i've reach absolute hell

Discussion in 'Malware Help (A Specialist Will Reply)' started by jak3y, Jul 6, 2005.

  1. jak3y

    jak3y Guest

    trend micro found 117 viruses however it couldnt delete them, because they are attached to processes being run currently.
    ad-aware took out 41
    spybot took out 600+ with 150 remaining, again because of attachments to files that the OS needs to run the basics.

    no clue where to turn to
    HSREMOVE caught 62
    cwshredder removed tons
    help...
     
  2. jak3y

    jak3y Guest

    just to follow up
    avg - MANAGED FINALLY to "heal 226 out of 228" infections
    now what that means, i have no clue...im assuming it's ok.
    however, the Vault in AVG makes me wonder if i have to restore the file or not...because of the options "restore" "restore as"...
    so if anyone can help me out here that'd be great.
    Spybot is still having problems removing
    -C2.lop
    which are basically 4 gif files in my windows directory (4kb in size each)
    -Altnet
    which is in c:\windows\smdat32a.sys
    i could post the spybot log...is that ok?

    im seriously considering just reinstalling winXP on my friends computer...it's just such a pain and in the future who knows if everything will be fine after all this removal...
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you are referring to here. Is this thread the continuation of another thread. It seems like you are starting in the middle of some discussion. If you already posted this problem in another thread, you should not be starting a new one. It will only delay you from getting help and causes us to waste time.

    Why would you want to restore things from AVG's virus vault? That is where baddies are sent. Do you want to restore a virus?

    Have you run ALL steps in the READ ME FIRST?
    Did you run Ad-Aware and Spybot in safe mode? I would not expect to be having so many problems with attached processes in safe mode but it is possible.

    List the current problems you are having on this PC.
     
  4. jak3y

    jak3y Guest

    Chas'...initially my friend couldn't see her desktop, control panel on regular start-up.
    But i got it to safe mode, ran ad-aware, spybot and it removed a few of those things, so between safemodew/network., and regular mode to do a few things there, i managed to get rid of some things...especially the firefox browser shaking...
    ...and tons of spyware over 800, plus 226 of 228 virus' in avg...
    one trojan, trend couldn't take care of...now there's altnet to deal with in the registry and c2.log (4 gif images in windows) which wont just delete easily because they're being used by some other programs while in safe mode as well...so...i told her, gimme your xp cd, im doing a clean reinstall i think...better peace of mind...
    ...even if i removed this other stuff...just so much crap on it, it was insane...never seen anything like it...
    it was so bad, that hjt analyze page wouldn't even take the text file, because of one R8 had about 35 of the same thing logitech/desktopmanager with some kind of attachment...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean O18 lines like the below for an example:

    O18 - Protocol: bw+0s - {6D4A1378-791F-4526-8D56-621AB47B41C2} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll


    All you had to do was fix those lines with HJT to remove them. I have seen loads of these. That program should be uninstalled as far as I'm concerned. It obviously has problems.
     
  6. jak3y

    jak3y Guest

    you scare me Chas'....you really do lol...yes those very lines.
    However like i said, i wasn't too sure, without the analyze on the site and the analyze just wouldn't take it...until...i cut those lines out literally from the txt, then resubmitted them and then it worked, then i put back one of those lines to see what it would say and sure enough...take it out.
    I am going to do a clean reinstall today and just protect the computer with everything
    spywareblaster
    spyguard
    (she bought Norton a month ago...so i have to put that in...poor thing, with only 128RAM :eek:)
    ad-aware
    spybot
    winpatrol
    and not sure as to firewall, either, sp2 version
    or im guessing Norton has its own.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have firewall installed and in place before connecting back to the internet. Make sure it is a real firewall. That is, if Win XP SP2, it is not a real firewall that is built in.

    Also, AV and spyware blockers should be in place before connecting to internet.

    Then make sure you get all Windows Updates ASAP.
     
  8. jak3y

    jak3y Guest

    Chas' funny you mentioned that, i was tellin my aunt as i was installing winxp about how you can get infected literally seconds after going online with a fresh install...anyways to make a long story short, i didn't right away, but i got avg running so far so good, no problems.
    However I can't seem to get Ad-Aware update, it says the file can't be read, after 5%...any ideas?
    I got AVG in place now and SpyGuard & Spywareblaster along with Winpatrol watching any start-ups and i think BHO's.
    But the Ad-Aware thing is kinda scaring me here.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some people have been having problems like that with Ad-Aware off and on. Sometimes just retrying at a later time helps.

    Try just doing the update manually by downloading Ad-aware SE referencefile SE1R53 07.07.2005 and just extract the defs.ref file to the C:\Program Files\Lavasoft\Ad-Aware SE Personal folder.

    By the way, did you mean SpywareGuard or are you really installing SpyGuard?
     
  10. jak3y

    jak3y Guest

    ooops ya i meant spywareguide :)
    javacoolsoftware seems to have a lot of nice little proggies goin on...makes me wonder if they dont have spyware lol...
    as for the ad-aware, thanks i did that, manually...i got a little worried b/c after installing winxp (clean reinstall w/formatting)...windows gave me 2 error pop-ups immediately (after registering online) something about registry errors and another one which i forgot...but i ran LexunREgScrub and it took out half of what windows said...so i got a lil' paranoid about the ad-aware update...
    the other error message pop-up is lingering in the back of my mind...tryin to remember what it was...
    ...but i think it was windows' way of trying to sucker me into purchasing this program to fix it...because i went to the suggested reg-fixing site, thinking it was free, but of course it wasn't :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SpywareGuard!!!
     
  12. jak3y

    jak3y Guest

    LMAO...ya that...it was late (well a long day rather), i was tired...
    Chas'...why'd I picture you like this when you typed that-> :mad: lol
    :p
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because that's my picture! :D

    It's just important to always get the names correct. Rogue software capitalizes on using similar names just like malware will name files similarly to try to hide and confuse users.

    For example: svchost.exe is good svdhost.exe and svchostc.exe are bad

    To take it a step further.

    - svchost.exe in c:\windows\system32 is good
    - svchost.exe in c:\windows or anywhere else is bad
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds