Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Members Search

>>> Get Paid to Hang Out Here! Activity = Points = Prizes. Want to Know More? <<<

Reply
 
LinkBack Thread Tools
  #1  
Old 22nd Nov 2007
No Avatar
Gavyd  United Kingdom
CJ New Member
 
Gavyd is offline
 
Join Date: 22nd Nov 2007
Last Online: 5th Dec 2007 11:13 AM
Posts: 5
iTrader: (0)
Gavyd is on a distinguished road
Default VIRUS - Help needed

VIRUS - Help needed

Hey troops.........I let my wee bro on my MAIN machine.....as stupid as the wee rat is its got a virus and is a to get rid of. Im no stranger to a PC and its causing me some grief! Its seems to be a browser hacker (IE Only) im using Firefox so im ok....its opening numerous windows and throwing up all sorts of error messages. I currently have AVG and Adaware installed and can’t get rid....its seems to have embedded itself in C: /Windows/System32........ Would be much appreciated of any help, bellow are a few error messages that are coming up

Thanks in advance

Black Door Trojan

Net-Worm-IVirsus@fp

Trojan-Spy.win32@mx

I installed AVG Anti-Spyware

Below are a few screen dumps




Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 22nd Nov 2007
sophus's Avatar
sophus  Brazil
CJ Donator
 
sophus is offline
 
Join Date: 18th Nov 2007
Last Online: 5th Sep 2008 04:48 PM
Posts: 27
iTrader: (0)
sophus is on a distinguished road
Default VIRUS - Help needed

hey, I went to this path (c:\windows) and there's no such shell.exe. So, kill this task, quarentine this thing and see if it works.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 22nd Nov 2007
No Avatar
Gavyd  United Kingdom
CJ New Member
 
Gavyd is offline
 
Join Date: 22nd Nov 2007
Last Online: 5th Dec 2007 11:13 AM
Posts: 5
iTrader: (0)
Gavyd is on a distinguished road
Default VIRUS - Help needed

Cheers im in work at the minute will do it when i go home. I will more than likely need to go into "safe mode" to delete this file?? Is there anything else in the list that you know should not be running??

Thanks for the help

Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 22nd Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default VIRUS - Help needed

Originally Posted by sophus View Post
hey, I went to this path (c:\windows) and there's no such shell.exe. So, kill this task, quarentine this thing and see if it works.
A) "If" you were able to delete it would possibly leave the system unbootable, or bootable with errors. system32 files are important to windows running properly, even if they are malicious.

B) "If" you were able to delete it, it would likely re-create itself before even hitting the recycle bin.

We don't mind people helping in malware removal, but if you are not familiar with the tools needed to properly clean infections please refrain from giving instructions.

You will need to run a few more scans and add the logs as attachments.
Guide for attaching logs to a post

==========

Use the ESET Nod32 Online Scanner

Click YES, I accept the Terms of Use. Then Start.

The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt

Add the EsetOnlineScanner\log.txt in your post as an Attachment.

Guide for attaching logs to a post

==========

Download HijackThis to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file or .log
Do NOT attach MS-Word .DOC files, they will NOT be looked at!
In your post, add the log as an Attachment.
* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

Guide for attaching logs to a post

==========

Items needed as attachments in next post:
EsetOnlineScanner\log.txt
HijackThis log
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 22nd Nov 2007
Carl's Avatar
Carl  United Kingdom
CJ Donator
 
Carl is offline
 
Join Date: 22nd Nov 2007
Last Online: 6 Days Ago 09:24 PM
Posts: 203
iTrader: (0)
Carl is on a distinguished road
Default VIRUS - Help needed

if you can`t get rid of it or your computer`s to badly infected, back up your most important files to an external HDD and then refomat windows (DON`T DO THE QUICK FORMAT as it may stay on there do the long format as it`ll wipe all your old files off and the virus with it,) and thern carry on installing windows xp.
best of luck mate.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 22nd Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default VIRUS - Help needed

Originally Posted by Carl View Post
if you can`t get rid of it or your computer`s to badly infected, back up your most important files to an external HDD and then refomat windows (DON`T DO THE QUICK FORMAT as it may stay on there do the long format as it`ll wipe all your old files off and the virus with it,) and thern carry on installing windows xp.
best of luck mate.
We aren't to that point yet.

Most virus can be cleaned without having to resort to wiping the drive and starting over.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 22nd Nov 2007
sophus's Avatar
sophus  Brazil
CJ Donator
 
sophus is offline
 
Join Date: 18th Nov 2007
Last Online: 5th Sep 2008 04:48 PM
Posts: 27
iTrader: (0)
sophus is on a distinguished road
Default VIRUS - Help needed

Originally Posted by evilfantasy View Post
A) "If" you were able to delete it would possibly leave the system unbootable, or bootable with errors. system32 files are important to windows running properly, even if they are malicious.

B) "If" you were able to delete it, it would likely re-create itself before even hitting the recycle bin.

We don't mind people helping in malware removal, but if you are not familiar with the tools needed to properly clean infections please refrain from giving instructions.

You will need to run a few more scans and add the logs as attachments.
Guide for attaching logs to a post

==========

Use the ESET Nod32 Online Scanner

Click YES, I accept the Terms of Use. Then Start.

The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt

Add the EsetOnlineScanner\log.txt in your post as an Attachment.

Guide for attaching logs to a post

==========

Download HijackThis to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file or .log
Do NOT attach MS-Word .DOC files, they will NOT be looked at!
In your post, add the log as an Attachment.
* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

Guide for attaching logs to a post

==========

Items needed as attachments in next post:
EsetOnlineScanner\log.txt
HijackThis log
Maybe I haven't read some of your forum rules, and I'm sorry for that.
But I'm not an irresponsible guy who throws random tips through the forum. My intention is to help this guy, only.
So I said, "kill this task" and "quarentine this thing", not "delete" it.
Even though I have said it, it wouldn't be something like leaving your system "unbootable", because shell.exe DOES NOT exist, it is clearly a malware. But I had to make sure, so I went to C:\windows\system32 and there was no shell.exe. Every one knows, that most of this malware we get, are installing themselves in specific places, and \system32 is a common one. Just my opinion.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #8  
Old 22nd Nov 2007
Carl's Avatar
Carl  United Kingdom
CJ Donator
 
Carl is offline
 
Join Date: 22nd Nov 2007
Last Online: 6 Days Ago 09:24 PM
Posts: 203
iTrader: (0)
Carl is on a distinguished road
Default VIRUS - Help needed

Quote evilfantasy "We aren't to that point yet.

Most virus can be cleaned without having to resort to wiping the drive and starting over"

i know i was just saying just incase.

Last edited by Carl : 22nd Nov 2007 at 07:36 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #9  
Old 22nd Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default VIRUS - Help needed

My point was, hiding/deleting/quarantining suspicious entries can make it harder for removal tools to detect, repair or remove them.

Shell.exe is added by a worm so again, it won't work, it will just recreate itself somewhere else.

I'm not taking a shot at your suggestions, just explaining that it won't work.
__________________
.
.

Last edited by evilfantasy : 22nd Nov 2007 at 07:33 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #10  
Old 22nd Nov 2007
sophus's Avatar
sophus  Brazil
CJ Donator
 
sophus is offline
 
Join Date: 18th Nov 2007
Last Online: 5th Sep 2008 04:48 PM
Posts: 27
iTrader: (0)
sophus is on a distinguished road
Default VIRUS - Help needed

I understand evilfantasy, we're both trying to help. So making my argument valid doesn't make your point invalid, and vice-versa. I prefer to solve problems like this by myself. And then, when I can't do that I try some anti-virus or anti-spyware. It's my method and experience not an absolute truth.
But let's quit this, and see how Gavyd is managing his problem.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help needed Mike0001 General Software Chat 21 5th Apr 2008 05:43 PM
A lil help needed. Gazray4699 Drives & Removable Media 3 7th Jan 2008 10:58 PM
help needed doomjeffs Virus, Spyware & Security 2 12th Aug 2007 12:37 PM
avg virus scanner: when i delete a file from the virus... tell me all!!! Virus, Spyware & Security 1 19th Mar 2007 07:45 PM


Copyright ©2006 - 2008 Computer Juice - Forums - Free PC Help, IT Support and Repairs.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape