CDR-Zone.COM Forum Index Home | Reviews | Software | Guides | Articles | Forum

 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
cant uninstall THEMIDA....help!!

 
Post new topic   Reply to topic    CDR-Zone.COM Forum Index -> Chit Chat
Author Message
EMDY
Newbie
Newbie


Joined: 18 Feb 2006
Posts: 43

PostPosted: Thu Aug 31, 2006 4:26 pm    Post subject: cant uninstall THEMIDA....help!! Reply with quote

i dont know how did the THEMIDA security or something sofware got into my pc...the thing is that everytime i reboot it appears in a window, i cant find how to unistall from the add/remove programs menu.....any help??? i even got into the web site of the soft..but got no luck....
Back to top
SirQUK
Webmaster
Webmaster


Joined: 20 Sep 2002
Posts: 2732
Location: Locked in the CDR-Zone basement

PostPosted: Thu Aug 31, 2006 5:27 pm    Post subject: Reply with quote

It looks like you have downlaoded a software protected by themida http://forums.torrentportal.com/fpost36505.html#36505 Will give you some clues. I would do as suggested and look for anything u have installed recently!
Back to top
Arron
Newbie
Newbie


Joined: 04 Sep 2006
Posts: 1

PostPosted: Mon Sep 04, 2006 11:20 am    Post subject: FOUND A WAY TO DELETE THE THEMIDA WELCOME SCREEN. Reply with quote

IN ORDER TO DELETE THE MESSAGE WHEN YOU LOG ON INTO WINDOWS XP, is to find the name. When logging on click the welcome splash of that Themida once to quit the first bit but dont click it twice(there are two splashs exactly the same). Press alt-control-del to open up that window and there should be a process named 'VMEDIA'. Close it to close the welcome screen. If it the welcome splash screen dissappears you know you've got the right one. Go to windows search by clicking the start button then search is to the right hand side and search 'VMEDIA'. It should detect about 7 files but 3 of them are the virus. They are embedded in system32 folder. Delete the files that have the exact letters 'VMEDIA' in that order, in them. One is an application, one is a file and one is some other crap. To test log off then log back in. This worked for me and I hope it does for you.
Back to top
EMDY
Newbie
Newbie


Joined: 18 Feb 2006
Posts: 43

PostPosted: Mon Sep 04, 2006 6:33 pm    Post subject: Reply with quote

yes...ti did work.....thank you very much...... Laughing
Back to top
guitarrocker
Newbie
Newbie


Joined: 17 Sep 2006
Posts: 20
Location: England

PostPosted: Sun Sep 17, 2006 10:33 pm    Post subject: resolved same problem Reply with quote

as i googled uninstalling themida and got this, to help other people i will amend what was different for me. do the same as the other guy suggests but i believe it isn't called "VMEDIA" in fact its called "WMEDIA" i searched and searched but couldn't find VMEDIA and once running task manager when the splash came up, i discovered it was infact called WMEDIA and then persisted in searching for it and deleting the files. PLEASE NOTE: have half a brain and restart your system as soon as you wipe the WMEDIA files off your computer. hope that helps any confusion
Back to top
SirQUK
Webmaster
Webmaster


Joined: 20 Sep 2002
Posts: 2732
Location: Locked in the CDR-Zone basement

PostPosted: Mon Sep 18, 2006 12:09 am    Post subject: Reply with quote

Thanks to all users for their suggestions in getting rid of this very annoying piece of c**p.
Back to top
Cryfcad
Newbie
Newbie


Joined: 17 Oct 2006
Posts: 1

PostPosted: Tue Oct 17, 2006 5:48 am    Post subject: Reply with quote

So for me it was called server.exe and it was located directly in :\Windows\ folder.. wish you all good luck removing this MF virus.
Back to top
onlyjuhi
Newbie
Newbie


Joined: 18 Oct 2006
Posts: 1

PostPosted: Wed Oct 18, 2006 9:18 am    Post subject: Reply with quote

hi got the same themida c..p on my computer for some reason i have 5 instances of it running and it disables alt+ctrl+del i tried loggin into safe mode but there do when i manage to get into task manager it does not show themida running and i tried searching for vmedia or wmedia still not able to find the infected file someone pls help ty
Back to top
snozzer
Newbie
Newbie


Joined: 28 Oct 2006
Posts: 1

PostPosted: Sat Oct 28, 2006 11:52 am    Post subject: Reply with quote

different again for me.. file was scvhost.exe in C:\Windows\ could only delete in safe mode, deleted file, rebooted and all is good. wot a bugger!
Back to top
chicagoSteve
Newbie
Newbie


Joined: 12 Jan 2007
Posts: 1

PostPosted: Fri Jan 12, 2007 6:29 pm    Post subject: Reply with quote

The name of the service was different for me as well - sys32hx.exe. Just delete the files and reboot.
Back to top
SirQUK
Webmaster
Webmaster


Joined: 20 Sep 2002
Posts: 2732
Location: Locked in the CDR-Zone basement

PostPosted: Fri Jan 12, 2007 8:47 pm    Post subject: Reply with quote

I really hope all of this information in this thread can help users who have been infected. Please keep posting any alterations to this mf u find!
Back to top
Wakefield
Newbie
Newbie


Joined: 18 Feb 2007
Posts: 1
Location: virtually

PostPosted: Sun Feb 18, 2007 3:31 pm    Post subject: Reply with quote

Themida is a commercial packer using kernel rootkit technology. I would suggest that your previous efforts to remove it didn't actually work. Rootkits hide other malware and themselves so your operating system lies to you. Your best bet would be to get some anti-rootkit scanners and some expert help using them. You need expert help because rootkits can hose your system.

Check out this whitepaper on Themida here: http://handlers.sans.org/pbueno/Jansen_ma7.pdf

The following security sites can help you detect and remove rootkits safely:

http://www.aumha.org/

http://www.bleepingcomputer.com/

http://www.castlecops.com/f233-Rootkit_Revelations.html

http://www.geekstogo.com/

http://www.gladiator-antivirus.com/

http://www.malwareremoval.com/

http://www.sysinternals.com/forum

http://www.spywareinfo.com/

http://www.spywarewarrior.com/

http://www.techguy.org/

http://www.TomCoyote.com/

Hope this helps you. All the best!
Back to top
silkykameron
Newbie
Newbie


Joined: 10 Sep 2007
Posts: 1
Location: Newbiggin by the sea, Northumberland

PostPosted: Mon Sep 10, 2007 7:02 pm    Post subject: update on this blested virus of sorts Reply with quote

hi everybody just thought i would mention that i got this problem also when i tried to download some phone software. anyway not to babble.

when doing a search for names that this software may be under it also comes under the name of himma or hima.

thats all
SilkyKameron
Back to top
CDR-Zone.COM
Advertisement Bot


Posted:     Post subject: Advertisement:

Back to top
Display posts from previous:   
Post new topic   Reply to topic    CDR-Zone.COM Forum Index -> Chit Chat All times are GMT
Page 1 of 1

 


Powered by phpBB © 2001, 2005 phpBB Group