll down to see if any updates are needed.
          • Update anything listed.
          .
          Here are some great tools to help you keep from getting infected again.

          To prevent unknown applications from being installed on your computer install WinPatrol 2007

          Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

          Spybot Search & Destroy - A safe and effective spyware scanner.
          * Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

          AVG Anti-Spyware Free Edition - Very reliable with a high detection rate.
          * AVG Anti-Spyware User Manual

          SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
          * Using SpywareBlaster to protect your computer from Spyware and Malware

          Comodo BOClean - Stops trojans and many more malicious attacks.

          Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
          * Click here for a list of free firewalls.
          * Why would I consider a third party firewall?
          * Understanding and Using Firewalls

           UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com[/b]]http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
          * Help with Windows updates

          Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

          Let us know if anything else comes up.