All system check, but still some left

Discussion in 'Malware Help (A Specialist Will Reply)' started by heathovc, Jan 19, 2006.

  1. heathovc

    heathovc Private E-2

    I ran through all the steps except the hijack this! step, I have done everything up to the online Panda scan. I did all of this in safe mode because i thought that if i lauched in normal boot mode, that my trojan would start REINSTALLING itself like it did almost billion times, not quite there yet, but getting close. After the programs deleted like literally hundreds of files, and it took HOURS I didnt have, I deep scanned everything also, I rebooted my computer into normal mode and it detected a "Network Monitor" deal. I am not advanced, but i do know have a router and am on a LAN. If you techies want the address, the spybot gave it to me as "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Network Monitor" and it also said that it is a Registry Key if that helps. I REALLY do not want to wipe my hdd, but since I dont have $200 I might have to. :(

    Keep in mind that I am on a computer in a different room, so I have to transfer the files...
     
  2. heathovc

    heathovc Private E-2

    I dont know what it was, but SpyBot deleted it! :D I really hope my computer is spyware/adware/virus/worm/trojan/comp-****er-upper free next time i boot it up. Thanks guys, your tutorial helped my wallet and my data GREATLY!:eek: I hope I never have to use it again, but most likely I will. Now I am passwording my computer so my bro doesnt dl any more **** to it. And thanks again for your tutorial and all of help:) !
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You should post the logs, so we can take a look at them and make sure there isn't something else on your system that may need to be removed.
     
  4. heathovc

    heathovc Private E-2

    ok, here is a log from hijackthis! that i just now did in normal mode...if you would like a screenshot of a suspicious folder...id upload it for you.
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix teh following:
    REBOOT to Safe Mode.

    Using the search feature in the Start Menu search for and delete every instance of lockbr.exe.

    Next open Windows Explorer navigate to a delete this folder: C:\Program Files\Common Files\VCClient.

    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    REBOOT to Normal Mode.

    Post the BitDefener and Panda ActiveScan logs from the turtorial; and post a fresh HijackThis log.

    Which folder are you taking about?
     
  6. heathovc

    heathovc Private E-2

    #1, i need to go to bed, would it be possible for me to do this once i turn the computer back on? well of course id have to copy and paste your steps into notepad...

    #2 That is the Local Disk (C:). my main hdd page. Some icons are blurred out and some arent.
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You can do the steps in the morning.

    If you are talking about the faded, greyish folders; those are hidden system files and folders. They always appear that way when view hidden system files and folders is enabled.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds