Syslem.exe malware spyfalcon HELP PLZ

Discussion in 'Malware Help (A Specialist Will Reply)' started by StOoGiEmEiStEr, Jun 28, 2007.

  1. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    how do i fix this malware cause ive tried everything in the past 2 months and yet i still fail.. it mainly spam crashs and emails and network stuffand it also spam runs closes and reopens programs till my 3.5gig pf usage is full all that while im on 100% cpu usage while idleing on a 5000+ dual amd.. this is bullshizle cause i cant do anything to fix it i cant even play games or watch movies, and no antispy or malware program in the world can remove this program. anyone recommend a proper hd nuking program and/or mobo firmware malware searcher. cause i have nfi how to fix it thx! or even if someone tells me how to remove this malware that would be great thx cause i currently cant do anything on my 2 grand comp.. thx
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you really have a SpyFalcon infection, the below should take care of it.



    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  3. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    i tried spyquake fix first but there was no files detected. so theres the smitfiles.txt and i just did the first instruction u said and i also uploaded the rapport for the first 1. thx will do 2nd one now
     

    Attached Files:

  4. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    heres the 2nd rapport.txt, i still have the syslem malware on my comp
     

    Attached Files:

  5. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

  6. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    syslem also disables all network activity except class 1 internet browsing. so in other words i cannot transfer any data from my comp using lan no matter how hard i try
     
  7. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    heres a syslem.exe crash technical log text file, see attachment
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  9. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    it also disables the backdoor trojan windows update, and the syslem.exe file is hidden in system32 folder which u can make it show but u cant delete it with anything including killbox or regrun or even safe mode it says its in use / dont have permission then when u try SAFE msdos it says it doesnt exist
     
  10. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    also u cant rename it or even regrun cant fix it. regrun thol says its a trojan in the title.. heres the hijackthis log without doing any scans, because i have to get the programs and i bet some u have to pay for em so torrent away.. and to find the so called do step 6 of some instructions will b a while.
     

    Attached Files:

  11. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    my comp is currently overloaded at 3.5gig pf usage and 100% cpu i can barely run mozilla and its impossible for me now to even install executables. to do ur spyscan list it will take me 3 days to a week at this rate!
     
  12. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    plz tell me how to nuke my hard drive (c drive) this is the only way, save me alot of time
     
  13. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    i fixed the cpu issues it seemd i had another trojan on my d drive so i fixed that but i still have syslem.. work in progress
     
  14. StOoGiEmEiStEr

    StOoGiEmEiStEr Private E-2

    well apparently i figured it all out. first i downloaded a imToo complete and copied it to my 2nd harddrive then after i reformatted it activated the trojan in directory D:\Other Files\Stuff\other programs and stuff\ImTOO\IMTOO\pou64\converter\ImTOO\Video\ImTOO.DVD.Ripper.Platinium.v4.0.43.0317b\crack\keygen.exe
    and infected my freshly formatted comp and thus came the syslem.exe auto start copying to system32 folder which made my comp lag so badly. i fixed this by using a free program called AVG Anti-spyware 7.5, thumbs up to that. thx for the help guys. add this ending info to ur brains or wateva to tell other people wat to do when they have the exact same trojan as me (syslem.exe). thx n goodbye
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you had followed the directions I gave to you in message # 8, you would have seen that AVG Antispyware was one of the tools that we ask you to run. You may still have the below service trying to load as seen in your HJT log:
    O23 - Service: Auto Start - Unknown owner - C:\WINDOWS\system32\Syslem.exe

    You really should have followed the directions in message # 8 to make sure you are really clean.

    At anyrate you should follow the below steps to help keep you clean.

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds