Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Affected with W32.gaobot.worm.gen.u [Solved]


  • This topic is locked This topic is locked

#91
Tweene

Tweene

    Trusted Helper

  • Malware Removal
  • 1,387 posts

I dont understand why it shows in the Porgrams and Features in the Control Panel.


You (or maybe a member of your familly) installed it, it appears in the first Combofix log :

2009-09-20 15:28:44 . 2009-09-20 22:38:43 0 d-----w- C:\HijackThis
2009-09-20 15:07:02 . 2009-09-20 15:07:02 0 d-----w- C:\Program Files\Trend Micro


Let me check something before giving you a new set of instructions.
  • 0

Advertisements


#92
bengaluru

bengaluru

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Thanks Tweene. I know I had installed it the day I started this thread, assuming that you guys would want me to send you the logs. I was just being proactive.

I will wait for your instructions.
  • 0

#93
Tweene

Tweene

    Trusted Helper

  • Malware Removal
  • 1,387 posts
Ok.


Step 1

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    HijackThis.*
    :folderfind
    HijackThis
    Trend Micro
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Step 2

Please download SWReg from here and save it to your desktop.

Please copy (Ctrl +C) and paste (Ctrl +V) the text in the code box below to Notepad
swreg acl HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis >> perms.txt
Save it as FixReg.bat and save it in your desktop.
Locate FixReg.bat and run it. It should be quick.
Then, please post the content of perms.txt (it is on your desktop)
  • 0

#94
bengaluru

bengaluru

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Hi Tweene,

SystemLook Log

SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 09:21 on 24/10/2009 by Nidhi (Administrator - Elevation successful)

========== filefind ==========

Searching for "HijackThis.*"
No files found.

========== folderfind ==========

Searching for "HijackThis"
No folders found.

Searching for "Trend Micro"
No folders found.

-=End Of File=-

Perms.txt

*******************************************************************************
Registrykey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis

Permissions:
*******************************************************************************
Username
Type Permissions Inheritance
*******************************************************************************
NIDHIPC\Users
Allowed Read This Key Only (Inherited)
NIDHIPC\Users
Allowed Special (Unknown) Subkeys only (Inherited)
NIDHIPC\Administrators
Allowed Full Control This Key Only (Inherited)
NIDHIPC\Administrators
Allowed Special (Unknown) Subkeys only (Inherited)
NT AUTHORITY\SYSTEM
Allowed Full Control This Key Only (Inherited)
NT AUTHORITY\SYSTEM
Allowed Special (Unknown) Subkeys only (Inherited)
\CREATOR OWNER
Allowed Special (Unknown) Subkeys only (Inherited)

Not enough privileges for Auditing

Owner: Administrators (NIDHIPC\Administrators)
  • 0

#95
Tweene

Tweene

    Trusted Helper

  • Malware Removal
  • 1,387 posts
Hum I get the same log with my computer and I can uninstall it.


If Hijackthis.exe is not on your computer, you can't uninstall it : windows should just ask you if you want to remove the entry from the Programs and Features. But it does not ...

Can I have a screenschot of the error message ? (when you try to uninstall Hijackthis)


Please run again FixReg.bat but with this new script :

swreg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis >> test.txt

And please post the log test.txt.
  • 0

#96
bengaluru

bengaluru

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Hello Tweene.

Here is the new test.txt

SteelWerX Registry Console Tool 3.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\hijackthis
DisplayName REG_SZ HijackThis 2.0.2
UninstallString REG_SZ "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
DisplayIcon REG_SZ C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
DisplayVersion REG_SZ 2.0.2
Publisher REG_SZ TrendMicro

Also attached is the screen shot.

HijackThis.jpg
  • 0

#97
Tweene

Tweene

    Trusted Helper

  • Malware Removal
  • 1,387 posts
Hi


Ok, there are many possibilities, let's try this :


Download and install Revo Uninstaller
  • Double click the Revo Uninstaller icon on your desktop to start the program
  • Scroll through the listed programs and Right Click on the program you wish to uninstall
  • From the pop out menu choose Uninstall
  • Click Yes to the confirmation dialogue
  • In the next window select the Advanced mode
  • Click Next to start uninstalling the program
  • Answer Yes to confirm the uninstall
  • When the program has completed the four steps, click Next to allow the program to search for leftovers
  • Once complete, click Next, then Finish
  • Repeat the above steps for any other programs you wish to remove.

  • 0

#98
bengaluru

bengaluru

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
I got an error message in Revo Unistaller - Running the application's Uninstalled failed. Possible invalid Uninstall command.

And when I click OK, the program run the full course, and then deleted the files.

Thank you so much for all your help.

Enjoy your Time off - well deserved one.

Edited by bengaluru, 25 October 2009 - 07:12 AM.

  • 0

#99
Tweene

Tweene

    Trusted Helper

  • Malware Removal
  • 1,387 posts
Just to be sure, it's gone ?
  • 0

#100
bengaluru

bengaluru

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Yes Tweene. it's gone. Thanks for all your help.
  • 0

Advertisements


#101
Tweene

Tweene

    Trusted Helper

  • Malware Removal
  • 1,387 posts
Great.

You can delete the last programs I asked you to download.


Regards
Tweene
  • 0

#102
Tweene

Tweene

    Trusted Helper

  • Malware Removal
  • 1,387 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP