Computer #2 help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Flowerchild, May 18, 2005.

  1. Flowerchild

    Flowerchild Private E-2

    I am now working on my 2nd computer which is in worse shape than my first one I think :eek:

    Whatever is going on here has taken over this computer. It took over my nortons and I had to delete it so I could try to download one of the free ones you guys suggest but I cant get a anti virus to download my computer freezes or I get booted off. I did manage to get a firewall downloaded (zone alarm) and all the other things in the read me page.

    I am still getting popups and fake window update pages. I cant download updates off of microsoft because whatever has control here wont allow it or I get their (the trojan) download permission window which of course I am not gonna download.

    I ran stinger in safe mode and it found and deleted a w32.sdbot.worm.gen.i it was in my c/windows/dumpreg.exe. Stinger found nothing else. I just ran it again and it says I am clean now but I'm still having problems.

    I ran adaware and found more errors but less than I had, I clicked fix and I think it deleted them but I still have problems.

    Spybot says I am clean.

    Symantec scan showed of course I have no antiviral program on my computer.

    Trend micro found a troj dloader.mg and said its noncleanable. its in c/windows/system32/config.

    I ran a hijack this if you need the file. I feel I have done everything I can do and now need some help. Thanks so much.
     
  2. Flowerchild

    Flowerchild Private E-2

    I found some further items you probably need to know about. I downloaded microsoft antispyware, it found IST items and searchmiracle items, those were deleted, ran the scan again and found searchmiracle.elitebar a browser plug in in my HJT backup files. Also a xrenoder browser plugin, these things just keep coming back. I delete them and they pop right back up they seem to have a mind of their own. I am still trying to download antiviral which isnt working out.
     
  3. Flowerchild

    Flowerchild Private E-2

    I finally got avast! to download, so I must be making some progress by myself. It found a couple trojans w32.trojano-1252 and w32.lowzones-m, they were deleted, I havent had a popup but the computer seems to freeze up, really it just runs very slow sometimes. I have run thru all the steps in the read me first page again and as of now everything is coming up clean. I just need someone to check my HJT log to make sure I got everything. I also downloaded spy sweeper but for some reason its not responding anymore. Not sure if something else is interferring or not. I have learned tons of stuff bout computers these past couple of weeks, I have come to the conclusion I never want to deal with trojans or worms again, ugh!

    I know something is still wrong with my windows update , can someone tell me how to fix that??
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run all of the READ ME FIRST steps (or at least as many as possible given your problem), follow the steps below.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. Flowerchild

    Flowerchild Private E-2

    Thank you :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\WINDOWS\System32\mcafe32.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Windows Media Player] mcafe32.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] mcafe32.exe
    O4 - HKCU\..\Run: [Windows Media Player] mcafe32.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\mcafe32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    What did TrendMicro find? What file name? Is it still there?
     
  7. Flowerchild

    Flowerchild Private E-2

    Trend micro found a troj dloader.mg and said its noncleanable. its in c/windows/system32/config. I clicked delete, does that delete it from my system?? I couldnt find the file, I did go thru and delete a bunch of stuff I knew I didnt download and that seemed to help. I have been able to do windows updates this morning.

    I didnt see any of the mcafe files you posted, I did delete the prefetch file.

    Heres the new log, thank you for your help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! Was that log before or after doing Windows Update?

    Are you having any problems?
     
  9. Flowerchild

    Flowerchild Private E-2

    Excellent! Thanks so much! The log was after a few window updates, still doing updates few at a time. Havent had any problems today.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You should check out the steps in the below thread to help keep you clean. The first step is Windows Update. You should try to get yourself up to SP2 level.

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds