Helpp!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Thekid18, Feb 19, 2009.

  1. Thekid18

    Thekid18 Private E-2

    I got some problems here tryed avenger tryed killbox tryed hijackthis tryed almost every spyware removal program .. they keep popping back..
    The worms are..

    Unocoppied.reg
    Hole.zip
    Empty.jp
    Blank.Doc

    Can somebody please help me with this..

    Cheers Carlos
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Thekid18

    Thekid18 Private E-2

    Tryed the instructions not working man can you give me some help since your the admin i have heard rumours that i got a dangerous worms that can spy on my passwords en bankaccount numbers i need 2 remove this man..
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What isn't working? What tools? What error messages? Have you tried doing them in safe mode, have you renamed them?

    Who told you what?

    I can not help you unless i can look at the requested logs...I am not in front of your computer and have no idea what is happening.
     
  5. Thekid18

    Thekid18 Private E-2

    Here my hijackthis log man

    Logfile of HijackThis v1.97.7
     
    Last edited by a moderator: Feb 19, 2009
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I did not ask for a HJT log. You did not answer my questions as to what problems you are having running the scans.

    You also did not install HJT correctly:
    You have this which needs to be removed:
    C:\DOCUME~1\Hafid\LOCALS~1\Temp\Rar$EX00.078\HijackThis.exe

    And it is obvious that you have been downloading warez....You need to read our caution about doing this.

    This needs to be renamed:
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe --> renamed to:
    C:\Program Files\Trend Micro\HijackThis\analyse.exe

    You can start by doing this:
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\dllChache\Empty.jpg
    C:\WINDOWS\system32\dllChache\Blank.doc
    C:\WINDOWS\system32\dllChache\Zero.txt
    C:\WINDOWS\system32\dllChache\Hole.zip
    C:\WINDOWS\system32\dllChache\Unoccupied.reg
    C:\WINDOWS\system32\libusbd-nt.exe

    I am sure some of this is in your system32 folder but until you get me the logs from the Read and Run First I can not tell what all is there.
     
  7. Thekid18

    Thekid18 Private E-2

    Ok i removed the maxi warez en the files you told me 2 but how can i remove the unocoppied.reg you keep asking me for a log.. that you need what program must i use 2 get that log ?

    Btw thanxs man
     
  8. Thekid18

    Thekid18 Private E-2

    What is the name of the program..
    So i can scan it quick give you the log..
    Need 2 remove this virus man.. its messing everything up..

    Btw thanxs man.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you did as I asked you to do in the beginning and followed the Read and Run First instructions, (READ & RUN ME FIRST. Malware Removal Guide] then you would know what scans I want you to run:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip ---> from running the C:\MGTools.exe
     
  10. Thekid18

    Thekid18 Private E-2

    Alright man here it is .. all the files you need attached in the mglogs file..

    Btw thanxs man..
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you wish to drag this process out, we can do that. You did not attach logs for:
    SAS
    MBAM
    ComboFix

    Now we will remove a few items, some of which may come back because things were not removed by the scans that you did not run,

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 1"
    Java(TM) 6 Update 6

    Now empty this folder:
    C:\Documents and Settings\Hafid\Local Settings\Temp\

    disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger, SAS, MBAM and the ComboFix logs.
     
  12. Thekid18

    Thekid18 Private E-2

    I got the logs.. the files are still here..
    Unocoppied.reg
    Blank.doc..
    Empty.jpg
    zero.txt

    Here are the files
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will get back to you once you download and attach the logs I asked for:
    SAS
    MBAM
    ComboFix
     
  14. Thekid18

    Thekid18 Private E-2

    Here are the superanti en malware logs i cant get you the combofix log becuase its not running man keeps popping up 8 times its not working so can you help me now get rid of the
    Unocoppied.reg
    Blank.doc
    Empty.jpg
    Zero.txt files

    because it feels like some one is stealing my passwords need 2 get rid of the crappy trojans..
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you disable your anti-virus and anti-spyware programs before you tried to run Combo?

    Why am I seeing this:
    Now follow these instructions:

    Disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    You hardly have room left on your hard drive. You might want to think about removing some unused items.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  16. Thekid18

    Thekid18 Private E-2

    thanxs i l give it a try ..
     
    Last edited by a moderator: Feb 24, 2009
  17. Thekid18

    Thekid18 Private E-2

    Thanxs TimW

    Thanxs timw your awesome..
    All the viruses are gone ..
    When i got some problems again i definitely come back here
    Later man en thanxs ..

    Btw here is the log file you asked for
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please keep all of your replies in this thread.

    Running cracked programs is a sure way to be infected. And much of what I wanted you to fix has not been done.

    You did not attach the Avenger log.

    Please follow these instructions:
    Using BitDefender Online Scan

    Attach the log when finished.
     
  19. Thekid18

    Thekid18 Private E-2

    here is the bdscan..
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see what was removed........so what problems are you still having?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds