WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

2 posters

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Don't bother trying to run BlueScreenViewer. It was the Recovery Console that was giving you a black screen on start-up. Actually, the recovery system is a good thing to have on your computer but if you don't want it, you can uninstall it.
windows\system32\command Parameters are not correct

I think this has something to do with Spybot S&D. If it continues, you should try uninstalling Spybot.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Superdave wrote:
Don't bother trying to run BlueScreenViewer. It was the Recovery Console that was giving you a black screen on start-up. Actually, the recovery system is a good thing to have on your computer but if you don't want it, you can uninstall it.
windows\system32\command Parameters are not correct

I think this has something to do with Spybot S&D. If it continues, you should try uninstalling Spybot.


Yes, I definitely do want the recovery system please. So, if I should I will do that fix for the Recovery Console you had posted. Let me know.

In reference to Spybot S&D, I got a box message once my computer booted up this morning.

It said:
"Spy Bot has detected an important registry entry that has been changed.
Catagory: System Startup user entry
Change: Value deleted
Entry: SpybotDeletingD5539
Old Data: cmd.exe /c del "C: \Documents and settings \ " and then it didn't show the rest.

It seems like this might be related to the above message I sent where you thought it was Spybot related.

If I uninstall Spybot will it put back all the viruses, trojans, etc.? Also, will it mess up my computer where I am unable to get on? (this is my only computer) Should we fix what Spybot was saying this morning?

Also, are you going to be here over this Labor Weekend? Just checking, I will be, but I know people need time off too

Thank you

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Yes, I definitely do want the recovery system please. So, if I should I will do that fix for the Recovery Console you had posted. Let me know.

If you want to leave the RC, you don't have to do anything. If you want to remove it, follow the instructions I gave you.
If I uninstall Spybot will it put back all the viruses, trojans, etc.? Also, will it mess up my computer where I am unable to get on? (this is my only computer) Should we fix what Spybot was saying this morning?

You should uninstall Spybot and leave it off for a few days to see how things work. Your computer is clean and removing it won't affect the computer, malware-wise. I have no holidays.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

Well, I just have a few more programs to update through that Secunia Software and it's done.

My computer is running pretty good. Faster then it has for quite a while.

Is there anything else we need to do or undo?

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

I guess my above post was jumping the gun.

I don't know what happened, but some how my my System Restore got turned off by some thing or some program. I went to do a system restore and I only have todays date without a restore point. I click to go to August and it won't let me. Did all my previous restore points get deleted in my System Tools?

Also, when I type in a web address to go to, it doesn't try to connect the first time, then I have to hit enter again (I realize this one is a small thing). Finally, Wednesday morning I tried Game House again and couldn't get into it still, but in the afternoon after I had installed Spyware Blaster, Spybot and something else Game House would come up. Now this morning, I can't access it again.

Thanks

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Is there anything else we need to do or undo?

No, that's about it.
I click to go to August and it won't let me. Did all my previous restore points get deleted in my System Tools?

That happens when ComboFix is uninstalled. The reason why we do that is because malware can hide in System Restore and by doing a SR, you're infecting your computer all over again.
Finally, Wednesday morning I tried Game House again and couldn't get into it still, but in the afternoon after I had installed Spyware Blaster, Spybot and something else Game House would come up. Now this morning, I can't access it again.

Something is blocking it but I don't really know what.

Download HostsXpert

•Unzip HostXpert to your Desktop

•Open up the HostXpert program.

•Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.

•Click Create Back Up

•Then click on Restore Microsoft's Host Files

•Close the HostXpert program

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

I don't have an unzipping program. My Winzip trial expired. Is there a free unzipping program?

Thanks

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
7-Zip

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

Thanks for the 7-Zip program.
I opened HostX and when I clicked on the Restore MS host files I came up with the following error:

Cannot creat file C:\WINDOWS\system32\DRIVERS\ETC\hosts

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Can you please check with your ISP(internet service provider) and ask them if Gamehouse.com is being blocked by them?

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

I just checked with them and tech support said "Absolutely not. Century Link does not block any web sites". Then she said that I should check my computer for any blocks and to see if I need to clear anything out, etc.

That HostX program that comes up with that error, that seems to me that it is and important thing. Is there a way to fix that?

Thank you

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Sorry for being so late in getting back to you. It's quite possible that you have been banned from Gamehouse. You should contact them about this.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
"That HostX program that comes up with that error, that seems to me that it is and important thing. Is there a way to fix that?"

The above is from my Sept. 6th post.

I'll check with them, but I've heard they have some kind of virus...I will check though.



descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Please try this:

Please download the following batch file and save it to your desktop: HostsPerm.bat Download Link

When the file has finished downloading, double-click on the HostsPerm.bat file that is now on your desktop. If Windows asks if you if you are sure you want to run it, please allow it to run. Once it starts you will see a small black window that opens and then quickly goes away. This is normal and is nothing to be worried about.

Reset Hosts File:

* Go to Start > Run and type Notepad.exe then click OK
* Copy and Paste everything from the Code Box below into Notepad:

Code:

@Echo off
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1  localhost>HOSTS
attrib +r +h +s hosts
popd
del %0


* Go to File > Save As
* Save File name as Reset.bat
* Change Save as Type to All Files and save the file to your desktop.

On the desktop double click the Reset.bat to run the batch file. It will self-delete when completed.

Download HostsXpert

•Unzip HostXpert to your Desktop

•Open up the HostXpert program.

•Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.

•Click Create Back Up

•Then click on Restore Microsoft's Host Files

•Close the HostXpert program

Note: if you use SpywareBlaster, Spybot and/or IE-SPYAD, it will be necessary to re-install the protection they afford. For SpywareBlaster, run the program and select Enable all protection. For Spybot run the program and select Immunize. For IE-SPYAD, run the batch file and reinstall the protection.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

I'm still getting the following error when I click on Restore Microsoft's Host Files.

Cannot creat file C:\WINDOWS\system32\DRIVERS\ETC\hosts.

Let me know what I should do.

Thanks

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Are you sure that you're doing this?
Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

Yes, I'm sure.

This is what I see...

It's a big box that's white and it has a left hand column.

The titles in the column are:

File Handling (to the right of that is a picture of a pencil)

"Make Read only?" and it shows an unlocked lock (because it's writeable)
"Make Writeable?" and it shows a locked lock (so I can't write)

Backup/Restore

Import Options

Restore MS Hosts Files

File Handling

Editing

Download

Tools

Help

I've tried it both ways (I've always done it with the lock unlocked). When it's locked I can't create a backup.

So, with the lock unlocked I'm able to click on the Backup/Restore button and create a backup. Then it confirms that did happen.

Then I go to Restore MS Hosts File and it asks if I want to do this I click on OK and then the error appears.

I believe I'm doing it correctly, but if I'm not, please tell me what I'm doing wrong.

Thanks

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Please try the information in this link to set your hosts file back to default.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

I went to the link and clicked on the icon so it would make the changes automatically.

What should I do now?

Thanks

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Click on the FixIt icon and when the box comes up click Run and follow the directions.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Superdave wrote:
Click on the FixIt icon and when the box comes up click Run and follow the directions.


Hi Dave,

I'm sorry, I didn't explain myself properly. I already did this when I click on the icon. I did run the fix it program.

Is there something else I need to do to check it...or do I need to run any reports for you?

Thanks

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
I did run the fix it program.

Is there something else I need to do to check it...or do I need to run any reports for you?

Sorry. I've never run this program before. Could you describe to me what happens after you let it run?

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

I'm sorry I hadn't been on sooner, I've been ill.

Anyway, I just clicked on the icon for it to run. It did run and that was it. That's why I was wondering if there was some way I should check it or something.

Thanks

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Anyway, I just clicked on the icon for it to run. It did run and that was it. That's why I was wondering if there was some way I should check it or something.

That should have reset your hosts file. It's been so long. Do you have any more problems with your computer?

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

Just little things that weren't there before, so other than those, nothing else.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
reginaac wrote:
Hi Dave,

Just little things that weren't there before, so other than those, nothing else.

That's good. Just do the cleanup I suggested earlier in this thread and you're good to go.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
Hi Dave,

I want to thank you so much for all of your help. I really appreciate everything you've done.

Sincerely,
Gina

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
reginaac wrote:
Hi Dave,

I want to thank you so much for all of your help. I really appreciate everything you've done.

Sincerely,
Gina

You're welcome, Gina. I will lock this thread. If you need it re-opened, please send me a pm.

descriptionTrojan.Dropper, Trojan.Generic, Trojan.Crypt and more - Page 2 EmptyRe: Trojan.Dropper, Trojan.Generic, Trojan.Crypt and more

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum