Forum Topic

TPC Virus & Spyware Removal Thread (must read page 1)




  • Thread Reminders:
    1. Before posting your issue, please try to initially read the first page of the thread. <click here for link>
    2. Keep the thread clean. And stick to the topic.
    3. Be patient. You don\'t have to repeat yourself. There are other people who can also answer your inquiry aside from the VSRT members. Most of us are volunteers in other sites too and we stop by here to help if we can steal more time from real life and our families, so please be patient. Then we look quickly for folks with no replies to help out. We hope you understand.
    4. Don\'t post links to warez and cracks, doing so may get you banned.
    5. When posting pictures of screenshots and other things related to the topic, please limit it to 640x480 pixels. Anything beyond that will be reported to our mods for immediate deletion.
    6. Upload your HiJackThis and/or other logs to our 4Shared account, and create a folder with your name in it. <click here for link>
    7. If our tools are detected as virus (like Win32/Packed.Themida), exclude the tool to be scanned by your antivirus. Better yet disable your AV temporarily as you run the tool/s.
    8. Our fixes are implied without warranty. Use at your own risk.
    9. No spoonfeeding and text speak here in the forum and anywhere else in TipidPC/CP.
    10. Please don\'t email or PM anyone from the VSRT members for \"personal\" HJT/virus help. We all benefit when a problem is discussed in the open.
    11. Not all error/s you get in Windows is/are caused by a virus. If this is so, then your issue will be out of the topic. However, we can still help you figure out if it is a virus problem or not, but then afterwards you may look for another forum for a solution.
    12. Sorry, but we can not provide support for those using illegitimate and/or unlicensed Software. As much as possible, we keep piracy to a minimum or zero level at all times.
    13. Those who violate the TPC-VSRT Rules and Regulations will be ignored of their issue, unless they manage to correct their mistake/s.
    14. People who may be interested in joining the TipidPC Virus & Spyware Removal Team may PM me (Yohan831)
    15. We are not 24/7 online, and we are a non-profit, all-volunteer group. If you cannot wait for us to get a solution, better ask another forum instead of wailing wildly and complaining.
    16. The TPC-VSRT thread cannot be utilized as a source of information for income-generating purposes such as Malware removal services and the like, and other unnecessary means. Any actions undertaken may lead to banning from this thread.


    Here are some steps that you may need to do first so we can assist you better:

    Intructions before posting your Malware issue
    1.Update your Antivirus
    2.Download MalwareByte\'s Anti-Malware Install and Update
    3.Download SuperAntispyware Install and Update
    4.Disconnect from the Internet
    5.Back-up important files
    6.Disable Sytem Restore
    7.Do a Full System Scan with your Antivirus
    8.Do a Full System Scan using MalwareByte\'s Anti-Malware(if prompted to restart do so)
    9.Do a Full System Scan using SuperAntiSpyware(if prompted to restart do so)
    10. If you think you are still infected Scan your system with HijackThis or QuickSmash

    Using HijackThis
    1.Download HijackThis Executable: <click here for link>
    2.Close all running applications and scan your system with HijackThis
    3.Save and Upload your HJT Logs in our 4Shared Account.
    4.Post the Download link of the log here along with your Malware issue.

    How to Upload HJT Logs
    1. Go to our 4Shared Account: <click here for link>
    2.Click on the Hijackthis logs folder
    3.Click on the folder with the green plus (+) icon (Create a new folder)
    4.When asked for a name, type in your tpc username, and click OK.
    5.Now click on your newly created folder
    6.Click Browse (on the lower part of the screen)
    7.Find your hijackthis log and select it.
    8.Click Open and then Upload
    9.Now it will say Uploaded successfully
    10.Right click on the Download link for the file, and click Copy Link Location (for Firefox Users) or Copy Shortcut (for Internet Explorer users)
    11.Paste the webpage on the thread and notify us if you have done so already.

    Do not post your hijackthis log directly in the thread.

    \"Quicksmash Assistance\" Developed by t68kv

    1. Download Quicksmash, after downloading open it.
    2. Check \"include hijackthislog\", \"Update Before Smashing\".
    3. Follow the steps on uploading the log created by the quicksmash.
    Wait for the \"Finish\" message, and follow the instruction on the next messageboxes.
    Usually the filename is named at the current date on you computer. EX \"13-08-2008\"
    4. Post the link, The link must be working for fast response from the team.
    5. Wait For Response Or Further Instruction From T68KV or Other Reliable Team Member.
    Usually they will tell you to redo the instruction. After Updating the Defintion.
    6. Download Quicksmash from here: <click here for link>


    Disclaimer:
    NEITHER THE TEAM OR ANYONE DIRECTLY CONNECTED IN PUBLISHING FIXES FOR YOUR PC SHALL MAKE ANY WARRANTY EITHER EXPRESSED OR IMPLIED. FURTHER, NEITHER THE TEAM OR ANYONE HELPING OUT SHALL BE LIABLE FOR ERRORS OR OMISSIONS CONTAINED HEREIN, OR FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES. THE FIXES ARE PROVIDED \"AS-IS\", AND THE READER/MEMBER BEARS ALL RESPONSIBILITIES AND RISKS CONNECTED WITH IT\'S USE.


    TipidPC Virus and Spyware Removal Team website: <click here for link>
    Feel free to leave your comments and suggestions!

    ===============================================

    \'The TipidPC - Virus & Spyware Removal Core Team Members\'
    March 14, 2008
    Core Director - GIGZ_09
    Assistant Director - hotpandesal

    Virus & Spyware Removal Team Committees
    Technical Committee aka Malware Killers - t68kv
    Research & Resource Committee - brwneyes
    Project Development Committee - uchiha_yueh
    Special Projects Committee - fireflyalpha
    Marketing Committee - ParticleX
    Screening Committee - Yohan831

    -------------------------------------------------------------------------------------------------------
    We are open for accepting new Active members, interested parties may PM GIGZ_09, or visit <click here for link> thank you
    -------------------------------------------------------------------------------------------------------

    -------------------------------------------------------------------------------------------------------
    TipidPC Virus & Spyware Removal Team Official Members
    1. nokie
    2. _enigma_ --- waive
    3. Ronell30
    4. lexlukkia

    Non-official members (under monitoring procedure)
    1. wendywenkz - October 21, 2008


    The TPC Virus Removal Team Pioneer=)


    1. GIGZ_09
    2. owenbaboy
    3. quigonjan
    4. ParticleX
    5. swat
    6. fireflyalpha
    7. hotpandesal
    8. Yohan831
    9. SOMER
    10. kenshinxian
    11. t68kv
    12. nokie
    13. theeye23
    14. uchiha_yueh

    -------------------------------------------------------------------------------------------------------

    fellow TPCers..

    if you are encountering new viruses/trojans/worms(any malicious scripts) or any viruses that always harm your system, or you can suggest what kind of virus should we treat here... just post it here.. then we are here to kick their ass.. :)


    Guidelines for posting your HijackThis logs


    We have created a 4shared account for your uploading site for the logs and images of your virus problems. We expect to use the account wisely. Posting images that depicts gore, adultery, and others that is out of the virus removal will be requested to the admin to be banned. Please PM the necessary Virus & Spyware Removal Team members to request for the link, and instructions will be given alongside with your request for the host site. or you can directly click here <click here for link>

    1. Please post the problem as accurately as you can (Note: Please don\'t use text speak or shortcuts in your post)
    2. Use the 4shared account in posting the logs and the pictures of the malware, if possible (PM us for the password and instructions)
    3. Before posting your log, be sure that you have followed the tips and tools located in the thread to minimize time used.


    Steps in Uploading you log
    1. PM one of the members of Virus Removal Team about the Account name and Password.
    2. Make a folder under the Hijackthis Logs directory.
    3. The created folder should be your TPC nick.
    Note: Only Hijackthis Log files are only permitted to be upload, or else we wil delete it without any notifications, no posting of unrelated files.
    4. Be patient enough while you wait for the results/replies.


    Warning: Please dont post the log here..

    (These guidelines should be followed)

    Format on posting your virus problems
    1. Name of virus (if you dont know, leave it blank)
    2. Description of harmful effects in your system.
    3. Notification for the VSRT members that you\'ve already uploaded the log file or Link of Log.

    Example:
    1. bar311.exe
    2. Shutdowns my system everytime i access my command prompt.
    3. sir ParticleX could you analyze my log, my folder name is GIGZ_09


    Disclaimer:

    NEITHER THE TEAM, NOR ANYONE DIRECTLY CONNECTED IN PUBLISHING FIXES FOR YOUR PC SHALL MAKE ANY WARRANTY EITHER EXPRESSED OR IMPLIED. FURTHER, NEITHER THE TEAM SHALL BE LIABLE FOR ERRORS OR OMISSIONS CONTAINED HEREIN, OR FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES. THE FIXES ARE PROVIDED AS-IS, AND THE READER/MEMBER BEARS ALL RESPONSIBILITIES AND RISKS CONNECTED WITH IT\'S USE.


    Note: as much as possible or procedures/steps that will be post here is in manual procedure. we are not encouraging users to change their AV installed on their systems.

    ________________________________________________________________

    suggestion of useful applications are also welcome here..

    ______________________________________________________________

    Note: Please don\'t email or PM the Virus & Spyware Removal Team-members for \"personal\" HJT/virus help. We all benefit when a problem is discussed on the open forum.

    -- edited by GIGZ_09 on Dec 22 2008, 06:25 PM

    -- edited by GIGZ_09 on Dec 29 2008, 10:17 PM

    -- edited by GIGZ_09 on Jun 23 2010, 12:51 PM
  • Virus / Spyware Cleanup & Prevention, READ THIS FIRST for tips and tools

    Virus and Spyware Removal Team Applications:




    QUICKSMASH ASSISTANCE

    1. Download quicksmash, after downloading open it.
    2. Check \"include hijackthislog\", \"Update Before Smashing\".
    3. Follow the steps on uploading the log created by the quicksmash.
    Wait for the \"Finish\" message, and follow the instruction on the next messageboxes.
    Usually the filename is named at the current date on you computer. EX \"13-08-2008\"
    4. Post the link, The link must be working for fast response from the team.
    5. Wait For Response Or Further Instruction From T68KV or Other Reliable Team Member.
    Usually they will tell you to redo the instruction. After Updating the Defintion.

    Quicksmash
    <click here for link>

    This thread has the information you need to fix and prevent problems with spyware and viruses. If you\'re new to the forums, please read through it before asking questions or (especially) posting HijackThis logs.

    CONTENTS OF THIS THREAD

    1) Simple steps to remove spyware and viruses.
    2) Where to find the tools you need.
    3) More spyware and virus information.

    +_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+

    Simple steps to removing spyware and viruses - Follow these steps and your PC will be fine in no time! Links to the tools mentioned here can be found also here.

    1) Back up valuable data. If the virus or spyware is deeply imbedded in the system, or the cleanup does not go well, your system may need to be reformatted and reinstalled..

    2) Try automated detection and cleanup. Some spyware and viruses disable scanners or prevent them from working properly, so you may be infected even if you have a spyware scanner installed. Download and run the latest versions of Ad Aware and Spybot S&D and try one or more online scans from the next post.

    3) Try a special-purpose cleanup tool. There are specialized fixes such as CWShredder for removing CoolWebSearch. If a scanner reports that you have a particular spyware or virus but is unable to clean it, see whether one of the manual tools like McAfee Stinger can clean it. The download pages for these tools (see next post) list the problems they can fix.

    4) Try HijackThis last. If you have tried the automated tools but still think you may have spyware or a virus, you can upload HijackThis scan log (only!) in this URL http://tpc-virus-removal.4shared.com <click here for link>. Because HJT requires special training to interpret the results and can take some time for even a knowledgable person to interpret, only post a scan after having tried the automated solutions. Be sure you have downloaded the latest version of HijackThis before running it and posting your scan.

    +_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+_+

    Where to find the tools you need - We have used and recommend these tools. If you are unsure of what has invaded your system, we advise that you run more than one cleanup tool. Take a look at the questions posted here in the forums, and don\'t be shy about asking for help if you need it!

    Please be careful when selecting anti-spyware and anti-virus programs. Some of them can make your problems even worse! Unless otherwise indicated, the tools below are FREE or available as trial/shareware versions. If you have questions ask about it on the forums. AVOID THESE PRODUCTS: <click here for link>

    Online Virus and Spyware Scans:

    TrendMicro: <click here for link>
    Bitdefender: <click here for link>
    Kaspersky: <click here for link>
    Panda ActiveScan: <click here for link>
    F-Secure: <click here for link>
    Jotti Online Malware Scanner (this website tests your PC with 22 scanners, which makes it comprehensive): <click here for link>


    Spyware Scan and Cleanup:

    Ad-Aware SE - Scan and clean spyware
    <click here for link> - Download
    <click here for link> - Ad-Aware Tutorial - A MUST READ!

    Spybot Search & Destroy - Scan and clean spyware
    <click here for link> - Download
    <click here for link> - Tutorial, A MUST READ!
    <click here for link> - Frequent Questions

    HijackThis - THE LAST STEP in spyware cleanup

    <click here for link> - Download
    <click here for link> - Alternative Download


    Antivirus Products:

    Avast! 4 Home A/V: <click here for link>
    AVG A/V Free: <click here for link>
    AntiVir Personal Edition A/V: <click here for link>

    Specialized Cleanup Utilities:

    Kaspersky: <click here for link>
    Symantec: <click here for link>
    Avast: <click here for link>
    AVG: <click here for link>
    F-Secure: <click here for link>
    McAfee: <click here for link>
    Panda: <click here for link>

    Virus and Spyware Prevention:

    <click here for link> - Windows Update (IMPORTANT!) note: we can\'t help users who are using illegitimate operating systems.
    <click here for link> - Spyware Blaster

    File Identification:

    <click here for link> - PCPitstop
    <click here for link> - Bleeping Computer
    <click here for link> - Answers that Work
    <click here for link> - Windows Startup Online
    <click here for link> Tony Klein\'s BHO List


    IMPORTANT

    Just a little information for you first. Most of us volunteer at other sites and we stop by here to help when we can steal more time from real life and our families, so please be patient. Then we look quickly for folks with no replies to help out. I hope this information helps. Thanks.

    Courtesy of ParticleX

    -- edited by GIGZ_09 on Aug 23 2008, 05:04 AM
    <click here for link>
    <click here for link>
    <click here for link>
  • nice thread.. up for you sir..
  • ok to. up for you sir GIGZ!
  • galing sir.. good steps. i agree with the use of hijackthis. karamihan kasi advise lang ng advise at hindi nag-aanalyze. btw.. pls add the download link of hijackthis para mas madali.
  • sir Jesehl and sir jayz13,

    thanks..hope this could really help our fellow TPCers! :)
    __________________________________________________________________________________

    Thread for Viruses, help our community to get rid off viruses:
    <click here for link>

    PIC Microcontroller Tutorial Thread:
    <click here for link>


  • galing sir.. good steps. i agree with the use of hijackthis. karamihan kasi advise lang ng advise at hindi nag-aanalyze. btw.. pls add the download link of hijackthis para mas madali.


    thanks sir, i already included the hijacthis application in my kaizer killer package :)
  • bookmarked!!
  • up
  • @GIGZ: how to use ba ung app mo? la kasing instructions
  • Don\'t forget to include the Noob Killer to the list of great virus killers.

    IMO, this thread must be properly renamed as \"The Virus Removal Thread\" or whatever that will appeal to the masses, especially to users (besides the ones here in TPC) that uses Google, some links are redirected here in TPC, and others may visit this thread frequently for tips on removing new viruses.

    Kudos.

    thanks for the suggestion, balak ko sana if marami na nakakaalam nito and marami na rin ang handang tumulong for virus treatments, then we can start another thread named \"The Virus Removal Thread\"

    about searching the google, i was suprised when one of the member of PCX forum was noted by my kaizer killer, gulat ako dun, syempre masaya din lalo na sa mga positive feedbacks :)

    bout the noob killer, we can use it, nut my purpose in this thread is to share our knowledge on how to remove/treat viruses manually.. para pede rin matuto yung mga users, hindi lang gamit ng gamit ng removal tools :) Correct me if im wrong here

    what do you think sir?

    ma\'am mamelreyes

    thanks for bookmarking the thread :)
  • lupet ng thread!!!

    Bookmarked!!!

    UP for the TS
  • bookmarked!!!
  • @GIGZ: how to use ba ung app mo? la kasing instructions


    sir just open it, dont forget to read the report so that you can see if the virus that you want to get rid off is included in the databases of kaizer killer...it can also removes viruses from flash drives, just plug it and open the kaizer killer, wait till the scanning finished.
  • mga sir parang may virus kasi computer ko.. hindi ko lang sure...
    symptoms nya ay:

    nag eerror yung svchost.exe tapos mag rcp call ata yun tapos after a min shutdown na.
    may tumatakbong rundll32.exe pero nde nakapangalan sa system sa username cya nakapangalan.
    nod32 gamit kong av wala naman na detect.


    winxp po os ko
    baka may naka expirience na nito sa inyo
    tia

    -- edited by nolitolits on Mar 14 2008, 10:09 PM
  • thanks sa mga praises bout starting this kind of thread and also for those who bookmarked :) nakakaiyak :)
  • boomarked

    @GIGZ
    a very nice idea.
  • mga sir parang may virus kasi computer ko.. hindi ko lang sure...
    symptoms nya ay:

    nag eerror yung svchost.exe tapos mag rcp call ata yun tapos after a min shutdown na.
    may tumatakbong rundll32.exe pero nde nakapangalan sa system sa username cya nakapangalan.
    nod32 gamit kong av wala naman na detect.

    baka may naka expirience na nito sa inyo
    tia


    thanks for sharing your experience here.. can you use hijackthis then post the log here..
    thanks...
  • Sa wakas may nag lakas loob din ^_^ sana mabawas bawasan na ang multiple thread \"May virus pc ko need help\" and other similar to any virus problem.

    UP for this topic and bookmark na agad. Try ko din mag contribute into this thread to the latest virus. Popost ko lahat ng ma eencounter ko dito hehehe.
  • Mahirap kasi yung sinasabi mo.. Kaya kasi tumaas ang appeal sa masa ng Noob Killer dahil sa \"automatic\" function nito, in a span of 30 seconds tanggal na ang virus sa PC mo (pati sa Flash Drives/USB) sa isang click lang. Ganito, kung makukumbinsi mo ang isang taong hindi alam tanggalin ang virus sa PC nya (or flash drive na malimit na dahilan ng virus na yan) using your \"manual application\" tool, I will REJECT suggesting Noob Killer anymore and switch to your app.

    I also bookmarked the thread. Will remove bookmark if \"The Official Virus Removal Thread\" will exist.


    ang akin lang po ay para matuto yung mga users, im not discouraging them to use removal tools, para naman den malaman nila kung pano gumalaw ng virus at syempre.. nde sila lagi nagpapatulong.. kasi sila mismo kayang magtanggal and mashashare din nila yung naexperience nila(procedures on how to remove the virus) dito or somewhere else..

    dati gumagamit din po ako ng noob killer, then napaisip ako.. eh pano kung mag-aral ako magremove manually para hindi na ako umasa sa mga removal tools.

    and para sa mga taong walang permanent internet connection atleast they know on how to treat those viruses. without downloading any applications na need pang iupdate if there are new pest! :p
  • Sa wakas may nag lakas loob din ^_^ sana mabawas bawasan na ang multiple thread \"May virus pc ko need help\" and other similar to any virus problem.

    UP for this topic and bookmark na agad. Try ko din mag contribute into this thread to the latest virus. Popost ko lahat ng ma eencounter ko dito hehehe.



    thanks.. gabi lang ako lagi andito but i will try to keep in touch with this thread as much as posible...

    may training kasi ako.. hehheh
  • could we make a list for those TPC members those who are willing to help that we/they can contact if ever they have problems??

    -- edited by GIGZ_09 on Mar 14 2008, 10:21 PM
  • @nolitolits

    parang similar signature ito ng blaster worm at sasser worm.. or pwede ring system error lang. svchost is a windows process that when encounters an error, would cause the system to shutdown.. you can prevent the shutdown by running the command \"shutdown -a\"

    may service pack na ba ang xp mo?

    run hijackthis and post log here.
  • nice one for this


    sa threadstarter sir konting tanong lang paano gamitin yung software... delikado po bang mag delete ng mga files na suspicious. balak ko sana gamitin sa mga partition drives,flash drive, at mga mp3/mp4, cp memory.
  • i think sir quigonjan can be one of those who can help us regarding viruses :P


    sir nolitolits, asan na po yung log?
  • could we make a list for those TPC members those who are willing to help that we/they can contact if ever they have problems??


    add me up. i fix virus problems manually though, usually not relying on antivirus programs. may mga limitations kasi ang antivirus programs.. iba pa rin yung ikaw mismo ang nag-aanalyze.

    -- edited by quigonjan on Mar 14 2008, 10:30 PM
  • sir iverson03,

    thanks just open the application..yes you can delete those files if you think that they are suspicious.. pero kung nag-aalangan ka magtanong ka sa mga masters naten :)

    sir quigonjan.. thanks..
  • The Manually Virus Removal Team =)

    1:
    TPC nick - GIGZ_09
    YM - gcace21 (blue_kaizer, ako din yan, usually at mmb21/60)
    Email - [email protected]

    2:
  • I also do the trick manually, but Noob Killer made things a little bit fast. Hindi naman sa tamad akong tao, pero mahirap magkamali sa diagnosis..

    Dati, may virus akong nakatapat na nung ginawa ko sa HijackThis ang trick, I made the system crash, tama naman ang ginawa ko, pero I never dared to gamble anymore.


    heheh tapos tayo jan =)) we can create also here a batch file of manually removal, so that users can use it also.. para may option sila :)

    thanks, sir just follow the format of the list :)
  • Dati, may virus akong nakatapat na nung ginawa ko sa HijackThis ang trick, I made the system crash, tama naman ang ginawa ko, pero I never dared to gamble anymore.


    hehe.. yeah, sometimes that happens.