infected explorer.exe etc.

Discussion in 'Malware Help (A Specialist Will Reply)' started by effingdelf, Feb 21, 2009.

  1. effingdelf

    effingdelf Private E-2

    Ok so i may be a little vague, been trying to sort this out for far too long.
    came home to find my computer with no explorer running and set about trying to sort it out.
    im sorry if it makes it difficult, i didnt follow your guide from the start because i only found this site an hour ago. but ill tell you what i have done.
    using programs including spybot / spyware doctor (full edition) / malwarebytes and a couple vundofix programs i found quite a few infections of virtumonde, along with other things like win32.delf.uc (which i dont seem to be able to get rid of)
    so i cleaned them off, this didnt really seem to help things, i now can use my pc in safe mode and explorer doesnt close. This is when i found your site, and since then ive followed all your cleaning etc. steps.
    i cant install SUPER anti spyware, something about the administrator has disabled installations of that type, but everything else is done.
    i have been considering just reinstalling winXP, however im not sure how it would work, because i have XP installed on one of my hard drives and Vista on the other, would they both need to be reinstalled??
    also i have a lot of data and not so much space to backup to, unless i want to sit here with DVD's all day.

    i shall include a couple more logs from last night to help you recognize my problems.

    any help you can give is greatly appreciated, and as i said im very tired so i may edit this to keep it up to date
    Gregg
     

    Attached Files:

  2. effingdelf

    effingdelf Private E-2

    other files

    again sorry this is messy.
    an updated MBAM log is here also, along with a DDS log i did from another program, not sure if it will be helpful, the info might be out of date but will show what ive had atleast.

    also, when i run MGtools i get this pop up message 'The application failed to initialize properly (0xc000007b). Click on OK to terminate the application'

    thanks again
     

    Attached Files:

  3. effingdelf

    effingdelf Private E-2

    also managed to get the SUPER anti spyware working, here is its log
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. We are currently reviewing your logs and will get back to you with a set of instructions as soon as I possibly can. Thanks for you patience during this time.

    Kes13!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have fallen victim to one of the latest attacks that is affecting system files. Notice your Combo log....this means that no matter what we remove, you will still have system files ( even the ones in your i386 folder) that are infected which open ports to download additional malware. The only option you have is to save your data and files and do a complete reformat and re-installation.

    Kestrel13!
     
  6. effingdelf

    effingdelf Private E-2

    nice...
    just what id always wanted :)
     
  7. effingdelf

    effingdelf Private E-2

    actually if you could tell me one more thing, like i said i have win xp installed on one hard drive and vista on the other - do i have to completely format everything?? or just my xp installation?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run Combo on the Vista partition......You may just need to reformat the xp partition.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds