got bugs again

Discussion in 'Malware Help (A Specialist Will Reply)' started by seaside, Jan 10, 2006.

  1. seaside

    seaside Corporal

    hi guys i'm in need of your help i have got a few bugs i cannot get rid of and some stuff i'm not to sure about i have done the scans heresis all the logs
    thanks in advance
     

    Attached Files:

  2. seaside

    seaside Corporal

    could chas look at this please:eek:
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    "Got bugs" is not a very descriptive piece of information for us to know what problems you are having. Can you please describe what your problems are? And what did you already fix with the tools?
     
  4. seaside

    seaside Corporal

    sorry i was trying to save time chas- you have fixed my puter loads of times in the past
    i ran the scans because i wanted to pay for a online item but the little lock icon did not show up so i started checking my puter that was about 8 hours ago
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What little lock icon are you talking about something when you go to a secure website to make sure it is safe?

    You do not show any signs of malware. Just a couple of blank R0 lines.


    But having nothing to do with the above, based on the below line, looks like you installed this patch: http://www.hexblog.com/2005/12/wmf_vuln.html

    O20 - AppInit_DLLs: F:\WINDOWS\System32\wmfhotfix.dll

    I recommend uninstalling Windows WMF Metafile Vulnerability HotFix from Add/Remove programs and install the Microsoft Official patch now that it is out.
    See: Security Update for Windows XP (KB912919)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that is not exactly what I meant to say. I meant to say your HJT log does not show any signs. The Panda log did but they do not seem to be loading. Try to delete the below files (use safe mode if necessary):


    F:\WINDOWS\kl.exe
    F:\WINDOWS\tool2.exe
    C:\Recycled\Q330995.exe <--- infact empty your Recycle Bin
     
  7. seaside

    seaside Corporal

    hi mate i tried but they are running says i cannot delete
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It said that in safe mode????

    I find it unlikely that Q330995.exe would be running from the Recycle Bin.

    You did not answer my question:
     
  9. seaside

    seaside Corporal

    ok im tryung to delete them in safe mode
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So what happened? Did they delete? Or did you mean you already tried to delete them in safe mode?

    Did you empty the Reccycle Bin? Did that Q330995.exe file go away now?

    You need to work on this quickly and may want to considered changing all of your passwords for online sites especial financial ones.
    See the below in regards to tool2.exe

    http://www.liutilities.com/products/wintaskspro/processlibrary/tool2/
     
  11. seaside

    seaside Corporal

    hi chas i did as you said but it says process being use etc getting a bit woried about my banking stuff:confused:
     
  12. seaside

    seaside Corporal

    this is some of the programs running of the programs running
    tool2through to tool 5 3 oct 05. it will not delete from safe mode and the other one running is called kl this was created on the 3rd oct 05
     
  13. seaside

    seaside Corporal

    just found another one called paytime i recon they are all linked together some how as they were all born on at the same time
     
  14. seaside

    seaside Corporal

    hi chas i have been on the puter all day i have ran loads of checks the latest one being ewido do you want me to post them.i think there must be about 6 or 7 by now
     
  15. seaside

    seaside Corporal

    me again not much cop at this stuff chas i am now installing 31 updates i thought i was on auto update dumb mothers that i am
     
  16. seaside

    seaside Corporal

    Re: got bugs again hello can you help



    come guys im desperate
     
  17. seaside

    seaside Corporal

    hi guys i loaded pocket kill box and this thing rocks it got rid of kl,paytime and tool 2,3 ,4,5. im not sure but i might have fixed it myself would love know if i did the right things
     
  18. seaside

    seaside Corporal

    hi chas read my post please i would like you to check if i did ok
     
  19. seaside

    seaside Corporal

    hey chas helpo me out
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be more patient. Continuously posting messages in your thread just makes it take longer to get an answer. We work from oldest to newest threads. Each time you added a message you basically lost your place in the queue and started over again working your way thru the queue to get an answer.


    First, please run this Running Ewido Security Suite and attach the Ewido log.

    Now download WinPFind
    • Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. .
    • Now click Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take sometimes take a while, upwards to 30 minutes or more.
    • When it is done, it will show the results of the scan. Right Click in the window and choose Select All. Then Right Click again and select Copy which will copy to the contents of the log to your clipboard. Then open a notepad window and paste in the log by pressing CTRL-V. Save it to a file and upload the text file here as an attachment.
     
  21. seaside

    seaside Corporal

    ok ewe thing posted
     

    Attached Files:

  22. seaside

    seaside Corporal

    hi mate heres the scan log
     
  23. seaside

    seaside Corporal

    chas i been at this fornearly 18 hours will get bak to you im f****d
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the log from WinPfind. Ewido did not really find anything of special interest.
     
  25. seaside

    seaside Corporal

    hi chas here is the log file you requested thank you for your help
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still nothing detected in the log either.

    I believe that you don't have any problems.
     
  27. seaside

    seaside Corporal

    thank you for all your help -seaside
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  29. seaside

    seaside Corporal

    hi chas how come i get this message i never tell anyone to delete antthing just the read me first thing.

    seaside, you do not have permission to access this page. This could be due to one of several reasons:

    Your user account may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
    If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I answered that in your PM a day or two ago.
     
  31. seaside

    seaside Corporal

    sorry dude i did'nt see the message thanks
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds