Marik Posted December 1, 2010 Share Posted December 1, 2010 Well I just found this after I rebootedHijack This found them F3 - REG:win.ini: load=U???F3 - REG:win.ini: run=U???I'd say it's pretty much safe to delete them yes?and also, where in the registry do I find those other two entries? :unsure: Link to comment Share on other sites More sharing options...
implague Posted December 1, 2010 Share Posted December 1, 2010 this mite help you Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 already consulted it...both are listed as nastyI never had these before, so I'm guessing their badalso found those other twoWindows Registry Editor Version 5.00[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Load]"key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows""item"="縘粐粐粐Ÿ踠踘ਸ਼粑Ƚ""hkey"="HKCU""command"="縘粐粐粐Ÿ踠踘ਸ਼粑Ƚ""inimapping"="1"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Run]"key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows""item"="縘粐粐粐Ÿ踠踘ਸ਼粑Ƚ""hkey"="HKCU""command"="縘粐粐粐Ÿ踠踘ਸ਼粑Ƚ""inimapping"="1" Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted December 1, 2010 Administrator Share Posted December 1, 2010 That's written in Chinese. The last time I had something like this, I was infected by a deadly Chinese keylogger which allowed the hacker to hack my msn mail account. Mentioned it many times, you must b knowing. It made thousands of folders into folders into folders which were empty but were written in chinese. Same with registry, folders into folders into folders, all with chinese names but empty. Scanned my system with everything but was not able to find anything. Then, to everyone's surprise, Microsoft Malicious Software Removal Tool found two keyloggers who's IP I traced to china via WireShark. Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 when I saw your avatar I almost mistook you for Shought :lol:...running the mrt now Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted December 1, 2010 Administrator Share Posted December 1, 2010 Yeah I'm watching South Park these days, got shought's viral. :bag:You can also try MBAM, it's known to remove registry infections. Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 I did try MBAM, and it removed two entries...one was trojan/work, and the other I can't remember, but it was bad as well Link to comment Share on other sites More sharing options...
HX1 Posted December 1, 2010 Share Posted December 1, 2010 Ohhwwa.. you catchuh deadwy Chinese viroos.. Vewy dangewous.. vawwwy rwaaaare.... - Crank2 :lmao: Just DON"T go jumping out of any airplanes anytime soon..Yeah I have like no entries in that area... I would have suggested probably checking it with SpyBot.. Definitely odd.. I found some Chinese labeled files in my Windows folder awhile back.. but I think that they have something to do with my AMANA Screensaver.. I wasn't for sure.. still not.. but nothing picks them up as anything..EDIT: Did see some other stuff you should probably clean.. just in the little bit of the Log I seen.. Link to comment Share on other sites More sharing options...
tipo Posted December 1, 2010 Share Posted December 1, 2010 use trojan remover to scan your pc. TR is not created to detect trojans and other bad stuff but the modifications to the system created by the malware. Link to comment Share on other sites More sharing options...
unknownasphyxiated Posted December 1, 2010 Share Posted December 1, 2010 try this to check any leftoverOTL = Hijackthis on steroiduse Sysinternals Autoruns to double check your systemRunScanner is also another good software to inspect youur systemuse GMER to detect rootkitalways be with me when dealing with infection Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 autorunsis the IE thingy supposed to be like that or is it dubious?btw, these things all started after I installed Megakyes Link to comment Share on other sites More sharing options...
Brrownie Posted December 1, 2010 Share Posted December 1, 2010 That's it Marik, Chinese are after you now :ph34r: ... Never mess with the Chinese girls !!! somebody going down ..Aye be a man, do the right thing ( Russell Peters):lmao: Try UnHackMe 2. Tizer Rootkit RemovalTo be honest I dont use S&D much now days...but saying that its not to say I will never use it again.Malwarebytes and Superantispyware are the best at the moment but there not 100%Cheers Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted December 1, 2010 Administrator Share Posted December 1, 2010 So megakey is culprit. Didn't you use a sandbox? Any results from MRT (yet)? Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 So megakey is culprit. Didn't you use a sandbox? Any results from MRT (yet)?no I didn't use a sandbox. MRT found absolutely nothingMBAM found the culprits....really the only thing left to deal with are those 4 entries in the msconfig and regedit listingtrojanremover found squat as expected, and so did Spybotthe only thing I wanna know is that if it's safe to delete those registry entries in my first post...the one's with run and load and the two in hijackthis Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted December 1, 2010 Administrator Share Posted December 1, 2010 You should backup your registry, and then remove them. Link to comment Share on other sites More sharing options...
unknownasphyxiated Posted December 1, 2010 Share Posted December 1, 2010 don't remove the key,just remove the datayou can ignore file not found About:Homealso you can remove HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ {Load and run} Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 don't remove the key,just remove the datayou can ignore file not found About:Homealso you can remove HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ {Load and run}did just that, then rebooted...everything is working as it should be....no more error messages about crap being missing at bootup, and no more slowdownsi may just watch pr0n anime (can u spot the troll?) to celebrate Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted December 1, 2010 Administrator Share Posted December 1, 2010 don't remove the key,just remove the datayou can ignore file not found About:Homealso you can remove HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ {Load and run}did just that, then rebooted...everything is working as it should be....no more error messages about crap being missing at bootup, and no more slowdownsi may just watch pr0n anime (can u spot the troll?) to celebrate How about sharing your celebration? :hehe: Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 hah...while I was at it...I also registered youruninstaller with a serial after one month of trying :lmao: Link to comment Share on other sites More sharing options...
Alpha1BA Posted December 1, 2010 Share Posted December 1, 2010 DL ASquared (Emsisoft) portable (tiz free) stick it on a usb/flash run update then full scan and try that just to make sure (scan will take a while), they are one of the "ones" I trust! also run a decent registry cleaner afterwards Link to comment Share on other sites More sharing options...
myidisbb Posted December 1, 2010 Share Posted December 1, 2010 dang hentai games :P joking. i do hope you using a second computer for now until you clean the other one.edit. read the above one wher eyou said you fix it. btw what anime etc was it, ffull file name and format? newsgroups? if so which one Link to comment Share on other sites More sharing options...
Marik Posted December 1, 2010 Author Share Posted December 1, 2010 dang hentai games :P joking. i do hope you using a second computer for now until you clean the other one.edit. read the above one wher eyou said you fix it. btw what anime etc was it, ffull file name and format? newsgroups? if so which oneYosuga no Sora ep 09 by UTW Can't wait to see my twincest in ep 10 http://utw.me/2010/12/01/yosuga-no-sora-09/and the world god only knows ep 9 by horriblesubshttp://horriblesubs.org/ Link to comment Share on other sites More sharing options...
myidisbb Posted December 1, 2010 Share Posted December 1, 2010 dang hentai games :P joking. i do hope you using a second computer for now until you clean the other one.edit. read the above one wher eyou said you fix it. btw what anime etc was it, ffull file name and format? newsgroups? if so which oneYosuga no Sora ep 09 by UTW Can't wait to see my twincest in ep 10 http://utw.me/2010/12/01/yosuga-no-sora-09/and the world god only knows ep 9 by horriblesubshttp://horriblesubs.org/so was it the website then? Link to comment Share on other sites More sharing options...
Marik Posted December 2, 2010 Author Share Posted December 2, 2010 I honestly have no idea what you're saying....:rofl:I think along the line, you misinterpreted my words, then I misunderstood yoursif you're talking about what caused my PC to get effed up in the first place, then like I said, it's due to Megakyes Link to comment Share on other sites More sharing options...
myidisbb Posted December 2, 2010 Share Posted December 2, 2010 I honestly have no idea what you're saying....:rofl:I think along the line, you misinterpreted my words, then I misunderstood yoursif you're talking about what caused my PC to get effed up in the first place, then like I said, it's due to Megakyesno problem wsnt giong to use that thing anyway. guess you guinie pig itthank s Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.