Help Needed - Virus, Perfect Code, Virusbusters

Discussion in 'Malware Help (A Specialist Will Reply)' started by nsylvia, Nov 18, 2006.

  1. nsylvia

    nsylvia Private E-2

    help me pls.
     

    Attached Files:

  2. nsylvia

    nsylvia Private E-2

    more files.
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Look in Add/Remove Programs for Perfect Codec, AutoUpdate & VirusBursters and uninstall if found.

    Also, you didnt attach a HJT log so please attach it to your next post.
     
  4. nsylvia

    nsylvia Private E-2

    i've already uninstall Perfect Codec. the rest not found.
    have attached hjt.log
     

    Attached Files:

  5. nsylvia

    nsylvia Private E-2

    have attached a printscreen with that critical error ballon that keeps appearing.
     

    Attached Files:

  6. nsylvia

    nsylvia Private E-2

    did ewido scan...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In BJ's absense, I'll give you the next steps and then BJ can continue to help after you complete these!

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.


    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  8. nsylvia

    nsylvia Private E-2

    now, i'm going to do step 2.
     

    Attached Files:

  9. nsylvia

    nsylvia Private E-2

    the balloon is gone! thanks man. this site is great.
     

    Attached Files:

  10. nsylvia

    nsylvia Private E-2

    new rapport.txt after step2.
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:

    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and let me know how things are running now.
     
  12. nsylvia

    nsylvia Private E-2

    done. flushed. i think i should be clear.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should not allow programs like below to always load at startup:

    O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
    O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"

    You should only run these programs when you really need them; otherwise they are stealing system resource and slowing your system down (and anyone else on your network too). Also they are security risks.



    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 7
    Java 2 SDK, SE v1.4.2_07
    Mozilla Firefox (1.5.0.8)
    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    If you need the Sun Java SDK you should also install the current version from:

    http://java.sun.com/javase/downloads/index.jsp


    Other than the above things you system appears to be clean. Are you having any other malware problems?

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. nsylvia

    nsylvia Private E-2

    thanks. ehh but i thought i've already uninstall ares and bitcomet. how to remove them entirely?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can just use HJT to fix the below lines:
    O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"

    But my comment still remains for uTorrent. You should not let it always load at startup.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds