unable to remove malware - please help :(

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thomasss, Oct 13, 2006.

  1. thomasss

    thomasss Private E-2

    hello
    I am new to these forums (obviously) so please forigive me if I do something wrong. I have read the sticky and followed as many of the steps as i am able, however most scan prgrams (adaware se, bitdefender and spybot search and destroy to name a few) lock up halfway through scanning,even in safe mode.
    Using panda antivirus i was able to learn that I have contracted something called downloader.zlob.DEZ (though the program was unable to remove it). Since infection, I am unable to browse any folder containing movie files through windows explorer, in normal or safe mode - the window just crashes. The same thing happens if i use IE to browse my C drive. I would just format, but that would mean losing about 20gb of files i really want to keep - and cant backup due to the explorer crashes.
    Enclosed are the log files i was able to generate. Please can someone advise me what to do next? I would be eternally grateful. If i have missed anything, let me know and I will add it in a future post.

    thomas
     

    Attached Files:

  2. thomasss

    thomasss Private E-2

    hello again

    just a quick note in case anyone has the same problem and finds this post. Using a tiny bit of initiative I managed to find a work around. Using an alternative to windows explorer called Universal explorer (trial version available at http://www.spadixbd.com/) I was able to navigate to the relevant folders and move them out of the "my documents" folder, and now I can access them through either program. I'm going to cut my losses, back everything up and format. Not exactly a fix but at least I wont lose any data now.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    The choice yours on whether you want to reinistall or not but your problems are not that bad and can be easily fixed. You have a Wareout infection. If you want to fix it, just continue with the below.

    Run this: WareOut Removal and attach the requested log!

    Then attach a new HJT log.
     
  4. thomasss

    thomasss Private E-2

    thanks for the reply, i was halfway through my backup when things started to go awry again!
    After running the fix everything seems ok. i can't thank you enough! here's the requested log.
     

    Attached Files:

  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi thomasss,

    What Chas was after was a new Hijackthis log as well as the Wareout log,

    Attach a new HJT log and Chas will be able to issue you with any further removal instructions if needed :)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Halo is correct I need a new HJT log as requested.

    Also make sure viewing of hidden files is enable as requested in the READ ME and look for the below file using Windows Explorer. Delete the file if found:

    C:\WINDOWS\SYSTEM32\CSEQH.EXE
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds