Please help me get rid of this virus!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by nyczmic, Sep 5, 2006.

  1. nyczmic

    nyczmic Private E-2

    My ZoneAlarm detected a Trojan called Win32.Softomate and it successfully deletes it but when i scan again the next day, the virus has somehow recreated itself and is detected by my ZoneAlarm again. I've already delted this Trojan 3 times, can anyone help me get rid of this virus permanently?

    thanks
    -Mike
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • CounterSpy - ONLY IF you were not able to run Windows Defender
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • HijackThis
     
  3. nyczmic

    nyczmic Private E-2

    alright..i followed the directions. The virus wasn't picked up by any of the scanners but i'm hoping that you could help me solve it's recreation every next day. I've attached the necessary logs below. Thanks!

    -Mike
     

    Attached Files:

  4. nyczmic

    nyczmic Private E-2

    Here's the other two attached logs.
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    << The installed version of Java on this compter is out-dated. Install Java Runtime Environment (JRE) 5.0 Update 8 available from http://java.sun.com/javase/downloads/index.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Uninstall the Logitech Desktop Messenger

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop.
    Close Notepad.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Reboot

    Post a fresh HijackThis log
     
  6. nyczmic

    nyczmic Private E-2

    thanks...heres the fresh HJT log
     

    Attached Files:

  7. nyczmic

    nyczmic Private E-2

    i've just run ZoneAlarm again, and the Win32.Softomate doesn't appear anymore but another virus keeps appearing called Year 1992/2 in C:\System Volume Information\_restore{CDA31C14-C93B-4B6A-9386-C6BB2B1F613}\RP137\A0011931.dll
    Its the second time its come up after i deleted it the first time. I dont understand how this virus is in my system after cleaning my computer just yesterday for the Win32.Softomate

    I'd really appreciate your help to clean out this virus.

    thanks
    -Mike
     
  8. nyczmic

    nyczmic Private E-2

    deleted the same virus again with ZoneAlarm..i'll reply back if the same virus is caught again after another scan. please check my HJT log posted above the message above this one. thanks..i really appreciate your help
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds