BleepingComputer.com: Virus - bearshare, bondoo, AVS, cyberlink, iMesh?

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Virus - bearshare, bondoo, AVS, cyberlink, iMesh?

#16 User is offline   Nile 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 79
  • Joined: 16-February 09

Posted 02 December 2010 - 05:54 PM

Sorry for being unclear - HJT fails to remove these entries.

#17 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,761
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 02 December 2010 - 06:43 PM

Ok we have MBAM installed.
Let's use MBAM's FileAssassin feature.

Open MBAM again.
    Click the More Tools tab and then the Run Tool button
    Now browse to the file(s) we want to remove using the drop down box next to Look in: at the top.
    Locate the file(s), click Open.
    You will be prompted with a message warning: This file will be permanently deleted. Are you sure you want to continue?. Click Yes.
    If removal did not require a reboot, you will receive a message indicating the file was deleted successfully, however, I recommend you reboot anyway.


Quote

Caution: Be careful what you delete. FileAssassin is a powerful program, designed to move highly persistent files. Using it incorrectly could lead to disastrous problems with your operating system.

How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#18 User is offline   Nile 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 79
  • Joined: 16-February 09

Posted 02 December 2010 - 08:12 PM

Thank you!
Sorry for all the questions. When I look in HJT now after all the files I delete it says (file missing) but the value is still in the registry - is this bad or is it fine?

As browsing through the files with FileASSASIN I noticed that there were still programs such as BearShare and other things that came from BearShare on the computer, should I also FileASSASIN these? They dont show up in revo uninstall or the control panel uninstaller.

Thanks!

#19 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,761
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 02 December 2010 - 08:54 PM

Yes you can kill the missing and then the Bearshare.
Back up the registry first Just in case.

Go to Start » Run and type: regedit
Click OK.
On the left side, click to highlight My Computer at the top.
Go up to File » Export
Make sure in that window there is a tick next to "All" under Export Branch.
Leave the "Save As Type" as "Registration Files".
Under "Filename" put RegBackup.
Choose to save it to C:\
Click save and then go to File » Exit.

Or you can download and use ERUNTwhich is an excellent free tool that allows you to to take a snapshot (backup) of your registry before making changes and restore it when needed.
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#20 User is offline   Nile 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 79
  • Joined: 16-February 09

Posted 02 December 2010 - 10:36 PM

Okay - thanks. I'll do this tomorrow afternoon. Thanks for all your help!
When you say scan weekly - what should I scan with? Avast, MBAM and SuperAntiSpyware? Also - what programs that I've installed now can I uninstall?

Thanks

#21 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,761
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 02 December 2010 - 11:05 PM

Yes scan with those 3. You can remove everything else.
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users