Author Topic: [Old] - Bit Che 2.0 Release Candidate 4 - Build 35  (Read 322334 times)

Offline ID101

  • Black Box Tester
  • Jr. Member
  • **
  • Posts: 73
  • Karma: +3/-0
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #135 on: April 13, 2012, 09:06:07 pm »
FC@ scrape magnet link form TPB

Offline chip!

  • Bad Ass
  • Administrator
  • Unstoppable
  • *****
  • Posts: 2301
  • Karma: +629/-6
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #136 on: April 14, 2012, 05:22:33 pm »
modi84

can you try the attached .exe?  note:  this will not create the error.txt

i am still working on this, but i am curios if the changes I have made thus far have fixed the problem or not :)


thanks
chip
« Last Edit: April 15, 2012, 02:12:09 pm by chip! »
  -  https://convivea.com  -   And...  boom goes the dynamite.

Offline modi84

  • Newbie Member
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #137 on: April 14, 2012, 08:42:27 pm »
still crashes  :)

Offline chip!

  • Bad Ass
  • Administrator
  • Unstoppable
  • *****
  • Posts: 2301
  • Karma: +629/-6
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #138 on: April 15, 2012, 03:33:39 am »
modi84,

can you go to this folder, and then .rar up all the folders that have bit che in the name?  how many do you have?

%localappdata%\Microsoft\Windows\WER\ReportArchive

type this in either Start | Run or hit  "Windows Key + R"
  -  https://convivea.com  -   And...  boom goes the dynamite.

Offline chip!

  • Bad Ass
  • Administrator
  • Unstoppable
  • *****
  • Posts: 2301
  • Karma: +629/-6
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #139 on: April 15, 2012, 04:17:44 am »
modi84,

here are 3 more test builds.. if one of these doesnt crash, then we are making progress :)

« Last Edit: April 15, 2012, 01:17:26 pm by chip! »
  -  https://convivea.com  -   And...  boom goes the dynamite.

Offline modi84

  • Newbie Member
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #140 on: April 15, 2012, 05:22:58 am »
all crashes  :-\

about "ReportArchive" there are 450+ folders !!
it's too much for you to handle it  :-X

[attachment deleted by admin]

Offline chip!

  • Bad Ass
  • Administrator
  • Unstoppable
  • *****
  • Posts: 2301
  • Karma: +629/-6
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #141 on: April 15, 2012, 01:53:06 pm »
well something interesting in your logs.. more than half of the crashes are related to some file: "ShellIcon32.dll" which is not a Microsoft file, and does not exist on my system. Google searching for that file looks like a number of people are reporting it as a Trojan. My guess is that you are infected with something like this: http://home.mcafee.com/virusinfo/virusprofile.aspx?key=856739

Can you check these locations for "ShellIcon32.dll":

C:\windows\
C:\windows\system32\


If it exists, upload it to www.virustotal.com

Also, put it in an .rar and upload it to me too.


NEXT, I'm going to recommend you do a ComboFix scan on your PC.

Download here: http://www.bleepingcomputer.com/download/anti-virus/combofix

Usage guide: http://www.bleepingcomputer.com/combofix/

When that completes, send me: C:\ComboFix.txt

Thanks
Chip
« Last Edit: April 15, 2012, 02:17:09 pm by chip! »
  -  https://convivea.com  -   And...  boom goes the dynamite.

Offline modi84

  • Newbie Member
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #142 on: April 15, 2012, 07:30:33 pm »
do u want me to delete ShellIcon32 from my computer ?
« Last Edit: April 15, 2012, 07:52:26 pm by modi84 »

Offline chip!

  • Bad Ass
  • Administrator
  • Unstoppable
  • *****
  • Posts: 2301
  • Karma: +629/-6
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #143 on: April 16, 2012, 12:32:27 am »
modi84,
you are definitely infected with a spy trojan, which very closely resembles that one I posted from the mcafee database (above):

2012-04-16 09:01 . 2012-02-20 18:26   47104   ----a-w-   c:\windows\system32\ShellIcon32.dll
2012-03-16 04:40 . 2012-02-20 18:26   261632   ----a-w-   c:\windows\system32\ShellIcon64.dll
2012-03-15 23:48 . 2012-02-20 18:26   261632   ----a-w-   c:\windows\system32\ShellIcon64.dll_[20120316].bak
2012-03-14 06:50 . 2012-02-20 18:26   261632   ----a-w-   c:\windows\system32\ShellIcon64.dll_[20120315].bak
2012-03-12 23:26 . 2012-02-20 18:26   261632   ----a-w-   c:\windows\system32\ShellIcon64.dll_[20120314].bak
2012-03-12 22:02 . 2012-02-20 18:26   261632   ----a-w-   c:\windows\system32\ShellIcon64.dll_[20120313].bak
2012-02-20 18:26 . 2012-02-20 18:26   261632   ----a-w-   c:\windows\system32\ShellIcon64.dll_[20120312].bak

there could be other files, which the mcafee site has shown, but from that log, you were infected back in February 20, 2012.

REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShellIcon1.01]
@="{C5994580-53D9-4125-87C9-F193FC689CC0}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShellIcon1.02]
@="{C5994580-53D9-4125-87C9-F193FC689CC0}"
[HKEY_CLASSES_ROOT\CLSID\{C5994580-53D9-4125-87C9-F193FC689CC0}]
2012-04-16 09:01   47104   ----a-w-   c:\windows\System32\ShellIcon32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShellIcon1.01]
@="{C5994580-53D9-4125-87C9-F193FC689CC0}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShellIcon1.02]
@="{C5994580-53D9-4125-87C9-F193FC689CC0}"
[HKEY_CLASSES_ROOT\CLSID\{C5994580-53D9-4125-87C9-F193FC689CC0}]
2012-04-16 09:01   47104   ----a-w-   c:\windows\System32\ShellIcon32.dll


the .rar file you posted says the ShellIcon32.dll is corrupt, so I'm not sure if you were able to submit to virustotal.com? 

1. first boot back into Safe Mode
2. Move *all* of those files above into a new folder c:\infected
3. .rar them with a password AND encrypt the file names
4. use regedit to remove those Registry entries above
5. update MBAM and scan your computer
6. Reboot back into regular mode, send me the password protected .rar file.
7. I would try using the trial version of McAfee to scan your computer (I would never normally recommend McAfee, but unless we can confirm from virustotal that other antivirus products are detecting your trojan, then I must suggest using the one which we know detects it.  I would also recommend using Microsoft Security Essentials to scan.)

note:  if you are not familiar with any of these steps, then I will have to suggest you consult with a computer technician to help you clean your computer.

the only good news here is that for the past week I have been trying to fix a bug in Bit Che that does not exist :)  So, when you clean your computer, Bit Che will work with no problems! :)
  -  https://convivea.com  -   And...  boom goes the dynamite.

Offline TheHalf™

  • The"better"Half™
  • Hero Member
  • *****
  • Posts: 726
  • Karma: +166/-0
  • Road Runner H.S.I. 30Mbps/5Mbps
    • View Profile
    • Bit Che
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #144 on: April 16, 2012, 12:44:08 am »
True chip, other than paying for a com. tech. I would suggest the factory restore disk which can be run in Safe Mode; correct me if I'am wrong.

TheHalf™

Offline modi84

  • Newbie Member
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #145 on: April 16, 2012, 05:23:26 am »
finally Bit Che works like a boss .. all versions works  ;D

my bro read ur post and he do all the things .. he said everything is ok now

biatche

  • Guest
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #146 on: April 28, 2012, 11:27:55 am »
what does it mean when i double click bitche.exe (2.0b18) nothing happens at all?

it was working before i formatted and now with a clean and up to date system clicking on it doesnt do anything.

Offline chip!

  • Bad Ass
  • Administrator
  • Unstoppable
  • *****
  • Posts: 2301
  • Karma: +629/-6
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #147 on: May 01, 2012, 06:37:41 am »
what does it mean when i double click bitche.exe (2.0b18) nothing happens at all?

it was working before i formatted and now with a clean and up to date system clicking on it doesnt do anything.

Hmm.. try installing Bit Che 1.0 build 60 first... not sure if your system needs additional files.
  -  https://convivea.com  -   And...  boom goes the dynamite.

biatche

  • Guest
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #148 on: May 01, 2012, 10:45:00 am »
worked after installing bit che first... care to explain what happened? what was i lacking? I had %appdata%\... from a backup

registries?

Offline nissensp

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Re: [Work in Progress] - Bit Che - 2.0 build 18 beta
« Reply #149 on: May 05, 2012, 06:09:09 pm »
According to AVG Antivirus 2012 the file zlibwapi.dll is a treath: Trojan Horse BackDoor.Hipigon.3.AE

Patrick