ComputerForum.com ComputerForum.com  
Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Display Modes
Old 07-17-2008, 10:41 AM   #11 (permalink)
Administrator
 
apj101's Avatar
 
Join Date: Apr 2005
Location: London
Age: 26
Posts: 9,239
Default

I wouldnt format untill one of out mods ceewi or buzz have had a look, given that it seems they are the only ones who know what they are talking about.
__________________
What did one snow man say to the other?
can you smell carrot?

The fight is won or lost far away from witnesses - behind the lines, in the gym, and out there on the road, long before I dance under those lights.

How you do anything, is how you do everything!
apj101 is offline   Reply With Quote


Old 07-17-2008, 10:47 AM   #12 (permalink)
Diamond Member
 
GameMaster's Avatar
 
Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,947
Default

Quote:
Originally Posted by apj101 View Post
I wouldnt format untill one of out mods ceewi or buzz have had a look, given that it seems they are the only ones who know what they are talking about.
Yes especially Buzz and his attempt to get rid of the Vundo notices using some RegCleaner
ceewi1 is a legend though...

I can say I know what I'm talking about. I don't know am I stupid or what, but I think I know a lot about helping other people ( cleaning viruses, mostly ). My only problem is that I didn't get a "license" to help people just because I was kicked from ALL universities for POSTING ON THIS FORUM.

Come on guys...if only ceewi1 is helping people on this forum, there would be a lot more unsolved cases...Taken that Buzz is not helping since I registered here.
__________________
dznutz:
Quote:
a firewall is like a gate. it keeps the bad people out and the dog in but it's not fool proof. but lets say you download and run an infected program. that will be like letting in a "friend." if it's infected you run that program you can get malware. that's like a friend raping your family and stealing your money.
GameMaster is offline   Reply With Quote
Old 07-17-2008, 10:53 AM   #13 (permalink)
Diamond Member
 
cohen's Avatar
 
Join Date: Jan 2008
Location: Melbourne, Australia
Age: 14
Posts: 8,179
Smile

Quote:
Originally Posted by GameMaster View Post
Yes especially Buzz and his attempt to get rid of the Vundo notices using some RegCleaner
ceewi1 is a legend though...

Come on guys...if only ceewi1 is helping people on this forum, there would be a lot more unsolved cases...Taken that Buzz is not helping since I registered here.
I agree,

No sure what a regcleaner does

ceewi1, is a legend,

people like me and other new starters, at least get the starting stuff of the thread going and ceewi1 / punk / gamemaster finished it off.
__________________
My Website
Desktop / Laptop
Motherboard: Asus M2N X SE / Unknown
CPU: AMD 4000+ 2.1GHZ x 2 / Intel Pentium M 1.60GHZ
Ram: 2GB Transcend / 512MB
Hard Drive: 320GB / 60GB
Video Card: Both Intergrated
Monitor: 19" Benq / 15.4"
OS: Windows Vista Home Premium Service Pack 1 / Windows XP Professional Service Pack 3
cohen is offline   Reply With Quote
Old 07-18-2008, 05:32 AM   #14 (permalink)
Moderator
 
ceewi1's Avatar
 
Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,299
Default

Quote:
Originally Posted by GameMaster View Post
Yes especially Buzz and his attempt to get rid of the Vundo notices using some RegCleaner
Buzz's approach to that thread had a great deal of merit. I'm sorry if you can't see the reasoning behind it, but frankly Buzz knows a lot more about this stuff than you do.

Quote:
people like me and other new starters, at least get the starting stuff of the thread going and ceewi1 / punk / gamemaster finished it off.
Reading through a 20 post thread to figure out what's been done since the first log usually takes a lot longer than just working the log from post 1. Also, ComboFix is not a one-size-fits-all anti-malware solution and needs to be used with care and only where appropriate.

Vizy93, while formatting will obviously resolve your problems, I am not yet convinced that it is necessary. If you have not yet formatted, please do the following:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan-tab, remove the mark at Heuristic analysis.
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new HijackThis log.
__________________

CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870
RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W

Cheap PSUs - 2% of system costs, responsible for 28% of system deaths
As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity.
- The "Warranty void if removed" sticker on numerous CoolerMaster PSUs.

ceewi1 is offline   Reply With Quote
Old 07-18-2008, 06:23 AM   #15 (permalink)
Moderator - F@H Guru
 
mep916's Avatar
 
Join Date: Aug 2007
Location: Northern Cali
Age: 28
Posts: 5,232
Default

Quote:
Originally Posted by GameMaster View Post
Yes especially Buzz and his attempt to get rid of the Vundo notices using some RegCleaner

I can say I know what I'm talking about. My only problem is that I didn't get a "license" to help people just because I was kicked from ALL universities for POSTING ON THIS FORUM.

Taken that Buzz is not helping since I registered here.
Don't be a smartass. Buzz has been helping people here long before you registered. Getting kicked out of universities was due to your own incompetence, and violating rules. Don't blame it on this community.
__________________
Q9450 @ 3.4 GHz || Zalman CNPS9700
ASUS Rampage Formula
XFX GTX 280
4GB Ballistix Tracer @ 850 MHz
2X 150GB WD Raptors (RAID 0)
1TB Hitachi Deskstar
Antec Nine Hundred Case
750W Quad Silencer

FOLDING FOR THE GOOD OF MANKIND:F@H Team 44358 || Team Stats || My Stats || Hardware Contributions: GTX 280/PS3/P4
mep916 is offline   Reply With Quote


Old 07-18-2008, 06:35 AM   #16 (permalink)
Diamond Member
 
Vizy93's Avatar
 
Join Date: Dec 2007
Location: The Angels
Age: 15
Posts: 3,058
Talking

Quote:
Originally Posted by ceewi1 View Post
Vizy93, while formatting will obviously resolve your problems, I am not yet convinced that it is necessary. If you have not yet formatted, please do the following:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan-tab, remove the mark at Heuristic analysis.
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new HijackThis log.
Ceewi, i really appreciate you helping me out, but i needed a reformat anyways so i just went ahead and did it.

My computer is ok now, but i am worried about my external drive, where i basically have EVERYTHING of any importance on.

I did some googling and i found that for the virus:

win32/gaelicum

that i had to use this:

http://www.grisoft.com/ww.virus-removal.ndi-93721

It asked me to download two files and save them to the same folder. so i did that, and i ran the program. All my drives were clean. but it didn't scan my external. So then i went to the command line:

Code:
G:>rmgael H:
Then it scanned my external and said there were NO problems found. All my files seem to be ok... but i thought that the internetworm would've spread itself.

Is there ANY type of log that can show the status of my external??


Thanks alot ceewi
__________________
Ludacris (On Top Of The World):
they say what goes up must come down but i ain't reached my cruising altitude
take a look at what i did but can you imagine what I'm about to do
the places I'm bout to go and the money im bout to see
gave bill gates some binoculars and said look out for me
private planes help me travel in peace
to four cities in one day and four countries in one week
Vizy93 is offline   Reply With Quote
Old 07-18-2008, 06:36 AM   #17 (permalink)
Diamond Member
 
Vizy93's Avatar
 
Join Date: Dec 2007
Location: The Angels
Age: 15
Posts: 3,058
Default

Oh and also,

please forgive me for making you waste your time by posting the cureit stuff. i still really appreciate it.

Sorry!
__________________
Ludacris (On Top Of The World):
they say what goes up must come down but i ain't reached my cruising altitude
take a look at what i did but can you imagine what I'm about to do
the places I'm bout to go and the money im bout to see
gave bill gates some binoculars and said look out for me
private planes help me travel in peace
to four cities in one day and four countries in one week
Vizy93 is offline   Reply With Quote
Old 07-18-2008, 06:53 AM   #18 (permalink)
Moderator
 
ceewi1's Avatar
 
Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,299
Default

Not a problem. Gaelicum is a very dangerous file infector and a full format and reinstall is the best solution to it.

Even though regular anti-virus programs can't disinfect the files, they should be able to detect the virus and delete any infected files. I recommend running a full scan with your antivirus and/or use an online scanner such as BitDefender's to check the drive.
__________________

CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870
RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W

Cheap PSUs - 2% of system costs, responsible for 28% of system deaths
As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity.
- The "Warranty void if removed" sticker on numerous CoolerMaster PSUs.

ceewi1 is offline   Reply With Quote
Old 07-18-2008, 07:14 AM   #19 (permalink)
Diamond Member
 
Vizy93's Avatar
 
Join Date: Dec 2007
Location: The Angels
Age: 15
Posts: 3,058
Default

Will do ceewi!

Thanks alot!
__________________
Ludacris (On Top Of The World):
they say what goes up must come down but i ain't reached my cruising altitude
take a look at what i did but can you imagine what I'm about to do
the places I'm bout to go and the money im bout to see
gave bill gates some binoculars and said look out for me
private planes help me travel in peace
to four cities in one day and four countries in one week
Vizy93 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
claims to not have activated windows? (w/ hijackthis log) wiwazevedo Computer Security 9 06-02-2008 11:18 AM
Hijackthis log - Werid Program? Respital Computer Security 3 05-19-2008 09:51 AM
Slightly Sluggish - see anything? (HijackThis Log Included) voyagerfan99 Computer Security 0 04-27-2008 08:44 PM
Suspected Trojan (HijackThis Log Included) GarmonXD Computer Security 2 02-15-2008 08:27 PM
HijackThis Log mpic92 Computer Security 2 10-30-2005 03:37 PM

All times are GMT +1. The time now is 09:30 PM.


Powered by: vBulletin Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright © 2002-2008 Computer Forum and Web Design Forum