|
#1
|
|||
|
|||
|
Viruses/Spyware/Malware, preliminary removal instructions
Hi Julio,
I came across your solution for removing spyware and malware and gave it a go. Please could you look at the log files attached, as mentioned in your post. While doing carrying out the solution i seem to have lost the system32\oidlmehb.dll and the system32\gaxhrtrs.dll. Also the solution has not removed a trojan (AVAST keeps alerting to) Win32:Agent-BSU [TrJ]. Please help. |
|
#2
|
||||
|
||||
|
Hi,
Before I can look over the log I would like you to do a couple of things for me, 1)Disable Teatimer Please disable Teatimer as it may interfere with the fix. First:
2)Run the avg antispyware again and get it to quarantine the results, 3)I would like you to do an online scan so that we can what else may be in your system, Run Kaspersky online scanner With the exception of Internet Explorer, which must be used for this scan, keep ALL programs closed Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans to speed up scan time and to make sure there are no conflicts. Do not go surfing while your resident protection is disabled! Once the scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use. Do an online scan with Kaspersky Online Scanner in Internet Explorer. You will be prompted to install and run an ActiveX component from Kaspersky, Click Yes. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75%. Once the licence accepted, reset to 100%.
Thanks, and sorry for getting looked over yesterday, its pretty busy round here. |
|
|
|
#3
|
|||
|
|||
|
kaspersky scan
Hi,
Thanks for that. Please see kaspersky scan log attached. Let me know what you think. |
|
#4
|
||||
|
||||
|
Delete Files and Folders
C:\Documents and Settings\Varinder\Local Settings\Temp\2961271612.exe<---------This File C:\Documents and Settings\Varinder\Local Settings\Temp\csrssc.exe<---------This File C:\Program Files\MSN Messenger\riched20.dll<---------This File C:\WINDOWS\system32\jfiehayd.dll<---------This File C:\WINDOWS\system32\service.exe<---------This File
***DO NOT USE MSCONFIG TO BOOT INTO SAFE MODE*** ********************NOTICE*************************************** This one is service.exe and not services.exe Navaigate to this folder and delete the contents of it but not the folder itself, C:\QooBox\Quarantine Empty the recycle bin Run HijackThis again after you have turned off Spybots TeaTimer using the instructions I gave earlier. Also run Kaspersky again. Last edited by kritius; 03-28-2008 at 01:52 PM.. |
|
#5
|
|||
|
|||
|
Hi Kritius,
tried to set "show all hidden files and folders" but for some reason option is not available. Tried through windows help and got message " this operation is cancelled due to restrictions in affect on this computer" Please contact system admin. |
|
#6
|
||||
|
||||
|
Back up the registry, see how HERE
1. Click Start - Run - type Regedit 2. Here expand to HKEY_CURRENT_USER SOFTWARE MICROSOFT WINDOWS CURRENTVERSION POLICIES EXPLORER 3. in the right-side pane check for the DWORD value NoFolderOptions 4. If it is not there then create a new DWORD value by right-clicking NEW-DWORD 5. Type a name 'NoFolderOptions" and press Enter. 6. Double-click the entry and set the value to 0 7. Open any folder and see if Folder Options is there. If it is still not there then Log Off and Log in again or make a restart Try that |
|
#7
|
|||
|
|||
|
Thanks i'll give it a shot.
|
|
#8
|
|||
|
|||
|
what a mess
Couldn't run regedit message "regedit disabled by administrator" even though i am one.
What i did. 1, Tried to run backup utilit- wouldn't backup to cd drive. Instead saved to desktop then copied to cd successfully. 2, Couldn't unhide hidden files and folders so used search to find files listed and removed that way instead. Not sure if this will give same result. 3, Since running Kapersky computer got worse, more WIN32:agents messages. Also Google page turned black. Also when i tried to uncheck resident teatimer resident kept blocking this even though i had exited at system tray. took a few goes before it allowed it. 4, After doing 1, and 2, No more WIN32: bsu messages yet. Google page is normal. However tried running regedit still saying it is disabled. Also still getting messag that modules c:\windows\system32\oidlmehb.dll and gaxhrts.dll not found. About to run kapersky again will post as soon as it finishes. |
|
#9
|
||||
|
||||
|
Quote:
It contains a program written by Rathat, and it is a Policy Controller. Save and extract this program to the desktop. Once extracted, click on the RatsCheddar.exe file. Enable everything, then click Exit Reboot your Computer. Download and Run Malwarebytes' Anti-Malware Please download Malwarebytes' Anti-Malware to your desktop.
This thread is for the use of shiva64 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum. |
|
|
|
#10
|
|||
|
|||
|
scan
Hi,
I'll do that now. Please find HJT and Kaspersky scans attached. |
|
#11
|
||||
|
||||
|
Can you run HJT from normal mode please? After Malwarebytes finishes
|
|
#12
|
|||
|
|||
|
I'll try it now and post if doable with malware log.
|
|
#13
|
||||
|
||||
|
I need it after Mlawarebytes finishes.
|
|
#14
|
|||
|
|||
|
scans
Tried to upload both scans but wabpage froze. Triying to upload again but attachment screen just says attachment in progress and upload errors.
|
|
#15
|
||||
|
||||
|
try deleting your previous uploads
|
|
#16
|
|||
|
|||
|
scans
Please find sca attached. Hijackthis was done after mlawarebytes had finished.
|
|
#17
|
||||
|
||||
|
Ill look over them as soon as I can. pretty backlogged here.
|
|
#18
|
|||
|
|||
|
No probs catch up later.
|
|
#19
|
|||
|
|||
|
Hi Kritius,
Did u get a chance to look at those scans i sent? |
|
#20
|
||||
|
||||
|
Fix entries using HiJackThis
O20 - Winlogon Notify: nnnoonn - C:\WINDOWS\
Boot into safe mode and delete this file, C:\WINDOWS\system32\gaxhrtrs.dll Boot into normal mode Please download VundoFix.exe to your desktop.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot. Please Download VirtumundoBeGone by secured2k
Note: It is normal for the the fix to terminate by producing a BLUE SCREEN OF DEATH so don't be concerned when this happens. It requires you to manually reboot to restore your normal windows desktop. The log created by VirtumundoBeGone called VBG.TXT will be on located on your desktop. Please retain VBG.TXT. Empty Recycle Bin. Reboot and "attach" a new HijackThis log file along with the VBG.TXT into this thread. Also please describe how your computer behaves at the moment. |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions | Virus & Malware removal | 2 | 09-11-2008 03:21 PM | |
| Viruses/Spyware/Malware, preliminary removal instructions by howard_hopkinso | Virus & Malware removal | 9 | 01-26-2008 10:17 AM | |
| Viruses/Spyware/Malware, preliminary removal | Virus & Malware removal | 1 | 01-22-2008 08:45 AM | |
| Viruses/Spyware/Malware, preliminary removal | Virus & Malware removal | 0 | 01-12-2008 05:25 AM | |
All times are GMT -4. The time now is 05:42 PM.




