Malware HELP!!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ANGELLS077, Feb 12, 2009.

  1. ANGELLS077

    ANGELLS077 Private E-2

    Please help!!! I have been getting a blue screen popping up at radom causing me to restart my computer. I have ran everything in order and still nothing..... it does say i have a trojan..... i have attached logs
     

    Attached Files:

  2. ANGELLS077

    ANGELLS077 Private E-2

    Malware HELP pt2

    ok here is my last attachment for my trojan problem
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Looks like your Norton Antivirus got in the way you running ComboFix since you do not have a log from it and it appears to have crashed. It may not really matter at this point as remaining issues you may be having are most likely not related to malware.

    Yes some items were removed and we have little more minor tweaking to do, but your crashes are most likely due to other problems. You will need to work them in the Software Forum.

    What is the below startup process for?
    O4 - HKCU\..\Run: [AbacastDistributedOnDemand:11] C:\Documents and Settings\Ronnie\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe -r:11 -x:1

    Did you purchase the below programs? If not, I suggest that you uninstall them now.
    Registry Mechanic 8.0
    Uniblue System Tweaker

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    iWin Games (remove only) <-- should have been uninstalled in step 1 of the READ ME
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 6
    Java(TM) 6 Update 7
    MyWay Search Assistant <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
    O8 - Extra context menu item: &Search - ?p=ZKxdm174YYUS

    Also optional fix the below unnesssary startups that are wasting system resources
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKUS\S-1-5-21-305973704-553336853-3892624212-1006\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'Ryan and Jamie')
    O4 - HKUS\S-1-5-21-305973704-553336853-3892624212-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Ryan and Jamie')
    O4 - HKUS\S-1-5-21-305973704-553336853-3892624212-500\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'Administrator')

    After clicking Fix, exit HJT.

    Now delete the below file
    C:\WINDOWS\system32\CF5886.exe

    Now reboot your PC

    After reboot, delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Ronnie\Local Settings\Temp

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds