sysconfig util/obj stupid found in startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by bratwhoknows, Apr 17, 2005.

  1. bratwhoknows

    bratwhoknows Private E-2

    i found when i was cleaning my system of spy/adware that there was a new file i have not seen and cannot find. under the sys config i found it to be located C:\docs & sets\all users\app data\face noun wave date\obj stupid.exe and in my registry wavedatejugsbarb. that's just the part showing up in my startup. i hunted down this folder "face noun wave date" and found several other .exe files... bin axis, cdrom1, keepinternet, platform nurb, build cash, copywave, and sectvc. i have removed all from my system, but i was wondering if ANYONE has any idea where it came from. i can't seem to find any information about it and none of my spy/adware progs found it.

    feel free to email me. bratwhoknows@hotmail.com
     
  2. bratwhoknows

    bratwhoknows Private E-2

    also, when i tried to remove it, it told me i couldn't. "cannot delete boob ooze log. it is being used by another person or program. close any programs that might be using the file and try again."
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the procedures below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. bratwhoknows

    bratwhoknows Private E-2

    ok. i think i'm in more than i thought. the last thing i want to know, before i download hijack this, can i delete the folder SYSTEM VOLUME INFORMATION? when i ran trend micro it found several trojans in amongst the files. it's a folder i have never seen before. i assume the whole thing is badness.
     
  5. bratwhoknows

    bratwhoknows Private E-2

    i retract my last note
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. bratwhoknows

    bratwhoknows Private E-2

    well, actually...i had a bunch of problems getting/running all the stuff you asked for. i just finished all of it and i'm still not sure what to do about the stuff in the system vol folder. i know it's a restore folder now (mind you i haven't worked on a computer since 2000 and i hadn't ever worked on xp). everything else seems to be clean. the only sticky one is reyhim and (crossing fingers) i hope it won't be back when i reboot. my question is: those files in sys vol info - are those backups and inactive or are they still f***ing around on my computer?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you disable System Restore? Step one in the READ ME FIRST!
     
  9. bratwhoknows

    bratwhoknows Private E-2

    i just checked and i know FOR A FACT i disabled it last night. i think my girlfriend has been trying to be "helpful." i'm starting over. you'll hear from me tomorrow. thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does that mean that it is not disable right now?
     
  11. bratwhoknows

    bratwhoknows Private E-2

    yes. that means it's not disabled right now. i'm starting over.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let us know when you finish. Make sure after you disable it that it actually disables. We have seen cases where it does not disable even though you try to disable it.
     
  13. bratwhoknows

    bratwhoknows Private E-2

    i think i have finally gotten everything cleaned up. my last battle was aurora and it was a tough one. i still can't get system restore to remain disabled and i even had one of my friends who's geekier than i here and he couldn't either. don't know what's up with it, but if i have any other problems, i will be back. THANK YOU!!!!!!!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you complete all the steps in message # 3 (the READ ME and then the HJT log) perhaps we can find your problem with System Restore.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds