I Did Everything for the iworm_attck_v122.02a

Discussion in 'Malware Help (A Specialist Will Reply)' started by chiqui, Jun 30, 2006.

  1. chiqui

    chiqui Private E-2

    I did all the steps you wrote down to remove the the iworm but when I did the Bitdefender and Panda Active scan it still came up as infected.

    Here's My Hijack Report b4 I did Evrything:



    Edit: inline log removed for guide to be actioned





    I also have attached the the bdscan and my activescan txt files see what you can do 4 me.
     

    Attached Files:

    Last edited by a moderator: Jun 30, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    Do pay close attention to the installing and running of Hijackthis instructions, as yours was installed in the exact place we mention not to and was run with browser and other none essential applciations running.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. chiqui

    chiqui Private E-2

    I did all the steps already but when I ran the bitdefender it found 2 viruses but it said deleted on the third step of the virus so I ran panda active scan and it said that I still had 3 spyware items and I want to remove them I have attched both bitdefender and the panda activescan reports to this thread. Below is the Hijack This Log after I did everything:


    Edit: Inline log removed
     
    Last edited by a moderator: Jun 30, 2006
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Sorry but if you had really read the guide fully you would have known not to post your logs inline, but to attach them, and also to not have applcations like........

    Internet Explorer
    MSN Messenger
    Yahoo Messenger

    etc running?

    http://forums.majorgeeks.com/showthread.php?t=35407

    Your panda and Bitdefender logs you mentioned you attached are not.


    Skipping steps, leads to removing your malware slower and not completly, so its paramount to follow the guide verbatim to catch all malware exploits.
     
  5. chiqui

    chiqui Private E-2

    That was my mistake to run the those programs while I'm trying to get rid of the worm but I have attached the logs I went to the bottom of the thread and click on the attach window or link but I have another question when I click on Internet Explorer I get that my comp has a w32.Myzor.FK@yf virus???
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! In the future, please do not edit your older messages in the thread. Just attach the files to your new message that you are posting. The attachments you now added to message # 1 should have been added to message # 5.

    Pleae run the steps in the below and attach the requested smitfiles.txt log.

    SpywareQuake & SpyFalcon Removal Procedure

    Afterwards also attach a new HijackThis log but make sure you follow the directions in step 7 because you previously had HijackThis running from one of the exact locations we specify not to run it from: C:\Documents and Settings\Chiqui\Desktop\HijackThis.exe
     
  7. chiqui

    chiqui Private E-2

    I couldn't find any of the files listed but here is my Hijackthis log I don't know why it says I run it from desktop when I have it in my c:\ drive in it's own folder:

    Edit by chaslang: Inline HJT log attached!
     

    Attached Files:

    Last edited by a moderator: Jul 4, 2006
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not matter whether you find the files or not! The instructions even tell you that in the very first Note at the top of the page. You MUST FOLLOW DIRECTIONS. The procedure asked you to attach the smitfiles.txt log. You did not attach it. Do not run it again. Just attach the smitfiles.txt log that was created when you ran the procedure.

    Also we have also told you multiple time and it is also specified in the READ & RUN ME that all logs (including HJT logs) must be attachments to your message. They must not be posted inline like you are doing.

    In your first HJT log, you were running HJT from: C:\Documents and Settings\Chiqui\Desktop\HijackThis.exe which was a problem!
    Now you are running it from: C:\HJT\HijackThis.exe which is not what we requested but it is acceptable.

    The READ & RUN ME also specifies not to use MSconfig to control startups, you did not follow those directions in step 7. You have the below in your log:

    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Please select Normal Startup and then reboot and ATTACH a new HJT log and also the missing smitfiles.txt log.

    You should also tell us how things are running now!
     
    Last edited: Jul 4, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds