viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by antoniog77, Aug 6, 2006.

  1. antoniog77

    antoniog77 Private E-2

    I found the following viruses on my pc java.trojan.exploit.bytverify, trojan task disabler, downloader swfdl.a. Below are my bitdefender, panda, and hijackthis logs. Please help. I have a pentium r4 cpu with 256 mb ram, windows xp
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the directions in the current version of the READ ME. You should not refer to local copies. Only the online version is current and you must always refer to it. I'm posting a copy of the boilerplate that shows everything required now. You don't need to start over again. Just rename HijackThis.exe as requested in step 7 and then run GetRunKey and ShowNew and attach those two logs. These scan run very quikly.

    ========== NEW BOILER PLATE ===========================


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. antoniog77

    antoniog77 Private E-2

    here are the logs, if I didnt do something correctly please let me know
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install Big Fish Games Toolbar yourself?

    Uninstall the below using Add/Remove programs (only uninstall these 3 items! Nothing else!)
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Notifier


    Start by downloading - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    c:\windows\downloaded program files\YazzleActiveX.inf
    C:\Program Files\Common Files\Microsoft Shared\Proof\timeupdate.exe
    C:\Program Files\Common Files\Microsoft Shared\Temp\MswService.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.
    After reboot locat the below folder and delete it if found:
    C:\Program Files\IntCodec

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Owner\Local Settings\TEMP


    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Aug 7, 2006
  5. antoniog77

    antoniog77 Private E-2

    no, I think my wife has done these things. I remember seeing yazzle somewhere but I didnt put it on here
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall it if you do not want it. It's your choice.

    I just added a fix to my previous message. Refresh your screen and see the fix.
     
  7. antoniog77

    antoniog77 Private E-2

    I did everything but some things of note I did not see the notifier program to uninstall nor did I see Yazzleactivex & mswservice.exe. Here is the get run key and hijack this log. My task manager is now working again. Do I remove big fish toolbar through add/remove programs. Thank you for all the help
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes uninstall Big Fish Games Toolbar if you do not want it.


    Your logs are clean! How is everything working now?
     
  9. antoniog77

    antoniog77 Private E-2

    I uninstalled big fish, and everything is looking good. I also have a question about antivirus, Im debating using norton av corporate or nod32 the ladder I dont know much about.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't recommend anything from Symantec (which you already have installed anyway). It is too much of a resource hog and does not do a very good job of detecting, protecting, and removing all the malware that exists anyway. The free tools we recommend in the below link work just as well or better and they are not resources hogs either. NOD32 is good but for some people it can be a little more difficult to use as it is not as user friendly as some programs.


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds