malware which i cant remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pearse99, Oct 5, 2006.

  1. Pearse99

    Pearse99 Private E-2

    Hi there,
    When the comp boots up i get a window saying
    "You (or a program) have requested information from tracker3.transamrit.net. Do you want to connect to the internet?" or something like that with the option of clicking underneath to connect. If i dont click 'dont ask me til next time i log in' the window will open every 30 secs or so when it is shut. I used AVG and it didnt find any viruses. I then used Spybot and it crashed - it found a bearshare prob but before finishing made a list of errors:
    C2.lop Access violation in kernel32.dll, Gain.gator Access violation in kernel32.dll
    etc. Before finishing the scan the computer crashes and i get the blue screen.
    One of the errors was: Stop: 0x0000008E (
    At this stage i tried various internet fixes but eventually looked at majorgeeks. I have tried to follow ur instructions as much as possible: After emptying recycle bin etc and rebooting in safe mode i ran ccleaner. Then i ran Microsoft Windows Malicious Software Removal Tool. It found stuff but crashed. I then rebooted and ran spybot. It also crashed with the same access violation errors as above. I cant run windows defender as my xp disk is second hand. I ran counterspy and it also crashed. Next i tried running to check registry only and it crashed. I installed jre. I ran bitdefender and kept the log. Ur system wont allow me to attach it as it is too big. I ran pandascan and kept report. I did the getrunkey and shownewbat stuff. I did the hijackthis and kept the report.
    I have sent three attachments can send the rest in further post if and when requested. Let me know what other inf u need.
    regards
    Pearse
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I don't think we are going to find that malware is the cause of all your problems. Sounds like you have other issues in your OS. But let's work thru a few things.

    You did not do the correct Bitdefender scan. You downloaded and installed a trial version of Bitdefender V8 which is a full antivirus program. This is in conflict with what we stated in step 3 of the READ ME. You now have AVG and Bitdefender installed. You can probably attach the log if you compress it into a ZIP file to reduce the size. Either way uninstall Bitdefender now!

    Also uninstall the below:
    BearShare <--- comes bundled with malware
    J2SE Runtime Environment 5.0 Update 5
    Java 2 SDK, SE v1.4.2


    Make sure viewing of hidden files is enabled (per the tutorial).

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\MyWay <--- the whole folder
    C:\WINDOWS\kmttgdip.dl$
    C:\WINDOWS\uyxixbjg.dll

    Now run Ccleaner (installed while running the READ ME FIRST).

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\USER\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  3. Pearse99

    Pearse99 Private E-2

    I have uninstalled Bitdefender. Am not sure what version u need but couldn't find it. Followed the rest of instructions i think ok. Have uploaded the files: newfiles and hijackthis. Also have uploaded the bitdefender log as zip file from previous scan. On reboot the system is behaving the same as before as far as i can tell.
    regards
    Pearse
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Its the online scanner exactly as stated in the READ ME.

    You did not upload anything!
     
  5. Pearse99

    Pearse99 Private E-2

    attachments this time

    Hi there,
    Sorry bout that. Hopefully this time i managed to attach items correctly. The bdscan is from the original scan. Also managed to find BitDefender online scan - ran it and it crashed giving me a blue screen with the error:0x00000024 (... Computer behaving same as before
    regards
    Pearse
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: attachments this time

    Your Bitdefender log is not useful! All you scan was your C:\WINDOWS\System32 folder and not your whole hard disk like the online scan would do. In addition the scan found no problems.

    You must run HijackThis in Normal Boot mode as requested in the sticky. Safe mode logs will not reveal everything. However it is still looking to me like you may be in the wrong forum. Thus far you have no major malware issues. Only a few minor things have been seen.
     
  7. Pearse99

    Pearse99 Private E-2

    hijackthis

    Hi there,
    here's the hijackthis log in normal boot mode. Maybe its good that not much has been detected. However something has changed as now spybot will always crash the machine and it also crashes regularly when it is simply switched on and i am not at the keyboard.
    regards
    Pearse
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: hijackthis

    You have no signs of malware! You more than likely have some kind of corruption in your file system or some hard disk error or some other kind of non-malware problems. You OS is way out of date too and you need to get updated ASAP but DO not try to update while your system is not operation smoothly. You may want to put a message in the Software Forum explaining in detail any CURRENT problems you are having and include any error message (word for word).
     
  9. Pearse99

    Pearse99 Private E-2

    Hi there,
    thanks for help. when u say OS is out of date i guess u mean bcos i haven't got updates for my xp system. actually buying it is out of question at moment so will have to wait. do i need to close this thread (how?) or can i simply jump to 'software forum'?
    regards
    Pearse
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just start a new thread in the Software Forum!

    If you continue to operate with the old OS (yes Windows XP is your OS) you will constantly have malware problems. If you don't have a valid license you need to get one!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds