• WELCOME
Welcome to the Myantispyware - free site offering help and assistance on spyware, malware and adware removal. As a guest you can only browse and view the various topics in the forums, but can not create a new topic and reply to an existing topic. If you are seeking help, you will need to be a logged into the forums with a registered account. Registering is free.
Click here to Create a free account and read How to use Spyware Removal Forum

Desprate! can't download hijack this or avenger

This forum is for removing Malware, Spyware, Adware. Post your HijackThis, DDS, RSIT, Combofix logs here.

Moderator: Moderators

Desprate! can't download hijack this or avenger

Postby papachetos » Tue May 05, 2009 8:51 am

Desprate I don't know what type of virus I have but its something cause I can't go to certain internet sites, and when I use search engine for Msn or yahoo and I click on links it take me to advertising pages. My computer is also running slow and it shouldn't cause I have DSL. I tried downloading Hijack this and the rest but can't and I do not have access to another computer. I read a situation similiar to mine and was able to get this log for you patrick hope I did it right! Please help!@
Attachments
virusinfo_syscheck.zip
(30.83 KiB) Downloaded 86 times
papachetos
 
Posts: 7
Joined: Tue May 05, 2009 8:03 am

Re: Desprate! can't download hijack this or avenger

Postby patrik » Wed May 06, 2009 2:07 pm

Hello papachetos, welcome to the Myantispyware forum.

Close all windows.
Run AVZ.
Click File > Custom scripts
Copy & paste the text in the code box below into textarea:
Code: Select all
begin
QuarantineFile('brastk.exe','');
QuarantineFile('C:\WINDOWS\svcho.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL','');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DeleteFile('C:\WINDOWS\svcho.exe');
BC_DeleteFile('brastk.exe');
RebootWindows(true);
end.

Click Run.
AVZ should run and may restart your computer. Restart your PC if it doesn't do it automatically.

Post back with a new AVZ report.
patrik
Site Admin
 
Posts: 8425
Joined: Sun Jan 08, 2006 1:11 pm

Re:NEW AVZ ReportDesprate! can't download hijack this or ave

Postby papachetos » Thu May 07, 2009 5:05 am

here is the new report! hope it helps!!!
Attachments
virusinfo_syscheck.zip
(20.82 KiB) Downloaded 119 times
papachetos
 
Posts: 7
Joined: Tue May 05, 2009 8:03 am

Re: Desprate! can't download hijack this or avenger

Postby patrik » Fri May 08, 2009 2:44 pm

Close all windows.
Run AVZ.
Click File > Custom scripts
Copy & paste the text in the code box below into textarea:
Code: Select all
begin
SetAVZPMStatus(True);
RebootWindows(true);
end.

Click Run.
AVZ should run and may restart your computer. Restart your PC if it doesn't do it automatically.

Run AVZ again. Click File > Custom scripts. Copy & paste the text in the code box below into textarea:
Code: Select all
begin
SearchRootkit(true, true);
QuarantineFile('C:\WINDOWS\system32\brastk.exe','');
QuarantineFile('C:\WINDOWS\svcho.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL','');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DeleteFile('C:\WINDOWS\svcho.exe');
DeleteFile('C:\WINDOWS\system32\brastk.exe')
DelAutorunByFileName('brastk.exe');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DelAutorunByFileName('C:\WINDOWS\svcho.exe');
BC_ImportDeletedList;
BC_LogFile(GetAVZDirectory + 'boot_clr.log');
BC_Activate;
ExecuteSysClean;
SaveLog(GetAVZDirectory + 'avz_log.txt');
RebootWindows(true);
end.

AVZ should run and may restart your computer. Restart your PC if it doesn't do it automatically.

Make a fresh AVZ report.

Post back with AVZ report (virusinfo_syscheck.zip) + include a content these files: avz_log.txt and boot_clr.log. Both files located in the AVZ home folder.
patrik
Site Admin
 
Posts: 8425
Joined: Sun Jan 08, 2006 1:11 pm

Re: Desprate! can't download hijack this or avenger

Postby papachetos » Sat May 09, 2009 6:38 am

I tried running the second instruction you gave me but for some reason it say error " ' " 11.1, 3.1, & 10.1
papachetos
 
Posts: 7
Joined: Tue May 05, 2009 8:03 am

Re: Desprate! can't download hijack this or avenger

Postby patrik » Sat May 09, 2009 2:20 pm

I have missed one ";".

Please repeat step 2. Use following script.
Code: Select all
begin
SearchRootkit(true, true);
QuarantineFile('C:\WINDOWS\system32\brastk.exe','');
QuarantineFile('C:\WINDOWS\svcho.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL','');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DeleteFile('C:\WINDOWS\svcho.exe');
DeleteFile('C:\WINDOWS\system32\brastk.exe');
DelAutorunByFileName('brastk.exe');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DelAutorunByFileName('C:\WINDOWS\svcho.exe');
BC_ImportDeletedList;
BC_LogFile(GetAVZDirectory + 'boot_clr.log');
BC_Activate;
ExecuteSysClean;
SaveLog(GetAVZDirectory + 'avz_log.txt');
RebootWindows(true);
end.
patrik
Site Admin
 
Posts: 8425
Joined: Sun Jan 08, 2006 1:11 pm

Re: Desprate! can't download hijack this or avenger

Postby papachetos » Mon May 11, 2009 12:18 pm

Still posting error message 21.1 I guess another comma is missing?
papachetos
 
Posts: 7
Joined: Tue May 05, 2009 8:03 am

Re: Desprate! can't download hijack this or avenger

Postby patrik » Mon May 11, 2009 2:17 pm

Just checked the script at my computer, its ok.

Please try again, after "end", script should have ".". Maybe you have missed it.
patrik
Site Admin
 
Posts: 8425
Joined: Sun Jan 08, 2006 1:11 pm

Re: Desprate! can't download hijack this or avenger

Postby papachetos » Tue May 12, 2009 10:35 am

ok I guess that was it sorry I got the files you requested!
Attachments
boot_clr.log
(303 Bytes) Downloaded 70 times
avz_log.txt
(3.56 KiB) Downloaded 108 times
virusinfo_syscheck.zip
(20.82 KiB) Downloaded 106 times
papachetos
 
Posts: 7
Joined: Tue May 05, 2009 8:03 am

Re: Desprate! can't download hijack this or avenger

Postby patrik » Tue May 12, 2009 2:13 pm

If you have previously downloaded ComboFix, please delete that version now.
Download Combofix from here. Close any open browsers. Double click on combofix.exe and follow the prompts.

Post back with combofix log.
patrik
Site Admin
 
Posts: 8425
Joined: Sun Jan 08, 2006 1:11 pm

Re: Desprate! can't download hijack this or avenger

Postby papachetos » Fri May 15, 2009 11:42 am

have been trying to download program but the internet page keeps giving error!!!!! what else can i do?
papachetos
 
Posts: 7
Joined: Tue May 05, 2009 8:03 am

Re: Desprate! can't download hijack this or avenger

Postby papachetos » Fri May 15, 2009 11:06 pm

Ok I was able to disable the TDSServ trojan and download combo fix
Attachments
ComboFix.txt
(9.2 KiB) Downloaded 155 times
papachetos
 
Posts: 7
Joined: Tue May 05, 2009 8:03 am

Re: Desprate! can't download hijack this or avenger

Postby patrik » Sun May 17, 2009 12:08 pm

Looks ok. Only remove a few malware files.
Open notepad, copy/paste the text in the code box below into notepad:
Code: Select all
File::
c:\windows\system32\TDSSfpho.dll
c:\program files\Common Files\diqixop.db
c:\program files\Common Files\bobawe.sys
c:\program files\Common Files\ysirolafe.exe
c:\program files\Common Files\fusaje.inf
c:\program files\Common Files\vekeky.scr
c:\program files\Common Files\yzemoqop.bin
c:\program files\Common Files\vajis.sys

Name the Notepad file CFScript and Save it to your desktop. Then drag the CFScript into ComboFix.exe as you see in the screenshot below.
Image
When finished, it will produce a report for you.

Post back with a combofix log.
patrik
Site Admin
 
Posts: 8425
Joined: Sun Jan 08, 2006 1:11 pm


Return to Spyware Removal

Who is online

Users browsing this forum: Google Adsense [Bot], patrik and 2 guests