HELP: Trojan or Malware infected computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by txstovalls, Aug 23, 2007.

  1. txstovalls

    txstovalls Private E-2

    Help, something has attacked my computer and I'm getting all kinds of problems. Many "application error" boxes pop up saying things like DLG.exe, BILLMINDER.exe, can't be opened, and many other strange .exe files I don't even recognize. Also get all kinds of pop ups, etc when web-browsing. I get a system alert popup in my start tray asking me to click to download some software trojan remover, etc.
    I used the below thread from this website (although closed) and followed all the instructions. I now have the HJT file that I'm wondering if I should post?

    forums.majorgeeks.com/showthread.php?t=35407 (MALWARE REMOVAL GUIDE)

    HELP!!!!

    -txstovalls
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com, please follow our standard cleaning procedures:

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
    • Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around..
    http://www.majorgeeks.com/images/grenade.gifWhen you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • CounterSpy Log - only for Windows XP, 2K, & NT users
    • AVG Antispyware Log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender Log - from step 6
    • Panda Scan Log - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis Log
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. txstovalls

    txstovalls Private E-2

    Thanks. Ok, I think I've covered all the bases here.
    1. Nothing to remove by "ADD/REMOVE PROGRAMS"
    2. Completed MSConfig Startup Mode
    3. Installed CCleaner (ran and post is below)
    4. Hidden files already "viewable"
    5. One Anti-Virus running
    6. Downloaded GetRunKey
    7. Downloaded ShowNew
    8. Downloaded Spybot
    9. WOULD NOT ALLOW ME TO RUN COUNTERSPY
    10. Therefore downloaded/ran AVG Anti-Spyware
    11. Rebooted into safe mode
    12. Ran Spybot but would not allow me to "fix" much since I did not subscribe.
    13. Attached below are posts:
    CCleaner, AVG Anti-Spy, and HJT

    Edit by bjgarrick: Inline logs attached!
     

    Attached Files:

    Last edited by a moderator: Aug 28, 2007
  4. abri

    abri MajorGeek

    Hi txstovalls!!
    You seem to have made it as far as here in point 4 of the READ & RUN ME FIRST instructions:
    Please do the following:
    Once you've done this, please continue with the instructions as per Step 5. Do not rerun CCleaner and AVG Antispyware if you've already done them in Safe Mode as per the instructions. We still need to see the following:
    • ComboFix Log
    • BitDefender Log
    • Panda Log
    • ShowNew Log
    • GetRunKey Log
    • a fresh HijackThis Log
    Do not do Step 8. This will be done only after your computer has been declared clean.

    You will have to post twice to attach all the logs, because you can only make three attachments with each post.

    Thanks!
    abri
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You need to update your HJT, your current version is way out dated.

    You also need to run AVG AntiSpyware again and this time remove all found infections, do not Ignore them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds