Bad Virus/Trojan scene Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bolexj, Jul 15, 2008.

  1. Bolexj

    Bolexj Private E-2

    I was recently hit with something that I believe is the XP AnitVirus scanner. It was Bad Mojo. I looked up some fixes and tried to follow some directions, but when i rebooted, it was back, ....and meaner then everand did a nice job changing my background as well. I ran HijackThis and tried to stop some obvious bad things from running...for instance rnc7nuj0en3v.exe (i think that is the combination of characters) and i had deleted the actual folder of XP AntiVirus (it was in t a folder of the same name as the exe file) from the drive.

    The XP things may actually be gone now...I ran spybot and it found some reg issues that i had it auto fix. However...i think that it may have taken the opportuntiy to install some other bad stuff while it was at it...

    right now i am getting about 10-15 instances of svchost when i boot up and they are constantly in motion doing things that i KNOW are bad (also using up all my cpu) and something that is called MS-1.exe. If i End all of the processes of MS-1 (and sometimes other -1 files) and all the svchost.exe that are using more than 10,000K (I assume some of the ones that are less than that are real, because if i end the wrong one the machine reboots) then i can acutally use my machine to write this message. otherwise it is pretty much unusable as it is running so much stuff that i dont know about.

    I will post a hijackThis file into the body of this post. Please help...suggestions about what to do and where to get something to remove the crap that I know is on here would be most welcome! I am running something called malewarebytes as I write this...i downloaded it from some other page...i am at a loss...please help! thank you!

    Logfile of HijackThis v1.99.1
    Scan saved at 3:41:33 PM, on 7/15/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Jul 16, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds