Trojans have attacked and won

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cwalker86, Jul 25, 2006.

  1. cwalker86

    cwalker86 Private E-2

    I tried reading the posts and downloading several different tools to get rid of these trojans, but they won't budge. I have Mcafee, and tried using there removal tools with no avail. I purchased xoftspy, but that didn't work. When I ran a virus scan earlier today, I had 147 trojan programs infecting my computer. All of them had one of the following names:

    Generic Downloader.y
    Generic Downloader.c
    Generic MultiDropper.d
    Exploit-Byte verify
    Adware-TVMedia
    Downloader-EV
    Downloader-AFY

    There all exisit is some file by the name of C\:_RESTORE\TEMP\......

    The file is write-protected and won't let me delete, clean or quarntine anything.

    I payed to have a technician at Mcafee take over my computer remotley, but that didn't work. I am running Windows ME. I ran the ME startup disk, and ran a scan in dos mode, but that didn't work. I contacted McAfee again, and they said that should have fixed it, and there was nothing else to do. HELP!!!!! This is driving me crazy. Thank you.
     
  2. matt.chugg

    matt.chugg MajorGeek

    Welcome to MajorGeeks cwalker86! :)

    - Please run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.



    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:


    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)

    Bitdefender
    Panda Scan
    HijackThis

    Good Luck!:)
     
  3. cwalker86

    cwalker86 Private E-2

    Okay...I followed all of the instructions from the 'READ and RUN ME FIRST." I have attached logs from the bdscan and HTJ. When I ran all the other scans, the programs either found and removed the problems or no problems were found. However, the trojans are still present. Please help, I don't know what else to do. Thanks!!!
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    HijackThis is not installed correctly. Move HijackThis to C:\Program Files\HJT. Once you have moved HJT; rename hijackthis.exe to analyse.exe

    Download DelDomains and unzip it to your desktop.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    Afterwards run Spybot and make sure you re-Immunize immediately. Then run a full system scan. If you get any reported problems, attach the log from Spybot.

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Post a fresh HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds