Need help with multible Viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by Agahnim, Mar 2, 2005.

  1. Agahnim

    Agahnim Private E-2

    Hey, an online friend accidently sent me a link that was packed with Trojans, HiJackers, Spyware, and Malware (I have no idea how he managed to go there without suffering from the mass infection like I did.:confused: ) and I ran several Spyware and Anti-Virus programs and got rid of over 6 Trojans and HiJackers but I know I still get more because I get this: (**Do not Click on**)slimshield.com/landing.htm?wm=netscreamer&soft=sshield&subacc=002 popping up every 5 minutes. I just need someone who is experience with what is spyware and what is not and how to get rid of it to diagnose the further problems my programs didn't catch.

    Should I post the logfile of what I see now or wait for approval? Before I do post it, I accidently deleted Online Services in the Program files when I was trying to get rid of a program that got damaged by one of the viruses and now I keep getting Windows cannot find Program.exe errors. How do I replace the lost file? Sorry, I emptied the Recycle Bin before I realised the mistake.:eek:
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs. TIP: Create a folder on your C:\ drive for the tools/utilities you will need to use. For example: Navigate to your Program Files directory, right click on a blank spot in the window > choose New > Folder. Name this folder Spyware Tools. Now you can save the needed tools to this folder and if you prefer, create sub-folders named for each individual utility.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an ATTACHMENT.
    All instructions are covered in the sticky thread
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting


    Now post a Hijack This log as an ATTACHMENT to your message (Do NOT copy/paste the log into your post). Please close unnecessary running programs before you run HijackThis. You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc.

    DO NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    To Repeat: Please be sure to reply in this thread if you need further assistance or have any questions. Someone WILL be along to help you as soon as they can. You can help us help you by following the above instructions and providing detailed information as to the difficulties you are having and/or continuing to have after you have completed the Basic Spyware, Trojan And Virus Removal tutorial. Just telling us you followed the tutorial does not give us enough information. You need to let us know the results...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    We all recognize that if you are here asking for help you are probably frustrated and maybe even angry that your computer has been taken over by some malicious program. Rest assured, we want to help you but that we get frustrated too when we are not given the requested information or when instructions are not followed. Don't be afraid to ask for additional help if you don't understand something! There is no such thing as a dumb question and we do not expect everyone who comes here to have vast computer knowledge, however you will be more educated and better prepared to prevent re-infestation when you leave here!:)

    Good luck!:)
     
  3. Agahnim

    Agahnim Private E-2

    LOL!! Interesting auto-reply.

    Yeah, I do need further help with it. I don't want to do anything further on my own without doing something stupid and messing up my computer.

    Here is the logfile.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First:

    Please EXTRACT HijackThis from the ZIP File to a Safer location. Here's how:

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To Extract HijackThis:
    Now, Right Click your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder
    (C:\Program Files\HJT) and click Next.

    Now run HJT from there. Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.


    Second:

    You have not ran all of these steps as there are no signs of you doing the online scans! Please pay close attention and follow forum guidelines closely.

    Please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal



    After you have completed ALL of these steps, attach a NEW HJT log.
     
  5. Agahnim

    Agahnim Private E-2

    Here's the txt file. Tell me what problems I am facing at the moment. The one I am currently physically seeing is this stupid SlimShield ad popping up from my harddrive from time to time. I hope there is nothing there that is an immediate threat that will do major harm to my computer because I just got my computer back from the shop (with the total cost of $300 to get my harddrive replace from it being burnt out.) so my computer runs differently from what I am used to. It's like a new computer.
     
  6. Agahnim

    Agahnim Private E-2

    Can somebody please help me out with this?
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Agahnim, You still have not done the online virus scans. You have MULTIPLE issues and these online scans will help with some of this. Please follow forum guidelines so that we can better assist you. Your log has NO signs of you doing these scans. All we ask if that you follow forum guidelines and pay close attention to our instructions.THIS READ ME IS REQUIRED!

    Before we continue, please follow ALL of the steps mentioned in this sticky thread:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  8. Agahnim

    Agahnim Private E-2

    Hmmm.... I thought I did the scans. The crap must've came back. I am loading in my programs in your list to scan my computer right at this moment but I do want to let you know is that SpyWare Blaster will not work. I keep getting a message when I press on the program's button. The message is attached here. I need to know how to fix that. I am scanning with my other programs so if it is a virus or something that the programs can detect and get rid of, then I can download Spyware Blaster later. The other stuff on your list does not work for me because I have Windows 98.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ, Is not referring to the normal spyware scanners. He is referring to the online scanners given in the READ ME. I'll repeat them here:

    do an online scan at Trend Micro's Free Online Virus Scan
    do an online scan at Symantec Security Check
     
  10. Agahnim

    Agahnim Private E-2

    Oh ok. I got everything scanned in that list and now I am gonna do those Online Scanners right now and post up the log file.

    Normally I would do the steps provided but I am in a state of panic that my computer will be damaged again by a Virus. Whoever creates Viruses needs to go to hell.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already have major problems!

    You have so much bad stuff running you may have a problem doing any scans. Below I give an initial cleanup that may help make your system more useable. There are other problems but we will get to those later.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\MEV.EXE
    C:\WINDOWS\SYSTEM\VIC.EXE
    C:\WINDOWS\PVQ.EXE
    C:\WINDOWS\SYSTEM\RUO.EXE
    C:\WINDOWS\SYSTEM\FQT.EXE
    C:\WINDOWS\SYSTEM\JHP.EXE
    C:\WINDOWS\SYSTEM\KRC.EXE
    C:\WINDOWS\SYSTEM\SND.EXE
    C:\WINDOWS\SYSTEM\GNS.EXE
    C:\WINDOWS\SYSTEM\HBQ.EXE
    C:\WINDOWS\BOO.EXE
    C:\WINDOWS\LLD.EXE
    C:\WINDOWS\SYSTEM\ALJ.EXE
    C:\WINDOWS\FAP.EXE
    C:\WINDOWS\SYSTEM\ILE.EXE
    C:\WINDOWS\SYSTEM\BBE.EXE
    C:\WINDOWS\SYSTEM\VVN.EXE
    C:\WINDOWS\GSH.EXE
    C:\WINDOWS\LCI.EXE
    C:\WINDOWS\SYSTEM\NTU.EXE
    C:\WINDOWS\KCE.EXE
    C:\WINDOWS\SYSTEM\LDP.EXE
    C:\WINDOWS\UUM.EXE
    C:\WINDOWS\MEV.EXE
    C:\WINDOWS\SYSTEM\VIC.EXE
    C:\WINDOWS\PVQ.EXE
    C:\WINDOWS\SYSTEM\RUO.EXE
    C:\WINDOWS\SYSTEM\FQT.EXE
    C:\WINDOWS\SYSTEM\JHP.EXE
    C:\WINDOWS\SYSTEM\KRC.EXE
    C:\WINDOWS\SYSTEM\SND.EXE
    C:\WINDOWS\SYSTEM\GNS.EXE
    C:\WINDOWS\SYSTEM\HBQ.EXE
    C:\WINDOWS\BOO.EXE
    C:\WINDOWS\LLD.EXE
    C:\WINDOWS\SYSTEM\ALJ.EXE
    C:\WINDOWS\FAP.EXE
    C:\WINDOWS\SYSTEM\ILE.EXE
    C:\WINDOWS\SYSTEM\BBE.EXE
    C:\WINDOWS\SYSTEM\VVN.EXE
    C:\WINDOWS\GSH.EXE
    C:\WINDOWS\LCI.EXE
    C:\WINDOWS\SYSTEM\NTU.EXE
    C:\WINDOWS\KCE.EXE
    C:\WINDOWS\SYSTEM\LDP.EXE
    C:\WINDOWS\UUM.EXE

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Die] C:\WINDOWS\Mev.exe
    O4 - HKLM\..\Run: [Ghq] C:\WINDOWS\SYSTEM\Vic.exe
    O4 - HKLM\..\Run: [Agv] C:\WINDOWS\Pvq.exe
    O4 - HKLM\..\Run: [Gha] C:\WINDOWS\SYSTEM\Ruo.exe
    O4 - HKLM\..\Run: [Iko] C:\WINDOWS\SYSTEM\Fqt.exe
    O4 - HKLM\..\Run: [Qkc] C:\WINDOWS\SYSTEM\Jhp.exe
    O4 - HKLM\..\Run: [Tvd] C:\WINDOWS\SYSTEM\Krc.exe
    O4 - HKLM\..\Run: [Gla] C:\WINDOWS\SYSTEM\Snd.exe
    O4 - HKLM\..\Run: [Tqb] C:\WINDOWS\SYSTEM\Gns.exe
    O4 - HKLM\..\Run: [Vnm] C:\WINDOWS\SYSTEM\Hbq.exe
    O4 - HKLM\..\Run: [Ako] C:\WINDOWS\Boo.exe
    O4 - HKLM\..\Run: [Ljg] C:\WINDOWS\Lld.exe
    O4 - HKLM\..\Run: [Fse] C:\WINDOWS\SYSTEM\Alj.exe
    O4 - HKLM\..\Run: [Epq] C:\WINDOWS\Fap.exe
    O4 - HKLM\..\Run: [Sgd] C:\WINDOWS\SYSTEM\Ile.exe
    O4 - HKLM\..\Run: [Hse] C:\WINDOWS\SYSTEM\Bbe.exe
    O4 - HKLM\..\Run: [Ruc] C:\WINDOWS\SYSTEM\Vvn.exe
    O4 - HKLM\..\Run: [Ujc] C:\WINDOWS\Gsh.exe
    O4 - HKLM\..\Run: [Avv] C:\WINDOWS\Lci.exe
    O4 - HKLM\..\Run: [Ccv] C:\WINDOWS\SYSTEM\Ntu.exe
    O4 - HKLM\..\Run: [Iua] C:\WINDOWS\Kce.exe
    O4 - HKLM\..\Run: [Doi] C:\WINDOWS\SYSTEM\Ldp.exe
    O4 - HKLM\..\Run: [Ihg] C:\WINDOWS\Uum.exe
    O4 - HKCU\..\Run: [Die] C:\WINDOWS\Mev.exe
    O4 - HKCU\..\Run: [Ghq] C:\WINDOWS\SYSTEM\Vic.exe
    O4 - HKCU\..\Run: [Agv] C:\WINDOWS\Pvq.exe
    O4 - HKCU\..\Run: [Gha] C:\WINDOWS\SYSTEM\Ruo.exe
    O4 - HKCU\..\Run: [Iko] C:\WINDOWS\SYSTEM\Fqt.exe
    O4 - HKCU\..\Run: [Qkc] C:\WINDOWS\SYSTEM\Jhp.exe
    O4 - HKCU\..\Run: [Tvd] C:\WINDOWS\SYSTEM\Krc.exe
    O4 - HKCU\..\Run: [Gla] C:\WINDOWS\SYSTEM\Snd.exe
    O4 - HKCU\..\Run: [Tqb] C:\WINDOWS\SYSTEM\Gns.exe
    O4 - HKCU\..\Run: [Vnm] C:\WINDOWS\SYSTEM\Hbq.exe
    O4 - HKCU\..\Run: [Ako] C:\WINDOWS\Boo.exe
    O4 - HKCU\..\Run: [Ljg] C:\WINDOWS\Lld.exe
    O4 - HKCU\..\Run: [Fse] C:\WINDOWS\SYSTEM\Alj.exe
    O4 - HKCU\..\Run: [Epq] C:\WINDOWS\Fap.exe
    O4 - HKCU\..\Run: [Sgd] C:\WINDOWS\SYSTEM\Ile.exe
    O4 - HKCU\..\Run: [Hse] C:\WINDOWS\SYSTEM\Bbe.exe
    O4 - HKCU\..\Run: [Ruc] C:\WINDOWS\SYSTEM\Vvn.exe
    O4 - HKCU\..\Run: [Ujc] C:\WINDOWS\Gsh.exe
    O4 - HKCU\..\Run: [Avv] C:\WINDOWS\Lci.exe
    O4 - HKCU\..\Run: [Ccv] C:\WINDOWS\SYSTEM\Ntu.exe
    O4 - HKCU\..\Run: [Iua] C:\WINDOWS\Kce.exe
    O4 - HKCU\..\Run: [Doi] C:\WINDOWS\SYSTEM\Ldp.exe
    O4 - HKCU\..\Run: [Ihg] C:\WINDOWS\Uum.exe
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.skoobidoo.com
    O15 - Trusted Zone: *.slotchbar.com
    O15 - Trusted Zone: *.windupdates.com (HKLM)
    O15 - Trusted Zone: *.skoobidoo.com (HKLM)
    O15 - Trusted Zone: *.slotchbar.com (HKLM)
    O15 - Trusted IP range: 67.19.185.246

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\MEV.EXE
    C:\WINDOWS\SYSTEM\VIC.EXE
    C:\WINDOWS\PVQ.EXE
    C:\WINDOWS\SYSTEM\RUO.EXE
    C:\WINDOWS\SYSTEM\FQT.EXE
    C:\WINDOWS\SYSTEM\JHP.EXE
    C:\WINDOWS\SYSTEM\KRC.EXE
    C:\WINDOWS\SYSTEM\SND.EXE
    C:\WINDOWS\SYSTEM\GNS.EXE
    C:\WINDOWS\SYSTEM\HBQ.EXE
    C:\WINDOWS\BOO.EXE
    C:\WINDOWS\LLD.EXE
    C:\WINDOWS\SYSTEM\ALJ.EXE
    C:\WINDOWS\FAP.EXE
    C:\WINDOWS\SYSTEM\ILE.EXE
    C:\WINDOWS\SYSTEM\BBE.EXE
    C:\WINDOWS\SYSTEM\VVN.EXE
    C:\WINDOWS\GSH.EXE
    C:\WINDOWS\LCI.EXE
    C:\WINDOWS\SYSTEM\NTU.EXE
    C:\WINDOWS\KCE.EXE
    C:\WINDOWS\SYSTEM\LDP.EXE
    C:\WINDOWS\UUM.EXE
    C:\WINDOWS\MEV.EXE
    C:\WINDOWS\SYSTEM\VIC.EXE
    C:\WINDOWS\PVQ.EXE
    C:\WINDOWS\SYSTEM\RUO.EXE
    C:\WINDOWS\SYSTEM\FQT.EXE
    C:\WINDOWS\SYSTEM\JHP.EXE
    C:\WINDOWS\SYSTEM\KRC.EXE
    C:\WINDOWS\SYSTEM\SND.EXE
    C:\WINDOWS\SYSTEM\GNS.EXE
    C:\WINDOWS\SYSTEM\HBQ.EXE
    C:\WINDOWS\BOO.EXE
    C:\WINDOWS\LLD.EXE
    C:\WINDOWS\SYSTEM\ALJ.EXE
    C:\WINDOWS\FAP.EXE
    C:\WINDOWS\SYSTEM\ILE.EXE
    C:\WINDOWS\SYSTEM\BBE.EXE
    C:\WINDOWS\SYSTEM\VVN.EXE
    C:\WINDOWS\GSH.EXE
    C:\WINDOWS\LCI.EXE
    C:\WINDOWS\SYSTEM\NTU.EXE
    C:\WINDOWS\KCE.EXE
    C:\WINDOWS\SYSTEM\LDP.EXE
    C:\WINDOWS\UUM.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now: Empty your recycle bin

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. Agahnim

    Agahnim Private E-2

    I just got rid of those now. I am doing the Online Scans now to see if it will catch any more stuff.

    TrendScan or whatever it is called is not working for me.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do all the steps I just gave to you? Kill the processes, fix the lines with HJT, boot to safe mode, delete the files. Reboot. I don't think you could do it that fast.
     
  14. Agahnim

    Agahnim Private E-2

    Ok, I followed your guide and also did Safe Mode to. Some of the bad programs did put up a fight to but I managed to get rid of them except this piece of dog turd: O15 - Trusted IP range: 67.19.185.246 I looked up to see what that was on Google and saw that it was a link to a porn pop-up ad. My online-friend who is not to computer smart had said he had found a funny image and gave me the link. Without thinking, I clicked on it since he usually sends links to photobucket pictures of comic strips and stuff, but this time it was a link to a Girl's Gone Wild pop-up ad picture and just as it loaded, AVG and Norton went crazy saying that my computer was being overrun by Trojans and Spyware. I told my friend several times NEVER to visit any porn sites (Besides containing disgusting content) they contain nothing but bad Viruses and stuff. *Sighs*

    O15 - Trusted IP range: 67.19.185.246 will not go away on my HJT scan. I fix it with the scan and scan again and it is back. Here is my log file.

     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HJT logs need to be run in normal boot mode unless otherwise indicated.

    Please provide a current log from normal boot mode.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also please disable Spybot's Teatimer. It could get in the way of the cleanup.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!
     
  17. Agahnim

    Agahnim Private E-2

    Now corrected:
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can fix the O15 line first:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    Now run HJT and fix the the O15 - Trusted IP range: 67.19.185.246 line
    if you still see it. Is it gone now? Check another HJT scan.
     
  19. Agahnim

    Agahnim Private E-2

    I followed your exact steps with the move.reg and others but the little bastard still won't die.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you go to C:\WINDOWS\TEMP (using Windows Explorer) can you see the se.dll file right now.
    Sort files by Creation date. What other files have the same data as se.dll?

    Also go to C:\WINDOWS\SYSTEM . Do you see PIDP.DLL?
    Sort files by Creation date. What other files have the same data as PIDP.DLL?

    Why are you loading HJT at startup?
     
  21. Agahnim

    Agahnim Private E-2

    Oh, for the start-up thing, I just clicked on the option "Load at Start-Up" and didn't turn it off yet.

    I don't see any dll files even though I did follow your steps and turned the hidden feature off. No se.dll or Pidp.dll

    I even searched on Find in my Start but it comes up with nothing.
     
  22. Agahnim

    Agahnim Private E-2

    I don't see any dll files even though I did follow your steps and turned the hidden feature off. No se.dll or Pidp.dll

    I even searched on Find in my Start but it comes up with nothing.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached ZIP file and extract the getWfiles.bat file from it to C:\

    Then double click on the .bat file. It will create a file named c:\wfile-list.txt
    Put this new file into a ZIP file (hope you know how to do that) and upload it back here as an attachment.
     

    Attached Files:

  24. Agahnim

    Agahnim Private E-2

    I had forgotten how to use ZipItFast Pro since I haven't used it in a very long time. Can you link me to a tutorial? Also attached is something I want to know whether it is something that is supposed to be there or not. It's circled in red.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Never used ZipItFast. I use WinZip. I just right click the file and select Add to Zip. If ZipItFast cannot do that, it is not fast. ;)

    Not sure about that file. But it looks to me like you are not showing file extensions as you are supposed to be.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After getting that file attached here for me. Do the following:

    Download: "StartDreck", from here:
    http://www.niksoft.at/_data/startdreck.zip

    Unzip to its own folder and start the program,
    Press 'Config'
    Press 'Unmark All'
    Check the following boxes only:
    Registry -> Run Keys
    System/drivers> Running processes
    Press 'Ok'
    Press 'Save' and select the location to save the log file
    (default is the same folder as the application)

    Please attach the log in this thread.
     
  27. Agahnim

    Agahnim Private E-2

    I'm back. I couldn't stay up any longer. I was on the verge of falling asleep at the desk. Anyways, I just got back on and noticed AVG catching this Virus everytime I clicked on IE: Startpage.16.M SE.DLL and my homepage has changed into something else and pop-up ads appear. It wasn't like this yesterday. Everytime I moved to the Vault or Deleted the Virus, it comes back. I hate the Advertisement industry.:mad:

    Here is what I am seeing.

    Now I am going to do the Zip thing right now but I can't do it with Winzip because I don't have $40 to blow away on a stupid program I would rarely ever use.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still need you to complete what I requested in messages # 23 & # 26.

    I know all about what AVG finds! Symantec finds the file too. Neither of them fix it.
     
  29. Agahnim

    Agahnim Private E-2

    Also, I can't post the Zip of the list thing you wanted me to save here. It says it is too large.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How large is the ZIP file in bytes. Perhaps we can take the original text file and split it into two pieces and make two ZIP files.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Winzip is only $29 and has a 30 day free trial. It is far from a stupid program. It is an industry standard that Everyone uses. Notice how most downloads are ZIP'ed
     
  32. Agahnim

    Agahnim Private E-2

    The file is 250.6 KB

    My AIM, My Computer, and my other programs are infected with this gay virus.
     
  33. Agahnim

    Agahnim Private E-2

    I'll split the file in half and Zip it that way.
     
  34. Agahnim

    Agahnim Private E-2

    Holy crap that is a big file. I guess it is thanks to my high graphics games that I have on my computer.


    Here is part 1 and 2 of the zip. I still got more to go.
     
  35. Agahnim

    Agahnim Private E-2

    Here are the final parts.
     
  36. Agahnim

    Agahnim Private E-2

    And the very last piece:
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Now run what I gave you in message #26 (the StartDreck program)
     
  38. Agahnim

    Agahnim Private E-2

    Here it is.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter command and click OK.
    The type the following commands each followed by the enter key:
    cd C:\WINDOWS
    attrib -s -h -r RECOVMR.TXT
    copy RECOVMR.TXT c:\Badfile.txt


    Leave the command prompt window open and now upload as an attachment, the c:\Badfile.txt file we just created.

    Also, post a new HJT log
     
  40. Agahnim

    Agahnim Private E-2

    I followed what you told me in the bold section I created here. I posted what I see in the window. I tried entering cd C:\\WINDOWS but it comes up saying it is an Invalid extention. Sorry, I am kinda slow on this since I never done this before.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My directions do not show C:\\WINDOWS
    They say: C:\WINDOWS
     
  42. Agahnim

    Agahnim Private E-2

    Oh! Now I see. The \ next to the W made it look like \W = \\

    I have bad eyes.

    I did what you said and it kinda worked except for this. What does it mean?
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some process is using it right now. Post a current HJT log. Do not make any changes youself. Also please do not install any more programs on this PC unless I request it. I see some new stuff (like BDonlineScan) that was just installed.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way there are still some bad files I asked you to delete much earlier present.
    You must delete:

    C:\Windows\BOO.EXE
    C:\Windows\FAP.EXE
    C:\Windows\FIM.EXE
    C:\Windows\GSH.EXE
    C:\Windows\KCE.EXE
    C:\Windows\LCI.EXE
    C:\Windows\LLD.EXE
     
  45. Agahnim

    Agahnim Private E-2

    BDonlineScan? I didn't install that. I haven't been installing anything except for what you been telling me to install. I haven't even installed my new Sims game yet and will not until I get everything installed.
     
  46. Agahnim

    Agahnim Private E-2

    Here ya go.
    I do see the se.dll stuff there this time but I didn't see

    C:\Windows\BOO.EXE
    C:\Windows\FAP.EXE
    C:\Windows\FIM.EXE
    C:\Windows\GSH.EXE
    C:\Windows\KCE.EXE
    C:\Windows\LCI.EXE
    C:\Windows\LLD.EXE

    in the hjt scan.
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BDonlinescan is Bit Defender and according to the text files you had to split apart it was installed on your PC on 03/04/2005 at 1:26 AM . Hmmmm! Is your computer's date set incorrectly too?
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in the text file you sent to me (the original before you split it apart). It shows the files on your PC. Load it into wordpad an search for those and you will see what I mean.
     
  49. Agahnim

    Agahnim Private E-2

    I'm from the future.

    Nah, my time keeps changing for some reason.

    Here is the file again just incase you missed it since I was editing the message to post it up after forgetting to do so.
     
  50. Agahnim

    Agahnim Private E-2

    I believe you. I just thought I got rid of them on hjt and they weren't showing up on hjt. I'll try to search on Find like I did to the others and get rid of them.

    *They are now dead*
     
    Last edited: Mar 3, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds