Infected with Malware, please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by raptur86, Jun 23, 2009.

  1. raptur86

    raptur86 Private E-2

    The problem came up yesterday, I downloaded a program through uTorrent, and only after running the keygen file in it, did I realize that someone had posted on isohunt that it was a Trojan. Now whenever I boot up windows (vista basic) it says Windows Explorer has stopped working and is restarting. Then everything seems to run fine for a while until some audio ads start playing.

    I can get the ads to stop by going to the Task Manager and ending a process that just has a bunch of random numbers. At first the process would just keep reappearing, although now that I've run the READ & RUN ME FIRST.Malware removal guide it seems that the process that I mentioned doesn't reappear after I end it. Though I still have the Windows Explorer restarting problem, and the process and ads do still show up when I first start the computer.

    After following the tutorial, the SuperAntispyware worked (I'm attaching the logs, it says it deleted a couple of Trojans) but the Malwarebytes, Combofix and Rootrepeal did not. When I tried to start those programs it simply says that the program has stopped working and it has to be closed. When that happened with Rootrepeal it also made a few .txt files appear on my desktop that seem to show what error happened, I'll attach those too.
    I ran the MGTools and it seemed to work fine, I'll attach the log.

    Please any help you could give me would be really appreciated!
     

    Attached Files:

  2. raptur86

    raptur86 Private E-2

    Here's the MGTools log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The very first thing you need to do is to uninstall Messenger Plus! Live!! This is probably the root of most of your problems.

    Now, let's continue with the below:

    Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now see if you can run the scans for:
    MBAM
    ComboFix

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * MBAM and Combo
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds