Help needed please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by philippe, Jan 5, 2006.

  1. philippe

    philippe Private E-2

    Hello,

    I have been fighting for 3 days to get my connection back and access your excellent forum. 3 days ago, my computer just froze, and I could not reboot in normal mode, could only access the Presario menu to restore using the D: drive. Which I did, and modifying the boot file in safe mode allowed me to stop the viruses to spread. It even killed Antivir. I almost have none of my application installed but I can at least post this thread.

    I followed the instructions in the "Start Here" thread. I've attached the log files for BitDefender (I had to split the log file in 2 because of the size), Panda Activescan (I only put half of it) and Hijack This. Any help would be greatly appreciated.
    Many Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! It seems like many of the files on your system are infected!

    Why are your running without an antivirus program and no firewall? This is a very bad idea.

    Did you run Panda or Bitdefender first?
     
  3. philippe

    philippe Private E-2

    Hi,

    I ran Bitdefender first. Regarding Antivirus, Antivir was killed by the first attack, so I removed it and Norton Firewall was slowing down the web too much.
    Can we still do something ?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Slowing down the web will happen when protecting tools are installed. Your alternative approach to not use them normally results in infected machines (like yours) and sometimes worse (like theft of important info or maybe a system that will not boot at all).

    I see remnants of both AntiVir and Panda in your log but neither of them are complete programs and are not doing anything.

    Have HJT fix the below two lines:
    O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
    O4 - HKLM\..\RunOnce: [Panda_cleaner_224707] C:\WINDOWS\System32\ActiveScan\pavdr.exe 224707

    Then remove the delete the below:
    C:\Program Files\AVPersonal <--- the whole folder
    C:\WINDOWS\System32\ActiveScan <--- the whole folder

    Now running scans with the following tools in the following order:
    avast! Virus Cleaner Tool - No installation required! Ready to run as is. Tell me if it finds anything.
    McAfee AVERT Stinger......- No installation required! Ready to run as is. Tell me if it finds anything.
    TrojanScan - Save and post the log

    Then I would try downloading, installing, updating and running ONE of the below:
    Avast! Home Edition
    AVG Free Edition

    Let me know what happens and post the logs.
     
  5. philippe

    philippe Private E-2

    Thanks.

    C:\Program Files\AVPersonal was not there, but I did the rest.

    Avast found tons of parite-B (log too big), I rebooted as advised and Stinger found (log attached).

    Then I installed AVG which found nothing.

    I keep on having the following message whenever I boot:

    "mdmxsdk.sys is needed"
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you re-run Avast now, does it come up clean? What about other scanners like Panda and BitDefender?

    See this for your missing file:

    http://www.file.net/process/mdmxsdk.sys.html

    I assume this is for a modem? Do you use one of their modems? Perhaps you need to reinstall drivers.
     
  7. philippe

    philippe Private E-2

    Funny enough, i don't think I even have a modem in the machine, and I don't need it. Since the problem started and was able to boot into safe mode again, it started to show this error message, trying to start this SOFT V92 MODEM DATA FAX (that XP does not recognise) and then was looking for the correct path to load mdmxsdk.sys. Is there a way to cancel the startup of this modem ?
    I began to run Bitdefender but stopped it half way (too long)
    I ran Panda (log attached)
    I run AVG, doesn't seem to find anything.

    I still don't have a firewall. Which one would you recommend ?
    Thanks a lot.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Windows Explorer to locate and delete the below:

    C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\entou0cc.default\cookies.txt[]
    C:\Documents and Settings\Propriétaire\Cookies\propriétaire@tribalfusion[1].txt
    C:\Program Files\Save\ACM.dll
    C:\WINDOWS\inf\dm.inf

    Note the below is considered adware and should be delete but deleting it may have an impacted on P2P file sharing programs if you are using any.
    C:\WINDOWS\smdat32m.sys

    Was BitDefender finding any problems?

    Look in Add/Remove programs to see if you have any modem software installed and also check Device Manager to see whether you have any modem hardware installed.
     
  9. philippe

    philippe Private E-2

    Deleted everything you said. BitDefender not finding anything.
    No Modem software installed, but "SM Bus controler" not installed and "Simplified communication PCI controller" is with a yellow ! in the management console.
    Could not find any modem harware, the system information panel is not showing any.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. philippe

    philippe Private E-2

    Ok, thanks for this. Do you think you fixed the malware pb then ?
     
  12. philippe

    philippe Private E-2

    I reboot and everything seems to run fine. No more errors.
    Thanks a million. Really appreciate your help. Merci.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. philippe

    philippe Private E-2

    Thanks again !
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  16. philippe

    philippe Private E-2

    it's coming back !!! Look at the log from AVG. Thanks.
     
  17. philippe

    philippe Private E-2

    Is this a question of automatic restore that I did not switch off ?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What's in particular is coming back! And what AVG log are you referring to?

    Yes system restore should have been toggle to disabled and then enabled to remove bad restore points but I'm not sure that is why you are getting reinfected (if you are reinfected).

    Where did you go surfing, did you install or run anything new?
    Did you restore anything from backups on floppies, CDs, or flash drives etc? They could be infected, since many of the files on your system already were infected, anything you had previously saved or copied elsewhere (even to other PCs) could be infected.
     
  19. philippe

    philippe Private E-2

    Sorry the AVG log did not uopload, here it is.
    When AVG ran the automatic scan, it found 400 Parite-B viruses. Since then, I scaned with avast or bitdefender which found nothing. I am not sure about how to proceed regarding bad restore points. Except this AVG bad log, everything seems to run fine.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not back! Those are system restore files.

    Complete step 1 of the READ & RUN ME.
     
  21. philippe

    philippe Private E-2

    Ok, thanks a lot !
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds