Latest posts of: Essexboy
My PC Hell Forum
December 02, 2008, 11:01:03 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Moving to New Location Soon! Watch out for notification. 14th Dec 2007.
 
  Home Help Search Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 57
1  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 18, 2008, 05:16:31 PM
Slight boboo on my part

"RegisteredOrganization"

"RegisteredOwner"

Are in HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion
2  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 18, 2008, 05:13:09 PM
OK open regedit and navigate to the following values in the key described

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\Winlogon

"RegisteredOrganization"

"RegisteredOwner"

"LegalNoticeCaption"

"LegalNoticeText"

"LogonPrompt"

"Welcome"

Open the values and delete the text - do not delete the value itself

i.e.  "RegisteredOwner"  "antichrist"
becomes "RegisteredOwner"

To open a value double click it and you will get the following - clear the data in the box and click OK

3  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 18, 2008, 04:56:15 PM
Would you be happy manually amending your registry ?
4  Windows XP Assistance / General Problems / Re: Office 2003 Won't Uninstall on: April 18, 2008, 04:51:22 PM
Will it allow you to install 2007 over 2003?
5  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 18, 2008, 04:47:22 PM
Has the system returned to normal (but still with the box) .  What is the status on re-boot ?

All that combofix did was replace the default registry values
6  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 18, 2008, 01:35:12 PM
Looks like it, Lets try a different way

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Code:
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"blank"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"blank"=-
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ Explorer]
"NoFolderOptions"=0
[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Window Title"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"Shell"="Explorer.exe"
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"Userinit"="%sysdir%\userinit.exe"
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows NT\ CurrentVersion\ Windows]
"Load"=""
[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Search Page"=""
[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Start Page"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"SFCDisable"=00, 00, 00, 00
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion]
"RegisteredOrganization"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion]
"RegisteredOwner"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"LegalNoticeCaption"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"LegalNoticeText"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"LogonPrompt"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Welcome"=""
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced]
"Hidden"=01, 00, 00, 00
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced]
ShowSuperHidden"=01, 00, 00, 00

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
7  Windows XP Assistance / Security-Virus/Spyware / Re: Trojans failed to disinfect? on: April 18, 2008, 01:29:58 PM
No just run the file - you will need to reboot for it to take effect
8  Windows XP Assistance / General Problems / Re: Office 2003 Won't Uninstall on: April 18, 2008, 01:27:54 PM
Are you able to uninstall 2003 ?
9  Windows XP Assistance / General Problems / Re: Office 2003 Won't Uninstall on: April 17, 2008, 06:03:26 PM
Quote
But EB, I just downloaded latest java a limewire
Did you download it from my link or did you get it via limewire - can you give me exact details of the problems you are experiencing
10  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 17, 2008, 05:51:32 PM
Did you run the vbs programme and then the registry fix ?
11  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 17, 2008, 04:31:39 PM
OK download this VBS file and run it - it should restore your registry.  Once done retry the regfix

 http://cid-32d8666f4048075b.skydrive.live.com/self.aspx/Malware%20files/regtmcmdrestore.vbs

Can you confirm that you have now lost the web pages opening on start
12  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 16, 2008, 04:23:40 PM
There are no tools for deleting this nightmare so I will have to do it manually

Download and run ERUNT  http://www.larshederer.homepage.t-online.de/erunt/

Start ERUNT, confirm the Welcome message.

Type in the name of a restore folder where the backed up registry
files should be saved, or click "..." to browse your computer's drives
and select a folder. You can also simply leave the default, which is a
folder named ERDNT inside your Windows folder, the advantage being
that you have access to this folder from the Windows Recovery Console
in case Windows does not boot anymore.


Next, select the backup options:

- System registry:

- Current user registy: .

- Other open user registries:

Click "OK" and wait until the backup process is complete. (Note that
depending on your system configuration this may take some time, and
that the first bar is NOT a progress bar, just an indicator that the
program is still running.) The ERDNT program for later restoration of
the registry is automatically copied to the restore folder.

WARNING these fixes are designed for this user only and may cause damage if run on an uninfected machine

REGISTRY FIX
Quote
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"blank"=-

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"blank"=-

[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ Explorer]
"NoFolderOptions"=0

[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Window Title"=""

[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"Shell"="Explorer.exe"

[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"Userinit"="%sysdir%\userinit.exe"

[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows NT\ CurrentVersion\ Windows]
"Load"=""

[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Search Page"=""

[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Start Page"=""

[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"SFCDisable"=00, 00, 00, 00

[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion]
"RegisteredOrganization"=""

[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion]
"RegisteredOwner"=""

[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"LegalNoticeCaption"=""

[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"LegalNoticeText"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"LogonPrompt"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Welcome"=""

[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced]
"Hidden"=01, 00, 00, 00

[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced]
ShowSuperHidden"=01, 00, 00, 00


Next you will need to create the repair registry fix to do that copy and paste ALL of the above in the quote box to a notepad file.  Ensure there is no space above the REGEDIT4.
Then in notepad go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES
Then in the FILE NAME box type fix.reg
This will create a fix.reg file on your desktop

To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done.

NEXT

During this run you will loose your desktop

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Code:
KillAll::

File::
C:\WINDOWS\SHELL.EXE
C:\WINDOWS\VXDS.EXE
C:\WINDOWS\system32\SYS.EXE
C:\WINDOWS\system32\OEMINFO.INI
C:\WINDOWS\system32\OEMLOGO.BMP
C:\WINDOWS\system32\BLANK.HTM
C:\WINDOWS\help\HLPS.EXE
C:\WINDOWS\media\WMA.EXE
C:\WINDOWS\media\WINDOWS XP RINGIN.WAV

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.  This will start ComboFix again.




5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
13  Windows XP Assistance / Security-Virus/Spyware / Re: Trojans failed to disinfect? on: April 16, 2008, 04:27:44 AM
Please download this file and run it - let me know the result

http://cid-32d8666f4048075b.skydrive.live.com/self.aspx/Malware%20files/FixShell.cmd
14  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 16, 2008, 04:24:43 AM
Now I need to do a deep search and look for drivers

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt  -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
15  Windows XP Assistance / Security-Virus/Spyware / Re: [Antichrist] [Day of judgment]-I really need help on: April 15, 2008, 06:13:16 PM
Here I be    This looks like a fun one as it does a lot of registry changes

So lets go to work - I will do some exploratory removal first and progress from there

Please download ComboFix from Here or Here to your Desktop.

**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:






  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-----------------------------------------------------------
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.[/color]
    -----------------------------------------------------------
  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
-----------------------------------------------------------
  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you. 
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Pages: [1] 2 3 ... 57
Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC Valid XHTML 1.0! Valid CSS!