Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > HijackThis Log Help (Inactive)
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


 
 
LinkBack Thread Tools
Old 01-26-2008, 02:16 AM   #1 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 4
OS: vista ultimate


Worm-Email.Bagle (General Components)

Symptoms
1.A message window was loading with windows start with the following message " select something to patch " It was like a normal explorer window but smaller and selected the folders and files wich patched without any confirmation.
2.Antivirus was not running anymore. The message was that is not valid win32 application
3. The following services was disabled. Windows defender - windows firewall - update - and security senter ( I reenabled manually but upon reboot a message appeared that some application was not running - on right click the name of the application was- install-which not appeared on the quik sturtup programs neither disabled nor enabled)
Actions taken
1Post to avira forums - Advise from another user to use combofix (After a breaf search the warnings on using this ap made me to try another solution first)
2.Uninstall avira
3.Install again (could not complete the installation)
4.Install other antivirus progs (nod 32-bit diffender- virus fighter) (could not complete installation)
5 fixes tools from microsoft - not worked -it was stacking in certain point
6. Antispy prog could make a scan and find this results

Infections found running Trojan remover (trial edition)

Worm-Email.Bagle (General Components)
Malware (General Components)

Infected registry keys/values detected
hkey_current_user\software\datetime4\
hkey_current_user\software\datetime4\port\
hkey_current_user\software\datetime4\uid\
hkey_current_user\software\datetime4\wdrn\
hkey_current_user\software\microsoft\windows\currentversion\run\german.exe\
Malware (General Components)
Infected registry keys/values detected
hkey_current_user\software\firstrrrun\
hkey_current_user\software\microsoft\windows\currentversion\run\drvsyskit\
Looking into registry found the folder datetime and firstrrun and deleted manually but not the other references
the prog deleted the rest but after rebooting and scanning i was back in the previous situation
I rebooted into safe mode to try to run hijack this in order to post the log in avira (in normal mode was stopping the scan in certain point)
my screen was freezing and i had to start new session - I was intented to type explorer but system 32 oppened and showed me (strange enough i think) a folder which was named in blue letters and almust the same name as the abobe folder windrivers(this not appeared in the system in normal mode) I oppened and looked into a file wich could open with text editor. It seemed to be the programming for the virus ( i am sorry not to keep a copy of this to post here) I remember that in first lines the autor was a name with guru extention )
Selecting the text i removed all the references then deleted the file and then the entire folder.
The results of my action. The select something to patch desapeared and also the install file mentioned before - My computer seemed to run normal but i took blue screen twice ( I think this was dew to many incoplete installations so i runned an unistaller wich removed them from registry )
The last problems that remain
1. I can run hijack in normal mode but i cant run delete or remove the combofix from my destop - when clicking starts loading for almust 2 minutes and then says is not win32 application.
2 I cant run an online scan
3 I can't run any antivirus
3 I cant open some hiden folders - the message is i dont have rights.


I have compleded the five steps I will wait instruction on what to do
In any case i can record what i am doing and send the swf file to have a clear image of my problem
Thanks for your time
joia is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 02:13 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85