Author Topic: Hi =] Trojan gen =/  (Read 28651 times)

0 Members and 1 Guest are viewing this topic.

jc81

  • Guest
Re: Hi =] Trojan gen =/
« Reply #45 on: August 28, 2008, 10:21:43 PM »
me?
thanks
 8)
just following everything i'm told lol

jc81

  • Guest
Re: Hi =] Trojan gen =/
« Reply #46 on: September 01, 2008, 02:51:27 AM »
Hi jc81,

First and foremost undo system restore:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039

Adclicker removal instructions

You have to be the Administrator (full priviledges). The way it works, it loads into RAM and then uses your O/S as it's slave to replicate and try to do its damage. One of the first things we do is temporarily kill its slave off.
-------------

1) Quit all open apps. Kill off everything except avast, your firewall, and anti-spyware programs, drivers.
2) Open the Task Manager (CTRL-ALT-DEL)
3) Find "Explorer.exe" and RIGHT-CLICK on it. Choose "end-process tree" to kill Explorer entirely.
4) Start DrWebCureIT from a mem stick. Scan your entire disk to get rid of all those infecting DLLs (You can have over 15,000).
5) Now that the slave is killed, lets go identify the "master" still in RAM. Under the Task Manager, Launch "sysinfo32".
6) Go to "Software Environment->Loaded Modules". Choose Advanced View. Once it's preflighted everything and displayed a list, sort it by date, so you can see what was most recently installed. Look at the Manufacturer column and look for "Melkosoft". You might see more than one evil entry.
7) Under SysInfo32, go to "Software Environment->Startup Programs" THIS is the one that causes it to launch when Explorer.exe runs.: It could look like

"c:\winnt\system32\????????????.exe"

Under the Task Manager, now that you know its name, go to File->Start Task and launch regedit. Search for the name. Mine was found in the registry here:

Computer->HKEY_LOCAL_MACHINE->SOFTWARE->Microsoft->Windows->CurrentVersion->Run->Control handler
Delete registry values:

Browse to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Delete the values 'SVCHOST', 'TcpDetect' and 'win32app'

8) DELETE the specific entry for "???????????.exe" (whatever yours was named).
9) Back in the Task Manager, go to File->Start Task, and launch Explorer.exe to bring your O/S back up. avast  should not holler because when Explorer.exe starts, it no longer launches the virus.
10) Go into where the replicating DLLs are:

c:\winnt\system32\

and add ".vir" to the end of the DLLs that anti-virus couldn't clean out because they were "in use" and couldn't be deleted (you identified these in Step #6.
11) Reboot
12) Go back into

c:\winnt\system32\

and delete all files you added the ".vir" suffix to.

13) Lastly, run your anti-spyware program and have it search your entire disk. This will remove malicious cooks that this thing also seems to plant.
14) Reboot.

polonus


Okay, so I'm doing this tomorrow. I'm so afraid I'm going to mess it up and kill my computer somehow.

But I have a question about number 4. Start DrWebCureIT from a mem stick.
I have no idea what that means or how to do it. A memory stick?? What is that? lol

wyrmrider

  • Guest
Re: Hi =] Trojan gen =/
« Reply #47 on: September 01, 2008, 03:47:05 AM »
Polonus is referring to one of those USB memory dongle things

Polonus  do you want her to Download Dr Web on a different computer
I think she needs to know how to ge Dr Web on whatever a memstick is

jc
Polonus is in the Netherlands he may be in neverland by now
hang tight and ask all these questions ahead of time

jc81

  • Guest
Re: Hi =] Trojan gen =/
« Reply #48 on: September 01, 2008, 04:00:30 PM »
Polonus is referring to one of those USB memory dongle things

Polonus  do you want her to Download Dr Web on a different computer
I think she needs to know how to ge Dr Web on whatever a memstick is

jc
Polonus is in the Netherlands he may be in neverland by now
hang tight and ask all these questions ahead of time

This is the only computer I haveeee.
I'm really freaked out about doing this stuff btw lol.
I think I'll destroy it somehow and...goodbye computer.

wyrmrider

  • Guest
Re: Hi =] Trojan gen =/
« Reply #49 on: September 02, 2008, 05:58:35 AM »
give polonus a pm with your concerns and have him give you explicit directions
he is really good at that  this is sort of a bump

jc81

  • Guest
Re: Hi =] Trojan gen =/
« Reply #50 on: September 04, 2008, 12:10:41 AM »
give polonus a pm with your concerns and have him give you explicit directions
he is really good at that  this is sort of a bump

Thank you wyrmrider, I have.
 :)

wyrmrider

  • Guest
Re: Hi =] Trojan gen =/
« Reply #51 on: September 04, 2008, 01:03:57 AM »
A Squared also has a memsitckable anti Trojan tool

http://www.emsisoft.com/en/software/download/
scroll down
a-squared Emergency USB Stick files
start download

should be handy to have around

did pol get back to you?
He PM'ed me about another post earlier today

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Hi =] Trojan gen =/
« Reply #52 on: September 04, 2008, 01:17:18 AM »
Hi wyrmrider,

Yes he PM-ed with the instruction as how to achieve a USB stick. Also known as pendrive or removable flash drive and how to download DrWebCureIt  onto there with save launch.exe  onto the drive number that the computer has given to the new removable drive, that is the USB stick when attached to the USB plughole (most modern XP machines have at least two of these). You can buy a memory stick or USB stick or pen drive or removable flash drive for a couple of bucks really (from 1 GB to 8 or more GB), and it is nice to have security scanners and tools on there to keep computers clean as well as other data to carry around, I hope I explained this right enough for people that are not actually geeks,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

wyrmrider

  • Guest
Re: Hi =] Trojan gen =/
« Reply #53 on: September 04, 2008, 01:33:05 AM »
Pol
Have you had your glasses checked lately?

YoKenny

  • Guest
Re: Hi =] Trojan gen =/
« Reply #54 on: September 05, 2008, 10:00:51 AM »
My favorite USB stick:
http://winpatrol.stores.yahoo.net/winpatrol-usb-flash-wristband.html

I put CCleaner on it as well.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Hi =] Trojan gen =/
« Reply #55 on: September 05, 2008, 06:09:33 PM »
My favourite usb stick, smallest 8GB usb ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

YoKenny

  • Guest
Re: Hi =] Trojan gen =/
« Reply #56 on: September 06, 2008, 04:30:34 AM »

wyrmrider

  • Guest
Re: Hi =] Trojan gen =/
« Reply #57 on: September 11, 2008, 07:42:05 PM »
JC

you ok?


wyrmrider

  • Guest
Re: Hi =] Trojan gen =/
« Reply #58 on: September 12, 2008, 07:59:55 PM »
jc
here is another tool that might help
http://forums.spybot.info/showthread.php?t=34034

jc81

  • Guest
Re: Hi =] Trojan gen =/
« Reply #59 on: September 17, 2008, 10:45:37 PM »
JC

you ok?



Yeah, thanks...

I still haven't done what polonus said...just kind of putting it off hoping the computer fixes itself. LOL You're welcome to come over and do it for me  ;) hahaha

Thanks for the link, I'll check it out.

jc