lesser-equity

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Security

Register


 Default 

VIRUS - Help needed




Reply
 
Thread Tools
  #1  
Old 22nd Nov 2007, 02:52
New Member Group
 
Default VIRUS - Help needed

VIRUS - Help needed

Hey troops.........I let my wee bro on my MAIN machine.....as stupid as the wee rat is its got a virus and is a to get rid of. Im no stranger to a PC and its causing me some grief! Its seems to be a browser hacker (IE Only) im using Firefox so im ok....its opening numerous windows and throwing up all sorts of error messages. I currently have AVG and Adaware installed and can’t get rid....its seems to have embedded itself in C: /Windows/System32........ Would be much appreciated of any help, bellow are a few error messages that are coming up

Thanks in advance

Black Door Trojan

Net-Worm-IVirsus@fp

Trojan-Spy.win32@mx

I installed AVG Anti-Spyware

Below are a few screen dumps




  #2  
Old 22nd Nov 2007, 06:37
Donor Group
 
Default VIRUS - Help needed

hey, I went to this path (c:\windows) and there's no such shell.exe. So, kill this task, quarentine this thing and see if it works.
  #3  
Old 22nd Nov 2007, 06:55
New Member Group
 
Default VIRUS - Help needed

Cheers im in work at the minute will do it when i go home. I will more than likely need to go into "safe mode" to delete this file?? Is there anything else in the list that you know should not be running??

Thanks for the help

  #4  
Old 22nd Nov 2007, 08:22
Moderator Group
 
Default VIRUS - Help needed

Quote:
Originally Posted by sophus View Post
hey, I went to this path (c:\windows) and there's no such shell.exe. So, kill this task, quarentine this thing and see if it works.
A) "If" you were able to delete it would possibly leave the system unbootable, or bootable with errors. system32 files are important to windows running properly, even if they are malicious.

B) "If" you were able to delete it, it would likely re-create itself before even hitting the recycle bin.

We don't mind people helping in malware removal, but if you are not familiar with the tools needed to properly clean infections please refrain from giving instructions.

You will need to run a few more scans and add the logs as attachments.
Guide for attaching logs to a post

==========

Use the ESET Nod32 Online Scanner

Click YES, I accept the Terms of Use. Then Start.

The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt

Add the EsetOnlineScanner\log.txt in your post as an Attachment.

Guide for attaching logs to a post

==========

Download HijackThis to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file or .log
Do NOT attach MS-Word .DOC files, they will NOT be looked at!
In your post, add the log as an Attachment.
* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

Guide for attaching logs to a post

==========

Items needed as attachments in next post:
EsetOnlineScanner\log.txt
HijackThis log
__________________

  #5  
Old 22nd Nov 2007, 09:42
Donor Group
 
Default VIRUS - Help needed

if you can`t get rid of it or your computer`s to badly infected, back up your most important files to an external HDD and then refomat windows (DON`T DO THE QUICK FORMAT as it may stay on there do the long format as it`ll wipe all your old files off and the virus with it,) and thern carry on installing windows xp.
best of luck mate.
  #6  
Old 22nd Nov 2007, 10:42
Moderator Group
 
Default VIRUS - Help needed

Quote:
Originally Posted by Carl View Post
if you can`t get rid of it or your computer`s to badly infected, back up your most important files to an external HDD and then refomat windows (DON`T DO THE QUICK FORMAT as it may stay on there do the long format as it`ll wipe all your old files off and the virus with it,) and thern carry on installing windows xp.
best of luck mate.
We aren't to that point yet.

Most virus can be cleaned without having to resort to wiping the drive and starting over.
__________________

  #7  
Old 22nd Nov 2007, 11:42
Donor Group
 
Default VIRUS - Help needed

Quote:
Originally Posted by evilfantasy View Post
A) "If" you were able to delete it would possibly leave the system unbootable, or bootable with errors. system32 files are important to windows running properly, even if they are malicious.

B) "If" you were able to delete it, it would likely re-create itself before even hitting the recycle bin.

We don't mind people helping in malware removal, but if you are not familiar with the tools needed to properly clean infections please refrain from giving instructions.

You will need to run a few more scans and add the logs as attachments.
Guide for attaching logs to a post

==========

Use the ESET Nod32 Online Scanner

Click YES, I accept the Terms of Use. Then Start.

The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt

Add the EsetOnlineScanner\log.txt in your post as an Attachment.

Guide for attaching logs to a post

==========

Download HijackThis to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file or .log
Do NOT attach MS-Word .DOC files, they will NOT be looked at!
In your post, add the log as an Attachment.
* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

Guide for attaching logs to a post

==========

Items needed as attachments in next post:
EsetOnlineScanner\log.txt
HijackThis log
Maybe I haven't read some of your forum rules, and I'm sorry for that.
But I'm not an irresponsible guy who throws random tips through the forum. My intention is to help this guy, only.
So I said, "kill this task" and "quarentine this thing", not "delete" it.
Even though I have said it, it wouldn't be something like leaving your system "unbootable", because shell.exe DOES NOT exist, it is clearly a malware. But I had to make sure, so I went to C:\windows\system32 and there was no shell.exe. Every one knows, that most of this malware we get, are installing themselves in specific places, and \system32 is a common one. Just my opinion.
  #8  
Old 22nd Nov 2007, 12:27
Donor Group
 
Default VIRUS - Help needed

Quote evilfantasy "We aren't to that point yet.

Most virus can be cleaned without having to resort to wiping the drive and starting over"

i know i was just saying just incase.
  #9  
Old 22nd Nov 2007, 12:31
Moderator Group
 
Default VIRUS - Help needed

My point was, hiding/deleting/quarantining suspicious entries can make it harder for removal tools to detect, repair or remove them.

Shell.exe is added by a worm so again, it won't work, it will just recreate itself somewhere else.

I'm not taking a shot at your suggestions, just explaining that it won't work.
__________________

  #10  
Old 22nd Nov 2007, 14:58
Donor Group
 
Default VIRUS - Help needed

I understand evilfantasy, we're both trying to help. So making my argument valid doesn't make your point invalid, and vice-versa. I prefer to solve problems like this by myself. And then, when I can't do that I try some anti-virus or anti-spyware. It's my method and experience not an absolute truth.
But let's quit this, and see how Gavyd is managing his problem.
Reply

Register

Bookmarks

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help Needed for Globalroot\systemroot Virus LostinCyberspace Virus, Spyware & Security 1 21st Jun 2009 14:40
Virus Question - Can anyone tell me if i may have a virus billozz Virus, Spyware & Security 1 2nd Apr 2009 13:58
My friends MAC has a virus...umm...yeah...a Virus... cheesepuff Virus, Spyware & Security 3 29th Oct 2008 12:58
Hey all, help needed robk89 General Hardware Chat 14 21st Nov 2007 10:53
Help needed doomjeffs Virus, Spyware & Security 2 12th Aug 2007 04:37
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright ©2006 - 2009 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.