Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93101 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Highjackthis log please help


  • Please log in to reply
30 replies to this topic

#16 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 12:03 PM

Yes It's gone Fixwareout ver 1.003 Last edited 04/26/2006 Post this report in the forums please Reg Entries that were deleted HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\iahmd HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\32refaselif ... Microsoft ® Windows Script Host Version 5.6 Random Runs removed from HKLM "dmhai.exe"=- ... PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Example ipsec6.exe is lagitamate »»»»» Search by size and names... »»»»» Misc files »»»»» Checking for older varients covered by the Rem3 tool »»»»» Search five digit cs, dm and jb files This WILL/CAN also list Legit Files, Submit them at Virustotal C:\WINDOWS\SYSTEM32\CSRRS.EXE 155,648 2002-08-29

    Advertisements

Register to Remove


#17 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 12:09 PM

One more thing, I have this CWS virus named feads, and I can't get rid of it. I try using CWS Shredder, and SBC yahoo antivirus, but It can't erase

#18 Micah_6:8

Micah_6:8

    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 20 May 2006 - 12:19 PM

:) :thumbup:

Can you find/delete this file?

C:\WINDOWS\SYSTEM32\CSRRS.EXE <-- this file

EXTREMELY IMPORTANT!!!

The may be a file in there named csrss.exe

That file is a VALID WINDOWS application.

BE SURE AND DELETE THE CORRECT FILE!!!

Please note the difference in the file names!!!

Some malware files may be "hidden".
Be sure to show hidden files when looking.

Then empty it from the recycle bin.

Then run the program you ran earlier that was picking up some things, and let me know what it finds.
:)
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

#19 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 12:29 PM

I see the file, but I cannot delete it. It says application could not be run in Win32 mode? Maybe I need to run safe mode?

#20 Micah_6:8

Micah_6:8

    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 20 May 2006 - 12:31 PM

Don't "run" it, <right-click> on it and choose "Delete". :)
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

#21 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 12:37 PM

I right click and clicked delete this time it says cannot delete CSRSS: Access is denied make sure the disk is not full or write-protected and that the is not currently in use. Im going to restart, and try again.

#22 Micah_6:8

Micah_6:8

    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 20 May 2006 - 12:41 PM

<right-click> on it and choose "Properties"

In the window that opens, look towards the bottom.

Next to Attributes:, if there is a check in the "Read-only" box, remove the check then click "Apply" then "OK", then try to delete it again.
:) :thumbup:
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

#23 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 12:47 PM

No same thing, anymore ideas? :)

#24 Micah_6:8

Micah_6:8

    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 20 May 2006 - 12:51 PM

Download Killbox from here:

Killbox.zip © Option^Explicit

Unzip it.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Now, run Killbox.

In Killbox select "Delete on Reboot".

Paste the next line into the "Full Path of File to Delete" text box.

C:\WINDOWS\SYSTEM32\CSRRS.EXE

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

When the machine reboots be sure it's gone.
:)
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

#25 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 12:52 PM

I wonder am I'm trying to delete the correct one. It says CSRSS client server runtime process. It doesn't say .exe. There's no exe.

    Advertisements

Register to Remove


#26 Micah_6:8

Micah_6:8

    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 20 May 2006 - 12:53 PM

See my last post.
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

#27 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 12:57 PM

It says the file doesn't excist. I think that wasn't the .exe file, so I think my PC is clean now? :)

#28 Micah_6:8

Micah_6:8

    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 20 May 2006 - 01:00 PM

I just ran the program Xoftspy and it found 4 objects. One was a browser highjacker, worm, and two data miners. When I earse them they tend to come back. How could I prevent this from coming back? I have zone alarm pro, but I guess it does not seem to prevent viruses.


Run that program again, and let me know what it finds.
:)
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

#29 Derek V

Derek V

    New Member

  • Authentic Member
  • Pip
  • 16 posts

Posted 20 May 2006 - 01:08 PM

It found nothing, it came out clean. I have to make sure I always open zone alarm pro before browsing. Thank You Micah if I have anymore problems I hope you are here. Thanks to you my pc is virus free, and running smoothly again. Thank You :) :thumbup:

#30 Micah_6:8

Micah_6:8

    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 20 May 2006 - 02:31 PM

You're welcome.

M68 :)

Post Infection Items To Ponder
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users