Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Members Search

>>> Get Paid to Hang Out Here! Activity = Points = Prizes. Want to Know More? <<<

Reply
 
LinkBack Thread Tools
  #11  
Old 7th Nov 2007
No Avatar
CJ Member
 
Insaneman1731 is offline
 
Join Date: 7th Nov 2007
Last Online: 1 Week Ago 02:45 AM
Posts: 32
iTrader: (0)
Insaneman1731 is on a distinguished road
Default Winzix Virus Delete/Removal

.
Attached Files
File Type: doc bdscan.doc (44.6 KB, 9 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #12  
Old 7th Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Winzix Virus Delete/Removal

There is one that is proving to be very stubborn.

Do you know what this file is?
[FONT=Arial]C:\Documents and Settings\All Users\Application Data\Wait Find Browse New\REAL STUPID.exe

We had combofix remove it but it is back.

Put up a fresh HijackThis log please.
[/FONT]
__________________
.
.

Last edited by evilfantasy : 7th Nov 2007 at 10:49 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #13  
Old 7th Nov 2007
No Avatar
CJ Member
 
Insaneman1731 is offline
 
Join Date: 7th Nov 2007
Last Online: 1 Week Ago 02:45 AM
Posts: 32
iTrader: (0)
Insaneman1731 is on a distinguished road
Default Winzix Virus Delete/Removal

No idea what that is.
Attached Files
File Type: txt hijackthis1.txt (10.6 KB, 6 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #14  
Old 7th Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Winzix Virus Delete/Removal

Press ctrl-alt-delete (all at once) to open Task Manager and select the processes tab.

Look for and end the processes for (if found)
REAL STUPID.exe
Mode wait.exe

==========
Open HijackThis and select "Do a system scan only"
Place a checkmark next to these entries
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Browse new fork rule] C:\Documents and Settings\All Users\Application Data\Wait Find Browse New\REAL STUPID.exe
O4 - HKCU\..\Run: [rule hide] C:\DOCUME~1\JOHNEY~1\APPLIC~1\GLUEPL~1\Mode wait.exe
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemp...ogin-devel.cab

Close all windows except for HijackThis and select "Fix checked"

=========

Now open My Computer from the desktop and navigate to and delete these folders/files (if found)
C:\Documents and Settings\All Users\Application Data\Wait Find Browse New\REAL STUPID.exe
C:\DOCUME~1\JOHNEY~1\APPLIC~1\GLUEPL~1\Mode wait.exe

==========

Reboot the computer and post a fresh HijackThis log

Tell me how things are now.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #15  
Old 8th Nov 2007
No Avatar
CJ Member
 
Insaneman1731 is offline
 
Join Date: 7th Nov 2007
Last Online: 1 Week Ago 02:45 AM
Posts: 32
iTrader: (0)
Insaneman1731 is on a distinguished road
Default Winzix Virus Delete/Removal

None of those are in the task manager. Ran HiJackThis and deleted those. I tried to delete the Wait Find Browse New folder and it says I can't because its being used by another program.
Attached Files
File Type: txt hjt2.txt (10.2 KB, 5 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #16  
Old 8th Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Winzix Virus Delete/Removal

No worries, we have gotten rid of a ton of crap so far and it is no longer showing up in the HijackThis log. We are into the final steps now.

But it still needs to go!

Download Killbox http://killbox.net/downloads/KillBox.exe

It will install directly to wherever you set it to download, I suggest right on the desktop.

Double click to open Killbox, see that "Standard File Kill" is selected, then click the little folder icon next to "Full Path of File To Delete" and find the offending C:\Documents and Settings\All Users\Application Data\Wait Find Browse New\REAL STUPID.exe
Double click it to select it, then click the red X in Killbox to begin the deletion.

If it tells you it can not delete it then select "Delete on Reboot" and follow the prompts.

If a reboot is needed then check to see that it is actually gone and let me know.

If it is still there we will move to another method.

==========

Go to Start > Run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit Enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

==========

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version of Java components and update.

Updating Java:

*Download the latest version of Java Runtime Environment (JRE) 6

*Click the "Free Java Download" button to install.

*Close any programs you may have running - especially your web browser.
*Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
*Check for any item with Java Runtime Environment (JRE or J2SE) in the name.
*The only version to keep is Java (TM) 6 Update 3
*Click the Remove or Change/Remove button.
*Repeat as many times as necessary to remove each of the Java versions.
*Reboot your computer once all Java components are removed.
*Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.

==========

Toggle System Restore to clear infected restore points

System Restore
1: Right click on the My Computer icon on your desktop and select properties.
2: Click on the system restore tab.
3: Check the box that says "Turn off system restore on all drives". Click OK.
4: Click Yes when you are prompted to restart the computer
5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.
* No restart will be needed after re-enabling System Restore.

==========

I think you were wanting Winzix for file compression/decompression?

Try ZipGenius It is free and has everything that is needed for in a zip utility. And wont infect your computer!

Or for something more basic see 7-Zip also free and uses the same technology.

Any other free tools you need just come here and ask, we should be able to help you out.

I won't give a speech on torrents, I think you have figured out how dangerous they are.

Keeping Yourself Safe On The Web All the programs in this thread are free to use and are spyware/virus free as well. Also there advice on how to adjust your computers settings to be safer when surfing and downloading.

Let me know how Killbox went, that file absolutely needs to go!
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #17  
Old 8th Nov 2007
No Avatar
CJ Member
 
Insaneman1731 is offline
 
Join Date: 7th Nov 2007
Last Online: 1 Week Ago 02:45 AM
Posts: 32
iTrader: (0)
Insaneman1731 is on a distinguished road
Default Winzix Virus Delete/Removal

Thanks man. I will have to see if that fixes it.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #18  
Old 8th Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Winzix Virus Delete/Removal

Originally Posted by Insaneman1731 View Post
Thanks man. I will have to see if that fixes it.
No problem, let me know how the Killbox went.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #19  
Old 8th Nov 2007
No Avatar
CJ Member
 
Insaneman1731 is offline
 
Join Date: 7th Nov 2007
Last Online: 1 Week Ago 02:45 AM
Posts: 32
iTrader: (0)
Insaneman1731 is on a distinguished road
Default Winzix Virus Delete/Removal

Ya I think it worked. Have not had anymore pop ups :).
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #20  
Old 8th Nov 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 7 Hours Ago 08:16 AM
Posts: 4,921
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Winzix Virus Delete/Removal

Did you look and check if C:\Documents and Settings\All Users\Application Data\Wait Find Browse New\REAL STUPID.exe is gone?
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus removal rongrace Virus, Spyware & Security 42 18th Jan 2008 08:26 PM
SWS AntiSpyware Virus Removal connolly269 Virus, Spyware & Security 1 4th Dec 2007 08:57 AM
Matcash.F Spyware Removal/Delete Graham M Virus, Spyware & Security 2 26th Mar 2007 06:41 PM
avg virus scanner: when i delete a file from the virus... tell me all!!! Virus, Spyware & Security 1 19th Mar 2007 07:45 PM
Cannot delete virus Matt999 Virus, Spyware & Security 3 4th Sep 2006 05:20 PM


Copyright ©2006 - 2008 Computer Juice - Forums - Free PC Help, IT Support and Repairs.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape