please can someone help me???????

Discussion in 'Malware Help (A Specialist Will Reply)' started by lorilu, May 17, 2005.

  1. lorilu

    lorilu Private E-2

    VBS/Lefarsi.A

    This is the virus I have and I downloaded all that stuff you guys said to nothing helped I also did a system thing I downloaded from trend housecall . I am scared to email people and sometimes when I reboot a screen comes on and tells me I have no operating system . Also all my ghames disappeared and my burner only works when it wants ( I was trying to save all I could in case of crash and the burner just started to pretend it was burning when I checked the discs were empty) sometimes on reboot i let it do the scandisc and it takes up to 8 hours and finds all kinds of bad clusters . I think I need HELP BIG TIME:eek:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. lorilu

    lorilu Private E-2

    I done it like you said
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First open Control Panel and run Add/Remove programs. Look for the below and uninstall if found:
    WinTools
    MyWebSearch (or similar)

    Let me know if you find them and they uninstall.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Missed one! Also uninstall: WeatherBug
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess I did not catch you before you logged off. So I just give you somethings to fix anyway. Some may have been fixed by the uninstall already.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Common Files\WinTools\WToolsS.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
    O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm867YYUS
    O9 - Extra button: (no name) - {44EFB53C-C965-43CF-9F45-52242D134187} - (no file)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/SmileyCentralFWBInitialSetup1.0.0.8-2.cab
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14389f89e6af9c587000/netzip/RdxIE601.cab
    O16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9F314A918228} - http://ak.imgfarm.com/images/nocache/myspeedbar/myinitialsetup1.0.0.7.cab
    O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Common Files\WinTools <--- the whole folder
    C:\Program Files\MyWebSearch <--- the whole folder
    C:\Program Files\AWS <--- the whole folder

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. lorilu

    lorilu Private E-2

    ok I done that but the original infected file is still on the PC and will not let me delete it ....will it still be ok ?
    I did everything else you told me to do ...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the original infected file name and where is it located? Which program finds it?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see Weatherbug and the Wintools service. Did you fix these in my last steps?
     
  10. lorilu

    lorilu Private E-2

    irus:VBS/Lefarsi.A No disinfected C:\Documents and Settings\ours\My Documents\Downloads\New ETOMI PRO DOWNLOADS (2)\Free Business Forms, Business Letters, Business Contracts, Legal Forms, Legal Letters, Worksheets, Templates, Checklists, Downloads, Agreements, Financial Forms, Applications,

    that is the copy from PAnda and McAfee found it there and so did house call the only one that never found it there was the stinger one

    I have also downloaded the system cleaner from house call and that never got it
    I am running a Panda scan now to see if it still picks it up

    I deleted the things you said I killed the folders and ran the CCshredder
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just boot to safe mode and delete the folder:
    C:\Documents and Settings\ours\My Documents\Downloads\New ETOMI PRO DOWNLOADS (2)

    Here are some other steps to do:


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to WinTools for IE service (or if you do not find that, look for WinToolsSvc) ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":
    WinTools for IE service
    Or if that does not work, try the short service name: WinToolsSvc
    Is the O23 line gone now.

    Have HJT fix the below lines with no browsers opened (the O23 line may already be gone due to the above steps)
    O9 - Extra button: (no name) - {44EFB53C-C965-43CF-9F45-52242D134187} - (no file)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
     
  12. lorilu

    lorilu Private E-2

    Ok I did that other stuff deleting the file and stuff here is the new hijack this log
     

    Attached Files:

  13. lorilu

    lorilu Private E-2

    this is the new log sorry ....
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. lorilu

    lorilu Private E-2

    Thank you so much !!!!


    you guys are great

    I was so worried the panda scan came back clean except for adware But the main thing is no virus's

    you are awesome:D :D
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds