Followed Read me sticky instructions but i think im still infected.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ravager, Jul 27, 2006.

  1. Ravager

    Ravager Private E-2

    Ok, so I had a virus or something that disabled system restore, task manager, tweak ui, regedit, and a few other things by saying that they were disabled by the administrator. I can access these things now but when I did the steps in the read me there were still some things found that were not removed. Also, I seem to have a lot of processes running all the time. Im not sure if this is normal or not but it seems suspicious. Ive attaced bdscan, activescan, and my hijackthis log. Am I still infected?
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Then you should have run Ewido Anti-Malware as part of that pocedure. Post teh Ewido log.

    There is no AV program or Firewall installed?

    I see that you are running msconfig in /auto mode which means that you may have selectively removed some items in the past from the startup procedure. This can be bad if they are malware, reenable those startup entries by doing the following:

    Please click on start, then run, and type msconfig and then press enter. When the window opens click on the startup tab and make sure there are checkmarks in every entry. Then press ok until you are out of the program. If it asks to reboot, do not reboot.

    Now please create a new Hijackthis Log and post it as a reply.
     
  3. Ravager

    Ravager Private E-2

    These things were disabled from my startup:
    svchost
    sstray
    nvmtray
    PDVDServ

    svchost.exe I disabled myself because when I ran AVG antivirus, it found a virus in some svchost thing and deleted it, so now start my computer I get error messages that the file isnt there. I just disabled it at startup so I didnt get the error anymore.

    I reenabled all the things in the startup and ran hijackthis again. I also downloaded and full scanned with ewido and posted the log.
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The Ewido Scan Report is blank.

    Download
    - Pocket Killbox

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  5. Ravager

    Ravager Private E-2

    Ok, I did all the steps and here is the new log.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    << The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://java.sun.com/javase/downloads/index.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    In Safe Mode, delete the following files:
    C:\WINDOWS\system32\bx260.exe
    D:\New Backup Job.C000

    Reboot

    How is your computer running?
     
  7. Ravager

    Ravager Private E-2

    It seems to be running pretty well. Thank you very much for all your help. :)
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds