poopoo time for me

Discussion in 'Malware Help (A Specialist Will Reply)' started by idratherbecleaningthebike, Feb 13, 2007.

  1. dear geeks

    please highlight what infection I need to remove from my scan files posted.
    i'm on the edge of self harm or harming something at least. Isn't it easier to jump to this point rather than spend hours and hours trawling through remedies I ask.
    my copy of unactivated Counterspy has just run as I connected to the net and removed something from 'tribalfusion'. Of course the 'activescan' [from Panda] came first then the 'highjackthis' file after.
    This infection probably happened due to my not being able to easily reload a previous Symantec subscription onto a reformatted harddrive. I'm currently running an updated copy of AVG.

    Tres mercies and thankx for any help.
    Mr Biker
     

    Attached Files:

  2. Dear Geeks

    How does your queueing system work?
    This certainly doesn't work for me. Is my problem too hard?
    Thanks anyway
    Bye
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. Hi
    Yes I have done all of the checks and hunting etc. before I did the hijackthis program. In fact I followed everything to the exact letter. About 8 hours on the machine last night doing it. The only marginal problem I encountered was with Counterspy. I did found the downloading of the program a little confusing as it only seemed to allow me use of the program if I payed up front, and, until I used it, wasn't sure whether it would work, but it did, although it was quite laboriously slow looking through files.
    Thanks for the reply
    Mr Biker
     
  5. Sorry, yawn.

    The files I did find were:-

    Spybot: 35 X ms win. redirected hosts; 1 X ms win. sec. centre firewall override; 1 X ms win. sec. centre - disabled, 1 X Smitfraud_c. All fixed
    Pandascan: will post later.
    Counterspy (this only worked in normal mode, RACM failed in safemode): 1 X trojan.killreg[c:\windows\autoclk.exe; 1 X virtual-IE.msmovies Adware [general] - 2 objects: c:\windows\system32\netstat.com and system32\taskkill.com. I think were all fixed
    Bitedefender: couldn't connect to the net.

    A previous AVG scan revealed 7 threats: 2 trojans - trojan H PSW. Generic 3Eko; and 5 hosts virus c:\windows\system32\drivers\etc\1.hosts .. 2.hosts ..3.hosts .. hosts.
    It deleted the trojans but not the hosts.Trojans were found through a users hotmail address, path docs & sttgs\user\local settings\temp. int. files\content.IES\SDEJS52Z\ also path c:\windows\system32idoelp\

    Many thanks for any help
    Mr Biker
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We can't do much to help you without the logs that were requested.
    Please attach the logs for:
    ShowNew
    GetRun
    Counterspy
     
  7. Hi.
    Back on THE machine now so here are the files requested.
    Thanks
     

    Attached Files:

  8. Hi
    And yet some more using Trojan Remover 6.5.6 (30 day free trial).
    Thanks
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey - please download the current version first!
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  10. Hi there
    I have copped out and paid to have it fixed.
    I think our time difference and the fact I'm at work in normal hours means fixing the home PC has made the process very slow and stressful - family pressures!
    If I can help with any info I'm happy to help. Hopefully it was a challenging educational experience. I'm sticking with AVG AV protection now. Putting Norton Security (I keep slipping and calling it Norton Insecurity) was tricky for me, I had had the PC upgraded and when I got it back it had AVG on it, as I had previously re-subscribed by download (until May 2007, will I get a refund?) and having used my first product (disk) from 2003, putting that on hoping to then update it. Which didn't work and URL updates didn't work, all other updates did, which is I think what let viruses in. It wasn't till later via the Sysmantec site that I had to go to through their subscription process to get it back on. Nothing like having something 3 dimensional like the product in disk form to do the job. Ah well now the kids are older I don't need kid protection, it was always a battle to stop them working around it as well (older son is studying for a Computor Science degree at London Imperial), I know damn all about programming. The worst thing was how slow Norton Security made the machine.

    Many thanks for the help
    Mr Biker
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds