o god im having probs with some viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by turkishsniper360, Nov 20, 2005.

  1. turkishsniper360

    turkishsniper360 Private E-2

    hi im new here and hopefully u guys wiilll help me.
    im having probs removing trojans and viruses here is a hyjack this report Logfile of HijackThis v1.97.7
    Scan saved at 10:50:37 AM, on 11/20/2005
    Platform: Windows 2000 SP3 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Edit by chaslang: Cleaning steps not followed, OLD HijackThis version, inline log removed
     
    Last edited by a moderator: Nov 20, 2005
  2. turkishsniper360

    turkishsniper360 Private E-2

    sry!!

    sry i didnt add hyjack this as an attachment all my apologies!!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    Please follow the steps below:

    - Look in Add/Remove programs for anything labeled WebHancer and uninstall if found.

    - download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover

    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet. We will run it later.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support


    Make sure you check version numbers and get all updates.

    - Now while still in safe mode, run the abiremover.exe but make sure you are physically disconnected from the internet (unplug your cable to be sure). Just click install, wait (explorer window will disapear)

    - When abiremover finishes just reboot into normal and continue with the below steps.


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.



    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note some additional problems which are part of the reason you are so badly infected:

    - Your Windows OS has not been updated to the current revision level. Missing many updates.
    - No Antivirus application
    - No firewall

    We will address all of this later after malware has been removed and you have a lot of malware.
     
  5. turkishsniper360

    turkishsniper360 Private E-2

    how do u get on to system restore on win2k it wont tell me how and niether will major attitudes post... and for some reaason and and remove programs will not apear and doesnt work... id reeaaly apreciate ur help
     
  6. turkishsniper360

    turkishsniper360 Private E-2

    my windows installer doesnt seem to be working because it wont load and keeps sayng its either because of safe mode or i have to reinstall it.. but its not becuz of safe mode becuz i booted normally and tried
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME clearly states

     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you the Administrator and are you logged on with administrator priviledges? If not, you will not be able to install anything.
     
  9. turkishsniper360

    turkishsniper360 Private E-2

    yes i am logged on as the administrater and windows installer wont work and i cannot get to add/remove programs!!!! i just need a way to get rid of this malware i have a lot of it like u said. thank u for the help by the way
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the steps that do not require any installation. You may be able to run ABIremover, definitely you can run hoster, and you can work up to & including step 5 of the READ & RUN ME. Try to run two of the online scanners. After that skip to step 7 and follow those steps exactly.
     
  11. turkishsniper360

    turkishsniper360 Private E-2

    spybot is not letting me update, it says connection error # 10054 connection reset by peer. any ideas? Bye the way i have 2 attachments 1 is a avast log and the other is adaware log
     

    Attached Files:

  12. turkishsniper360

    turkishsniper360 Private E-2

    ABLremover justmakes my desktp go away for like 5 minutes and nothing happens or does something happen?
     
  13. turkishsniper360

    turkishsniper360 Private E-2

    uu could i chat with u on something chaslang like aim or irc or something?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One of your many problems is a Look2Me infection and you will have to run this: Running Spy Sweeper...

    Let's try to complete one thing at a time. Run the above and post the spysweeper.txt file log as an attachment to your next message. Don't do anything else but this.

    I'll be out for a few hours and will log back in later to see how this worked.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It is shutting down your Desktop so it can fix problems in the background. They cannot be fixed with explorer.exe running which is what displays you Desktop.
     
  16. turkishsniper360

    turkishsniper360 Private E-2

    i cant download spy sweeper becuz i already had a trial version a long time ago so it wont let me, everytime i download it, it says its expired so im gonna go download this thing called malware remover and try kill2 me and see if i can download it.. k gimme some time ill see what i can show u
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me exactly what it is (exact name and where you are getting it from) that you plan on downloading. There are a lot of bad rogue tools out there that do more harm than good.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also many programs out there will just detect stuff (sometime falsely) and then you must buy it to remove what they find. If you want to but something, buy Spy Sweeper. It is one of best available.
     
  19. turkishsniper360

    turkishsniper360 Private E-2

    kill2me says it removed the look2me virus or whatever it is ( i got kill 2 me from 1 of your downloads)
     
  20. turkishsniper360

    turkishsniper360 Private E-2

    also i have this thing called psguard that i keep scanning and removing but ad-aware keeps scanning and saying its still on my comp
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me the exact program you are referring to. Using non-exact incomplete names does not help us.
    If it was just Kill2me, it will not fix the Look 2 Me forms that exist.
    If it was Look2Me Remover it may have worked.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you completed running all of READ & RUN ME FIRST Before Asking for Support

    If not please do so. And in step 6 make sure you click Special Removal Procedures which covers Smitfraud and PSGuard
     
  23. turkishsniper360

    turkishsniper360 Private E-2

    i folowed most but i cannot folow some becuz of my windowa installers inability to work and run lol. i tried kill2me and it removed the look2me becuase i tried look 2 me remover and it didnt detet anything but a registry key that i deleted right away i have to reboot now so gimme a sec ( i downloaded the psgaurd remover thing)
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please be more specific with your answers. What is "most"?

    Deleting a registry is deleting something!!! I repeat. Kill2Me will NOT fix the latest forms of Look 2 ME.

    Attach a new HJT log.
     
  25. turkishsniper360

    turkishsniper360 Private E-2

    i mean i followed mot like 1-5 and 6 i used the special tools for psgaurd and i have the vundo trojan so im using the tool for thhat and i cant get to every online scanner. i have used the psguard remoover thing from the special tools but now i am running disc cleanup witch may take a while gimme a while cuz it says it can take up to an hour.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot do all of step 6 if you cannot install software.

    CCleaner is what you should be running. It is much more efficient then disc cleanup. But if you cannot install it then you cannot use it.

    Please go to the below link and download and install the latest MS installer.

    Windows Installer 3.1 Redistributable (v2)

    Let me know if that fixes the install problems.
     
  27. turkishsniper360

    turkishsniper360 Private E-2

    heres a hjt and please tell me which ones to check
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First do what I gave you in message number 26.

    Also more important, you did not follow my instructions from message # 3. I repeat

     
    Last edited: Nov 23, 2005
  29. turkishsniper360

    turkishsniper360 Private E-2

    i cant download it because i keep getting a error whenever i try to get thevalidation code i tyed several times
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the exact error message?

    Complete the rest of what I gave you in message # 28.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds